OFAC compliance maturity model

Compliance matures in stages, from ad-hoc screening to a continuously monitored program that is tested and documented.

TL;DR

TL;DR: The model moves from no screening, to manual checks, to automated screening, and finally to a monitored and continuously improved program.

Stage one: ad hoc

At the earliest stage there is no consistent screening. A team might check a counterparty once in a while, but there is no policy and no automation. Any transaction that slips through is a strict liability exposure, since intent is not required for an OFAC violation.

Stage two: automated screening

The next stage adds an automated check before payment. A screening API that returns clean or flagged in under 100 ms, such as SanctionsAI, replaces guesswork with a hard gate. The 4-Gate Agent Payment Protocol structures this as SCREEN, SCORE, STOP, and STAMP.

Stage three: monitored and improved

The mature stage layers on monitoring, testing, and documentation. Coverage stays at 100 percent, flagged results are logged and reviewed, and new payment rails are assessed before launch. SanctionsAI supports this with tools like sanctions_check, risk_score, kya_verify, and dispute_open, synced hourly.

Screen your agent’s next payment

Free OFAC sanctions screening — 5 checks/day, no signup.

Check a wallet →