Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFAC

Sanctions risk assessment under OFAC: what businesses must know

A cross-border distribution business is acquired by a private equity sponsor with investors across three continents. The compliance team has a standard screening tool, a Consolidated List check, and a policy document last updated two years ago. Six months later, a secondary-sanctions query arrives from a correspondent bank. The question is not whether the business has a sanctions compliance programme – it does. The question is whether that programme was calibrated against actual risk. In our experience, that gap between having a programme and having a risk-based programme is where most enforcement exposure originates.

A sanctions risk assessment under OFAC is a structured, documented evaluation of where a business is exposed to US sanctions prohibitions – across counterparties, geographies, products, and transaction channels. OFAC's own compliance guidance identifies a risk assessment as one of five essential elements of an effective compliance programme. The assessment is not a one-time exercise: it must be reviewed when the business changes, when the regulatory environment shifts, or when a potential breach surfaces.

This guide walks through the assessment in five stages, identifies the cross-regime dimension that many US-focused programmes overlook, and sets out the risk flags that make external counsel worth engaging before a problem hardens into a violation.

Step 1 – Mapping the business model against the OFAC universe

The first step in any OFAC sanctions risk assessment is to build a complete map of the business: what it does, who it transacts with, through which channels, and in which currencies. OFAC's authority extends to US persons, US-dollar transactions wherever they clear, and goods and technology with a US nexus – meaning a business does not need US operations for OFAC to be relevant.

The mapping exercise should cover at minimum:

  • Legal entities in the group and their jurisdictions of incorporation
  • Counterparty types: customers, suppliers, distributors, agents, intermediaries, and financial institutions
  • Geographic reach: countries of operation, delivery destinations, and transit jurisdictions
  • Products and technology: whether any item has a US origin, US-origin component, or US intellectual property
  • Payment rails: US-dollar correspondent banking, dollar-denominated trade finance, digital assets
  • Sector exposure: defence, energy, financial services, and telecommunications carry elevated baseline risk under most OFAC programmes

Mapping is not a checklist exercise. It requires interviews with business lines, a review of the actual transaction data, and – critically – an examination of what the compliance function does not currently see. Shadow flows, delegated payment arrangements, and third-party agency structures are common blind spots.

The business also needs to confirm whether any of its officers, directors, or significant shareholders are themselves on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) or connected to listed persons through the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked, regardless of whether those entities appear on the SDN List). Ownership aggregates: two listed persons each holding a minority stake may together trigger the rule.

Step 2 – Scoring exposure by risk category

Once the map is complete, each exposure identified should be scored against two dimensions: probability of a sanctions nexus arising, and potential severity of the consequence if it does. OFAC's guidance frames this as a relative ranking; the output is a risk matrix that tells the compliance function where to concentrate resources.

The risk categories that most commonly drive elevated scores are:

Counterparty risk. Does the business transact with state-owned entities, financial intermediaries, or correspondent banks in high-risk jurisdictions? Does it use agents whose own ownership structures are opaque? In our cross-border practice, counterparty risk in distribution chains is consistently underrated: a business that knows its direct buyer may have no visibility into the buyer's buyer.

Geographic risk. Operations in or adjacent to comprehensively sanctioned jurisdictions carry the highest inherent risk. Even where a business has no direct nexus, goods can be diverted, payments can be re-routed, and correspondent banks can refuse to process.

Product and technology risk. Dual-use items, energy-sector technology, financial services software, and telecommunications equipment attract scrutiny across multiple regimes simultaneously – OFAC, the EAR (the Export Administration Regulations administered by BIS), the EU dual-use rules, and the UK's Export Control Order.

Transactional and payment risk. US-dollar payment routing is the most common vector for inadvertent OFAC exposure for non-US businesses. A single dollar-denominated payment that clears through a US correspondent bank subjects that transaction to OFAC jurisdiction, regardless of the nationalities of the parties.

Scoring should be documented with a rationale for each rating. An undocumented assessment is almost as risky as no assessment at all: if OFAC later reviews the business, the absence of a contemporaneous record suggests the exercise was not genuinely conducted.

The position above covers the standard case. Your facts – the counterparty's ownership chain, the goods involved, the clearing currency, the jurisdictions in play – change the scoring materially. For a review of your specific risk profile, contact Calder & Vance at info@caldervance.com.

Step 3 – Reviewing the controls against the mapped risk

A completed risk map and score tells you where the exposure sits. Step three tests whether the existing controls are calibrated to address it. Controls that were designed for a different business model, an earlier regulatory environment, or a narrower geographic footprint will produce gaps even when they operate exactly as intended.

