The U.S. Department of Treasury’s Office of Foreign Assets Control (OFAC) has become highly visible and active in 2026. The agency has even infiltrated popular culture, as Jon Hamm and James Marsden navigate OFAC sanctions violations in the Apple series Friends and Neighbors. As many companies have found out, however, OFAC penalties are far from fiction.
Indeed, non-compliance penalties are very real and they can be extremely costly, from both a financial and reputational perspective. OFAC fines have been steadily increasing over the years, from an annual total of US$3.5 million in 2003 to more than $265 million in 2025.
For companies and individuals involved in cross-border trade, the increased visibility and gravity of OFAC compliance is impossible to ignore. The U.S. administration has made it abundantly clear that national security and trade compliance are top priorities, imposing serious penalties that reflect OFAC’s continued regulatory expansion and aggressive enforcement.
Case in point: OFAC recently reached a $275-million agreement with a multinational company, settling its potential civil liability for apparent violations of Iran sanctions related to the importing of liquified petroleum gas.
Recordkeeping and reporting in the spotlight
What’s notable about some of the recent enforcement actions is the role that reporting and recordkeeping, in particular, have played. As part of a broader modernization initiative, OFAC recently updated its Reporting, Procedures and Penalties Regulations (RPPR), imposing mandatory electronic filing and extending recordkeeping requirements from five years to a decade. These changes reflect the government’s more data-driven approach to compliance enforcement moving forward.
Regulators expect organizations to show clear, traceable records for every sanctions-related decision, with gaps in reporting increasingly serving as an early indicator of weak compliance controls. Based on a company’s data completeness and accuracy, OFAC can assess whether escalation paths work and whether the organization’s data governance supports accurate decision-making. OFAC is increasingly using reporting data to identify anomalies, exposure points, and patterns of non-compliance.
To satisfy OFAC’s stringent RPPR requirements, companies must present documentation that demonstrates compliance at every stage of the process:
- Identification – a record of the screening for unsanctioned parties, plus details of what sanctions lists and compliance tools were used for screening.
- Review – a record of who reviewed the screening results.
- Escalation – a record of if, and why, results were escalated, providing transparency into how decisions were assessed.
- Determination – a record of “block” or “reject” decisions to prove risk mitigation.
- Reporting – submission of reports to OFAC within the initial 10-day reporting deadline, plus annual blocked property reports.
- Retention – maintaining complete, retrievable records for the newly-expanded 10-year period.
- Voluntary self-disclosure (VSD) preparation – collection of documentation to help assess the scope of an incident to support a VSD. Robust recordkeeping simplifies the VSD process.
How well an organization meets RPPR obligations provides a view into the efficacy of its sanctions compliance program. When reports are late, incomplete, or missing, OFAC increasingly treats those failures as evidence of broader compliance weaknesses, not isolated errors.
The high cost of recordkeeping and reporting breakdowns
Poor recordkeeping and reporting can independently trigger OFAC enforcement actions, pummelling profit margins, damaging company reputations, and potentially resulting in up to 20 years’ imprisonment for individuals. In a recent case, OFAC imposed a $7-million penalty on a New York property management company for “violating OFAC’s Russia-related sanctions and for failing to report blocked assets to OFAC.” Missing records, weak oversight, and gaps in its OFAC sanctions check process cost this organization dearly.
Similarly, OFAC issued a formal violation to an international bank for violating RPPR requirements. Accurate reporting and robust record maintenance are mandatory, not discretionary. Regardless of the extent of the underlying sanctions exposure, inconsistent documentation, human error, and fragmented data can trigger enforcement actions. In this case, the financial firm appeared on regulators’ radar because it failed to maintain complete and accurate records of blocked property, leading to submission of inaccurate reports to OFAC.
Common OFAC compliance pitfalls
Many organizations face persistent challenges in meeting OFAC regulatory requirements, and it’s increasingly less about prohibited transactions. Fragmented data sources compromise a company’s ability to maintain accurate, complete records. Without integration across compliance tools, enterprise resource planning (ERP), banking, and trade documents, compliance data becomes scattered across shared drives, emails, and ticketing systems.
Manual reporting processes create a similar chaos, increasing the risk of incomplete or inaccurate data, late filings, and inconsistencies across submissions. Further complicating RPPR recordkeeping obligations, most legacy systems were not designed to retain compliance records securely and accessibly for 10 years or longer.
Beleaguered by inconsistent OFAC screening processes (i.e., lacking a standardized process for denied party screening cadence or escalation protocol for potential matches), companies struggle to satisfy compliance requirements. And even if an organization screens effectively, failure to document why a match was cleared or escalated leaves critical gaps during audits.
Improper handling due to unclear rules about “block vs. reject” — coupled with limited visibility into aging, changes, or updates tied to previously identified risks — is a main driver of enforcement cases. Employees are often unsure when to block, when to reject, and what constitutes “property” or “interest in property.”
Finally, companies struggle with disconnected workflows and siloed operations that lead to data quality deficiencies. Sanctions events involve multiple teams across the enterprise (e.g., procurement, sales, operations, legal, logistics) but, without a centralized system, compliance falters and audits become problematic. Companies face increased risk of missed events, late reporting, and incomplete customer data for ownership checks or 50 Percent Rule exposure, while lacking a single source of truth for counterparty information.
Getting the proverbial compliance ducks in a row
With OFAC adopting a data-driven enforcement model, forward-thinking companies are revisiting their compliance strategies to mitigate the risk of non-compliance enforcement actions. Those organizations still relying on inefficient manual compliance practices expose themselves to human error, reporting delays and omissions, and costly penalties.
From executing transactions to reporting and recordkeeping, businesses need to ensure their compliance processes are capable of accurately capturing and storing the breadth of required data, including transaction records, customer certifications, and compliance-related communications.
Best practices recommend establishing a centralized digital repository for compliance data, ideally integrated with existing ERP, CRM, and other business systems. By leveraging a single source of truth, companies can simplify the process of maintaining a complete and compliant data trail, ensure data accessibility during audits, and support the extended 10-year retention requirement.
Given the inadequacies of manual compliance practices and legacy systems for satisfying evolving RPPR requirements, companies are best served by automating OFAC compliance workflows using advanced OFAC screening software with robust reporting and audit history capabilities. Data-driven compliance tools not only prevent non-compliant transactions, they also ensure timely reporting and immutable audit trails that can withstand regulators’ increasing scrutiny, which is a non-negotiable in today’s data-focused OFAC enforcement environment.
