OFAC is the U.S. Treasury's Office of Foreign Assets Control, the body that administers economic sanctions and requires banks to block property or reject transactions involving sanctioned persons, countries, and entities. Its enforcement history includes 1,071 actions totaling about $7.9 billion since 2003, including a $30 million Wells Fargo penalty and a $968,618,825 Binance action shown on OFAC's 2023 enforcement page: OFAC enforcement information.
You may learn what OFAC means because a routine USD payout has just stopped. Your payment partner says the beneficiary resembles an SDN, asks for ownership documents, or returns the wire without giving your operations team a clear explanation. From your side, the payment looked ordinary. Inside the bank, it entered a sanctions-control process designed to decide whether funds can move at all.
That's the practical answer to what is OFAC in banking. OFAC isn't a website containing a list of prohibited names. It's the U.S. sanctions authority whose rules become operational decisions across onboarding, payment processing, account monitoring, correspondent banking, and digital-asset settlement. The bank must determine whether a person or entity is blocked, whether ownership makes an apparently clean company blocked, and whether a license permits an otherwise restricted activity.
Table of Contents
Why OFAC Matters the Moment You Move Money
At 3 p.m., a fintech operations lead sees a routine USD payout return with the status “sanctions review.” The beneficiary's legal name resembles an entry on the Specially Designated Nationals and Blocked Persons List, commonly called the SDN List. The payment provider pauses the transfer, requests more information, and may limit the explanation because detailed screening logic could help someone bypass the control.
The invoice may be legitimate. The bank still has to answer a different question first: would processing the payment place funds, or an interest in property, at the disposal of a blocked person? Could the transfer facilitate activity restricted by a sanctions program? Until those questions are resolved, the commercial purpose of the invoice does not settle the payment decision.
That is the practical meaning of what is OFAC in banking. OFAC's rules become decisions inside the bank's systems, from customer onboarding to payment processing, account monitoring, correspondent banking, and digital-asset settlement. A bank must assess names, locations, counterparties, ownership, payment instructions, and any license that could permit an otherwise restricted activity.
OFAC administers sanctions that can restrict dealings connected with an entire jurisdiction or program, as well as selective sanctions aimed at named people, companies, vessels, aircraft, or activities. The Federal Financial Institutions Examination Council's OFAC guidance describes controls that may combine manual review with interdiction software. It also expects institutions to define how OFAC list names are compared with customer records and payment instructions.
Why the payment can stop before an investigation begins
An enforcement action may follow a lengthy review. A screening decision occurs inside the payment workflow, often before settlement. OFAC risk therefore reaches the bank first as a real-time operating question, not as a later courtroom event.
A USD route can create a U.S. compliance touchpoint through a correspondent bank, payment processor, ACH network, wire intermediary, or digital-asset service tied to U.S. financial infrastructure. A foreign company can face practical OFAC constraints even without being incorporated in the United States. Its payment access may depend on a partner's sanctions policy and contractual duties.
Practical rule: Treat every blocked payment as a control signal. Do not retry it with a different description, intermediary, or wallet. Establish whether the result is a false positive, a blocked counterparty, an ownership issue, or a transaction that may be licensed.
The bank's review usually connects three operational layers. Onboarding identifies the customer and investigates ownership. The transaction engine checks the parties and payment data as the wire is prepared. Ongoing rescreening checks whether a later list change, ownership discovery, or regime update changes the risk. A customer that passed onboarding can therefore trigger review months later, before one payment moves.
The Origins and Reach of OFAC
A wire can enter review even when no one at the bank suspects fraud. The reason may be a sanctions program whose scope, target, or licensing conditions changed after the customer was onboarded. OFAC's modern identity began in December 1950, after President Truman declared a national emergency during the Korean War and blocked Chinese and North Korean assets subject to U.S. jurisdiction. The U.S. Treasury's history of OFAC traces the office's development from emergency economic controls into a system that turns foreign-policy and national-security decisions into restrictions on property, payments, trade, and account activity.
Those authorities have expanded over time. Congress can create or modify sanctions through legislation, while presidential emergency powers can produce rapid changes in response to international events. Banks therefore work with a collection of programs, each with its own targets, prohibitions, licenses, and reporting expectations, rather than one permanent rulebook.
A useful operating distinction is:
- Restrictions: These can broadly limit transactions connected with a jurisdiction or sanctions program, subject to applicable exceptions and licenses.
