Beneficiary Sanctions Rules: A Practical NGO Guide

An NGO can easily turn a sensible compliance question into the wrong operational rule. A donor asks about sanctions. A bank queries a transfer. Someone suggests screening every person who receives assistance. Before long, a food distribution list, a cash programme or a protection register is being treated as though every recipient were a commercial counterparty. That is not a sound starting point.

The practical question is not simply, “Do we screen?” It is, “Who is this person or organisation in the transaction, what are they receiving, which sanctions regime actually applies, and is there a humanitarian exception?” A beneficiary who receives food because she meets vulnerability criteria is not in the same legal position as a transport company paid to deliver the food, an implementing partner entrusted with programme funds, a landlord receiving rent, or a bank carrying the payment. Treating all of them alike can produce both under-compliance and over-compliance.

For NGOs, the better approach is role-based and risk-based. Screening should follow the legal and operational relationship, not become an automatic condition imposed on every human being touched by a programme.

Why “beneficiary” is the first word to define

NGOs use the word beneficiary broadly. It may mean a household receiving emergency food, a refugee receiving cash, a trainee receiving a travel allowance, a community organisation receiving a subgrant, or even a local partner receiving programme funds. Sanctions law does not necessarily treat these situations in the same way.

A final humanitarian beneficiary is ordinarily the person in need whom the programme is designed to assist. An implementing partner, vendor or consultant is different because the NGO is entering a contractual or financial relationship with that party and transferring money, goods or economic value so that the party can perform a function. A bank or money-transfer provider is different again: it is part of the payment route. The classification matters because sanctions commonly restrict making funds or economic resources available to, or for the benefit of, designated persons or entities. The closer a party is to controlling programme money, providing a paid service or acting as an intermediary, the stronger the practical reason for sanctions due diligence.

This distinction is not merely an NGO preference. The European Commission’s 2022 guidance on humanitarian aid and EU restrictive measures expressly distinguishes final beneficiaries from intermediaries. Its position is unusually clear: persons in need receiving humanitarian aid should not be vetted merely to determine whether they are designated, including where the assistance is cash. The operator should instead be able to demonstrate that the person was genuinely a person in need. By contrast, an intermediary receiving funds or economic resources on the way to those beneficiaries may require sanctions scrutiny because a designated intermediary can create a prohibited transfer unless an exception applies.

The United Nations framework has moved in the same direction. Security Council Resolution 2664 of 2022 created a standing humanitarian exception to asset-freeze measures across UN sanctions regimes for specified humanitarian providers where funds, assets, goods or services are necessary for timely humanitarian assistance or activities supporting basic human needs. Resolution 2761 of 2024 confirmed that the exception continues to apply to the ISIL and Al-Qaida sanctions regime. The point is important for NGOs: sanctions compliance is not supposed to be read as a command to stop life-sustaining assistance whenever a designated person may be among people in need.

When screening is more likely to be required

There are situations in which screening is legally or contractually important. An NGO must first identify the legal regimes that actually reach it. That may depend on where the NGO is incorporated, where staff and operations are located, the nationality of persons involved, the country through which a transaction passes, the bank and payment network used, and the sanctions rules implemented in the country of operation. A donor agreement can add a contractual obligation even where the donor’s preferred screening standard is not itself local law.

The United Kingdom’s Office of Financial Sanctions Implementation, in guidance updated in January 2026, tells charities and NGOs to use a risk-based approach, understand the sanctions regimes relevant to their activities and maintain proportionate compliance programmes. It also reminds them that sanctions imposed by other countries may matter where operations fall within another jurisdiction, goods originate there, or a transaction involves that country’s financial system. OFSI does not prescribe one universal screening method for every NGO activity.

The United States takes a similarly risk-based compliance approach. OFAC’s Framework for Compliance Commitments recommends that organisations assess their exposure by looking at customers, counterparties, intermediaries, products, services and geography. The practical lesson is that an NGO should not start by buying screening software and then decide whom to screen. It should first map where a sanctions prohibition could arise.

