OFAC’s Six-Step Framework: Why Indian Banks Fail at Step 3 and What the RBI’s New Mandate Means

OFAC six-step framework infographic by Adv Shoeb Hakim showing the critical Step 3 and Indian bank challenges

Key Facts

  • Framework: OFAC’s six-step process for assessing name matches on sanctions lists
  • Critical Step: Step 3 — evaluating the quality of the potential match
  • Core Problem: Indian banks lack the data infrastructure to compare “all of the details” in OFAC listings
  • Transliteration Challenge: OFAC SDN List includes names transliterated from Arabic, Persian, and Urdu; Indian banks screen names like Mohammed, Abdul, Khan
  • 50 Percent Rule Gap: Banks must identify entities blocked by operation of law, but UBO data is often self-declared and unverified
  • RBI Mandate: Cybersecurity, Technology: Risk, Resilience and Assurance Framework issued 31 July 2026
  • Reporting Timeline: Real-time reporting of cyber incidents within six hours on the DAKSH platform
  • Supervisory Priority: RBI’s 2025-26 priorities explicitly list “sanctions compliance” as a focus area

Direct Answer

OFAC’s six-step framework for assessing name matches is the gold standard for sanctions screening. But its most critical step — Step 3, evaluating the quality of the match — is where most Indian banks fail.

The framework directs banks to compare “all of the details” in the OFAC listing with available information. For Indian banks, the challenge is not the framework — it is the data. OFAC’s SDN List includes names transliterated from Arabic, Persian, Urdu, and other languages.

Indian banks screen customers with names like Mohammed, Abdul, and Khan. A single OFAC entry for “Muhammad” may have a dozen spelling variants. Most Indian banks use legacy screening software that does not support fuzzy matching or phonetic algorithms.

The result is either too many false positives (which overwhelm compliance teams) or too many false negatives (which create regulatory risk). The 50 Percent Rule gap compounds the problem: ownership chains are often opaque, particularly for entities registered in tax havens, and UBO data collected by Indian banks is often self-declared and unverified.

The RBI’s 2026 Cybersecurity Framework signals a broader regulatory shift towards continuous assurance — a shift that will inevitably extend to sanctions compliance.


In this article:

  • The OFAC Six-Step Framework: An Overview
  • Step 3: The Critical Step Where Banks Fail
  • The Transliteration Problem
  • The 50 Percent Rule Gap
  • The RBI’s New Mandate
  • The Lesson from the Citibank OFSI Case
  • The Path Forward for Indian Banks
  • FAQ

By Adv. Shoeb Hakim — Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police forces since 1996.


The OFAC Six-Step Framework: An Overview

The Office of Foreign Assets Control (OFAC) recommends that organisations follow a six-step process when investigating potential matches to individuals or entities on its sanctions lists. The framework, updated on 9 September 2026, is as follows:

Step 1: Determine whether the “alert” or “hit” matches against one of OFAC’s sanctions lists or matches against a list maintained by other government agencies or organisations.

Step 2: If the hit involves OFAC sanctions, determine whether it involves a potential match to a name on one of OFAC’s sanctions lists, a country, region, or government targeted by OFAC sanctions, or any other non-listed sanctions target.

Step 3: If the hit involves a potential match to a name or alias on one of OFAC’s sanctions lists, evaluate the quality of the potential match.

Step 4: Determine next steps required for a valid match.

Step 5: Determine whether you are required to block the property, or whether you are required to reject the transaction or stop certain activity.

Step 6: Report valid matches to OFAC and maintain required records.

While all six steps are important, Step 3 is where the quality of a bank’s sanctions compliance programme is truly tested — and where Indian banks most often fail.


Step 3: The Critical Step Where Banks Fail

Step 3 directs banks to “compare all of the details in the OFAC listing with the information available to you about the data in your transaction or activity that led to the alert or hit.”

OFAC’s list entries include:

  • Full names
  • Former names
  • Known aliases
  • Nationalities
  • Passport numbers
  • Tax ID numbers
  • National identification numbers
  • Place of birth
  • Date of birth
  • Business registration numbers
  • Known addresses
  • Date of designation
  • Names and aliases in non-Latin character sets

The framework acknowledges that “many potential matches identified through screening are false positives.”

To verify or disqualify a potential match, banks must gather additional information from parties involved in the transaction or activity, such as a birth certificate, driver’s license, or a business’s corporate registration documentation.

