Sanctions screening is the process of comparing customers, counterparties and transactions against official lists of sanctioned persons, entities, vessels and jurisdictions, so that an institution does not deal with a blocked party. It is one control inside a wider sanctions compliance program, which OFAC describes as five components: management commitment, risk assessment, internal controls, testing and auditing, and training. Because OFAC enforces its regulations on a strict liability basis, screening is designed to catch near matches as well as exact ones, and every potential match is reviewed, decided and recorded.
Sanctions screening is the process of comparing the names and identifying details of customers, counterparties and transactions against official lists of sanctioned persons, entities, vessels and jurisdictions, in order to detect dealings that the law prohibits. A sanctions screening program is the set of policies, systems, people and records an institution uses to perform that comparison, decide each potential match, block or reject prohibited transactions, and report them to the authority that administers the sanctions.
In the United States the administering authority for most economic sanctions is the Office of Foreign Assets Control (OFAC), a component of the Department of the Treasury. Sanctions obligations apply to all U.S. persons, not only to banks, and they are separate from the Bank Secrecy Act, although banks usually run sanctions compliance alongside their BSA/AML program.
The legal basis and strict liability
OFAC's reporting, procedures and penalties regulations appear at 31 CFR Part 501, and each sanctions program has its own part of Chapter V of Title 31. OFAC's approach to enforcement is set out in the Economic Sanctions Enforcement Guidelines, published as Appendix A to 31 CFR Part 501. The guidelines describe the general factors OFAC weighs in deciding a response to an apparent violation, including whether the conduct was willful or reckless, the harm to sanctions program objectives, and the existence and adequacy of a compliance program at the time of the violation.
Civil liability for a sanctions violation is strict. In the Tri-Seal Compliance Note of March 6, 2024, the Departments of Commerce, the Treasury and Justice state that OFAC may impose civil penalties for sanctions violations based on strict liability, which means a person subject to U.S. jurisdiction can be liable even without knowing, or having reason to know, that a transaction was prohibited. Strict liability is the reason screening programs are built to find possible matches broadly and then resolve them by review, rather than to look only for exact matches.
The five components of a sanctions compliance program
OFAC's May 2019 framework identifies five essential components of a risk-based sanctions compliance program. The Federal Financial Institutions Examination Council (FFIEC) BSA/AML Examination Manual, in its Office of Foreign Assets Control section, describes a comparable set of expectations for banks: identifying higher-risk areas, internal controls for screening and reporting, independent testing, a designated person responsible for OFAC compliance, and training.
| Component | What it covers |
|---|---|
| Management commitment | Senior management approves the program, gives it adequate resources and authority, and names a person responsible for sanctions compliance. |
| Risk assessment | An assessment of sanctions exposure across customers, products, services, supply chain, counterparties, transactions and geographic locations, refreshed as the business changes. |
| Internal controls | Written policies and procedures, screening systems and lists, escalation and decision rules for potential matches, blocking and rejecting, reporting, and recordkeeping. |
| Testing and auditing | Independent, periodic review of whether the controls work, including whether the screening system finds the matches it is configured to find. |
| Training | Training for employees and relevant stakeholders scaled to their role and the institution's risk profile. |
OFAC states in the framework that it will consider the existence, nature and adequacy of a sanctions compliance program when it resolves an apparent violation, which is one reason the framework is used as the design standard for programs outside banking.
The lists screened
A screening program defines which lists it screens against, and the choice follows from the risk assessment and from the jurisdictions whose law applies to the institution. The principal official sources are:
- United States: OFAC's Specially Designated Nationals and Blocked Persons List (the SDN List), and OFAC's Consolidated Sanctions List of non-SDN lists, such as the Sectoral Sanctions Identifications List.
- United Nations: the United Nations Security Council Consolidated List, which member states implement through their own law.
- European Union: the consolidated list of persons, groups and entities subject to EU financial sanctions, maintained by the European Commission.
- United Kingdom: the UK Sanctions List maintained by the Foreign, Commonwealth and Development Office. Since 28 January 2026 it has been the only source for UK designations; HM Treasury's former OFSI Consolidated List of Asset Freeze Targets closed on that date.
- Canada: the Consolidated Canadian Autonomous Sanctions List published by Global Affairs Canada.
- Australia: the Consolidated List maintained by the Australian Sanctions Office within the Department of Foreign Affairs and Trade.
Lists change frequently, so a program records which list versions were in use when a screening decision was made and how quickly updates are loaded.
What is screened, and when
Screening normally runs at two points. Customer or name screening checks a customer, beneficial owners and other related parties at onboarding and again when lists change. Transaction screening checks payments and the parties, banks, addresses and free-text fields they carry before the payment is released. Institutions also screen vendors and other counterparties where the risk assessment shows exposure.
Fuzzy matching and alert disposition
Names are spelled in many ways, transliterated from other scripts, abbreviated and reordered. Screening systems therefore use approximate or "fuzzy" matching, which scores how closely two strings resemble each other and raises an alert above a set threshold. The threshold is a risk decision: set too high, it misses true matches; set too low, it floods reviewers with false positives. The chosen settings, the reasons for them and the testing behind them are part of the program's documentation.
