CIS · Business support

Sanctions Compliance and Verification of Contractors in the CIS

Erich Rath12 min read

Mainstream

Sanctions compliance when working with counterparties from Russia and CIS countries is not a one-time check on lists. It is a system of protection of the whole group against extraterritorial, secondary sanctions and coercive measures.

The main question is not whether the contractor was included in the sanctions lists. The main question is whether the parent company will assume unacceptable risk, which could lead to asset locking, criminal liability or business disruption in a key jurisdiction.

Effective sanctions compliance is based on three checks:

  • Does the contractor, its ultimate beneficiaries, controlling persons and related structures have subsanctions ties?
  • Is the entire supply chain controlled right up to end-use?
  • Is there an early warning system in place to stop the operation before the risk is realized?

If these three tasks are not met, the parent company risks secondary sanctions, losing correspondent accounts, being involved in the investigation or losing its reputation, even if the counterparty was formally in the “green” zone at the time of the inspection.

When there is a need for sanctions compliance and in-depth due diligence

Sanctions compliance and extended verification of counterparties are necessary if the parent company or its subsidiaries:

  • conduct business or plan operations in Russia, Belarus, Kazakhstan or other CIS countries;
  • supply equipment, technologies, dual-use products or components;
  • have counterparties with offshore ownership or a complex corporate structure;
  • interact with companies from the defense, energy, financial or mining sectors;
  • are faced with requests from banks servicing payments on transactions;
  • evaluate an M&A transaction, the establishment of a joint venture or the acquisition of an asset;
  • received a notification from the regulator or a request from the compliance service of the bank;
  • want to insure the group against unintentional violations of sanctions regimes;
  • implement a global compliance program and extend it to subsidiaries;
  • We are faced with the fact that Russian counter-sanctions restrictions make the execution of the contract illegal for the local “daughter”.

The mistake most companies make

Many parent companies start with the question:

Is this counterparty listed on the SDN, SSI or EU Consolidated List?

That's the wrong first question.

The right question is:

“Does interaction with this counterparty and its entire ecosystem pose an unacceptable risk to the parent company and the group as a whole, given the extraterritorial application of sanctions, end-use rules and likely tightening of regimes?”

Sometimes a formally pure counterparty is associated with a sanctioned person through a chain of nominee shareholders. Sometimes civilian products have an end-user. Sometimes the operation is completely legal from the point of view of US law, but violates Russian counter-sanctions decrees, exposing local management to criminal liability. Sometimes the best way to avoid risk is not to conduct a transaction at all, rather than building a complex “layout”.

Sanctions compliance does not require a check check, but a comprehensive assessment, in which lawyers who know several regimes at once participate.

Step 1. Identify applicable sanctions regimes

The first thing to do is not to look at the counterparty, but to understand what sanctions regimes regulate the behavior of the parent company and its subsidiaries.

Key jurisdictions:

  • US (OFAC, SDN, SSI, sectoral sanctions, country restrictions, rule 50%);
  • EU (Council Regulations, own lists, sectoral restrictions)
  • UK (OFSI, autonomous regimes after Brexit)
  • national lists of other countries where shareholders, banks or counterparties are located;
  • counter-sanctions of the Russian Federation and CIS countries (decrees of the President of the Russian Federation, restrictions on transactions with shares, a ban on the execution of “unfriendly” decisions).

The parent company must determine whose sanctions are binding and whose create the risk of secondary sanctions. Often, it is required to follow multiple regimes at the same time, including those where its subsidiary structure is simply located.

Step 2. Make a complete map of counterparties and supply chain

It is necessary to identify all participants in the operation: not only the direct counterparty, but also the final recipient, consignee, buyer for re-export purposes, technical customer, real user of products, payment agents, intermediaries.

We need to prepare:

  • corporate scheme of the counterparty with the beneficiaries;
  • information about the final recipient of the goods or services;
  • a description of the claimed end-use;
  • data on the sources of funding;
  • contracts, specifications, delivery routes;
  • licenses and permits if the products are subject to export control.

Especially dangerous are transactions in which “extra” intermediaries appear without an obvious commercial function. Their only job is often to hide the end user.

