How to audit an OFAC compliance program

An audit tests whether screening actually runs everywhere, catches matches, blocks flagged parties, and stays current.

TL;DR

TL;DR: Audit an OFAC compliance program by testing every payment path for screening coverage, using known listed parties to test detection, and confirming your data source is current and every decision is recorded.

Test coverage first

Map every path where value moves, then confirm a screening call sits in front of each one. Watch for rails that move money but do not screen, such as x402, AP2, ACP, and Coinbase AgentKit. A single unscreened path is an audit finding.

Test detection with known hits

Run test cases using parties known to be on the SDN List, the Specially Designated Nationals and Blocked Persons List. sanctionsai.dev (agentmail) screens a counterparty and returns clean (ALLOW) or flagged (BLOCK). If a listed party returns clean, the program has failed detection.

Check freshness and records

Verify the underlying data is current. sanctionsai.dev covers 947 OFAC-listed crypto wallets and 19,218 SDN names across 16 jurisdictions, synced hourly. Finally, confirm the 4-Gate sequence (SCREEN, SCORE, STOP, STAMP) produces a record for every decision, so the audit trail is complete.

Documenting the audit

An audit ends with findings, not just a pass or fail. Document what was tested, which parties were used, and what the results were. Then fix any gaps and re-test. A dated record of the audit itself is valuable evidence that the program is actively maintained rather than left to drift.

Screen your agent’s next payment

Free OFAC sanctions screening — 5 checks/day, no signup.

Check a wallet →