For the complete documentation index, see llms.txt. This page is also available as Markdown.

Automated Sanctions Screening

EasyCLA automatically screens organizations against government sanctions lists before a Corporate CLA can be signed or an employee acknowledgement (ECLA) can be completed.

In addition to the compliance confirmation checkbox that must be checked before signing a CLA, EasyCLA automatically screens organizations against government sanctions and trade-compliance lists, such as the lists published by the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC).

The screening is performed by the LFX Sanctions Screening Service (SSS), a shared LFX platform service that checks organizations against sanctions and watch lists through a specialized trade-compliance provider. Every screened organization receives one of two statuses:

  • Clean — no sanctions match was found. All EasyCLA workflows proceed normally.

  • Flagged — the organization potentially matches an entry on a sanctions or watch list. Corporate CLA (CCLA) signing and employee acknowledgements (ECLA) are blocked until the organization is reviewed and cleared.

Understanding the concept

Embargo compliance refers to the process of adhering to regulations and restrictions imposed by governments, organizations, or industries that prohibit or limit the sale, export, or transfer of certain goods, services, or technologies. Embargoes are often implemented to:

  1. Embargo Countries: Nations with whom trade is entirely or heavily restricted due to political, economic, or security reasons.

  2. Sanctioned Countries: Nations or entities under specific restrictions, such as trade, financial dealings, or travel, imposed by governments or organizations like the UN.

  3. OFAC: The U.S. Treasury's Office of Foreign Assets Control, which enforces sanctions programs targeting countries, entities, and individuals.

What is screened, and when

EasyCLA screens the organization that a corporate CLA workflow is being performed for — its name, its website domain, and (when available) its Linux Foundation organization record.

Sanctions screening applies to organizations only. Individuals are not screened, so signing an Individual CLA (ICLA) on your own behalf is not affected.

A fresh screening runs automatically — there is no extra step for you to perform — at the key points in the EasyCLA workflows:

The most recent screening result is also enforced at other points in the workflows — for example, when the Auto Enable Acknowledgement (Auto ECLA) workflow is enabled, when EasyCLA automatically creates employee acknowledgements for contributors who are added to the approved list, and when the EasyCLA checks on pull requests and merge requests verify contributor authorization.

A screening result is reused for a few minutes, so repeating an action in a short period of time does not trigger another screening.

What happens when an organization is flagged

Corporate contributors (ECLA)

If the organization you select in the EasyCLA Contributor Console is flagged, a Sanctions Screening dialog appears and the employee acknowledgement (ECLA) cannot be completed:

Sanctions Screening dialog in the EasyCLA Contributor Console
The EasyCLA Contributor Console blocks the ECLA acknowledgement because the selected organization is flagged by sanctions screening

Because the acknowledgement cannot be completed, the EasyCLA check on your pull request, merge request, or Gerrit change continues to fail until your organization is cleared.

If your organization was flagged during an earlier screening, the Contributor Console can show an advisory warning immediately after you select the organization. You can still proceed to the next step — EasyCLA re-verifies the status with a fresh screening, and blocks the acknowledgement only if the organization is still flagged.

CLA Managers and CLA Signatories (CCLA)

If the organization is flagged when the CCLA is being prepared for signature, the Preparing CCLA dialog changes to Unable to Prepare CCLA with a message that the CCLA cannot be completed at this time, and the Sign CCLA button remains disabled. Similarly, a CLA Manager who tries to send a signature request email to an authorized signatory for a flagged organization sees an Unable to Sign message, and the request is not sent.

If you believe your organization is flagged in error

Sanctions screening compares organization details against external watch lists, so a flag can result from a name similarity that does not apply to your organization. If you believe your organization is flagged in error, contact EasyCLA support via the chat widget in the console, or file a support ticket. The compliance team will review the screening result, and the flag is removed if the review confirms there is no match.

After an organization is cleared

No manual steps are needed in EasyCLA after an organization is cleared. The next time you retry the blocked action, EasyCLA re-screens the organization, picks up the clean status, and the workflow proceeds normally. Because screening results are reused for a few minutes, allow up to five minutes after the clearance before retrying.

Last updated

Was this helpful?