Due Diligence of Contractors: How to reduce sanctions risks

Due Diligence of Contractors: How to reduce regulatory risks: a business protection system in the era of EU sanctions and export controls
Mainstream
Due diligence of counterparties in the conditions of EU sanctions is not a questionnaire that the client fills out. It is a continuous monitoring process that allows businesses to survive.
The main question is not whether the contractor was included in the sanctions list today. The main question is whether the regulator will have grounds to claim that you knew or should have known about the counterparty’s connection with sanctioned persons or prohibited operations tomorrow.
Therefore, an effective system of reducing regulatory risks is based on three checks:
- Know your counterparty (KYC): Establishing the ultimate beneficiaries and control structure.
- Know the transaction (KYT): Analysis of product, technology, logistics route and end use.
- Follow the procedure: documenting each step to protect not only the company but also its management.
If these three elements are not integrated into the business process, the company risks not being fined. It risks a complete shutdown of operations, loss of correspondent accounts in euros and personal liability of managers.
When the standard check is insufficient
Deeper compliance of counterparties is mandatory if:
- Dual-use goods (Dual-Use)
- The supply chain affects countries on the high-risk list.
- The structure of the transaction includes transit hubs or non-standard routes;
- the counterparty is registered in a “sensitive” jurisdiction;
- The request comes from a company with an opaque corporate structure.
- the counterparty insists on payment through third parties that are not a party to the contract;
- The terms of the transaction include atypical confidentiality clauses.
- products can potentially be used for military purposes;
- There is the slightest suspicion of circumvention of export controls.
- You purchase sanctioned components or technologies, even if the final product is civilian.
The mistake most businesses make
Many companies operate on the principle of:
We checked it on the base - it's clean.
That's the wrong depth level.
The right approach asks the question:
“Can this transaction, supply chain or counterparty pattern of behaviour be interpreted by the European regulator as a breach, regardless of the formal lack of direct matching to the lists?”
EU sanctions regimes use the principle of extraterritoriality and responsibility for “knowing participation”. The absence of malice does not absolve from liability unless due diligence has been exercised.
Step 1. Identify the real counterparty
The first thing that starts with the verification is not the registers, but the establishment of the subject.
It is necessary to clearly define:
- the full name of the legal entity;
- registration number and jurisdiction of incorporation;
- the address of the actual activity (not the nominal service address);
- UBOs with a share of 25% or less (in some jurisdictions the threshold is lower);
- Communication with public authorities (SOEs);
- the presence of nominee directors;
- structure of the holding and subsidiaries.
Surface knowledge of the counterparty is the main cause of compliance disasters. The enemy is often not in the first line, but in the second or third.
Step 2. Collect and verify data
For international compliance, only documented facts are relevant.
It is necessary to request and retain:
- constituent documents;
- Certificate of registration and tax residency;
- Extract from the commercial register (fresh);
- Passports of directors and beneficiaries;
- trust declarations;
- licenses and permits;
- bank details;
- confirmation of the origin of the goods;
- End-User Certificate (End-User Certificate)
- Letters of guarantee not to be used for prohibited purposes.
Particularly valuable are documents in which the counterparty declares its control areas and the absence of ties with sanction jurisdictions. This creates an evidentiary basis for the integrity of your verification.
Step 3. Conducting sanction screening
Screening answers the question: Whether the contractor or its beneficiaries are on the sanctions lists now.
This is a dynamic process, not a one-time action. The verification shall cover:
- Consolidated list of EU financial sanctions;
- OFAC (SDN List, SSI List)
- United Nations and United Kingdom (OFSI) sanctions lists;
- National sanctions lists of countries where business operates;
- Lists of restrictions on the export of Dual-Use goods;
- Related Persons (the 50% rule in OFAC)
Screening without verification (Step 2) is a simulation of the activity that, if verified, forms the basis of the charge.
Step 4. The Red Flags (Red Flags)
This is the key intellectual stage that distinguishes paper check from real protection.
Red flags are indicators that indicate a likely attempt to circumvent sanctions:
- Non-standard logistics: The route of delivery through third countries without economic sense.
- Atypical buyer profile: The shell company orders high-tech equipment.
- Reluctance to disclose the end user: Refusing to complete the End-User Statement.
- The structure of the matryoshka: The offshore company owns an offshore company that owns an asset in the risk zone.
- Payment anomalies: payment from a bank of a country not related to the contract, or the offer of cryptocurrency settlements without justification.
- Commercial anomaly: ordering components that do not fit the customer’s business profile.
- Military liaison: any references to military departments in correspondence.
