OFAC screening is the process of checking customers, counterparties, beneficial owners, vessels, aircraft, payments, and other relevant parties against sanctions restrictions administered by the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC). It is often described as “watchlist screening,” but sanctions compliance is broader than matching a name to a list. A company may also need to understand ownership, location, transaction purpose, goods or services involved, applicable sanctions programs, licenses, and whether a blocked person owns an entity that is not itself named on the SDN List. Automated OFAC screening can help organizations manage large volumes of names and transactions, but software does not make the compliance decision by itself. OFAC expressly states that it does not recommend one universal name-match threshold because appropriate settings depend on an organization’s own risk assessment and compliance practices.
OFAC published a new introductory guide on June 1, 2026 to help U.S. and foreign persons understand how its sanctions work, how licensing works, and how enforcement is handled. Businesses building or reviewing a sanctions program should use current OFAC sources because sanctions lists and program rules can change frequently. This guide explains who should think about OFAC compliance, the SDN and non-SDN lists, the 50 Percent Rule, fuzzy matching, false positives, screening frequency, payment screening, escalation, blocking and rejecting transactions, risk-based controls, and the limits of sanctions-screening software.
What Is OFAC Screening?
The preserved OFAC — Introduction to OFAC Guide, June 2026 is especially useful in 2026 because Treasury published it on June 1 as a foundational explanation of how OFAC sanctions work, how licensing and delisting operate, and how enforcement fits into compliance. Screening should therefore be understood as one control inside a broader sanctions program, not as a single software lookup that guarantees compliance. The Office of Foreign Assets Control administers and enforces U.S. economic and trade sanctions based on U.S. foreign-policy and national-security objectives. Sanctions can target: individuals; companies; organizations; governments; sectors; vessels; aircraft; specified activities.
Who Must Comply and How Risk Changes
Who Must Comply With OFAC Sanctions?. U.S. persons generally must comply with OFAC sanctions. This includes, depending on context: U.S. citizens; U.S. permanent residents; persons physically in the United States; entities organized under U.S. law; their foreign branches in many programs. Some sanctions programs also impose obligations on U.S.-owned or controlled foreign entities. Foreign Companies Can Also Face OFAC Risk. The common statement that “every transaction in U.S. dollars automatically requires OFAC screening” is too simplistic. Foreign companies can face U.S. sanctions exposure when, for example, they: cause a U.S. person to violate sanctions; route activity through the U.S. financial system; deal with blocked property under U.S. jurisdiction; engage in conduct covered by a particular sanctions program; face secondary-sanctions risk. Scope should be assessed transaction by transaction with qualified counsel when necessary. Screening Is a Control, Not the Entire Compliance Program. A business can screen every customer name and still violate sanctions if it ignores: ownership; geography; product restrictions; sectoral sanctions; prohibited services; transaction structure.
Lists, Ownership, and the 50 Percent Rule
The OFAC — Sanctions List Service is OFAC’s current primary delivery point for the SDN and consolidated non-SDN lists. Ownership analysis also remains essential: the preserved OFAC — 50 Percent Rule FAQ explains that entities owned 50% or more in the aggregate by one or more blocked persons are themselves blocked even if not separately named. Control below 50% is not automatically the same rule, although OFAC urges caution around significant ownership or control. The SDN List. OFAC’s Specially Designated Nationals and Blocked Persons List identifies persons whose property and interests in property are generally blocked when they come within U.S. jurisdiction. The SDN List can include: individuals; companies; groups; vessels; aircraft.
Non-SDN Lists. OFAC also administers several non-SDN sanctions lists. Restrictions on a non-SDN-listed person may be narrower than full blocking. Depending on the list or program, restrictions can involve: certain debt; certain equity; specific securities; specified transactions. Use the Current Sanctions List Service. OFAC’s Sanctions List Service provides current SDN and consolidated non-SDN list data and supports downloadable datasets and search tools. Businesses operating automated screening should establish a process for: list updates; data refresh; change monitoring; version control. The OFAC 50 Percent Rule. One of the most important sanctions concepts is that an entity can be blocked even when its name does not appear on the SDN List.
