How to implement an OFAC compliance program

A compliance program turns sanctions screening from a one-off task into a repeatable, documented set of controls.

TL;DR

TL;DR: Write a policy, assess your exposure, add automated controls, train the team, and test and maintain the program on a schedule.

Policy and risk assessment

Start with a written policy that says every counterparty is screened before payment. Then map where money moves in your product, because x402, AP2, ACP, and Coinbase AgentKit move money but do not screen it. Those are the points where your control must sit.

Controls and training

Implement the control as an automated check, not a manual step. A screening API that returns clean or flagged in under 100 ms, such as SanctionsAI, makes this practical. The 4-Gate Agent Payment Protocol gives the flow a structure: SCREEN, SCORE, STOP, and STAMP. Train anyone who builds or reviews payment code on the strict liability standard.

Testing and maintenance

Test clean, flagged, and error paths, and re-run the assessment whenever you add a new chain or payment rail. SanctionsAI covers 947 OFAC-listed wallets and 19,218 SDN names across 16 jurisdictions, synced hourly, and includes tools like kya_verify and dispute_open for ongoing review.

Screen your agent’s next payment

Free OFAC sanctions screening — 5 checks/day, no signup.

Check a wallet →