Beneficiary Sanctions Rules: A Practical NGO Guide
An NGO can easily turn a sensible compliance question into the wrong operational rule. A donor asks about sanctions. A bank queries a transfer. Someone suggests screening every person who receives assistance. Before long, a food distribution list, a cash programme or a protection register is being treated as though every recipient were a commercial counterparty. That is not a sound starting point.
The
practical question is not simply, “Do we screen?” It is, “Who is this person or
organisation in the transaction, what are they receiving, which sanctions
regime actually applies, and is there a humanitarian exception?” A beneficiary
who receives food because she meets vulnerability criteria is not in the same
legal position as a transport company paid to deliver the food, an implementing
partner entrusted with programme funds, a landlord receiving rent, or a bank
carrying the payment. Treating all of them alike can produce both
under-compliance and over-compliance.
For
NGOs, the better approach is role-based and risk-based. Screening should follow
the legal and operational relationship, not become an automatic condition
imposed on every human being touched by a programme.
Why
“beneficiary” is the first word to define
NGOs
use the word beneficiary broadly. It may mean a household receiving emergency
food, a refugee receiving cash, a trainee receiving a travel allowance, a
community organisation receiving a subgrant, or even a local partner receiving
programme funds. Sanctions law does not necessarily treat these situations in
the same way.
A
final humanitarian beneficiary is ordinarily the person in need whom the
programme is designed to assist. An implementing partner, vendor or consultant
is different because the NGO is entering a contractual or financial
relationship with that party and transferring money, goods or economic value so
that the party can perform a function. A bank or money-transfer provider is
different again: it is part of the payment route. The classification matters
because sanctions commonly restrict making funds or economic resources
available to, or for the benefit of, designated persons or entities. The closer
a party is to controlling programme money, providing a paid service or acting
as an intermediary, the stronger the practical reason for sanctions due
diligence.
This
distinction is not merely an NGO preference. The European Commission’s 2022
guidance on humanitarian aid and EU restrictive measures expressly
distinguishes final beneficiaries from intermediaries. Its position is
unusually clear: persons in need receiving humanitarian aid should not be
vetted merely to determine whether they are designated, including where the
assistance is cash. The operator should instead be able to demonstrate that the
person was genuinely a person in need. By contrast, an intermediary receiving
funds or economic resources on the way to those beneficiaries may require
sanctions scrutiny because a designated intermediary can create a prohibited
transfer unless an exception applies.
The
United Nations framework has moved in the same direction. Security Council
Resolution 2664 of 2022 created a standing humanitarian exception to
asset-freeze measures across UN sanctions regimes for specified humanitarian
providers where funds, assets, goods or services are necessary for timely
humanitarian assistance or activities supporting basic human needs. Resolution
2761 of 2024 confirmed that the exception continues to apply to the ISIL and
Al-Qaida sanctions regime. The point is important for NGOs: sanctions
compliance is not supposed to be read as a command to stop life-sustaining
assistance whenever a designated person may be among people in need.
When
screening is more likely to be required
There
are situations in which screening is legally or contractually important. An NGO
must first identify the legal regimes that actually reach it. That may depend
on where the NGO is incorporated, where staff and operations are located, the
nationality of persons involved, the country through which a transaction
passes, the bank and payment network used, and the sanctions rules implemented
in the country of operation. A donor agreement can add a contractual obligation
even where the donor’s preferred screening standard is not itself local law.
The
United Kingdom’s Office of Financial Sanctions Implementation, in guidance
updated in January 2026, tells charities and NGOs to use a risk-based approach,
understand the sanctions regimes relevant to their activities and maintain
proportionate compliance programmes. It also reminds them that sanctions
imposed by other countries may matter where operations fall within another
jurisdiction, goods originate there, or a transaction involves that country’s
financial system. OFSI does not prescribe one universal screening method for
every NGO activity.
The
United States takes a similarly risk-based compliance approach. OFAC’s
Framework for Compliance Commitments recommends that organisations assess their
exposure by looking at customers, counterparties, intermediaries, products,
services and geography. The practical lesson is that an NGO should not start by
buying screening software and then decide whom to screen. It should first map
where a sanctions prohibition could arise.
Local
law also matters. In Kenya, the Prevention of Terrorism framework and the 2024
regulations implementing relevant UN Security Council resolutions provide a
domestic structure for targeted financial sanctions, while the Financial
Reporting Centre continues to circulate targeted financial sanctions notices.
