OFAC vs FinCEN: What's the Difference Between the Two US Treasury Bureaus?

Office of Foreign Assets Control (OFAC) is a bureau of the US Department of the Treasury that administers and enforces economic and trade sanctions programs. It administers the Specially Designated Nationals (SDN) list and other sanctions lists that identify persons, entities, and countries subject to asset freezes and transaction prohibitions.

The authority of OFAC is grounded in statutes including International Emergency Economic Powers Act (IEEPA), 50 U.S.C. §§ 1701 et seq., and the Trading with the Enemy Act, 50 U.S.C. §§ 4301 et seq (TWEA). OFAC compliance is governed by a strict liability standard, meaning that the institution is held liable for sanctioned transactions regardless of intent.

The Financial Crimes Enforcement Network (FinCEN) is a bureau of the U.S. Department of the Treasury responsible for collecting, analyzing, and disseminating financial intelligence to protect the financial system from illicit use. It oversees the implementation of the Corporate Transparency Act (CTA), the Anti Money Laundering Act (AMLA) and the Bank Secrecy Act (BSA). FinCEN’s compliance framework is risk based, meaning institutions put in place controls based on their own risk profile.

The difference simply put: OFAC is telling you the entities you can not do business with. FinCEN issues guidance on how to identify and report suspicious activity. Both are Treasury agencies, subject to the same examination cycle, and enforce two of the most important compliance regimes in U.S. financial services. However, they answer different questions, apply different standards, and produce different results when mistakes are made.

First, compliance leaders should slay the misconception that these regimes are simply two variations of the same obligation. They are not. An institution could pass an OFAC examination and fail a FinCEN examination or vice versa because of the structural differences between the two exams. The following sections explore the operational implications of these structural differences.

The following sections provide a more detailed explanation:

  • Side-by-Side Comparison Table
  • Strict Liability vs Risk-Based: Why This Distinction Matters
  • How They Overlap in Practice
  • What financial institutions need to do for both
  • Common compliance mistakes in both regimes
  • How Sanction Scanner Can Help You Comply with Both

Mceclip2 17

Side-by-side comparison table

The best way to look at both regimes at the same time is column by column.

Dimension

OFAC

FinCEN

Full Name

Office of Foreign Assets Control

Financial Crimes Enforcement Network

Part Of

US Department of the Treasury

US Department of the Treasury

Primary Mission

Administer and enforce economic sanctions

Safeguard the financial system from illicit use

What They Regulate

Sanctions compliance (who you can't transact with)

AML/CFT compliance (how you detect and report suspicious activity)

Legal Authority

IEEPA, TWEA, Foreign Narcotics Kingpin Act, AEDPA, program-specific statutes

Bank Secrecy Act, Anti-Money Laundering Act (2020), Corporate Transparency Act

Liability Standard

Strict liability, intent irrelevant to whether a violation occurred

Risk-based, reasonable, well-designed program expected

Key Lists / Tools

SDN List, SSI List, FSE List, Non-SDN CAPTA List, country programs

SAR, CTR, CDD Rule, 314(a)/(b), FinCEN National AML/CFT Priorities

Who Must Comply

All US persons and entities, not just financial institutions

BSA covered entities (banks, MSBs, broker dealers, casinos, others)

Primary Obligation

Screen and block prohibited transactions

Monitor, detect, and report suspicious activity

If You Miss Something

Violation regardless of intent; penalty severity is what varies

Evaluated against program adequacy, was the program reasonable?

