
Client Intake Screening for Consulting and Advisory Firms
A practical guide for consulting and advisory firms on screening clients at intake for sanctions and conflicts before engagement, covering what to screen against, beneficial ownership traps, a repeatable intake workflow, and ongoing re-screening for long engagements.
Consulting and advisory firms have historically treated client intake as a business development and conflicts-checking exercise, with sanctions screening, if it happens at all, sitting as an afterthought handled informally by whoever ran the conflicts check. That separation is no longer defensible.
A consulting engagement with a sanctioned client, or with a client whose beneficial ownership traces to a sanctioned party, exposes the firm to the same regulatory liability that applies to financial institutions, regardless of whether the firm itself is a regulated entity.
This guide sets out what advisory and consulting firms should screen clients against at intake, the most common compliance traps that catch firms in this category specifically, and how to build a repeatable intake workflow that covers both the initial engagement decision and the ongoing life of a long-running client relationship.
Why This Matters for Firms Outside Financial Services
Consulting and advisory firms are not typically obliged entities under AML regulation in the way banks and FinTechs are, but that does not mean sanctions exposure does not apply to them. From a regulatory perspective, a violation occurs as soon as a business relationship is formed with a sanctioned entity. There is no grace period for new client relationships. A firm that signs an engagement letter with, invoices, or accepts payment from a sanctioned party or entity has engaged in a prohibited transaction, independent of whether the firm holds any financial services license.
A well-documented case involved PwC's work for Sonangol, Angola's state-owned oil company, where the firm audited Sonangol's accounts while simultaneously holding paid advisory contracts on the company's restructuring during the tenure of Isabel dos Santos, daughter of Angola's then-president, as Sonangol's chair. The payments were investigated as part of the Luanda Leaks reporting, which found that PwC, alongside Boston Consulting Group and McKinsey, received tens of millions of dollars routed through an obscure Dubai-based intermediary as part of a project to restructure Sonangol while dos Santos led the company. The case is instructive precisely because it was a consulting and advisory relationship, not a financial services transaction, that produced both the conflict and the reputational fallout, illustrating the risks firms face when client relationships intersect with politically exposed individuals. (Source: ICIJ, "Banking documents reveal consulting giants' cash windfall under Angolan billionaire Isabel dos Santos")
What to Screen Clients Against at Intake
Sanctions Lists
Every prospective client, the named legal entity and the individuals authorized to sign the engagement, should be screened against the core sanctions lists: the OFAC SDN list, the EU consolidated sanctions list, the UN Security Council Consolidated List, and the UK OFSI list.
{{snippets-guide}}
Beneficial Ownership: The Trap That Catches Advisory Firms Specifically
This is the single most common compliance failure in client intake across professional services, and it catches advisory firms more often than financial institutions because advisory engagements frequently involve complex corporate clients with layered ownership structures. One of the most frequent compliance failures is screening only the legal entity, the account holder, while ignoring the ultimate beneficial owners and controlling parties.
A company might be clean on its face but if it is 60% owned by a sanctioned individual, engaging with it is a direct violation of the OFAC 50 percent rule.
The aggregation effect of the 50 percent rule is frequently missed: if two sanctioned individuals each own a 30% stake in a company, their combined ownership surpasses the 50% threshold, resulting in the company being effectively sanctioned even though no single owner crosses the threshold individually. Every individual with a 25% or greater stake, plus directors and authorized signatories, requires screening, not just the named legal entity on the engagement letter.
Politically Exposed Persons and Related Close Associates
PEP screening at intake should extend beyond the immediate client contact to the broader ownership and governance structure. Related close associates include business partners, well-known professional consultants, and direct family members such as spouses, children, and parents.
Enhanced due diligence is triggered even though being a related close associate is not itself a crime. For advisory firms, this is particularly relevant where the client relationship involves government-adjacent entities, state-owned enterprises, or politically connected business families, common in jurisdictions with concentrated economic and political power.
Adverse Media
Adverse media, also known as negative news, refers to information from media sources indicating potential sanctions risks linked to certain customers or business partners, offering early warning signs of non-compliance ahead of any formal designation. For consulting and advisory engagements specifically, adverse media screening also surfaces reputational risk relevant to engagement acceptance decisions that go beyond pure sanctions exposure, including pending litigation, regulatory investigations, or credible fraud allegations involving the prospective client.
