OFAC · Sanctions · Compliance · AML · Sanctions screening
OFAC Sanctions: An Overview of the Most Prominent Sanctions Regime
What OFAC is, who must comply, the penalties and what it means for screening.
AML Compliance Officer at dilisense

TL;DR
OFAC sanctions are the US economic and trade sanctions administered and enforced by the Office of Foreign Assets Control (OFAC), part of the US Treasury. OFAC runs more than 30 sanctions programs across several lists, of which the SDN List is only the best known. All US persons must comply. Non-US persons can also come within their scope. Penalties are severe. Civil liability can apply even without intent to violate the sanctions. For most companies the practical obligation comes down to screening customers and counterparties against OFAC's lists and keeping that screening current.
Introduction
For the basics of what sanctions are and how they work, see What are Sanctions?. This article focuses on the US regime specifically.
What is OFAC?
The Office of Foreign Assets Control sits inside the US Department of the Treasury. It administers and enforces US economic and trade sanctions against targeted governments, individuals, groups and entities, in line with US national-security and foreign-policy goals.
OFAC is not new. It traces back to the Office of Foreign Funds Control, set up in 1940. OFAC itself was formally created in December 1950 after China entered the Korean War, when the US blocked Chinese and North Korean assets under US jurisdiction. Today it runs more than thirty active sanctions programs, each targeting a country, a government or a type of conduct such as terrorism or narcotics trafficking.
OFAC publishes its designations across several lists, of which the SDN List is the best known. Screening well means covering all of them, not only the most familiar one. The lists, what each one covers and how to screen them are set out in The OFAC Sanctions Lists.
Comprehensive versus targeted programs
OFAC administers different kinds of sanctions programs. Some are comprehensive and broadly prohibit most transactions with a whole jurisdiction. Others are targeted, hitting specific persons tied to a jurisdiction or an activity while leaving normal trade untouched.
OFAC does not publish one master list of “banned countries”, because the scope of each program differs. The jurisdiction-based programs cover Cuba, Iran and North Korea, along with the Crimea, Donetsk and Luhansk regions of Ukraine. Most other programs are targeted and list-based. The current roster, each with its own update date, lives on OFAC’s sanctions-programs page.
Who must comply
All US persons must comply with OFAC sanctions. That means US citizens and permanent residents wherever they are, anyone and any entity within the United States, plus every US-incorporated entity including its foreign branches. The rules can also reach transactions involving US-origin goods, services or technology. Some programs, such as Iran and North Korea, reach foreign subsidiaries owned or controlled by US persons.
A less obvious nexus can arise for foreign firms. Routing a US-dollar payment through a US bank can create that link. OFAC identifies exactly this pattern, non-US persons processing payments through US financial institutions, almost all of them denominated in US dollars, as a recurring root cause of violations. Non-US persons are also prohibited from causing or conspiring to cause US persons to breach sanctions and from evading them.
Why OFAC exposure is bigger than it looks
Two things about OFAC catch firms out. Both mean that matching a name against the SDN List, on its own, leaves real risk on the table.
Ownership may be indirect. A company does not have to be named to be blocked. Under OFAC's 50 Percent Rule, any entity owned 50 percent or more, directly or indirectly, individually or in aggregate, by one or more blocked persons is itself blocked, even if it never appears on the SDN List. That ownership can sit behind layers of intermediate companies and subsidiaries. Screening a name alone will not surface it, which is why ownership-structure checks matter.
Civil liability does not require intent. OFAC's civil penalties carry no knowledge requirement. The International Emergency Economic Powers Act (IEEPA), the main authority OFAC uses for most sanctions programs, imposes civil liability on any person who commits a violation, even without knowledge that the conduct was prohibited. Individuals and companies can face a civil penalty for a violation they did not know they were committing.
Criminal liability requires willfulness. Under IEEPA, only criminal liability requires a willful violation. Knowledge or recklessness can be an aggravating factor. A strong compliance program and a voluntary disclosure are mitigating ones.
Secondary sanctions, briefly
OFAC can also target non-US persons who have no other US connection, for their dealings with sanctioned parties or other sanctionable activities. The consequence ranges from a menu-based measure to a limit on US correspondent banking. At the extreme it can be an SDN designation. This is a large topic in its own right.
Penalties
The numbers are serious. Willful criminal violations of IEEPA carry fines up to $1,000,000. For individuals they also carry up to 20 years in prison. Civil penalties are set by statute at the greater of a fixed amount or twice the value of the transaction underlying the violation. The fixed amount is adjusted for inflation each year. For IEEPA it stood at $377,700 per violation in 2026. Recent enforcement shows the real-world scale. In May 2026 OFAC reached a $275 million settlement with Adani Enterprises over Iran-related sanctions violations.
What OFAC compliance means for screening
OFAC's own compliance guidance, A Framework for OFAC Compliance Commitments, asks firms to run a risk-based sanctions compliance program built on five parts. They are management commitment, risk assessment, internal controls, a testing-and-auditing function and training. An effective program at the time of a violation is treated as a favorable factor.
The same guidance names screening failures directly. Its list of root causes includes screening software that was not updated with the latest list changes, filters that miss identifiers or alternative spellings, plus weak due diligence on ownership. OFAC also stresses that lists change constantly and that keeping them current is part of your due-diligence duty.
That is the core of the obligation for most businesses. You need to screen the people and entities you deal with against OFAC's lists, resolve the ownership question behind them and re-screen as designations change. For how screening works in practice, see What is Sanctions Screening?. With dilisense you can search OFAC's SDN and consolidated lists, alongside EU, UN, UK and other sources, through a single API. The data updates hourly and every match is traceable to its origin.
Screen against OFAC's sanctions lists
dilisense gives you the OFAC SDN and consolidated lists alongside EU, UN, UK and other sources through one API, updated continuously, with every match traceable to its source.
Try the free searchFrequently asked questions
About the author

Rosario Andrea Mirante
AML Compliance Officer at dilisense
Rosario Andrea Mirante is a legal expert at dilisense, covering sanctions, AML and KYC with a focus on key legal and regulatory developments.
- Sanctions screening
- Anti-money laundering (AML)
- Know your customer (KYC)
- Politically exposed persons (PEP)
- Regulatory compliance
Related articles

3 min read
The OFAC Sanctions Lists: SDN, Consolidated and How to Screen Them
How OFAC's sanctions lists fit together, what each one covers and how to check a name against them.

7 min read
What is Sanctions Screening?
Get an overiew of one of the most crucial compliance processes.

7 min read
What are AML Checks?
Key components, benefits, and pitfalls of AML checks in the increasingly complex regulatory landscape.
