Back to all articles
SCALESUCCESSCOMPLIANCE

Sanctions and Watchlist Screening for SMEs: Minimal Setup to Reduce EU Sanction Risks and Regulatory Risks

·
30 min
Sanctions and Watchlist Screening for SMEs: Minimal Setup to Reduce EU Sanction Risks and Regulatory Risks

Author: NEXORA Unternehmensberatung GmbH Date: January 2026 Reading time: approx. 11 minutes

The 5 most important points at a glance:

  • EU sanctions affect every SME that works with third countries, distributors or sensitive goods – regardless of whether you have direct business with Russia. Supply chains, export and payment transactions can harbor sanction risks.
  • A minimal setup can also work without expensive software: With clearly defined trigger events, assigned responsibilities and simple documentation, SMEs can establish effective sanctions screening.
  • Four central checkpoints form the core: Business partner screening during onboarding, checks for export and payments, regular re-checks in risk cases, and structured handling of hits.
  • Structured processes can reduce concrete risks: Liability risks towards authorities, problems with banks (account terminations, payment stops) and reputational damage can be significantly reduced through comprehensible, documented procedures.
  • Official EU Guidance provides the legal framework: In its guidelines on the circumvention of sanctions, the European Commission explicitly mentions “appropriate due diligence” for EU operators – this article shows how SMEs can derive a pragmatic setup from this.
Why SMEs are affected – realistic business cases without scaremongering

Many SME owners and managing directors assume that sanctions compliance is only relevant for large corporations or companies with direct business with Russia. This assumption is risky, because EU sanctions are broader than often assumed.

Typical SME situations with sanction risks

Export of machinery or software via distributors: An Austrian machine manufacturer exports CNC milling machines via a distributor in Turkey or the United Arab Emirates. The distributor sells on – possibly also to sanctioned countries. If the Austrian manufacturer does not carry out an appropriate check (due diligence), it may unintentionally contribute to constructions that could be regarded as circumvention of EU sanctions.

Complex supply chains with intermediaries: An IT service provider obtains hardware components via several intermediaries. Suddenly new suppliers appear, the delivery is to take place via “free trade zones” or third countries. Such constructions may indicate possible circumvention attempts – keyword re-export risk.

Increased bank controls in payment transactions: Your bank is increasingly asking questions about payments to certain countries or to business partners. Or worse: payments are blocked, accounts are terminated. Banks are themselves regulated and carry out intensive sanctions screening. If your company cannot prove that it carries out its own appropriate checks, you can quickly become a high-risk customer.

FMA risks for non-supervised SMEs – what does that mean in concrete terms? - FMA risks arise for non-directly supervised SMEs primarily indirectly – for example, through stricter sanctions checks by their banks and other institutions supervised by the FMA. With the Sanctions Act 2024 (SanktG 2024), which came into force on February 11, 2025, the Austrian National Council has created the legal basis for the implementation of financial sanctions. From 01/01/2026, the FMA will take over the central supervisory function for compliance with financial sanctions from the OeNB and is authorized to impose administrative penalties for violations.

What does that mean for SMEs in practice?

  • Your bank (FMA-supervised) tightens compliance requirements and can terminate accounts or stop payments if documentation is insufficient
  • If there is a suspicion of sanctions violations, banks may be obliged to report them to the FMA
  • Direct contacts between non-financial SMEs and the FMA on sanctions issues remain rather exceptional cases – the regulation typically takes place via the financial intermediaries
Why “We have no Russia business” is not enough

EU sanctions include far more than Russia. The EU has established sanctions regimes against numerous countries and individuals – from Belarus to Iran to specific terrorist organizations and individuals involved in human rights violations. In addition, there is the risk of sanctions circumvention: Even if you do not deliver directly to sanctioned countries, your products or services can reach them via detours.

The European Commission has clarified in its Guidance on Circumvention of Russian Sanctions (2023): EU operators must carry out “appropriate due diligence” that is adapted to their business model and risk profile. In sectors with an increased risk of circumvention, even “enhanced due diligence” is expected.

What is “Sanctions and Watchlist Screening”?

Definition on AML/KYC : What is checked and why?

