CGSS Domain 1 Topic Premium
The Purpose and History of Sanctions
Sanctions are political decisions made as part of diplomatic efforts by countries, regional organizations, and international bodies β primarily a foreign policy and security tool, not a criminal-law one. At their core, every sanction is aimed at behavioral change through deterrence, prevention, or punishment; the specific objective (protecting national security, punishing military aggression, discouraging WMD proliferation, disrupting terrorist financing, diminishing a regime's power to commit human rights violations, or targeting corrupt officials) is just that underlying goal applied to a specific situation. Sanctions sit between diplomacy and war β a lower-cost, lower-risk intervention used either instead of military action or while military options are still being evaluated.
The practice is old: one of the first recorded uses dates to 5th-century BCE Athens, which barred citizens of Megara from its markets. The League of Nations (post-WWI) began the shift toward multilateral sanctions β multiple countries acting together β and the UN Charter formally recognized sanctions as a foreign policy tool in 1945. A precise, testable distinction worth holding onto: Counter-Proliferation Financing (CPF) targets WMD-related financing specifically (anchored in UNSCR 1540 and FATF Recommendation 7), while Countering the Financing of Terrorism (CFT) covers targeted financial sanctions, investigation, information sharing, and due diligence aimed at terrorist financing β related concepts, but distinct obligations.
Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.6β22)- Sanctions are fundamentally about changing behavior (deterrence/prevention/punishment) β not a punitive criminal-law mechanism in themselves.
- CPF (proliferation financing, UNSCR 1540 / FATF R.7) and CFT (terrorist financing) are related but legally distinct obligation sets.
- Multilateral sanctions can carry real, documented unintended humanitarian consequences (e.g., North Korea) even where the underlying policy goal is legitimate.
Learning Outcomes- Define sanctions and explain their core purpose.
- Distinguish the main policy objectives sanctions are used to pursue.
- Explain the CPF vs. CFT distinction.
- Recognize that sanctions can produce unintended humanitarian consequences.
Exam tip: If a question asks "what are sanctions ultimately meant to achieve," the Study Guide's own framing is behavioral change through deterrence, prevention, or punishment β more precise than just "punishing bad actors." (CGSS Study Guide v2.0, Domain 1, p.9)
Practise this topic β
CGSS Domain 1 Topic Premium
Who Imposes Sanctions: UN, EU, US & UK Regimes
Sanctions come from three levels: multilateral (UN Security Council, binding on all member states), regional (the EU, applicable across member states), and unilateral (a single country acting alone, such as the US, UK, Canada, or Australia). The UN's authority derives from Article 41 of Chapter VII of its Charter; the Security Council's 15 members include five permanent members with veto power (Russia, US, UK, China, France β the "P5"), and at least 9 affirmative votes with no P5 objection are needed to pass a resolution. Once adopted, sanctions are legally binding under Articles 25 and 48, and the UN maintains the Consolidated List of all sanctioned persons and entities β though enforcement itself falls to member states, who must pass their own implementing legislation.
The EU calls its own sanctions "restrictive measures," prepared by the European External Action Service and adopted unanimously under its Common Foreign and Security Policy; it both implements UN sanctions (via Council Decisions/Regulations) and imposes autonomous ones. The US runs the most comprehensive framework globally β sanctions originate from the President (via Executive Orders under IEEPA/TWEA) or Congress (via statute, e.g., CAATSA), and are implemented mainly by OFAC (Treasury), which maintains the SDN List, alongside BIS (Commerce, export controls/EAR) and the State Department. The UK, post-Brexit, runs its own regime under the 2018 Sanctions and Anti-Money Laundering Act (SAMLA), with OFSI (financial sanctions/licensing), the FCA, the Department for Business and Trade, and the Home Office (travel bans) each holding a distinct piece.
Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.24β36)- UN sanctions require 9+ affirmative votes AND no P5 veto β a single P5 objection blocks the resolution entirely.
- Confusing which US agency owns which list: OFAC (SDN List, financial/economic), BIS (Denied Persons List, Entity List, EAR export controls), State Department (Cuba Restricted List, Nonproliferation list).
