Sanctions compliance and monitoring
1) Objectives and frame
Sanctions compliance prevents the provision of services to individuals/countries from sanctions regimes and reduces the risks of blocking payments, domains, hosting and licenses. In iGaming, this covers players (B2C), partners and providers (B2B), affiliates, payment chains, crypto-on/off-ramp and traffic.
2) Sources of sanctions requirements
International lists: UN, EU, OFAC (SDN/SSI), UK HMT, Canada, Australia, etc.
Ownership/control rules: prohibition on servicing companies controlled (usually ≥50% in total) by a person from the list.
Sectoral/embargoes: total ban or limited services by industry/jurisdiction.
Export control: cryptography/software, technical data transfer and access to services.
3) Governorship and roles
Board/Risk Committee: approves sanctions policy, risk appetite, exceptions (if allowed by law).
Sanctions Officer/MLRO: owner of procedures, lists and reporting; manages incidents.
Compliance Ops: screening/rescreening, match analysis, escalation.
Security/Data/Infra: geo-block, anti-VPN/Tor, logging; vendor API integration.
Procurement/Legal: DD of third parties (PSP, KYC-vendors, affiliates), inclusion of clauses in contracts.
4) Coverage areas and screening facilities
1. Customers/players (B2C) - KYC data, payment instruments, devices, IP/geo.
2. B2B counterparties - legal entities, UBO/directors, ownership chains (50% +), affiliates/agency networks.
3. Payments - sender/recipient, correspondent banks, purpose, MCC/country of origin.
4. Content/infra - hosting/CDN/registrars/vendors, export of cryptography.
5. Crypto - addresses/exchanges, risk tags (mixers, high-risk exchanges), transfer chains.
5) Screening and Rescreening Process
Onboarding: full-text name/company + date of birth/country; fuzzy logic, normalization of transliterations.
Continuous rescreening: daily for active B2Cs, daily/weekly for B2Bs and payees.
Re-screening triggers: change of document/address/device, new payment instrument, significant activity, change of UBO in B2B.
Sensitivity calibration: different thresholds for frequent names/languages, "watchlist only" mode for Adverse Media.
Data quality: standard fields (full name in Latin/Cyrillic, DOB, citizenship), homonym control.
6) Geo-contour and deanonymization
Geo-block: country/region block lists; prohibition of registration and access; keep evidence (logs).
IP control: ASN categorization, VPN/Tor/proxy detection, geovelosity.
Devices: Device-fingerprint, prohibition of "common" devices and re-onboarding from block geo.
Payment methods: card/wallet block from Sank Geo; additional checks for A2A/crypto.
Content and languages: Avoid "targeting signals" (local currency, payment methods, locale) for prohibited geo.
7) Payments and banks
Payment screening: recipient's name, bank, BIC/IBAN masks, correspondent account route; bans on sunk geo.
PSPs: sanctions/export obligations, suspension rights, reporting SLAs, step-in and alternative corridors.
Hold/Reject logic: Automatically hold doubtful transfers until verified.
8) Crypto risks (on/off-ramp)
Checking addresses/counterparties: exchanges, mixers, high-risk wallets, sank tags.
SoF policy (source of funds) for crypto; limits, whitelist to addresses.
Incidents: block/report, no re-deposit, SAR/STR on reasonable suspicion.
9) Work with third parties
SUS/Sank Vendors: SLA list coverage and update latency, accuracy, log audit.
Affiliates/agencies: sanctions clauses; blocking traffic from block geo; evidence for geo-targeting.
Hosting/CDN/registrars: checking jurisdictions, right to fast "traffic migration."
10) Export controls
Assessment of export restrictions on software/encryption and remote access; prohibition of the provision of services to sanctioned persons/countries; user registers by geo.
11) Incident management and reporting
Play/Stop/Report: temporary account/payment lock → manual check → MLRO escalation → report (if required) → final decision.
Tipping-off: prohibition to disclose to the client the fact of a sank check/report.
Logging: who/when made the decision, sources, screenshots, hashes of artifacts.
Timing: internal SLAs (e.g. P1 ≤ 24 h), storage 5 + years (to be specified locally).
12) Risk Matrix (RAG)
13) Checklists
Before Launch/Market Entry
- Sanctions policy (list sources, 50% + rule, export).
- Geo-contour: block lists, anti-VPN/Tor, log evidence.
- Vendors: SLA list updates, accuracy, redundancy.
