How Often Should You Run OFAC Screening? Rescreening Frequency by Risk Level
A Clean Result Has an Expiration Date
You screened a customer at onboarding, got no match, and moved on. That result was accurate the moment you ran it, not a guarantee about next week. OFAC adds and removes names from the Specially Designated Nationals (SDN) List and the other sanctions lists with no fixed publication calendar, and in practice that means changes land multiple times a week, sometimes multiple times a day when a new sanctions program rolls out. Someone who searched clean on Monday can be a designated party by Wednesday, and nothing about your original search was wrong. It just went stale.
This is the part of OFAC compliance that trips up businesses who treat screening as a one-time gate at signup. You do need to rescreen existing customers, not just clear them once: the gate matters, but sanctions screening is not a task you finish. It is a task you schedule.
How Often Does the OFAC List Actually Update?
OFAC's own guidance is direct about this: there is no predetermined timetable for updating the SDN List. Names are added, removed, or edited as designations happen, on the government's timeline, not yours. In active periods, such as a new executive order or a fast-moving geopolitical event, multiple updates in a single week is normal, not exceptional.
Because there is no fixed schedule from OFAC's side, the burden shifts to you: OFAC expects institutions to set their own download and rescreening cadence based on their own risk assessment, and to revisit that cadence periodically to confirm it still works. "We screen against OFAC" is not a complete answer without "and here is how often we check for updates."
There Is No Single Legally Required Frequency
People searching for a rescreening rule are usually hoping for a number: screen every 30 days, or every 90. No regulation states one. Examiners and auditors instead look for a written, risk-based schedule you can explain, matched to the risk of what you are screening. A bank moving wire transfers and a one-person consulting shop that occasionally signs a new client are not held to the same cadence, and neither should try to copy the other's.
What you cannot defend is having no schedule, or a schedule that exists on paper but does not match what actually happens. If your compliance manual says "monthly rescreening" and your last rescreen was eight months ago, that gap is worse in an exam than a looser but honestly-followed policy.
Recommended Rescreening Tiers by Risk Level
These tiers are a starting point, not a mandate. Adjust them to your actual exposure, but the logic behind each one is what an examiner will expect you to articulate.
- Real-time, at onboarding and at transaction: everyone. Screen a new customer, vendor, tenant, or counterparty before you do business with them, and again at the point of any transaction moving money or property. This is the non-negotiable floor.
- Daily, or on every list update: financial institutions and other high-risk businesses. Banks, money services businesses, fintechs, and anyone processing payments at volume should rescreen the active customer base against the current list version, ideally the same day OFAC publishes a change. This is the tier where automation stops being a convenience and becomes the only realistic way to keep pace.
- Monthly or quarterly: lower-risk customer bases. A business with a stable, low-turnover customer list and low individual transaction risk, for example a local service business or long-term B2B vendor relationships, can typically defend a monthly or quarterly sweep of the full customer file rather than continuous monitoring.
- Event-driven: one-off deals and infrequent counterparties. For a single real estate closing, an M&A counterparty, or a one-time vendor contract, the right cadence is a screen at the point of the deal, not a recurring schedule. The question becomes which events trigger a re-check.
Trigger Events That Demand an Immediate Rescreen
Independent of whatever recurring schedule you run, these events should trigger an off-cycle screen right away, for every risk tier:
- A new sanctions program is announced. Major geopolitical events, a new executive order, or a newly designated country or sector program are exactly when OFAC's list activity spikes. Do not wait for the next scheduled run.
- A customer's identifying details change. A legal name change, new registered address, ownership change, or updated identification documents mean the record you screened before is no longer the record you have now.
- A dormant account or relationship reactivates. The longer an account sat inactive, the more list updates happened while nobody was checking. Reactivation is a natural checkpoint to rescreen before activity resumes.
- Beneficial ownership changes. You may have cleared an entity and its prior owners, but a new beneficial owner is a new party who has never been screened.
A defensible program treats these as automatic triggers written into policy, not judgment calls left to whoever happens to notice.
Point-in-Time Checks vs. Continuous Monitoring
These solve different problems, and conflating them is a common mistake.
Point-in-time screening is a single search run at a specific moment: onboarding, closing a deal, reactivating an account. It is cheap, fast, and easy to document, but coverage ends the second the search completes. It is fully defensible for the moment it covers and says nothing about the day after.
Continuous monitoring means your customer base is checked automatically every time the list changes, without someone manually initiating each search. It costs more to set up and typically requires an integration, but it is the only approach that closes the gap between screening events. Regulators generally expect this tier from financial institutions and other high-volume businesses, because a static customer base under continuous list changes needs continuous coverage to stay current.
Most businesses run both: point-in-time checks at the moments that matter most, layered under a continuous or near-continuous sweep of the existing base.
How to Implement Each Tier
The right tool depends on the tier, not the other way around:
- Event-driven, one-off checks: a manual search at OFACScreen's free sanctions search covers this well, full results against all eight lists we screen (OFAC SDN, OFAC Non-SDN Consolidated, BIS Denied Persons, UN Consolidated, EU FSF, UK OFSI, Canada SEMA, and Swiss SECO), no signup required.
- Periodic sweeps of an existing customer or vendor file: upload the whole list at once rather than searching names one at a time. See batch screening best practices for structuring a recurring sweep so it is repeatable, not a manual chore each time.
- Daily or on-update automated rescreening: this is where an API or MCP integration earns its place. Wiring screening into your onboarding flow and customer database means new signups are screened the moment they arrive and the existing base is rescreened automatically whenever the underlying lists change, without anyone kicking off each run by hand.
Document the Schedule, Not Just the Searches
Two separate things belong in your compliance file, and businesses often only keep one.
First, document the schedule itself: what tier each part of your customer base falls into, why, how often each tier gets rescreened, and what events trigger an off-cycle check. This is what an examiner reads first to gauge whether you have a program or just a habit.
Second, document each individual run. A dated, itemized record proves the schedule was actually followed, not just written down. OFACScreen's one-time $9.99 audit-ready PDF report gives you exactly that kind of point-in-time proof, the name searched, the date, all eight lists and their versions, and the result, so each rescreen leaves its own paper trail instead of you reconstructing one later.
When Stale Screening, Not Missing Screening, Caused the Violation
OFAC's enforcement history includes cases where the failure was not that a company never screened, it was that its screening did not keep pace. In 2021, OFAC settled with MoneyGram Payment Systems over hundreds of apparent violations tied in part to screening and technology failures: even while MoneyGram was screening transactions, gaps in how that screening operated let transactions to blocked individuals through anyway. The lesson generalizes: a screening program that exists but does not run often enough, or does not catch up with list changes fast enough, exposes a business to the same category of violation as having no program at all. See OFAC penalties and enforcement for how OFAC weighs these failures.
Regulators are not grading you on effort. They are grading you on whether your screening, as actually run, was current when it mattered. A defensible, written, risk-based rescreening schedule, matched by dated proof that you followed it, turns "we screen for OFAC compliance" from a claim into something you can put in front of an examiner.
Start Screening Against OFAC Today
14-day free trial. No credit card required. Screen against OFAC SDN, Non-SDN, BIS, and more.
Start Free Trial