Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFAC

Sanctions compliance programmes under OFAC: explained

A cross-border trading group acquires a new subsidiary in South-East Asia. Three months later, a routine payment is flagged by a correspondent bank: a supplier in the subsidiary's network has indirect links to a blocked person. The group's legal team asks a straightforward question – does the company have an OFAC-compliant sanctions compliance programme in place? The answer, it turns out, is that no documented programme exists at all. As of mid-2026, OFAC continues to treat the presence or absence of a compliance programme as a central factor in its enforcement decisions.

Sanctions compliance programmes (structured, documented systems that a business uses to identify, prevent, and report potential sanctions violations) are not legally mandated by OFAC in every case, but their absence is a significant aggravating factor in any enforcement action. OFAC's own guidance identifies five essential components that an effective programme must address. Businesses that cannot demonstrate a credible programme face materially higher civil penalties than those that can.

This briefing sets out how OFAC defines a compliant programme, how the five-component standard works in practice, how it compares with the equivalent requirements under OFSI, the EU, and BIS, and what the most common structural failures look like in a cross-border context.

Who administers sanctions compliance programmes under OFAC, and what is the legal basis?

OFAC – the Office of Foreign Assets Control, an agency within the US Department of the Treasury – administers the US economic sanctions regime under the authority of the International Emergency Economic Powers Act (IEEPA) and the Trading with the Enemy Act (TWEA), as well as specific statutory programmes. OFAC's jurisdiction is broad: it reaches US persons wherever they are located, transactions cleared through the US financial system, and – through the secondary-sanctions architecture – non-US persons who engage in specified conduct connected to listed persons or programmes.

OFAC has published guidance on what it calls a "Framework for OFAC Compliance Commitments." That document does not create a new legal obligation in the way a regulation does. Rather, it codifies OFAC's longstanding enforcement practice: a business that can demonstrate a credible, risk-calibrated compliance programme will ordinarily receive meaningful mitigation in any penalty determination. Conversely, a business that has no programme, or one that exists on paper only, can expect that gap to be treated as an aggravating factor.

OFAC's enforcement authority extends to both wilful violations and those caused by reckless disregard or even negligence. A compliance programme is the primary mechanism by which a business demonstrates that it is neither reckless nor negligent in managing its sanctions exposure.

The position above covers the standard regulatory posture. Your specific facts – the sector, the counterparty relationships, the jurisdictions you touch, and the sanctions programmes in play – will change the analysis materially. For an initial assessment of where your programme stands under OFAC's current framework, contact Calder & Vance at info@caldervance.com.

What are the five components of an effective OFAC compliance programme?

OFAC's guidance articulates five essential components that a compliance programme must address to be considered credible. Each component is assessed individually, and a weakness in any one of them can undermine the mitigating value of the others. In our cross-border practice, we consistently find that organisations underestimate how granular OFAC's expectations are.

The first component is management commitment. OFAC expects senior leadership – up to and including the board – to be actively engaged with the sanctions compliance function. A programme that exists at operational level but has no board visibility does not satisfy this element. OFAC will look for evidence that senior management has reviewed and approved the programme, that adequate resources are allocated to it, and that a culture of compliance is demonstrably present.

The second component is risk assessment. The programme must be calibrated to the actual risks the business faces. A wholesale bank, a commodities trader, and a technology exporter each carry a different sanctions-risk profile, and OFAC expects each to have assessed that profile systematically. Risk assessments should be documented, repeated at appropriate intervals, and refreshed when the business enters new markets or takes on new counterparties.

The third component is internal controls. These are the operational mechanisms by which the business detects and prevents prohibited transactions: screening systems, transaction-review procedures, escalation protocols, and controls over the onboarding of new customers and suppliers. OFAC expects the internal controls to be proportionate to the risk assessment and to be tested periodically.

The fourth component is testing and auditing. A programme that is never tested is, in practice, untested. OFAC expects organisations to conduct periodic audits of their sanctions controls, to identify gaps, and to remediate them. Testing should be independent of the teams whose work is being reviewed.

The fifth component is training. All relevant staff must receive training appropriate to their role and their exposure. A trade-finance analyst carries a different risk profile from a relationship manager in a low-risk retail segment. Training records must be maintained and updated as the law changes.

These five elements interact. A business can have sophisticated screening tools (internal controls) but if management has not committed resources to them, and if staff have not been trained to interpret alerts correctly, the tools will produce false assurance rather than genuine protection.

How does the OFAC standard compare with OFSI, the EU, and BIS requirements?

Comparing the OFAC compliance-programme standard with those of its principal counterparts reveals both common ground and significant divergence – and that divergence matters for any business operating across jurisdictions.

