OFAC Compliance Testing

Verifying that screening controls actually work, by testing against known sanctioned wallets, reviewing logs, and probing for bypasses.

TL;DR

TL;DR: Compliance testing confirms the screening control works in practice, not just on paper. It means running known sanctioned wallets through the check and reviewing logs for decisions the control should have made.

How testing is done

Testing feeds known sanctioned wallets and names into the screening step and confirms the result is BLOCK. It also reviews logs to confirm checks ran when expected and probes for bypasses, such as a payment route that skips the check. The point is to catch silent failures: a control that exists in code but does not fire is worse than no control, because it creates false confidence.

Why it matters for agent payments

An agent's screening call can break without anyone noticing, especially if the agent keeps paying normally. Regular testing against known listed wallets and names proves the control still works. Tools such as risk_score and the SCREEN, SCORE, STOP, STAMP flow give the operator concrete outputs to verify, so testing is about confirming real results rather than trusting the wiring.

Testing checklist

Making testing continuous

Testing should be continuous, not annual. A control can break the day after an audit, and an agent will keep paying through the gap. Automated tests that run known sanctioned wallets on a schedule, and alert when the result is not BLOCK, turn testing from an event into a standing check. Pair that with log reviews and the operator has early warning that the control has degraded, before OFAC or a missed block reveals it.

Screen your agent’s next payment

Free OFAC sanctions screening — 5 checks/day, no signup.

Check a wallet →