OFACguidesSDN

OFAC Screening: What It Is, Who Needs It, and How to Do It Defensibly

OFAC screening checks counterparties against the SDN list and OFAC's other sanctions lists. Learn who must screen and how to keep OFAC compliance defensible.

Kleerance Editorial
OFAC Screening: What It Is, Who Needs It, and How to Do It Defensibly

OFAC screening is the process of checking the people and companies you do business with against the U.S. sanctions lists published by the Office of Foreign Assets Control — primarily the SDN list — before you onboard them, pay them, or transact with them. It is how a business avoids dealing with a sanctioned party, and it is a strict-liability obligation for every U.S. person, not just banks.

That last point is where most guidance goes quiet. The vendors selling you screening tools rarely give you a straight answer on what you actually have to do, and the free government tools weren't built to prove you did it. This guide is the straight answer, written for the operator running a lean program — a fintech founder, an importer, a marketplace, a payments company — rather than a bank with a compliance department.

What is OFAC screening?

The Office of Foreign Assets Control (OFAC) is the arm of the U.S. Department of the Treasury that administers and enforces economic and trade sanctions in support of U.S. foreign policy and national security goals. It is simply the act of comparing your counterparties — customers, vendors, beneficial owners, transaction parties — against the lists OFAC maintains, to catch anyone who is sanctioned before money or goods change hands.

There are two buckets of OFAC lists you need to know:

  • The SDN list. The full name is the Specially Designated Nationals and Blocked Persons List. It names thousands of individuals, companies, vessels, and aircraft whose property is blocked and with whom U.S. persons are generally prohibited from dealing. When people say "an OFAC check," they usually mean checking a name against this list of Specially Designated Nationals. Entities on the SDN list are blocked outright.
  • The Consolidated Sanctions List. This bundles OFAC's non-SDN lists — the Foreign Sanctions Evaders list, the Sectoral Sanctions Identifications list, and others. Entities on these lists face narrower or program-specific restrictions rather than a full block, but they still carry real prohibitions.

It helps to separate two ideas that get used interchangeably. OFAC sanctions are the underlying legal restrictions — sometimes aimed at named parties, sometimes at entire countries, regions, or economic sectors (comprehensive sanctions and sectoral sanctions). Screening is the control you run to detect exposure to those sanctions. Checking against the OFAC watch lists is not itself the law; it is the practical way you comply with it. Hold onto that distinction — it matters in the next section.

OFAC is also only one of several authorities that publish restricted-party data. Its sanctions regulations sit within a broader landscape of global sanctions, so a complete program checks the SDN and Consolidated lists alongside the BIS lists, the State Department lists, and the UN, EU, and UK regimes. We cover how those fit together in OFAC vs. BIS vs. SAM.gov and what the BIS Entity List is.

Who must screen for OFAC compliance?

OFAC's economic sanctions bind all U.S. persons: U.S. citizens and permanent residents wherever they are, anyone physically in the United States, and any entity organized under U.S. law, including its foreign branches. The reach extends further than that, though. Because so much of global commerce touches the U.S. financial system, a transaction denominated in U.S. dollars or cleared through a U.S. bank can pull a non-U.S. company into OFAC's jurisdiction, and many foreign firms screen to manage that exposure and the risk of secondary sanctions.

The common misconception is that this is a banking problem. It isn't. OFAC compliance applies to any business that pays or gets paid — importers, SaaS companies, marketplaces, insurers, freelancers hiring abroad. And it is strict liability: you can face a penalty for dealing with a sanctioned party even if you had no idea they were listed. "We didn't know" is not a defense. If you're weighing whether your specific situation requires a program, our founder-focused breakdown on whether you need sanctions screening for your fintech works through the thresholds.

Is OFAC screening actually required by law?

Here is the nuance almost no vendor page will tell you plainly: OFAC's regulations do not mandate any specific screening regime. There is no rule that says "run this software" or "screen every name nightly." What the OFAC regulations require is that you not violate the sanctions. Screening is the risk-based control you adopt to meet that obligation — and OFAC expects you to design controls that fit your own risk, and OFAC requirements scale with that risk.

