🦚 Happy Krishna Janmashtami!

Sanctions Screening in Banks: A KYC-AML Exam Guide (2026)

KYCAML By Ashish Jain · IIBF STORE Editorial · 09 July 2026 · Updated 22 Aug 2026 · 7 min read · 46 views
Sanctions Screening in Banks: A KYC-AML Exam Guide (2026)

Sanctions screening in banks sits at the sharp end of financial-crime compliance — it is the control that stops a designated terrorist, proliferator, or sanctioned entity from moving money through the banking system undetected. For KYC-AML aspirants, this topic bridges customer onboarding, transaction monitoring and correspondent banking, and it shows up repeatedly in exam scenarios built around watchlist hits and cross-border wire transfers. This guide covers what sanctions screening in banks actually involves, which lists matter, how the alert-to-disposition workflow runs, and where Indian banks sit relative to global sanctions regimes such as UNSC and OFAC.

🔍 What Is Sanctions Screening in Banks?

Sanctions screening is the process of checking customer names, beneficial owners, counterparties and transaction parties against official lists of individuals, entities, vessels and countries that are prohibited or restricted from dealing with the financial system. It runs at three points: onboarding (before an account is opened), on an ongoing basis (whenever list updates are published), and in real time on payment messages before funds move. It is distinct from routine customer identity checks — a customer can be perfectly "known" and still generate a sanctions hit if a name matches a designated party. In India the legal backbone for this control sits in directions issued under the Unlawful Activities (Prevention) Act, layered on top of each bank's own compliance programme covered under correspondent banking risk assessments.

🌍 Key Sanctions Lists and Watchlists

Banks typically screen against a handful of core lists, each issued by a different authority and with different legal force inside India. Knowing which list is binding and which is screened for commercial/currency-exposure reasons is a frequent exam distinction.

Sanctions ListIssued ByPrimary UseBinding on Indian Banks
UNSC Consolidated ListUnited Nations Security CouncilTerrorism & proliferation financing✅ Yes, via domestic notification
OFAC SDN ListUS Department of the TreasuryUS-dollar clearing, secondary sanctionsNot directly binding
EU Consolidated ListEuropean UnionEU-linked trade & correspondent flowsNot directly binding
MHA/UAPA ScheduleMinistry of Home Affairs, IndiaDomestic terror-financing control✅ Yes, mandatory

Even where a list isn't legally binding in India, banks with correspondent accounts in US dollars or euros screen against it anyway — a foreign correspondent can freeze a nostro relationship over a repeated OFAC exposure regardless of Indian law.

💡 Exam Tip: If a question asks which list is legally mandatory for an Indian bank versus screened for commercial reasons, UNSC/UAPA lists are mandatory; OFAC/EU lists are typically "risk-based" screening.
Key Concepts — KYC, AML and CFT
Key Concepts — KYC, AML and CFT

⚙️ How the Screening Process Works

Screening software runs fuzzy name-matching, not exact string matching, because sanctioned names are transliterated from Arabic, Cyrillic and other scripts and Indian names carry huge spelling variation. Each match generates a similarity score; anything above the bank's threshold becomes an alert for a human reviewer. Reviewers use date of birth, nationality, address and transaction context to decide whether a hit is a true match or a false positive. This workflow sits alongside the broader compliance standards discussed in international guidelines and standards, and it complements — but does not replace — the risk-based due diligence framework banks build for every customer relationship. Payment-message screening additionally checks originator and beneficiary fields on SWIFT messages before the funds are released, which is why cross-border wires can be delayed for manual review even when the underlying customer relationship is entirely clean.

🚩 Handling Alerts and False Positives

Common names generate the overwhelming majority of screening alerts, and most resolve as false positives after a documented review. Where a hit is confirmed as a true match, the bank must freeze the funds or refuse the transaction, escalate to the compliance/nodal officer, and consider a report to the Financial Intelligence Unit. A second reviewer (four-eyes) typically signs off on true-match decisions given the operational and reputational stakes. Weak alert disposition is also how banks get exposed to related typologies — a screening gap on a shell counterparty can mask trade-based money laundering moving through invoice mismatches rather than a direct sanctioned-name hit.

⚠️ Common Mistake: Treating every screening alert as a false positive because "the name is common" — each hit needs a documented rationale, not just a gut call, or the bank's own audit trail collapses under regulatory review.
Process & Framework — KYC, AML and CFT
Process & Framework — KYC, AML and CFT

🏦 Correspondent Banking and Cross-Border Risk

Sanctions exposure concentrates in correspondent banking, where an Indian bank relies on a foreign bank to clear US dollar or euro payments. Nested and downstream relationships — where a respondent bank lets its own customers use the correspondent account — multiply the screening burden because the foreign bank often can't see the ultimate originator. This is one reason global banks have "de-risked" out of certain corridors entirely rather than carry the compliance cost. These controls sit alongside other operational-risk safeguards a bank maintains, from correspondent due diligence to the defences covered in our guide on ransomware attack prevention. Aspirants studying the FATF-aligned global standards behind these expectations should also read our breakdown of the FATF 40 Recommendations, and keep an eye on evolving guidance via our IIBF news resource.

