OFAC Sanctions Compliance for Nonprofits: A Practical Guide
Learn what OFAC sanctions compliance means for nonprofits. Practical screening steps, due diligence tips, and risk scenarios explained in plain English.
On this page
OFAC enforcement is expensive enough that small nonprofits shouldn't treat screening as optional. In 2023 alone, OFAC issued 17 public enforcement actions and imposed more than $1.5 billion in civil penalties, while 2024 still saw roughly $48.8 million across 12 public enforcement actions.
If you're running a nonprofit, OFAC sanctions compliance means checking volunteers, donors, vendors, and partners against the U.S. Treasury's blocked-party lists and handling possible matches with a real process, not a casual Google search. Skip it, and you can create exposure before any payment even settles, because the risk isn't just money moving. It's the relationship, the service, the benefit, or the transaction path touching a blocked person.
A lot of nonprofit teams are in the same spot right now. A volunteer coordinator is onboarding helpers for a weekend event. Development is cleaning up recurring gifts. Operations is trying to pay a new overseas vendor. Nobody thinks of this as sanctions work, because it doesn't look like banking or export control. That's the mistake.
Most sanctions failures in nonprofits don't come from bad intent. They come from ordinary workflows with weak screening, no escalation path, and zero re-checking after intake. That's checkbox theater. Real OFAC sanctions compliance is operational.
Table of Contents
- What OFAC Sanctions Compliance Means for Nonprofits
- How OFAC Lists Work
- The Five Pillars of an OFAC Compliance Program
- Where Sanctions Risk Lives in a Nonprofit
- A Practical Screening Workflow You Can Run
- Beyond the Name Match Ownership and Ongoing Change
- Penalties Recordkeeping and Your Next Steps
- Common OFAC Compliance Questions Answered
What OFAC Sanctions Compliance Means for Nonprofits
A youth mentoring charity in Ohio accepts a recurring donation pledge from the cousin of a volunteer coordinator. The donor's name matches an SDN entry closely enough to trigger concern later. No money moves for months because the donor never completes the payment setup. Staff assume that means there's no problem.
That's the wrong instinct.

It applies to ordinary nonprofit work
For a nonprofit, OFAC sanctions compliance is the discipline of avoiding dealings with blocked persons and sanctioned parties maintained by the U.S. Treasury's Office of Foreign Assets Control. That includes money, of course, but also services, support, vendor relationships, volunteer roles, and cross-border partnerships.
If your team still thinks sanctions rules belong only to banks, fix that assumption now. A useful plain-English refresher on broader compliance rules for businesses helps frame why this matters outside financial institutions.
OFAC's own compliance framework says organizations subject to U.S. jurisdiction, and even foreign entities doing business in or with the United States or using U.S.-origin goods or services, are expected to build a risk-based sanctions compliance program to their size, counterparties, products, services, and geographies (OFAC framework guidance).
The four nonprofit workflows that matter most
Most nonprofit exposure shows up in the same four places:
- Donor intake: New donations, recurring gifts, foreign-origin funds, and donor-advised disbursements.
- Volunteer onboarding: Especially where volunteers receive access, travel support, stipends, or operational authority.
- Vendor selection: Payment processors, contractors, software resellers, logistics providers, and consultants.
- Cross-border partnerships: Grantees, field partners, schools, churches, and community organizations abroad.
Practical rule: If a person or entity can give your organization money, receive money from it, deliver services to it, or act in its name, screen them.
If your volunteer process is still informal, this walkthrough on OFAC checks in volunteer background screening is worth reviewing with whoever owns onboarding.
The key point is simple. Compliance is preventive. You don't wait for a wire to clear and then ask whether you should have screened. You screen because relationships themselves can create sanctions risk.
How OFAC Lists Work
A volunteer coordinator clears a new field volunteer on Monday. Finance approves a grant payout to a small partner on Thursday. Nothing looked wrong at intake. Then a sanctions update hits, or you learn the partner is owned by a blocked person through a parent company that never appeared on your basic screen. That is how nonprofits get caught. Not because nobody ran a search, but because they treated OFAC screening like a one-time name check.
