Glossary

What are sanctions?

A sanction is a legally binding restriction that a government or international body places on dealings with a named person, company, vessel, country or crypto wallet address. Sanctions, plural, are the programs built from those measures, imposed to advance foreign-policy and national-security goals.

Most are economic sanctions: restrictions on trade, finance and access to property, applied instead of military force. They come in two shapes. Country programs, or embargoes, restrict trade and finance with a whole jurisdiction — the comprehensive US programs covering North Korea and Iran are the best-known examples. Targeted, list-based programs name specific people, companies, vessels, aircraft and other assets. Once a party is listed, its property is usually frozen, and anyone under the issuer's jurisdiction is barred from dealing with it.

The best-known list is the US Treasury's Specially Designated Nationals and Blocked Persons (SDN) list, kept by the Office of Foreign Assets Control (OFAC). Since November 2018, OFAC has published cryptocurrency wallet addresses in SDN records, and other issuers have followed. That is why compliance now covers on-chain activity, not just bank transfers.

What is a sanction?

A sanction, singular, is one restrictive measure imposed by a government or international body to change the behaviour of its target without using force. In practice it takes one of a few legal forms: a designation that blocks a named person or company and freezes its assets; a sectoral restriction that bans specific dealings, such as new debt or securities, with a listed party; a trade or financial embargo on a country or region; a travel ban; or an arms embargo.

"Sanctions" in the plural usually means the program — the set of measures an issuer applies to one target, such as OFAC's Iran program or the EU's Russia measures. That is why a screening result reports the program behind a match: the same designation can carry a full asset freeze under one program and a narrower restriction under another.

What are the different types of sanctions?

Sanctions are usually classified by scope: whether they apply to a whole jurisdiction, to a sector of its economy, or to named parties. Four of the six types below are economic sanctions, aimed at trade, finance and property; arms embargoes and travel bans are the non-economic ones. How a sanction works follows from that scope. A country program is enforced by knowing where a counterparty, user or shipment is; a list-based designation is enforced by screening who the counterparty is.

Designation and sanction are related but distinct terms. A designation is the administrative act of adding a person, company, vessel or wallet address to a list. The sanction is the restriction that follows from it — usually an asset freeze plus a prohibition on dealings.

TypeWhat it restrictsExample
Comprehensive (country) sanctionsNearly all trade and financial dealings with a jurisdictionThe US programs covering Cuba, Iran and North Korea — maintained on the OFAC sanctioned countries list
Targeted (list-based) sanctionsDealings with named people, companies, vessels, aircraft and crypto wallet addressesA designation on OFAC's SDN list, such as the Garantex exchange (April 2022)
Sectoral sanctionsSpecific dealings — new debt, equity or technology — with listed parties in named economic sectorsOFAC's Sectoral Sanctions Identifications (SSI) list for sectors of the Russian economy, published as part of the Non-SDN Consolidated list
Secondary sanctionsThird-country parties that deal with a sanctioned target, by exposing them to designation themselvesProvisions in several US programs that reach non-US banks and suppliers of listed targets
Arms embargoesWeapons and military equipment onlyUN Security Council arms embargoes, implemented by every member state
Travel bansEntry into the issuing jurisdiction for named individualsThe travel bans that accompany many UN and EU designations

What does it mean to be sanctioned?

For a person or company, being sanctioned means being designated by an issuer and placed on its list. The consequences follow at once: property and interests in property within the issuer's reach are blocked, and everyone subject to that jurisdiction is prohibited from dealing with the designated party — no payments, no services, no trade. In the United States the prohibition also covers entities owned 50 percent or more, directly or indirectly, by one or more blocked persons, even when those entities are not listed themselves (OFAC's 50 Percent Rule, set out in FAQ 401).

For a crypto wallet address, being sanctioned means the address is published as an identifier in a designated party's list record. Regulated services must then block or reject transactions involving it, which is why exchanges and DeFi front-ends screen addresses before value moves. In everyday speech "state-sanctioned" can also mean officially approved; this page uses the legal sense throughout.

