Compliance
OFAC visitor screening: what facilities must do at check-in.
The Office of Foreign Assets Control publishes the Specially Designated Nationals list that regulated US organisations must screen against. For most companies this happens in accounting and payroll. For a subset of regulated facilities it also has to happen at physical entry. This post covers what OFAC actually requires, who is in scope, and how to run screening at the front desk without slowing arrivals to a crawl.
Who is legally in scope
OFAC sanctions apply broadly to US persons and to any transaction involving US persons or the US financial system. That covers all US-incorporated entities, US-based individuals, and any foreign entity doing business with US customers or through US banks.
For physical entry specifically, screening becomes a compliance obligation when:
- The facility handles controlled goods, technology, or information under ITAR or EAR (export controls).
- The facility is part of critical national infrastructure (energy, defence supply chain, water, telecoms).
- The facility processes financial transactions (banks, some fintech, MSBs).
- The facility holds Personally Identifiable Information at scale (healthcare, some SaaS, some legal).
Beyond the strictly regulated set, many organisations screen visitors as a risk-management measure even without an explicit legal mandate. The reasoning: if a sanctioned individual walks in and something goes wrong, questions get asked.
What the SDN list actually is
The Specially Designated Nationals and Blocked Persons list (SDN List) is maintained by OFAC. As of 2026 it contains roughly 12,000 to 15,000 named individuals, entities, aircraft, and vessels, subject to blocking orders under one or more sanctions programmes.
SDN entries include:
- Primary name in Latin script.
- Aliases, alternative spellings, and transliterations.
- Date of birth if known.
- Nationality and country of residence if known.
- Passport or ID numbers if known.
- The specific sanctions programme they are on (e.g. SDGT for global terrorism, IRAN for Iran-related, RUSSIA for Russia-related).
The list is updated at least weekly, sometimes daily. Any screening tool that uses a cached copy older than 24 hours is running behind the current list.
Fuzzy matching: the strong-vs-weak distinction
A visitor types their name at the kiosk. The screening engine compares against every SDN entry using fuzzy matching. Matches score on a confidence scale:
- Exact match on primary name. Almost always a strong match. Stops the check-in for review.
- Exact match on alias plus matching country of residence. Strong match.
- Phonetic match on primary name with different country. Weak match. Logged, does not stop check-in unless the organisation's policy says otherwise.
- Transliterated name match. Depends on script and confidence. "Alexei" vs "Alexey" should match; "Alexander" vs "Alexey" should not.
Every strong match should hold the check-in for human review by a named reviewer. Weak matches should be logged for audit but not block the visitor. If everything blocks, front-desk staff learn to override; nothing gets caught.
What the audit trail must contain
For a facility ever audited on OFAC compliance (OFAC itself, an insurer, an M&A due-diligence team), the screening record must show:
- Timestamp of the screening event.
- The name that was screened, as typed.
- The SDN list version used for the check.
- Match result: no match, weak match, strong match.
- If a match: reviewer decision, reviewer name, decision timestamp.
Related reading
Screen a real SDN name in a live demo.
Bring a name off the SDN list. See the exact match flow, human review handoff, and audit trail export in 30 minutes.