Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFAC

Sanctions risk assessment under OFAC: step by step

A multinational trading house is screening a new distribution partner in South-East Asia. The counterparty passes its automated name-check. Six weeks later, a correspondent bank flags the relationship: a holding company two layers up appears on OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The deal is already live. That six-week gap – between the first screen and the flag – is where sanctions exposure is created.

A sanctions risk assessment under OFAC is a structured, documented evaluation of the people, entities, jurisdictions, products, and transactions in a business's operations that may create exposure under US economic sanctions administered by the Office of Foreign Assets Control. As of August 2026, OFAC expects all organisations with US-person nexus to maintain a risk assessment that is proportionate to their size, sector, and counterparty base – and that assessment forms the foundation of an effective compliance programme (the five-pillar framework OFAC has published in its compliance commitments guidance). The steps set out below follow that framework in sequence.

This guide walks through each stage of the assessment: scoping your exposure base, mapping ownership and control, testing products and jurisdictions, identifying gaps, and documenting conclusions in a form that would withstand regulatory scrutiny. Where OFAC's approach diverges from OFSI, the EU, or other regimes, those differences are flagged – because for a cross-border business, the gap between regimes often determines the commercial outcome.

Step 1: Define the scope of your exposure base

The first step is to map every population of people, entities, and transactions that could create sanctions exposure for your organisation. Start with your legal entities and their US-person nexus: any US citizen, US permanent resident, US-incorporated company, or person physically present in the United States triggers OFAC jurisdiction. Secondary-sanctions risk extends this further – non-US parties transacting in US dollars or through US correspondent banks may also face OFAC scrutiny even without a direct US-person element.

For each business line, identify the categories of counterparties: customers, suppliers, distributors, agents, joint-venture partners, and financial intermediaries. Do not stop at the immediate contractual party. Beneficial ownership chains, intermediary entities, and payment routes all form part of the exposure base. In our experience, businesses that map only their direct counterparties routinely undercount their actual exposure – sometimes by a considerable margin.

The output of Step 1 is a population inventory: a written record of every category of party and transaction in scope. This document becomes the control input for every subsequent step. Without it, gaps in the assessment are invisible.

Step 2: Apply the ownership and control test to counterparties

Once the population is defined, each counterparty must be tested against the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by one or more blocked persons as themselves blocked, regardless of whether the entity is separately listed). This is the most technically demanding part of the assessment and the source of the greatest number of missed exposures.

Aggregation is where the analysis most often fails. Two listed persons, each holding twenty-five percent of the same target, reach the threshold together. A chain of three holding companies, each individually below the trigger, can still reach it in aggregate. OFAC's position under IEEPA is mechanical: the ownership percentage is the test; the intent of the parties is irrelevant to it.

Control is a separate question under OFSI and the EU. Both regimes apply an ownership and control test (the UK and EU rule that a non-listed entity is caught if a listed person owns or controls it). Under OFSI, an entity can be within scope even if a listed person owns less than fifty percent, provided that person can direct or significantly influence the entity's activities. The EU position is substantively similar. For a business operating across all three regimes, the OFSI/EU control arm catches cases the mechanical OFAC ownership test would release.

The practical implication: where an OFAC ownership analysis returns a result below fifty percent, the EU and UK analysis must still be run independently. The stricter prohibition governs the transaction.

What does this mean for your existing counterparty file? Every entity with any listed-person shareholder, even a small one, warrants a documented ownership-chain review. That review should be refreshed whenever a new designation is published in a relevant programme.

Step 3: Map jurisdictions and sector risk

After counterparties, the assessment turns to geography and sector. OFAC administers a set of programme-specific prohibitions whose scope varies significantly. Some programmes impose comprehensive embargoes: transactions with certain jurisdictions or their governments are broadly prohibited regardless of the identity of the specific counterparty. Other programmes are list-based, targeting named individuals and entities rather than entire economies.

