A payment firm processes hundreds of thousands of transactions daily. Somewhere in that volume, a beneficiary's account is held at a bank that a listed entity controls. The payment clears. Three months later, a compliance review surfaces the connection. Is that a sanctions violation? The answer turns on a precise analysis of OFAC's payment-processing controls – and on whether the firm's screening caught what it was required to catch.
Payment-processing controls under OFAC rules require banks, payment institutions, and intermediaries to screen every transaction against the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and all applicable programme-specific lists, to block or reject prohibited payments, and to report blocked or rejected funds to OFAC within a short statutory window. The obligation reaches correspondent relationships, wire transfers, trade-finance flows, and increasingly digital-asset settlements. As of mid-2026, OFAC has signalled continued focus on cross-border payment channels as a primary enforcement priority.
This briefing sets out who administers payment-processing controls under OFAC, what the key prohibitions are, how the screening obligation applies across payment rails, how OFAC's approach compares with OFSI in the United Kingdom and the EU regime, where enforcement concentrates, and when to bring in sanctions counsel.
Who administers OFAC's payment-processing regime – and on what authority?
The Office of Foreign Assets Control (OFAC), a bureau of the US Department of the Treasury, administers US economic sanctions under authority delegated principally through the International Emergency Economic Powers Act (IEEPA) and, for older programmes, the Trading with the Enemy Act (TWEA). OFAC issues programme-specific regulations for each sanctions regime and publishes guidance on how those regulations apply to financial transactions.
OFAC's jurisdiction is broad. It reaches US persons wherever located, entities organised under US law, and – critically – transactions that involve the US financial system, US-dollar clearing, or US persons in any role. That last limb is where the extraterritorial reach materialises. A non-US bank routing a dollar payment through a US correspondent is, at the moment of that routing, subject to OFAC's rules. In our experience, this is the single most underestimated compliance risk for non-US payment firms.
The regulatory structure layers programme-specific regulations over a common framework of prohibitions, reporting, and licensing. OFAC's administrative guidance – including its Framework for OFAC Compliance Commitments – sets out the five elements that OFAC expects any compliance programme to address: management commitment, risk assessment, internal controls, testing and auditing, and training. Payment firms of all sizes are assessed against this framework when enforcement questions arise.
What does OFAC prohibit in relation to payment-processing?
OFAC's core prohibition is the processing of any transaction in which a Specially Designated National or otherwise sanctioned party has an interest, unless a licence applies. For payment processing, this means four distinct obligations.
First, blocking. A US person or a firm with US nexus that identifies a payment involving a blocked party must freeze the funds. Blocked funds must be held in an interest-bearing account and reported to OFAC. The reporting deadline is short – verify the current position before relying on it, but it is measured in business days, not weeks. Second, rejection. Where a payment does not involve a blocked party but the underlying transaction would itself violate a programme-specific prohibition – for example, because it relates to an activity subject to comprehensive restrictions under the applicable country regime – the payment must be rejected rather than blocked, and that rejection must also be reported. Third, no substitution. A firm may not re-route, restructure, or substitute parties to achieve what the prohibited transaction would have achieved. Fourth, no facilitating. A US person may not approve, finance, guarantee, or otherwise facilitate a transaction that a non-US person could not directly conduct because of OFAC prohibitions.
The distinction between blocking and rejecting matters operationally. Blocked funds are held; rejected transactions are returned. A firm that rejects when it should block – or blocks when it should reject – compounds an original exposure with a procedural failure. OFAC's civil penalty framework treats the two differently, and enforcement actions have turned on exactly this distinction.
The position above covers the standard case. Your facts – the payment rail, the correspondent chain, the underlying goods or services, the counterparty's ownership structure – change the analysis.
For an assessment of your payment-processing exposure under OFAC, contact Calder & Vance at info@caldervance.com.
How does the 50 percent rule apply to payment transactions?
The 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) creates one of the most operationally difficult challenges in payment screening. A counterparty that does not appear on any published OFAC list may nonetheless be a blocked entity if a listed person owns or controls it at or above that threshold.
For a payment firm, this means name-based screening against published lists is necessary but not sufficient. The screening logic must extend to beneficial ownership data. Where a corporate payee is partly owned by an entity with SDN exposure, the payment firm must assess whether the aggregate ownership of blocked persons reaches the threshold. Two blocked persons each holding twenty-six percent of the same payee exceed it together.
Commercial screening tools vary considerably in how far they trace ownership chains. Tools that flag only direct SDN matches miss layered structures. In our practice, we regularly advise payment firms that their screening catches the obvious cases and misses the aggregation problem. The question to ask is not "does this payee appear on a list?" but "does any listed person own this payee at or above the threshold, directly or indirectly, in any combination?"
Under the EU and UK regimes, a parallel but distinct test applies. The EU relies on an ownership and control test (whether a listed person owns or controls a non-listed entity), and OFSI in the United Kingdom applies a similarly constructed test under SAMLA regulations. Both regimes can catch entities below the 50 percent line if effective control is present. A payment firm operating across these regimes must maintain separate compliance logic for each – OFAC's mechanical 50 percent test is not interchangeable with the EU or UK approach.
Which payment channels does OFAC's screening obligation cover?
OFAC's screening obligation attaches to the processing firm, not to the payment rail. The obligation applies to wire transfers, automated clearing-house transactions, trade-finance instruments including letters of credit and documentary collections, card-network settlements, and digital-asset transfers where a US person or US nexus is present.
Correspondent banking channels deserve particular attention. A foreign bank with no US customers that processes a dollar-denominated wire through a US correspondent bank is, through that correspondent relationship, subject to OFAC's rules at the moment of clearing. US correspondent banks that clear dollar payments are themselves OFAC-obligated and typically impose downstream screening requirements on their respondent banks as a contractual matter. This creates a layered compliance environment: the respondent must screen, and the correspondent screens again.