- Assuming UK sanctions still mirror EU sanctions post-Brexit β they diverge, and firms with a UK connection must monitor both separately.
Learning Outcomes- Distinguish multilateral, regional, and unilateral sanctions authority.
- Explain the UN Security Council's voting and veto structure for sanctions resolutions.
- Identify the key US agencies (OFAC, BIS, State) and their respective lists.
- Describe the UK's post-Brexit sanctions architecture (SAMLA, OFSI, FCA).
Exam tip: If a scenario references the SDN List, that's OFAC; if it references the Entity List or Denied Persons List, that's BIS β the exam tests this agency/list pairing directly. (CGSS Study Guide v2.0, Domain 1, p.31)
Practise this topic β
CGSS Domain 1 Topic Premium
US Primary vs. Secondary Sanctions & OFAC
US primary sanctions apply where a "US nexus" exists β a US citizen or permanent resident (wherever located), any entity organized under US law, anyone physically present in the US, or (in some programs, like Iran and Cuba) a non-US entity owned/controlled by a US person. US secondary sanctions are different in kind, not just degree: they target non-US persons for transactions entirely outside the US, with no US nexus at all β used in a limited set of programs (Iran, North Korea, Russia), and made a far more prominent tool after CAATSA in 2017. Because no US connection is required, secondary sanctions don't impose fines for a "violation" the way primary sanctions do; instead, the non-US party risks being cut off from the US financial system or added to the SDN List themselves.
Determining secondary-sanctions exposure turns on whether a non-US person "knowingly" facilitated a "significant transaction" β OFAC weighs factors like transaction size/frequency, whether it fits a pattern, management's awareness, and any connection to a blocked person, explicitly on a case-by-case basis rather than a fixed threshold. OFAC itself sits inside Treasury and administers both targeted programs (e.g., Global Magnitsky, Counter Narcotics Trafficking) and comprehensive country programs (Iran, North Korea) β its core list, the Specially Designated Nationals and Blocked Persons (SDN) List, blocks the named person's assets and generally bars US persons from dealing with them at all.
Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.32β34, 46)- Primary sanctions require a US nexus; secondary sanctions explicitly do not β that absence of a nexus is the defining feature, not an edge case.
- "Significant transaction" has no fixed legal definition β it's a case-by-case, multi-factor determination, not a bright-line dollar threshold.
- Secondary sanctions don't produce fines for non-US persons the way primary sanctions do; the consequence is exclusion from the US financial system or SDN designation.
Learning Outcomes- Define "US person" and identify what triggers primary sanctions.
- Distinguish primary from secondary sanctions and explain why secondary sanctions need no US nexus.
- Identify the factors OFAC weighs in a "significant transaction" determination.
- Explain OFAC's role and the function of the SDN List.
Exam tip: If a question describes a transaction between two non-US parties with zero US connection, and asks whether US sanctions could still apply, the answer almost always turns on secondary sanctions exposure, not primary. (CGSS Study Guide v2.0, Domain 1, p.32)
Practise this topic β
CGSS Domain 1 Topic Premium
Jurisdictional Reach & Extraterritoriality
Extraterritoriality is a state applying its laws to persons, property, or conduct beyond its own borders. The US is the primary jurisdiction that does this deliberately through its sanctions regimes; the EU considers the practice a violation of international law and does not apply its own restrictive measures extraterritorially β EU sanctions instead require an actual EU nexus (an EU national, an EU-incorporated entity, or activity conducted at least partly within the EU). This asymmetry is exactly what creates blocking regulations: EU/UK law that can prohibit EU/UK persons from complying with certain extraterritorial US sanctions, specifically to protect their own economic interests and foreign policy positions from being overridden by another country's law.
Two named, testable cases capture how this plays out in practice. In Cynergy Bank, a UK bank stopped paying loan interest to a Cyprus-based lender after the lender's ultimate beneficial owner (Russian oligarch Viktor Vekselberg) was designated an SDN β UK courts held that Cynergy was correctly complying with US secondary sanctions, even though Cynergy itself was never a "US person," because the underlying transaction involved an SDN-linked party. In the JCPOA case, when the US withdrew from the Iran nuclear deal in 2018 and reimposed sanctions, the EU stood up INSTEX β a special-purpose vehicle meant to let European exporters keep trading with Iran outside the reach of US secondary sanctions β but it struggled against financial-sector reluctance to risk US exposure and was ultimately liquidated in 2023, a real illustration of how hard blocking mechanisms are to make work in practice.
Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.40β44)- The EU requires an actual EU nexus for its sanctions to apply; the US does not require a US nexus for secondary sanctions β this asymmetry is the direct cause of blocking-regulation conflicts.
- Cynergy Bank: complying with US secondary sanctions (by not paying) was found to be the correct, legally defensible action for a non-US bank β not a sanctions violation.
- Blocking regulations don't force businesses to trade with sanctioned parties β they protect against being compelled to comply with a foreign country's extraterritorial sanctions, not create an obligation to defy them.
Learning Outcomes- Define extraterritoriality and contrast the US and EU approaches to it.
- Explain how and why blocking regulations arise.
- Apply the Cynergy Bank case to a UBO/SDN-designation scenario.
- Explain what INSTEX was built to do and why it struggled.
Exam tip: If a scenario shows a non-US, non-UK, non-EU-connected entity avoiding a transaction specifically because a counterparty's UBO is an SDN, that's a Cynergy-Bank-style secondary sanctions exposure question β refusing the transaction is usually the correct, compliant answer. (CGSS Study Guide v2.0, Domain 1, p.41)
Practise this topic β
CGSS Domain 1 Topic Premium
Sanctions Targets & Facilitation
Everyone is subject to sanctions based on jurisdiction, but not everyone needs a formal sanctions compliance program β that obligation falls on organizations that are directly regulated for sanctions compliance, or whose risk exposure (nature, size, complexity of business) warrants one. Citizens and permanent residents must comply with their home jurisdiction's sanctions wherever they physically are, and separately must comply with the sanctions law of wherever they're physically located β both apply simultaneously, not one or the other. Two real limitations exist on who can be targeted: a country generally cannot sanction its own citizens without violating its own domestic law, and sanctions must respect human rights and humanitarian obligations.
Facilitation is a precisely defined, separately prohibited concept: making a sanctionable activity easier for a third party, even without directly engaging in the underlying transaction yourself β this covers providing personnel, software, technology, goods, services, financing, approvals, guarantees, or even referring a business opportunity to a foreign entity. OFAC prohibits US persons from facilitating; the EU has similar anti-circumvention rules. The named Alfa Laval case shows exactly how this plays out: a Middle East subsidiary of a US company falsified export documents to reroute oil-tank-cleaning equipment to Iran via Dubai, without informing the US parent β OFAC still penalized the responsible subsidiary over US$615,000, more than 30 times the shipment's value, illustrating how facilitation penalties are designed to deter, not merely recover losses.
Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.50β54)- Home-jurisdiction sanctions obligations and physical-location sanctions obligations both apply at once β being outside your home country doesn't suspend either one.
- Facilitation covers referring a business opportunity alone β actual participation in the underlying transaction isn't required to violate it.
- A US parent company's lack of direct knowledge did not prevent OFAC from penalizing facilitation carried out by a foreign subsidiary.
Learning Outcomes- Identify who must comply with sanctions vs. who must maintain a formal compliance program.
- Explain the two limitations on eligible sanctions targets.
- Define facilitation and list the activities it covers.
- Apply the Alfa Laval case to a subsidiary-facilitation scenario.
Exam tip: If a scenario describes someone merely referring, approving, or arranging a deal with a sanctioned party β without directly transacting themselves β that's facilitation, a distinct violation from the underlying sanctionable transaction itself. (CGSS Study Guide v2.0, Domain 1, p.52)
Practise this topic β
CGSS Domain 1 Topic Premium
Types of Sanctions and Embargoes
Sanctions take several forms β financial/economic sanctions, trade sanctions (including arms embargoes and export controls), asset freezes, and travel bans β and separately can be either comprehensive (targeting an entire jurisdiction, like the Iraq sanctions after the 1990 Kuwait invasion, which triggered severe currency inflation and infrastructure collapse alongside their intended effect) or targeted/"smart" (focused on specific individuals to limit collateral damage to the broader population). The 2022 Magnitsky Act case is the textbook targeted-sanctions example: named after a Russian lawyer who died in custody after exposing a US$230 million fraud, the Act lets governments freeze assets and bar entry for human rights violators and corrupt officials specifically, anywhere in the world, without sanctioning their whole country.
