Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFAC

Compliance audit and testing under OFAC: what businesses miss

A multinational trader operating across the Americas, Europe, and the Gulf runs quarterly OFAC screening on its counterparty database. The list-matching logic is sound. The ownership mapping, however, stops at the first corporate layer. A joint-venture partner's parent company has carried a blocked person on its cap table for eighteen months. No alert fires. The exposure is live, and the business does not know it.

Compliance audit and testing under OFAC – that is, the structured review of whether a sanctions programme actually works as designed – is one of the five elements OFAC identifies as constituting an effective programme. As of July 2026, OFAC's enforcement posture treats the absence or inadequacy of testing as an aggravating factor in penalty calculations. A programme that is documented but untested offers only the appearance of compliance, not the substance.

This analysis examines what OFAC expects from compliance auditing and testing, where businesses consistently fall short, how OFAC's approach compares with the positions taken by OFSI and the EU, and what a cross-border business should do to close the most common gaps.

What does OFAC expect from a compliance audit and testing programme?

OFAC's published framework identifies auditing and testing as a distinct, mandatory element of an effective sanctions compliance programme – not an optional enhancement layered on top of the other four elements. The expectation is that a business will periodically and independently test whether its controls are performing as designed, identify gaps, and remediate them. The framework is generic by design: it applies to financial institutions, corporates, brokers, payment processors, and any other entity subject to the jurisdiction of the United States.

What does that mean in practice? OFAC distinguishes between two related activities. The first is internal testing: the business itself runs structured exercises against its own controls, typically by running synthetic transactions through its screening logic, reviewing recent transaction files against the current list state, or commissioning internal audit to examine the end-to-end screening workflow. The second is independent audit: an external or functionally independent reviewer examines the programme against stated policy and OFAC's five-element standard. Both are expected. Neither substitutes for the other.

The frequency of testing is not prescribed by number in OFAC's published materials; it is risk-calibrated. A business with high-volume, automated transaction screening should test more often than a low-volume exporter. What OFAC penalises is not a specific testing interval but the demonstrable absence of testing – or testing that is purely cosmetic. In our experience, the most common failure is not that businesses refuse to test, but that they test the easy parts (list-matching on direct counterparties) and do not test the harder parts (ownership chains, correspondent-bank exposure, licensing compliance).

The five-element standard: where does auditing sit?

OFAC's framework groups the attributes of an effective sanctions compliance programme into five elements: management commitment, risk assessment, internal controls, testing and auditing, and training. Auditing and testing is element four. It sits downstream of the risk assessment (which tells a business what to test) and internal controls (which create the systems to be tested), and upstream of training (which responds to what testing reveals). This sequencing matters because it means that a testing programme that does not feed back into risk assessment and training is structurally incomplete.

In practice, many businesses treat the five elements as parallel compliance pillars rather than as an interconnected cycle. The risk assessment is conducted at onboarding and never refreshed. Internal controls are designed to match the risk assessment at that point in time. Testing confirms that the controls match the documentation. Training covers the documented policy. Nothing in this loop surfaces the fact that the business has expanded into a new geography, taken on a new product line, or encountered a regime change that the original risk assessment did not anticipate.

The position above covers the standard case. Your facts – the counterparty mix, the jurisdictions in play, the product lines, the route of payment – change the analysis substantially.

For a review of how your current programme maps to the five-element standard, contact Calder & Vance at info@caldervance.com.

Where do businesses miss the most ground?

In our cross-border practice, the gaps we encounter most consistently fall into six categories. Not every business has all six; most have at least two.

First: ownership and control mapping that stops at one layer. OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) requires aggregation across all direct and indirect holdings. A screening tool that flags the counterparty's name but does not map its parent, grandparent, and co-shareholders leaves the most structurally significant risk undetected. We regularly advise businesses that have accurate direct-counterparty screening but no systematic process for mapping the ownership stack above the counterparty.

Second: static list snapshots. OFAC updates the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) on an irregular basis – sometimes multiple times in a week. A business that downloads a list snapshot once a month and screens against it is not screening against the list; it is screening against a version of the list that may be weeks out of date. The gap between the list update and the next screening cycle is an uncovered window. Periodic re-screening of the existing counterparty population against the current list is a distinct exercise from screening new counterparties at onboarding.

Third: correspondent and intermediary exposure. A payment that passes through a US correspondent bank is subject to OFAC jurisdiction at the point of processing. A non-US business that assumes OFAC compliance is the correspondent's problem, not its own, is mistaken. OFAC's extraterritorial reach under IEEPA means that the US-nexus transaction can generate exposure for the originating party as well. Testing that does not include payment-routing review misses this.

