Compliance program
OFAC Compliance Software Built Around the Five Program Components
OFAC compliance software helps a business run its sanctions compliance program: screening customers and payments against OFAC lists, controlling how possible matches are decided and keeping records that show the program works. OfacScanner covers the screening, workflow and evidence parts.
What is OFAC compliance software
OFAC compliance means making sure your business does not deal with sanctioned parties and can show how it prevents that. Software is the tool, not the program. A program is the set of policies, people and controls your company runs. The software makes the controls repeatable and leaves a record of each step.
In 2019 OFAC published A Framework for OFAC Compliance Commitments. It describes five essential components of a sanctions compliance program and is the clearest public guide to what OFAC looks for. When OFAC weighs an apparent violation, the existence and quality of a program like this is one of the factors it considers.
How the software supports each component
Some components are about people and decisions. Others depend on tools. This table shows where OfacScanner helps and where your own work comes in.
| Component | What it means | How OfacScanner supports it |
|---|---|---|
| Management commitment | Leaders approve the program, fund it and give compliance real authority | An Admin role and a shared record of every check that leaders can review |
| Risk assessment | You map your customers, products, countries and payment flows to find sanctions risk | A choice of lists and a threshold you set to match your risk appetite |
| Internal controls | Written rules for screening, escalation and decisions, applied the same way every time | Screening, batch files, monitoring, case management and reasons for every cleared match |
| Testing and auditing | An independent check that the controls work as written | Evidence records, search history and audit log export on Scale and higher |
| Training | Staff know the rules and how to handle a possible match | Clear ratings, score breakdowns and roles that show who does what |
Source of the framework is the OFAC website of the U.S. Department of the Treasury.
How to build an OFAC compliance program step by step
A practical order for a small or growing company.
-
01
Get management sign off
Name a person responsible for sanctions compliance and have leadership approve the policy and budget.
-
02
Assess your risk
Write down who your customers are, where they are, what you sell and how money moves. Note the high risk points.
-
03
Set your controls
Decide where screening happens, which lists apply, which threshold you use and who decides a possible match.
-
04
Screen and monitor
Screen new parties before you deal with them and keep existing ones under ongoing sanctions monitoring.
-
05
Test and train
Review a sample of decisions on a schedule, fix what you find and train staff on the result.
Recordkeeping that holds up years later
OFAC requires records of transactions subject to its rules to be kept for 10 years. The statute of limitations for sanctions violations was extended from 5 to 10 years in 2024, and OFAC extended its recordkeeping requirement to match. A question about a customer you onboarded today can come up long after the staff who checked it have moved on.
Good records answer three questions without guesswork. Which list version was checked. What the result was and why. Who made the decision and when. OfacScanner stores all three with every check and lets you export them, so you can keep a copy in your own archive for the full period.
- List version and timestamp on every result
- Score breakdown and the alias that matched
- User, decision and reason for each cleared match
- PDF certificate per check and audit log export on Scale and higher
Reports and duties beyond screening
Screening is one part of OFAC compliance. Your program also has to cover these duties.
-
Blocking reports
Property of a blocked person must be blocked and reported to OFAC within 10 business days.
-
Reject reports
Rejected transactions also have to be reported within 10 business days.
-
Annual report
Holders of blocked property file an annual report of what they hold.
-
Ownership review
Under the 50 percent rule, a company owned 50 percent or more by blocked persons is blocked too, so ownership needs your own due diligence.
-
Other lists
If you trade abroad, UN, EU, UK and other regimes may apply. See watchlist screening.
-
AML link
For regulated firms, sanctions controls sit next to Bank Secrecy Act duties. See AML sanctions screening.
The compliance decision belongs to you
OfacScanner gives you current lists, scored results and a full record. It does not decide whether to block, reject or report, and it does not give legal advice. Those calls belong to your compliance team and your counsel. OfacScanner is not affiliated with OFAC or the U.S. Department of the Treasury.
OFAC compliance software questions
Another question? Write to [email protected].
Does OFAC require a written compliance program?
Can software make my company OFAC compliant on its own?
How long should OFAC compliance records be kept?
Does OfacScanner check ownership under the 50 percent rule?
Which plan suits a compliance team?
Keep exploring
Screen your first name in seconds
Type a person or company name, see the risk rating and top candidates from the current OFAC list, and keep the evidence when you sign up.
Results support your compliance decisions, and the final decision stays with your team. OfacScanner is not affiliated with OFAC or the U.S. Department of the Treasury.