Company Brochure

Sanctions Screening on the Isle of Man: What Code 4(1) and Code 13 Actually Require

A compliance officer reviewing a sanctions screening list at a desk in an Isle of Man office

Strengthen your compliance strategy

— with confidence. clarity. experts.

Book a
consultation

Sanctions screening on the Isle of Man is a Code 4(1) procedures-and-controls duty at onboarding and a Code 13 ongoing-monitoring duty for the life of the relationship, both tested against the sanctions list maintained by the Treasury. A screening tool subscription covers neither duty — the Isle of Man Financial Services Authority tests the procedures and the evidence behind them.

That distinction matters because most firms already run some form of screening software and assume the box is ticked. It is not. The tool produces a match or no-match against a name; the Authority is looking for the procedures around it, and for evidence that monitoring kept running after day one.

What does Code 4(1) actually require at onboarding?

Code 4(1)(a) is a procedures-and-controls duty, not a one-off check. It states that a relevant person must not enter into or carry on a business relationship, or carry out an occasional transaction, with or for a customer or another person unless the relevant person establishes, records, operates and maintains procedures and controls for determining whether a customer, any beneficial owner, beneficiary, introducer or eligible introducer is included on the sanctions list. The Handbook's guidance at §3.3.8 spells out the scope of what you are checking: a customer's — and, where appropriate, the beneficial owner's and controller's — nationality, residency, expected activities and source of funds, to confirm none of them engages a relevant financial sanction.

Read those two together and the obligation is broader than "screen the customer's name." You are expected to have a procedure that reaches beneficial owners, controllers, introducers and eligible introducers, and to have recorded that procedure so it can be shown to a supervisor. Code 4(2) adds that the extent and frequency of this work must be risk-based — a higher-risk relationship warranting closer and more frequent checking than a low-risk one. §3.2.1.5 of the Handbook folds sanctions screening into the same paragraph as negative-press and open-source checks, which is a useful signal of how the Authority frames it: not a standalone module bolted onto CDD, but one strand of the ongoing due diligence a relevant person owes every customer.

We help Isle of Man firms turn that procedures-and-controls requirement into something a supervisor can actually follow on paper.

What counts as the "sanctions list" on the Island?

Code 3(1) defines the sanctions list precisely: the list of persons who are subject to international sanctions which apply in the Island, maintained by the Customs and Excise Division of the Treasury. Following the UK's exit from the EU, that is the list published by HM Treasury. This is worth stating plainly because it is easy to default to whatever list a screening vendor ships as its "global" dataset, or to assume an EU consolidated list applies here — it does not govern the Island in the way the Treasury-maintained list does. Further guidance and information on the international sanctions applying in the Isle of Man is maintained by IOMCI, and the Handbook points relevant persons there rather than to any UK or EU regulator. Your procedures should name the correct list explicitly, not just "our screening provider's database."

A risk meeting around a table with sanctions and compliance documents laid out

What does Code 13 require once the relationship is live?

This is where most gaps sit. Code 13(1)(c) requires a relevant person to perform ongoing and effective monitoring of any business relationship or occasional transaction, including monitoring whether the customer, beneficial owner, beneficiary, introducer or eligible introducer is listed on the sanctions list. The duty does not end at onboarding — it runs for the life of the relationship, and the Handbook's §3.3.8 guidance is explicit that checking happens both at the outset and on an ongoing basis.

§3.4.6.2 goes further than most Handbook sections on how that ongoing check has to work in practice. Its guidance states that procedures for ongoing monitoring in the context of sanctions lists should be capable of detecting when a customer involved in an existing business relationship or occasional transaction becomes listed on a sanctions list, and that periodic or trigger-event customer reviews may not be adequate to detect such listings in a timely manner such that the relevant person does not breach sanctions requirements. In plain terms: if your only sanctions check happens at the annual or triennial customer review, a listing that occurs six months into that cycle sits undetected for the rest of it. That gap is itself the breach the guidance is warning against.

