Skip to content
Share
Sanctions
December 08, 2025
•
4 min read

OFAC's $7M Wake-Up Call: Why Visitor Screening Can't Ignore Sanctions Guidance Anymore

On December 4, 2025, OFAC announced a $7M+ penalty against a company that ignored sanctions guidance around Russia-linked dealings. That fine is a flashing light for defense contractors and regulated manufacturers: one unvetted visitor, vendor, or field engineer can trigger the same chain reaction: audits, halted shipments, reputational damage, and consent orders. If OFAC or DCMA asked today, could you prove every visitor was screened against the latest lists, adjudicated by humans, and logged in an append-only audit log?

OFAC visitor screening 2025sanctions compliance defense contractorsreal-time denied party screening

What happened

The enforcement story (and why it hits your lobby)

OFAC cited repeated disregard for sanctions guidance: no real-time checks, weak ownership tracing, and missing controls. Defense contractors and ITAR/EAR programs face the same exposure: a visitor with a buried Russia ownership link walks in, and your program risk spikes. Documented controls, human review of possible matches, and a record of how each hit was resolved are the evidence you will want in hand.

  • OFAC $7M penalty (Dec 4, 2025) proves “ignored guidance” is costly, fast.
  • BIS Affiliates / 50% Rule signals keep ownership risks in scope, even while BIS enforcement is paused.
  • Defense sites need a reviewable record of every screening event and decision.
  • Ignoring near-matches or ownership red flags can be weighed as reckless conduct in an enforcement review.

Visitor flow risk

Where sanctions hits hide in everyday visits

Sanctions risk isn't just for shipments. It shows up in lobby check-ins, contractor rotations, and vendor demos. A single miss can trigger ITAR/EAR disruptions or OFAC scrutiny.

  • Lobby check-ins: consultants and field engineers still need a legal-name screen before a badge prints.
  • Service vendors & temp labor: inherited supply-chain risk deserves the same rigor as employees.
  • Foreign national visits: screen against OFAC and BIS lists and hold high-severity hits for review.
  • Auditability: without time-stamped adjudication notes per org, you're exposed to “inadequate controls.”

SecurePoint controls

How SecurePoint stays ahead (and auditable)

SecurePoint screens visitors against OFAC and BIS lists at check-in, holds possible matches for human review, and writes dispositions to an append-only audit log.

Real-time multi-list

OFAC, BIS, UN, EU, UK with severity scoring. OFAC 50% ownership checks run in shadow mode by default, and BIS affiliate hits are held for review.

Human-in-loop

Possible matches go to a reviewer. Clean screens can auto-approve. Dispositions are logged.

Append-only audits

Append-only logs: actor, org_id, action, target_id, metadata, timestamps. Built for regulator reviews.

Published plan volume

Screening runs at check-in and on scheduled workforce and vendor re-screens, subject to the fair-use caps on each plan.

Red flags to catch

Red FlagWhy It MattersSecurePoint Control
Match on OFAC SDN or SSIStrict liability. An SDN match is a stop point; SSI restrictions are narrower and depend on the directive.Real-time SDN/SSI screening with severity labels and adjudication history.
Ownership link to sanctioned party (>50% aggregate)OFAC 50% Rule aggregates blocked ownership, even if the entity is not listed.Ownership look-through where ownership records exist. OFAC 50% results run in shadow mode by default.
Russia/Belarus nexus vendors or site accessSectoral sanctions and export controls heighten risk for ITAR/EAR environments.Screen against OFAC SDN/SSI and BIS lists, and hold elevated matches for human review.
Incomplete identity fieldsMissing legal name or document capture weakens screening and the audit record.Required identity fields and document capture at check-in before a badge can issue.
Ignored near-matches or repeat hitsPattern of control failures; OFAC can weigh ignored warning signs as reckless conduct.Hit history, reviewer notes, append-only audit logs, and escalation for high-severity hits.

Illustrations

Concept images for this post

These are illustrations of adjudication, a review queue, and an enforcement cascade. They are not product screenshots.

Illustration of an adjudication drawer with a possible OFAC hit and review controls

Adjudication concept

Illustration of an adjudication drawer with a possible OFAC hit, match reasons, and review controls.

Illustration of a screening queue with flagged visitors and list-source labels

Screening queue concept

Illustration of a review queue with flagged visitors and list-source labels.

Illustration of an OFAC penalty cascading into operational disruption

Enforcement cascade

Illustration of how an OFAC penalty can cascade into paused shipments and a consent order.

10-minute hardening

Playbook for facilities and security leads

Rapid actions to stay ahead of OFAC, ITAR/EAR, and BIS scrutiny while keeping throughput high.

Gate every badge on denied-party screening against OFAC SDN/SSI and BIS lists before print.
Hold high-severity OFAC or BIS hits for a reviewer before clearing the visitor.
Export evidence packs from visit, screening, and decision records for the period an auditor asks about.
Rehearse a tabletop audit: surface recent adjudications with timestamps and list versions.
Confirm who can clear a match, and that every disposition is written to the append-only audit log.

Human-in-loop

Why human adjudication stays mandatory

AI is assistive, not determinative. Possible matches go to a reviewer. Clean screens can auto-approve.

  • AI surfaces explainable match reasons (aliases, countries, ownership), but humans record the final disposition.
  • Every action emits an append-only audit log with org_id, actor, target, and metadata for regulator-ready traceability.
  • High-severity OFAC/BIS hits can be escalated, and every clear records who made it and why.
  • Evidence packs stay org-scoped with checksums and rules_version to align with audit expectations.

Ready to screen visitors before they reach your floor?

See SecurePoint's real-time denied party screening, human-in-loop adjudication, and append-only audit trails in action. Keep screening inline without slowing your lobby.

Found this helpful? Share it with a colleague.

Visitor Compliance Checklist

  • ITAR/EAR and CMMC L2 requirements
  • Audit-ready evidence collection
  • Possible matches go to a reviewer
Download PDF

Stay ahead of compliance changes

Get occasional notes on sanctions, export controls, and visitor compliance when we publish them.

No spam. Unsubscribe anytime.

OFAC's $7M Wake-Up Call - SecurePoint USA