INTERNATIONAL TRADE LAW
Sanctions Risk Assessment: A Practical Guide

A sanctions risk assessment is the exercise of mapping where your business is most likely to touch a sanctioned party or country, so you can size your controls to match. It is the second of the five components in OFAC’s compliance Framework, and in practice it is the one everything else depends on — your screening, training, and audits should all be calibrated to the risks this step uncovers. Done honestly, it tells you where to spend and where you are over-investing.
Why risk assessment comes first
The Office of Foreign Assets Control (OFAC) enforces sanctions on a strict-liability basis, so a prohibited transaction is a violation whether or not you knew. You cannot eliminate that exposure, but you can find it before it finds you. A risk assessment turns a vague sense that “sanctions might apply to us” into a specific list of the customers, routes, and products that actually carry risk — which is exactly what lets you build a compliance program that is neither careless nor wastefully heavy.
OFAC expects the assessment to be routine, not one-and-done. Your customer base, your markets, and the sanctions landscape all move, so the assessment is a living document you revisit on a set cadence and after any material change.
The four risk categories to map
Most sanctions risk falls into four buckets. Work through each one against your real operations rather than in the abstract.
| Risk category | Questions to ask |
|---|---|
| Customer / counterparty | Who are our customers, vendors, intermediaries, and owners? Are any in higher-risk sectors or near sanctioned networks? |
| Geographic | Do we touch comprehensively sanctioned jurisdictions or high-risk transshipment points — directly or through a distributor? |
| Product / service | Could our goods, software, or technology be controlled, dual-use, or attractive for diversion? |
| Channel / payment | Do we sell through resellers, marketplaces, or agents who obscure the end user? How do funds flow? |
The goal is not a perfect score in each box — it is an honest picture of where the exposure concentrates, so the rest of the program can lean there.
Rate the risks, then respond
Once the map exists, rate each risk by likelihood and impact and decide how to treat it. A risk-based approach means matching the strength of the control to the size of the risk: a domestic customer with a clean profile gets standard screening, while a new counterparty in a high-risk jurisdiction warrants enhanced due diligence — verifying ownership, identifying the true end user, and documenting the rationale before you proceed.
The 50 Percent Rule belongs in this analysis. An entity owned 50% or more, in aggregate, by blocked persons is itself blocked even if it never appears on a list, so ownership — not just the name on the invoice — is part of assessing counterparty risk.
Watch for red flags
Certain patterns recurring in OFAC and export-control guidance signal elevated risk: a customer reluctant to give end-use or end-user information, requests to route shipments through a third country for no commercial reason, addresses that are freight forwarders rather than real businesses, payment from an unrelated third party, or orders that do not fit the customer’s line of work. A red flag is not proof of a violation, but it is a prompt to stop, ask questions, and document the answers before shipping.
Turn the assessment into controls
A risk assessment is only useful if it drives action. Feed the findings directly into your other components: tighten counterparty screening where customer or geographic risk is highest, focus training on the teams handling the riskiest transactions, and document the whole exercise. OFAC now requires records of sanctions-relevant transactions to be kept for ten years (extended from five, effective March 12, 2025), and a dated risk assessment is part of showing you took a reasoned, risk-based approach.
Frequently asked questions
How often should we redo the risk assessment?
At least annually, and again whenever something material changes — a new market, a new product line, an acquisition, or a significant shift in the sanctions landscape. The assessment should track the business, not sit frozen.
What is enhanced due diligence?
A deeper level of investigation for higher-risk counterparties: confirming beneficial ownership, identifying the real end user and end use, checking for adverse information, and recording why you concluded the relationship was permissible.
Does a risk assessment reduce our penalty exposure?
It cannot make strict liability disappear, but a documented, reasoned assessment is evidence of an effective program — which OFAC weighs when deciding whether conduct was egregious and how large a penalty to impose.
Who should own the risk assessment?
Your sanctions compliance officer, with input from sales, operations, and finance — the people who actually know the customers, routes, and products. It is a cross-functional exercise, not a solo legal memo.
A risk assessment is what makes the rest of a sanctions program proportionate instead of guesswork. Reidel Law Firm runs sanctions and export-control risk assessments for U.S. exporters and importers on a flat fee, then hands you a plain-English memo and a prioritized action list: get a flat-fee compliance memo to start.


