
Photo by pixelshunter
A transaction that clears DFAT's Consolidated List can still breach OFAC or UN Security Council sanctions — and expose your remittance business to secondary sanctions, correspondent banking loss, or criminal liability. If your corridors touch US dollars, US-based banks, or high-risk jurisdictions, screening against Australia's sanctions regime alone is not enough. You need a single, layered screening program that covers every regime your money movements touch.
This guide shows you how to build that program: which lists to screen, how the regimes overlap and diverge, and how to configure your screening engine so one transaction check satisfies DFAT, OFAC, and UN obligations at once. It is written for compliance officers and MTO operators who move money across borders and need a defensible, auditable approach.
Key Takeaways
- DFAT compliance is your legal minimum in Australia, but it does not shield you from OFAC or UN exposure when your corridors involve USD or US financial infrastructure.
- OFAC's reach is extraterritorial — any transaction touching the US financial system, a US person, or US-origin goods can trigger enforcement, even for a fully Australian MTO.
- UN sanctions are implemented differently in each country, so screening the UN Consolidated List directly closes gaps that national lists may leave open.
- A single multi-regime screening engine with combined watchlist data eliminates the false confidence of checking only one regime.
- Under the AML/CTF Act 2006 and the Charter of the United Nations Act 1945, sanctions breaches carry strict-liability criminal penalties in Australia.
Why One Sanctions List Is Never Enough
Most Australian MTOs start by screening against the DFAT Consolidated List — and rightly so. This is the list you are legally required to screen under the Autonomous Sanctions Act 2011 and the Charter of the United Nations Act 1945. But treating DFAT as your only reference point creates a dangerous blind spot.
The three major sanctions regimes overlap heavily but never perfectly. A designation can appear on OFAC's Specially Designated Nationals (SDN) List weeks before DFAT adopts it, or reflect a US-only policy Australia never adopts. The UN Security Council may list an entity that both DFAT and OFAC implement with different scope. Screening one list means missing what the others catch.
The risk is not theoretical. If your MTO settles funds in USD, routes payments through a US correspondent bank, or serves a corridor involving a comprehensively sanctioned jurisdiction, OFAC jurisdiction can attach to your transaction even though your business sits entirely in Australia. That is the essence of secondary sanctions and extraterritorial reach.
The Three Regimes Explained
DFAT — Australia's Sanctions Authority
The Department of Foreign Affairs and Trade (DFAT) administers Australia's two sanctions frameworks: UN Security Council sanctions (implemented domestically) and Australian autonomous sanctions. Both are published in the single DFAT Consolidated List, which you must screen every customer, beneficiary, and ordering party against.
Breaching Australian sanctions is a strict-liability offence. Under the Autonomous Sanctions Act 2011, penalties reach 10 years imprisonment and fines of the greater of AUD 825,000 or three times the value of the transaction for individuals, with corporate fines significantly higher. "I didn't know" is not a defence — you are expected to screen.
OFAC — The Extraterritorial Regime You Cannot Ignore
The Office of Foreign Assets Control (OFAC), part of the US Treasury, administers US sanctions. Its primary reference is the SDN List, alongside sectoral and consolidated non-SDN lists. OFAC's jurisdiction extends to any transaction with a US nexus — USD clearing, a US correspondent bank, US-person involvement, or US-origin goods and technology.
For Australian MTOs, the exposure is real. If a customer sends AUD that you convert and settle in USD through a US bank, that leg of the payment touches OFAC jurisdiction. Enforcement actions have hit non-US financial institutions with penalties running into hundreds of millions of dollars for stripping or facilitating prohibited transactions.
OFAC also enforces the 50 Percent Rule: any entity owned 50% or more, directly or indirectly, by one or more SDNs is itself blocked — even if not separately listed. This makes beneficial ownership screening (see our UBO checklist) inseparable from sanctions screening.
UN — The Global Baseline
The United Nations Security Council Consolidated List underpins the sanctions every UN member state must implement, including Australia and the US. Because each country implements UN designations through its own legislation and on its own timeline, national lists can lag or diverge from the underlying UN measures.
Screening the UN Consolidated List directly gives you the global baseline and catches designations before or beyond national adoption. For corridors touching conflict zones or terrorism-financing risk jurisdictions, the UN list is your first line of defence against financing designated terrorist entities.
