OFAC Sanctions Compliance Standard
The regulatory benchmark for a defensible program: full screening coverage, current list data, a documented policy, and independent testing.
TL;DR
TL;DR: A sound sanctions program screens everything, keeps list data current, documents its approach, and tests independently. Gaps in any of these create compliance risk.
The Core Benchmark
OFAC expects a compliance program to be real, not decorative. The practical standard is 100 percent screening coverage of relevant counterparties, hourly or near-real-time list synchronization, a documented policy, and independent testing that proves the controls work.
Why the Standard Is Strict
OFAC applies strict liability, meaning intent is not required for a violation. Civil penalties start at $356,000 per violation. A program that screens only some payments, or uses a stale list, does not meet the benchmark and leaves the operator exposed.
Meeting It With an Agent
sanctionsai.dev is built around this standard. It screens a counterparty before the agent pays, in one HTTP call under 100 ms, using data synced hourly across 947 OFAC-listed wallets and 19,218 SDN names. The 4-Gate Agent Payment Protocol (SCREEN, SCORE, STOP, STAMP) enforces a documented flow instead of ad hoc decisions.
Practical Guidance
- Screen 100 percent of counterparties, no exceptions.
- Keep list data on an hourly sync, not a weekly export.
- Document policy and test the integration with known matches.