Max Civil Penalty (2026)

$377,700 per IEEPA violation, or twice the transaction value, whichever is greater

Up to $250,000 and 5 years per willful violation (31 USC 5322(a)); up to $500,000 and 10 years if committed while violating another law or as part of a pattern of illegal activity over $100,000 in 12 months (31 USC 5322(b))

Criminal Penalty (willful)

Up to $1M and 20 years imprisonment per IEEPA violation

Up to $500,000 and 10 years imprisonment per willful BSA violation

Penalty Framework

OFAC Economic Sanctions Enforcement Guidelines (31 CFR Part 501, App. A)

FinCEN Statement on Enforcement of the BSA (Aug 2020)

Examination

OFAC compliance examined during the BSA/AML exam cycle (separate authority)

BSA/AML examination by Fed, FDIC, OCC, NCUA, and state regulators per the FFIEC BSA/AML Examination Manual

Reporting Volumes (FY 2024)

Blocked property reports (case by case; annual public disclosure)

4.7 million SARs and 20.5 million CTRs filed in FY 2024

Note on OFAC Penalty: The Bureau of Labor Statistics did not publish the October 2025 consumer price index for all urban consumers (CPI-U) data due to the government shutdown, and the Office of Management and Budget determined that an annual inflation adjustment could not be made for 2026. Therefore, federal agencies, including OFAC, will use the 2025 civil monetary penalty amounts for 2026. This means the current IEEPA maximum of $377,700 remains in place for the 2026 calendar year.

Strict liability vs risk based: Why this distinction matters

This is the most important difference between the two regimes, and it is the decisive factor in almost every practical decision compliance teams make when putting together programs to combat them.

OFAC operates under a strict liability standard. If your institution processes a transaction with a sanctioned party, a violation has occurred. It doesn't matter if you didn't know, if your screening system failed or if you were acting in good faith. The violation was done. What matters is whether a violation occurred, not whether there was intent.

For example, two institutions may be involved in the same transaction with the same sanctioned entity. Institution A was aware of the payment and deliberately concealed it; Institution B’s screening system failed to identify the match due to a misspelling of the counterparty’s name. They both have broken OFAC rules. Institution A might get a criminal referral and an egregious case penalty that could be in the tens or hundreds of millions of dollars. After application of the voluntary self disclosure and remediation credit, Institution B could receive a Cautionary Letter, a Finding of Violation or a small civil penalty. The same underlying determination that there was a breach, but with different results.

OFAC’s Economic Sanctions Enforcement Guidelines employ a matrix considering the seriousness of the violation and whether the institution voluntarily disclosed the conduct. The matrix then adjusts the sanction up or down based on eleven specific factors set out in 31 CFR Part 501, Appendix A. Aggravating factors include the presence of prior similar apparent violations, knowledge of the conduct at issue, damage to sanctions program objectives, the individual characteristics of the subject person (including size and sophistication), the structure and functioning of the compliance program at the time of the violation, and the existence of willful or reckless conduct. Factors that mitigate include a remedial response following the violation, cooperation with the investigation and the existence of an effective compliance program. In particular, a qualifying voluntary self-disclosure results in a base penalty amount at least 50 percent lower than in comparable cases without one. The violation itself is a fixed determination from the transaction record but the result of applying all of these adjustments can range from a Cautionary Letter with no monetary penalty to civil penalties in the tens or hundreds of millions of dollars.

FinCEN assesses program sufficiency. If your monitoring program was well designed, calibrated correctly, and you filed SARs when you saw suspicious activity, you may not be in violation if a money launderer moves funds through your institution. FinCEN’s Statement on Enforcement of the Bank Secrecy Act, issued in August 2020, codified the agency’s use of the risk based analytic framework. The framework asks a preset set of questions. Was there a compliance program at the institution? Was it intentionally built and populated to match the risk profile of the institution’s clients, products and geographies? Did the institution carry out the plan that was written down? Did it have the ability to detect and report the suspicious activity which its program was reasonably designed to detect? Did the institution now resolve deficiencies identified by the regulators, auditors or the institution itself? The standard is not a spotless record. The standard is a reasonable, risk based and well implemented program.

One of the most important FinCEN enforcement actions in recent years was the $1.3 billion penalty against TD Bank, which was based on the same finding as a number of other large enforcement actions: The institution’s overall program was structurally insufficient for the risk profile in which it was operating, rather than it overlooked a specific suspicious transaction. TD Bank’s action documented systemic failures in staffing, technology and monitoring calibration that allowed years of suspicious activity to pile up without the requisite SAR coverage. That’s the FinCEN test in action. It is not ‘did you catch this transaction,’ but ‘was your program capable of catching this kind of transaction?’

