What CFOs Should Know About Stablecoin Sanctions Screening
A practical guide to sanctions screening for USDC and USDT: what to check, when to screen, how to handle alerts, and which records finance teams should retain.
Sanctions screening for stablecoin payments has two parts: checking the people and companies involved, and checking the blockchain addresses used to send or receive funds. A clean company-name result does not make its wallet safe, while a low-risk wallet score does not confirm who controls it.
For CFOs, the operational question is straightforward: can the finance team demonstrate that it screened the relevant parties and wallets at the right time, reviewed any alerts consistently, and retained evidence of the decision?
This is especially important for USDC and USDT because transfers often settle within seconds or minutes and generally cannot be reversed by the sender. Some stablecoin issuers can freeze tokens at specific addresses, but finance teams should not treat issuer intervention as a substitute for pre-transaction screening.
What sanctions screening needs to cover
The exact legal requirements depend on the company’s jurisdiction, ownership, employees, counterparties, and payment routes. U.S. persons must comply with OFAC sanctions, and non-U.S. companies may still have U.S. exposure through employees, banking partners, U.S. operations, or transactions involving a U.S. nexus. Other regimes, including the UK, EU, and UN, may also apply.
A practical stablecoin screening process normally covers three layers:
- Counterparty identity: Screen the legal entity, beneficial owners, directors, and relevant individuals against applicable sanctions lists. OFAC’s 50 Percent Rule can block an entity that is owned, directly or indirectly, 50% or more in aggregate by one or more blocked persons, even if the entity is not named on a list.
- Wallet address: Check whether the sending or receiving address is sanctioned or has exposure to sanctioned entities, theft, ransomware, mixers, or other high-risk services.
- Transaction context: Review the payment purpose, jurisdiction, network, amount, invoice, and relationship between the wallet and named counterparty.
Blockchain analytics tools usually classify exposure as direct or indirect. Direct exposure means the wallet transacted with a flagged address. Indirect exposure means funds passed through one or more intermediate wallets. Indirect exposure is not automatically prohibited, but it can increase counterparty risk and require review.
When to screen stablecoin transactions
Screening only during onboarding is not enough. Sanctions lists and blockchain risk labels change, and a wallet that was clean six months ago may later receive funds from a designated address.
| Stage | What to screen | Recommended timing |
|---|---|---|
| Onboarding | Company, owners, directors, jurisdictions, declared wallets | Before activating the relationship |
| Before a payout | Recipient name and destination wallet | As close as practical to signing or broadcast |
| Queued or approved payment | Destination wallet and counterparty | Rescreen if execution is delayed or data changes |
| Incoming payment | Originating wallet and known sender | On detection, before funds are swept, converted, or used |
| Existing relationship | Names, ownership, and active wallets | Periodically and when lists or risk information change |
For batch payments, every destination should be screened rather than checking only the batch owner or uploaded file. The same principle applies across Ethereum, Base, Arbitrum, Polygon, Tron, BNB Chain, Optimism, and Solana: screen the actual address on the network being used.
Address formats and analytics coverage vary by blockchain. Finance teams should confirm that their screening provider supports each network before enabling payouts on it. A result for an Ethereum address should not be assumed to cover a visually similar address or account on another chain.
How to handle a screening alert
An alert should pause the transaction, not automatically determine the outcome. Screening tools can generate false positives from similar names, incomplete ownership data, or broad blockchain exposure rules.
A clear disposition process can follow these steps:
- Stop execution: Do not sign or broadcast an outbound transfer while a material alert is unresolved.
- Confirm the data: Check the legal name, aliases, date of birth or incorporation, registration number, jurisdiction, and wallet address.
- Review the match: Determine whether the alert is an exact sanctions match, a partial name match, direct wallet exposure, or indirect exposure.
- Establish ownership: Verify that the wallet belongs to the stated counterparty. Evidence may include a signed wallet message, a test transfer, exchange account documentation, or confirmation through an established communication channel.
- Assess the transaction: Review the invoice, payment purpose, source of funds, destination, network, and commercial relationship.
- Escalate where required: Send confirmed or unresolved material matches to the designated compliance or legal reviewer.
- Record the decision: Approve, reject, hold, or block according to the applicable sanctions program and legal advice.
Terms such as “blocked” and “rejected” have specific legal meanings under OFAC rules. A company should not move or return potentially blocked property without determining the correct treatment. Where OFAC reporting applies, initial reports of blocked property and rejected transactions are generally due within 10 business days. Requirements can change, so teams should verify current deadlines and retention periods with counsel.
What evidence finance teams should retain
A defensible record should allow an independent reviewer to reconstruct what happened without relying on an employee’s memory. Saving only a green check mark is rarely enough.
For each screened payment, retain:
- Transaction ID, amount, asset, blockchain, wallet addresses, and timestamp
- Counterparty legal name and identifying information used in the search
- Sanctions lists and wallet data sources checked
- Screening timestamp and result, including the risk category and exposure path
- Alert details, supporting documents, and reviewer notes
- Final decision, decision-maker, approval time, and policy rule applied
- Blockchain transaction hash if the payment was completed
- Any report, legal instruction, or communication related to a blocked or rejected transaction
Evidence should be stored with controlled access and retained for the period required by the relevant sanctions and recordkeeping regimes. OFAC recordkeeping rules have changed over time, so a policy should cite the current rule rather than relying on an old five-year assumption.
Setting thresholds without treating a score as law
Wallet screening providers often return a risk score, but there is no universal score that defines whether a transaction is lawful. Scores vary by provider, data source, attribution method, and the number of transaction “hops” considered.
A practical policy should define which findings cause an automatic pause. Examples include an exact listed-address match, direct interaction with a sanctioned entity, or a counterparty identity match. It should separately define findings that require review, such as indirect exposure to a mixer or activity involving a higher-risk jurisdiction.
The policy should also specify who can clear each alert level. High-risk overrides should not depend on the employee who created the payment. Quorum signing—requiring multiple authorized signers—can prevent a payment from leaving a self-custodial vault until the required review is complete.
Building screening into treasury operations
Sanctions screening works best when it is part of the payment workflow rather than a separate spreadsheet task. Stablerail supports wallet screening, allowlists, approval limits, audit logs, and evidence packs alongside stablecoin accounts and payouts. Teams can use these controls to check a destination before authorized signers release USDC or USDT.
For recurring vendor, contractor, or payroll payments, an allowlist reduces address-entry risk but should not bypass rescreening. If a recipient changes its wallet, the new address should be verified and approved through a controlled process. See the stablecoin payouts guide for more on batch payment operations, or use the wallet checker when reviewing an address.
The objective is not to eliminate every alert. It is to make sure that stablecoin payments are screened before value moves, exceptions are reviewed by the right person, and each decision leaves a complete audit trail.
Finance writers covering stablecoin treasury, payments, compliance, and risk controls.
More about the Stablerail team- Stablecoin treasury managementApprovals, limits, yield and reporting on one balance.
- Stablecoin payoutsBatch contractor and vendor payments with screening.
- USDT vs USDCWhich stablecoin your company should settle in.
- Stablecoin finance glossaryMPC, off-ramp, travel rule and the rest, in plain English.
- Product updatesEverything we ship, month by month.

