A cross-border payments firm receives a wire transfer instruction. The beneficiary name produces a partial match against an entry on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). Is this a true hit or a false positive? Does the firm block the transaction, reject it, or request more information? The answer depends on whether the firm has a screening programme that is calibrated for the obligations OFAC actually imposes – and whether its compliance team knows what to do in the next few hours.
Name and entity screening under OFAC is the process by which a business checks its customers, counterparties, and transactions against the SDN List and other OFAC-administered lists before engaging with them or processing value on their behalf. The obligation derives from IEEPA and the programme-specific regulations OFAC administers. Crucially, the standard is strict liability: OFAC does not require intent to impose a civil penalty. Every US person, and any business with a US nexus, must screen.
This briefing covers who must screen, which lists carry legal weight, how the ownership test extends screening obligations beyond the SDN List, how OFSI and the EU impose parallel obligations that diverge in important ways, where firms most commonly fail, and when to bring in counsel. As of August 2026, OFAC's published guidance and its enforcement posture make screening programme adequacy a central factor in any penalty calculation.
Who administers name and entity screening under OFAC?
OFAC – the Office of Foreign Assets Control, a bureau of the US Department of the Treasury – administers the sanctions programmes that give screening its legal force. OFAC operates under authority delegated through IEEPA and, for a small number of older programmes, the Trading with the Enemy Act. It maintains the SDN List and a suite of additional lists, including the Sectoral Sanctions Identifications List, the Non-SDN Menu-Based Sanctions List, and the Consolidated Sanctions List, which consolidates all OFAC-administered lists into one file.
BIS – the Bureau of Industry and Security within the Commerce Department – runs parallel lists under the Export Administration Regulations, most notably the Entity List and the Denied Persons List. These are export-control tools rather than financial-sanctions instruments, but they overlap with OFAC concerns in practice: a party on the Entity List may also appear on the SDN List, and a shipment can trigger both regimes simultaneously. Compliance counsel working on screening programmes must address both.
The Department of Justice has criminal jurisdiction over wilful violations of OFAC regulations. A screening failure that produces an apparent violation, or a pattern of violations, can escalate from a civil OFAC matter to a DOJ referral. That escalation risk is one reason we regularly advise clients to treat screening adequacy as a legal obligation rather than a box-ticking exercise.
What is the legal scope of the screening obligation?
The screening obligation extends to every US person – individuals who are US citizens or permanent residents wherever located, entities organised under US law, and any person physically in the United States – and to any transaction that has a US nexus, including transactions processed in US dollars through a US correspondent bank. Non-US businesses that process USD payments are therefore within scope of OFAC's reach even when neither counterparty is American.
Which lists must a firm screen against? The SDN List is the foundation. A deal or payment involving an SDN – or an entity that the 50 percent rule (OFAC's rule treating entities owned 50 percent or more in the aggregate by one or more blocked persons as themselves blocked, even if not named on any list) treats as blocked – is generally prohibited without a licence. That rule extends the effective screening universe substantially beyond the published SDN List: a clean-named entity may still be blocked if its ownership chain runs through an SDN.
Beyond the SDN List, the Sectoral Sanctions Identifications List imposes transaction-specific restrictions rather than a blanket prohibition. Parties on that list are not fully blocked, but defined categories of transaction – new debt of certain tenors, new equity, and specified dealings in the energy and financial sectors – are prohibited. Screening against this list requires a different analytical response than an SDN hit: the analysis turns on the nature of the transaction, not merely the identity of the counterparty.
The position above covers the standard case. Your counterparties, your goods, your payment routes, and the regimes in play will all change the analysis. For an assessment of your screening obligations under OFAC, contact Calder & Vance at info@caldervance.com.
How does the 50 percent rule operate in practice?
The 50 percent rule requires any business conducting screening to look through a counterparty's corporate structure, not merely to check the entity name against OFAC's published lists. If one or more blocked persons own the counterparty at 50 percent or more in the aggregate – whether directly or through layers of intermediate holding companies – the counterparty is itself treated as blocked, regardless of whether it appears anywhere on a published OFAC list.
