A payment firm processes thousands of transactions each day. Its screening tool clears a counterparty automatically. Weeks later, a regulator query reveals that a layered holding company with a common name variant sat on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) the entire time. The transaction was prohibited. The exposure is real. Could better screening have caught it?
Name and entity screening under OFAC is the process of checking counterparties, beneficial owners, and payment fields against OFAC's published lists – principally the SDN List – before a transaction is processed or a relationship is established. As of July 2026, OFAC administers more than thirty active sanctions programmes under statutory authorities including IEEPA and TWEA. A single missed match can constitute a sanctions violation regardless of intent, and OFAC's civil liability standard does not require proof of knowledge.
This guide walks through the screening process step by step, identifies where programmes and tools most commonly fail, and explains where OFAC's approach diverges from the OFSI and EU regimes.
Step 1: Understand what you are screening against
Before configuring any tool, a compliance team must understand the lists and the legal standard that the screening programme is meant to satisfy. The SDN List is the primary OFAC prohibition list; a transaction with any person or entity on it is blocked unless a licence applies. OFAC also maintains several other restricted-party lists – including the Sectoral Sanctions Identifications list and the Non-SDN Menu-Based Sanctions list – each carrying different legal consequences. Not every hit on a non-SDN list results in a full block; some impose targeted transactional restrictions rather than a categorical prohibition.
Understanding the legal effect of each list matters at the point of configuration. Screening tools that treat all list hits as equivalent – and either over-block or under-block as a result – are a recurring source of both compliance failures and unnecessary operational disruption. In our experience, firms that skip this analytical step and move directly to tool selection end up reconfiguring their programmes within twelve months.
The OFAC regulations also require attention to geography. Certain country-based programmes prohibit transactions with persons located in a specific territory, not just those who are designated. Territorial scope questions sit alongside the list-matching exercise and are often handled by separate controls – most commonly payment routing filters and trade-document review.
Step 2: Map your data inputs and counterparty population
Effective screening starts with a clear map of every data source the programme must cover. The counterparty population for OFAC purposes is broader than most firms initially assume. It includes: the direct counterparty, its beneficial owners at the 50 percent rule threshold (OFAC's rule treating entities owned 50 percent or more in the aggregate by one or more blocked persons as themselves blocked), intermediary banks in correspondent and trade-finance transactions, named parties in shipping documents, and – for virtual-asset businesses – wallet addresses and counterparty VASPs.
Data quality problems are the primary source of false negatives in production screening environments. Transliterated names in multiple scripts, abbreviated legal-entity names, outdated beneficial-ownership records, and poorly parsed payment message fields all create gaps. A programme that screens the correct population but works from bad data is not a compliant programme. Have you audited the data fields your tool actually reads – and confirmed they match what arrives in the live transaction stream?
The data-mapping stage should produce a written inventory: each counterparty category, the data source, the field or fields screened, the update frequency, and the owner of each data feed. That inventory is also the starting point for any regulator enquiry about programme design.
Step 3: Configure the matching algorithm and fuzzy-match logic
The matching algorithm is the analytical core of any screening programme, and it is where both over-alerting and under-alerting originate. OFAC's published guidance makes clear that screening programmes must account for name variations, transliterations, aliases, and misspellings – all of which appear on the SDN List alongside primary names. A tool set to match only exact strings will miss a substantial proportion of genuine hits.
Fuzzy matching logic introduces a tolerance parameter – commonly expressed as a percentage score – that captures approximate matches. The challenge is calibration. Set the threshold too high and the tool floods analysts with false positives, consuming review capacity and encouraging alert fatigue. Set it too low and genuine matches slip through. We regularly advise clients that the right threshold is not a universal number; it varies by name type (common surnames require tighter logic than uncommon corporate names), by script (Arabic and Chinese transliteration requires bespoke treatment), and by the risk tier of the customer population.
Alias coverage is equally important. OFAC SDN entries list primary names and a variable number of aliases. A screening configuration that only tests against primary names – a limitation some legacy tools carry – does not satisfy the standard OFAC expects. Confirm that your tool ingests the full alias field from each list update.
The position above covers the standard configuration case. Your own facts – the counterparty profile, the transaction type, the data quality, the geography – change the analysis significantly.
For an initial assessment of your screening programme design, contact Calder & Vance at info@caldervance.com.
Step 4: Establish the alert-review and disposition workflow
A screening alert is a potential match, not a confirmed violation. The alert-review workflow is the process by which a trained analyst determines whether the alert represents a genuine sanctions concern or a false positive. That determination is a legal judgment, not a mechanical one, and it must be documented.
A well-designed workflow has several fixed elements. First, a clear escalation path: who reviews the alert initially, who has authority to clear it, and at what point the matter goes to legal or senior compliance. Second, defined decision criteria: what information the reviewer gathers, how the comparison between the alert subject and the list entry is made, and what standard of confidence is required to clear. Third, a documented record: every alert disposition should generate a contemporaneous record that captures the reviewer's reasoning. OFAC expects firms to maintain records for a period of five years – verify the current requirement under the applicable programme regulations before relying on this figure.
Turnaround time matters. Payment-processing environments work in real time or near-real time. A workflow that requires multiple sign-offs for every alert is operationally impractical and risks either processing prohibited transactions or blocking legitimate ones. The calibration question – how many alerts can your review team handle without compromising quality? – should be answered before the programme goes live, not after the first operational crisis.
