INTERNATIONAL TRADE LAW
Sanctions Risk Assessment: A Practical Guide

A sanctions risk assessment is a structured review of where your business is most likely to touch a sanctioned party or jurisdiction — so you can size your controls to the actual risk instead of guessing. It is the foundation of every credible sanctions compliance program, and OFAC expects it. This guide explains what to assess, how to score it, and how to turn the findings into controls that hold up under scrutiny.
A risk assessment is not a one-time document. It is the first of the five components OFAC treats as essential, and it drives the screening and metrics work that follows.
Why a Risk Assessment Comes First
OFAC’s 2019 Framework for OFAC Compliance Commitments sets out five components it considers essential to any sanctions compliance program: management commitment, risk assessment, internal controls, testing and auditing, and training. The framework is explicitly risk-based — it expects a small importer’s program to look different from a global bank’s. You cannot build proportionate controls until you know where your risk actually sits, which is why the assessment comes first.
The point is not to eliminate risk but to find it, rank it, and put your resources where the exposure is highest.
What to Assess
A complete assessment maps four dimensions of your business and asks where each creates sanctions exposure:
| Risk area | What to examine | Higher-risk signals |
|---|---|---|
| Customers | Who you sell to, their owners, their location | Opaque ownership, high-risk jurisdictions, intermediaries |
| Products & services | What you provide and its end uses | Dual-use items, controlled technology, financial services |
| Geographies | Where you ship, source, and bank | Embargoed or adjacent jurisdictions; transshipment hubs |
| Channels | How deals are routed and paid | Freight forwarders, third-party payers, complex payment chains |
For each area, gather the data you already hold — customer records, transaction history, supplier lists — and supplement it with screening results and current OFAC and BIS guidance. The goal is an honest map of your exposure, not a wish list.
Scoring and Prioritizing Risk
Once exposure is mapped, evaluate each identified risk on two axes: likelihood (how probable is contact with a sanctioned party?) and impact (how severe — financial, legal, reputational — if it happens?). A simple high/medium/low rating on each is enough for most businesses. The combination tells you where to act first: a high-likelihood, high-impact risk gets immediate, robust controls; a low/low risk may need only baseline screening.
This prioritization is what makes the program defensible. If you are ever examined, you want to show that your controls were calibrated to a documented assessment — not applied uniformly without thought, and not missing entirely where the risk was greatest.
Turning Findings Into Controls
Each prioritized risk should map to a specific mitigation. Common controls include:
- Restricted-party and country screening at onboarding and before each transaction, scaled up for higher-risk relationships.
- Enhanced due diligence — beneficial-ownership checks and end-use verification where ownership is opaque or the destination is sensitive.
- Internal controls — clear escalation paths, segregation of duties, and recordkeeping so decisions are documented.
- Training for the people who actually touch transactions, focused on the risks your assessment surfaced.
- Periodic re-assessment — at least annually, and whenever your business or the regulatory landscape changes materially.
Frequently Asked Questions
What is a sanctions risk assessment?
It is a structured review of where a business is most exposed to dealing with a sanctioned party or jurisdiction, across its customers, products, geographies, and transaction channels — used to size compliance controls to the actual risk.
Is a sanctions risk assessment legally required?
OFAC’s Framework for OFAC Compliance Commitments treats risk assessment as one of five essential components of a compliance program. While there is no single statute mandating a specific format, OFAC weighs the existence and quality of a risk-based program heavily in enforcement decisions.
How often should I update it?
Reassess at least annually, and immediately after any material change — a new market, product line, acquisition, or significant shift in sanctions rules. A risk assessment that no longer reflects your business gives you little protection.
Who should conduct it?
For most businesses, a cross-functional effort works best: people from compliance, legal, finance, and operations who together understand the customers, products, and money flows. Outside counsel can help structure the assessment and interpret regulatory expectations.
A sound risk assessment turns sanctions compliance from guesswork into a defensible, right-sized program. Reidel Law Firm helps importers and exporters assess sanctions exposure and build controls on flat-fee terms. Get an export compliance memo.


