Skip to Main Content

Sanctions Policy

The United Nations (UN), European Union (EU), the UK, and the United States (US) have established sanctions and embargo programs designed to prohibit or regulate trade with certain countries, entities, and individuals. Some of these controls are designed to penalise countries for human rights violations, control weapon proliferation and/or limit commerce with entities and individuals associated with terrorism or narcotics trafficking.

Applicable sanctions laws include those managed by the US Office of Foreign Assets Control (OFAC) sanctions regulations, various UK Statutory Instruments which implement EU sanctions regulations, and the UK Export Control Act 2002 (hereon in collectively known as “the Sanctions Laws”). Please see the below links.

The Sanctions Laws prohibit trade with any party (or individual or entity) that has been specifically listed on one of the various sanctions lists or trade with any party in an Embargoed Country (defined below) without prior governmental permission.

Policy Statement

Phoenix Software (“the Company”) has established a statement for Sanctions policies, procedures, guidance, awareness, and monitoring (the “Code”). The Company is furthermore committed to maintaining, developing, and constantly improving the Code.

This Code, and the internal controls herein, have been designed to prevent violations of the Sanctions Laws from occurring, avoid the appearance of wrongdoing and enable the Company to respond promptly and effectively to any enquiries about its conduct. The code is also published on our website and available to the public for review.

Scope

The Company’s Board of Directors has overall responsibility for the development and implementation of its Sanctions policy; the day-to-day management, operation and monitoring of its Sanctions procedures is carried out by the Company’s Managing Director.

The Code applies to all entities within the Group and to all individuals working at all levels and grades. This includes directors, senior managers, employees, agency workers and any other person working for us regardless of location.

The Company will take appropriate action to ensure that third parties, such as clients, customers, consultants, contractors, agents, suppliers, advisers, and joint venture partners (“Third Parties”), also understand and commit to the principles and relevant practices of the Code.

Code Guidelines

All Employees, without prior approval from the Company’s Managing Director, are not permitted to engage in any business or dealings with Embargoed Countries, Blocked Persons, BIS Restricted Parties, or individuals or entities listed as a sanctions target by UK and/or EU Legislation; or facilitate transactions with third parties that involve Embargoed Countries, Blocked Persons, or BIS Restricted Parties.

The Code prohibits all Employees from engaging in direct and indirect business and dealings with Embargoed Countries and Blocked Persons. This means that the Company will not enter into any agreement with end-users or other customers whereby the Company agrees to export products or services to or import products or services from Embargoed Countries.

Additionally, all Employees will not authorise distributors or agents to resell products to customers in Embargoed Countries. More specifically, the Company will not enter into a distribution agreement that includes any Embargoed Country in the distributor’s authorised “territory”.

Should an Employee learn that a distributor is reselling products to an Embargoed Country they are required to immediately notify the Company’s Managing Director.

Third Party Business Relationships

All new business relationships with Third Parties are reviewed by the relevant Departmental Manager and checks on their suitability and integrity are carried out prior to being appointed, according to the procedure set out above.

The Company’s zero-tolerance approach to Sanctions must be communicated to all Third Parties at the outset of any business relationship with them, and they are required to commit to the principles and relevant practices of the Code as a term of their engagement. This commitment will be subject to monitoring by the Company’s Managing Director.

Awareness

The Company will provide periodic Sanctions compliance awareness to educate directors about the requirements and obligations of Sanctions Laws and this Code. This is reviewed at yearly intervals, with refreshers taking place to update them with any developments.

The Company will encourage all its business associates to adopt similar Sanctions compliance awareness in their organisations.

Employee Responsibilities

It is the Employee’s responsibility to ensure that they understand and comply with the terms of the Code. Should they be in any doubt as to how to proceed in a particular circumstance the matter should be referred to the Company’s Managing Director before proceeding.

Controls, Monitoring & Review

The Company is committed to controlling, monitoring and assessing the implementation and effectiveness of its Sanctions Policy and procedures.

Controls

As the majority of the Company’s customers are based in the UK, the Company’s risk exposure to sanctioned countries is very low. However, there are controls in place within the Finance and Operations teams to identify accounts/orders that may be impacted by sanctions and in breach of this policy.

At point of account creation, the Credit Control team carry out a credit check using third party tools Credit Checker and Experian, which will identify the customer accounts country of registration. If all checks are passed and it has been confirmed there is no breach of the Code, the account is created, and Sales can begin to add orders. However, if a conflict to the Code is identified, the account is escalated to the Finance Director and no orders can be placed.

For UK registered companies, with a UK bank account, licences purchased to be used outside of the UK must conform to the UK Sanctions List and Vendor would not be blocked by default. However, checks would be made against the UK Government sanctions list if it is suspected that licences are going to be used in these countries.

On a monthly basis, the Operations team will validate a list of sanctioned countries against those outlined by Microsoft and the UK Government, maintaining an audit trail of countries that are added or removed from this list.

As per the End User Licensing Agreement (EULA) between the Vendor and End User (customer), it is the End User’s responsibility to ensure the licence usage is compliant with the agreed terms, therefore the Company cannot be held liable for any misuse.

Monitoring & Review

The Finance Department reviews the Sanctions Policy annually, ensuring its suitability, adequacy and effectiveness.

In addition, an annual external audit is carried out to validate whether there may have been any potential breaches of the Code. Following an audit, any improvements to existing monitoring or processes around sanctions will be made at the earliest opportunity.

Employees are invited to comment on the Code and suggest ways in which it might be improved. All comments, suggestions and queries should be forwarded to the Finance and Governance Departments.

The Code does not form part of any employee’s contract of employment, and it may be amended at any time.

Confidential Reporting

The Company expects and requires all Employees who have knowledge of, or reason to suspect, any violation of this Code to contact the Company’s Managing Director immediately.

All and any reports of suspected violation will be dealt with in a safe and confidential manner (see ‘Whistleblowing Policy’) and will be investigated rigorously.

Last revised: 10 March 2026