Sectoral sanctions sit in between β they don't target a whole country or just named individuals, but a specific economic sector (finance, energy, defense). Russia's 2014 and 2022 sectoral sanctions are the most heavily tested example: a price cap on seaborne oil, bans on aircraft-part exports, mining-sector import restrictions, and β notably β removing designated Russian banks from SWIFT, which blocked their ability to send or receive international payments at all. Asset freezes are their own distinct tool: the Roman Abramovich case shows a freeze can coexist with a targeted license for narrow purposes (his Chelsea Football Club was licensed to keep playing matches and paying players even while his broader assets stayed frozen) β freezing and total prohibition are not the same thing.
Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.55β70)- Comprehensive sanctions target an entire jurisdiction; targeted/smart sanctions and sectoral sanctions are both narrower, but sectoral targets an industry, not named individuals.
- Removal from SWIFT is a specific, real sectoral sanctions tool β not the same as a blanket trade ban.
- A frozen asset can still be the subject of a general license permitting narrow, specific activity (Abramovich/Chelsea) β freezing isn't automatically absolute.
Learning Outcomes- Distinguish comprehensive, targeted, and sectoral sanctions.
- Explain the Magnitsky Act's targeted human-rights sanctions model.
- Describe how SWIFT removal functions as a sectoral sanctions tool.
- Apply the Abramovich/Chelsea case to a licensed-activity-under-freeze scenario.
Exam tip: If a question names a specific economic sector (energy, defense, finance) rather than a whole country or a named person, that's sectoral sanctions β a distinct category the exam tests against comprehensive and targeted sanctions. (CGSS Study Guide v2.0, Domain 1, p.65)
Practise this topic β
CGSS Domain 1 Topic Premium
Sanctions Exceptions, Exemptions & Licensing
A license is written authorization permitting an activity that sanctions would otherwise prohibit β and there are two distinct types. A general license (called a derogation in the EU) authorizes a whole category of transactions for any qualifying person, with no individual application needed β typically covering humanitarian aid, legal services, or basic needs. A specific license is granted case-by-case, only after a written application demonstrating the activity meets the program's criteria, and approval is never guaranteed β OFAC can take months, and some categories carry a standing policy of denial. Both types come with real limits: a license authorizes only the specific activity and amount described, never unrestricted dealings with a sanctioned party, and a bank that helps move licensed funds still bears its own compliance obligations for enhanced monitoring, separate from the customer's own license.
The named Syria Property Ltd. case shows this concretely: a UK real estate firm's accounts were frozen once its Syrian parent became a designated entity, and even after obtaining a license to resume basic operating payments (payroll, utilities, insurance), the bank was still expected to actively monitor every withdrawal for license-scope compliance β obtaining a license doesn't end an institution's own due diligence duty. On the humanitarian side, the Study Guide's Taliban/Afghanistan example shows how narrow "general license" language really is: OFAC's General License 19 permitted education-related humanitarian transfers into Afghanistan, but explicitly did not authorize payments to any blocked person beyond specific categories like taxes, fees, or permits β a license's precise wording, not its general humanitarian purpose, defines what's actually allowed.
Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.63, 74β86)- A general license needs no application; a specific license does, and approval is never guaranteed even with a strong case.
- Holding a license doesn't remove a bank's own obligation to monitor that the licensed activity stays within scope β Syria Property Ltd. is the exam's anchor case for this.
- Assuming a general license's humanitarian purpose covers any related payment β GL 19 explicitly excluded most payments to blocked persons beyond narrow named categories.
Learning Outcomes- Distinguish general licenses/derogations from specific licenses/exceptions.
- Explain why obtaining a license doesn't end a bank's monitoring obligation.
