Skip to content
OFAC Sanctions Screening
Whitepaper · 2026

OFAC Sanctions Screening Best Practices

Why single-list screening is no longer sufficient, and how screening across multiple lists with fuzzy name matching catches what basic systems miss.

10 min readMay 2026OFAC · BIS · EU · UK
01 · Executive Summary

Screening Is an Architecture, Not a Checkbox

The Office of Foreign Assets Control (OFAC) administers and enforces economic sanctions against targeted foreign countries, regimes, terrorists, narcotics traffickers, and proliferators of weapons of mass destruction. OFAC compliance is not limited to financial institutions. It applies to all US persons and entities, including defense contractors, educational institutions, healthcare organizations, and any business engaging with foreign nationals.

Yet many organizations screen against a single list, typically the SDN list, and treat that as compliance. That approach can miss restricted parties that appear only on other lists, such as the BIS Entity List and the UK, EU, and UN sanctions lists.

Worse, basic exact-match screening misses name variations, transliterations, and aliases that sophisticated sanctions targets deliberately use to evade detection. OFAC can impose civil penalties on a strict liability basis, so a missed match can be a violation even if nobody knew. Intent still shapes the penalty: OFAC weighs whether conduct was willful or reckless and how strong the compliance program was.

Screened by default

OFAC SDN and SSI, the BIS Entity List and Denied Persons List, and the UK, EU, and UN sanctions lists, among other US and international sources.

10
Years of Records
31 CFR 501.601
50%
Ownership Rule
Indirect blocking
02 · The Problem

Why Single-List Screening Fails

Organizations that screen only against the OFAC SDN list are operating with significant blind spots. Here's what a single-list approach misses.

BIS Entity List Entities Are Not on the SDN List

The Bureau of Industry and Security maintains a separate Entity List of organizations subject to export restrictions under the EAR. An entity can be on the BIS list (requiring export licenses for even basic technology) without appearing on the SDN list. SDN-only screening would clear them for access to your facility.

EU and UK Sanctions Diverge from US Lists

Post-Brexit, the EU and UK maintain independent sanctions regimes. Entities sanctioned by the EU may not appear on OFAC lists, and vice versa. If your organization operates globally, or hosts visitors from EU/UK-sanctioned jurisdictions, US-only screening creates compliance gaps in your international obligations.

Exact-Match Screening Misses Name Variations

Sanctioned individuals routinely use transliterated names, aliases, and spelling variations to evade detection. “Mohammed” has 30+ English transliterations. Russian Cyrillic names have multiple romanization standards. Chinese names vary in Pinyin, Wade-Giles, and regional dialect spellings. An exact-match system catches none of these variations.

Ownership Structures Are Not Captured by Name Matching

Under OFAC's 50 Percent Rule, an entity is blocked if one or more blocked persons own 50 percent or more of it, directly or indirectly, individually or in the aggregate, whether or not it is named on any list. Many such entities are not named on the SDN List, so name screening alone can miss them; ownership analysis finds them. If you are screening names only, you are missing an entire category of sanctioned entities.

Strict Liability Means No Excuses

OFAC can impose civil penalties on a strict liability basis, so “we only screened one list” or “our system doesn't do fuzzy matching” is not a defense. OFAC asks for a risk-based compliance program with screening tools calibrated to your risk profile and tested regularly, and its compliance framework names outdated lists and missed spelling variants among the common causes of violations. For an organization that hosts foreign nationals, we recommend screening several lists with matching that catches spelling variants.

03 · The Landscape

The Sanctions Lists You Should Be Screening

A comprehensive sanctions screening program covers multiple government sources across jurisdictions. Here are the primary lists, why each matters, and whether SecurePoint screens it by default.

