Sanctions Compliance (OFAC)
OFAC sanctions compliance means following the rules set by the U.S. Office of Foreign Assets Control, which prohibit dealing with certain individuals, entities, and countries subject to sanctions. Organizations typically screen the people and businesses they work with against OFAC-maintained lists to avoid violations. Failing to have a sanctions compliance program in place can expose an organization to enforcement risk.
Sanctions compliance under OFAC refers to an organization's adherence to the laws and regulations administered by the U.S. Department of the Treasury's Office of Foreign Assets Control, typically implemented through a sanctions compliance program consistent with OFAC's published compliance framework. That framework applies to U.S. organizations as well as foreign entities doing business in or with U.S. parties or goods. A core operational component is OFAC verification, the process of screening an individual, entity, or business against sanctions lists maintained by OFAC. Note that OFAC is not itself a bank regulator; its basic requirement is that financial institutions not violate the laws it administers. The specific screening obligations, program elements, and enforcement exposure depend on an organization's activities, jurisdiction, and the applicable OFAC-administered sanctions programs; this entry does not address how sanctions exposure interacts with insurance coverage or exclusions, which is a separate question governed by policy wording.
Why it matters
OFAC sanctions compliance has become a significant concern in the cyber insurance and incident response context, particularly where ransomware and cyber extortion are involved. When an organization contemplates paying an extortion demand, there is a risk that the recipient of the payment may be a sanctioned individual, entity, or party located in a sanctioned jurisdiction. Because OFAC administers sanctions programs that apply to U.S. organizations as well as foreign entities doing business in or with U.S. parties or goods, a payment made to a sanctioned party can create enforcement exposure regardless of whether the payer knew the recipient was sanctioned.
The requirement to maintain a sanctions compliance program is grounded in OFAC's published compliance framework, which outlines key expectations for organizations. Enforcement risk is real: OFAC's guidance and recent cases illustrate the exposure that can arise from failing to have a sanctions compliance program in place. This matters to any organization that screens counterparties or that may find itself deciding whether to make a payment in the wake of a cyber incident.
It is important to keep this compliance question distinct from the question of insurance coverage. Whether a given cyber extortion payment or related loss is covered, and whether a sanctions-related exclusion or condition applies, is a separate matter governed entirely by the specific policy wording, endorsements, and applicable jurisdiction. Sanctions compliance concerns adherence to OFAC-administered law; it does not by itself determine what an insurer will pay.
Who it's relevant to
Inside OFAC
Common questions
Answers to the questions practitioners most commonly ask about OFAC.
