A mid-sized payment processor routes a batch transfer on behalf of a European corporate client. The originating bank passes the transaction through a US correspondent. Somewhere in the chain, a beneficiary name triggers an automated alert. Operations pauses the payment. Compliance now has hours – not days – to determine whether the transaction is prohibited, whether property must be blocked, and whether a report is required. That is the operational reality of payment-processing controls under OFAC.
Under OFAC's authority, derived from IEEPA and related statutes, any US person or entity processing a payment that involves a sanctioned party, a sanctioned jurisdiction, or property in which a designated person has an interest must block or reject the transaction and, in certain circumstances, report to OFAC within a short statutory window. As of August 2026, those obligations apply not only to US-domiciled firms but also to foreign banks and payment firms clearing US-dollar transactions through a US correspondent – a reach that frequently surprises non-US compliance teams. This guide walks through the controls in sequence, flags where OFAC's requirements diverge from OFSI and the EU, and identifies the risk points that most commonly generate enforcement exposure.
The guide covers: the legal basis and who is caught; screening architecture and when it must fire; the block-or-reject decision; reporting and record-keeping obligations; the cross-regime picture; common failure modes; and when to involve sanctions counsel.
Step 1 – Understand who is caught and why US-dollar flows matter globally
OFAC's jurisdiction reaches every US person and every transaction that touches US infrastructure – including US-dollar clearing – regardless of where the parties are located. That single fact determines the scope of a payment compliance programme.
US persons include US citizens and permanent residents wherever they are based, US-incorporated entities and their branches, and any person physically present in the United States at the time of the transaction. But the jurisdiction does not stop there. A foreign bank that processes a US-dollar payment routes that transaction through the US clearing system, almost always a US-domiciled correspondent or a US-regulated clearing house. At the moment the transaction touches a US institution, OFAC's rules apply. The foreign bank's home jurisdiction – and whether it operates its own sanctions programme – is beside the point for that clearing step.
Why does this matter in practice? Consider a Singapore-based payment institution processing a trade payment denominated in US dollars between two non-US counterparties. Neither party is US. Neither instruction originates in the United States. Yet the US-dollar leg clears through a New York correspondent. At that moment, OFAC's prohibitions are engaged. The Singapore institution may have no direct OFAC obligation, but the correspondent does – and if the correspondent identifies a sanctions issue, it will reject or block the payment and notify the originating bank. The commercial and reputational consequences land squarely on the party that submitted the flawed instruction.
This is the extraterritorial fact that many non-US payment teams have not fully built into their controls. In our experience, compliance programmes designed around the home-jurisdiction regime alone routinely under-screen counterparties and transaction fields that a US correspondent will scrutinise. The first control, then, is an accurate picture of when your payment flows touch US jurisdiction.
Step 2 – Build a screening architecture that covers the right fields at the right time
Effective OFAC-compliant screening is not a single list-check at payment initiation; it is a layered control applied across multiple data fields, at multiple points in the payment lifecycle, against a set of lists that updates without notice.
OFAC maintains the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) as well as several sectoral and country-based consolidated sanctions lists. All of them must be screened. The SDN List alone contains tens of thousands of entries, each with aliases, alternate spellings, and associated entities. Screening must run across at minimum: the originator name and account; the beneficiary name and account; any intermediary or correspondent identified in the instruction; the originating and receiving countries; and, for trade-linked payments, the vessel, goods description, and ports of loading and discharge.
Timing matters as much as field coverage. OFAC updates its lists on a rolling basis, without advance notice. A counterparty that passed screening yesterday may be designated this morning. Payment firms need to screen at instruction receipt and again before final settlement – and must have a process for re-screening open orders and recurring payment mandates when a list update is published. What happens to a standing direct-debit instruction the morning a payee is designated? That question should be answered in your written procedures, not improvised under operational pressure.
Fuzzy-match logic is a persistent design challenge. Exact-match screening catches obvious hits; it misses transliterations, name variants, and deliberate misspellings. Over-tuned fuzzy matching generates large volumes of false positives that overwhelm investigative capacity and create delay risk. In our experience, the right calibration depends on the firm's transaction volumes, geographic mix, and the composition of its customer base – and it needs documented, periodic review. A setting appropriate for a US domestic payments firm will not serve a multi-currency cross-border processor.
The position above covers the standard screening architecture. Your facts – the currency, the corridor, the customer type, the goods behind the payment – change the calibration materially.