- PSP/banks: sanitary clauses, step-in, alternatives.
- Incident procedures (P1/P2), training, roles.
Operational cycle (daily/weekly)
- Rescreening of active B2C/B2B.
- Check new payment channels/instruments.
- Anti-VPN/Tor monitoring; reports on geovelosity.
- Crypto addresses: updating labels, whitelist review.
- QA sampling of "false matches."
Quarterly
- Audit list covers and latency.
- Recovery test (vendor down/bank block).
- Updating contractual clauses and playbooks.
14) Contractual clause templates (fragments)
A. Sanctions and exports
B. Ownership and Control
C. Geo-targeting and affiliates
D. Payments
15) Recommended registries (YAML)
15. 1 Sank Policy Profile
yaml policy_id: "SAN-PLCY-2025-01"
lists: ["UN","EU","OFAC_SDN","OFAC_SSI","UK_HMT","CA","AU"]
ownership_rule: ">=50% aggregate"
rescreening:
b2c_active: "daily"
b2b_active: "daily"
payouts: "pre-disbursement"
geo_block:
blocked_countries: ["..."]
vpn_tor_block: true crypto:
address_risk_vendor: "ChainIntelX"
mixers_block: true psp:
sanction_clauses: true step_in: true owner: "Sanctions Officer"
15. 2 Log of matches/decisions
yaml hit_id: "HIT-2025-2117"
subject:
type: "person"
name: "Ivan Petrov"
dob: "1984-07-10"
match:
list: "OFAC_SDN"
score: 91 fields: ["name","dob","country"]
decision: "false_positive"
analyst: "m. ivanova"
qa_by: "san. officer"
closed_at: "2025-11-05T17:10Z"
evidence: ["passport_scan. png","watchlist_export. pdf"]
15. 3 Geo-loop/anti-VPN
yaml geo_control:
blocked_countries: ["IR","KP","SY","CU","RU","BY", "..."]
tor_exit_nodes_block: true vpn_providers_block: true geovelocity_threshold:
km_per_min: 200 action: "challenge+hold"
15. 4 B2B and UBO rescreening
yaml b2b_entity: "AffNet Media Ltd"
ubos:
- name: "John Doe"
ownership: 40
- name: "Jane Roe"
ownership: 60 last_rescreened: "2025-11-05"
status: "clear"
notes: "ownership change 2025-10-28 verified"
16) Playbooks (operational scenarios)
P-SAN-01: Onboarding list match
Auto-hit → check DOB/address/sources → upon confirmation - denial of service, preservation of evidence → registry/notification (if required).
P-SAN-02: Payment via Sank Route
Hold → checking correspondent bank/BIC → requesting alternative corridor → if not possible - refund → report to PSP.
P-SAN-03: Geo-traversal (VPN/Tor)
Autoblock session → KYC challenge → with confirmed bypass - closing, cancellation of bonuses, entry into the registry, notification of the affiliate, if any.
P-SAN-04: Crypto with mixer label
Deposit freeze → chain analysis → SoF request → MLRO escalation → possible SAR/STR and block.
P-SAN-05: Partner UBO change
Rescreen trigger → update of the → ownership tree with a flag - suspension of services, request for documents, legal assessment → board decision.
17) KPIs and Reporting
Rescreening Coverage% (B2C/B2B/payments).
Average Sanctions TAT по P1/P2.
False Positive Rate/Precision @ Top-N by coincidence.
Geo Evasion Block% (share of blocked VPN/Tor attempts).
Vendor SLA Compliance% (list updates/availability).
PSP Route Incidents/month and average block bypass time.
18) Mini-FAQ
Is it enough to block only SDN? No: consider ownership/control rules and sectoral lists.
Do I need to screen affiliates? Yes, as well as their sub-networks; blocking traffic from block geo is mandatory.
How to deal with false matches? QA sampling, threshold calibration, clear evidence packets, and DOB/address field control.
Is VPN access allowed? For Sank Geo, No; in general, use a risk approach with challenges.
19) Disclaimer
Sanctions regimes are dynamic and jurisdictionally different. The present material is an operational framework; specific prohibitions and reporting formats should be checked with local law and consultants.
20) Conclusion
Sanction compliance is the architecture of processes: policies and roles, continuous screening, rigid geo-contour, proven vendors and clear incident playbooks. Standardize registries and KPIs - and sanctions risks will become manageable, and access to the payment and infrastructure ecosystem predictable.