Skip to main content
Your Sanctions Controls Don't Stop FacilitationRegulations and Standards
4 min readFor AML/KYC Compliance Officers

Your Sanctions Controls Don't Stop Facilitation

The Conventional Wisdom

Many compliance teams see OFAC sanctions as a simple screening task. You set up a watchlist system, check counterparties against the Specially Designated Nationals (SDN) List, and block any matches. If a transaction doesn't involve a sanctioned entity directly, you assume it's safe.

This seems logical. Your sanctions policy likely states "we prohibit transactions with sanctioned parties." Training modules show examples of blocked wire transfers. Audit checklists confirm screening at onboarding and transaction time. The belief is: if your screening works, you're compliant.

Why We Disagree

Screening controls catch primary violations but miss facilitation and causing violations. These enforcement actions surprise compliance teams because they don't require direct contact with a sanctioned party.

OFAC's enforcement targets U.S. Persons who indirectly enable prohibited transactions. The regulation doesn't just ban dealing with sanctioned entities; it bans facilitating others' dealings with them. It also prohibits causing violations through misrepresentation. OFAC aggressively pursues new types of violations, meaning what seems lawful today might lead to a settlement tomorrow.

The issue isn't your technology; it's your control framework. Screening tools catch names and addresses but miss structural arrangements that enable sanctions evasion. They don't flag when your foreign subsidiary conducts business you couldn't do directly. They don't detect when expense reports reveal prohibited activity offshore.

The Evidence

Consider OFAC's enforcement actions. In the Schlumberger Oilfield case, the violation wasn't a wire transfer to Iran. It was U.S. employees approving expense reports for business in Sudan and Iran. The parent company supplied materials to its foreign subsidiary, which then engaged with sanctioned parties. OFAC deemed this facilitation because the U.S. entity enabled transactions it couldn't conduct directly.

This wasn't a screening failure. It was a structural arrangement your watchlist system wouldn't flag. The expense reports didn't name sanctioned entities, and the materials didn't ship to prohibited destinations. But the parent company's support for the subsidiary's sanctioned business triggered liability.

OFAC's jurisdictional definitions are broad. A U.S. Person includes permanent resident aliens, entities organized under U.S. laws, and foreign branches of U.S. companies. If you're a multinational financial institution with a U.S. parent and foreign subsidiaries, your corporate structure creates facilitation risk. Your foreign branch might legally serve customers under local law, but if your U.S. personnel approve transactions, supply systems, or provide operational support, you're potentially facilitating.

OFAC tests the boundaries of statutory definitions and acts against conduct it views as violating sanctions programs, even when not explicitly defined. Firms often find out OFAC disagrees with their practices only after an investigation begins.

What to Do Instead

Stop treating sanctions compliance as just a screening exercise. Approach it as a structural risk assessment.

Map your corporate architecture for facilitation exposure. Document every point where U.S. Persons interact with foreign subsidiaries in international business. This includes expense approval chains, shared services, technology provisioning, and personnel rotation. If your U.S. entity provides materials, systems, or support that enables a foreign branch to serve customers in high-risk areas, you have facilitation exposure.

Implement enhanced due diligence triggers beyond name screening. Your Customer Due Diligence (CDD) and Know Your Customer (KYC) controls should flag structural red flags: shell companies with unclear ownership, customers whose business depends on access to sanctioned markets, and counterparties requesting routing through foreign branches. These patterns don't trigger watchlist alerts but indicate potential sanctions evasion.

Review cross-border approval workflows. If U.S. personnel approve transactions, expenses, or operational decisions for foreign branches in high-risk areas, you're creating facilitation risk. Segregate approval authority so U.S. Persons don't enable transactions they couldn't conduct directly. Document the business rationale for every shared service crossing this boundary.

Train on causing violations, not just primary violations. Your team must understand that misrepresentation and obfuscation create liability even if your organization isn't the direct violator. If a customer lies about beneficial ownership to evade sanctions, and your institution processes the transaction, OFAC can pursue you for causing the violation. Your controls must detect inconsistencies in customer representations, not just match names against lists.

When the Conventional Wisdom Is Right

Screening is essential. You can't catch facilitation risks if you're missing primary violations. A robust watchlist screening program is the foundation, not the problem.

The conventional wisdom is right about one thing: sanctions compliance requires constant vigilance. Where it falls short is assuming vigilance means better screening technology. Real vigilance means questioning whether your corporate structure, approval chains, and customer relationships create indirect pathways to sanctioned parties.

If you're a domestic institution with no foreign branches, minimal cross-border activity, and straightforward customer relationships, your screening-focused approach probably covers your risk. The conventional wisdom works when your business model is simple.

But if you're a multinational institution, have foreign subsidiaries, provide correspondent banking services, or your customers operate in multiple jurisdictions, screening alone won't protect you. OFAC's enforcement reach extends to structural arrangements that enable sanctions evasion, and your controls need to match that scope.

The question isn't whether your screening works. It's whether your compliance framework addresses how your organization could facilitate violations you'd never conduct directly.

You Might Also Like