Each alert is reviewed and closed with a documented decision. OFAC's published guidance on evaluating a potential match (OFAC FAQ 5) describes the steps: confirm that the alert relates to an OFAC list, compare the complete list entry (name, aliases, dates of birth, nationality, addresses, identification numbers) with the institution's own information, decide whether there is a valid match, and then determine whether property must be blocked or the transaction rejected. Alerts that are resolved as false positives are closed with the reason recorded.
Ownership and the 50 percent rule
A party that does not appear on any list can still be blocked. Under OFAC's "Revised Guidance on Entities Owned by Persons Whose Property and Interests in Property Are Blocked" (August 2014), any entity owned 50 percent or more, directly or indirectly, individually or in the aggregate, by one or more blocked persons is itself blocked, whether or not it is named on a list. A name-matching system cannot detect this on its own, so programs combine screening with ownership information collected during customer due diligence. Other jurisdictions apply their own ownership and control tests, which differ from OFAC's.
Blocking, rejecting, reporting and recordkeeping
When a valid match is confirmed, the regulations of the relevant program determine whether property must be blocked (frozen) or the transaction rejected. Blocked property and rejected transactions are reported to OFAC within 10 business days (31 CFR 501.603 and 501.604), and holders of blocked property file an annual report of blocked property as of June 30 by September 30 (31 CFR 501.603).
Records of transactions subject to OFAC regulations are kept under 31 CFR 501.601. The retention period was extended from five years to ten years, following 2024 legislation that lengthened the statute of limitations for violations of the International Emergency Economic Powers Act and the Trading with the Enemy Act from five to ten years. OFAC adopted the ten-year period by an interim final rule published in September 2024, effective March 12, 2025, and finalized it in March 2025.
PEP screening as a separate practice
Screening for politically exposed persons (PEPs) is often run through the same software as sanctions screening, but it serves a different purpose. A PEP is not prohibited; PEP status is a risk factor that informs customer due diligence and the depth of review. The Joint Statement on Bank Secrecy Act Due Diligence Requirements for Customers Who May Be Considered Politically Exposed Persons (FinCEN and the federal banking agencies, August 2020) states that due diligence for these customers should be commensurate with the risk and that the customer due diligence rule does not create a separate PEP requirement. A PEP match therefore feeds customer risk rating rather than a block or reject decision.
Who performs the work
A designated sanctions compliance officer, or the BSA officer where the roles are combined, owns the program. Screening analysts review and disposition alerts, with escalation to the compliance officer or legal counsel for possible true matches. Independent testing, performed by internal audit or an outside party, reviews the program and typically includes testing of the screening system's configuration and list coverage.
Primary sources
- OFAC, A Framework for OFAC Compliance Commitments (May 2019): The five essential components of a sanctions compliance program.
- Tri-Seal Compliance Note: Obligations of foreign-based persons to comply with U.S. sanctions and export control laws (Commerce, Treasury, Justice, March 6, 2024): States that OFAC may impose civil penalties on a strict liability basis.
- Economic Sanctions Enforcement Guidelines, Appendix A to 31 CFR Part 501: The general factors OFAC weighs in responding to an apparent violation, including the compliance program in place.
- 31 CFR 501.601, 501.603 and 501.604: Recordkeeping (ten years), reports of blocked property and the annual report, and reports of rejected transactions.
- OFAC, Reporting, Procedures and Penalties Regulations, final rule, 90 FR (March 21, 2025): Adopts the ten-year recordkeeping period first published as an interim final rule in September 2024.
- FFIEC BSA/AML Examination Manual, Office of Foreign Assets Control: Supervisory expectations for a bank's OFAC compliance program, risk assessment and screening controls.
- OFAC, Revised Guidance on Entities Owned by Persons Whose Property and Interests in Property Are Blocked (August 13, 2014): The 50 percent rule, including aggregation of ownership by multiple blocked persons.
- OFAC FAQ 5: OFAC's steps for evaluating whether a screening alert is a valid match.
- OFAC Specially Designated Nationals and Blocked Persons List: The primary U.S. sanctions list and the Consolidated (non-SDN) lists.
- United Nations Security Council Consolidated List: Individuals and entities subject to UN Security Council sanctions measures.
- Consolidated list of persons, groups and entities subject to EU financial sanctions: The European Commission's consolidated EU list.
- The UK Sanctions List (FCDO): The single source for UK sanctions designations since 28 January 2026.
- Consolidated Canadian Autonomous Sanctions List (Global Affairs Canada): Persons listed under Canada's Special Economic Measures Act and related statutes.
- Consolidated List (Australian Department of Foreign Affairs and Trade): Persons and entities subject to Australian sanctions.
- Joint Statement on Bank Secrecy Act Due Diligence Requirements for Customers Who May Be Considered Politically Exposed Persons (August 21, 2020): PEP due diligence is risk-based; the CDD rule creates no separate PEP requirement.