OFAC sits inside the U.S. Department of the Treasury and has the authority to block transactions, freeze assets, and issue civil penalties that reach millions of dollars per violation. For platforms disbursing to large contractor or grantee networks, that authority touches every payment in every batch, including payments routed outside U.S. banks. Here’s how OFAC sanctions programs work, what the screening requirement actually covers, and why this belongs inside your payout infrastructure, not outside it.
TLDR:
- OFAC sits inside the U.S. Department of the Treasury, not FinCEN, and applies to all U.S. persons and entities globally.
- Your OFAC screening obligation covers three layers: country-based, SDN list, and sectoral programs. Missing any one creates liability.
- Civil penalties can reach $377,700 per violation, and a single unscreened batch run produces one violation per transaction.
- Manual OFAC screening stops scaling past a few hundred payees; compliance must be embedded in the payout workflow itself.
- Routable screens every payee against 6,000+ watchlists (including OFAC, EU, and FTO) at both onboarding and immediately before each disbursement fires, so a payee added months ago who is later designated gets caught before funds move.
What OFAC Is and Which Agency It Belongs To
The Office of Foreign Assets Control sits inside the U.S. Department of the Treasury, not FinCEN, not the Department of Justice. That distinction matters because OFAC’s authority flows from Treasury’s mandate to enforce economic and trade sanctions, giving it broad reach over financial transactions and not merely criminal investigations. OFAC administers sanctions programs targeting specific countries, governments, entities, and individuals deemed threats to U.S. national security or foreign policy. Its primary tool is the Specially Designated Nationals and Blocked Persons List, commonly called the SDN list, which names the people and organizations that U.S. persons and companies are prohibited from doing business with.
What OFAC Is Responsible For
OFAC’s scope extends well beyond banking. Any U.S. person or company conducting transactions subject to U.S. jurisdiction falls under its authority, including:
- Blocking transactions with sanctioned parties and freezing their assets held within U.S. jurisdiction
- Maintaining the SDN list and publishing updates when new designations are added or removed
- Issuing licenses that permit otherwise-prohibited transactions under specific, narrow conditions
- Enforcing sanctions violations, which can carry civil penalties reaching into the millions per transaction, making vendor risk management and compliance a critical compliance priority
For platforms running mass payouts across large contractor or grantee networks, OFAC compliance is not a banking-only requirement. Every disbursement to a payee who appears on the SDN list, or who is located in a fully sanctioned country, is a potential violation regardless of the payment rail used.
OFAC’s Mission and Core Responsibilities
OFAC, the Office of Foreign Assets Control, is a financial intelligence and enforcement agency operating under the U.S. Department of the Treasury. It administers and enforces economic and trade sanctions based on U.S. foreign policy and national security objectives. The agency’s authority is sweeping. OFAC targets foreign governments, regimes, terrorists, international narcotics traffickers, and other threats to U.S. national security by restricting their access to the U.S. financial system. Its core responsibilities include:
- Maintaining the Specially Designated Nationals (SDN) list, which names individuals and entities whose assets are blocked and with whom U.S. persons are generally prohibited from transacting
- Publishing country-level sanctions programs that apply broad restrictions to entire jurisdictions, such as Iran, North Korea, and Cuba
- Issuing licenses that authorize otherwise prohibited transactions on a case-by-case basis
- Investigating potential violations and imposing civil and criminal penalties on non-compliant parties
OFAC is not a division of FinCEN. It operates as a separate office within Treasury, distinct from the Financial Crimes Enforcement Network, though both agencies share overlapping interests in financial crime prevention.
How OFAC Sanctions Programs Work
OFAC runs its sanctions programs through a few distinct mechanisms, each targeting different threats.
Country-based programs restrict entire jurisdictions. As of 2026, fully sanctioned countries include Cuba, Iran, North Korea, and the Crimea, Donetsk, and Luhansk regions of Ukraine. (OFAC lifted comprehensive sanctions on Syria in 2025, though targeted sanctions on Assad-linked individuals and other bad actors remain; Russia is not under a comprehensive embargo but instead faces the sectoral and list-based restrictions described below.) Transactions routed to or through these territories face severe restrictions regardless of who the counterparty is.
