Skip to content
OfacScanner

Compliance program

OFAC Compliance Software Built Around the Five Program Components

OFAC compliance software helps a business run its sanctions compliance program: screening customers and payments against OFAC lists, controlling how possible matches are decided and keeping records that show the program works. OfacScanner covers the screening, workflow and evidence parts.

OFAC SDN list, published , checked
Auditor comparing a printed evidence record with a laptop

What is OFAC compliance software

OFAC compliance means making sure your business does not deal with sanctioned parties and can show how it prevents that. Software is the tool, not the program. A program is the set of policies, people and controls your company runs. The software makes the controls repeatable and leaves a record of each step.

In 2019 OFAC published A Framework for OFAC Compliance Commitments. It describes five essential components of a sanctions compliance program and is the clearest public guide to what OFAC looks for. When OFAC weighs an apparent violation, the existence and quality of a program like this is one of the factors it considers.

How the software supports each component

Some components are about people and decisions. Others depend on tools. This table shows where OfacScanner helps and where your own work comes in.

Component What it means How OfacScanner supports it
Management commitment Leaders approve the program, fund it and give compliance real authority An Admin role and a shared record of every check that leaders can review
Risk assessment You map your customers, products, countries and payment flows to find sanctions risk A choice of lists and a threshold you set to match your risk appetite
Internal controls Written rules for screening, escalation and decisions, applied the same way every time Screening, batch files, monitoring, case management and reasons for every cleared match
Testing and auditing An independent check that the controls work as written Evidence records, search history and audit log export on Scale and higher
Training Staff know the rules and how to handle a possible match Clear ratings, score breakdowns and roles that show who does what

Source of the framework is the OFAC website of the U.S. Department of the Treasury.

How to build an OFAC compliance program step by step

A practical order for a small or growing company.

  1. 01

    Get management sign off

    Name a person responsible for sanctions compliance and have leadership approve the policy and budget.

  2. 02

    Assess your risk

    Write down who your customers are, where they are, what you sell and how money moves. Note the high risk points.

  3. 03

    Set your controls

    Decide where screening happens, which lists apply, which threshold you use and who decides a possible match.

  4. 04

    Screen and monitor

    Screen new parties before you deal with them and keep existing ones under ongoing sanctions monitoring.

  5. 05

    Test and train

    Review a sample of decisions on a schedule, fix what you find and train staff on the result.

Recordkeeping that holds up years later

OFAC requires records of transactions subject to its rules to be kept for 10 years. The statute of limitations for sanctions violations was extended from 5 to 10 years in 2024, and OFAC extended its recordkeeping requirement to match. A question about a customer you onboarded today can come up long after the staff who checked it have moved on.

Good records answer three questions without guesswork. Which list version was checked. What the result was and why. Who made the decision and when. OfacScanner stores all three with every check and lets you export them, so you can keep a copy in your own archive for the full period.

  • List version and timestamp on every result
  • Score breakdown and the alias that matched
  • User, decision and reason for each cleared match
  • PDF certificate per check and audit log export on Scale and higher

Reports and duties beyond screening

Screening is one part of OFAC compliance. Your program also has to cover these duties.

  • Blocking reports

    Property of a blocked person must be blocked and reported to OFAC within 10 business days.

  • Reject reports

    Rejected transactions also have to be reported within 10 business days.

  • Annual report

    Holders of blocked property file an annual report of what they hold.

  • Ownership review

    Under the 50 percent rule, a company owned 50 percent or more by blocked persons is blocked too, so ownership needs your own due diligence.

  • Other lists

    If you trade abroad, UN, EU, UK and other regimes may apply. See watchlist screening.

  • AML link

    For regulated firms, sanctions controls sit next to Bank Secrecy Act duties. See AML sanctions screening.

The compliance decision belongs to you

OfacScanner gives you current lists, scored results and a full record. It does not decide whether to block, reject or report, and it does not give legal advice. Those calls belong to your compliance team and your counsel. OfacScanner is not affiliated with OFAC or the U.S. Department of the Treasury.

OFAC compliance software questions

Another question? Write to [email protected].

Does OFAC require a written compliance program?

OFAC does not require one specific program for every business, but it strongly encourages a risk based program built on the five components and considers it when it evaluates a violation.

Can software make my company OFAC compliant on its own?

No. Software runs the controls and keeps the records. Compliance also needs leadership support, a risk assessment, testing and trained staff.

How long should OFAC compliance records be kept?

Ten years for records of transactions subject to OFAC rules. OfacScanner keeps results for your plan retention period, and you can export everything for longer storage.

Does OfacScanner check ownership under the 50 percent rule?

No. It screens names and aliases against the lists. Ownership has to be checked with your own due diligence.

Which plan suits a compliance team?

Growth adds monitoring, case management, global lists and roles for 5 users. Scale adds the API, audit log export, SSO and 20 users. See pricing.

Screen your first name in seconds

Type a person or company name, see the risk rating and top candidates from the current OFAC list, and keep the evidence when you sign up.

Results support your compliance decisions, and the final decision stays with your team. OfacScanner is not affiliated with OFAC or the U.S. Department of the Treasury.