The detection of red flags does not mean an automatic rejection of the transaction. This means that an in-depth examination (Enhanced Due Diligence) and a record of conclusions are required.
Step 5. Select the depth level: Standard or Advanced Due Diligence (EDD)
The choice of level depends on the results of the screening and the risk appetite of the business.
| Level. | Subject of verification | When applicable | Methods |
|---|---|---|---|
| Standard (SDD) | Direct counterparty | Low-risk jurisdiction, transparent structure | Screening, constituent documents, licenses |
| Deepened (EDD) | Contractor, supply chain, product | High-risk jurisdiction, Dual-Use, red flags | On-site inspections, insider analytics, requests to government agencies, analysis of commodity flows |
The error in level selection is almost always more expensive than the EDD itself. Savings on inspection is a loan at a huge interest rate issued to the regulator.
Step 6. Check the product and end use
EU sanctions are about controlling flows, not just controlling individuals.
Even with a “clean” counterparty, goods cannot be delivered if:
- goods (HS code) are included in the lists of prohibited for delivery in the Russian Federation (Annexes to Regulation 833/2014);
- The product is classified as Dual-Use (Regulation 2021/821).
- There is a risk of military end-use.
- The goods are subject to sectoral sanctions (equipment for energy, aviation, the marine sector, luxury goods).
The check should include an analysis for the presence of bypass technological chains: The assembly of a civilian drone from subsanctioned components purchased through third countries is a violation of the law.
Step 7. Documentation of Compliance Decision
This is the most underrated stage.
Due diligence results are the company’s security file. In the case of a BAFT (Germany), OFSI or OFAC check, you will not be asked "Why did you miss?" but "Show how you checked."
The documentation shall contain:
- date of verification and identification of the analyst;
- screenshots from the sanctions databases with the date;
- confirmation of the analysis of the ownership structure;
- Red flag analysis (both positive and negative)
- written approval of the transaction (or refusal) with justification from the compliance officer;
- Risk memorandum on the deal.
An undocumented inspection is equivalent to an undocumented inspection.
Step 8. Implement real-time monitoring
The verification of the counterparty does not end on the day of signing the contract.
The system shall ensure that:
- automatic screening of updates to sanctions lists;
- Monitoring of negative news (adverse media) about the counterparty;
- Control of changes in registration data (change of director, UBO, address);
- monitoring of litigation related to the counterparty;
- Repeated Request for Supporting Documents (Refresh KYC)
A huge number of violations occur not at the beginning of the relationship with the client, but six months later, when the client was put on the sanctions list, and the business did not know about it.
Step 9. Managing the risks of third parties
Your risks are not just your direct customers and suppliers.
These are all third parties in the value chain:
- customs brokers;
- Transport companies and forwarders;
- Agents and trade intermediaries;
- financial institutions;
- subsidiaries and joint ventures.
Contracts with them should include:
- Sanctions Limitation Clauses (Sanctions Limitation Clauses)
- The right to unilateral refusal to perform without penalties (Termination for Sanctions Risk);
- guarantees of non-participation in schemes of circumvention of sanctions;
- The obligation to disclose information about subcontractors involved.
Step 10. Manage a transaction when risk is triggered
If a red flag is triggered during monitoring or incoming control, the algorithm of actions should be prescribed in advance:
- Stop delivery: Immediate blocking of shipment or payment.
- Escalation: Transferring the issue from the sales department to the compliance department.
- Analysis: Enhanced Due Diligence.
- Regulator request: In some cases, a license must be obtained from the national competent authority.
- Refusal: Legally verified notification of the counterparty about the impossibility of the transaction.
- Disclosure (Voluntary Disclosure): In case of unintentional violation, immediately inform the authorities to minimize liability.
Common Mistakes in International Compliance of Contractors
1. The system gave the green light, but the person did not analyze the context. It's a false calm.
2. The company is not on the sanctions list, but 51% belongs to a person from the SDN List. The assets of such a company must be considered blocked under US rules, which often overlaps with the risks for European operators.
3. Your “daughter” in the country of risk signs a contract that the parent company would never agree.
4. Accepting a counterparty guarantee without verification of the End-User Certificate signed by an unknown person is not a proof of innocence, but an aggravating circumstance (“I should have known that the document was questionable”).
5. You produce a civilian machine, but the chip to it is bought from a distributor who illegally exports it from the EU in circumvention of sanctions. You're part of the violation.
6. Transactions that have a connection with the EU (European goods, euros or dollars as the contract currency, EU citizens in management) create an extraterritorial effect.
