INTERNATIONAL TRADE LAW
Sanctions Audit Checklist: Test Your OFAC Program

A sanctions audit is an independent test of whether your OFAC compliance program actually works — not whether it exists on paper. This checklist walks the audit from scope and independence through transaction sampling, screening tests, and remediation. It covers the “testing and auditing” pillar of a sanctions program; for the whole framework, see the international trade compliance program checklist.
Auditing is one of the five components the Office of Foreign Assets Control (OFAC) names in its 2019 Framework for OFAC Compliance Commitments: management commitment, risk assessment, internal controls, testing and auditing, and training. An audit is how you find the gap before OFAC does.
Why a Sanctions Audit Matters
OFAC enforces civil penalties on a strict-liability basis — a company can be liable for a prohibited transaction even with no intent and no knowledge. An audit is the cheapest way to catch a control failure while it is still a finding instead of a violation.
It also pays off if something does slip through. Under OFAC’s Economic Sanctions Enforcement Guidelines, the existence and quality of a compliance program — including whether you test it — is a mitigating factor in how a penalty is calculated. A program that is audited and remediated looks very different from one that was never checked.
What to Audit
A useful audit maps to the same five framework areas the program is built on. Each gets its own evidence question.
| Framework area | The audit asks |
|---|---|
| Management commitment | Are resources, authority, and a named owner actually in place? |
| Risk assessment | Is the risk assessment current and tied to real products, customers, and geographies? |
| Internal controls | Do written procedures match what employees actually do? |
| Testing and auditing | Are screening hits and prior findings tracked to closure? |
| Training | Did the people in risk-facing roles complete relevant training? |
The Audit Checklist
Set Scope and Independence
- Define the period, business units, and transaction types under review before you start.
- Have the audit run by someone independent of day-to-day sanctions operations — internal audit, a separate compliance function, or outside counsel. The reviewer should not be grading their own work.
- Write the scope and methodology down so the audit is repeatable next cycle.
Sample Real Transactions
- Pull a risk-based sample of actual transactions, not a tidy demo set. Weight the sample toward higher-risk customers, jurisdictions, and goods.
- Re-run the sampled counterparties through screening as the audit, and compare the result to what the business did at the time.
- Trace a handful of “possible match” alerts end to end: who reviewed, what they decided, and whether the rationale was documented.
Test the Screening Engine
- Confirm the tool screens against OFAC’s Specially Designated Nationals (SDN) List and consolidated lists, and that lists update on a defined schedule.
- Test the 50% Rule: screening that only checks named parties will miss an unlisted company that sanctioned persons own 50% or more of, individually or in aggregate. Confirm ownership is part of diligence.
- Run known test names through the system to confirm it actually flags them and is not over-tuned to suppress alerts.
Check Recordkeeping and Retention
- Verify that screening results, alert dispositions, and licensing decisions are retained.
- Confirm records are kept for 10 years. OFAC extended its recordkeeping requirement from five to 10 years, effective March 2025, to match the longer limitations period for sanctions violations.
Close the Loop on Findings
- Log every gap with an owner, a remediation step, and a due date.
- Re-test remediated items in the next cycle; an open finding that recurs is a far worse fact than one caught once and fixed.
- Report results up to management so the “commitment” pillar has something to act on.
How Findings Connect to Penalties
Audit findings are not just housekeeping. The same factors an audit surfaces — whether you screened, whether you applied the 50% Rule, whether you kept records — are the factors OFAC weighs in an enforcement action. Civil penalties can reach the greater of an inflation-adjusted statutory maximum (about $377,700 per violation in 2025) or twice the value of the transaction, and willful violations can be prosecuted criminally. A documented audit-and-remediation history is one of the strongest mitigating facts you can bring to that conversation. If an audit does surface a likely violation, see how to respond to an OFAC enforcement action.
Frequently Asked Questions
How often should we run a sanctions audit? At least annually for most exporters, and after any material change — a new product line, a new market, an acquisition, or a screening-system change. Higher-risk businesses audit more often.
Who should perform the audit? Someone independent of the sanctions operation. That can be internal audit, a separate compliance team, or outside counsel, but it should not be the same person who runs screening day to day.
Is a sanctions audit the same as a risk assessment? No. A risk assessment identifies where your exposure is; an audit tests whether the controls you built in response actually work. They feed each other.
How long do we keep audit records? Ten years, consistent with OFAC’s recordkeeping rule effective March 2025. Retain the scope, the sample, the findings, and proof of remediation.
A sanctions audit is only useful if it tests the right transactions and the findings actually get fixed. Reidel Law Firm helps importers and exporters scope, run, and remediate sanctions audits, delivered as a flat-fee compliance memo with direct attorney access. Get an export compliance memo →


