Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFAC

Sanctions risk assessment under OFAC: procedure and pitfalls

A mid-size technology distributor in the United States closes a routine sale to a reseller in a third market. The reseller's beneficial owner does not appear on any watchlist. Six months later, a bank correspondent freezes a payment and flags the counterparty for review. As of mid-2026, OFAC's enforcement posture targets exactly this kind of gap – the transaction that passed a surface screen but was never subjected to a genuine sanctions risk assessment (a structured evaluation of the exposure a business or transaction carries under the applicable sanctions regime, considering counterparties, geographies, goods, and payment routes). The question is not whether to run an assessment. The question is whether the assessment you run will actually catch what OFAC expects you to catch.

A sanctions risk assessment under OFAC is a structured, documented review that maps a business's exposure to US sanctions prohibitions across four dimensions: counterparties and their ownership chains, geographies and routing, products or services, and payment and financial channels. It is governed by IEEPA, TWEA, and the relevant programme regulations administered by the Office of Foreign Assets Control. OFAC's own compliance guidance identifies a formal risk assessment as one of the five essential elements of an effective compliance programme.

This guide walks through the procedure step by step, compares the OFAC approach to the parallel requirements under OFSI and the EU, identifies the most common risk flags, and explains when to involve external counsel.

Step 1 – Establish the legal basis and scope of the assessment

The starting point for any OFAC risk assessment is to define precisely which programme or programmes apply to your business and why.

OFAC administers more than thirty active sanctions programmes. Each rests on a distinct statutory authority – most commonly IEEPA or TWEA – and each carries its own set of prohibitions, general licences, and reporting obligations. A risk assessment that treats "OFAC" as a single uniform regime will miss material differences between list-based programmes (where the trigger is a named person or entity) and comprehensive or jurisdiction-based programmes (where the trigger is a geographic or sectoral connection). The scope question therefore has two parts: which programmes are live for your business, and do they operate as list-based, comprehensive, or sectoral controls?

Scope also turns on US nexus. OFAC's authority reaches US persons wherever they are located, non-US entities that are owned or controlled by US persons, and – critically – any transaction that passes through the US financial system or involves US-origin goods, technology, or services. We regularly advise non-US businesses that are surprised to discover they hold a US nexus through a US-dollar clearing bank, a cloud-services contract, or a parent-company structure. Identifying every nexus point before the substantive risk analysis begins is not optional; it defines the universe of transactions in scope.

The cross-border angle matters from the outset. If the same business is also subject to UK financial sanctions administered by OFSI or to EU Council regulations, the scope of each regime may differ. A transaction that falls outside a comprehensive OFAC programme because it involves a non-US person with no US nexus may still be caught by an EU restrictive measure or an OFSI asset-freeze. Practitioners must define the scope of the OFAC assessment and then layer the other applicable regimes on top.

Step 2 – Map the four risk dimensions

Once scope is fixed, the assessment maps exposure across four structured dimensions: counterparties and ownership, geographies and routing, products and services, and payment channels.

Counterparties and ownership. OFAC's 50 percent rule (the rule treating any entity owned 50 percent or more in the aggregate by one or more blocked persons as itself blocked, even if it does not appear on the SDN List – OFAC's list of Specially Designated Nationals and blocked persons) is the single biggest source of undetected exposure. Screening the direct counterparty against published lists is necessary but not sufficient. The assessment must trace beneficial ownership through every layer of intermediate holding companies until it reaches natural persons. Two listed persons each holding a minority stake can aggregate to cross the threshold together. Have you verified the full beneficial ownership chain, or only the registered name on the contract?

Geographies and routing. Comprehensive sanctions programmes impose broad prohibitions on transactions that touch the relevant territory, directly or indirectly. The routing risk arises where goods or services pass through a jurisdiction or where a transaction is structured to avoid a direct connection. The risk assessment must map every physical and financial routing point, not just the named counterparty's home jurisdiction.

Products and services. Certain products carry elevated risk because they are subject to both OFAC sanctions and US export controls under the EAR (the Export Administration Regulations administered by the Bureau of Industry and Security). Items with a US-origin component, technology with US intellectual-property content, and software subject to the Commerce Control List can trigger parallel obligations. The risk assessment should identify any product or service that could create a concurrent BIS exposure, because enforcement by the two agencies can proceed simultaneously.

Payment channels. US dollar transactions clear through the US financial system. That single fact brings virtually any commercial transaction into OFAC's reach, regardless of where buyer and seller are located. The assessment must identify every currency and every correspondent bank in the payment chain and flag any routing that touches a US financial institution.

