Secondary Sanctions, Facilitation and Evasion Risk

Secondary sanctions are difficult because they do not fit the simple model of “this transaction is prohibited, therefore stop it.” In the most important United States examples, a non-US person can face a risk of being designated, blocked, or restricted from US correspondent or payable-through accounts for specified conduct even where that person is not itself a US person and the underlying activity does not depend on an ordinary US transactional nexus. The consequence is potentially severe, but the legal mechanism is different from a direct prohibition that already binds the bank or transaction.

That distinction is the starting point for this chapter. A bank must not collapse four different questions into one generic sanctions flag. First, does a directly applicable law prohibit the bank from acting? Second, does a particular authority expose a non-US person or foreign financial institution to secondary-sanctions consequences for defined conduct? Third, does the bank’s own service create separate exposure under an applicable facilitation, causing, evasion, circumvention, material-assistance or support provision? Fourth, even where the proposed activity is not prohibited, is the exposure outside the bank’s approved risk appetite?

The words secondary sanctions, facilitation, evasion and circumvention are therefore related but not interchangeable. Their legal meaning depends on the relevant programme, statute, executive order, regulation and jurisdiction. The United States uses secondary-sanctions authorities extensively. The European Union and United Kingdom have their own prohibitions, anti-circumvention rules, ownership and control concepts, trade restrictions and enforcement frameworks; they should not be described as if they simply reproduce the US secondary-sanctions model. A global bank needs a regime-by-regime legal map and then a group risk framework capable of managing the commercial exposure created by those differences.

A five-stage proximity model separates direct prohibition, secondary-authority exposure, bank service involvement, risk appetite and ongoing monitoring.

A practical four-layer mental model

The first layer is direct legal obligation. A bank asks which legal entities, branches, employees, systems, currencies, clearing arrangements and transaction touchpoints bring particular sanctions laws into scope. If applicable law requires an asset freeze, prohibits a service, restricts a trade activity or requires rejection or reporting, the bank must follow that law subject to valid exemptions, licences or derogations. Risk appetite cannot authorise prohibited activity.

The second layer is secondary-sanctions exposure. This is authority-specific. The bank identifies the exact legal authority, the person or activity covered, any significance or knowledge criteria, the potential sanctioning consequences and the authority responsible for determining whether those consequences should be imposed. The bank is not the sanctioning authority. It can assess risk and proximity, but it should not pretend to determine with certainty that a discretionary designation threshold has been crossed unless the law itself produces a direct mandatory consequence for the bank.

The third layer is the bank’s own conduct. A transaction that looks permissible for a customer can still create a separate question about the bank’s financing, processing, advisory, underwriting, insurance, custody or correspondent service. Different legal systems use different concepts here. Under US sanctions, for example, programme-specific rules can prohibit US persons from approving, financing, facilitating or guaranteeing certain foreign-person transactions that would be prohibited if performed by a US person. OFAC also states that non-US persons can be exposed where they cause or conspire to cause US persons to violate US sanctions or engage in conduct that evades US sanctions. Other authorities use their own anti-circumvention or participation tests. These concepts must be mapped separately rather than treated as one universal “facilitation rule.”

The fourth layer is risk appetite and business viability. Even where legal analysis concludes that a transaction is not directly prohibited, management can decide that the relationship creates unacceptable sanctions exposure, correspondent risk, reputational risk, operational burden or future-change risk. That is a policy decision, not a statement that the customer has broken the law. Good governance keeps those two conclusions visibly separate.

Secondary sanctions in practice: a concrete US example

Executive Order 14024, as amended by Executive Order 14114, provides a useful example because it shows why banks need a precise authority map. OFAC FAQ 1147 explains that section 11 of E.O. 14024 authorises sanctions on foreign financial institutions that conduct or facilitate certain significant transactions involving Russia’s military-industrial base. Depending on the facts, the available measures can include prohibiting or imposing strict conditions on US correspondent or payable-through accounts, or blocking the foreign financial institution.

The authority is not a universal rule that every transaction involving Russia is sanctionable. OFAC FAQ 1151 explains how OFAC interprets “foreign financial institution,” “Russia’s military-industrial base” and “significant transaction or transactions.” Significance is assessed from the totality of the facts and circumstances, including factors such as size, number and frequency, nature of the transactions, management awareness and pattern of conduct, nexus to sanctioned or military-industrial-base persons, deceptive practices and national-security impact. That is very different from a fixed monetary threshold.

OFAC FAQ 1150 also explains that specified critical items can bring a transaction into the section 11 risk framework. At the same time, FAQ 1182 makes an equally important point: foreign financial institutions may continue to conduct or facilitate transactions or provide services related to activities that are otherwise authorised or exempted under the Russian Harmful Foreign Activities Sanctions programme, and foreign persons do not risk sanctions merely for engaging in transactions authorised for US persons under relevant general licences. A bank that teaches only the risk and not the authorisation boundary will over-restrict legitimate activity.

This is why the working question is never simply “Is Russia involved?” It is: Which authority applies, to whom, for what conduct, under what conditions, with what permissions, and with what possible consequence?

Significance without false precision

Secondary-sanctions provisions often use terms such as “significant transaction” rather than a published bright-line amount. The bank therefore needs a structured assessment, but the structure must not become a fictional threshold model. Published designations, advisories and FAQs can help analysts understand how authorities describe concerning conduct, yet they are not a substitute for the actual legal criteria and do not create a safe harbour below historical transaction values.

A sound significance assessment considers the authority’s stated factors, the purpose and nature of the activity, volume and frequency, whether the conduct is isolated or sustained, management awareness, deceptive behaviour, the role of targeted sectors or persons, and the strategic importance of the service being provided. Where an authority has published specific factors, the bank should use those factors rather than inventing a generic score and labelling it law.

The output should also be calibrated. “Potential secondary-sanctions exposure under E.O. 14024 section 11” is a defensible conclusion where the facts fit the authority. “This transaction definitely crosses the secondary-sanctions threshold” may not be, because the authority may retain discretion and additional facts may matter. Legal and sanctions specialists should review boundary cases, and the decision record should show the authority, facts, assumptions, evidence gaps and management consequence.

Facilitation: do not turn one jurisdiction’s concept into a global rule

The word facilitation appears in several sanctions contexts, but its legal effect depends on the authority. In US programmes, a US-person facilitation prohibition can prevent a US person from approving, financing, facilitating or guaranteeing a transaction by a foreign person where the transaction would be prohibited if performed by the US person. Separate authorities can expose non-US persons to sanctions for material assistance, support or specified dealings, and OFAC’s general guidance also warns non-US persons against causing US persons to violate US sanctions or engaging in evasion.

The European Union and United Kingdom should be analysed through their own legal instruments. EU Russia sanctions, for example, include anti-circumvention provisions and increasingly detailed due-diligence expectations for particular goods and activities. UK sanctions legislation and OFSI guidance likewise address circumvention and facilitation of breaches within the relevant statutory framework. The correct approach is therefore an authority-to-conduct matrix: identify the rule, who it binds, the prohibited or sanctionable conduct, the mental element if any, the available permissions and the operational consequence.

For a bank, service analysis then becomes concrete. Lending can fund a transaction. Trade finance can support the movement of goods. Correspondent banking can provide access to a clearing system. Securities, custody and asset-management services can enable holding or transferring value. Insurance can sustain transport or trade. Advisory and structuring services can help a customer execute a transaction. None of these services is automatically unlawful merely because it is useful to a customer. The question is whether the particular service, in the particular legal and factual context, engages a prohibition, sanctionable-activity authority, or unacceptable policy exposure.

The facilitation map separates direct obligations, US-person facilitation rules, non-US secondary-sanctions exposure and internal policy so that one concept is not misapplied across regimes.

Knowledge and awareness: record facts before applying the legal test

There is no safe universal statement that “constructive knowledge” applies to sanctions facilitation across jurisdictions. Different laws use different formulations: knowing, knowingly and intentionally, reasonable cause to suspect, knew or should have known, or other programme-specific tests. Some designation authorities focus on the nature of the support rather than a simple knowledge formula. The bank should therefore avoid building one global field called constructiveKnowledge = true and allowing it to drive legal outcomes everywhere.

What can be standardised is the evidence record. The bank should preserve what it knew, when it knew it, how the information was obtained, what questions were asked, how the customer responded, what external information was available, which risk indicators accumulated, and which legal standard was ultimately applied. Deliberate avoidance of obvious facts may be relevant under some legal frameworks, but the legal team should map that conclusion to the actual authority rather than to an invented global doctrine.

This evidence-first approach also improves investigations. If a customer restructures ownership immediately after a designation, removes restriction-relevant words from payment narratives, adds intermediaries with no clear commercial role and refuses to explain new routes, the bank has a set of observable facts. Those facts can support a circumvention or evasion hypothesis, enhanced due diligence, transaction restriction, suspicious-activity reporting where applicable, or a relationship decision. They should not be converted automatically into a criminal-law conclusion without applying the relevant jurisdiction’s offence and mental-element requirements.

