OFAC Compliance for Small Businesses: A Practical Checklist
Why Small Businesses Need an OFAC Program
Many small business owners assume OFAC compliance is only for big banks and multinational corporations. That assumption is wrong, and it can be expensive. OFAC regulations apply to all US persons and businesses, regardless of size. The agency has penalized small companies, and the fines can be devastating for a business without deep pockets.
The good news is that building a basic OFAC compliance program is straightforward. Here is a practical checklist you can follow.
Step 1: Designate a Compliance Officer
Someone in your organization needs to own OFAC compliance. For a small business, this does not have to be a full-time role. It can be the CFO, the operations manager, or anyone with enough authority to make decisions and enough attention to detail to follow through. The important thing is that someone is responsible.
Document who this person is, what their responsibilities include, and who backs them up when they are out of the office.
Step 2: Write a Compliance Policy
You need a written policy that describes your OFAC screening procedures. It does not have to be long or complicated. At minimum, it should cover:
- When you screen (new customers, ongoing transactions, periodic rescreening)
- What lists you screen against
- Who is responsible for reviewing potential matches
- What happens when a true match is found
- How you document your screening activity
Step 3: Implement Screening
You need to screen names against OFAC's SDN List and, depending on your industry, potentially other lists as well. There are three ways to approach this:
- Manual screening: Searching names on OFAC's website one at a time. This is free but slow, hard to document, and not practical for more than a handful of checks.
- Spreadsheet-based screening: Downloading the SDN List and running your own comparisons. This is slightly better but still error-prone and misses fuzzy matches.
- Screening software: Using a tool like OFACScreen to automate the process. This is the most reliable approach, and for businesses doing more than a few checks per month, it is well worth the cost.
Step 4: Screen at the Right Times
At minimum, you should screen:
- At onboarding: Before you open an account, issue a policy, or begin a business relationship.
- Before transactions: Especially high-value or unusual transactions.
- On a regular schedule: Rescreen your existing customer base periodically. Monthly is a common frequency, but the right cadence depends on your risk profile.
- When lists are updated: New names are added to the SDN List frequently. Rescreening after updates ensures you catch new designations.
Step 5: Document Everything
Regulators and examiners want to see documentation. Keep records of every screening you perform, every potential match you investigate, and every decision you make. OFACScreen automatically logs all screening activity, which makes this step easy.
Step 6: Train Your Staff
Your employees need to understand what OFAC is, why screening matters, and what to do if they encounter a potential match. Training does not need to be elaborate. A 30-minute annual session covering the basics is a good starting point. Document your training sessions, including who attended and what topics were covered.
Step 7: Review and Update Annually
Your compliance program should not be static. Review it at least once a year. Update your policies if your business changes, if regulations change, or if you identify gaps. An annual review shows regulators that you take compliance seriously.
Getting Started
If you do not have an OFAC compliance program today, do not let the perfect be the enemy of the good. Start with the basics on this checklist, and improve over time. OFACScreen can help you get screening up and running quickly, with plans starting at $49 per month.
Start Screening Against OFAC Today
14-day free trial. No credit card required. Screen against OFAC SDN, Non-SDN, BIS, and more.
Start Free Trial