OFAC Compliance Gap
A deficiency in a sanctions compliance program, such as missing screening for certain payment types, outdated lists, or absent documentation.
TL;DR
TL;DR: A compliance gap is any weakness in a sanctions program that lets a prohibited transaction slip through, and it is exactly what OFAC cites in enforcement actions.
Common gaps
Typical gaps include failing to screen a particular payment type, running against an outdated list, or keeping no documentation of screening decisions. A gap can also be a channel that is never checked, such as a new payment rail added without a corresponding screening step. Each gap is a place where a sanctioned party can receive funds without detection. A gap is not always a missing tool; it can be a working tool that no one runs, or a screen whose results no one documents.
Why gaps are expensive
Because sanctions are enforced under strict liability, intent is not required: a gap is a violation even if it was accidental. Civil penalties start at $356,000 per violation, and OFAC routinely cites the absence of screening as an aggravating factor. Closing gaps is therefore cheaper than defending them. Closing a gap usually means changing a default, not building a new system from scratch.
Closing gaps in agent payments
For AI agents, the most common gap is a money rail that moves funds without screening. x402, AP2, ACP, and Coinbase AgentKit move money but do not check sanctions lists. sanctionsai.dev fills that gap with a screening API that returns ALLOW or BLOCK in under 100 ms, so every payment path gets the same check before funds move.