π International Sanctions: An Overview
International sanctions are coercive measures imposed by governments and international bodies to achieve foreign policy, national security, and counter-terrorism objectives. In the context of crypto payments, sanctions compliance means ensuring that your business does not facilitate transactions with sanctioned individuals, entities, or jurisdictions.
The crypto industry has become a key focus for sanctions enforcement because of the pseudonymous nature of blockchain transactions, the global reach of crypto payments, and the potential for sanctions evasion through digital assets. VASPs (Virtual Asset Service Providers), exchanges, and payment processors are on the front lines of sanctions compliance.
Sanctions violations can result in multi-million or even billion-dollar fines, criminal prosecution, loss of banking relationships, and severe reputational damage. In 2024, the crypto industry saw over $500 million in sanctions-related penalties.
βοΈ Key International Sanctions Regimes
Crypto payment businesses must comply with multiple sanctions regimes. Here are the most important ones:
Office of Foreign Assets Control. Administers US sanctions including SDN List, SSI List, and country-based sanctions. Has jurisdiction over US persons and any transactions involving US dollars or US-based systems.
Council of the European Union sanctions. Binding on all EU member states. Includes asset freezes, travel bans, and sectoral restrictions. Applies to any business operating in or serving the EU.
UN Security Council sanctions. Globally recognized and implemented by member states. Focuses on terrorism, nuclear proliferation, and conflict zones.
Office of Trade Sanctions Implementation. UK's independent sanctions regime post-Brexit. Applies to UK persons and businesses.
OFAC SDN List
The Specially Designated Nationals (SDN) List is the primary US sanctions list. It includes individuals, entities, and organizations owned or controlled by sanctioned countries, as well as terrorists, drug traffickers, and other designated persons. VASPs must screen all transactions against this list.
Country-Based Sanctions
Beyond list-based screening, businesses must consider country-based sanctions. For example:
- US: Prohibited transactions involving Iran, North Korea, Syria, Cuba, Crimea, and Donetsk/Luhansk regions.
- EU: Similar restrictions with additional country-specific sanctions (e.g., Belarus, Myanmar).
- UK: Independent sanctions list covering many of the same jurisdictions.
- UN: Sanctions on North Korea, Iran, and various terrorist groups.
Even if a transaction is not with a listed entity, it may still be prohibited if it involves a sanctioned jurisdiction. GeoIP blocking and jurisdictional screening are essential components of a robust sanctions compliance program.
π Sanctions Screening Obligations for Crypto Payments
1. Real-Time Transaction Screening
All transactions must be screened before they are confirmed on-chain. This includes:
- Deposits and withdrawals
- Internal transfers between accounts
- Peer-to-peer transfers
- Merchant payments
2. Address Screening
Wallet addresses must be screened against sanctions lists and risk databases. This includes:
- New address screening at the time of onboarding
- Ongoing screening of all addresses involved in transactions
- Retrospective screening of historical addresses when sanctions lists are updated
3. Beneficial Ownership Screening
For corporate customers, beneficial owners must be screened against sanctions lists. This applies to both initial onboarding and ongoing monitoring.
4. Jurisdictional Screening
IP addresses, device information, and other data should be used to identify and block transactions from sanctioned jurisdictions.
| Screening Type | Frequency | Key Tools |
|---|---|---|
| Real-time Transaction | Every transaction | Chainalysis, TRM Labs, Elliptic |
| Address Screening | Ongoing + retrospective | Sanctions list APIs, blockchain analytics |
| Beneficial Ownership | Onboarding + periodic review | KYC/AML platforms, corporate registry |
| Jurisdictional | Every interaction | GeoIP, device fingerprinting |
βοΈ Blockchain-Specific Sanctions Challenges
The nature of blockchain technology creates unique challenges for sanctions compliance:
- Pseudonymity: Wallet addresses are not linked to real-world identities by default, making it harder to verify counterparties.
- Cross-Chain Activity: Users can move funds between blockchains, potentially avoiding screening on one chain.
- Mixing Services: Tumblers and mixers can obfuscate the origin of funds, making it harder to trace sanctions connections.
- DeFi Protocols: Smart contracts can execute transactions without a centralized entity, raising questions about who is responsible for screening.
- Privacy Coins: Monero, Zcash, and other privacy coins obscure transaction details, complicating screening.
- Speed: Blockchain transactions are fast β screening must happen in seconds.
- Global Nodes: Transactions may be processed by nodes in multiple jurisdictions, creating jurisdictional ambiguity.