The five control categories that OFAC's compliance guidance treats as essential are: management commitment; risk assessment; internal controls; testing and auditing; and training. In our experience, most businesses that have any compliance programme perform adequately on management commitment and training. The gaps are almost always in internal controls and testing – specifically, in whether the screening tool actually covers the SDN List in its current form, whether the 50 percent rule logic is applied to indirect ownership chains, and whether transaction-monitoring rules are tuned to the business's actual risk profile rather than a generic financial-crime template.

Specific control weaknesses to examine:

  • Screening tool coverage: does it screen against the SDN List, the Sectoral Sanctions Identifications (SSI) List, and other OFAC lists simultaneously?
  • Name-matching logic: does it handle transliteration variants, aliases, and incomplete data?
  • Ownership-chain analysis: does it go beyond the immediate counterparty to apply the 50 percent rule to intermediate holding structures?
  • Refresh frequency: how often is the database updated, and is there a process for re-screening existing counterparties when new designations are issued?
  • Payment-level controls: are US-dollar transactions subject to separate review before clearing instructions are issued?
  • New-product and new-market review: is there a process for triggering a sanctions review before a new product line or geographic market is approved?

Each gap identified at this stage becomes a remediation item. Remediation should be prioritised by reference to the risk scores from Step 2: close the highest-risk gaps first, document the plan, and set measurable milestones.

How does OFAC differ from other regimes here?

OFAC's approach to risk assessment shares its general logic with OFSI, the EU, and other major regimes – but three specific divergences matter for any business that operates across jurisdictions.

Ownership versus control. OFAC's 50 percent rule is mechanically applied: if blocked persons own 50 percent or more in aggregate, the entity is blocked. Period. OFSI and the EU add a separate control test: an entity can be caught even where the listed person's ownership stake falls below 50 percent, if that person exercises control over the entity's decisions. A business that passes the OFAC ownership screen can still fail the OFSI or EU control test for the same counterparty. This divergence is a live issue in M&A and trade-finance transactions where counterparty chains cross jurisdictions.

Extraterritorial reach and secondary sanctions. OFAC's secondary-sanctions programmes can restrict access to the US financial system for non-US persons who engage in specified categories of activity involving certain programmes, even where no US nexus would otherwise exist. OFSI and the EU do not operate equivalent secondary-sanctions mechanisms in the same form. A risk assessment that only asks whether a transaction triggers OFAC primary prohibitions will miss the secondary-sanctions dimension for a business with significant US market access or US correspondent banking relationships.

Specific-licence practice. OFAC's specific-licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) process is administered by OFAC directly and has a published track record that informs expectations. OFSI's licensing regime operates under a different statutory basis and with different published categories. EU licensing is decentralised to competent authorities in each member state. A cross-border risk assessment must account for which regime's licensing route is available for which element of a transaction – and whether a US-licensed transaction is nonetheless restricted under EU or UK rules.

For further analysis of how OFAC interacts with the Australian sanctions regime and DFAT's risk-based expectations, see our related guidance: Compliance Audit and Testing – Australia.

What are the most common risk flags that warrant escalation or external review?

Certain patterns, when identified during a sanctions risk assessment, indicate that the matter requires escalation within the compliance function or engagement of external sanctions counsel. They are not necessarily violations – but they are the situations where the gap between a general compliance view and a specialist sanctions view most often produces a material outcome.

A counterparty with a multi-layered ownership structure in a high-risk jurisdiction. Opaque holding structures are a consistent feature of enforced sanctions violations. Where beneficial ownership cannot be confirmed to a reasonable standard, the transaction carries elevated risk regardless of whether a name-match returns a result on screening.

A transaction involving a US-dollar payment route through a jurisdiction subject to comprehensive sanctions. Even where the underlying commercial parties are not themselves sanctioned, correspondent banks may block the payment, and the business may face scrutiny of its intent in structuring the transaction as it did.

A business or asset under consideration for acquisition that has historical exposure to a sanctioned programme. In M&A contexts, acquiring a business that previously operated in a sanctioned jurisdiction – or that has legacy contracts with now-designated counterparties – can transfer exposure to the acquirer. A pre-acquisition sanctions review is a distinct exercise from a standard legal due diligence process.

A product or technology that is also subject to EAR controls. Where a product is export-controlled under the EAR as well as potentially sanctions-relevant, the two regimes interact: an export licence from BIS does not authorise what OFAC prohibits, and a specific OFAC licence does not override an EAR requirement. The risk assessment must address both.

A voluntary self-disclosure – VSD – situation. If the assessment reveals a potential prior violation, the calculus changes immediately. The decision whether to make a VSD to OFAC, and the timing and content of any disclosure, is a specialist determination that affects both the penalty exposure and the enforcement approach OFAC takes. This is not a decision for the standard compliance review process.

If a transaction has already been flagged, or if the risk assessment surfaces a possible prior breach, an early review can preserve options that narrow materially with time. Contact Calder & Vance at info@caldervance.com for a confidential initial review.