The Indian Challenge

For Indian banks, the challenge is not the framework — it is the data. The information required to perform Step 3 effectively is often unavailable, unverified, or inconsistently formatted.


The Transliteration Problem

OFAC’s SDN List includes names transliterated from Arabic, Persian, Urdu, and other languages. Indian banks screen customers with names like Mohammed, Abdul, and Khan.

A single OFAC entry for “Muhammad” may have a dozen spelling variants:

  • Muhammad
  • Mohammed
  • Mohammad
  • Muhammed
  • Mohamad
  • Mohamed

The OFAC guidance acknowledges this by including “known aliases” and “non-Latin character sets” in its enhanced data formats.


The Legacy Software Problem

Most Indian banks use legacy screening software that does not support fuzzy matching or phonetic algorithms. The result is either:

  • Too many false positives: Which overwhelm compliance teams
  • Too many false negatives: Which create regulatory risk

The Scale of the Problem

India’s banking sector processes millions of transactions daily. With high transaction volumes and limited compliance staff, the temptation is to auto-dismiss alerts. But auto-dismissal creates regulatory risk — and regulatory risk creates enforcement action.


The 50 Percent Rule Gap

Step 2 of the framework directs banks to consider whether a potential match involves an entity “blocked by operation of law” under OFAC’s 50 Percent Rule.

What Is the 50 Percent Rule?

An entity may not be on the SDN List, but if it is 50% or more owned by a sanctioned person, it is legally blocked.

The Indian Challenge

Indian banks’ customer due diligence (CDD) frameworks, mandated under the RBI’s KYC Master Directions, require beneficial ownership identification.

But in practice:

  • Ownership chains are often opaque
  • Particularly for entities registered in tax havens
  • The UBO data that Indian banks collect is often self-declared and unverified

The Capability Gap

The 50 Percent Rule requires proactive analysis that most Indian banks do not have the capability to perform. Identifying a 50% ownership threshold requires tracing complex ownership chains across multiple jurisdictions — a task that requires sophisticated data analytics and access to reliable corporate registries.


The RBI’s New Mandate

The RBI’s Cybersecurity, Technology: Risk, Resilience and Assurance Framework, issued on 31 July 2026, mandates continuous monitoring and real-time reporting of cyber incidents within six hours on the DAKSH platform.

The Broader Regulatory Shift

While this framework focuses on cybersecurity, it signals a broader regulatory shift towards continuous assurance — a shift that will inevitably extend to sanctions compliance.

The Supervisory Priority

The RBI’s 2025-26 supervisory priorities explicitly list “sanctions compliance” as a focus area. Indian banks that treat sanctions screening as a periodic tick-box exercise will face regulatory consequences.

What This Means

Banks must move from periodic screening to continuous monitoring. The framework’s emphasis on real-time reporting in cybersecurity is a preview of what will be expected in sanctions compliance.


The Lesson from the Citibank OFSI Case

The Citibank OFSI case revealed critical failures in sanctions compliance.

The Facts

Citibank’s screening software failed to recognise “PAO” prefixes — a Russian form of incorporated entity. Alerts were missed. Compliance teams were overwhelmed.

The Lesson

A bank can have the best screening software, but if the compliance team does not investigate alerts properly, the software is useless.

The six-step framework is only as good as the people and processes behind it. Technology alone does not solve the compliance problem.


The Path Forward for Indian Banks

1. A Shared, Neutral Sanctions Screening Utility

FATF Vice President Vivek Aggarwal called for a shared, neutral sanctions screening utility at Global Fintech Fest 2026. Such a utility would allow banks to pool resources and access enhanced screening capabilities without each bank building its own system.

2. Investment in Fuzzy Matching and Phonetic Algorithms

Indian banks must invest in screening software that supports fuzzy matching and phonetic algorithms. Legacy systems that require exact matches are no longer sufficient.

3. Better UBO Verification for the 50 Percent Rule

Banks must invest in UBO verification capabilities. This includes:

  • Access to reliable corporate registries
  • Data analytics to trace ownership chains
  • Verification mechanisms for self-declared UBO data

4. Training for Compliance Teams on the Six-Step Framework

Compliance teams must be trained on the OFAC six-step framework. They must understand that auto-dismissal of alerts creates regulatory risk. They must be empowered to investigate alerts properly.

