Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFAC

Sanctions compliance programmes under OFAC: legal support

A US-headquartered technology business acquires a European subsidiary and assumes responsibility for its trade relationships overnight. The subsidiary's counterparty list has never been screened against the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). One distributor in a third market is part-owned by a designated person. Under OFAC, that may mean the business has been conducting prohibited transactions since the acquisition closed – and did not know it.

Sanctions compliance programmes under OFAC are the structured, documented controls that prevent a business from triggering the prohibitions administered by the Office of Foreign Assets Control. OFAC's own framework guidance identifies five essential elements: management commitment, risk assessment, internal controls, testing and auditing, and training. A programme that addresses all five – and is calibrated to the specific risk profile of the business – is the primary mitigant in any enforcement proceeding.

This page sets out how OFAC evaluates a compliance programme, where the design process begins, how the US regime compares with OFSI and the EU, and what Calder & Vance does for clients who need their programme built, repaired, or stress-tested against current enforcement expectations.

What does OFAC expect from a sanctions compliance programme?

OFAC expects a programme that is specific to the business, not a generic policy document. The five-element standard – management commitment, risk assessment, internal controls, testing and auditing, and training – appears in OFAC's published framework guidance and is applied directly in enforcement decisions. A programme that can demonstrate each element, with evidence, is treated as a significant mitigating factor when a violation occurs.

Management commitment means that the programme has visible senior-level ownership. This is not a compliance-function issue alone. The board and executive leadership must be demonstrably involved in setting the risk appetite and receiving the results of audits. OFAC has consistently noted, in enforcement decisions, that a lack of management support for the compliance function is an aggravating factor.

Risk assessment is the technical core. It requires the business to map its products, services, customers, counterparties, intermediaries, and geographies against the sanctions programmes that are relevant to it. A financial institution has a very different profile from a manufacturer of industrial equipment – and the risk assessment must reflect that difference. Generic assessments, templated from another industry or another regime, do not satisfy this requirement in our experience.

Internal controls are the operational procedures: who screens, when, against which lists, through which tools, and with what escalation path. They must cover onboarding, transaction monitoring, payment processing, and any goods or technology flows that intersect with the Commerce Control List (CCL) administered by BIS. Where the business has subsidiaries or joint ventures, the controls must extend to those entities or the gap will be found.

How does an OFAC risk assessment work in practice?

An OFAC risk assessment begins with identifying the sanctions programmes that are relevant to the business and then mapping the exposure within each one. The output is a risk register that assigns likelihood and severity scores to each identified exposure and drives the design of the internal controls.

In a recent matter, a financial services firm had maintained a compliance programme for several years but had not re-run its risk assessment after entering a new product line involving digital-asset settlement. We assessed the product flows against current OFAC programme guidance, identified two counterparty categories that the existing screening logic did not reach, and redesigned the transaction-monitoring rules to close those gaps. The programme was then tested against a sample of historical transactions before being presented to the compliance committee.

The risk assessment must also capture secondary-sanctions risk – the exposure that arises not from a direct dealing with a sanctioned person, but from a transaction that is structured in a way that could trigger OFAC's secondary-sanctions authorities under IEEPA. This is a point where many programme designs fall short. Businesses that have no US nexus in their primary operations can still be exposed if they deal in US dollars, route payments through US correspondent banks, or involve US-person employees in a transaction. Have you mapped those connection points in your own programme?

We regularly advise businesses that underestimate the aggregation risk under the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked). A counterparty that is not on the SDN List may still be a blocked person if the ownership chain runs through a listed entity. Standard screening tools check the name; they do not always follow the ownership structure. The risk assessment must address this gap explicitly.

The position above covers the standard assessment for a single-entity business. Your facts – the counterparty mix, the product type, the payment routes, the jurisdictions of your subsidiaries – change the analysis significantly. For an assessment of your OFAC exposure, contact Calder & Vance at info@caldervance.com.

How does OFAC's compliance framework compare with OFSI and the EU?

All three major Western regimes now expect a documented, risk-based compliance programme, but the standards differ in scope, ownership test, and enforcement posture – and those differences have direct consequences for a business that operates across multiple jurisdictions.