Compliance teams will have to create programs that directly address these issues.

Completeness is OFAC’s operating rule. Assess each customer, counterparty and transaction against each relevant list at each relevant point in time. One missed match is equivalent to one violation. Partial credit for good faith does not exist when the outcome is a successful match. The system must be complete and cover all touchpoints.

Mceclip0 29

This obligation is further supported by the 50 Percent Rule, which requires institutions to screen not only against listed persons but also against entities that are 50 percent or more owned, individually or collectively and directly or indirectly, by SDN-listed persons, even if those downstream entities are not named on any list. The Russia sanctions program has been particularly educational in this regard, as the complex, layered ownership structures used by sanctioned oligarchs have forced regulator expectations toward aggregate ownership analysis that legacy screening architectures were never built to perform. Comprehensive means really comprehensive, not “the list plus what’s easy to check.”

FinCEN works on the principle of adequacy. Create a suitable program that fits your particular risk profile. Monitor transactions that your risk assessment determines are material. Identify the patterns your typologies map out. Report any suspicious activity you observe. The FinCEN framework doesn't count every miss as a violation, because every program will miss things. However, a structurally deficient program is a violation. This difference allows a well designed program to survive a single failure, but condemns a badly designed program, even if the individual outputs look acceptable in isolation.

Both rest on the operational principle of documentation. In an OFAC enforcement action, your documentation is your mitigation for the penalty. The compliance program factor and the remedial response factor require evidence, which is defined as contemporaneous records, not reconstruction. In a FinCEN exam or enforcement matter, your documentation is your program adequacy evidence. The “was the program reasonable?” test is influenced by such things as risk assessments, alert dispositions, and training records. Their substantive tests are different. But the audit trail that decides the outcome in both regimes is the combination of what you did, why you did it and what you found.

That whole distinction can be summed up in one sentence: OFAC requires completeness. Adequacy is required by FinCEN. The most successful programs to fight both regimes are those that recognize the difference from the start and build them accordingly.

How they overlap in practice

Obligations of OFAC and FinCEN are not two parallel workflows in daily compliance operations. They overlap constantly and often a single transaction will give rise to obligations under both. The six most important overlap patterns are as such:

Both regimes are triggered by a sanctions match. The screening process identifies a customer as a potential SDN match. OFAC is required to block the transaction and file a Blocked Property Report within ten business days. Depending on the underlying investigation, the same event could also trigger a SAR under FinCEN. For instance, if the customer’s attempt to route a payment to an Iran related entity uncovers a larger scheme of suspicious activity beyond the sanctions hit, then a SAR may be appropriate. If so, both filings are needed for one triggering event and the stories to support both need to be consistent with each other.

AML investigation finds a sanctions nexus. The opposite pattern is just as frequent. Your AML monitor flagged an unusual pattern of transactions. The subsequent investigation revealed that a beneficiary is related to a sanctioned entity. This could be due to beneficial ownership under OFAC’s 50 Percent Rule or a corporate chain that was missed in the initial screening. FinCEN’s obligation is to file the SAR describing the pattern. OFAC’s role is to report and block any subsequent transactions. This is where sanctions compliance and AML come together in real life: The sanctions exposure was found as part of the AML investigation. This has been the pattern in a number of high profile enforcement actions in recent years, including cases related to Russia sanctions evasion via third country corridors, with the AML monitoring layer being the first line to catch what sanctions screening missed.

Trade finance and correspondent banking. In some areas of correspondent banking and trade finance, the overlap is almost total. A letter of credit with a sanctioned counterparty is an OFAC issue. The same instruments are of concern to FinCEN for facilitating trade based money laundering. The evidence for both determinations is contained in the same underlying documents such as invoices, bills of lading, letters of credit and insurance certificates. In this area effective controls are screening against sanctions lists and applying TBML typologies to the same document set in a single review workflow.