An NGO operating in Kenya should therefore not assume that checking only a
foreign donor’s list is enough. The correct list and legal consequence must be
determined from the law that applies to the organisation and the transaction.
Vendors,
implementing partners and other counterparties
Vendors
are usually an obvious screening priority because they receive payment. The
same is true of consultants, transporters, landlords, security providers,
cash-transfer companies and other service providers. Screening should not be
reduced to typing the entity’s name into one list. For a legal person, the NGO
may need to consider ownership and control, because a company that is not
itself named can still present sanctions risk if it is owned or controlled by a
designated person under the applicable regime.
Implementing
partners deserve equally careful treatment. They may receive substantial funds,
procure goods, select downstream vendors and make payments on the NGO’s behalf.
A reasonable file should therefore identify the partner, verify its legal
existence, understand its leadership and ownership or control where relevant,
examine the proposed payment route, check applicable sanctions lists and record
any red flags. The depth of this work should rise with the risk. A
long-standing local organisation receiving a small restricted grant in a
low-risk setting does not necessarily call for the same level of due diligence
as a newly formed intermediary moving large sums in an area controlled by a
sanctioned armed group.
The
Financial Action Task Force’s 2023 Best Practices paper on Recommendation 8
supports this proportionality. FATF states that higher-risk NPOs may conduct
targeted screening of beneficial owners of partners and staff using domestic
and UN sanctions lists, but says any sanctions screening should be targeted and
proportionate and should not result in the undue exclusion of beneficiaries.
FATF’s later work has continued to emphasise focused and proportionate measures
and to address the unintended consequences that can arise when standards
designed to prevent terrorist financing are over-applied to legitimate civil
society.
Canada’s
2026 sanctions guidance for the humanitarian sector makes the distinction even
more practical. It says the purpose of sanctions-screening due diligence is not
to deny humanitarian assistance to final beneficiaries. It directs screening
attention toward intermediaries who may receive funds, goods or services,
including implementing partners, consultants, suppliers, logistics providers
and subcontracted staff. That is a useful operational model even for an NGO
that is not subject to Canadian law: follow the money and the control over
resources before treating the person in need as the primary sanctions risk.
Banks
are part of the route, not final beneficiaries
A
bank should not be confused with a beneficiary. It is a financial intermediary
with its own sanctions and anti-money-laundering obligations. The NGO’s task is
to understand the route by which its money will move, whether any bank or
payment provider is subject to relevant restrictions, and whether the
transaction requires a licence, exemption or additional information.
This
is also why a bank may ask an NGO questions that appear broader than the NGO’s
own screening policy. The bank is managing its own legal risk and may need to
understand the donor, destination, local partner, payment purpose and
counterparties before processing a transfer. A good NGO response is not to hand
over an entire beneficiary database. It is to provide the information necessary
to explain the transaction, the applicable humanitarian exception where
relevant, the NGO’s due diligence on intermediaries and the controls used to
prevent diversion.
Where
an NGO uses hawala, mobile money, cash agents or other alternative payment
routes, the same principle applies with more care. OFSI’s current charity and
NGO guidance advises organisations using informal value transfer systems to
assess partners, contractors and financial institutions involved in the payment
route. That is more useful than screening every recipient simply because the
formal banking route is difficult.
Why
blanket beneficiary screening can cause harm
Screening
is not a neutral administrative act. It requires data. To distinguish a genuine
sanctions match from a person with a similar name, an organisation may need a
date of birth, nationality, identity number, address or other identifiers. OFAC
itself warns that a name match may be a false hit and recommends comparing
additional identifying information before treating it as a valid match. This
matters greatly in humanitarian settings, where spelling variations,
transliteration, incomplete identity documents and common names can produce
misleading results.
Collecting
more personal data creates a second legal problem: the NGO must justify why it
needs that data and how it will protect it. The ICRC’s Handbook on Data
Protection in Humanitarian Action treats personal-data protection as part of
protecting life, integrity and dignity. East African data-protection laws point
in the same practical direction. Kenya’s Data Protection Act requires lawful,
fair and transparent processing and limits collection to data that is adequate,
relevant and necessary for the purpose. Rwanda’s Law No. 058/2021 requires
personal data to be collected for explicit and legitimate purposes, related to
those purposes and retained no longer than necessary. Uganda’s Data Protection
and Privacy Act regulates the collection, use and disclosure of personal data
and applies to organisations processing personal data in Uganda.
