Whether you’re new to OFAC compliance or looking to strengthen your vendor screening process, you’ve got questions. We’ve got answers. Below is a comprehensive resource covering everything from the basics of OFAC search to automated screening best practices for accounts payable teams.
Everything You Need to Know About OFAC Screening for Vendors
OFAC compliance is a legal requirement for virtually every U.S. business that processes payments, onboards suppliers, or transacts with international partners. But navigating the rules, the lists, and the right screening approach can feel overwhelming. These FAQs are designed to cut through the complexity and give you the clarity your organization needs to screen vendors with confidence.
What is OFAC?
OFAC stands for the Office of Foreign Assets Control, a division of the U.S. Department of the Treasury. OFAC administers and enforces economic and trade sanctions based on U.S. foreign policy and national security goals. It maintains a series of sanctions lists — most notably the Specially Designated Nationals (SDN) list — that prohibit U.S. persons and businesses from transacting with certain individuals, entities, and countries.
What is OFAC screening?
OFAC screening (also called OFAC search, OFAC checking, or sanctions screening) is the process of checking individuals, businesses, or entities against government-maintained sanctions lists before conducting a transaction or business relationship. For vendor management, this means screening suppliers and vendors against the SDN list and other relevant watchlists before onboarding them or processing payments to them.
Why is OFAC screening important for accounts payable teams?
AP departments are often the last line of defense before money leaves your organization. If a payment is made to a sanctioned vendor — even unintentionally — your organization can face severe civil and criminal penalties. OFAC does not accept “we didn’t know” as a valid defense. That makes proactive, documented vendor screening a non-negotiable part of any responsible AP operation.
Is OFAC compliance mandatory?
Yes. OFAC compliance is mandatory for all U.S. persons and businesses, regardless of company size or industry. This includes domestic transactions that involve foreign parties, as well as international transactions processed through U.S. banks or conducted in U.S. dollars. There is no minimum revenue threshold or transaction size that exempts an organization from OFAC obligations.
What is the OFAC SDN list?
The Specially Designated Nationals (SDN) list is OFAC’s primary sanctions list. It includes individuals, organizations, and entities whose assets are blocked and with whom U.S. persons are generally prohibited from doing business. The list includes terrorists, narcotics traffickers, weapons proliferators, foreign government officials under sanctions, and entities connected to sanctioned countries. The SDN list is updated frequently — sometimes daily — as geopolitical conditions change.
Are there other OFAC sanctions lists besides the SDN list?
Yes. In addition to the SDN list, OFAC maintains several other targeted lists, including the Foreign Sanctions Evaders (FSE) list, the Sectoral Sanctions Identifications (SSI) list, the Non-SDN Menu-Based Sanctions (NS-MBS) list, the Foreign Narcotics Kingpin Sanctions list, and various country and program-specific sanctions lists. A comprehensive vendor screening program should check against all relevant lists, not just the SDN.
Does OFAC screening apply to international sanctions lists too?
Yes. Beyond OFAC, organizations doing business internationally may also be subject to sanctions maintained by the United Nations (UN), the European Union (EU), the UK’s Office of Financial Sanctions Implementation (OFSI), the Office of the Superintendent of Financial Institutions (OSFI) in Canada, and other bodies. A robust screening program covers international watchlists in addition to OFAC’s domestic lists.
Who needs to be screened as part of vendor compliance?
Any party involved in a business transaction should be screened. For vendor programs, this typically includes the vendor’s legal business entity, their key principals and beneficial owners, subsidiary entities, any aliases or doing-business-as (DBA) names, and the countries associated with the vendor. Screening only the company name is not sufficient — screening must extend to the individuals and ownership structures behind the company.
When should OFAC screening take place during vendor onboarding?
Screening should occur at the point of vendor registration, before a vendor is approved and added to your vendor master file. This prevents a sanctioned entity from ever becoming an active vendor. Additionally, screening should be repeated when a vendor updates their banking information, when their business details change, and on a continuous or periodic basis after onboarding, since sanctions lists are updated frequently and a clean vendor today can become sanctioned tomorrow.
What is continuous OFAC screening, and do I need it?
Continuous (or ongoing) screening means your vendors are automatically re-screened against updated sanctions lists on a regular basis — daily, weekly, or in real time — rather than only at the point of onboarding. This matters because OFAC updates its lists without advance notice. An organization that only screens vendors at onboarding is exposed every day that passes without a re-check. Continuous screening is considered a best practice and is increasingly expected by regulators as part of a robust compliance program.
What are the penalties for violating OFAC regulations?
