A US-headquartered technology business acquires a European subsidiary and assumes responsibility for its trade relationships overnight. The subsidiary's counterparty list has never been screened against the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). One distributor in a third market is part-owned by a designated person. Under OFAC, that may mean the business has been conducting prohibited transactions since the acquisition closed – and did not know it.
Sanctions compliance programmes under OFAC are the structured, documented controls that prevent a business from triggering the prohibitions administered by the Office of Foreign Assets Control. OFAC's own framework guidance identifies five essential elements: management commitment, risk assessment, internal controls, testing and auditing, and training. A programme that addresses all five – and is calibrated to the specific risk profile of the business – is the primary mitigant in any enforcement proceeding.
This page sets out how OFAC evaluates a compliance programme, where the design process begins, how the US regime compares with OFSI and the EU, and what Calder & Vance does for clients who need their programme built, repaired, or stress-tested against current enforcement expectations.
What does OFAC expect from a sanctions compliance programme?
OFAC expects a programme that is specific to the business, not a generic policy document. The five-element standard – management commitment, risk assessment, internal controls, testing and auditing, and training – appears in OFAC's published framework guidance and is applied directly in enforcement decisions. A programme that can demonstrate each element, with evidence, is treated as a significant mitigating factor when a violation occurs.
Management commitment means that the programme has visible senior-level ownership. This is not a compliance-function issue alone. The board and executive leadership must be demonstrably involved in setting the risk appetite and receiving the results of audits. OFAC has consistently noted, in enforcement decisions, that a lack of management support for the compliance function is an aggravating factor.
Risk assessment is the technical core. It requires the business to map its products, services, customers, counterparties, intermediaries, and geographies against the sanctions programmes that are relevant to it. A financial institution has a very different profile from a manufacturer of industrial equipment – and the risk assessment must reflect that difference. Generic assessments, templated from another industry or another regime, do not satisfy this requirement in our experience.
Internal controls are the operational procedures: who screens, when, against which lists, through which tools, and with what escalation path. They must cover onboarding, transaction monitoring, payment processing, and any goods or technology flows that intersect with the Commerce Control List (CCL) administered by BIS. Where the business has subsidiaries or joint ventures, the controls must extend to those entities or the gap will be found.
How does an OFAC risk assessment work in practice?
An OFAC risk assessment begins with identifying the sanctions programmes that are relevant to the business and then mapping the exposure within each one. The output is a risk register that assigns likelihood and severity scores to each identified exposure and drives the design of the internal controls.
In a recent matter, a financial services firm had maintained a compliance programme for several years but had not re-run its risk assessment after entering a new product line involving digital-asset settlement. We assessed the product flows against current OFAC programme guidance, identified two counterparty categories that the existing screening logic did not reach, and redesigned the transaction-monitoring rules to close those gaps. The programme was then tested against a sample of historical transactions before being presented to the compliance committee.
The risk assessment must also capture secondary-sanctions risk – the exposure that arises not from a direct dealing with a sanctioned person, but from a transaction that is structured in a way that could trigger OFAC's secondary-sanctions authorities under IEEPA. This is a point where many programme designs fall short. Businesses that have no US nexus in their primary operations can still be exposed if they deal in US dollars, route payments through US correspondent banks, or involve US-person employees in a transaction. Have you mapped those connection points in your own programme?
We regularly advise businesses that underestimate the aggregation risk under the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked). A counterparty that is not on the SDN List may still be a blocked person if the ownership chain runs through a listed entity. Standard screening tools check the name; they do not always follow the ownership structure. The risk assessment must address this gap explicitly.
The position above covers the standard assessment for a single-entity business. Your facts – the counterparty mix, the product type, the payment routes, the jurisdictions of your subsidiaries – change the analysis significantly. For an assessment of your OFAC exposure, contact Calder & Vance at info@caldervance.com.
How does OFAC's compliance framework compare with OFSI and the EU?
All three major Western regimes now expect a documented, risk-based compliance programme, but the standards differ in scope, ownership test, and enforcement posture – and those differences have direct consequences for a business that operates across multiple jurisdictions.
OFAC's five-element framework is the most prescriptive in published form. It is a US domestic standard that carries extraterritorial reach through the secondary-sanctions authorities under IEEPA: non-US businesses that deal in US dollars or involve US persons can be pulled into OFAC's jurisdiction even if they have no US office. That extraterritorial dimension means that many non-US businesses should be designing to OFAC standards regardless of where they are incorporated.
OFSI – the Office of Financial Sanctions Implementation, which administers UK financial sanctions under the Sanctions and Anti-Money Laundering Act – operates a broadly similar five-element expectation in its enforcement guidance. However, the ownership-and-control test under UK law is not purely mechanical. Where OFAC applies a fixed 50 percent ownership threshold, OFSI and the EU apply a combined ownership-and-control analysis that can catch entities where no single listed person meets the percentage threshold but the aggregate pattern of control does. A programme designed only to the OFAC standard may miss that second dimension.
The EU Council regulations impose direct obligations on EU-person businesses, including a reporting requirement when a relevant asset or fund is held. EU sanctions also carry a strict-liability element in most member-state implementing laws: intent is not a defence to the underlying prohibition, only to the criminal penalty. A business operating in both the US and EU markets must design a programme that satisfies both standards. Where the regimes are in tension – as occasionally happens when the EU's Blocking Regulation comes into play – the analysis requires specific legal input. That is a topic we address in our cross-border diligence work.
