Skip to content
OfacScanner

Fintech and payments

Sanctions Screening for Fintech Onboarding and Monitoring

Sanctions screening for fintech means checking every new user against the OFAC lists at signup, then re-checking the whole customer base whenever the lists change. OfacScanner does both through one sanctions screening API and keeps evidence your bank partner can review.

OFAC SDN list, published , checked
Fintech compliance lead reviewing onboarding screening results on a laptop

What is sanctions screening for fintech

A fintech moves money for people and businesses it has never met in person. Sanctions screening is the control that stops a blocked person or company from opening an account, receiving a payout or sending a transfer. In practice it means comparing names, dates of birth, countries and identifiers against the OFAC Specially Designated Nationals list and the OFAC consolidated non-SDN lists, plus other national lists where you operate.

Most fintechs do not hold a bank charter. They work through a sponsor bank or a bank partner, and that bank stays responsible to its own examiners. So the bank writes sanctions controls into the program agreement and asks the fintech to prove them. A screening step that runs on every signup, keeps a record of each result and re-checks customers after each list update is what those reviews look for.

OFAC liability is strict, which means a payment to a listed party can lead to a penalty even if nobody knew. That is why the check has to be automatic and complete, not a manual search that someone runs when they have time.

Built for product flows

What fintech teams get from OfacScanner

Each part maps to a step in your onboarding or payment flow, so compliance does not slow the product down.

Real time API at signup

Send a name with date of birth and country, get a rating and candidates back in under 300 ms on Scale, so the check fits inside the signup request.

Monitoring of the whole book

Add customers to monitoring once. After each list update OfacScanner re-screens them and raises an alert only for new or changed hits.

Signed webhooks

Events such as screening.completed, case.created and monitoring.alert reach your backend, signed with HMAC SHA-256.

Case management

Possible matches become cases your analysts assign, comment on and close with a reason, so nothing sits in an inbox.

Payment screening

Screen originator, beneficiary, bank and free text fields before a transfer leaves, with payment screening on Scale.

Audit trail by default

Every check stores the list version, time, user or API key and score breakdown, with audit log export on Scale.

One call inside your signup flow

Call the screening endpoint right after the user submits identity details. Use an Idempotency-Key header so a retried request never creates a second check, and use the sandbox key while you build.

Request

curl -X POST https://ofacscanner.com/api/v1/screen \
  -H "Authorization: Bearer $OFACSCANNER_KEY" \
  -H "Idempotency-Key: signup-48213" \
  -H "Content-Type: application/json" \
  -d '{"name": "Maria Lopez", "type": "individual", "dob": "1988-04-12", "country": "US"}'

Then add the customer to monitoring

curl -X POST https://ofacscanner.com/api/v1/monitor \
  -H "Authorization: Bearer $OFACSCANNER_KEY" \
  -H "Content-Type: application/json" \
  -d '{"reference": "cust_48213", "name": "Maria Lopez", "type": "individual"}'

How to set up screening in a fintech product

Most teams follow the same order. Start with signup, then cover the people you already have.

  1. 01

    Decide where the check runs

    Place the API call after identity data is collected and before the account can send or receive money. Hold the account in a pending state while a Review or Likely match rating is open.

  2. 02

    Set your threshold

    Start with the Balanced sensitivity at 85. Move to Strict 95 or Broad 75 once you see how your customer names behave, and write the reason into your policy.

  3. 03

    Load your existing customers

    Upload the current book as a CSV file with batch sanctions screening and add every record to monitoring in the same step.

  4. 04

    Connect alerts to your team

    Point the monitoring.alert and case.created webhooks at your case queue or chat, and assign Analyst, Reviewer and Admin roles.

  5. 05

    Export evidence for reviews

    Before a bank partner review or an audit, export the audit log and sample evidence PDFs for the period they ask about.

Engineer integrating screening into an onboarding flow at a standing desk

Engineers ship it in a sprint

The API is small on purpose. A handful of endpoints cover single checks, batch files, results, monitoring and list status. Keys are created in the dashboard, and a separate sandbox key returns test results while you build and test the integration.

There are no overage fees. If you reach your monthly check limit, new checks pause until the next period or an upgrade, while monitoring of existing records keeps running.

  • Bearer keys with a sandbox key for testing
  • Idempotency keys for safe retries
  • Webhooks signed with HMAC SHA-256
  • Full reference in the API docs

What your sponsor bank will ask to see

Bank partners usually ask how screening works, which lists are covered, how often lists refresh, who decides on possible matches and how long records are kept. OfacScanner answers each point with data from your own account: list sources with their last update date, checks of the official files every 30 minutes, named reviewers on each case and an evidence record for every check. The decision on any match still belongs to your compliance team, and OfacScanner is not affiliated with OFAC or the U.S. Department of the Treasury.

Which plan fits a fintech

Growth at $499 a month, or $249 a month billed yearly, fits an early fintech that onboards through a dashboard or a batch process. It includes 50,000 checks a month, monitoring of up to 50,000 records, case management, global lists, webhooks and 5 users.

Scale at $1,999 a month, or $999 a month billed yearly, is the usual choice once screening runs inside the product. It adds the REST API with real time responses, payment screening, allow lists for known good customers, SSO, audit log export and monitoring of up to 500,000 records. See every limit on the pricing page.

Fintech sanctions screening questions

Another question? Write to [email protected].

Do fintechs without a bank charter need sanctions screening?

Yes in practice. OFAC rules apply to U.S. persons, including U.S. fintech companies, and sponsor banks require their fintech partners to screen customers and transactions as part of the program agreement.

How fast is the API check at signup?

On the Scale plan the real time endpoint answers in under 300 ms, so it can run inside the signup request without a visible delay for the user.

What happens to existing customers when the SDN list changes?

Records you add to ongoing sanctions monitoring are re-screened after each list update. You get an alert only when a new or changed list entry scores above your threshold.

Can we screen outgoing transfers as well as customers?

Yes on Scale and Enterprise. Payment screening checks originator, beneficiary, bank, free text and vessel fields, and crypto addresses that appear on the lists.

Does OfacScanner cover PEP or adverse media checks?

No. OfacScanner focuses on sanctions lists. If your program needs PEP or adverse media screening, use a separate provider for those checks.

Screen your first name in seconds

Type a person or company name, see the risk rating and top candidates from the current OFAC list, and keep the evidence when you sign up.

Results support your compliance decisions, and the final decision stays with your team. OfacScanner is not affiliated with OFAC or the U.S. Department of the Treasury.