INTERNATIONAL TRADE LAW
How to Build a Risk-Based Sanctions Compliance Program

A risk-based sanctions compliance program scales your controls to your actual exposure — heavy where the risk is real, light where it is not — instead of applying one generic checklist to every transaction. It is the approach the Office of Foreign Assets Control (OFAC) expects, and the approach OFAC rewards with reduced penalties when something goes wrong. Here is how to build one.
Start With What “Risk-Based” Means
A risk-based program begins with a clear-eyed look at where sanctions risk actually lives in your business: the countries you touch, the customers and intermediaries you deal with, the products you move, and the channels through which money and goods flow. You then concentrate your resources on the highest-risk areas rather than spreading them evenly. A company that sells software to enterprise buyers in low-risk countries needs a lighter program than a freight forwarder routing goods through high-risk transshipment hubs. The point is proportionality.
Use OFAC’s Five Components
In May 2019, OFAC published A Framework for Compliance Commitments, which lays out the five components it considers essential to an effective sanctions compliance program. These are the backbone of any defensible program, and OFAC weighs them directly when deciding how to resolve an enforcement matter.
| Component | What it requires |
|---|---|
| Management commitment | Senior leadership approves the program, gives the compliance function real authority and resources, and appoints a dedicated sanctions officer |
| Risk assessment | A documented, periodic assessment of your sanctions exposure across customers, products, and geographies |
| Internal controls | Written policies, procedures, screening, and escalation that translate the risk assessment into daily practice |
| Testing and auditing | Independent review to confirm the program works and to catch weaknesses before regulators do |
| Training | Role-specific, recurring training so the people who make decisions understand their obligations |
The components reinforce one another. The risk assessment tells you where to put internal controls; testing tells you whether those controls hold; training keeps the people who run them current; and management commitment supplies the authority and budget that make all of it real.
Make the Risk Assessment the Engine
The risk assessment is the component everything else depends on, and it is the one OFAC looks at first. Inventory your touchpoints — who your counterparties are, where they sit, what you sell, and how transactions are paid and shipped — then rate each for sanctions risk. The output is not a binder that sits on a shelf; it is the document that decides where enhanced due diligence applies and where standard screening is enough. Reassess on a set schedule and whenever your business changes: a new market, a new product line, or an acquisition can move your risk profile overnight.
Translate Risk Into Controls
Internal controls are where the program meets the transaction. At minimum that means screening customers and counterparties against OFAC’s Specially Designated Nationals (SDN) List and other restricted-party lists, applying the 50 Percent Rule to catch entities owned by blocked persons, and building clear escalation paths so a screening hit stops the deal and reaches the right person. Many businesses use data analytics and automated screening tools to handle volume, but technology supplements human judgment rather than replacing it.
Test, Train, and Keep It Current
A program you never test is a program you cannot trust. Build in independent audits, fix what they surface, and document both. Pair that with recurring, role-specific training so that sales, finance, logistics, and compliance staff all recognize the red flags relevant to their jobs. Because sanctions programs change constantly, a static program decays — the testing-and-training loop is what keeps it alive. Done well, this structure also limits exposure on the back end: a strong, well-run program is a recognized mitigating factor that can substantially reduce penalties if a violation occurs.
Frequently Asked Questions
Is a sanctions compliance program legally required? There is no one-size-fits-all mandate, but OFAC strongly expects businesses with sanctions exposure to maintain a risk-based program, and the absence of one is treated as an aggravating factor in enforcement.
What are OFAC’s five components? Management commitment, risk assessment, internal controls, testing and auditing, and training — set out in OFAC’s 2019 Framework for Compliance Commitments.
How big does my program need to be? As big as your risk. A risk-based approach means a small, low-exposure business can run a lean program, while a high-exposure business needs more robust controls.
Does a compliance program reduce penalties? Yes. OFAC treats a well-designed, well-implemented program as a mitigating factor that can meaningfully lower a civil penalty.
Need a sanctions compliance program sized to your business? Reidel Law Firm prepares flat-fee Import/Export Compliance Memos and helps build practical, right-sized OFAC compliance programs — with direct access to the trade attorney handling your matter. Get a flat-fee compliance memo →