Sanctions and Watchlist Screening is a systematic process with which EU operators (companies that are based in the EU or have to apply EU law) check their customers, suppliers, distributors, beneficial owners (Ultimate Beneficial Owners, UBOs) and relevant transactions against various risk lists. These lists include:

  • EU sanctions lists (consolidated lists of persons, organizations and institutions against whom EU sanctions have been imposed)
  • UN sanctions lists (e.g. terrorism lists; Note: the binding nature of UN sanctions in the EU takes place via EU legal acts)
  • Other watchlists, depending on the risk profile (e.g. PEP lists for politically exposed persons, Adverse Media)
The goal: To ensure that your company does not violate the prohibition of making funds or economic resources available to sanctioned persons or organizations, and that you are not involved in circumvention constructions.

Distinction from AML/KYC – where are the overlaps?

Many SMEs are already familiar with the terms AML (Anti-Money Laundering) and KYC (Know Your Customer). These concepts primarily aim to combat money laundering and terrorist financing. Sanctions screening has a different legal focus, but is often integrated into the same framework organizationally.

Comparison AML/KYC vs. Sanctions Screening:

ElementSanctions ScreeningAML/KYC
GoalCompliance with sanctions prohibitions (provision of funds/resources to sanctioned persons/entities, export embargoes)Combating money laundering and terrorist financing
Legal sourcesEU sanctions regulations (CFSP decisions, Council Regulations), Sanctions Act 2024 (AT)AMLD 4/5/6, Austrian Financial Market Money Laundering Act (FM-GwG), CDD obligations
Typical checkpointsComparison against EU/UN sanctions lists, export/import control, circumvention risks in supply chainsCustomer identification, risk assessment, transaction monitoring, suspicious activity reports to the Financial Intelligence Unit/FMA at supervised institutions
Typical OwnerCompliance, Legal, CFO, Export-Control-OfficeCompliance, Money Laundering Officer, Legal

Practical overlap: Legally, sanctions obligations and AML obligations are based on different EU regulations and directives; organizationally, they can be combined in an integrated risk framework. The data points (name, address, UBO) are often the same, and the audit logic is similar.

Information sources: EU Sanctions Map and official lists

The EU Sanctions Map (https://www.sanctionsmap.eu/) is a central information portal of the European Union. It offers:

  • An overview of all EU sanctions regimes by country
  • Links to the official legal acts (Council Regulations and Decisions)
  • The consolidated list of sanctioned persons and entities
Important note: The EU Sanctions Map is an information and navigation aid, but not the legally authentic source. Only the texts published in the Official Journal of the European Union and on EUR-Lex are legally binding. However, the map makes access much easier for SMEs without having to work through hundreds of pages of EUR-Lex documents.

Minimal setup in 7 building blocks

Effective sanctions screening for SMEs does not have to be complex or costly. The key is to define the right processes, clearly assign responsibilities and document your checks in a comprehensible manner. The following seven building blocks form the foundation.

4.1 Scope & Risk Trigger – which cases do you have to check?

Not every customer and not every transaction requires the same level of screening. A risk-based approach helps you to use resources efficiently:

Define your scope:

  • Business partners (customers, suppliers, distributors) with headquarters or economic ties to sanctioned countries or high-risk jurisdictions
  • Export of certain goods or technologies (dual-use goods, sensitive technologies)
  • Payments to or from third countries with an increased risk of circumvention (e.g. according to EU Guidance on Russia Sanctions)
  • Transactions with unusually high amounts or unclear end users
Define internal trigger events: Clearly define when a screening must be carried out – for example, for new business partners, new destination countries, unusual payment methods or if your bank asks questions. You will find a list of practical trigger examples further down in the article.

4.2 Responsibilities – Owner, Backup and Escalation Paths

A common problem in SMEs: Nobody feels explicitly responsible for sanctions compliance, questions “get bogged down” between sales, purchasing and accounting.

Name a Sanctions Owner:

  • Typically the CFO, Head of Finance, Legal or Compliance
  • This person is responsible for the implementation of the screening processes, decisions in the event of hits and the documentation
  • In addition, name a deputy in case the owner is absent
Define clear escalation paths:
  • Sales/Purchasing/Finance report conspicuous cases (trigger events) to the Sanctions Owner
  • Owner decides on screening measures and evaluates hits
  • In the case of complex or unclear hits: Escalation to the management and – if necessary – to external, specialized legal or compliance advice
4.3 Data points and identifiers – what you need at a minimum

The quality of your screening results depends directly on the quality of your master data. Poor or incomplete data leads to many “False Positives” (false alarms) and makes the work considerably more difficult.