An
NGO that screens every beneficiary “just in case” may therefore create a
database it cannot properly justify. If the screening service is cloud-based or
operated outside the country, cross-border transfer rules may also become
relevant. If a false positive is handled carelessly, a vulnerable person could
be denied food, cash or medical support on the basis of a name similarity that
was never properly investigated. If communities learn that registration for aid
involves checking names against terrorism or sanctions lists, trust may
collapse and people may avoid assistance altogether.
There
is also a protection risk. A beneficiary list may reveal displacement status,
ethnicity, family composition, location, disability, health information or
economic vulnerability. Adding sanctions-screening data to that file can
increase the consequences of unauthorised access, sharing or seizure. The
compliance question should therefore include not only “Can we screen?” but
“What additional data would screening require, who would receive it, how long
would it be kept, and what harm could follow if it were wrong or exposed?”
A
practical decision rule for NGOs
The
most defensible policy is not “screen everyone” or “screen no one.” It is a
written decision rule that separates categories.
For
a final beneficiary receiving humanitarian assistance because of assessed need,
the NGO should first check whether the applicable sanctions regime contains a
humanitarian exception or non-vetting principle. Where it does, the
organisation should document the needs-based eligibility process rather than
automatically screen the person. It should also confirm whether a donor clause
attempts to impose broader screening and, if so, obtain legal review before
accepting a condition that may conflict with the applicable humanitarian
framework, data-protection duties or the organisation’s own principled-action
policy.
For
an implementing partner, vendor, consultant, landlord, bank, money-transfer
provider or other intermediary that will receive or control funds or economic
resources, sanctions due diligence is generally more appropriate. The NGO
should identify which list applies, screen at the stage when the relationship
is being established, assess ownership and control where relevant, investigate
potential matches rather than treating software alerts as findings, and
re-screen when the risk changes or the applicable list is updated.
The
file should explain the reasoning. It should record why a category was
screened, why another category was not, which legal regime was considered, what
humanitarian exception was relied on, what donor clause was reviewed, what data
was collected and how a possible match would be escalated. That record is more
valuable than a spreadsheet containing thousands of names with no explanation
of why they were checked.
The
deeper point is that sanctions compliance should protect humanitarian work from
unlawful diversion without converting people in need into suspects.
International practice is increasingly explicit about that balance. UN
humanitarian exceptions, European Commission guidance, FATF’s proportionality
language and current national guidance all point away from indiscriminate
screening and toward a more disciplined question: where, in this particular
programme, does money or economic value create a real sanctions exposure?
For
an NGO, that question is both legally safer and operationally fairer. Screen
the relationship that creates the risk. Protect the person whose need creates
the mission.
Source
note. This article is based on United Nations Security Council Resolutions 2664
(2022) and 2761 (2024); the European Commission, Guidance Note on the Provision
of Humanitarian Aid in Compliance with EU Restrictive Measures (2022); the
Financial Action Task Force, Best Practices: Combating the Terrorist Financing
Abuse of Non-Profit Organisations, Recommendation 8 (2023), together with
FATF’s subsequent work on proportionality and unintended consequences; the UK
Office of Financial Sanctions Implementation, Financial Sanctions Guidance for
Charities and Non-Governmental Organisations, updated 28 January 2026; the US
Office of Foreign Assets Control, A Framework for OFAC Compliance Commitments
and its guidance on assessing sanctions-list matches; Global Affairs Canada,
Canadian Sanctions Guidance: Humanitarian Sector (2026); the ICRC, Handbook on
Data Protection in Humanitarian Action; Kenya’s Data Protection Act 2019 and
Prevention of Terrorism targeted-financial-sanctions framework; Rwanda’s Law No.
058/2021 relating to the Protection of Personal Data and Privacy; and Uganda’s
Data Protection and Privacy Act 2019. Foreign guidance is used comparatively
and should not be treated as locally binding unless the relevant jurisdictional
connection exists.
Suggested citation:
Ronald Serwanga, “Beneficiary Sanctions Rules: A Practical NGO Guide” East Africa Legal Insight (4 September 2026).