Mon - Sat: 9:00 AM - 6:00 PM
Pacific Time (Los Angeles)
Call: 844-376-2274
24/7 Nationwide Service
LIVEJoin Demo Call
Interactive Training Session

F&I & Compliance

OFAC Compliance Software for Car Dealerships

The obligation is small, constant, and unforgiving. Most stores handle it by accident rather than by process.

OFAC screening means checking the parties to your transaction against US Treasury sanctions lists before you deliver a vehicle. LeadLocate does not sell an OFAC screening engine. SecureWebX provides the intake, identity capture, versioned consent and document records that sit around your screening tool. This page is buyer education, not legal advice.

What OFAC actually requires of a dealership

The Office of Foreign Assets Control is part of the US Treasury. It maintains sanctions programs and publishes lists of sanctioned parties, the best known being the Specially Designated Nationals and Blocked Persons list, usually shortened to the SDN list.

Two features of the rules matter more to a car store than any software feature. First, the obligation applies to all US persons, which includes your dealership regardless of size, franchise status or whether the deal was financed. There is no small business exemption. Second, the standard is generally treated as strict liability, meaning a violation can exist even where nobody intended one and nobody knew. Good faith is relevant to penalties, not to whether the violation occurred.

Practically, that means a store is expected to check the parties to a transaction against the current lists, to keep evidence that it checked, and to know what to do if something matches. Sanctions lists change frequently, which is why a printout from last spring is worse than useless: it creates a record that you screened against stale data.

We are describing a general framework, not giving you legal advice. Your obligations depend on your state, your business lines and your specific transactions, and this is a subject where an hour with counsel who knows dealership compliance is money well spent.

Where the obligation shows up in a deal

Stores that get this wrong usually get it wrong by scope rather than by effort. They screen financed retail customers and nothing else, because that is where the lender's checklist told them to look.

Think instead about who the parties to your transactions are. Retail buyers, cash buyers, co buyers and co signers. The person you are buying a vehicle from, including a consumer selling you their car. Wholesale counterparties. Vendors you pay. Employees in some contexts. The point is not that every one of these carries identical risk, it is that the risk does not begin and end with the customer who filled out a credit application.

A related confusion worth clearing up because it costs stores real money: cash reporting is a separate obligation. The requirement to file a report for cash received over ten thousand dollars in a transaction or in related transactions comes from a different part of the rules and has nothing to do with sanctions screening. Stores routinely conflate the two, then assume that satisfying one covers the other. It does not, and both get examined.

Build a written policy that names, for each transaction type, who screens, at what point in the process, against which list, and what record gets kept. A policy that lives only in the finance manager's head disappears when they leave.

What OFAC screening software does

The category itself is narrow and it should be. A screening tool takes a name and identifying details, compares them against current sanctions lists, and returns a match, a possible match or a clear result.

The engineering that matters is in the middle option. Names are messy: transliterations vary, middle names come and go, dates of birth are missing, and a common surname will produce hits constantly. A good tool does fuzzy matching well enough to catch a genuine hit spelled differently, without producing so many false positives that your finance manager starts clicking through them without reading. That balance is the whole product.

Beyond matching, decent tools handle list currency automatically so you are never screening against a stale file, apply the ownership rules that extend sanctions to entities owned by blocked parties, keep a timestamped audit record of every screen including the clear ones, and support the escalation path when something hits.

What they do not do is make the decision for you. A potential match requires a human to investigate, and a true match requires you to stop, block the property and report it within the required window. Software surfaces the question. Your policy answers it.

Where we sit, said plainly

We would rather lose the search than imply a capability we do not have.

LeadLocate and SecureWebX do not perform OFAC or SDN list screening. There is no sanctions list matching, no automated list updates, no watchlist monitoring, and no blocked party reporting workflow in our products. If sanctions screening is what you came here to buy, you need a dedicated compliance vendor or a screening service, and you should evaluate one on its own merits.

That is a straightforward statement and it is the honest one. Plenty of automotive software marketing implies compliance coverage by association: the vendor mentions compliance in a feature list, the dealer assumes screening is included, and nobody discovers the gap until an examiner asks for the audit trail. We would rather you find out on this page.

What we do have is the layer around it, and that layer is genuinely useful, because a screening result is only as good as the identity information it was run against and the record you kept afterward.

What SecureWebX does provide around your screening

Screening is a check performed on data. Getting that data cleanly, and proving later what you had and when, is a real problem and it is the one we solve.

Secure online credit applications capture the customer's legal name, addresses and identifying details in structured fields rather than in handwriting somebody transcribes later. Transcription errors are a quiet cause of both missed hits and false ones.

Apply links are shareable secure application URLs you can text to a customer so they complete the application privately from their own phone. Applications land in a company inbox rather than an individual's email.

Identity verification at intake and document collection mean identification and supporting documents arrive attached to the application record, with camera capture from a phone and document reading to assist. That is the file an examiner wants to see, assembled at the time rather than reconstructed afterward.

The compliance module and a terms and consent gate with versioning record which version of your disclosure language a specific customer accepted and when. Version tracking sounds like a detail until you need to prove what a customer saw eighteen months ago. Role based permissions control who can see what, and eFax exists on the admin side for the counterparties who still require it. More detail on the digital F&I platform page.

