Unit 05 · Chapter 1 · 15 min read

Sanctions scope, prohibitions, and licenses

Translate legal restrictions into a precise control boundary.

A payment is low risk for fraud and still cannot proceed under an applicable restriction. Sanctions compliance is not a model score with a price attached. It starts with the people, activity, jurisdiction, and legal rule.

Establish jurisdiction and activity

Sanctions programs can restrict dealings with named parties, certain territories, sectors, or specified activity. The applicable duties depend on the relevant legal nexus and program. An entity’s location, the involvement of U.S. persons, and other facts can matter.

Build a legal applicability map with qualified owners. The map should identify the actual entity, product, parties, route, and source rule. Avoid using a single global blocked-country table as a substitute for this analysis. It can both miss prohibited activity and reject permissible activity. Engineering needs a structured policy that states what the law requires for the defined situation.

A sanctions decision begins with the activity and the legal connection, not with a generic country score. Identify the relevant parties, institutions, currencies, goods or services, and jurisdictions. A U.S. obligation may apply through one connection while another jurisdiction imposes a separate requirement. The engineering model should be able to represent these facts without pretending that one universal screening flag resolves every legal question.

Keep the scope analysis distinct from the evidence match. A system can correctly detect a listed name and still need review to determine whether the person is the listed subject and what restriction applies. Conversely, a transaction can raise a prohibition issue that a simple name comparison would never detect. Scope and screening are complementary parts of the control.

Inside the mechanism. Start with the parties, activity, jurisdictions, and applicable program. A customer’s address alone does not establish the full legal scope of a transaction. Preserve the actual route, institutions, ownership information, and relevant dates. The control should identify which facts support the applicable determination and which remain unresolved. A generic high-risk flag is not a substitute for this scoped analysis.

A concrete example. The transaction connects customers, banks, currencies, services, and places. A legal scope analysis determines which restrictions can apply to those facts. The case identifies 2,451 eligible records from a source population of 4,300. The required workflow completes for 2,377, but 36 completed records miss the illustrative internal target. Another 74 remain incomplete. Communication evidence covers 2,353 generated notices. Scope, completion, timeliness, and delivery are four separate properties of the customer outcome.

When the assumption fails. The product substitutes a country score for the activity-specific analysis. Retain parties, connections, activity, authority, and the qualified owner’s determination. The following worked sequence shows the reference condition, a stress condition, and a response condition with explicit synthetic data. These are comparative assumptions, not measured causal effects.

Follow a worked case3 conditions · 36 figures

The transaction connects customers, banks, currencies, services, and places. A legal scope analysis determines which restrictions can apply to those facts.

Establish jurisdiction and activity — the flow
Establish jurisdiction and activity Establish jurisdiction and activity — the flow Follow the sequence. Map the relevant restriction. Facts Identify parties route and activity Nexus Establish the applicable jurisdiction Rule Map the relevant restriction
  1. FactsIdentify parties route and activity
  2. NexusEstablish the applicable jurisdiction
  3. RuleMap the relevant restriction
Follow the sequence. Map the relevant restriction. Chapter sources · Open image
Establish jurisdiction and activity — the distinction
Establish jurisdiction and activity Establish jurisdiction and activity — the distinction These concepts answer different questions. Read each definition in the context of the section. Geographic restriction Applies to defined locations or activity Party restriction Applies to identified persons or entities
Geographic restriction
  • Applies to defined locations or activity
Party restriction
  • Applies to identified persons or entities
These concepts answer different questions. Read each definition in the context of the section. Chapter sources · Open image
Scope record
Establish jurisdiction and activity Scope record Fictional teaching record. Requires an approved interpretation. Scope record Illustrative data; not a real customer record or a prescribed policy. Product cross-border payment Specific activity Parties sender receiver intermediary Relevant actors Legal basis program-specific Requires an approved interpretation Sanctions scope is more than a country list
Fictional educational excerpt / Not for execution

Scope record

Illustrative data; not a real customer record or a prescribed policy.

  1. Productcross-border payment

    Specific activity

  2. Partiessender receiver intermediary

    Relevant actors

  3. Legal basisprogram-specific

    Requires an approved interpretation

Sanctions scope is more than a country list

Fictional teaching record. Requires an approved interpretation. Chapter sources · Open image
Establish jurisdiction and activity — control and failure modes
Establish jurisdiction and activity Establish jurisdiction and activity — control and failure modes Sanctions scope is more than a country list. The branches show why alternative designs fail. Control design Use a program-specific applicability map. Sanctions scope is more than a country list. Failure mode 1 Approve from a low fraud score. Fraud probability does not override a prohibition. avoid Failure mode 2 Block all foreign activity automatically. The rules are not a universal foreign-payment ban. avoid Failure mode 3 Assume one jurisdiction covers every entity. Legal nexus can differ. avoid
Control design

Use a program-specific applicability map. Sanctions scope is more than a country list.