ListSourceDescriptionIn SecurePoint
OFAC SDNUS TreasurySpecially Designated Nationals and Blocked Persons. The primary US sanctions list, covering individuals, entities, vessels, and aircraft.On by default
OFAC SSIUS TreasurySectoral Sanctions Identifications. Targets specific sectors of sanctioned economies (financial, energy, defense).On by default
BIS Entity ListCommerce DeptEntities subject to specific export license requirements under the Export Administration Regulations (EAR). Critical for dual-use technology.On by default
BIS Denied PersonsCommerce DeptIndividuals and entities whose export privileges have been denied. Taking part with them in a transaction involving items subject to the EAR is prohibited.On by default
DDTC DebarredState DeptParties debarred from participating in defense trade under ITAR. Directly relevant to defense contractors.Off until enabled
UK Sanctions (OFSI)HM TreasuryUK consolidated sanctions list maintained by the Office of Financial Sanctions Implementation.On by default
EU FSFEuropean UnionThe EU Financial Sanctions Facility: the consolidated list of EU sanctions targets across all EU sanctions regimes.On by default
UN ConsolidatedUN Security CouncilUN Security Council sanctions committees consolidated list. Foundation for many national sanctions programs.On by default
FBI Most WantedFBITerrorism, kidnapping, and fugitive lists. Catches individuals who may not appear on financial sanctions lists.On by default
INTERPOL Red NoticesINTERPOLInternational wanted persons. Relevant for organizations with global visitor programs.On by default
SAM ExclusionsGSAGovernment contractor exclusions from SAM.gov. Relevant to organizations with federal contracts.Off until enabled
LEIEHHS OIGList of Excluded Individuals/Entities from federal healthcare programs. Relevant to healthcare-adjacent organizations.Off until enabled

Additional lists include UFLPA, World Bank Debarment, IADB Sanctions, French DGT, Federal Reserve Enforcement, and Singapore MAS Enforcement, all on by default.

04 · Fuzzy Matching

The Science of Name Resolution

Exact-match screening misses a true match that differs by a transliteration, a misspelling, an alias, or name order. Fuzzy matching closes that gap by scoring how similar two names are rather than whether they are identical, and a threshold decides which scores a person reviews. These are the techniques most often used.

The challenge is balancing sensitivity (catching true matches) against specificity (avoiding false positives). Too sensitive and compliance teams drown in false alerts. Too specific and true sanctions hits slip through.

Exact Match

Character-for-character comparison after normalization. Highest confidence, but it catches only direct hits.

Normalized Exact

Matches after removing company suffixes (Inc., Ltd., GmbH, LLC) and standardizing formatting. Catches corporate name variations.

Jaro-Winkler

Optimized for name-length strings. Good at catching transpositions, missing characters, and common misspellings.

Levenshtein

Edit distance algorithm. Catches typos by measuring the minimum number of single-character edits needed to transform one string into another.

Double Metaphone

Phonetic matching that generates pronunciation codes. Catches transliterations across alphabets, which matters for Arabic, Cyrillic, and CJK romanizations.

Trigram

Breaks names into 3-character substrings and measures overlap. Effective for partial matches and name reordering (first/last swap).

How SecurePoint Scores a Name

Sanctions screening in SecurePoint scores each candidate with Jaro-Winkler similarity, compares the name in several orders so a surname-first entry still matches, and looks up each listed alias exactly. Common names must clear a stricter minimum. The default match threshold is 0.75, and candidates that screening rules dismiss are recorded in the decision trace.

Where the Weighted Composite Runs

SecurePoint uses a weighted composite of all six techniques in two other places: to match owners in the ownership graph against listed parties, and to match names in adverse-media monitoring.

05 · Ownership Rule

The OFAC 50% Ownership Rule

Under OFAC's 50 Percent Rule, an entity owned 50 percent or more in total, directly or indirectly, by one or more blocked persons (including parties on the SDN List) is itself blocked, whether or not it is named on any list. Many such entities are not named on the SDN List, so name screening alone can miss them.

Finding them takes ownership analysis: tracing ownership chains through corporate structures and adding up the stakes held by blocked persons.