In practice that means the right question isn't "what's the mandatory tool?" It's "what does a reasonable, risk-based sanctions compliance program look like for a business my size and shape?" That starts with an OFAC risk assessment: which counterparties, geographies, and payment flows expose you, and how much. A payments company moving cross-border funds carries very different risk than a domestic-only SaaS tool, and OFAC expects your program to reflect that difference rather than copy a bank's.

This is genuinely good news for a lean operator. OFAC compliance requirements are not a product you buy; to comply with OFAC you build an OFAC compliance program sized to your risk. You are not required to staff an analyst team — you are required to make sensible, documented choices about how you conduct OFAC screening, and to ensure compliance you actually follow them.

OFAC penalties: what happens if you get it wrong

The consequences of sanctions violations are steep enough that the strict-liability standard bites hard, which is why compliance with OFAC regulations is not optional if you want to comply with sanctions cleanly. Civil penalties can reach well into the millions of dollars per violation, and the amounts are tied to the specific sanctions program and adjusted over time. Willful violations can bring criminal liability on top of that.

There is also a mechanical obligation once you find a real match. If a transaction involves blocked property, you generally must block it, freeze the funds, and report the action to OFAC — typically within 10 business days. You can't simply decline the business and move on.

Beyond the fines sits a quieter risk that hits smaller companies hardest: your bank. Payment processors and banking partners screen you too, and a sanctions incident — or the absence of any demonstrable compliance program — is a fast way to get de-risked out of your accounts. For a startup, losing your banking relationship can be more existential than the penalty itself.

How to run OFAC screening, step by step

A working screening process comes down to when you screen and how you handle what comes back.

How OFAC screening works end to end — screen at onboarding and before payment, review each candidate against the primary source, document the result, and re-screen as lists change.

When to screen

  • At onboarding. Screen every new customer, vendor, or counterparty before you establish the relationship.
  • Before transactions. For higher-risk flows, screen at the point of payment, not just at signup.
  • On an ongoing basis. Lists change constantly. A counterparty who was clear last quarter can be designated tomorrow, so periodically re-screen your existing base — and re-screen on triggers like a change in ownership.

How to handle results

Names rarely match cleanly. Sanctioned parties use aliases, and names get transliterated and misspelled, so effective matching uses fuzzy logic rather than exact-match rules — and returns a confidence score so you can tell a strong hit from noise. When a potential match surfaces, you pause and review it against the primary source before acting. These tools surface candidates; the official register is what confirms them. At volume, manual list screening gives way to automated screening in OFAC screening software, though a person still verifies each hit against the source.

Most of what screening returns is false positives — common names that resemble a listed party without being one. The discipline is to review each candidate, verify it against OFAC's own record, and document your conclusion. Legitimate programs keep a "false hit" record so a name cleared once doesn't have to be re-litigated every time it reappears. For a concrete walkthrough, see how to screen vendors against the OFAC SDN list.

The 50% Rule (the trap most tools don't explain)

You can clear a name against the SDN list itself and still be dealing with a blocked entity. Under OFAC's 50% Rule, any company that is owned 50% or more — in the aggregate, directly or indirectly — by one or more blocked persons is itself treated as blocked, even though its name never appears on the list.

The OFAC 50% Rule: a company owned 50% or more in aggregate by blocked persons is itself blocked, even when its own name never appears on the SDN list.

That is why checking the entity name alone isn't enough for anything beyond the lowest-risk relationships. To catch 50% Rule exposure you have to look through to beneficial ownership and screen the owners, not just the operating company in front of you. It's one of the most common ways a business ends up transacting with a sanctioned party while believing it screened correctly.

Free OFAC search vs. dedicated screening software

OFAC publishes a free Sanctions List Search on the OFAC website, and it's real and useful — one OFAC search against one sanction list at a time, and that sanctions list search covers U.S. names well. If you screen one name a quarter, it's genuinely enough — we'll say that plainly. The question is whether a manual, one-name-at-a-time search against a single sanction list scales to how your business actually operates.