List-based programs operate differently. Instead of blocking entire countries, they target specific individuals, entities, and vessels added to the SDN List or other watchlists. A payee in a non-sanctioned country can still trigger a block if their name appears on one of these lists.
Sectoral programs add another layer. These restrict specific industries within a country and not the country as a whole, often targeting energy, finance, or defense sectors in partially sanctioned jurisdictions. For platforms running mass payouts, all three program types create screening obligations:
- Country-based restrictions require geographic filtering at the payee level before any disbursement is queued.
- SDN List screening must run against every payee name, including those outside high-risk regions.
- Sectoral restrictions require understanding the nature of the payee’s business activity, beyond location or identity alone.
Missing any one of these layers isn’t a compliance gap that surfaces quietly. According to the Finance Leader’s Fraud Report 2024, OFAC violations carry civil penalties that can reach into the millions per transaction, and willful violations carry criminal exposure.
The OFAC Sanctions Lists: SDN List, SSI List, and More
OFAC maintains several distinct sanctions lists, each targeting different categories of designated parties. The Specially Designated Nationals and Blocked Persons List (SDN List) is the most widely referenced. It names individuals, entities, and vessels whose assets are blocked and with whom U.S. persons are generally prohibited from transacting. When people search for the “OFAC list,” this is typically what they mean. Beyond the SDN List, OFAC maintains additional list-based programs:
- The Sectoral Sanctions Identifications (SSI) List targets entities in specific sectors of sanctioned economies, such as Russian finance or energy, without imposing full blocking sanctions.
- The Foreign Sanctions Evaders (FSE) List identifies foreign individuals and entities that have violated U.S. sanctions or helped others evade them, which is a key concern when learning how to avoid payment fraud at scale.
- The Non-SDN Palestinian Legislative Council (NS-PLC) List covers members of certain Palestinian legislative bodies under specific legal authorities.
For platforms running mass payouts, the SDN List is the primary screening requirement. A single disbursement to an SDN-listed payee can trigger civil penalties, regardless of whether the match was intentional. At payout volumes of thousands of transactions per cycle, manual cross-referencing against any of these lists is not a viable compliance posture. Platforms need vendor fraud detection and prevention software to keep up.
Who Must Comply with OFAC Regulations
OFAC compliance obligations extend across a wide range of organizations, and the scope is broader than most finance teams assume when they first encounter it. Any U.S. person or entity is subject to OFAC regulations. That includes:
- U.S. citizens and permanent residents, regardless of where they are located in the world
- All U.S.-registered businesses and their foreign branches
- Foreign subsidiaries that are majority-owned or controlled by U.S. parent companies
- Any person or entity physically located within U.S. territory at the time of a transaction
For platforms running mass payouts, your compliance obligation does not stop at the U.S. border. If your marketplace pays creators in Southeast Asia, your gig platform disburses to contractors across Latin America, or your nonprofit routes grant payments to field workers in sanctioned regions, OFAC screening applies to every disbursement in that batch, including those that never touch a U.S. bank account.
Industries with Heightened OFAC Exposure
Certain sectors face more frequent OFAC scrutiny because of their transaction volume, geographic reach, or payee diversity:
- Financial institutions and payment processors are expected to screen every transaction against the SDN List before funds move
- Marketplaces and gig platforms disbursing to large international contractor populations face broad exposure simply because volume creates surface area
- Nonprofits and NGOs disbursing grants to field workers or program recipients in high-risk regions must screen payees even when the mission is humanitarian (see the international payment compliance guide for nonprofits for a deeper look)
- Insurers, freight brokers, and trade finance operators face industry-specific OFAC guidance tied to their transaction types
The common thread is transaction volume meeting geographic diversity. At scale, that combination makes manual screening structurally unworkable. Routable is built for exactly this exposure profile: platforms disbursing to gig workers, creators, marketplace sellers, contractors, and grantees across 220+ countries run OFAC and sanctions screening through the payout orchestration layer itself, so compliance checks scale with disbursement volume without adding headcount to a manual review queue.
