Sanctions and Third Party Risk: What Every TPRM Practitioner Should Know || TPRM Exchange Podcast – Episode 4
- 3 days ago
- 6 min read
Sanctions compliance may traditionally sit with legal, trade compliance, or another specialized function, but it has direct implications for third party risk management. A prohibited relationship can expose an organization to blocked transactions, frozen payments, regulatory enforcement, financial penalties, operational disruption, and reputational damage.
In this episode of the TPRM Exchange, host Hilary Jewhurst speaks with Michael Volkov of The Volkov Law Group about how sanctions apply to third parties, where sanctions risk appears throughout the lifecycle, and what practitioners can do to build a practical and defensible process.
Sanctions Risk Does Not Stop at the Border
One of the most common—and potentially costly—misunderstandings is that U.S. sanctions no longer apply when a transaction is routed through an entity outside the United States.
As Volkov explains, a U.S. company cannot avoid its sanctions obligations simply by working through a third party in another country.
“The risk continues from wherever you’re located. If you’re a U.S. person or a U.S. company, it continues through your third parties, no matter where they are located.” — Michael Volkov
Sanctions may target particular activities, individuals, entities, industries, or entire countries. Regardless of the specific program, the practical question for an organization is whether it is permitted to conduct business or complete a financial transaction with the party involved.
Screening Should Begin During Onboarding
Sanctions issues can emerge at several points in the third party lifecycle, but onboarding is the most important place to establish a control.
Before a vendor, supplier, customer, distributor, or other third party is entered into an organization’s master database or approved for payment, the party should be screened. Building screening into the existing approval workflow allows the organization to identify potential issues before a contract is signed, goods are shipped, or money changes hands.
Waiting until a bank blocks a payment puts the organization in a much more difficult position. By that point, goods may already have been delivered, contractual commitments may have been made, and funds may be frozen while the parties investigate.
The Entity Name Is Only the Beginning
Screening the contracting entity is an essential first step, but it may not reveal the full risk. Organizations may also need to examine the company’s beneficial owners, officers, directors, or other principals.
Under certain sanctions rules, an entity can be treated as blocked when one or more sanctioned persons own 50% or more of it—even if the entity itself does not appear by name on a sanctions list.
Ownership structures can also obscure the individuals who ultimately control or benefit from a company. When an initial screen produces a red flag, practitioners may need to gather additional ownership information and work with legal or compliance specialists to determine whether the relationship is permissible.
Sanctions Exposure Extends to Nth Parties
The conversation also highlights the importance of looking beyond direct contractual relationships. Sanctioned goods, materials, entities, or individuals may appear several levels down a supply chain or later in a distribution channel.
Volkov uses supply chain and transshipment examples to illustrate how an organization can face liability even when it does not directly contract with the sanctioned party. Risk may arise when prohibited materials enter the supply chain through a subcontractor or when a distributor redirects a product to a sanctioned destination.
Managing that exposure may require:
Risk-based supply chain due diligence
Appropriate sanctions and trade-compliance clauses
End-use and end-user controls
Supplier representations and certifications
Supply chain audits
Escalation procedures for geographic or ownership concerns
The appropriate level of diligence will depend on the organization’s products, markets, geographic reach, distribution model, and overall exposure.
Build Forward Instead of Trying to Fix Everything at Once
Organizations implementing formal sanctions screening may discover that hundreds or thousands of existing third parties have never been screened. That does not mean the program must resolve the entire backlog before introducing an effective control.
“You’re not going to boil the ocean over this. We don’t have time for that, nor the resources.” — Michael Volkov
A more manageable approach is to establish a clear implementation date and screen every new third party from that point forward. The organization can then address its existing population using a risk-based plan.
Higher-priority reviews may include third parties with:
Operations in higher-risk countries or regions
Significant organizational spend or revenue
Exposure to known transshipment locations
Complex or unclear ownership structures
Access to regulated products, technology, or services
Roles deeper within critical supply or distribution chains
This approach allows the organization to establish a consistent control immediately while addressing historical exposure in a deliberate, defensible order.
Screening Is Not a One-Time Activity
A third party that passes screening today may be added to a sanctions list tomorrow. Sanctions designations can change quickly in response to geopolitical events, national security concerns, criminal activity, or changes in government policy.
Automated screening platforms can help by retaining screened parties and issuing alerts when a party’s status changes. Organizations without an automated tool may begin with available government screening resources or seek assistance from qualified legal or compliance professionals, but manual screening becomes harder to sustain as international activity grows.
Regardless of the technology used, the process should define:
Who is screened
When screening occurs
Which lists and data sources are used
How potential matches are reviewed
Who can clear or reject a match
How decisions are documented
How active relationships are monitored
When issues must be escalated
The tool supports the control, but it does not replace a clear workflow and accountable decision-making.
TPRM Does Not Have to Own the Process—but It Must Understand It
Sanctions screening may be performed by compliance, legal, procurement, trade compliance, sustainability, or another team. Organizational structures vary, and there is no single operating model that works for every company.
However, TPRM practitioners should understand how the process works even when another function owns it. They should know who makes sanctions decisions, what tools or information that team uses, what evidence confirms that screening occurred, and how an issue is escalated.
That knowledge is necessary to explain the organization’s controls to business stakeholders, auditors, examiners, and leadership. It also prevents gaps between functions—particularly when onboarding involves several teams with different approval responsibilities.
Compliance Must Be Positioned as a Business Partner
Business stakeholders may view sanctions screening as another obstacle standing between them and a time-sensitive transaction. Volkov recommends approaching those conversations as a partner focused on helping the business proceed safely.
The message should be straightforward: involve the appropriate risk and compliance teams early, and they can identify concerns, explore permissible options, and help prevent transactions from being blocked later.
TPRM and compliance teams should also establish reasonable turnaround expectations. A well-designed screening process should support timely decision-making while ensuring that unresolved red flags do not pass unnoticed into the vendor master or payment process.
When an Existing Supplier Triggers an Alert
If a long-term supplier appears on a sanctions notice, the organization must act promptly.
The immediate response should generally include pausing business and financial activity, notifying the appropriate internal stakeholders, and investigating the alert. The organization should contact the third party for an explanation while legal or trade-compliance personnel determine whether the notice is accurate and whether the relationship can lawfully continue.
Contracts and purchase orders should contain sanctions-compliance language that supports the organization’s ability to suspend or terminate prohibited activity. These protections are particularly important when a designation occurs in the middle of a transaction or during a multiyear agreement.
Practitioners should not assume that every alert establishes a confirmed violation. False positives and explainable matches occur. Nevertheless, activity should not resume until qualified personnel have reviewed the issue and documented a defensible decision.
Two Practical Priorities
Volkov closes with two primary actions for practitioners:
Implement a sanctions-screening capability that supports onboarding and continued monitoring.
Provide annual sanctions training to employees whose responsibilities may bring them into contact with sanctions-related issues.
Training does more than communicate rules. It creates an opportunity for employees to raise questions, describe emerging business activities, and identify transactions or relationships that might otherwise remain outside the risk team’s view.
Ultimately, effective sanctions compliance depends on visibility, defined ownership, appropriate technology, and cooperation across the organization. By embedding screening into onboarding, monitoring active relationships, accounting for beneficial ownership and nth parties, and responding quickly to alerts, TPRM practitioners can help protect the organization while still enabling the business to move forward.


Comments