INTERNATIONAL TRADE LAW

How to Comply With OFAC Sanctions Regulations

To comply with OFAC regulations, build a risk-based sanctions compliance program around the five components OFAC itself publishes, screen every counterparty against the SDN List and the 50 Percent Rule, get a license before touching anything blocked, and keep your records for ten years. Compliance is not a one-time checklist — it is an ongoing system. Here is how to stand one up.

Start With OFAC’s Five Components

In 2019 OFAC published A Framework for OFAC Compliance Commitments. It is the closest thing to an official rubric, because OFAC weighs these five elements when it evaluates a program during enforcement.

ComponentWhat to put in place
Management commitmentName a compliance owner, fund the program, and have leadership endorse the policy in writing
Risk assessmentDocument exposure across customers, products, geographies, and supply chain; update it as the business changes
Internal controlsWritten policies and procedures to identify, escalate, report, and record sanctions activity
Testing and auditingIndependent, periodic checks that the controls work — and fixes when they do not
TrainingRole-specific training for staff who touch onboarding, payments, shipping, or sales

Size each element to your risk. A formal sanctions risk assessment is the foundation everything else rests on, and training your team is what makes the controls hold in daily operations.

Screen the Right Things, the Right Way

Screening is the operational heart of compliance, and most violations trace back to a screening gap.

  • Check the SDN List for customers, vendors, agents, banks, and shippers — at onboarding and on an ongoing basis, since the list updates constantly.
  • Apply the 50 Percent Rule. An unlisted company is still blocked if blocked persons own 50% or more of it in the aggregate. That means looking through to beneficial owners, not just matching names.
  • Watch the goods and destinations, not only the parties, because activity- and country-based programs can prohibit a deal even when every name comes back clean.

For the mechanics, see our guides on the sanctions screening process and denied-party screening in exports.

License Before You Touch Anything Blocked

If a transaction would otherwise be prohibited, the lawful path is an OFAC license. A general license is a standing authorization in the regulations that you self-qualify for and document; a specific license is case-by-case written permission you must apply for. Never assume a deal is fine because “it’s humanitarian” or “it’s just spare parts” — confirm a license covers it first. See how to apply for OFAC licenses.

Record, Report, and Block

Three obligations are easy to overlook and expensive to miss:

  • Recordkeeping — ten years. As of a 2025 final rule, you must keep records of sanctions-relevant transactions for ten years (up from five). The statute of limitations for violations is now ten years as well, so your records and your liability window line up.
  • Blocking. If property of a blocked person comes into your control, you must freeze it — you cannot return or transfer it — and report the blocking to OFAC, generally within 10 business days.
  • Rejected transactions. If you decline a transaction because of sanctions, you generally must report that rejection to OFAC, also within 10 business days.

Maintain the Program

Compliance decays without upkeep. Re-run your risk assessment when you enter new markets or add products, refresh screening against the latest lists, retrain staff, and audit the controls. When something goes wrong, OFAC’s enforcement response turns heavily on whether you had a real program and acted on it.

Frequently Asked Questions

Do I need expensive screening software? Not always. Risk drives the tooling. A low-volume business may screen against OFAC’s free search tool with documented procedures; high-volume or high-risk operations usually need automated screening.

How often should I screen existing customers? Re-screen against updated lists on a regular cadence and at key events (renewals, ownership changes). The SDN List changes frequently, so a one-time check at onboarding is not enough.

Is intent a defense? No. OFAC civil penalties are strict-liability. A strong, well-documented program is your best protection because it reduces both the chance of a violation and the penalty if one occurs.

What records actually matter? Screening results (including hits cleared and why), licenses relied on, beneficial-ownership checks, training logs, and audit findings — all retained for ten years.

A program that satisfies OFAC has to fit your specific customers, products, and routes — a generic template will leave gaps. Reidel Law Firm delivers a flat-fee import/export compliance memo that maps your exposure and lays out the controls you actually need. Get an export compliance memo →

← All articles