Under OFSI – the Office of Financial Sanctions Implementation at HM Treasury – there is no published five-component framework equivalent to OFAC's. OFSI's enforcement guidance emphasises proportionality: what is expected of a major clearing bank differs from what is expected of a small trading firm. OFSI does, however, treat the quality of a firm's compliance measures as a central factor in its enforcement decisions, and its published penalty guidance makes clear that an inadequate programme will increase the penalty outcome. The UK regime under the Sanctions and Anti-Money Laundering Act (SAMLA) and the relevant thematic regulations imposes a reporting obligation – a firm that knows or suspects it holds frozen assets or has breached financial sanctions must report to OFSI within a short statutory window – and the compliance programme must be capable of generating those reports reliably.

The EU regime, operating through Council regulations, imposes obligations that vary by member state in terms of their domestic implementation and enforcement. There is no single EU-wide compliance-programme framework analogous to OFAC's. Enforcement sits with national competent authorities, and the standards they apply reflect domestic administrative traditions. That said, the EU's ownership and control test (the EU and OFSI treat control, not just ownership, as a basis for catching non-listed entities) means that the scope of entities a programme must screen against is frequently broader under EU rules than under the mechanical 50 percent OFAC ownership threshold.

BIS – the US Bureau of Industry and Security – governs export controls under the Export Administration Regulations (EAR) rather than asset-freeze sanctions. Its compliance expectations overlap with OFAC's in structure: BIS has published its own compliance-programme guidance, which similarly emphasises risk assessment, management commitment, internal controls, and training. For businesses that export controlled items, an integrated programme that addresses both OFAC and BIS requirements is strongly preferable to two parallel but disconnected systems.

The cross-regime lesson is direct: a programme designed solely around OFAC will not be sufficient for a business with EU, UK, or BIS exposure. In our experience, the most common structural failure we see in multi-jurisdictional businesses is an OFAC-calibrated programme that has not been extended to address the control and reporting obligations arising under OFSI or the relevant EU Council regulation.

If a transaction has already been flagged, or an internal audit has surfaced a gap in your screening or reporting capability, an early legal review preserves options that narrow as time passes. Contact Calder & Vance at info@caldervance.com to discuss your position.

What are the key prohibitions OFAC enforces, and how do they shape programme design?

The core prohibitions enforced by OFAC under the major sanctions programmes are: blocking transactions involving designated persons or entities, prohibiting dealings with blocked property, prohibiting the import and export of goods, services, and technology to or from sanctioned programmes, and prohibiting US persons from facilitating transactions that they themselves could not undertake directly. Each prohibition has a distinct implication for how a compliance programme must be designed.

The blocking prohibition means that a programme must screen not just at onboarding but at each material transaction. A counterparty that was clean at onboarding can be designated overnight. Real-time or near-real-time screening against the SDN List (OFAC's Specially Designated Nationals and blocked persons list) and the Consolidated Sanctions List is a minimum expectation. Screening should extend to the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked, even if those entities do not appear on the SDN List by name).

The facilitation prohibition has particularly broad implications for financial intermediaries, professional service firms, and logistics providers. A US bank that processes a payment on behalf of a non-US firm, knowing that the payment ultimately benefits a blocked person, is itself in breach. A compliance programme must therefore address not only direct counterparty exposure but also the risk that the business's services are being used as a conduit. This requires transaction-monitoring capabilities that go beyond simple name-screening.

The prohibition on importing and exporting goods, services, and technology to or from sanctioned programmes intersects heavily with BIS export-control requirements. For manufacturers and exporters, the sanctions compliance programme must be integrated with export-control classification procedures: a shipment that is licenced for export-control purposes may still be sanctionable if the end-user is connected to a blocked person.

What risk flags indicate that a programme needs urgent attention? A business should treat the following as red flags: screening tools that do not cover the 50 percent rule or indirect ownership; audit findings that have not been remediated within a reasonable period; training records that are out of date or do not cover staff whose roles involve third-party payments or counterparty management; and a risk assessment that has not been refreshed since the business entered a new market or product line. In our experience, it is precisely these gaps – each individually addressable – that cumulatively produce the conditions for a serious enforcement outcome.

How is the OFAC compliance standard enforced, and what does that mean for your programme?

OFAC enforcement operates through civil penalties, criminal referrals to the Department of Justice, and – for the most egregious cases – debarment. Civil penalties can be significant, and OFAC has the authority under IEEPA to impose a penalty for each violation separately, which means that a systemic failure across many transactions can produce a cumulative penalty base that is very large. The exact figures for a given enforcement action depend on the statutory maximum, OFAC's guidelines, and the application of aggravating and mitigating factors.

