# Sanctions screening on a confidential ledger

> Sanctions screening on a confidential ledger: The genuinely open problem. Region: Global.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Where privacy tech meets the rulebook
- Region: Global
- Subject: The genuinely open problem
- Tags: sanctions, OFAC, strict liability, open problem
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/why-sanctions-screening

## What it actually says

Worth stating plainly rather than glossing: this is the weakest part of the case for confidential ledgers. Sanctions liability under the US regime attaches without knowledge or intent, so any design that leaves a regulated intermediary unable to determine whether it dealt with a designated party hands that intermediary unmanaged legal risk. That mechanism, more than any explicit prohibition, is what drives delisting. The architectural answer is that screening does not require public amounts and parties, only that somebody with the duty can screen: at the on-ramp and off-ramp where identity already exists, inside the state machine as issuer policy, or through authorised disclosure. The unsolved parts are real. Designations are retroactive while proofs are historical, and a shielded transfer between two self-custodied parties has no intermediary at all. We found no regulator guidance and no enforcement precedent on any of it.

## The instruments that matter

- **Strict liability**: OFAC liability attaches without knowledge or intent, so a design that leaves an intermediary unable to tell whom it dealt with transfers unmanaged legal risk to that intermediary
- **Where screening can still happen**: at the regulated on-ramp and off-ramp where identity already exists, inside the confidential state machine as issuer policy, or by disclosure to the obliged entity
- **What has no clean answer**: designations are retroactive while proofs are historical, and a shielded peer-to-peer transfer has no intermediary to do the screening

## Related entries

- [Anonymity is not the same thing as confidentiality](https://www.sodalabs.xyz/privacy-hub/regulation/why-programmable-confidentiality): Why two privacy designs get treated differently
- [Central banks are building confidentiality themselves](https://www.sodalabs.xyz/privacy-hub/regulation/why-central-banks-build-privacy): What the people writing the rules do when they design money
- [Erasure against an append-only ledger](https://www.sodalabs.xyz/privacy-hub/regulation/why-erasure): The one collision with no clean answer yet
- [Proving where funds did not come from](https://www.sodalabs.xyz/privacy-hub/regulation/why-privacy-pools): Association sets, and the Tornado Cash aftermath
- [Selective disclosure as a compliance primitive](https://www.sodalabs.xyz/privacy-hub/regulation/why-viewing-keys): Bilateral disclosure versus publishing to everyone
- [The travel rule binds institutions, not ledgers](https://www.sodalabs.xyz/privacy-hub/regulation/why-travel-rule): The rule everyone assumes ends on-chain confidentiality