Three obligations that keep getting confused

Dealers routinely treat sanctions screening, identity theft prevention and data security as one compliance blob. They are three separate programs with three separate examiners' expectations.

OFAC sanctions screening asks whether you are transacting with a sanctioned party. It is a list check with a blocking and reporting obligation attached.

The Red Flags Rule asks whether you have a written program to detect and respond to indicators of identity theft in covered accounts. It is about the person not being who they claim to be, which is a different question from whether the person is sanctioned. Our page on Red Flags Rule compliance covers the program elements.

The FTC Safeguards Rule asks whether you protect customer information you hold: risk assessment, access controls, encryption, vendor oversight, an incident response plan and a named qualified individual. See FTC Safeguards Rule compliance.

The overlap is the customer file. All three programs draw from the same intake, which is exactly why the intake layer deserves attention even though it is not the screening tool itself. Build one clean file and three programs get easier.

Building a process that survives a staff change

Most compliance failures in car stores are process failures, not knowledge failures. Someone knew the rule and the step got skipped on a busy Saturday.

  1. Write the policy down and name a person, by role, who owns it. If nobody owns it, it belongs to whoever is standing there when it goes wrong.
  2. Fix the trigger point. Screening should happen at a defined moment in the process every time, not whenever someone remembers. Before delivery is the common answer; earlier is better because it is cheaper to stop a deal than to unwind one.
  3. Cover every party, including co buyers, co signers and the consumer you are buying a car from, not only financed retail buyers.
  4. Keep the negative results. The clear screens are the evidence your program ran. Storing only the hits proves nothing.
  5. Train and re train. Turnover in the finance office is high, and a program that was explained once to someone who has since left is not a program.
  6. Audit yourself quarterly. Pull ten random deals and try to reconstruct the compliance file from what is stored. Whatever you cannot find is what an examiner will ask for.

Document handling for the record keeping side is covered on our compliance document management page.

Questions for a screening vendor

Since you will be buying this elsewhere, buy it well. These are the questions that separate serious vendors from checkbox ones.

How often are the lists refreshed, and can you show me the timestamp on the copy I screened against? What is your false positive rate on common surnames, and can I tune the matching threshold? Do you apply the ownership rules that extend sanctions to entities controlled by listed parties? Do you screen once or monitor continuously, and what happens if a customer is added to a list after delivery on a retained obligation? What exactly is in the audit record, and can I export it if I leave you? How does a potential match get escalated, and who at my store is expected to resolve it? Is training included?

Then ask the one most vendors dislike: what does your product not cover. Any vendor who cannot answer that clearly is a vendor who will let you assume too much. We hold ourselves to the same test, which is why the limits on this page are stated in the middle rather than in small print at the bottom.

If you want to talk through where the intake and record layer would fit alongside whatever screening tool you choose, contact us and we will tell you honestly whether we help.

Frequently Asked Questions

Does LeadLocate perform OFAC or SDN screening?

No. There is no sanctions list matching, no automated list updates, no watchlist monitoring and no blocked party reporting in our products. Screening requires a dedicated compliance vendor. We provide the application intake, identity capture, consent versioning and document records around it.

Do car dealerships really have to screen against OFAC lists?

The obligation applies to US persons generally, including dealerships, and it is not limited to financed deals. Specifics depend on your transactions and your state, so confirm your program with counsel who knows dealership compliance rather than relying on a vendor page.

Is cash reporting the same as OFAC screening?

No. Reporting cash received above the threshold comes from a different part of the rules and satisfying one does nothing for the other. Stores commonly conflate them and then find both gaps at once during an examination.

What records should we keep?

Keep evidence that a screen ran, when, against which list version, on which parties, and what the result was, including the clear results. Storing only the hits proves nothing about whether the program actually operated.

How does SecureWebX help if it does not screen?

It makes the file you screen against and keep. Structured application data instead of transcribed handwriting, identity verification at intake, document collection attached to the record, a compliance module and consent captured with version tracking.

Is this page legal advice?

No. It is buyer education written for dealership decision makers. Sanctions compliance is fact specific and the rules change, so build your program with qualified counsel and a dedicated screening vendor rather than from any marketing page.

More Resources from LeadLocate

Get the intake file right and three programs get easier

See secure applications, apply links, identity capture at intake and versioned consent records running together. Month to month, no long term contract.

LeadLocate
Accepted credit cards: Visa, MasterCard, American Express and Discover
LeadLocate® All rights reserved. Other product and company names mentioned herein are the property of their respective owners.

Answers to your questions:

What is LeadLocate?

LeadLocate is an all-in-one lead generation software and CRM platform. We generate in-market sales leads and provide you with all the tools necessary to sell that customer. All of your leads, texts, calls, emails, deals, and files are available in one place, accessible with a single login.

Accepted credit cards: Visa, MasterCard, American Express and Discover
LeadLocate® All rights reserved. Other product and company names mentioned herein are the property of their respective owners.

Answers to your questions:

What is LeadLocate?

LeadLocate is an all-in-one lead generation software and CRM platform. We generate in-market sales leads and provide you with all the tools necessary to sell that customer. All of your leads, texts, calls, emails, deals, and files are available in one place, accessible with a single login.