- Selective restrictions: These target named individuals, entities, vessels, aircraft, sectors, or activities. A payment can be prohibited even when the country itself is not broadly restricted.
- Licensing exceptions: OFAC may authorize defined activities through general or specific licenses. The bank must confirm that the transaction fits the authorization before releasing funds.
The same country can therefore require different handling at different times. A named SDN may create a blocking obligation. A country program may require rejection rather than blocking when no blocked property is involved. A general license may permit an activity that would otherwise be restricted, but only under its stated conditions.

OFAC also maintains SDN-list history reaching back to 1994. That history shows why a bank's controls must do more than store the latest file. They need to preserve screening evidence, identify what changed, and show how the institution handled a customer or payment after a designation was added, removed, or amended, as documented in the Treasury's OFAC overview. Regime changes can force the bank to remap customers, ownership, products, and payment routes, not rerun a name check.
How the SDN List and the 50 Percent Rule Work
The SDN List is a key input into sanctions screening. It contains designated people and organizations, and OFAC also identifies sanctioned vessels and aircraft. A screening engine compares names and related details from the list with customer files, payment instructions, and other records. The comparison cannot rely only on exact spelling because legal names may contain aliases, transliterations, abbreviations, or formatting differences.
A likely match isn't automatically a confirmed sanctions hit. The bank's investigator compares additional information, such as address, registration details, date of birth, incorporation information, account data, and the payment's commercial context. A name match with no supporting identifiers may be a false positive. A weaker name match combined with matching ownership or location information may require escalation.
The ownership puzzle
The 50 Percent Rule creates the most important gap between list screening and sanctions analysis. OFAC treats property and interests in property of an entity as blocked when one or more blocked persons own 50 percent or more in aggregate, directly or indirectly. The entity doesn't need to appear by name on the SDN List, as explained in OFAC FAQ 401.
Consider a simple structure:
- A blocked person owns half of Holding Company A.
- Holding Company A owns half of Operating Company B.
- The bank receives a payment instruction naming Operating Company B, which isn't listed.
- The bank must still examine whether the blocked person's indirect ownership makes B subject to the rule.
The analysis becomes harder when several blocked persons hold separate interests, when ownership passes through parent companies, or when a joint venture sits inside a layered corporate structure. That's why beneficial-ownership information must be connected to entity-resolution tools. A name-screening engine can flag the legal name, but it can't reliably solve an ownership graph without structured ownership data and analyst review.
Blocked, rejected, or authorized
Banks also need a disposition decision. If a transaction involves blocked property, the institution may need to block the funds. If the underlying activity is prohibited but there's no blockable interest, the institution may reject it. If a general or specific license applies, the bank must verify the conditions and document why the transaction is permitted.
That distinction affects correspondent banking, trade finance, treasury transfers, and digital-asset settlement. A clean-looking beneficiary isn't enough. The bank needs confidence in the entity's ownership, the transaction's purpose, the parties in the payment chain, and any applicable license.

Inside a Bank's OFAC Screening Stack
A payment partner can block a wire even when the beneficiary's name looks clean. The bank's controls operate through three connected layers, each asking a different question. Clearing one layer does not guarantee approval at the next.
Layer one, customer onboarding
At account opening, the institution gathers identity and business information, including the legal name, registered address, formation details, identification documents, directors, and beneficial owners. It screens the customer and relevant owners against sanctions data, then investigates possible matches before activating the relationship.
The 50 Percent Rule makes ownership a customer-risk issue, not only a payment issue. If a bank accepts a company without understanding its ownership chain, a later transaction may expose a weakness that began during KYB. Teams designing this process can compare it with broader AML and KYC procedures, while keeping sanctions decisions separate from ordinary identity checks because blocking, rejection, and licensing may apply.
Layer two, transaction screening
When a payment enters processing, the bank reviews the information attached to the instruction. That may include the originator, beneficiary, sending and receiving institutions, intermediary institutions, addresses, free-text payment details, and other relevant parties. Screening software compares these fields with current sanctions records, while analysts investigate possible matches and determine the proper disposition.
The operational sequence is:
- The payment enters the bank or payment partner's queue.
- Screening software compares relevant data with sanctions records.
- A potential match is held for review.
- An analyst clears the match, or the institution blocks, rejects, or escalates the payment.
- The system retains evidence of the decision.
