The SDN List is the list most people mean when they say “the sanctions list”, and it is the one most screening systems are built around.
What an entry contains
Each entry carries a unique identifier, the party’s primary name, any aliases OFAC is aware of, addresses, dates and places of birth or incorporation, identity document numbers, and one or more programme tags explaining the authority for the listing.
Entries have also carried digital currency addresses as a structured identifier type since 28 November 2018, when OFAC designated two Iran-based facilitators of the SamSam ransomware scheme and, for the first time, published the associated bitcoin addresses. That field is what makes automated screening of blockchain transactions against the list possible at all.
What it does not contain
Entities blocked by operation of the 50 percent rule are not on the list unless separately named. An entity owned fifty per cent or more in aggregate by listed parties is blocked whether or not it appears, so a system that screens only against published names will not find it.
That gap is the single most important thing to understand about this list, and it is why corporate ownership analysis is a necessary complement to screening rather than an optional one.
Formats
OFAC publishes through the Sanctions List Service in XML, CSV and plain text, and the list is also bundled into the Consolidated Screening List with the Commerce and State lists. The XML is the fullest representation; the flat files lose some of the identifier structure.