Wait, don't go!

Sign up to our newsletter to be the first to know about new developments at Diligex!

    Name

    Surname

    Email

    I consent to Diligex storing my personal data provided for the sole purpose of responding to my enquiry and administering my request.


    ×
    Call the incident response team of our strategic cybersecurity partner, Thomas Murray, on the emergency 24/7 UK line +44 (0) 2074594888, for immediate help from their experts.

    Implementing Article 32: Sanctions Compliance Requirements

     

    The Sanctions Monitoring Board (SMB) has published its guidance on the implementation of Article 32 of the National Interest (Enabling Powers) Act, following the consultation process held earlier this year. The guidance is available here: Implementing Article 32: Sanctions Compliance Requirements – SMB

    In the SMB’s own words, the guidance sets out its expectations regarding sanctions governance, risk assessments, screening measures, escalation procedures, record keeping and reporting obligations. As the Board notes, sanctions compliance is not a one-size-fits-all exercise — controls are expected to be risk-based, proportionate, documented and effective, and operators should regularly assess whether their policies and procedures remain aligned with the nature, size and risk profile of their business.

    A number of points are worth noting:

    • The guidance confirms that “should” reflects the SMB’s minimum expectations for operators, and that failure to implement such measures may support enforcement action (administrative penalties under Article 35) for breaches of Article 32.
    • Sanctions Risk Assessment: this must be carried out on an enterprise-wide basis, covering all relevant activity lines within a single entity-level assessment. Operators may integrate sanctions risk into an existing ML/FT risk assessment or keep it standalone, provided it is properly documented, proportionate and capable of producing consistent results. The assessment must be approved at the level holding ultimate business responsibility (senior management or the Board), and while no fixed review frequency is prescribed, operators must be able to justify and document the frequency they adopt.
    • Enhanced Due Diligence is now a standalone requirement, with defined triggers for when extra scrutiny is expected.
    • Ownership below 50%: where an operator identifies a designated person holding less than 50% and has not screened the full ownership structure, it must proceed to screen all persons within the structure to determine whether designated persons collectively meet the 50% threshold. If aggregate ownership remains below 50%, the client may be serviced subject to:
      • a board resolution confirming no funds/economic resources will be made available to designated persons; and
      • notification to the SMB.
    • Data protection/GDPR obligations have been added as a dedicated section covering how sanctions-related personal data must be handled and retained.
    • CDD/screening must be completed before delivery of goods or services, not merely before invoicing, for occasional transaction customers offered payment terms.
    • New requirements apply to frozen funds: any accrued interest/dividends must sit in a separate frozen account, any payment out of a frozen account now needs SMB authorisation, and the SMB must be told immediately if frozen-fund customers are involved in an acquisition, transfer or closure of a business.
    • The rules on client communications during a sanctions assessment have been clarified — CDD/EDD information can still be requested from a client, provided the fact that sanctions concerns are under consideration is not disclosed.
    • Operators relying on or outsourcing to third parties must ensure those parties notify them of any non-compliance findings or criminal proceedings, and undertake ongoing sanctions training.
    • A new route to appeal administrative penalties before a Tribunal, as an alternative to the Court of Appeal, has also been added.

    Please don’t hesitate to reach out if you’d like to discuss any of this in the context of your own framework.

     

     

    For further information, advisory support and tooling contact us at Diligex on [email protected] for assistance.