Failure mode 1avoid
Approve from a low fraud score. Fraud probability does not override a prohibition.
Failure mode 2avoid
Block all foreign activity automatically. The rules are not a universal foreign-payment ban.
Failure mode 3avoid
Assume one jurisdiction covers every entity. Legal nexus can differ.
Sanctions scope is more than a country list. The branches show why alternative designs fail. Chapter sources · Open image

Distinguish blocking and rejection

Blocking and rejecting are different actions under sanctions rules. Blocking generally involves immobilizing property in which a blocked person has an interest, when required. Rejection concerns refusing a transaction that is prohibited but not subject to blocking under the relevant rule. Exact treatment and reporting depend on the program and facts.

The application should not offer one generic deny button for every outcome. Separate customer messaging, ledger treatment, custody, reporting, and release authority. A blocked balance cannot be treated as ordinary platform revenue or simply returned because a support agent wants to resolve a complaint.

The difference between blocking and rejection changes how funds are handled and how the customer is informed. A generic decline state is not sufficient for every disposition. The workflow needs the applicable determination, the amount and property affected, the institution holding it, required records, and any reporting or follow-up action. Engineers should obtain the approved disposition logic from qualified owners and preserve its version in the decision record. A manual override must not turn a legal restriction into an ordinary customer-service exception.

Inside the mechanism. Blocking and rejection have different effects on property and transaction processing. Model the applicable disposition explicitly rather than mapping both to declined. Keep the affected amount, currency, property interest, authority, recordkeeping, and required reporting workflow linked to the decision. Do not release or return property solely because an internal case was closed. The relevant action must follow the applicable program and facts.

A concrete example. Different applicable restrictions can require different handling of a transaction or property. A generic decline code cannot express every disposition or retained obligation. The case identifies 605 eligible records from a source population of 680. The required workflow completes for 587, but 9 completed records miss the illustrative internal target. Another 18 remain incomplete. Communication evidence covers 581 generated notices. Scope, completion, timeliness, and delivery are four separate properties of the customer outcome.

When the assumption fails. The product uses the same release behavior for blocked property and rejected instructions. Implement the approved disposition with amount, property, holder, reporting, and follow-up evidence. The following worked sequence shows the reference condition, a stress condition, and a response condition with explicit synthetic data. These are comparative assumptions, not measured causal effects.

Follow a worked case3 conditions · 36 figures

Different applicable restrictions can require different handling of a transaction or property. A generic decline code cannot express every disposition or retained obligation.

Distinguish blocking and rejection — the flow
Distinguish blocking and rejection Distinguish blocking and rejection — the flow Follow the sequence. Preserve custody and reporting evidence. Analyze Identify the property interest and prohibition Act Use the required block or reject treatment Record Preserve custody and reporting evidence
  1. AnalyzeIdentify the property interest and prohibition
  2. ActUse the required block or reject treatment
  3. RecordPreserve custody and reporting evidence
Follow the sequence. Preserve custody and reporting evidence. Chapter sources · Open image
Distinguish blocking and rejection — the distinction
Distinguish blocking and rejection Distinguish blocking and rejection — the distinction These concepts answer different questions. Read each definition in the context of the section. Block Immobilize property when the rule requires it Reject Refuse a prohibited transaction under its applicable treatment
Block
  • Immobilize property when the rule requires it
Reject
  • Refuse a prohibited transaction under its applicable treatment
These concepts answer different questions. Read each definition in the context of the section. Chapter sources · Open image
Disposition record
Distinguish blocking and rejection Disposition record Fictional teaching record. No ordinary refund path. Disposition record Illustrative data; not a real customer record or a prescribed policy. Result blocking required Approved legal conclusion Ledger restricted property Separate balance treatment Release authorized process only No ordinary refund path Their legal and financial handling can differ
Fictional educational excerpt / Not for execution

Disposition record

Illustrative data; not a real customer record or a prescribed policy.

  1. Resultblocking required

    Approved legal conclusion

  2. Ledgerrestricted property

    Separate balance treatment

  3. Releaseauthorized process only

    No ordinary refund path

Their legal and financial handling can differ

Fictional teaching record. No ordinary refund path. Chapter sources · Open image
Distinguish blocking and rejection — control and failure modes
Distinguish blocking and rejection Distinguish blocking and rejection — control and failure modes Their legal and financial handling can differ. The branches show why alternative designs fail. Control design Model block and reject as distinct dispositions. Their legal and financial handling can differ. Failure mode 1 Use one decline state for everything. It loses custody and reporting meaning. avoid Failure mode 2 Return blocked property on request. Release requires the appropriate authority. avoid Failure mode 3 Recognize blocked funds as revenue. The property remains subject to restrictions. avoid
Control design

Model block and reject as distinct dispositions. Their legal and financial handling can differ.

Failure mode 1avoid
Use one decline state for everything. It loses custody and reporting meaning.
Failure mode 2avoid
Return blocked property on request. Release requires the appropriate authority.
Failure mode 3avoid
Recognize blocked funds as revenue. The property remains subject to restrictions.
Their legal and financial handling can differ. The branches show why alternative designs fail. Chapter sources · Open image

Treat licenses as scoped authority

A license can authorize activity that would otherwise be prohibited, subject to its terms. General and specific licenses have different forms and scopes. A license is not a blanket exemption for every transaction involving a party.

Capture the authority, eligible activity, parties, conditions, dates, and supporting documents. Evaluate the actual transaction against that scope. Store the interpretation and approval. If a license expires or conditions change, the control must notice before new activity relies on it. A screenshot of an old license is not a maintained authorization system.

Inside the mechanism. A license or other authorization has a scope, conditions, dates, and relevant parties or activity. Store the exact authority and the facts that make it applicable. A document attached to one case is not a permanent allowlist for every future transaction by that customer. Changes in amount, purpose, route, or ownership can require another assessment. A release record should show why this particular action was within the authorization.

A concrete example. A license or other authority can depend on parties, activity, conditions, dates, and reporting requirements. It is not an unlimited whitelist entry. The case identifies 346 eligible records from a source population of 540. The required workflow completes for 336, but 5 completed records miss the illustrative internal target. Another 10 remain incomplete. Communication evidence covers 333 generated notices. Scope, completion, timeliness, and delivery are four separate properties of the customer outcome.

When the assumption fails. A prior licensed transaction is reused to approve a different activity after conditions change. Bind the authority to its exact scope, evidence, validity, and required handling. The following worked sequence shows the reference condition, a stress condition, and a response condition with explicit synthetic data. These are comparative assumptions, not measured causal effects.

Follow a worked case3 conditions · 36 figures

A license or other authority can depend on parties, activity, conditions, dates, and reporting requirements. It is not an unlimited whitelist entry.

Treat licenses as scoped authority — the flow
Treat licenses as scoped authority Treat licenses as scoped authority — the flow Follow the sequence. Record the approved reliance. Authority Identify the relevant license Conditions Match activity parties and dates Evidence Record the approved reliance
  1. AuthorityIdentify the relevant license
  2. ConditionsMatch activity parties and dates
  3. EvidenceRecord the approved reliance
Follow the sequence. Record the approved reliance. Chapter sources · Open image
Treat licenses as scoped authority — the distinction
Treat licenses as scoped authority Treat licenses as scoped authority — the distinction These concepts answer different questions. Read each definition in the context of the section. License scope Defined authorized activity and conditions Blanket clearance An unsupported assumption of unrestricted activity
License scope
  • Defined authorized activity and conditions
Blanket clearance
  • An unsupported assumption of unrestricted activity
These concepts answer different questions. Read each definition in the context of the section. Chapter sources · Open image
License check
Treat licenses as scoped authority License check Fictional teaching record. Cannot rely on this license. License check Illustrative data; not a real customer record or a prescribed policy. Activity specified category Must match the authorization Expiry recorded Time condition Transaction outside scope Cannot rely on this license Authority applies within its stated scope
Fictional educational excerpt / Not for execution

License check

Illustrative data; not a real customer record or a prescribed policy.

  1. Activityspecified category

    Must match the authorization

  2. Expiryrecorded

    Time condition

  3. Transactionoutside scope

    Cannot rely on this license

Authority applies within its stated scope

Fictional teaching record. Cannot rely on this license. Chapter sources · Open image
Treat licenses as scoped authority — control and failure modes
Treat licenses as scoped authority Treat licenses as scoped authority — control and failure modes Authority applies within its stated scope. The branches show why alternative designs fail. Control design Evaluate every relevant license condition. Authority applies within its stated scope. Failure mode 1 Treat a license as permanent clearance. Dates and conditions can limit it. avoid Failure mode 2 Reuse another entity’s authority blindly. Party scope may differ. avoid Failure mode 3 Skip recordkeeping once approved. Reliance needs evidence. avoid
Control design

Evaluate every relevant license condition. Authority applies within its stated scope.