📌 Remember: A clean sanctions screen at onboarding does not stay clean forever — every list update must be re-run against the existing customer base, not just new accounts.

Official sources: cross-check the latest syllabus, circulars and rates on the IIBF official website and the Reserve Bank of India.

In Practice — KYC, AML and CFT
In Practice — KYC, AML and CFT

🧠 Practice MCQs: Sanctions Screening in Banks

Q1. Sanctions screening in banks primarily checks customer and transaction names against which of the following? (a) Credit bureau records (b) Designated-party watchlists such as UNSC and OFAC (c) Income tax returns (d) Aadhaar database

Answer: (b) — Screening matches names against official sanctions/watchlists, not credit or tax records.

Q2. In India, which sanctions list is legally mandatory to screen against due to domestic notification? (a) OFAC SDN List (b) EU Consolidated List (c) UNSC Consolidated List, via UAPA notification (d) FinCEN 314(a) list

Answer: (c) — UNSC-designated names are given domestic legal effect through UAPA notifications, making screening mandatory.

Q3. What is the standard first response when a screening alert is a confirmed true match? (a) Ignore it if the amount is small (b) Freeze/refuse the transaction and escalate to the compliance officer (c) Process the transaction and monitor later (d) Ask the customer to explain by email

Answer: (b) — A confirmed true match requires immediate freezing/refusal and escalation, not routine processing.

Q4. Why do fuzzy-matching algorithms generate a high volume of false positives in sanctions screening? (a) Because banks intentionally over-screen (b) Because sanctioned names are transliterated and common names overlap widely (c) Because RBI mandates a fixed alert quota (d) Because screening software is outdated everywhere

Answer: (b) — Transliteration variance and common-name overlap, not policy quotas, drive false-positive volume.

Q5. Nested and downstream correspondent banking relationships increase sanctions risk mainly because: (a) They reduce transaction fees (b) The correspondent bank often cannot see the ultimate originator of funds (c) They are always illegal (d) They eliminate the need for screening

Answer: (b) — Limited visibility into the true originator through layered correspondent access is the core risk driver.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

Frequently Asked Questions

Is sanctions screening the same as KYC verification?

No. KYC verification confirms who a customer is; sanctions screening separately checks that name against designated-party watchlists, and can flag an otherwise fully-verified customer.

How often should a bank re-screen its existing customers?

Every time a sanctions list is updated, not just at onboarding or periodic review — designated-party lists change frequently and re-screening must cover the full existing customer base.

What happens if a bank misses a genuine sanctions match?

It can face regulatory penalties, loss of correspondent banking relationships, and reputational damage, since processing funds for a designated party is a serious compliance failure.

Are OFAC and EU sanctions lists relevant to Indian banks even though they aren't legally binding?

Yes — banks with US dollar or euro correspondent accounts screen against them anyway, since a foreign correspondent can restrict the relationship over repeated exposure regardless of Indian law.

Next Steps for KYC-AML Aspirants

Sanctions screening in banks connects directly to correspondent banking, alert management and cross-border payment controls — all high-yield areas for the KYC-AML exam. Reinforce this topic with chapter-wise practice tests and browse more KYC-AML articles to round out related topics before exam day.

Quick quiz

Quick quiz on this topic

5 exam-style questions from our free test bank — check yourself before you move on.

KYC, AML and CFT · 5 questions · instant result
Q1. Counterfeit currency is detected during a cash deposit, and separately a forged valuable security is used in another cash transaction. How are these reported to FIU-IND under CCR norms?
Q2. Among the five FIU reports, why is the STR described as the 'keystone' that consumes the maximum resources of a reporting entity, while CTR/NTR/CBWTR carry only supplementary AML value?
Q3. An NRI sends an inward foreign remittance of Rs. 6 lakh into a resident's account for a personal gift. The branch must decide on cross-border reporting. Which is correct?
Q4. A walk-in customer enquires about a remittance arrangement, the staff become suspicious about the purpose, and the customer leaves without completing any transaction. No money moved at all. Based on the chapter, what is the correct AML treatment?
Q5. A bank submits a CTR for a month three days late and argues the penalty should be a single violation. Under Rule 8(4) of PMLR as described, how is a reporting delay treated?
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading