Two features of U.S. sanctions law make it different from almost everything else in financial regulation. First, the prohibitions administered by the Office of Foreign Assets Control apply to all U.S. persons — every U.S. citizen and permanent resident wherever located, everyone physically in the United States, and every entity organized under U.S. law including foreign branches. There is no asset threshold, no bank charter requirement, and no small-company exemption.
Second, civil liability is strict. A company can violate a sanctions prohibition without knowing the counterparty was designated, without intent, and without any benefit from the transaction. Knowledge and intent matter enormously to penalties and to whether a matter becomes criminal, but they are not elements of the civil violation. That combination is why sanctions screening has to live in the transaction flow rather than in a periodic review.
Who is actually bound
The reach of the prohibitions is broader than most product teams assume. A U.S.-incorporated fintech is a U.S. person. So are its U.S.-citizen employees working abroad for a foreign subsidiary. Certain programs extend further, reaching foreign subsidiaries owned or controlled by U.S. persons, and secondary sanctions can create serious consequences for non-U.S. companies that deal with designated parties even without direct U.S. jurisdiction.
Facilitation is the trap that catches otherwise careful organizations. A U.S. person generally may not approve, finance, guarantee, refer, or otherwise facilitate a transaction by a foreign person that the U.S. person could not perform directly. Referring a sanctioned-country customer to a non-U.S. affiliate to complete a payment is not a workaround; it is the classic facilitation fact pattern.
Watch out: "our banking partner screens for us" is not an allocation of legal liability. Sanctions obligations attach to each U.S. person independently. A program agreement can decide who performs screening and who indemnifies whom, but it cannot transfer the prohibition itself — the same distinction between operational responsibility and legal duty explored in our guide to compliance risk allocation in embedded finance.
Blocking, rejecting, and the difference that matters
When a screening hit is confirmed, the required action depends on the program.
Blocking applies where there is an interest in property of a blocked person. The U.S. person must freeze the property, place funds in a separate interest-bearing blocked account at a U.S. financial institution, and not release, transfer, or otherwise deal in it without authorization. Blocked funds do not go back to the sender. They sit until OFAC licenses their release.
Rejecting applies where a transaction is prohibited but there is no blockable property interest — for example, certain transactions involving a comprehensively sanctioned jurisdiction where the program calls for rejection rather than blocking. The transaction is refused and, where applicable, funds are returned.
Both outcomes carry reporting duties, and the choice between them is not discretionary. Returning funds that should have been blocked is itself a prohibited dealing in blocked property.
- Hit generated. Screening flags a name, address, jurisdiction, vessel, digital-asset address, or other identifier against current OFAC data.
- Alert reviewed. A trained reviewer clears the false positive or escalates. Documentation of the clearing rationale matters as much as the decision.
- True match confirmed. Determine the applicable program and whether blocking or rejecting is required. OFAC's compliance hotline exists for genuinely unclear cases.
- Action taken. Funds blocked into an interest-bearing blocked account, or the transaction rejected. Customer communication should be careful and factual.
- Reported. Blocked property and rejected transactions are reported to OFAC within 10 business days, and blocked property is also reported annually.
- Reviewed for disclosure. If the event reveals a past violation, evaluate voluntary self-disclosure, which is a significant mitigating factor under OFAC's enforcement guidelines.
The reporting duties people forget
- Blocked property reports — filed with OFAC within 10 business days of blocking property, identifying the property, the parties, and the legal basis.
- Rejected transaction reports — also generally due within 10 business days, covering transactions refused because of a sanctions prohibition rather than blocked.
- Annual report of blocked property — a comprehensive year-end filing covering property held as of a specified date, submitted on OFAC's schedule.
- Recordkeeping — records of blocked and rejected transactions must be retained for at least five years, and records relating to blocked property for at least five years after the property is unblocked.
- License reporting — general and specific licenses often carry their own reporting conditions, which are easy to miss because they sit in the license text rather than the regulation.
Reporting failures are independently sanctionable. Institutions frequently discover during an examination that they blocked correctly and never filed, which converts a compliance success into a violation.
Designing a program OFAC will recognize
OFAC's published compliance framework describes five essential components. Regulators across the banking agencies use the same vocabulary, and the FDIC, OCC, and Federal Reserve examine supervised institutions against equivalent expectations.
| Component | What it requires | Common failure |
|---|---|---|
| Management commitment | Senior support, adequate resources, and independent authority for compliance | Compliance can flag a payment but cannot stop a product launch |
| Risk assessment | Documented assessment of customers, products, geographies, and channels | Assessment written once and never updated after new markets or features launched |
| Internal controls | Screening, escalation, blocking, reporting, and recordkeeping procedures that match actual operations | Fuzzy-match thresholds tuned to reduce alert volume rather than to catch matches |
| Testing and auditing | Independent testing of the screening engine, list currency, and alert handling | No one has verified that list updates actually reach production |
| Training | Role-specific training for compliance, operations, engineering, and sales | Annual slideshow with no scenario work for the teams that see the hits |
Two technical points separate programs that work from programs that look good on paper. First, list currency: OFAC data changes without warning, and the operational question is how quickly a new designation reaches your live screening environment. Second, data quality: screening only works against the fields you actually capture, so a payment message that carries no counterparty address, or a customer record with an unparsed name field, will not generate the hit even with a perfect engine.
