A cross-border payments team at a mid-sized financial institution receives a wire instruction. The beneficiary name looks clean. The bank passes. Three weeks later, OFAC issues a finding that an intermediate correspondent in the payment chain held funds for a blocked person. The firm did not screen the full chain. That omission is the problem.
Payment-processing controls under OFAC require firms to screen every party in a transaction – originator, beneficiary, and each intermediary – against the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and all applicable sanctions lists, reject or block prohibited payments, and report blocked or rejected transactions within required windows. The obligation is strict-liability: intent is irrelevant to whether a violation occurred. As of mid-2026, OFAC's enforcement posture has continued to emphasise systemic screening failures over isolated manual errors.
This guide sets out the step-by-step controls a business must have in place, where those controls diverge across OFAC, OFSI, and the EU, and when to bring in sanctions counsel before a compliance gap becomes an enforcement matter.
Step 1 – Understand what OFAC's payment-processing obligations cover
OFAC's authority derives from IEEPA (the International Emergency Economic Powers Act) and related statutes. It prohibits US persons – and in many contexts non-US persons – from processing, facilitating, or receiving payments that benefit blocked persons or sanctioned territories. The obligation attaches to the transaction, not only to direct counterparties.
What does that mean in practice? It means a US bank acting as a correspondent for a foreign bank must screen incoming wire instructions even when it has no direct relationship with the originator. The payment message carries the relevant data; the processor is responsible for reading it. Incomplete or truncated payment messages are themselves a red flag – OFAC has addressed this issue in its published guidance under the applicable regulations.
Three categories of payment receive distinct treatment. First, payments to or for the benefit of blocked persons must be blocked – the funds are frozen and held, not returned. Second, payments that fall within a prohibitory rule but do not involve blocked property must be rejected – returned to the sender without processing. Third, payments that appear suspicious but do not trigger a clear prohibition still require escalation and may require a report to relevant US authorities under parallel obligations. Understanding which category applies is the first practical decision a compliance team must make.
The distinction between blocking and rejection matters beyond procedure. Blocked funds must be reported to OFAC. Rejected transactions must also be reported. Both have short statutory windows. Failing to report is a separate violation from the underlying transaction issue.
Step 2 – Design a screening architecture that covers the full payment chain
Effective payment-screening architecture covers every data field in the payment message, not only the beneficiary name. A firm that screens only beneficiary names will miss the majority of sanctions exposure that arises in practice. The originator, the originator's bank, the beneficiary's bank, any intermediate institutions, and any referenced parties in the message body – all require screening.
What data fields matter most? For wire transfers, screening should cover the originator name and address, the beneficiary name and address, the beneficiary account number, each routing institution, and any free-text reference fields. Structured payment messages (SWIFT or equivalent) carry this data in defined fields; unstructured messages – still common in certain trade-finance instruments – require parsing logic to extract the relevant content.
Firms regularly underestimate the challenge of name-matching. The SDN List includes aliases, transliterations, and variant spellings. Screening software configured with a match threshold that is too high will generate unmanageable false-positive volumes; one set too low will generate false negatives. In our experience, the right calibration is not a one-time decision – it requires periodic testing against a reference set of known matches, including aliases that appeared in recent OFAC additions. We regularly advise clients to run a retrospective exercise against new list additions each quarter to identify gaps in historical screening.
A separate issue is the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked, regardless of whether those entities appear by name on the SDN List). Standard screening tools match against listed names. They do not resolve beneficial ownership. A payment to a company that is 60 percent owned by a blocked person is prohibited, even if the company itself is not listed. Addressing the 50 percent rule in payments requires a separate beneficial-ownership verification layer – screening alone is insufficient.
Step 3 – Set up blocking, rejection, and reporting procedures
Once a screening alert fires, the compliance team must move quickly. OFAC's reporting obligation for blocked transactions has a short window – verify the current deadline against the applicable regulations before relying on any stated figure, as reporting windows are set by programme-specific rules and can differ. For rejected transactions, a separate report is required. Both reports must contain specified information about the parties, the amount, the reason for the block or rejection, and the date.
The internal procedure should assign a clear decision owner – not a committee. Speed matters. An escalation chain that requires three levels of approval before a wire can be blocked will exceed any short reporting window in a complex transaction. The decision owner should have standing authority to act, access to the firm's screening results and the underlying list entry, and a direct line to legal counsel for ambiguous cases.
Documentation is equally critical. OFAC's record-keeping rules require that firms maintain records of blocked property and of all relevant transactions for a significant period – as currently in force, verify the applicable record-keeping period before relying on it, as it differs between programmes. In our practice, we advise clients to treat each block or rejection as a file: record the screening result, the list entry consulted, the name of the decision-maker, the date, the amount, and the disposition. That file is what OFAC's examiners will request in any inquiry.
A common structural gap: firms establish a blocking procedure but not a rejection procedure. The two differ. Blocked funds are held by the firm. Rejected payments are returned. Both generate a reporting obligation, but the operational steps diverge. Every payment-compliance programme should contain written procedures for both, tested separately.
How does OFAC differ from OFSI and EU payment controls?
The OFAC model – strict-liability, broad correspondent-bank obligations, short reporting windows – is more demanding than the baseline obligations under OFSI and the EU, though the gap is narrowing. Businesses that operate across these regimes cannot assume that compliance with one satisfies the others.
Under OFSI (the UK's Office of Financial Sanctions Implementation), the financial-sanctions prohibition covers UK persons and conduct in the United Kingdom. OFSI applies an ownership and control test: a non-listed entity can be caught not only by ownership of 50 percent or more, but also by a listed person exercising control through other means – governance rights, commercial dependency, or contractual authority. The OFAC rule is, by contrast, purely mathematical at the 50 percent threshold; control below that line is not, on its own, determinative for OFAC purposes. For a business processing payments through both US correspondent relationships and UK accounts, the stricter prohibition governs each leg separately.