To discuss your screening design or to commission a programme review, contact Calder & Vance at info@caldervance.com.
Step 3 – Apply the block-or-reject decision correctly
When screening identifies a potential match, OFAC's rules draw a clear distinction between transactions that must be blocked and those that must be rejected – and the consequences of misapplying this distinction are significant.
Blocking applies where the transaction involves property in which a designated person has an interest. The funds must be placed in a segregated, interest-bearing account and reported to OFAC within a short statutory window – verify the current reporting deadline before relying on it, as OFAC guidance specifies precise timeframes that can be updated. The funds cannot be returned to the originator; they are frozen pending authorisation or a change in the underlying designation.
Rejection applies where the transaction is prohibited but does not involve property of a designated person – for example, a transfer to a jurisdiction subject to a comprehensive embargo where no SDN-listed party is involved. Rejected transactions are returned to the originating institution. A rejection must also be reported to OFAC, and records must be retained.
The distinction between blocking and rejecting is not always obvious at the point of decision. A transaction that appears to involve only a sanctioned jurisdiction may, on closer analysis, involve an SDN-listed intermediary – shifting it from a rejection to a blocking situation. A transaction that initially reads as an SDN hit may, after investigation, involve only a false-positive name match. The practical answer is a documented triage process: identify the match type, gather the relevant transactional data, apply a consistent decision standard, and record every step. OFAC's enforcement approach consistently treats the quality of documentation as an indicator of whether a compliance programme was genuinely effective.
One question compliance teams frequently ask: can an ongoing transaction be unwound once a hit is identified mid-flight? In most cases, no. A US correspondent that has identified blocked property is obliged to freeze it. The originating institution cannot instruct reversal as a means of avoiding the blocking obligation. This is a point where operational teams and compliance teams sometimes conflict – and where clear internal governance matters.
Step 4 – Meet reporting and record-keeping requirements
OFAC's reporting and record-keeping obligations are standalone compliance requirements. Failing to report a blocked transaction is a separate violation from the underlying screening failure – and both may attract civil penalties.
For blocked transactions, an initial report must be submitted to OFAC within the applicable window following the blocking. An annual report of all blocked property held during the prior year is also required. Both reports must be accurate and complete; the property must be held in an interest-bearing account for the duration of the blocking.
Rejected transactions carry their own reporting requirement, typically satisfied by submission of a report to OFAC within a defined period of the rejection. OFAC's guidance specifies the form and content; verify the current requirements before constructing your reporting workflow.
Record-keeping obligations under OFAC require that records of blocked and rejected transactions be maintained for five years from the date of the transaction, or five years from the date of unblocking where funds are subsequently released. This retention period is a baseline; some institutions subject to additional regulatory requirements maintain records for longer. The records must be sufficient to reconstruct the transaction, the screening decision, the basis for the blocking or rejection, and every communication with OFAC.
In our practice, record-keeping failures are among the most preventable enforcement findings. Firms that block transactions correctly but cannot produce a coherent documentary record of their process find that OFAC's penalty analysis treats the absence of records as evidence of a weak compliance programme – which in turn affects the penalty calculus.
Step 5 – Map the cross-regime picture for multi-currency and multi-jurisdiction flows
A payment compliance programme focused exclusively on OFAC will leave material gaps for any firm operating in more than one currency or jurisdiction. OFSI, the EU, and other regimes impose parallel obligations – and they diverge from OFAC in ways that directly affect payment controls.
Under OFSI, the ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person) captures entities that a designated person controls, even without meeting a fixed ownership threshold. OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) is mechanical: reach the threshold and the entity is blocked, regardless of effective control. Under OFSI and EU regulations, a person with a smaller ownership stake but meaningful control over management decisions can still render a counterparty subject to the relevant prohibition. For payment teams, this means a counterparty that passes OFAC's ownership screen may still fail the OFSI or EU control analysis.
The EU regime adds a further dimension for euro-denominated transactions. Even where a payment does not touch US infrastructure, a euro-clearing step through a European correspondent brings EU Council regulations into play. The EU's asset-freeze provisions apply to funds – and where a designated person has an interest in the funds being transferred, the EU-regulated correspondent must freeze them. The prohibited-transactions analysis under EU law also extends, in some programmes, to making economic resources available to designated parties, which can capture certain payment types that OFAC's regime would treat differently.