5. Continuous Monitoring, Not Periodic Screening

The RBI’s shift towards continuous assurance means banks must move from periodic screening to continuous monitoring. Real-time reporting on the DAKSH platform is a preview of what will be expected.

6. Documentation and Record-Keeping

Step 6 of the framework requires organisations to keep complete, accurate records detailing the steps taken to investigate potential matches. Banks must document their Step 3 analysis — including why a match was verified or disqualified.


FREQUENTLY ASKED QUESTIONS (FAQ)

What is the OFAC six-step framework?

The OFAC six-step framework is a process for assessing name matches on sanctions lists. It includes determining whether a hit matches an OFAC list, evaluating the quality of the match, determining next steps, blocking or rejecting, and reporting valid matches.

What is Step 3 of the OFAC framework?

Step 3 directs banks to evaluate the quality of a potential match by comparing all details in the OFAC listing with available information about the party in the transaction.

Why do Indian banks fail at Step 3?

Indian banks fail at Step 3 because they lack the data infrastructure to compare all details. Legacy screening software does not support fuzzy matching or phonetic algorithms. UBO data is often self-declared and unverified.

What is the transliteration problem?

OFAC’s SDN List includes names transliterated from Arabic, Persian, and Urdu. Indian banks screen names like Mohammed, Abdul, and Khan. A single OFAC entry for “Muhammad” may have a dozen spelling variants.

What is the 50 Percent Rule?

The 50 Percent Rule provides that an entity not on the SDN List is legally blocked if it is 50% or more owned by a sanctioned person.

Why is the 50 Percent Rule a challenge for Indian banks?

Indian banks’ UBO data is often self-declared and unverified. Ownership chains are often opaque, particularly for entities registered in tax havens.

What is the RBI’s new mandate?

The RBI’s Cybersecurity, Technology: Risk, Resilience and Assurance Framework, issued on 31 July 2026, mandates continuous monitoring and real-time reporting of cyber incidents within six hours on the DAKSH platform.

How does the RBI’s framework relate to sanctions compliance?

The framework signals a broader regulatory shift towards continuous assurance — a shift that will inevitably extend to sanctions compliance. The RBI’s 2025-26 supervisory priorities list “sanctions compliance” as a focus area.

What is the Citibank OFSI case?

The Citibank OFSI case revealed that screening software failed to recognise “PAO” prefixes. Alerts were missed. Compliance teams were overwhelmed.

What is the path forward for Indian banks?

The path forward includes a shared sanctions screening utility, investment in fuzzy matching and phonetic algorithms, better UBO verification, training on the six-step framework, and continuous monitoring.

Q: What are the six steps in OFAC’s updated sanctions screening framework?
Ans: Step 1: Identify hit source; Step 2: Determine if hit involves OFAC sanctions/targets; Step 3: Evaluate match quality; Step 4: Determine next operational steps; Step 5: Block property or reject transaction; Step 6: Report valid matches and maintain records.


Q: Why is Step 3 considered the most critical vulnerability for Indian financial institutions?
Ans: Because Step 3 requires deep qualitative data comparison that is severely hampered by legacy IT infrastructure, unverified self-declared UBO data, and high-volume false-positive alert fatigue.


Q: How does the lack of verified Ultimate Beneficial Ownership (UBO) data compromise the 50 Percent Rule?
Ans: Without robust data analytics to trace opaque ownership chains across foreign tax havens, banks cannot accurately determine if unlisted corporate entities cross the 50 percent sanction threshold.


Q: What strategic recommendation did FATF Vice President Vivek Aggarwal propose at Global Fintech Fest 2026?
Ans: He called for a shared, neutral sanctions screening utility enabling banks to pool resources and access advanced screening capabilities collaboratively.


Explore More:

Read my blog: Shoeb Hakim Blog

Book Now: Book a Consultation

Contact: Contact Adv. Shoeb Hakim

Careers: Careers at Shoeb Hakim


Disclaimer: This content is for informational purposes only and does not constitute legal advice. Readers should consult qualified legal counsel for advice on their specific circumstances.

#AdvShoebHakim #OFAC #SanctionsCompliance #RBI #DAKSH #AML #WhiteCollarCrime #DigitalForensics #LegalDefense #Compliance #RiskManagement

Leave a Reply

Your email address will not be published. Required fields are marked *

Find