Practical guide

OFAC recordkeeping: screening evidence and retention policy

Understand current OFAC recordkeeping periods, distinguish legal retention from product settings, and preserve screening decisions with usable evidence.

On this page

Check the current rule before copying a retention period

Current 31 CFR 501.601 includes ten-year recordkeeping periods for covered transactions and separate treatment for blocked property. Older materials can still describe five years. Use the current regulation and activity-specific advice when establishing the policy.

Do not translate that into “every search must always be kept for ten years.” Determine which records the rule covers, what event starts the period, which property remains blocked, and whether other legal duties or holds apply.

A retained screening result is one part of the file

A useful file distinguishes the submitted subject, original screening outcome, source versions, analyst reasoning, and business action. A screenshot of a search page rarely explains all five. A later rescreen also does not reconstruct precisely what an earlier source version contained.

Keep enough provenance for someone to understand what the reviewer knew at the time. That includes changes to the customer record and any source ambiguity that affected the decision.

Decide what belongs in the case and what stays elsewhere

Identity documents, contracts, and transaction records may belong in controlled repositories with their own access and retention rules. A case can reference the approved location, version, owner, and verification date without distributing a new copy to every analyst.

SanctionsKit supports retained screening evidence, notes, text attachments, and approved external document references. A referenced document is not copied into SanctionsKit merely because its link appears in the case. Verify the repository’s own retention and access controls.

Align product settings with the approved policy

A software default is not a legal opinion. Review the workspace retention configuration, account history, contractual terms, and the effect of minimal-retention screening before relying on a default. Do not select a short-lived result mode for a workflow that needs a retained case.

The retention documentation describes product behavior. Legal holds, export procedures, and preservation of external evidence need an organization-level process as well.

Test retrieval before an audit or investigation

Choose a retained screening and ask another authorized reviewer to reconstruct the decision. Can they identify the subject version, selected coverage, relevant source record, rationale, approvals, and subsequent changes? Can they open an approved evidence reference without asking the original analyst to search email?

A failed retrieval test is actionable even when the organization has nominally retained every record. Storage duration and useful evidence are different control qualities.

  • Sample retained cases from more than one reviewer and source family.
  • Verify that exported evidence keeps its source and time context.
  • Check access to externally referenced records and version history.
  • Document gaps, assign remediation, and repeat the test after changes.

Plan for correction, closure, and deletion

A mistaken analyst note should be corrected in a way that preserves the history and reason for change. Closing a monitoring relationship should not be confused with deleting every retained screening. Conversely, an obligation to retain some records is not permission to collect unrelated personal data indefinitely.

Use this guide with qualified legal and privacy advice. The practical objective is a policy that identifies the records, owners, access, retention triggers, holds, and eventual disposition clearly enough for the team to execute.

Official references