INTERNATIONAL TRADE LAW

Sanctions Compliance Program Checklist

A sanctions compliance program is the set of policies, controls, and people that keeps your business from dealing with sanctioned parties — and OFAC says an effective one rests on five components. This checklist is the build sequence for standing that program up: secure leadership commitment, assess your risk, install controls, test them, and train your people. It is the hub that ties the individual component checklists together.

OFAC laid out the expectation in its Framework for OFAC Compliance Commitments (May 2019), which remains the working standard for what an adequate program contains. The five components below are the framework; the rest of this checklist is how you put them in place.

The Five Components

Every effective sanctions compliance program, in OFAC’s view, contains these five elements. They are also the lens OFAC uses when weighing penalties after a violation, so building to them protects you twice.

ComponentWhat it requiresChecklist
Management commitmentSenior leadership owns sanctions risk, funds the program, and empowers a compliance officerThis page
Risk assessmentIdentify exposure by customer, product, and geographyRisk assessment
Internal controlsScreening, due diligence, escalation, and recordkeeping that match the riskScreening · Due diligence
Testing and auditingIndependent review that the controls actually workAudit
TrainingThe people running the controls understand themTraining

Start With Management Commitment

The first component is the one programs most often skip, and the one OFAC weights most heavily. Senior management must visibly own sanctions risk — fund the program adequately, appoint a compliance officer with real authority and direct access to leadership, and treat compliance as a legal and reputational imperative rather than a box to check. A program without leadership backing tends to lose budget, get overruled by sales, and collapse under pressure. Commitment from the top is what holds the other four components together.

The Build Checklist

Work the components in order; each depends on the one before it.

  1. Secure management commitment. Get leadership sign-off, a budget, and a named compliance officer with authority and direct access to senior management.
  2. Run a risk assessment. Map exposure across customer, product, and geographic risk — see the risk assessment checklist.
  3. Write policies and procedures that match the risk you found, in plain language your team can actually follow.
  4. Install screening against the SDN and Consolidated lists, applying the 50% Rule — see the screening checklist.
  5. Set due diligence and escalation paths so high-risk parties get deeper review and a clear route to raise concerns.
  6. Build recordkeeping that retains the required records — now for 10 years.
  7. Train your people by role, at onboarding and on a set cadence — see the training checklist.
  8. Test and audit the program independently — see the audit checklist.
  9. Review and improve on a schedule and after any material change to the business or the rules.

Size the Program to the Risk

OFAC does not expect identical programs from every company; it expects each program to be proportionate to the risk. A domestic-focused business with simple supply chains needs far less than a multi-country exporter of dual-use goods. The risk assessment is what justifies where you invest and where you keep things lean — and what an examiner will look to first. Build the framework, then scale each component to what your own assessment surfaces. For the underlying rules and agency role, see OFAC sanctions compliance.

Frequently Asked Questions

What are the five components of a sanctions compliance program? Management commitment, risk assessment, internal controls, testing and auditing, and training — the elements OFAC identifies in its Framework for OFAC Compliance Commitments.

Is a sanctions compliance program legally required? No statute mandates a specific program, but U.S. sanctions liability is generally strict, and OFAC treats an effective, risk-based program as the expectation. The strength of your program directly affects penalty exposure if a violation occurs.

Where do we start? With management commitment and a risk assessment. Leadership buy-in funds and empowers the program, and the risk assessment tells you how big each of the other components needs to be.

How big does our program need to be? As big as your risk — no bigger. A simple, domestic business needs less than a multi-country exporter of controlled goods. The risk assessment sets the scale.

Standing up a program is mostly sequencing and judgment — and the judgment calls about how much control your specific risk demands are where outside review helps most. Reidel Law Firm prepares flat-fee Import/Export Compliance Memos that assess your exposure and map a right-sized program to OFAC’s five components, with direct access to the trade attorney handling your matter. Get an export compliance memo →

← All articles