Minimal data set for legal entities (at least):

  • Full company name (incl. legal form)
  • Registered office/address
  • Commercial register number
  • VAT number (if EU)
  • If possible: Information on beneficial owners (UBOs) and control structures
Minimal data set for natural persons (at least):
  • Full name (first and last name)
  • Date of birth
  • Nationality
  • If applicable, place of birth
Important: Maintain name variants and spellings carefully. Sanctions lists often contain transliterated names (e.g. from Cyrillic or Arabic scripts) that can appear in different variants. Therefore, you should document common spelling variants and consciously work with variants in the event of hits.

4.4 Screening process – when and how is it checked?

A structured screening process integrates into your existing business processes:

Process flow overview:

    • Trigger detected
    • Data collection (name, address, UBO etc.)
    • Screening against EU/UN lists
    • Evaluation (Hit/False Positive/No Hit)
    • Escalation (in case of uncertainty)
    • Decision (Release/Rejection/Conditions)
    • Documentation & Filing
Concrete screening points:

Pre-Contract Screening:

  • Check new business partners (customers, suppliers, distributors) before concluding contracts
  • Particularly important for partners in high-risk jurisdictions or in sensitive industries
Invoice/Order Level Screening:
  • For certain characteristics (country, amount, type of goods), also check at invoice or order level
  • Practical example (no legal requirement): Export of dual-use goods, payments over e.g. EUR 50,000 to third countries (threshold to be determined individually by the company)
Payment Level Screening:
  • Before executing payments to risk-relevant countries or to unknown recipients
  • Coordination with your accounting/treasury department
Periodic Review (regular repeat check):
  • A possible orientation: High-risk partners (sensitive countries, industries, high amounts) annually or in the event of trigger events, standard risk partners every 2–3 years or in the event of significant changes (UBO change, business model, new markets)
  • Event-related re-check in the event of trigger events
4.5 Hit Handling – False Positives, Escalation and Documentation

Not every hit during screening is a real hit. The challenge lies in distinguishing False Positives (false alarms) from real matches.

Structured approach to hits:

  • Initial check: Do the name, date of birth, address or other characteristics really match? Similar names or common spellings often lead to false positives.
  • Plausibility check: Are there any other indications that confirm or exclude a match (e.g. industry, business activity, public information)?
  • Escalation in case of uncertainty: If you are not sure whether it is a real hit, get a second opinion – internally (management) or externally (specialized legal or compliance advice).
  • Documentation of the decision: Record in writing why you have assessed a hit as a false positive or why you reject or terminate a business relationship. This documentation can serve as important evidence for banks, auditors and, if necessary, authorities.
Principle of “appropriate due diligence”: The term “Best Efforts” is not an official legal term, but describes an appropriate, documented level of due diligence as expected by the EU Guidance. In practice, EU operators cannot achieve 100% certainty – the key is that they take appropriate, documented measures that correspond to the risk. A documented, comprehensible process is more important than perfection.

4.6 Recordkeeping & Audit Trail – which documents to keep?

Complete documentation is not only “nice to have”, but essential. It protects you during audits by banks, auditors or authorities and helps you with internal investigations.

What should you keep?

  • Screening logs: Date, list/source used, search criteria, result (no hit/hit/false positive)
  • Hit analysis: Documentation of your assessment (why false positive, why real hit)
  • Escalation correspondence: E-mails, notes on internal discussions, external legal advice
  • Releases/Decisions: Who made the final decision (business relationship yes/no)?
  • Communication with banks: If your bank asks questions or blocks payments
Retention periods: In Austria, a minimum of 7 years generally applies according to tax regulations; in the sanctions context, longer retention may be useful in complex cases (after individual case assessment).

Filing structure: Use a simple, consistent system – such as a separate folder “Sanctions Screening” with subfolders per year and business partner.

4.7 Training & “Do/Don't” Rules for Sales, Procurement and Finance

Even the best setup is of little use if your employees do not know when and how to use it.

