TRAFEED

Sanctions and Restricted-Party Lists Explained — OFAC SDN, BIS Entity List, and Japan’s Foreign End User List (2026)

Published2026-04-24Updated2026-08-09Ryuta Hamamoto

Five screening families compared: OFAC SDN, BIS Entity List and related lists, and Japan's FEUL. How to run dual-jurisdiction checks without mixing list logic.

Sanctions and Restricted-Party Lists Explained — OFAC SDN, BIS Entity List, and Japan’s Foreign End User List (2026)
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

If you work export control, trade finance, or economic security, sanctions and restricted-party lists are no longer a specialty corner of the bank. They are part of ordinary B2B shipping. This piece is a field map of the list families I see companies actually need, written for teams that have to screen both U.S. and Japanese exposure.

Since early 2026, OFAC has continued to replace Russia-related general licenses, BIS has kept adding semiconductor-related and diversion-related parties to the Entity List, and the United Kingdom stopped updating its OFSI consolidated list on January 28 and moved to a single UK Sanctions List. On the Japanese side, METI expanded the Foreign End User List to 835 entities in the revision effective October 9, 2025. Watching one list and calling the job done is no longer a serious control. Below is how to read each major family, how they differ, and how to build a cross-list screening workflow that still works when the designated person is on leave.

Turn this screening flow into a written procedure: A fill-in procedure sheet for the five systems covered here (U.S. OFAC, U.S. BIS, EU, UK, UN) plus Japan’s Foreign End User List — which official source to check, how often, and against what. The 50% and ownership-control tests and Red Flags are included as fields. → Download the Five Sanctions-List Systems Screening Procedure (2026) (Free. Company name and work email required.)

Why multi-list screening became a board issue

Ten years ago, deep sanctions screening was mostly a job for major banks, a subset of trading houses, and defense-adjacent firms. Russia’s full-scale invasion of Ukraine in 2022 and the G7 and EU wartime sanctions packages that followed pulled ordinary dual-use goods into the perimeter: semiconductors, CNC machine tools, bearings, EV battery materials, drone components, industrial software, and financial services.

Payment rails matter as much as packing lists. Dollar transfers touch U.S. financial infrastructure. Euro transfers touch the EU. Sterling and insurance markets touch the UK. One hit freezes the deal even if the commercial contract is clean. Add OFAC secondary sanctions, EU anti-circumvention clauses, UK extraterritorial reach in some regimes, and Japan’s FEFTA international-commitment provisions, and a domestic yen contract between two non-U.S. companies can still trip foreign lists depending on counterparty, destination, and end use.

The operational pain is structural. There is no single global master list. On the U.S. side alone you have SDN, Entity List, Denied Persons List, Unverified List, Military End-User List, and Section 1260H-related China military-company lists, each with a different legal job. The EU maintains sanctions through many regulations and annexes. The UK is mid-migration to a single list. Japan runs its own Foreign End User List plus catch-all controls. Manual tracking does not scale. Screening design is now a management system question, not a junior checklist.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

OFAC’s SDN List: the financial core

SDN means Specially Designated Nationals and Blocked Persons. It is the flagship financial sanctions list run by the Treasury Department’s Office of Foreign Assets Control. Assets of listed parties in the United States are blocked. U.S. persons are generally prohibited from dealing with them. Several programs also create secondary-sanctions risk for non-U.S. companies that knowingly facilitate significant transactions with designated parties. A third-country company can itself become an SDN target.

The practical force of the SDN is its link to dollar clearing. Trade finance still routes heavily through correspondent banks that clear in New York. A transfer involving an SDN party often has nowhere to go. Japanese megabanks and regional banks are not exceptions. Letting an SDN-linked payment through creates U.S. regulatory exposure, so banks bounce transfers when identification or corporate registration looks off. A perfect export contract with no collectible payment is not a deal.

OFAC stayed active in 2026. On April 17, 2026 it issued General License 134B for certain Russia-related transactions, conditionally allowing handling of Russian crude and oil products already in transit and fine-tuning EO 14024-based operations. In the weeks before mid-March it also delisted names. Entries enter and exit. Operations need a daily or near-daily habit of reading Recent Actions and Federal Register notices against counterparties, affiliates, and end users.

The easy-to-miss rule is the 50% rule. Any entity owned 50% or more, directly or indirectly, by one or more blocked persons is itself treated as blocked even if the name is not printed on the SDN List. Without ownership and beneficial-owner data, name-only screening fails by design. If you want a quick interactive feel for ownership aggregation in a related BIS context, our free BIS 50% rule check is a useful teaching tool. Final legal calls still belong to your compliance officer and the latest official text.

BIS lists: Entity List, Denied Persons, Unverified

Goods and technology flows under the EAR are policed by the Bureau of Industry and Security. The best-known list is the Entity List, which identifies foreign parties of national-security or foreign-policy concern and imposes license requirements on exports, reexports, and transfers of items subject to the EAR. Many entries carry a policy of denial. In commercial terms that often functions like a de facto embargo for EAR items, even when the party remains active in ordinary commerce.

