INTERNATIONAL TRADE LAW

Sanctions Record Keeping Checklist (10-Year Rule)

OFAC now requires you to keep sanctions-related records for 10 years, up from five — a change that took effect on March 12, 2025. Under 31 CFR 501.601, U.S. persons must retain a full record of transactions and compliance activity for the longer period, and your records are the proof that your program actually ran. This checklist covers what to keep, how long, and how to organize it so the records hold up if OFAC ever asks.

Recordkeeping cuts across every part of the sanctions compliance checklist: screening logs, due diligence files, training records, and audit reports are all records you must retain. Without them, even a well-run program looks like an unprovable one.

What Changed: Five Years to Ten

The retention period doubled because the enforcement window did. Effective April 24, 2024, the statute of limitations for most civil and criminal violations of the International Emergency Economic Powers Act (IEEPA) and the Trading with the Enemy Act (TWEA) was extended from five years to 10 years. To match it, OFAC amended its recordkeeping rule: an interim final rule published September 13, 2024 set a 10-year retention requirement, the requirement began on March 12, 2025, and OFAC finalized it in March 2025. The only substantive change to 31 CFR 501.601 was the number — five became ten — but the practical effect is significant: records you might have purged at year five must now be kept twice as long.

BeforeNow
Retention period5 years10 years
Authority31 CFR 501.60131 CFR 501.601 (amended)
In force sinceMarch 12, 2025
Driven by10-year statute of limitations (effective April 24, 2024)

What to Keep

Keep the records that show both your transactions and the compliance work behind them. If a control is worth running, its output is worth retaining.

  • Transaction records — invoices, contracts, shipping and customs documents, payment and wire records, letters of credit.
  • Screening results — every check against the SDN and Consolidated lists, including the date, lists screened, and how any hit was resolved.
  • Due diligence files — ownership analysis, the 50% Rule assessment, and beneficial-owner research for entity counterparties.
  • Licenses and authorizations — any OFAC license application, the license itself, and records of activity conducted under it.
  • Blocked and rejected transactions — what was blocked or rejected, when, and the report filed with OFAC.
  • Program documents — your risk assessment, policies and procedures, training records, and audit reports.

The Checklist

Stand up recordkeeping against these items.

  1. Confirm the 10-year period applies across your records and update any retention policy that still says five years.
  2. Map every record type your program generates to a retention rule.
  3. Capture compliance work, not just transactions — screening logs, due diligence, training, and audits are records too.
  4. Centralize storage so records are findable, not scattered across inboxes and shared drives.
  5. Index records by counterparty, transaction, and date for fast retrieval.
  6. Protect integrity with access controls and backups; records must be complete and tamper-evident.
  7. Make records retrievable on demand — OFAC can require production, and “we have it somewhere” is not a record.
  8. Set disposal rules that delete only after the full retention period, and document the disposal.
  9. Audit your recordkeeping periodically as part of testing and auditing.

Organizing for Retrieval

A record you cannot find on request is, for practical purposes, a record you do not have. Store sanctions records in one system with consistent naming, and index them so you can pull every document tied to a counterparty or transaction quickly. Because the timeline is now a decade, plan for staff turnover, system migrations, and format changes — a screening log saved only in software you no longer license is a gap waiting to happen. Build retrieval into the design from the start rather than reconstructing files under deadline pressure during an inquiry.

Frequently Asked Questions

How long do I have to keep OFAC records now? Ten years, as of March 12, 2025, under 31 CFR 501.601. The period was five years before this change.

Why did the retention period change? Congress extended the statute of limitations for most IEEPA and TWEA sanctions violations from five to 10 years, effective April 24, 2024. OFAC extended recordkeeping to match the longer enforcement window.

What records do I actually have to keep? A full record of each transaction plus the compliance work around it — screening results, due diligence, licenses, blocked/rejected transaction reports, and program documents like your risk assessment, policies, training, and audits.

Does the 10-year rule apply to old records? Going forward, retain records for 10 years. For records you still hold, the prudent course is to keep them for the longer period given the extended enforcement window; consult counsel about records approaching the old five-year limit.

Recordkeeping is the quiet control that determines whether your other controls can be proven — and the rules just changed underneath it. Reidel Law Firm prepares flat-fee Import/Export Compliance Memos that review your recordkeeping against the current 10-year requirement and flag the gaps, with direct access to the trade attorney handling your matter. Get an export compliance memo →

← All articles