Penalties for OFAC violations can be severe. Civil penalties can reach the greater of $356,579 per violation or twice the value of the transaction involved. Willful or egregious violations can result in criminal prosecution, with fines up to $1 million and prison sentences of up to 20 years for individuals. Penalties apply even for unintentional violations — and ignorance of a party’s sanctioned status is not a legal defense. OFAC enforcement actions have resulted in settlements ranging from tens of thousands of dollars to over $1 billion for major financial institutions.
What is a “false positive” in OFAC screening, and how should it be handled?
A false positive occurs when a screening system flags a vendor as a potential sanctions match, but further investigation reveals the vendor is not actually the sanctioned party. Common causes include similar names, shared addresses, or common names shared between a legitimate vendor and a designated individual. When a false positive is identified, it must be documented thoroughly, including the steps taken to verify the vendor’s identity and confirm they are not the sanctioned entity. This documentation is critical for audit trails and potential regulatory inquiries.
What is fuzzy matching in OFAC screening?
Fuzzy matching is a technique used by OFAC screening software to identify potential matches even when names are spelled differently, transliterated from another language, or listed under aliases. Because sanctioned parties often use alternate spellings, nicknames, or shell companies to evade detection, a screening solution that only checks for exact matches will miss many high-risk vendors. Robust OFAC screening tools use fuzzy matching algorithms tuned to catch these variations without generating an unmanageable volume of false positives.
My company doesn’t export goods. Do I still need to screen vendors?
Yes. OFAC compliance applies to any transaction that involves the transfer of money, goods, services, or technology — including purely domestic businesses. Many large transactions are processed through U.S. banks in U.S. dollars, which means even a domestic payment can trigger OFAC jurisdiction if the recipient is a sanctioned party. Service businesses, professional firms, staffing agencies, and technology companies are all subject to OFAC screening requirements.
How often is the OFAC SDN list updated?
The SDN list and other OFAC sanctions lists are updated regularly — sometimes multiple times per week, and occasionally multiple times in a single day in response to breaking geopolitical events. This is why relying on manual screening or infrequent batch checks is risky. Automated screening tools that pull the latest list data in real time ensure your vendor screening process never operates on outdated information.
What is the difference between OFAC screening and a background check?
An OFAC screen checks a party against government sanctions lists to determine whether they are legally prohibited from doing business with U.S. organizations. A background check is a broader due diligence tool that may include criminal records, credit history, employment verification, and other personal or business information. OFAC screening is a specific legal compliance requirement; background checks are a separate due diligence consideration. Both may be used as part of a vendor onboarding process, but they serve different purposes.
How does OFAC screening integrate with other compliance programs?
OFAC screening should not exist in isolation. Best-practice compliance programs integrate sanctions screening with Know Your Customer (KYC) processes, Anti-Money Laundering (AML) controls, Anti-Bribery and Corruption (ABC) programs, and IRS TIN matching requirements. When vendor data is centralized in a single system — with automated verifications running across all of these dimensions simultaneously — compliance becomes more consistent, more defensible, and far less burdensome on staff.
What documentation should we maintain for OFAC compliance?
A defensible OFAC compliance program requires thorough recordkeeping. At minimum, organizations should document when each vendor was screened, which lists were checked, the results of each screening, how any potential matches were investigated and resolved, and the name of the individual or system that conducted the screening. This audit trail is essential if your organization is ever subject to a regulatory inquiry or enforcement action. Automated screening platforms generate this documentation automatically, which is a major advantage over manual processes.
What should we do if we discover a vendor is on the OFAC SDN list?
If screening reveals a confirmed match, you are required to block or reject the transaction and, in most cases, report the finding to OFAC within 10 business days. You should cease all business activities with the entity immediately, freeze any assets that are in your possession or control, and consult legal counsel to ensure you fulfill your reporting obligations correctly. Do not simply delete the vendor from your system — proper documentation of the discovery and your response is required.
How is VendorInfo different from manual OFAC screening?
Manual OFAC screening — using spreadsheets, the OFAC.gov search tool, or email-based processes — is slow, inconsistent, and difficult to audit. VendorInfo automates OFAC and sanctions screening directly within the vendor onboarding workflow, screening vendors against hundreds of government and industry watchlists in real time as supplier information is submitted. Matches are flagged instantly with documentation, ongoing rescreening runs automatically, and every check is logged for audit-ready reporting — eliminating the manual workload and closing the compliance gaps that manual processes leave behind.
Can VendorInfo screen vendors against lists beyond OFAC?
Yes. VendorInfo screens vendors against hundreds of global government and industry watchlists, including international sanctions lists maintained by the UN, EU, UK, and other bodies, in addition to OFAC’s full suite of lists. This is essential for organizations with international supplier relationships, where domestic OFAC compliance alone is not sufficient to meet full regulatory requirements.
Disclaimer: This page is intended to provide a general overview of OFAC screening concepts and is not legal advice. Consult qualified legal counsel for guidance specific to your organization’s compliance obligations.

