OFAC - the Office of Foreign Assets Control - is a financial intelligence and enforcement agency of the U.S. Department of the Treasury. It administers and enforces economic and trade sanctions based on U.S. foreign policy and national security goals. For any business operating across borders, understanding OFAC';s authority, its lists, and the compliance obligations it creates is not optional - it is a core element of legal risk management. This guide covers the legal definition of OFAC, the scope of its authority, the key lists it maintains, how violations occur, and what businesses must do to stay compliant.
What OFAC is and why it matters in international business
OFAC is a U.S. government office operating within the Department of the Treasury. It was formally established in its current form in the early 1950s, though its roots trace to earlier wartime controls on enemy assets. Today, OFAC administers more than thirty active sanctions programs targeting specific countries, regions, entities, and individuals.
The legal foundation for OFAC';s authority rests on several statutes. The International Emergency Economic Powers Act (IEEPA) grants the President broad authority to regulate international commerce and financial transactions during a declared national emergency. The Trading with the Enemy Act (TWEA) applies in times of war. The Foreign Narcotics Kingpin Designation Act and the Global Magnitsky Act, among others, extend OFAC';s reach to specific categories of actors such as narcotics traffickers and human rights violators.
OFAC';s authority is extraterritorial in significant ways. U.S. persons - meaning U.S. citizens, permanent residents, entities incorporated in the United States, and their foreign branches - must comply regardless of where a transaction takes place. Non-U.S. companies can also face exposure if they cause U.S. persons to violate sanctions or if they process transactions through the U.S. financial system.
In practice, any business that uses U.S. dollars, maintains correspondent banking relationships with U.S. banks, or employs U.S. nationals in decision-making roles is within OFAC';s practical reach. Many underestimate how broadly this net is cast.
The SDN list and other OFAC designations
The Specially Designated Nationals and Blocked Persons List - commonly called the SDN List - is OFAC';s primary enforcement tool. It is a publicly available register of individuals, companies, vessels, and aircraft whose assets are blocked and with whom U.S. persons are generally prohibited from doing business.
Being on the SDN List means that any property or interests in property of the listed party that come within U.S. jurisdiction must be frozen. U.S. persons cannot engage in transactions with SDN-listed parties without a specific license from OFAC. The list is updated frequently, sometimes multiple times per week.
Beyond the SDN List, OFAC maintains several other lists and programs:
- The Sectoral Sanctions Identifications List (SSI List) targets specific sectors of designated economies, such as energy, finance, or defense, rather than blocking all transactions with listed parties.
- The Foreign Sanctions Evaders List identifies foreign individuals and entities that have violated U.S. sanctions or assisted others in doing so.
- The Non-SDN Palestinian Legislative Council List and other program-specific lists apply to narrower contexts.
A common mistake made by foreign businesses is assuming that only the SDN List matters. In practice, the SSI List and country-specific programs impose significant restrictions that do not require a party to appear on the SDN List at all. Certain transactions with entire sectors of a designated country';s economy may be prohibited regardless of whether the counterparty is individually listed.
OFAC also applies the "50 percent rule": any entity owned 50 percent or more, directly or indirectly, by one or more SDN-listed persons is itself treated as blocked, even if it does not appear on the SDN List by name. This rule creates substantial due diligence obligations for businesses dealing with complex ownership structures.
How OFAC violations occur and what they look like
OFAC violations fall into two broad categories: those involving prohibited transactions and those involving the failure to block or report. A prohibited transaction is any dealing - whether a payment, a contract, a loan, a service, or a transfer of goods - that involves a sanctioned party or a sanctioned jurisdiction without an applicable license or exemption.
Violations do not require intent. OFAC operates a strict liability framework for many civil violations. A company can be held liable even if it did not know that a counterparty was on the SDN List, provided that OFAC determines the company had reason to know or failed to conduct adequate due diligence. This is a critical point that many founders and compliance officers overlook.
