woman sitting at desk working on computer

Why OFAC-Check Your Vendors

A Primer for Accounts Payable and Finance Teams

In May 2022, a Houston freight forwarder called Fracht FWO needed to get a shipment of car parts from Mexico to Argentina fast, for a customer that couldn’t wait. Fracht turned to a logistics broker in Mexico, who arranged air transport through a cargo airline. Fracht paid the broker $885,000; the broker paid $825,000 of it on to the airline, plus a $110,000 late fee Fracht paid directly. The airline turned out to be wholly owned by Venezuela’s state carrier, flying a Boeing 747 that OFAC had separately blocked years earlier for its ties to Iran’s Mahan Air, crewed by Iranian nationals. Fracht settled with OFAC for $1,610,775.

That’s the kind of “OFAC” risk that accounts payable faces: paying the wrong vendor for an ordinary service — freight, in this case, but it could just as easily be an IT contractor, an office supplier, or a logistics provider. The Treasury Department’s Office of Foreign Assets Control (OFAC) administers most U.S. economic sanctions programs, maintaining lists of individuals, companies, vessels, and countries that Americans are barred from doing business with. The programs exist to keep money away from terrorists, narcotics traffickers, weapons proliferators, and hostile regimes. None of that sounds like a mid-sized company’s problem — until a routine payment to a vendor turns out to be a payment to someone on that list.

Ignorance Isn’t a Defense

The Romans handed down the principle “Ignorantia juris non excusat”—ignorance of the law does not excuse. For its part, OFAC does not have to prove intent to find a violation. You become liable the moment a prohibited transaction happens, whether or not you meant to violate the sanction.

Fracht’s case shows how far that standard reaches: OFAC found that two of the company’s own vice presidents bypassed Fracht’s internal compliance procedures under deadline pressure and moved ahead without the sanctions screening or legal review their own policy required. The airline’s Venezuelan address and tail number were red flags sitting in plain view. OFAC didn’t need to prove the company set out to help a sanctioned carrier. It only had to show the checks that should have caught it never happened, and that senior people knew enough to have caught it anyway. The combination of no strategic intent but no excuse either, is a common pattern in most vendor-side sanctions cases.

Who Must Comply, and Why Size Doesn’t Matter

OFAC’s authority covers “U.S. persons,” a category that includes any company organized under U.S. law, any U.S. citizen or resident, and anyone acting from U.S. soil. That’s it — there’s no carve-out for industry or company size. A regional manufacturer, a nonprofit, a construction firm, a school and a bank are all bound by the same core prohibition against dealing with a Specially Designated National (SDN), another blocked entity, or a country under comprehensive embargo.

What a Violation Costs

Civil penalties are calculated per transaction and adjusted annually for inflation. OFAC routinely aggregates violations when it settles, which is how single cases climb into six and seven figures. Fracht’s $1.6 million came from just two payments on a single shipment. OFAC treated the case as egregious partly because senior managers had actual knowledge of who they were paying, and partly because Fracht didn’t get credit for voluntary disclosure: U.S. authorities already knew about the transaction by the time Fracht reported it, since the aircraft had been detained in Argentina. 

Less than a year later, the consulting firm FTI Consulting settled for $1.05 million after indirectly dealing in prohibited debt of VTB Bank, a Russian bank on OFAC’s sectoral sanctions list — a reminder that this isn’t only a logistics-industry problem.

Cooperation and voluntary self-disclosure matter to the outcome. Fracht’s remedial steps after the fact — terminating the employees involved, requiring legal review on future contracts and increasing its compliance budget — helped bring the settlement down from the statutory maximum, even without full self-disclosure credit. That distinction, between fixing things because you got caught and finding them yourself, routinely moves settlement amounts by a large margin, which is the practical argument for catching problems before OFAC does.

Beneficial Ownership and the 50 Percent Rule

A vendor can pass a name check and still be off-limits because of who owns it. Under what’s commonly called OFAC’s 50 Percent Rule, an entity is treated as blocked if it’s owned 50 percent or more, directly or indirectly, by one or more blocked persons, even if the entity’s own name never appears on any list. OFAC’s guidance is explicit that this ownership is aggregated across multiple blocked owners: if one sanctioned person owns 25 percent of a company and a second sanctioned person owns another 25 percent, the company is blocked at the 50 percent threshold even though no single owner controls it. Screening the entity’s name alone doesn’t catch this. Reaching a defensible answer means understanding who is behind the businesses you pay, not just what they’re called.

