ClearSanction Intelligence
Monthly Compliance Brief
Edition 003 · September 2026
September 2026 Compliance Brief
Beyond the name match: building better sanctions and financial crime decisions through investigation, evidence and ongoing monitoring.
- Beyond the Name Match
- Ownership & Control
- UK AML Reform
- Virtual Asset Risk

ClearSanction Intelligence
Edition 003 · September 2026
September 2026 Compliance Brief
- Beyond the Name Match
- Ownership & Control
- UK AML Reform
- Virtual Asset Risk
ClearSanction Intelligence
In this edition
Beyond the Name Match
OFAC's February 2026 settlement with IMG Academy concerned 89 apparent violations involving two Spec
02Ownership & Control
Key regulatory and sanctions developments compliance teams should be aware of this month.
03UK AML Reform
Effective sanctions controls connect screening with assessment, investigation, decision-making, docu
04Virtual Asset Risk
New features and roadmap for the ClearSanction platform.
Beyond the Name Match: What Should Happen After Sanctions Screening?
Sanctions screening is designed to identify potential exposure to designated persons and entities. But a result — whether a potential match or no apparent match — still needs to be interpreted in context.
Beyond the Name Match: What Should Happen After Sanctions Screening?
The Screening Result Is the Starting Point
Sanctions screening is designed to identify potential exposure to designated persons and entities. But a result — whether a potential match or no apparent match — still needs to be interpreted in context.
A strong process asks six questions:
Case Study: IMG Academy
OFAC's February 2026 enforcement action against IMG Academy provides a useful starting point.
OFAC said IMG Academy entered into tuition agreements and processed related transactions involving two Specially Designated Nationals. Between 2019 and 2025, the conduct resulted in 89 apparent violations. The settlement was $1.72 million.
The case is striking because it was not a sophisticated fuzzy-matching problem. The sanctioned individuals supplied their full names during the relationship.
The control failure occurred earlier: the relevant counterparties were not being sanctions screened.
Practical lesson: Before debating algorithms and match thresholds, organisations need confidence that their process identifies who actually needs to be screened.
Depending on the relationship, relevant parties may include:
The correct scope depends on the organisation's legal obligations, sanctions exposure and risk assessment.
Case Study: Rice Lake
OFAC's 12 August 2026 settlement with Rice Lake Weighing Systems illustrates the next problem.
The case involved an Italian subsidiary selling weighing equipment through a distributor in the UAE while knowing the goods were ultimately destined for an end user in Iran.
A direct screening check on the immediate distributor could not, by itself, answer the underlying sanctions question.
The relationship needed to be understood in context:
supplier → distributor → destination → end user
Practical lesson: Screening needs to sit inside a wider sanctions control framework capable of recognising indirect exposure.
What a Potential Match Should Trigger
A potential sanctions match should normally lead to assessment of the available identifying information.
That can include:
A match score can help prioritise review, but it is not evidence that two records represent the same person or entity.
What a No-Match Result Does — and Does Not — Tell You
A no-match result tells you what the screening process found against the data and criteria used at that point in time.
It does not automatically answer:
The Compliance Objective
The objective should not be to produce as few alerts as possible, nor to maximise the number of potential matches.
It should be to produce decision-useful information.
A defensible sanctions decision should make clear:
Select a sample of recent sanctions screening decisions and attempt to reconstruct them from the audit record alone.
If a second reviewer cannot understand what was checked and why the decision was reached, the weakness is not simply a documentation problem. It is a control-design problem.
Ownership and Control: Why Screening the Named Entity Is Only the Beginning
A company does not necessarily need to appear by name on a sanctions list for sanctions restrictions to become relevant.
Ownership and Control: Why Screening the Named Entity Is Only the Beginning
A company does not necessarily need to appear by name on a sanctions list for sanctions restrictions to become relevant.
Ownership and control rules can extend restrictions beyond the directly designated person or entity. The precise legal tests differ between sanctions regimes, which makes simplistic global rules dangerous.
Start With the Applicable Regime
Before assessing an ownership structure, establish:
The UK and US regimes should not be treated as interchangeable.
Ownership Is Only Part of the Analysis
Percentage ownership can be comparatively easy to visualise. Control is often more difficult.
