A payment firm processing a cross-border transaction discovers, mid-settlement, that a counterparty shares a name with an entry on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The transaction freezes. The compliance team cannot confirm whether it is a true match or a false positive. Time pressure mounts. This scenario plays out across financial institutions, exporters, and multinationals every week – and the cost of getting the next step wrong runs in multiple directions.
Name and entity screening under OFAC is the process of checking counterparties, owners, and associated parties against OFAC's published lists – principally the SDN List – before engaging with them commercially or financially. As of July 2026, the core obligation under IEEPA and related executive authorities is absolute: US persons, and non-US persons handling US-nexus transactions, must not deal with blocked parties. No intent is required for a violation. A single missed match, or an over-aggressive false-positive rate that disrupts legitimate trade, both carry cost.
This guide sets out the OFAC screening procedure step by step, explains where the common failures arise, and addresses how the OFAC approach diverges from the parallel obligations under OFSI and the EU Council regulations – differences that matter to any business with cross-border exposure.
Step 1: Understand which lists you must check and why
OFAC administers several lists, but the SDN List is the primary instrument: it designates individuals and entities whose property is blocked and with whom US persons are prohibited from dealing. Beyond the SDN, practitioners must also be aware of the Consolidated Sanctions List (a combined OFAC list that includes the SDN and several subsidiary lists) and the non-SDN categories, such as the Non-SDN Menu-Based Sanctions List and the Sectoral Sanctions Identifications List, which impose narrower transaction-specific restrictions rather than an outright asset freeze.
The distinction between a full block and a sectoral restriction is operationally critical. A party appearing on a sectoral list is not fully blocked; only defined categories of transaction – typically debt or equity dealings above a specified maturity or percentage threshold – are prohibited. Treating a sectoral match as a full SDN hit leads to unnecessary de-risking. Treating an SDN hit as merely sectoral is a violation. In our experience, screening tools that consolidate all OFAC lists into a single "hit" category without flagging the list type create exactly this confusion.
The UN Consolidated List (maintained by the Security Council) should also sit within any comprehensive screening programme, particularly where a business has non-US operations subject to UN-implementing regimes. OFSI in the United Kingdom and the EU's lists under the relevant Council regulations overlap with OFAC designations in many cases, but diverge materially in others. A name absent from the SDN may still appear on the UK or EU list, and vice versa.
Step 2: Map the correct search population before you run a single check
The search population – who and what you screen – is determined by two variables: the legal entity running the screening programme (US person or entity with US nexus) and the nature of the underlying transaction. Getting this wrong means either screening too narrowly (missing the obligation) or too broadly (generating false positives at a rate that overwhelms the analyst team).
For a US financial institution, the obligation typically extends to all counterparties, beneficiaries, originators, and intermediaries in a payment chain. For a non-US exporter with US-nexus goods – goods incorporating US-origin components above the applicable de minimis threshold under the EAR – the search population must include the end-user and any known intermediate consignee. For an M&A team, it extends to the target, its beneficial owners, its directors, and its material counterparties.
We regularly advise clients whose search population has crept outward through acquisitions and new product lines without a corresponding update to the screening configuration. The programme that covered a single-country payments business does not automatically cover a global trade-finance operation. When did you last re-scope your population against your actual business footprint?
One practical calibration point: the 50 percent rule (OFAC's rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked, even if not listed by name) means the search population must include not just named counterparties but their ownership chains. An entity that does not appear on any list is nonetheless blocked if blocked persons own it above that threshold. Standard screening tools that check only named parties miss this entirely.
Step 3: Configure your matching algorithm – fuzzy logic, thresholds, and transliteration
Name-matching logic is where compliance programmes most frequently fail in practice. OFAC designations include aliases, transliterations from Arabic, Persian, Cyrillic, and Chinese scripts, and common name variants. A threshold set too high (requiring near-exact character matches) will miss true positives masked by a single transposition or transliteration difference. A threshold set too low floods analysts with false positives and, over time, produces alert fatigue – the condition where genuine hits are dismissed because the analyst has reviewed hundreds of near-miss false alerts that day.
The matching configuration decisions a programme must make include: the minimum similarity score for generating an alert; whether to apply phonetic matching (Soundex, Metaphone, or proprietary equivalents) in addition to string matching; how to handle partial name matches where a first name or a single surname element triggers; and whether to apply separate logic for legal-entity names (which may include abbreviations such as "LLC", "GmbH", "JSC") versus natural person names.