Step 3 – Apply the OFAC compliance-programme standard

OFAC has published guidance identifying five essential elements of an effective compliance programme: management commitment, risk assessment, internal controls, testing and auditing, and training. The risk assessment step is not a standalone exercise; it feeds the other four.

In practice, an assessment that satisfies OFAC's compliance-programme standard must do four things. First, it must be documented: OFAC expects a written record showing how the assessment was conducted, what data was reviewed, and what conclusions were reached. An oral review or an informal email thread is not a record. Second, it must be risk-rated: not all exposures are equal, and the programme resources allocated to high-risk counterparties or geographies should reflect their relative weight. Third, it must be reviewed periodically and updated when the business, its counterparties, or the regulatory environment changes. Programmes that were calibrated three years ago and never updated represent a documented compliance gap. Fourth, it must be capable of being tested – meaning that the screening logic, the ownership-tracing process, and the escalation pathway can be demonstrated to function as described.

The position above covers the standard operating model. Your specific facts – the counterparties in your supply chain, the financial institutions processing your payments, the jurisdictions through which your goods route – change the analysis materially.

To discuss how the OFAC standard applies to your business, contact Calder & Vance at info@caldervance.com.

How does OFAC's approach compare to OFSI and the EU?

The OFAC risk-assessment procedure differs from its OFSI and EU counterparts in three important respects: the ownership test, the licensing architecture, and the record-keeping and reporting obligations.

Ownership test. OFAC's 50 percent rule is mechanical: ownership at or above the threshold triggers the prohibition, regardless of whether the blocked person exercises any operational control. OFSI and the EU apply an ownership and control test (the test for whether a non-listed entity is caught through the acts or instructions of a listed person). Under both the UK and EU regimes, control – meaning the ability to direct the entity's decisions without necessarily owning a majority – can catch an entity that passes the OFAC ownership screen. In our experience, this divergence creates the most significant cross-border compliance gap: a counterparty that is not blocked under the mechanical OFAC test may still be subject to an asset freeze under OFSI or EU regulations because a listed person exercises effective control. A thorough multi-regime risk assessment must apply each test separately.

Licensing architecture. OFAC operates a system of general licences (standing authorisations for defined categories of transactions) and specific licences (case-by-case authorisations). OFSI in the UK issues licences under the relevant thematic UK sanctions regulations; the EU licensing regime operates programme by programme through the Council regulations and national competent authorities. The procedures, timelines, and grounds for granting a licence differ across the three regimes. A risk assessment that identifies a transaction requiring authorisation must map which regime's licensing route applies, because the analysis for each proceeds differently.

Record-keeping and reporting. Under OFAC's governing framework, a US person who holds blocked property must report that fact to OFAC within a short statutory window and must keep records for five years. OFSI imposes its own reporting obligations under SAMLA and the relevant thematic regulations. The EU requires notification to national competent authorities in each member state where assets are held. A cross-border business may therefore face concurrent reporting obligations on different timelines, to different authorities, in different forms.

The practical implication is that a risk assessment designed only for OFAC will not discharge a business's obligations under OFSI or EU regulations. We regularly advise businesses on how to run a single integrated assessment that applies all three ownership-and-control tests and maps the applicable licensing and reporting obligations across regimes.

What are the most common risk flags?

Certain patterns, in our experience, consistently signal elevated OFAC exposure in a risk assessment – and consistently appear in enforcement actions where a prior assessment missed them.

The first is incomplete beneficial ownership data. When a counterparty cannot or will not provide information about its beneficial owners beyond the first corporate layer, the risk assessment cannot be completed to the standard OFAC expects. Proceeding on incomplete ownership data is itself a documented compliance failure.

The second is over-reliance on automated screening without human review. Screening software identifies exact or near-match names against published lists. It does not apply the 50 percent rule to an undisclosed ownership structure, identify an unlisted person who exercises control over a listed entity, or flag an indirect geographic connection created by a sub-contractor's routing decision. The risk assessment must combine automated screening with a structured manual review of the ownership and supply chains.

The third is the assumption that a single screen at onboarding is sufficient. Lists change. OFAC adds names, removes names, and modifies entries. A counterparty that was clean at the time of onboarding may be designated months later. The risk assessment process must include a mechanism for ongoing monitoring, not just a point-in-time check.

The fourth is failing to account for secondary-sanctions risk. OFAC administers programmes that carry secondary-sanctions exposure – meaning that a non-US person who engages in certain conduct with a designated party or within a certain sector can itself be at risk of designation or of losing access to the US financial system, even if the underlying transaction involves no US nexus. A risk assessment for a non-US business with global operations must identify secondary-sanctions exposure alongside primary-sanctions prohibitions.

