
Back in 2023, the U.S. government turned its attention to the increasing intersection of corporate crime and national security. The Deputy Attorney General at the time stated that “sanctions are the new Foreign Corrupt Practices Act (FCPA)” and announced the expansion of the National Security Division’s (NSD) ability to investigate and prosecute corporate sanctions violations.
Fast-forward to 2026, and the Department of Justice (DOJ) is continuing to modernize and escalate its enforcement efforts. With regulatory enforcement entering a new phase defined by data intelligence and inter-departmental cooperation, agencies like the U.S. Department of Treasury’s Office of Foreign Assets Control (OFAC) are shifting to more data-driven enforcement.
By implementing artificial intelligence and sophisticated algorithmic tools, regulators can “perform regulatory enforcement tasks such as monitoring compliance; detecting potential noncompliance; identifying potential subjects for investigation, inspection or audit; and gathering evidence to determine whether corrective action against a regulated person is warranted.”
This data-led shift enables OFAC to detect patterns and anomalies within an organization’s transaction records, reports and other documentation, creating a fundamentally different risk environment for companies: one where data patterns, not just transactions, trigger investigations.
As a result, businesses face increased expectations of how sanctions-related activity is documented, reported and retained. OFAC is no longer just penalizing prohibited transactions; it is penalizing poor documentation practices, late reports and missing or inaccurate records.
Demonstrating OFAC Compliance
An effective OFAC compliance framework must be able to demonstrate compliance with the Reporting, Procedure and Penalties Regulations (RPPR), consistently and at scale. Indeed, OFAC considers the ability to meet RPPR requirements an indicator of an organization’s compliance culture and how well it manages sanctions risk.
To close compliance gaps and prevent costly violations, organizations must meet the agency’s expectations for documenting, reporting and retaining sanctions-related information, including:
Mandatory electronic filing: OFAC recently updated its RPPR in line with its evolving data-forward approach. Electronic filing is no longer optional; companies are required to use the OFAC Reporting System (ORS) to file initial reports on blocked property, reports on rejected transactions and the Annual Report of Blocked Property (ARBP). This digital shift helps regulators analyze data at scale, identify patterns of sanctions evasion and cross-reference reports across institutions and industries.
Long-term record retention. Consistent with the statute of limitations for certain OFAC sanctions violations, the agency updated its record retention requirements in 2025 from five to 10 years. Organizations must retain accurate records of every transaction subject to OFAC sanctions, including screening results and alert data; internal reviews, escalation decisions and approvals; reports submitted to OFAC; and all transactions conducted under general or specific licenses. Records must be accessible on demand.
Strict reporting deadlines. Blocked property reports must be filed within 10 business days and then annually until the property is unblocked. Rejected transaction reports must be submitted no more than 10 business days after the rejection. Plus, any transfer, release or unblocking of previously blocked property must be reported to OFAC promptly, with full documentation of how the determination was made.
Complete data capture. Businesses must maintain complete sanctions-related records including transaction details, parties involved, legal authority and supporting documentation. The records should have clear audit trails, demonstrating when screening occurred, which lists were used and how decisions were reached.
Creating an Evidence-Based Audit Trail
OFAC is looking for patterns and anomalies within an organization’s documentation that suggest deeper compliance concerns. To mitigate the risk of drawing regulators’ attention, proactive companies recognize the value of audit-ready documentation that enables compliance teams and regulators alike to trace decisions, validate controls and confirm that risks were managed appropriately.
Clear, verifiable records for every sanctions-related decision, and timely, accurate reporting have become the backbone of a robust sanctions compliance program (SCP). Importantly, transparent documentation across the full compliance lifecycle helps demonstrate the rationale behind a company’s determinations:
- Identification. Records show how transactions and counterparties were screened and what sanctions lists and tools were used (sanctions screening software or OFAC search tool).
- Escalation. Documentation captures how screening results were reviewed, who made escalation decisions and what information informed those decisions.
- Determination. Records demonstrate why a property was blocked or a transaction rejected, and how the organization assessed and mitigated risk.
- Reporting. Each determination must be reflected accurately and in a timely manner in formal submissions to OFAC to meet the initial 10-day reporting requirement, plus annual blocked property reports.
- Record retention. Under the expanded 10-year requirement, records must remain complete, intact and fully retrievable.
- Voluntary self-disclosure (VSD) preparation. High-quality documentation simplifies the process of assessing the scope of an incident and preparing supporting materials if a VSD is warranted.
Without structured records at each step, organizations struggle to defend compliance decisions, meet reporting deadlines or demonstrate good-faith efforts during an enforcement review.
The High Cost of Record-Keeping and Reporting Breakdowns
OFAC has identified several root causes of compliance program breakdowns or deficiencies, including the lack of a formal OFAC SCP; misinterpreting or failing to understand the applicability of OFAC’s regulations; outdated sanctions screening software; and de-centralized compliance functions, among others.
Notably, OFAC enforcement actions repeatedly show that poor documentation, from inaccurate or incomplete records to delayed reporting, compromises SCPs and triggers significant penalties that hammer the bottom line. Case in point: OFAC imposed a massive $216-million fine upon a San Francisco venture capital firm for violating Ukraine/Russia-related sanctions and failing to meet RPPR reporting obligations.
One of the clearest examples of how record-keeping failures evolve into costly violations — and of how OFAC has extended reporting expectations beyond financial institutions — involves a New York–based property management company. The company failed to report blocked property for more than 45 months, resulting in a $7.1 million penalty.
In this case, OFAC cited multiple breakdowns, including failed escalation of blocked property; lack of ongoing monitoring; inaccurate or incomplete records; and failing to report blocked assets to OFAC in a timely manner as mandated by RPPR. Missing and inconsistent documentation significantly amplified the severity of enforcement, transforming what began as a reporting failure into a multimillion-dollar fine.
In addition to financial consequences, OFAC violations can damage a company’s reputation, eroding customer, partner and investor trust. OFAC issued a Finding of Violation, rather than a monetary penalty, to an international finance firm for inaccurate reporting and weak blocked-property record maintenance that violated RPPR requirements.
Although no fine was imposed, OFAC emphasized that accurate reporting and robust record maintenance are mandatory, not discretionary. The case highlights how human error, inconsistent documentation and fragmented data can still trigger enforcement actions, even when underlying sanctions exposure appears limited.
As OFAC continues to modernize and shift towards a more data-driven enforcement model, regulators are placing greater scrutiny on delayed filings, incomplete records and weak compliance processes to uncover sanctions violations. With this focus in mind, companies should rethink sanctions governance and prioritize audit-ready sanctions-related data, accurate reporting and long-term record-keeping before gaps become costly violations.
Jackson Wood is director of industry strategy, global trade intelligence, at Descartes.




.png?auto=format%2Ccompress&fit=crop&h=141&q=70&w=250)