In our cross-border practice, we see the transliteration issue arise acutely for businesses with counterparties in markets where romanisation of local-script names is inconsistent. The same individual may appear in your system under three different romanisations, none of which exactly matches the OFAC entry. The solution is not to lower the matching threshold indiscriminately; it is to apply multiple transliteration schemas and to require analyst review at an intermediate confidence band rather than only at the highest-confidence tier.
OFSI in the United Kingdom and the EU sanctions authorities publish guidance on name-matching expectations that differs in emphasis from OFAC's approach, although the underlying practical challenge is the same. Where a business runs a single screening system for all three regimes, the configuration must accommodate the formatting conventions of all three list types simultaneously.
Step 4: Triage the alert – true positive, false positive, and the "possible match" middle ground
An alert generated by the screening engine is not a finding; it is a question. The triage process determines whether the alert is a true positive (a genuine match to a listed party), a false positive (a name coincidence with no sanctioned-party connection), or a possible match requiring further investigation.
OFAC's own guidance makes clear that businesses are expected to conduct a reasonable enquiry when a possible match arises. That enquiry should examine: the name, including all aliases and known variants; date of birth and nationality where available; address and country of operation; and any identification numbers present in the underlying transaction documentation. The more data points that align between the counterparty and the OFAC listing, the stronger the case for a true positive.
For financial institutions processing high volumes, the triage protocol must be documented in writing and applied consistently. Inconsistent triage – where the same data pattern produces different outcomes depending on the analyst – creates both a compliance gap and an enforcement risk. OFAC's enforcement guidance rewards structured, documented, and consistently applied programmes; it treats ad hoc decisions as indicators of a weak compliance culture.
The "possible match" category is the hardest to manage. A business that unilaterally decides to proceed despite an unresolved possible match takes on the risk that OFAC will later characterise the decision as wilful blindness. Conversely, blocking every possible match creates its own exposure – operational disruption, potential liability for wrongful holds, and damage to commercial relationships. The correct approach in an unresolved case is to seek an OFAC specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) or, where the specific facts are clear enough, to rely on a documented legal analysis. OFAC also operates an OFAC Compliance Hotline for urgent queries, though responses through that channel are not formal legal opinions.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. To discuss an unresolved alert or an enforcement-related screening question, contact Calder & Vance at info@caldervance.com.
Step 5: Handle a confirmed hit – blocking, reporting, and record-keeping obligations
A confirmed SDN match triggers immediate obligations. Property of a blocked party that comes into the possession or control of a US person must be blocked – held in an interest-bearing account separate from the institution's own assets – and reported to OFAC. The reporting obligation is subject to a short statutory window; OFAC's rules require the report to be filed promptly, and the relevant deadline should be confirmed against the current version of the applicable regulations before reliance.
Record-keeping obligations run alongside the blocking requirement. OFAC expects businesses to retain records of blocked transactions, triage decisions, and licence applications for a period of five years from the date of the transaction or the date of the licence, whichever is later. This five-year retention requirement means that screening logs, alert-disposition records, and supporting documentation must be archived in a retrievable form for the duration.
The obligation to block is distinct from the obligation to report and the obligation to retain. Failing on any one of them is a separate basis for enforcement action. In a recent matter, a financial-services business came to us after discovering that it had blocked funds correctly but had not filed the required report within the applicable window. The corrective filing and supporting voluntary disclosure were prepared promptly, and the matter was resolved through OFAC's administrative process. Early advice made it manageable; delayed advice would not have changed the underlying facts.
Under the UK regime, OFSI imposes its own obligation on firms that know or have reasonable cause to suspect they hold funds belonging to a designated person: the obligation is to report to OFSI as soon as practicable. The EU's relevant Council regulations impose comparable reporting obligations on persons holding frozen assets. The trigger and timing differ from the OFAC position, and a business operating across all three regimes must ensure its incident-response process captures all three sets of obligations simultaneously – not just the US one.
How does OFAC screening differ from OFSI and EU sanctions screening?
The core difference lies in the ownership-and-control test. Under OFAC, the 50 percent rule is mechanical: if blocked persons own 50 percent or more of an entity in the aggregate, that entity is blocked regardless of whether it appears on any list. There is no separate control analysis. Under OFSI and the EU regime, the test for whether a non-listed entity is caught runs on both ownership – typically the same 50 percent threshold – and control. An entity owned below the threshold may still be caught if a designated person controls it through other means: board appointment rights, veto powers, or contractual rights over material decisions.
