Guides
Aug 25, 2026

Free Crypto Sanctions Screening: What It Covers and Where It Fails

Free crypto sanctions screening tools exist and have real uses. Here is what they actually check, the four gaps that make them unusable as a compliance control, and when to upgrade.

Free Crypto Sanctions Screening: What It Covers and Where It Fails

Free sanctions screening tools are a reasonable search. Screening is a legal obligation with no minimum revenue threshold, and an early-stage team with no budget still has to do it. So what can you actually get for nothing, and where does it stop being enough?

What free tools genuinely do

Several useful free resources exist:

  • Official list lookups. OFAC's SDN search, the EU consolidated list and the UN list are all publicly searchable, free, and authoritative. For a one-off check on a name or a wallet address published on a list, they are the primary source.
  • Free address checkers. Some blockchain analytics vendors expose a limited lookup that tells you whether an address appears on a sanctions list or has direct exposure to one.
  • Open-source datasets. Aggregated sanctions data is published in machine-readable form and can be self-hosted.

For a genuinely pre-revenue team doing occasional manual checks, this is a legitimate starting point. It is better than nothing, and "nothing" is the actual alternative for a lot of early projects.

The four gaps that break it

1. No continuous re-screening

This is the big one. Sanctions lists change constantly. A customer who cleared at onboarding may be designated three months later, and the obligation is to know. Free tools give you a point-in-time answer. Compliance requires a standing one — every customer re-screened against every list update, automatically, with a record.

Manually re-checking a book of 2,000 customers each time OFAC updates is not a process anyone sustains.

2. No fuzzy matching

Real screening has to catch transliteration variants, name ordering, nicknames and deliberate misspellings. "Mohammed" versus "Muhammad", surname-first conventions, and Cyrillic transliteration all defeat exact-match lookups. Commercial engines score partial matches and let you tune the threshold; free lookups return a match or nothing.

An exact-match-only control creates the illusion of screening while missing the cases most likely to matter.

3. No indirect exposure

A wallet is rarely on a list itself. What matters is whether funds reached it through a sanctioned entity two or three hops back. That requires clustering and attribution data, which is precisely the expensive part of the product. Free address checkers typically flag direct designation only.

4. No audit trail

Even if you catch everything, you cannot prove it. Supervisors ask for evidence of who was screened, against which list version, on what date, with what result and what decision followed. A browser search leaves no record. This alone fails an inspection regardless of how diligent the underlying work was.

A defensible interim process when there is genuinely no budget

If the choice is between a documented manual process and nothing, run the manual process. Regulators are considerably more sympathetic to a small firm with a modest, evidenced control than to one that skipped the obligation because tooling was expensive. What makes it defensible is the record, not the sophistication.

A minimum viable process looks like this:

  • A written procedure. One page stating which lists you check, who checks them, at what points, and what happens on a hit.
  • A screening log. One row per customer per check: name screened, lists checked, date, result, who ran it. A spreadsheet is acceptable. An empty spreadsheet is not.
  • A re-screening calendar. A recurring task to re-run the standing book against current lists. Monthly is a reasonable floor at low volume.
  • An escalation path. A named person who decides on a hit, and a rule that they document the reasoning either way.
  • Retention. Keep the log, including negative results, for your jurisdiction's retention period.

This process breaks at a volume you can predict in advance — roughly the point where re-screening the book takes longer than a working day. Plan the upgrade before you hit it rather than after.

What screening has to cover beyond names

Free tools tend to answer one question: is this name or address on a list? Real obligations are broader, and the gaps are where enforcement actually lands.

  • Indirect exposure. An address that is not itself designated may have received funds from one two hops ago. Direct-match tools return clean. Analytics tools score the exposure. This distinction is the substance of most crypto sanctions enforcement.
  • Ownership and control. Sanctions extend to entities owned or controlled by designated persons, commonly at a 50% threshold, even when the entity itself is not listed. Detecting that requires ownership data, not a name lookup.
  • Jurisdictional exposure. Comprehensive country programmes prohibit dealings with entire jurisdictions regardless of whether a specific party is named.
  • Counterparty screening. Under travel-rule obligations you may need to assess the receiving institution, not only the customer. See the travel rule for how that interacts.

