Skip to main content
Category: Regulatory & Privacy Compliance

Sanctions Compliance (OFAC)

Also known as: OFAC, OFAC Compliance, OFAC Sanctions Screening, OFAC Verification
Simply put

OFAC sanctions compliance means following the rules set by the U.S. Office of Foreign Assets Control, which prohibit dealing with certain individuals, entities, and countries subject to sanctions. Organizations typically screen the people and businesses they work with against OFAC-maintained lists to avoid violations. Failing to have a sanctions compliance program in place can expose an organization to enforcement risk.

Formal definition

Sanctions compliance under OFAC refers to an organization's adherence to the laws and regulations administered by the U.S. Department of the Treasury's Office of Foreign Assets Control, typically implemented through a sanctions compliance program consistent with OFAC's published compliance framework. That framework applies to U.S. organizations as well as foreign entities doing business in or with U.S. parties or goods. A core operational component is OFAC verification, the process of screening an individual, entity, or business against sanctions lists maintained by OFAC. Note that OFAC is not itself a bank regulator; its basic requirement is that financial institutions not violate the laws it administers. The specific screening obligations, program elements, and enforcement exposure depend on an organization's activities, jurisdiction, and the applicable OFAC-administered sanctions programs; this entry does not address how sanctions exposure interacts with insurance coverage or exclusions, which is a separate question governed by policy wording.

Why it matters

OFAC sanctions compliance has become a significant concern in the cyber insurance and incident response context, particularly where ransomware and cyber extortion are involved. When an organization contemplates paying an extortion demand, there is a risk that the recipient of the payment may be a sanctioned individual, entity, or party located in a sanctioned jurisdiction. Because OFAC administers sanctions programs that apply to U.S. organizations as well as foreign entities doing business in or with U.S. parties or goods, a payment made to a sanctioned party can create enforcement exposure regardless of whether the payer knew the recipient was sanctioned.

The requirement to maintain a sanctions compliance program is grounded in OFAC's published compliance framework, which outlines key expectations for organizations. Enforcement risk is real: OFAC's guidance and recent cases illustrate the exposure that can arise from failing to have a sanctions compliance program in place. This matters to any organization that screens counterparties or that may find itself deciding whether to make a payment in the wake of a cyber incident.

It is important to keep this compliance question distinct from the question of insurance coverage. Whether a given cyber extortion payment or related loss is covered, and whether a sanctions-related exclusion or condition applies, is a separate matter governed entirely by the specific policy wording, endorsements, and applicable jurisdiction. Sanctions compliance concerns adherence to OFAC-administered law; it does not by itself determine what an insurer will pay.

Who it's relevant to

Incident Response and Crisis Management Teams
Teams that manage cyber extortion events must consider sanctions exposure before any payment is contemplated, since a payment to a sanctioned party can create OFAC enforcement risk. OFAC verification against sanctions lists is often part of the pre-payment diligence process. This is distinct from the incident containment and recovery work these teams perform.
Legal and Compliance Professionals
Compliance staff are typically responsible for building and maintaining a sanctions compliance program consistent with OFAC's published framework, which outlines key expectations. They also assess how program elements and screening obligations apply given the organization's activities and jurisdiction, and the enforcement exposure that can follow from failing to have a program in place.
Risk Managers and Brokers
Those arranging cyber coverage should understand that sanctions compliance and insurance coverage are separate questions. Whether a sanctions-related exclusion or condition affects a claim is governed by the specific policy wording, and this entry does not address that interaction. Risk managers weigh sanctions exposure as a compliance risk to be managed, not as something insurance alone resolves.
Financial Institutions
Financial institutions are subject to OFAC's basic requirement that they not violate the laws it administers, even though OFAC is not itself a bank regulator. Screening counterparties against OFAC-maintained lists is a routine part of their sanctions compliance obligations.
Organizations Doing Business With U.S. Parties or Goods
Because OFAC's compliance framework applies to U.S. organizations and to foreign entities doing business in or with U.S. parties or goods, non-U.S. organizations within that reach also need to consider their screening and program obligations under OFAC-administered sanctions programs.

Inside OFAC

OFAC Screening Obligation
The requirement to screen counterparties, claimants, and payees against sanctions lists administered by the U.S. Office of Foreign Assets Control before making payments. In the cyber insurance context this frequently arises when a ransomware extortion payment may flow to a sanctioned person, entity, or jurisdiction.
Strict Liability Standard
Sanctions enforcement generally operates on a strict-liability basis, meaning a violation can occur without intent or knowledge that the recipient was sanctioned. This distinguishes sanctions exposure from many other compliance regimes and shapes how insurers, insureds, and vendors approach extortion payments.
Ransom Payment Facilitation Risk
The risk that paying a cyber extortion demand, directly or through a ransomware negotiator, incident response firm, or insurer, may constitute prohibited dealing with a sanctioned party. This affects first-party cyber extortion coverage, where the loss being indemnified is the insured's own ransom payment.
Sanctions Exclusion / Compliance Clause
A policy provision, subject to the specific wording, under which an insurer will not provide coverage, payment, or service to the extent doing so would expose it to sanctions penalties. Whether a given extortion payment is covered depends on this wording, applicable endorsements, and the relevant jurisdiction.
Jurisdictional Scope
Sanctions programs are defined differently across regimes. OFAC administers U.S. sanctions, but insureds and insurers may also be subject to other national or supranational sanctions authorities. A payment permissible under one regime is not necessarily permissible under another.
Due Diligence and Documentation
The processes, attribution analysis, list screening, and record-keeping, used to assess whether an extortion payment would involve a sanctioned party, and to evidence a good-faith compliance effort. This is a risk-mitigation activity distinct from the risk transfer provided by insurance.

