Background
Following on from Bulletin 401, “Financial crime prevention – why risk assessments matter”, this Bulletin continues the financial crime theme by focusing on and explaining the UK financial sanctions regime.
The FCA has repeatedly stated that reducing and preventing financial crime is one of its strategic priorities. This is reflected in the fact that 75 of the 130 enforcement operations it commenced in 2025 related to financial crime and, of these, it deemed 37 to be criminal. In its dealings with small firms in particular, the regulator has found a widespread lack of awareness of the UK financial sanctions regime, and a persisting belief that general insurance is ‘low risk’.
The Office of Financial Sanctions Implementation (OFSI), part of HM Treasury, is responsible for the implementation and enforcement of financial sanctions in the UK. It reports that most breaches – which constitute criminal offences – involve financial services firms in some capacity.
Introduction
In its April 2026 paper, Synthetic Data and Anti Money Laundering Project Report, the FCA stated that criminal behaviour is evolving rapidly, with criminals finding new ways to circumnavigate safeguards and to exploit weaknesses in systems. It warns of the danger of optimising controls for yesterday’s risks rather than tomorrow’s. This caution should be applied to all elements of the financial crime prevention framework, including risk assessments, policies and procedures, training material, and detection tools.
There is good reason to be proactive rather than reactive. A breach of financial sanctions is a serious criminal offence with potentially far-reaching consequences. Criminal offences are “strict liability”, which means there is no need for OFSI to prove that there was intent. Simply by accepting a premium from a designated person (“DP”), an FCA-authorised firm might be considered a “professional enabler”, i.e., offering services that enable criminality. Offences carry a custodial sentence of up to 7 years (although the law allows for the creation of new offences with up to 10 years’ imprisonment on indictment), with monetary fines for civil breaches in addition.
Clearly any risk that exposes a firm to criminal liability is a conduct risk, which may lead to FCA enforcement, with suspension or revocation of permissions and/ or authorisation.
As an example (and HR departments responsible for employing staff should also take note), employing or paying a Democratic People’s Republic of Korea worker could directly or indirectly breach financial sanctions.
With so much at stake, let’s take a closer look at the UK’s financial sanctions regime.
What are financial sanctions?
Financial sanctions are restrictions put in place by the United Nations or the UK to achieve a specific foreign policy or national security objective, tackle global threats such as terrorism or nuclear proliferation, and advance international norms.
Financial sanctions take many forms, but the most common are:
- Denials of access to, or restrictions on the use of, financial markets and services, e.g., investment bans, restrictions on access to capital markets, and directions to cease banking relationships.
- Denials of access on the provision of financial services to specific persons, groups, sectors, government, or country (for example, legislation introduced in July 2022 imposed restrictions on providing certain financial services to designated Russian persons, entities, and sectors).
- Targeted asset freezes, applied to named individuals and entities and listed on the UK Sanctions List (see below).
- Specified ships or aeroplanes.
- Unlisted entities owned or controlled by designated individuals.
The legal framework
Listings made by the United Nations Security Council have an automatic effect in UK law via regulations made under the Sanctions and Anti-Money Laundering Act 2018 (“The Sanctions Act”).
The UK also imposes its own financial sanctions to protect its interests, which are implemented through a combination of statutory instruments, the most significant of which are detailed below:
The Sanctions Act
This is the core UK law that created the UK sanctions regime after Brexit. The Act itself does not set out the sanctions offences directly. Instead, it gives the government power to create offences in sanctions regulations made under the Act. The specific offences are found in the sanctions regulations, e.g., Russia (Sanctions) (EU Exit) Regulations 2019 and Global Human Rights Sanctions Regulations 2020. These regulations contain provisions such as:
- “A person must not make funds available to a designated person.”
- “A person must not make economic resources available to a designated person.”
Under The Sanctions Act, the term ‘financial services’ includes insurance-related services consisting of direct life assurance; direct insurance other than life assurance; reinsurance and retrocession; insurance intermediation, such as brokerage and agency; and services auxiliary to insurance, such as consultancy, actuarial, risk assessment and claim settlement services.
What does this mean for firms?
The effect of The Sanctions Act, therefore, in relation to insurance, is that it is an offence under the Act (unless there is an exception or a licence that can be taken advantage of) to provide and of the above-named insurance-related services to DPs. The key question is, how do you know whether you are providing insurance-related services to a DP unless you check the lists of DPs?
Counter Terrorism Act 2008 (CTA 2008)
This creates terrorist financing offences, such as:
- Using, receiving, or collecting funds for terrorist purposes.
- In some instances, it is an offence to offer financial services that might benefit terrorists.
