What is a sanctions screening audit?

A sanctions screening audit reviews how well your systems catch and handle SDN List matches before money moves.

TL;DR

TL;DR: A sanctions screening audit is a review of your screening program: whether every counterparty is checked against the SDN List, how matches are decided, and whether records show consistent, defensible decisions.

What an audit looks at

An auditor checks coverage (are all payment paths screened?), data quality (is the list current?), decision quality (are flagged parties actually blocked?), and recordkeeping. The goal is evidence that a clean party was allowed and a flagged party was blocked, every time.

Data freshness matters

sanctionsai.dev (agentmail) keeps live sanctions data: 947 OFAC-listed crypto wallets and 19,218 SDN names across 16 jurisdictions, synced hourly. A screening audit is only as strong as the list behind it, so stale data is a common audit finding.

Building an auditable trail

The 4-Gate Agent Payment Protocol gives agents a repeatable sequence: SCREEN, SCORE, STOP, STAMP. Each step produces a record, and the STAMP step captures the decision. Tools include sanctions_check for the match, risk_score for the severity, kya_verify for counterparty identity, and dispute_open to challenge a false positive.

Running the audit with live data

An auditor will also check whether the data being screened is current. sanctionsai.dev syncs hourly, so an audit can confirm the list in use matches the latest SDN data. Pair that with the 4-Gate STAMP record, and the audit becomes a matter of reviewing logs rather than reconstructing decisions from memory.

Screen your agent’s next payment

Free OFAC sanctions screening — 5 checks/day, no signup.

Check a wallet →