Relevant questions may include:
A Practical Ownership Review
For higher-risk relationships:
The Documentation Question
The strongest test of an ownership assessment is simple:
> Could an independent reviewer understand how you moved from the corporate structure to your sanctions conclusion?
If the answer depends on undocumented assumptions, the assessment is difficult to defend.
The UK's Changing AML Framework: What Compliance Teams Need to Review
The UK's 2026 amendments to the Money Laundering Regulations took effect on 30 June and introduced a series of targeted changes rather than a wholesale replacement of the AML framework.
The UK's Changing AML Framework: What Compliance Teams Need to Review
The UK's 2026 amendments to the Money Laundering Regulations took effect on 30 June and introduced a series of targeted changes rather than a wholesale replacement of the AML framework.
For compliance teams, precision matters. Several of the reforms have already been reduced to misleading one-line summaries.
CDD Thresholds: Understand the Scope
The amendments converted and changed a number of euro-denominated thresholds into sterling.
The often-quoted £800 threshold should not be treated as a universal new CDD threshold across every regulated business. Firms need to identify which threshold applies to their activity and amend procedures accordingly.
Pooled Client Accounts: A More Risk-Based Approach
The reforms affect the treatment of pooled client accounts.
The important compliance question is not simply whether every underlying customer must automatically be subject to duplicate CDD by the account provider. Firms need to understand the purpose and proposed use of the account, assess the associated risk and be able to obtain appropriate information where required.
Cryptoasset Correspondent Relationships
The amendments introduce requirements for cryptoasset exchange providers and custodian wallet providers in relation to correspondent relationships.
These include understanding the respondent, assessing its AML controls, obtaining senior management approval for new relationships, documenting responsibilities and addressing shell-bank exposure.
For crypto firms, correspondent risk is therefore becoming a more explicit part of the UK AML control environment.
High-Risk Jurisdictions
The amendments replace references to a high-risk third country in relevant provisions with FATF call for action country.
This is an important distinction.
FATF's jurisdictions under increased monitoring — commonly called the grey list — and jurisdictions subject to a call for action are not the same category.
Country risk therefore needs to be interpreted through the applicable legal requirement and the firm's wider risk assessment rather than through a single list.
What Should Organisations Do Next?
Map the 2026 amendments against:
The key control is not simply updating the policy document. It is ensuring the operational workflow reflects the amended requirement.
Virtual Assets and Financial Crime: The Risk Is Becoming More Interconnected
FATF's July 2026 targeted update on virtual assets and VASPs describes an increasingly interconnected illicit-finance environment.
Virtual Assets and Financial Crime: The Risk Is Becoming More Interconnected
FATF's July 2026 targeted update on virtual assets and VASPs describes an increasingly interconnected illicit-finance environment.
The report identifies risks involving organised crime-linked scam centres, DPRK-related cyber theft, terrorist and proliferation financing, sanctions evasion and cross-border money laundering.
It also highlights growing risks involving stablecoins, offshore VASPs, peer-to-peer transactions through unhosted wallets and DeFi.
Regulation Is Expanding — Implementation Still Matters
FATF reported that 83% of surveyed jurisdictions had passed legislation implementing the Travel Rule, up from 73% in 2025.
But legal frameworks are only part of the problem.
FATF continues to identify gaps in:
This distinction matters to compliance teams operating across borders. A jurisdiction having rules on paper does not necessarily mean the underlying control environment is mature.
DeFi Remains a Significant Gap
FATF's separate July report on DeFi found that almost 93% of reporting jurisdictions had not implemented FATF Standards in relation to qualifying DeFi arrangements, while only two jurisdictions reported having licensed or registered a DeFi arrangement in practice.
That creates a difficult risk environment for regulated firms interacting with decentralised protocols and cross-border counterparties.
Think in Risk Chains, Not Individual Controls
Virtual asset compliance increasingly requires teams to consider how risks connect:
customer → wallet → counterparty → VASP → jurisdiction → transaction behaviour
A wallet screening result may be valuable, but it is one input within that chain.
Questions for Compliance Teams
Ongoing Monitoring: What Should Firms Actually Be Monitoring?
AMLA's consultation on draft Guidelines for ongoing monitoring of business relationships closes on **3 September 2026**.
Ongoing Monitoring: What Should Firms Actually Be Monitoring?