Sector risk interacts with jurisdiction risk in two ways. First, certain sectors – defence, energy, financial services, and technology in particular – attract targeted sectoral measures within broader country programmes. These measures may prohibit specific transaction types (new-debt financing above defined maturities, equity investments) without necessarily requiring the counterparty to be on the SDN List. The sectoral distinction is important and easily missed by teams that run only name-screening. Second, certain sectors carry elevated secondary-sanctions risk because US enforcement historically focuses on the financial intermediaries that support them.

For each jurisdiction appearing in your population inventory, record: whether a comprehensive programme applies, whether sectoral measures apply to your business line, and whether any OFAC-identified persons or entities are active in that market. Cross-reference the result against the UK and EU position. Where OFSI has issued a different list or the EU's designations diverge from OFAC's, the business faces a patchwork of obligations that a single-regime screen will not resolve.

Step 4: Assess products, services, and payment channels

The assessment must also cover what is being sold or supplied, and how payment flows. For goods exporters and manufacturers, the OFAC analysis intersects with BIS export-control obligations under the EAR. A good that requires a BIS licence for export to a particular destination may also be subject to OFAC programme restrictions in that market. Both analyses are required; a clean OFAC screen does not substitute for a BIS classification review, and vice versa.

For financial institutions and payment firms, the product analysis focuses on transaction types. Wire transfers routed through the US financial system that touch a blocked party or a comprehensively embargoed jurisdiction create automatic liability under OFAC's strict-liability standard – knowledge of the violation is not required. This makes payment-channel mapping particularly important for correspondent banks, payment aggregators, and virtual-asset service providers.

VASPs (virtual-asset service providers) face a further layer of complexity. OFAC has made clear that the obligations applicable to financial institutions apply equally to VASPs with a US-person nexus. Blockchain address screening, wallet-level due diligence, and the tracing of counterparty identity through pseudonymous transactions are all part of a compliant VASP sanctions programme. The risk here is amplified by the speed and irreversibility of on-chain settlement.

The position above covers the standard case. Your facts – the counterparty, the goods, the route, the regime in play – change the analysis considerably. For a structured review of your product and payment exposure, contact Calder & Vance at info@caldervance.com.

Step 5: Identify gaps and rate residual risk

The fifth step converts the mapping work into a gap analysis. For each population category and each risk dimension examined in Steps 1 to 4, the assessment records: what controls currently exist, whether those controls are adequate given the risk, and what the residual exposure is if a gap is not addressed.

OFAC's compliance commitments guidance describes a five-element standard: senior management commitment, risk assessment, internal controls, testing and auditing, and training. The gap analysis should map directly to these five elements. Where a control is absent or inadequate, record it. Where a population is screened but the screening tool does not cover the relevant programme or list, that is a gap. Where ownership analysis stops at the first legal tier, that is a gap. Where training covers only basic SDN-list obligations and does not address sectoral measures, that is a gap.

Residual risk is rated in two dimensions: probability (how likely is the gap to result in a prohibited transaction?) and consequence (what is the severity of a violation in this area?). Both dimensions inform the remediation priority. In our experience, teams that rate probability alone underweight high-severity low-frequency risks – exactly the profile of a large, missed designation in a key trading relationship.

If a transaction has already been flagged, or if a compliance gap has already produced a potential violation, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.

Step 6: Document the assessment and design the remediation plan

A sanctions risk assessment that is not documented provides no regulatory protection. OFAC's enforcement guidance treats the existence, quality, and currency of a written risk assessment as a significant mitigating factor when evaluating potential violations. An undocumented assessment is, from a regulatory standpoint, an absent one.

The documentation should record: the methodology used, the populations and risk dimensions examined, the sources consulted, the gap findings, the residual risk ratings, and the proposed remediation steps with timelines and owners. It should be dated and version-controlled. It should identify the senior manager who approved it. And it should be reviewed whenever there is a material change in the business's operations, counterparty base, or the sanctions programmes relevant to its sector.

How frequently should the assessment be refreshed? A static annual review is rarely sufficient for businesses with active cross-border operations. OFAC designation activity is continuous; a counterparty that cleared the assessment in January may be listed by April. Periodic rescreening of the full counterparty population, triggered by new designations in relevant programmes, is standard practice in well-run compliance functions.

