Skip to content
Reference

Sanctions Screening Program: Definition, Components and Process

The short version

Sanctions screening is the process of comparing customers, counterparties and transactions against official lists of sanctioned persons, entities, vessels and jurisdictions, so that an institution does not deal with a blocked party. It is one control inside a wider sanctions compliance program, which OFAC describes as five components: management commitment, risk assessment, internal controls, testing and auditing, and training. Because OFAC enforces its regulations on a strict liability basis, screening is designed to catch near matches as well as exact ones, and every potential match is reviewed, decided and recorded.

Sanctions screening is the process of comparing the names and identifying details of customers, counterparties and transactions against official lists of sanctioned persons, entities, vessels and jurisdictions, in order to detect dealings that the law prohibits. A sanctions screening program is the set of policies, systems, people and records an institution uses to perform that comparison, decide each potential match, block or reject prohibited transactions, and report them to the authority that administers the sanctions.

In the United States the administering authority for most economic sanctions is the Office of Foreign Assets Control (OFAC), a component of the Department of the Treasury. Sanctions obligations apply to all U.S. persons, not only to banks, and they are separate from the Bank Secrecy Act, although banks usually run sanctions compliance alongside their BSA/AML program.

The legal basis and strict liability

OFAC's reporting, procedures and penalties regulations appear at 31 CFR Part 501, and each sanctions program has its own part of Chapter V of Title 31. OFAC's approach to enforcement is set out in the Economic Sanctions Enforcement Guidelines, published as Appendix A to 31 CFR Part 501. The guidelines describe the general factors OFAC weighs in deciding a response to an apparent violation, including whether the conduct was willful or reckless, the harm to sanctions program objectives, and the existence and adequacy of a compliance program at the time of the violation.

Civil liability for a sanctions violation is strict. In the Tri-Seal Compliance Note of March 6, 2024, the Departments of Commerce, the Treasury and Justice state that OFAC may impose civil penalties for sanctions violations based on strict liability, which means a person subject to U.S. jurisdiction can be liable even without knowing, or having reason to know, that a transaction was prohibited. Strict liability is the reason screening programs are built to find possible matches broadly and then resolve them by review, rather than to look only for exact matches.

The five components of a sanctions compliance program

OFAC's May 2019 framework identifies five essential components of a risk-based sanctions compliance program. The Federal Financial Institutions Examination Council (FFIEC) BSA/AML Examination Manual, in its Office of Foreign Assets Control section, describes a comparable set of expectations for banks: identifying higher-risk areas, internal controls for screening and reporting, independent testing, a designated person responsible for OFAC compliance, and training.

ComponentWhat it covers
Management commitmentSenior management approves the program, gives it adequate resources and authority, and names a person responsible for sanctions compliance.
Risk assessmentAn assessment of sanctions exposure across customers, products, services, supply chain, counterparties, transactions and geographic locations, refreshed as the business changes.
Internal controlsWritten policies and procedures, screening systems and lists, escalation and decision rules for potential matches, blocking and rejecting, reporting, and recordkeeping.
Testing and auditingIndependent, periodic review of whether the controls work, including whether the screening system finds the matches it is configured to find.
TrainingTraining for employees and relevant stakeholders scaled to their role and the institution's risk profile.

OFAC states in the framework that it will consider the existence, nature and adequacy of a sanctions compliance program when it resolves an apparent violation, which is one reason the framework is used as the design standard for programs outside banking.

The lists screened

A screening program defines which lists it screens against, and the choice follows from the risk assessment and from the jurisdictions whose law applies to the institution. The principal official sources are:

Lists change frequently, so a program records which list versions were in use when a screening decision was made and how quickly updates are loaded.

What is screened, and when

Screening normally runs at two points. Customer or name screening checks a customer, beneficial owners and other related parties at onboarding and again when lists change. Transaction screening checks payments and the parties, banks, addresses and free-text fields they carry before the payment is released. Institutions also screen vendors and other counterparties where the risk assessment shows exposure.

Fuzzy matching and alert disposition

Names are spelled in many ways, transliterated from other scripts, abbreviated and reordered. Screening systems therefore use approximate or "fuzzy" matching, which scores how closely two strings resemble each other and raises an alert above a set threshold. The threshold is a risk decision: set too high, it misses true matches; set too low, it floods reviewers with false positives. The chosen settings, the reasons for them and the testing behind them are part of the program's documentation.

