INTERNATIONAL TRADE LAW

How to Comply With OFAC Sanctions Regulations

To comply with OFAC regulations, build a risk-based sanctions compliance program around the five components OFAC itself publishes, screen every counterparty against the SDN List and the 50 Percent Rule, get a license before touching anything blocked, and keep your records for ten years. Compliance is not a one-time checklist — it is an ongoing system. Here is how to stand one up.

Start With OFAC’s Five Components

In 2019 OFAC published A Framework for OFAC Compliance Commitments. It is the closest thing to an official rubric, because OFAC weighs these five elements when it evaluates a program during enforcement.

ComponentWhat to put in place
Management commitmentName a compliance owner, fund the program, and have leadership endorse the policy in writing
Risk assessmentDocument exposure across customers, products, geographies, and supply chain; update it as the business changes
Internal controlsWritten policies and procedures to identify, escalate, report, and record sanctions activity
Testing and auditingIndependent, periodic checks that the controls work — and fixes when they do not
TrainingRole-specific training for staff who touch onboarding, payments, shipping, or sales

Size each element to your risk. A formal sanctions risk assessment is the foundation everything else rests on, and training your team is what makes the controls hold in daily operations.

Screen the Right Things, the Right Way

Screening is the operational heart of compliance, and most violations trace back to a screening gap.

  • Check the SDN List for customers, vendors, agents, banks, and shippers — at onboarding and on an ongoing basis, since the list updates co