Quick Read

SPK DDMS2000:2026 Section 10.20 requires sanctions compliance to operate as a distinct discipline beyond name-matching, encompassing regime determination by jurisdiction, ownership aggregation analysis, and secondary sanctions exposure assessment. Organizations must identify which sanctions regimes apply based on incorporation, operations, currency exposure, and ownership nationality—not assumption—and then conduct genuine beneficial ownership aggregation to detect sanctioned parties whose names do not appear directly on lists but who are controlled above applicable thresholds by sanctioned persons. This layered approach addresses the regulatory logic of sanctions (sectoral restrictions, licensing regimes, and extraterritorial reach) that generic AML or export screening processes do not fully capture.

Why This Whitepaper Exists

Sanctions screening looks, at first glance, like a subset of AML/KYC — a name checked against a list, a hit or a clean result. SPK DDMS2000:2026 treats it as its own dedicated module at Section 10.20, distinct from both the AML/KYC module at Section 10.6 and the export control module at Section 10.7, because sanctions compliance carries a regulatory logic of its own: ownership and control aggregation rules, secondary sanctions exposure, and licensing regimes that a generic name-matching process does not capture. This whitepaper sets out why the standard separates sanctions compliance out as its own discipline, and what genuine sanctions due diligence involves once name-matching has already returned a clean result.

Sanctions compliance has its own regulatory logic — sectoral sanctions, secondary sanctions exposure, ownership/control aggregation rules, and general licence regimes — that a generic AML or export screening process does not fully capture, particularly given current geopolitical volatility.

What the Standard Actually Says

10.20.1 — Determining which regimes actually apply

The organisation must determine and document which sanctions regimes apply to its activity by jurisdiction of incorporation, operation, currency exposure, and nationality of ownership, recognising that an organisation may be subject to more than one regime simultaneously with differing scope and extraterritorial reach. This is the starting discipline most informal sanctions programmes skip entirely: assuming a single regime applies, based only on where the organisation is headquartered, without checking whether currency exposure, ownership nationality, or operational footprint bring additional, potentially extraterritorial regimes into play.

10.20.2 — Beyond the direct name check: ownership and control aggregation

A subject whose own name never appears on any sanctions list can still be a sanctioned party in substance, if it is owned or controlled, in aggregate, by one or more sanctioned persons above the applicable threshold under the relevant regime — commonly a 50% aggregation rule, though the specific threshold varies by regime. Section 10.20.2 requires this aggregation analysis be genuinely applied, not assumed away because the direct name check came back clean. This is, in practice, the requirement most frequently missed — aggregation analysis requires beneficial ownership data that a simple screening tool query does not, by itself, provide.

10.20.3 — Secondary sanctions: risk from a clean counterparty

The organisation must assess secondary sanctions exposure — where dealing with a non-sanctioned counterparty could itself trigger sanctions risk because of that counterparty's own dealings — for subjects and transactions in higher-risk jurisdictions or sectors identified in the Applicable Obligations Register. This is a genuinely counter-intuitive risk category for many organisations to internalise, because the immediate counterparty passes every direct check available, and the exposure arises entirely from a relationship one or more steps removed from the organisation's own direct dealings.

Where a general or specific licence, exemption, or authorisation may be available for a transaction that would otherwise be restricted, the organisation must maintain a documented process for evaluating this before proceeding, and retain the licence or authorisation itself as part of the case record. A sanctions programme that treats licensing as a legal question handled separately from the DD case file will struggle, at audit, to demonstrate that a transaction proceeding despite an apparent restriction was actually authorised, rather than simply overlooked.

10.20.5 — The immediate-hold rule

A confirmed sanctions match is an immediate hold trigger across all modules in which the subject appears, consistent with the override provisions at Annex A.2, and the transaction or relationship must not proceed pending resolution. This is the operational rule that ties the sanctions module into the rest of the standard's decisioning framework — a confirmed match does not wait for the ordinary tiered approval process; it stops everything, in every module, immediately.

10.20.6 — Deciding who owns this

The organisation must designate accountable ownership for sanctions compliance, which may be combined with or distinct from the AML/KYC owner and the export control owner, depending on the organisation's risk profile, with the rationale for the chosen structure documented.

Why Ownership and Control Aggregation Is Where Most Programmes Fail

Direct name-matching against a sanctions list is a well-understood, mature control most organisations already have in some form. Aggregation analysis is a different kind of task entirely — it requires the organisation to actually understand a subject's beneficial ownership structure, layer by layer, and test each layer against the applicable regime's aggregation threshold. A subject that is 30% owned by one sanctioned person and 25% owned by another may aggregate to a controlling interest that triggers the regime, even though neither individual holding alone would. This kind of analysis depends on beneficial ownership data of a depth that many organisations only collect for their highest-tier AML/KYC subjects, which means sanctions aggregation risk can be systematically under-assessed for subjects that were tiered primarily on other criteria.

