search

OFAC Compliance for Banks: Sanctions Screening Best Practices

5/18/2026

OFAC compliance is routinely taught alongside BSA/AML and is fundamentally different from it. The BSA asks you to detect and report. Sanctions ask you to stop — and they impose strict liability, with no suspicion standard, no dollar threshold, and no requirement that anyone intended anything.

An institution that processes a single prohibited transaction has violated sanctions law, whether or not its program was reasonable and whether or not anyone was negligent. That asymmetry should drive how the control is designed.

What OFAC Administers

The Office of Foreign Assets Control, part of the Treasury Department, administers and enforces economic and trade sanctions based on U.S. foreign policy and national security goals. Sanctions programs target foreign countries and regimes, terrorists, international narcotics traffickers, those engaged in proliferation of weapons of mass destruction, and other threats.

The obligations apply to all U.S. persons — not only financial institutions — and extend to foreign branches and, for certain programs, foreign subsidiaries.

The core lists and concepts:

The SDN List — Specially Designated Nationals and Blocked Persons. Individuals and entities whose property must be blocked. Also includes vessels and aircraft.

Consolidated Sanctions List — non-SDN lists covering sectoral sanctions and other restrictions that prohibit specific types of dealings rather than requiring full blocking.

Country and regional programs — comprehensive or targeted programs restricting dealings with particular jurisdictions.

The 50 percent rule — an entity owned 50 percent or more, directly or indirectly, in the aggregate, by one or more blocked persons is itself blocked, even though it is not named on any list. This is the single most important concept in sanctions compliance, because name screening cannot find it. Identifying it requires ownership analysis.

Blocking Versus Rejecting

These are different actions with different consequences, and staff confuse them constantly.

Blocking applies when property in which a blocked person has an interest comes into your possession or control. The funds must be placed into a blocked, interest-bearing account. They may not be returned to the sender, may not be forwarded, and may not be released without an OFAC license. The customer relationship is frozen, not terminated.

Rejecting applies where a transaction is prohibited but no blockable property interest came into your possession — for example, a payment instruction you decline to process. The transaction is refused and, where applicable, returned.

Getting this wrong in either direction is a violation. Returning funds that should have been blocked releases blocked property. Blocking funds that should have been rejected holds property without authority.

Reporting Obligations

Blocked property must be reported to OFAC within 10 business days of blocking.

Rejected transactions must be reported within 10 business days.

An annual report of blocked property held as of June 30 is due by September 30 each year.

These deadlines are short and are frequently missed by institutions that block correctly but treat the report as an administrative follow-up. The report is part of the obligation, not a courtesy.

What to Screen, and When

At onboarding — customers, beneficial owners, signers, and related parties, before the account is opened.

On every transaction — wires, ACH, checks presented, card transactions, and trade finance documents. Interdiction should occur before release, not after settlement.

On list changes — the entire customer base rescreened when lists are updated. Lists change without notice and without a schedule, so an institution screening its portfolio monthly may carry a prohibited relationship for weeks. Screening promptly after each update is the expectation.

Periodically across all data — including counterparties, beneficiaries, vendors, employees where appropriate, and loan participants.

Tuning the Screening

This is where sanctions programs actually succeed or fail, and it is an engineering problem more than a legal one.

Match logic. Too strict and you miss transliteration variants, reversed name order, and common misspellings — the ways sanctioned parties actually appear in payment messages. Too loose and analysts receive hundreds of daily hits, which produces mechanical clearing and defeats the control entirely. Both failure modes look like a working program on a dashboard.

Test it. Run known-positive test cases through the system periodically — variants of listed names, names embedded in free-text fields, and non-Latin transliterations — and confirm the system catches them. An untested filter is an assumption.

Document tuning decisions. Every threshold and every suppression rule should have a recorded rationale and an owner. "The vendor set it up" is not a defensible answer for why a match threshold sits where it does.

Measure clear rates and time-to-clear. A queue cleared at a rate of hundreds per analyst-day is not being reviewed. Volume is the enemy of accuracy here, and reducing false positives through better tuning is a compliance improvement, not just an efficiency one.

Escalate rather than clear on ambiguity. Analysts should have a defined path for uncertain matches, including consulting OFAC's own resources and its hotline.

Licenses

Some otherwise-prohibited activity is authorized.

General licenses authorize categories of transactions without an application, and are published within the sanctions programs. They change, and an institution relying on one should confirm it remains in effect.

Specific licenses are issued on application for particular transactions. Applying takes time, and the transaction must not proceed while the application is pending.

Institutions should never assume an exception; they should identify the license and record which one they relied on.

Enforcement and Self-Disclosure

Penalties are assessed under OFAC's Economic Sanctions Enforcement Guidelines, which weigh factors including willfulness, awareness of the conduct, the harm to sanctions program objectives, the institution's compliance program, remedial response, and cooperation.

Voluntary self-disclosure is a significant mitigating factor — typically the difference between a substantially reduced penalty and a full one. Where an institution discovers an apparent violation, the practical calculus almost always favors prompt disclosure through counsel over hoping it goes unnoticed, particularly since the transaction records sit in payment systems that other institutions and regulators can see.

OFAC has also published guidance describing the essential components of a sanctions compliance program: management commitment, risk assessment, internal controls, testing and auditing, and training. An institution whose program can be described in those five terms, with evidence for each, is in a materially better position when something goes wrong.

