Youverify
  • Developers
Login

Subscribe to our newsletter

Subscribe to our weekly newsletter for expert insights, regulatory updates, and actionable tips to optimize your compliance strategy.

By subscribing, you'll receive updates from Youverify.

Solution

    Customer OnboardingFraud InsightsTransaction MonitoringVyra AIPricing

Industry

    Commercial banksFintech & PaymentsGamingGig WorkersGovernment

Company

    About UsCompliance CertificationsPress and MediaPartnersCareersContact Us

Resources

    BlogsGlossaryDevelopersIndustry ReportsData SourcesFAQsCountry CoverageAI Governance

Legal

    Privacy PolicyTerms of UseCookies PolicyPAIAInformation Security PolicyGDPR Compliance StatementResponsible AI

    Customer OnboardingFraud InsightsTransaction MonitoringVyra AIPricing

youverify-logo

©2026 Copyright. All Rights Reserved

Sanctions Screening for Banks: How It Works in South Africa and Saudi Arabia
Identity Verification

Sanctions Screening for Banks: How It Works in South Africa and Saudi Arabia

ByTemitope Lawal
August 25, 2026•5mins Read

Key Takeaways

  1. Sanctions screening and PEP screening are separate controls that answer different risk questions. Sanctions screening matches customers against government and international sanctions lists; PEP screening flags politically exposed persons using different data sources entirely.


 

  1. In South Africa, the Prudential Authority, not the Financial Sector Conduct Authority, is the body that supervises banks for AML/CFT compliance, including sanctions screening, under the FIC Act, while the Financial Intelligence Centre sets the underlying guidance.


 

  1. The FIC's own guidance tells institutions to screen at onboarding, during transactions, and again "without delay" whenever the UN Security Council's sanctions list changes, which is the practical definition of how often screening needs to happen.

Introduction 

Sanctions screening is the process of checking a customer or a transaction against government and international sanctions lists before a bank proceeds, so it never knowingly deals with a person, company, or country that is legally off-limits. For banks operating in South Africa and Saudi Arabia, that check has to satisfy two different regulatory regimes at once, and it has to run continuously, not just once at onboarding.
 

It is also frequently confused with PEP screening, which is a separate control built to catch a different kind of risk: political exposure, not sanctions status. Compliance teams that blend the two into one process tend to get weaker results on both. This article breaks down exactly what sanctions screening checks, what South Africa's Financial Intelligence Centre (FIC) and Prudential Authority and Saudi Arabia's SAMA actually require of it, and how it works end to end.

What Sanctions Screening Actually Checks

Sanctions screening matches a customer's identifying details full name, date of birth, nationality, and sometimes address or place of business against sanctions lists maintained by governments and international bodies. The two lists that show up in almost every screening programme are the OFAC Specially Designated Nationals (SDN) List, maintained by the US Treasury, and the United Nations Security Council Consolidated List, which underpins South Africa's own targeted financial sanctions regime. A bank operating regionally also screens against the EU list and any domestic list, such as the one the FIC publishes for South Africa.
 

A name match, or a close statistical near-match, stops the transaction or onboarding step until a human reviews it. Because sanctions lists work on name-matching, most of what gets flagged is a false positive: a real, legitimate customer who happens to share a name with a listed individual or entity, not an actual hit.
 

Snippet-ready answer: Sanctions screening checks a customer's name, date of birth, and nationality against government and international sanctions lists, chiefly the OFAC SDN List and the UN Security Council Consolidated List, to stop a bank from dealing with a legally prohibited individual, entity, or country before the relationship or transaction proceeds.


 

This is a fundamentally different exercise from PEP screening, which checks whether a customer is a current or former senior public official, or closely connected to one, using PEP databases and adverse media rather than sanctions lists. Ongoing watchlist screening programmes typically run both checks side by side but keep them as distinct decision paths, because a sanctions hit and a PEP flag carry different legal consequences and require different escalation steps.

Why FIC, the Prudential Authority, and SAMA Require It

South Africa's Financial Intelligence Centre sets the country's targeted financial sanctions (TFS) framework under the Financial Intelligence Centre Act and publishes the list institutions must screen against. But the FIC is not the body that examines banks day to day  under the FIC Act, that responsibility sits with the Prudential Authority, housed within the South African Reserve Bank, which is "responsible for the AML/CFT supervision of banks, mutual banks and life insurers." The Financial Sector Conduct Authority coordinates with the Prudential Authority on shared conglomerate risk, but it is not the AML/CFT supervisor of banks  a distinction worth getting right, because attributing bank AML supervision to the wrong regulator undermines a compliance team's own credibility with examiners.


 

In Saudi Arabia, the Saudi Central Bank (SAMA) sets AML/CFT expectations for banks, money exchangers, and foreign bank branches through its published Rulebook, which includes sanctions screening obligations alongside broader customer due diligence requirements. SAMA's specific screening-frequency language could not be independently confirmed from its rulebook site this run (the page blocks automated access), so any cadence claim attributed to SAMA below is flagged rather than stated as fact.

How Sanctions Screening Works, Step by Step

1. Building the watchlist set. A screening programme draws on multiple lists at once: the OFAC SDN List, the UN Security Council Consolidated List, EU sanctions lists, and, in South Africa, the FIC's own targeted financial sanctions list. List coverage matters less than update frequency  a provider refreshing its lists weekly instead of daily creates a real detection gap between when a name is added and when a bank would catch it.