Entity List activity accelerated in recent years. On December 2, 2024, Commerce added 140 entities in a single action centered on semiconductor manufacturing equipment fields. That action is a change in licensing treatment under the EAR. It is not, by itself, a finding that each listed company committed a commercial crime. Listed parties can include local commercial equipment makers and China operations of multinational groups. Legitimate commercial businesses get swept into broad regulatory categories. Screening work is name, location, and ownership reconciliation, not moral scoring.

In September 2025 BIS added 32 more parties, 23 of them China-related and 13 semiconductor or IC-related, including research entities such as Shanghai Fudan Microelectronics, the Chinese Academy of Sciences’ Aerospace Information Research Institute, and Sino IC Technology. Beyond semiconductors, trading firms in Hong Kong and the UAE linked to diversion toward Russia and Iran continue to appear, which reaches Japanese and other non-U.S. resale channels.

Two adjacent EAR lists should sit on the same dashboard.

Denied Persons List (DPL). Parties that have lost export privileges after EAR violations. As a rule you cannot deal in items subject to the EAR with DPL parties, and restrictions can reach management support and technical assistance.

Unverified List (UVL). Parties for whom BIS could not complete a post-shipment verification or end-use check. Continuing business usually requires a UVL Statement from the end user, and License Exceptions are restricted. A UVL hit is a Red Flag that must be resolved. Leaving it open damages later license prospects.

The three lists form a practical hierarchy. Unresolved UVL problems can migrate toward Entity List treatment. Repeated violations can escalate toward denial of privileges. Getting off any of them is hard. Prevention and clean documentation beat rehabilitation.

EU, UK, and UN lists: read the scheme, not only the name match

EU sanctions are built regulation by regulation. Each Council Regulation has annexes naming individuals and entities. Those annexes feed the EU Consolidated List of Sanctions, available through the European Commission’s Financial Sanctions Database and the EU Sanctions Map. The 14th package in June 2024 pushed “No Russia Clause” contract terms and best-efforts anti-circumvention duties. The 15th package on December 16, 2024 added 54 individuals and 30 entities and extended attention to Russia’s shadow fleet and certain Chinese drone-component suppliers. On February 6, 2026 the Commission proposed a 20th package with further maritime, banking, and crypto-related measures. Enforcement still fragments across 27 member states. The same fact pattern can be handled differently in Germany, France, or the Netherlands.

The United Kingdom stopped updating the OFSI Consolidated List of Asset Freeze Targets at 9:00 a.m. UK time on January 28, 2026 and made the UK Sanctions List (UKSL) the sole official source. That implements the single-list direction from the May 2025 cross-government review. Designations on or after January 28 no longer receive OFSI Group IDs and are managed by Unique ID only. Screening vendors and internal connectors have to swap URLs and ID fields. If migration lags, new Unique-ID entries are invisible to Group-ID lookups. That is a pure systems failure, not a judgment failure.

The UN Security Council Consolidated List still needs a parallel check. As of mid-April 2026 it holds on the order of 1,000 individual and entity entries across committees such as ISIL/Al-Qaida (1267), DPRK (1718), and Somalia (751). Hit or no-hit is not enough. You need the underlying resolution, because Japan’s domestic FEFTA response depends on which international commitment is in play.

Japan’s Foreign End User List and catch-all posture

Japan’s economic security tools for exporters rest on two pillars: FEFTA asset-freeze measures that domesticate UN resolutions, and catch-all controls. The centerpiece of the latter information system is METI’s Foreign End User List. It tells exporters which foreign parties raise WMD-related and, more recently, conventional-weapons-related concerns. Exports to listed parties are likely to meet objective customer criteria under catch-all rules, which effectively forces a license application.

The list moved twice in 2025. The revision effective February 5, 2025 reached 15 countries and regions with 748 entities. The revision issued September 29, 2025 and effective October 9, 2025 expanded to 835 entities. A material change in that revision is joint publication of parties relevant to conventional-weapons catch-all concerns alongside traditional WMD concerns. Defense-adjacent and dual-use shippers both feel the wider net.

The list is distributed as PDF and searchable Excel. The hard part in operations is orthography and identity. Chinese entity names have multiple accepted English spellings. Cyrillic and Arabic transliterations vary by institution. Without the end user’s exact official English name and registration identifiers in your master data, false negatives are guaranteed.

Japan-specific caution: absence from the Foreign End User List is not clearance. If end use or customer character still raises diversion concerns, subjective catch-all criteria can require a license application anyway. The list is a watch list that signals probable concern when a party is on it. It is not a safe list that clears a party simply because the name is missing. Treat list screening as necessary and incomplete. METI also publishes supporting materials such as examples of goods of particular concern and plain-language guidelines. Cross-reading those materials is expected practice, not optional homework.

How to run multi-list screening without burning the team

A company that wants gap-resistant screening needs at least five streams on the same counterparty at the same time:

  1. U.S. Consolidated Screening List (CSL), which covers multiple U.S. lists including SDN-adjacent and EAR lists in one search surface
  2. EU Financial Sanctions Database
  3. UK Sanctions List
  4. Japan’s Foreign End User List
  5. UN Consolidated List

Adjacent sources that are not pure sanctions still appear in daily operations: U.S. Section 1260H and related Chinese military-company lists, Canadian SEMA, Australian DFAT, and company-specific watch lists. Updating all of that with one or two people in a mid-market compliance team is not a serious plan.

