INTERNATIONAL TRADE LAW

Sanctions Policies & Procedures Checklist

A sanctions policy is the written record of how your business stays on the right side of OFAC — it names who is responsible, defines what gets screened, and sets the rules for due diligence, recordkeeping, and escalation. Policies and procedures are the “internal controls” pillar of OFAC’s compliance framework: the part that turns intent into repeatable practice. A program that lives only in people’s heads cannot be trained, audited, or defended.

This checklist covers what belongs in the document and how to keep it from becoming shelfware.

Why written controls matter

In its 2019 Framework for OFAC Compliance Commitments, the Treasury’s Office of Foreign Assets Control lists internal controls as one of five essential components, alongside management commitment, risk assessment, testing and auditing, and training. Internal controls are where a risk assessment becomes action — written policies, procedures, and the screening and escalation steps employees follow every day. When OFAC evaluates a company after the fact, it looks at whether those controls existed and whether people actually used them.

What belongs in the policy

A workable sanctions policy is specific to how your business operates. At a minimum it should cover:

  • Scope and definitions — which entities, people, products, and destinations the policy reaches, and which sanctions programs apply to your trade lanes.
  • Ownership and accountability — the designated compliance officer, senior-management oversight, and who decides a close call.
  • Risk assessment — how exposure is identified and how often the assessment is refreshed.
  • Screening — when parties and transactions are screened, against which lists, and how potential matches are resolved.
  • Due diligence — the checks performed on customers, suppliers, and intermediaries before onboarding and at defined triggers.
  • Recordkeeping — what is kept, where, and for how long.
  • Escalation and reporting — how an employee raises a concern and how a possible violation moves up the chain.

The screening and due-diligence core

Screening and due diligence are where most sanctions exposure is actually caught or missed, so the procedures need to be concrete.

Screening has to test counterparties against the live Specially Designated Nationals and Blocked Persons (SDN) List and the other lists relevant to your business — and it has to account for ownership. Under OFAC’s 50 Percent Rule, an entity owned 50% or more, individually or in the aggregate, directly or indirectly, by one or more blocked persons is itself blocked, even if it never appears on a list by name. A screen that checks only the named counterparty and stops there will miss a blocked entity hiding one layer up.

Due diligence procedures should spell out the baseline check every counterparty gets and the enhanced due diligence triggered by higher-risk destinations, opaque ownership, or unusual transaction patterns. The point is consistency: the same risk should get the same scrutiny regardless of who is handling the deal.

A documentation checklist

Use this as a quick audit of whether the program is genuinely written down.

ControlDocumented?
Designated officer and reporting lineNamed, with authority and resources
Risk assessmentWritten, dated, scheduled for refresh
Screening procedureLists used, match-resolution steps, 50 Percent Rule applied
Due diligence standardBaseline plus enhanced-diligence triggers
RecordkeepingWhat is kept and the retention period
Escalation pathWho an employee tells, and what happens next
TrainingWho must complete it and how attendance is logged

Recordkeeping: build it into the procedure

Set the retention rule in the policy so it is not left to chance. OFAC’s recordkeeping requirement now runs ten years for covered transaction records — extended from five years effective March 12, 2025, to align with the longer statute of limitations for sanctions violations (31 CFR 501.601). Your procedures should say plainly that screening logs, due-diligence files, license determinations, and escalation decisions are retained for that period.

Keep it living

A policy is only as good as its last review. Tie it to the training program so employees know the current rules, and to your audit and exam readiness so gaps surface internally rather than in an enforcement inquiry. For broader context on operating under sanctions, see the guide to navigating sanctions and embargoes in exporting.

Frequently asked questions

Can we adopt a template policy and be done? A template is a starting point, not a finish line. OFAC expects a program calibrated to your actual risk — your destinations, products, and counterparties. A generic policy that does not match how you trade can be worse than none, because it documents a standard you are not meeting.

How often should the policy be updated? Review it on a set schedule and whenever something material changes — a new market, a new product line, an acquisition, or a significant change in the sanctions landscape. The risk assessment should drive the policy, so when the risk picture moves, the document should too.

Who should own the policy internally? The designated compliance officer should own and maintain it, with visible senior-management sign-off. Shared ownership with no clear accountability is how policies go stale.

Putting your sanctions program in writing? Reidel Law Firm’s flat-fee import/export compliance memo pressure-tests your policy against the transactions you actually run — in plain English, with direct attorney access. Get an import/export compliance memo →