- Apply the Syria Property Ltd. case to a frozen-account licensing scenario.
- Identify common licensing errors (assuming past approvals apply, misreading scope, incomplete documentation).
Exam tip: If a scenario asks whether a bank can stop monitoring a customer's transactions once a license is granted, the answer is no β enhanced monitoring of licensed activity is an ongoing institutional obligation, not a one-time check. (CGSS Study Guide v2.0, Domain 1, p.79)
Practise this topic β
CGSS Domain 1 Topic Premium
Delisting
Delisting removes an entity, individual, or item from a sanctions list, and can happen for several distinct reasons: genuine behavior change (ending terrorism support, complying with an agreement), correcting an error (the person was listed by mistake), positive diplomatic developments, humanitarian necessity, or simple goodwill. Outside of automatic delisting on death or an entity's legal dissolution, every delisting decision is made case-by-case by the body that imposed the original sanction β at the UN, that means petitioning the Focal Point for Delisting (or, for ISIL/Al-Qaida-linked listings specifically, the Office of the Ombudsperson); the EU General Court hears direct challenges only for autonomous EU sanctions; the UK allows a ministerial review under SAMLA Section 23; and OFAC handles US petitions directly. A real, testable risk: jurisdictions can disagree β the EU delisting someone while OFAC keeps them listed creates a genuine legal and operational conflict, not just an administrative inconvenience.
Delisting does not end an institution's compliance obligations β this is the exam's most heavily tested angle. The GlobalTrade Corp. case shows the correct response: once a wrongly-sanctioned customer was cleared and delisted, the compliance officer still had to refresh KYC information, reassess (typically lower) the customer's risk rating, document the entire episode, notify internal stakeholders across risk/legal/relationship management, and recalibrate transaction-monitoring thresholds to match the new profile β delisting triggers a review, it doesn't close the file. Financial institutions may also choose to apply enhanced due diligence for a defined period after delisting, purely as a precaution against illicit activity resuming post-delisting.
Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.87β93)- Delisting is automatic only on death or entity dissolution β every other delisting is a case-by-case decision by the relevant sanctions authority.
- A person delisted by one jurisdiction (e.g., the EU) can remain listed by another (e.g., OFAC) β creating real, practical compliance conflicts.
- Delisting triggers a KYC refresh and risk-rating reassessment; it does not end monitoring or documentation obligations.
Learning Outcomes- Explain the reasons delisting can occur and which are automatic vs. case-by-case.
- Identify the delisting process for the UN, EU, UK, and US.
- Apply the GlobalTrade Corp. case to a post-delisting KYC scenario.
- Explain why cross-jurisdictional delisting conflicts occur.
Exam tip: If a question asks what a compliance officer should do immediately after a customer is delisted, the correct answer bundles KYC refresh + risk-rating reassessment + documentation β "resume business as normal" is always the wrong answer. (CGSS Study Guide v2.0, Domain 1, p.91)
Practise this topic β
CGSS Domain 1 Topic Premium
Consequences of Noncompliance
Sanctions violations generally carry strict liability β an individual or organization can be held liable even without knowledge or intent to violate, and even where a genuinely risk-based compliance program was in place. For individuals, consequences range far beyond fines: frozen assets, blocked banking access, travel restrictions, criminal penalties (in the US, up to US$1 million and 20 years' imprisonment for willful violations), and lasting reputational and social damage. The Mikhail Fridman case shows how narrow post-sanctions life becomes even for a billionaire: UK courts limited him to roughly Β£760,000/year in living expenses and specific security costs, rejecting his request for materially more β sanctions relief for personal maintenance is licensed narrowly, not restored to pre-sanctions normalcy.