Practical training for front teams:

  • What is a sanction?
Brief explanation of why EU sanctions are relevant to the company
  • Which risks affect our business?
Concrete examples from your business area (export, supply chain, payment transactions)
  • Who do I report conspicuous cases to?
Clear reference to the Sanctions Owner and escalation paths
  • What are typical red flags?
See next section on trigger events

Do/Don't list for practice:

DO:

  • Inform the Sanctions Owner early on about new countries or business partners
  • Report conspicuous payment instructions or detours via third countries immediately.
  • Document any conspicuous issues in writing, even if you are unsure.
DON'T:
  • Blindly accept contract changes that obscure the real end recipient.
  • Execute payment instructions to third countries without consultation and approval from the Sanctions Owner.
  • Under pressure from business partners, make quick deliveries without clarifying end users.
10 examples of trigger events – when you should prick up your ears

The following situations should trigger an internal screening or at least a query to the Sanctions Owner:

  • New distributor in a third country close to sanctioned countries – e.g. Turkey, UAE, certain states in Central Asia – depending on the product, industry and current EU guidance for products that are also in demand in Russia.
  • Unexpected demand from a country that appears in the EU Sanctions Map as sanctioned or partially sanctioned – e.g. sudden inquiries from Belarus, Iran, North Korea.
  • Request to deliver goods via an alternative intermediary or a "free zone" – especially if the explanation remains vague or deviates from usual practice.
  • Change of the beneficial owner (UBO) shortly before larger orders – may indicate an attempt to circumvent sanctions.
  • Conspicuous pricing or unusually high margins for certain markets – possibly indicates re-export activities or smuggling.
  • Payments are to be made via banks or financial intermediaries in high-risk jurisdictions – e.g. via Russian, Iranian or other sanctioned banks or intermediaries that are named in EU sanctions lists.
  • Request to label goods "neutrally" or rewrite documents to obscure the end user or destination country – a clear red flag for circumvention.
  • Repeated refusal to provide sufficient information about the end user – legitimate business partners should be transparent.
  • Substantial negative media reports or indications of sanctions risks with existing or new partners – for example, in adverse media screening or Google searches.
  • Indications from your bank of "sanctions risk" or increased queries about transactions – take such signals seriously; banks often have stricter internal processes and recognize patterns earlier.
Documentation that really counts – the 1-page evidence list

Many SMEs shy away from compliance measures for fear of bureaucratic effort. The good news is: you don't need a 50-page policy. What counts is Minimal-Viable-Documentation – lean, but complete.

Your 1-page evidence list should include:

  • Process description (1/2 page):
  • Brief description: What is checked, when, by whom?
  • Reference to trigger events
  • Escalation routes
  • List of defined trigger events (1/4 page):
  • Bullet point list as in the section above
  • Screening evidence per case:
  • Screenshot or export from used list/tool (incl. date, search criteria, result)
  • Note: Even if there is "no match", you should document that you have checked
  • Hit-Handling Protocol:
  • Short form for each hit: Date, description, analysis, decision, signature
  • You can find a template in the download package below
  • Training certificates:
  • Agenda, list of participants, short handout of the last training
  • Sufficient 1x annually for existing teams, individually for new hires
  • Filing of correspondence:
  • Folder with relevant e-mails on bank inquiries, authority contacts, external consultations
Storage: Maintain a central digital or physical filing system. Simplest setup: a folder "Sanctions Compliance" with subfolders per year and thematic categories.

10 common mistakes made by SMEs – and how to avoid them

  • "We don't have any Russia business, so we don't need a sanctions setup."
→ Deceptive. EU sanctions affect many countries, and circumvention risks also arise in third countries.
  • No defined owner – sanctions questions "peter out" between departments.
→ Solution: Appoint a clear Sanctions Owner with decision-making authority.
  • Screening only for new customers, not for distributors, suppliers or payments.
→ Risk: You miss circumvention structures in the supply chain or in payment transactions.
  • No documented process for hit handling – decisions remain informal.
→ Problem: During audits, you cannot prove that you have checked appropriately.
  • No clean database (name variants, missing UBO information).
→ Consequence: High false-positive rate, inefficient screening, frustration.
  • Reliance on bank screening as the only measure: "The bank will check everything anyway."
→ Error: The EU Guidance expressly addresses the responsibility of the respective EU operator itself. Banks are a supplement, not a replacement.
  • No training for front teams – red flags are not recognized or not reported.
→ Solution: Invest in short, practical training sessions at least once a year.
  • No regular review of the program for new markets or products.
→ Risk: Your setup no longer fits your actual risk profile.
  • Use of unofficial or unclear lists without understanding the source/quality.
→ Error: You do not know whether your checks are legally sufficient. Use official EU sources.
  • Missing disclaimer/reference to external advice for complex export or embargo questions.
→ Problem: SMEs are not sanctions specialists. If you are unsure, you should seek external expertise.

