OFAC Enforcement Trends in 2025: What Compliance Teams Should Watch
OFAC's enforcement activity picked up in 2024 and shows no signs of slowing down. A few trends stand out.
Smaller Companies, Bigger Penalties
OFAC used to focus enforcement primarily on large financial institutions. That's changed. Recent actions have targeted payment processors, fintechs, and companies with fewer than 100 employees. The penalty amounts haven't scaled down with the company size, either. A small business can face six-figure penalties just as easily as a large bank.
The takeaway: "we're too small for OFAC to care about" is not a safe assumption.
Crypto Enforcement Is Real
OFAC has added cryptocurrency wallet addresses to the SDN list and has brought enforcement actions against exchanges that processed transactions involving sanctioned persons. If your business touches crypto in any way, you need a sanctions screening process that covers it.
Voluntary Self-Disclosure Gets Rewarded
OFAC's enforcement guidelines give significant credit for voluntary self-disclosure (VSD). Companies that discover a potential violation and self-report it to OFAC receive substantially reduced penalties compared to those that get caught. In some cases, OFAC has issued "no action" letters for self-disclosed violations by companies with otherwise strong compliance programs.
This only works if you have the monitoring and detection capabilities to discover violations in the first place. You can't self-disclose what you don't know about.
Russia Sanctions Keep Getting More Complex
The Russia-related sanctions programs have expanded significantly since 2022. The Sectoral Sanctions Identifications (SSI) list has grown, and the 50% rule (where entities owned 50% or more by a sanctioned party are themselves sanctioned even if not listed) makes screening harder. A name might not appear on any list but still be sanctioned by ownership.
For businesses with any Russian exposure, this means screening alone isn't enough. You also need to understand ownership structures.
What To Do About It
- Screen against all relevant lists, not just the SDN list. The Non-SDN, SSI, and international lists carry their own obligations.
- Monitor continuously. One-time screening at onboarding does not protect you when lists get updated weekly.
- Keep audit trails. If you do face an enforcement inquiry, documented screening records are the single most important thing you can show OFAC.
- Have a self-disclosure plan. Know who at your company is responsible for reporting potential violations and what the process looks like.