 

2. Real-time versus batch screening. Real-time screening checks a customer or transaction against the current list set at the moment of the interaction, typically at onboarding or at the point of a transaction. Batch screening instead runs periodically against a stored customer base, which means a change to a sanctions list is only caught the next time the batch runs not the moment it happens.
 

Snippet-ready answer: Real-time sanctions screening checks a customer against current sanctions lists the instant an interaction occurs at onboarding or transaction time while batch screening runs periodically against a stored customer base, meaning newly listed names are only caught at the next scheduled run rather than immediately.
 

3. Match scoring and false-positive handling. Because screening relies on name-matching, exact and fuzzy matches both surface, and the majority of what surfaces is a false positive. How a system tunes match sensitivity and routes false positives to the right reviewer, instead of flooding a compliance team with noise, is what actually separates a workable sanctions screening software setup from an unusable one.


 

4. Continuous rescreening after onboarding. A customer who passed screening on day one is not permanently cleared. The FIC's own guidance for South Africa is explicit that institutions must scrutinise client information "at client onboarding," "when conducting transactions," and "when the [sanctions] list is updated," adding that this rescreening should happen "without delay." That third trigger, a list update, not a transaction, is the one manual or batch-only processes most often miss, which is why continuous post-onboarding screening against sanctions, PEP, and adverse-media sources has become the practical baseline rather than a nice-to-have.

A Real-World Compliance Scenario

Consider a mid-sized South African bank onboarding a new corporate customer whose beneficial owner clears screening cleanly at account opening. Eight months later, the UN Security Council adds that individual to its Consolidated List following a sanctions designation. A bank running only onboarding-time screening has no mechanism to catch this  the account stays active, and any transaction processed afterward is technically a sanctions breach the moment the list updates. A bank running continuous rescreening flags the match within hours of the list update, freezes the relevant activity, and files the required report before a transaction ever clears. The difference between the two outcomes is not the quality of the original onboarding check; it's whether screening continued after onboarding ended.

Sanctions Screening vs PEP Screening: Why They Are Not the Same Control

Sanctions screening matches customers against government and international sanctions lists to identify prohibited individuals, entities, or countries. PEP screening identifies people in prominent public positions  senior government officials, judges, military officers, and their close associates and family members  using PEP databases and adverse-media monitoring, not sanctions lists. A person can be a PEP without being sanctioned, and a sanctioned entity is not necessarily politically exposed at all. The two controls exist to catch different risks, use different data sources, and should be run, documented, and escalated as separate processes, even when the same platform handles both in a single workflow.

What to Compare When Evaluating a Sanctions Screening Approach

Capability

Manual or spreadsheet process

Point solution

Integrated platform

List coverage and update frequency

Depends on manual downloads; update lag is common

Usually automated; coverage varies by vendor

Automated across global and local lists, including regional equivalents

Real-time screening at onboarding and transaction

Not feasible at any real volume

Often available

Typically embedded directly in the onboarding and transaction flow

False-positive tuning

No tuning; every match needs manual review

Basic tuning; maturity varies by vendor

Configurable tuning with ongoing model refinement

Rescreening on list updates

Requires a manual re-run of the whole customer base

Automated, but often siloed from onboarding data

Automated and tied to the same customer record used at onboarding

Audit trail

Manual, prone to gaps

Present, but usually siloed from other compliance data

Unified trail across screening, monitoring, and case management


 

A spreadsheet-based process can technically satisfy screening at very low transaction volume, but the audit-trail and rescreening gaps make it a liability at any real scale, particularly once a regulator asks an institution to reconstruct why a matched account was cleared eighteen months earlier.

Common Gaps in Sanctions Screening Programmes

Three gaps show up repeatedly in institutions' own screening programmes, independent of any specific regulator's examination findings. First, screening against a stale snapshot of a sanctions list rather than the current version. Second, treating rescreening as an onboarding-only event instead of an ongoing one  which is precisely the gap the FIC's "without delay" language is written to close. Third, an audit trail that cannot show, months later, why a flagged match was cleared rather than escalated. None of these are claims about what any specific regulator has cited in an enforcement action; they are structural weaknesses worth testing against your own programme regardless of jurisdiction.


 

Learn more about how continuous screening fits into a broader fraud and compliance monitoring approach.


Conclusion

Sanctions screening for South African and Saudi banks comes down to three things: matching customers against the right lists, doing it continuously rather than only at onboarding, and keeping it entirely separate from PEP screening even when one platform runs both. Getting the regulator right matters as much as getting the process right  in South Africa, that means the Prudential Authority as bank supervisor, with the FIC setting the underlying sanctions guidance; in Saudi Arabia, it means SAMA's Rulebook. A programme built on outdated lists, onboarding-only checks, or an unclear audit trail is exposed the moment a customer's status changes after the account is already open, and that is precisely where continuous sanctions screening earns its place in the compliance stack.

 


 

FAQs

Frequently Asked Questions

Related Articles

What Is A Neo Bank?
Identity Verification
Lola, Edited by Emmanuel Agwu•May 31, 2023

What Is A Neo Bank?

Read More
How to Protect Your Business from Identity Fraud in the US
Identity Verification
Temitope Lawal•June 18, 2024

How to Protect Your Business from Identity Fraud in the US

Read More
What is a Qualified Electronic Signature (QES)?
Identity Verification
Hakeem Akiode•March 20, 2024

What is a Qualified Electronic Signature (QES)?

Read More