Common questions

Answers to the questions practitioners most commonly ask about OFAC.

If my cyber policy covers extortion, does that mean my insurer will always pay a ransom demand?
No. Cyber extortion coverage is a first-party coverage that responds subject to the specific policy wording, but it does not override sanctions law. If a ransom payment would be made to a sanctioned individual, entity, or jurisdiction, making or facilitating that payment may be prohibited regardless of whether the policy would otherwise respond. In many policies, sanctions exclusions or conditions expressly carve out payments that would violate applicable law. Coverage and legal permissibility are separate questions, and both must be satisfied.
Does paying a ransom count as a violation only if I knew the recipient was sanctioned?
Not necessarily. OFAC's sanctions authorities are generally understood to apply on a strict-liability basis, meaning a party can face enforcement exposure even without knowledge that the recipient was sanctioned. Intent and knowledge may bear on how a matter is evaluated and on the severity of any response, but the absence of knowledge does not by itself establish that no violation occurred. Because enforcement approaches and mitigating factors depend on the specific facts and applicable guidance, parties typically treat sanctions screening as a mandatory step rather than relying on a lack of awareness.
What sanctions screening steps are typically taken before a ransom payment is considered?
In practice, parties commonly attempt to identify the threat actor or wallet associated with the demand, screen available identifiers against applicable sanctions lists, and assess any nexus to sanctioned jurisdictions. This work is often performed by or with incident response firms, ransom negotiation specialists, and counsel. Whether such screening is fully possible depends on the information available, and inconclusive results do not necessarily resolve the legal risk. The specific procedures and documentation expectations vary by insurer form, vendor, and jurisdiction.
How should sanctions considerations be built into an incident response plan?
Sanctions review is typically incorporated as a decision gate within the incident response and crisis management process, engaged before any payment is authorized. Common elements include defined roles for counsel and specialist vendors, a documented screening step, escalation paths for inconclusive or high-risk findings, and coordination with the insurer where a claim may be involved. Because incident response and crisis management are distinct functions, organizations often clarify who holds payment-decision authority. The precise structure should be tailored to the organization and reviewed against current legal guidance.
What role does the insurer play in sanctions compliance during a ransom event?
Insurers and their appointed vendors are often involved in coordinating the response, and many policies contain sanctions clauses that condition or limit the insurer's ability to pay when doing so would breach applicable sanctions. However, the insured generally remains responsible for its own legal compliance, and insurer involvement does not transfer or eliminate that obligation. Risk transfer through insurance addresses financial loss subject to policy terms; it does not by itself satisfy sanctions requirements. Roles and responsibilities depend on the specific wording and the parties' agreements.
Can voluntary disclosure or engaging authorities affect how a potential sanctions issue is handled?
Engagement with the relevant authorities and voluntary self-disclosure are frequently cited as factors that can influence how a potential sanctions matter is evaluated, and organizations often coordinate such steps closely with counsel. The weight given to any particular action depends on the applicable guidance and the specific facts, and there is no guaranteed outcome. Because approaches differ across matters and over time, these decisions are typically made with qualified legal advice rather than as a routine or predetermined step.

Common misconceptions

If a cyber policy includes extortion coverage, any ransom payment will be reimbursed.
Cyber extortion coverage is conditional. Even where the peril is covered, a sanctions exclusion or compliance clause may bar payment to the extent it would violate sanctions, and coverage ultimately turns on the specific policy wording, endorsements, exclusions, and jurisdiction.
A violation only occurs if the insured knew the recipient was sanctioned.
Sanctions enforcement generally applies on a strict-liability basis, so a violation can arise even without knowledge or intent. Attribution of a ransomware actor is often uncertain, which is precisely why screening and due diligence matter before any payment is made.
Sanctions compliance is solely the insurer's responsibility once a claim is filed.
Multiple parties in an extortion payment chain, the insured, the insurer, and vendors such as negotiators or response firms, can each face exposure. Sanctions compliance is a shared obligation, and transferring financial risk through insurance does not transfer the underlying legal duty to avoid prohibited dealings.

Best practices

Conduct OFAC and applicable multi-jurisdictional sanctions screening on any prospective extortion payee, and treat unresolved attribution as a material risk before authorizing payment.
Review the policy's sanctions exclusion or compliance clause and extortion coverage wording in advance, so all parties understand that reimbursement is conditional and jurisdiction-dependent.
Coordinate early with legal counsel and any incident response or negotiation vendors, confirming each party's respective sanctions compliance obligations across the payment chain.
Maintain contemporaneous documentation of screening, attribution analysis, and decision-making to evidence a good-faith compliance effort.
Recognize that insurance transfers financial loss but does not reduce sanctions exposure or the underlying legal duty, and factor this into pre-incident planning rather than relying on coverage alone.
Confirm which sanctions regimes apply to both the insured and the insurer, since a payment acceptable under one authority may be prohibited under another.
Application Security Isn’t Optional Anymore.