INTERNATIONAL TRADE LAW

Sanctions Risk Assessment: A Practical Guide

A sanctions risk assessment is the exercise of mapping where your business is most likely to touch a sanctioned party or country, so you can size your controls to match. It is the second of the five components in OFAC’s compliance Framework, and in practice it is the one everything else depends on — your screening, training, and audits should all be calibrated to the risks this step uncovers. Done honestly, it tells you where to spend and where you are over-investing.

Why risk assessment comes first

The Office of Foreign Assets Control (OFAC) enforces sanctions on a strict-liability basis, so a prohibited transaction is a violation whether or not you knew. You cannot eliminate that exposure, but you can find it before it finds you. A risk assessment turns a vague sense that “sanctions might apply to us” into a specific list of the customers, routes, and products that actually carry risk — which is exactly what lets you build a compliance program that is neither careless nor wastefully heavy.

OFAC expects the assessment to be routine, not one-and-done. Your customer base, your markets, and the sanctions landscape all move, so the assessment is a living document you revisit on a set cadence and after any material change.

The four risk categories to map

Most sanctions risk falls into four buckets. Work through each one against your real operations rather than in the abstract.

Risk categoryQuestions to ask
Customer / counterpartyWho are our customers, vendors, intermediaries, and owners? Are any in higher-risk sectors or near sanctioned networks?
GeographicDo we touch comprehensively sanctioned jurisdictions or high-risk transshipment points — directly or through a distributor?
Product / serviceCould our goods, software, or technology be controlled, dual-use, or attractive for diversion?
Channel /