Digital-asset processing has become a distinct area of OFAC focus. OFAC has published guidance on virtual-currency obligations, and its programme regulations have been extended to cover digital-asset transactions with sanctioned parties or jurisdictions. For virtual asset service providers (VASPs) – firms that exchange, transfer, or custody digital assets – the compliance obligation includes screening wallet addresses against OFAC's published list of digital-currency addresses associated with SDNs. OFAC has added a significant number of such addresses to the SDN List in recent enforcement cycles.
Trade-finance channels introduce a further layer of complexity. Letters of credit and documentary collections involve multiple correspondent banks, the issuing bank, the advising bank, and in some cases confirming banks. Each party that processes the payment leg is independently obligated. In our experience, gaps arise most often at the advising bank stage, where operational pressure to process can crowd out adequate screening review.
How does OFAC's payment-processing enforcement compare with OFSI and the EU?
OFAC enforces through civil administrative penalties and, in the most serious cases, through criminal referral to the Department of Justice. Civil penalty calculations consider multiple factors – the nature of the violation, the existence of a voluntary self-disclosure (VSD: a proactive report to the regulator before enforcement contact), the strength of the compliance programme, and whether the violation was egregious. OFAC's published penalty framework indicates that a timely VSD can significantly reduce the penalty exposure, though no specific outcome is guaranteed.
OFSI, the UK's Office of Financial Sanctions Implementation, enforces UK financial sanctions under SAMLA. OFSI has the power to impose a monetary penalty and to publish enforcement decisions. OFSI's licensing and enforcement posture has become more active in recent years. A key operational difference: OFSI operates a reporting obligation that requires disclosure of knowledge or reasonable cause to suspect a sanctions breach, and the reporting deadline is measured in a short window. OFSI's approach to VSD is broadly similar in spirit to OFAC's, but the procedural mechanics and the penalty calculation methodology differ.
The EU enforces through member-state competent authorities, with no single pan-European enforcement body for financial sanctions. This creates variation in enforcement intensity across the EU. The EU General Court provides the annulment route for designation challenges, but payment-processing enforcement decisions are taken at the national level. Firms operating EU payment rails must map the competent authority in each relevant member state.
Where OFAC, OFSI, and EU rules apply simultaneously – as they do for many European banks with US dollar clearing – the stricter prohibition governs. A transaction that EU rules permit but OFAC prohibits cannot proceed through the US correspondent channel. Cross-regime compliance design must start from the most restrictive position.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time.
Write to Calder & Vance at info@caldervance.com for a confidential review.
What are the principal risk flags in payment-processing compliance?
Practitioners advising on OFAC matters identify a consistent set of failure modes in payment-processing compliance. Each represents a point at which the screening obligation can fail even when a programme exists on paper.
The first is incomplete screening coverage. Programmes that screen outgoing payments but not incoming receipts, or that screen corporate names but not individuals in the ownership chain, create gaps that OFAC enforcement has repeatedly exploited. A payment firm must screen all parties – the originator, the beneficiary, the originating bank, the beneficiary bank, and any intermediary – at every stage of processing.
The second is poor name-matching logic. SDN names appear in multiple transliterations, with alternate spellings, and under aliases. Screening tools calibrated at too high a match threshold will miss genuine hits. Tools calibrated too low generate unmanageable false-positive volumes. The calibration decision is a documented compliance choice that OFAC will review on enforcement.
The third is the "payment straight-through processing" problem. Automated payment environments route transactions without human review. Where a screening alert is generated and auto-cleared without a qualified review, the clearing becomes a compliance event in its own right. OFAC has found violations in exactly this pattern.
The fourth is correspondent-bank reliance. Some payment firms assume that because their US correspondent screens independently, their own screening obligation is satisfied. It is not. Each party in the chain bears its own obligation.
The fifth is the failure to block promptly. When a payment is identified as potentially involving a blocked party, a firm that delays while it investigates may itself incur a reporting violation. The obligation to block is triggered by identification, not by confirmed certainty. A hold-and-investigate procedure needs to be timed carefully against the reporting deadline.
Have you tested your screening coverage against a simulated layered-ownership scenario? Have you reviewed the auto-clear rate on your screening alerts in the past twelve months? These are the questions OFAC examiners ask first.
The myth that OFAC applies only to US banks
A persistent misconception among non-US payment firms is that OFAC's payment-processing rules are a US-domestic matter, relevant only to US-chartered banks and their direct US customers. This is incorrect, and acting on it creates serious exposure.
OFAC's jurisdiction extends to any transaction that touches the US financial system, which in practice means any US-dollar-denominated wire, any transaction processed through a US correspondent, and any transaction in which a US person participates in any capacity. A UK payment institution processing a dollar wire on behalf of a European corporate – with no US customer relationship and no US office – is subject to OFAC rules at the moment the wire transits a US correspondent. The correspondent will screen; if the respondent has not, the correspondent's alert becomes the respondent's compliance problem.
In our practice, we regularly advise non-US payment firms that are encountering OFAC exposure for the first time through a correspondent-bank query or a derisking notice. The assumption that US rules stop at the US border is wrong. The practical question is not whether OFAC applies, but how thoroughly the firm has assessed and documented its own exposure.
Related practices
- Sanctions compliance audit and testing – assessing and stress-testing your screening and compliance programme across regimes
- Payment-processing controls under OFSI – how UK financial sanctions apply to payment firms and where OFSI diverges from OFAC
- Payment-processing controls under the UN regime – the UN Consolidated List and its interaction with domestic payment-screening obligations