Fintech and payments
Sanctions Screening for Fintech Onboarding and Monitoring
Sanctions screening for fintech means checking every new user against the OFAC lists at signup, then re-checking the whole customer base whenever the lists change. OfacScanner does both through one sanctions screening API and keeps evidence your bank partner can review.
What is sanctions screening for fintech
A fintech moves money for people and businesses it has never met in person. Sanctions screening is the control that stops a blocked person or company from opening an account, receiving a payout or sending a transfer. In practice it means comparing names, dates of birth, countries and identifiers against the OFAC Specially Designated Nationals list and the OFAC consolidated non-SDN lists, plus other national lists where you operate.
Most fintechs do not hold a bank charter. They work through a sponsor bank or a bank partner, and that bank stays responsible to its own examiners. So the bank writes sanctions controls into the program agreement and asks the fintech to prove them. A screening step that runs on every signup, keeps a record of each result and re-checks customers after each list update is what those reviews look for.
OFAC liability is strict, which means a payment to a listed party can lead to a penalty even if nobody knew. That is why the check has to be automatic and complete, not a manual search that someone runs when they have time.
Built for product flows
What fintech teams get from OfacScanner
Each part maps to a step in your onboarding or payment flow, so compliance does not slow the product down.
Real time API at signup
Send a name with date of birth and country, get a rating and candidates back in under 300 ms on Scale, so the check fits inside the signup request.
Monitoring of the whole book
Add customers to monitoring once. After each list update OfacScanner re-screens them and raises an alert only for new or changed hits.
Signed webhooks
Events such as screening.completed, case.created and monitoring.alert reach your backend, signed with HMAC SHA-256.
Case management
Possible matches become cases your analysts assign, comment on and close with a reason, so nothing sits in an inbox.
Payment screening
Screen originator, beneficiary, bank and free text fields before a transfer leaves, with payment screening on Scale.
Audit trail by default
Every check stores the list version, time, user or API key and score breakdown, with audit log export on Scale.
One call inside your signup flow
Call the screening endpoint right after the user submits identity details. Use an Idempotency-Key header so a retried request never creates a second check, and use the sandbox key while you build.
Request
curl -X POST https://ofacscanner.com/api/v1/screen \
-H "Authorization: Bearer $OFACSCANNER_KEY" \
-H "Idempotency-Key: signup-48213" \
-H "Content-Type: application/json" \
-d '{"name": "Maria Lopez", "type": "individual", "dob": "1988-04-12", "country": "US"}'
Then add the customer to monitoring
curl -X POST https://ofacscanner.com/api/v1/monitor \
-H "Authorization: Bearer $OFACSCANNER_KEY" \
-H "Content-Type: application/json" \
-d '{"reference": "cust_48213", "name": "Maria Lopez", "type": "individual"}'
How to set up screening in a fintech product
Most teams follow the same order. Start with signup, then cover the people you already have.
-
01
Decide where the check runs
Place the API call after identity data is collected and before the account can send or receive money. Hold the account in a pending state while a Review or Likely match rating is open.
-
02
Set your threshold
Start with the Balanced sensitivity at 85. Move to Strict 95 or Broad 75 once you see how your customer names behave, and write the reason into your policy.
-
03
Load your existing customers
Upload the current book as a CSV file with batch sanctions screening and add every record to monitoring in the same step.
-
04
Connect alerts to your team
Point the monitoring.alert and case.created webhooks at your case queue or chat, and assign Analyst, Reviewer and Admin roles.
-
05
Export evidence for reviews
Before a bank partner review or an audit, export the audit log and sample evidence PDFs for the period they ask about.
Engineers ship it in a sprint
The API is small on purpose. A handful of endpoints cover single checks, batch files, results, monitoring and list status. Keys are created in the dashboard, and a separate sandbox key returns test results while you build and test the integration.
There are no overage fees. If you reach your monthly check limit, new checks pause until the next period or an upgrade, while monitoring of existing records keeps running.
- Bearer keys with a sandbox key for testing
- Idempotency keys for safe retries
- Webhooks signed with HMAC SHA-256
- Full reference in the API docs
What your sponsor bank will ask to see
Bank partners usually ask how screening works, which lists are covered, how often lists refresh, who decides on possible matches and how long records are kept. OfacScanner answers each point with data from your own account: list sources with their last update date, checks of the official files every 30 minutes, named reviewers on each case and an evidence record for every check. The decision on any match still belongs to your compliance team, and OfacScanner is not affiliated with OFAC or the U.S. Department of the Treasury.
Which plan fits a fintech
Growth at $499 a month, or $249 a month billed yearly, fits an early fintech that onboards through a dashboard or a batch process. It includes 50,000 checks a month, monitoring of up to 50,000 records, case management, global lists, webhooks and 5 users.
Scale at $1,999 a month, or $999 a month billed yearly, is the usual choice once screening runs inside the product. It adds the REST API with real time responses, payment screening, allow lists for known good customers, SSO, audit log export and monitoring of up to 500,000 records. See every limit on the pricing page.
Fintech sanctions screening questions
Another question? Write to [email protected].
Do fintechs without a bank charter need sanctions screening?
How fast is the API check at signup?
What happens to existing customers when the SDN list changes?
Can we screen outgoing transfers as well as customers?
Does OfacScanner cover PEP or adverse media checks?
Keep exploring
Screen your first name in seconds
Type a person or company name, see the risk rating and top candidates from the current OFAC list, and keep the evidence when you sign up.
Results support your compliance decisions, and the final decision stays with your team. OfacScanner is not affiliated with OFAC or the U.S. Department of the Treasury.