The sanctions compliance landscape facing UK-regulated firms in 2026 is materially more complex than it was two years ago, and significantly more complex than the compliance frameworks of most firms were designed to address. The combination of an expanded Russia sanctions regime, new end-use controls, an active OFSI enforcement programme now operating under a revised framework, and the FCA's consolidation of AML supervisory responsibility across professional services has created a compliance environment in which a static, list-screening-centred approach to sanctions compliance is genuinely inadequate.
Understanding what has changed, and what it demands from compliance functions operationally, is more useful than a general statement that sanctions risk is elevated.
The end-use controls extension
From 13 May 2026, the Sanctions (EU Exit) (Miscellaneous Amendments) Regulations 2026 introduced powers to implement sanctions end-use controls in the UK. These extend the scope of sanctions obligations beyond designated persons and the lists that firms typically screen against, to goods or services at risk of being used in ways that undermine UK sanctions through their end use or end user, even where those goods or services are not otherwise directly prohibited.
For many regulated firms, particularly those involved in trade finance, supply chain financing or correspondent banking for trade, this represents a genuine extension of the due diligence obligation. Compliance programmes built around screening counterparties against consolidated sanctions lists, without consideration of the end use of goods or services being financed or facilitated, are now structurally incomplete relative to the current legal framework.
The practical question for compliance teams is whether their customer and transaction due diligence processes, and the risk-based judgements embedded in them, have been updated to reflect end-use exposure. For many, the honest answer will be that this has been identified as a priority without the procedures having been updated to address it.
OFSI's revised enforcement framework in practice
OFSI's revised enforcement framework, introduced in February 2026 and already applied to its first enforcement conclusion involving Deutsche Bank, represents a meaningful change in how sanctions breaches will be assessed and penalised. The four-level seriousness matrix, the structured discount tiers for voluntary disclosure and settlement, and the fixed penalty regime for information and reporting offences together create an incentive structure that firms need to understand as a matter of management policy rather than leaving to the compliance function to navigate in isolation.
The 30% discount available for voluntary self-disclosure is not a modest incentive: over a penalty of any materiality it represents a significant financial difference. More importantly, firms that have established internal protocols for identifying, escalating and disclosing potential sanctions breaches promptly will be in a structurally better position than firms that discover breaches during regulatory review and respond reactively. Building those protocols, testing them, and ensuring that senior management and the board understand the voluntary disclosure framework and the time-sensitivity it implies, is a governance priority rather than a compliance function detail.
The Russia sanctions due diligence standard
The Russia (Sanctions) (EU Exit) Regulations 2019 remain the most enforcement-active sanctions instrument in the UK regime, as demonstrated by the Deutsche Bank penalty and the broader pattern of OFSI investigations. The due diligence expectations for Russia-exposed relationships continue to evolve, and firms that have not reviewed their Russia exposure, their due diligence procedures for Russia-connected counterparties and transactions, and their transaction monitoring parameters for Russia-related indicators since 2022 are operating with a potentially material gap.
Russia sanctions compliance is not adequately addressed by list screening alone. The combination of complex corporate structures designed to obscure Russian beneficial ownership, correspondent banking channels that have been identified in typologies as higher-risk routes for sanctions evasion, and the use of third-country intermediaries in trade transactions requires a more substantive analytical approach than screening against consolidated lists.
The FCA's supervisory consolidation
The FCA's forthcoming assumption of consolidated AML and sanctions supervisory responsibility for legal, accountancy and trust and company service provider sectors will bring a materially different supervisory intensity to firms currently supervised by bodies such as HMRC and the Legal Sector Affinity Group. The FCA's approach to sanctions supervision is more intervention-focused, more data-driven in its selection of firms for review, and more likely to result in enforcement action where weaknesses are identified than the approaches of predecessor supervisors in those sectors.
Professional services firms in scope for this change have a finite window in which to assess the gap between their current compliance frameworks and the standards the FCA will apply, and to make meaningful improvements before the FCA's active supervision begins. Waiting for the transition to occur before beginning that assessment is a reasonable description of the wrong approach.
What a current sanctions compliance programme needs to contain
A sanctions compliance programme adequate to the current environment needs to address five things that many existing programmes do not explicitly cover. It needs a clear policy on end-use controls and how they are applied in transaction and customer due diligence. It needs a documented voluntary disclosure protocol that has been approved by senior management and is understood across the compliance function. It needs Russia-specific due diligence procedures that go beyond list screening to address the typologies that characterise Russia-related sanctions evasion. It needs transaction monitoring parameters that have been reviewed and calibrated to current Russia and Ukraine sanctions risk indicators. And it needs a governance framework that ensures the board and senior management are informed of the firm's sanctions risk profile and significant compliance decisions, not insulated from them.
None of these is a new regulatory requirement in isolation, but the combination of them, applied consistently and evidenced in operational documentation, represents a sanctions compliance programme that is positioned for the environment that regulated firms now operate in rather than the one they were designed for.