Under OFAC’s 50 Percent Rule, property and interests in property of an entity are generally blocked when one or more blocked persons own, directly or indirectly, 50% or more in the aggregate. Example of Aggregate Ownership. Suppose: Blocked Person A owns 30% of Company X; Blocked Person B owns 25% of Company X. Their aggregate blocked ownership is 55%. Company X can therefore be treated as blocked even if “Company X” is not separately listed. Control Is Not the Same as Ownership. OFAC’s 50 Percent Rule is ownership-based. A blocked person controlling an entity without reaching the ownership threshold does not automatically make the entity blocked solely under that rule. However, transactions involving that control relationship can still create risk and warrant escalation. Why Beneficial Ownership Matters. A simple legal-name screen can miss: holding-company structures; indirect ownership; aggregated sanctioned ownership; recent ownership changes. Higher-risk customers and counterparties may require ownership due diligence beyond list matching.
Matching, Fuzzy Search, and Escalation
The OFAC — Sanctions List Search FAQs explains that OFAC’s public search uses fuzzy logic for names and that lower score thresholds return broader possible matches. OFAC does not prescribe one universal match threshold because the appropriate setting depends on the user’s own risk assessment and compliance practices. A score is therefore a screening aid, not a final determination; analysts still need to compare identifiers, addresses, dates, nationality, ownership, and transaction context. How OFAC Sanctions List Search Works. OFAC’s public search tool can return exact and fuzzy name matches. OFAC says fuzzy logic in its tool applies to the name field. Other fields use character-matching logic.
What Is Fuzzy Matching?. Fuzzy matching looks for similar rather than identical names. This helps identify variations such as: spelling differences; transliteration differences; word-order changes; phonetic similarity. A High Match Score Is Not Proof of a Sanctions Match. A similarity score tells you how similar two names are. It does not tell you that they are the same person. Analysts must compare additional identifiers. OFAC Does Not Recommend One Universal Threshold. OFAC FAQ 250 states that it cannot recommend a specific match threshold because each search has its own facts. Organizations should select thresholds based on: risk assessment; customer population; languages/transliterations; false-positive volume; transaction risk. Too High a Threshold Can Miss Matches. Exact-match-only screening can miss: minor spelling errors; abbreviations; Arabic/Russian/Chinese transliteration differences; name-order variation. Too Low a Threshold Can Overwhelm Analysts. A very loose threshold can create thousands of false positives. That can: delay legitimate business; consume analyst time; reduce attention to genuine alerts. How to Investigate a Potential Match. OFAC’s match guidance recommends comparing available identifying information. Depending on the subject, review:
- full name;
- aliases;
- entity type;
- date of birth;
- place of birth;
- nationality;
- citizenship;
- address;
- passport number;
- national ID;
- company registration details.
Example of a False Positive. A customer named “Mohammed Ali” triggers a name alert. The listed person is: born in 1965; a national of a different country; has a different passport; has a different address. Those differences may allow the alert to be cleared, subject to company procedure. When to Escalate. Escalate when: multiple identifiers align; the ownership structure is unclear; the country/program creates additional restrictions; the transaction involves a sanctioned sector; legal interpretation is required.
Onboarding, Rescreening, and Transaction Screening
Screening at Customer Onboarding. Organizations commonly screen: customer; beneficial owners; directors; authorized signers; relevant counterparties. Which parties are screened should follow the risk assessment and legal obligations. Rescreening Existing Customers. Sanctions status can change after onboarding. Rescreening may occur: when OFAC lists change; periodically; when ownership changes; before high-risk transactions. Transaction Screening. Payment screening may need to evaluate: originator; beneficiary; banks; intermediaries; free-text payment fields; vessels; locations. Shipping and Trade Screening. Exporters may screen: buyer; consignee; end user; freight forwarder; vessel; banks. OFAC is only one part of U.S. trade compliance; Commerce and State Department restrictions can also apply. Country Sanctions Are Not All the Same. OFAC programs vary substantially. Some are: territory-based; government-focused; sectoral; activity-specific; person-specific. Do not use an outdated “banned countries” list as a substitute for program analysis.
