Peak AML

Sanctions

How to Screen a Customer Against OFAC

OFAC screening is more than typing a name into a search box. A defensible sanctions control collects enough information to distinguish the customer, screens against relevant sanctions data, investigates potential matches, documents the decision, and escalates genuine concerns before prohibited activity occurs.

Updated September 1, 2026 · Educational information, not legal advice.

1. Collect enough identifying information

Begin with reliable customer or counterparty information. A name alone can create large numbers of false positives, especially for common names. Depending on the relationship, useful identifiers can include date of birth, nationality, address, country, aliases, entity registration information, and identification numbers.

2. Run sanctions screening

Screen the customer using a sanctions-screening process appropriate to your business. U.S. businesses commonly need controls designed around OFAC sanctions, while international operations may need additional lists or jurisdiction-specific controls.

Screening systems often use fuzzy matching because sanctioned names can have spelling variations, transliterations, aliases, or incomplete data. That means the system may intentionally return possible matches that require human review.

3. Investigate potential matches

A potential match is not automatically a true match. Compare the customer's identifiers with the sanctions record. Look for both confirming and conflicting information: date of birth, geography, citizenship, addresses, aliases, entity ownership, and other available identifiers.

Do not clear a meaningful alert solely because the spelling is slightly different. Conversely, do not reject a customer solely because a common name resembles a listed person.

4. Document the disposition

The compliance record should explain why an alert was cleared or escalated. Record the information reviewed, the relevant list entry, distinguishing identifiers, reviewer, date, and conclusion. This creates evidence that the control was actually performed rather than merely configured.

5. Escalate possible true matches

If available information does not reasonably resolve the match, stop and follow the company's sanctions escalation procedure. Depending on the facts, that can include senior compliance review, legal counsel, the financial institution involved, or contact with OFAC. Do not proceed with a potentially prohibited transaction simply to meet an operational deadline.

6. Consider ongoing screening

Sanctions lists and customer circumstances change. Businesses with continuing customer relationships should determine whether periodic or event-driven rescreening is appropriate for their risk profile. Screening at onboarding alone may not identify a customer who becomes designated later.

Where PeakAML fits

PeakAML provides a workflow for sanctions and PEP screening, review of potential matches, and retention of screening evidence. Your organization remains responsible for deciding which lists, frequency, thresholds, escalation rules, and legal requirements apply to its activities.

Put the workflow into practice

Create a PeakAML account at no cost, then choose the compliance products your business needs.

Create free account

Peak AML provides compliance advisory support and optional technology. Information and services provided through this website do not constitute legal advice. Customers remain responsible for their regulatory obligations, filings, policies, and compliance decisions.