Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFAC

Sanctions risk assessment under OFAC: a compliance guide

A mid-sized technology distributor operating between the United States and a third-country market runs its quarterly counterparty refresh. One entity in its supply chain has a new shareholder – a person whose name appears on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The deal team wants to proceed. The compliance officer is not sure whether to block the payment, file a report, or seek a licence. The legal risk falls on the US parent regardless of where the transaction settles.

A sanctions risk assessment under OFAC is the structured process by which a business identifies, measures, and prioritises its exposure to US economic sanctions prohibitions administered by the Office of Foreign Assets Control. As of mid-2026, OFAC operates more than thirty active sanctions programmes under IEEPA, TWEA, and related statutes. The assessment maps every dimension of exposure – counterparties, products, geographies, payment routes, and ownership chains – against those prohibitions and produces a risk-ranked action plan.

This guide walks through each phase of a sound OFAC sanctions risk assessment, explains where the analysis diverges from the UK and EU tests, and identifies the risk flags that most commonly produce enforcement referrals.

Why OFAC sanctions risk assessment differs from ordinary compliance review

OFAC's jurisdiction reaches further than most compliance officers expect. The prohibitions extend to US persons wherever they are located, to transactions cleared in US dollars regardless of the parties' nationalities, and – through secondary-sanctions mechanisms – to non-US persons whose conduct implicates designated programmes. That extraterritorial reach is what makes a generic compliance review insufficient.

A standard anti-money-laundering review asks whether a counterparty is suspicious. An OFAC risk assessment asks a different question: does any element of this business relationship – the counterparty, its owners, its jurisdiction, the goods, the payment route – touch a US sanctions prohibition? The answer can be yes even where the counterparty itself is clean.

In our cross-border practice, we see the highest-risk gaps when firms treat OFAC screening as a list-check rather than a programme-wide analysis. List-checking catches direct hits. It does not catch a non-listed subsidiary owned 50 percent or more in the aggregate by blocked persons under the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked). It does not catch a product destined for an end use that a sectoral sanction restricts. And it does not catch a US-dollar wire that routes through a correspondent bank touching a restricted geography.

The cross-border dimension compounds the complexity. A European exporter may have no direct US nexus on its face. But if it invoices in dollars, uses a US-domiciled payments processor, or has a US parent or investor, OFAC jurisdiction attaches. The correct starting point is not "does OFAC apply?" but "how does OFAC apply here, and what does that mean alongside the applicable OFSI and EU rules?"

Step 1 – Define the scope: what your business actually touches

Before any screening can run, a business must map its own exposure footprint – the universe of counterparties, products, geographies, and transaction types that the assessment will cover.

Scope mapping has four dimensions. First, identify every legal entity in the corporate group that either is a US person or processes US-dollar transactions. Both categories carry direct OFAC obligations. Second, list every product, service, and technology the group offers and note whether any is subject to the Export Administration Regulations administered by the Bureau of Industry and Security – because BIS and OFAC exposure frequently overlap on the same transaction. Third, identify all counterparty jurisdictions and flag those where OFAC operates a comprehensive or targeted programme. Fourth, trace the payment routes: which banks process US-dollar settlements, and where are those banks' correspondent accounts?

This scope map becomes the master input for every subsequent step. A risk assessment that does not start here will have blind spots. We regularly advise clients to treat the scope document as a living record – updated whenever the business enters a new market, adds a product line, or changes its banking arrangements.

The position above covers the standard case. Your facts – the structure of your group, the nature of your goods, and the jurisdictions you operate in – will change the analysis materially.

For a preliminary review of your scope and exposure, contact Calder & Vance at info@caldervance.com.

Step 2 – Identify the applicable OFAC programmes and prohibitions

Once the scope is mapped, the assessment must identify which OFAC programmes are live and relevant to the business's specific exposure footprint. OFAC administers programmes that operate in two modes: comprehensive country-based programmes that prohibit virtually all transactions with a particular jurisdiction, and targeted programmes that prohibit dealings with named persons, sectors, or activities without a country-wide bar.

For each relevant programme, the assessment must answer three questions. What transactions are prohibited? What general licences (standing authorisations that permit a defined category of transactions without a separate application) are available and whether the business's transactions qualify? And what specific licences (case-by-case authorisations to conduct an otherwise prohibited transaction) would be needed if general-licence coverage does not apply?

