How to Prove You Ran an OFAC Check: Documentation and Audit Trails That Satisfy Examiners
Someone Is Asking You to Prove It
You screened a customer, a tenant, a vendor, or a counterparty against the OFAC sanctions lists. Now a bank examiner, a title underwriter, an escrow officer, or the other side's counsel in a deal wants to see the proof. "We checked" is not an answer they can file. They want a record, dated, specific, and reviewable, that shows what you searched, against what, and what came back.
This is where a lot of small and mid-size businesses get caught flat-footed. They have been screening names diligently, but have nothing to hand over except a memory of having done it, or a screenshot that raises more questions than it answers.
Why a Screenshot of a Search Box Is Weak Evidence
A screenshot of a search result feels like proof, but to an examiner or underwriter it usually is not. It is missing the things that make a record credible:
- No timestamp integrity. A screenshot's visible date can be edited, cropped out, or simply absent. There is no way to confirm when the search actually happened.
- No list version. Sanctions lists change constantly. OFAC updates the SDN List multiple times a month. A screenshot does not show which publication of the list was in effect when you searched, so there is no way to confirm the result was current at the time.
- No match parameters. Did the search use fuzzy matching or exact matching? What threshold? A plain screenshot does not capture the settings that determined whether a near-match name would have surfaced.
- No reviewer trail. If the search returned a potential hit, who looked at it and cleared it? A screenshot of a clean result does not show that a human evaluated anything.
None of this means your underlying screening was bad. It means the evidence of it does not hold up on its own. Examiners are trained to ask "how do you know this is real and current," and a screenshot cannot answer that.
What Examiners and Auditors Actually Expect to See
Whether it is a bank regulator, an internal auditor, or a counterparty's diligence team, the expected record looks the same. A defensible screening record includes:
- The name searched, exactly as entered, including any variants or aliases checked.
- The date and time of the search, in a format that cannot be edited after the fact.
- Which lists were checked, and the publication version or date of each list at the time of the search. This matters because "we screen against OFAC" is not specific enough; the question is whether you screened against the list as it existed that day.
- The match threshold or methodology used, so a reviewer can judge how sensitive the search was.
- The result: no match, or a list of potential matches with their match scores.
- Who reviewed the result, and, if there was a potential match, the reasoning for clearing it or escalating it.
If you can produce a document with all six of those elements for a given transaction, you have satisfied the substance of what almost every examiner or underwriter is actually asking for, regardless of the label they put on the request.
What OFAC's Own Recordkeeping Rules Require
This isn't just about satisfying a curious counterparty. OFAC's regulations impose their own recordkeeping obligations. Businesses subject to OFAC's rules must keep records of transactions subject to OFAC regulations, and of any property they block, and those records need to be available for examination.
The retention period got longer recently. Following the 21st Century Peace through Strength Act, signed into law in April 2024, which extended the statute of limitations for IEEPA violations from five years to ten, OFAC updated its own recordkeeping rule to match: general transaction records now need to be retained for at least 10 years, and records of blocked property for at least 10 years after the property is unblocked. If your retention policy still says five years, it is out of date. Build your screening records with a decade of shelf life in mind from the start, not just what you need to answer this week's request.
Who Actually Asks for This, and Why
The request for proof of screening comes from a short list of sources:
- Bank examiners, reviewing your BSA/AML and OFAC program as part of a regulatory exam or, if you are a bank's business customer, as part of the bank's own due diligence on you.
- Lenders, who often require documented proof that you screened a borrower, buyer, or the other parties to a financed transaction against OFAC before they will fund. A mortgage lender asking for proof of an OFAC search wants the same defensible record: name searched, date, lists and versions, and result.
- Title underwriters and escrow officers, who will not close a real estate transaction without documented OFAC clearance on the parties involved.
- Corporate counterparties in deal diligence, checking that the entity or individuals on the other side of a transaction, acquisition, or partnership have been screened.
- Auditors, internal or external, testing whether your compliance program functions the way your written policy says it does.
In every case, the ask is the same: not "did you screen," but "show me." The documentation habits in how to handle a potential OFAC match are the same ones that make this kind of request painless.
Generating an Audit-Ready Record Instead of Assembling One by Hand
You can build this record yourself: run a search, note the date and time, copy down which lists you checked and their version, record the threshold, and write up your review. It works, but it is manual, easy to skip under deadline pressure, and inconsistent from one employee to the next.
OFACScreen's free sanctions search gives you full results with no signup, fine for a quick check. When you need something to hand to an examiner or put in a deal file, the $9.99 audit-ready PDF report is built for exactly that: one search produces one document with the name searched, the date and time, all eight lists checked (OFAC SDN, OFAC Non-SDN Consolidated, BIS Denied Persons, UN Consolidated, EU FSF, UK OFSI, Canada SEMA, and Swiss SECO) with their versions, the match parameters, and the result. It is the difference between reconstructing evidence after the fact and having it the moment the search runs.
Documenting Cleared False Positives
Most hits on a fuzzy-match search are false positives: a common name, a partial match, no other identifying details in common. That is normal and expected. What matters for your audit trail is not that you had zero hits, it is that you can show your reasoning for clearing the ones you had.
For every potential match you clear, write down what you compared (name, date of birth, address, ID numbers, aliases), why it did not hold up as a true match, who made that call, and when. A clean search with nothing to explain looks fine on paper. A cleared hit with no explanation looks like a gap, even if the underlying decision was correct. The reasoning trail turns "we looked at it" into something an examiner can verify without taking your word for it.
Batch and API Screening: What to Retain Automatically
If you are screening at volume, whether through batch uploads of your customer or vendor database, or through the REST API wired into your onboarding flow, you cannot document each search by hand. At that scale, your system needs to log, automatically, for every screening event:
- The input data submitted (name and any identifying fields)
- A timestamp for each individual screen, not just the batch job
- The list versions in effect at run time
- Every match returned and its score
- The disposition: cleared automatically below threshold, or escalated for human review
- For escalated items, who reviewed them and the outcome
OFACScreen's batch and API screening on paid plans logs this by default, so the same record standard applies whether you screened one name manually or ten thousand names overnight. That consistency is what an auditor is checking for: not just that high-volume screening happened, but that it left the same kind of trail a single manual search would.
Sample Documentation Checklist
Copy this into your compliance file as a template for each screening record you need to be able to produce:
- [ ] Full name (and variants/aliases) searched
- [ ] Date and time of search
- [ ] Lists checked and their publication version or date
- [ ] Match threshold or methodology used
- [ ] Search result (no match, or list of potential matches with scores)
- [ ] For any potential match: identifying details compared, reasoning, and reviewer
- [ ] Determination and action taken (cleared, escalated, blocked)
- [ ] Name of reviewer and date of review
- [ ] Record retained per your retention policy (at least 10 years for OFAC-regulated transactions and blocked property)
If every screening record in your file checks all nine boxes, you are not just compliant on paper, you are ready for the next time someone asks you to prove it.
Start Screening Against OFAC Today
14-day free trial. No credit card required. Screen against OFAC SDN, Non-SDN, BIS, and more.
Start Free Trial