Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFAC

Compliance audit and testing under OFAC: step by step

A multinational's compliance team completes its annual sanctions review. Screening is live, policies are documented, and training records are in order. Six months later, OFAC opens a voluntary self-disclosure inquiry. The gap was not in the written programme – it was in the testing. Nobody had verified that the screening tool was actually catching what it was supposed to catch.

A compliance audit and testing programme under OFAC is the structured, periodic process by which a business verifies that its sanctions controls work in practice, not just on paper. OFAC's own guidance identifies a well-designed compliance programme as a central factor in penalty mitigation – and "well-designed" means tested. As of mid-2026, OFAC continues to treat the absence of periodic testing as an aggravating factor in enforcement assessments.

This guide walks through the audit and testing process step by step: what OFAC expects, how the process differs from the UK OFSI and EU approaches, and where businesses most often fall short.

Step 1: Understand what OFAC expects from a compliance programme

OFAC's compliance guidance sets out five essential elements of an effective sanctions compliance programme: management commitment, risk assessment, internal controls, testing and auditing, and training. Testing and auditing is one of the five – not a supplement to them. A programme that has four of the five elements in place but has never been independently tested remains incomplete in OFAC's assessment.

The practical significance of that position is direct. When OFAC assesses a penalty for an apparent violation, it weighs the existence and quality of the compliance programme at the time of the breach. A programme with documented, periodic testing is treated more favourably than one relying on self-reported adequacy. In our experience advising businesses across sectors, the single most common gap is not absent policies but absent evidence that those policies were ever put to a live test.

The governing instruments are set by OFAC under the authority of IEEPA and TWEA. The specific standards for programme quality are published in OFAC's guidance documents, which are updated periodically. Verify the current position before designing a testing cycle.

Step 2: Conduct a structured risk assessment before auditing

A risk assessment is the foundation of any meaningful audit: without it, the audit tests the wrong things. Under OFAC, the risk assessment maps each business unit's exposure across products, services, customers, geographies, and transaction types – and the results determine the depth of testing each area receives.

Risk factors that routinely increase OFAC exposure include: correspondent banking relationships that transit multiple jurisdictions; trade-finance transactions involving goods with dual-use potential; payment processing that passes through third-country clearing systems; and corporate ownership structures where a counterparty sits one or two steps removed from a listed entity. Each of these warrants a specific testing protocol rather than a generic annual screen.

The risk-weighting step is also where cross-border complexity enters the picture. A business operating under both OFAC and the EU Council regulations faces overlapping ownership-and-control tests. OFAC applies the mechanical 50 percent rule (the rule treating any entity owned 50 percent or more in the aggregate by blocked persons as itself blocked). The EU and OFSI (the UK's Office of Financial Sanctions Implementation) apply an additional control test that can catch entities where ownership sits below that line. A risk assessment that ignores the interaction between those tests leaves a cross-border business exposed on the UK and EU side even if the OFAC screen is clean.

Is your risk assessment genuinely transaction-level, or does it describe risks at the entity level and stop there? That distinction shapes every subsequent testing decision.

Step 3: Design the testing methodology

OFAC's guidance distinguishes between two types of review: audits (independent assessments of the overall programme) and testing (targeted checks on specific controls). A well-designed methodology uses both in sequence: transaction-level testing throughout the year, and a broader programme audit on a periodic basis.

Transaction testing should cover a statistically meaningful sample of completed transactions across each risk tier. The sample must include transactions that were cleared as well as any that were flagged and released. Cleared transactions are where silent failures hide – a control that flags nothing is not necessarily working; it may simply be mis-calibrated.

Screening-tool testing is a separate discipline. It requires running a test file of known-listed names, aliases, and transliterations through the live production system to verify that the tool's fuzzy-matching logic catches them. A tool that misses an alias used by a listed person is defective regardless of how often it is run. In our practice, we see this test omitted in roughly half the initial compliance reviews we conduct.

The methodology should also include a VSD (voluntary self-disclosure) readiness check: does the business have a documented process for identifying an apparent violation, conducting an internal investigation, and making an accurate disclosure to OFAC within the applicable window? The window is not open-ended. Verify the current disclosure deadlines with qualified sanctions counsel before relying on any figure.

Testing under OFSI in the UK follows a broadly similar logic but requires additional attention to the ownership-and-control test and to OFSI's own enforcement guidance, which scores programme quality against a distinct set of criteria. The practical takeaway for any cross-border business is that a test file and a sampling protocol designed for OFAC alone will not satisfy both regulators simultaneously.

Step 4: Execute the audit and document findings

The audit execution phase converts the methodology into a workable sequence: gather evidence, test controls, identify gaps, and record findings with enough precision to drive remediation. Documentation is not optional – it is the mechanism by which the audit's existence is provable to OFAC if a violation later comes to light.

A structured audit typically covers: screening logic and configuration; the completeness and currency of list sources in use; the escalation and alert-review process; the ownership-chain verification procedure for counterparties above defined risk thresholds; the record-keeping practice; and the training completion records. Each area should produce a written finding that states what was tested, what the test revealed, and what action, if any, is required.

Record-keeping is a control in its own right. OFAC requires businesses to maintain records of transactions involving blocked or rejected property. Under OFAC's rules, a five-year record-keeping period applies. That figure is drawn from OFAC's published requirements; confirm the current standard before designing your retention policy. Records must be available for OFAC inspection on request.