How the Regimes Overlap and Diverge
The following table shows how the three regimes compare on the dimensions that matter for an MTO screening program.
| Dimension | DFAT | OFAC | UN |
|---|---|---|---|
| Administering body | DFAT (Australia) | US Treasury | UN Security Council |
| Primary list | DFAT Consolidated List | SDN + Consolidated Lists | UNSC Consolidated List |
| Legal basis (for you) | Autonomous Sanctions Act 2011; Charter of the UN Act 1945 | Extraterritorial via US nexus | Implemented via DFAT domestically |
| Applies to your MTO when | Always (you operate in Australia) | Transaction touches USD/US bank/US person | Always (via DFAT); direct screening recommended |
| Ownership rule | Control test | 50 Percent Rule | Case-by-case |
| Update frequency | Regular, follows UN + autonomous decisions | Frequent, often ahead of others | Per Security Council resolution |
| Penalty exposure | Up to 10 years jail; AUD 825k+ fines | Civil + criminal; hundreds of millions | Via national implementation |
The practical lesson: DFAT is mandatory, OFAC is conditionally mandatory based on your settlement rails, and UN screening closes timing and scope gaps. A robust program screens all three simultaneously.
Building a Single Multi-Regime Screening Program
Step 1: Map Your Sanctions Exposure by Corridor
Start by documenting every corridor you operate and the settlement path each takes. For each corridor, answer three questions:
- Does the payment touch USD at any point — funding, FX conversion, or settlement?
- Does the payment route through a US correspondent bank or a US-headquartered PSP?
- Does the corridor involve a jurisdiction subject to comprehensive or targeted sanctions (for example, Iran, North Korea, Syria, Russia-related restrictions)?
Any "yes" to the first two brings OFAC into scope. A "yes" to the third elevates your risk rating and may require enhanced screening and enhanced due diligence. Record this mapping in your AML/CTF risk assessment so your screening scope is documented and defensible.
Step 2: Consolidate Your Watchlist Data
Do not run three separate screening checks against three separate lists. Instead, feed all relevant lists into a single screening engine that maintains a combined, de-duplicated watchlist. At minimum, load:
- DFAT Consolidated List
- OFAC SDN List and OFAC Consolidated (non-SDN) List
- UN Security Council Consolidated List
- Relevant sectoral lists (for corridors touching Russia, for example)
Most commercial sanctions data providers deliver these as a single normalised feed with daily updates. If you are choosing a vendor, our guide on AML compliance software covers what to look for. Verify update frequency — a list that refreshes weekly leaves you exposed for six days after a new OFAC designation.
Step 3: Configure Fuzzy Matching and Thresholds
Sanctioned names rarely appear in your system exactly as listed. Transliteration from Arabic, Chinese, Cyrillic, or other scripts produces spelling variations, and aliases multiply the challenge. Configure your engine for:
- Phonetic and fuzzy matching to catch transliteration variants (Mohammed / Muhammad / Mohamed).
- Alias and AKA screening across all loaded lists.
- Date-of-birth and nationality secondary matching to reduce false positives on common names.
- A calibrated match threshold — too tight and you miss variants; too loose and your team drowns in false hits.
Document your threshold logic. When AUSTRAC reviews your program (see our compliance assessment readiness checklist), you must be able to explain and justify your matching configuration.
Step 4: Screen at the Right Points
Screen at every point where sanctions exposure arises, not just at onboarding:
- Customer onboarding — screen the sender against all three regimes before you accept them.
- Every transaction — screen the sender, beneficiary, and any ordering or intermediary party in real time before you release funds.
- Ongoing / batch re-screening — re-screen your entire customer base whenever any loaded list updates, because a customer clean yesterday may be designated today.
The transaction-level check is non-negotiable. Screening only at onboarding means a beneficiary added to the SDN List after you onboarded the sender goes unscreened.
Step 5: Build a Consistent Alert Handling Workflow
Alerts from different regimes need a single, consistent resolution process. For each alert, your workflow should:
- Record which list(s) generated the match and the match score.
- Require a documented true-match / false-positive determination by a trained analyst.
- Escalate confirmed matches to your AML/CTF Compliance Officer immediately.
- Freeze the transaction pending resolution — never release funds against an open sanctions alert.
Maintain a full audit trail. Every alert, decision, and rationale must be retained for seven years under the AML/CTF Act 2006 record-keeping obligations.
What to Do When You Get a True Match
A confirmed sanctions match triggers immediate obligations across regimes. Handle it in this order:
- Freeze the asset or funds — do not process, return, or release. Under Australian law, dealing with a designated person's assets is itself an offence.
- Report to DFAT — notify the Australian Sanctions Office as required and seek guidance on next steps.
- Consider AUSTRAC reporting — a sanctions match will frequently also require a Suspicious Matter Report within the statutory timeframe.
- Assess OFAC obligations — if the transaction has a US nexus, OFAC may require blocking and a report to the US Treasury.
- Document everything — every decision, timestamp, and communication.