Sectoral and programme-specific prohibitions require particular attention. Some programmes restrict a defined category of transactions – new-debt financing above a specified maturity, for example, or the export of particular energy-sector services – without prohibiting all dealings with the target. These targeted restrictions are narrower than a comprehensive block, but they are also harder to identify through list-based screening alone. The risk sits in the transaction type, not just the counterparty name.

A note on secondary-sanctions exposure: certain OFAC programmes create risk for non-US persons who engage in defined conduct, even if that conduct involves no US person and no US-dollar transaction. The legal mechanism and the precise scope of secondary sanctions vary by programme. In our experience, non-US businesses underestimate this dimension most frequently when they assume that OFAC is a US-only concern. It is not.

Step 3 – Screen counterparties and trace ownership chains

Counterparty screening against OFAC's SDN List and other restricted-party lists is the most visible part of sanctions compliance – but it is also the step where firms make their most consequential mistakes. Effective screening requires both technical accuracy and human judgement.

The technical requirements are well understood: name-matching algorithms must handle transliterations, aliases, and partial matches; screening must cover legal entities and their individual beneficial owners; and the database must be current. What firms underinvest in is the ownership analysis that must sit behind the name match.

The 50 percent rule requires aggregation. Two blocked persons each owning a 25 percent stake in a target company together reach the threshold; neither does alone. Three blocked persons at 20 percent each exceed it collectively. Screening tools that flag only direct ownership miss layered structures. The correct approach maps every ownership tier above the immediate counterparty up to the ultimate beneficial owners and checks whether any blocked person's holdings aggregate to the threshold at any level.

The UK and EU ownership tests diverge from OFAC's here. Under OFSI and the relevant EU Council regulations, a non-listed entity can be caught not only through ownership meeting the applicable threshold but also through ownership and control (the UK and EU test for whether a non-listed entity is caught through a listed person) – meaning control exercised through contractual rights, board appointments, or economic dependency, without reaching a numerical ownership threshold. In our practice, this divergence produces the most friction on cross-border deals: an entity that passes OFAC's mechanical 50 percent test may still be restricted under UK or EU rules if a designated person controls it in practice. Both analyses should run in parallel on any transaction touching multiple regimes.

Step 4 – Assess products, services, and transaction types

Product and transaction-type analysis is the dimension of OFAC risk assessment most likely to be skipped on the assumption that counterparty screening is sufficient. It is not. Certain prohibitions attach to what is being traded or financed, not only to who the counterparty is.

Where a product or technology also falls within the scope of the EAR, the OFAC and BIS analyses interact. A product may require a BIS export licence to a particular destination independently of whether the consignee is sanctioned; and a transaction that clears the BIS analysis may still be blocked by OFAC if the end user or end use falls within a sanctioned programme. The ECCN (Export Control Classification Number under the US Commerce Control List) is the starting point for the BIS classification, but it does not resolve the OFAC question.

Financial institutions face a parallel analysis on transaction types. Wire transfers, trade-finance instruments, and correspondent-banking relationships each carry their own OFAC exposure. For payment firms and banks, the relevant question is not only whether the named parties to a transaction are sanctioned, but whether the underlying commercial activity the payment supports would be prohibited.

If a transaction has already been flagged by your bank or a payment processor, an early review can preserve options that narrow with time.

To discuss a specific transaction or product classification question, write to info@caldervance.com.

Step 5 – Rate risk, prioritise gaps, and document findings

With the exposure map, programme analysis, counterparty screening results, and product review complete, the assessment moves to risk rating. This step produces the ranked action plan that guides remediation.

Risk rating should combine two variables: the likelihood of a prohibited transaction occurring, and the severity of the OFAC violation it would constitute. Severity is itself a function of several factors: the nature of the sanctions programme (comprehensive programmes carry strict liability in a way that targeted programmes sometimes moderate through available licences), the transaction value, and whether the violation would be apparent or egregious under OFAC's enforcement framework. OFAC's published guidance distinguishes between base-penalty calculations for apparent violations and aggravated penalties where wilful conduct or repeated violations are present.

Documentation is not optional. OFAC's enforcement guidance explicitly identifies the quality of a firm's compliance programme as a mitigating factor in penalty determinations. A well-documented risk assessment – one that records what was screened, what was found, what was escalated, and what action was taken – is among the most valuable assets a business can have in an enforcement inquiry. Record-keeping obligations under the applicable regime specify a defined retention period; verify the current requirement before setting your document-retention policy.

The output of Step 5 is a written risk register: each identified gap, its risk rating, the responsible owner, and a remediation deadline. This document should go to senior management and, where material exposure is identified, to the board.

How does OFAC enforcement shape the risk assessment calculus?

