Introduction
Sanctions are instruments of a country's foreign policy, designed to respond to situations of international concern without, or in addition to armed force.
Businesses with international supply chains, technology exports, shipping exposure, energy or resources operations, financial services capability, or dealings in higher-risk regions should assume that regulators and counterparties increasingly expect firms to have a framework that addresses sanctions.
This is also becoming a contractual issue, with more customers, financiers and insurers seeking sanctions representations, audit rights and termination triggers.
Australia's sanctions framework
Australia’s sanctions framework is principally governed by the Autonomous Sanctions Act 2011 (Cth) and the Autonomous Sanctions Regulations 2011 (Cth), alongside United Nations Security Council sanctions implemented in Australia as a matter of international law.
Australian sanction laws apply to:
- Activities conducted in Australia;
- Activities conducted overseas by Australians and Australian corporates; and
- Activities conducted on Australian flagged vessels and aircraft.
Sanctions are also imposed internationally, for example in the United States administered by the Office of Foreign Assets Control and in the European Union and its Member States.
The regulations prohibit a range of dealings, including making assets available to designated persons or entities, using or dealing with controlled assets, supplying export sanctioned goods, importing sanctioned goods, providing sanctioned services, and engaging in certain sanctioned commercial activities. The framework is dynamic and country and activity specific.
The Australian Sanctions Office, part of the Department of Foreign Affairs and Trade, publishes tools and guidance that emphasise sanctions compliance is a dynamic process requiring continuous monitoring and reassessment.
DFAT’s Consolidated List, a list that includes individuals, entities and vessels subject to Australian sanctions, is frequently updated, reinforcing the need for continuous screening and review to ensure compliance.
Questions to ask
Regulatory expectations around sanctions compliance have sharpened.
DFAT’s guidance places particular emphasis on two threshold questions: whether an activity is associated with a designated person or entity, and whether it has a nexus to a sanctioned country, region or terrorist group. That sounds simple, but in practice it requires businesses to look beyond the named counterparty.
For example, DFAT’s guidance highlights the need to identify all persons and entities associated with a proposed activity, understand beneficial ownership structures, determine who may derive a benefit, and assess destination, transit, end-use and end-user risks.
The guidance also reinforces the breadth of targeted financial sanctions. These restrictions generally prohibit directly or indirectly making an asset available to, or for the benefit of, a designated person or entity, and prohibit dealing with assets owned or controlled by such a person or entity. “Asset” is interpreted broadly and is not limited to cash. It can include goods, contractual rights, services, technology and other forms of property or value.
What an effective program looks like in 2026
An effective sanctions compliance program in 2026 should include the following elements.
1. Board and executive ownership
Sanctions risk should be allocated to a clear accountable owner, with board or risk committee visibility where exposure is material. The program should define roles across legal, compliance, finance, procurement, sales and operations, and set approval thresholds for higher-risk transactions, jurisdictions and counterparties.
2. A documented sanctions risk assessment
Businesses should maintain a written risk assessment that considers customers, suppliers, intermediaries, beneficial owners, products, services, jurisdictions, shipping routes, payment corridors and delivery models. It should be refreshed periodically and when the business enters new markets, launches new products, restructures supply chains or undertakes M&A activity.
3. Screening that goes beyond names
Effective screening should cover counterparties, beneficial owners, controllers, directors where relevant, vessels, and other transaction touchpoints against the DFAT Consolidated List. Screening should occur at onboarding, before payment or shipment, on material changes, and at appropriate intervals for existing relationships. Fuzzy matching, escalation rules and documented false-positive handling are now basic hygiene.
4. Transaction and activity-based controls
A mature program does not stop at list screening. It also asks whether the activity involves sanctioned goods, sanctioned imports, sanctioned services, or sanctioned commercial activity. This requires controls around product classification, end-use and end-user checks, destination and transit country review, and review of services that may facilitate a prohibited dealing.
5. Escalation, legal review and permit pathways
There must be a practical process for stopping and escalating red flags. Where a proposed dealing may be prohibited, the organisation should have a defined pathway for internal legal review, external advice where needed, and consideration of whether a sanctions permit application is appropriate. Permits are not a substitute for weak controls; they are a targeted mechanism for otherwise prohibited conduct in limited circumstances.
6. Training, testing and record-keeping
Training should be tailored by function. Procurement, sales, logistics and customer-facing teams often need more than generic annual compliance modules. Organisations should also retain records of screening, decisions, investigations and approvals. DFAT’s guidance expressly notes the importance of documentation in demonstrating reasonable precautions and due diligence.
Practical implications
For many corporates, the immediate challenge is operational rather than conceptual.
The question is not whether the business has a sanctions policy, but whether its controls are embedded where decisions are actually made. A policy sitting in a compliance folder will not help if procurement can appoint a distributor without ownership checks, or if finance can release funds without rescreening a changed payee.
Due Diligence remains as vital as ever. Internal review of sanctions compliance, as well as external legal review, is a vital part of ensuring compliance, and also demonstrating that an organization has done all it can to comply with sanctions law. External legal review, in particular, helps an organisation mitigate against the possibility of a court imposing strict liability on companies found to have committed an offence.
Penalties remain severe. DFAT states that sanctions offences may attract, for individuals, up to 10 years’ imprisonment and/or a fine of 2,500 penalty units (A$825,000) or three times the value of the transaction, and for bodies corporate, up to 10,000 penalty units (A$3.3 million) or three times the value of the transaction.
Giving false or misleading information to the ASO in relation to sanctions administration is also a serious offence, with similar penalties.
What you should do
- Refresh your sanctions risk assessment: Map where sanctions risk arises across customers, suppliers, products, services, jurisdictions, vessels and payment flows.
- Review your screening model: Ensure it captures beneficial ownership, control, end-users and transaction-specific touchpoints, not just named counterparties.
- Embed controls into workflows: Build sanctions checks into onboarding, procurement, contracting, shipping and payment approvals.
- Test escalation and freeze procedures: Confirm staff know when to stop a transaction, who to notify, and how to preserve records.
- Review permit and incident response protocols: Establish when to seek legal advice, when a permit may be required, and how to respond to a potential match or asset-freezing issue.
Further information
For further information on how these issues may affect your business, please contact:
Andrew Chalet | Partner | achalet@thomsons.com.au| 0421051484