Fourth: product and service classification. Not all prohibited transactions involve a listed person. Embargo programmes impose sector-specific and transaction-type restrictions regardless of whether the counterparty appears on any list. A business entering a new product category – technology licensing, financial services, energy – may trigger a separate prohibition that its existing testing regime does not cover because the regime was scoped to list-based controls only.

Fifth: licensing compliance. A business that holds an OFAC specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) is expected to operate within its exact terms. Licence conditions are frequently specific about counterparties, transaction amounts, purposes, and reporting obligations. Testing whether the business is operating within those terms is a compliance function that is distinct from initial screening. In our experience, this is among the most consistently overlooked testing areas in post-licence operations.

Sixth: the voluntary self-disclosure (VSD) decision framework. Testing may surface an apparent violation. The business then faces a decision: whether to make a VSD to OFAC, and how to present the facts and the remediation plan. Many businesses have testing programmes that surface issues but no pre-established process for evaluating the VSD question. When a violation surfaces at audit, the absence of a prepared process means the analysis happens under time pressure, which increases the risk of a poorly framed disclosure.

How does OFAC's approach compare with OFSI and the EU?

Compliance audit and testing under OFAC differs from the positions taken under OFSI and the EU in three structurally significant ways – and understanding those differences is essential for any business subject to more than one regime.

Under OFAC, the five-element framework is a published, named standard with explicit enforcement consequences. The absence of effective auditing and testing is an aggravating factor in penalty decisions. OFAC's published guidance on how it assesses compliance programmes at the enforcement stage makes the connection between testing adequacy and penalty quantum explicit. This creates a direct, quantifiable incentive to invest in testing.

OFSI's position is similar in outcome but differently articulated. OFSI's enforcement guidance sets out a compliance maturity model under which the quality of a business's compliance programme affects how OFSI characterises the violation and, ultimately, the penalty. A business that can demonstrate a structured, tested programme will be treated more favourably than one that cannot. The UK regime does not use the phrase "five elements", but it requires the same substantive content. One concrete difference: OFSI requires disclosure of a suspected sanctions breach within a defined reporting window – this is a positive legal obligation distinct from OFAC's VSD framework, which is voluntary in the strict sense. Verify the current reporting obligation under the applicable OFSI rules before relying on any specific timeline.

The EU presents a more fragmented picture. Compliance obligations are set at member-state level under EU Council regulations. There is no single, pan-EU five-element standard equivalent to OFAC's published framework. Member states differ in how prescriptively they define what a "good" compliance programme looks like and how they weigh it in enforcement. A business subject to both OFAC and EU sanctions should not assume that a programme built to OFAC's five-element standard is automatically adequate in every EU member state. The convergence is broad but the specifics require checking jurisdiction by jurisdiction.

One point is consistent across all three regimes: where a stricter prohibition or standard applies across overlapping regimes, the stricter rule governs the business's conduct in that area. A business cannot calibrate its testing programme to the least demanding regime and treat itself as compliant across the board.

For a detailed comparison of the OFAC and OFSI standards as they apply to compliance audit and testing, see our analysis at Compliance audit and testing: OFAC vs OFSI.

If a transaction has already been flagged, or an audit has surfaced an apparent violation, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential initial assessment.

How should a cross-border business structure its testing programme?

A cross-border business subject to OFAC as its primary regime should build its testing programme around three distinct exercises, each addressing a different layer of risk.

The first exercise is list-screening validation. This tests whether the screening tool is receiving accurate, current list data; whether the matching logic is calibrated to surface genuine hits without generating false-negative results at the expense of suppressing true positives; and whether alerts are being reviewed and resolved according to the documented procedure. This exercise should run on a frequency matched to the volume and speed of the business's transaction activity. For a high-frequency payment business, that means ongoing rather than periodic review.

The second exercise is ownership and control testing. This maps the beneficial ownership of a sample of counterparties – not just those flagged by list screening – against current SDN and other list data, including the 50 percent rule aggregation test. It should extend to entities where the business has contractual relationships, correspondent-banking chains, and, where relevant, investment targets. In our experience, this exercise most frequently surfaces the structural gaps that list-matching alone does not catch. Have you stress-tested your ownership mapping logic against a counterparty with a layered holding structure in a high-risk geography?

The third exercise is transaction and documentation review. This pulls a sample of completed transactions and checks them against the applicable prohibitions, licence terms, and reporting obligations. It is specifically designed to surface issues that screening does not prevent: transactions that were permitted by a licence but conducted outside the licence's terms, transactions with counterparties who were not list-flagged but who were subject to sector or activity restrictions, and transactions where the documentation record is insufficient to demonstrate compliance if a regulator later asks. Record-keeping requirements are material here: OFAC expects records to be maintained for five years.

