A multinational treasury team completes a routine counterparty screen before wiring funds. The tool returns a partial name-match. The compliance officer escalates. Two hours later, senior counsel is asking a question nobody had prepared for: does the company actually have a written sanctions compliance programme that an OFAC examiner would recognise? For many cross-border businesses, the honest answer is no – or not quite.
Sanctions compliance programmes under OFAC are structured internal control systems designed to prevent, detect, and respond to violations of US economic sanctions administered by the Office of Foreign Assets Control. OFAC has published a five-component framework – management commitment, risk assessment, internal controls, testing and auditing, and training – that it applies when evaluating both voluntary self-disclosures and whether to mitigate a penalty. A documented, proportionate programme is the single most important factor in determining how OFAC responds to an apparent violation.
This guide walks through each component of the OFAC framework, explains where the US approach diverges from the UK and EU equivalents, identifies the risk flags that indicate a programme needs rebuilding, and sets out when to bring in external sanctions counsel.
Step 1: Establish management commitment and governance
The foundation of any effective sanctions compliance programme is visible, documented commitment from senior management – not a policy signed and filed, but active governance. OFAC's framework places management commitment first because, in its enforcement analysis, a programme that exists on paper but lacks board-level ownership is treated as a significant mitigating weakness rather than a mitigating strength.
Practical governance means three things. First, a named individual – typically a Chief Compliance Officer or equivalent – must hold documented authority and accountability for sanctions compliance. Second, the board or audit committee must receive periodic reporting on sanctions risk, including screening results, escalation outcomes, and any apparent violations identified. Third, resource allocation decisions must be traceable: if a compliance team requests additional screening tools and the request is refused without documented reasoning, that gap becomes an enforcement liability.
In our experience, the most common governance failure is not an absence of commitment but a diffusion of it. Sanctions risk is parcelled between legal, treasury, and trade operations without a single owner. When an apparent violation surfaces, each team believes another team has primary responsibility. OFAC examiners see that diffusion clearly in the document record.
How does this compare with other regimes? Under OFSI's approach in the United Kingdom, the equivalent emphasis falls on "appropriate systems and controls" – language drawn from the financial services regulatory tradition. The EU Council regime does not mandate a specific five-element structure but expects documented controls proportionate to a firm's exposure. Across all three regimes, the common thread is that undocumented governance does not count.
Step 2: Conduct and document a sanctions risk assessment
A risk assessment is the diagnostic engine of the programme – it tells a business which parts of its operations carry material sanctions exposure and at what level. Without a current, documented risk assessment, every other control is calibrated to an unknown threat profile.
OFAC expects the risk assessment to cover, at minimum: customers and counterparties; geographies (countries, territories, and sub-national regions relevant to a designated person's operations); products and services; and transaction channels. For a trading business, this means mapping the full supply chain – not only the end-buyer but the freight forwarder, the correspondent bank, and the jurisdiction through which payment flows. For a financial institution, it means understanding which correspondent banking corridors carry elevated exposure to designated jurisdictions or to secondary-sanctions risk.
Secondary-sanctions risk deserves particular attention here. OFAC's secondary-sanctions authorities – derived from statutes including IEEPA – operate extraterritorially and can affect non-US persons who engage in significant transactions with designated parties even where no US-person nexus exists. A risk assessment that maps only primary US-person obligations and ignores secondary exposure is, in practice, incomplete. We regularly advise non-US clients who discover this gap only after a transaction has been flagged.
The risk assessment should be updated at defined intervals and when a material change occurs – a new product line, a new market, a corporate acquisition, or a significant change to OFAC's designation lists. Treat it as a living document, not a one-time deliverable. A risk assessment that is two years old and predates a major OFAC designation cycle is not a mitigating asset.
Step 3: Design internal controls proportionate to the risk
Internal controls are the operational layer of the programme: the screening systems, transactional approval workflows, escalation protocols, and record-keeping requirements that convert policy into daily practice. OFAC evaluates the quality of internal controls by asking whether they are proportionate to the risk identified in the assessment and whether they are actually followed.
Screening is the most visible control. The key design questions are: which lists are screened (the SDN List – OFAC's list of Specially Designated Nationals and blocked persons – the Non-SDN Consolidated Sanctions List, BIS's Entity List, and equivalent lists for other regimes); at what point in the transaction lifecycle; and with what fuzzy-matching threshold. A firm that screens only on exact name matches will miss transliterated names, name variants, and aliases. A firm that screens too broadly creates alert fatigue that causes genuine matches to be dismissed.
The 50 percent rule – OFAC's rule treating any entity owned 50 percent or more in the aggregate by blocked persons as itself blocked – requires controls that go beyond direct-name screening. Ownership-chain analysis must extend to beneficial ownership. Aggregation matters: two listed persons each holding a minority stake can together reach the threshold. Screening tools that resolve only one layer of the corporate tree will not catch this pattern.
Escalation protocols must define, in writing, who receives an alert, what information they must gather, by when they must make a determination, and who has authority to approve a release, block funds, or reject a transaction. Ambiguity in the escalation chain is itself a control failure. Record-keeping requirements under the applicable US sanctions regulations require that certain transaction records be retained; verify the current retention period that applies to your business type before setting your policy.
The position above covers the standard case. Your facts – the counterparty structure, the goods or services, the payment corridor, the mix of regimes in play – change the analysis materially. For a review of your internal controls against the OFAC framework, contact Calder & Vance at info@caldervance.com.
Step 4: Build a testing and auditing function
Testing and auditing is the control on the controls. A programme that has never been tested against real transaction data, against adversarial name variants, or against an updated designation list is a programme whose effectiveness is unknown – and unknown effectiveness is not a mitigating factor in OFAC enforcement.
OFAC distinguishes between ongoing testing (periodic internal reviews of screening logic, alert dispositions, and escalation records) and independent auditing (a structured review conducted by a team or external adviser with no operational stake in the results). Both are expected. The frequency and depth of each should be calibrated to the risk assessment: a business with high sanctions exposure in its correspondent-banking book needs more frequent and more rigorous testing than a domestic retailer with incidental cross-border activity.
What does testing in practice look like? At minimum: run a sample of historical transaction data against the current list configuration to identify any records that would be flagged today but were not flagged at the time; review a sample of closed alerts to assess whether dispositions were documented and reasonable; test the screening system against known name variants of designated persons; and review the escalation log to confirm that alerts were resolved within the timeframes set by the internal protocol.
Audit findings must feed back into the programme. An audit that identifies a gap and then sees no corrective action is evidence of systemic compliance failure. OFAC's enforcement guidance treats the failure to remediate known weaknesses as an aggravating factor. Document the finding, the corrective action taken, the person responsible, and the deadline. Then re-test.
For UK-headquartered groups subject to OFSI in parallel, note that OFSI's enforcement guidance – which carries its own assessment of aggravating and mitigating factors – similarly values documented testing and prompt remediation. The parallel regime does not create a lighter standard; in our practice we treat the higher of the two standards as the design floor for any cross-border programme.
Step 5: Deliver targeted, documented training
Training is the element most often treated as a box-ticking exercise – annual e-learning completed, certificates filed, obligation discharged. OFAC does not evaluate training by volume of certificates. It evaluates whether the people who make sanctions-relevant decisions understand the rules that apply to their decisions.
Targeted training means segmenting the audience. The front-line account manager who onboards new counterparties needs to understand screening alerts and escalation triggers. The treasury officer processing correspondent payments needs to understand secondary-sanctions risk and payment-chain exposure. The board needs to understand governance obligations and reporting duties. A single generic module does not serve any of these audiences well.
Documentation matters independently of content. Training records should capture who was trained, on what material, on what date, and – for the higher-risk roles – should include some form of competency assessment. Where a training need is identified and not addressed, that gap should be recorded with a remediation plan. An OFAC examiner reviewing a firm's programme will ask for training records; the absence of records is treated as absence of training.
Role-based refresh cycles are appropriate. Sanctions list designations change frequently – sometimes with short notice and significant scope. Staff in high-risk roles should be briefed when a major OFAC action occurs that is relevant to their business line. Waiting for the annual cycle to communicate a material change is a control gap.
Cross-regime comparison: where OFAC, OFSI, and the EU diverge
A business subject to more than one sanctions regime – which describes most multinationals and all internationally active banks – cannot design to the lowest common denominator. The regimes share the five-element logic but diverge on specifics that matter operationally.
The ownership and control test is the sharpest divergence. OFAC's 50 percent ownership threshold is mechanical: aggregate the blocked persons' ownership stakes; if the result is at or above 50 percent, the entity is blocked regardless of who manages it. OFSI and the EU apply an ownership and control test – the UK and EU test for whether a non-listed entity is caught through a listed person – that looks beyond bare ownership to actual or potential control. A listed person holding 45 percent of a company and also holding veto rights over disposals may well bring the entity within the UK and EU prohibitions even without reaching the US threshold. For any dual-regime analysis, this divergence must be mapped explicitly.
Voluntary self-disclosure – a VSD (disclosure of an apparent violation to a regulator before it is discovered independently) – exists in different forms across the regimes. Under OFAC, a timely, complete, and accurate VSD is treated as a significant mitigating factor and can result in a substantially reduced penalty base. OFSI operates a comparable voluntary disclosure regime under SAMLA and its enforcement guidance, though the mechanics differ. The EU regime currently lacks a harmonised VSD standard across member states. Where a single transaction implicates OFAC and OFSI, the timing and content of any VSD must be coordinated: a disclosure made in one jurisdiction can affect the evidential position in the other.
Record-keeping periods differ. Verify the specific retention requirement for each regime and set your policy to the longest of the applicable periods. A record destroyed in compliance with one regime's timeline may be non-compliant under another.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Write to us at info@caldervance.com for a confidential assessment.
Risk flags that indicate a programme needs rebuilding
Most sanctions compliance failures do not arise from a calculated decision to ignore the rules. They arise from programmes that were adequate at the time of design but have not kept pace with the business, the regime, or the designation environment. The following risk flags indicate that a programme requires more than a refresh.
The risk assessment has not been updated in more than twelve months and the business has entered new markets, acquired a counterparty base, or launched a new product line in that period. An assessment calibrated to last year's business and last year's list is a known gap.
Screening generates a high volume of false positives that are routinely closed without documented review. Alert fatigue is among the most common pathways to a genuine match being dismissed as noise. If the disposition rate for alerts is very high and disposition records are thin, the screening function is operating as theatre rather than as a control.
The escalation protocol has never been tested against a real adverse finding. Some businesses discover, only when a genuine SDN match surfaces, that their escalation chain is unclear, that the person designated to make the blocking decision is unavailable, or that the record-keeping system cannot capture the required information. A tabletop exercise costs far less than discovering these gaps during an OFAC review.
Training records do not exist for staff in high-risk roles, or those roles have turned over significantly since the last training cycle. Turnover in compliance-relevant functions without re-training is a straightforward control gap.
The programme has never been reviewed by an external adviser with OFAC expertise. An internal team that designs, operates, and audits the same programme cannot provide the independent view that OFAC's own guidance anticipates. This is not a criticism of internal teams; it is a structural limitation of any wholly internal assurance function.
Related practices
- Sanctions compliance audit and testing (Australia) – independent testing of controls against Australian autonomous sanctions obligations
- Sanctions compliance programme design under OFSI – step-by-step guide to the UK five-element framework and OFSI's enforcement expectations
- Sanctions compliance programme design under OFSI (part 2) – advanced OFSI topics including licensing, VSD, and cross-regime coordination