How SecurePoint Checks Ownership

1

Identify the Entity

The entity to check, such as a vendor or another counterparty, is submitted through the screening API or the compliance team's ownership lookup and matched against the ownership records the platform holds. Ownership analysis runs on entities; individual visitors are screened by name.

2

Trace Ownership Chains

Ownership chains are traced through several levels of ownership records drawn from GLEIF LEI relationship data and other open datasets. Coverage is limited to the entities those records include.

3

Calculate Aggregate Ownership

Stakes held by listed parties are added together. An intermediate company passes its stake through only if it is itself 50 percent or more owned by them, the way OFAC's FAQ 401 counts indirect ownership. A total of 50 percent or more is treated as blocked.

!

What Happens by Default

By default the ownership result is recorded with the screening result and does not change the decision. An organization can turn enforcement on, and an entity at or above 50 percent is then held for review. Either way, the owners and their attributed stakes are recorded with the result.

The Hidden Sanctions Exposure

Entities blocked under the 50 Percent Rule often do not appear on any public sanctions list under their own name, so ownership analysis is how you find them. A visitor from a seemingly legitimate company could represent an entity owned by blocked persons. Check the ownership of the companies you do business with before you rely on a clean name result.

06 · Adjudication

Adjudication Workflows That Scale

Screening produces matches. Adjudication determines what to do about them. A well-designed workflow clears noise by rule, holds genuine ambiguity for a person, and records both, so compliance officers spend their time on the cases that need judgment.

Automatic Disposition

Rules clear what they can and hold what they must. Low-risk results are approved automatically when an organization allows it, and candidates that a rule dismisses, such as a common name whose country or date of birth does not match, are recorded in the decision trace. Results in the review range are held for a reviewer. A result at 0.90 or above blocks check-in until a person decides. No rule issues a final denial.

Auto-Approve
Low risk, when allowed
Human Review
Review range
Auto-Block
Held for a person to decide

Human-in-the-Loop Review

Held records reach a reviewer with a decision trace: the screened name, each candidate's list source, program, and country, its similarity score, and why other candidates were dismissed. The reviewer approves, denies, escalates for senior review, or marks the result as not a match. Denials and escalations require a reason code, and the decision, the reviewer, and the reason are written to the audit log.

07 · Evidence

Building Defensible Screening Evidence

OFAC's enforcement actions have looked closely at how screening failed, citing outdated lists, name variations that screening tools missed, and matching logic that let close matches through. The existence, nature, and adequacy of your compliance program is one of the general factors OFAC weighs in an apparent violation. Defensible evidence means documenting every step.

What to Be Able to Show

  • Which sanctions lists were screened and when they were last updated
  • What matching methods were used and at what thresholds
  • The complete screening result, not just pass/fail but the match details
  • Who made the adjudication decision and what reasoning they documented
  • Whether AI recommendations were used and whether humans overrode them
  • An append-only, tamper-evident audit trail from screening through disposition
  • Evidence that screening occurs at multiple points (pre-registration and check-in)
  • Record retention meeting or exceeding the 10-year period in 31 CFR 501.601

Evidence Pack Generation

A defensible screening system produces evidence on demand: case files that include entity identity, screening parameters, match results with scores, adjudication decisions with reasoning, and the audit trail. Exports should come in formats both regulators and analysts can use, with a checksum for each file so a recipient can confirm nothing changed.

08 · SecurePoint USA

Screening Architecture Built for Compliance

Consolidated Sanctions Sources, Refreshed on Schedule

SecurePoint USA maintains a consolidated sanctions database covering OFAC SDN, OFAC SSI, BIS Entity List, BIS Denied Persons, DDTC Debarred, UK OFSI, EU FSF, UN Consolidated, FBI Most Wanted, INTERPOL Red Notices, SAM Exclusions, LEIE, and additional government sources; the DDTC, SAM, and LEIE lists are off until an organization turns them on. Each list refreshes on its own schedule: OFAC SDN and SSI, the BIS Denied Persons List, and the UK, EU, and UN lists daily, and the BIS Entity List and most other sources weekly. For several lists, including OFAC SDN and the UK list, the sync compares content hashes and writes only the records that changed.