For Swiss-franc and Canadian-dollar flows, SECO and Global Affairs Canada respectively administer their own lists and asset-freeze regimes. A multi-currency payment platform with exposures across these corridors needs to build each regime's list-screening and decision logic into the architecture – not as an add-on, but as a designed component of the platform's compliance infrastructure.
The practical implication: if a transaction fails under OFAC, the stricter prohibition governs for the US-dollar leg. But a transaction that clears OFAC may still require blocking or rejection under a parallel regime for a different currency leg. Firms running multi-currency books need a compliance matrix that maps each currency corridor to the applicable regime and identifies where the tightest restriction falls.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com.
Step 6 – Identify the risk flags that generate enforcement exposure
Most OFAC enforcement actions involving payment firms trace back to a small number of recurring failure modes. Recognising them before they generate a violation is the point of a well-designed compliance programme.
Incomplete field screening. Many firms screen the originator and beneficiary but fail to screen intermediary banks, reference fields, or goods descriptions embedded in structured payment messages. OFAC's guidance is clear that all fields of a payment message are subject to review. A reference to a sanctioned port, vessel name, or commodity in the free-text field can convert an otherwise compliant transaction into a violation.
Legacy or manual workarounds. Payment operations teams under commercial pressure to clear backlogs sometimes route transactions through manual review channels that lack the same screening coverage as automated systems. If a manual channel bypasses the screening infrastructure, it bypasses OFAC controls. Governance over manual processing is a consistent finding in OFAC enforcement.
Correspondent-bank stripping. The practice of removing or omitting identifying information from a payment message before forwarding it to a US correspondent is itself prohibited under OFAC's rules. Firms receiving incomplete instructions from upstream correspondents should treat missing fields as a risk indicator and apply enhanced scrutiny, not assume that what was omitted was unimportant.
Failure to re-screen open items. Recurring payments, standing orders, and long-dated trade-finance facilities create re-screening obligations each time a list update is published. A customer who passed onboarding screens twelve months ago may now appear on the SDN List. Compliance programmes that screen only at origination, and not at the point of each individual settlement, carry endemic re-screening risk.
Inadequate escalation paths. When a potential match is identified, the decision of whether to block, reject, or release the payment must follow a defined escalation path with clear authority levels. Decisions made informally, or reversed under commercial pressure without documented rationale, are exactly the pattern OFAC's enforcement team looks for when assessing whether a compliance failure was systemic.
Does your written compliance programme address each of these risk points explicitly? If it does not, the gap is a finding waiting to be written.
Step 7 – Know when to involve sanctions counsel
Payment firms often involve outside sanctions counsel reactively – after a correspondent has rejected a payment, after OFAC issues a subpoena or administrative demand, or after an internal audit surfaces a potential unreported block. Earlier involvement is almost always more efficient.
Counsel adds specific value at five points in the payment-compliance lifecycle. First, at programme design: classifying which transaction types and which currency corridors require which regime's analysis, and designing the screening architecture accordingly. Second, at the point of a potential hit: determining whether a match is a true positive, whether blocking or rejection applies, and preparing the OFAC report with the precision and completeness the agency expects.
Third, where a voluntary self-disclosure (VSD – a proactive report of an apparent violation to a regulator, before the regulator identifies it independently) may be appropriate: timing, framing, and completeness of a VSD all affect how OFAC treats it in the penalty analysis, and the difference between a well-prepared VSD and a poorly prepared one is material. Fourth, in the context of a licensing need: where a blocked transaction may be eligible for an OFAC specific licence, early application preserves the ability to complete the underlying commercial transaction within a reasonable timeframe. Fifth, where a correspondent or counterparty has raised concerns: correspondence with OFAC or with a US correspondent is better managed with counsel in the loop from the first communication.
In a recent matter, a financial institution discovered that a series of recurring payments had been processed without re-screening following a list update. We scoped the apparent violations, advised on the voluntary self-disclosure process, and prepared the documentation package for submission. The matter was handled in an orderly way, with OFAC's co-operation framework applied consistently throughout.
Related practices
- Sanctions compliance audit and testing – systematic review of screening logic, controls architecture, and programme gaps across regimes
- Payment-processing controls under OFAC: advanced issues – deeper analysis of licensing, VSDs, and multi-jurisdiction payment compliance
- Payment-processing controls under OFSI – the UK regime's treatment of financial-institution payment obligations