What an OFAC Check Is and How It Works
An OFAC check screens a name, entity, or transaction against OFAC’s consolidated sanctions lists before funds move. Screening tools use fuzzy-logic name matching, comparing inputs against the SDN list and other OFAC lists using configurable match thresholds to catch spelling variations, transliterations, and aliases.
What Gets Screened
Most screening workflows check three categories of data against the lists:
- Payee name and any known aliases, since sanctioned individuals frequently appear under multiple name variants across different records
- Country of residence or incorporation, which flags payees located in fully sanctioned jurisdictions like Cuba, Iran, North Korea, Syria, and the Crimea region
- Bank account details and routing information, which can reveal connections to sanctioned financial institutions even when the payee name itself returns no match, a risk covered in depth in the cross-border payments guide
Where OFAC Checks Fit in a Payout Workflow
For platforms running mass disbursements, screening fires before payment initiation. A payee who clears screening at onboarding still needs to clear again at payout, because sanctions lists update without notice. Screening at a single point in the lifecycle is not enough.
Penalties for Violating OFAC Sanctions
OFAC violations carry serious financial and legal consequences. Civil penalties can reach the greater of $368,136 per violation or twice the transaction value, while criminal penalties for willful violations can reach $1 million per violation and up to 20 years in prison.
For platforms running mass payouts at scale, these figures compound fast. A single batch run that processes payments to sanctioned parties without screening doesn’t produce one violation. It produces one per transaction.
Beyond direct fines, OFAC violations can trigger:
- Reputational damage that strains banking relationships and payment processor access, making it harder to operate entirely
- Regulatory scrutiny that pulls in other agencies and expands the scope of any investigation
- Loss of correspondent banking access, which can effectively shut down global payout corridors across 220+ countries your payee network depends on
OFAC does consider whether a violation was voluntary or caused by a compliance failure, which is why documented screening programs matter: they are evidence of good-faith effort when something goes wrong.
Building an OFAC Compliance Program
An effective OFAC compliance program has a few core components that any operator running mass payouts needs in place.
Screening against the SDN List and other OFAC watchlists is the starting point. Every payee must be checked before funds are released, and that screening needs to repeat whenever payee data changes or new sanctions are added.
Beyond screening, your program should cover:
- A clear policy outlining who owns OFAC compliance, what triggers a review, and how potential matches get escalated and resolved
- Ongoing monitoring so new designations are caught between pay cycles, not identified after a disbursement has already cleared
- Record-keeping that documents every screening decision, including how false positives were cleared, in case of a regulatory inquiry
- Training for anyone on your team who touches payee onboarding, payment approval, or exception handling
For platforms disbursing to contractors, gig workers, creators, or grant recipients across multiple countries, manual screening at volume stops being practical past a few hundred payees. At that scale, compliance needs to be embedded into the payout workflow itself, firing automatically before each disbursement and not as a separate offline check. Routable embeds OFAC screening directly into the disbursement cycle, running watchlist checks against 6,000+ global lists at both payee onboarding and pre-payment execution, so the compliance record builds continuously as payments run throughout the year, instead of being managed as a separate review process that stalls batch runs when something surfaces mid-cycle.
OFAC Compliance Inside Mass Payout Infrastructure
For platforms running mass payouts across contractor networks, gig workers, or international grantees, OFAC compliance is baked into every disbursement cycle, not handled as a separate review step.
Every batch run requires screening payees against the SDN list and applicable sanctions programs before funds move. At scale, that screening has to be automated. A manual review queue across thousands of payouts per cycle creates a structural bottleneck that compounds with every new payee added to the network.