Failure mode 1avoid
Treat a license as permanent clearance. Dates and conditions can limit it.
Failure mode 2avoid
Reuse another entity’s authority blindly. Party scope may differ.
Failure mode 3avoid
Skip recordkeeping once approved. Reliance needs evidence.
Authority applies within its stated scope. The branches show why alternative designs fail. Chapter sources · Open image

Operate the compliance program

OFAC’s compliance framework identifies management commitment, risk assessment, internal controls, testing and auditing, and training as core program components. The specific program should fit the organization’s risk and operations.

Turn those components into owned work. Track unresolved screening gaps, list failures, overdue reviews, and training needs. Test the complete transaction path, including manual channels and exceptional releases. A sanctions control that covers only the main API can miss activity initiated through a back-office tool. Governance should surface those gaps and ensure that fixes are verified.

Inside the mechanism. A functioning program connects risk assessment, control design, data quality, staffing, training, testing, and corrective action. Test whether the required population reaches the control and whether an unresolved issue prevents an unauthorized release. List-update success is only one part of that path. Case ownership, evidence retention, and a tested response to unavailable screening are equally important operational dependencies.

A concrete example. Governance, risk assessment, internal controls, testing, and training must connect to the actual product and institution. A vendor contract alone does not perform those tasks. The case identifies 877 eligible records from a source population of 1,020. The required workflow completes for 851, but 13 completed records miss the illustrative internal target. Another 26 remain incomplete. Communication evidence covers 842 generated notices. Scope, completion, timeliness, and delivery are four separate properties of the customer outcome.

When the assumption fails. A new payment feature launches without updating control ownership and coverage. Trace each affected exposure through the program and require evidence that the control works. The following worked sequence shows the reference condition, a stress condition, and a response condition with explicit synthetic data. These are comparative assumptions, not measured causal effects.

Follow a worked case3 conditions · 36 figures

Governance, risk assessment, internal controls, testing, and training must connect to the actual product and institution. A vendor contract alone does not perform those tasks.

Operate the compliance program — the flow
Operate the compliance program Operate the compliance program — the flow Follow the sequence. Verify coverage and remediate gaps. Commit Assign authority and resources Control Cover the real activity paths Test Verify coverage and remediate gaps
  1. CommitAssign authority and resources
  2. ControlCover the real activity paths
  3. TestVerify coverage and remediate gaps
Follow the sequence. Verify coverage and remediate gaps. Chapter sources · Open image
Operate the compliance program — the distinction
Operate the compliance program Operate the compliance program — the distinction These concepts answer different questions. Read each definition in the context of the section. Primary API coverage One route is screened Complete channel coverage All relevant initiation routes are addressed
Primary API coverage
  • One route is screened
Complete channel coverage
  • All relevant initiation routes are addressed
These concepts answer different questions. Read each definition in the context of the section. Chapter sources · Open image
Channel audit
Operate the compliance program Channel audit Fictional teaching record. Verify before relying on it. Channel audit Illustrative data; not a real customer record or a prescribed policy. Public API screened Main path works Back-office transfer not mapped Coverage gap Remediation add controlled screening Verify before relying on it Manual paths can bypass the main control
Fictional educational excerpt / Not for execution

Channel audit

Illustrative data; not a real customer record or a prescribed policy.

  1. Public APIscreened

    Main path works

  2. Back-office transfernot mapped

    Coverage gap

  3. Remediationadd controlled screening

    Verify before relying on it

Manual paths can bypass the main control

Fictional teaching record. Verify before relying on it. Chapter sources · Open image
Operate the compliance program — control and failure modes
Operate the compliance program Operate the compliance program — control and failure modes Manual paths can bypass the main control. The branches show why alternative designs fail. Control design Test every relevant channel and exception. Manual paths can bypass the main control. Failure mode 1 Count a policy as complete coverage. Implementation may differ. avoid Failure mode 2 Ignore release overrides. Exceptions can carry high impact. avoid Failure mode 3 Close gaps without retesting. The correction remains unproven. avoid
Control design

Test every relevant channel and exception. Manual paths can bypass the main control.

Failure mode 1avoid
Count a policy as complete coverage. Implementation may differ.
Failure mode 2avoid
Ignore release overrides. Exceptions can carry high impact.
Failure mode 3avoid
Close gaps without retesting. The correction remains unproven.
Manual paths can bypass the main control. The branches show why alternative designs fail. Chapter sources · Open image

Chapter connections

Continue with Screening engines and match resolution to follow the next part of the system. Use the glossary for terminology and risk mathematics for formulas and worked calculations.

Sources

Reviewed 2026-09-17
  1. OFAC: A Framework for Compliance Commitments
  2. OFAC: sanctions programs and country information
  3. OFAC FAQ 11: general and specific licenses
  4. OFAC FAQ 9: blocked property
  5. OFAC FAQ 5: resolving matches and choosing a disposition