Practical step: screen on more than names. Addresses, dates of birth, jurisdictions, IP and geolocation signals, vessel and aircraft identifiers, and — for digital-asset businesses — the wallet addresses OFAC has published as identifiers all belong in the screening logic. Digital-asset-specific considerations are covered further in our stablecoin and digital-asset compliance checklist.
Penalties, mitigation, and voluntary self-disclosure
Civil penalties are set by the underlying statutes, most often the International Emergency Economic Powers Act, and the maximum amounts are adjusted for inflation each year — check the current figures at Treasury rather than relying on a number quoted in an older article. Willful violations can be prosecuted criminally.
OFAC's enforcement guidelines set out how it evaluates cases: whether the conduct was egregious, whether there was a voluntary self-disclosure, the harm to sanctions program objectives, the sophistication and awareness of the party, the existence and quality of the compliance program, and remedial response. Voluntary self-disclosure — a genuine disclosure before OFAC learns of the matter from another source — substantially reduces the base penalty. That mathematics is why discovering a violation should trigger a legal analysis immediately rather than an internal cleanup that delays disclosure.
Beyond OFAC, an institution's supervisor may treat a sanctions failure as a safety-and-soundness or governance problem, and correspondent banks routinely terminate relationships over screening deficiencies. Loss of banking access is often the more damaging consequence.
Where fintech platforms get caught
Recurring patterns in enforcement actions involving technology-driven financial firms are consistent enough to be a checklist. Products that launched internationally before compliance built country controls. Geolocation blocking that users defeated with commercial VPNs while the company had data showing it. Screening applied at onboarding but never re-run as designations changed. Acquired user bases migrated without re-screening. Third-party integrations that introduced counterparties the platform never screened.
The vendor dimension is significant: screening engines, list providers, KYC vendors, and payment processors all sit in the control path, and diligence over them is part of the program. Contractual audit rights, data-quality commitments, and change-notification duties should be negotiated up front, as described in our guide to third-party risk management. Where funds movement itself is the product, the sanctions analysis should be run alongside the licensing analysis in our guide to following the flow of funds.
Quick answers
Does OFAC only apply to banks?
No. The prohibitions apply to all U.S. persons — individuals, companies of any size, nonprofits, and their U.S.-citizen employees anywhere in the world. Banks receive the most examination attention because supervisors review their programs, but a small technology company processing payments has the same underlying legal duty and the same strict-liability exposure.
What is the 50 percent rule?
OFAC treats an entity as blocked if blocked persons own, directly or indirectly, 50 percent or more of it in the aggregate — even though that entity is not itself named on any list. This means list screening alone is insufficient for entity customers. Ownership information has to be collected and analyzed, and aggregation across multiple blocked owners counts.
If we block a customer's funds, what do we tell them?
You can tell a customer that a transaction was blocked or rejected pursuant to U.S. sanctions requirements, and the funds are not returned in a blocking case. Be factual and avoid speculation about the customer's status. The customer may apply to OFAC for a specific license to release blocked funds; that application is theirs to make, and you should not advise on the merits of their designation.
How current do sanctions lists have to be?
Effectively current. Designations take effect when issued, and there is no grace period built into the prohibitions. The operational standard most programs target is same-day propagation of list updates into production screening, with documented verification that updates were applied. Testing that the pipeline works is as important as subscribing to the data.
Is there any de minimis exception for small transactions?
No general one. Some programs contain exemptions and general licenses covering specific categories such as certain personal remittances, informational materials, or humanitarian activity, but these are program-specific and conditional. Assuming a small dollar amount is safe is one of the more common and expensive mistakes in this area.
Your next moves
Start with the risk assessment, because everything else derives from it: which customers, which corridors, which products, which channels. Then verify that your screening actually runs where the money moves, on current data, against the fields you collect — and test that pipeline independently rather than trusting the vendor dashboard.
Write the blocking-versus-rejecting decision procedure before you need it, calendar the 10-business-day and annual reports, and make sure someone owns the voluntary-self-disclosure analysis when a problem surfaces. Confirm program details and current requirements directly at ofac.treasury.gov, since the programs change more often than most compliance calendars anticipate. Related guides sit in the banking, payments, and fintech pathway.