CapabilityFree government searchDedicated OFAC screening
One-off check of a single nameYesYes
One search across OFAC plus other government lists at onceNoYes
Fuzzy matching tuned for aliases and transliterationsLimitedYes
Bulk / batch screening of a customer or vendor baseNoYes
Ongoing re-screening as lists changeNoYes
A timestamped record proving you screenedNoYes
API access to screen inside your own workflowNoYes

Dedicated screening software doesn't replace the primary sources — the best tools link every match straight back to the official government register so you can verify before acting. What it removes is the tab-juggling across six list websites, the re-typing, and the "how do I prove I did this?" problem the free tools were never designed to solve. Kleerance screens across nine government watchlists at once and gives every candidate a 0–100 confidence score with a link back to the source record.

What a defensible OFAC program looks like at SMB scale

"Defensible" is the word that matters, because compliance isn't a one-time lookup — it's a continuing obligation with a paper trail. When a bank, an auditor, or OFAC itself asks how you cleared a counterparty, screenshots and spreadsheets don't hold up. A defensible program at SMB scale has five parts:

  • A short written policy that says who you screen, against which lists, and when.
  • Consistent screening at the points you defined — onboarding, payment, periodic review.
  • Documented decisions on every potential match, including why you cleared a false positive.
  • A timestamped audit trail of every search: the query you ran, the lists you checked, the results, and when.
  • Re-screening, so a newly designated party in your existing base gets caught.

The audit trail is the part teams skip and later regret. It's the difference between saying you have a compliance program and being able to prove it. We go deep on this in what a restricted-party screening audit trail is and why it matters. Kleerance is built around exactly this: every signed-in search is permanently stored with the exact query, the source lists, the full result set, and a UTC timestamp — the record you show when someone asks you to prove the work.

Frequently asked questions

Is OFAC screening mandatory?

OFAC's regulations don't require a specific screening system, but complying with OFAC sanctions is mandatory for all U.S. persons, and screening is the standard risk-based control used to do it. In practice, not screening leaves you exposed to strict-liability penalties for dealing with a sanctioned party.

How often should I re-screen existing counterparties?

Because OFAC updates its lists frequently, re-screen your active base on a regular cadence and on triggers such as a change in ownership. Higher-risk businesses re-screen more often; the right frequency comes out of your OFAC risk assessment.

What's the difference between the SDN list and the Consolidated Sanctions List?

The SDN list — the Specially Designated Nationals and Blocked Persons List — covers parties whose property is blocked and with whom dealings are generally prohibited. The Consolidated Sanctions List covers OFAC's non-SDN lists, which carry narrower, program-specific restrictions. A thorough check of the OFAC sanctions list picture covers both.

Does OFAC apply to non-U.S. companies?

It can. A foreign company transacting in U.S. dollars, clearing through U.S. banks, or dealing with U.S. persons can fall within OFAC's reach, and many screen to manage secondary-sanctions risk even when they aren't U.S. persons themselves.

How do I clear an OFAC false positive?

Review the candidate against OFAC's primary record, compare identifying details beyond the name, document your conclusion and reasoning, and keep that record. A confidence score helps you triage, but the primary source is what actually clears or confirms a match.

Is OFAC screening a background check?

No. It checks parties against publicly published government sanctions lists for compliance purposes. It is not a consumer report or a background check and must not be used to make decisions about credit, employment, tenancy, or insurance eligibility under the Fair Credit Reporting Act.

Screen your first counterparty in seconds

You don't need enterprise software to run a defensible program — you need consistent screening and a record that proves it. Run a free single search against all nine government watchlists, or compare plans to add monitoring, batch screening, and API access as you grow.

Kleerance aggregates publicly available government watchlist data for informational counterparty screening only. It is not a consumer report, not a background check, and not authorized for use in FCRA-regulated decisions. Every potential match must be verified against the official primary source before any action is taken.

This article is for informational purposes only and is not legal advice. Consult a qualified sanctions or export-controls attorney for guidance on your specific obligations.

Related articles