OFAC uses several list families, and they do different jobs. If your team treats all matches the same, you will either freeze routine work for no reason or miss a restriction that matters.
What sits on the lists
The SDN List is the one nonprofit staff need to respect most. A true match can create blocking obligations and stop the relationship cold.
OFAC also maintains non-SDN lists and other program-based restrictions. Those can limit certain dealings without creating full blocking in every case. For a nonprofit, that distinction matters when you are reviewing donors, paying vendors, onboarding volunteers with access, or funding cross-border partners.
Here is the working view:
| List | Effect of a Match | Typical Nonprofit Relevance |
|---|---|---|
| SDN List | Full blocking concerns and strongest restrictions | Donors, vendors, grantees, volunteers, partner organizations |
| Consolidated Non-SDN Lists | Program-specific restrictions, not always full blocking | Vendors, counterparties, service providers, cross-border activities |
| Sectoral sanctions lists | Limits tied to specific sectors or activities | Financial relationships, procurement, overseas partnerships |
| Program-specific non-SDN lists | Restrictions vary by sanctions program | International projects, specialized vendor relationships |
If your team needs a plain-language refresher on search logic, this guide to an OFAC sanctions list search lays out the mechanics.
Why list screening breaks down in nonprofits
Nonprofits rarely fail because they skipped the SDN List on purpose. They fail because the workflow is too shallow.
A donor gets screened once at the first gift, then keeps giving for years. A volunteer is screened at onboarding, then later receives travel funds, admin access, or authority over local distributions. A foreign partner passes a name check, but nobody asks who owns it or whether its control changed after the agreement was signed.
That is the gap.
OFAC's own FAQ explains that when an alert appears, the organization has to determine whether it matches a sanctions list or program and then investigate before deciding whether to block, reject, or proceed (OFAC FAQ 5). So a match is the start of review, not the end of it.
Names alone are not enough. Screening has to account for aliases, alternate spellings, reordered names, and transliterations. Staff also need a simple triage rule so common names do not trigger panic and bad names do not get waved through.
A sanctions hit means "review this relationship now," not "same name, same person."
The point many nonprofit teams miss
Lists change. Ownership changes. Programs change. OFAC publishes frequent updates and enforcement-related changes on its recent actions page.
That is why one-and-done screening is weak control design for nonprofits. Your highest-risk relationships need rescreening over time, and entities need ownership review when money, services, travel support, or field authority are involved. If your process stops at intake, it is incomplete.
The Five Pillars of an OFAC Compliance Program
Nonprofits get in trouble when sanctions screening is treated like a one-time purchase instead of an operating discipline. A tool can screen a donor name or volunteer applicant. It cannot decide who needs review, when to rescreen, how to handle a possible hit, or who checks ownership before funds or authority are handed over.
Right near the start of your program design, use this visual with leadership and operations:

OFAC organizes sanctions compliance around five core pillars: management commitment, risk assessment, internal controls, testing or auditing, and training. For a nonprofit, those pillars have to show up inside donation intake, volunteer onboarding, vendor payments, travel support, and partner oversight.
What each pillar looks like in real nonprofit operations
Management commitment starts at the top. The executive director and board should approve a short sanctions policy, assign one accountable owner, and make clear that no program deadline or fundraising target overrides review. If leadership treats sanctions as clerical cleanup, staff will do the same.
Risk assessment means mapping your real workflows, not copying a template from a bank. Look at recurring donors, major gifts, volunteer placements, overseas grantees, fiscal sponsorships, reimbursed travel, cash assistance, procurement, and any situation where someone gains access to money, goods, or decision-making power.
Internal controls are the written rules people follow. Define who gets screened, at what point in the workflow, what names and entities get checked, how potential matches are escalated, who can clear them, and when rescreening happens. Include ownership review for entities. Screening only the legal name on an invoice or agreement is weak control design.
