INTERNATIONAL TRADE LAW
How to Comply With OFAC Sanctions Regulations

To comply with OFAC regulations, build a risk-based sanctions compliance program around the five components OFAC itself publishes, screen every counterparty against the SDN List and the 50 Percent Rule, get a license before touching anything blocked, and keep your records for ten years. Compliance is not a one-time checklist — it is an ongoing system. Here is how to stand one up.
Start With OFAC’s Five Components
In 2019 OFAC published A Framework for OFAC Compliance Commitments. It is the closest thing to an official rubric, because OFAC weighs these five elements when it evaluates a program during enforcement.
| Component | What to put in place |
|---|---|
| Management commitment | Name a compliance owner, fund the program, and have leadership endorse the policy in writing |
| Risk assessment | Document exposure across customers, products, geographies, and supply chain; update it as the business changes |
| Internal controls | Written policies and procedures to identify, escalate, report, and record sanctions activity |
| Testing and auditing | Independent, periodic checks that the controls work — and fixes when they do not |
| Training | Role-specific training for staff who touch onboarding, payments, shipping, or sales |
Size each element to your risk. A formal sanctions risk assessment is the foundation everything else rests on, and training your team is what makes the controls hold in daily operations.
Screen the Right Things, the Right Way
Screening is the operational heart of compliance, and most violations trace back to a screening gap.
- Check the SDN List for customers, vendors, agents, banks, and shippers — at onboarding and on an ongoing basis, since the list updates co