OFAC's five-element framework is the most prescriptive in published form. It is a US domestic standard that carries extraterritorial reach through the secondary-sanctions authorities under IEEPA: non-US businesses that deal in US dollars or involve US persons can be pulled into OFAC's jurisdiction even if they have no US office. That extraterritorial dimension means that many non-US businesses should be designing to OFAC standards regardless of where they are incorporated.

OFSI – the Office of Financial Sanctions Implementation, which administers UK financial sanctions under the Sanctions and Anti-Money Laundering Act – operates a broadly similar five-element expectation in its enforcement guidance. However, the ownership-and-control test under UK law is not purely mechanical. Where OFAC applies a fixed 50 percent ownership threshold, OFSI and the EU apply a combined ownership-and-control analysis that can catch entities where no single listed person meets the percentage threshold but the aggregate pattern of control does. A programme designed only to the OFAC standard may miss that second dimension.

The EU Council regulations impose direct obligations on EU-person businesses, including a reporting requirement when a relevant asset or fund is held. EU sanctions also carry a strict-liability element in most member-state implementing laws: intent is not a defence to the underlying prohibition, only to the criminal penalty. A business operating in both the US and EU markets must design a programme that satisfies both standards. Where the regimes are in tension – as occasionally happens when the EU's Blocking Regulation comes into play – the analysis requires specific legal input. That is a topic we address in our cross-border diligence work.

What are the most common gaps in OFAC compliance programmes?

The most common gaps we find are not in policy documents – those are usually in place. They are in the translation of policy into operational procedure, and in the maintenance of that procedure over time as the business changes.

Screening logic that was set up at programme launch is often not updated when OFAC adds new programmes or amends existing ones. The SDN List, the Entity List administered by BIS, and the Consolidated List maintained by the UN Security Council are updated on a rolling basis. A screening tool that is not refreshed against current list versions is not providing the protection the programme claims to offer. In our cross-border practice, we see this problem repeatedly in businesses that licence a screening tool but do not maintain a governance process around list-update frequency and exception handling.

A second gap is in the treatment of general licences (standing authorisations that permit a defined category of transactions without a separate application). General licences expire, are amended, and are sometimes revoked. A business that has built a transaction pathway around a general licence without a monitoring obligation to track its current status can find itself operating outside the licence without realising it. Verify the current position before relying on any general licence.

Third: the training element is frequently reduced to an annual e-learning module. OFAC's framework expects training to be role-specific, current, and demonstrably completed. A compliance officer's training requirements differ from those of a relationship manager in a sanctions-exposed corridor or a product manager responsible for technology exports. Generic training does not satisfy that standard and will not serve as a mitigating factor in enforcement.

Fourth – and this is the gap that produces the most acute risk – is the failure to address a programme to the full scope of OFAC's jurisdiction. OFAC's authority extends to US persons worldwide, to transactions that transit the US financial system, and to non-US entities that involve US-person employees or directors in a prohibited transaction. A programme that scopes itself narrowly to the entity's country of incorporation may leave material exposure unaddressed. Is your programme scoped to OFAC's jurisdictional reach, or only to your domestic regulatory perimeter?

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential initial review.

When does an OFAC compliance programme need a voluntary self-disclosure?

A voluntary self-disclosure (VSD) to OFAC – a proactive report of an apparent violation before the regulator identifies it independently – is one of the most consequential decisions in sanctions enforcement, and the programme design must provide a clear pathway to it.

OFAC treats a timely, accurate VSD as a significant mitigating factor. The decision to file is not automatic. It requires a scoping exercise to characterise the apparent violation, an assessment of whether the transaction was egregious or non-egregious, and a review of whether other regulators – including OFSI, the relevant EU competent authority, or BIS – need to be notified simultaneously. Programmes that have no documented escalation path to the general counsel and senior management for this decision leave the business exposed to poorly timed or incomplete disclosures, which can convert a mitigating factor into an aggravating one.