AMLA's consultation on draft Guidelines for ongoing monitoring of business relationships closes on 3 September 2026.
The consultation is useful because it reinforces a basic principle of effective AML controls: understanding a customer is not a one-time onboarding exercise.
AMLA describes ongoing monitoring as maintaining a clear and current understanding of the relationship after it has been established, including keeping customer information current and monitoring transactions and activities over time.
Monitoring Is More Than Rescreening
Sanctions rescreening can be one component of ongoing monitoring.
But a broader AML framework may also need to detect changes in:
Event-Driven Versus Periodic Review
Periodic reviews remain useful, but important changes do not necessarily occur conveniently before a scheduled annual review.
Organisations should therefore consider which events should trigger reassessment between review dates.
Examples include:
The Practical Test
Ask:
> What could change tomorrow that would make yesterday's customer-risk decision incomplete?
Those are the events your monitoring framework needs to be capable of identifying or receiving.
FATF Grey Lists: What Should Actually Change When a Country's Status Changes?
At its June 2026 Plenary, FATF added **Bosnia and Herzegovina** and **Iraq** to jurisdictions under increased monitoring and removed **Algeria** and **Namibia**.
FATF Grey Lists: What Should Actually Change When a Country's Status Changes?
At its June 2026 Plenary, FATF added Bosnia and Herzegovina and Iraq to jurisdictions under increased monitoring and removed Algeria and Namibia.
The operational response should not be a mechanical change from green to red.
What Increased Monitoring Means
A jurisdiction under increased monitoring has committed to work with FATF or the relevant FATF-style regional body to address identified strategic deficiencies within agreed timeframes.
That status is relevant risk information.
It does not mean every person, company or transaction connected to that jurisdiction presents the same level of risk.
Look at the Underlying Deficiencies
The more useful question is:
Why has the jurisdiction been placed under increased monitoring?
For Bosnia and Herzegovina, FATF's action plan includes areas such as beneficial ownership information, AML/CFT supervision, suspicious transaction reporting, money laundering investigations and targeted financial sanctions.
For Iraq, areas include informal money or value transfer services, VASP regulation, PEP and targeted financial sanctions measures, beneficial ownership, terrorist financing and proliferation-financing sanctions evasion.
Those details may be considerably more useful to a risk assessment than the label grey list on its own.
When a Country Leaves the List
Removal should also trigger analysis rather than an automatic reduction in every customer's risk rating.
Consider:
What Should Organisations Do Next?
For each FATF change:
Country risk should support judgement, not replace it.
European Outlook: AMLA Moves Ongoing Monitoring Into Focus
AMLA's developing rulebook will increasingly shape how obliged entities across the EU interpret the new AML framework.
European Outlook: AMLA Moves Ongoing Monitoring Into Focus
AMLA's developing rulebook will increasingly shape how obliged entities across the EU interpret the new AML framework.
For September, the most immediate development is its consultation on ongoing monitoring, but the wider direction matters too: EU AML supervision is moving towards greater consistency in how risk-based controls are interpreted and applied.
What Compliance Teams Should Watch
For organisations operating across multiple EU jurisdictions, the long-term significance is potentially substantial: AML compliance is moving towards a more centralised European supervisory architecture.
Regulatory Watch
On 12 August, OFAC announced a $60,764 settlement concerning eight apparent Iran-related sanctions violations. The case involved exports through a UAE distributor where the goods were known to be destined for Iran.
Regulatory Watch
Key developments to keep on the compliance agenda.
OFAC — Rice Lake Weighing Systems
On 12 August, OFAC announced a $60,764 settlement concerning eight apparent Iran-related sanctions violations. The case involved exports through a UAE distributor where the goods were known to be destined for Iran.
Compliance takeaway: Review indirect dealings, distributors, destinations and end-user controls rather than relying solely on direct counterparty screening.
FATF — Virtual Assets
FATF's seventh targeted update identifies increasingly complex and interconnected virtual asset risks, including sanctions evasion, fraud, DPRK-linked cyber theft and cross-border money laundering.
Compliance takeaway: Review how wallet, VASP, customer, jurisdiction and transaction risks interact.
AMLA — Ongoing Monitoring
The consultation on draft Guidelines for ongoing monitoring closes on 3 September.
