8 Oct 2026
OFAC Compliance for Ecommerce: What Online Sellers Must Know (and What Violations Cost)
What OFAC is, who its rules bind, what strict liability means for an online store, current penalty maximums, the 10-year look-back and recordkeeping rule, and real ecommerce enforcement cases.

Last reviewed: 8 October 2026. Penalty amounts and regulations are current as of this date and are adjusted periodically. This is general information, not legal advice.
Quick answer
OFAC, the US Treasury's Office of Foreign Assets Control, administers US economic sanctions. Its rules apply to US persons of every size, including one-person online stores. Civil penalties can be imposed on a strict liability basis: OFAC doesn't have to prove you knew. The maximum civil penalty under IEEPA, the law behind most programs, is the greater of $377,700 per violation or twice the transaction value. Since 2024, OFAC can reach back 10 years, and since March 2025 you must keep transaction records for 10 years.
Penalties actually imposed are often far lower than the maximum, especially when the violation is non-egregious and voluntarily disclosed. The factor that most changes the outcome is whether you had a reasonable compliance program in place.
What OFAC is and what it administers
OFAC administers and enforces US sanctions programs: country-based programs, such as the comprehensive sanctions on Cuba, Iran and North Korea and the region-wide restrictions on Crimea and the so-called DNR and LNR, and list-based programs targeting named persons.
The best-known list is the Specially Designated Nationals and Blocked Persons List (SDN List). US persons must block the property of SDNs and generally may not deal with them. Under OFAC's 50 percent rule, entities owned 50% or more, individually or in aggregate, by blocked persons are blocked too, even if they are not named on the list. OFAC also publishes a Consolidated (non-SDN) Sanctions List of narrower restrictions.
Who OFAC rules bind
"US persons" means US citizens and permanent residents wherever located, entities organized under US law and their foreign branches, and anyone in the United States. For an online store this includes:
- a US-registered store selling anywhere in the world;
- a US citizen running a store from abroad;
- in some programs (notably Cuba and Iran), foreign entities owned or controlled by US persons.
Non-US merchants are not automatically outside OFAC's reach. A transaction that causes a US person, such as a US bank, card network or payment processor, to violate sanctions can create exposure.
What strict liability means for an online sale
Strict liability means a civil violation can exist even if you didn't intend it and didn't know. If a US store sells and ships to an SDN, or to an address in an embargoed region, OFAC can treat it as an apparent violation whether or not anyone looked.
That's why "I didn't know" isn't a defense on its own. What you did to find out matters a great deal in how OFAC responds. Its Economic Sanctions Enforcement Guidelines weigh, among other factors:
- willfulness or recklessness;
- awareness of the conduct;
- harm to sanctions program objectives;
- the individual characteristics of the business, including size and sophistication;
- the existence, nature and adequacy of a compliance program;
- remedial response;
- cooperation, including voluntary self-disclosure.
What violations cost
| Penalty type | Maximum (as of 8 October 2026) |
|---|---|
| Civil penalty, IEEPA-based programs | Greater of $377,700 per violation or twice the transaction value |
| Criminal penalty, willful violation of IEEPA | Up to $1,000,000 and, for individuals, up to 20 years' imprisonment |
Source: OFAC's Sanctions Penalties Regulations, 31 CFR Part 505, effective 25 September 2026. They consolidate penalty rules previously scattered across more than 40 program regulations and restate the IEEPA amounts without substantive change. The civil maximum is adjusted for inflation; it rose from $368,136 to $377,700 in January 2025. Cuba sanctions rest on a different statute, the Trading with the Enemy Act, with its own penalty amounts.
"Per violation" matters. Each order can be a separate violation, so a few hundred small orders add up even though each is worth very little.
The 10-year look-back and the 10-year record rule
The 21st Century Peace through Strength Act, signed on 24 April 2024, extended the statute of limitations for IEEPA and TWEA violations from five to ten years. OFAC then extended its recordkeeping requirement in 31 CFR 501.601 to ten years by a final rule that took effect on 21 March 2025.
For a merchant, that means keeping a full and accurate record of each transaction subject to US sanctions rules for ten years after the transaction. Screening results and decisions are a natural part of that record. Many apps, including Shopify apps, delete data when you uninstall them. Plan your own archive.
Ecommerce cases worth knowing
These settlements are public, and each one teaches a specific lesson.
| Company and date | Settlement | What OFAC described |
|---|---|---|
| Amazon.com, Inc., July 2020 | $134,523 | Orders accepted from persons in Crimea, Iran and Syria. Automated screening missed alternative spellings of sanctioned places and, in several hundred instances, correctly spelled SDN names and addresses. OFAC treated the case as non-egregious and voluntarily self-disclosed. |
| BitPay, Inc., February 2021 | $507,375 | 2,102 apparent violations. BitPay screened its merchants, but not the location data, including IP addresses, it held about the merchants' buyers in sanctioned jurisdictions. |
| Payoneer Inc., July 2021 | $1,400,301 | Weak screening algorithms, failure to monitor IP addresses and flag sanctioned-location addresses, and software that auto-released flagged payments during backlogs. |
