OFAC Screening Policy
A documented statement of an organization's screening approach: what gets screened, when, how, and by whom.
TL;DR
TL;DR: A screening policy writes down what is screened, when, how, and by whom. It turns an informal habit into a documented control.
What a Policy States
A screening policy answers four questions: which counterparties are screened, at what point in the flow, with which tools, and who is accountable for the result. It should also state what happens on a flag, including escalation and logging. A policy that exists only in someone's head is not a control.
Why Documentation Defends You
OFAC applies strict liability, and civil penalties start at $356,000 per violation. A written policy is evidence that screening is an intentional program rather than an accident. It also gives reviewers a standard to hold the process against.
Writing It for Agent Payments
For an AI agent, the policy should specify that every counterparty is screened before payment via sanctions_check, that risk_score and kya_verify are used on unclear cases, that the 4-Gate Agent Payment Protocol (SCREEN, SCORE, STOP, STAMP) governs the flow, and that every decision is logged. The policy should also note that x402, AP2, ACP, and Coinbase AgentKit move money but do not screen.
Practical Guidance
- State screen-before-pay as a non-negotiable rule.
- Name the compliance officer and the escalation path.
- Review and re-sign the policy when tools or rules change.