"What to do next?" – Your 14-day Quick-Win Plan

You don't have to plan for months. With this 14-day plan, you lay the foundation for a functioning minimal setup:

Day 1–2: Roles and As-Is Analysis

  • Appoint your Sanctions Owner and Deputy
  • Do a quick check of your existing processes: How do you currently create customers, suppliers and payments? Where could sanctions checks be integrated?
Day 3–5: Trigger Events and SOP Draft
  • Define 5–10 concrete trigger events for your company (use the examples from this article)
  • Create a 1-page SOP for screening and hit handling (basic version) – use the templates from the download package as a starting point
Day 6–8: Selection of Screening Sources
  • Decide which lists you use: At least EU Sanctions Map (as a navigation aid) / EUR-Lex (legally binding) / official EU lists
  • Optional: Evaluate professional screening providers (if budget is available), but if necessary, start with manual checks against official lists
Day 9–11: Set up documentation routine
  • Create a simple filing structure (digital or physical)
  • Create templates: Screening protocol, hit handling form
  • Define who files what where
Day 12–14: Training and decision on external support
  • Conduct a 1-hour training session for Sales, Procurement and Finance (use the Do/Don't list from this article)
  • Decide whether you want to book an external Sanctions Quick-Check or a Policy Package (see CTA below)
After 14 days you have:
  • A defined owner
  • A list of trigger events
  • A 1-page basic SOP
  • A simple documentation structure
  • Trained employees
This is your minimal setup – and it can provide a solid foundation.

When should you involve authorities or specialized advice?

Not all sanctions questions can be clarified internally. In the following situations, you should consider external expertise or contact with the authorities:

Contact with Austrian authorities:

BMF (Federal Ministry of Finance) / FMA (Financial Market Authority):

  • For questions regarding the interpretation of the Sanctions Act 2024
  • If you have any ambiguities about the application of financial sanctions
  • Contact information can be found at: https://www.bmf.gv.at/ and https://www.fma.gv.at/
OeNB (Oesterreichische Nationalbank):
  • For practical information on sanctions (especially historical cases until 2025-12-31)
  • Contact: https://www.oenb.at/
BMEIA (Federal Ministry for European and International Affairs):
  • For questions on foreign policy sanctions, embargoes and export controls
  • Contact: https://www.bmeia.gv.at/
Involve specialized legal/compliance advice in the case of:
  • Unclear hits with high transaction volumes or critical business relationships
  • Export of dual-use goods to sensitive jurisdictions
  • Complex UBO structures with high-risk partners
  • Official inquiries or suspicion of sanctions violations
  • Establishment of sanctions compliance for first-time export/import business
FAQ – Frequently Asked Questions about Sanctions Screening for SMEs

1. Does this really apply to every SME – even without export business?

Answer: Yes, as soon as your company makes payments, maintains business relationships or uses supply chains that may have a sanctions dimension. This also includes domestic business if your business partners are themselves internationally active or have unclear ownership structures. EU sanctions regulations are generally directly applicable and affect all companies in the EU.

2. Is it sufficient if our bank does sanctions screening?

Answer: No. The EU Guidance on the circumvention of sanctions explicitly addresses the responsibility of the "EU operator" – i.e. your company. Banks carry out their own checks to fulfill their own regulatory obligations. However, these do not replace your own due diligence. If your bank discovers a problem and you cannot prove your own checks, you risk account terminations or payment stops.

3. Do we have to check every business partner against all global lists?

Answer: No, you should proceed risk-based. Focus on EU and UN sanctions lists as well as lists that are relevant to your business model and target markets. An Austrian furniture retailer that only operates in the DACH region typically does not need global PEP screening. An exporter of dual-use goods to third countries does.