- Any dealings with proscribed organisations or their members.
What does this mean for firms?
Insurance brokers are expected to include terrorist financing risk in their anti-money laundering and sanctions controls. If a firm suspects a transaction involves terrorist financing, it must make a report to the National Crime Agency (NCA). Failure to do so can lead to prosecution.
Anti-Terrorism, Crime and Security Act 2001 (ATCSA 2001)
This was enacted to strengthen the UK’s counter-terrorism framework.
What does this mean for firms?
Insurance brokers handle funds, assets, and policies, which means they could inadvertently be involved in a prohibited transaction under ATCSA 2001, e.g., accepting money from or paying a claim to a sanctioned or proscribed person.
Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017
Not all the regulations apply to insurance brokers, but they are useful because they establish that “A relevant person must apply customer due diligence measures if the person establishes a business relationship.” They also specify the stages at which due diligence must be carried out.
What does this mean for firms?
‘Relevant persons’ include an insurance intermediary when it acts in respect of contracts of long-term insurance. Although that does not include ‘general insurance’, the FCA expects firms to have appropriate systems and controls in place to counter the risks of financial crime.
Economic Crime and Corporate Transparency Act 2023
This is a UK law aimed at tackling fraud, money laundering, and the misuse of companies. It strengthens the powers of Companies House to verify identities of those who own and operate companies, and gives law enforcement more tools to investigate and prevent economic crime.
The national Economic Crime Plan (2023 to 2026) and Fraud Strategy
These were both published by the Government in 2023, established actions for public and private sector parties, with the aim of reducing financial crime.
What are the main financial sanctions offences?
The main offences under UK’s financial sanctions regimes are:
- Providing a service, if that service results in funds or other economic resources being made available a DP, e.g., offering a quote for an insurance policy to a DP, or an undesignated person if a DP funds the company, or is a named beneficiary, or could otherwise benefit from the policy.
Note: Many sanctions regulations specifically prohibit financial services and professional or business services being provided to DPs.
- Making economic resources, i.e., assets that could be used to obtain funds, goods, or services (e.g., property, vehicles, equipment) available to a DP.
- Dealing with funds or economic resources belonging to a DP, e.g., receiving a premium.
- Making funds available to a DP, e.g., paying a claim or returning a premium.
What are the FCA’s expectations?
Guidance in the FCA’s Financial Crime Guide at FCG 2.2.1 G on governance in relation to financial crime also applies to sanctions.
“We expect senior management to take clear responsibility for managing sanctions risks, which should be treated in the same manner as other risks faced by the business. There should be evidence that senior management are actively engaged in the firm’s approach to addressing the risks of non-compliance with UK financial sanctions. Where they identify gaps, they should remediate them.”
and
“A firm should have effective, up-to-date screening systems appropriate to the nature, size, and risk of its business. Although screening itself is not a legal requirement, screening new customers, counterparties to transactions and payments against the Consolidated List, and screening existing customers when new names are added to the list, helps to ensure that firms will not breach UK sanctions.”
- Inadequate sanctions controls could be a breach of Principle 3 – Management and Control – A firm must take reasonable care to organise and control its affairs responsibly and effectively with adequate risk management systems, including for financial crime and sanctions risk.
- SYSC 3.1 / SYSC 3.2 – Firms must establish and maintain effective governance, risk-management, and internal controls appropriate to the nature, size, and complexity of the business — covering financial crime risks. This includes policies, procedures, and controls for dealing with sanctions risk (adequate systems to prevent the firm being used to breach sanctions).
- SYSC 6.1 / SYSC 6.3 (Financial crime) – FCA guidance integrates sanctions into the broader financial crime risk framework — requiring firms under SYSC to consider sanctions in their systems and controls. A failure to mitigate sanctions risk can be seen as a failure of the firm’s financial crime systems and controls.
Adopting a risk-based approach
It is not possible to adopt a risk-based approach without first understanding the risk.
In February 2025, OFSI published its Financial Services Threat Assessment to assist stakeholders with prioritisation as part of a risk-based approach to compliance. Most suspected breaches involve UK financial services firms, usually because of premium payments from UK banks which are operating accounts for DPs and/or their enablers.
“Often these transactions stem from existing insurance policies… particularly those relating to UK residential properties. Without the correct oversight, these contracts can automatically renew and lead to debits from accounts held by DPs.”
Not a one-off exercise
The UK sanctions landscape has changed significantly since Russia’s illegal invasion of Ukraine in February 2022. Because of the severity of sanctions prohibitions, Russian DPs are adopting increasingly sophisticated methods to overcome sanctions, involving both professional and non-professional “enablers” (individuals or entities providing services or assistance on behalf of or for the benefit of DPs). The same may apply to DPs from Libya, Belarus, Iran, and the Democratic People’s Republic of Korea (DPRK – North Korea).
