← Back to blog
OFACCompliance basicsRegulation

OFAC Screening Requirements: Who Must Screen

The Screen100 Team··8 min read
Compliance team reviewing documents to meet OFAC screening requirements

Photo by Mikhail Nilov on Pexels

OFAC screening requirements catch out more businesses than the phrase "sanctions compliance" suggests, because the obligation isn't limited to big banks. If you're a US person — a category that's broader than most people assume — you're bound by OFAC's rules the moment you deal with a counterparty, regardless of your size, sector, or whether you meant to break anything. Understanding exactly who's covered, why intent doesn't matter, and what a reasonable screening programme looks like is the difference between a manageable compliance habit and an unpleasant surprise.

Key takeaways

  • OFAC rules bind every "US person" — US citizens and permanent residents anywhere in the world, US-organised entities and their foreign branches, and anyone physically present in the United States.
  • OFAC's civil penalty regime is strict liability: a violation can occur, and be fined, even without knowledge or intent.
  • There's no formal size threshold — a small e-commerce business with international sellers can fall squarely within scope.
  • OFAC expects a risk-based sanctions compliance programme built on five components: management commitment, risk assessment, internal controls, testing and auditing, and training.
  • Records connected to sanctions-relevant transactions must now be kept for ten years, not five, following a 2025 rule change.

Who counts as a "US person" bound by these rules?

OFAC's jurisdiction turns on the concept of a "US person," and it's wider than most non-lawyers expect. It covers US citizens and permanent resident aliens no matter where in the world they're living or working, any entity organised under the laws of the United States or a US state — including that entity's foreign branches — and, separately, anyone physically located within the United States regardless of nationality. That last category is easy to overlook: a foreign visitor conducting business while on US soil is bound by OFAC rules for the duration of that presence, even though they'd fall outside US jurisdiction back home.

This matters practically because it means "we're not a US company" isn't automatically a way out. A foreign subsidiary of a US parent, a US citizen working abroad for a non-US employer, or a foreign bank's US branch can all trigger OFAC exposure through the underlying corporate structure or physical presence, even when the immediate transaction looks entirely foreign. OFAC's own FAQ on the subject confirms the same scope: citizens, permanent residents, US-organised entities and their foreign branches, and anyone within US territory.

Why is OFAC compliance "strict liability"?

This is the detail that trips up businesses that assume good intentions are a defence. OFAC's civil penalty authority doesn't require proof that a person or company knew a transaction was prohibited — a violation can exist, and be penalised, purely because it happened. Ignorance of a counterparty's sanctioned status, or of the fact that funds ultimately touched a blocked jurisdiction, doesn't stop a violation from being a violation; it only affects how severely OFAC responds once one is discovered. Knowledge and intent become relevant later, as mitigating factors that can reduce a penalty, not as something that prevents liability from attaching in the first place.

That distinction is worth sitting with. A business that never screens counterparties at all and one that screens diligently but still misses an obscure alias can both technically commit a violation — but they will not be treated the same way once OFAC evaluates the case. A documented, consistently applied screening process is the single clearest piece of evidence that a business took its obligations seriously, and it's the factor that shows up repeatedly in OFAC's published settlements as a reason penalties were reduced rather than escalated.

A marketplace that didn't think it was "in scope"

Consider a mid-sized e-commerce marketplace based in the United States that connects domestic buyers with independent sellers. For its first few years, the business assumes sanctions screening is something for banks and payment processors, not a listings platform. As the seller base grows to include individuals and small businesses shipping goods internationally, and as the marketplace itself starts settling payouts to sellers in additional countries, it becomes a US person facilitating transactions that could — without anyone intending it — involve a sanctioned party sitting somewhere in that seller or payout chain. There's no dramatic trigger moment; the exposure simply accumulates as the platform scales internationally. By the time the founders look into it properly, they realise a basic screening step at seller onboarding, repeated periodically as lists update, would have closed the gap from day one. This scenario is illustrative rather than a specific real case, but it reflects a pattern regulators have flagged repeatedly as marketplaces and fintechs have grown into sanctions exposure without a formal compliance background.

Do small businesses have to screen against OFAC?

There's no revenue or headcount threshold that exempts a business from OFAC's rules — the obligation follows from being a US person engaged in a transaction, not from company size. In practice, the businesses that face the most formal, examined obligations are regulated financial institutions, money service businesses, broker-dealers and payment processors subject to Bank Secrecy Act (BSA) requirements, since their federal regulators actively examine sanctions compliance as part of BSA/AML supervision. But the underlying OFAC prohibition applies just as much to a small export business, a freelance marketplace, a property manager taking an international tenant's deposit, or a professional services firm invoicing an overseas client.

What changes with size and sector isn't whether the rule applies, but how much of a formal, examined programme is reasonable to expect. OFAC has been explicit that it expects a risk-based approach: a global bank's screening programme should look very different from a two-person export business, but both are expected to have thought about their exposure and to have some proportionate control in place. A business with no international counterparties at all carries a lower baseline risk than one regularly dealing with cross-border payments, high-risk jurisdictions, or unfamiliar counterparties — and its programme should reflect that.

What does a reasonable OFAC compliance programme actually include?

