A prohibited parties background check is a compliance screening that compares the names of your customers, vendors, and business partners against U.S. government watch lists identifying people and organizations barred from certain transactions. If a match is confirmed, you cannot lawfully complete the deal. Every U.S. person and U.S.-incorporated business is required to comply, and civil penalties for a single violation can reach $377,700 under the most commonly applied sanctions authority.1Federal Register. Inflation Adjustment of Civil Monetary Penalties
Who Has to Screen
OFAC sanctions bind all U.S. citizens and permanent residents wherever they live, all individuals and entities physically located in the United States, and all U.S.-incorporated companies along with their foreign branches.2Office of Foreign Assets Control. Frequently Asked Questions – 11 Some programs reach further and pull in foreign subsidiaries owned or controlled by U.S. companies.
This is not a rule aimed only at banks and defense contractors. A software company selling a cloud subscription to a foreign buyer, a real estate firm closing with a foreign investor, and a university admitting a visiting researcher all sit under the same obligation. And OFAC enforces on a strict liability basis: you can face civil penalties even if you had no idea the other party was restricted.3Office of Foreign Assets Control. Frequently Asked Questions – 65 Ignorance is not a defense. A company that never screens is accumulating risk with every transaction.
Which Lists to Check
The U.S. government maintains over a dozen restricted party lists across three main agencies.
Treasury (OFAC) runs economic and trade sanctions. Its flagship list is the Specially Designated Nationals and Blocked Persons List, known as the SDN List, which names parties whose assets must be frozen and with whom nearly all transactions are prohibited.4U.S. Department of the Treasury. Sanctions List Search OFAC also publishes the Foreign Sanctions Evaders List, the Sectoral Sanctions Identifications List, and the Non-SDN Chinese Military-Industrial Complex Companies List, each with its own restrictions.5International Trade Administration. Consolidated Screening List
Commerce (BIS) controls exports of commercial and dual-use items under the Export Administration Regulations. Its main lists are the Denied Persons List (parties whose export privileges have been revoked),6Bureau of Industry and Security. Denied Persons List (DPL) the Entity List (foreign parties who need a specific license before receiving items subject to the EAR, generally reviewed under a presumption of denial),7eCFR. 15 CFR 744.11 – License Requirements That Apply to Entities Acting Contrary to the National Security or Foreign Policy Interests of the United States the Unverified List (end users BIS could not verify in prior transactions), and the Military End User List.
State (DDTC) regulates defense articles and services under ITAR.8Directorate of Defense Trade Controls. Understand the ITAR Its AECA Debarred List names parties prohibited from any defense trade activity, generally for three years, with reinstatement requiring a formal request rather than happening automatically.9eCFR. 22 CFR 127.7 – Debarment
The Consolidated Screening List
Checking each list individually is impractical, so the International Trade Administration publishes the Consolidated Screening List, which aggregates the restricted party lists from Commerce, State, and Treasury into one searchable resource.5International Trade Administration. Consolidated Screening List The CSL is available as a free online search, downloadable files, and an API for automated compliance systems. Each hit carries program codes that tell you which underlying rules apply, and those rules differ. Treating every match the same way can lead to unnecessary blocked deals or, worse, underestimating a serious restriction.
The 50 Percent Rule
One trap catches companies that screen only names. Under OFAC’s 50 percent rule, any entity owned 50 percent or more, directly or indirectly, by one or more blocked persons is itself treated as blocked, even if it appears on no list by name.10Office of Foreign Assets Control. Frequently Asked Questions – 398 For complex foreign entities, that means looking at ownership structure, not just the counterparty’s name.
How to Run the Check
Screening starts with reliable identifying information. At a minimum you need the party’s full legal name, known aliases, physical addresses, and country. For individuals, date of birth is critical for separating common names. For entities, registration numbers and known subsidiary relationships help avoid both missed matches and false positives.
Beyond a handful of transactions, most organizations use automated screening software that checks party data against all relevant lists at once. Good tools use fuzzy matching to catch spelling variations, transliteration differences, and reordered name components, so a name transliterated one way from Arabic or Cyrillic still trips a review against another spelling. Many compliance teams wire screening into customer onboarding, order management, and payment systems so every new transaction is checked automatically.
Government lists change often, so one-time screening at onboarding is not enough. Ongoing monitoring means automatically re-screening your existing customer and vendor base whenever the lists update. A party that cleared six months ago may appear on a new list today, and continuing to transact with them from that point creates liability.
Handling Matches and False Positives
Most screening hits are not confirmed matches. Automated tools cast a wide net on purpose, so you will regularly see potential matches involving a different person with a similar name. Your program needs a defined process: who reviews potential matches, what additional information they gather, and how they document the decision to clear or escalate.
