By SanctionsAI team · Updated 2026-08-09

Sanctions compliance audit trail retention period

Your audit trail is your compliance evidence. OFAC and FinCEN require 5-year retention of all sanctions-related records.

What constitutes an audit trail

RecordContentsRetention
Screening logSubject, timestamp, result, SDN list version, API response5 years
Alert dispositionAlert details, reviewer, decision, rationale, timestamp5 years
Blocking/rejection recordsTransaction details, SDN match, report filed5 years
Training recordsAttendee, date, content, completion5 years
Risk assessmentsDocument, date, approval, next review5 years

For AI agents

AI agent screening decisions must be logged with: (1) transaction identifier, (2) counterparty screened, (3) screening result (clean/blocked), (4) SDN list version, (5) timestamp, (6) agent identifier, (7) action taken (proceed/block).

SanctionsAI logging: Every API call is logged with timestamp, subject, result, and list version. The audit trail is available via the dashboard and exportable for compliance reviews.

Screen your agent's next payment

Check any wallet, name, or entity against OFAC, EU, UN sanctions lists in real time.

Free wallet checker

Frequently Asked Questions

How long must I keep sanctions screening records?
5 years per OFAC and FinCEN requirements. This applies to screening logs, alert dispositions, blocking reports, and training records.
What must an AI agent screening log contain?
Transaction ID, counterparty, result, SDN list version, timestamp, agent ID, and action taken.
Can audit trails be digital?
Yes. Digital records are acceptable if they are complete, accurate, and readily retrievable. Most institutions use digital-only audit trails.
What happens if I cannot produce records during an OFAC exam?
Failure to maintain records is a sanctions violation. Civil penalties up to $356,571 per violation. Document any records that cannot be produced and explain why.

← Back to deadlines · SanctionsAI