The fifth is treating the risk assessment as a compliance project rather than a business-process integration. An assessment that lives in a compliance file but is not connected to the systems used by procurement, sales, treasury, and logistics will not catch the deal that originates outside the compliance function. The assessment must map where in the business the risk arises, who owns it, and how the escalation pathway works.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. For a confidential review of a potential breach or a compliance gap, contact Calder & Vance at info@caldervance.com.

When to involve external sanctions counsel

External counsel adds the most value at four points in the risk-assessment process: initial scoping, ownership-chain analysis for complex structures, the assessment of transactions that touch a comprehensive or high-risk programme, and the preparation of a documented assessment record for regulatory purposes.

Initial scoping is the step most often underestimated. Identifying which OFAC programmes apply, where the US nexus lies, and whether there is a concurrent OFSI or EU obligation requires regime-specific knowledge that goes beyond a generic compliance checklist. A risk assessment that begins with the wrong scope will be systematically wrong in its conclusions.

Ownership-chain analysis for complex structures – multi-layered holding companies, trust structures, nominee arrangements – requires the application of the 50 percent rule through each layer. Where the structure is opaque or the available information is incomplete, a lawyer can advise on what level of enquiry OFAC would regard as reasonable diligence, and when the residual uncertainty is itself a reportable risk flag.

Transactions that touch a comprehensive or high-risk OFAC programme require a specific-licence analysis or a general-licence review before they proceed. In our practice, the licence-eligibility question is frequently misread at the risk-assessment stage, either because a general licence is missed or because a transaction is assumed to be authorised when it falls just outside the general-licence conditions.

Finally, the documented assessment record matters because it is the primary evidence OFAC will review in any enforcement action. A well-documented risk assessment – one that shows the methodology, the data reviewed, the ownership tracing, the conclusions, and the decision rationale – is OFAC's main mitigating factor in determining whether a violation was non-egregious and whether a VSD (voluntary self-disclosure to a regulator) is warranted. We assist businesses in producing assessment records that will withstand regulatory scrutiny.

A common misconception about sanctions risk assessments

The most persistent myth in this area is that a sanctions risk assessment is primarily a technology problem. The argument runs: invest in a good screening tool, run counterparties through it at onboarding, and the compliance obligation is met.

That framing is incorrect, and OFAC's own compliance guidance makes this clear. Automated screening addresses one input – direct name matches against published lists. It does not apply the 50 percent rule to ownership structures that are not in those lists. It does not identify secondary-sanctions exposure. It does not assess product or geographic risk. It does not test whether a general licence actually covers the transaction or whether a specific licence is required. And it does not produce the documented decision record that OFAC treats as evidence of a genuine compliance programme.

The risk assessment is a legal and analytical process. Technology is a tool within it, not a substitute for it. Businesses that have invested in screening infrastructure but have not conducted a structured, documented risk assessment have typically discharged a small fraction of what OFAC expects. The gap between what a screen catches and what a compliant programme requires is precisely where enforcement exposure accumulates.

In our experience advising compliance teams across multiple industries, the most effective risk assessments are those that are built around the business's actual transaction flows, ownership data, and geographic exposure – not around the capabilities of a software product. The starting point is always the business model, not the tool.

Related practices

Frequently asked questions

What are the steps to carry out a sanctions risk assessment under OFAC?
A sanctions risk assessment under OFAC proceeds in four structured steps: (1) establish which OFAC programmes apply and where the US nexus lies; (2) map exposure across four dimensions – counterparties and ownership, geographies and routing, products and services, and payment channels; (3) apply the OFAC compliance-programme standard by producing a documented, risk-rated record; and (4) build in periodic review and an ongoing monitoring mechanism. Each step must be supported by written records. The assessment feeds the other four elements of an effective compliance programme: management commitment, internal controls, testing and auditing, and training.
What is the most common mistake in sanctions risk assessment?
The most common mistake is treating automated name-screening as a complete risk assessment. Screening software checks direct counterparty names against published lists. It does not apply the 50 percent rule to beneficial ownership structures that sit behind the listed name, does not assess geographic or product risk, and does not test whether a general licence covers the transaction. Businesses that rely on a screening tool alone have addressed only one element of what OFAC expects and carry a documented gap across the rest of the compliance-programme standard.
How does OFAC differ from other regimes here?
OFAC's ownership test is mechanical: the 50 percent rule is triggered by aggregate ownership at or above that threshold, regardless of operational control. OFSI and the EU supplement the ownership test with a control test, meaning that effective control over a non-listed entity by a listed person can trigger an asset freeze even where ownership falls below 50 percent. OFAC also operates a more developed general-licence architecture than most other regimes, and its record-keeping and reporting obligations – including a requirement to retain records for five years – run on their own timeline, separate from OFSI and EU reporting requirements.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.