Evasion and circumvention: behaviour matters, but labels require care

Sanctions evasion can involve front or shell companies, obscured beneficial ownership, intermediaries, altered trade routes, false or incomplete documentation, payment fragmentation, virtual assets, alternative messaging or settlement channels, and manipulation of shipping or logistics data. FATF’s June 2025 report on complex proliferation-financing and sanctions-evasion schemes describes these patterns across multiple jurisdictions and emphasises the use of intermediaries, beneficial-ownership opacity, virtual assets and maritime channels.

A bank should detect the pattern rather than rely on one indicator. A new intermediary is not evasion by itself. A changed route can reflect legitimate commercial disruption. An AIS gap can have technical explanations. A virtual-asset transfer does not prove sanctions circumvention. Risk rises when several facts align: the timing follows a new restriction, the structure has no credible commercial benefit, transparency decreases, counterparties change while economic purpose remains the same, documents become less specific, or the customer repeatedly modifies arrangements after controls identify them.

The legal response then depends on jurisdiction. In the UK, current government guidance states that intentionally participating in activities whose object or effect is directly or indirectly to circumvent sanctions or enable or facilitate a breach can be a criminal offence, and circumvention can also attract civil consequences. EU sanctions contain their own anti-circumvention provisions. US authorities address evasion, causing and conspiracy as well as programme-specific support and secondary-sanctions authorities. The bank should preserve the evidence and route the case to the correct legal and reporting process rather than declaring that “evasion is criminal everywhere.”

Customer and relationship risk

Secondary exposure usually appears first as a relationship question. A customer can be legally established, transparently owned and not designated, yet operate in a sector or network where the bank faces secondary-sanctions or future-designation risk. A useful customer assessment therefore combines ordinary KYC with sector, geography, counterparty, product, corridor, trade, ownership and network information.

Trajectory matters because exposure can change faster than the KYC cycle. A manufacturer may move from ordinary industrial sales into high-priority dual-use goods. A respondent bank may grow its business with customers active in a targeted military-industrial sector. A shipping company may begin serving ports, vessels or routes associated with evasion typologies. A fintech may expand into payment or virtual-asset channels used by networks already subject to sanctions alerts. These changes should trigger event-driven review rather than wait for the next calendar-based refresh.

The outcome does not have to be binary. The bank may continue a relationship but restrict products, require stronger transparency, impose use-of-proceeds conditions, cap particular exposures, require pre-transaction review, or prohibit defined corridors. Where risk cannot be understood or controlled, managed exit can be appropriate. The decision should state clearly whether it is driven by law, licence conditions, sanctions risk appetite, correspondent expectations, or a combination.

Correspondent banking and foreign-financial-institution exposure

Correspondent banking deserves special attention because one bank can provide access to settlement and clearing for another institution’s customer base. In the E.O. 14024 example, OFAC specifically addresses foreign financial institutions. A correspondent therefore needs to know whether respondent activity falls within the relevant definition, whether transactions involve Russia’s military-industrial base or specified critical items, and whether significance factors are present. It also needs visibility into nested activity where that visibility is necessary to understand the risk.

The response should be evidence-led. A respondent’s refusal to provide information is not itself proof of sanctions evasion, but it can make risk impossible to manage. Rapid growth in an opaque corridor, repeated links to designated or military-industrial-base counterparties, use of alternative settlement arrangements after restrictions, or unexplained changes in message content can justify enhanced inquiry and tighter conditions. OFAC’s November 2024 alert on Russia’s System for Transfer of Financial Messages illustrates why foreign financial institutions are expected to consider sanctions risks created by alternative financial messaging and settlement infrastructure in the Russia context.

The bank should maintain a respondent knowledge record rather than claim that all accumulated indicators automatically create a universal legal doctrine of constructive knowledge. The record supports whichever awareness or knowledge test is actually relevant and, separately, the bank’s own appetite decision.

Product and system touchpoints

Secondary-sanctions risk crosses systems that are often owned by different teams. Customer data sits in KYC platforms. Ownership graphs may sit in entity-master or screening tools. Payment messages contain debtor, creditor, agent, address, purpose and remittance information. Trade systems hold invoices, bills of lading, goods descriptions, ports and vessel data. Treasury and markets systems hold securities, derivatives, currencies and counterparties. Correspondent platforms hold respondent and nested-flow information. Case-management systems hold prior investigations and decisions.

A useful control architecture does not force all of this data into one score. It makes the relevant facts retrievable for the legal question being asked. An alert concerning a foreign financial institution may need its legal-entity classification, the counterparties, the sector involved, whether a designated person or military-industrial-base actor is implicated, transaction values and frequency, management-awareness indicators, any deceptive practices, applicable licences and previous cases. The system should show the provenance and effective date of each fact so analysts can reconstruct what was known at decision time.

Structured ISO 20022 data can improve party and agent identification, but it does not solve the legal analysis. Better debtor, creditor and intermediary data supports screening and network analysis; remittance and purpose data can provide context; UETR and end-to-end references improve traceability. Yet a structured payment message may still omit the goods, end user, ownership chain or commercial purpose that determines secondary-sanctions exposure. Requirements should therefore connect payment data to customer, trade and investigation data rather than assume the message itself contains the full answer.

Proximity monitoring architecture

A practical monitoring design starts with a current authority library: relevant sanctions programmes, executive orders, regulations, determinations, lists, advisories, FAQs, licences and effective dates. Legal and sanctions policy translate those authorities into operational rules. Customer and transaction data then provide the facts against which the rules are assessed. Cases preserve the reasoning where automation cannot make the decision safely.

Different signals deserve different treatment. A direct list match routes to sanctions interdiction. A customer’s growth in a targeted sector may route to enhanced relationship review. A foreign financial institution processing potentially significant transactions for a targeted network may require secondary-sanctions assessment. A pattern of newly inserted intermediaries and stripped payment narratives may route to an evasion investigation. These should not all be forced through the same threshold because the legal questions and operational outcomes differ.

The control architecture joins current legal authorities with customer, payment, trade and network data before routing facts to distinct legal, secondary-risk, evasion and appetite decisions.

Risk appetite and trajectory monitoring

Risk appetite is most useful in the space where law does not already dictate the answer. The bank can define categories such as ordinary exposure, enhanced-review exposure, senior-approval exposure and prohibited-by-policy exposure. The criteria should be linked to observable facts rather than labels such as “high risk.” Examples include customer activity in a specifically targeted sector, repeated dealings with persons close to designation networks, respondent opacity, critical-item trade, use of evasion-prone routes, or inability to verify end use.

Trajectory monitoring asks how the position is moving. A customer whose exposure remains stable and transparent presents a different management question from one rapidly expanding into a targeted sector after competitors have withdrawn. Trend analysis can examine volume, frequency, corridor changes, new counterparties, sector changes and network proximity. External events such as new designations or changes to legal authorities can trigger immediate reassessment.

Policy boundaries should never be presented as legal thresholds. A group may decide that it will not bank certain activity even though the applicable law would permit it. That decision can be entirely legitimate, but customer communication, governance and internal records should describe it accurately as a risk or policy decision.

Investigation workflow

A secondary-sanctions or evasion investigation starts by freezing the facts, not necessarily the funds. The investigator preserves relevant payment, customer, ownership, trade, communications and network evidence; identifies the applicable legal entities and jurisdictions; and records the authority or risk hypothesis being tested. If a directly applicable law requires a hold, freeze, rejection or other protective action, that action follows the relevant procedure immediately. If the issue is secondary exposure rather than direct prohibition, the bank should not invent blocking obligations that do not exist.

The next step is to test competing explanations. Was the new intermediary commercially necessary? Did a route change because of logistics disruption? Is the customer trading goods actually covered by a determination or merely goods in the same broad industry? Does the foreign financial institution meet the relevant definition? Does the activity involve the targeted person, sector or military-industrial base? Are significance factors present? Is there an applicable exemption, general licence, specific licence or other authorisation? What did the bank and customer know, and when?

The conclusion should separate four outcomes: legal disposition; regulatory or suspicious-activity reporting where applicable; customer or product risk decision; and control remediation. A relationship can be exited without the bank alleging criminal conduct. A transaction can be prohibited while the wider relationship remains possible. An evasion concern can produce an intelligence report even when a separate sanctions disposition is not required. Keeping those outcomes separate produces better controls and fairer customer treatment.

Winding down business safely

When the decision is to exit or restrict activity, the bank must understand whether the wind-down itself is permitted. Existing loans, custody positions, securities, guarantees, letters of credit, insurance obligations, trade shipments and payments in flight can create continuing legal and operational duties. Some regimes provide general licences, wind-down periods, derogations or licensing routes; others do not. Contractual obligations do not override sanctions law.