Compliance takeaway: Test whether monitoring processes capture material changes after onboarding, not merely scheduled rescreening.
FATF — Country Risk
Bosnia and Herzegovina and Iraq remain newly added to increased monitoring following the June Plenary; Algeria and Namibia were removed.
Compliance takeaway: Review the underlying FATF action plans before deciding what the change means for customer risk.
Iran's Digital Asset Sanctions Escalation: What Compliance Teams Should Take From OFAC's 24 August Action
On 24 August 2026, OFAC announced a substantial Iran-related sanctions action that included five sectoral determinations under Executive Order 13902 covering **digital assets, technology, gold, aviation and shipping**.
Iran's Digital Asset Sanctions Escalation: What Compliance Teams Should Take From OFAC's 24 August Action
On 24 August 2026, OFAC announced a substantial Iran-related sanctions action that included five sectoral determinations under Executive Order 13902 covering digital assets, technology, gold, aviation and shipping.
The action is particularly important for financial crime teams because it places digital assets explicitly within a broader sanctions-evasion and illicit-finance picture rather than treating crypto as a separate compliance problem.
Why the Digital Asset Determination Matters
Digital asset sanctions risk can present through more than the name of a customer. Relevant indicators can include wallet addresses, VASPs and exchanges, transaction counterparties, connected persons and entities, ownership relationships, jurisdictional exposure and the underlying purpose and pattern of activity.
This reinforces a recurring theme throughout this edition: the compliance decision needs to consider the relationship between different pieces of risk information.
From FATF Risk Warning to Sanctions Action
FATF's July 2026 virtual asset work highlighted increasingly interconnected risks involving sanctions evasion, cyber theft, fraud, terrorist and proliferation financing and cross-border money laundering.
OFAC's August action provides a current regulatory example of those risks translating into sanctions policy and designations.
For compliance teams, the useful question is not simply "Did we screen the customer's name?" It is whether controls can recognise sanctions exposure when it appears through a wallet, exchange, counterparty, ownership relationship or wider network.
What Should Organisations Do Next?
Virtual asset businesses and firms exposed to crypto activity should review whether their sanctions framework screens relevant parties, identifies designated digital asset addresses where relevant, considers VASP, jurisdiction and ownership risk, escalates interacting risk indicators and preserves evidence supporting the final decision.
The objective is not to treat every crypto transaction as high risk. It is to ensure that the control framework can recognise the forms sanctions exposure can actually take.
When Sanctions Change Direction: What Syria Tells Us About Dynamic Country Risk
Compliance teams spend considerable time responding when sanctions are imposed or countries move into higher-risk categories. Less attention is sometimes given to the opposite problem:
When Sanctions Change Direction: What Syria Tells Us About Dynamic Country Risk
Compliance teams spend considerable time responding when sanctions are imposed or countries move into higher-risk categories. Less attention is sometimes given to the opposite problem:
What should happen when the legal or regulatory position becomes less restrictive?
Developments announced on 24 August 2026 affecting the US approach to Syria provide a useful example, including removal of Syria's designation as a State Sponsor of Terrorism and associated changes to OFAC designations and licensing.
Country Risk Is Time-Sensitive Evidence
A country-risk assessment is a conclusion based on information available at a particular point in time.
That evidence can change because of new or removed sanctions, FATF listing changes, terrorism-related designations, licensing or exemptions, corruption and governance indicators, regulatory guidance and the firm's own experience.
A risk methodology therefore needs to know not only what a country's current classification is, but why it has that classification and when the underlying evidence was last reviewed.
Removal Does Not Mean Ignore the History
A reduction in sanctions restrictions does not automatically mean that every relationship connected to the jurisdiction should immediately be treated as low risk.
Firms may still need to consider remaining sanctions restrictions, designated persons and entities, other applicable regimes, terrorist-financing and proliferation-financing exposure, corruption and governance risks, customer-specific circumstances and historic activity relevant to the relationship.
The same principle applies to FATF grey-list removals.
The correct response is reassessment, not an automatic switch from one risk category to another.
Build Reassessment Into the Methodology
A practical country-risk process should:
The Wider September Lesson
Sanctions screening, customer risk and country risk share the same fundamental challenge:
> Compliance information changes. A defensible decision therefore needs both evidence and a mechanism for reassessment.
