Sanctions and proliferation financing are risk-assessment obligations before they are screening obligations. Screening is a control; the assessment is the judgement that decides which controls you need. On the Isle of Man that judgement sits in Part 3 of the Anti-Money Laundering and Countering the Financing of Terrorism Code 2019, headed "Risk Based Approach": a business risk assessment at paragraph 5, a customer risk assessment at paragraph 6 and a technology risk assessment at paragraph 7. As its onsite Sanctions and Proliferation Financing inspections were ending, the Isle of Man Financial Services Authority used its AML Focus newsletter of May 2026 to tell firms their BRA, CRA and TRA should be "up to date in relation to the risks associated with PF and sanctions, especially in this current global climate". A firm with a screening subscription and a silent BRA has answered only the smaller question.
Why this belongs in the assessment, not the screening system
Part 3's three paragraphs run in near-identical terms: paragraph 5(1) requires an assessment "that estimates the risk of ML/FT posed by the relevant person's business and customers", paragraph 6(1) the risk "posed by the relevant person's customer", and paragraph 7(1) the risk "posed by any technology to the relevant person's business". Worth noting once: the Code says ML/FT, while the April 2026 AML/CFT Handbook works in terms of ML/FT/PF, folding proliferation financing into the same frame, and that is the framing the Authority's May 2026 message assumes.
The Authority put it plainly: "As per Part 3 of the Code, relevant persons must understand the risk exposure of their business by understanding their business profile, including their business sanctions exposure." Exposure of that kind is a property of the business model, knowable before any name is screened. FATF amended the Recommendations in 2020, the newsletter recalls, "to ensure sanctions risks are properly addressed in our risk assessments".
Its suggested starting point is a review of your business and business model, focusing on four things: your customers and how you engage with them; your customers' customer; your service providers; and your use of technology. Screening is not among them. It sits elsewhere in the newsletter, as one of four things a firm should have in place alongside internal controls, employee training and regular review of the sanctions programme. Our post on what Code 4(1) and Code 13 require of sanctions screening covers that side; this one stops where it starts.

What the Authority asks you to assess
The Authority lists the elements to consider, "but are not limited to", in five groups. The third column is our reading, not the Authority's allocation; several elements belong in two assessments at once.
| Element | What to look at | Where it lands |
|---|---|---|
| Products and services | The products and services offered, and where they fit into other financial or commercial products, services, networks or systems | BRA |
| Customers | Customers' nationality, supply chain, intermediaries, and counterparties | CRA, aggregated up into the BRA |
| Geography | Locations of the business, its customers, supply chain, intermediaries and counterparties | BRA and CRA |
| Distribution channels | Third party transactions such as agents, intermediaries, or distributors; employee risks | BRA, and the TRA where the channel is technology-delivered |
| Other factors | Transactions: payment methods and high-value asset transactions. Technology: cybersecurity risks, use and transfer of technology, software or information | CRA for transactions; TRA for technology risks |
Identifying the elements is only half of it. The Handbook requires that identified risks "must be assessed to determine how these risks affect the relevant person", analysing the information "to understand the likelihood of the risks occurring and the impact they would have if they did occur". A business risk assessment that names sanctions without reaching a likelihood-and-impact conclusion has stopped halfway, as has a technology risk assessment that catalogues systems without asking what proliferation financing exposure they carry.
That work is analytical rather than administrative.
Who actually runs sanctions on the Isle of Man
The Isle of Man Financial Services Authority is not the sanctions competent authority. It supervises AML/CFT compliance, but it neither administers sanctions nor maintains the list, and a firm treating it as the source of sanctions rules is looking in the wrong place.
Code paragraph 3(1) defines "sanctions list" as "the list of persons who are subject to international sanctions which apply in the Island which is maintained by the Customs and Excise Division of the Treasury". The Handbook's endnote records that, following the UK's exit from the European Union, the applicable list is the one published by HM Treasury. On administration it is direct: "The competent authority in relation to the administration of United Nations and UK financial and trade sanctions and export licensing controls in the Isle of Man is the Isle of Man Customs and Immigration Division ('IOMCI')."
IOMCI's website carries the Island's primary guidance on financial sanctions and current sanctions regimes, terrorist financing, proliferation financing, export and trade control, and trade-based money laundering. The Handbook also points to its guidance titled Proliferation Financing Risks, May 2024, which highlights proliferation financing specific risk factors, higher risk indicators and red flags, and belongs among the sources your BRA cites.

