"We screened against the OFAC list at deposit and withdrawal" no longer survives an audit. In 2025 the list itself became a moving target, while value received by sanctioned entities rose 694% and 84% of illicit volume moved through stablecoins — much of it via entities not yet on any list. The operators who hold run screening as a living operational discipline. The ones who treat it as a checkbox are the ones the examiner finds. Coinbase Europe's €21.5 million fine and OKX's $504 million resolution are what the checkbox costs.
A two-moment name-match is a snapshot of something that moves continuously.
Three developments in 2025 made the checkbox indefensible
The list stopped being fixed — 21 March 2025
OFAC delisted Tornado Cash after the Fifth Circuit ruled in Van Loon that the 2022 designation exceeded its statutory authority. Treasury signaled it could redesignate.
The flow industrialized — October 2025
Operation Prince produced the largest forfeiture in DOJ history, roughly $15 billion in Bitcoin, with OFAC and the UK jointly sanctioning 146 targets.
The value moved to stablecoins — Chainalysis, 2026 report
Value to sanctioned entities rose 694% year over year inside $154 billion of illicit volume, 84% of it in stablecoins. The ruble-backed A7A5 alone moved $93.3 billion in under a year.
The risk is no longer the name on the list. It is the proximity to the cluster, and the change you did not re-screen.
Why the checkbox fails the audit
A deposit-and-withdrawal SDN check answers one question at two moments: was this exact name on the published list right then. It does not answer the questions an examiner now asks:
- Was the counterparty a known cluster affiliate before it was formally designated — a Huione or Grinex counterparty transacting in the window before the effective date?
- Did the customer's residence or activity pattern shift into a sanctioned nexus after onboarding, with no re-screen?
- Did the value arrive through a stablecoin rail and an intermediary that the name-match never touched?
The cost of not answering them is concrete. The Central Bank of Ireland found Coinbase Europe had left more than 30 million transactions unmonitored in a single year, part of a control failure spanning roughly four years. The fine was €21.5 million.
A checkbox that ran, and did not see. The discipline is what sees.
What running it as a discipline requires
The operational standard the operators who survive an audit actually run — concrete enough to test against your own screening this week.
1. The SDN match is the floor, not the ceiling
Screen OFAC's continuously updated SDN list, the UK OFSI consolidated list, and the EU sanctions list in parallel, then add behavioral detection on proximity to sanctioned-entity clusters: A7A5, Grinex, and Huione counterparties transacting before the effective date. The name-match catches the listed entity; the cluster analysis catches the value moving through entities not listed yet.
Stop at the name-match and you are screening the past.
2. Jurisdictional-nexus screening at deposit, with continuous monitoring
Bind screening to a verified KYC residence and continuous geolocation triangulation, and re-screen when residence, employer, or activity-pattern signals change materially — treating the AMLA single rulebook as one supervisory perimeter rather than a set of national checks.
Screen once at onboarding and you miss the customer who moves into a sanctioned nexus later.
3. Screening vendors under documented ICT third-party risk management
Place the vendor inside the supervisory perimeter — NYDFS Section 500.11, DORA Articles 28 to 44, NIS 2 Article 21 — with list-update frequency contractually specified and tested, and incident reporting on the operator's regulatory clock, not the vendor's.
Assume the vendor's list is current and you carry a lag you cannot see.
4. Decision logic that produces auditable outcomes, not stalled queues
Run hold, block, and release as coded decisions, each timestamped with rationale, with a named MLRO escalation path and SAR filings managed against statutory deadlines.
Let alerts pile up and you get both failures: the false positive that strangles legitimate flow, and the true hit left unactioned past the deadline.
The four compound. The cluster analysis feeds the nexus re-screen, the governed vendor keeps the lists current, and the decision logic turns all of it into an auditable record. A match is a moment; a discipline is a system.
What to automate, and what to never automate away
Automate all of it: the name-match volume. Off-the-shelf screening tools and generic outsourcing handle it well. That layer should be automated and cheap.
Never automate away the decision. The cluster-proximity judgment, the nexus change that warrants a re-screen, the hold-or-release on a real hit under a statutory clock — judgment against an adversary structuring specifically to beat the list.
Cost-per-alert is the wrong instrument for that work. Tiered on purpose: tooling for the match, a specialized operation for the decision.
Where the discipline is operated
Running screening as a living discipline is an operational design, not a bigger alert queue. A specialized operation runs the sanctions and AML support layer: the hold-block-release decisions, the MLRO escalation, the SAR discipline, and the audit trail, built into the workflow rather than bolted on. The point is not more alerts cleared. It is a screening record that answers the examiner's questions before they are asked.
Five questions an examiner would ask
Run these against your screening operation, whether you run it or a partner does.
- Does your screening detect proximity to sanctioned-entity clusters, or only exact matches on the published list?
- Do you re-screen when a customer's residence, employer, or activity pattern shifts into a new nexus, or only at onboarding?
- Is your screening vendor's list-update frequency contractually specified, tested, and reporting incidents on your regulatory clock?
- Are hold, block, and release coded, timestamped, and auditable, with a named MLRO path and SAR filings tracked against deadlines?
- If an examiner reconstructed a transaction from twelve months ago, would your record show a decision, or an alert that sat in a queue?
The question you cannot answer cleanly is the one the next enforcement action is written around.
Common questions
Isn't screening against the OFAC SDN list at deposit and withdrawal enough?
Not in the current environment. The list moves: Tornado Cash was delisted by court order in 2025 and could be redesignated. The illicit flow increasingly moves through clusters and stablecoins before entities are listed. A two-moment name-match is a snapshot; auditing now asks whether the operation saw the proximity and the nexus change.
What does the checkbox actually cost?
Coinbase Europe paid €21.5 million to the Central Bank of Ireland for a monitoring configuration that left more than 30 million transactions unscreened in a single year. OKX paid $504 million to the US DOJ for AML and KYC failures. The fine is written around the gap the checkbox could not see.
Where does a specialized operation fit?
As the layer that runs the decision, not just the match: cluster-proximity analysis, nexus re-screening, governed vendors, and an auditable hold-block-release record. Toeshee operates that layer for regulated crypto, iGaming, and fintech operators under compliance discipline.
Toeshee is the specialized customer-support partner for iGaming, fintech, and digital-asset platforms, with risk management and compliance as the design principle of every workflow — SOC 2-compliant operations and audit-ready discipline built into every escalation.
We've got your back. Crypto-native.