None of these are available in a free list lookup, and none of them are optional at scale.

The honest threshold

Free tools are defensible while you have no customers. The moment you onboard third parties and hold their assets, you need screening that is continuous, fuzzy-matched, exposure-aware and logged. That is not a vendor upsell, it is what the obligation actually says.

The practical trigger points:

  • You are onboarding customers rather than testing with your own funds
  • You are preparing a licence application — the file will be assessed on this
  • You have banking relationships that ask about your controls
  • Your customer count has passed the point where manual re-screening is realistic (in practice, low hundreds)

What getting it wrong actually costs

Sanctions breaches are strict liability in most regimes. Intent is not a defence, and neither is a good-faith attempt with an inadequate tool. Penalties are assessed per violation, which for a payments or exchange business can mean per transaction — the arithmetic escalates quickly from a book of customers screened once and never again.

The secondary costs usually bite sooner than the fine. Banking partners run their own diligence on your compliance stack, and an undocumented screening process is a common reason for a correspondent relationship to be declined or withdrawn. Licence applications ask directly what you screen against and how. A free-tool answer will not clear a CASP file — see CASP licence cost for how the compliance stack is assessed.

What to move to

When you upgrade, the questions that matter are list coverage and refresh frequency, fuzzy-match tuning, indirect exposure depth, chain coverage for the networks you actually settle on, and the quality of the audit export. We compare the options in best sanctions screening software for crypto exchanges.

Screening is one control among several. It pairs with ongoing behavioural monitoring — see crypto transaction monitoring software — and with identity checks at onboarding, covered in best crypto KYC providers. Screening beyond sanctions into PEP and adverse media is set out in watchlist and PEP screening explained.

One thing not to do

Do not build a partial in-house solution on free datasets and describe it to a regulator as a screening programme. Self-hosting sanctions data is legitimate engineering, but without fuzzy matching, continuous re-screening and an audit trail it will be assessed as inadequate — and having built something makes the gap look deliberate rather than resource-constrained.

If budget is the constraint, say so and document a dated plan to close it. Supervisors deal with that far better than with a control that looks complete and is not.

For the full programme view, see our crypto AML compliance guide for exchanges and VASPs.

Frequently asked questions

Is free sanctions screening legal to rely on?

There is no rule prohibiting free tools, and official list lookups from OFAC, the EU and the UN are authoritative sources. What matters is whether your overall control meets the obligation: continuous re-screening, fuzzy matching, indirect exposure and a retained audit trail. A free point-in-time lookup does not meet that on its own, regardless of the quality of the underlying list.

What is the single biggest gap in free tools?

The absence of continuous re-screening. Lists change constantly, and a customer who cleared at onboarding may be designated months later while remaining an active customer. A point-in-time check answers a question the obligation does not ask.

Are official OFAC and EU list searches good enough for a one-off check?

Yes — for a genuine one-off, they are the primary source and better than any intermediary. The limitation is exact-ish matching: they will not reliably catch transliteration variants, and they cannot tell you about indirect on-chain exposure. Use them for what they are good at.

At what point do I have to upgrade?

Three practical triggers: when re-screening your book manually no longer fits in a working day; when you take on a regulated obligation such as a CASP or VASP authorisation; or when a banking partner asks to review your screening process. Any one of these means the manual process has reached its limit.

Does screening a wallet address replace screening the customer?

No. They cover different risks and both are usually required. Name screening catches designated persons; address screening catches designated or exposed on-chain counterparties. See watchlist and PEP screening for how the screening types divide up.

What should I never do?

Screen once at onboarding, keep no record, and assume the obligation is discharged. That is the exact fact pattern that produces enforcement — not because the tool was free, but because there was no evidence the control ever ran.

About the author.

Co-Founder at JewelSwap & CMO at iDenfy. Viktor brings his successful track record of superb development & project management.