You can’t outsource sanctions judgement

Close-up of computer screen showing lines of code slightly out of focus

Sanctions compliance now depends heavily on external inputs. Screening tools, data vendors and third‑party providers sit at the centre of most control frameworks and are often treated as the primary means by which risk is identified.

In practice, they do something more fundamental. They determine what is visible, what remains uncertain, and what falls outside the process altogether. Decisions are still taken by firms, but they are shaped, and sometimes constrained, by what those systems make available for review.

What reliance looks like in practice

Outsourcing rarely appears as a deliberate transfer of responsibility. It emerges instead through a series of operational decisions.

Screening depends on external datasets; matching thresholds are set to reduce volumes; alerts are filtered and prioritised; known false positives are suppressed, sometimes permanently. One provider becomes the default source, even where others return different results, while the configuration put in place at implementation is often left unchanged.

In many organisations, these choices quietly become the main way sanctions risk is identified. Clear matches are escalated and clean results are accepted, while anything that falls short of those thresholds is handled within the process. Additional checks could be requested, parameters adjusted, and cases are closed where nothing conclusive can be demonstrated.

Over time, sanctions issues come to resemble the system outputs. What the system does not surface begins to fall outside the frame of consideration.

Where the gap emerges

The limitations of this model do not appear in unusual or complex cases, but in routine activity.

A name might generate several partial matches across different datasets, none of which meets escalation thresholds. A distributor may appear in one source but not another. Ownership information remains incomplete without triggering a clear red flag. A transaction screens cleanly, yet the surrounding commercial context raises questions. These are all part of normal sanctions work; what varies is how they are handled.

In practice, they are treated as data issues. Further screening is requested, cases remain open while more information is sought, or are closed because no definitive match can be confirmed. Different outputs are reconciled rather than interpreted, and the focus remains on resolving the data rather than forming a view of underlying risk.

A common example is where an existing counterparty screens cleanly but sits within a structure linked to a higher‑risk jurisdiction. Additional checks are initiated while business continues, and the issue is approached as one of data sufficiency rather than whether the activity itself warrants a different decision or is escalated for intensive investigation.

At that point, the system has reached its limit, but the process continues as if it has not. The absence of a clear system output is often treated as a reason not to act, rather than as a signal that judgement is required.

Close-up of person pointing at data displayed on laptop screen in office setting

“What the system does not surface begins to fall outside the frame of consideration.”

Responsibility does not move with the process

Reliance on third‑party inputs can create distance between activity and responsibility.

Systems determine what is surfaced for review, and vendors influence the calibration, often based on their own models or on aggregated user behaviour. Internal processes then shape what is escalated and what is not, with responsibility increasingly linked to process outcomes rather than underlying activity.

The underlying position does not change, though: responsibility remains with the firm.

Recent enforcement has emphasised this point. Where firms rely on third‑party screening or data providers, failures in those inputs do not transfer responsibility; they simply determine how those failures arise in practice. Work can be outsourced, but judgement cannot.

In practice, this requires firms to calibrate external systems against their own risk profile, rather than relying on default configurations, and to establish clear escalation points for situations that fall outside standard outputs. These arrangements do not remain static, and need to be revisited periodically as the firm’s business and risk exposure change.

“Work can be outsourced, but judgement cannot.”

Conclusion

Third‑party tools are now central to sanctions compliance and, for many organisations, define the practical boundaries of what can be identified through routine processes.

The difficulty arises when those boundaries are mistaken for the limits of the risk itself.

The point at which a system stops providing a clear answer is the point at which judgement becomes necessary. In practice, that moment is rarely explicit; it is absorbed into workflow, handled as a data issue, or deferred while additional checks are carried out.

The issue is not whether firms rely on external tools. It is whether they recognise when those tools have reached their limits, and whether they are prepared to act without a definitive output.

Discover more from Fairgreen Consulting Limited

Subscribe now to keep reading and get access to the full archive.

Continue reading