The bank should map outstanding positions, new-value creation, payments needed to close obligations, collateral, fees, interest, asset transfers, counterparties and deadlines. Legal analysis determines what can be performed, what requires authorisation and what must stop. Operations then build an executable plan with maker-checker controls and evidence. Post-exit monitoring can look for attempted re-entry through new entities, ownership changes or renamed counterparties where the risk justifies it.

A controlled wind-down checks legal authority first, then separates permitted close-out from new support, executes authorised actions and preserves evidence for review.

Insurance, asset management and professional services

The same analytical discipline applies outside traditional payments. An insurer may provide cover that supports transport or trade. An asset manager may hold or trade securities connected to targeted actors or sectors. A custodian may process income or corporate actions. A trustee or fiduciary may administer structures with sanctions-sensitive beneficiaries. A law firm or other professional intermediary may use client accounts or escrow services in transactions the bank does not otherwise see directly.

The bank should avoid category assumptions. Banking a law firm is not facilitation of every client matter. Financing an insurer is not participation in every insured transaction. The question is how the bank’s actual service relates to the relevant activity and what information it has. Product-specific due diligence can distinguish ordinary operating accounts from transaction-specific escrow, general corporate lending from ring-fenced financing, or diversified insurance operations from cover directly connected to sanctionable activity.

Published actions are evidence, not a private rulebook

Treasury and other authorities publish designation actions describing networks, sectors and conduct that triggered sanctions. These are valuable learning materials because they show real structures: front companies, payment channels, foreign financial institutions, shipping networks, trade intermediaries and material-support relationships. Treasury’s January 15, 2025 action, for example, described a cross-border payment scheme for sensitive exports and separately highlighted mandatory secondary-sanctions exposure under a specific Russia-related authority for foreign persons knowingly facilitating significant transactions for or on behalf of certain entities.

But published actions should not be converted into an unofficial threshold table. A designation may reflect classified intelligence, policy priorities, facts not disclosed publicly, or authority-specific criteria. The bank can use precedents to identify patterns and questions, not to claim that an amount below a prior case is safe or an amount above it is automatically sanctionable.

Technology and BA design considerations

Business analysts should model the legal concepts explicitly. Useful entities include legalAuthority, programme, effectiveFrom, effectiveTo, subjectType, coveredConduct, knowledgeStandard, significanceFactors, permissionType, permissionReference, applicableBankEntity, customer, counterparty, sector, transaction, serviceProvided, decision, decisionBasis and evidenceSource. Avoid a single Boolean such as secondarySanctions=true because it cannot explain who is exposed, under which authority or why.

Rules need effective dating. A transaction initiated before a new determination but settled after it may need temporal analysis. Customer sectors change. Designations are added and removed. Licences expire or are amended. Authorities publish new FAQs and guidance. The system should retain the rule version and data snapshot used at decision time so audit can reconstruct the outcome.

Testing should include deliberately divergent cases. A US-person transaction directly prohibited under an applicable regulation should not be treated the same way as a non-US foreign financial institution facing a potential E.O. 14024 secondary-sanctions risk. A payment connected to activity authorised by an OFAC general licence should not be blocked merely because the counterparty is in a higher-risk sector if the authorisation genuinely covers the activity. An EU operator facing an anti-circumvention question needs the EU legal test, not an imported OFAC “significance” rule. Negative tests are as important as positive ones because over-compliance can interrupt lawful humanitarian, medical, agricultural and ordinary commercial activity.

Mini case: foreign bank and a Russia-related payment chain

Consider a fictional non-US bank processing repeated cross-border payments for an industrial customer. The payments do not pass through the United States and are denominated in a non-US currency. Initial screening finds no direct SDN match. Further review identifies that a counterparty operates within a part of Russia’s military-industrial base relevant to E.O. 14024 section 11, and transaction values have increased materially. Payment narratives are generic, while invoices show machinery and components matching categories requiring specialist review.

The wrong approach is to say “no US nexus, therefore no US sanctions risk.” The second wrong approach is to say “Russia military industry, therefore freeze the funds.” The correct analysis separates direct applicability from secondary exposure. The bank confirms whether it falls within the foreign-financial-institution definition, identifies the relevant E.O. 14024 authority and current determinations, assesses whether the activity involves the military-industrial base, evaluates OFAC’s published significance factors, checks licences and exempt or authorised activity, and documents any deceptive-practice indicators. Legal and senior sanctions specialists then decide whether to process, impose conditions, restrict the relationship or exit according to law and risk appetite.

If facts instead show that the activity is authorised for US persons under a relevant general licence, FAQ 1182 becomes highly relevant and the bank should not describe the activity as automatically sanctionable merely because a blocked person or Russia-related context appears in the chain. If the customer has inserted entities and routes specifically to disguise a prohibited beneficiary, the issue expands into evasion and potential reporting. The quality of the outcome depends on keeping each legal question separate while joining the facts into one investigation record.

Governance and assurance

First-line business and operations teams own accurate customer and transaction data and execute restrictions. Sanctions compliance owns policy interpretation, control standards and specialist decisions within its mandate. Legal advises on jurisdiction, authority, conflicts and ambiguous legal boundaries. Financial-crime investigations examine evasion patterns and reporting obligations. Product and technology teams implement the rules and evidence model. Senior management owns risk appetite. Internal audit independently tests whether the framework works as designed.

Management information should show more than alert volumes. Useful measures include secondary-exposure cases by authority and outcome, aged legal escalations, customers under conditional continuation, breaches of transparency conditions, trajectory-triggered reviews, correspondent restrictions, licensing dependencies, control overrides, repeat evasion patterns, and cases where legal and policy outcomes diverged. Those measures expose whether the bank is managing the risk or simply creating paperwork around it.

Common failure modes

The first failure is US-centric overgeneralisation: taking a US concept such as secondary sanctions or facilitation and presenting it as global law. The second is nexus blindness: assuming absence of an ordinary US payment nexus eliminates secondary exposure. The third is over-compliance: treating potential secondary risk as if it created an automatic asset freeze. The fourth is threshold invention: converting published designation examples into unofficial safe harbours or mandatory cut-offs. The fifth is knowledge shorthand: using “constructive knowledge” without identifying the legal standard actually applicable. The sixth is permission blindness: ignoring exemptions, licences and authorised activity. The seventh is data fragmentation: leaving customer, payment, trade and network facts in systems that investigators cannot join.

A mature programme addresses all seven. It maps authorities precisely, separates direct obligations from sanctioning risk, preserves the bank’s evidence position, detects evasion patterns across systems, incorporates permissions, gives senior management explicit appetite choices and tests both under-blocking and over-blocking scenarios.

What to remember

Secondary sanctions are not simply “sanctions outside the country.” They are specific authorities that can expose non-domestic persons to consequences for defined conduct even without the ordinary jurisdictional nexus associated with primary prohibitions. The United States makes extensive use of this model, including authorities applicable to foreign financial institutions.

Facilitation, material assistance, causing, evasion and circumvention are separate legal concepts whose scope depends on the relevant regime. Banks should standardise evidence and workflow, not invent one global legal test.

The strongest operating model separates direct prohibition, secondary-sanctions exposure, bank-service exposure and internal risk appetite; connects current legal authorities to customer, payment, trade and network data; and preserves the reasoning behind every decision. That makes the framework both more accurate and more practical: lawful activity can continue where justified, while genuinely sanctionable or evasive activity is identified early enough for controlled action.

Operational deep dive: significance, knowledge and proximity instrumentation

The base chapter separates direct prohibition, secondary-sanctions exposure, bank-service exposure and policy appetite. This deep dive turns that separation into a workable operating model. The central discipline is to standardise the fact gathering and decision process while allowing the legal test to remain authority-specific. A global bank can use one evidence architecture, but it cannot safely use one universal legal threshold.

Significance assessment without invented bright lines

Some secondary-sanctions authorities use a significance concept without publishing a single monetary threshold. OFAC’s interpretation of “significant transaction or transactions” under E.O. 14024 is a good example. FAQ 1151 describes a totality-of-the-circumstances assessment that can consider size, number and frequency, nature of the transactions, management awareness and pattern of conduct, nexus to sanctioned or military-industrial-base persons, deceptive practices, national-security impact and other relevant factors.

A bank should translate those stated factors into an evidence template, not into a point score presented as law. For each relevant transaction set, the analyst should record the authority being assessed, the covered conduct, the amounts and frequency, the role of the customer and bank, the counterparties and sectors, any evidence of concealment, management awareness and any applicable authorisation or exemption. The conclusion should explain which factors increase or reduce exposure and which facts remain uncertain.

Published designation and enforcement actions can help analysts understand what authorities have considered important in real cases. They should be treated as context, not as private thresholds. A prior designation involving a large value does not imply that smaller activity is safe. A prior action involving a particular sector does not mean the same outcome follows automatically for every customer in that sector. Public notices rarely contain every fact available to the authority, and policy priorities can change.