Local law also matters. In Kenya, the Prevention of Terrorism framework and the 2024 regulations implementing relevant UN Security Council resolutions provide a domestic structure for targeted financial sanctions, while the Financial Reporting Centre continues to circulate targeted financial sanctions notices. An NGO operating in Kenya should therefore not assume that checking only a foreign donor’s list is enough. The correct list and legal consequence must be determined from the law that applies to the organisation and the transaction.

Vendors, implementing partners and other counterparties

Vendors are usually an obvious screening priority because they receive payment. The same is true of consultants, transporters, landlords, security providers, cash-transfer companies and other service providers. Screening should not be reduced to typing the entity’s name into one list. For a legal person, the NGO may need to consider ownership and control, because a company that is not itself named can still present sanctions risk if it is owned or controlled by a designated person under the applicable regime.

Implementing partners deserve equally careful treatment. They may receive substantial funds, procure goods, select downstream vendors and make payments on the NGO’s behalf. A reasonable file should therefore identify the partner, verify its legal existence, understand its leadership and ownership or control where relevant, examine the proposed payment route, check applicable sanctions lists and record any red flags. The depth of this work should rise with the risk. A long-standing local organisation receiving a small restricted grant in a low-risk setting does not necessarily call for the same level of due diligence as a newly formed intermediary moving large sums in an area controlled by a sanctioned armed group.

The Financial Action Task Force’s 2023 Best Practices paper on Recommendation 8 supports this proportionality. FATF states that higher-risk NPOs may conduct targeted screening of beneficial owners of partners and staff using domestic and UN sanctions lists, but says any sanctions screening should be targeted and proportionate and should not result in the undue exclusion of beneficiaries. FATF’s later work has continued to emphasise focused and proportionate measures and to address the unintended consequences that can arise when standards designed to prevent terrorist financing are over-applied to legitimate civil society.

Canada’s 2026 sanctions guidance for the humanitarian sector makes the distinction even more practical. It says the purpose of sanctions-screening due diligence is not to deny humanitarian assistance to final beneficiaries. It directs screening attention toward intermediaries who may receive funds, goods or services, including implementing partners, consultants, suppliers, logistics providers and subcontracted staff. That is a useful operational model even for an NGO that is not subject to Canadian law: follow the money and the control over resources before treating the person in need as the primary sanctions risk.

Banks are part of the route, not final beneficiaries

A bank should not be confused with a beneficiary. It is a financial intermediary with its own sanctions and anti-money-laundering obligations. The NGO’s task is to understand the route by which its money will move, whether any bank or payment provider is subject to relevant restrictions, and whether the transaction requires a licence, exemption or additional information.

This is also why a bank may ask an NGO questions that appear broader than the NGO’s own screening policy. The bank is managing its own legal risk and may need to understand the donor, destination, local partner, payment purpose and counterparties before processing a transfer. A good NGO response is not to hand over an entire beneficiary database. It is to provide the information necessary to explain the transaction, the applicable humanitarian exception where relevant, the NGO’s due diligence on intermediaries and the controls used to prevent diversion.

Where an NGO uses hawala, mobile money, cash agents or other alternative payment routes, the same principle applies with more care. OFSI’s current charity and NGO guidance advises organisations using informal value transfer systems to assess partners, contractors and financial institutions involved in the payment route. That is more useful than screening every recipient simply because the formal banking route is difficult.

Why blanket beneficiary screening can cause harm

Screening is not a neutral administrative act. It requires data. To distinguish a genuine sanctions match from a person with a similar name, an organisation may need a date of birth, nationality, identity number, address or other identifiers. OFAC itself warns that a name match may be a false hit and recommends comparing additional identifying information before treating it as a valid match. This matters greatly in humanitarian settings, where spelling variations, transliteration, incomplete identity documents and common names can produce misleading results.

Collecting more personal data creates a second legal problem: the NGO must justify why it needs that data and how it will protect it. The ICRC’s Handbook on Data Protection in Humanitarian Action treats personal-data protection as part of protecting life, integrity and dignity. East African data-protection laws point in the same practical direction. Kenya’s Data Protection Act requires lawful, fair and transparent processing and limits collection to data that is adequate, relevant and necessary for the purpose. Rwanda’s Law No. 058/2021 requires personal data to be collected for explicit and legitimate purposes, related to those purposes and retained no longer than necessary. Uganda’s Data Protection and Privacy Act regulates the collection, use and disclosure of personal data and applies to organisations processing personal data in Uganda.