Testing and auditing means pressure-testing the process against normal nonprofit activity. Pull samples from cleared donor records, volunteer files, partner files, and payment batches. Check whether staff documented match resolution, whether repeat screenings happened on schedule, and whether ownership questions were asked when they should have been.
Training should be brief, role-based, and practical. Development staff need to know what to do with a donor alert. Program staff need to know when a foreign partner, traveler, or local distributor needs escalation. Finance needs to know that payment release is a control point, not just an accounting step.
The pillars nonprofits neglect first
The breakdown usually happens in the same three places.
- No clear owner: If nobody owns sanctions decisions, alerts sit in inboxes or get cleared by the wrong person.
- Weak rescreening rules: A donor, volunteer, or partner may look clean at intake and change later. If your process ends after onboarding, it misses the control that matters.
- No ownership logic: Entities can present low risk on the surface while blocked ownership or control sits behind them. That risk shows up in vendors, local partners, and counterparties receiving funds or equipment.
These are fixable problems. Put one person in charge. Set rescreening triggers and intervals for higher-risk relationships. Require ownership review before approving entity payments, overseas partnerships, or field authority.
Use the video below only as a basic orientation tool for staff who are new to sanctions concepts. It does not replace your policy, triage steps, or review standards.
Screening technology is one internal control. Your program stands or falls on ownership, rescreening, escalation, and documented decisions.
Where Sanctions Risk Lives in a Nonprofit
Sanctions risk doesn't usually show up wearing a villain costume. It arrives as normal nonprofit activity with thin context and too much trust.

Five situations that deserve immediate scrutiny
A wire donation lands through an intermediary bank your development team didn't expect. The donor may be known to you, but the routing path changes the risk picture. If a sanctioned jurisdiction or blocked institution is in the chain, you need review before anyone treats it as routine revenue.
An international volunteer is flying in for a short service trip. Staff focus on housing, transportation, and liability waivers. Nobody asks whether nationality, travel routing, or affiliated organizations create sanctions issues.
A contractor offers donated or discounted laptops for a community lab. The operating company looks clean. The beneficial owners don't. Nonprofits get burned by screening only the invoice name.
A scholarship applicant transfers from a partner institution in a sanctioned region. Academic staff may see only admissions criteria. Compliance has to ask whether the relationship involves prohibited services, funds, or blocked interests.
A board member's spouse takes a leadership role at a listed company. That doesn't automatically create a violation, but it can change conflict, vendor, or fundraising risk around related transactions.
Risk rises when counterparties get harder to see
The point isn't paranoia. It's opacity. Nonprofits work through sponsors, churches, foreign intermediaries, foundations, volunteers, and local project partners. Those structures create distance between your team and the counterparty.
That's also why digital asset donations deserve extra attention. If your organization accepts crypto, this overview of crypto economy shifts under sanctions is useful context for understanding how sanctions risk can move through less transparent channels.
A simple nonprofit exposure map
Use a practical heat map instead of abstract scoring:
- Low exposure: Domestic volunteers, local cashless donations, established U.S. utilities vendors
- Medium exposure: New vendors, recurring donors with limited identifying data, board-related counterparties
- High exposure: Cross-border projects, foreign intermediaries, crypto donations, overseas travel, unfamiliar grant partners
The common thread is simple. Risk hides where identity, ownership, or transaction routing is incomplete.
A Practical Screening Workflow You Can Run
A volunteer coordinator, development associate, or operations lead can run this workflow without a bank-sized team. That is the standard to aim for. If the process only works when legal, finance, and a spreadsheet power user all happen to be available, it will fail the first time a volunteer signup, donation, or vendor payment needs a same-day answer.