Trajectory is still useful, but it belongs to risk management rather than legal threshold invention. A foreign financial institution whose relevant exposure grows tenfold, adds new counterparties in a targeted military-industrial network and becomes less transparent creates a different appetite question from an institution with small, stable and well-explained activity. The change in direction can justify enhanced review before a direct legal issue arises.

Build an authority sheet before assessing the case

Each secondary-sanctions assessment should begin with a short authority sheet. It identifies the exact statute, executive order, determination or regulation; the persons potentially exposed; the activity capable of triggering consequences; any significance, knowledge or support criteria; available authorisations or exclusions; the sanctions measures the authority may impose; and the effective date. The sheet should also identify which bank legal entities are directly subject to the rule and which are assessing secondary exposure as non-domestic persons.

For E.O. 14024 section 11, for example, the sheet should distinguish the foreign-financial-institution definition, Russia’s military-industrial base, the current critical-items determination, the significance factors in FAQ 1151 and the possible correspondent-account or blocking consequences described by OFAC. It should also point reviewers to FAQ 1182 so authorised or exempt activity is not incorrectly treated as automatically sanctionable.

The same template can be used for a different programme, but the content must be rebuilt from that programme’s authority. Analysts should never copy the E.O. 14024 significance factors into an unrelated regime unless the authority actually uses them.

Knowledge: standardise the evidence, not the legal label

A recurring control error is to use constructive knowledge as if it were a universal sanctions doctrine. It is not. Authorities use different mental-element formulations and different legal mechanisms. US sanctions can use terms such as knowingly, material assistance or causing; UK and EU anti-circumvention provisions have their own wording and enforcement rules; civil enforcement can also differ from criminal liability. The correct legal standard must be taken from the applicable authority.

What the bank can standardise is a knowledge chronology. That chronology records each relevant fact, when it became available, its source, who received it, how reliable it was considered, what follow-up was performed and how the fact affected the decision. The chronology should include customer disclosures, screening results, adverse public information, payment and trade patterns, relationship-manager knowledge, legal advice, prior alerts and information received from correspondents or competent authorities.

This design avoids two opposite failures. The first is knowledge amnesia, where indicators are reviewed in separate systems and no one sees the cumulative picture. The second is legal overreach, where the mere existence of multiple indicators is declared to satisfy a legal knowledge test without authority-specific analysis. A longitudinal evidence record solves the first problem without creating the second.

Where a customer repeatedly resists reasonable transparency requests, changes structures immediately after sanctions changes, or provides explanations contradicted by independent evidence, those facts should be recorded and escalated. They can strengthen an evasion or circumvention hypothesis and may be relevant to an applicable mental-element test. They do not eliminate the need to apply the actual law.

Distinguish four decisions in the case record

A strong case file contains four separate decisions.

Legal disposition records whether directly applicable law requires a freeze, block, rejection, prohibition, licence, reporting action or other treatment.

Secondary-exposure assessment records whether a non-domestic person or foreign financial institution may fall within a specific sanctionable-activity authority and how strong that exposure appears based on the published criteria.

Financial-crime investigation outcome records whether the facts indicate evasion, circumvention, suspicious activity, false documentation, ownership concealment or another behaviour requiring investigation or reporting under applicable law.

Risk-appetite outcome records whether the bank is willing to continue the customer, transaction, product or corridor even where legal analysis permits it.

Keeping these decisions separate prevents the system from converting “outside appetite” into “illegal” or “secondary risk” into “asset freeze.” It also lets the bank explain later why it refused business that was technically lawful without falsely accusing the customer of a sanctions breach.

Sector and network monitoring

Secondary exposure often concentrates around sectors named in specific authorities or around networks supporting designated actors. Monitoring therefore needs more than static industry codes. The bank should understand the customer’s actual products and services, material counterparties, trade routes, end users where relevant, geographic footprint and changes in business activity.

For foreign financial institutions, the bank may also need to understand respondent or nested flows. OFAC’s Russia-related guidance is particularly relevant where a foreign financial institution conducts or facilitates significant transactions or provides services involving Russia’s military-industrial base. The bank should identify what information it actually possesses about the underlying activity and avoid making confidence claims that its data cannot support.

Network analysis can add context by connecting customers to counterparties, owners, directors, intermediaries, vessels, virtual-asset addresses and previously investigated entities. The purpose is not guilt by association. The purpose is to reveal paths that may explain otherwise disconnected transactions and to identify where additional facts are needed.

The proximity architecture combines current authorities with customer, payment, trade and network evidence, then routes cases to legal, secondary-exposure, investigation and appetite decisions.

Trajectory analytics

Trajectory monitoring is most effective when it tracks interpretable changes. Useful measures include growth in transactions with a targeted sector, new high-risk corridors, new intermediaries, increased use of alternative payment or messaging channels, changes in goods categories, recurring transfers just below internal review triggers, a rise in counterparties linked to designated networks, and customer behaviour after sanctions changes.

External-event correlation can make those measures more meaningful. If a new restriction is announced and the customer immediately changes invoicing entities, routing countries and payment narratives while the economic purpose stays the same, the timing deserves investigation. If similar changes occurred months earlier for unrelated commercial reasons and are transparently documented, the same pattern may be benign.

Analytics should therefore generate questions, not legal conclusions. A trajectory alert can trigger enhanced due diligence or specialist review. The legal decision remains with the appropriate sanctions and legal function.

Payment and dollar-clearing exposure

Dollar clearing can create direct US sanctions questions because US financial institutions and US jurisdiction may enter the payment path. That direct-nexus analysis must be kept separate from secondary sanctions. A non-dollar, non-US payment can still create secondary exposure under a specific authority; conversely, a dollar payment can create direct OFAC obligations even where secondary sanctions are irrelevant.

For correspondent banking, the system should preserve the payment route, currencies, agents, respondent, any nested institution, originator and beneficiary data, message fields used in screening, repair history and changes to routing. Repeated removal or mutation of information after sanctions alerts can be an important evasion signal, while ordinary formatting repairs should not be treated as concealment without supporting evidence.

Respondent questionnaires can collect sector exposure, sanctions-control design, nested-activity governance, material incidents and escalation arrangements. High-risk answers should be verified with evidence proportionate to the exposure rather than accepted as policy statements. Contractual transparency provisions can require timely responses to investigations and material-change notifications, subject to local confidentiality and data-protection law.

Evasion typologies as hypotheses

FATF’s 2025 report on complex proliferation-financing and sanctions-evasion schemes is useful because it shows how evasion networks combine techniques: intermediaries, front and shell companies, obscured beneficial ownership, virtual assets, trade-based methods and maritime channels. Banks should use these patterns as investigative hypotheses rather than deterministic rules.

A shell company can have a legitimate purpose. A third-country intermediary can have a real distribution role. Virtual assets can be used lawfully. Maritime route changes can follow weather, insurance or port disruption. The investigation becomes stronger when several independent facts support the same hidden-purpose explanation and weaker when transparent commercial evidence explains the activity.

This approach also protects against over-compliance. Controls that automatically reject every third-country intermediary or every virtual-asset touchpoint push legitimate activity away without necessarily improving sanctions effectiveness. Evidence-led investigation concentrates attention where facts actually support evasion.

Failure-mode testing

Testing should prove that systems distinguish legal questions rather than simply generate alerts. A good scenario pack includes:

  • a directly prohibited transaction with a clear jurisdictional nexus and no permission;
  • a non-US foreign financial institution with potential secondary exposure under a specified authority but no direct blocking obligation;
  • activity covered by a valid general licence or exemption;
  • an EU circumvention scenario that must be assessed under EU law rather than OFAC significance factors;
  • a UK case where current OFSI rules and the applicable statutory test drive the outcome;
  • a customer outside policy appetite even though legal review finds the activity permissible;
  • an evasion pattern with multiple corroborating indicators and a competing legitimate explanation.

For each test, expected results should cover screening, case routing, decision ownership, legal basis, customer treatment, reporting and audit evidence. Testers should fail the implementation if the system produces the right operational result for the wrong legal reason, because that defect will become dangerous when the next scenario differs.

Practitioner checkpoint

A practitioner completing this deep dive should be able to identify the exact secondary authority before assessing exposure, use the authority’s own significance and knowledge criteria, preserve a longitudinal evidence record without inventing universal legal doctrines, separate direct disposition from secondary risk and policy appetite, and design data and testing around those distinctions. If the framework cannot explain which authority, which person, which conduct, which evidence and which consequence, it is not ready for production use.

Advanced practice: worked secondary-sanctions, facilitation and evasion cases

The cases below are fictional and the figures are illustrative. Their purpose is to show how an experienced bank separates legal applicability, secondary-sanctions exposure, evasion evidence and internal appetite. None of the cases assumes that the same legal outcome applies across the United States, European Union, United Kingdom or another jurisdiction. A live case must be tied to the actual law, authority, licence position and bank entity involved.

