VerifySanctionsAll guides

How often should you re-screen customers and vendors against OFAC?

OFAC does not set a re-screening frequency. Its answer is that the frequency must be guided by your organization's own policies and procedures, and that missing a sanctioned party can lead to funds reaching them, an enforcement action and bad publicity (OFAC FAQ 28). A defensible schedule screens every new party before the first transaction, re-screens the whole file whenever OFAC changes its lists, and re-screens a party whenever its details change.

How often the lists actually change

OFAC publishes changes as "recent actions". In the 16 days from 23 September to 8 October 2026, its recent actions page shows designations or removals on seven separate days (OFAC recent actions). A list that moves that often means a monthly scrub can leave a gap of several weeks between a designation and your next check.

OFAC's SDN and Consolidated files are complete each time they are published, so you can overwrite the previous copy with the new one rather than applying patches (OFAC FAQ 89).

Three ways to schedule

ApproachGap after a new designationEffort
Calendar, monthlyUp to about a monthOne batch a month
Calendar, weeklyUp to about a weekOne batch a week
On each list changeHours to a dayAutomated; needs a tool or script

The calendar is easy to write into a policy. Screening on each list change closes the gap without extra work once it is automated, because your file only needs re-checking against the names that changed.

Events that should trigger a check

  • a new customer or vendor, before the first transaction
  • a change of name, address, bank account or ownership
  • a payment to a new country
  • a large or unusual payment
  • a request to pay a third party on the vendor's behalf

These are the moments when the facts you screened last time stop being true. OFAC's framework lists ownership, geographic location and counter-parties among the details companies failed to check in past enforcement cases (OFAC framework).

Why stale screening is a known failure

OFAC's 2019 compliance framework describes the root causes of apparent violations it has seen. One of them is organizations failing to update their screening to incorporate updates to the SDN list (OFAC framework). A schedule that screens the file against an old copy of the list is that failure, however diligent the team running it.

Writing the schedule into your policy

Your policy should say, in plain words:

  1. Which parties are screened: customers, vendors, employees, owners.
  2. When: before onboarding, on each list update or on a fixed date, and on the trigger events above.
  3. Against which lists, and how you get the current version.
  4. Who reviews candidates and how decisions are recorded.

Our OFAC compliance program template includes a section for this. If you screen vendors in batches, the monthly vendor scrub and the vendor master file guide show the mechanics.

Keep the evidence of each run

For each run, keep the date, the list publication dates used, the names screened and the decisions on any candidates. OFAC requires records of transactions subject to its rules for at least 10 years (31 CFR 501.601). The record of when you screened, and against which version, is what shows the schedule was actually followed.

This is screening data, not legal advice. Run a free OFAC check against today's lists on anyone whose details changed since your last run.