In this fast-moving environment, with the possibility that financial relationships with customers, employees and/or third parties may pre-date designation, assessing risk is never a one-off exercise, but one that needs to be revisited regularly. If your Board devised its financial crime framework prior to 2022, it is time to look again.
Self-assessment
The FCA has published self-assessment questions in its financial crime guidance at FCG 7.2.1. Such questions should perhaps form the backbone of any financial crime risk assessment.
- Has your firm clearly allocated responsibility for adherence to the sanctions regime? To whom?
- Does the firm’s organisational structure with respect to sanctions compliance across different jurisdictions promote a coordinated approach and accountability?
- Has senior management set a clear risk appetite in relation to its sanctions risks, including in its exposure to sanctioned persons, activities and jurisdictions?
- Has you firm conducted a risk assessment and formed a clear view on where within the firm potential sanctions breaches are most likely to occur? (This may cover different business lines, sales channels, customer types, geographical locations, etc.)
- How is the risk assessment kept up to date, particularly after the firm enters a new jurisdiction or introduces a new product, or where it has identified new sanctions risk events, such as new sanctions regimes, sanctioned activities and evasion typologies?
- How are senior management kept up to date with sanctions compliance issues?
- Are there established procedures to identify and escalate new sanctions risk events?
- Is your firm utilising available guidance and resources on new and emerging sanctions evasion typologies?
- Has your firm established risk metrics to help detect and analyse sanctions compliance exposure on an ongoing basis?
- How does the firm monitor performance, e.g., statistical or narrative reports on matches or breaches?
- Does the firm have evidence that sanctions issues are escalated where warranted?
- Where sanctions controls processes rely on resource external to the firm, e.g., use of a third-party checking system, is there appropriate oversight and understanding of that resource?
- Where sanctions controls processes rely on third parties, including Ars, to carry out checks, is there appropriate oversight and can checks be evidenced?
Due diligence
Customer Due Diligence (“CDD”)
While CDD is not a defence to a prosecution for breach of sanctions regulations, it minimises the risk of inadvertently committing an offence. OFSI will consider whether the level of due diligence conducted was appropriate to the degree of sanctions risk and nature of the transaction.
The FCA has highlighted that firms should ensure that their documented procedures for verifying customer identity:
- Require staff to record the purpose and intended nature of the business relationship.
- Instruct staff how to assess the financial crime risks posed by each customer (See High Risk Risks and Red Flags below).
- Pinpoint when enhanced due diligence (“EDD”) is required, and what this should entail.
- Provide sufficient detail and clear guidance for staff, including the identification of politically exposed persons (“PEPs”) and their relatives and close associates (“RCAs”), and what alternative evidence can be accepted when customers lack standard forms of identification.
- State how often and at what stages periodic CDD and EDD reviews should take place.
- State if the same member of staff can be responsible for both onboarding CDD/EDD and repeat CDD/EDD, or if a second line of defence is required.
- State what staff should do if an event-driven review happens, e.g., a change in ownership or control of a customer’s company, changes to the nature of the client’s business or risk profile, regulatory or legal developments affecting the client, etc.
- State when senior management sign-off is required (specific scenarios and customer types).
- State the requirement for evidence of checks carried out to be retained on file.
Stages when CDD should be carried out and what it should entail
1. At onboarding (before entering into a business relationship, i.e., before a service is provided)
- Verify the identity of the customer
- For companies, identify and verify beneficial owners
- Understand the nature and purpose of the insurance arrangement
- Conduct sanctions screening against the UK sanctions list (See Conducting Sanctions Screening below)
- Assess money laundering / terrorist financing risk (See Higher Risk Customers and Red Flags).
2. Before placing a policy/accepting a premium
- The frozen assets list may have been updated since the initial check.
- If the insured party or beneficiary has changed, or if the instruction involve news parties (loss payees, additional insureds), or if the risk profile differs, additional checks.
3. When receiving payments, returning premiums, and paying claims.
4. When there is a change in the customer relationship – Under UK AML regulations, customer due diligence must be kept up to date and reviewed where there is a change in circumstances that may affect the customer’s risk profile, including changes in ownership or control, changes to insured parties or business structure, or changes in geographic or transactional risk.
5. Ongoing monitoring during the relationship – a prudent broker should conduct ongoing monitoring of customers to ensure the information held remains accurate.
