top of page

How Sanctions and Payment Screening Change When You Enter a New Market

  • Writer: FinScan
    FinScan
  • 9 hours ago
  • 7 min read

Sanctions, payment, and KYC screening obligations often shift when a PSP, fintech, or MSB enters a new country or takes on a new license.


Sanctions and Payment Screening Changes When Entering New Markets



Entering a new country or securing a new payments or banking license can change an organization's sanctions and payment screening obligations. If compliance is brought in after the commercial plan is set, the screening implications can surface late, sometimes only when a regulator or sponsor bank starts asking questions. For a payment service provider, fintech, or money services business, that creates two unique challenges. The screening has to work properly on day one in the new market, and the firm must show a regulator, or a sponsor or correspondent bank, that the program is in place before it can operate there.



Does entering a new country change your sanctions screening obligations?


Yes, it often does. Entering a new country can change which sanctions lists a company must screen against, how those lists reach it, and what its new regulator expects to see.


Which sanctions regimes apply are driven less by where it is based and more by what it touches. Screening against the U.S. Office of Foreign Assets Control (OFAC) lists applies to anyone clearing or settling in U.S. dollars or dealing with U.S. citizens and permanent resident aliens regardless of location. Exposure to European Union or United Kingdom (OFSI) designations follows from euro or sterling activity, or from EU and UK customers and counterparties. The United Nations consolidated list sits underneath most national regimes, because member states implement UN designations into local law. A firm entering a new country usually picks up a local currency, local customers, and correspondent or sponsor banks that carry their own screening expectations.



Not every country maintains its own autonomous sanctions list. Some publish national designations on top of the UN baseline, while others rely largely on UN and partner-country lists. The local regulator will still have a view on which lists a firm should cover, how current they have to be kept, and how quickly a new designation has to be actioned. Some of a company's list coverage is therefore obligatory, set by the regimes it is exposed to, and some is a documented risk decision it has to be able to defend to a supervisor. 


Part of that coverage is not negotiable at all. FATF Recommendation 6 requires countries to apply targeted financial sanctions related to terrorism, and Recommendation 7 requires the same for proliferation financing connected to weapons of mass destruction. Both are rule-based rather than risk-based, so the designations they cover must be applied in full rather than sampled according to appetite. Countries write these obligations into national law, which is how they reach the company. Terrorism or proliferation designations are never low enough risk to skip.


What does a new payments or banking license require for AML screening?


A license application almost always requires the firm to submit an AML and counter-terrorist-financing program, and the screening design inside it becomes a commitment the regulator can examine after launch.


The program sets out which lists get screened, how often existing customers are rescreened, how the firm resolves beneficial ownership, and how alerts are reviewed and closed. After the license is granted, a supervisor can hold the firm to those specifics. Early reviews usually probe whether the program runs the way the application described it. Organizations that document screening they have built, at a scope they can sustain, tend to fare better than those that describe an ideal-state program they have not finished building.


How does joining new payment rails affect payment screening?


New rails and correspondent relationships bring new payment message formats, and the format decides what a screening engine can read from a transaction. The shift to ISO 20022 has changed that considerably, though local schemes a company joins in a new market may use their own formats alongside it.


The coexistence period for cross-border payment instructions on the Swift network ended on 22 November 2025, and legacy MT payment instructions between financial institutions are now rejected rather than delivered. Further milestones fall in November 2026, including the retirement of unstructured postal addresses in favor of structured or hybrid formats, and the migration of MT101 initiation messages to the pain.001 format.



Structured party and address data gives a screening engine far more to work with than the old free-text fields did. When the data is complete and mapped to the right fields, matching improves, because names, addresses, and identifiers get compared on a like-for-like basis instead of being pulled out of a single block of text. Sparse or inconsistently mapped data produces false positives in some cases and missed hits in others.


Richer data is available in principle during the current transition, but it is not guaranteed in practice. Counterparties populate the structured fields to different standards, and some still send close to the minimum. A company joining a new corridor cannot assume the incoming data is clean, so its screening has to hold up against whatever a counterparty sends.