There are three areas where OFAC compliance intersects directly with payout infrastructure:
- Screening at onboarding and at payment time: Catching a sanctioned payee during mass payments vendor onboarding prevents the disbursement from ever entering the batch. Waiting until payment execution means a compliance hold stalls the entire run.
- Rescreening on list updates: The SDN list changes. A payee who clears screening on day one may appear on an updated list by the next pay cycle. Infrastructure that rescreens against current list versions on each run closes that gap.
- Blocking and flagging with audit trails: When a match surfaces, the system needs to block the payment, flag the record, and generate a documented audit trail. OFAC expects organizations to show that blocked transactions were identified, held, and reported where required.
Routable handles all three layers as part of the payout orchestration workflow. Every payee is screened against 6,000+ global watchlists (covering OFAC, EU, FTO, and more) at both initial onboarding and immediately before each disbursement fires, going beyond a one-time registration check. When a match surfaces, Routable applies a compliance hold to that individual payee’s payment only: the rest of the batch continues processing uninterrupted, so a single flagged contractor or grantee doesn’t stall disbursements across an entire pay cycle. For platforms disbursing to gig workers, creators, drivers, and grant recipients across 220+ countries, that per-payee hold architecture is what separates a compliance event from a complete platform shutdown.
Final Thoughts on OFAC Sanctions, the SDN List, and Screening at Scale
OFAC compliance covers more ground than a single list check at onboarding. It spans country-based restrictions, SDN screening, and sectoral programs, all of which require ongoing monitoring as designations change between pay cycles. For gig workers, creators, contractors, and grantees spread across multiple countries, that surface area grows with every payee you add. Screening that fires automatically before each disbursement is the only architecture that holds at volume.
See Routable’s built-in OFAC screening in action.
FAQ
What is OFAC, and which government agency is it a division of?
OFAC (the Office of Foreign Assets Control) is a financial enforcement agency that operates under the U.S. Department of the Treasury, not FinCEN or the Department of Justice. It administers economic and trade sanctions by maintaining the Specially Designated Nationals (SDN) list, publishing country-level sanctions programs targeting jurisdictions like Iran, North Korea, and Cuba, and imposing civil and criminal penalties on parties that violate those programs.
What does OFAC compliance require for platforms running mass payouts to contractors, gig workers, or grantees?
Every disbursement in your batch must clear OFAC screening before funds move. That means every payee, every cycle, including payments routed to low-risk countries. Country-based restrictions, SDN list screening, and sectoral program checks each create independent obligations, and a payee who cleared screening at onboarding still needs to clear again at payout because the sanctions list updates without notice.
How does OFAC screening work inside a payout workflow, and what happens when a match surfaces?
OFAC screening uses fuzzy-logic name matching to compare payee names, aliases, country of residence, and bank account details against the SDN list and applicable watchlists before payment initiation. When a match surfaces, the payment is placed on a compliance hold. On infrastructure like Routable’s, that hold is applied to the individual payee’s disbursement only, so the rest of the batch continues processing uninterrupted and does not stall the entire run.
What are the penalties for OFAC sanctions violations, and do they compound across a batch?
Civil penalties can reach the greater of $377,700 per violation or twice the transaction value, and they compound. A single batch run that processes payments to sanctioned parties without screening produces one violation per transaction, not one per batch. Willful violations carry criminal exposure up to $1 million per violation and up to 20 years in prison, which is why documented screening programs matter as evidence of good-faith compliance effort.
What is the difference between the OFAC SDN list and other OFAC sanctions lists like the SSI list?
The SDN list names individuals, entities, and vessels whose assets are fully blocked and with whom U.S. persons are prohibited from transacting; this is the primary screening requirement for mass payout platforms. The Sectoral Sanctions Identifications (SSI) list targets entities in specific industries within sanctioned economies, like Russian finance or energy, without imposing full blocking sanctions. For platforms disbursing to large contractor or grantee networks, SDN screening is the baseline, but sectoral and country-based programs create additional obligations depending on your payee population’s geographic and industry profile.
