Sanctions data updated hourly

Industry Guides

OFAC Compliance for Banks and Credit Unions

The Highest Standard

Banks and credit unions face more scrutiny on OFAC compliance than any other type of business. Federal and state examiners evaluate your OFAC program regularly, and deficiencies can lead to enforcement actions, consent orders, and significant penalties. If you are a compliance officer at a bank or credit union, OFAC screening is one of your most important responsibilities.

BSA/AML and OFAC: Two Programs, One Goal

Most banks and credit unions manage OFAC compliance alongside their Bank Secrecy Act and Anti-Money Laundering (BSA/AML) program. While BSA/AML and OFAC are technically separate regulatory frameworks, they share common goals and are usually examined together.

Your BSA/AML program focuses on detecting and reporting suspicious activity. Your OFAC program focuses on ensuring you do not process transactions with sanctioned parties. In practice, the same team often manages both, and many of the same controls apply.

When to Screen

Banks and credit unions should screen at multiple points:

  • Account opening: Screen all new customers before establishing a relationship.
  • Wire transfers: Screen originator and beneficiary names for all outgoing and incoming wires.
  • ACH transactions: Screen names on ACH originations and, depending on your risk profile, incoming ACH credits.
  • Loan origination: Screen borrowers, co-borrowers, guarantors, and any other parties to the transaction.
  • Ongoing monitoring: Rescreen your entire customer base when OFAC updates its lists.

The frequency and scope of your screening should be documented in your OFAC policy and should reflect your institution's risk profile.

The Five Pillars of BSA/AML Compliance

Examiners evaluate your OFAC program in the context of the five pillars of BSA/AML compliance:

  1. A system of internal controls. Written policies and procedures that govern your OFAC screening process.
  2. Independent testing. Regular audits or reviews of your OFAC program by someone who does not manage it day to day.
  3. A designated BSA/OFAC officer. Someone with the authority and knowledge to oversee the program.
  4. Training. All relevant staff should receive OFAC training at least annually.
  5. Customer due diligence (CDD). Know your customers, including beneficial owners of legal entity accounts.

What Examiners Look For

During an examination, regulators will typically:

  • Review your written OFAC policy and procedures
  • Test a sample of transactions to verify screening was performed
  • Ask how you handle potential matches and false positives
  • Review your screening software and matching methodology
  • Check that your sanctions data is current
  • Evaluate your training program and documentation

Examiners want to see that your program is risk-based, well-documented, and consistently followed. A small community bank is not expected to have the same program as JPMorgan, but you are expected to have a program that is appropriate for your size and risk profile.

Choosing Screening Software

Most banks and credit unions use third-party screening software rather than trying to screen manually. When evaluating tools, look for accurate fuzzy matching, current sanctions data, clear audit trails, and the ability to integrate with your core banking system.

OFACScreen is built for community banks and credit unions that need reliable OFAC screening without the complexity and cost of enterprise platforms. We offer single-name searches, batch screening, and API access, with all results logged for examiner review.

Start Screening Against OFAC Today

14-day free trial. No credit card required. Screen against OFAC SDN, Non-SDN, BIS, and more.

Start Free Trial