For organizations, strict liability means an entity can be penalized even when a subsidiary acted without the parent's knowledge β this is exactly what happened in the Oleg Deripaska/Rusal case, where sanctions on Rusal (tied to Deripaska's ownership) disrupted the entire global aluminum industry before OFAC lifted them once Deripaska's ownership stake dropped below 50%. Successor liability extends this further: an acquiring company inherits the sanctions-violation history of whatever it acquires, including subsidiaries β due diligence on a target's own past violations is not optional. Critically, self-reporting and remediation genuinely reduce penalties: OFAC's own enforcement framework weighs voluntary self-disclosure, cooperation, and remedial action (firing responsible staff, strengthening controls) as mitigating factors β the Study Guide's own worked scenario treats "take remedial action and self-report" as the textbook-correct response to discovering an accidental violation, not "confirm the vendor is liable instead."
Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.94β101)- Strict liability applies regardless of intent or knowledge β a compliance program's existence reduces penalties but never eliminates liability outright.
- Organizations cannot shift sanctions liability to third parties, vendors, or distributors β the Study Guide states this explicitly.
- Successor liability means an acquiring company inherits a target's sanctions-violation history, including that of its subsidiaries.
- Self-disclosure and remediation are real, weighted mitigating factors in enforcement outcomes, not just goodwill gestures.
Learning Outcomes- Explain strict liability and why it applies regardless of intent.
- Describe the individual consequences of sanctions designation using the Fridman case.
- Explain successor liability in an acquisition context.
- Identify the correct response to discovering an unintentional violation (remediate + self-report).
Exam tip: Any scenario ending in "what should the compliance officer do after discovering an unintentional violation" almost always resolves to strengthening controls and self-reporting to the regulator β never to shifting blame to a vendor or distributor. (CGSS Study Guide v2.0, Domain 1, p.95)
Practise this topic β
CGSS Domain 1 Topic Premium
Types of Sanctions Risk: Operational, Legal, Concentration & Reputational
Four risk types recur across the whole sanctions curriculum. Operational risk is loss from failed internal processes, people, or systems β human error causes most of it, but natural disasters, ransomware, and inadequate screening-software updates are named contributors too. Legal risk is the possibility of criminal penalties, lawsuits, or unenforceable contracts causing harm; the Arab Bank Plc. case is the anchor example β a US jury found the bank liable in 2014 for knowingly facilitating payments connected to Hamas, brought under the Anti-Terrorism Act by nearly 600 private plaintiffs (not a regulator), and even though the case was later dismissed on a technicality, the bank still lost its US operations and other banking relationships β legal risk can materialize as private litigation entirely separate from any regulatory enforcement action.
Concentration risk comes from over-exposure to a single customer, sector, or jurisdiction β the Fortum case shows this precisely: the Nordic energy company had over β¬6 billion concentrated in Russia through one subsidiary, and when Russia seized that subsidiary in 2023, Fortum recorded a β¬1.7 billion loss β roughly 20% of its total equity β from a single geographic/sector concentration. Reputational risk is the hardest to quantify but the fastest to materialize: the Clarita National Bank case shows how it compounds β a first sanctions-and-AML enforcement action (US$100 million in fines) was followed by a second media leak revealing further undisclosed violations, triggering depositor withdrawals, termination of correspondent banking relationships in three countries, a collapsed acquisition deal, and even the loss of a sports sponsorship β reputational damage from a compliance failure regularly extends well beyond the institution's direct banking relationships.
Real Exam Concepts (CGSS Study Guide v2.0, Domain 1, pp.102β115)- Legal risk can arise from private lawsuits (Arab Bank), not only from regulatory enforcement β the exam tests this distinction.
- Concentration risk is about over-exposure to any single customer, sector, or jurisdiction β Fortum shows a sector/jurisdiction concentration, not just a customer one.
- Reputational risk compounds: a second disclosed failure (Clarita National Bank) causes disproportionately larger damage than the first.
Learning Outcomes- Define operational, legal, concentration, and reputational risk.
- Apply the Arab Bank Plc. case to a private-litigation legal-risk scenario.
- Apply the Fortum case to a sector/jurisdiction concentration-risk scenario.
- Explain how reputational risk compounds using the Clarita National Bank case.
Exam tip: If a question describes a lawsuit brought by private citizens or victims β not a regulator β that's testing legal risk via private litigation, exactly the Arab Bank Plc. pattern, not a standard enforcement-action scenario. (CGSS Study Guide v2.0, Domain 1, p.110)
Practise this topic β