Practical guide

OFAC screening requirements: obligations and practical controls

Separate OFAC legal obligations from screening procedures. Build coverage, review, escalation, recordkeeping, and testing controls around your actual risk.

On this page

Compliance obligations are not a universal search checklist

OFAC sanctions obligations depend on the persons, programs, activities, and jurisdiction involved. OFAC FAQ 11 describes the general persons within scope. A software search is one control used to support compliance; the existence of an obligation does not create a universal requirement to use a particular commercial database.

Avoid policies that say only “run an OFAC check.” They leave unanswered which parties, lists, events, evidence, and exceptions the organization will handle. Bank-specific examination guidance can be useful for banks without becoming a legal checklist for every other business.

Translate risk into a documented screening scope

Identify the business relationships and activities that create exposure. Define who is screened, which sources are required, what known identity data is used, and when screening happens. Add ownership and activity-related checks where appropriate rather than assuming direct-list matching covers them.

A supplier onboarding workflow, a payment-party review, and a property closing can need different handoffs. Record who owns each control so an unresolved candidate is not lost between the commercial team and compliance.

Define the review and exception process

OFAC’s match guidance explains that identifying information must be compared when evaluating a candidate. Your procedure should distinguish a potential match, a reasoned dismissal, a confirmed identity, and an incomplete screening. It should also identify who decides the legal or business action.

An unavailable source is not a false positive. A workflow that silently skips a required list changes the scope of the control. An exception must be visible, authorized under policy, and followed to resolution.

  • Required sources and acceptable availability conditions.
  • Input-quality checks and handling for incomplete identities.
  • Reviewer authority, evidence standards, and second review where required.
  • Escalation ownership for unresolved or confirmed identities.
  • Retention, access controls, and periodic control testing.

Retain the records that apply to the activity

Current 31 CFR 501.601 sets recordkeeping requirements for covered transactions and blocked property, including ten-year periods. Do not copy an old five-year OFAC statement from an outdated checklist.

That rule is not a reason to claim that every possible name search has the same legal retention trigger. Determine applicable records, the start of each retention clock, legal holds, and privacy obligations with the responsible team. Align the application’s retention settings with the approved policy.

Test whether the control works in your environment

Use synthetic fixtures and carefully governed known cases to test expected candidates, name variants, missing identifiers, source failures, and review handoffs. Measure missed candidates and noisy alerts separately. A low alert count alone does not show an effective control.

Test the end of the process too: can a reviewer retrieve the source version and reasoning for a retained result? Can operations see a failed rescreen? Can an independent reviewer understand why a candidate was dismissed?

Use software as a control, not a guarantee

SanctionsKit provides selected-source screening, retained evidence, case review, and monitoring. It does not certify that a business is OFAC compliant, perform every ownership inquiry, or decide which transactions are authorized.

Use this guide as an operational starting point, not legal advice. The next step is a written screening policy tied to the organization’s actual obligations and workflow.

Official references