OFAC compliance for payment infrastructure providers

Payment infrastructure providers must screen every transaction that flows through their rails against the SDN List.

TL;DR

TL;DR: Providers of payment rails, including banking-as-a-service and payment APIs, must screen every transaction they carry and block any match, because they are the control point for the value that flows through.

The control point principle

Infrastructure providers sit where value moves, so regulators look to them to stop sanctioned flows. OFAC applies strict liability, meaning a provider can violate without intent when a prohibited transaction crosses its rails. The further up the stack you sit, the more transactions you touch and the more you must screen.

What to screen

Controls and evidence

Screen every transaction in the flow, not just a sample. A check that returns in under 100 ms keeps throughput high. Log each screen, and block on match. For providers serving AI agents, wire the screen into the agent's payment path so no automated transaction skips the check.

Coverage across the stack

Infrastructure providers often run many rails, and the risk is a rail that was added later and never wired into screening. Maintain a list of every payment channel and confirm each one calls the screen before authorizing. A check that runs on nine rails but not the tenth is a hole, and a single unscreened rail can carry a sanctioned payment.

Screen your agent’s next payment

Free OFAC sanctions screening — 5 checks/day, no signup.

Check a wallet →