Sanctions scope, prohibitions, and licenses
Translate legal restrictions into a precise control boundary.
A payment is low risk for fraud and still cannot proceed under an applicable restriction. Sanctions compliance is not a model score with a price attached. It starts with the people, activity, jurisdiction, and legal rule.
Establish jurisdiction and activity
Sanctions programs can restrict dealings with named parties, certain territories, sectors, or specified activity. The applicable duties depend on the relevant legal nexus and program. An entity’s location, the involvement of U.S. persons, and other facts can matter.
Build a legal applicability map with qualified owners. The map should identify the actual entity, product, parties, route, and source rule. Avoid using a single global blocked-country table as a substitute for this analysis. It can both miss prohibited activity and reject permissible activity. Engineering needs a structured policy that states what the law requires for the defined situation.
A sanctions decision begins with the activity and the legal connection, not with a generic country score. Identify the relevant parties, institutions, currencies, goods or services, and jurisdictions. A U.S. obligation may apply through one connection while another jurisdiction imposes a separate requirement. The engineering model should be able to represent these facts without pretending that one universal screening flag resolves every legal question.
Keep the scope analysis distinct from the evidence match. A system can correctly detect a listed name and still need review to determine whether the person is the listed subject and what restriction applies. Conversely, a transaction can raise a prohibition issue that a simple name comparison would never detect. Scope and screening are complementary parts of the control.
- FactsIdentify parties route and activity
- NexusEstablish the applicable jurisdiction
- RuleMap the relevant restriction
- Geographic restriction
- Applies to defined locations or activity
- Party restriction
- Applies to identified persons or entities
Scope record
Illustrative data; not a real customer record or a prescribed policy.
- Productcross-border payment
Specific activity
- Partiessender receiver intermediary
Relevant actors
- Legal basisprogram-specific
Requires an approved interpretation
Sanctions scope is more than a country list
Use a program-specific applicability map. Sanctions scope is more than a country list.
- Failure mode 1avoid
- Approve from a low fraud score. Fraud probability does not override a prohibition.
- Failure mode 2avoid
- Block all foreign activity automatically. The rules are not a universal foreign-payment ban.
- Failure mode 3avoid
- Assume one jurisdiction covers every entity. Legal nexus can differ.
Separate detection from legal disposition
Screening identifies possible matches or relevant attributes. Legal disposition determines what the institution must do under the applicable restriction. A fuzzy name match is not itself a confirmed prohibited party. Equally, a lack of a name match does not prove all activity is permissible.
Use states such as candidate, under review, false match, confirmed relevant match, and resolved action. Tie each transition to evidence and authorized roles. The system should preserve the list version and matched identifiers. A reviewer must be able to explain why two similar names refer to different people without erasing the original alert.
- DetectFind a candidate match
- ResolveCompare identifying evidence
- DisposeApply the relevant legal action
- Candidate hit
- Possible identity or rule match
- Confirmed disposition
- Evidence and policy support an action
Screening state
Illustrative data; not a real customer record or a prescribed policy.
- Name similarityhigh
Candidate evidence
- Birth dateconflicting
Identity distinction
- Actionreview
No automatic guilt conclusion
A candidate requires identity and rule analysis
Separate matching from disposition. A candidate requires identity and rule analysis.
- Failure mode 1avoid
- Treat every fuzzy hit as a confirmed target. Similar names can identify different people.
- Failure mode 2avoid
- Treat no hit as full legal clearance. Other restrictions may apply.
- Failure mode 3avoid
- Delete false-match evidence. The resolution needs a trace.
Distinguish blocking and rejection
Blocking and rejecting are different actions under sanctions rules. Blocking generally involves immobilizing property in which a blocked person has an interest, when required. Rejection concerns refusing a transaction that is prohibited but not subject to blocking under the relevant rule. Exact treatment and reporting depend on the program and facts.
The application should not offer one generic deny button for every outcome. Separate customer messaging, ledger treatment, custody, reporting, and release authority. A blocked balance cannot be treated as ordinary platform revenue or simply returned because a support agent wants to resolve a complaint.
The difference between blocking and rejection changes how funds are handled and how the customer is informed. A generic decline state is not sufficient for every disposition. The workflow needs the applicable determination, the amount and property affected, the institution holding it, required records, and any reporting or follow-up action. Engineers should obtain the approved disposition logic from qualified owners and preserve its version in the decision record. A manual override must not turn a legal restriction into an ordinary customer-service exception.
- AnalyzeIdentify the property interest and prohibition
- ActUse the required block or reject treatment
- RecordPreserve custody and reporting evidence
- Block
- Immobilize property when the rule requires it
- Reject
- Refuse a prohibited transaction under its applicable treatment
Disposition record
Illustrative data; not a real customer record or a prescribed policy.
- Resultblocking required
Approved legal conclusion
- Ledgerrestricted property
Separate balance treatment
- Releaseauthorized process only
No ordinary refund path
Their legal and financial handling can differ
Model block and reject as distinct dispositions. Their legal and financial handling can differ.
- Failure mode 1avoid
- Use one decline state for everything. It loses custody and reporting meaning.
- Failure mode 2avoid
- Return blocked property on request. Release requires the appropriate authority.
- Failure mode 3avoid
- Recognize blocked funds as revenue. The property remains subject to restrictions.
Treat licenses as scoped authority
Operate the compliance program
OFAC’s compliance framework identifies management commitment, risk assessment, internal controls, testing and auditing, and training as core program components. The specific program should fit the organization’s risk and operations.
Turn those components into owned work. Track unresolved screening gaps, list failures, overdue reviews, and training needs. Test the complete transaction path, including manual channels and exceptional releases. A sanctions control that covers only the main API can miss activity initiated through a back-office tool. Governance should surface those gaps and ensure that fixes are verified.
- CommitAssign authority and resources
- ControlCover the real activity paths
- TestVerify coverage and remediate gaps
- Primary API coverage
- One route is screened
- Complete channel coverage
- All relevant initiation routes are addressed
Channel audit
Illustrative data; not a real customer record or a prescribed policy.
- Public APIscreened
Main path works
- Back-office transfernot mapped
Coverage gap
- Remediationadd controlled screening
Verify before relying on it
Manual paths can bypass the main control
Test every relevant channel and exception. Manual paths can bypass the main control.
- Failure mode 1avoid
- Count a policy as complete coverage. Implementation may differ.
- Failure mode 2avoid
- Ignore release overrides. Exceptions can carry high impact.
- Failure mode 3avoid
- Close gaps without retesting. The correction remains unproven.
Chapter connections
Continue with Screening engines and match resolution to follow the next part of the system. Use the glossary for terminology and risk mathematics for formulas and worked calculations.