Practical guide
Who must comply with OFAC? Businesses, people, and screening scope
Understand OFAC’s general jurisdiction, why nonbanks still consider sanctions, and how compliance obligations differ from a universal screening mandate.
On this page
Start with OFAC’s jurisdiction statement
OFAC FAQ 11 explains that U.S. persons must comply, including U.S. citizens and permanent residents wherever located, persons within the United States, and U.S.-incorporated entities and their foreign branches. Some sanctions programs extend particular requirements to other persons or relationships.
This is a starting point, not a complete cross-border legal analysis. A business should assess the applicable program and activity rather than using an address, payment currency, or company label as its only test.
Sanctions obligations are not limited to banks
Retail, property, professional-services, trade, nonprofit, and technology businesses can encounter sanctions questions. A nonfinancial business should not assume that sanctions are solely its bank’s responsibility. At the same time, bank examination procedures do not automatically apply word for word to every business.
A useful distinction is between an obligation to avoid prohibited activity and the controls selected to meet that obligation. Name screening, ownership diligence, country controls, and transaction review answer different parts of that problem.
Decide which parties the workflow needs to cover
Map the people and entities that matter to the relationship. Depending on the activity, these might include the customer, supplier, payee, beneficial owners, or another participant. Document why each role is in or out of scope. Screening a brand name cannot stand in for identifying the legal counterparty.
For an invented property purchase, the buyer’s company name, seller’s legal identity, and an unfamiliar refund recipient are different subjects. Searching only the individual who filled out the form can leave a gap. This is a process-design example, not a universal legal rule about all property files.
Keep BSA/AML rules and OFAC controls distinct
Certain financial institutions have specific Bank Secrecy Act and customer-due-diligence duties. Those requirements are not identical to sanctions restrictions. A business can have a sanctions question without being subject to every bank-style AML obligation.
Likewise, a cash-reporting form, an identity check, or a beneficial-ownership filing does not establish that a sanctions comparison has been completed. The KYC, AML, and sanctions guide separates these controls.
Make responsibility explicit when another business is involved
A lender, payment provider, settlement agent, or outsourced screening vendor may perform part of a workflow. Document what it actually covers, which results are available to your team, and how exceptions reach the right decision-maker. Do not infer coverage from a commercial relationship alone.
For example, a dealer’s financing partner may review a financed transaction while the dealer also handles a cash sale. The existence of the financing relationship is not evidence that the cash-sale parties were screened.
Build a proportionate control and review it
Begin with a documented risk assessment, authorized advice on legal scope, selected sources, and clear checkpoints. Train staff to distinguish a possible match from a confirmed identity and a technical failure from a completed no-match result. Keep records and test the process.
SanctionsKit supports the screening and review portion through the dashboard and API. It does not determine whether every law applies to your business or transfer the organization’s responsibilities to a software provider.