INTERNATIONAL TRADE LAW
Sanctions Compliance Program KPIs: What to Measure

The most defensible way to measure a sanctions compliance program is against the five pillars OFAC itself uses to judge one: management commitment, risk assessment, internal controls, testing and auditing, and training — set out in OFAC’s 2019 Framework for Compliance Commitments. Pick two or three KPIs per pillar — screening coverage and match-resolution time for controls, findings-closure rates for testing, completion and role-based depth for training — and you have a dashboard that tells management whether the program works and shows OFAC the same thing if a violation ever surfaces.
Why Sanctions KPIs Matter: Strict Liability and the Penalty Math
OFAC — the Treasury Department’s Office of Foreign Assets Control — enforces U.S. economic sanctions on a strict-liability basis: a company can be civilly penalized for a violation it did not know about and did not intend. What separates a manageable penalty from a catastrophic one is largely the record of the compliance program. The existence and quality of that program is a general factor in OFAC’s Enforcement Guidelines, and a qualifying voluntary self-disclosure (VSD) can cut the base civil penalty by up to 50%.
The measurement stakes also got longer. A 2024 statute extended the limitations period for most sanctions violations from five to ten years, and OFAC extended its recordkeeping requirement to match — records must now be kept for ten years (effective March 2025). Your KPI evidence — screening logs, training records, audit reports — has to survive a decade, because that is how far back an investigation can reach.
The Five Pillars, in Brief
OFAC’s Framework describes five components every sanctions compliance program should have: senior management commitment with real authority and budget; a risk assessment that maps where sanctions exposure actually sits; internal controls (above all, screening) that catch prohibited transactions; independent testing and auditing; and training matched to each role’s risk. The KPIs below measure each pillar directly.
The Sanctions Compliance KPI Table
| KPI | What it measures | Direction | Pillar |
|---|---|---|---|
| Screening coverage | % of customers, vendors, banks, and transactions screened against current OFAC lists | Toward 100% | Internal controls |
| List-update latency | Time from an OFAC list change to its reflection in live screening | Lower | Internal controls |
| Match-resolution time | Time to clear or escalate a potential match | Lower | Internal controls |
| False-positive rate | Share of alerts that are not true matches | Lower, without loosening match logic | Internal controls |
| Escalation rate and time | How fast true matches reach compliance leadership | Faster, fully documented | Management commitment |
| VSD decision time | Time from confirmed issue to a documented disclose/don’t-disclose decision | Lower | Management commitment |
| Budget and headcount vs. risk | Whether resources track the risk assessment | Reviewed at least annually | Management commitment |
| Risk-assessment refresh cadence | How often the assessment is updated, including trigger events | Annual minimum plus event-driven | Risk assessment |
| Pre-launch risk reviews | % of new products, markets, and counterparties assessed before go-live | Toward 100% | Risk assessment |
| Audit findings closure rate | Share of audit findings remediated on schedule | Higher | Testing and auditing |
| Open-finding aging | How long findings stay unresolved past their due date | Lower | Testing and auditing |
| Training completion rate | % of in-scope employees current on sanctions training | Toward 100% | Training |
| Role-based training depth | Whether high-risk roles get enhanced, scenario-based training | Expanding with risk | Training |
Internal Controls: Screening Is Where Programs Live or Die
Internal controls are the policies and systems that stop a prohibited transaction before it happens — and for most companies, that means screening. Coverage is the first question: a program screening 95% of counterparties has a 5% blind spot that strict liability does not forgive. Speed is the second: stale lists and slow match resolution both create exposure windows. Treat the false-positive rate carefully — driving it down by loosening match logic is failure dressed up as efficiency, so always pair it with a measure of detection quality, such as periodic seeded-name testing.
Risk Assessment: Cadence and Coverage
A sanctions risk assessment maps where exposure actually sits — customers, geographies, products, payment flows, and intermediaries. The KPIs are cadence and coverage: refresh the assessment at least annually and on trigger events (a new market, an acquisition, a major OFAC program change), and measure the percentage of new products and markets that get a sanctions review before launch rather than after.
Testing, Training, and Management Commitment
Testing and auditing verify the program works as designed; the KPI that matters is not how many findings an audit produces but how fast they close. Training only counts if it reaches everyone in scope and goes deeper for the people who touch risk daily — sales teams in gray-market regions need more than the annual all-hands module. And management commitment, the pillar OFAC lists first, shows up in measurable ways: escalation speed, a rehearsed VSD decision protocol, and budget that moves when the risk assessment does.
One caution: there are no official OFAC benchmarks for any of these numbers. Directional targets and trend lines beat invented industry averages — what regulators and auditors want to see is that you measure, notice deterioration, and act. For the broader trade-compliance picture, these KPIs pair well with our trade compliance KPI cheatsheet and our guide to trade compliance roles and responsibilities.
Frequently Asked Questions
What are the five pillars of an OFAC sanctions compliance program?
Management commitment, risk assessment, internal controls, testing and auditing, and training — from OFAC’s Framework for Compliance Commitments (2019), the agency’s benchmark for evaluating programs during enforcement.
Are sanctions violations strict liability?
Civil violations generally are — OFAC does not need to prove you knew or intended to violate sanctions. Program quality, cooperation, and voluntary self-disclosure are the main levers that reduce the penalty.
How long must sanctions compliance records be kept?
Ten years. OFAC extended its recordkeeping requirement from five to ten years (effective March 2025), matching the 2024 statutory extension of the limitations period for most sanctions violations.
What is a good false-positive rate for sanctions screening?
There is no universal benchmark. Track your own trend, and never evaluate the false-positive rate in isolation — pair it with detection-quality testing so a falling rate reflects better tuning, not weaker matching.
Reidel Law Firm helps exporters and growing businesses build sanctions and export compliance programs that hold up under OFAC scrutiny. Our flat-fee import/export compliance memo gives you a written assessment of your sanctions exposure, screening obligations, and the controls your risk profile actually requires.