What should a business do with the results? Each exercise should produce a written findings report tied to the risk assessment. Findings should be classified by severity and assigned to a remediation owner with a deadline. The remediation cycle should feed back into the next iteration of the risk assessment. And where a finding suggests an apparent violation, the VSD analysis should begin immediately, because the window for voluntary disclosure – and the credit that flows from it – does not remain open indefinitely.

A common myth: sophisticated screening technology eliminates the need for independent audit

A belief we encounter regularly in compliance consultations is that investment in automated, real-time screening technology removes the need for independent audit. The argument runs: the technology screens continuously, it covers the full list set, and it is configured by specialists – so what is the audit for?

The argument is wrong on the facts. Technology screens what it is configured to screen, at the frequency it is configured to run, against the data it is configured to receive. It cannot assess whether it is configured correctly. Independent audit is the mechanism by which that question is answered. Has the matching logic been tested against known aliases and transliterations? Is the ownership data feeding the tool current? Are the alert-resolution records complete? Are licensing conditions being monitored by a person with authority to act?

None of these questions is answered by the technology itself. They require human review of the technology's design, configuration, and output. OFAC's enforcement guidance is explicit that the quality of a business's internal controls – including its technology – is evaluated through the adequacy of its testing and audit, not through the sophistication of the technology in isolation. We have acted for clients who invested substantially in best-in-class screening platforms and still faced enforcement questions because the platform's configuration had not been audited since initial deployment.

The myth is also costly in a practical sense. A business that relies on technology without audit tends to discover its configuration gaps in one of two ways: a regulator finds them first, or a counterparty exposure surfaces at the worst possible time in a transaction lifecycle. Neither is a position a compliance counsel would design into a programme from the outset.

When should a business involve external sanctions counsel?

External counsel adds most value at three specific points in the audit and testing cycle: at programme design or redesign, when a testing exercise surfaces an apparent violation, and when the business is about to enter a new market or product category with materially different sanctions exposure.

At programme design or redesign, external counsel can map the business's actual activity profile against OFAC's five-element standard, identify the specific gaps, and recommend a testing methodology that is proportionate to the risk. A generic audit template drawn from a compliance handbook is not calibrated to the business's specific counterparty geography, product mix, and payment flows. The value of counsel at this stage is in the calibration, not the template.

When a testing exercise surfaces an apparent violation, external counsel's first function is to scope the violation accurately. Not every apparent hit is a true violation. Not every true violation is a reportable one under the applicable regime's reporting rules. And not every reportable violation benefits from a VSD in the same way. The analysis of those questions in the hours and days after a finding is where the difference between a manageable compliance event and a material enforcement matter is often made.

When entering a new market or product category, the risk assessment needs to be updated before the controls are deployed, not after. External counsel can map the applicable prohibitions – list-based, sector-based, transaction-type-based – against the new activity and ensure that the testing programme is adjusted to cover the new exposure before the first transaction goes out.

What does Calder & Vance do in this context? We assess eligibility and prepare the compliance programme documentation; we run the gap analysis against the five-element standard; we scope apparent violations and advise on voluntary self-disclosure; and we design the end-use controls and ownership-mapping methodology specific to the business's structure. Our cross-regime coverage means that where OFSI or EU obligations intersect with the OFAC position – as they do for most multinational businesses – we manage the analysis across all three from a single engagement.

Related practices

Frequently asked questions

Where do the regimes diverge on compliance audit and testing?
OFAC uses a named, published five-element framework with an explicit link to penalty calculations. OFSI uses a compliance maturity model in its enforcement guidance that produces similar outcomes but imposes a positive legal reporting obligation not present in OFAC's voluntary-disclosure architecture. EU member states operate under national transpositions of EU Council regulations and vary in how they define adequate programme standards, with no single pan-EU equivalent to OFAC's five elements. For a business subject to all three, the most demanding element of each regime sets the baseline for that area.
Which regime is stricter on compliance audit and testing?
OFAC's framework is the most explicitly documented at a programme level: the five-element standard, the published guidance linking programme quality to penalty outcomes, and the detailed enforcement framework create the most transparent and measurable compliance obligation. OFSI's mandatory reporting requirement introduces a distinct obligation that OFAC's voluntary framework does not replicate. The EU's position depends on the member state. For a US-nexus business, OFAC's framework is typically the governing standard, but OFSI's reporting obligation is an independent legal requirement that demands separate attention.
What should a cross-border business do about compliance audit and testing?
A cross-border business should first map the regimes to which it is actually subject – US, UK, EU, and any other applicable national regime – and then build a testing programme calibrated to the most demanding standard in each area. The programme should include list-screening validation, ownership and control testing, and transaction-and-documentation review. Results should feed back into the risk assessment and training cycle. Where a testing exercise surfaces an apparent violation, external sanctions counsel should be involved immediately to scope the finding and advise on any disclosure obligation before the reporting window narrows.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.