Use a combination of on-chain analytics, real-time screening, address scoring, and enhanced due diligence for high-risk transactions. For DeFi, consider implementing compliance at the smart contract level or using compliance oracles.
π Risk-Based Approach to Sanctions Compliance
Regulators expect VASPs to adopt a risk-based approach (RBA) to sanctions compliance. Key elements include:
Customer Risk Assessment
Categorize customers based on:
- Geographic location and jurisdiction
- Transaction volume and frequency
- Transaction patterns (e.g., unusual activity, rapid movement)
- Source of funds and wealth
- PEP (Politically Exposed Person) status
Transaction Risk Assessment
Screen transactions based on:
- Transaction amount (higher amounts = higher risk)
- Destination jurisdiction
- Destination address risk score
- Transaction patterns (e.g., structuring, layering)
- Speed of transaction (rapid movement can indicate sanctions evasion)
Jurisdictional Risk
Consider the countries involved in the transaction β both the sending and receiving jurisdictions. Some countries are considered "high-risk" due to:
- Active sanctions against them
- High levels of corruption or money laundering
- Lack of effective AML/CFT controls
- FATF "grey list" or "black list" status
Document your risk assessment methodology and apply it consistently. Higher-risk customers and transactions should trigger enhanced due diligence (EDD) and increased monitoring.
βοΈ Notable Sanctions Enforcement Actions
Understanding past enforcement actions helps illustrate the importance of sanctions compliance:
- Binance (2024): $4.3 billion settlement with DOJ for BSA/AML violations, including sanctions failures.
- OFAC v. Crypto Exchange (2023): $15M fine for failing to screen transactions involving sanctioned jurisdictions.
- OFAC v. DeFi Protocol (2024): $8M settlement after allowing North Korean-linked addresses to interact with its protocol.
- OFAC v. Payment Processor (2025): $20M fine for processing $100M+ in transactions with sanctioned entities over three years.
- EU Sanctions Enforcement (2025): First EU sanctions penalties against a crypto business for facilitating Russian sanctions evasion.
Sanctions enforcement in crypto is intensifying. Regulators are increasingly focused on:
- DeFi protocols and their compliance frameworks
- Cross-chain transaction monitoring
- Sanctions evasion through mixers and privacy tools
- Complicity of VASPs in sanctions evasion
Proactive compliance is the best defense.
π Building a Sanctions Compliance Program
1. Written Policies and Procedures
Develop a written sanctions compliance policy that covers:
- Scope of sanctions screening (all transactions, all customers)
- Roles and responsibilities for sanctions compliance
- Procedures for screening, blocking, and reporting
- Escalation procedures for sanctions hits
- Record-keeping requirements
2. Sanctions Screening Technology
Implement automated screening tools that:
- Screen all transactions in real time
- Automatically update sanctions lists
- Provide risk scoring and investigation tools
- Generate audit trails
3. Sanctions Officer
Appoint a qualified Sanctions Officer responsible for:
- Oversight of the sanctions compliance program
- Investigations and reporting
- Staff training
- Regulatory liaison
4. Staff Training
Conduct regular training for employees on:
- Sanctions regulations and their implications
- How to identify red flags for sanctions evasion
- Escalation procedures
- Reporting obligations
5. Independent Audit
Engage an independent auditor to review your sanctions compliance program at least annually. The audit should assess:
- Effectiveness of screening systems
- Completeness of policies and procedures
- Staff training and awareness
- Record-keeping and reporting
Regulators like OFAC, the EU, and the FCA expect VASPs to have a written, tested, and audited sanctions compliance program that is proportionate to their risk profile. The program should be a living document, updated as regulations and risks evolve.
π Best Practices for Sanctions Compliance
- Screen All Transactions: No transaction is too small to screen. Sanctions evaders often use small-value transactions to avoid detection.
- Implement Retrospective Screening: Sanctions lists change β historical addresses may become sanctioned. Screen your entire transaction history periodically.
- Use Multiple Data Sources: Rely on multiple sanctions lists and risk databases to ensure comprehensive coverage.
- Document Everything: Maintain detailed records of all screening activities, investigations, and reporting.
- Engage Regulators: Build relationships with regulators and seek guidance when needed.
- Plan for Emergencies: Have procedures in place for handling sanctions hits, including blocking, freezing, and reporting.
- Stay Informed: Sanctions regimes change frequently. Subscribe to regulatory updates and industry alerts.