INTERNATIONAL TRADE LAW
Sanctions Exam & Audit Prep Checklist

To prepare for a sanctions audit or an OFAC inquiry, assemble the records that prove your program works — your risk assessment, written policies, screening logs, training rosters, and remediation history — and test them against the gaps before someone else does. “Testing and auditing” is one of OFAC’s five essential compliance components, and it is the one that tells you whether the other four are real. The exporters who handle scrutiny well are the ones who audited themselves first.
This checklist explains who actually reviews exporters, what a reviewer looks for, and how to get ready.
Who reviews an exporter’s sanctions compliance
It helps to be precise about the kind of “exam” most exporters face. Banks and other financial institutions undergo periodic sanctions examinations by their federal regulators. Most exporters do not — their scrutiny usually comes in three other forms:
- An internal or independent audit the company commissions itself, which is the testing-and-auditing pillar in practice.
- An OFAC administrative inquiry, often beginning with a request for information or an administrative subpoena after a possible violation surfaces.
- A counterparty or customer audit, where a bank or large buyer reviews your controls as a condition of doing business.
The good news is that preparation is the same for all three: a documented program you have already stress-tested.
What a reviewer looks for
Whoever is reviewing, the questions track OFAC’s five compliance components. Use the table as a readiness checklist.
| Area | What a reviewer expects to see |
|---|---|
| Management commitment | A designated compliance officer with authority, plus senior-management oversight |
| Risk assessment | A current, written assessment tied to your destinations, products, and counterparties |
| Internal controls | Written policies and procedures and screening that applies the 50 Percent Rule |
| Testing and auditing | Evidence of independent review and that findings were fixed |
| Training | A training program with documented attendance |
| Recordkeeping | Complete records kept for the required retention period |
Run a self-assessment first
The most valuable preparation is an honest internal audit. Work through the program as a skeptical outsider would:
- Pull the documents. Risk assessment, policy, screening procedure, training records, and any prior findings. Missing or undated documents are the first thing a reviewer notices.
- Test the screening. Run sample transactions, including ones with layered ownership, and confirm the 50 Percent Rule analysis was actually performed.
- Trace an escalation. Pick a past potential-match and follow the paper trail. Was it resolved, documented, and decided by the right person?
- Check training coverage. Confirm the higher-exposure roles were trained and that attendance is logged.
- Close the gaps and record it. Remediation that is documented and tracked to completion is itself a mitigating factor.
Why recordkeeping is the backbone
Audits and inquiries are won or lost on records. OFAC’s recordkeeping requirement now runs ten years for covered transaction records — extended from five years effective March 12, 2025, to align with a longer statute of limitations. That limitations period for civil and criminal violations of the principal sanctions statutes was itself doubled from five to ten years by legislation signed in April 2024, reaching violations dating back to April 24, 2019. The practical takeaway: a reviewer can look back a decade, so your records have to reach back that far too (31 CFR 501.601).
After the review
Whether the review is internal or external, treat the findings as the start of the next cycle. Feed gaps back into the policies and procedures, refresh training, and make sure the incident response plan reflects what you learned. For broader context, see the practice area page for international trade law.
Frequently asked questions
Will OFAC audit my company on a schedule like a bank exam? Usually not. Most exporters are not subject to routine sanctions examinations the way banks are. The realistic scenarios are an audit you run yourself, a customer or bank reviewing your controls, or an OFAC inquiry after a possible violation. Preparing for one prepares you for all three.
What single thing should we have ready? A current, written risk assessment with the records that back it up. Almost every line of inquiry starts there, and a program that cannot show its risk assessment looks improvised regardless of how well it actually operates.
Does finding our own problems make us look worse? The opposite. Identifying and fixing gaps before a regulator does is exactly what the testing-and-auditing pillar is for, and documented remediation can reduce exposure if an issue ever reaches OFAC.
Facing a sanctions audit or an OFAC inquiry? Reidel Law Firm’s flat-fee import/export compliance memo shows you where your program would hold up — and where it wouldn’t — in plain English, with direct attorney access. Get an import/export compliance memo →