Stage one through stage three
Collect the right data at intake
Start where nonprofits work. Volunteer forms, donor forms, vendor setup, grant partner onboarding, and travel approvals should all capture enough information to screen a real person or entity, not a nickname and an email address. For individuals, collect full legal name and other identifiers your process can lawfully support, such as date of birth, nationality, address, or ID details where justified. For entities, collect legal name, registration details, address, and ownership information when the relationship or geography raises risk.Run screening against the lists that matter
Screen names through OFAC tools or software that checks the SDN list and relevant non-SDN lists, and that can catch aliases, transliteration issues, and reversed name order. Exact-name matching is weak control theater. It misses the kinds of variations that show up constantly in volunteer rosters, donor records, and overseas partner files.Triage alerts instead of freezing every intake file
Your first pass should sort results into clear false positives, possible matches, and likely matches. A common-name hit with the wrong country and no overlapping identifiers does not deserve the same response as a close match tied to the same location, birth date, or entity details. Staff need permission to clear obvious noise fast, and a rule for when to stop and escalate.
A useful primer on screening mechanics is this CEFCore sanction screening resource, especially if your team still checks names manually.
Stage four and stage five
Escalate possible matches with a written decision tree
Frontline staff should not guess. If a volunteer applicant, donor, grantee, or vendor produces a plausible hit, pause the onboarding step or transaction internally, send it to the designated reviewer, and document what triggered the hold. Your decision tree should say who reviews the alert, what identifiers must be checked, when to request more information, and who has authority to approve, reject, or seek legal advice.Record the search and keep the file
Save the search date, the lists checked, the matched names, the reviewer, the final disposition, and the support for that decision. Keep the screenshots or case notes. Treasury has also updated sanctions recordkeeping expectations in recent years, so this is not the place to be casual. For current sanctions program updates and rulemaking notices, use Treasury and OFAC pages such as the OFAC recent actions and updates page.
Tool choices that make sense
Pick tools based on volume, geography, and how your nonprofit takes in people and money.
- Free OFAC search portal: Fine for occasional manual checks. Poor for repeatable audit trails, shared review, and rescreening.
- Screening platforms: Better if you need ongoing monitoring, alias handling, ownership review, and case management.
- CRM or onboarding integrations: Useful if donor intake, volunteer applications, and vendor approvals already live in one system.
If you want sanctions screening built into volunteer background screening, VolunteerBadge includes OFAC sanctions and global watchlist checks as part of its workflow. That setup can keep volunteer intake and sanctions review in the same process instead of splitting them across separate tools.
Beyond the Name Match Ownership and Ongoing Change
Your finance manager approves a new overseas vendor. The name clears. The invoice gets paid. Two months later, you learn the company is controlled by a blocked party through a holding structure that never showed up in the first screen. That is how nonprofits get into trouble. Not through exotic trade deals, but through ordinary payments, volunteer placements, grants, and partner onboarding.
Ownership changes the answer
A clean name match is only the first check. It is not the decision.
OFAC can treat an entity as blocked based on ownership and control, even if the operating name you screened does not appear on the SDN List. In nonprofit work, that risk shows up in places teams overlook. Fiscal sponsors. Local implementing partners. Vendors tied to a board member abroad. Donors using intermediaries. Volunteer placements arranged through third-party organizations.
Treasury has also warned that formal paperwork does not end the analysis where ownership changes appear designed to hide the party in interest. Read OFAC's guidance and FAQs on the 50 Percent Rule and related ownership questions. The practical takeaway is simple. If the facts suggest paper ownership and control do not match, stop treating the intake form as the whole story.
Ask harder questions when the risk is higher. Who owns the entity. Who can direct funds. Who benefits from the transaction. Did ownership change right before onboarding. Is the contact pushing unusual urgency, substitute bank details, or a payment route that makes no program sense.
What proper screening requires
| Check | One-Time Name Match | Ownership-Aware Ongoing Screening |
|---|---|---|
| Direct name screening | Screens the person or entity name once | Screens at onboarding and again when the relationship changes |
| Alias handling | Often limited or manual | Built into review and checked during triage |
| Beneficial ownership review | Commonly skipped | Required for higher-risk vendors, partners, and grantees |
| Program changes and delistings | Missed after the first check | Picked up through periodic or event-based re-screening |
| Audit support | Thin screenshots or no trail | Decision notes, supporting documents, and retained evidence |
Ongoing monitoring beats annual box-checking
Nonprofits tend to screen at intake and then forget about the person or entity for a year. That is a weak control. Sanctions lists change. So do counterparties. A donor changes employers. A volunteer moves countries. A local partner adds a new owner. A vendor starts asking for payment through a different bank.