Layer three, ongoing rescreening
A customer can pass onboarding and become risky later. Ongoing rescreening checks customer and counterparty data after sanctions-list changes and according to the institution's risk-based schedule. It also prompts review when ownership information changes or a new designation affects a connected entity.

The evidence trail matters as much as the alert. A bank must be able to show the data used, matching logic, investigation, final disposition, and any approval or license analysis. That record separates a documented false-positive clearance from an unexplained release.
OFAC Penalties and What Banks Actually Get Fined For
A payment partner blocks one wire, then asks for customer records, ownership documents, alert notes, and prior transaction reviews. That response reflects how OFAC risk is assessed inside a bank. An enforcement case rarely concerns one isolated alert. Investigators examine whether the institution's screening, escalation, list management, ownership analysis, governance, and remediation worked together.
The same OFAC 2023 enforcement record lists a $30 million Wells Fargo Bank, N.A. penalty on March 30, 2023, and a Binance action dated November 21, 2023, reaching $968,618,825. The broader enforcement data covers actions since 2003, including 1,071 actions totaling about $7.9 billion. These figures show the scale of possible exposure, not a rule that every alert becomes a penalty.
Two cases, different operational lessons
Wells Fargo shows how a bank can face material exposure when payment activity continues despite sanctions-related risk signals or inadequate controls. Binance shows how exposure can become far larger when a digital-asset business processes a substantial pattern of transactions involving sanctioned jurisdictions and users.
For a fintech founder, the practical question is not whether the company resembles either institution. It is whether a payment partner can answer five control questions:
- Detection: Did the system identify the relevant party, country, or ownership link?
- Escalation: Did staff investigate alerts with reliable identifying information?
- Disposition: Did the institution block, reject, or authorize the transaction correctly?
- Governance: Did management know about a control gap and leave it unresolved?
- Remediation: Did the firm stop the activity, correct the system, and review prior transactions?
| Institution | Year | Approximate penalty | Root cause | Apparent violations |
|---|---|---|---|---|
| Wells Fargo Bank, N.A. | 2023 | $30 million | Bank-related sanctions-control failure identified in OFAC enforcement information | Not specified in the verified data provided |
| Binance | 2023 | $968,618,825 | Transactions involving users in sanctioned jurisdictions | Not specified in the verified data provided |
The phrase apparent violations requires careful reading. OFAC enforcement releases describe conduct the agency believes violated sanctions rules. A settlement resolves the matter without making every allegation a criminal finding.
Banks still treat the outcome seriously. They preserve records, review similar transactions, test whether the same weakness exists elsewhere, and show that corrected controls can prevent recurrence. A clean alert disposition therefore needs evidence, not only a final status in the screening system.
Why OFAC Is Not Just a U.S. Problem
A company doesn't need a U.S. incorporation certificate to encounter OFAC controls. A USD payment can pass through a U.S. correspondent bank, and that intermediary may require the originating institution to screen the parties and payment details. A foreign fintech can therefore face a practical compliance perimeter created by its access to dollar clearing and correspondent relationships.
The same issue appears in digital assets. A platform may serve customers outside the United States but still depend on U.S.-connected banks, dollar settlement, stablecoin infrastructure, technology providers, or contractual representations that prohibit sanctioned activity. A payment partner can block or terminate a relationship based on those obligations even when the foreign firm believes local law is the only relevant standard.
Industry analysis of OFAC exposure for foreign businesses with U.S. correspondent relationships describes why USD access can make OFAC-style restrictions relevant outside U.S. borders. The important nuance is that jurisdictional reach and commercial reach aren't identical. A bank may apply stricter controls than the minimum legal question because its correspondent agreement, risk appetite, or network obligations require it to do so.
What this means for a foreign operator
A Turkish neobank routing a USD wire through New York may receive an alert because the intermediary's screening rules apply to the payment message. A Singapore payments company clearing dollars through a U.S. bank may need to provide ownership and purpose information before the transfer proceeds. A DAO with a Cayman or other offshore structure may still face payment restrictions if its treasury provider relies on U.S. banking rails.
The right question isn't, “Am I a U.S. person?” Ask instead:
- Does the transaction touch a U.S. financial institution or correspondent?
- Is the payment denominated in USD and routed through U.S. infrastructure?
- Does a partner contract require sanctions screening or compliance with U.S. sanctions?
- Are any owners, controllers, wallets, vendors, or intermediaries connected to blocked persons?
