For many operators entering regulated markets for the first time, sanctions screening and politically exposed person checks can feel like abstract compliance obligations. In practice, they are two of the most operationally consequential requirements your team will face, carrying direct legal exposure and reputational risk if handled poorly. This guide explains what each concept means, why regulators demand them, and how to set up a screening workflow that holds up under scrutiny.
What Is Sanctions Screening?
A sanctions list is a register of individuals, companies, vessels and jurisdictions that governments or intergovernmental bodies have prohibited others from doing business with. The most relevant lists for iGaming operators are published by the United Nations Security Council, the European Union, the UK Office of Financial Sanctions Implementation (OFSI), and the US Office of Foreign Assets Control (OFAC). Being found to have processed deposits or withdrawals for a sanctioned party, even unknowingly, can result in substantial fines and licence revocation.
Sanctions screening is the process of checking your customer data, including full name, date of birth, nationality and address, against these lists before onboarding and on an ongoing basis throughout the relationship. A match, often called a hit or an alert, requires manual review to determine whether it is a true match or a false positive caused by similar names.
What Is a Politically Exposed Person?
A politically exposed person, universally abbreviated to PEP, is an individual who holds or has recently held a prominent public function. Standard categories include heads of state, senior politicians, senior government officials, senior military officers, senior executives of state-owned enterprises, and senior officials of international organisations. The Financial Action Task Force, whose recommendations underpin most national AML frameworks, defines PEPs as higher-risk customers because their position creates opportunities for bribery, corruption and misuse of public funds.
Two additional categories extend the concept further: relatives of PEPs and close associates of PEPs, frequently referred to as RCAs. These individuals may indirectly benefit from or facilitate corrupt activity, so most licensing regimes require operators to screen for them alongside direct PEPs.
Why the Two Checks Are Different
Sanctions screening is binary and urgent. If a customer is on a sanctions list, you must not provide services and you are generally obligated to freeze any funds and report to the relevant authority. There is no discretion involved. PEP screening, by contrast, triggers enhanced due diligence rather than an automatic block. A PEP can be a legitimate customer; the operator simply needs to understand the source of their wealth, apply greater scrutiny to transactions and obtain senior management approval before or shortly after establishing the relationship.
Building a Practical Screening Workflow
Step 1: Choose a Data Provider
Manual checks against government websites are not scalable. Most operators use a commercial screening provider that aggregates and continuously updates sanctions lists and PEP data from multiple sources. When evaluating providers, look for coverage of the jurisdictions where your players are located, clear update frequency commitments, and an API that integrates with your KYC platform.
Step 2: Screen at Registration and on Trigger Events
Initial screening should occur before or immediately at the point of account creation. Ongoing screening must capture changes in status; a customer who was clean at registration can appear on a sanctions list the following week. Best practice is to run continuous or daily batch screening against your full active customer database and to re-screen on specific trigger events such as a change of name, address or nationality.
Step 3: Manage Alerts Systematically
- Log every alert with a timestamp, the list matched and the analyst who reviewed it.
- Document your reasoning for every true-positive and false-positive decision.
- Escalate true sanctions matches to your MLRO immediately; do not tip off the customer.
- For PEP matches, open an enhanced due diligence file and assign a review deadline.
Step 4: Train Your Team
Screening tools only work if the people operating them understand what they are looking at. Front-line KYC staff should be able to distinguish between a sanctions hit and a PEP alert, know the escalation path for each and understand why false positives still require documented decisions.
A screening programme is only as strong as the governance around it. Documented decisions, clear escalation paths and regular audits are what regulators look for when they review your AML framework.
Common Operator Mistakes to Avoid
- Screening only at onboarding and not on an ongoing basis.
- Treating all PEP alerts as automatic declines rather than triggers for enhanced due diligence.
- Using free or infrequently updated list sources that miss recent designations.
- Failing to screen existing customers when a new sanctions list is published.
- Not documenting false-positive decisions, leaving audit trails incomplete.
How OnlineShine Approaches This
At OnlineShine, we implement sanctions and PEP screening as part of an integrated AML and MLRO managed service, meaning operators benefit from daily screening runs, structured alert management protocols and audit-ready documentation without having to build those capabilities in-house. For operators in the early stages of building their compliance function, getting the screening infrastructure right from day one avoids costly remediation later.