OFAC's own published guidance, A Framework for OFAC Compliance Commitments, sets out what it expects from a sanctions compliance programme (SCP) in plain terms: "OFAC strongly encourages organizations subject to U.S. jurisdiction, as well as foreign entities that conduct business in or with the United States, U.S. persons, or using U.S.-origin goods or services, to employ a risk-based approach to sanctions compliance by developing, implementing, and routinely updating a sanctions compliance program." The Framework doesn't prescribe a single template — it explicitly expects programmes to vary by size, sophistication, products, and geographic footprint — but it identifies five components that should show up in some form in every risk-based programme.

Component What it involves in practice
Management commitmentSenior leadership reviews and approves the programme, allocates adequate resources, and empowers the compliance function to escalate issues without interference.
Risk assessmentA routine, documented review of customers, products, services, supply chains and geographies to identify where sanctions exposure actually sits, updated as the business changes.
Internal controlsWritten policies and procedures, including counterparty and transaction screening, that let staff identify, escalate and report potential matches consistently.
Testing and auditingPeriodic independent review of whether the programme is actually working as designed, with findings fed back into the risk assessment and controls.
TrainingRole-appropriate training for relevant staff, delivered at least annually, covering what a potential match looks like and what to do with one.

None of this requires enterprise software to get started. For a smaller business, "internal controls" might mean running every new counterparty through a free OFAC check before onboarding and keeping a record of the result; for a larger one, it means automated screening wired into onboarding and payment workflows via an API, with periodic re-screening as lists update. The OFAC SDN list and the Consolidated list both change frequently, so a one-off check at signup isn't the same as an ongoing programme.

What recordkeeping does OFAC expect?

Screening is only half of what a documented programme requires — you also need to be able to show your work. Under 31 CFR 501.601, anyone engaging in a transaction subject to OFAC regulations must keep a full and accurate record of it, and that record must remain available for examination. In March 2025, OFAC extended this retention period from five years to ten, following amendments that extended the statute of limitations for most sanctions violations to match. Practically, that means screening logs, match decisions, and the reasoning behind any false-positive dismissal need to be retained for a decade, not filed away and forgotten after a few years — a meaningfully longer horizon than many compliance calendars were built around before the change.

How does this relate to BSA/AML obligations?

OFAC sanctions compliance and Bank Secrecy Act anti-money-laundering (BSA/AML) programmes are legally distinct regimes administered by different parts of Treasury — OFAC itself, and the Financial Crimes Enforcement Network (FinCEN) for the BSA — but in practice they overlap heavily for regulated institutions. Sanctions screening checks the identity of a counterparty against a specific prohibited-party list; BSA/AML transaction monitoring looks at behavioural patterns for signs of money laundering. A bank or money service business is expected to run both, and its federal banking regulator will examine OFAC controls as part of a broader BSA/AML review even though the underlying legal obligations come from separate statutes.

Turning the requirement into a habit

The clearest way to close the gap between "we're aware of OFAC" and "we have a working programme" is to make screening a routine step rather than a one-off audit reaction. That starts with knowing how to run an OFAC check properly — matching names against aliases and transliteration variants rather than a raw string search — and understanding what happens if a violation does slip through, covered in our companion piece on how OFAC penalties are actually calculated. If you're weighing up whether to build screening in-house or lean on a dedicated tool, Screen100's pricing page lays out what a metered API and ongoing monitoring cost against the risk of getting it wrong.

The bottom line

OFAC screening requirements aren't reserved for banks: they follow from being a US person, and they apply on a strict liability basis regardless of company size or intent. A proportionate, risk-based programme — built around the five components OFAC itself has published, backed by records kept for ten years — is what turns "we didn't know" from a losing argument into a genuinely mitigating one. The easiest place to start is the transaction in front of you: try Screen100's free screening tool on your next new counterparty.

Frequently asked questions

Who is legally required to screen against OFAC?

Anyone who qualifies as a US person — US citizens and permanent residents anywhere in the world, entities organised under US law and their foreign branches, and anyone physically located in the United States — is bound by OFAC's prohibitions. There's no size threshold; regulated financial institutions face more formal examination of their programmes, but the underlying obligation applies just as much to small businesses with international counterparties.

Does a small business really need a formal OFAC compliance programme?

OFAC expects a risk-based programme proportionate to the business's actual exposure, not a one-size-fits-all template. A small business with modest international dealings needs far less than a global bank, but it's still expected to have assessed its risk and put some reasonable screening step in place — the obligation doesn't disappear just because the business is small.

Why does 'strict liability' matter if my business acted in good faith?

Because OFAC's civil penalty authority doesn't require proof of knowledge or intent for a violation to exist — good faith doesn't prevent liability, it only affects how OFAC responds afterwards. A documented screening process and prompt remediation are treated as significant mitigating factors when a violation is found, which is why running one matters even though it can't guarantee a mistake never happens.

How long do OFAC-related records need to be kept?

As of a March 2025 rule change, records connected to transactions subject to OFAC regulations must be kept for ten years, up from the previous five-year requirement under 31 CFR 501.601. That includes screening logs and the reasoning behind match decisions, not just the underlying transaction records.

Run this check on a real name

Free, no account required. Screen against the OFAC SDN, OFAC Consolidated and UN Security Council lists.