Sanctions & Compliance

Secondary sanctions exposure: the risk small businesses miss.

Sanctions used to feel like a problem for big banks. They aren't. In 2026, the smallest businesses can quietly accumulate exposure through ordinary vendors, intermediaries, and payment paths. Most of it is preventable with a short, disciplined screening pass.

2 June 2026·7 min read·By KYA Axiom

The conversation about sanctions has changed shape. Two things moved at once: enforcement actions are now reaching far smaller entities than they used to, and the lists themselves have grown — OFAC, the EU restrictive measures regime, the UK consolidated list, and a widening secondary-sanctions perimeter that touches counterparties of counterparties.

The result is that an SMB can be functionally exposed without ever touching a sanctioned name directly. Exposure now leaks in sideways — through a software vendor's data processor in a third country, through a logistics provider's sub-contractor, through a payment route that goes via a correspondent bank in a jurisdiction now under scrutiny.

Where SMBs typically get caught

Downstream vendors

The vendor you onboard is clean. Their sub-processor is not. The contract you signed says nothing about sub-processors, and you have no visibility into the chain.

Payment routes

An overseas supplier asks for payment via a third-country intermediary "for convenience". The intermediary is in a jurisdiction increasingly used to mask transfers from sanctioned regions. The funds you wire are technically going to your supplier; functionally, they are entering a chain you cannot trace.

Investors and acquirers

A friendly capital introduction surfaces a fund whose limited partners are not disclosed. Two years later, the fund's investor base becomes the subject of a public news cycle. Your cap table is now part of that cycle.

Reputational adjacency

You haven't violated a sanction. You've appeared next to one in a public list, a news article, or a regulatory letter. The financial consequences of the adjacency are often almost identical to the consequences of the violation itself — bank accounts slow, investors pull, customers ask awkward questions.

The shape of sanctions risk has stopped being "did you do business with a listed name?" and started being "what does your supplier's supplier look like, and can you tell?"

A starter screening checklist

For SMBs without an in-house compliance team, a basic screening pass at onboarding closes a surprising amount of exposure. None of this is exotic — it is just rarely done in order.

  1. Screen the counterparty against the three big lists. OFAC SDN, EU consolidated, UK consolidated. Free official sources are enough for a first pass.
  2. Screen the beneficial owners, not just the entity. Many hits sit on the human, not the company.
  3. Screen the addresses. A shared address with a flagged entity is a clue worth chasing.
  4. Check the payment path. Where does your money actually go? Through which banks, in which jurisdictions?
  5. Capture the date and source of each check. A check you can't reproduce later is half a check.
  6. Re-screen at renewal. Lists move. Counterparties move. A clean check in 2024 is not a clean check in 2026.
What we'd add in a Vendor & Supplier Review

Beyond the list checks, we look for adverse media, ownership-chain anomalies, jurisdictional drift in payment routes, and contract gaps that leave you exposed to sub-processor risk. The output is a vendor file with a one-page risk summary — usable for procurement, banking, and audit conversations alike.

The honest limit

No screening pass is a guarantee. Lists are incomplete and sometimes out of date. Beneficial ownership records vary in quality by jurisdiction. The point of the exercise is not certainty. The point is to identify what is checkable, check it, and write down what you couldn't verify — so that the residual risk is at least visible.

That visibility, more than anything else, is what banks, investors, and regulators are now looking for in an SMB compliance posture. Not perfection. A demonstrable, repeatable, documented process.

Need a sanctions and integrity pass on a new vendor?

Tell us the entity, the geography, and the contract value. We'll scope a Vendor & Supplier Review and tell you what we can check and what we can't — before you sign.