Where the Exposure Accumulates

Sanctions risk in accounts payable rarely comes from an obviously suspicious new vendor showing up. Risk increases quietly, in a handful of predictable places:

  • Onboarding without screening — a vendor gets added to the master file to meet a deadline, and the sanctions check is skipped or treated as a formality.
  • Stale vendor files — a vendor that screened clean five years ago is never re-checked, even though OFAC adds and removes names from the SDN List on an ongoing basis. Most companies only think to run new vendors against the list; they don’t think to run new SDN additions back against the vendor file they already have. Both directions matter, because a vendor added last year can end up matching a name OFAC adds today.
  • Name-matching gaps — sanctioned parties share common names, use transliterated spellings, or operate through aliases. A simple exact-match search misses the variants that matter.
  • Affiliates and intermediaries — payments routed through a vendor’s affiliate, joint-venture partner or freight forwarder can carry exposure a direct vendor check never surfaces. This is exactly what tripped up Fracht: the company’s contract was with a broker, not the airline itself, and the broker relationship was where the screening gap occurred.
  • Fourth-party exposure — a vendor’s own suppliers or subcontractors, particularly in regions with sanctioned-country ties, can create indirect risk that doesn’t show up in your own vendor master. Are they doing OFAC checking? 

What a Defensible Screening Program Does

OFAC doesn’t prescribe a specific compliance program, but its settlements consistently reward companies that can show a genuine, risk-based effort when something slips through anyway. In practice that tends to mean the same handful of habits:

  • Screen every new vendor before the first payment goes out, including legal name, known aliases or DBAs and principal owners.
  • Re-screen in both directions, not just one. Checking new vendors against OFAC’s list is the easy half; the harder half is checking every new SDN addition against the vendor master you already have. OFAC updates its list on its own schedule and there’s no way to predict when. So, a monthly or quarterly batch check on your side still leaves a gap. Running both directions daily closes the risk gap.
  • Check beneficial ownership for higher-risk vendors: foreign vendors, vendors in high-risk jurisdictions, or anyone flagged by other red flags.
  • Use fuzzy matching logic that catches near-misses, not just exact hits. A straight text comparison misses transliterations, typos and phonetic variants, for example Osama versus Usama, Smith versus Smyth. Effective screening tools lean on techniques that flag names that sound alike even when they’re spelled differently, and scoring tools that measure how close two strings are letter by letter;  then route anything above a threshold to a person for review.
  • Keep a dated record of every check, including near-matches that were reviewed and cleared. An audit trail is the difference between a real program and a policy binder that no one follows.
  • Define, in advance, who reviews a potential match, who can hold a payment and who decides whether to file a report.
  • Train the people who touch vendor onboarding and payment approval. Software flags a near-match; a person still has to know what to do with it.

OFAC-Check Red Flags

Be particularly on guard for: 

  • A registered address that’s residential, a P.O. box or a shared office/registered-agent address with no other verifiable business presence.
  • Payment instructions that route to a different country or bank than the vendor’s stated place of business, with no clear explanation.
  • A vendor that resists providing ownership information or documentation that comparable vendors provide routinely.
  • A name that’s a close but imperfect match to an SDN List entry, for example: a transposed word, an added initial, an alternate transliteration.
  • Invoices referencing intermediary or connected parties that were never part of the original vendor agreement.

OFAC Compliance Bottom Line

It’s tempting to file sanctions compliance under “bank problem” or “export-control problem” and move on. Fracht is a reminder that the underlying law doesn’t care what a company does for a living; it reaches anyone who pays the wrong counterparty, even for something as routine as a freight bill. For accounts payable and finance teams, that means vendor screening isn’t a box checked once at onboarding. It is a control that must keep running alongside the rest of disbursement risk management. Running that control costs far less than a single violation does.

To learn how VendorInfo’s automated OFAC checking can help you comply, contact us.

Share This Post