This divergence has direct consequences for screening configuration. An OFAC-only programme that checks ownership chains to the 50 percent threshold will miss the control leg of the UK and EU analysis. A business with EU or UK-nexus transactions must build a separate control assessment layer into its ownership mapping, or use a vendor tool that explicitly models control as well as ownership.
A second divergence concerns the list infrastructure itself. OFAC publishes a relatively consolidated set of lists with a single downloadable data feed. The EU sanctions regime involves designations published across multiple Council Regulations – and, for third-country nationals, entries may appear in regime-specific regulations rather than a single consolidated instrument. Keeping an EU-compatible list current requires monitoring the Official Journal and applying updates on the date of publication, since EU sanctions take effect from publication rather than from a separate effective date. OFSI's consolidated list is more closely analogous to OFAC's single feed, but the underlying legal authority differs.
A third point of divergence is jurisdictional reach. OFAC sanctions operate on a US-person basis and on a US-nexus basis (property in the US, US dollar transactions cleared through US correspondent banks). OFSI sanctions operate primarily on a UK-person and UK-nexus basis. EU sanctions operate within EU territory and on EU persons. The practical consequence is that a transaction between two non-US parties with no US dollars and no US-incorporated entities may fall entirely outside OFAC's reach while remaining squarely within the EU and UK obligations. Designing a screening programme without mapping which legal entities sit in which jurisdiction, and which transaction flows carry US nexus, leads either to over-screening or to gaps.
The position above covers the standard configuration. Your facts – the entities involved, the currency, the goods, the intermediaries, and the regime in play – change the analysis materially. For an assessment of your screening programme's cross-regime coverage, contact Calder & Vance at info@caldervance.com.
Common risk flags and when to involve counsel
Five patterns recur across the screening programmes we review. Each one represents a known failure mode that OFAC's enforcement guidance has, directly or indirectly, addressed.
First: screening only named counterparties, not their owners. The 50 percent rule means that the entity you are dealing with may not appear on any list but is nonetheless blocked. A programme that does not map ownership chains beyond the first layer will miss this. The ownership mapping obligation is not satisfied by asking the counterparty to self-certify; it requires independent verification using company registries, beneficial-ownership databases, or a structured due-diligence process.
Second: static list versions. OFAC updates its lists frequently – designations are added, amended, and (occasionally) removed. A programme that does not update its list data in near real-time may process a transaction against a list version that is already out of date. In the period between a new designation and the next scheduled list update in your system, every transaction against the newly designated party is a potential violation.
Third: inadequate documentation of triage decisions. OFAC's enforcement framework distinguishes between a business that missed a hit because its programme was structurally deficient and one that missed it despite a well-designed, well-documented programme. The documentation of triage decisions – why a possible match was resolved as a false positive, what information was reviewed, who made the decision – is the primary evidence of good faith in an enforcement review.
Fourth: no escalation protocol for complex ownership structures. Where an ownership chain involves nominee shareholders, bearer shares, or multi-layered intermediaries in opaque jurisdictions, the standard alert-triage workflow is insufficient. These structures require escalation to a specialist who can assess the control question under the relevant regime and, where necessary, seek external legal advice before the transaction proceeds.
Fifth: the myth that screening software is compliance. This is the most pervasive misconception we encounter. A screening tool generates alerts; it does not constitute a compliance programme. OFAC's published guidance on the elements of an effective sanctions compliance programme identifies five components: management commitment, a risk assessment, internal controls, testing and auditing, and training. A well-configured screening system contributes to internal controls. It does not, on its own, satisfy the other four elements. A business that relies entirely on a vendor tool without the supporting infrastructure of policy, training, escalation, and audit will not receive meaningful mitigation credit in an enforcement action.
When should you involve sanctions counsel rather than manage the issue internally? The answer is: earlier than most businesses do. The threshold indicators include an unresolved possible match that the triage team cannot close, a transaction that has been blocked and requires a licence application, a voluntary self-disclosure (VSD) situation where a violation has been identified, and any query from OFAC, OFSI, or the relevant EU competent authority. In all four situations, early legal involvement narrows the exposure. Delayed involvement does not reduce the underlying facts; it reduces the options available to manage them.
Related practices
- Sanctions compliance audit and testing – audit and testing services for sanctions screening programmes across major regimes.
- Name and entity screening: extended guide – deeper treatment of screening methodology, vendor evaluation, and cross-regime calibration.