Skip to content
OfacScanner

AML programs

AML Sanctions Screening That Fits Your KYC Onboarding

AML sanctions screening is the part of an anti money laundering program that checks customers and counterparties against government sanctions lists. It runs during KYC onboarding and again over the life of the relationship. OfacScanner covers this sanctions control, while the rest of your AML program stays in your hands.

OFAC SDN list, published , checked

Onboarding check, new business customer

Review
Name similarity 82/100

Close spelling to a listed alias

Country 20/100

Customer country differs from the entry

Entity type 100/100

Organization against organization

Identifiers 0/100

No shared registration number

Example scores for illustration. The reviewer decides.

Compliance officer comparing a customer file with screening results at her desk

What is AML sanctions screening

An anti money laundering program, or AML program, is the set of policies and controls a business uses to stop its services from being used for financial crime. In the United States the Bank Secrecy Act sets the base rules for banks, money services businesses and other covered firms. Around the world the Financial Action Task Force, known as FATF, publishes the standards that national AML laws follow.

Sanctions compliance sits next to AML and shares most of its data. Both start with knowing who the customer is. AML then looks at how money moves and whether activity is suspicious. Sanctions screening asks a narrower question with a hard legal answer. Is this person, company, vessel or wallet on a list that forbids doing business with it.

That is why most teams run sanctions screening inside their AML and KYC workflow, even though the legal basis is different. In the U.S. sanctions rules come from OFAC and apply to all U.S. persons, not only to firms covered by the Bank Secrecy Act. A clean AML review does not replace a sanctions check, and a sanctions check does not replace AML monitoring.

Where sanctions screening fits in an AML program

A typical AML program has several controls. This is what OfacScanner covers and what you run elsewhere.

AML control Purpose Covered by OfacScanner
Customer identification and KYC Collect and verify identity data No, but screening uses that data
Sanctions screening Check parties against official lists Yes, OFAC and global lists
Ongoing sanctions monitoring Re-screen customers after list changes Yes, on Growth and higher
Payment screening Check parties inside each transfer Yes, on Scale and higher
PEP and adverse media checks Find higher risk customers No
Beneficial ownership Identify who owns or controls an entity No, you collect and review it
Transaction monitoring and SAR filing Spot and report suspicious activity No

Being clear about scope helps your auditor see which control each tool supports.

How to add sanctions screening to KYC onboarding

Five steps that place the check where it does the most good.

  1. 01

    Collect the right fields

    Ask for full legal name, date of birth for people, country, and registration or tax numbers for companies. These are the same fields KYC already needs.

  2. 02

    Screen before approval

    Run the check after identity data is captured and before the account opens, in the app or through the sanctions screening API.

  3. 03

    Route possible matches

    Clear results continue automatically. Review, Likely match and Exact match open a case for an analyst instead of blocking the whole queue.

  4. 04

    Decide and record the reason

    The reviewer compares the details with the listed entry and closes the case with a written reason, saved with the score breakdown.

  5. 05

    Keep the customer under watch

    Add approved customers to sanctions monitoring so later list changes are caught.

What an examiner usually asks to see

These points line up with the five parts of the OFAC Framework for Compliance Commitments from 2019. Management commitment, risk assessment, internal controls, testing and auditing, and training.

  • A written risk assessment

    Which customers, products and regions carry sanctions risk, and which lists apply to you.

  • Documented screening rules

    When you screen, which lists, which threshold, and why that threshold fits your risk.

  • Evidence for each check

    The list version, time, user and result for every screening, kept for the full retention period.

  • Decisions with reasons

    Why each possible match was cleared or escalated, and who decided.

  • Proof of re-screening

    That existing customers were checked again after list updates.

  • Testing and training records

    Periodic tests of the screening setup and training for the people who review matches.

Screening informs the decision and your team makes it

OfacScanner shows what the lists say, how close each name is and which list version was used. It does not decide whether to open an account, file a report or end a relationship. It also does not trace ownership, so entities owned 50 percent or more by blocked persons need your own ownership review. OFAC requires records of covered transactions to be kept for 10 years, so export your evidence if your plan retention is shorter. OfacScanner is not affiliated with OFAC or the U.S. Department of the Treasury.

AML sanctions screening questions

Another question? Write to [email protected].

Is sanctions screening part of AML?

It is usually run inside the AML program and shares its KYC data, but it has its own legal basis. In the U.S. sanctions come from OFAC rules, which apply to all U.S. persons, while AML duties come mainly from the Bank Secrecy Act for covered firms.

Does OfacScanner replace my AML software?

No. It covers sanctions screening, monitoring and payment screening. Identity verification, PEP checks, adverse media, transaction monitoring and suspicious activity reports need other tools or processes.

When in onboarding should I screen?

After you have the full name and key details, and before the account is approved or the first transaction is allowed. Then keep the customer under monitoring for list changes.

Which lists should an AML program screen?

At least the lists that bind you legally. For U.S. persons that is the OFAC SDN list and consolidated lists. Firms in or trading with other regions add the UN, EU, UK, Canadian or Australian lists, all covered on Growth and higher. See watchlist screening.

What threshold should we use?

The default is 85, called Balanced. Strict at 95 raises fewer alerts, Broad at 75 raises more. Pick the one your risk assessment supports and write down why.

Screen your first name in seconds

Type a person or company name, see the risk rating and top candidates from the current OFAC list, and keep the evidence when you sign up.

Results support your compliance decisions, and the final decision stays with your team. OfacScanner is not affiliated with OFAC or the U.S. Department of the Treasury.