Overlap of examinations. OFAC compliance is reviewed as part of the BSA/AML exam cycle, but is separately subject to regulatory review. Examiners frequently test sanctions screening (an OFAC obligation) and transaction monitoring (a FinCEN obligation) in adjacent testing phases during the same examination. But to fail one doesn’t necessarily mean you pass the other. If an institution has a good AML transaction monitoring program and bad sanctions screening or vice versa, the test results will be indicative of each regime separately. The FFIEC BSA/AML Examination Manual clarifies that OFAC regulations are not part of the BSA, but they are examined concurrently with the BSA cycle.

Customer onboarding. When onboarding an institution, customer due diligence (CDD) and customer identification program (CIP) (FinCEN/BSA obligations) and screening against OFAC lists (sanctions obligation) are required. Both duties are part of the same process and are, in a good system, performed as one integrated screening operation and not two separate ones. The Sanction Scanner Fusion platform checks for both in a single scan during customer onboarding.

Customer lifecycle continues. Overlap does not stop onboarding. Both regimes require the institution to keep track of the evolving risk profiles of customers, such as the introduction of new products, the expansion of geographic limits, changes in ownership and the release of negative media. OFAC requires the customer to be rescreened against updated sanctions lists as they are updated, which may be weekly. FinCEN requires that the customer risk profile be updated and that ongoing monitoring be adjusted to reflect the changed situation. The most efficient programs rerun both checks on the same triggering events, so that one customer record update can flow through both regimes instead of requiring two separate refresh cycles.

Mceclip3 16

What financial institutions need to do for both

The operational obligations are clearly separated into two lists with the caveat that neither list can operate on its own; they need to run in parallel with clear escalation paths between them.

In accordance with OFAC regulations:

☐ Confirm all customers are not on the OFAC list before onboarding.

☐ Screen all transactions (wires, ACH, SWIFT) against OFAC lists prior to processing.

☐ Track for list updates, OFAC updates its lists without prior notice, and may issue multiple updates in a week.

☐ Report and block any transaction involving a sanctioned party (Blocked Property Report within 10 business days).

☐ Maintain a documented OFAC Sanctions Compliance Program (SCP) in accordance with OFAC’s May 2019 framework.

☐ Reject transactions involving comprehensively sanctioned jurisdictions.

☐ Apply 50 Percent Rule: deny entities owned 50 percent or more by SDN listed persons, individually or in the aggregate, even if not on the list.

☐ Screen against Non-SDN lists, as applicable (SSI, FSE, CAPTA).

Mceclip1 25

To comply with FinCEN and BSA requirements:

☐ Implement a BSA/AML compliance program, including the five pillars of internal controls, independent testing, a designated BSA Officer, training, and CDD (added May 2018). Risk assessment is a fundamental expectation.

☐ On boarding: CDD and CIP for each individual including name, date of birth, address and ID number.

☐ Identify beneficial owners of legal entity customers (25% ownership threshold + control person)

☐ Monitor transactions for suspicious activity, as defined by the risk profile of the institution, on an ongoing basis

☐ File SARs within 30 days of detection (60 days if unknown subject).

☐ File CTRs for cash transactions over $10,000 within 15 days.

☐ Acknowledge Section 314(a) law enforcement requests within 14 days

☐ Where appropriate, engage in voluntary information sharing under Section 314(b).

☐ File any other required BSA reports (for example, FBARs where applicable) on their required schedules

Escalation between the two routes. The combined requirement is not just to run both programs. It’s to create explicit escalation pathways between the two. Your screening system should not only trigger OFAC reporting for a sanctions match, but it should also route the match to the AML case queue for pattern analysis, as the context of the transaction often determines if a SAR is also required. However, an AML alert for a possibly sanctioned counterparty must be sent to the sanctions review workflow, which can stop the transaction until the issue is resolved. The most common program design gap in this space is not the presence of both workflows, but the lack of bridges between them. For example, a sanctions team files the OFAC report and does not ask the AML team if a SAR is also required, or an AML team closes a case as false positive without checking that no sanctions nexus was missed. In practice, institutions with mature programs apply a unified case management perspective. Both perspectives are visible in the same case, avoiding any cross signal between teams.