Step 5: Address the 50 percent rule and beneficial-ownership screening
The 50 percent rule extends OFAC's prohibitions to entities owned by blocked persons even where the entity itself does not appear on the SDN List. The rule applies on an aggregate basis: multiple blocked persons who together own 50 percent or more of an entity cause that entity to be treated as blocked. The SDN entries of the owning persons are the relevant source; the entity may be entirely unlisted and still prohibited.
Beneficial-ownership screening is therefore a separate and complementary exercise to name-list screening. It requires access to ownership data – corporate registry records, UBO declarations, commercial databases – and a methodology for mapping ownership chains through intermediate holding structures. Automated tools can assist, but they depend on the quality of the underlying ownership data, which varies significantly by jurisdiction.
This is one of the areas where OFAC and the UK OFSI regime diverge in a commercially significant way. Under OFSI, the test for whether a non-listed entity is caught is one of ownership and control – control alone, even without 50 percent ownership, can be sufficient. The EU regulations apply a similar ownership-or-control analysis. A business that screens only for the OFAC 50 percent ownership threshold and then relies on that result for OFSI and EU purposes is under-screening for those regimes. The stricter prohibition governs in any multi-regime transaction, and a single compliance architecture that applies only the OFAC threshold will miss exposures in OFSI and EU contexts.
In a recent matter, a financial institution with both US and EU client exposure had configured its screening programme entirely to the OFAC 50 percent threshold. When a counterparty was later identified as subject to EU restrictive measures through a control relationship below 50 percent ownership, the institution's records showed no alert had been generated. We assisted the institution in redesigning the ownership-screening layer and updating the programme's legal basis to reflect the applicable EU analysis.
How does OFAC differ from OFSI and EU screening requirements?
OFAC, OFSI, and the EU differ in four practically significant ways for screening programme design. Understanding the divergence is essential for any business operating across US, UK, and EU jurisdictions simultaneously.
Ownership threshold. OFAC's 50 percent rule is a bright line. OFSI and the EU apply an ownership-or-control test: control without majority ownership can still bring a counterparty within the prohibition. A programme calibrated only to the OFAC threshold misses the additional exposure under the other two regimes.
List structure. OFAC maintains multiple lists with different legal consequences. OFSI publishes a consolidated UK sanctions list. The EU publishes the EU Consolidated Financial Sanctions list, updated through Official Journal notices. Each list has a different update cycle and a different resolution of aliases and transliterations. A multi-regime screening programme must ingest all three list families and apply the correct legal consequence to each hit.
Strict liability versus knowledge. OFAC's civil enforcement is on a strict liability basis for most violations: the payment processed, the asset was not blocked, the question of what the firm knew is relevant to penalty calculation, not to the underlying violation. OFSI introduced a strict civil liability standard for financial-sanctions breaches above a monetary threshold, verified before reliance. EU member-state enforcement varies and is generally knowledge-sensitive in the criminal track. These differences affect both the risk weighting of a missed alert and the disclosure analysis if a potential breach is identified.
Reporting obligations. OFAC requires a firm that holds blocked property to report that holding and update the report annually. OFSI requires reporting of knowledge or suspicion of a sanctions breach within a short statutory window; verify the current period under the applicable OFSI guidance before relying on it. EU reporting obligations are set by the applicable Council regulation and vary by programme. A multi-regime programme must track all three reporting streams separately.
If a transaction has already been flagged, or a filing or report has been refused or is outstanding, early legal review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com.
Common risk flags and when to involve counsel
Several patterns in screening programme design and operation recur as the proximate cause of OFAC compliance failures. Recognising them early – before a transaction is processed or a relationship is onboarded – substantially reduces enforcement exposure.
- List update lag. OFAC updates the SDN List without advance notice, sometimes multiple times in a week. A programme that refreshes its list data on a weekly or monthly cycle will have a window during which newly designated persons or entities are not caught. Real-time or daily list updates are the standard for higher-risk businesses.
- Stale beneficial-ownership data. Corporate structures change. A UBO record that was accurate at onboarding may no longer reflect the current ownership chain twelve months later. Periodic re-screening of existing relationships – on a risk-tiered basis – addresses this gap.
- Payment message truncation. In correspondent banking and trade finance, payment messages may be truncated or abbreviated before they reach the screening tool. If the tool receives a shortened version of a name or address, it is screening against incomplete data. This is a configuration and data-quality issue, not a policy one, but it is a common cause of missed hits.
- Nested structures and aggregation. The 50 percent rule applies on an aggregate basis across all blocked-person holdings in the same entity. A firm that calculates each blocked person's holding separately – and clears the counterparty because no single holding reaches 50 percent – without aggregating them is misapplying the rule.
- Alert-fatigue degradation. When false-positive alert volumes are high, review quality declines over time. Analyst error rates rise; genuine hits are cleared in batches. Regular quality-assurance sampling of alert dispositions – checking cleared alerts against the list – is the standard mitigation.
Counsel should be involved when: a firm is designing or significantly reconfiguring its programme; a genuine potential match has been identified on the SDN List; there is a question about whether the 50 percent rule applies to a specific counterparty; a transaction has been processed that may have involved a prohibited party; or a regulator has made an enquiry about the programme. The VSD (voluntary self-disclosure to OFAC) route is available in some circumstances and can affect the penalty analysis – it requires legal assessment before submission.
Related practices
- Sanctions compliance audit and testing – programme-level review and gap analysis across regimes
- Name and entity screening under OFAC: advanced topics – deep-dive on virtual assets, nested structures, and automated screening
- Name and entity screening under OFSI – how the UK ownership-and-control test operates in practice