If your process only runs at signup, your file is aging out the minute you save it.
Use re-screening triggers tied to real workflow events:
- New donation pattern or unusual payment route
- Contract renewal, new invoice contact, or bank change
- International travel, shipment, or program launch
- Board, officer, or ownership change
- Cross-border grant approval or disbursement
- Volunteer placement with a new host organization
This matters more in nonprofits than many teams realize. Your highest-risk touchpoints are often human and operational, not just financial. A volunteer coordinator may onboard a host site. A development staffer may accept a large gift through an intermediary. A program lead may hire a local consultant fast because the grant clock is running. Those are exactly the moments where ongoing monitoring catches what one-time screening misses.
You do not need enterprise software to fix this. You need rules your staff will follow, a short list of triggers, and a record of what changed and who reviewed it.
Penalties Recordkeeping and Your Next Steps
The reason to take this seriously isn't theoretical. OFAC can and does enforce at scale.
From 2006 through 2020, OFAC imposed $5.68 billion in civil money penalties, which shows the cumulative weight of sanctions enforcement over time (sanctions enforcement summary). In 2023, OFAC issued 17 public enforcement actions and imposed more than $1.5 billion in civil penalties, while 2024 dropped to roughly $48.8 million across 12 public enforcement actions (Paul, Weiss sanctions year-in-review). Those swings are exactly why nonprofits shouldn't rely on “we're too small to matter” logic.
What to do this quarter
Turn all of this into five concrete actions:
- Name an owner: Assign one person to own sanctions screening, escalations, and record retention.
- Write the policy: Keep it short. State who gets screened, when re-screening happens, and who approves dispositions.
- Pick a workable tool: Use something that handles aliases, supports documentation, and can accommodate ownership review when needed.
- Set a re-screen cadence: Quarterly is a reasonable baseline for many nonprofits, with immediate re-screening for material events.
- Rehearse the response: Walk through what happens when a likely hit appears. Don't wait for a real alert to discover no one knows the next step.
A lot of teams also need to tighten their file discipline. This guide to compliance documentation practices is a useful starting point for building an audit trail that staff can maintain.
The standard to aim for
You are not trying to look complex. You are trying to be defensible. That means your nonprofit can show it had a risk-based process, followed it consistently, escalated real issues, and kept the records.
Common OFAC Compliance Questions Answered
How often should a nonprofit re-screen?
Quarterly is a practical baseline for many organizations. Re-screen sooner when there's a material event, such as a new donation path, overseas travel, contract renewal, beneficial ownership change, or a new cross-border partner.
What should staff do with a possible positive hit?
Pause the transaction or onboarding step internally. Escalate it to the designated reviewer or counsel. Don't let frontline staff clear or reject the matter casually.
Do volunteers need OFAC screening too?
Yes, when the role creates a real organizational relationship or benefit flow. Volunteers can receive access, travel support, stipends, equipment, or authority. Treat that as a sanctions-relevant touchpoint.
What about fuzzy matches that look weak?
Weak matches still need review, but not panic. Compare additional identifiers such as date of birth, address, nationality, entity details, and known aliases. Document why you cleared it.
Is the free OFAC search enough?
It's useful for low-volume manual checks. It isn't enough by itself if you need audit trails, repeatable triage, ownership-aware review, or ongoing monitoring. The free tool is a search function. A compliance process is bigger than a search box.
VolunteerBadge helps nonprofits fold OFAC screening into volunteer onboarding without building a bank-style compliance stack from scratch. If you need a practical way to screen volunteers and keep the process tied to real documentation, visit VolunteerBadge.