Beyond name-matching

What it actually requires

Ownership and control aggregation

Assessing whether a subject is, in aggregate, 50% or more owned or controlled by one or more sanctioned persons — not only whether the subject's own name appears on a list

Secondary sanctions exposure

Evaluating whether dealing with a non-sanctioned counterparty could itself create sanctions risk, because of that counterparty's own dealings with a sanctioned party

Licence and exemption evaluation

Determining whether a general or specific licence, exemption, or authorisation is available before proceeding with a transaction that would otherwise be restricted

Regime overlap

Recognising that an organisation may be subject to more than one sanctions regime simultaneously, with differing scope and extraterritorial reach

Where Sanctions Ownership Should Sit

Section 10.20.6's flexibility on ownership structure is deliberate, but it is worth thinking through the trade-off explicitly rather than defaulting to whichever structure is administratively simplest. Combining sanctions ownership with AML/KYC ownership under Section 10.6 has genuine efficiency benefits — the two modules share significant screening infrastructure and beneficial ownership data. It also carries a real risk: sanctions compliance's distinct regulatory logic, particularly aggregation analysis and secondary exposure assessment, can be diluted if it is treated as a subset of a broader AML/KYC role rather than a distinct discipline with its own specialist attention. Organisations with material sanctions exposure — particularly those in sectors or geographies where sectoral or secondary sanctions risk is elevated — should weigh this trade-off deliberately and document the reasoning, not simply default to combined ownership because it is the path of least resistance.

Building Sanctions Compliance in Practice

Map regime applicability at the organisational level, then re-test it periodically

Section 10.20.1's applicability determination should not be a one-time exercise. New currency exposure, a new jurisdiction of operation, or a change in ownership nationality can each bring a new regime into scope — this connects directly to the ongoing due diligence obligation addressed elsewhere in this series, and should be one of the event-based triggers the organisation defines for its sanctions programme specifically.

Build aggregation analysis into the highest-tier workflow, not as an optional extra

Because aggregation analysis depends on beneficial ownership depth, it should be a structural requirement of Tier 3–4 due diligence workflow — not a step an analyst adds only when something about the subject already looks unusual.

Treat secondary exposure as its own assessment step for higher-risk geography

Rather than folding secondary sanctions exposure into general risk narrative, build it as its own explicit question in the due diligence workflow for subjects and transactions connected to jurisdictions or sectors flagged in the Applicable Obligations Register.

Retain the licence, not just a note that one exists

Section 10.20.4 requires the licence or authorisation itself in the case record, not merely a reference to it. A case file that states “licence obtained” without the document itself will not satisfy an audit of this requirement.

Common Misconceptions Worth Correcting

  • “A clean name-match result means the subject is not a sanctions risk.” Ownership and control aggregation can bring a subject into scope even with a clean direct name check.

  • “Secondary sanctions only matter for organisations dealing directly with sanctioned entities.” By definition, secondary exposure arises from dealing with a non-sanctioned counterparty — that is exactly what makes it easy to overlook.

  • “Our headquarters jurisdiction determines which sanctions regime applies to us.” Currency exposure, ownership nationality, and operational footprint can each independently bring additional regimes into scope.

  • “Licensing is a legal team question, separate from the DD file.” Section 10.20.4 requires the licence itself in the case record — it is part of the evidentiary file, not a parallel legal process.

Common Gaps Worth Checking

  • Sanctions regime applicability is assessed once, based only on headquarters jurisdiction, with no reassessment of currency exposure, ownership nationality, or operational footprint.

  • Ownership and control aggregation is not performed — screening stops at the subject's own name.

  • Secondary sanctions exposure has never been assessed for counterparties in higher-risk jurisdictions or sectors.

  • A transaction proceeded under an assumed licence or exemption, with no documentation of the evaluation or the licence itself in the case record.

  • Sanctions ownership was folded into a broader AML/KYC role with no documented rationale for that structural choice.

How Speeki Sentinel Certification Assesses This

Certification against SPK DDMS2000:2026 tests whether sanctions regime applicability has been genuinely assessed rather than assumed, whether ownership and control aggregation is actually performed for relevant subjects, and whether licence or exemption evaluations are documented and retained in the case record where relied upon. An assessor will look specifically for evidence that aggregation analysis was performed, not merely that a direct name check returned clean.

Speeki Sentinel is the certification product through which this assessment is delivered. Organisations may build and operate their own sanctions compliance programme on a self-assessed basis, without ever seeking Speeki Sentinel certification. Speeki Sentinel certification — the independent verification of that DDMS against the standard — is available once an organisation believes its programme is ready to be independently tested.

Speeki is an accredited certification body. For current information on the specific accreditations Speeki holds and their scope, please refer to speeki.com rather than relying on this whitepaper, as accreditation status and scope are maintained centrally and can change.

Closing Note

A clean name-match result answers one question and leaves several others unasked. Section 10.20 exists because sanctions risk today is layered — direct designation, aggregated ownership, secondary exposure, and licensing all operate on different logic, and an organisation that only checks the first has not actually assessed the risk the current sanctions landscape presents, however clean its screening dashboard appears.