Brief

Sanctions screening assurance: connecting risk assessment to alert decisions

The FCA's May 2026 findings connect sanctions exposure, screening design, data quality, alert calibration, escalation and breach reporting.

MC

Michaela Clarke

Operations & Compliance Coordinator

Week of 3 August 20267 min read
A compliance professional reviewing a printed file alongside a laptop in a bright office.

At a Glance

The FCA's May 2026 findings give MLROs, nominated officers and financial-crime teams a source-led way to test sanctions assurance. The useful question is whether the firm's exposure assessment can be followed through screening coverage, calibration, alert decisions, escalation and breach reporting.

Evidence-led compliance lifecycle Source-backed facts are separated from MEMA analysis stages SOURCE Primary evidence 28 May 2026 MEMA Scope and outcome Define the question MEMA Control design Owner and evidence MEMA Assurance cycle Test and refresh Primary-source fact MEMA analysis or control stage
MEMA visual analysis. Source anchor: Sanctions systems and controls in our firms: our findings. The lifecycle is a MEMA implementation framework, not a substitute for the linked rule or guidance. On smaller screens, scroll the visual horizontally to see every stage.

The FCA reviewed more than 150 firms from February 2022 and published examples of good and poor practice across governance, risk assessment, data feeds, screening, calibration, alert handling, asset freezing and breach reporting. The publication does not create new sanctions law or prescribe one operating model. It does show the control areas the FCA considers important when assessing whether a firm's approach is proportionate to its exposure.

The FCA says firms should maintain systems, controls and oversight that are proportionate to their sanctions exposure. A defensible assurance review therefore needs to show how the exposure assessment informs list management, screening coverage, calibration, alert decisions and escalation.

Where the findings are most useful

Firms with customer or payment-screening processes can use the FCA's findings to test their own sanctions exposure and control environment. The review is particularly relevant to MLROs, nominated officers, sanctions specialists, risk teams and internal audit, but it does not prescribe one operating model for every firm.

While the FCA’s review is relevant to all firms with sanctions obligations, those with higher sanctions exposure or complex screening environments should prioritise aligning their controls with the FCA’s good practice examples. Firms that are interested in sanctions compliance but do not conduct customer or payment screening may find the publication informative but less directly applicable. The FCA does not impose a single prescribed operating model, so firms should tailor their assurance approach to their specific risk profile and business model.

Evidence to Prepare

MEMA analysis indicates that firms should begin by clearly documenting their sanctions risk assessment, linking it explicitly to screening design and calibration decisions. This includes verifying that data feeds for sanctions lists are complete, accurate, and timely. Firms should then evaluate their alert management processes, ensuring that alert thresholds and disposition criteria are aligned with the assessed risk and operational capacity. Evidence of regular calibration reviews and adjustments based on emerging risks or changes in sanctions lists will support a defensible control framework.

A key practical step is establishing a robust breach escalation and reporting process that is well understood across relevant teams. Firms should maintain records of alert investigations, decisions to escalate, and outcomes of breach reports. Independent assurance testing, such as internal audit or second-line reviews, should focus on the end-to-end sanctions screening lifecycle, from risk assessment through to breach reporting. MEMA recommends scheduling these assurance activities periodically to provide ongoing evidence of control effectiveness and to identify areas for improvement.

The Decision Firms Need to Make

Comprehensive FCA review of sanctions controls

The FCA’s May 2026 publication presents findings from an extensive review of sanctions systems and controls at over 150 firms since February 2022. It covers governance, risk assessments, screening design, data feeds, alert calibration, evasion detection, asset freezing, and breach reporting. Firms should assess their sanctions programmes against these areas to identify gaps and improve control effectiveness, distinguishing between FCA requirements and areas where MEMA recommends enhanced assurance testing.

Emphasis on proportionate systems and controls

The FCA says firms should maintain sanctions systems and controls proportionate to their exposure. This means firms should calibrate screening thresholds and alert volumes based on their specific risk profile and business model. MLROs and sanctions officers should review whether their current screening calibration aligns with their assessed sanctions risk, ensuring that alert volumes are manageable and meaningful for effective investigation and escalation.

Alert management and breach escalation focus

The FCA’s findings underscore the importance of clear processes for managing sanctions alerts and escalating suspected breaches. Firms should have documented procedures for alert disposition, including criteria for escalation to nominated officers and reporting to relevant authorities. MEMA analysis suggests firms test these processes regularly to ensure timely and consistent breach reporting, supporting a defensible sanctions control framework.

