OFAC check: how to screen a customer against sanctions lists

Photo by Darlene Alderson on Pexels
"Run an OFAC check" is one of the most common instructions in a compliance workflow — during customer onboarding, before wiring funds internationally, before signing a new vendor, or as part of periodic re-review. This is the practical, step-by-step version of what that instruction should actually mean.
Step 1: Gather the identifying details you have
Before you search anything, collect whatever identifying information you have about the subject — not just their name. At minimum you want:
- Full legal name (avoid initials or nicknames where possible)
- Entity type: individual or organization
- Date of birth (for individuals) or registration jurisdiction (for entities), if known
- Nationality or country of operation, if known
These extra fields aren't decoration — they're what let you distinguish a true match from a common-name coincidence later, without doing manual detective work on a name you barely recognize.
Step 2: Screen against all relevant lists, not just the SDN
A proper OFAC check covers more than the SDN list. At minimum:
- OFAC SDN — the primary blocked-persons list.
- OFAC Consolidated (Non-SDN) — sectoral and other narrower restriction programs.
- UN Security Council Consolidated list — relevant if you or your counterparty operate outside the US, since UN member states have their own obligation to implement these designations domestically.
Screening only the SDN list and calling it "an OFAC check" is a common gap — it misses Consolidated-list hits and any UN-only designation entirely. A tool like Screen100 runs the query against all three in a single search, which is the point of screening this way rather than checking each government source by hand.
Step 3: Run the search — and let it search aliases automatically
Type the full legal name into the search. A well-built screening tool automatically checks the name against every primary name and every alias across all listed entities — you shouldn't have to manually think of every possible spelling variant. What you get back is a set of candidate hits, each with a match score.
Step 4: Read the result by score band, not just "match or no match"
Rather than a binary yes/no, results should fall into three bands:
- Clear — no meaningful correspondence found. Record the result and move on, but remember it reflects the list at this moment, not permanently.
- Possible match — a partial correspondence that needs a closer look. This is the band that requires actual review work.
- Match — high confidence. Treat this as a hit requiring escalation before you proceed with the relationship.
Step 5: Review a possible match against supporting details
This is where the details you gathered in Step 1 earn their keep. For any possible match:
- Check whether the hit is against the primary name or a weak/low-quality alias — primary-name hits carry more weight.
- Compare date of birth, nationality, and address against the listed entry's attributes, if the entry provides them. A wrong birth year or contradicting nationality is strong evidence against a true match.
- Check the designation's program and date — an old designation under a narrow program may carry different implications than a fresh SDGT (terrorism) listing.
- If still ambiguous, look for independent corroborating information (public records, news) before concluding either way.
Step 6: Document the decision
Whatever you conclude — cleared, escalated, or still pending — write it down with a timestamp and the exact list version you searched against. This is the step teams skip under time pressure, and it's the one an auditor or regulator will ask about first. If you're using a tool with built-in audit certificates, this step happens automatically on every screen.
Step 7: Don't stop at onboarding
A single OFAC check at the start of a relationship only covers that moment. Sanctions lists update weekly or more often, so a customer who cleared in January can be designated in March. For any relationship that persists — an ongoing customer, a recurring vendor, a beneficial owner you're tracking — you need periodic re-screening, not just a one-time check. This is what ongoing monitoring is built to automate: save the subject once, and it gets re-screened every time the lists refresh, with an alert if anything changes.
A minimal checklist
- Full legal name, entity type, and any supporting details collected
- Screened against OFAC SDN, OFAC Consolidated, and UN Security Council
- Result read by score band, not treated as binary
- Any possible match reviewed against supporting attributes
- Decision documented with timestamp and list version
- Ongoing subjects added to periodic re-screening, not left as a one-time check
You can run through this whole flow right now — screen a name for free and see the score, the band, and the cited source entry for yourself. For the difference between this and a related check, see sanctions screening vs PEP screening.
Frequently asked questions
What information do I need to run an OFAC check?
At minimum, the subject's full legal name and whether they're an individual or organization. Date of birth, nationality, and address, where available, sharply reduce false positives when reviewing a possible match.
Does an OFAC check cover more than the SDN list?
It should. A thorough OFAC check screens the SDN list, the OFAC Consolidated (Non-SDN) list, and typically the UN Security Council Consolidated list, since obligations can differ by jurisdiction and program.
How often should I re-run an OFAC check on the same customer?
For any ongoing relationship, don't rely on a single onboarding check. Sanctions lists update frequently, so persisting subjects should go into an ongoing monitoring queue that re-screens automatically as lists refresh.
Run this check on a real name
Free, no account required. Screen against the OFAC SDN, OFAC Consolidated and UN Security Council lists.