Who issues sanctions?

There is no single global list. The United Nations Security Council issues designations that member states implement, and each jurisdiction runs its own programs on top, with its own list, legal basis and update schedule. A business that operates across borders can fall under several regimes at once. Lists overlap a lot, but never completely.

The issuers that matter most to financial products:

  • United States — OFAC, part of the US Treasury, publishes the SDN list and runs the country programs. US persons and any transaction that touches the US must comply.
  • European Union — the EU's consolidated financial sanctions list combines the designations adopted across all member states.
  • United Kingdom — the UK Sanctions List is published by the Foreign, Commonwealth & Development Office; OFSI oversees financial enforcement.
  • National authorities — countries also run their own instruments: France's registre national des gels (asset-freeze register), Japan's Ministry of Finance list, and Israel's NBCTF seizure orders against terror-linked crypto wallets.

Why do they matter for crypto and fintech businesses?

The rules attach to who you deal with, not what technology you use. A stablecoin transfer to a designated wallet raises the same legal issues as a wire to a designated bank account. In the US, civil enforcement is strict liability: a violation does not require intent or knowledge, although both affect the penalty.

Crypto is squarely in scope. OFAC has designated hundreds of wallet addresses as identifiers of listed persons, from ransomware operators to North Korea's Lazarus Group. It has also listed whole platforms: the Russian exchange Garantex was designated in April 2022 for laundering illicit funds. Designations move in both directions, too. The smart-contract mixer Tornado Cash was designated in August 2022, then removed from the SDN list in March 2025 after litigation over whether immutable smart contracts can be "property". Screening against stale list data therefore produces both missed matches and false positives.

For exchanges, payment companies, DeFi frontends and other virtual asset service providers, the practical result is a screening duty: check counterparties and wallet addresses against current list data before value moves, and check again as the lists change.

What are some examples of sanctions?

Four designations that reached crypto businesses directly, each with the official OFAC announcement linked below (all re-verified September 2026):

  • Garantex — a Russia-linked virtual currency exchange, designated on 5 April 2022 alongside the Hydra darknet market for processing ransomware and other criminal proceeds.
  • Blender.io — the first virtual currency mixer ever sanctioned, designated on 6 May 2022 for laundering proceeds of North Korea's Axie Infinity heist.
  • Tornado Cash — a smart-contract mixer designated on 8 August 2022; the designation was removed on 21 March 2025, which is why screening data has to track delistings as well as additions.
  • Sinbad.io — a mixer designated on 29 November 2023 as a key laundering tool of the Lazarus Group, North Korea's state-sponsored hacking organisation.
  • Country programs are the comprehensive examples — the US embargoes on Cuba, Iran and North Korea — and are covered on the embargo page and the OFAC sanctioned countries list rather than here.

What is sanctions screening?

Sanctions screening means checking identifiers — names, wallet addresses, emails, websites, government ID numbers, countries — against the lists to find out whether a counterparty is designated before you do business with them.

Screening usually runs at several points: when a customer or counterparty is onboarded, when a transaction is about to execute (a withdrawal address, a payment recipient), and on a schedule against stored identifiers, because the lists change all the time. A useful result says which list matched and links to the official source record, so a reviewer can verify the hit instead of trusting a bare yes or no.

Approaches differ in scope. Direct screening answers whether an identifier appears on a list. Blockchain-analytics platforms go further: they cluster addresses and score indirect exposure, such as whether funds have passed through a designated entity. Many businesses use both — fast direct checks inline in the product, and deeper analysis where their risk policy calls for it.

What happens when an entity is delisted?

Designations are not permanent. Issuers remove entries when the basis for a listing lapses, when a legal challenge succeeds, or when policy changes, and OFAC publishes removals alongside new designations. For screening, delistings matter as much as listings: blocking a delisted counterparty creates false positives, friction and legal exposure of its own.

That is why screening infrastructure has to track removals, not just additions. CompliAPI keeps delisted entries with their removal date and publishes them, so a match today always reflects the current state of each list.

What should you look for in screening software?

