Custom software for sanctions screening of relations and payments
Sanctions screening fails at two moments, and neither is the moment you take on a new relationship. It fails when a list changes while your file stays the same, and when there is a match and nobody knows who must act now. The first is a systems question, the second a process question.
Screen, freeze, report
Under the Sanctions Act 1977 and the Supervision Regulation based on it, institutions must screen their relationships against the sanctions lists, both at the start of the relationship and periodically thereafter. If the identity of a relationship matches a person or entity under sanctions regulations, funds must be frozen immediately and no further service may be provided.
In addition there is a reporting obligation: a match must be reported to the supervisor without delay. This is not a quarterly return but an action at the moment itself, and she requires that someone is available to carry it out, including on a Friday afternoon.
What makes the task difficult is that sanctions lists change without your customer file changing. A relationship that was clean last month may appear on a list today, and nobody at your firm has done anything. Screening only at the start does not cover that situation, and that is exactly the situation where things go wrong in practice.
This page covers the relationship register, re-screening whenever a list changes, and resolving false matches. The check at the point where the transaction takes place, at a viewing or at the loading bay, is described separately in the transaction sanctions screening app.
How we build this
A change to a list is the trigger here, not the customer. If your register is re-screened as soon as a list changes, screening becomes continuous rather than a one-off event.
Customers, suppliers, ultimate beneficial owners, intermediaries. This scoping decides the entire scale of the exercise and is a legal decision rather than a technical one.
Which lists you include and how changes come in. This is the engine of the system; anyone working on this manually is screening against outdated information.
As soon as a list changes, your register is run through it again. That is the only way to find the relationship that came in clean.
Who assesses, who freezes, who reports, and within what timeframe. Without those roles defined in advance, a match on a Friday afternoon becomes a problem rather than an action.
What the software actually does
Re-screening on list changes carries the whole approach. Which components you need depends on your sector and the size of your relationship register.
Screening at onboarding and on an ongoing basis
Every new relationship is screened, and the entire register is re-screened whenever a list changes. It is the second that catches the matches onboarding screening misses.
A relationship register covering all parties involved
Not only the contracting party but also ultimate beneficial owners, directors and intermediaries, to the extent your framework requires. A match on a beneficial owner counts just as much.
Matches with freezing and reporting
A match becomes a process with roles and a clock: assess, freeze, report. The system records every step with time and person, because that is your accountability after the fact.
Name variants and false matches
Transliterations, alternative spellings and namesakes produce matches that are not actual matches. The system stores, for each assessment, why something was not a match, so the same name does not have to be reviewed again every month.
Rationale retained for each decision
Who assessed what, when and on what basis, against which version of the list. In supervision, it is that reasoning that matters, not the outcome as of today.
Connecting to your own systems
Relationships live in your CRM or accounts system and payments in your payment system. We connect to these through integrations, rather than creating a second relationship file.
Who we build for
The obligation reaches further than the financial sector alone. Four situations.
Supervised financial institutions
For you this is set out in the Supervision Regulation, with a reporting obligation towards your supervisor. The challenge lies in re-screening and in the quality of your name matching, not in whether you must screen at all.
Trade and export
Sanctions apply not only to persons but also to goods and destinations. Screening relationships alone does not cover your risk if you supply to a country subject to measures. You gather the supply chain data you need for that with CSDDD software.
Insurers and pension providers
Long relationships with many beneficial owners, whose data may be years old. Here, ongoing re-screening delivers more than stricter checks at onboarding. Reporting to your supervisor often runs through a regulatory reporting platform.
Service providers outside the financial sector
Notaries, estate agents, accountants and advisers face comparable obligations, often alongside their own frameworks. The system is then lighter, but the question is the same. See also KYC and AML software.
Test your idea first: a working prototype in 1 day
With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.
Explore OneDayBuild →Technology and integrations
The legislative framework is moving: a bill is before parliament that would largely replace the Sanctions Act 1977. Everything relating to lists, thresholds and reporting routes should therefore be configurable and retained per version.
For trade, industry and logistics firms that need to screen customers, suppliers and owners, there is our sanctions list screening tool.
Why Appfront
The list changes, your records don't
We re-screen on every list change. Screening only at onboarding inevitably misses the relationship that came in clean and was later listed.
False positives are the real work
Name variants and namesakes generate noise that numbs your staff. For each decision we record why something was not a match, so the same name doesn't come back every month.
Honest about what is changing
A bill is before parliament that would largely replace the Sanctions Act 1977 and is still under consideration. We build on what applies today and keep lists, thresholds and routes configurable.
Your related-party data already exists
Relationships live in your CRM and payments in your payment system. We connect to these through integrations; a second file would inevitably drift out of step.
Security and privacy
A system that records which relationships were assessed and why certain matches were dismissed holds sensitive judgements about individuals. A wrongful match left on file can follow someone for years, and an undocumented dismissal is a problem under supervision. We therefore restrict access by role, separate assessing from recording, and log every inspection.
With a genuine match, the picture changes. You then process data about someone subject to measures, which is processing under a legal obligation with its own retention regime. What you want to avoid is that this information circulates more widely than necessary; in practice the circle allowed to see a match is smaller than the circle that screens. We build that separation in and ensure reports to the supervisor go through a fixed route rather than by email. How we handle security ourselves is set out in our information security policy; external reports come through our vulnerability disclosure policy.
Frequently asked questions about sanctions screening
At the start of the relationship and periodically thereafter. What delivers the most in practice is re-screening as soon as a list changes, because that is how you find the relationship that came in clean and was later listed. Which frequency suits your organisation is for your compliance function to determine, not your software supplier.
If a person or entity matches sanctions legislation, funds must be frozen immediately, no further services may be provided, and this must be reported to the supervisor without delay. This mainly requires agreed roles: who assesses, who freezes and who reports, including outside office hours.
A bill, the International Sanctions Measures Act, would largely replace the Sanctions Act 1977 and was submitted in early 2026. Its passage is still under way and critical questions have been raised. The current law therefore applies; we build on it and keep lists, thresholds and reporting routes configurable so that a change does not mean a rebuild.
By recording why a hit was not a true match and reusing that outcome for as long as the underlying data stays unchanged, you avoid the same name returning every cycle, which would have your team clicking through faster and risk missing the real match at some point. The sensitivity of the name comparison is a configurable setting, not a fixed choice.
They overlap, but they are not the same. KYC and AML concern knowing your customer and flagging unusual transactions under the Dutch Anti-Money Laundering and Anti-Terrorist Financing Act (Wwft); sanctions screening concerns checking against lists with a direct freezing and reporting obligation. See KYC and AML software; in practice they share the same customer file.
The Sanctions Act is not limited to financial institutions, although supervision there is the most developed. Trade, export and service providers can also be affected, and it often concerns not only individuals but also goods and destinations. Your lawyer will determine what applies to you.
Yes, and this is common in practice: alongside the mandatory lists, institutions keep their own list of parties they do not wish to work with. That list is separate from the legal obligation and should also be recorded separately, as the consequences of a hit are different.
That depends on the size of your customer file, how many lists you include and whether the hit process needs to include freezing. Screening with re-checking is usually quick to put to use and immediately shows how much noise your current approach generates. We give a reasoned estimate after the initial assessment.
Continuous screening rather than only at onboarding?
Check when your file was last fully re-screened and how many list changes have occurred since then. That gap is your risk today. We build this as a standalone application and as part of a broader custom software project.