What are the most common gaps in OFAC compliance programmes?
The most common gaps we find are not in policy documents – those are usually in place. They are in the translation of policy into operational procedure, and in the maintenance of that procedure over time as the business changes.
Screening logic that was set up at programme launch is often not updated when OFAC adds new programmes or amends existing ones. The SDN List, the Entity List administered by BIS, and the Consolidated List maintained by the UN Security Council are updated on a rolling basis. A screening tool that is not refreshed against current list versions is not providing the protection the programme claims to offer. In our cross-border practice, we see this problem repeatedly in businesses that licence a screening tool but do not maintain a governance process around list-update frequency and exception handling.
A second gap is in the treatment of general licences (standing authorisations that permit a defined category of transactions without a separate application). General licences expire, are amended, and are sometimes revoked. A business that has built a transaction pathway around a general licence without a monitoring obligation to track its current status can find itself operating outside the licence without realising it. Verify the current position before relying on any general licence.
Third: the training element is frequently reduced to an annual e-learning module. OFAC's framework expects training to be role-specific, current, and demonstrably completed. A compliance officer's training requirements differ from those of a relationship manager in a sanctions-exposed corridor or a product manager responsible for technology exports. Generic training does not satisfy that standard and will not serve as a mitigating factor in enforcement.
Fourth – and this is the gap that produces the most acute risk – is the failure to address a programme to the full scope of OFAC's jurisdiction. OFAC's authority extends to US persons worldwide, to transactions that transit the US financial system, and to non-US entities that involve US-person employees or directors in a prohibited transaction. A programme that scopes itself narrowly to the entity's country of incorporation may leave material exposure unaddressed. Is your programme scoped to OFAC's jurisdictional reach, or only to your domestic regulatory perimeter?
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential initial review.
When does an OFAC compliance programme need a voluntary self-disclosure?
A voluntary self-disclosure (VSD) to OFAC – a proactive report of an apparent violation before the regulator identifies it independently – is one of the most consequential decisions in sanctions enforcement, and the programme design must provide a clear pathway to it.
OFAC treats a timely, accurate VSD as a significant mitigating factor. The decision to file is not automatic. It requires a scoping exercise to characterise the apparent violation, an assessment of whether the transaction was egregious or non-egregious, and a review of whether other regulators – including OFSI, the relevant EU competent authority, or BIS – need to be notified simultaneously. Programmes that have no documented escalation path to the general counsel and senior management for this decision leave the business exposed to poorly timed or incomplete disclosures, which can convert a mitigating factor into an aggravating one.
Record-keeping is the foundation of any VSD. OFAC expects businesses to maintain records sufficient to reconstruct the transaction, the screening decision, and the decision-making chain. A programme that does not specify retention obligations – or that relies on retention policies designed for a different regulatory purpose – creates a gap that the enforcement process will find. Sanctions and export-control record-keeping requirements run for a significant period; verify the current requirement for your specific regime and transaction type before relying on a generic policy.
A common misconception about OFAC compliance programmes
A frequent view among in-house teams is that once an OFAC compliance programme has been written and approved, the work is done until the next scheduled audit cycle. That view does not reflect how OFAC evaluates programmes in enforcement proceedings.
OFAC assesses a programme as it existed at the time of the apparent violation and as it has been maintained since. A programme that was adequate when written but has not been updated to reflect changes in the business – new products, new geographies, new ownership structures, new OFAC designations in a relevant programme – will not receive full mitigation credit. The relevant question is not whether the programme existed; it is whether it was adequate for the risk the business was actually running at the time of the conduct.
We regularly advise businesses that discover this gap during a transaction or an internal review. Remediation – updating the risk assessment, revising the internal controls, retraining affected staff, and documenting the changes – takes time. Starting that work before a regulator has made an inquiry preserves the VSD option and the mitigation credit that goes with it. The alternative is remediating under enforcement pressure, which is a significantly more constrained process.
How Calder & Vance supports sanctions compliance programme design under OFAC
Calder & Vance advises businesses at every stage of the OFAC compliance programme lifecycle – from the initial risk assessment and programme design, through testing and audit, to remediation following a compliance failure or an enforcement inquiry.
For a business building a programme for the first time, we assess eligibility for the relevant general licences, design the five-element structure against the specific risk profile, and document the programme to the standard OFAC applies in enforcement. We also address the cross-border dimension: for clients that operate in the UK or EU, we align the OFAC programme with OFSI and EU expectations so that the business is not running duplicative or conflicting compliance procedures.
For a business that already has a programme but needs it stress-tested, we test the screening logic, map the ownership and control chain for the ten highest-risk counterparties, and identify gaps between the written policy and the operational practice. We then produce a gap register with prioritised remediation steps and, where appropriate, prepare the documentation for a VSD if an apparent violation has been identified.
For businesses facing an OFAC inquiry or enforcement proceeding, we scope the apparent violation, advise on voluntary self-disclosure, and prepare the penalty defence. That work draws on our experience in OFAC enforcement and our understanding of how the five-element framework is applied in practice. The social proof for that experience is in the matters we have handled: cross-border businesses, financial institutions, and exporters operating in the most complex sanctions environments.
Related practices
- OFSI compliance programme design – UK financial-sanctions programme design and OFSI alignment
- Sanctions compliance audit and testing – Australia – independent testing of sanctions controls under the Australian autonomous-sanctions regime
- Counterparty due diligence – BIS EAR – export-control screening and end-use assessment under the Export Administration Regulations