Understanding how OFAC approaches enforcement decisions helps a compliance team calibrate how much resource to direct at each identified risk. OFAC has published detailed guidance on the factors it weighs when deciding whether to take enforcement action and at what penalty level.

The key distinction is between wilful or reckless conduct and violations that result from inadequate controls but not deliberate intent. OFAC will credit a robust compliance programme, a timely VSD (voluntary self-disclosure to a regulator), and prompt remediation. Conversely, a business that ignores a known risk, fails to maintain adequate screening, or delays reporting once a violation is discovered faces significantly worse outcomes.

This enforcement calculus has a direct implication for the risk assessment process: the assessment itself, properly conducted and documented, is evidence of the compliance programme. A business that can show OFAC a structured, comprehensive, regularly updated risk assessment is in a materially different position from one that cannot. We have acted for clients in enforcement investigations where the existence of a documented programme – even an imperfect one – was a meaningful mitigating factor.

The cross-regime point is worth noting too. OFSI in the UK has adopted a similarly graduated approach, distinguishing between prompt voluntary reporting and non-disclosure in its enforcement guidance. The EU's enforcement posture varies by member state but is converging toward a more penalty-oriented approach following recent legislative changes. A business operating across jurisdictions should design its risk assessment process to generate documentation that satisfies multiple regulators simultaneously where possible.

Common risk flags and when to involve counsel

Certain patterns appear repeatedly in OFAC enforcement actions and in the matters we review. Recognising them early is the most reliable way to avoid an enforcement referral.

The first flag is an incomplete ownership trace. As described above, the 50 percent rule requires aggregation across all blocked-person interests at every level of a structure. Where an ownership chain involves trusts, nominees, or opaque offshore vehicles, the trace is harder but the obligation does not diminish.

The second flag is US-dollar transaction routing. A transaction between two non-US parties settled through a US correspondent bank passes through OFAC jurisdiction at the moment the dollars clear. Businesses that believe they have no US nexus often have a US-dollar nexus they have not identified.

The third flag is use of third-party intermediaries whose own compliance programmes are unknown. A freight forwarder, distributor, or financial intermediary that is itself subject to OFAC jurisdiction can transmit exposure to the principal. Contractual representations and warranties are a minimum; due-diligence review of the intermediary's screening practices is better.

The fourth flag is sector-specific exposure. Certain OFAC programmes restrict transactions in defined sectors – energy, finance, defence, technology – with entities from a particular jurisdiction, even where those entities are not listed. A counterparty review that checks names but not sector classification misses this category of risk entirely.

Involve counsel when: the ownership trace produces an ambiguous result; a transaction routes through a restricted geography; a product or service may fall within a sectoral prohibition; a potential violation has been identified; or OFAC, a bank, or a regulator has made an enquiry.

Related practices

Frequently asked questions

What are the steps to carry out a sanctions risk assessment under OFAC?
A sound OFAC sanctions risk assessment runs through five sequential steps: (1) scope the business to identify every entity, product, geography, and payment route carrying US sanctions exposure; (2) identify the applicable OFAC programmes and their specific prohibitions; (3) screen counterparties and trace ownership chains to check the 50 percent rule on aggregated blocked-person holdings; (4) analyse product and transaction types for programme-specific restrictions; and (5) rate each identified risk, document the findings, and produce a ranked remediation plan. The output should be reviewed and approved at senior-management level, and updated whenever the business changes materially or a programme is amended.
What is the most common mistake in sanctions risk assessment?
The most common mistake is treating sanctions risk assessment as a list-check rather than a programme-wide analysis. Screening names against the SDN List catches direct hits; it does not catch entities blocked under the 50 percent rule through aggregated ownership, transactions restricted by sectoral prohibitions without a named counterparty, or US-dollar payment routes that carry OFAC jurisdiction through a correspondent bank. In our experience, the second most common mistake is failing to document the assessment at all – which removes a key mitigating factor if OFAC later opens an inquiry.
How does OFAC differ from other regimes here?
OFAC's ownership test is mechanical: the 50 percent rule triggers on aggregate blocked-person ownership at or above that threshold, regardless of control. OFSI and the EU apply both an ownership threshold and a separate control test, meaning an entity can be caught even where no numerical threshold is met if a designated person exercises practical control. OFAC also has a broader secondary-sanctions mechanism affecting non-US persons than most other major regimes. For businesses operating across jurisdictions, the three analyses – OFAC, OFSI, and the EU – must run in parallel; the strictest applicable prohibition governs each dimension of the transaction.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.