Each alert is reviewed and closed with a documented decision. OFAC's published guidance on evaluating a potential match (OFAC FAQ 5) describes the steps: confirm that the alert relates to an OFAC list, compare the complete list entry (name, aliases, dates of birth, nationality, addresses, identification numbers) with the institution's own information, decide whether there is a valid match, and then determine whether property must be blocked or the transaction rejected. Alerts that are resolved as false positives are closed with the reason recorded.

Ownership and the 50 percent rule

A party that does not appear on any list can still be blocked. Under OFAC's "Revised Guidance on Entities Owned by Persons Whose Property and Interests in Property Are Blocked" (August 2014), any entity owned 50 percent or more, directly or indirectly, individually or in the aggregate, by one or more blocked persons is itself blocked, whether or not it is named on a list. A name-matching system cannot detect this on its own, so programs combine screening with ownership information collected during customer due diligence. Other jurisdictions apply their own ownership and control tests, which differ from OFAC's.

Blocking, rejecting, reporting and recordkeeping

When a valid match is confirmed, the regulations of the relevant program determine whether property must be blocked (frozen) or the transaction rejected. Blocked property and rejected transactions are reported to OFAC within 10 business days (31 CFR 501.603 and 501.604), and holders of blocked property file an annual report of blocked property as of June 30 by September 30 (31 CFR 501.603).

Records of transactions subject to OFAC regulations are kept under 31 CFR 501.601. The retention period was extended from five years to ten years, following 2024 legislation that lengthened the statute of limitations for violations of the International Emergency Economic Powers Act and the Trading with the Enemy Act from five to ten years. OFAC adopted the ten-year period by an interim final rule published in September 2024, effective March 12, 2025, and finalized it in March 2025.

PEP screening as a separate practice

Screening for politically exposed persons (PEPs) is often run through the same software as sanctions screening, but it serves a different purpose. A PEP is not prohibited; PEP status is a risk factor that informs customer due diligence and the depth of review. The Joint Statement on Bank Secrecy Act Due Diligence Requirements for Customers Who May Be Considered Politically Exposed Persons (FinCEN and the federal banking agencies, August 2020) states that due diligence for these customers should be commensurate with the risk and that the customer due diligence rule does not create a separate PEP requirement. A PEP match therefore feeds customer risk rating rather than a block or reject decision.

Who performs the work

A designated sanctions compliance officer, or the BSA officer where the roles are combined, owns the program. Screening analysts review and disposition alerts, with escalation to the compliance officer or legal counsel for possible true matches. Independent testing, performed by internal audit or an outside party, reviews the program and typically includes testing of the screening system's configuration and list coverage.

Primary sources

Common questions

What is sanctions screening?
Sanctions screening is the comparison of customers, counterparties and transactions against official lists of sanctioned persons, entities, vessels and jurisdictions, such as OFAC's SDN List, to detect dealings the law prohibits. Potential matches are reviewed and either cleared as false positives or confirmed, in which case the property is blocked or the transaction rejected and reported.
What are OFAC's five components of a sanctions compliance program?
OFAC's A Framework for OFAC Compliance Commitments (May 2019) names five essential components: management commitment, risk assessment, internal controls, testing and auditing, and training.
Is sanctions liability strict?
Yes, for civil purposes. OFAC may impose civil penalties on a strict liability basis, so a person subject to U.S. jurisdiction can be liable without knowing a transaction was prohibited. OFAC weighs the general factors in its Economic Sanctions Enforcement Guidelines (Appendix A to 31 CFR Part 501), including the adequacy of the compliance program, when deciding a response.
What is the OFAC 50 percent rule?
Under OFAC's August 2014 revised guidance, an entity owned 50 percent or more, directly or indirectly and in the aggregate, by one or more blocked persons is itself blocked, even if it does not appear on any list.
How long must OFAC records be kept?
Ten years. OFAC amended 31 CFR 501.601 to extend the recordkeeping period from five to ten years, effective March 12, 2025, following 2024 legislation that extended the statute of limitations for most sanctions violations to ten years.
Is PEP screening part of sanctions screening?
It often uses the same software, but it is a different control. A politically exposed person is not prohibited; PEP status is a risk factor that informs customer due diligence and customer risk rating, while a confirmed sanctions match leads to blocking or rejecting.
About this library

This reference library is maintained by Rupture Labs. We perform BSA/AML independent testing and automated control testing against every record, with each requirement cited to its rule. Talk to a practitioner.