FINMA Updates ISIL Sanctions List: Why Compliance Officers Can't Screen Fast Enough Across Fragmented Vendor Stacks

The UN Security Council's ISIL and Al-Qaida Sanctions Committee amended its designations list on September 4, 2026. Three days later, SECO updated the SESAM database. One day after that, FINMA notified financial intermediaries of their obligations: implement the prohibitions, freeze affected assets, report to SECO. The regulatory expectation is clear. The operational reality for most regulated digital asset firms is not.
Under Swiss law, UN sanctions enter into force in Switzerland without delay. The Federal Council's 2016 Ordinance on the automatic application of UN Security Council sanctions lists ensures that amendments are directly applicable the moment they are enacted in Geneva or New York. For financial intermediaries, this creates a compliance obligation that begins the instant a list changes, not when their vendor sends an updated file.
FINMA's expectations reflect this immediacy. Banks must screen new sanctions entries against their client base on the same day those entries take effect. If a list amendment is published at noon and enters into force at 6 PM, the institution must complete screening within that six-hour window. For other financial intermediaries, including most VASP categories, the expectation is screening within 24 hours. Relying solely on third-party service providers is explicitly deemed insufficient, as FINMA recognises that external vendors often integrate updates with delays.
This is where the infrastructure problem surfaces. A typical regulated crypto exchange or broker operating in Switzerland does not run a monolithic stack. Liquidity comes from one or more external providers. Custody sits with a separate qualified custodian. Fiat rails run through a banking partner. Transaction monitoring, wallet screening, and customer due diligence may each involve different vendors. Each system maintains its own view of the customer, the counterparty, and the transaction, and each updates its sanctions data on its own schedule.
The compliance gap appears in the seams. When a client initiates a withdrawal, the execution layer checks whether the trade can fill. The custody layer checks whether assets are available. The banking layer checks whether the fiat transfer clears. But if sanctions screening happens asynchronously, after execution, before settlement, or in overnight batch runs, the transaction may be processed against a stale list. A designation that entered force that morning may not appear in the screening engine until the next vendor update cycle.
Switzerland's revised Anti-Money Laundering Act, adopted by Parliament in September 2025 and entering into force in late 2026, makes this architecture question explicit. The new Article 8d AMLA expressly requires financial intermediaries to take organisational measures to prevent violations of coercive measures under the Embargo Act. FINMA's corresponding revision to its Anti-Money Laundering Ordinance introduces Article 30, which cross-references standard AML provisions, travel rule requirements, effective monitoring of business relationships and transactions, assessment of risks related to new technologies, and applies them to sanctions compliance. The message is structural: sanctions screening is not a standalone function. It must be integrated into the operational fabric of the business.
The timing is not accidental. Switzerland faces its fifth-round FATF mutual evaluation in 2026-2027. FATF's most recent targeted update on virtual assets, published in July 2026, highlighted that significant gaps remain across jurisdictions in operationalising licensing frameworks, identifying unlicensed VASP activity, and ensuring risk-based supervision. Switzerland's regulators are demonstrating, through ordinance revisions and enforcement posture, that implementation will be scrutinised.
For compliance officers at regulated exchanges and custodians, this creates a practical dilemma. The regulatory expectation is real-time or near-real-time screening at the point of execution and settlement. The vendor landscape delivers batch updates and siloed data models. Bridging that gap requires either building proprietary integration layers that synchronise sanctions data across every touchpoint in the transaction lifecycle, or accepting the residual risk that transactions may slip through unscreened during the window between a list update and vendor propagation.
Neither option is comfortable. Custom integration is expensive, fragile, and creates ongoing maintenance burden as vendors change APIs or data formats. Accepting residual risk is a regulatory posture that invites enforcement attention, particularly when the underlying obligation is not to screen within a reasonable timeframe, but to screen before the transaction is processed.
The root issue is that compliance in a multi-vendor environment becomes a coordination problem rather than a policy problem. No amount of governance documentation changes the fact that your LP's sanctions data may be 48 hours behind your custodian's, or that your banking partner's screening engine may not flag an address that your blockchain analytics tool has already attributed to a designated entity. These are not failures of intent. They are failures of architecture.
Swiss regulators understand this. FINMA's language, that third-party reliance is insufficient, that screening must occur before transactions settle, implies that the burden falls on the regulated entity to ensure synchronisation. The question for compliance leaders is whether their current infrastructure can bear that weight, or whether the operational model itself creates exposure that scales with transaction volume.
As sanctions regimes grow more dynamic and list changes arrive with increasing frequency, the gap between regulatory expectation and operational capability will widen for firms that have not solved the integration problem. The September 8 notification is routine in content but clarifying in implication: real-time compliance requires real-time infrastructure, and that infrastructure does not exist by default in a multi-vendor stack.
References
[1] FINMA Sanctions Notification: ISIL (Da'esh) and Al-Qaida, September 8, 2026
[2] UN Security Council Press Release SC/16446, September 4, 2026
[3] UN Security Council ISIL (Da'esh) and Al-Qaida Sanctions List
[4] FINMA, Switzerland implements international sanctions through the Embargo Act (EmbA)
[5] Swiss Federal Act on Combating Money Laundering and Terrorist Financing (AMLA), Fedlex
[6] FATF Seventh Targeted Update on Implementation of Standards on Virtual Assets/VASPs, July 2026