Aggregation is where programmes fail most often. Two blocked persons each owning thirty percent of a target entity reach the threshold together. A single blocked person owning forty-five percent, combined with a second owning eight percent, reaches the threshold if both are SDNs. Standard name-matching tools that flag only direct counterparty names do not detect this pattern.
What does that mean operationally? It means screening cannot stop at the entity name. Ownership data – beneficial-owner registries, corporate filings, counterparty questionnaires, third-party commercial data providers – must be consulted and checked against the SDN List. The depth of that review should be proportionate to the transaction's size, sector, and geographic risk profile. In our practice, we see firms that run excellent name-screening systems but have no process for aggregating ownership across shared blocklisted holders. Those firms face the same legal exposure as firms that do no screening at all.
How does OFAC screening compare with OFSI and EU obligations?
OFAC screening is, at its core, a mechanical ownership test: fifty percent or more, blocked. OFSI – the Office of Financial Sanctions Implementation in the UK Treasury – and the EU impose a different test, one that incorporates control alongside ownership. Under OFSI and the relevant EU Council regulations, a non-listed entity may be caught if a designated person controls it, even if ownership sits below fifty percent. Control can arise through contractual rights, voting arrangements, or the ability to appoint a majority of the board.
That divergence has direct operational consequences. A counterparty analysis that satisfies OFAC's ownership test may fail the OFSI or EU control test. For a business operating under both US and UK sanctions exposure – a common position for global banks and multinationals – a single screening result cannot answer the compliance question for both regimes. Two analyses are required, applying two different legal standards.
There is a further practical difference. OFAC prohibitions are programme-specific: the same counterparty may be prohibited under one programme but not another, depending on the goods or services being traded. The EU and UK regimes are also programme-specific, but the control test and the licencing routes available differ. Where both regimes apply to a transaction, the stricter prohibition governs – the business cannot rely on a looser standard in one regime to justify proceeding under both.
Australia, Singapore, the UAE, and Japan each maintain screening obligations tied to UN Security Council designations and their own autonomous measures. Those regimes generally apply an ownership-and-control test closer to the EU/UK model than OFAC's pure-ownership approach. For a cross-border business operating in multiple jurisdictions, screening architecture must accommodate each applicable regime's standard, not merely the most familiar one.
If a transaction has already been flagged across more than one regime, or a filing under one regime conflicts with an obligation under another, early advice can preserve options that close with delay. Contact us at info@caldervance.com.
What are the core technical requirements for an OFAC-compliant screening programme?
An OFAC-compliant screening programme must address five interconnected requirements: list coverage, matching logic, alert management, escalation procedures, and record-keeping. Each element is evaluated in OFAC enforcement actions and should be treated as a legal requirement, not a preference.
List coverage means screening against every OFAC-maintained list relevant to the business's transaction types – at minimum the SDN List and the Consolidated Sanctions List. Firms that process sectoral-risk transactions must screen against the SSI List. The lists are updated without advance notice; a screening system that does not pull live updates is systematically out of date.
Matching logic determines what counts as a hit. Exact-name matching is insufficient. SDN entries include aliases, variant spellings, transliteration differences, and name-order variations. A compliant system must apply fuzzy-matching algorithms calibrated to the level of risk the firm faces. The calibration decision – how many false positives to accept in exchange for a lower false-negative rate – is itself a legal and compliance judgement. Setting the sensitivity too low to reduce operational friction is a common programme deficiency.
Alert management is the process for handling matches. Every hit must be assessed to determine whether it is a true match or a false positive. That assessment must be documented. If a transaction is blocked or rejected, OFAC's reporting requirements apply. The reporting window is short under applicable regulations; verify the current deadline before relying on it.
Escalation procedures ensure that potential true matches reach personnel with the authority and expertise to act. A compliance officer who discovers a possible SDN match and is uncertain what to do next must have a clear internal route to counsel. Delays at this stage, in our experience, produce more legal exposure than the original hit.