4. How often should we re-screen existing customers?

Answer: That depends on the risk profile. A possible practical orientation (no legally prescribed intervals, but risk-based recommendation):

  • High-risk partners (sensitive countries, industries, high amounts): annually or in the event of trigger events
  • Standard risk partners: every 2–3 years or in the event of significant changes (UBO changes, business model, new markets)
  • Low-risk partners (EU customers, established relationships): every 3–5 years or on an ad hoc basis
These intervals are practical examples and do not replace an individual, risk-based determination. You should adapt the actual intervals to your business model.

5. Which tools are suitable for SMEs?

Answer: This article deliberately remains tool-neutral. More important than the software are clear processes, good data quality and comprehensible documentation. For SMEs with a limited budget, manual checks against official lists (EU Sanctions Map as a navigation aid, EUR-Lex for legally binding lists, UN lists) can be a starting point. Professional screening tools offer automation, better data quality and fewer false positives – the investment is worthwhile from a certain number of transactions. The tool selection is a case-by-case decision.

6. What happens if we overlook something despite screening?

Answer: What is decisive is whether you have established an appropriate, documented program that reflects a reasonable level of due diligence (as described in the EU Guidance). If you can prove that you have taken measures appropriate to the risk, defined processes and provided training, the liability risk may be significantly lower – compared to a situation in which you have done nothing at all. In case of doubt or complex cases, you should seek specialized advice at an early stage or, if necessary, contact the responsible authorities.

7. How does sanctions screening differ from AML/KYC?

Answer: AML/KYC focuses on money laundering and terrorist financing and includes customer identification, risk assessment and transaction monitoring. Sanctions screening aims to comply with specific prohibitions (provision of funds/resources to sanctioned persons, export embargoes). Legally, these are independent obligations arising from different EU regulations. Organizationally, many SMEs can bundle both in an integrated risk framework – the data points and audit processes often overlap.

8. Where can we find official information on EU sanctions?

Answer:

  • EU Sanctions Map: https://www.sanctionsmap.eu/ (information and navigation portal; only the texts published in the Official Journal are legally binding)
  • EUR-Lex / Council of the EU: Primary sources for sanctions regulations and decisions (legally authentic source)
  • European Commission: Guidance documents on the circumvention of sanctions
  • Austria:
  • Federal Ministry of Finance (BMF) / Financial Market Authority (FMA): Information on the implementation of financial sanctions since 2026-01-01
  • Oesterreichische Nationalbank (OeNB): Practical information (historically until 2025-12-31)
  • Federal Ministry for European and International Affairs (BMEIA): Information on embargoes and foreign policy sanctions
  • Austrian Economic Chambers (WKO): Practical information for companies (as far as official)
Self-Assessment: How mature is your sanctions screening?

Answer the following questions with Yes/No to assess your current status:

No.QuestionYesNo
1Do you have a designated Sanctions Owner with clear responsibilities?[ ][ ]
2Is there a written list of trigger events for when screening must take place?[ ][ ]
3Do you check new business partners against sanctions lists before signing a contract?[ ][ ]
4Do you have a documented process for hit handling?[ ][ ]
5Are screening results and decisions documented in a comprehensible manner?[ ][ ]
6Have your sales/purchasing/finance teams been trained in the last 12 months?[ ][ ]
7Do you carry out regular re-checks with risky business partners?[ ][ ]

Evaluation:

  • 6–7 Yes: Very good! You have a solid basic setup. Optimize continuously and stay up to date on new sanctions.
  • 3–5 Yes: Good start, but there are gaps. Prioritize the missing elements in the next 3–6 months.
  • 0–2 Yes: Critical. You should start the 14-day plan immediately or book a Sanctions Quick-Check.
Next step: Contact NEXORA for a 90-minute remote Quick-Check and concrete recommendations.

Download Packages – Templates for Direct Use

You can use the following three documents as a basis for your own setup. They are deliberately kept lean – adapt them to your business model.

