Guide
What OFAC Screening Requires
By Keelstar Team · Updated June 1, 2026
The short answer
OFAC screening checks parties against U.S. Treasury sanctions lists — primarily the Specially Designated Nationals (SDN) list — before you engage them in business. You must screen vendors, customers, and counterparties using legal names and aliases, investigate potential matches, and re-screen on a schedule. OFAC is separate from OIG; healthcare exclusion screening does not satisfy sanctions obligations.
What OFAC regulates
The Office of Foreign Assets Control, part of the U.S. Department of the Treasury, administers economic and trade sanctions against targeted foreign countries, regimes, terrorists, and narcotics traffickers. U.S. persons — including companies — generally may not engage in transactions with parties on OFAC lists unless authorized by a license.
The lists that matter most
The Specially Designated Nationals and Blocked Persons (SDN) list is the primary screening target for most U.S. operations teams. Depending on your industry and geography, you may also screen consolidated non-SDN lists, sectoral sanctions, and country-based programs. Your compliance policy should name which lists you check and how often.
Who to screen
Screen vendors, customers, contractors, payment recipients, and — under the 50 Percent Rule — entities owned 50% or more in aggregate by one or more blocked persons. Ownership screening is where manual name-only checks often fall short.
- New vendors before first payment or contract signature
- Existing vendors on a recurring schedule
- Customers in high-risk industries or geographies
- Wire transfer beneficiaries and international counterparties
Handling potential matches
Sanctions screening produces false positives — especially on common names. Your process must define how analysts resolve matches: compare addresses, dates of birth, country, and other identifiers; escalate true hits; and document the disposition. Blocking a payment or relationship without a documented review trail creates its own compliance risk.
How OFAC differs from OIG
OIG LEIE covers federal healthcare program exclusions. OFAC covers sanctions and blocked parties globally. A vendor can appear on one list and not others. Healthcare providers typically screen all three; other industries may emphasize OFAC.
Building a defensible program
Regulators and banking partners expect a risk-based program: documented policy, screening before engagement, periodic re-screening, match resolution procedures, and retained evidence. Point-in-time searches without logs are difficult to defend. Automated screening with an audit trail closes the gap between policy and proof.
Frequently asked questions
- Does OFAC apply to small U.S. businesses?
- Yes. OFAC sanctions apply broadly to U.S. persons and entities. Size does not exempt you from screening vendors and business partners.
- Is OIG screening enough for OFAC?
- No. OIG covers healthcare program exclusions. OFAC covers economic and trade sanctions. Most regulated organizations screen both.
Related guides
Put this into a monitored workflow
Exclusion Monitor handles this continuously — with reminders and an audit trail.