Practical guide

Sanctions screening audit trail: what the record should show

Build a sanctions screening audit trail that preserves original results, source versions, analyst reasoning, approvals, changes, and usable evidence references.

On this page

The record should explain the decision, not just the clicks

An audit trail is useful when it shows what the organization knew and did at the time. A sequence of timestamps without the subject, source context, or reasoning cannot fully explain a sanctions review.

Keep the screening event, investigation actions, identity decision, and business disposition distinguishable. Logging a button press is not the same as retaining the evidence behind the decision.

Preserve the original screening context

Record the internal subject reference, submitted identity version, coverage, policy version where used, completion time, source versions, original outcome, and candidate references. Preserve technical failures as failures.

A later source refresh should not silently rewrite the historical facts of an earlier result. If a reviewer consults newer information, record that as additional evidence with its own date and provenance.

Include reasoning, approvals, and corrections

A decision should show supporting, conflicting, and unknown facts, evidence references, reviewer identity, required independent approval, and scope. A correction should state what changed and why rather than making the earlier action disappear.

The decision-note template is designed for this purpose. OFAC FAQ 5 also directs businesses to keep reasoning for match determinations.

Test the evidence reference, not only the export

An export can contain a valid link to a document that has moved or lost its version history. Verify that authorized reviewers can retrieve the intended record and that the external repository meets the organization’s retention and access requirements.

SanctionsKit’s approved external document references do not store the document bytes. Its audit package therefore should be interpreted alongside the evidence repository, not as a guarantee that every referenced original is inside the export.

Avoid unsupported claims about immutability

“Audit trail,” “tamper evident,” and “immutable” describe different properties. Do not infer cryptographic tamper resistance, write-once storage, or legal admissibility from the presence of a timeline. Evaluate the actual product contract and controls.

Limit access, separate duties where needed, review export permissions, and test how corrections are represented. These are concrete controls that can be checked without relying on an unexplained marketing label.

Run a reconstruction exercise

Select a retained case and ask a reviewer who did not work on it to explain the result, source scope, evidence, conclusion, approval, and later changes. Document what cannot be reconstructed and remediate the gap.

Align retention with current OFAC recordkeeping guidance and other applicable requirements. A long retention period is useful only when the preserved record remains understandable and accessible to authorized people.

Official references