A) SME Sanctions Screening – 1-Page SOP (Outline)

Purpose and scope:

  • This SOP regulates sanctions and watchlist screening for [Company Name]
  • Scope: All relevant business partners (customers, suppliers, distributors) and relevant transactions and UBOs
  • Objective: Compliance with EU sanctions and avoidance of circumvention risks
Roles and Responsibilities:
  • Sanctions-Owner: [Name, Function] – responsible for screening process, hit evaluation, escalation
  • Backup: [Name, Function]
  • Reporting points: Sales/Purchasing/Finance report trigger events to Sanctions Owner
Trigger Events (when is a check performed?):
  • New business partner
  • New destination country (outside established markets)
  • Payments above defined threshold (to be determined individually, e.g. [Amount] EUR) in third countries
  • Export of sensitive goods/technologies
  • UBO changes with existing partners
  • Indications from the bank of sanctions risks
  • Substantial negative media reports regarding business partners
  • Unusual payment methods or detours via third countries
  • Request to conceal documents/end use
  • [add more individually]
Process steps:
  • Data collection: Collect minimum data according to section 4.3 (name, address, UBO where possible)
  • Screening: Comparison against EU Sanctions Map (as a navigation aid) / EUR-Lex (legally binding) / official lists [or tool used]
  • Assessment: No match / False Positive / plausible match?
  • Escalation: In case of unclear matches → Sanctions-Owner → if necessary, management/external advice
  • Decision: Approval / Rejection / additional conditions
  • Documentation: Complete and file screening protocol, hit-handling form
Reference to official sources:
  • EU Sanctions Map (navigation aid): https://www.sanctionsmap.eu/
  • EUR-Lex / Council of the EU (legally binding): Consolidated sanctions lists
  • BMF/FMA: National implementation (Austria from 01/01/2026)
  • OeNB: Practical information (until 12/31/2025)
Version: 1.0 | Date: [DD.MM.YYYY] | Next review: [DD.MM.YYYY+1]

B) Hit-Handling Form (Template)

FieldDescription
Date of review[DD.MM.YYYY]
Reviewing person[Name, Function]
Business partner[Company name / Name of person]
Type of transaction/relationship[ ] New customer [ ] Existing customer [ ] Supplier [ ] Payment [ ] Export
Description of the hitList/Source: [e.g., EU Sanctions Map] Found name: [...] Type of match: [ ] Exact [ ] Similar [ ] Unclear
Analysis (False Positive or plausible?)Reasons for False Positive: [ ] Different spelling [ ] Different date of birth [ ] Different country/address [ ] Different industry/activity Reasons for plausible match: [ ] Name and date of birth match [ ] Address/country matches [ ] Further information: [...]
Escalation[ ] Not required [ ] Escalated to: [Name, Function, Date] Result of escalation: [...]
Decision[ ] Approval – Business relationship/payment is continued [ ] Rejection – Business relationship/payment is rejected [ ] Additional conditions: [...]
Signature/ApprovalSanctions-Owner: ________________ Date: ______ Management (if required): ________________ Date: ______
Storage location/reference number[e.g., Folder “Sanctions 2026", File name “..."]

C) SME Checklist: Trigger & Documentation

Part 1: Trigger Checklist (check off for each potential sanctions case)

  • New partner (customer/supplier/distributor)
  • New country or unusual route
  • Payment above threshold in a third country
  • Export of sensitive goods/technologies
  • UBO change
  • Unusual payment methods
  • Request for concealment
  • Negative media/Adverse Media
  • Bank notification of sanctions risk
  • Rejection of end-user information
Part 2: Minimum Documents per Case
  • Screening Report (with date, source, result)
  • Hit-Handling Form (in case of a hit)
  • Internal decision (email/note)
  • External advice (if necessary)
  • Owner approval (signature/email)
Part 3: Open Points / Follow-Ups
DateDescriptionResponsibleStatus
[DD.MM.YYYY][e.g., Re-Check Partner X after 6 months][Name][ ] Open [ ] Completed
[DD.MM.YYYY][e.g., Training for new employees][Name][ ] Open [ ] Completed

Retention periods:

  • General: At least 7 years (based on tax deadlines)
  • Complex/sensitive cases: Possibly longer after individual assessment
NEXORA Unternehmensberatung – Your support for Sanctions Compliance

SME Sanctions Quick-Check (Remote, 90 minutes)

Would you like to know where your company stands on the topic of sanctions screening?

What you get:

  • Structured review of your existing setup (or status quo, if no setup exists yet)
  • Rapid Gap Analysis: What is missing, what is already in place?
  • Concrete priority list for the next 3–6 months
  • Recommendations for quick wins and critical points
Format: Remote session via video conference

Target group: SME owners, CFOs, Compliance officers

Policy/SOP Package + Training (Fixed Scope)

Would you like a structured, documented program – without investing months in conception?