- Could a country program restrict the activity even if no party appears on the SDN List?
A foreign registration address can describe where your company exists. It doesn't describe every payment system your company uses.
For web3 firms, the final question is often the hardest. Wallet addresses, protocol participants, governance delegates, and service providers may not fit neatly into a traditional bank's customer file. That makes documented exposure mapping especially important before a transaction reaches a correspondent account.
Keeping Up When Sanctions Regimes Flip Overnight
A static sanctions snapshot can become inaccurate when OFAC changes a program. The OFAC FAQ page records active updates, including the June 30, 2025 Syria relief that removed all Syrian financial institutions from the SDN List and allowed U.S. persons to provide financial services to Syria from July 1, 2025.
That kind of change creates an awkward operational situation. A bank may need to remove a former restriction from a screening rule, update a country-policy table, review blocked-payment queues, and confirm that new permissions don't accidentally authorize dealings with still-designated individuals or entities. Delisting one group doesn't make every Syria-connected activity automatically safe.
A regime-change operating checklist
- Capture list deltas: Record additions, removals, amendments, ownership updates, and new or changed licenses from OFAC.
- Trigger rescreening: Connect list-update events to automated reruns of affected customers, counterparties, beneficiaries, and open payment instructions.
- Recalculate ownership: Rebuild the ownership graph when a parent, subsidiary, or blocked owner changes status. A list change can alter the conclusion for connected entities.
- Map permissions: Translate general and specific licenses into clear internal rules. State what is allowed, for whom, during which period, and under what conditions.
- Review queues: Revisit held, rejected, and blocked transactions after a program changes. Don't leave a former restriction embedded in an old case decision.
- Assign accountability: Give compliance, product, engineering, and operations named responsibilities for implementation, testing, approval, and evidence retention.
- Test payment rails: Verify that the updated logic works across wires, ACH, SWIFT, card settlement, stablecoin flows, and treasury transfers where relevant.
A continuous process also needs a written change-management record. The team should be able to answer when it received the update, which systems changed, which customers were rescreened, who approved the interpretation, and how exceptions were handled.
For crypto-native firms, automation can help connect list changes with payment controls, provided analysts retain authority over ambiguous matches and licensing questions. OneSafe's discussion of the future of automated compliance for crypto and digital assets reflects the broader need to coordinate identity, transaction, and sanctions workflows rather than operate disconnected checks.

Practical Takeaways for Banks, Fintechs, and Web3 Firms
The most useful way to manage OFAC risk is to stop treating sanctions screening as one vendor checkbox. Build controls around the moments when risk enters the business.
Start with the three layers. Screen customers and beneficial owners before account activation, screen payment instructions before release, and rescreen existing records when sanctions data changes. Each layer needs its own owner, service-level expectation, escalation path, and evidence.
Solve ownership before settlement. For legal entities, holding companies, investment vehicles, and DAO treasuries, collect enough ownership information to apply the 50 Percent Rule. Don't rely on the fact that the beneficiary's exact legal name isn't on the SDN List. An undisclosed upstream owner can change the decision.
Design for change. Maintain a sanctions-regime playbook that identifies who interprets OFAC updates, who changes product rules, who tests payment scenarios, and who approves release. Include licenses and delistings, not only new designations.
Treat partners as part of the control environment. Your bank or payment provider may screen more fields, apply stricter contractual rules, or pause a transaction that your internal system cleared. Know what information your partners need to investigate an alert, and preserve consistent customer, ownership, and payment data across systems.
Budget for operational friction. False positives require analyst time. True positives require blocking or rejection, customer communication, records, and sometimes regulatory reporting. A reliable process is cheaper than improvising after a correspondent bank has paused your funds.
For international and crypto-native teams, safeguards for cryptocurrency fraud across banks and fintechs should sit alongside sanctions governance, not apart from it. OFAC compliance is ultimately continuous remapping, the repeated process of connecting people, entities, ownership, payment rails, licenses, and changing sanctions programs.
OneSafe provides multi-currency business accounts, ACH, wire, and SWIFT payment workflows, along with crypto-compatible deposits, withdrawals, and fiat conversion for global and web3 businesses. Its onboarding and KYB controls include sanctions and watchlist screening, giving teams a structured place to manage cross-border payment operations, so visit OneSafe to review whether its account and treasury workflows fit your compliance needs.