A worked-case pattern moves from authority and facts through direct-law analysis, secondary-exposure assessment, permissions, investigation and policy outcome.

Case 1: a foreign bank processing Russia military-industrial-base payments

A non-US commercial bank processes repeated non-dollar payments for a manufacturing customer. The bank has no branch in the United States and the payment chain does not use a US correspondent. Initial screening finds no direct name match. Enhanced review identifies that a material counterparty operates in an area falling within Russia’s military-industrial base as described in current OFAC guidance, and invoices refer to components that require review against the current Russia Critical Items Determination.

The first question is not “Is there a US nexus?” It is whether the bank falls within the foreign-financial-institution definition relevant to E.O. 14024 section 11 and whether the activity fits the current sanctionable-activity authority. OFAC FAQ 1147 explains the section 11 mechanism; FAQ 1151 explains how OFAC interprets foreign financial institution, Russia’s military-industrial base and significant transactions. The bank therefore gathers the value, number and frequency of transactions, nature of the activity, management awareness, links to covered persons or sectors and any deceptive practices rather than applying a fictional dollar threshold.

The second question is whether an authorisation or exemption changes the analysis. FAQ 1182 makes clear that foreign financial institutions may continue to support activity that is otherwise authorised or exempted under the relevant Russia sanctions programme. The third question is risk appetite: even where legal review cannot say that designation is inevitable, management may decide that sustained financing of the activity creates unacceptable exposure.

A defensible outcome in this fictional case is enhanced restriction while specialist review completes, followed by either conditional continuation with defined transparency and product limits or managed exit. The bank does not automatically freeze funds merely because secondary-sanctions risk exists. A freeze would require a separate legal basis applicable to the bank or property.

Case 2: dollar payment with a direct OFAC issue

A European corporate customer sends a US-dollar payment through a US correspondent to a beneficiary whose ownership structure indicates that it is blocked under OFAC’s 50 Percent Rule. The customer argues that the bank is European and therefore the issue is only “secondary sanctions.”

That framing is wrong. The dollar-clearing route can bring a US financial institution and US jurisdiction into the transaction. The case therefore begins with direct OFAC applicability and the obligations of the US correspondent, not with a secondary-sanctions proximity model. The European bank separately assesses its own applicable EU law, contract and correspondent obligations.

The teaching point is fundamental: extraterritorial-looking facts do not automatically mean the issue is secondary sanctions. Payment routing, currency, bank entities and property location can create direct legal obligations. Systems need to preserve routing and agent data so analysts can identify the correct legal path.

Case 3: EU operator and suspected circumvention

An EU-established exporter has historically sold industrial equipment directly to customers in a third country. Shortly after new EU restrictions affect exports to Russia, the exporter’s volumes to that third country triple. New distributors have minimal operating history, documents become less specific about end use and freight routes converge toward logistics hubs commonly used for onward trade into Russia.

The bank should not import OFAC’s E.O. 14024 “significant transaction” factors and call this a secondary-sanctions case. The relevant EU legal instruments and anti-circumvention provisions must be assessed on their own terms. European Commission guidance on circumvention and due diligence is directly relevant to the customer’s obligations and to the bank’s understanding of the risk.

The bank builds an evidence picture: customer explanation, historical sales, end users, distributors, shipping documents, goods classification, payment route, ownership and whether the restructuring has a credible commercial rationale. If the evidence supports a circumvention concern, the case routes through the bank’s EU sanctions, legal and financial-crime processes. The customer may also fall outside risk appetite even before a final legal conclusion is available.

The lesson is that one behaviour can create different legal questions in different regimes. The workflow can be common; the legal test cannot.

Case 4: UK services and a possible circumvention arrangement

A UK-based professional-services firm is asked to structure a chain of entities and payment arrangements for a client whose normal business has become restricted. Internal emails obtained through the bank’s legitimate due-diligence process show that the commercial objective is to preserve the same economic activity while removing visible references to the restricted counterparty.

Current UK government guidance warns that intentionally participating in activities whose object or effect is directly or indirectly to circumvent sanctions or enable or facilitate a breach can be a criminal offence, with civil consequences also possible. The bank therefore treats the evidence as a potential UK circumvention issue, not as a generic “secondary-sanctions proximity” concern.

If the bank provides escrow or transaction services specifically enabling the restructured deal, its own role requires separate analysis. General banking of the professional firm is not automatically equivalent to facilitating every client matter. The bank should distinguish operating accounts from transaction-specific services and apply the UK legal test to the facts.

Case 5: respondent bank and opaque nested flows

A respondent bank provides access to payment services for several money-service businesses. The correspondent observes rapid growth in flows involving sectors and counterparties linked to a sanctions-sensitive network. Requests for additional information repeatedly produce incomplete answers. Some payment narratives become less descriptive after earlier inquiries, and routing moves across several intermediaries without an obvious efficiency benefit.

Opacity is not proof of evasion. However, it can make the risk unmanageable. The correspondent records what it knows, what is missing and why the missing information matters. It considers whether any direct sanctions rule applies to payments already received, whether a specific secondary-sanctions authority is relevant to the respondent, whether the patterns support an evasion investigation, and whether the respondent’s transparency is consistent with the correspondent’s contractual requirements and appetite.

A plausible policy outcome is a deadline for enhanced transparency, transaction restrictions on defined high-risk flows and exit preparation if the respondent cannot provide evidence sufficient to manage the exposure. If a suspicious-activity or sanctions report is required, that reporting decision is documented separately from the relationship decision.

The lesson is that insufficient transparency can justify a risk decision without being mislabelled as a proven legal breach.

Case 6: aviation finance and diversion risk

An aircraft lessor financed by the bank leases aircraft to carriers operating near sanctioned markets. Flight data, maintenance arrangements and route changes suggest that two aircraft may be serving prohibited destinations through indirect routing. Lease contracts contain geographic restrictions, but enforcement by the lessor appears weak.

The bank combines aircraft identifiers, lease documents, routing data, maintenance providers, insurance, payment flows and the lessor’s monitoring records. It asks whether the actual use of the aircraft engages sanctions or export-control restrictions applicable to any bank entity, whether any non-domestic secondary-sanctions authority creates exposure for the lessor or bank, and whether the lessor is taking credible action under its contractual rights.

The bank should not treat an ADS-B gap or indirect route as proof. It looks for corroboration: repeated route patterns, landing or service records, payments to relevant facilities, communications and ownership or control links. Where evidence remains unresolved, the bank can tighten financing conditions and require additional reporting without declaring that sanctions evasion has been legally established.

Case 7: virtual-asset off-ramp and a sanctioned network

A regulated fintech customer converts virtual assets into fiat currency. Blockchain analytics indicates repeated exposure to wallets attributed by reliable sources to a sanctioned network, while some flows pass through mixers or nested services before reaching the customer. The customer argues that blockchain attribution is probabilistic and that privacy tools have legitimate uses.

The correct response is empirical verification. The bank reviews the analytics methodology, confidence level, hop distance, transaction values, timing and corroborating customer information. It distinguishes direct dealings with identified sanctioned addresses from more remote exposure. It checks whether any transaction involves a directly prohibited person under law applicable to the bank and whether the customer’s behaviour creates separate secondary or evasion concerns.

The bank also considers FATF’s current typology work, which highlights virtual assets as one of several channels used in sanctions-evasion and proliferation-financing schemes. FATF typologies inform detection but do not themselves create a sanctions prohibition.

A differentiated outcome may restrict higher-risk flow categories, require real-time screening and enhanced source-of-funds evidence, and prepare for exit if the customer’s business model depends on opaque sanctioned exposure. The bank should be equally willing to clear false positives where the evidence does not support the initial attribution.

Case 8: humanitarian trade near a blocked network

A foreign financial institution is asked to process payments for medical equipment entering a jurisdiction with extensive sanctions. One logistics provider is owned by a blocked person, while the underlying medical activity may fall within an applicable authorisation. Operations proposes rejecting everything to avoid risk.

That approach can be legally and ethically wrong. The bank must examine the specific authorisation, parties, ownership and control, permitted services, reporting conditions and payment route. OFAC FAQ 1182 is important in the Russia context because it states that foreign financial institutions do not face sanctions risk merely for engaging in activity authorised for US persons under relevant general licences. Other programmes have their own humanitarian permissions and conditions.

The bank may still need a licensed or alternative logistics solution if the blocked provider is not covered, but it should not collapse “blocked person in the chain” into “all humanitarian activity prohibited.” Good sanctions control protects legitimate authorised activity while preventing diversion.

Case 9: conglomerate with one high-risk division

A multinational group has a large clean manufacturing business, a smaller trading division active in a sanctions-sensitive sector and a financing subsidiary serving third parties. The bank provides lending, cash management and trade finance across the group.