Fuzzy and Alias Name Matching

Candidates are scored with Jaro-Winkler similarity across several name orders, each listed alias is looked up exactly, and common names must clear a stricter minimum. Candidates that screening rules dismiss are recorded in the decision trace, so a reviewer can see why a name did not match.

OFAC 50% Ownership Graph Analysis

For entities such as vendors and counterparties, SecurePoint USA traces ownership chains through several levels of ownership records drawn from GLEIF LEI relationship data and other open datasets, and adds up the stakes held by listed parties the way OFAC’s guidance counts indirect ownership. By default the result is recorded with the screening result without changing the decision; an organization can turn enforcement on, which holds any entity at or above 50 percent for review. Ownership analysis runs through the screening API and the compliance team's ownership lookup, not on individual visitors at check-in. Separately, BIS suspended its Affiliates Rule, which applies Entity List and Military End-User List restrictions to entities owned 50 percent or more by listed parties, from November 10, 2025 through November 9, 2026, as published in the Federal Register; confirm its status at bis.gov before relying on it. A match against the BIS Entity List or Military End-User List is held for manager review.

Adverse Media & PEP Screening

Adverse media runs as a monitoring source alongside sanctions screening. It draws on DOJ, SEC, FinCEN, and FCA enforcement material and news search, and its matches are recorded with the screening without blocking access or changing the decision. PEP screening is off until an organization turns it on.

Hash-Chained Audit Log & Evidence Exports

Screening completions and adjudication decisions are written to an append-only audit log in which each entry's SHA-256 hash includes the previous entry's hash, and a verifier checks the chain for breaks. Application users cannot edit or delete entries. Evidence and report exports cover screening activity, adjudication decisions, and the audit trail, with a SHA-256 checksum recorded for each export, for internal audits or assessor review.

Parallel Search Across Every Enabled List

Each screening searches every enabled list in one pass, with the list searches running in parallel. Bulk screening takes a CSV upload for high-volume pre-screening.

Sanctions Enforcement Actions

These U.S. enforcement actions range from deliberate, multi-year evasion schemes at global banks to screening and due-diligence gaps at a payment processor and a private school. Where several agencies settled together, the figure shown is the combined total.

BitPay

2021
$507,375
OFAC settlement

Screened its merchant customers against the SDN List but not the location data, including IP addresses, it held about those merchants' buyers. Buyers apparently in Crimea, Cuba, Iran, North Korea, Sudan, and Syria paid through its platform.

Société Générale

2018
$1.34 billion
Total across U.S. agencies

From 2004 to 2010, deliberately left Cuban references out of U.S. dollar payment messages for credit facilities it ran for Cuban banks and companies. The OFAC settlement also covered transactions involving Iran and Sudan.

UniCredit Group

2019
$1.3 billion
Total across U.S. agencies

Its German bank pleaded guilty to knowingly routing payments through the U.S. financial system for Iran's state shipping line, under a bank policy designed to hide sanctioned parties. OFAC's settlements also covered Burma, Cuba, Libya, Sudan, and Syria.

IMG Academy

2026
$1.72 million
OFAC settlement

A Florida sports boarding school signed tuition agreements with, and accepted tuition payments from, two parents on the SDN List designated under the Kingpin Act. OFAC said minimal due diligence would have revealed they were sanctioned.

Standard Chartered

2019
$1.1 billion
Total across U.S. and UK authorities

Employees at its Dubai branch willfully helped Iran-connected customers move U.S. dollar payments through U.S. banks. OFAC's settlement covered transactions involving Iran, Burma, Cuba, Sudan, and Syria.

ZTE Corporation

2017
$1.19 billion
Total across DOJ, Commerce, and OFAC

Ran a multi-year scheme to supply Iran with U.S.-origin equipment through third-party companies, and shipped controlled items to North Korea. It pleaded guilty to conspiring to violate U.S. sanctions law, obstruction of justice, and making a false statement.

