INTERNATIONAL TRADE LAW
Sanctions Compliance Checklist: Build a Program

A sound sanctions compliance program covers five things OFAC treats as essential: management commitment, a risk assessment, internal controls, testing and auditing, and training. This checklist walks each one in plain English so you can see what your business already has, what is missing, and where the gaps create real exposure. It is a program-level checklist; for the narrower question of how to vet a single customer or transaction, see the sanctions due diligence checklist.
Why This Checklist Is Built on OFAC’s Five Components
OFAC’s 2019 Framework for OFAC Compliance Commitments is the reference point every U.S. regulator, bank, and counterparty now uses to judge whether a sanctions program is adequate. It names five essential components, and it is deliberately risk-based — a small importer is not expected to run the same program as a multinational bank, but every program should address all five at a scale that matches its risk. Organize your compliance around these five and you are speaking OFAC’s language.
The Checklist
1. Management Commitment
- Senior leadership (and, where relevant, the board) has formally approved a sanctions compliance policy.
- A specific person owns sanctions compliance with real authority, resources, and a direct line to leadership. (See sanctions compliance officer roles.)
- Compliance has the budget and headcount to actually do the work, not just the title.
2. Risk Assessment
- You have mapped exposure across customers, products, geographies, and payment channels.
- Risks are scored, so resources go where exposure is highest rather than being spread evenly.
- The assessment is refreshed on a schedule and after major changes (new markets, new product lines, acquisitions). A deeper walkthrough lives in the sanctions risk assessment guide.
3. Internal Controls
- You screen customers and counterparties against the SDN List and OFAC’s consolidated lists, at onboarding and on an ongoing basis.
- Your controls account for the 50% Rule — an unlisted entity is blocked if sanctioned parties own 50% or more of it, alone or in the aggregate.
- Written procedures tell employees how to handle a hit, freeze a transaction, and escalate.
- Records are retained for 10 years (see the rule change below).
4. Testing and Auditing
- An independent review periodically tests whether the controls actually work — not just whether they exist on paper.
- Findings are tracked to closure, and audit results feed back into the risk assessment and training.
- You measure performance with real metrics. The performance metrics checklist is a good starting set.
5. Training
- Employees in exposed roles are trained on red flags and the escalation path, at least annually and after major changes.
- Training is role-specific and documented. A full walkthrough is in the sanctions compliance training guide.
Two 2025–2026 Updates to Build Into the Checklist
Two recent changes affect how this checklist is applied, and both are easy to miss if your program predates them:
| Change | What it means for you | Effective |
|---|---|---|
| Recordkeeping extended to 10 years | Keep sanctions screening logs, decisions, and training records for a full decade, not five years | March 2025 |
| “50% is a floor, not a ceiling” guidance | A clean 50% Rule result no longer ends the inquiry — look at practical and economic control, not just legal ownership | March 31, 2026 |
The recordkeeping change followed the 2024 law that doubled the statute of limitations for sanctions violations from five to 10 years. The March 2026 OFAC guidance on sham transactions and evasion confirms the 50% Rule remains in force but tells businesses to look “beyond legal formalities” when ownership is structured to disguise a blocked person’s involvement.
What Happens If You Get It Wrong
Sanctions civil penalties are strict liability — you can be liable even if you had no idea a counterparty was sanctioned. Civil penalties run to the greater of a per-violation statutory cap that OFAC adjusts for inflation each year (about $377,700 in 2024) or twice the value of the transaction. Willful violations are criminal, carrying up to 20 years in prison and a $1 million fine. A documented, five-component program is your best protection: it reduces the chance of a violation and, if one happens, is a mitigating factor in how OFAC calculates any penalty.
Frequently Asked Questions
Does a small business really need all five components? Yes, but scaled to your risk. OFAC’s framework is risk-based, so a small importer’s program will be lighter than a bank’s — but it should still address management commitment, risk assessment, controls, testing, and training in some proportionate form.
Is there an official OFAC checklist we can just adopt? OFAC publishes the Framework for OFAC Compliance Commitments rather than a fill-in checklist. This checklist translates that framework into concrete items; your program still has to be tailored to your actual business.
How long do we keep our compliance records now? Ten years, as of March 2025. The extension aligns recordkeeping with the longer statute of limitations for sanctions violations.
Is screening against the SDN List enough? No. You also have to apply the 50% Rule to catch unlisted entities owned by sanctioned parties — and, after the March 2026 guidance, look past pure ownership to who really controls the counterparty.
A checklist shows you the gaps; closing them is the harder part. Reidel Law Firm builds and reviews sanctions and export-compliance programs for importers and exporters on a flat fee, delivered as a plain-English compliance memo with direct attorney access. Get an export compliance memo →


