INTERNATIONAL TRADE LAW
Sanctions Compliance Metrics: A KPI Checklist

Sanctions compliance metrics are the measurable indicators that tell you whether your program is actually working — not just whether it exists on paper. OFAC expects programs to be tested and audited, and you cannot test what you do not measure. This checklist sets out the key performance indicators (KPIs) worth tracking across screening, alerts, training, audit, and remediation, and explains how to read them.
Metrics are the “testing and auditing” leg of a complete program — they tell you whether the risk assessment and screening you built are doing their job.
Why Measure at All
OFAC’s Framework for OFAC Compliance Commitments lists testing and auditing among the five essential components of a sanctions compliance program. Metrics turn that expectation into something concrete: they reveal weaknesses before regulators do, justify resourcing decisions to management, and create the documented evidence of diligence that matters if you ever face an enforcement inquiry. The aim is not a vanity dashboard — it is a small set of numbers that change behavior.
The KPI Checklist
Track a focused set of indicators across the parts of the program. The table below groups the most useful ones.
| Area | KPI | What it tells you |
|---|---|---|
| Screening coverage | % of transactions and parties screened before completion | Whether screening is actually happening everywhere it should |
| Alert quality | False-positive rate; alert-to-true-match ratio | Whether your matching is tuned — too loose wastes time, too tight misses hits |
| Timeliness | Average time to clear an alert; time to report a true match | Whether hits are resolved and escalated promptly |
| Training | % of relevant staff trained; assessment pass rates | Whether the people touching transactions actually understand the rules |
| Audit | Audit frequency; number and severity of findings | Whether independent review is happening and what it surfaces |
| Remediation | % of findings closed on time; recurrence rate | Whether problems get fixed and stay fixed |
You do not need every metric on day one. Start with screening coverage, alert quality, and remediation timeliness — the three that most directly show whether the program prevents violations.
Reading the Numbers
Individual KPIs are most useful in relation to each other and over time. A few patterns worth watching:
- A very low false-positive rate is not automatically good. It can mean your screening is tuned too tight and missing real matches. Read it alongside your true-match count.
- Rising alert-clearing times often signal that volume has outgrown staffing — a resourcing flag for management.
- High training completion but recurring audit findings suggests the training is not landing where the real risk is; revisit content, not just attendance.
- Repeat findings on the same control are the clearest sign of a program weakness that needs a structural fix, not another reminder email.
Trends matter more than any single reading. Review the metrics on a set cadence, compare against your prior periods, and feed what you learn back into the risk assessment and controls.
Putting It to Work
Metrics earn their keep only when someone acts on them. Assign clear ownership for each KPI, report them to senior management on a regular schedule, and tie material changes to a decision — retune screening, add staff, refresh training, or escalate a control gap. For a complementary view focused on program success indicators, see our guide to sanctions compliance KPIs.
Frequently Asked Questions
What are sanctions compliance metrics?
They are measurable indicators — KPIs — that show how well a sanctions compliance program is performing across screening, alert handling, training, audit, and remediation, rather than simply confirming that policies exist.
Which sanctions KPIs matter most?
For most businesses, the highest-value indicators are screening coverage (are all parties and transactions screened?), alert quality (false-positive and true-match rates), and remediation timeliness (are findings fixed on schedule?). These most directly reflect whether the program prevents violations.
Does OFAC require metrics?
OFAC’s Framework for OFAC Compliance Commitments treats testing and auditing as one of five essential program components. Metrics are how most organizations meet that expectation in practice, even though no rule prescribes a specific set.
How often should I review compliance metrics?
Review core operational metrics monthly or quarterly, and roll them into a fuller program review at least annually. The cadence matters less than consistency and acting on what the numbers show.
The right metrics turn a sanctions program from a binder on a shelf into something you can prove works. Reidel Law Firm helps importers and exporters build and test sanctions compliance programs on flat-fee terms. Get an export compliance memo.