In a recent matter, a financial-services business retained us to conduct an independent audit after its internal team had flagged unusual clearing patterns on a correspondent account. The audit identified that the screening tool had been misconfigured following a software update nine months earlier, with the result that a known alias was no longer being checked. We advised on the steps required to scope the apparent exposure, prepare the internal investigation, and assess whether a voluntary self-disclosure was appropriate. The matter was resolved without a referral to enforcement. That outcome is never guaranteed, but early action consistently preserves more options than late action.

Step 5: Remediate and re-test

An audit that ends with a findings report but no remediation cycle is incomplete. OFAC's own guidance treats the failure to act on audit findings as evidence of programme weakness – which can convert a minor aggravating factor into a significant one in a penalty assessment.

Remediation priorities should be tiered. Critical gaps (a mis-configured screening tool, an absent escalation process, a gap in list coverage) require immediate action. Operational improvements (enhanced training, clearer procedure documentation, expanded risk-tiering) can follow a defined schedule. Each remediation action should be assigned to an owner, tracked against a deadline, and re-tested once complete.

Re-testing is the step that closes the loop. It is not enough to implement a fix; the fix must be shown to work. A re-test of the specific control that failed, conducted within a reasonable period after remediation, is the documented proof that the programme has been strengthened. That proof is what matters to OFAC if a subsequent apparent violation occurs in the same area.

Cross-border businesses should run the re-test against all applicable regimes. A control that now satisfies OFAC's requirements should also be checked against the EU and OFSI standards if those regimes are in scope. A control gap that exists only on the UK or EU side will not be visible in an OFAC-only re-test.

Step 6: Train staff and refresh the cycle

Training is the fifth of OFAC's five programme elements – and the one most frequently treated as a tick-box exercise. Effective training is targeted, role-specific, and tested. A compliance officer who understands the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) in detail needs different training from a customer-relationship manager who runs initial onboarding checks. One-size training fails both audiences.

Training records must be maintained and must be verifiable. OFAC can request evidence of training as part of an enforcement inquiry. If the only record is a sign-in sheet from a group session three years ago, that will not demonstrate a functioning training programme.

The audit cycle itself should be refreshed at a frequency that reflects the risk profile of the business. A payment firm processing high volumes across multiple jurisdictions requires more frequent testing than a manufacturer with a small, stable customer base. The cycle should also be triggered by external events: a major designation in a relevant programme, a change in regulatory guidance, a software update to the screening tool, or a significant change in the business's product or geography mix. Waiting for the calendar to dictate the audit schedule is not a risk-based approach.

We regularly advise businesses on calibrating the audit cycle to the risk profile rather than to a fixed annual schedule. In our experience, the annual default is too infrequent for high-volume payment firms and unnecessarily burdensome for businesses with genuinely low sanctions exposure.

When do you need external sanctions counsel?

Independent external review adds weight to an audit that an entirely internal process cannot. OFAC treats independent audits more favourably than self-assessed ones when weighing penalty factors. "Independent" in this context means conducted by a function or party without a direct stake in the findings – which, in practice, means either an internal audit team that sits outside the compliance function, or external counsel.

External counsel is specifically valuable in four situations. First, when the business has received an OFAC administrative subpoena, information request, or informal inquiry – at that point, the audit and its findings are potentially disclosable and must be handled with legal-privilege considerations in mind. Second, when an internal test or transaction review has surfaced a possible apparent violation and the business is assessing whether to make a VSD. Third, when a merger, acquisition, or joint venture requires a confirmatory audit of the target's sanctions posture. Fourth, when the business is entering a new geography or product line with materially different sanctions risk.

A common myth is that a clean internal audit eliminates the need for external review. It does not. An internal audit is conducted by people who designed the programme, operate within it daily, and have an institutional interest in its adequacy. External counsel brings no such interest – and brings knowledge of what OFAC's examination teams actually focus on, drawn from cross-client experience across the regime.

The position above covers the standard programme-review scenario. Your specific facts – the regimes in play, the transaction type, the counterparty, and whether a potential violation has already been identified – change the analysis materially.

For an initial assessment of your OFAC compliance programme or testing cycle, contact Calder & Vance at info@caldervance.com.

Related practices

Frequently asked questions

What are the steps to audit and test a compliance programme under OFAC?
The process runs in six phases: (1) establish what OFAC's five-element framework requires, (2) conduct a risk assessment across products, geographies, and counterparties, (3) design a testing methodology that covers transaction sampling and screening-tool validation, (4) execute the audit and document findings with enough precision to support remediation, (5) remediate gaps and re-test the specific controls that failed, and (6) refresh training and calibrate the cycle to the current risk profile. Each phase should produce written evidence that OFAC could review in an enforcement inquiry.
What is the most common mistake in compliance audit and testing?
Treating screening configuration as a one-time setup rather than a live control that requires periodic validation. In our practice, the most frequent gap we identify is a screening tool that has never been tested with a file of known-listed names, aliases, and transliterations run against the live production system. A tool can be technically operational and still miss matches if its fuzzy-matching parameters were set incorrectly or if the configuration changed following a software update. The absence of that test is itself an aggravating factor in OFAC's penalty assessment.
How does OFAC differ from other regimes here?
OFAC's ownership test is mechanical: the 50 percent rule applies regardless of control or intent. OFSI and the EU layer a control test on top, meaning an entity below the ownership threshold can still be caught. OFAC's five-element compliance framework is also more explicitly codified in published guidance than the equivalent OFSI or EU standards, which creates a clearer audit target but also a clearer set of criteria against which programme adequacy is measured. Cross-border businesses must design test methodologies that satisfy all applicable regimes, not just the primary one.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.