Record-keeping underpins everything. OFAC's regulations require that records of transactions and blocked property be maintained for five years from the date of the transaction, or five years from the date the property is unblocked, whichever is later. Records must be available for inspection. A programme that screens correctly but does not retain the evidence of what it did provides no protection in an OFAC examination.
What are the most common screening failures and risk flags?
Screening failures cluster around a small number of recurring deficiencies. Identifying them before an OFAC examination is significantly less costly than addressing them after one.
The most frequent failure mode is incomplete list coverage. Firms that screen against the SDN List but not the SSI List or programme-specific lists miss a category of prohibited transactions. A US bank that processes a debt transaction for an SSI-listed energy company has committed a violation regardless of how well it screened for SDN matches.
Second is the ownership-research gap described above. Screening the entity name but not the ownership chain produces a systematic blind spot. Commercial data providers can assist with ownership research, but their data has known coverage gaps in privately held companies and in jurisdictions with weak disclosure requirements. Where data is unavailable, the firm should document its research, record the gaps, and consider enhanced due diligence – counterparty questionnaires, third-party investigations – before proceeding with high-value transactions.
Third is stale data. A counterparty screened clean at onboarding may be designated the following week. Periodic re-screening – and real-time transaction monitoring for payment businesses – is a requirement, not an option. How frequently a business re-screens depends on its risk profile; there is no single interval that satisfies the obligation in all circumstances.
Fourth is inadequate false-positive review. A programme that generates large numbers of false positives creates pressure on compliance teams to clear alerts quickly. Speed-clearing without proper documentation, or with inadequate analysis, turns a well-calibrated technical system into a liability. We have seen enforcement outcomes in which the quality of the alert-review record was as important to OFAC's penalty calculation as the underlying screening methodology.
Fifth is programme drift. A screening programme designed for one business model may not cover new products, new geographies, or new payment rails. A payment firm that adds a new currency corridor, or a lender that enters a new sector, should re-scope its screening programme before launch. The obligation runs to the full range of the firm's activities.
How is name and entity screening enforced under OFAC, and when should a business involve counsel?
OFAC enforces primarily through civil penalties, which can be substantial. The penalty framework under IEEPA sets the maximum civil penalty per violation at a figure that is periodically adjusted for inflation; verify the current figure before relying on it. OFAC uses a matrix of factors – including the egregious-case standard, the presence or absence of a voluntary self-disclosure (a VSD – proactive reporting of an apparent violation to OFAC before the agency discovers it independently), and the adequacy of the firm's sanctions compliance programme – to determine where within the range a given enforcement action lands.
A timely VSD is a significant mitigating factor. OFAC's published guidance states that a VSD can reduce the base penalty in non-egregious cases. The analysis of whether to file a VSD – timing, scope, the evidentiary record, the risk of attracting further scrutiny – is a legal decision that should not be made without counsel. Filing incorrectly or incompletely can convert a mitigating factor into an aggravating one.
The adequacy of the screening programme at the time of the apparent violation is the single most important factor in penalty mitigation after the VSD analysis. OFAC's published framework sets out five elements it considers when evaluating a compliance programme: management commitment, a risk-based assessment, internal controls, testing and auditing, and training. A business whose programme addressed all five elements – even if a violation still occurred – is positioned very differently in an enforcement proceeding than one that had no programme at all.
Counsel should be involved at three points. First, at programme design: the structure of the screening system, the ownership-research methodology, and the record-keeping architecture are legal questions, not purely technical ones. Second, when an apparent violation is identified: the VSD decision must be made quickly, and the consequences of the wrong call are significant. Third, at programme review: as the business grows, its screening obligations grow with it.
Related practices
- Sanctions compliance audit and testing – stress-testing screening logic, ownership-research processes, and programme documentation against the five-element standard
- Name and entity screening under OFSI – how the UK ownership-and-control test diverges from OFAC and what that means for cross-border compliance
- Name and entity screening under the UN Consolidated List – the Security Council list, who it binds, and how it interacts with national-regime designations