The remediation plan closes the loop. Each gap identified in Step 5 should have an assigned owner, a target completion date, and a defined remediation action – whether that is a policy update, a system enhancement, a training intervention, or a structural change to a counterparty relationship.

Common risk flags and when to involve counsel

Certain fact patterns consistently produce the most significant exposure across the client base we advise. Recognising them early is the most efficient form of risk management.

  • Newly listed counterparties in active trading relationships. A designation mid-relationship is one of the most time-sensitive situations in sanctions compliance. The obligation to cease performance and block assets arises immediately. There is no grace period for existing contracts.
  • Layered ownership structures with a listed-person connection below fifty percent. The OFAC mechanical test may not trigger; the OFSI and EU control tests may still catch the entity. A cross-regime ownership analysis is required.
  • US-dollar payment routing for a transaction that is OFAC-clean on its face. Where the underlying counterparty or jurisdiction carries programme risk, routing through a US correspondent bank creates exposure for all parties in the payment chain.
  • Sectoral measures that do not appear on standard SDN-list screens. Businesses that rely solely on name-matching tools will not detect sectoral prohibitions. A product-and-sector analysis is required in addition to name screening.
  • VASP and digital-asset exposure. The speed and pseudonymity of on-chain transactions make real-time compliance more demanding. Address-level screening and counterparty identity verification are both required.
  • Jurisdictions where OFAC, OFSI, and EU designations diverge. A counterparty cleared under OFAC may still be listed under EU or UK measures. For businesses with operations in multiple jurisdictions, each regime requires an independent analysis.

Involve counsel when: a counterparty or beneficial owner appears on any list; when a transaction involves a jurisdiction with a comprehensive programme; when an internal screen returns an inconclusive result; when the business is about to enter a new market or product line with elevated sanctions exposure; or when a potential violation has occurred and a VSD (voluntary self-disclosure to a regulator) is being considered.

A common misconception is that a sanctions risk assessment is a one-time exercise – something to be filed at programme inception and revisited only during a regulatory examination. In practice, OFAC and its enforcement counterparts treat a stale, undated, or unrevised assessment as evidence of inadequate management commitment. The assessment is a living document. Treating it otherwise is itself a risk flag.

Related practices

Frequently asked questions

What are the steps to carry out a sanctions risk assessment under OFAC?
An OFAC sanctions risk assessment proceeds in six steps: define the exposure population (entities, counterparties, transactions, and payment channels); apply the fifty-percent ownership test to each counterparty and trace the full beneficial ownership chain; map jurisdiction and sector risk against the applicable OFAC programmes; assess product and payment-channel exposure, including any intersection with BIS export-control obligations; identify gaps against the five-element compliance standard and rate residual risk by probability and consequence; and document the findings with a dated remediation plan approved by senior management. Each step requires a written output. The assessment should be refreshed whenever a material change occurs in operations, counterparties, or the relevant programmes.
What is the most common mistake in sanctions risk assessment?
The most common mistake is limiting the counterparty analysis to direct contractual parties screened by name only. This misses two critical exposure categories: beneficial owners and intermediate holding companies that could trigger the fifty-percent rule through aggregated holdings, and sectoral measures that apply by transaction type and sector rather than by the listed status of a named party. A third frequent error is treating the assessment as static – failing to rescan the counterparty population when new designations are published in relevant programmes. Each of these gaps has produced enforcement exposure in matters we and others have advised on.
How does OFAC differ from other regimes here?
OFAC applies a mechanical ownership test: an entity is blocked when listed persons own fifty percent or more in the aggregate, full stop. OFSI and the EU both extend this with a control dimension – an entity can be caught even below the fifty-percent threshold if a listed person can direct or materially influence its decisions. OFAC also imposes strict liability: knowledge of a violation is not required for civil penalties. Under EU and UK law, knowledge and intent are relevant to penalty severity, though not to the underlying prohibition. For businesses operating across these regimes simultaneously, the control arm of OFSI and the EU consistently catches exposures that the OFAC mechanical test would release.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.