INTERNATIONAL TRADE LAW
De-Risking and Sanctions Compliance Explained

De-risking is when a bank or company cuts off an entire category of customers — say, all money-services businesses or all clients in a high-risk region — rather than assess and manage the sanctions risk client by client. It feels safe, but it trades one risk for another: lost business, customers pushed into less-transparent channels, and regulatory attention of its own.
The pull toward de-risking is easy to understand. U.S. sanctions are enforced by the Treasury Department’s Office of Foreign Assets Control (OFAC), penalties are largely strict liability, and the statutory maximum civil penalty per violation is adjusted for inflation each year (roughly $377,700 in 2026, or twice the value of the transaction, whichever is greater). Faced with that exposure, the temptation is to drop whole segments instead of doing the work to manage them. The better answer is almost always a risk-based program, not a blanket exit.
What De-Risking Actually Is
De-risking is the wholesale termination or avoidance of customer relationships by category rather than by individual assessment. A bank that closes every correspondent account in a region, or an insurer that refuses an entire industry, is de-risking. The distinguishing feature is that the decision is made at the level of a group — defined by product, geography, or customer type — without analyzing the specific risk each customer presents.
U.S. regulators have flagged this as a problem, not a solution. In April 2023, the U.S. Treasury published its first formal De-risking Strategy, required by Section 6215 of the Anti-Money Laundering Act of 2020. The strategy found that de-risking drives financial activity out of the regulated system, hampers remittances and humanitarian flows, and cuts lower-income customers off from financial services — while concluding that profitability, not just compliance fear, often drives the decision. The takeaway for compliance teams: regulators expect risk to be managed, not avoided by exclusion.
Why Blanket De-Risking Backfires
| Blanket de-risking | Risk-based management |
|---|---|
| Drops whole customer categories | Assesses each customer’s actual risk |
| Loses revenue and good clients along with bad | Keeps low-risk business while controlling high-risk |
| Pushes activity into opaque channels | Keeps activity visible and monitored |
| Draws its own regulatory criticism | Aligns with OFAC and Treasury expectations |
| Treats risk as binary | Treats risk as something to be measured and mitigated |
De-risking can also be its own form of risk. When legitimate activity is forced outside regulated institutions, it becomes harder to monitor — the opposite of what sanctions compliance is meant to achieve.
The Risk-Based Alternative
The framework regulators expect is the one OFAC laid out in its Framework for OFAC Compliance Commitments (May 2019): management commitment, risk assessment, internal controls, testing and auditing, and training. Applied to the de-risking problem, a risk-based approach lets an institution keep a relationship while controlling it:
- Assess each relationship on its facts — ownership, geography, products, and transaction patterns — rather than by category. A structured sanctions risk assessment is the engine for this.
- Apply proportionate controls — enhanced due diligence, transaction monitoring, and tighter limits for higher-risk customers instead of exit.
- Escalate and document the close calls through a defined path, so a credible concern is resolved deliberately rather than by reflex. See our guide on building a sanctions escalation process.
- Reassess on a schedule, because both customer behavior and the sanctions lists change.
This is more work than closing accounts, but it preserves legitimate business, keeps activity inside the regulated system, and matches what OFAC and Treasury say a good program looks like. For the broader mechanics, see how to assess and manage sanctions compliance.
When Exiting a Relationship Is Justified
Risk-based does not mean keeping every customer. Sometimes the responsible decision is to exit — when a customer is blocked, when the activity cannot be brought within risk appetite, or when diligence cannot resolve a serious concern. The difference is that the exit follows an individual assessment, with the reasoning documented, rather than a category-wide rule applied without analysis. Keep those records for 10 years — OFAC extended its recordkeeping requirement from five to 10 years in March 2025.
Frequently Asked Questions
Is de-risking illegal? No. Institutions can choose their customers. But regulators have publicly discouraged wholesale, category-based de-risking, and Treasury’s 2023 strategy treats it as a problem to reduce. The expectation is to manage risk, not avoid it by exclusion.
Why not just drop every high-risk customer to be safe? Because it loses good business with the bad, pushes activity into channels you cannot monitor, and invites its own regulatory criticism. A risk-based program usually controls the exposure at lower overall cost.
What does a risk-based approach require? Individualized assessment of each relationship, proportionate controls for higher-risk customers, a defined escalation path for close calls, documented decisions, and periodic reassessment — the elements of OFAC’s compliance framework.
Is it ever right to exit a relationship? Yes — when a customer is blocked or the risk cannot be brought within appetite. The key is that the decision rests on an individual assessment and is documented, not applied as a blanket category rule.
De-risking by category trades a manageable problem for a worse one. Reidel Law Firm helps banks and businesses build risk-based sanctions programs that keep good customers while controlling real exposure, delivered as a flat-fee compliance memo with direct attorney access. Get an export compliance memo →