For engineering and compliance teams comparing tools, a few properties separate infrastructure you can build on from a static list download:

  • Data freshness — lists change without notice, so ingestion should be continuous. CompliAPI re-ingests the OFAC SDN list every 15 minutes and refreshes other sources daily or weekly.
  • Multi-list coverage with attribution — every match should say which list it came from and link to the official source record, because different lists carry different obligations.
  • Identifier breadth — screening names alone misses the identifiers that matter in digital products. Wallet addresses, emails, websites and government IDs all appear in list records.
  • Delisting handling — removed entries must stop matching, and the removal should be auditable.
  • An audit trail — regulators and auditors ask what was screened and when, so every check should be logged.
  • Integration effort — a check should fit inline in your product: one authenticated GET request per identifier, or an MCP tool call for AI-agent workflows.

Where screening fits in a product

Customer and counterparty onboarding

Screen the email, website and government ID a new customer or partner submits against the enabled lists before the relationship starts.

OFAC API — screen against the official SDN list

Wallet and transaction checks

Screen wallet addresses — deposits, withdrawal destinations, payment recipients — for direct appearance on the lists before funds move.

Wallet screening API for crypto compliance

Jurisdiction controls

Geolocate sessions and flag countries under OFAC programs to apply country-program rules, with a VPN signal to weigh the result.

IP Geofencing API for Sanctioned Countries

AI-agent workflows

Give agents the same screening checks as application code, as MCP tools with shared tokens, quotas and request logging.

OFAC MCP server for AI agents

Scope

This article is educational background, not legal advice. Which regimes apply to your business, and what your program must include, are questions for qualified counsel. CompliAPI's role is direct screening: checking identifiers for appearance on the enabled official lists and labeled risk lists, with the source record attached. It does not cluster addresses or score indirect exposure the way blockchain-analytics platforms do.

Frequently asked questions

What is the difference between sanctions and an embargo?

An embargo is a comprehensive, country-level restriction on trade or finance, like the US programs covering North Korea. Targeted, list-based programs instead name specific people, companies and assets. Modern programs mix both: a country program plus lists of designated parties connected to it.

Are sanctions lists the same in every country?

No. The UN, US, EU, UK and many national governments each keep their own lists, with separate legal bases and update schedules. They overlap heavily but never completely. That is why businesses with international exposure screen against several lists at once.

Can a crypto wallet address be sanctioned?

Yes, in effect. Issuers publish wallet addresses as identifiers of designated persons and entities — OFAC has done so since November 2018. Dealing with a listed address carries the same prohibitions as dealing with the listed party any other way.

What are the penalties for violating sanctions?

In the US, civil penalties apply on a strict-liability basis and scale with the size and number of violations. Willful violations can bring criminal fines and prison. Other jurisdictions have their own enforcement regimes. The specifics for any business are a matter for legal counsel.

Do designated entities ever come off the lists?

Yes. Issuers delist entries when designations are lifted, successfully challenged or superseded — Tornado Cash, designated by OFAC in 2022, was removed in March 2025. Screening systems need to track removals as carefully as additions, which is why CompliAPI records and publishes delisted entities.

Is sanctions screening the same as KYC?

No. Know Your Customer verifies who a customer is. Screening checks whether that customer or counterparty appears on a list. The two usually run together at onboarding, but they are distinct controls — CompliAPI provides the screening side.

Is OFAC the same as sanctions?

No. OFAC — the Office of Foreign Assets Control — is the US Treasury office that administers US sanctions programs and publishes the SDN list. Sanctions are the measures themselves, and the EU, the UK, the UN and many national authorities issue their own, each with its own list and update schedule.

Related solutions and data sources

Data sources behind this term: US OFAC SDN, EU sanctions, UK Sanctions List

Related terms: Sanctions screening, OFAC, Embargo, Asset freeze, Anti-money laundering (AML)

From the blog: OFAC SDN vs non-SDN lists, what's the difference?

Screen against live list data

Get a free API key and screen your first identifier in minutes.

14-day free trial. No credit card required.