Common compliance mistakes in both regimes

Some program failures are found in institutions that repeatedly have examination findings or enforcement exposure. The most cost effective way to improve programs is to understand them upfront.

Consider the two regimes as one programme. The most basic mistake. Those institutions that build “sanctions and AML compliance” as one undifferentiated function eventually learn (usually during an examination) that the operational tests, documentation requirements and failure modes are different. Successful programs treat sanctions and AML as two distinct disciplines with clean interfaces between the two rather than a combined function that cannot pass either test cleanly.

Screening of SDN list only, not Non-SDN list. The most famous of the sanctions lists is the SDN list, but it is not the only one. An SDN only screening operation will completely miss restrictions imposed by the Foreign Sanctions Evaders (FSE) List, the Non-SDN Correspondent Account or Payable-Through Account Sanctions (CAPTA) List (correspondent account and payable through account sanctions), and the Sectoral Sanctions Identifications (SSI) List. “Regulators have repeatedly identified gaps in coverage against these lists in enforcement actions.

Fixed rule sets that never change. From the FinCEN side, the most common finding is transaction monitoring rules that were calibrated at some point in the past, often years ago, and never reviewed. The rules didn’t change, the product mix changed, the threat landscape changed, the customer base changed. The program, which was well designed at the time of calibration, is in a state of poor design for the present book, empirically.

Documentation deficits. In both regimes, situations that could be recovered are unrecoverable if there is no contemporaneous documentation. There is no compliance program mitigating factor for an OFAC violation in the absence of an evidenced compliance program. Without an evidence based risk assessment, a FinCEN examination cannot demonstrate that the monitoring was risk based. The rule of thumb is that if an event does not get recorded in the moment, it did not happen in the evidentiary universe of the regulator.

Delayed remediation. Remediation is a priority in both the OFAC and FinCEN frameworks. Significant credit is given where institutions act quickly to remedy deficiencies with documented actions, timelines and completion. Institutions which discover an omission and allow it to remain uncorrected until an examination is made are treated just the opposite. The delay itself is an aggravating factor.

Poor escalation between AML functions and sanctions. One of the most consistent gaps in mature programs is the lack of defined pathways between the two functions. SARs don't have the context of sanctions, Blocked Property Reports don't have the context of suspicious activity. Signals get lost as they go from one team to another. Workflow design can resolve the gap, but it can not be detected until it is uncovered by an examination or enforcement action.

How Sanction Scanner Can Help You Comply with Both

Most compliance software solutions are focused on either sanctions (OFAC) or anti money laundering (FinCEN). In reality, financial crime compliance’s operational reality is that the two obligations are inextricably linked, and Sanction Scanner’s Fusion platform is designed to encompass both mandates in a single, integrated system.

Obligation

OFAC Requirement

FinCEN Requirement

Sanction Scanner Capability

Screening

SDN, SSI, FSE, CAPTA, country programs

PEP, adverse media, ongoing screening

AML Screening 3,000+ lists, real-time and ongoing

Monitoring

List updates, blocked transactions

Suspicious activity detection, typology-based scenarios

Transaction Monitoring + Ongoing Monitoring

Reporting

Blocked Property Reports (10 days)

SARs (30 days), CTRs (15 days)

Case management with SAR-ready documentation and filing timeline tracking

Risk Assessment

OFAC sanctions risk assessment

BSA/AML risk assessment

Customer Risk Assessment with dynamic scoring

Documentation

SCP documentation and audit trail

Program documentation and alert trail

Complete audit trail across every module

What it does is feed CDD with sanctions/PEP/adverse media checks and check OFAC lists, all in one screening operation at onboarding, instead of two separate screening operations with reconciliation. One transaction monitoring engine that finds both suspicious patterns (FinCEN) and sanctions hits (OFAC) rather than two disconnected engines that don’t find cross signals. One case management system records the audit trail that determines outcomes in both regimes and also records OFAC blocked transaction reports and SAR investigations.