When a hit comes back, compare every available identifier against the list entry. Government lists typically include addresses, dates of birth, nationalities, passport numbers, and aliases. If the details clearly do not line up, document the result as a false positive and proceed. When the picture is ambiguous, pause the transaction and gather more information from the counterparty or from public records before deciding.
If screening confirms a genuine match, halt the transaction immediately. Proceeding after discovering a match sharply increases your exposure, because you can no longer claim the violation was inadvertent. For OFAC matches involving blocked persons, any property or funds in your possession connected to that party must go into a blocked, interest-bearing account and cannot be released without OFAC authorization.11Office of Foreign Assets Control. Frequently Asked Questions – Blocking and Rejecting Transactions
Reporting a Confirmed Match
A confirmed match triggers reporting obligations that depend on which list is involved. For OFAC sanctions, both blocked and rejected transactions must be reported to OFAC within 10 business days.12Office of Foreign Assets Control. Frequently Asked Questions – Filing Reports with OFAC A blocked transaction is one where you hold funds or property on behalf of the blocked party. A rejected transaction is one you simply refuse to process. Both require a report.
Financial institutions carry an extra layer. Under the Bank Secrecy Act, banks and other covered institutions must file Suspicious Activity Reports with FinCEN when they know or suspect that a transaction involves funds tied to illegal activity, including sanctions evasion or export control circumvention.13Financial Crimes Enforcement Network. Joint Notice on US Export Controls For export control matters, suspected violations should go to the BIS Office of Export Enforcement.
Whichever agency is involved, keep detailed records of every screening performed, every match reviewed, every decision made, and every report filed. Those records are your main evidence of a functioning program if regulators come asking.
What You Face for Getting It Wrong
OFAC’s strict liability standard means civil penalties can attach without any intent.3Office of Foreign Assets Control. Frequently Asked Questions – 65 Under the International Emergency Economic Powers Act, the maximum civil penalty per violation is $377,700 as of the most recent inflation adjustment. Under the older Trading With the Enemy Act, the maximum is $111,308 per violation.1Federal Register. Inflation Adjustment of Civil Monetary Penalties Those numbers are per violation, and a pattern of prohibited transactions stacks quickly.
When violations are willful, criminal charges become possible. Under IEEPA, a person who knowingly commits a sanctions violation faces up to $1,000,000 in fines and up to 20 years in prison.14Office of the Law Revision Counsel. 50 USC 1705 – Penalties Export control violations under the EAR carry comparable penalties, and ITAR violations can be prosecuted under the Arms Export Control Act. The dividing line is intent. A company that genuinely tried to comply but made a mistake faces civil liability. A company that ignored red flags or structured transactions to evade sanctions faces criminal prosecution.
Building Screening Into a Program
Both OFAC and BIS have published formal guidance on what a compliance program should look like, and the presence of a well-designed program is a significant mitigating factor if a violation occurs. OFAC’s Framework for Compliance Commitments identifies management commitment, risk assessment, internal controls, testing and auditing, and training as the essentials.15Office of Foreign Assets Control. A Framework for OFAC Compliance Commitments BIS publishes a similar model for export compliance programs.16Bureau of Industry and Security. Developing an Export Compliance Program
What both frameworks share is that compliance cannot be a checkbox exercise. Senior leadership has to support the program visibly and fund it. Risk assessments should be run at least annually and reflect the specific products, services, geographies, and customer types you handle. Internal controls need automated screening, clear escalation, and recordkeeping that will survive an audit. Training has to reach everyone whose work touches regulated activity, not just the compliance officer.
If You Find a Violation After the Fact
If a review turns up a past violation, both OFAC and BIS strongly encourage voluntary self-disclosure, and the difference in outcomes is stark. OFAC treats self-disclosure as a mitigating factor that reduces the base civil penalty.17Office of Foreign Assets Control. Disclosure Under BIS regulations, self-disclosure is likewise a mitigating factor, while a deliberate choice not to disclose significant violations is treated as aggravating and increases penalties.18eCFR. 15 CFR 764.5 – Voluntary Self-Disclosure
For BIS, the process runs on two tracks. Minor or technical violations can be filed through an abbreviated report, which BIS generally resolves within 60 days with either no action or a warning letter. Significant violations require an initial notification as soon as the issue is discovered, with a complete narrative report within 180 days.18eCFR. 15 CFR 764.5 – Voluntary Self-Disclosure Self-disclosure does not guarantee immunity from criminal referral, but it substantially reduces the likelihood and severity of administrative penalties. The worst place to end up is having known about a violation, done nothing, and had the government find it on its own.