That is why monitoring should be designed around meaningful changes in risk rather than treated solely as a periodic administrative exercise.
Practical Compliance Guide
Six Questions to Test Your Sanctions Screening Framework
Customers are not always the only relevant party. Consider counterparties, payers, beneficial owners, controllers, intermediaries and end users where appropriate to the risk.
A score without supporting identity information is difficult to investigate.
Ownership, control, intermediaries and transaction context can materially change the sanctions analysis.
The audit trail should show what was reviewed, by whom, when and why the conclusion was reached.
New designations, ownership changes, customer behaviour and geographic exposure can all change risk.
If not, strengthen the evidence and documentation process.
The Intelligence Brief
September in 60 Seconds
What to Watch in September
Key regulatory and sanctions developments compliance teams should be aware of this month.
Screening Failure Leads to $1.72m IMG Academy Settlement
OFAC's February 2026 settlement with IMG Academy concerned 89 apparent violations involving two Specially Designated Nationals over several years.
The case demonstrates that sanctions exposure is not confined to financial institutions and that organisations must identify which parties to a relationship require screening.
Rice Lake Case Highlights Indirect Sanctions Exposure
On 12 August 2026, OFAC announced a $60,764 settlement with Rice Lake Weighing Systems after its Italian subsidiary exported goods through a UAE distributor knowing they were ultimately destined for Iran.
Screening the immediate distributor alone cannot resolve risks involving end users, destinations, intermediaries and indirect dealings.
Virtual Asset Risks Become More Interconnected
FATF's July 2026 targeted update identifies growing risks involving fraud, stablecoins, offshore VASPs, unhosted wallets, sanctions evasion and cross-border money laundering.
Crypto compliance frameworks need to consider interconnected customer, counterparty, wallet, platform and jurisdiction risks rather than treating each control in isolation.
2026 Money Laundering Regulation Amendments Now in Force
Amendments effective from 30 June 2026 changed requirements affecting unusually complex transactions, pooled client accounts, cryptoasset correspondent relationships, high-risk jurisdictions and sterling thresholds.
Firms should ensure policies reflect the actual scope of the amendments rather than relying on simplified summaries of the reforms.
Ongoing Monitoring Consultation Closes 3 September
AMLA's draft Guidelines address keeping customer information current and monitoring transactions and activities throughout a business relationship.
Ongoing monitoring is broader than simply rescreening a name against a sanctions list.
Grey List Changes Require Risk-Based Interpretation
FATF added Bosnia and Herzegovina and Iraq to increased monitoring in June 2026 and removed Algeria and Namibia.
Increased monitoring should inform a risk-based assessment rather than operate as an automatic proxy for the risk of every customer connected to that jurisdiction.
Iran Sanctions Campaign Expands Focus to Digital Assets
On 24 August 2026, OFAC announced five sectoral determinations under Executive Order 13902 covering digital assets, technology, gold, aviation and shipping, alongside a broad package of Iran-related designations.
The action reinforces that sanctions exposure can arise through digital asset infrastructure as well as traditional names and entities.
Syria Changes Reinforce Dynamic Country Risk
On 24 August 2026, US authorities announced significant changes affecting the Syria sanctions and terrorism framework, including removal of Syria's State Sponsor of Terrorism designation and associated OFAC changes.
Sanctions and country-risk status can move in both directions, so historic risk classifications should not remain static when the legal framework changes.
Take a recent cleared alert and ask whether another compliance professional could reconstruct what was checked, what evidence was considered and why the final decision was reasonable.
A Screening Result Is an Input, Not the Decision
Effective sanctions controls connect screening with assessment, investigation, decision-making, documentation and ongoing monitoring.
“The objective is not simply to generate a match or a no-match result. It is to reach a defensible compliance decision and preserve the evidence behind it.”
Effective sanctions controls connect screening with assessment, investigation, decision-making, documentation and ongoing monitoring.
New in ClearSanction
On the roadmap
- Beneficial ownership screening (OFAC 50 Percent Rule)
- Trade & export control datasets
- Iran country intelligence
- North Korea country intelligence
- Myanmar country intelligence
- Belarus intelligence module
- Venezuela sanctions spotlight
Stay ahead of sanctions, PEP and financial crime risk.
Book a demo or start screening with ClearSanction.