Stop Screening Against
One List and Calling It Compliance

OFAC can impose civil penalties on a strict liability basis, so “we only checked the SDN list” is not a defense. OFAC does not prescribe lists, algorithms, or match thresholds, but it expects risk-based screening that is kept current, calibrated, and tested.

SecurePoint USA screens against configured sanctions sources with fuzzy and alias name matching, OFAC 50% ownership analysis for entities, human adjudication, and a hash-chained audit log.

Consolidated Sanctions SourcesFuzzy and Alias MatchingParallel List Search

Frequently asked questions

Does screening a party make our organization OFAC compliant?

No. Sanctions compliance is a program you run, and the legal obligation stays with your organization. Screening is one internal control inside that program. What a tool can do is give you a consistent screen, a documented decision on every possible match, and the records that evidence reasonable care.

What is the OFAC 50 percent rule?

OFAC treats an entity as blocked when blocked persons own it 50 percent or more in aggregate, even when that entity does not appear on a list by name. This is why name-only screening is incomplete and why ownership needs to be resolved rather than assumed. Verify current ownership positions against primary sources at the time of the decision.

What happens when a name partially matches a list?

A candidate at or above the review threshold holds the record and routes it to a review queue. An authorized reviewer sees the matched source, the program, and the match detail, then records a decision; denials and escalations require a reason code. Candidates that screening rules dismiss, such as a common name whose country or date of birth does not match, are recorded in the decision trace rather than dropped silently. The decision, the reviewer, and the reason are written to the audit log.

What records evidence reasonable care?

What was screened, which sources it was screened against, when, the result, who decided, and why. SecurePoint records those together against the visit or party so the decision can be reconstructed later without rebuilding it from separate systems.

How often should parties be re-screened?

Lists change continuously, so a screen is only current as of the moment it ran. Periodic or continuous re-screening is the point of the control. Set the interval against your own risk assessment, and confirm the retention period your applicable regimes require.

Which sanctions and restricted-party lists outside the United States are screened?

Non-US sources screen alongside the US ones in the same call, rather than one jurisdiction at a time: the UK HMT/OFSI consolidated list, the EU Financial Sanctions Facility, the UN Security Council consolidated list, France’s national asset freezing list (DGT), Singapore MAS enforcement actions, INTERPOL Red Notices, the OpenSanctions aggregated dataset, World Bank debarred firms and individuals, and Inter-American Development Bank sanctions.

Which lists screen by default, and which have to be turned on?

The US and non-US lists named above screen on every call. Several further sources are built and kept current but stay off unless an organization turns them on: the ITAR/DDTC debarred list, SAM exclusions, the HHS OIG exclusion list (LEIE), and politically exposed persons. Adverse media is different again: it runs in a monitoring capacity and does not gate access on its own. Confirm which sources your own tenant has enabled rather than assuming everything in the catalogue is active.

What does sanctions screening at scale actually require?

Four things beyond a match engine. Lists that refresh on a schedule rather than on request, because a screen is only current as of the moment it ran. A deterministic threshold with a review queue behind it, so a possible match is held for a person rather than silently passed. Ownership resolved rather than assumed, since an entity can be blocked without appearing on any list by name. And a record of what was screened, against what, when, by whom and why, written where it cannot be edited afterwards.

Informational only. This whitepaper is provided for general informational purposes only and does not constitute legal, regulatory, or compliance advice. It is not a substitute for review by qualified sanctions counsel familiar with your specific programs, jurisdictions, and risk profile.

Thresholds and screening defaults reflect SecurePoint USA configurations as of the “Last reviewed” date in the PDF version and can differ by organization. OFAC and partner-jurisdiction guidance changes; consult primary sources before acting on anything in this document. © 2026 SecurePoint USA. All rights reserved.

OFAC Sanctions Screening Best Practices | SecurePoint USA