Sanctions exposure is an ownership problem
Screening a counterparty against a list answers a narrow question. The exposure that causes trouble usually sits one or two ownership layers behind a name that screens clean.
Most institutions treat sanctions as a screening function. A name goes in, a list is checked, a result comes back, and the file is documented. That process is necessary and it catches the obvious cases, which is exactly the problem: the obvious cases were never the ones that were going to cause difficulty.
Designation regimes reach further than the names they print. Under the US approach, an entity owned fifty percent or more, in the aggregate, by one or more blocked persons is itself blocked, whether or not it appears on any list. Nobody publishes that entity's name. The obligation exists regardless.
Which converts sanctions compliance from a lookup into something considerably harder: a question about ownership structure.
Aggregate, and indirect
Two words in that rule do most of the damage.
Aggregate means the fifty percent does not need to come from one blocked person. Three designated individuals holding twenty percent each own sixty percent between them, and the entity is blocked. Screen each shareholder individually and each one comes back at twenty percent, below any threshold anyone is watching for, and the file closes clean.
Indirect means ownership counts through the chain. A blocked person owning a holding company that owns the operating company owns the operating company. Chains of three and four layers, crossing several jurisdictions, are ordinary rather than exotic. They are how corporate groups are structured for entirely mundane tax and liability reasons, which is precisely what makes the deliberate versions hard to distinguish from the innocent ones.
Thirty-nine thousand entries across five registers, and the entity in the example above appears on none of them. That is the whole difficulty in one line. The lists are the easy part, they are free, and an institution that has diligently screened all five has answered a narrower question than it believes it has.
And the regimes differ. The US ownership rule, the EU's approach built around ownership and the separate concept of control, and the UK's control tests are related but not identical, and an entity can fall inside one and outside another. An institution operating across those jurisdictions is subject to all of them and cannot satisfy them with a single test.
Screening a name asks whether this counterparty is designated. The question that matters is who ultimately owns it, and that one has no list.
Control without ownership
Ownership percentages are the codified test. They are not the whole risk.
An entity can be controlled through mechanisms that never show up in a shareholder register: board appointment rights, golden shares, management contracts, a single dominant creditor, or an informal arrangement in a jurisdiction where the formal register is not the operative document. Several regimes address control directly for this reason, and where they do, the test is qualitative and the answer requires judgement rather than arithmetic.
This is the point where sanctions work stops being a compliance discipline and becomes a country-risk one. Deciding whether a holding structure in a particular jurisdiction reflects genuine commercial ownership or a nominee arrangement requires knowing how that jurisdiction actually works: who the operative families and networks are, what the registries do and do not record, and which intermediary jurisdictions recur in structures from that region. That knowledge is regional and specific. It does not come from the screening vendor.
Building the map
The practical exercise for a meaningful exposure runs roughly like this.
The exercise runs upward from the counterparty to natural persons or a state, recording percentages at every step and the jurisdiction of each layer. Where the chain goes dark, at a nominee, a jurisdiction with no public register or a trust, the honest entry is unresolved rather than clean. Unresolved is a finding; a blank is a gap in the paperwork, and the two get recorded identically by most systems.
Then screen every node in that structure, not just the counterparty, and aggregate the designated ownership through the chain rather than layer by layer. Finally, ask the control question separately: who actually directs this entity, and does the answer match the register?
Documented, the whole thing is defensible even if a designation later lands on someone in the chain, because you can show what you knew, when, and what you did about it. Undocumented, an accurate screening result is worth remarkably little.
The part nobody gets right
Everything above concerns exposure that already exists. The more valuable question, where designations are heading, is genuinely geopolitical: which sectors are under discussion, which jurisdictions are drifting toward secondary exposure, which entities sit structurally adjacent to something already designated.
Nobody forecasts that reliably, and the firms that claim to are selling a confidence the problem does not support.
What separates institutions in practice is therefore not foresight but preparation. One that has already traced its ownership structures can answer, in an afternoon, what a designation on a given sector would cost it. One that has only screened names starts from the beginning, on the day that answer is most urgently needed. Neither of them saw it coming; only one of them is in a position to respond.
← Back to all insights