How often to rescreen customers against sanctions lists, what to screen beyond names, and a cadence that holds up under OFAC strict liability.
Screen every customer at onboarding, rescreen the whole customer base each time a sanctions list changes, and screen the parties and wallet addresses on every transaction before it settles. Scope covers individuals, businesses, beneficial owners, counterparties, and blockchain addresses. Batch rescreening on a fixed calendar leaves gaps of weeks, and OFAC liability is strict.
This article is general information, not legal advice. Sanctions obligations depend on where you operate and who your customers are, so confirm yours with counsel.
Key takeaways
Sanctions screening is one of the four parts of an automated risk monitoring program. This guide covers its two big decisions: how often to screen, and what to screen.
Because sanctions lists change after the customer signs up, and OFAC liability does not depend on whether you knew. A customer cleared in January can be designated in March, and every payment after that date is exposed.
The Office of Foreign Assets Control (OFAC), part of the US Treasury, is direct about the standard. Its sanctions compliance guidance for the virtual currency industry says OFAC may impose civil penalties "based on a strict liability legal standard," meaning a US person can be held liable "even without having knowledge or reason to know" of the violation. OFAC weighs the facts of each case, but "we screened them at signup" does not make the payment legal.
The same guidance notes that the Specially Designated Nationals and Blocked Persons List (SDN List) "is frequently updated." OFAC posts each change on its Recent Actions page, and sanctions-related actions there often land several times a month.
So the question is not whether to rescreen. It's how fast you pick up a change, and what you rescreen when you do.
At minimum, the OFAC lists for any business with a US nexus, plus the UN, EU, and UK lists wherever you or your customers operate. PEP and adverse media sources feed risk rating rather than blocking decisions.
| List | Who it applies to | Why it matters | Typical screening trigger |
|---|---|---|---|
| OFAC SDN List | US persons and transactions touching the US financial system | Listed parties are blocked; dealing with them is prohibited | Onboarding, every list update, every transaction |
| OFAC non-SDN consolidated lists | US persons | Narrower prohibitions on specific dealings, not full blocking | Onboarding, every list update, every transaction |
| UN Security Council Consolidated List | UN member states, through national law | Base layer that many national lists implement | Onboarding, every list update |
| EU consolidated financial sanctions list | EU persons and business done in the EU | Asset freezes and prohibitions across member states | Onboarding, every list update, every transaction |
| UK Sanctions List | UK persons and business done in the UK | Financial sanctions enforced by the Office of Financial Sanctions Implementation (OFSI) | Onboarding, every list update, every transaction |
| Politically exposed person (PEP) databases | Firms following FATF Recommendation 12 | PEPs are allowed but need enhanced due diligence | Onboarding, periodic review, data change |
| Adverse media | Risk-based, no single legal list | Early signal of fraud, corruption, or pending designation | Onboarding, periodic review |
Lists overlap but don't match, so a US-only screen is not enough for a business with EU customers. And PEP is not a sanctions category. A PEP match means more questions, as the FATF guidance on politically exposed persons lays out, not a refused payment.
Rescreen the full customer base every time a list you rely on changes, and screen parties at transaction time before settlement. Fixed calendar batches, monthly or quarterly, are better than nothing and worse than both.
| Approach | What it catches | What it misses | Risk level |
|---|---|---|---|
| Onboarding only | Parties already listed at signup | Every designation after signup | High |
| Periodic batch, quarterly | Designations up to the last run | Up to three months of new designations and the payments made in between | High |
| Periodic batch, monthly | Designations up to the last run | Up to a month of new designations | Medium to high |
| On every list update | New designations, across the whole base, as soon as the update is ingested | Changes on the customer side between updates, such as a new owner or wallet | Low to medium on its own |
| On every transaction | Parties and addresses at the moment money moves | Dormant customers who hold balances but don't transact | Low to medium on its own |
| List update plus transaction plus data change | New designations, new counterparties, and changed customer data | Very little, if matching is tuned | Lowest |
The combination wins because each method covers the other's blind spot. List-update screening finds the customer who became a match while doing nothing. Transaction screening finds the new counterparty or wallet that was never in your customer base. Data-change screening catches the new beneficial owner who joined after KYB.
For stablecoin flows, transaction-time screening has to run before settlement. A confirmed on-chain transfer can't be reversed, so a match found afterward is a report, not a control.
Screen every party whose property or interest is in the payment: the customer, the people who own and control a business customer, the counterparty, and the wallet addresses involved. A name-only screen of the account holder misses most of the ways a sanctioned party actually shows up.
