Articles
14th Sep 2026

What Is OFAC and Why Payout Platforms Must Comply (September 2026)

Download (86)

When you’re disbursing to thousands of contractors, sellers, or grantees across dozens of countries, a single payment to a newly designated payee is a sanctions violation, and no intent is required. OFAC’s strict liability standard means the obligation follows the transaction, and the penalty follows the platform. Payout platforms operating at scale face a compliance math problem that manual review cannot solve: the larger your payee network, the higher the probability that at least one name in a given batch has been designated since your last check. This post breaks down what OFAC is, how its sanctions programs work, and what a screening architecture needs to look like when you’re running thousands of disbursements per cycle.

TLDR:

  • OFAC is a U.S. Treasury division that enforces sanctions; it applies to your platform, banks included
  • Strict liability means you can be penalized for paying a sanctioned party even without knowing it
  • Screening only the SDN List leaves gaps; a complete check requires the broader consolidated dataset
  • A payee who clears onboarding in January can be designated by March; screen at onboarding and before every disbursement
  • Routable screens every payee against 6,000+ global watchlists at two points and holds only the flagged payment, not the full batch

What Is OFAC?

OFAC stands for the Office of Foreign Assets Control, a division of the U.S. Department of the Treasury. Its mandate is to administer and enforce economic and trade sanctions based on U.S. foreign policy and national security goals, targeting foreign countries, regimes, terrorists, narcotics traffickers, weapons proliferators, and other threats to U.S. interests.

In practice, OFAC sets and enforces the rules that determine who U.S. persons and businesses can transact with. Sanctions take different forms: some block specific individuals or entities from accessing the U.S. financial system, while others broadly restrict all transactions with a particular country or regime. That makes OFAC one of the most consequential financial regulators for any U.S. business moving money internationally, particularly platforms running mass payouts at high volume.

How OFAC Sanctions Work

Sanctions don’t all work the same way. Some are broad, covering entire countries or regimes. Others are targeted, restricting specific individuals, companies, or organizations without prohibiting all transactions with a given country.

Broad vs. Targeted Sanctions

Broad, jurisdiction-wide sanctions apply to entire countries, such as North Korea or Iran, prohibiting nearly all transactions between U.S. persons and those countries, with narrow licensed exceptions. Targeted sanctions work differently: they designate specific parties whose assets are blocked and with whom U.S. persons are generally forbidden from dealing, regardless of where those parties are located.

When OFAC “blocks” an asset, the property is frozen in place. The owner cannot move it, transfer it, or access it. Any U.S. person holding that asset must maintain it in a blocked account and report it to OFAC.

The Specially Designated Nationals List

The SDN List is OFAC’s primary enforcement tool, naming individuals, companies, vessels, and other entities whose assets are blocked and with whom U.S. persons are generally prohibited from dealing. The list currently covers over 17,000 targets, including terrorists, narcotics traffickers, state-owned entities, and sanctions evaders spanning nearly every active OFAC program.

The SDN List is one of several OFAC administers. The Sectoral Sanctions Identifications (SSI) List targets entities in specific sectors of the Russian economy, imposing transaction restrictions without fully blocking assets. The Consolidated Sanctions List bundles the SDN List with other non-SDN lists into a single downloadable file for screening purposes. For platforms running automated compliance checks, OFAC screening for mass disbursements requires the broader consolidated dataset, not the SDN List alone. Routable screens every payee against 6,000+ global watchlists, including OFAC, EU, and FTO lists, and not merely the SDN file, closing the coverage gap that SDN-only screening leaves open for platforms paying into sectors or regions with non-SDN restrictions.

Types of OFAC Sanctions Programs

OFAC administers dozens of active sanctions programs, each structured differently depending on the threat it targets. Three broad categories cover most of what platforms encounter in practice.

Country-based sanctions impose the broadest restrictions, prohibiting or severely limiting transactions involving entire jurisdictions. Cuba, Iran, North Korea, and the Crimea, Donetsk, and Luhansk regions of Ukraine fall under full-scope programs that block nearly all financial dealings with U.S. persons, with limited exceptions requiring an OFAC license. Syria was under a comparable comprehensive embargo until OFAC lifted it in 2025; targeted sanctions on Assad-linked individuals and other bad actors remain, but the country as a whole is no longer subject to a blanket prohibition.

List-based sanctions work differently. Instead of targeting a country, they designate specific individuals, companies, or organizations, with the SDN List as the primary vehicle. A sanctioned party may be a citizen of a U.S.-friendly nation, operate a business in an unsanctioned country, and still be completely off-limits. Nationality is irrelevant. What matters is whether the name appears on a covered list.

