In this article I'll give you a quick overview of the concept of international sanctions, how they work and how it may impact a FinTech company, especially from the standpoint of technical implementation and tools.
There are so many conspiracy theories, wrong interpretations, and misconceptions about sanctions and sanctions scanning. People sometimes get totally overwhelmed and feel like sanctions and embargoes are even more stressful than GDPR or Brexit.
So, where do international sanctions come from?
Sanctions can be imposed by individual countries or international organizations and, simply speaking, there are 4 types of sanctions:
  1. Against a country or territory (e.g. North Korea or Crimea). These sanctions are extremely rare because territorial sanctions usually impact a lot of innocent people who happen to live or be in that place. Territorial sanctions mean that you cannot offer your services on that territory at all. For example, your perfectly valid Visa card may not work in Crimea.
  2. Against specific individuals, sometimes called "Specially Designated Nationals" or "SDNs." Usually, those people are criminals, known members of terrorist organizations and politicians responsible for civil wars, human rights violations, and other international crimes.
  3. Against members of certain groups or organizations. For example, there are specific sanctions against members of Hamas or the Taliban, regardless of their residence or nationality. There are specific sanctions against members of certain governments or governmental organizations (for example, against certain government officials in Venezuela or members of the Iranian Revolutionary Guards). This category of sanctions does not always specify the names of individuals (because people may join these groups at any time), but rather they say that any member of this group or organization is under sanctions, and therefore you cannot offer your financial services to them.
  4. Against certain industries or types of commercial activities. For example, you cannot buy Iranian or Venezuelan oil, you cannot buy or sell arms with governments of certain African countries, you cannot export certain products to or from Russia, etc. 
Why is this important?
People often say “Iran is under sanctions” or “Russia is under sanctions” or “Venezuela is under sanctions” and it’s not correct. 
From the technical implementation standpoint, it sometimes makes a huge difference: either you block an entire country and cannot serve anyone there, or you find a way to detect and block a couple of dozens of people and can work with everyone else without breaking any laws.
On the other hand – the consequences of even a single mistake can be huge, especially if those are OFAC (US) sanctions.
"Fun" facts: there are some contradictory and mutually exclusive sets of sanctions, which can make the life of a compliance officer super interesting. The most common examples would be Cuba (the US still has sanctions against most activities in Cuba, but Europe has nothing against Cuba whatsoever) and Russia vs Ukraine (where both countries claim that the other side is an occupant and international criminal).
How do you go about the technical implementation of sanctions compliance to keep it simple and reasonable?
Usually, I recommend to implement the following basic rules (obviously those are a very general set of guiding principles, just for an illustration purpose):
Hope this summary was helpful. If you have any questions - feel free to reach out. You can find my contact details on my company website.