Step 3. Conducting in-depth due diligence of the counterparty

Standard checks on automated databases are not enough. We need a thorough due diligence, including:

  • analysis of the chain of ownership with disclosure to an individual;
  • verification of directors, signatories, founders for links with sanctioned persons;
  • study of commercial history, litigation, public tenders;
  • identification of affiliation with organizations of the defense sector;
  • analysis of the geography of supplies and customers of the counterparty;
  • Reputational risk assessment from open and closed sources.

Practice shows that the risk often comes not from the counterparty itself, but from the ultimate beneficiary, who does not formally own the company, but controls it through trusted persons.

Step 4. Reviewing Control and Beneficial Property

Sanctions regimes, especially the US, apply the 50% rule: If one or more sanctioned persons collectively own 50% or more of the company, such company is considered blocked, even if it does not appear on the lists. It is necessary to identify all beneficiaries upstream, including trusts, nominees, offshore funds.

Frequent situation in the CIS: The nominal owner is a management or relative, and the real beneficiary is a person from the sanctions list. This structure must be disclosed before the operation.

Step 5. Check the end user and the purpose of use

Even a fully “clean” counterparty does not protect if the goods, technology or service ultimately arrive at the sanctioned person or are used for prohibited purposes (military, intelligence, projects in the sanctioned territories). It is necessary:

  • obtain and verify the end user certificate;
  • include in the contract the right of inspection and audit;
  • establish an obligation to notify any change in end-use;
  • prohibit re-export without prior written consent.

Particular caution should be exercised when deliveries to Kazakhstan, Kyrgyzstan, Uzbekistan, Armenia, if there is the slightest risk of subsequent resale to Russia in circumvention of restrictions. In this case, the parent company is seen as having created a circumvention scheme, even if the delivery was formally to a "safe" country.

Step 6. Assess the risks of secondary sanctions and extraterritorial action

A parent company incorporated outside the United States may be subject to secondary sanctions for transactions that have no connection to U.S. jurisdiction if they are deemed “significant.” This can lead to disconnection from the dollar system, a ban on working with American counterparties and getting into the SDN list.

Before a transaction, you should consider whether it falls under the criteria of “sanctionable activity”: sectoral transactions with Russian banks, energy projects, supplies of military products, assistance in circumventing sanctions. The assessment should be conducted with the participation of lawyers specializing in extraterritorial risks.

Step 7. Developing sanctions clauses and protection mechanisms in treaties

The best defense is a treaty that initially provides for sanctions scenarios. Each contract with the Russia/CIS element must include:

  • sanctions clause: assurances of absence from the lists and an obligation to notify immediately of inclusion;
  • a termination clause without liability in the case of new sanctions that make the execution illegal or create a risk for the parent company;
  • End-use clause and monitoring right;
  • A clause on the applicable law, taking into account the hierarchy of sanctions regimes (which regime is prioritized for the parties in the event of a conflict);
  • a clause prohibiting performance if it requires a breach of sanctions;
  • the mechanism of suspension of execution for the time of obtaining licenses of the regulator.

Without these provisions, a treaty could become a trap: the contractor will require execution, the refusal of which will be recognized as a violation of the contract in the local court, and the execution – a violation of sanctions with a risk to the parent company.

Step 8. Implement compliance and continuous monitoring procedures

A single Due Diligence becomes obsolete the day after signing. The compliance system should include:

  • primary screening and in-depth testing;
  • regular (quarterly, and for high-risk – monthly) review of the status of key counterparties;
  • automatic triggers when making changes to the sanctions lists;
  • The escalation of the red flags to the level of the compliance officer of the group and the legal committee;
  • mandatory training of employees, especially in regional offices;
  • suspending the transaction until the analysis is completed when new circumstances arise.

It is especially important that subsidiaries in the CIS countries do not have the opportunity to bypass the global compliance policy of the group under pressure from local management.