What you get:

  • Creation or update of your sanctions and screening policies including SOPs
  • Adapted templates (screening protocol, hit-handling form, checklists)
  • Compact training for your sales, procurement and finance teams (1–2 hours, practical)
  • Integration into existing AML/KYC frameworks (if available)
Format: Fixed Scope project, remote or on-site (Vienna and surrounding area)

About NEXORA Unternehmensberatung GmbH

NEXORA is a Vienna-based boutique consultancy focusing on Compliance, RegTech, Market Entry and digital processes for financial service providers, FinTech startups and SMEs in Austria, Germany and Switzerland.

Our services in the area of Sanctions & Screening:

  • Conception of pragmatic, implementable minimal setups for SMEs
  • Integration of sanctions screening into existing AML/KYC frameworks
  • Training courses and workshops for your teams
  • Support with tool selection and implementation (product-neutral, without sales interest)
  • Ongoing Advisory and Trouble-Shooting for specific sanctions cases
Our approach: We believe in "Compliance that works" – no 200-page policies that nobody reads, but clear processes that fit into your everyday business.

Sanctions compliance is part of the broader development towards clean financial centers, zero-tolerance policies against financial market crime, and the FATF recommendations as well as the EU AML package. NEXORA supports SMEs in meeting these requirements in a practical manner.

Disclaimer – Important legal notices

No legal advice: This article provides general information and does not replace individual legal advice. The requirements for sanctions compliance depend on the specific business model, jurisdiction and risk profile of your company.

Individual case review required: In the case of specific export, embargo or high-risk constellations, you should consult specialized legal or compliance advice. NEXORA Unternehmensberatung GmbH offers compliance consulting, but not legal advice within the meaning of the Lawyers Act and the Lawyers' Fees Act.

Official sources are decisive: When implementing, always rely on the official sources of the EU and the responsible national authorities. The EU Sanctions Map is a helpful information and navigation portal, but not the legally authentic source – you will only find this in the Official Journal of the EU and on EUR-Lex, and these do not replace consultation of the legal acts published in the Official Journal of the EU. Lists and information on third-party websites should only serve as a supplement.

Dynamic legal situation: The Sanctions Act 2024 has formed the legal basis for the implementation of financial sanctions in Austria since 11.02.2025. Since 01.01.2026, the central supervision has been with the FMA. These regulations may continue to develop – consult the official sources (BMF, FMA, OeNB) regularly.

Disclaimer: NEXORA Unternehmensberatung GmbH assumes no liability for damages arising from the use of the information contained in this article. All information is provided without warranty.

Sources & further links

EU level:

  • EU Sanctions Map: https://www.sanctionsmap.eu/ – Information and navigation portal on EU sanctions (Note: not a legally authentic source; only the texts published in the Official Journal are legally binding)
  • European Commission – Guidance on the circumvention of sanctions: https://finance.ec.europa.eu/eu-and-world/sanctions-restrictive-measures_en
  • Council of the European Union / EUR-Lex: https://eur-lex.europa.eu/ – Primary sources for sanctions regulations and decisions (CFSP decisions, Council regulations) – legally authentic
  • Consolidated EU Sanctions List: https://data.europa.eu/data/datasets/consolidated-list-of-persons-groups-and-entities-subject-to-eu-financial-sanctions
Austria:
  • Federal Ministry of Finance (BMF): https://www.bmf.gv.at/ – Information on the implementation of financial sanctions
  • Financial Market Authority (FMA): https://www.fma.gv.at/ – Central supervision of financial sanctions since 01.01.2026, practical information on Sanctions Act 2024
  • Oesterreichische Nationalbank (OeNB): https://www.oenb.at/ – Practical information on sanctions (especially historical cases until 31.12.2025)
  • Federal Ministry for European and International Affairs (BMEIA): https://www.bmeia.gv.at/ – Foreign policy sanctions and embargoes
  • Austrian Federal Economic Chamber (WKO): https://www.wko.at/ – Practical information for companies on export control and sanctions (as far as official)
UN level:
  • UN Security Council Sanctions Lists: https://www.un.org/securitycouncil/sanctions/information – UN sanctions (Note: Binding in the EU via EU legal acts)
© 2026 NEXORA Unternehmensberatung GmbH. All rights reserved.

Need a consultation?

Book a free initial consultation with the NEXORA team.

Free Consultation