Sectoral sanctions sit between the two. Instead of blocking entire countries or specific named parties, they restrict certain transaction types with entities in targeted economic sectors: energy, finance, and defense in Russia, for example. These entities appear on the SSI List, not the SDN List, which is why screening only the SDN List leaves a meaningful compliance gap for platforms paying into affected regions.

Who Must Comply with OFAC Regulations

OFAC regulations apply to all U.S. persons: citizens, permanent residents, and any entity organized under U.S. law, including the foreign branches of those entities.

The reach extends further than most expect. Non-U.S. companies can face OFAC exposure when their cross-border payments clear through U.S. correspondent banks, involve U.S. persons, or use U.S.-origin goods or tech. Routing a payment through a U.S. dollar correspondent account is often enough to trigger jurisdiction, regardless of where the payer or payee is located.

In March 2024, the U.S. Departments of Treasury, Commerce, and Justice issued a joint Tri-Seal Compliance Note explicitly warning foreign-based companies about these obligations. Non-U.S. companies that continue engaging with sanctioned jurisdictions or persons risk legal exposure under U.S. law, and the interconnected nature of global commerce does not insulate foreign firms from U.S. sanctions enforcement.

Penalties for Violating OFAC Rules

Civil penalties for OFAC violations can reach $377,700 per violation under IEEPA, the statute governing most modern sanctions programs, or twice the underlying transaction value, whichever is greater. Penalties climb well into the millions when violations are aggregated across a batch of transactions, or under other OFAC-enforced statutes with higher per-violation caps.

OFAC distinguishes between egregious and non-egregious violations when setting penalties. Egregious cases involving willful conduct, reckless disregard, or harm to sanctions policy objectives draw amounts closer to the statutory maximum. Non-egregious violations where the party self-discloses can result in materially reduced fines. Willful or repeated violations can also carry criminal liability, including fines and imprisonment for individuals involved.

Documented screening procedures in place before a violation occurs are a meaningful factor in penalty mitigation, but they do not eliminate liability; gaps in those procedures also create openings for payout fraud that compound the risk.

What an OFAC Check Is and How Screening Works

In practice, a sound screening program goes beyond a single name lookup. There are four dimensions that separate a compliance-grade approach from one that creates exposure.

Key Dimensions of Effective OFAC Screening

  • Dual-point screening. Screening at onboarding and again immediately before each disbursement fires closes the gap that a single onboarding check leaves open, since OFAC lists update regularly and a payee who cleared initial screening may appear on a subsequent list update months later. Routable’s architecture fires at both moments, at initial onboarding and immediately before each disbursement executes, and when a pre-payment match triggers a compliance hold, only that payee’s payment pauses while the rest of the batch continues processing uninterrupted.
  • Fuzzy-match logic. Exact-match screening fails against transliterated names, aliases, and alternate spellings, so a screening system needs approximate string matching to surface potential matches that a character-for-character comparison would miss. OFAC’s own Sanctions List Search tool uses this approach, and any compliance-grade program should do the same.
  • Alert investigation and escalation. A potential match is not a confirmed violation. A defined review process must determine whether it is a true match or a false positive, with a documented escalation path, resolution timeline, and clear record of the determination made, following the same workflow that underpins payee fraud detection and prevention.
  • Documented recordkeeping. OFAC weighs the existence of a compliance program when assessing penalties, so retaining records of screening decisions, alert resolutions, and the lists screened at each touchpoint builds a documented compliance posture before a problem surfaces. Routable maintains these records automatically within its payout orchestration layer, giving platforms audit-ready documentation without a separate compliance workflow.

OFAC vs. Other U.S. Sanctions and Compliance Agencies

OFAC, FinCEN, and BIS come up in the same compliance conversations, but they govern completely different obligations. Conflating them creates gaps in one area while over-investing in another.

OFAC handles sanctions enforcement: blocking assets, prohibiting transactions with designated parties, and restricting financial activity involving targeted countries or regimes. A payment to a sanctioned contractor is an OFAC problem, a missed screening at disbursement is an OFAC problem.

FinCEN administers AML and Bank Secrecy Act requirements, asking whether transaction patterns suggest criminal activity, and your banking partners face FinCEN scrutiny through their own AML programs regardless of your platform’s registration status.

BIS oversees exports of controlled goods, software, and technology with national security implications, and becomes relevant once a platform’s product involves any controlled technology component beyond pure cash disbursements.

