INTERNATIONAL TRADE LAW

Sanctions Compliance Benchmarking Checklist

Sanctions compliance benchmarking measures your program against external reference points — OFAC’s published framework, its enforcement actions, and peer practice — to surface gaps before a regulator does. This checklist focuses on the reference points that actually matter and how to turn a comparison into a prioritized fix list. For the program those gaps live in, see the international trade compliance program checklist.

Benchmarking goes wrong when it chases a vague sense of “what everyone else does.” The useful benchmarks are concrete and public, and most of them come straight from the Office of Foreign Assets Control (OFAC).

What to Benchmark Against

There are three reference points worth measuring against, in priority order.

BenchmarkWhat it tells you
OFAC’s 2019 compliance frameworkThe five elements a program is expected to have
OFAC enforcement actionsThe control failures that actually get penalized
Peer and sector practiceWhere your controls sit relative to comparable firms

The framework comes first because it is the standard OFAC itself applies: management commitment, risk assessment, internal controls, testing and auditing, and training. Enforcement actions come second because OFAC publishes them, and its framework lists the recurring root causes of breakdowns — the absence of a formal program, screening-software gaps, weak ownership diligence, and decentralized controls among them. Those root causes are a ready-made benchmark of what failure looks like.

The Benchmarking Checklist

Pick Your Reference Points

  • Anchor on OFAC’s five framework elements as the baseline scorecard.
  • Add the root causes from OFAC’s framework and recent enforcement actions in your sector as a “failure mode” list.
  • Only then layer in peer practice, scaled to your size and risk — a global manufacturer and a small exporter should not be held to identical operational benchmarks.

Gather Your Own Evidence

  • Inventory what your program actually does in each of the five areas, with documents, not assumptions.
  • Pull metrics you already have: screening volumes, alert clearance times, training completion, audit findings. The performance metrics checklist covers what to track.

Compare Across the Five Elements

  • Score each element against the benchmark: meets, partially meets, or gap.
  • Be specific about why something is a gap — “screening does not apply the 50% Rule” is actionable; “screening is weak” is not.
  • Flag any root cause from OFAC’s list that your program does not clearly guard against.

Prioritize by Risk, Not by Ease

  • Rank gaps by the exposure they create, not by how quickly they can be closed.
  • A missing 50% Rule check or a screening engine that does not update its lists outranks cosmetic policy edits.
  • Tie each gap to an owner and a target date.

Re-Benchmark on a Cycle

  • Re-run the comparison at least annually and after any major change in markets, products, or ownership.
  • Track movement over time; the trend matters as much as the snapshot.

Benchmark the Substance, Not the Binder

The point of benchmarking is to compare what your program does, not how thick its policy is. Two areas separate strong programs from weak ones in practice.

First, screening. Benchmark whether you screen against the SDN List and consolidated lists, whether lists update on a schedule, and whether diligence reaches beyond named parties to the 50% Rule — an unlisted entity owned 50% or more by sanctioned persons, in the aggregate, is itself blocked.

Second, recordkeeping. Confirm records are kept for 10 years, the standard OFAC adopted effective March 2025 to match the longer limitations period for sanctions violations. A program that benchmarks well on screening but retains records for five years has a real, dateable gap.

Because OFAC civil penalties are imposed on a strict-liability basis, benchmarking is not academic — it is how you find the control that would otherwise fail silently. For the broader self-assessment, pair this with how to assess and manage sanctions compliance.

Frequently Asked Questions

What should we benchmark our sanctions program against? Start with OFAC’s 2019 framework and its list of root causes, add relevant enforcement actions, and only then compare to peers. The first two are public and authoritative; peer practice is context.

Is benchmarking the same as auditing? No. Benchmarking compares your program to an external standard; an audit tests whether your own controls work as designed. Many firms benchmark to set targets, then audit to confirm they are met.

How often should we benchmark? At least annually, and after material changes in products, markets, ownership, or the sanctions landscape. Track the trend, not just the latest score.

Where do most programs fall short? On the operational details OFAC’s enforcement record highlights: screening that misses the 50% Rule, lists that are not refreshed, weak ownership diligence, and short record retention.

Benchmarking only helps if the comparison is honest and the gaps actually get closed. Reidel Law Firm helps importers and exporters benchmark and strengthen their sanctions programs, delivered as a flat-fee compliance memo with direct attorney access. Get an export compliance memo →

← All articles