Step 5 – Documenting the assessment and building in periodic review

A sanctions risk assessment is only as useful as the record it produces. OFAC's compliance guidance is explicit that documentation – of the methodology, the findings, and the remediation plan – is a core element of a defensible compliance programme. An undocumented assessment that reaches the right conclusions provides materially less credit than a documented one in an enforcement context.

The documentation package for a completed assessment should include: the scope and methodology; the risk-category definitions and scoring rationale; the control-gap findings; the remediation plan with owners and timelines; and an attestation from senior management that the assessment was reviewed and approved. This package should be retained in a retrievable form. Under OFAC's general record-keeping expectations, and under the equivalent requirements of most parallel regimes, records relevant to sanctions compliance should be maintained for a substantial period – the specific retention period applicable to your business will depend on the regulatory regimes in scope; verify the current position before relying on any stated period.

Equally important is the review cycle. A sanctions risk assessment conducted two years ago does not reflect today's regulatory environment. Trigger events for a fresh assessment or a targeted update include: a material change in the business model or geographic footprint; a new designation affecting a counterparty category the business operates in; a merger, acquisition, or restructuring; and a regulatory enquiry or a correspondent bank query that indicates external concern about the business's exposure.

We regularly advise clients on the frequency and scope of periodic reviews, including what an assessment conducted internally by the compliance team should cover versus what benefits from an external, independent perspective. The two are not mutually exclusive; in our practice, the most effective programmes use internal assessments for routine cycles and external reviews when the risk profile has changed materially or when an external signal – a bank query, a regulatory contact, a compliance-programme audit – indicates that an independent view adds value.

For a structured approach to testing and auditing that maps to OFAC's published compliance expectations, see our guide: Sanctions Risk Assessment under OFAC – Guide 4. For specific-licence and general-licence considerations arising from the risk assessment, see: Sanctions Risk Assessment under OFAC – Guide 5.

A common myth: "We screened the counterparty, so we are covered"

A persistent misconception in cross-border compliance is that running a counterparty's name through a screening tool exhausts the sanctions risk assessment obligation. It does not, and the gap between that belief and the actual standard is where enforcement exposure accumulates.

Screening identifies name matches against published lists. It does not assess whether an unlisted entity is caught by the 50 percent rule through its ownership chain. It does not identify whether a transaction's structure, payment route, or geographic path creates exposure that would not surface as a name match. It does not address secondary-sanctions risk, which operates by reference to the nature and volume of activity – not by reference to whether a specific counterparty is listed. And it does not identify historical violations that may already have occurred.

OFAC's published compliance guidance describes risk assessment and internal controls as separate, equally weighted elements of an effective programme. Screening is one component of internal controls. It is not a substitute for the broader assessment. Have you confirmed that your screening tool applies the 50 percent rule to indirect ownership chains – not just the direct counterparty? That single question identifies a gap in the majority of screening implementations we review.

In a recent matter, a mid-market trading business had maintained a screening programme for several years and had recorded no SDN matches. A pre-transaction due diligence review identified that a distributor – not itself on any list – was majority-owned through a two-layer holding structure by a blocked person. The business's screening tool had not been configured to analyse indirect ownership. We assisted the business in conducting a full ownership analysis, assessing the historical exposure, and designing a revised screening and control architecture. The matter was resolved without enforcement action, though outcomes of this kind depend on the specific facts and the response taken.

Related practices

Frequently asked questions

What are the steps to carry out a sanctions risk assessment under OFAC?
An OFAC sanctions risk assessment follows five core steps: mapping the business model and transaction flows against the OFAC universe; scoring each exposure by probability and severity; reviewing existing controls against the identified risk; addressing the cross-regime dimension for businesses with OFSI or EU exposure; and documenting the findings with a remediation plan and a defined review cycle. Each step feeds the next, and the documentation from each stage is part of the defensible compliance record.
What is the most common mistake in sanctions risk assessment?
The most common mistake is treating counterparty name-screening as a substitute for a full risk assessment. Screening identifies list matches; it does not apply the 50 percent rule to indirect ownership chains, assess secondary-sanctions exposure, or identify structural vulnerabilities in payment routing. OFAC's published compliance guidance treats risk assessment and internal controls – of which screening is one part – as separate, equally weighted elements. Conflating them leaves systematic gaps.
How does OFAC differ from other regimes here?
OFAC's ownership test is mechanical: the 50 percent rule applies to aggregate direct and indirect ownership by blocked persons, without a separate control analysis. OFSI and the EU add a control limb – a non-listed entity can be caught even below the ownership threshold if a listed person controls it. OFAC also maintains secondary-sanctions programmes that restrict US market access for non-US persons who engage in specified conduct, a mechanism without a direct equivalent under OFSI or the EU regime. A risk assessment that addresses only the OFAC ownership test will miss both of these dimensions for cross-border businesses.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.