Answer:
OFAC compliance; i.e. checking the list, is risk based and depends on the individual bank's risk assessment. There is no legal requirement to check the OFAC list under any circumstance nor is there any guidance published on each of the myriad of circumstances where banks might choose to check the list.
You and your AP department have a difference of opinion. In the incredibly unlikely event that one of your vendors is an SDN or directs a payment to an SDN locale, OFAC will likely say that your opinion was correct.