Individuals. Full legal name, plus date of birth, nationality, and address as secondary identifiers.
Businesses. Legal name, trade names, registration number, and registered address. Screen former names too.
Beneficial owners and controllers. OFAC's 50 percent rule guidance treats an entity as blocked when blocked persons own 50 percent or more of it, directly or indirectly, individually or in aggregate. The company's own name may appear on no list. Only screening the owners, as collected during KYB, catches it.
Counterparties. The beneficiary of a payout or the sender of a payin, plus their bank or provider where you have it. A clean customer paying a listed supplier is still a prohibited dealing.
Wallet addresses. OFAC first listed digital currency addresses on SDN entries on November 28, 2018, for two Iran-based individuals. Its FAQ 562 says those address listings are "not likely to be exhaustive." Screen addresses against the list, then score their exposure to sanctioned actors through blockchain analytics. The crypto wallet compliance checklist covers address screening in more depth.
Fuzzy matching compares names by similarity, not exact spelling, and secondary identifiers decide whether a similar name is the same person. Exact matching is cheaper to run and misses too much.
Exact matching fails on transliteration (Mohammad, Mohammed, Muhammad), word order, dropped middle names, and alternate country spellings. OFAC's Framework for OFAC Compliance Commitments lists both failure modes among the root causes of past violations: screening software not updated for SDN List changes, and screens that did not account for alternative spellings, such as Habana for Havana.
Fuzzy matching fixes recall and creates noise. The fix for the noise is not a looser threshold. It's a second check before an alert reaches a person:
When an analyst clears a match, the record should say what matched, which list entry and list version, which identifiers were compared, the decision, who made it, and when. That record lets you suppress the same alert next time, but only while both the customer data and the list entry stay the same. If either changes, the pair goes back through the screen. A suppression that outlives its facts is how a real match gets waved through.
Define the scope, load the lists as events, screen on three triggers, and hold before settlement. The steps:
A sanctions hold is one of the transaction monitoring red flags a system scores before money moves.
Illustrative example. The names, dates, and amounts below are invented to show the mechanics.
A logistics company in Mexico passes KYB on January 12. It has two owners: one holds 60 percent, the other 40 percent. Neither owner, nor the company, is on any list. Clean.
On March 18, OFAC adds the 60 percent owner to the SDN List. The company's name appears nowhere in the update. Under the 50 percent rule, it is now blocked anyway.
With quarterly batch screening. The next run is April 1. Between March 18 and March 31, the company sends six payouts totaling USD 84,000. Each one is a dealing with a blocked entity, and the April run finds the match only after the money is gone.
With list-update screening. The March 18 update loads that afternoon. The rescreen matches the owner's name, then confirms on date of birth and nationality. Because owners are in scope, the match rolls up to the company. Its account is frozen and the payout queued for March 19 is held before settlement. Compliance confirms the match, blocks the funds, and files the report to OFAC.
Same customer, same list. The difference is when the screen ran and whether owners were in it.
Most failures come from screening too rarely or too little:
BlindPay runs KYC, KYB, sanctions screening, and transaction monitoring inside the API flow, before money moves. BlindPay is registered with FinCEN as a money services business, and its registrations are on the licenses page.
Customers are verified before their first transaction: KYC Standard is automated and takes about 60 seconds, while KYC Enhanced and KYB Standard are manual reviews that take 3 hours to 1 business day. Entities or individuals on OFAC, EU, UN, or other sanctions lists are not supported, per the prohibited activities list. Creating a customer or bank account in a prohibited country fails outright, with no override.
A sanctions or watchlist match on a payment is one of the documented compliance hold triggers. The payin or payout moves to on_hold for manual review. A hold can last up to 30 days: approval resumes the normal flow, and a timeout without a decision fails the transaction.
Pull three facts from your current setup: the date of your last full-base rescreen, the list version it used, and whether owners and wallet addresses were in scope. If the rescreen ran on a calendar instead of on a list update, or owners weren't in it, fix that before anything else. Then sample 20 cleared matches and check that each one has a written reason.
This article is general information, not legal advice.
The evidence examiners expect from automated risk monitoring: a 10-item evidence table, good vs poor practice, SAR timelines, RFIs, and a 30-day plan.
Blockchain payments are legal for businesses in the US, EU, UK, Brazil, and Mexico, under different rules. What each country regulates, as of October 2026.
Stablecoin transfers settle final in minutes and cannot be reversed. That finality proves custody at every step, but it also opens a fraud gap on the fiat side of the payment.