An NGO that screens every beneficiary “just in case” may therefore create a database it cannot properly justify. If the screening service is cloud-based or operated outside the country, cross-border transfer rules may also become relevant. If a false positive is handled carelessly, a vulnerable person could be denied food, cash or medical support on the basis of a name similarity that was never properly investigated. If communities learn that registration for aid involves checking names against terrorism or sanctions lists, trust may collapse and people may avoid assistance altogether.

There is also a protection risk. A beneficiary list may reveal displacement status, ethnicity, family composition, location, disability, health information or economic vulnerability. Adding sanctions-screening data to that file can increase the consequences of unauthorised access, sharing or seizure. The compliance question should therefore include not only “Can we screen?” but “What additional data would screening require, who would receive it, how long would it be kept, and what harm could follow if it were wrong or exposed?”

A practical decision rule for NGOs

The most defensible policy is not “screen everyone” or “screen no one.” It is a written decision rule that separates categories.

For a final beneficiary receiving humanitarian assistance because of assessed need, the NGO should first check whether the applicable sanctions regime contains a humanitarian exception or non-vetting principle. Where it does, the organisation should document the needs-based eligibility process rather than automatically screen the person. It should also confirm whether a donor clause attempts to impose broader screening and, if so, obtain legal review before accepting a condition that may conflict with the applicable humanitarian framework, data-protection duties or the organisation’s own principled-action policy.

For an implementing partner, vendor, consultant, landlord, bank, money-transfer provider or other intermediary that will receive or control funds or economic resources, sanctions due diligence is generally more appropriate. The NGO should identify which list applies, screen at the stage when the relationship is being established, assess ownership and control where relevant, investigate potential matches rather than treating software alerts as findings, and re-screen when the risk changes or the applicable list is updated.

The file should explain the reasoning. It should record why a category was screened, why another category was not, which legal regime was considered, what humanitarian exception was relied on, what donor clause was reviewed, what data was collected and how a possible match would be escalated. That record is more valuable than a spreadsheet containing thousands of names with no explanation of why they were checked.

The deeper point is that sanctions compliance should protect humanitarian work from unlawful diversion without converting people in need into suspects. International practice is increasingly explicit about that balance. UN humanitarian exceptions, European Commission guidance, FATF’s proportionality language and current national guidance all point away from indiscriminate screening and toward a more disciplined question: where, in this particular programme, does money or economic value create a real sanctions exposure?

For an NGO, that question is both legally safer and operationally fairer. Screen the relationship that creates the risk. Protect the person whose need creates the mission.

Source note. This article is based on United Nations Security Council Resolutions 2664 (2022) and 2761 (2024); the European Commission, Guidance Note on the Provision of Humanitarian Aid in Compliance with EU Restrictive Measures (2022); the Financial Action Task Force, Best Practices: Combating the Terrorist Financing Abuse of Non-Profit Organisations, Recommendation 8 (2023), together with FATF’s subsequent work on proportionality and unintended consequences; the UK Office of Financial Sanctions Implementation, Financial Sanctions Guidance for Charities and Non-Governmental Organisations, updated 28 January 2026; the US Office of Foreign Assets Control, A Framework for OFAC Compliance Commitments and its guidance on assessing sanctions-list matches; Global Affairs Canada, Canadian Sanctions Guidance: Humanitarian Sector (2026); the ICRC, Handbook on Data Protection in Humanitarian Action; Kenya’s Data Protection Act 2019 and Prevention of Terrorism targeted-financial-sanctions framework; Rwanda’s Law No. 058/2021 relating to the Protection of Personal Data and Privacy; and Uganda’s Data Protection and Privacy Act 2019. Foreign guidance is used comparatively and should not be treated as locally binding unless the relevant jurisdictional connection exists.

Suggested citation: 

Ronald Serwanga, “Beneficiary Sanctions Rules: A Practical NGO Guide” East Africa Legal Insight (4 September 2026).