6. Before providing any new service, such as claims handling.
7. Before paying any third-party beneficiaries.
8. Before making payments to foreign jurisdictions.
Enhanced Due Diligence (“EDD”)
Higher risk customers
The level of risk that firms face may depend on the product lines they distribute. Let’s consider ‘high risk’ risks. If your firm offers insurances for any of the following, they may present a higher-than-average level of risk, which should trigger EDD checks:
- Household, especially high net worth.
- Luxury real estate or commercial property in major cities (e.g., London, Edinburgh).
- Property Owners/ blocks of flats with high rental value that may attract illicit investment.
- Properties held in trust or owned by limited companies – e.g., figures in Iran’s Revolutionary Guard are known to have brokered deals to buy luxury properties particularly in Hampstead using shell companies to hide identities.
- Luxury Cars.
- Superyachts.
- IT companies (use of North Korean contractors and employees).
- Policies with “hidden” beneficiaries – Motor, Employee Benefits, PMI.
- Bonds where the identity of the end-customer is not notified until late in the process, e.g., legal indemnity insurance and bonds.
- Certain marine-freight shipping (ship may have been sanctioned and/or routes).
Red flags
- Parties who have recently become British citizens.
- Clients are reluctant to provide beneficial ownership information.
- Hard to identify the ultimate beneficial owner (UBO), which is a regulatory requirement.
- Companies with unusual, opaque ownership or complex structures (sanctions include any company funded by a DP, even if the DP does not own the company).
- Properties owned through multiple layers of companies, trusts or foundations in opaque jurisdictions or offshore entities in jurisdictions known for secrecy (e.g., British Virgin Islands, Panama, Nevis)
- Properties with high rental yields or cash flow that may attract illicit investment.
- Customers with associations with British Virgin Islands (BVI); the Cayman Islands; the Republic of Cyprus; Switzerland; United Arab Emirates (UAE); Guernsey; Isle of Man; Luxembourg; Austria; and Türkiye; North Korea/Democratic People’s Republic of Korea; Yemen; China; Russia; Southeast Asia or Iran.
- Vessels frequently changing names, flags, or IMO numbers or turning off AIS tracking.
- Ship-to-ship transfers (especially oil).
- Vague or inconsistent cargo descriptions.
- Shipments of coal, iron, seafood (historically sanctioned exports).
- Oil and refined petroleum imports.
- Dual-use goods (industrial equipment, machinery).
- Ports near sanctioned waters.
- Sudden changes in trade routes or counterparties.
- Identification documentation discrepancies.
- Payments routed through multiple jurisdictions with no clear reason.
- Use of small regional banks or intermediaries.
- Mismatch between, policyholder, premium payer, and claims beneficiary.
If a broker suspects money laundering or sanctions risk, EDD should occur immediately.
This may involve:
- Enhanced verification.
- Additional source-of-funds checks.
- Pausing transactions.
- Referring to a senior manager.
Conducting a sanctions search
The government frozen assets list can be found at https://search-uk-sanctions-list.service.gov.uk/
It has also devised a simple search tool, with a tick box to include fuzzy matches FCDO – UK Sanctions List Search – GOV.UK. There is an option to download results, so that these can be placed against customer records.
“Reliance on, or use of, the search tool or its results does not limit any criminal or civil liability or reduce the obligation to undertake due diligence.”
This makes it very clear that however firms chose to conduct sanctions searches, they are only part of wider due diligence, and cannot be used in place of customer due diligence (“CDD”).
If the search returns a close match, but details such as the address differs: “You may have identified a new alias being used to circumvent financial sanctions.”
What are the reporting obligations?
If a firm knows or reasonably suspects a customer is a DP (sanctions list), or if a firm suspects a transaction involves terrorist financing, it must make a report to the National Crime Agency (NCA) as soon as is reasonably practical. Failure to do so can lead to prosecution.
The standard mechanism for reports to the NCA is via a Suspicious Activity Report, but in the case of urgent time-critical issues, in addition to submitting a SAR, firms should:
- Contact the NCA’s UK Financial Intelligence Unit (UKFIU) urgently.
- Use law enforcement channels (e.g. police) if there is an immediate threat to life or active criminal activity in progress.
This would apply in the event of:
- Suspected terrorist financing with imminent risk
- Ongoing fraud where funds are actively being moved
- Situations where delay could allow assets to be dissipated
The FCA advises firms to consider whether they should report sanctions breaches to the regulator, e.g., in the event of a significant rule breach or failure in their financial crime systems and controls.
UKGI can help
We can assist you in considering your firm’s financial crime risks and financial sanctions controls. If you have any questions about, or need any support in relation to, any aspect of financial sanctions, we will be happy to discuss how we can assist.