The country lists changed in February 2026
Following the February 2026 FATF Plenary, the Cabinet Office amended the AML/CFT Country Lists, published on the Department of Home Affairs website. As at 13 February 2026:
| Jurisdiction | Movement | List |
|---|---|---|
| Kuwait and Papua New Guinea | Added | List B(i) |
| Côte d'Ivoire | Added | List B(ii) |
| Djibouti | Removed | List B(ii) |
| Saint Kitts and Nevis, and Suriname | Added | List C |
| Kuwait and Papua New Guinea | Removed | List C |
| Sint Maarten | Added | List D |
| Kuwait | Removed | List D |
The Authority's comment puts the work on the firm: "Most regulated or supervised entities should already have carried out their own evaluation for any impact on their own risk assessments and customer procedures arising from this." The task is to establish whether any of it touches your customers, counterparties, supply chain or geography, and to record the conclusion either way. No exposure is a good answer, provided it is written down.
Resist the reflex to reclassify a relationship the moment a country moves on a list. Except where paragraph 15(5) of the Code applies, the Handbook's guidance is that isolated risk factors do not necessarily move a relationship into a higher or lower risk category, though they could, depending on the particular circumstances. A country movement is an input to that judgement, not a substitute for it.
How often is "up to date"?
Neither the Code nor the Authority sets a review frequency. The Authority says "the frequency of conducting a risk assessment depends on your risk appetite", while adding that "consideration should be given to the dynamic nature of PF and sanctions, and a more fluid approach is encouraged" for those elements in the BRA, CRA and TRA. In our experience that is an invitation to decouple the sanctions and PF elements from the annual cycle, not to review everything more often.
A practical trigger arrived on Friday 15 May 2026, when the Authority launched a sanctions notification service, emailing all primary contacts about the latest changes to the sanctions list that may affect their customer relationships and transactions. Each is a dated prompt to test against your assessments. The Handbook warns on the monitoring side that periodic or trigger event customer reviews "may not be adequate to detect such listings in a timely manner".
The Island's sixth-round MONEYVAL mutual evaluation on-site also runs from 28 September to 9 October 2026, with the fuller integration of proliferation financing among the noticeable methodology changes for industry. The Isle of Man Government's 2026 National Risk Assessment suite now includes a proliferation financing assessment alongside money laundering and terrorist financing, which your own assessments should reconcile against.
If you would rather find the gaps before an assessor does, we can work through all three with you.

Common mistakes we see
The most common is treating sanctions as a control question only: the screening procedure is documented in detail while the BRA says nothing about the firm's sanctions exposure. Close behind is assessing the customer and stopping there, when the Authority's starting points expressly include your customers' customer and your service providers. And TRAs are often written as IT documents about system security, with no view on the proliferation financing risk in the use and transfer of technology, software or information.
Frequently asked questions
Does our sanctions screening system satisfy Part 3 of the Code?
No. Screening is a control under separate Code duties; paragraphs 5, 6 and 7 require assessments that estimate risk, and the Authority's May 2026 message is that those assessments must be up to date on PF and sanctions risk.
Which of the three assessments should carry proliferation financing risk?
All three. The BRA carries the business-model exposure the Authority calls your business sanctions exposure; the CRA carries customer nationality, supply chain, intermediaries and counterparties; the TRA the use and transfer of technology, software or information.
Who should we go to for sanctions guidance on the Island?
IOMCI, which the Handbook names as the competent authority for United Nations and UK financial and trade sanctions and export licensing controls in the Isle of Man. Its website carries the Island's primary guidance, including Proliferation Financing Risks, May 2024.
The country lists moved in February 2026. What do we have to do?
Evaluate the impact on your own risk assessments and customer procedures, and record the outcome. The Authority's position is that most regulated or supervised entities should already have carried this out.
An inspection will ask what you concluded about your sanctions exposure and when, and a screening log is not an answer to that question.