A group-level yes/no risk score is too crude. The bank maps legal entities, ownership, intra-group funding, cash pooling, use of proceeds and product access. Clean subsidiaries may remain bankable while specific services to the higher-risk division are restricted. General corporate lending needs analysis of whether funds can be diverted to the sensitive activity; cash pooling needs visibility into value movement; trade finance requires transaction-level review.

The legal analysis remains authority-specific. The policy analysis can be broader. Management can choose to prohibit financing of the sensitive division even if some transactions are legally permitted, while preserving ordinary banking for clean subsidiaries where controls can prevent cross-benefit.

Case 10: publication of a new designation during settlement

A customer payment has passed customer screening and entered settlement when a relevant authority publishes a new designation. Different systems update the list at different times. One operations team sees the change before another.

The bank’s response depends on the effective time of the designation, the law applicable to the bank entities and property, the status of the payment, and any permissions. Operations should not apply a secondary-sanctions risk model where a direct asset-freeze rule now applies. Conversely, if the announcement creates only a new secondary-sanctions exposure for a non-domestic bank, teams should not invent a freeze obligation.

This case tests list-update latency, event timestamps, payment status, control sequencing and legal decision ownership. It also shows why secondary-sanctions training must connect to sanctions interdiction: the same customer can move from appetite-managed proximity to direct prohibition when a designation or legal change occurs.

What these cases teach

The common pattern is not “be conservative.” It is be precise. Identify the authority before applying the test. Separate direct law from secondary exposure. Check permissions as carefully as prohibitions. Treat typologies as evidence prompts, not proof. Preserve the bank’s own service role. Distinguish legal outcomes from policy outcomes. Use senior governance for material appetite decisions, and make the system retain enough data to reconstruct why the decision was made.

Practice close: the secondary-sanctions analyst's playbook

A good analyst should be able to move from an unfamiliar sanctions question to a defensible decision without reaching first for a generic “high risk” label. The playbook below is designed for sanctions specialists, relationship managers, operations teams, investigators, business analysts and technology teams who need a common sequence while still respecting jurisdiction-specific law.

Step 1: define the bank entity and the transaction footprint

Start with the bank legal entity, branch, booking location, payment route, currencies, clearing banks, products and systems involved. Identify the customer, counterparties, agents, owners and any trade or asset information that matters. This prevents a secondary-sanctions discussion from obscuring a direct prohibition created by a US, EU, UK or other nexus.

Record what is known and what is missing. Missing information is not automatically suspicious, but it can determine whether the bank can safely continue. If the legal analysis depends on an end user, goods classification, respondent customer or beneficial owner that the bank cannot identify, the case should say so explicitly.

Step 2: identify the exact authority

Do not assess “secondary sanctions” in the abstract. Name the statute, executive order, determination, regulation or other authority. Record who can be exposed, what conduct is covered, whether significance or knowledge criteria apply, what sanctions measures can be imposed and which permissions or exclusions can change the result.

For a foreign financial institution reviewing Russia-related exposure under E.O. 14024, the authority sheet should point to the current section 11 framework, current determinations and relevant OFAC FAQs. For an EU circumvention issue, use the applicable EU regulation and Commission guidance. For a UK case, use the relevant UK sanctions regulations and current OFSI or government guidance. The workflow can be common; the legal test is not.

Step 3: separate direct prohibition from secondary exposure

The case record should answer two different questions.

Direct question: Is the bank, transaction, property or service already subject to a binding prohibition, asset freeze, service restriction, reporting duty or licensing requirement?

Secondary question: If no direct prohibition resolves the case, does a specified authority expose a non-domestic person or foreign financial institution to sanctions consequences for the conduct?

This separation prevents two common mistakes: assuming there is no risk because there is no ordinary jurisdictional nexus, and treating secondary risk as if it automatically creates a freeze obligation.

Step 4: check permissions before escalating the risk conclusion

Licences, general licences, exemptions, derogations and statutory exceptions are not afterthoughts. They are part of the legal analysis. A control framework that identifies prohibitions faster than permissions will over-block lawful activity.

The case should identify the permission, its scope, effective dates, conditions, reporting obligations and whether every relevant party and service falls within it. Where a permission covers only part of the activity, the bank should split the transaction or service analysis rather than assume the whole relationship is authorised.

Step 5: build the evidence chronology

Record what the bank knew, when it knew it and what it did next. Include customer disclosures, screening hits, ownership information, payment patterns, trade documents, relationship-manager knowledge, external intelligence, legal advice and previous cases. Where a customer provides inconsistent or incomplete explanations, capture the inconsistency and the follow-up.

Do not label the result “constructive knowledge” unless the applicable legal framework and legal analysis support that terminology. The chronology is the reusable control asset; the legal label is authority-specific.

Step 6: test the evasion hypothesis against alternatives

If activity changes after sanctions developments, ask why. If an intermediary appears, identify its economic role. If payment narratives become shorter, compare the change with business and system reasons. If routing moves through third countries, examine logistics, taxes, supply constraints and ordinary commercial explanations alongside the circumvention hypothesis.

A strong investigation tries to disprove its own theory. Evidence that survives credible alternatives is more useful than a collection of red flags treated as self-proving.

Step 7: make four decisions

Every material case should state separately:

  1. the direct legal disposition;
  2. the secondary-sanctions exposure assessment;
  3. the investigation and reporting outcome; and
  4. the risk-appetite or relationship outcome.

A customer can be outside appetite without being accused of a breach. A transaction can be directly prohibited while the wider relationship remains possible. A suspicious pattern can be reported without implying that every payment was prohibited. Clear decision separation improves both fairness and auditability.

Step 8: translate the decision into executable controls

A policy outcome is not complete until systems and operations can implement it. Conditions might include product restrictions, transaction pre-clearance, corridor blocks, use-of-proceeds covenants, enhanced respondent transparency, customer information deadlines, event-driven review or exit milestones.

Each condition needs an owner, effective date, system location, breach trigger and escalation route. A senior committee approving “conditional continuation” without executable conditions has not actually controlled the exposure.

Step 9: communicate accurately with customers

Where the bank acts because of risk appetite rather than a legal prohibition, customer communication should say so in appropriate terms. It should not falsely state that the customer is sanctioned or that the law requires an exit if that is not the case. Equally, communication should not disclose confidential intelligence, internal thresholds or information whose disclosure is restricted by law.

Customers should have a practical route to provide missing facts or evidence where that can change the assessment. Material decisions should have review or appeal mechanics proportionate to the relationship and local requirements.

Step 10: test the control like an adversary

Testing should include cases where the system must not block. Use authorised humanitarian activity, false-positive network links, legitimate third-country distributors and benign routing changes as negative scenarios. Pair them with evasion scenarios using ownership layering, intermediary chains, stripped narratives, critical goods, alternative financial messaging and rapid restructuring after sanctions changes.

The test is not only whether an alert fires. It is whether the alert reaches the correct legal path, retrieves the right evidence, applies the right authority, recognises permissions, produces the correct operational action and preserves a usable audit trail.

Common failure patterns

One global sanctions rule. A policy or system hard-codes one jurisdiction’s concepts across the group. Remedy: authority-specific rule objects with common evidence and workflow.

Secondary equals prohibited. Operations freezes or rejects activity because secondary risk is high. Remedy: separate direct disposition from secondary-risk outcome.

No nexus equals no risk. Teams close the case because a payment does not touch the sanctioning jurisdiction. Remedy: ask whether a specific secondary authority applies to non-domestic conduct.

Published precedent becomes a threshold. Analysts compare only transaction values with historical designations. Remedy: use the authority’s stated factors and treat public actions as context.

Permissions are discovered late. Lawful medical, agricultural or humanitarian activity is delayed. Remedy: permission logic and reference data sit beside prohibition logic.

Indicators become proof. A third-country route, mixer, AIS gap or shell company is treated as conclusive. Remedy: corroboration and competing-explanation testing.

Policy is described as law. A risk-appetite exit is communicated as mandatory sanctions compliance. Remedy: decision-basis fields and governance discipline.

BA acceptance criteria

A strong implementation should allow a tester to verify that every material case stores the bank entity, applicable authority, effective rule version, direct-nexus conclusion, secondary-authority conclusion, permissions checked, evidence sources, investigation hypothesis, legal outcome, reporting outcome, appetite outcome, approver and timestamp.

The user interface should show those decisions separately. It should not offer a single sanctions outcome drop-down that mixes “blocked by law,” “potential secondary exposure,” “suspicious evasion,” and “outside policy appetite.” Those outcomes have different meanings and different downstream actions.

Rules and data need lineage. If an analyst sees that a customer is linked to a targeted sector, the case should show how that attribution was derived and when it was last verified. If a licence is relied upon, the version and conditions should be recorded. If an external alert or list update triggered review, the source and effective timestamp should be retrievable.

