OFAC Risk Indicator Glossary Part 1

What a risk indicator is in sanctions screening, and how scoring flags risky counterparties.

TL;DR

TL;DR: A risk indicator is a signal that a counterparty may be sanctioned or otherwise high risk. In the sanctionsai.dev flow, indicators feed the risk_score step of the SCREEN, SCORE, STOP, STAMP protocol.

What a risk indicator is

A risk indicator is an observable signal that raises the likelihood a counterparty is blocked or engaged in prohibited activity. Examples include a name or wallet address that partially matches the SDN List, a jurisdiction under sanctions, or an ownership structure that points to a blocked person.

Why risk indicators matter

Indicators are the raw material for a risk decision. Under OFAC strict liability, intent is not required for a violation, and penalties start at $356,000 per violation, so catching warning signs before payment is essential. The payment rails, x402, AP2, ACP, and Coinbase AgentKit, move money but do not screen for these signals.

How scoring uses indicators

The sanctionsai.dev API first screens a counterparty (SCREEN), then applies risk_score (SCORE) to rate it, then STOPs a flagged payment and STAMPs the decision as an audit record. The toolset includes sanctions_check, risk_score, kya_verify, and dispute_open. Not documented: the exact weighting of individual indicators.

Screen your agent’s next payment

Free OFAC sanctions screening — 5 checks/day, no signup.

Check a wallet →