Spelling variation and ownership depth make the job harder. The same Chinese company can arrive as English legal name, simplified Chinese, pinyin, parent name, brand name, and office name in inconsistent fields. Russian names jump between Cyrillic and multiple Latin systems. Middle Eastern names combine Arabic script with several English spellings. On top of that sit OFAC’s 50% rule, EU ownership and control tests, and Japan’s beneficial-owner concepts. Complex logistics then multiply parties: importer, destination, end user, forwarder, customs broker, settlement bank. One sanctioned party anywhere can stop the chain.

TRAFEED, TIMEWELL’s export control AI agent, is built to run that cross-list work without turning the team into full-time list readers. Enter counterparty, destination, and cargo context and the system cross-references major lists, surfaces fuzzy matches for spelling variants and abbreviations, and flags ownership-linked concern parties. List updates are handled on the backend, so regime changes such as the January 28, 2026 UK list consolidation do not require a manual connector rewrite every time. Multilingual names and aliases are first-class inputs, not afterthoughts. People should spend time on judgment of candidates, not on scrolling PDFs. Details are on the TRAFEED service page. Feature overview is in the TRAFEED product catalog (PDF).

Three principles for a screening framework that survives audit

First, stop relying on a single list. SDN-only, Entity List-only, or Foreign End User List-only designs always leave a hole: money, goods, or catch-all. Make five-stream screening against the same counterparty the default, not the special case.

Second, automate update tracking. OFAC moves daily. EU annexes move with each package. The UK restructured the list itself in January 2026. A framework that freezes when the designated analyst is on vacation will not survive management or regulator questions. Ingest, change detection, and hit notification belong on tooling.

Third, retain the rationale. When customs, METI, or a bank asks what you knew at shipment time, “we ran a tool” is not enough. You need when you screened, which list versions, which rule produced the hit, and who approved the outcome. Automation that keeps search logs and judgment logs in explainable form is the difference between a control and a black box.

Sanctions and restricted-party lists will keep expanding faster than they contract. Building the framework early is cheaper than reconstructing years of weak screening after a hit. If you need help redesigning party screening for U.S. and Japanese exposure together, contact us.

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Free download

Recommended materials

Five Sanctions-List Systems Screening Procedure (US OFAC/BIS, EU, UK, UN + Japan's Foreign End User List, 2026)

A fill-in cross-list screening procedure for the five systems (US OFAC, US BIS, the EU, the UK, the UN) plus Japan's Foreign End User List — where, what and how to screen. Covers SDN/non-SDN and the BIS lists, the 50% / ownership-control tests, official source URLs and update cadence, and Red Flags. Based on each authority's primary sources; listing is a regulatory classification, not a judgment — final decisions rest with each authority's original list and your own officer.

China Business Travel: Technology Pre-Departure Worksheet (fill-in, 2026)

A fill-in worksheet for engineers, sales and researchers travelling to China, and for the teams that send them. Under Japan's Foreign Exchange and Foreign Trade Act, taking technical information on a trip can amount to providing technology in a foreign country (Art. 25(1)), and carrying it on a laptop or opening it from abroad can fall within Art. 25(3)(i). Most trips stay within the exemptions in Article 9 of the Ordinance on Trade Relations Invisible Trade (publicly available technology, basic scientific research, patent filings, technology incidental to exported goods). This worksheet shows where the line sits, situation by situation, with fill-in sections for before, during and after the trip. The China side reflects State Council Order No. 841 (in force 15 September 2026) Arts. 3 and 5, the Exit and Entry Administration Law Art. 28, and Japan's MOFA overseas safety advisory. Classification and licensing decisions rest with your export-control officer.

Economic Security Management Guidelines (1st Edition): 44-Item Self-Check Worksheet (2026)

A fill-in worksheet built from the appendix checklist of the Economic Security Management Guidelines (1st Edition), published by METI's Trade and Economic Security Bureau on 23 January 2026. All 44 items are transcribed from the original text and laid out in its three-column form: check item, Y/N, and the structures (organisation, internal rules) and track record behind your answer. The breakdown follows the original: 5 items on principles executives should keep in mind, 13 on securing autonomy, 13 on securing indispensability, and 13 on strengthening governance, with the 8 items the original phrases as "it is also useful to" badged separately. Opens with a plain-language primer on what economic security, autonomy, indispensability, governance and duty of care actually mean. Includes METI-published survey data showing that 70.7% of 3,007 manufacturers had heard the term but had no concrete image of it, and that the share expecting lost revenue to outweigh the cost of action rises from 22.3% over one to three years to 31.9% over four to ten. As METI states explicitly, the guidelines are not an obligation imposed on companies and are not premised on transactions with any specific country, company, or person. This worksheet was produced by TIMEWELL and was not prepared or endorsed by METI. Final decisions should rest with your legal and compliance leadership and the latest publications of the relevant authorities.

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles