A multinational technology distributor operating across the Americas, Europe, and Asia-Pacific asks a question that arrives in our inbox regularly: "We have a screening tool – does that mean we have a sanctions compliance programme?" The short answer is no. A screening tool is one control. A programme is the architecture that surrounds it: governance, risk assessment, testing, training, and a credible response to the unexpected.
An effective sanctions compliance programme (a structured system of policies, controls, and governance mechanisms designed to identify and prevent violations) under OFAC rests on five elements set out in OFAC's published framework: management commitment, risk assessment, internal controls, testing and auditing, and training. As of July 2026, OFAC continues to treat the presence – or absence – of a documented, functioning programme as a primary factor in calculating whether a penalty should be imposed and at what level. A weak or absent programme converts what might be a technical breach into an egregious violation.
This guide walks through the design of an OFAC sanctions compliance programme step by step. It also maps where OFSI, the EU, and other regimes diverge, and it identifies the risk flags that most commonly bring a programme into enforcement scrutiny.
Step 1: Establish the governance foundation and management commitment
Management commitment is listed first in OFAC's framework because a programme without board-level ownership is structurally unreliable. OFAC's own guidance states explicitly that senior management – up to and including the board – should be visibly engaged with the programme, review its outputs, and take responsibility for resource allocation. That is not a soft principle. In enforcement decisions, OFAC has cited the absence of senior oversight as an aggravating factor.
What does this mean operationally? The programme needs a designated compliance officer with direct access to senior management and, ideally, a reporting line that does not pass through the business units the programme is meant to control. It needs a written sanctions compliance policy that has been approved at board or equivalent level. And it needs a governance record – minutes, sign-offs, escalation logs – that demonstrates the system is alive, not merely documented.
The governance question matters differently across regimes. Under OFSI's enforcement guidance, senior management failure can ground a personal liability finding against individual officers, not merely the entity. The EU's approach embeds similar expectations for financial institutions through the broader anti-money-laundering regulatory architecture. For a cross-border business, the governance structure should be designed so that the same evidence of management commitment satisfies OFAC, OFSI, and the EU simultaneously – because in a multi-regime enforcement scenario, you will need to show all three.
In our experience, the single most common gap at this stage is a compliance function that exists on paper but lacks the staffing, budget, and authority to act on its findings. Governance that cannot stop a transaction is not governance.
Step 2: Conduct and document a risk assessment
Risk assessment is the analytical engine of any sanctions compliance programme. Without it, the controls that follow are guesswork. OFAC expects a programme to be calibrated to actual exposure – the nature of the business, the counterparties it engages, the jurisdictions it operates in, and the products and services it handles.
The risk assessment should cover at minimum: customer and counterparty profile (where are they located, who owns them, what do they do?); transaction type (payments, trade finance, technology transfers, services?); geographic reach (does the business have any nexus to a regime of heightened risk?); product and service scope (are the goods, technology, or services subject to export-control intersections or sectoral restrictions?); and channel exposure (are there correspondent banking relationships, intermediaries, or freight forwarders that extend the risk chain?). Each dimension should be scored, and the aggregate score should drive the intensity of the controls in Step 3.
A risk assessment that does not consider the 50 percent rule (OFAC's rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked) in the ownership-chain analysis is immediately incomplete. The rule applies regardless of whether the entity itself is listed. For a business with complex counterparty structures – private equity-backed buyers, joint ventures, multi-layer holding companies – this is not a peripheral question.
The cross-border dimension is acute here. OFSI's ownership and control test (the UK and EU rule that catches non-listed entities acting at the direction or under the control of a listed person) is broader than OFAC's mechanical threshold. A risk assessment designed only around OFAC's 50 percent rule will miss the control-based risk that OFSI and the EU would catch. We regularly advise businesses to run a combined ownership-and-control pass during risk assessment, covering OFAC, OFSI, and the EU in a single analytical layer.
Document everything. The risk assessment is not a static exercise. It should be refreshed when the business changes and, as a baseline, at regular intervals – the frequency calibrated to the risk profile. A programme that cannot show a dated, signed risk assessment is a programme that OFAC will treat as absent.
Step 3: Design and implement internal controls
Internal controls translate the risk assessment into operational reality. They are the specific policies, procedures, and system configurations that prevent and detect violations before they become enforcement matters. For most businesses, the controls layer has three components: transaction screening, ownership and control checks, and escalation and blocking procedures.
Transaction screening is where programmes are tested most often. The screening logic should cover the SDN List (OFAC's list of Specially Designated Nationals and blocked persons), the Sectoral Sanctions Identifications List, the Consolidated Sanctions List, the Entity List published by BIS, the OFSI Consolidated List, the EU Consolidated List, and any other lists relevant to the business's operational footprint. The tool must be configured to generate hits at a threshold that balances completeness against false-positive overload – and that calibration is not a one-time decision. It requires ongoing tuning.
Ownership and control checks go beyond the screening tool. A screened entity that generates no hit can still be a blocked counterparty if its ultimate beneficial owner or a controlling person is listed. The control for this is a beneficial-ownership verification process – proportionate to the risk level established in the assessment – that maps the ownership chain to the ultimate natural persons and checks each layer against the relevant lists.
Escalation and blocking procedures define what happens when a hit is generated. Who receives the alert? What is the decision timeline? Who has authority to clear or block? How is blocked property recorded and reported to OFAC? A procedure that stops at the alert and does not close the loop with a documented decision and, where required, a report is a control gap.
The position above covers the standard architecture. Your business's specific counterparty base, the goods and services you handle, and the regimes in play will each change the analysis. For a review of your current controls against the OFAC framework, contact Calder & Vance at info@caldervance.com.
How does OFAC's five-element standard compare to OFSI and the EU?
OFAC's five-element framework is the most extensively published of the major regimes, but it is not uniquely demanding – and the differences between regimes matter for a business that must satisfy more than one simultaneously.
OFSI has published its own compliance guidance, which maps broadly to OFAC's model: policy, risk assessment, due diligence, monitoring, and training. The emphasis on senior management personal liability is more explicit in the UK regime. OFSI's enforcement guidance confirms that individual officers can be held accountable where they consented to or connived at a violation. A cross-border programme must therefore ensure that the governance structure and escalation procedures satisfy both OFAC's institutional-level expectations and OFSI's personal-liability risk.
The EU approach does not have a single equivalent to OFAC's five-element document. Requirements flow from the relevant Council regulations and, for financial institutions, from the intersection with anti-money-laundering obligations. The practical effect is that EU obligations are often policed indirectly – through national competent authorities, financial regulators, and the intersection with broader financial-crime controls. A programme that treats the EU as merely an additional list to screen, rather than a separate regulatory regime with its own escalation and reporting architecture, is under-designed.
One divergence deserves particular attention: reporting of blocked property. OFAC requires a report to be filed within a defined short statutory window following the blocking of property. OFSI also has a mandatory reporting obligation, with its own timeline. The EU reporting requirements depend on the specific regulation and national transposing instrument. Where a business holds assets that are blocked or frozen across multiple regimes simultaneously – which happens in multi-regime enforcement scenarios – the reporting obligations run in parallel and on separate clocks. Failing to report in one regime while complying with another creates a violation even where the underlying transaction was handled correctly.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. For urgent matters, contact us at info@caldervance.com.
Step 4: Testing, auditing, and continuous monitoring
Testing and auditing are the mechanisms that establish whether the programme works in practice, as distinct from what the policy document says. OFAC's framework distinguishes between testing (internal operational checks run by the compliance function) and auditing (independent reviews, whether conducted by a separate internal audit team or external advisers). Both are expected. Neither substitutes for the other.
What should testing cover? At minimum: whether screening is running correctly and generating the expected results; whether ownership checks are being completed and documented; whether escalations are being processed in line with the procedure; whether blocked-property reporting is timely; and whether the training records are complete. Testing should be risk-based – meaning higher-risk transaction types and counterparty categories receive more intensive scrutiny.
Auditing provides the independent layer. An internal audit function that reports to the same business line it is reviewing is not independent. OFAC's framework and the broader market standard expect independence to be structural, not just claimed. In our practice, we conduct testing and audit exercises for clients where the internal audit function lacks sanctions-specific expertise. The combination of technical sanctions knowledge and audit methodology is what makes the exercise meaningful.
Continuous monitoring is the third element. Sanctions lists change without warning. A counterparty that was clean when onboarded may be listed six months later. A parent company may be designated after a subsidiary has been active in a supply chain for years. The control for this is a periodic re-screening programme – not just a screen at onboarding – calibrated to the update cadence of the relevant lists and the risk level of the counterparty. At a minimum, re-screening should run whenever a major list update is published and at regular intervals between updates.
Step 5: Training and embedding a compliance culture
Training is the final element in OFAC's framework, and it is the one most frequently treated as a box-ticking exercise. Annual e-learning completion rates are not a training programme. A training programme calibrated to the actual job functions of the people receiving it, delivered at a depth that changes how they handle borderline decisions, is what OFAC is looking for.
The training architecture should distinguish between general awareness training (appropriate for all staff) and role-specific deep-training (for compliance officers, trade-finance specialists, relationship managers, and anyone else with direct exposure to sanctions risk in their work). General awareness training covers what sanctions are and what to do if a concern arises. Role-specific training covers the specific controls, decision trees, and escalation paths relevant to that person's job.
Records matter. OFAC expects a business to be able to demonstrate who was trained, when, on what subject, and whether they completed an assessment. Training records should be retained for at least the same period as other compliance documentation. The record-keeping standard under the EAR for export-control documents is five years – a useful benchmark even for sanctions-only programmes, though the exact requirements vary by regime and instrument.
The cultural dimension of training is harder to document but equally real. A compliance culture is one where business staff bring borderline questions to the compliance function rather than resolving them alone. Building that culture requires more than annual e-learning. It requires visible management commitment (Step 1), a compliance function that responds usefully to queries without creating procedural roadblocks, and a track record of acting on what the testing finds.
Common risk flags and when to involve counsel
Even a well-designed programme can develop gaps under operational pressure. The risk flags that most frequently surface in enforcement reviews fall into a predictable pattern.
Ownership-chain gaps are the single most common structural weakness. A programme that screens the named counterparty but does not map the beneficial ownership chain to the ultimate level leaves OFAC's 50 percent rule unenforced. In cross-border M&A, joint-venture, and trade-finance contexts, the ownership chain is often the entire risk.
A second risk flag is over-reliance on a single screening tool or list. Businesses sometimes configure their screening to cover one list – often the SDN – and not others. The Entity List (BIS), the OFSI Consolidated List, the EU Consolidated List, and regime-specific sectoral lists each carry obligations that a single-list screen will miss. Where a business has operations in multiple jurisdictions, the screening architecture must be multi-list and multi-regime.
A third flag is the absence of a voluntary self-disclosure (VSD – a proactive report to a regulator disclosing an apparent violation) protocol. When a compliance review surfaces a potential violation – a payment that cleared a blocked counterparty, a shipment to a restricted destination – the business faces a time-sensitive decision: disclose proactively or wait. A programme that has no pre-built VSD procedure will resolve that decision inconsistently and often incorrectly. VSD can significantly affect the enforcement outcome, but the decision requires legal advice on the specific facts before a report is made.
The myth that only large businesses attract OFAC enforcement attention is incorrect. OFAC's published enforcement actions include businesses of all sizes, across multiple sectors, and in many cases the violation arose from a process failure – not an intentional evasion. The presence of a functioning programme does not guarantee the absence of a violation, but it is the primary mechanism by which a civil penalty is reduced or a finding of egregious violation is avoided.
Involve counsel when: a screening hit has not been resolved within the decision window; a counterparty disclosure reveals an ownership structure that was not previously assessed; a licence application has been denied and an appeal or reconsideration is needed; a potential past violation has been identified; or the programme is undergoing a significant redesign. In each case, early engagement narrows the range of adverse outcomes.
Related practices
- Compliance audit and testing – independent review of sanctions screening and programme controls
- Sanctions compliance programme design: advanced topics – ownership chains, multi-regime gaps, and redesign
- OFAC licensing and enforcement: a practitioner's guide – specific licences, voluntary self-disclosure, and penalty defence