Agency Primary Focus Key Instrument Typical Trigger for Payout Platforms
OFAC Sanctions and asset-blocking SDN List / Sanctions programs Paying a designated party or restricted jurisdiction
FinCEN AML / BSA compliance SAR filings / AML programs Suspicious transaction patterns flagged through banking partners
BIS Export controls Entity List / Commerce Control List Distributing controlled software or tech internationally

Why OFAC Matters for Platforms Making Mass Payouts

Scale changes the compliance math in a direct way. When you pay 50 contractors a month, manually reviewing each payee is inconvenient but possible. When you pay 5,000 gig workers, 10,000 marketplace sellers, or 2,000 insurance agents monthly, the same manual approach becomes structurally impossible, and the probability that at least one payee in that population appears on a sanctions list grows with every new onboard.

Volume also creates a specific structural problem that manual review cannot solve at any scale: a payee who passes onboarding screening in January may be added to the SDN List in March. If the next payment fires in April without a fresh check, the platform has processed a sanctions violation despite the payee clearing initial review. Screen at onboarding to gate entry into your payee network, and screen again immediately before each disbursement fires to catch any designation that occurred in between.

How Routable Embeds OFAC Screening Into the Mass Payout Workflow

It screens every payee against 6,000+ global watchlists, including OFAC, EU, and FTO lists, at two distinct points: initial onboarding and immediately before each disbursement fires. That dual-check architecture is why Routable screens at both onboarding and pre-disbursement. Sanctions screening runs automatically within Routable’s payout orchestration layer on its mass payout platform, the very same orchestration layer that handles multi-rail routing, automatic fallback, and TIN validation against IRS records. When a pre-payment match triggers a compliance hold, Routable pauses only that payee’s payment while the rest of the batch continues processing uninterrupted. For a platform running 5,000 disbursements in a single cycle across global payouts across 220+ countries, that per-payment hold is the difference between a contained compliance review and a full batch shutdown that delays every contractor, seller, or grantee in the run.

Final Thoughts on Understanding OFAC and Sanctions Screening

Sanctions compliance is one of the few areas where “we didn’t know” is not a defense, and the volume of your payout operation determines how fast that exposure compounds. A single unscreened disbursement to a newly designated payee is a violation, even if that payee cleared initial review months earlier. Building a screen into every disbursement cycle, at onboarding and each subsequent payout, is the structural fix. If you want to see what dual-point sanctions screening looks like embedded inside a live mass payout workflow, request a demo.

FAQ

What is OFAC and why does it matter for platforms paying contractors or gig workers at scale?

OFAC is the Office of Foreign Assets Control, the U.S. Treasury division that administers economic sanctions against designated individuals, entities, and entire jurisdictions. For platforms disbursing payments to thousands of contractors, creators, or gig workers, OFAC compliance is not optional: if even one payee in a batch of 10,000 appears on the Specially Designated Nationals list, processing that payment carries strict civil liability regardless of whether your team knew the payee was listed.

Is screening against the OFAC SDN List enough for mass payout compliance, or do I need to screen against additional lists?

Screening only the SDN List leaves a meaningful compliance gap. A complete check requires the broader Consolidated Sanctions List, which bundles the SDN List with non-SDN lists including the Sectoral Sanctions Identifications list; this matters for platforms paying into sectors like Russian energy or finance where entities are restricted but not fully blocked. Platforms running automated compliance checks should confirm their screening provider covers the full consolidated dataset, beyond the SDN file alone.

How should I structure OFAC screening if my platform onboards hundreds of new payees every month and runs batch disbursements weekly?

Screen at two distinct points: once at onboarding to gate entry into your payee network, and again immediately before each disbursement fires. Screening at both points closes the gap a single onboarding check leaves open. When a pre-payment match triggers a hold, the flagged payment should pause for review while the rest of the batch continues processing uninterrupted; stalling the entire run over a single flag turns a contained compliance event into a disbursement-wide crisis affecting every contractor, seller, or grantee in that cycle.

What is the difference between OFAC, FinCEN, and BIS for platforms making mass payouts internationally?

These three agencies cover distinct obligations that compound for platforms disbursing at scale. OFAC governs who you can pay, blocking transactions with designated parties and restricted jurisdictions. FinCEN administers anti-money laundering requirements under the Bank Secrecy Act, asking whether transaction patterns suggest criminal activity; your banking partners face FinCEN scrutiny regardless of your own registration status. BIS oversees exports of goods, software, and technology with national security implications, which becomes relevant once your platform’s product involves any controlled technology component beyond pure cash disbursements.

Can a foreign-registered platform face OFAC liability if its payments route through U.S. correspondent banks?

Yes. Routing a payment through a U.S. dollar correspondent account is often enough to trigger OFAC jurisdiction regardless of where the payer or payee is located. The U.S. Departments of Treasury, Commerce, and Justice issued a joint Tri-Seal Compliance Note in March 2024 explicitly warning foreign-based companies about these obligations. The interconnected nature of global commerce does not insulate foreign-registered platforms from U.S. sanctions enforcement when their payment flows touch U.S. financial infrastructure.