Practical guide

How to perform an OFAC search and check a possible match

Follow an OFAC search workflow: select SDN or Non-SDN coverage, use known identifiers, review candidates, and document the result without false clearance.

On this page

Start with the scope, not the search box

An OFAC search should begin with the question the organization needs answered. Identify the person or organization, the applicable policy, and the required list coverage. OFAC’s Sanctions List Service provides official list resources; a commercial service can add matching, workflow, and retained evidence around selected data.

Do not confuse a synthetic product demo with a live sanctions search. SanctionsKit’s sandbox is for testing the contract and review flow. Use available production sources and an authorized live workflow for a real customer check.

Use the official OFAC search tool for a manual check

Open OFAC’s official Sanctions List Search. Enter the known name and choose the appropriate subject type and list scope. The form also offers identifier, location, program, and minimum-name-score controls. Use filters deliberately; a narrowly entered detail can change which candidates are returned.

Inspect the list and program columns for each candidate, then open the underlying record and compare the available identifiers. OFAC does not recommend one universal minimum name score. Record the settings used rather than changing the threshold until the results disappear. The commercial API tutorials on this site call SanctionsKit, not this government search interface.

Prepare the identity you actually know

Use the full known name and correct entity type. Keep original-script names and reliable identifiers in the internal customer record where appropriate. Preserve the precision of dates: a year-only source value is not a full date, and a missing value is not an inconsistency.

Confirm which inputs your chosen tool accepts. Sending an unsupported field or putting a whole case narrative in the name box can make the request misleading. The API subject contract is the source of truth for programmatic submissions.

Choose SDN, Non-SDN, or another specific source

Record whether the check covers SDN, selected Non-SDN lists, or a wider documented package. Do not describe a single SDN search as all global sanctions screening. An export-control list and an OFAC blocking list have different purposes even when the same party appears in both.

For a retained API screening, select `sources` or a versioned `package`, not both. Check source availability before the workflow and handle an unavailable required source as an incomplete check.

Inspect possible matches using the original record

Follow OFAC FAQ 5: identify the actual source and compare the available identifying information. Review the name that triggered the candidate, published aliases, type, dates, identifiers, and addresses. Record facts that support identity, conflict with identity, or remain unknown.

A partial name resemblance is not proof of identity. Equally, a blank field cannot be used to dismiss a candidate. The false-positive checklist provides worked review examples.

Save a result that another person can understand

A useful search record contains the submitted identity reference, coverage, result time, source record references, original outcome, reviewer, decision, and reason. Preserve the original result even when the reviewer later dismisses a candidate.

This invented checklist is a process aid, not a legal clearance certificate.

OFAC search record
Internal subject reference: the record being checked
Identity version: the facts available for this check
Coverage: actual sources or package version
Result: completed potential match / completed no match / incomplete
Candidate references: source IDs and listing identifiers
Review: supporting, conflicting, and unknown facts
Next action: named owner and policy-based deadline

What to do after the search

A no-match result can move to the next step of the organization’s process, not automatic universal approval. An unresolved candidate needs evidence or escalation. A confirmed identity requires a separate assessment of the applicable restriction and activity. OFAC states that it does not confirm potential matches or false positives for a business.

Keep retained relationships in an appropriate monitoring process. New names, changed source details, or corrected identifiers can make a later check different from the original one.

Official references