The EU regime, operating through Council regulations, applies to EU persons and EU-territory conduct. The EU ownership-and-control test is similarly broader than OFAC's mechanical rule. Importantly, the EU Blocking Regulation creates a further complication for EU-based firms: it restricts compliance with certain US secondary-sanctions measures. EU payment-processors should take specific advice before applying OFAC-driven restrictions in a way that could conflict with their EU Blocking Regulation obligations.
Secondary-sanctions exposure adds another dimension. OFAC's secondary sanctions target non-US persons who conduct significant transactions in specific sectors or with blocked persons, even without any US nexus. A European payment-processor that clears a transaction through a non-US bank may still face secondary-sanctions risk if the transaction involves a party targeted by OFAC's secondary measures. This extraterritorial reach is a core design feature of OFAC's authority under IEEPA; it is not mirrored in the OFSI or EU regimes.
For businesses operating across multiple regimes, the practical answer is to apply the strictest applicable standard to each payment leg, while documenting the regime-specific analysis. Do not assume that a single screening pass satisfies all three authorities.
What are the principal risk flags in payment processing?
Systemic screening gaps account for most enforcement exposure. But certain transaction patterns create heightened risk regardless of how well a firm's routine screening is calibrated.
Truncated or incomplete payment messages are a persistent issue. When a payment instruction omits the originator's name or address, or uses a coded reference instead of the party's full legal name, the screening system cannot match against the SDN List. OFAC has been clear that processing payments with incomplete party data is itself a compliance failure. Firms should reject or return messages that do not carry the required identifying fields.
Third-country routing is a related risk. A payment that originates in a jurisdiction with weaker sanctions controls and passes through a US correspondent bank may carry party information that has not been screened upstream. The US correspondent inherits the exposure. In our experience, correspondents that establish clear message-quality standards for their respondents – and verify compliance periodically – substantially reduce this exposure.
Trade-finance instruments – letters of credit, documentary collections, guarantees – are an underappreciated vector. The goods, the shipping route, the ports of loading and discharge, and the vessel all require review, not only the counterparties named in the financing instrument. A payment that funds the purchase of goods transiting a prohibited port implicates the payment-processor even if both the buyer and seller are clean.
Virtual-asset and crypto payments present a distinct challenge. OFAC has confirmed that its sanctions obligations apply fully to virtual-asset transactions. A VASP (virtual-asset service provider) processing transactions that touch a wallet address attributable to a blocked person is in the same position as a bank processing a prohibited wire. Blockchain analytics tools can assist with address-level screening, but they do not resolve beneficial-ownership questions at the wallet level in the way that a traditional KYC programme resolves them for bank accounts. We regularly advise VASPs on building a screening programme that addresses both listed addresses and the 50 percent rule at the entity level.
When should a business involve a sanctions lawyer?
A firm should involve sanctions counsel before a problem crystallises, not after. Three situations in particular call for early external advice.
First, when a firm is building or materially revising its payment-screening programme. A compliance counsel can assess whether the programme covers the full payment chain, whether the match threshold is appropriately calibrated, whether the blocking and rejection procedures are correctly differentiated, and whether the reporting chain can execute within the applicable windows. Getting this right at the design stage is substantially less expensive than remediation after an enforcement inquiry.
Second, when a screening alert fires and the compliance team cannot resolve it quickly. An ambiguous hit – where the name is a close match but the other identifying data is inconclusive – is one of the most common situations we handle. The decision to block, reject, or release a payment on that basis has enforcement consequences. An early call to counsel, even for a single transaction, can preserve options that are lost once the payment is released.
Third, when a firm identifies a past failure. If a review reveals that payments were processed that should have been blocked, or that reporting deadlines were missed, the question of whether and how to make a VSD (voluntary self-disclosure to OFAC) becomes urgent. OFAC's published guidance indicates that a timely, accurate VSD is treated as a significant mitigating factor in penalty determinations. The window for that benefit narrows once OFAC becomes aware of the issue through other means.
The position above covers the standard case. Your facts – the currency, the correspondent relationships, the underlying goods or services, the regime in play – change the analysis. If a transaction has already been flagged, or a filing deadline has been missed, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.
Objection: "Our screening vendor handles this – we do not need a programme"
This is the most common misconception we encounter. Vendors screen against published lists. They do not apply legal judgment to ambiguous matches, they do not resolve the 50 percent rule against private beneficial-ownership data, and they do not make the blocking or rejection decision that the firm itself must own. OFAC's enforcement record makes clear that the responsibility for sanctions compliance sits with the regulated entity, not its vendor.
A screening vendor is a tool. The programme – the policies, the decision procedures, the escalation chain, the reporting process, the record-keeping – is the firm's obligation. In a number of enforcement actions documented in OFAC's published penalty releases, firms that had screening tools in place were nonetheless penalised because those tools were misconfigured, undertested, or operated without adequate written procedures. Vendor coverage does not substitute for programme governance.
The related myth is that OFAC only targets large institutions. OFAC's enforcement remit extends to any US person, any person operating in the United States, and, for secondary sanctions, to non-US persons conducting significant transactions in covered sectors. Company size is a factor in penalty calculation, but it is not a threshold for the obligation. A mid-sized payments firm, a fintech, or a freight forwarder is as subject to the screening obligation as a global correspondent bank.
Related practices
- Compliance audit and testing – sanctions screening and programme stress-testing services for cross-border businesses.
- Payment-processing controls – OFAC guide 4 – deeper analysis of trade-finance and correspondent-bank obligations under US sanctions.