The architectural point that runs throughout this article is that OFAC and FinCEN ask different questions, apply different standards and produce different results. But they work on the same customer, transaction and institution and are best combated as one integrated program rather than two separate ones.

Mceclip4 10

Sources

[1] eCFR, U.S. Code of Federal Regulations. Appendix A to Part 501, Title 31: Economic Sanctions Enforcement Guidelines. 2026.

[2] Office of Foreign Assets Control, U.S. Department of the Treasury. Basic Information on OFAC and Sanctions. 2024.

[3] U.S. Office of Management and Budget. Memorandum M-26-11: Cancellation of Penalty Inflation Adjustments for 2026. 2026.

[4] Financial Crimes Enforcement Network. FinCEN Statement on Enforcement of the Bank Secrecy Act. 2020.

[5] Financial Crimes Enforcement Network. FinCEN Assesses Record $1.3 Billion Penalty against TD Bank. 2024.

[6] eCFR, U.S. Code of Federal Regulations. 31 CFR 1020.320: Reports by Banks of Suspicious Transactions. 2025.

FAQ's Blog Post

OFAC updates its sanctions lists on no fixed schedule and without advance notice, sometimes several times in a single week. Because a customer who was clear at onboarding can become sanctioned later, institutions are expected to rescreen their customer base against the latest lists, not only at the initial check.

OFAC and FinCEN examinations test different things, so an institution can pass one and fail the other. Sanctions screening and transaction monitoring are usually reviewed in the same BSA/AML exam cycle but under separate standards, meaning a strong AML program does not make up for weak sanctions screening, or the reverse.

Accidental sanctions violations can still trigger OFAC liability, because sanctions enforcement uses a strict liability standard where intent is not required for a violation to occur. Good faith and a failed screening system do not erase the violation, though voluntary self-disclosure, cooperation, and a strong compliance program can substantially reduce the penalty.

Bank Secrecy Act obligations fall on BSA-defined financial institutions, including banks, credit unions, money services businesses, broker-dealers, casinos, and certain others. These entities must maintain an AML program, monitor for suspicious activity, and file SARs and CTRs. Unlike OFAC sanctions, the BSA does not bind every US person or business.

OFAC sanctions apply to all US persons, meaning US citizens and permanent residents wherever located, everyone physically in the United States, and all US-incorporated entities and their foreign branches. This reach is much broader than the Bank Secrecy Act, which binds specific categories of financial institutions rather than every person and company.

A Blocked Property Report is the filing OFAC requires when an institution freezes property connected to a sanctioned party. It must be submitted to OFAC within 10 business days of blocking, and blocked assets are also disclosed in an annual report. It is a sanctions obligation, separate from any SAR filed with FinCEN.

A SAR and a CTR are both FinCEN filings but serve different purposes: A Suspicious Activity Report flags transactions that appear linked to illicit activity and is filed within 30 days of detection, while a Currency Transaction Report is filed for any cash transaction over $10,000, within 15 days.

OFAC 50 Percent Rule treats any entity owned 50% or more, directly or indirectly, by one or more blocked persons as blocked itself, even if that entity is not named on any list. Ownership can be aggregated across multiple sanctioned parties, so screening only named entities leaves a significant gap.

OFAC SDN list, short for the Specially Designated Nationals and Blocked Persons List, names individuals, entities, and vessels whose US assets must be frozen and with whom US persons are prohibited from transacting. It is OFAC's most prominent sanctions list, though not the only one institutions must screen against.

OFAC and FinCEN are separate bureaus of the US Department of the Treasury, not one inside the other. OFAC administers and enforces economic sanctions, deciding who you cannot do business with, while FinCEN oversees anti-money laundering rules under the Bank Secrecy Act, focusing on detecting and reporting suspicious activity.