The most direct enforcement-relevant function of a compliance programme is its role in determining those aggravating and mitigating factors. OFAC's penalty guidelines treat the existence of a compliance programme as a mitigating factor. Critically, the programme must be real: a programme that exists in written policy but is not operationalised in screening, training, or testing will receive little or no mitigation credit. OFAC has been explicit that a paper programme is not a credible compliance programme.

A voluntary self-disclosure (VSD) – a proactive report to OFAC by a business that has identified a potential violation – can reduce the applicable penalty base substantially. But a VSD is credible, and its mitigating value is greatest, when it is accompanied by a root-cause analysis and a remediation plan. A business that submits a VSD without a credible remediation plan signals that the same failure could recur. The compliance programme is the vehicle through which a remediation plan is designed and implemented.

OFAC also conducts compliance reviews as part of civil settlement negotiations. In those reviews, OFAC assesses not only what happened in the past but whether the current programme is capable of preventing a recurrence. A business that has taken an enforcement matter seriously, documented its response, and made verifiable improvements to its programme is in a materially different position from one that has done none of those things.

Practitioners advising on OFAC matters note that the timing of a compliance programme enhancement matters. Enhancements made after a violation is identified but before OFAC opens an inquiry carry less weight than enhancements made before any apparent violation. The best time to strengthen a programme is before a problem arises. The second best time is as soon as one is identified.

When should a business involve external sanctions counsel?

A business should involve external sanctions counsel at several identifiable points. Not all of them involve an active enforcement problem. In our experience, many of the most valuable mandates we handle are preventive: assessing a programme before a new market entry, before an acquisition, or before a regulatory change takes effect.

The following situations warrant prompt external advice. First, where a transaction has been flagged by a bank or a screening system and the business is uncertain whether a true match exists. Second, where an internal audit or a third-party review has identified gaps in screening coverage, ownership-chain analysis, or training records. Third, where the business is entering a market or taking on counterparties in a sector that carries elevated sanctions risk. Fourth, where a potential violation has been identified – including a payment that may have involved a blocked person or property – and the business is considering whether to submit a VSD. Fifth, where the business has received a subpoena, an information request, or a cease-and-desist communication from OFAC or a federal law-enforcement body.

There is a common misconception worth correcting directly. Some compliance teams assume that because OFAC does not mandate a specific programme structure, any documented process will suffice for enforcement-mitigation purposes. That is not accurate. OFAC's guidance makes clear that it assesses the quality of the programme: whether the risk assessment is genuinely calibrated to the business's actual exposure, whether training reaches the right people, and whether testing is independent and produces actionable findings. A programme that ticks boxes without addressing real risk is unlikely to produce meaningful mitigation.

We regularly advise financial institutions, trading companies, and technology exporters on both the design of compliant programmes and their defence in enforcement matters. The two functions are deeply connected: the better the programme design, the stronger the enforcement defence.

Related practices

Frequently asked questions

Who administers sanctions compliance programmes under OFAC?
OFAC – the Office of Foreign Assets Control within the US Department of the Treasury – administers and enforces US economic sanctions, including the compliance-programme expectations that apply to businesses subject to its jurisdiction. OFAC's authority derives from IEEPA, TWEA, and specific statutory programmes. It publishes enforcement guidelines and compliance guidance that set out how it weighs a firm's compliance measures in any penalty determination. OFAC coordinates with the Department of Justice on criminal referrals and with BIS on export-control matters.
What does OFAC prohibit in relation to sanctions compliance programmes?
OFAC does not prohibit having a weak programme; it treats programme quality as an enforcement factor. The substantive prohibitions it enforces – blocking transactions with designated persons, prohibiting dealings in blocked property, restricting imports and exports connected to sanctioned programmes, and prohibiting facilitation of prohibited transactions by US persons – each generate specific compliance obligations. A programme that does not address all of the relevant prohibitions applicable to a business's activities will leave material exposure unmitigated. OFAC specifically expects screening to cover the 50 percent rule and indirect ownership.
How is sanctions compliance enforced under OFAC?
OFAC enforces through civil penalties, which can be substantial and are calculated per-violation under applicable statutory maxima and OFAC's penalty guidelines. It also refers egregious cases to the Department of Justice for criminal prosecution. A voluntary self-disclosure (VSD) can materially reduce the penalty base, and the quality of a business's compliance programme is a significant mitigating factor. Conversely, a paper programme with no operational substance will not receive mitigation credit and may itself be treated as evidence of reckless disregard.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.