Common scenarios in which violations arise include:
- Processing a payment through a U.S. correspondent bank where the ultimate beneficiary is an SDN-listed entity.
- Providing software, cloud services, or professional services to a company that is majority-owned by a sanctioned person.
- Entering into a joint venture with a foreign partner without screening the partner';s ultimate beneficial owners against OFAC lists.
A non-obvious requirement is that OFAC compliance extends to subsidiaries and affiliates. A European subsidiary of a U.S. parent must comply with U.S. sanctions as a U.S. person. Conversely, a U.S. subsidiary of a foreign parent must also comply, even if the parent';s home country does not impose equivalent restrictions.
OFAC penalties can be severe. Civil penalties for non-egregious violations are calculated based on the greater of a statutory maximum per violation or the value of the transaction involved. Egregious violations - those involving willful conduct or reckless disregard - attract significantly higher penalties. Criminal penalties, including imprisonment, apply in cases of willful violations.
If your business operates across multiple jurisdictions and you are uncertain whether a transaction or counterparty triggers OFAC exposure, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
OFAC licenses: general and specific
An OFAC license is an authorization that permits a transaction that would otherwise be prohibited. Licenses come in two forms: general licenses and specific licenses.
A general license is a standing authorization published in the Code of Federal Regulations or in OFAC';s program-specific regulations. It permits a defined category of transactions without requiring the applicant to seek individual approval. For example, general licenses commonly authorize certain humanitarian transactions, personal remittances, or the wind-down of pre-existing contracts following a new designation.
A specific license is an individual authorization issued by OFAC in response to a written application. It is required when no general license covers the proposed transaction. OFAC reviews specific license applications on a case-by-case basis, applying a policy framework that reflects the goals of the relevant sanctions program. Processing times vary and can extend to several months for complex matters.
In practice, founders should consider whether a general license might cover their situation before assuming that a specific license application is necessary. Misreading the scope of a general license - either by relying on one that does not apply or by failing to recognize one that does - is a frequent compliance error.
OFAC also issues guidance documents, frequently asked questions, and interpretive letters that clarify how it applies its regulations. These are not legally binding in the same way as regulations, but they carry significant practical weight and are routinely relied upon by compliance professionals and courts.
OFAC compliance programs: what businesses are expected to maintain
OFAC does not mandate a specific compliance program structure by statute, but it has published a detailed framework - the "Framework for OFAC Compliance Commitments" - that describes the five essential components of an effective program. These are management commitment, risk assessment, internal controls, testing and auditing, and training.
Management commitment means that senior leadership takes ownership of sanctions compliance and allocates adequate resources to it. Risk assessment requires the business to identify and evaluate its exposure based on its customers, products, services, geographic footprint, and transaction types. Internal controls include the screening systems, approval workflows, and escalation procedures that operationalize the compliance policy.
Testing and auditing means that the program is periodically reviewed - both by internal teams and, for higher-risk businesses, by external auditors - to verify that controls are working as intended. Training ensures that employees who handle transactions, onboard customers, or manage counterparty relationships understand their obligations.
A common mistake is treating OFAC compliance as a one-time setup rather than an ongoing process. Sanctions lists change frequently. A counterparty that was clean at onboarding may be designated months later. Businesses that screen only at the point of initial engagement, rather than on a continuous or periodic basis, face significant residual risk.
The level of program sophistication expected by OFAC scales with the risk profile of the business. A small domestic company with no international transactions faces minimal exposure. A financial institution, a commodities trader, or a technology company with global customers faces a much higher bar. OFAC takes the adequacy of a compliance program into account when determining penalties and whether to pursue enforcement.
Voluntary self-disclosure and enforcement priorities
OFAC encourages voluntary self-disclosure of potential violations. A business that discovers a possible violation and reports it to OFAC before the agency becomes aware of it through other means may receive a significant reduction in any civil penalty. OFAC treats voluntary self-disclosure as a mitigating factor in its enforcement matrix.
