INTERNATIONAL TRADE LAW

Sanctions Compliance Certification Checklist

A sanctions compliance certification is a formal, documented attestation — by your own leadership, a counterparty, or an outside reviewer — that a sanctions compliance program meets a defined standard. It is not a government license, and OFAC does not “certify” company programs. This checklist covers what a credible certification should rest on and how to assemble the evidence behind it.

Certification is where the internal controls of a program get committed to writing and signed. Done well, it forces an honest inventory of what the program actually does. Done as a rubber stamp, it creates a record that can be used against you.

What “Certification” Does and Does Not Mean

There is no official OFAC seal of approval. When people say “sanctions certification,” they usually mean one of three things, and the distinction matters.

TypeWho signsWhat it is
Internal attestationOfficer or compliance leadA statement that the program meets the company’s own standard
Counterparty certificationA vendor or partnerA contractual representation about their sanctions controls
Third-party assessmentOutside reviewer or counselAn independent evaluation against a recognized framework

All three turn on the same underlying evidence: the five elements of OFAC’s 2019 Framework for OFAC Compliance Commitments — management commitment, risk assessment, internal controls, testing and auditing, and training. A certification is only as good as the program it describes. For the underlying concept, see the compliance attestation glossary entry.

The Certification Checklist

Confirm Management Commitment

  • Identify a named program owner with real authority and a reporting line to senior management.
  • Document that the program has adequate budget, staff, and tools — not just a policy.

Point to a Written Policy and Procedures

  • Attach the current written sanctions policy and the step-by-step procedures employees follow.
  • Confirm the procedures cover screening, alert handling, escalation, licensing, and recordkeeping.

Tie It to a Current Risk Assessment

  • Reference a dated risk assessment that maps the company’s real products, customers, and geographies to sanctions risk.
  • Confirm the assessment is recent; certifying against a stale risk picture is a common weakness.

Evidence the Screening Controls

  • State that counterparties are screened against the SDN List and consolidated lists at onboarding and on an ongoing basis.
  • Confirm the program applies the 50% Rule — an unlisted entity owned 50% or more by sanctioned persons, individually or in aggregate, is itself blocked.

Show Testing and Training Records

  • Reference the most recent sanctions audit and its remediation status.
  • Confirm employees in risk-facing roles completed training, with dates and completion records.

Verify Recordkeeping

  • Confirm sanctions records are retained for 10 years, consistent with OFAC’s recordkeeping requirement effective March 2025.

Get the Right Signature

  • Have the certification signed by someone with authority and actual knowledge of the program — typically a compliance officer or senior executive.
  • Date it, version it, and re-certify on a fixed cycle.

A certification is a statement people will rely on. A counterparty’s sanctions representation may be the basis for your own diligence; your internal attestation may be produced to regulators or in litigation. Overstating what the program does — certifying “full compliance” when controls are partial — converts a paperwork problem into a credibility problem.

Keep certifications accurate and bounded. Certify what the program is designed to do and what evidence supports it, not an absolute guarantee against any violation. Because OFAC civil liability is strict, no program eliminates risk entirely; an honest certification reflects that. The payoff for accuracy is real: under OFAC’s enforcement guidelines, a genuine, well-documented program is a mitigating factor, while a false or hollow certification is the opposite.

The same caution applies to certifications you receive. When a vendor or partner certifies its sanctions controls, treat the wording as a representation you can act on but still verify. Vague, absolute language tells you far less than a specific description of what they screen, how often, and who owns the process — tie any reliance to the strength of the words on the page.

Frequently Asked Questions

Does OFAC issue a sanctions compliance certification? No. OFAC publishes the compliance framework and enforcement guidelines, but it does not certify or pre-approve company programs. Any “certification” is internal, contractual, or from a third party.

What is the difference between a certification and an audit? An audit tests whether the program works; a certification attests, in writing, that it meets a standard. A sound certification should be backed by a recent audit.

Can we rely on a vendor’s sanctions certification? It is useful evidence but not a substitute for your own diligence. OFAC liability is strict, so a counterparty’s representation does not transfer your obligation to screen and document.

How often should we re-certify? On a fixed cycle — annually is common — and after any material change in products, markets, ownership, or the program itself.

A certification is only as strong as the program and the evidence behind it. Reidel Law Firm helps importers and exporters document and stand behind their sanctions programs, delivered as a flat-fee compliance memo with direct attorney access. Get an export compliance memo →

← All articles