Sanctiewet 1977: reporting a sanctions hit to DNB
In the Netherlands, a sanctions match is not an internal decision — it is a notification you owe the supervisor immediately, in a prescribed format, with the funds already frozen. The obligation sits in the Sanctiewet 1977 and, operationally, in the Regeling toezicht Sanctiewet 1977 made jointly by DNB and the AFM. Three short articles carry almost all of the weight: measures in your administrative organisation and internal control, a duty to report a match onverwijld, and a five-year retention clock tied to the life of the sanctions regulation itself. This guide sets out who and what you have to screen, when a match becomes a reportable hit, what the report has to contain, and what changes when the replacement statute now before parliament is adopted.
1. The rule, in four articles
The Regeling toezicht Sanctiewet 1977 entered into force on 1 October 2005 and was last amended on 9 May 2014. It is short, and it is worth reading in the original because the obligations are drafted tightly.
- Article 1 defines a relatie as “een ieder die betrokken is bij een financiële dienst of een financiële transactie” — anyone involved in a financial service or a financial transaction. The supervisor is either the AFM or DNB, depending on the institution.
- Article 2(1) requires the institution to ensure that it “op het gebied van de administratieve organisatie en interne controle maatregelen heeft getroffen ter naleving van de Sanctieregelgeving”. Article 2(2) requires those measures to cover, at minimum, an adequate check of the institution’s records for a match between a relation’s identity and a listed person or entity.
- Article 3 is the reporting duty: where the institution establishes that a relation’s identity matches a person or entity referred to in the sanctions rules, it “meldt de instelling dit onverwijld aan de toezichthouder”.
- Article 4 requires retention of the notifications and of the account and transaction data of the relations involved until five years after the relevant sanctions regulation ceases to have effect. Article 5 obliges the institution to hand over data on request.
2. Who counts as a “relation”
The definition is deliberately broad, because sanctions rules prohibit making funds or services available both directly and indirectly. In DNB’s guidance the population includes clients; representatives and authorised signatories; the clients’ ultimate beneficial owners; beneficiaries of a product or of a domestic or international transfer of funds; the counterparty to a financial transaction or product; parties to transactions involving a trust office’s target company; and the directors of clients and of parties related to them.
Ownership and control extend it further. Making funds available to a person or entity that is not itself listed, but that is owned or controlled by a listed person or entity, counts in principle as making funds indirectly available to the listed party. The threshold for ownership is 50% or more, and control is defined broadly enough that it can exist below any shareholding threshold. DNB’s practical recommendation is to work from the Wwft definition and know every beneficial owner at 25% or more, because a listed person can hold control through a chain of entities without ever appearing at 50% in any single one.
At acceptance, the full set of relations is established and recorded in the relation file, with the identifying data that make screening work: name, date of birth, place of residence, registered address. DNB is blunt about the consequence of thin data — a missing date of birth or place of residence makes a hit harder to assess, not easier. For legal persons a check against commercial-register data generally suffices; for natural persons, against the identity document. When a client-side change occurs, the relation file is updated and the whole file, not the delta, goes back through screening.
3. When you screen
An effective process is characterised by frequent screening, timed so that the institution can continuously detect whether its relations appear on a list or whether its services and transactions touch a sanctions regime. DNB names four moments:
| Moment | What it catches | Common failure |
|---|---|---|
| Acceptance | A listed client, UBO, director or representative at onboarding | Screening the applicant only, not the wider relation set |
| Relevant client-side change | New UBO, new authorised signatory, change of control | Re-screening only the changed record |
| Change to the lists | An existing relation newly listed | List updates applied on a batch cycle that is too slow |
| Transactions | Counterparties who are never clients | Filtering on name only, without country and description fields |
The lists themselves are not a single file. They comprise EU decisions and regulations, decisions of the Minister of Foreign Affairs under the Sanctieregeling Terrorisme 2007-II — the national terrorism list — and UN Security Council resolutions. Alongside asset freezes and the prohibition on making funds available, several regimes carry prohibitions or restrictions on providing financial services in connection with goods: military goods, dual-use goods, strategic services such as software and technology, and goods usable for internal repression. Where those apply, the institution must have recorded its position on them in an accessible way.
4. Filtering transactions
The starting point is that the parties involved in a transaction are tested against the lists. At minimum, filtering covers the originator, the beneficiary, place names, country and the description field. Institutions active in payments filter the MT message series and its fields, including free-format n99 messages, and the SEPA message fields that the institution has determined on the basis of a documented risk assessment. That word carries weight: the scoping decision is itself an artefact a supervisor will ask to see.
Payments executed through third parties do not move the obligation. The institution’s internal control has to be arranged so that the sanctions rules are met even where a third party sits in the chain. Where adequate arrangements exist with those third parties, the institution can rely on them to freeze when needed — and those arrangements should include mutual notification of frozen transactions and the use of the Dutch lists by foreign third parties when they screen.
5. Reporting a hit, and what happens next
Only genuine hits are reported. An institution screening against the lists will meet many potential matches; all are assessed, and false positives are not notified. Where there is doubt whether a potential match is a real one, the institution investigates further to establish or exclude it — but the investigation does not suspend the onverwijld clock once a match is established.
The report is made on the notification format drawn up jointly by the AFM and DNB, and it contains four things: identifying data (name, alias, place of residence, place and date of birth); the nature and size of the frozen funds or assets; the action the institution has taken; and the applicable sanctions regulation or regulations. DNB assesses the reports it receives for completeness, and forwards them to the Minister of Finance.
