INTERNATIONAL TRADE LAW
Sanctions Compliance: How to Assess and Manage Risk

You assess and manage sanctions compliance by building a risk-based program around the five components OFAC laid out in its 2019 Framework for OFAC Compliance Commitments: management commitment, risk assessment, internal controls, testing and auditing, and training. OFAC does not require a one-size-fits-all program. It expects a program sized to your actual risk — which means the assessment comes first, and everything else follows from it.
Why “Risk-Based” Is the Whole Game
OFAC sanctions apply to all U.S. persons on a strict-liability basis: a prohibited transaction is a violation whether or not you intended it. But OFAC also makes clear that the existence and quality of a compliance program is a central factor in how it responds to a violation. A company with a genuine, risk-calibrated program is treated very differently from one with a paper policy nobody follows. So “managing” sanctions compliance is really about matching the strength of your controls to where your exposure actually lies.
The Five Components, in Practice
OFAC’s framework is the recognized standard. Here is what each component means operationally.
| Component | What OFAC expects | What it looks like day to day |
|---|---|---|
| Management commitment | Senior leadership backs and funds the program | Named compliance officer, real budget, board visibility |
| Risk assessment | Identify your specific exposure | Map customers, suppliers, geographies, products |
| Internal controls | Policies that catch prohibited dealings | Screening, escalation, recordkeeping procedures |
| Testing and auditing | Independent check that controls work | Periodic audit, sample testing, gap remediation |
| Training | Staff understand their role | Role-specific, recurring, documented |
Step One: Assess the Risk
The risk assessment is the foundation, and OFAC weighs it heavily. A useful assessment looks at the points where sanctions exposure enters your business:
- Customers and counterparties — who they are, where they are, and who owns them.
- Geographies — whether you touch sanctioned or high-risk jurisdictions directly or through intermediaries.
- Products and services — whether anything you sell has dual-use or controlled characteristics.
- Supply chain and intermediaries — distributors, freight forwarders, and agents who can introduce risk you do not see.
The output is a written, ranked picture of where a violation is most likely to occur. That ranking tells you where to concentrate controls — heavy screening and diligence on high-risk channels, lighter touch on low-risk ones.
Step Two: Build Controls That Match the Risk
Internal controls turn the assessment into action. The core control is screening counterparties against OFAC’s SDN list and other restricted-party lists — and looking through ownership, because under OFAC’s 50 Percent Rule an entity owned 50% or more by blocked persons is itself blocked even if unlisted. Around screening sit the supporting controls: written policies, a defined escalation path for potential matches, and recordkeeping that preserves what you checked and decided.
Step Three: Test, Audit, and Train
A program you never check is a program you cannot rely on. Periodic independent testing — sampling transactions, re-running screens, probing for gaps — confirms the controls work and creates the evidence that they do. Training closes the loop: the people in sales, procurement, and finance who actually encounter risk need recurring, role-specific instruction on what to flag and how.
Managing a Violation If One Occurs
Even strong programs occasionally miss something. How you respond shapes the outcome. A qualifying voluntary self-disclosure to OFAC generally halves the base civil penalty in a non-egregious case, and substantial cooperation short of disclosure still earns meaningful credit. The civil maximum itself is steep — as of 2026, the greater of roughly $377,700 or twice the transaction value per violation, adjusted annually for inflation — so the discount for doing the right thing is substantial. Build a self-disclosure decision into the program before you ever need it.
Frequently Asked Questions
What framework should a U.S. company use for sanctions compliance?
OFAC’s 2019 Framework for OFAC Compliance Commitments, which sets out five components: management commitment, risk assessment, internal controls, testing and auditing, and training. It is the recognized standard and the lens OFAC uses when evaluating a program.
Does a small company really need a sanctions compliance program?
Yes, scaled to its risk. OFAC expects a risk-based program, not a particular size — but liability is strict and applies to every U.S. person, so even a small importer or exporter needs documented screening and controls proportional to its exposure.
What is the most important part of the program?
The risk assessment. It determines where your real exposure is and therefore how strong every other control needs to be. OFAC weighs the quality of the risk assessment heavily.
How does having a program reduce penalties?
OFAC treats the existence and quality of a compliance program as a key factor in enforcement, and a voluntary self-disclosure made through your own program can roughly halve the base civil penalty in a non-egregious case.
A sanctions program is only worth what its risk assessment and controls can withstand under scrutiny. Reidel Law Firm builds and audits OFAC-aligned compliance programs for a predictable flat fee: get a flat-fee compliance memo sized to your actual risk.