Practical Controls

  • Screen before release, not after. Post-settlement detection means the violation already occurred.
  • Own the 50 percent rule. For higher-risk entity customers, perform ownership analysis rather than relying on name screening, and refresh it when ownership changes.
  • Keep the sanctions risk assessment separate from the BSA/AML risk assessment. The risks and the controls differ, and combining them obscures both.
  • Train the strict liability point explicitly. Staff trained only on BSA thinking will apply a suspicion mindset to a rule that has none.
  • Test the filter, and document the tests.
  • Calendar the annual blocked property report. It is missed every year by institutions that blocked correctly.

Formal coverage is available in the Office of Foreign Asset Control (OFAC) course, and the surrounding financial crimes framework in our BSA and AML training and the Certificate in BSA and AML Compliance.

Handling a Hit

When a genuine match surfaces, the first hour matters and improvisation is expensive. A written escalation procedure should be in place before it is needed, and it should answer four questions.

Who decides? A named role with authority to stop a payment, not a committee that meets tomorrow. The transaction cannot be released while the question is open, and someone must be empowered to say so.

What is preserved? The payment message, the screening result, the customer record, and the timeline of who knew what and when. This becomes the record supporting either the blocking report or the decision that the match was false.

Who is told, and who is not? Counsel and senior management, immediately. The customer is a harder question: there is no SAR-style confidentiality rule for sanctions, but statements to a customer about a blocking should be scripted with counsel, because a blocked party has no right to their funds and telling them the wrong thing can create problems.

What is the deadline? Ten business days from blocking to report. That clock starts on the blocking, not on the completion of an internal review, and institutions that treat the report as the last step of a leisurely investigation miss it.

Rehearsing this once, on a hypothetical, costs an afternoon and is the difference between a controlled response and a scramble.

Where Sanctions Programs Actually Break

Enforcement actions in this area follow a small number of recurring patterns, and none of them involve an institution deciding to process a prohibited transaction.

Screening that was never applied to a channel. A new product, an acquired portfolio, or a third-party origination stream that was implemented without being connected to the interdiction system. The screening works perfectly on everything it sees; the failure is what it never sees. Any new payment channel, product, or partner should require confirmation that screening covers it before launch.

Free-text fields. Payment messages carry names in structured fields and also in remittance information, originator-to-beneficiary instructions, and reference lines. Filters configured to read only structured fields miss names deliberately placed elsewhere, and some enforcement actions have turned on exactly this.

Stripping. Removing or altering identifying information from payment messages so that screening elsewhere in the chain does not catch it. This is the conduct that produced the largest sanctions penalties in banking history. It is not an operational error — it is deliberate — but it typically begins as an accommodation to a customer whose payments keep getting stopped.

The 50 percent rule. An entity nobody screened positive on, because it is not listed, owned by parties who are. Name screening structurally cannot find this, and institutions relying on screening alone are exposed by design.

Alert fatigue. A queue tuned so loosely that analysts clear hundreds of hits a day mechanically. The control exists, the alerts are generated, and the genuine match is cleared in the flow along with everything else. This is why false positive reduction is a risk reduction rather than an efficiency exercise.

The annual report. Not a violation of the prohibition, but a violation nonetheless, and one that recurs annually at institutions that handle blocking correctly and treat the September 30 filing as optional housekeeping.

Frequently Asked Questions

Is OFAC compliance part of BSA/AML?

No. They are separate regimes commonly trained together. The BSA imposes recordkeeping and reporting duties triggered by thresholds and suspicion, while OFAC prohibits dealings with sanctioned parties under strict liability — no suspicion standard, no dollar threshold, and no intent requirement. Policies and risk assessments should treat them distinctly.

What is the 50 percent rule?

An entity owned 50 percent or more, directly or indirectly and in the aggregate, by one or more blocked persons is itself blocked even though it appears on no list. Because name screening cannot detect it, compliance requires ownership analysis for higher-risk entity customers and refreshed analysis when ownership changes.

What is the difference between blocking and rejecting a transaction?

Blocking applies when property in which a blocked person has an interest comes into the institution's possession or control: the funds go into a blocked interest-bearing account and cannot be returned, forwarded, or released without an OFAC license. Rejecting applies where a transaction is prohibited but no blockable property interest was received — the institution declines to process it.

How quickly must blocked property be reported?

Within 10 business days of blocking. Rejected transactions must also be reported within 10 business days. Separately, an annual report of blocked property held as of June 30 is due by September 30 each year, and that annual report is the one most commonly missed.

How often should we screen our customer base?

At onboarding, on every transaction before release, and promptly after each list update — not on a fixed monthly cycle, since lists change without notice and a stale screen can leave a prohibited relationship in place for weeks. Periodic screening should also extend beyond accountholders to counterparties, beneficiaries, and vendors.

Does voluntary self-disclosure help if we find a violation?

Yes, substantially. Voluntary self-disclosure is an explicit mitigating factor under OFAC's Economic Sanctions Enforcement Guidelines, along with the quality of the compliance program, remedial response, and cooperation. Because the underlying transaction records are visible to other institutions and regulators, prompt disclosure through counsel is usually the better calculation.

BankTrainingCenter.com 9715 Rod Road Suite A Alpharetta, GA 30022 1-770-410-1219 support@BankTrainingCenter.com
Certifications Webinars Seminars
Stay Up To Date
Need Training Or Resources In Other Areas? Try Our Other Training Center Sites:
HR Accounting Financial Services Insurance Mortgage Payroll Real Estate Safety
Training By Delivery Format & Subjects Covered:
Special Promotions Online Training Resource Materials Seminars Webinars All Banking Subjects
Facebook Copyright BankTrainingCenter.com 2026