The decision to self-disclose is not straightforward. It requires a careful assessment of the nature and severity of the potential violation, the likelihood that OFAC would discover it independently, and the potential penalty exposure. Disclosure also triggers a formal review process that demands significant internal resources and documentation.
OFAC';s enforcement priorities shift over time in response to policy developments. Recent enforcement actions have focused on financial institutions that failed to screen transactions adequately, technology companies that provided services to sanctioned jurisdictions through automated platforms, and intermediaries that facilitated transactions on behalf of SDN-listed parties.
Two practical scenarios illustrate the range of exposure. First, a European fintech company processes payments in U.S. dollars through a U.S. correspondent bank. One of its customers is a company majority-owned by an SDN-listed individual. The fintech did not screen for the 50 percent rule. The U.S. correspondent bank flags the transaction. The fintech faces potential liability both in the U.S. and reputational damage with its banking partners. Second, a software-as-a-service company based in Canada provides cloud services globally. A customer in a comprehensively sanctioned jurisdiction signs up using a third-country address. The company';s automated onboarding did not include IP-based geolocation screening. OFAC considers this a potential violation even though the company had no direct knowledge.
For businesses navigating complex cross-border structures or uncertain counterparty relationships, contact info@vlolawfirm.com. We can assist with documents and filings related to OFAC compliance and licensing matters.
Frequently asked questions
Does OFAC apply to non-U.S. companies with no U.S. operations?
OFAC';s primary jurisdiction covers U.S. persons and U.S.-connected transactions. However, non-U.S. companies can face exposure in several ways. If they process transactions through the U.S. financial system - including U.S. dollar clearing - they may trigger OFAC';s jurisdiction. If they employ U.S. nationals in roles that involve sanctioned transactions, those individuals are personally subject to OFAC rules. Additionally, non-U.S. companies that cause U.S. persons to violate sanctions can face secondary consequences, including being placed on OFAC';s own lists. The practical reach of OFAC is therefore considerably broader than its formal jurisdictional boundaries suggest.
How long does it take to obtain an OFAC specific license, and what does the process involve?
The timeline for a specific license application varies significantly depending on the complexity of the transaction, the sanctions program involved, and OFAC';s current caseload. Straightforward applications in well-established program areas may receive a response within a few weeks. Complex applications involving novel fact patterns or high-risk programs can take several months or longer. The process involves submitting a detailed written application to OFAC explaining the transaction, the parties, the legal basis for the request, and the policy reasons why the license should be granted. OFAC may request additional information during its review. There is no filing fee, but the administrative burden of preparing a well-documented application is substantial.
What is the difference between a blocked transaction and a rejected transaction under OFAC rules?
These are two distinct outcomes with different legal consequences. A blocked transaction involves funds or property that must be frozen and held in a segregated, interest-bearing account because they belong to or are controlled by a sanctioned party. The funds are not returned to the sender and not forwarded to the intended recipient - they are held pending further OFAC authorization or a change in sanctions status. A rejected transaction, by contrast, involves a payment that is simply refused and returned to the originator because it involves a prohibited dealing, but where there is no blocked property to hold. The distinction matters because blocking creates ongoing reporting and record-keeping obligations, while rejection does not carry the same custodial requirements.
Conclusion
OFAC is one of the most consequential regulatory bodies in international business law. Its authority extends well beyond U.S. borders, its lists change frequently, and its strict liability framework means that ignorance of a violation is rarely a complete defense. Businesses operating internationally must treat OFAC compliance as a continuous, risk-based process rather than a one-time check.
VLO Law Firms advises international clients on OFAC compliance, sanctions screening, and licensing matters. We can assist with risk assessments, license applications, voluntary self-disclosure, and the design of compliance programs appropriate to your business profile. To request a consultation, contact: info@vlolawfirm.com