The same paragraph requires clear procedures and controls for staff on the actions to take if a customer is listed — who is notified, what is frozen or reported, and on what timescale. A firm that can screen a name but has no written escalation path for a positive match has half a control, not a complete one.

Isn't this just a screening-tool subscription, not something worth paying a consultant for?

We hear this a lot, and it misreads what a visit from the Authority actually tests. A screening tool answers one narrow question: does this name match an entry on a list, right now. It does not write your procedures under Code 4(1), it does not decide how deep your beneficial-owner and controller checks go, it does not set your risk-based frequency under Code 4(2), and it certainly does not produce the continuous-detection capability §3.4.6.2 asks for between review cycles. A supervisor sitting across from your compliance officer is not going to ask which vendor you subscribe to — they are going to ask to see the documented procedure, the evidence that monitoring ran between reviews rather than only at them, and the record of what happened the one time a match came back. The tool is an input to all three. It is not a substitute for any of them. Firms that treat the subscription as the control usually discover the shortfall only when a supervisor asks to see the paperwork behind it.

A close-up of a compliance policy document with sanctions procedure text highlighted

Common mistakes we see

The most frequent error is treating the screening tool's output as the finished control, with no written procedure describing when checks happen, who reviews a match, or how beneficial owners and controllers are brought into scope alongside the named customer. Close behind it is relying on periodic customer reviews as the only ongoing monitoring — exactly the gap §3.4.6.2 calls out, since a mid-cycle listing goes undetected until the next scheduled review. We also regularly see firms screening against a generic "global" sanctions dataset from their vendor without confirming it reflects the Treasury-maintained list that actually applies on the Island, and firms with no documented escalation path for a positive match, so the one moment the control is actually needed is the moment nobody has a procedure to follow.

Sanctions screening running properly touches most of the same ground covered in our AML/CFT Handbook April-2026 health-check — it is one duty among several the Handbook expects a firm to evidence, not a checkbox that sits apart from the rest of the framework.

An Isle of Man compliance officer's desk with a laptop, notes and a sanctions escalation checklist

Frequently asked questions

Does sanctions screening at onboarding satisfy the ongoing-monitoring duty too?

No. Code 4(1) and Code 13(1)(c) are separate duties tested separately. §3.3.8 is explicit that the check applies both at the outset of the relationship and on an ongoing basis, and §3.4.6.2's guidance specifically warns that periodic reviews alone may not detect a listing that occurs between them.

Who is covered by the sanctions check — just the customer?

No. Code 4(1)(a) and Code 13(1)(c) both extend the check to any beneficial owner, beneficiary, introducer or eligible introducer connected to the relationship, not only the named customer. §3.3.8 adds that beneficial owners and controllers should be checked where appropriate, alongside the customer's nationality, residency, expected activities and source of funds.

Which sanctions list should we be screening against?

The list defined at Code 3(1): the list of persons subject to international sanctions applying in the Island, maintained by the Customs and Excise Division of the Treasury, which following the UK's exit from the EU is the list published by HM Treasury. Further guidance on the sanctions applying here is maintained by IOMCI.

How often should ongoing sanctions monitoring run?

Code 4(2) sets the frequency on a risk-based footing, so a higher-risk relationship should be checked more closely and more often than a lower-risk one. The starting point for that risk view sits in your Customer Risk Assessment, which is what should be driving how tightly you calibrate the screening cadence for each customer.

A name that clears the screen once is not a name that stays clear forever — and Code 13 exists precisely because the Authority knows that.

Knight Consultancy Limited
(Company No: 136669C)
Design House, Hills Meadow, Douglas,
Isle of Man ,IM1 5EB

© Knight Consultancy Limited {{Y}}. All Rights Reserved. Privacy Policy

Website and marketing partner: Yellowstone Accounts

Knight