Freezing then persists by default. Funds stay frozen until the relevant sanctions regulation is amended and the freezing obligation falls away, an exemption is granted, or the institution receives notice to the contrary from the Minister of Finance or DNB. DNB states the default explicitly: if the institution hears nothing, it must assume the hit is real and the funds remain frozen until further notice. Exemptions are decided by the Minister of Finance on a reasoned request. And the institution may not exit the client on the strength of the hit.
One further step is routinely missed. Where an institution freezes on the basis of a hit, it is expected to look back over the transaction history to assess whether transactions took place that give reason to suspect money laundering or terrorist financing. Where such a suspicion arises, that is a separate report to the FIU under Article 16 of the Wwft. A sanctions hit and an unusual-transaction report are two obligations with two recipients, and one does not discharge the other.
6. Three situations, worked through
An incoming SEPA credit transfer whose debtor name matches an EU listing. The debtor is not a client, but it is a relation — a party involved in a financial transaction. The firm holds the funds rather than crediting the account, completes the assessment against the identifying data it has, and where the match is real it freezes, reports to DNB on the notification format with the amount and the regulation cited, and does not release on the customer’s insistence. It then reviews the account’s history for related flows and decides separately whether an Article 16 Wwft report is owed. It does not close the customer’s account on the back of the hit.
Onboarding a Dutch BV whose 60% shareholder is listed. The BV itself appears on no list. The 60% holding is over the ownership threshold, so funds of the legal person must be frozen and no funds may flow to it: the prohibition on indirect availability bites through the shareholding. The firm does not onboard, reports the established match, and records the ownership analysis — including how it identified holders below 50%, since control can exist without majority ownership.
A strong name match on a common surname, resolved as a false positive. The alert is investigated against date of birth and place of residence and excluded. Nothing is reported. What the firm must still be able to show is the handling: DNB assesses the design of the screening process including how hits are handled and recorded, alongside the sanctions risks captured in the SIRA, the design of the policy and procedures, their application in client files, and training and awareness. An undocumented dismissal of an alert is a control weakness even when the conclusion was right.
7. What is changing
The Sanctiewet 1977 is being replaced. The Wet internationale sanctiemaatregelen was introduced in the Tweede Kamer as bill 36898 on 19 February 2026 by the Minister of Foreign Affairs, referred to the Foreign Affairs committee on 25 February 2026, with written input submitted on 15 April 2026 and clearance for plenary treatment on 24 June 2026; a plenary debate is scheduled for 2 November 2026. The bill modernises the framework for implementing UN and EU sanctions, improves data exchange, and introduces administrative enforcement of sanctions breaches.
Two practical points follow. First, the Sanctiewet 1977 and the Regeling toezicht remain the applicable law until the replacement is adopted and enters into force — nothing in the bill’s progress changes today’s obligations. Second, DNB’s guidance position is itself transitional: the former Leidraad Wwft en Sw was replaced in May 2024 by DNB’s Q&As and Good Practices on the Wwft, and the Sanctiewet was deliberately left out of that exercise pending the modernisation, with the sanctions chapter republished unchanged and a new DNB publication promised in due course. Build your framework on the regulation’s text and the republished chapter, and expect the guidance layer to be reissued.
8. FAQ
How quickly must a hit be reported to DNB?
Article 3 of the Regeling toezicht Sanctiewet 1977 requires notification onverwijld — immediately — once the institution establishes that a relation’s identity matches a listed person or entity. There is no grace period and no risk-based deferral.
Do we report false positives?
No. Only genuine hits are notified. Potential matches are all assessed, and where doubt remains the institution investigates further to establish or exclude a match. The handling and recording of alerts is nevertheless part of what DNB assesses in the screening process.
What must the notification contain?
Identifying data (name, alias, place of residence, place and date of birth), the nature and size of the frozen funds or assets, the action taken by the institution, and the applicable sanctions regulation or regulations, submitted on the notification format drawn up by the AFM and DNB.
Can we terminate the customer relationship after a hit?
No. An existing client may not be exited on the basis of the hit. In some cases an exemption can be sought from the Ministry of Finance, which decides on a reasoned request.
How long do we keep the records?
Notifications and the account and transaction data of the relations involved are kept until five years after the relevant sanctions regulation ceases to have effect or is suspended — a retention clock tied to the life of the regulation, not to the date of the report.
Does a sanctions hit also require an FIU report?
Not automatically, but it triggers the question. After freezing, the institution reviews the transaction history for transactions that give reason to suspect money laundering or terrorist financing; where such a suspicion arises, a separate report is made to the FIU under Article 16 of the Wwft.
9. What to do, today
- Write down your relation population — clients, representatives, UBOs, beneficiaries, transaction counterparties, directors — and test whether your screening actually covers each category, not just the account holder.
- Check that transaction filtering covers originator, beneficiary, place names, country and description, and that the scoping of MT and SEPA fields rests on a documented risk assessment you can produce.
- Confirm the notification format is pre-filled with your four mandatory elements and that a named person can send it the same day a hit is established, including outside office hours.
- Set the retention rule to the life of the sanctions regulation plus five years, rather than to a fixed period from the report date.
- Track bill 36898 through its plenary stage, but change nothing yet — the Sanctiewet 1977 regime applies until the replacement is in force.
Related: The Dutch AML framework beyond goAML · EU asset-freeze reporting · DNB SIRA — the integrity risk analysis · Sanctions screening under instant payments