| PayPal, Inc., March 2015 | $7,658,300 | 486 apparent violations. Its filter didn't correctly identify potential SDN matches, and alerts were dismissed. |
The pattern across these cases is not companies that ignored sanctions. They all had screening. The screening missed spellings, ignored data the company already held, or let flagged items through.
What OFAC expects from a small seller
OFAC's Framework for OFAC Compliance Commitments (May 2019) isn't a regulation, but it's what OFAC uses to judge a program after the fact. It is risk-based and names five components. For a Shopify store, they translate roughly as:
- Management commitment. The owner decides that sanctions checks are part of fulfilling an order and names who is responsible.
- Risk assessment. Where do you ship? Who buys from you? What do you sell? Do you take B2B orders?
- Internal controls. Screen buyers, recipients and companies against the SDN and Consolidated lists, plus the other lists that apply to you. Check destinations for embargoed regions. Hold fulfillment on possible matches.
- Testing and auditing. Check periodically that screening actually ran, for example on a sample of orders and on known spelling variants such as "Krimea".
- Training. Whoever reviews flagged orders should understand what a match means, what a false positive looks like, and when to stop and escalate.
If you find a problem
If you discover you may already have shipped to a sanctioned party or region:
- stop further dealings with that party;
- preserve the records;
- don't tip off the customer;
- get legal advice on whether and how to make a voluntary self-disclosure to OFAC. Under the enforcement guidelines, voluntary self-disclosure substantially reduces the base penalty.
OFAC screening for Shopify with MatchAudit
MatchAudit is a Shopify app that screens orders and customers against OFAC and other lists. Get it on the Shopify App Store.
- OFAC SDN and Consolidated lists are available as sources, alongside the US Consolidated Screening List, US State Department lists and the US SAM exclusions list. SAM is labeled as federal debarments, not sanctions.
- Spelling-tolerant matching: normalization, alias comparison, word-order-tolerant, phonetic and transliterated comparisons. These target exactly the kind of variant spellings that came up in the Amazon case.
- Freshness rules: MatchAudit downloads source lists on a six-hourly schedule. An OFAC SDN version older than 24 hours is not used. If a selected list isn't current, the order is held for review, not passed as clear.
- A hold and a human decision on open fulfillment orders, with the reviewer taken from the verified Shopify session.
- Evidence for the 10-year question: each decision records the canonical index generation, the exact matched-entry hash, the algorithm version, the threshold, the country assessment, the timestamp and the reviewer. Paid plans export PDF and JSONL evidence over a date range. Export regularly and keep the files in your own archive, because the app isn't a 10-year archive.
- Look-back: a free one-time screen of past orders covers the most recent 60 days by default. It widens once Shopify grants the protected
read_all_ordersscope. A CSV upload covers older or off-platform records from the last 12 months. Historical results never auto-apply a hold, refund or filing; they open a separate review queue.
Find out what your last 60 days look like. Install MatchAudit and run the free retroactive screen. Then decide whether anything needs a closer look before you have to explain it.
Frequently asked questions
What happens if I accidentally sell to someone on the OFAC list? It can be an apparent violation even if it was accidental. Stop dealing with the party, preserve records, don't alert the customer, and get legal advice about voluntary self-disclosure. The outcome depends heavily on the facts and on your compliance program.
Do OFAC rules apply to small online businesses? Yes. There is no general small-business exemption. OFAC considers a company's size and sophistication when deciding on enforcement, but the prohibitions apply to all US persons.
How do I check someone against the OFAC SDN list? OFAC provides a free Sanctions List Search tool for one-off lookups. For every order on a live store, use an automated screen that also checks the Consolidated list and keeps a record.
How long must I keep sanctions records? Ten years for transactions subject to OFAC's regulations, under 31 CFR 501.601 as amended effective 21 March 2025.
Related reading
- Do Shopify stores need sanctions screening?
- How to screen Shopify orders against OFAC, EU, UK and UN lists
- Why was my payout frozen?
Official sources
- OFAC, Sanctions Penalties Regulations, 31 CFR Part 505 (Federal Register, 25 September 2026): federalregister.gov
- OFAC, Inflation Adjustment of Civil Monetary Penalties (Federal Register, 15 January 2025): federalregister.gov
- OFAC, Economic Sanctions Enforcement Guidelines, Appendix A to 31 CFR Part 501: ecfr.gov
- 31 CFR 501.601, Records and recordkeeping requirements: ecfr.gov
- OFAC, A Framework for OFAC Compliance Commitments: ofac.treasury.gov
- OFAC, Sanctions List Search: sanctionssearch.ofac.treas.gov
- OFAC enforcement releases: Amazon (8 July 2020) ofac.treasury.gov; BitPay (18 February 2021) ofac.treasury.gov; Payoneer (23 July 2021) ofac.treasury.gov; PayPal (25 March 2015) ofac.treasury.gov
Related reading

Best Sanctions Screening Apps for Shopify (2026): Compared
A dated comparison of the sanctions screening apps on the Shopify App Store, covering lists, fulfillment holds, review workflow, evidence and pricing, sourced from each app's public listing.

How to Screen Shopify Orders Against OFAC, EU, UK and UN Sanctions Lists (and Keep Proof)
A step-by-step sanctions screening process for Shopify: which lists to use, which names to screen, how to handle false positives, how to decide a possible match, and what records prove you screened.