Step 9. Ensure documentation and audit trail

In the event of an investigation by a regulator, the parent company must prove that it has taken all reasonable steps to prevent the infringement. This means that every transaction decision must be documented:

  • Protocol of verification of the counterparty and beneficiaries;
  • conclusion of lawyers on sanctions risks;
  • End user report;
  • correspondence with the counterparty about assurances;
  • the decision of the compliance committee;
  • Staff training records.

The absence of documents is often interpreted as the absence of a control system, which has more severe consequences.

Step 10. Develop an action plan in case of detection of a violation

Even with an ideal system, the risk can be realized: The counterparty will be on the lists, the payment will be blocked, the bank will request explanations. The parent company should have a ready-made scenario:

  • immediate suspension of operations and communication with the counterparty;
  • Notification of internal compliance and external lawyers;
  • analysis of the need for voluntary disclosure of information to the regulator (self-disclosure);
  • apply for a license, if permitted;
  • Management of reputational consequences;
  • Assessment of force majeure effects on all related contracts;
  • Communication with banks and auditors.

The faster and more professional the company works, the higher the chance to minimize damage.

Base screening or in-depth Due Diligence: pick

CriteriaScreening for sanctions listsDeep Due Diligence
CostBelow.Higher.
CoverageJust direct coincidences.Beneficiaries, end-users, communications
ApplicabilityFor standard low-risk counterpartiesFor high-risk jurisdictions and critical transactions
Discovering Hidden LinksMinimumHigh, with proper execution
Protection from secondary sanctionsInsufficientIt is a basic element of protection
Documentary justificationLimited.Full audit trail

The choice does not depend on the overall strategy, but on the specific counterparty risk profile, country, type of product and transaction amount. Basic screening is not enough for most operations in the Russia/CIS region.

How to strengthen the position of the parent company before the transaction

The best risk minimization begins at the stage of building a compliance architecture.

The parent company is desirable:

  • adopt and extend to all subsidiaries a single sanctions policy of the group;
  • to establish in it the obligation of in-depth Due Diligence for transactions with the CIS region;
  • to include in treaties model sanctions clauses approved by international jurists;
  • centralize decision-making on high-risk transactions;
  • develop a procedure for interaction with banks exercising currency control;
  • provide double legal verification: from the position of the parent company’s sanctions regimes and from the position of local bans in Russia or the CIS;
  • provide for insurance or transaction structuring mechanisms that reduce sanctions risks, but in strict accordance with the law.

Politics should be lively: Revise each new package of sanctions.

Common mistakes in sanctions compliance

  1. Check only the direct counterparty. The risk is almost always deeper, in the end recipient or beneficiary.
  2. Rely on assurances without verification. A signed end-user certificate does not replace reasonable verification if there are red flags.
  3. Ignore Russian counter-sanctions. Fulfillment of Western sanctions requirements may violate local law and lead to personal liability of the directors of the local subsidiary.
  4. Do not update due diligence. Yesterday’s net counterparty can be included on the SDN list today.
  5. Cutting contracts and deliveries. Actions aimed at circumventing sanctions through the dividing of amounts or the use of intermediaries increase, rather than reduce, risk, being regarded as a deliberate scheme.
  6. Not training staff in the region. Local management may miss red flags simply because they don’t understand the logic of extraterritorial application.
  7. Consider sanctions compliance as a cost. For the parent company, it is an investment in the survival of a global business.
  8. Save money on legal expertise. The cost of consultation is not comparable to the losses from the freezing of assets or inclusion in the SDN.

Checklist of the parent company

Before a transaction with a contractor from Russia or the CIS, you must answer 15 questions:

  1. Who is the contractor and who is behind it?
  2. Who is the ultimate beneficiary – a natural person?
  3. Are there any people on the sanctions list?
  4. Does the 50% rule apply?
  5. What are the stated and actual end-use goals?
  6. Is the contractor related to the defense sector?
  7. Are products on the list of dual-use goods?
  8. Which jurisdictions will the payment and delivery go through?
  9. Will the deal violate Russian counter-sanctions decrees?
  10. What sanctions are required for the parent company?
  11. Is there a risk of secondary sanctions?
  12. What sanctions clauses are included in the treaty?
  13. Are there enough documents to protect the regulator?
  14. Has the permanent monitoring mechanism been launched?
  15. If the contractor is placed on the SDN list tomorrow, what will be the procedure for exiting the transaction?