What changes in KYC and onboarding screening in a new market?


Onboarding screening is only as good as the customer data behind the name, and a new market introduces names, identifiers, and ownership structures the existing configurations may not handle well.


A new jurisdiction brings names in scripts the current setup may not process cleanly, transliteration variance, local identifier formats, and beneficial ownership recorded in registries the organization has not worked with before. The definition of a politically exposed person differs by country, so who a company must flag as PEPs shifts as their footprint grows.


Additionally, name-matching logic tuned for one language or naming convention performs unevenly against another. Matching that works well on Latin-script Western names can miss true matches and throw extra false positives when it meets Arabic, Chinese, Cyrillic, or other conventions, where transliteration, name order, and the frequency of common names all behave differently. Stronger matching settings help, but they cannot compensate for incomplete or poorly structured underlying data.


Does adverse media screening need to change for a new region?


Yes. Adverse media screening (also known as negative news) results reflect company subscription sources and the languages those sources publish in, and both change by region.


Coverage that is reliable in one region is not automatically reliable in another, and relevant reporting in a new market often appears in a local language before it reaches English-language sources. Compliance teams expanding into a new jurisdiction should confirm that its adverse media feeds reach that market, and the languages spoken there, before treating the results as a basis for onboarding or risk decisions.


Why do screening alert volumes rise after expansion?


Alert volumes climb with every new market expansion for two reasons: Customer base growth and thresholds tuned for one population that rarely fit another.


Match-string settings that historically produced a manageable alert rate can flood a queue in a new market or, perhaps more alarmingly, quietly miss matches the local risk profile should catch. Without a tuning plan and conditional rules, the backlog builds, and a buried true match is exactly what a regulator asks about later. Configuration and analyst headcount are worth settling before launch, while the queue is still hypothetical.


What to confirm before launch


The firms that scope and tune screening before the first customers and payments arrive spend less time explaining gaps to a regulator later.

A few questions are worth answering before the launch date is locked:

  • Which sanctions lists and watchlists does the new market require, and does current coverage already include them?

  • Is an AML program required? Does the AML program filed with the regulator match what will run in production on day one?

  • Do the payment rails in scope use ISO 20022 formats, and is screening configured to read structured data?

  • Can onboarding screening handle local names, scripts, identifiers, and beneficial ownership sources?

  • Does adverse media coverage reach the new market and the languages spoken there?

  • Has alert tuning been reviewed for the new customer base, with capacity to work the volume it produces?


Answering these questions now is far cheaper than answering them under examination, or missed match. The firms that scope and tune screening before the first customers and payments arrive spend less time explaining gaps to a regulator later.


FAQ


Usually, yes. A new country can add local designations to the UN and partner-country lists you already cover, and it changes which regimes you are exposed to through local currency, customers, and counterparties. Your regulator will also have expectations about which lists you screen and how current you keep them.

In most jurisdictions, yes. The AML and counter-terrorist-financing program filed with a license application usually specifies the screening design, and that design becomes examinable once the license is granted.

It gives screening engines richer, more structured party and address data. Clean, well-mapped data sharpens matching, while sparse or inconsistent data can cause both false positives and missed matches. During the current transition, a firm cannot assume counterparties will always send complete structured data.

Reusing matching thresholds set for the home market. Alert volumes and name profiles differ from one country to the next, so untuned settings tend to create backlog or miss local risks.


Sources

  • Financial Action Task Force, The FATF Recommendations (Recommendation 6 on targeted financial sanctions related to terrorism and terrorist financing; Recommendation 7 on proliferation financing). fatf-gafi.org

  • Financial Action Task Force, update to Recommendation 6, June 2026 (humanitarian exemptions under UNSCRs 2664, 2761, and 2615). fatf-gafi.org

  • Swift, ISO 20022 for Financial Institutions (end of the cross-border coexistence period on 22 November 2025). swift.com

  • J.P. Morgan, ISO 20022 Migration: Guidance, Messaging & More (November 2026 milestones: end of unstructured addresses, MT101 to pain.001v9 migration). jpmorgan.com

bottom of page