Final practitioner check

Before closing the chapter, ask whether you can explain a case in one sentence without losing the legal distinction: “This bank entity is not directly prohibited from processing the transaction, but this named authority creates potential secondary-sanctions exposure because of these facts; no permission currently resolves the exposure; the investigation found these evasion indicators; and management therefore chose this policy outcome.”

If the organisation cannot produce that sentence from its case data, it is still mixing law, risk and suspicion in a way that will eventually cause either a missed sanctions exposure or unnecessary customer harm.

Masterclass: governing extraterritorial sanctions risk

Secondary-sanctions exposure becomes dangerous when the organisation treats it as a specialist legal issue with no clear business owner. The bank may have excellent lawyers and sanctions analysts yet still drift into unacceptable activity because product teams do not know the appetite boundary, relationship managers do not know when to escalate, systems cannot distinguish legal prohibition from policy restriction, and senior committees see the exposure only after a designation or correspondent challenge.

The governance objective is therefore simple: law determines what the bank must or must not do; management determines what additional exposure the bank is willing to accept; systems and operations must preserve that distinction.

Risk appetite belongs outside the legal prohibition boundary

Risk appetite should never be used to “accept” activity that applicable law prohibits. Direct legal restrictions are hard constraints. Appetite becomes relevant in the discretionary space around secondary exposure, future-designation risk, correspondent sensitivity, opaque customer behaviour and activities that are technically permissible but difficult to control.

A useful appetite framework names the exposures the bank is prepared to consider and the conditions under which it will consider them. It can distinguish ordinary business, enhanced-review business, senior-approval business and policy-prohibited business. Criteria might include specified secondary-sanctions authorities, targeted sectors, foreign-financial-institution exposure, critical goods, respondent transparency, sanctions-sensitive trade corridors, repeated links to designated networks or unresolved evasion indicators.

The framework should state what is policy and what is law. A group may decide, for example, that it will not finance certain sanctions-sensitive sectors even where a particular transaction is permitted. That can be a sensible risk decision, but it should not be encoded in the system as though the sector were legally blocked.

Decision rights

Material secondary-exposure decisions need a deliberate division of responsibility. Legal identifies the applicable authorities, conflicts and permissions. Sanctions compliance interprets policy and control requirements. Business owns the customer and economic rationale. Operations confirms whether the proposed treatment can actually be executed. Financial-crime investigations develop evasion or suspicious-activity evidence. Technology and data teams ensure controls use the right facts. Senior management owns the appetite decision.

A senior committee should receive a decision pack that separates:

  • direct legal obligations;
  • potential secondary-sanctions exposure under named authorities;
  • evidence supporting or weakening an evasion hypothesis;
  • available permissions;
  • customer and product exposure;
  • control options short of exit;
  • operational feasibility;
  • commercial impact; and
  • the requested management decision.

This structure prevents legal advisers from being asked to make commercial appetite decisions and prevents business leaders from treating legal ambiguity as permission to continue indefinitely.

Multinational banks: one group, several laws

A multinational bank cannot solve sanctions differences by declaring that the strictest regime always wins. Group policy can choose a conservative global standard, but that is a policy choice and can itself be constrained by local law, blocking statutes, data-transfer restrictions, contractual obligations or regulatory expectations.

The correct architecture starts with entity-level applicability. Each relevant bank entity maps the laws that bind it. Group compliance then identifies shared minimum controls and areas where entities legitimately diverge. Cross-border cases are escalated when one entity’s legal duty conflicts with another entity’s restrictions or when information needed for a group decision cannot lawfully be transferred.

Decision records should show whether an outcome is driven by local law, another entity’s direct obligations, a group policy, correspondent requirements or a genuine conflict-of-laws decision. That transparency is especially important when a customer receives different treatment from two entities in the same banking group.

Correspondent strategy

Secondary sanctions can threaten access to critical financial infrastructure even before a bank itself is designated. A foreign financial institution that creates concern for a US correspondent may face questions, restrictions or relationship consequences independent of the bank’s own view of the customer activity.

Correspondent strategy therefore belongs in governance. Senior management should understand which clearing and settlement relationships are critical, which sanctions authorities create potential correspondent-account consequences, what information correspondents expect, and how the bank will respond to an inquiry. The objective is not to let correspondents write the bank’s legal policy. It is to recognise that continued access to clearing is a material business dependency with its own risk implications.

Contingency planning should identify alternative arrangements where realistic, but it should not assume that routing through another correspondent solves the underlying issue. Moving a transaction purely to avoid a sanctions restriction or correspondent control can worsen the risk and may become evidence of circumvention or evasion depending on the facts and law.

Designation-wave readiness

A designation wave can convert an appetite-managed exposure into a direct legal problem within minutes. The bank therefore needs a current inventory of material sanctions-sensitive customers and products, an event-response process, rapid access to legal and sanctions specialists, list-update monitoring and operational playbooks for payments, securities, custody, lending, trade finance and correspondent products.

The playbook should answer practical questions. Which payments can still be stopped? Which assets are under the bank’s control? Which products continue to accrue interest or fees? Which legal entities are affected? Are there general licences or wind-down permissions? Which reports are due, to whom and by when? Which customer communications are permitted? How will the bank prevent inconsistent decisions across systems while the assessment is still developing?

Scenario exercises should use realistic portfolio positions rather than abstract examples. A simulation involving one corporate customer with cash accounts, derivatives, securities, a guarantee and payments in flight will reveal more operational weaknesses than a tabletop discussion about a generic “sanctions hit.”

Control assurance

Independent assurance should test both under-compliance and over-compliance. Sampling should include cases where the bank processed activity after concluding that secondary exposure was manageable, cases where it exited for policy reasons, cases relying on licences or exemptions, and cases where suspicious evasion indicators were ultimately cleared.

Reviewers should ask whether the authority was identified correctly, whether the facts supported the conclusion, whether a permission was interpreted within scope, whether decision rights were followed, whether controls implemented the approved outcome and whether the customer was treated consistently with the recorded basis.

A particularly useful test is to compare similar cases across business lines and legal entities. Materially different outcomes may be justified by law or facts, but unexplained divergence often indicates weak policy or inconsistent expertise.

Management information

Alert counts alone say little about secondary-sanctions risk. Better management information includes material cases by authority, customers under conditional continuation, product restrictions, overdue transparency conditions, respondent-bank escalations, exposures dependent on licences, evasion investigations linked to sanctions changes, policy exits, legal-policy divergences, correspondent inquiries and repeated control overrides.

Trend reporting should also show whether risk is moving. A stable number of cases can hide rapidly increasing transaction values or network complexity. Conversely, a spike in alerts can reflect a new rule or better data rather than deteriorating customer behaviour. Senior management needs context, not volume theatre.

Board education

Boards do not need to become sanctions technicians, but they should understand the difference between direct prohibition and secondary exposure, the potential consequences for correspondent access and designation, the role of risk appetite and the limits of published precedents. They should also understand that over-compliance can harm legitimate customers and authorised trade.

Education is most effective when linked to the bank’s own exposures. A short case showing a foreign financial institution, a sanctions-sensitive sector, a general licence and a correspondent-risk decision is more useful than a long presentation listing sanctions programmes. Minutes should show meaningful challenge of appetite, control conditions and unresolved exposure rather than passive receipt of a compliance update.

Model governance and automation

Automation can support this area, but it should not collapse legal judgement into a hidden model score. A model may identify sector proximity, network links, changes in trade routes or transaction concentration. A rules engine may identify that a counterparty falls within a named determination. A workflow may require senior approval when specified conditions are present. But the system should expose the facts and rule version that produced the escalation.

Where machine-learning or graph models influence prioritisation, model governance should cover training data, false positives, explainability, change control and bias toward certain countries or customer types. Sanctions risk is particularly vulnerable to spurious association because networks are dense and legitimate trade often passes through the same hubs as high-risk activity.

Crisis communication

A major designation or sanctions-evasion incident can trigger simultaneous inquiries from customers, regulators, correspondents, auditors, media and internal executives. The bank should coordinate communications without letting communication pressure distort the legal analysis.

Internal messages should distinguish confirmed facts from hypotheses. External statements should avoid accusing customers of wrongdoing before the facts and legal basis are established. Regulatory and correspondent communications should be accurate, timely and consistent with the bank’s investigation record. Customer communications should follow legal restrictions on disclosure and tipping off where relevant.

Lessons learned

Every significant proximity case should feed back into the framework. If a customer reached an unacceptable exposure because sector data was stale, fix sector-data governance. If a respondent hid relevant activity behind nested flows, improve transparency requirements. If a licence was found only after payments were delayed, improve permission reference data. If the same evasion pattern appears across several customers, create a detection scenario or intelligence rule.

The objective is not a growing library of post-incident reports. It is measurable reduction in repeat failure. Each lesson needs an owner, action, deadline and evidence that the control changed.