7. If you delete an email asking the counterparty to “hide the end recipient,” you destroy your own defense and create evidence of concealment.
Compliance officer checklist
Before concluding a contract for the supply of sensitive goods, 15 questions must be answered affirmatively:
- Is the ultimate beneficiary (UBO) an individual identified?
- Are all parties to the deal verified on the EU, OFAC and UN lists?
- Does the buyer’s profile match the product being purchased?
- Is the End-User Certificate verified?
- Is the logistics route economically viable and understandable?
- Is the transit country excluded as a springboard for evading sanctions?
- Does the product fall under the Prohibited Luxury Products or Dual-Use codes?
- Is the export control license checked?
- Are there any banks in the payment chain that are disconnected from SWIFT?
- Are there no sanctioned individuals (members of the boards of directors) in the structure of the transaction?
- Is there a sanction clause in the treaty?
- Have you been screened for negative media in the past 12 months?
- Is the deal with Head of Compliance agreed?
- Is there a file ready to be presented to the regulator?
- Is the business willing to publicly justify the continuation of this transaction?
What an Effective Risk Reduction Strategy Looks Like
A strong strategy usually includes five levels of protection:
1. Regulatory Intelligence: Understanding not only current EU regulations, but also the Commission’s guidelines and the practices of national regulators (BAFAs).
2. Risk Assessment Risk Mapping: Classification of customers and goods by category, creation of a threat matrix.
3. Due Diligence Process: A clear, documented KYC/KYT process with escalation stages rather than disparate actions.
4. Contractual Protection Development and implementation of sanctions and export clauses in contracts protecting the company’s right to stop shipment without penalties.
5. Crisis Management Protocol of Action in case of detection of violation: Internal investigation, voluntary self-disclosure, communication with banks and regulators.
Without the fifth level, the first four can be destroyed by a single management panic.
FAQ
Can you do business with a company that has an office in Moscow but is not under sanctions?
Yes, it's technically allowed. However, such activities require the highest level of care. You must prove to the regulator that the goods will not fall into the banned sectors of the Russian economy and will not be used for military purposes. The final recipient check is critical here.
What if the contractor refuses to disclose the beneficiary?
Denial of UBO when requested by a supplier in transactions involving sanctions risk is a classic red flag. The transaction must be stopped until the situation is resolved.
How often should I update the KYC file?
Regularity depends on the level of risk. For high-risk clients – once every six months, for standard ones – once a year, as well as for any trigger event (change of payment details, request for a non-standard transaction, negative publication in the media).
More importantly: Customer inspection or final consignee inspection?
In export controls and sectoral sanctions, verification of the final consignee and its supply chains is more important. You can sell the product to a completely “pure” trader who will resell it to the end user from the military-industrial complex. All participants in the chain are responsible for improper verification.
Can you rely on the assurances of the European bank that makes the payment?
Nope. Bank compliance protects the bank, not the customer. The fact that the bank has not blocked the payment is not an indulgence for you and does not prove the absence of export control violations or sanctions in the commodity part of the transaction.
What to do if an indirect link with a sanctioned person is found?
Stop the operation immediately. Do an EDD. If the connection is confirmed and the risks are not removed, contact the competent authority for clarification or license or refuse the transaction, fixing the reasons.
Related services
- Sanctions, Export Controls & International Compliance
- International Regulatory Risk & Strategic Advisory
- Corporate Investigations, Regulatory Investigations & Business Integrity
- International Trade, Distribution & Cross-Border Transactions
- Commercial Contracts
Related material
- EU sanctions against Russia: Full practical overview of the limitations
- How to Build an Export Control Program Within a Company
- How to Protect Businesses from Secondary Sanctions
- Dual-use goods: licensing and risk
- How to make a sanctions clause in an international treaty
- Red flags when checking counterparties: analysis
- Arrest of accounts in the EU due to sanctions risks: do
- Personal liability of the Director for violation of sanctions
- Bypassing sanctions (Circumvention): criteria, signs and consequences
Conclusion
Due diligence of counterparties in the sanctions era is not a costly bureaucratic function, but the only legal way to remain in the global market.
A strong compliance system is not based on simple database binary searches, but on an analytical conclusion about the control structure, end-use of the product, and predictability of the supply chain.
In today’s regulatory environment, the winner is not the one who will close the deal faster bypassing the rules. The winner is the one who built a system that can prove to the regulator: We did our best and did our utmost due diligence. This separates a large fine and criminal prosecution from continuing the business.
Have a question about the topic of this article?
Write to us and we will respond within one business day.