What a strong sanctions compliance system looks like

A strong system usually includes five levels:

1. Legal & Regulatory Intelligence Map of all applicable sanctions regimes, jurisdictional analysis, control of extraterritoriality.

2. Risk-Based Due Diligence Automated Screening plus In-depth Verification for High-Risk Operations, including End Users.

3. Contractual Protection Sanctions, export-control clauses, right to termination and suspension, end-use audit.

4. Monitoring & Internal Controls Periodic review of the status of counterparties, compliance training, escalation, audit.

5. Incident Response & Crisis Management Plan for the event of new sanctions or violations, licensing, protection of the group’s assets.

Without a fifth level, the whole system could collapse in a crisis.

FAQ

Can a parent company legally work with companies from Russia and the CIS?

Yes, unless the contractors are sanctioned, the transaction is not subject to restrictions, does not pose a risk of secondary sanctions and local laws are complied with. Each case requires individual analysis.

What if the contractor was sanctioned after signing the contract?

Immediately suspend execution, contact lawyers, assess the possibility of obtaining a license to wind down operations, notify the bank and apply a contractual sanctions clause for withdrawal without loss.

Should the Russian subsidiary comply with US sanctions against its founder?

The Russian company is not legally bound by foreign sanctions, but its actions could create a risk of secondary sanctions for the parent. Russia also has a counter-sanctions mechanism that can prohibit the execution of decisions based on foreign sanctions. A balance is required, verified by lawyers.

Is automatic verification of OFAC sufficient?

Nope. Automatic screening does not reveal hidden links, end recipients and does not allow to assess the risk of secondary sanctions. It is only the first filter that should be followed by professional analysis.

How to check the end user in the CIS?

Request an end-user certificate, verify it through an independent Due Diligence, include the right to audit and monitor in the contract, analyze the company’s public profiles. The lack of willingness to provide transparent information is a red flag.

What threatens the parent company for violating the sanctions regime?

Fines, criminal liability for officials, loss of access to the US and EU financial system, inclusion in sanctions lists, reputational damage, forced sale of assets, destruction of global business.

Can a compliance review protect against accusations?

Yeah. A documented system, good faith in-depth analysis, and immediate voluntary disclosure when a breach is detected are often seen as mitigating factors and can reduce liability.

Which deals are considered the most risky?

Related to the military-industrial complex, the energy sector, the supply of dual-use technologies, transactions involving intermediaries without an explicit commercial role, payments bypassing conventional banking channels.

Related services

  • Sanctions, Export Controls & International Compliance
  • Corporate Investigations, Regulatory Investigations & Business Integrity
  • International Trade, Distribution & Cross-Border Transactions
  • International Regulatory Risk & Strategic Advisory
  • Commercial Contracts
  • Cross-Border M&A and Joint Ventures

Related material

  • How to Build a Global Compliance Sanctions Program for a Group of Companies
  • Russia & CIS: Practical aspects of circumvention of sanctions and its consequences
  • Russian counter-sanctions: Risks to foreign business
  • Export controls and dual-use goods in the CIS region
  • How to check the ultimate beneficiary in a transaction with a Russian asset
  • Sanctions clauses in international contracts: drafting guide
  • Self-disclosure: When and how to voluntarily report a breach to the regulator
  • Parallel import and sanction compliance: What You Need to Know About the Parent Company

Conclusion

Sanctions compliance and Due Diligence of counterparties in Russia and the CIS is not a function of “refusal of the transaction”, but a strategy for preserving the business of the parent company.

A strong position is based on knowledge of all applicable regimes, disclosure of real beneficiaries and end users, contractual protection, constant monitoring and readiness to act immediately when risk occurs.

In today’s sanctions world, the winner is not the one who has conducted surface screening, but the one who has built a system in advance that allows you to safely continue operations in difficult markets or to leave them in a timely manner and without catastrophic losses.

Have a question about the topic of this article?

Write to us and we will respond within one business day.