Licenses, Blocking, and Rejecting
Licenses. OFAC can authorize otherwise prohibited activity through: general licenses; specific licenses. General license. Applies to a defined category of transactions without requiring each user to obtain individual written permission, provided all conditions are met. Specific license. Issued in response to an application for a particular transaction or activity. Licenses Have Conditions. A license may impose: dates; reporting; counterparty limits; payment conditions. Keep evidence showing why the license applies. Blocking vs. Rejecting. These are different actions. Blocking. Property is frozen and must be held as blocked property according to OFAC requirements. Rejecting. A prohibited transaction may be refused without the property being blocked, depending on the applicable regulation. The correct treatment requires program-specific analysis. Do Not “Return” Blocked Funds Without Authorization. Once property must be blocked, a company should not simply send the money back to the sender. Follow OFAC’s reporting and holding requirements.
Risk-Based Sanctions Compliance Program
OFAC’s compliance framework emphasizes five core components: management commitment; risk assessment; internal controls; testing and auditing; training. 1. Management Commitment. Senior management should: allocate resources; support escalation; promote compliance culture; respond to identified weaknesses. 2. Risk Assessment. Assess exposure by: customer; product; geography; transaction channel; industry; counterparty; merger/acquisition. 3. Internal Controls. Controls should explain: who is screened; when screening occurs; threshold settings; alert handling; escalation; blocking/rejection; reporting. 4. Testing and Auditing. Test whether controls actually work. This can include: sample alerts; list-update testing; data-field mapping; false-negative testing; case documentation. 5. Training. Training should match job responsibilities. Employees who enter customer names need different detail from: sanctions analysts; trade teams; executives; IT staff.
Common Screening Failures and Recordkeeping
Common Screening Failures. stale sanctions data; wrong field mapping; exact-match-only configuration; failing to screen beneficial owners; poor transliteration handling; alert clearing without evidence; screening only at onboarding. Software Limitations. Screening software cannot independently determine: complex ownership; license applicability; program-specific legal interpretation; the true identity behind weak data. Human review remains necessary. Recordkeeping. Retain evidence of: search results; alert decisions; supporting identifiers; escalation; licenses; blocked/rejected transaction handling. Strict-Liability Risk. OFAC civil enforcement can apply on a strict-liability basis in many sanctions contexts, meaning a person can face civil liability even without knowing they were dealing with a sanctioned party. That is one reason reasonable preventive controls matter.
Frequently Asked Questions. Is OFAC screening required only for banks?. No. Sanctions obligations can affect many industries. The exact compliance controls should reflect the organization’s legal exposure and risk. Does OFAC recommend a match threshold?. No. OFAC says organizations should determine thresholds using their own risk assessments and compliance practices. Does a company have to be named on the SDN List to be blocked?. No. An entity can be blocked under the 50 Percent Rule through aggregate ownership by blocked persons. Are all sanctions “country bans”?. No. OFAC administers many different program structures, including person-, sector-, government-, and activity-based restrictions. Can software make the final match decision?. Software can generate alerts, but qualified human review is necessary for potential matches and legal interpretation.
A mature 2026 screening process also needs list-update governance. OFAC’s Sanctions List Service is designed to provide current list data and downloadable formats for automated systems, while the public web search is intended for individual users rather than continual automated querying. Businesses should document how list updates reach screening systems, how quickly customers and transactions are rescreened, how potential matches are dispositioned, and how blocked or rejected transactions are escalated and reported. These controls become more important as sanctions programs change and as ownership structures make exposure less obvious than a direct name match.
Conclusion
OFAC screening is an important sanctions-compliance control, but it should not be mistaken for the entire sanctions program. Name matching can identify possible listed parties, while ownership analysis, transaction review, geography, sanctions-program rules, and licensing determine whether activity is actually prohibited or restricted. The strongest screening systems use current OFAC list data, risk-based thresholds, beneficial-ownership review, documented alert investigation, periodic rescreening, and clear escalation procedures. Do not assume that a clean name screen means a transaction is safe—or that a fuzzy name alert means a person is sanctioned. Sanctions compliance depends on evidence and context.