Record-keeping is the foundation of any VSD. OFAC expects businesses to maintain records sufficient to reconstruct the transaction, the screening decision, and the decision-making chain. A programme that does not specify retention obligations – or that relies on retention policies designed for a different regulatory purpose – creates a gap that the enforcement process will find. Sanctions and export-control record-keeping requirements run for a significant period; verify the current requirement for your specific regime and transaction type before relying on a generic policy.

A common misconception about OFAC compliance programmes

A frequent view among in-house teams is that once an OFAC compliance programme has been written and approved, the work is done until the next scheduled audit cycle. That view does not reflect how OFAC evaluates programmes in enforcement proceedings.

OFAC assesses a programme as it existed at the time of the apparent violation and as it has been maintained since. A programme that was adequate when written but has not been updated to reflect changes in the business – new products, new geographies, new ownership structures, new OFAC designations in a relevant programme – will not receive full mitigation credit. The relevant question is not whether the programme existed; it is whether it was adequate for the risk the business was actually running at the time of the conduct.

We regularly advise businesses that discover this gap during a transaction or an internal review. Remediation – updating the risk assessment, revising the internal controls, retraining affected staff, and documenting the changes – takes time. Starting that work before a regulator has made an inquiry preserves the VSD option and the mitigation credit that goes with it. The alternative is remediating under enforcement pressure, which is a significantly more constrained process.

How Calder & Vance supports sanctions compliance programme design under OFAC

Calder & Vance advises businesses at every stage of the OFAC compliance programme lifecycle – from the initial risk assessment and programme design, through testing and audit, to remediation following a compliance failure or an enforcement inquiry.

For a business building a programme for the first time, we assess eligibility for the relevant general licences, design the five-element structure against the specific risk profile, and document the programme to the standard OFAC applies in enforcement. We also address the cross-border dimension: for clients that operate in the UK or EU, we align the OFAC programme with OFSI and EU expectations so that the business is not running duplicative or conflicting compliance procedures.

For a business that already has a programme but needs it stress-tested, we test the screening logic, map the ownership and control chain for the ten highest-risk counterparties, and identify gaps between the written policy and the operational practice. We then produce a gap register with prioritised remediation steps and, where appropriate, prepare the documentation for a VSD if an apparent violation has been identified.

For businesses facing an OFAC inquiry or enforcement proceeding, we scope the apparent violation, advise on voluntary self-disclosure, and prepare the penalty defence. That work draws on our experience in OFAC enforcement and our understanding of how the five-element framework is applied in practice. The social proof for that experience is in the matters we have handled: cross-border businesses, financial institutions, and exporters operating in the most complex sanctions environments.

Related practices

Frequently asked questions

How long does designing a sanctions compliance programme take under OFAC?
The timeline depends on the complexity of the business and the current state of its controls. A focused risk assessment and programme design for a single-entity business with a defined counterparty set can be completed in a matter of weeks. A multi-entity, multi-jurisdictional programme requiring alignment across OFAC, OFSI, and EU standards will take longer. We agree a defined scope and timeline at the outset; fixed-fee entry points are available for scoped engagements. The urgency of any apparent violation in the background affects the sequencing significantly.
What are the main risks in sanctions compliance programmes under OFAC?
The main risks are gaps between written policy and operational practice; screening logic that does not follow the ownership chain to the 50 percent threshold; general licences that have been amended or revoked without the business noticing; and training that is not role-specific. A secondary risk is a programme that is scoped to the entity's country of incorporation rather than to OFAC's full jurisdictional reach, which includes US-dollar transactions and the involvement of US persons anywhere in the world. Each of these gaps is addressable before an enforcement inquiry arises.
Do we need specialist counsel for sanctions compliance programmes?
For a business with material sanctions exposure – financial institutions, exporters of controlled goods, businesses with counterparties in high-risk jurisdictions, or businesses that have recently acquired a new entity – specialist counsel is not optional. OFAC's enforcement decisions consistently distinguish between programmes built with legal input and those assembled from generic templates. The distinction matters at the penalty stage. In our experience, the cost of building a programme correctly is a fraction of the cost of defending one that did not hold under scrutiny.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.