The interaction between DFAT freezing obligations, AUSTRAC SMR duties, and any OFAC reporting is complex. This is where legal advice pays for itself — do not improvise.
Common Multi-Regime Screening Failures
| Failure | Why it happens | How to fix |
|---|---|---|
| Screening DFAT only | Assuming Australian compliance covers all risk | Load OFAC + UN lists into one engine |
| Stale watchlist data | Weekly or manual list updates | Use daily automated feeds |
| No beneficiary screening | Only screening the sender | Screen all parties per transaction |
| Ignoring the 50 Percent Rule | Screening names, not ownership | Combine sanctions + UBO screening |
| No re-screening | One-time onboarding checks | Batch re-screen on every list update |
| Weak match tuning | Default vendor thresholds | Calibrate and document your logic |
The 2026 AML/CTF Reforms and Sanctions Screening
The 2026 AML/CTF reforms sharpen expectations around risk-based systems and controls. While sanctions screening is governed primarily by the Autonomous Sanctions Act and the Charter of the UN Act rather than the AML/CTF Act, AUSTRAC increasingly expects your AML/CTF program to integrate sanctions screening as a core control.
Expect scrutiny of whether your screening scope matches your actual corridor and settlement risk. An MTO settling in USD that screens only DFAT will struggle to demonstrate its program is genuinely risk-based. Align your screening scope with your documented risk assessment and revisit it whenever you add a corridor or change settlement rails.
Practical Example: A USD-Settled Corridor
Consider an MTO running an Australia-to-Middle East corridor. A customer sends AUD 4,000 to a beneficiary. The MTO converts to USD and settles through a US correspondent bank.
Screening only DFAT, the beneficiary comes back clean — Australia has not designated them. But the beneficiary appears on the OFAC SDN List, added the previous week. Because the payment clears USD through a US bank, processing it exposes the MTO to OFAC enforcement and puts its correspondent banking relationship at immediate risk.
A multi-regime program catches this. The single screening check flags the OFAC match, the transaction freezes, the compliance officer assesses reporting obligations to both DFAT and OFAC, and the correspondent relationship is protected. One integrated check prevented a breach that single-list screening would have missed entirely.
Frequently Asked Questions
Do Australian MTOs legally have to screen against OFAC?
Australian law requires you to screen against the DFAT Consolidated List. OFAC compliance is not directly mandated by Australian legislation, but OFAC's extraterritorial reach means you face US enforcement and correspondent banking loss if your transactions touch the US financial system and breach US sanctions. If you settle in USD or use US banks, screening OFAC is a practical necessity, not an optional extra.
How often should I update my sanctions watchlists?
Daily. OFAC and DFAT add designations frequently, sometimes with immediate effect. A watchlist that refreshes weekly leaves a window of several days during which you could process a transaction involving a newly designated party. Use a data provider that delivers automated daily updates across all loaded lists.
What is the OFAC 50 Percent Rule and does it affect my screening?
The 50 Percent Rule blocks any entity owned 50% or more, directly or indirectly, by one or more SDNs — even if that entity is not itself named on any list. It affects your screening because name-matching alone will not catch these entities. You must combine sanctions screening with beneficial ownership verification to identify blocked entities that appear clean on the face of the list.
Can I use one screening engine for all three regimes?
Yes, and you should. Running separate checks against separate lists creates gaps and inconsistent alert handling. A single engine loaded with a consolidated, de-duplicated feed of the DFAT, OFAC, and UN lists screens every party against all regimes in one check, with one audit trail and one resolution workflow.
What happens if I process a transaction that breaches sanctions?
Under Australian law, sanctions breaches are strict-liability offences carrying up to 10 years imprisonment and fines of the greater of AUD 825,000 or three times the transaction value for individuals. If the breach involves a US nexus, you also face OFAC civil and criminal penalties and likely loss of your correspondent banking relationship. Freezing and reporting a suspected match immediately is far cheaper than an enforcement action.
Bringing It Together
Multi-regime sanctions screening is not about running more checks — it is about running one smarter check that reflects the real regulatory surface your corridors touch. Map your exposure, consolidate your lists, tune your matching, screen at every point, and handle alerts consistently.
Start by reviewing whether your current screening scope matches your settlement rails. If you settle in USD or route through US banks and screen only DFAT, you have a gap to close today. Build your integrated sanctions logic into your broader compliance framework with our AML/CTF Program tool, and keep pace with corridor-specific risk through our corridor guides and compliance newsletter.
This information is general in nature and does not constitute legal advice. Consult AUSTRAC, DFAT's Australian Sanctions Office, or a qualified legal professional for advice specific to your situation.