How to Prepare

ActionOwnerStatusTimingEvidence
MEMA recommended action: map the firm's sanctions exposure to customer, counterparty and payment-screening coverage, then record any unsupported assumptions or data gaps. MLRO / Sanctions Officer MEMA recommended action MEMA planning point: at the next sanctions risk-assessment review SECTIONS 3 TO 8 - Sanctions systems and controls in our firms: our findings
MEMA recommended action: test list and data-feed governance, including update timing, failed loads, record corrections and the evidence retained for material changes. Data Owner / Sanctions Operations MEMA recommended action MEMA planning point: before the next screening configuration change SECTIONS 3 TO 8 - Sanctions systems and controls in our firms: our findings
MEMA recommended action: sample calibration scenarios and alert decisions across customers and payments, retain exceptions and document the resulting tuning or control decision. Financial Crime Assurance MEMA recommended action MEMA planning point: during the next independent assurance cycle SECTIONS 3 TO 8 - Sanctions systems and controls in our firms: our findings
MEMA recommended action: trace potential breaches from detection through investigation, escalation and external reporting decisions, then confirm that remediation and retesting are closed. MLRO / Legal MEMA recommended action MEMA planning point: before the next board financial-crime report SECTIONS 3 TO 8 - Sanctions systems and controls in our firms: our findings

What credible assurance looks like

MEMA's view is that boards should understand how the sanctions risk assessment drives screening design and calibration. Useful evidence includes the approved risk assessment, calibration-change records, management information on alert volumes and ageing, sampled alert decisions and a clear record of breach escalation and reporting. The assurance record should also identify control owners, exceptions and follow-up actions.

Boards should also seek assurance that breach escalation and reporting processes are robust and consistently applied. This includes reviewing evidence of alert investigation quality, escalation decisions, and reporting to relevant authorities. Independent assurance reports or internal audit findings on the sanctions screening lifecycle provide useful independent evidence about control effectiveness. MEMA analysis highlights that boards benefit from clear, periodic reporting on sanctions control performance to support informed governance and risk oversight.

Source Evidence

SourceDocument typePublishedWhy it matters
Sanctions systems and controls in our firms: our findings FCA good and poor practice (Sections 3 to 8) 28 May 2026 Primary FCA review covering governance, risk assessment, screening, data feeds, calibration, alerts, evasion, asset freezing and breach reporting.

Disclaimer

This article is for general information only and does not constitute legal or regulatory advice. Firms should assess the application of regulatory requirements by reference to their permissions, products, customers and operating model.

How MEMA Can Help

MEMA can help firms translate regulatory change into practical controls, policies, monitoring activity and board evidence. Book a free scoping call to discuss what this development means for your firm.

MEMA helps firms apply regulatory developments through its financial crime compliance support.

Further reading: a related surveillance-controls case study.

Frequently asked questions

Does the FCA sanctions review create new sanctions rules?

Sanctions systems and controls in our firms: our findings reports the FCA's cross-sector findings and examples of good and poor practice. It does not replace UK sanctions legislation or prescribe one operating model for every firm. The FCA says the publication is relevant to authorised and registered firms, with particular relevance for MLROs, nominated officers and financial-crime professionals. MEMA recommends using the findings as an assurance benchmark while keeping legal duties, FCA expectations and firm-specific control design clearly separated.

What should a sanctions-screening assurance review cover?

Sanctions systems and controls in our firms: our findings covers governance, management information, risk assessment, due diligence, customer and payment screening, policies, list and data-feed management, calibration, alert resourcing, evasion detection, asset freezing and breach reporting. MEMA recommends selecting tests from that source-led control chain according to the firm's exposure. The review record should show scenarios, data populations, results, exceptions, approved changes and the outcome of retesting rather than relying only on a vendor configuration statement.

What sanctions evidence should reach the board?

MEMA recommends giving the board a concise line from the exposure assessment to screening coverage, material data or calibration changes, alert trends, significant exceptions, escalation decisions and outstanding remediation. Sanctions systems and controls in our firms: our findings identifies governance, oversight and management information as part of the FCA's review findings. The board pack should therefore distinguish source facts from management judgement and show whether previous actions changed the weakness or exception that prompted them.

Need expert regulatory guidance?

Our ex-regulator team helps firms navigate complex requirements and evidence compliance with confidence.

Book a Free Scoping Call