INTERNATIONAL TRADE LAW

Sanctions Compliance Metrics: A KPI Checklist

Sanctions compliance metrics are the measurable indicators that tell you whether your program is actually working — not just whether it exists on paper. OFAC expects programs to be tested and audited, and you cannot test what you do not measure. This checklist sets out the key performance indicators (KPIs) worth tracking across screening, alerts, training, audit, and remediation, and explains how to read them.

Metrics are the “testing and auditing” leg of a complete program — they tell you whether the risk assessment and screening you built are doing their job.

Why Measure at All

OFAC’s Framework for OFAC Compliance Commitments lists testing and auditing among the five essential components of a sanctions compliance program. Metrics turn that expectation into something concrete: they reveal weaknesses before regulators do, justify resourcing decisions to management, and create the documented evidence of diligence that matters if you ever face an enforcement inquiry. The aim is not a vanity dashboard — it is a small set of numbers that change behavior.

The KPI Checklist

Track a focused set of indicators across the parts of the program. The table below groups the most useful ones.

AreaKPIWhat it tells you
Screening coverage% of transactions and parties screened before completionWhether screening is actually happening everywhere it should
Alert qualityFalse-positive rate; alert-to-true-match ratioWhether your matching is tuned — too loose wastes time, too tight misses hits
TimelinessAverage time to clear an alert; time to report a true matchWhether hits are resolved and escalated promptly
Training% of relevant staff trained; assessment pass ratesWhether the people touching transactions actually understand the rules
AuditAudit frequency; number and severity of findingsWhether independent review is happening and what it surfaces
Remediation% of findings closed on time; recurrence rateWhether problems get fixed and stay fixed

You do not need every metric on day one. Start with screening coverage, alert quality, and remediation timeliness — the three that most directly show whether the program prevents violations.

Reading the Numbers

Individual KPIs are most useful in relation to each other and over time. A few patterns worth watching:

  • A very low false-positive rate is not automatically good. It can mean your screening is tuned too tight and missing real matches. Read it alongside your true-match count.
  • Rising alert-clearing times often signal that volume has outgrown staffing — a resourcing flag for management.
  • High training completion but recurring audit findings suggests the training is not landing where the real risk is; revisit content, not just attendance.
  • Repeat findings on the same control are the clearest sign of a program weakness that needs a structural fix, not another reminder email.

Trends matter more than any single reading. Review the metrics on a set cadence, compare against your prior periods, and feed what you learn back into the risk assessment and controls.

Putting It to Work

Metrics earn their keep only when someone acts on them. Assign clear ownership for each KPI, report them to senior management on a regular schedule, and tie material changes to a decision — retune screening, add staff, refresh training, or escalate a control gap. For a complementary view focused on program success indicators, see our guide to sanctions compliance KPIs.

Frequently Asked Questions

What are sanctions compliance metrics?

They are measurable indicators — KPIs — that show how well a sanctions compliance program is performing across screening, alert handling, training, audit, and remediation, rather than simply confirming that policies exist.

Which sanctions KPIs matter most?

For most businesses, the highest-value indicators are screening coverage (are all parties and transactions screened?), alert quality (false-positive and true-match rates), and remediation timeliness (are findings fixed on schedule?). These most directly reflect whether the program prevents violations.

Does OFAC require metrics?

OFAC’s Framework for OFAC Compliance Commitments treats testing and auditing as one of five essential program components. Metrics are how most organizations meet that expectation in practice, even though no rule prescribes a specific set.

How often should I review compliance metrics?

Review core operational metrics monthly or quarterly, and roll them into a fuller program review at least annually. The cadence matters less than consistency and acting on what the numbers show.

The right metrics turn a sanctions program from a binder on a shelf into something you can prove works. Reidel Law Firm helps importers and exporters build and test sanctions compliance programs on flat-fee terms. Get an export compliance memo.

← All articles