A Repeatable Intake Workflow
Build the Relationship Map, Not Just a Single Name Check
High-performing compliance teams don't screen related parties in separate silos. They use a single-workflow network screen: as the entity provides its ownership structure, the system builds a digital map of the relationship, then triggers screening calls that check the company, directors, beneficial owners, and signatories simultaneously. If a director is a PEP and a beneficial owner is a related close associate, the system doesn't just flag them individually; it raises the entity's overall risk score.
For advisory firms, this means the intake form itself should be designed to capture ownership structure, not just the contracting entity's name, since the screening that matters most often cannot happen without that underlying data being collected at the point of intake.
Define the Inhibition Trigger
If any single related party returns a confirmed match, the entire onboarding for the entity should be automatically inhibited, meaning the engagement should not proceed to signature, billing setup, or work commencement until the match has been investigated and resolved. This is a policy decision the firm needs to make explicit before it is tested in practice, not something to improvise when the first confirmed match appears.
Integrate Screening Into the Engagement Acceptance Process
Many advisory firms already run a structured conflicts check before accepting new business. Modern client intake platforms combine firm data, third-party intelligence, sanctions lists, and AML screening to guide every approval, converting approved intake data into engagement letters and routing for review and signature. Sanctions and beneficial ownership screening should be embedded into this same workflow, not run as a separate, parallel process that conflicts checking and sanctions screening teams handle independently, since duplicating the intake process across two unconnected systems is where data and accountability gaps emerge.
Ongoing Re-Screening for Long Engagements
Why a One-Time Check at Signature Is Not Sufficient
Treating screening as a gate that stays closed after entry is a recipe for disaster. A client who passes today may be sanctioned tomorrow. Without ongoing monitoring, an exposure window opens where a prohibited actor can operate freely inside the relationship for years until the next periodic review.
This is a particularly acute risk for consulting and advisory engagements, which often run for months or years rather than resolving in a single transaction. A multi-year advisory mandate signed with a clean client today carries genuine sanctions risk if that client's ownership or designation status changes midway through the engagement and the firm has no mechanism to detect it.
Building Continuous Monitoring Into the Client Lifecycle
Risk doesn't end at onboarding. Firms should receive alerts when client ownership, sanctions status, litigation exposure, or jurisdictional risk shifts, with strategic reviews triggered based on configurable AML, independence, or risk scoring thresholds. Continuous monitoring that automatically re-screens existing clients against list updates removes the dependency on remembering to schedule periodic manual reviews, which is the practical failure mode in most firms that lack an automated re-screening process.
Onboarding should feed directly into a daily batch-screening cycle for the existing client base, rather than relying on an annual or ad hoc review that leaves long gaps between checks.
Embedding Screening Into the Firm's Existing Systems
For advisory and consulting firms, the practical path to a working screening program is integration with the systems intake teams already use, rather than a standalone tool that creates a separate manual step. A screening API integrated into the firm's CRM or intake platform allows the relationship-mapping and screening process described above to happen automatically as part of the existing engagement acceptance workflow.
For firms that prefer a lighter-weight approach without full API integration, a manual screening portal supporting batch upload of an Excel file with the full relationship map, the company, directors, beneficial owners, and signatories, provides a practical middle ground for firms screening on a per-engagement basis rather than continuously across a large existing client book.
{{snippets-case}}
Conclusion
Client intake screening for consulting and advisory firms requires the same rigor applied in financial services, even though the regulatory framework that compels it is less explicit for non-financial professional services. The specific trap that catches advisory firms, screening the named contracting entity while missing the beneficial ownership structure behind it, is well documented and avoidable with the right intake workflow design. Firms that build relationship-mapping and continuous re-screening into their existing engagement acceptance process, rather than treating sanctions screening as a one-time check separate from conflicts review, close the exposure window that catches firms relying on a single point-in-time check at signature.
sanctions.io is a highly reliable and cost-effective solution for real-time screening. AI-powered and with an enterprise-grade API with 99.99% uptime are reasons why customers globally trust us with their compliance efforts and sanctions screening needs.
To learn more about how our sanctions, PEP, and criminal watchlist screening service can support your organisation's compliance program: Book a free Discovery Call.
We also encourage you to take advantage of our free 7-day trial to get started with your sanctions and AML screening (no credit card is required).