Final governance principle

The strongest programme is neither the most permissive nor the most restrictive. It is the one that can show, case by case, which law applied, which secondary authority was considered, what evidence the bank had, what permission was checked, what management decided, how the decision was implemented and how the bank learned from the outcome. That is the difference between sanctions anxiety and governed sanctions risk.

Knowledge checks with explained answers

1. A customer's activity is lawful under every directly applicable regime but may fall within a US secondary-sanctions authority. Must the bank exit?

No. The bank first identifies the exact secondary authority, the person and conduct covered, any significance or knowledge criteria, and available permissions. It then assesses the facts and applies its own risk appetite. Management may choose standard monitoring, enhanced conditions, product restriction or managed exit. A policy exit does not mean the customer has violated sanctions law, and potential secondary exposure does not by itself create an automatic asset-freeze obligation.

2. Why must direct-applicability analysis come before secondary-sanctions analysis?

Because direct law can already dictate the operational outcome. A payment that uses a US correspondent, property under a bank entity subject to an asset freeze, or a service provided by an EU or UK entity may create binding obligations that are different from secondary sanctions. Only after the direct legal position is understood should the bank assess authority-specific secondary exposure and discretionary appetite.

3. What is the safest way to assess a “significant transaction” where the authority has no bright-line amount?

Use the authority's published factors and the totality of the facts. For E.O. 14024 section 11, OFAC FAQ 1151 identifies factors including size, number and frequency, nature, management awareness and pattern of conduct, nexus to relevant sanctioned or military-industrial-base persons, deceptive practices and national-security impact. Published designations can provide context, but they are not private safe-harbour thresholds.

4. Can a bank use one global “constructive knowledge” field for facilitation and evasion decisions?

No. Different sanctions laws and authorities use different mental-element formulations. The bank can standardise the evidence chronology: what it knew, when, from which source, what inquiries were made and how facts accumulated. Legal analysis then maps that evidence to the specific authority's knowledge, intent, reasonable-cause or other applicable test.

5. A respondent bank refuses information about nested flows while sanctions-sensitive volumes grow quickly. Does that prove evasion?

No. Opacity is not proof of evasion, but it can make the exposure unmanageable and justify enhanced conditions or a risk-based exit. The bank should record the missing information, why it matters, the respondent's explanations, transaction patterns and any other evidence. If the facts also support a circumvention or evasion hypothesis, that investigation and any reporting decision should be documented separately.

6. What distinguishes direct sanctions obligations from secondary-sanctions consequences?

Direct obligations bind the relevant person, transaction, property or service under applicable law and can require actions such as freezing, rejecting, prohibiting or reporting. Secondary-sanctions authorities can expose non-domestic persons to measures such as designation or restrictions for specified conduct even without the ordinary nexus associated with primary prohibitions. The exact mechanism is authority-specific; the United States is the principal user of this model.

7. A foreign financial institution handles a Russia-related transaction involving a blocked person. Is it automatically sanctionable under E.O. 14024?

Not automatically. The bank must examine the exact section 11 authority, whether the activity falls within Russia's military-industrial base or another covered category, OFAC's significance factors, and any applicable authorisation or exemption. OFAC FAQ 1182 is particularly important because it explains that foreign financial institutions may continue to support activities otherwise authorised or exempted under the relevant Russia sanctions programme.

8. Why are EU and UK circumvention rules not simply “secondary sanctions”?

Because they arise from their own legal frameworks and apply their own jurisdictional, conduct and mental-element tests. Similar behaviour can be relevant across regimes, but the legal mechanism is different. A global bank should use a common fact and workflow model while applying the correct EU, UK, US or other legal rule to each entity and transaction.

9. What should an evasion investigation do with red flags such as shell companies, third-country intermediaries, mixers or unusual shipping routes?

Treat them as hypotheses requiring corroboration. Each can have legitimate explanations. Risk becomes stronger when several independent facts align, timing follows a sanctions change, transparency deteriorates, structures lack commercial logic, or counterparties change while the economic purpose remains constant. Investigators should actively test competing benign explanations before reaching a conclusion.

10. Why should licences and exemptions be part of the first-line decision model?

Because a control that detects restrictions but discovers permissions only after escalation will over-block lawful activity. The case should identify the relevant permission, its scope, effective dates, conditions and reporting requirements at the same time it evaluates the restriction. This is especially important for humanitarian, medical, agricultural and safety-related activity.

11. What four outcomes should a mature case record separate?

The direct legal disposition, the secondary-sanctions exposure assessment, the investigation or reporting outcome, and the bank's risk-appetite or relationship outcome. Keeping these separate prevents “outside appetite” from being recorded as “illegal” and prevents potential secondary exposure from being treated as an automatic freeze.

12. What is the core BA requirement for this topic?

The system must be able to answer: which authority, which bank entity, which person or conduct, which evidence, which permission, which legal outcome, which secondary-risk conclusion, which policy decision and which approver. A single Boolean such as sanctionsRisk=true cannot support that audit trail.

Glossary of working terms

Secondary sanctions: Authority-specific measures, used particularly by the United States, that can expose non-domestic persons to sanctions consequences for defined conduct even where the conduct does not depend on the ordinary domestic nexus associated with primary prohibitions.

Primary or direct sanctions obligation: A binding restriction that applies to the relevant person, property, transaction or service because the legal framework has jurisdiction over it.

Sanctionable activity: Conduct described by a particular secondary-sanctions or designation authority as capable of exposing a person to sanctions measures. The definition must be taken from the authority, not inferred from a generic risk score.

Significant transaction: A term used by some authorities. Under E.O. 14024 section 11, OFAC evaluates significance from the totality of the facts and circumstances using factors described in FAQ 1151 rather than one published monetary threshold.

Facilitation: A term whose legal effect depends on the sanctions programme and jurisdiction. In some US programmes it can describe prohibited US-person assistance to foreign-person transactions; other authorities use separate support, causing, evasion or circumvention concepts. It should not be treated as one universal global rule.

Material assistance or support: A designation concept present in certain sanctions authorities. Whether conduct qualifies depends on the wording and facts of the specific authority.

Circumvention: Conduct structured to get around sanctions restrictions. EU and UK frameworks contain their own anti-circumvention rules; US authorities address evasion and causing as well as programme-specific support and secondary-sanctions conduct.

Evidence chronology: The time-ordered record of what the bank knew, when it knew it, the source, follow-up performed and decision effect. It is preferable to applying a generic “constructive knowledge” label across jurisdictions.

Proximity or secondary-exposure assessment: The bank's structured assessment of how closely activity fits a named sanctionable-activity authority, including stated factors, permissions and uncertainties. It is a risk assessment, not an asset-freeze order.

Risk appetite: Management's decision about exposure the bank is willing to accept beyond minimum legal requirements. Policy can be stricter than law but should be labelled accurately.

Trajectory monitoring: Monitoring of how sanctions-relevant customer, sector, corridor, counterparty or network exposure changes over time, used to trigger review before risk becomes unmanageable.

Foreign financial institution (FFI): A defined term under specific US authorities. E.O. 14024 section 11 and OFAC FAQ 1151 provide a current Russia-related example; definitions should not be assumed to be identical across programmes.

Permission: A general licence, specific licence, exemption, derogation, exception or other legal basis allowing activity that would otherwise be restricted, subject to its terms and conditions.

References and further reading

Secondary-sanctions, facilitation, evasion and circumvention analysis must be tied to the exact authority that applies to the person and conduct. The sources below were used in the 17 September 2026 manual review. They are starting points for professional analysis, not substitutes for the current statutes, executive orders, regulations, determinations, licences and legal advice relevant to a live transaction.

United States: scope, nexus and permissions

United States: foreign financial institutions and Russia-related secondary sanctions

Current 2026 examples of sanctions-evasion and third-country financial risk

  • U.S. Department of the Treasury — Operation Economic Outcast Sanctions Major Bank Helping Iran Evade Sanctions, 14 September 2026. This is a current example of Treasury using sanctions authorities against a financial institution for Iran-related evasion activity and warning foreign financial institutions about continuing relationships: https://home.treasury.gov/news/press-releases/sb0629
  • European Commission — EU adopts 21st package of sanctions against Russia, 23 July 2026. The package includes additional transaction bans involving third-country financial operators and further anti-circumvention measures; these are EU measures under EU law, not an OFAC-style universal secondary-sanctions test: https://finance.ec.europa.eu/news/eu-adopts-21st-package-sanctions-against-russia-2026-07-23_en

Evasion and proliferation-financing typologies

European Union: circumvention and due diligence

United Kingdom: sanctions, circumvention and enforcement

Accuracy note — reviewed 17 September 2026: the chapter deliberately separates direct legal obligations from potential secondary-sanctions consequences, programme-specific facilitation or support concepts, and EU/UK circumvention rules. Secondary-sanctions authorities, determinations, lists, licences and enforcement positions can change quickly. Confirm the current authority and permissions before making a live legal or payment decision.