Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFAC

Sanctions compliance programmes under OFAC: procedure and pitfalls

A multinational's procurement team signs a long-term supply agreement. Weeks later, a compliance officer discovers that the programme has no documented screening policy, no ownership-chain procedure, and no process for handling a positive match. OFAC's enforcement guidance treats the absence of an effective compliance programme as an aggravating factor when calculating civil penalties. That absence can convert a technical violation into a significant monetary penalty – and a pattern of absent controls into a criminal referral.

An effective sanctions compliance programme (a documented, tested, and senior-endorsed set of controls designed to prevent prohibited transactions) under OFAC rests on five elements: management commitment, risk assessment, internal controls, testing and auditing, and training. OFAC has set out this five-element standard in its published compliance guidance, and adherence – or its absence – is a named factor in every civil enforcement outcome. As of July 2026, that standard remains the benchmark against which OFAC assesses a firm's good faith.

This guide walks through each element in sequence, identifies the failure points we see most often in cross-border businesses, and compares the OFAC standard with the parallel requirements under OFSI in the United Kingdom and the EU Council framework, so that firms operating across jurisdictions can build a single programme architecture that satisfies all three.

Step 1: Establish management commitment and a governance structure

Management commitment means that a named senior officer owns the sanctions compliance function and that the board has formally approved the programme. OFAC treats management endorsement as foundational: a programme signed off only at the compliance-team level carries less weight in an enforcement review than one with documented board oversight and a dedicated budget line.

In our cross-border practice, the governance failure we see most often is not outright neglect but diffusion – sanctions responsibility shared across legal, compliance, finance, and operations without a single accountable owner. When a positive screening match surfaces, the result is a handover chain that consumes the statutory response window.

Practical steps at this stage include:

  • Appoint a Chief Sanctions Officer or equivalent with explicit delegated authority from the board.
  • Adopt a board-level sanctions policy statement that names OFAC, and, for internationally active firms, OFSI and the relevant EU regulations, as the governing regimes.
  • Create a reporting line from the compliance function to the audit committee that is independent of the business units generating revenue.
  • Minute board approval annually; OFAC's enforcement guidance treats documented management engagement as a mitigating factor in penalty calculations.

A rhetorical point worth asking early: does your current governance structure ensure that a compliance officer can halt a transaction without commercial pressure overriding the decision? If that authority is not written down and tested, it does not exist in practice.

Step 2: Conduct and document a sanctions risk assessment

A sanctions risk assessment maps the firm's specific exposure – by customer type, product, geography, transaction channel, and counterparty ownership profile – and produces a tiered risk ranking that drives the intensity of controls. OFAC's guidance is explicit that a one-size-fits-all programme is not adequate; the controls must be proportionate to the risk the firm actually runs.

Risk assessment is where many programmes stall. Firms conduct an initial assessment at programme launch and then treat it as a static document. OFAC expects the assessment to be a living record, updated whenever the firm enters a new market, launches a new product, or when a material change in a sanctions regime occurs – for instance, when a programme adds a new designation category or when extraterritorial rules tighten.

The assessment should address at minimum:

  • Customer and counterparty risk: jurisdiction of incorporation, ultimate beneficial ownership, industry sector, and prior screening history.
  • Product and service risk: whether any goods, software, or technology fall within export-control categories that interact with sanctions, including dual-use classifications under the EAR (Export Administration Regulations, administered by BIS).
  • Geographic risk: any nexus to a country subject to a comprehensive or sectoral OFAC programme.
  • Channel risk: correspondent banking chains, payment routing, and any custody or settlement exposure in the financial sector.

We regularly advise firms that conflate a sanctions risk assessment with an AML risk assessment. They overlap but they are not the same exercise. A sanctions risk assessment must include the ownership-chain analysis required by the 50 percent rule (OFAC's rule treating entities owned in the aggregate 50 percent or more by one or more blocked persons as themselves blocked, regardless of whether they appear on a sanctions list). AML risk assessments rarely go that deep into the ownership chain.

The position above covers the standard case. Your facts – the counterparty, the goods, the route, the regime in play – change the analysis. For an assessment of your exposure under OFAC or an allied regime, contact Calder & Vance at info@caldervance.com.

Step 3: Design and implement internal controls

Internal controls are the operational layer of the programme: the screening logic, the transaction monitoring rules, the due-diligence procedures, the escalation protocols, and the documentation requirements that translate policy into daily practice. OFAC evaluates the adequacy of these controls in every enforcement context, and the quality of documentation is frequently decisive.

Screening sits at the centre. A programme that screens only direct counterparties against the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and ignores indirect ownership, transactional intermediaries, or vessel and cargo identifiers is structurally deficient. In our experience, the ownership-chain gap – failing to aggregate holdings across multiple listed persons to test the 50 percent threshold – produces the highest rate of undetected exposure.

Key control elements for a mid-to-large cross-border business:

  • Screening coverage: all customers, counterparties, intermediaries, beneficial owners, vessels, and cargo, not just named parties on the transaction document.
  • List currency: a defined process for ingesting OFAC list updates, which can occur on any business day, and for re-screening existing relationships when updates are published.
  • Match-review protocol: a tiered escalation matrix that distinguishes a false positive from a true hit within a defined window, with legal review mandatory for any unresolved true hit.
  • Payment and transaction blocks: automated blocking or rejection rules in payment systems, with an audit trail that records the reason for each block or release.
  • Blocking and reporting obligations: a clear internal procedure for reporting blocked property to OFAC within the applicable statutory window – the exact deadline is a short regulatory period; verify the current requirement before relying on it.

Cross-border note: firms subject to both OFAC and OFSI controls should be aware that the UK ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person) is broader than OFAC's mechanical 50 percent threshold. Under OFSI and the parallel EU standard, a non-listed entity can be caught where a designated person exercises control by other means, even without a majority ownership stake. That divergence means the OFAC-calibrated screening logic may underperform when the counterparty has a UK or EU nexus. Where regimes diverge, the stricter prohibition governs for any transaction that touches both jurisdictions.

How does testing and auditing validate the programme?

Testing and auditing closes the loop between policy design and operational reality: they are the mechanisms by which management verifies that the controls written in the programme manual are the controls actually operating in the firm. OFAC's guidance treats the absence of a testing function as an independent aggravating factor, separate from the absence of underlying controls.

The distinction between testing and auditing matters. Testing is the ongoing, transaction-level sampling that the compliance function performs itself – pulling a sample of screened transactions, verifying that the screening tool flagged the correct matches, checking that escalation paths were followed, and that false positives were resolved consistently. Auditing is the periodic, independent review, typically conducted by an internal audit team or external advisers, that assesses whether the programme as a whole is fit for purpose.

A programme that is tested but never audited, or audited once at launch and then left, does not satisfy the OFAC standard. We regularly advise clients after an OFAC inquiry has surfaced that their programme was tested against historical transactions but never stress-tested against forward-looking scenarios – new country programmes, a change in beneficial ownership, or a change in the firm's product line.

Testing should, at minimum, cover:

  • Screening-tool accuracy against current OFAC lists, including the SDN List, the Non-SDN Sectoral Sanctions Identifications List, and the Consolidated Sanctions List.
  • Ownership-chain completeness – do the controls apply the 50 percent rule correctly across aggregated holdings?
  • Escalation-path integrity – did flagged items reach the right decision-maker within the required window?
  • Documentation completeness – are records sufficient to demonstrate, to OFAC in an enforcement context, that the firm followed its own procedures?

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. To discuss an urgent compliance matter, contact Calder & Vance at info@caldervance.com.

Step 5: Build and maintain a training programme

Training is the element most often treated as a formality – an annual online module that generates a completion certificate. OFAC's guidance and enforcement outcomes indicate that a training programme is evaluated by its content and targeting, not its completion rate. Generic anti-financial-crime training that mentions sanctions in passing does not satisfy the standard.

Effective training under OFAC's five-element model is role-differentiated. A front-line sales team in an export-heavy business needs different training content than a treasury team managing USD correspondent payments, which in turn differs from the training needed by the logistics team documenting end-use for a dual-use product shipment. The risk assessment drives the content; the content drives the delivery format and frequency.

Minimum requirements for a defensible training programme:

  • Annual role-specific training, with additional training triggered by material changes to the sanctions environment or the firm's business activity.
  • Documented delivery, completion records, and assessment results retained for the applicable record-keeping period.
  • Board-level briefings at least annually, covering enforcement trends and any change in the firm's risk profile.
  • New-joiner training before the employee has access to systems or processes that touch sanctioned-entity or controlled-goods workflows.

A practical note on cross-border training: firms operating across OFAC, OFSI, and EU regimes benefit from a unified training architecture that identifies, per role, which regime is primary and which is supplementary. A payment-operations employee at a bank with a US dollar book and a UK entity is exposed to OFAC through USD clearing and to OFSI through the entity's own UK legal obligations. Training that addresses only one regime creates a coverage gap that an enforcement review will find.

Common risk flags and when to involve counsel

Most programme failures share a recognisable pattern: a control that exists on paper but has not been tested, a screening tool that has not been updated to reflect a change in the OFAC lists, or a governance gap that becomes visible only when a positive match arrives without a clear escalation path. The risk flags below are the ones we see most frequently in cross-border businesses seeking a programme review.

Structural risk flags:

  • No documented ownership-chain procedure that applies the 50 percent rule to aggregated holdings across multiple blocked persons.
  • Screening limited to direct counterparties, excluding intermediaries, correspondent banks, freight forwarders, or vessel operators.
  • No defined escalation timeline for an unresolved positive match – this omission alone can create a reporting violation if a blocking deadline is missed.
  • A programme last updated before a significant expansion of the relevant OFAC programme – particularly where the firm has since entered a new geographic market.
  • No documented process for handling a voluntary self-disclosure – VSD (a proactive report to OFAC of an apparent violation before the agency has commenced an inquiry) – including who authorises it, what it must contain, and the window within which it must be filed.

There is a persistent myth in the market that a small compliance team or a small annual revenue base reduces OFAC exposure to negligible levels. It does not. OFAC's jurisdiction is transaction-based, not entity-size-based: a single USD-denominated wire that clears through a US correspondent bank brings a foreign firm within OFAC's reach, regardless of the firm's headcount or turnover. We have acted for businesses of all sizes facing OFAC inquiries that originated from a single payment routing decision.

Involve counsel when:

  • A screening match cannot be resolved as a confirmed false positive within the firm's normal process.
  • The firm has identified a transaction that may have involved a blocked person, a sanctioned territory, or a controlled export without the required licence.
  • OFAC, BIS, or a correspondent bank has issued a subpoena, an administrative summons, a request for information, or an informal inquiry.
  • A programme audit has identified a systemic control failure rather than an isolated incident.
  • The firm is entering a new market, completing an acquisition, or restructuring in a way that changes its sanctions risk profile materially.

In a recent matter, a mid-market financial services firm discovered during an internal audit that its screening tool had been operating against a list version that had not been updated for a significant period. The gap had resulted in a number of transactions that required review for potential OFAC exposure. We scoped the apparent violations, advised on voluntary self-disclosure, and assisted in preparing the disclosure package and the remediation plan. The matter was resolved without a formal enforcement proceeding. We cite this to illustrate the kind of work involved, not to suggest any particular outcome in your circumstances.

Related practices

Frequently asked questions

What are the steps to design a sanctions compliance programme under OFAC?
OFAC's five-element framework requires, in sequence: documented management commitment with board endorsement; a risk assessment proportionate to the firm's specific customer, product, and geographic exposure; internal controls covering screening, escalation, blocking, and record-keeping; periodic testing and independent auditing; and role-differentiated training. Each element must be documented, tested, and updated when the firm's business or the sanctions environment changes. The five elements are cumulative: a strong training programme does not compensate for absent internal controls.
What is the most common mistake in sanctions compliance programmes?
The most common structural failure is screening that covers only direct counterparties against the SDN List while omitting the ownership-chain analysis required by the 50 percent rule. A non-listed entity that is majority-owned in the aggregate by one or more blocked persons is itself blocked under OFAC, regardless of whether it appears on any list. Tools that flag only name matches, without aggregating ownership across the full beneficial-ownership chain, systematically miss this exposure. A second common failure is treating the programme as static – built once and never updated.
How does OFAC differ from other regimes here?
OFAC's ownership test is mechanical: the 50 percent threshold triggers blocked status without reference to control or management. OFSI in the UK and the EU Council framework both apply an additional control test, which means a non-listed entity can be caught even where listed persons hold below 50 percent, if they exercise control by other means. For a firm subject to multiple regimes, the stricter prohibition governs any transaction that has a nexus to that regime. OFAC also operates an extensive secondary-sanctions architecture that can reach non-US persons through USD transactions and US market access, a feature with no direct OFSI or EU parallel.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.