INTERNATIONAL TRADE LAW
Sanctions Risk Assessment Checklist

A sanctions risk assessment is a structured review of where your business is most exposed to sanctions violations — by customer, product, and geography — so you can size your controls to the actual risk. It is the foundation of a risk-based compliance program: OFAC expects the depth of your screening, training, and monitoring to be proportionate to the risk this assessment surfaces. This checklist shows what to evaluate and how to turn it into a defensible record.
Risk assessment is the second of the five components in OFAC’s Framework for OFAC Compliance Commitments, and everything else in the sanctions compliance checklist flows from it. You cannot right-size screening or training until you know where the risk concentrates.
Why a Risk Assessment Comes First
OFAC does not expect every company to run identical controls; it expects controls matched to risk. A domestic-only software vendor and a machinery exporter shipping to dozens of countries face very different exposure, and their programs should look different. The risk assessment is what justifies those choices — and what an examiner or enforcement officer will ask to see first. Skip it, and you are either over-spending on controls you do not need or, more dangerously, under-protecting a high-risk line of business.
The Three Risk Dimensions
Most sanctions risk sorts into three categories. Work through each for your actual business, not a generic template.
| Dimension | What to examine | Higher-risk signals |
|---|---|---|
| Customer / counterparty | Who you sell to, their owners, intermediaries, and end users | Opaque ownership, shell companies, third-party intermediaries, politically exposed persons |
| Product / service | What you ship and its end use | Dual-use items, defense articles, items with military or surveillance applications |
| Geographic | Where parties, shipments, and payments touch | Comprehensively sanctioned jurisdictions, transshipment hubs, high-corruption regions |
A transaction that scores high on two or three dimensions — say, a dual-use item routed through a transshipment hub to a buyer with hidden ownership — deserves enhanced due diligence and senior sign-off.
The Checklist
Work these items and capture the answer to each in writing.
- Inventory your customers and counterparties. List customer types, key intermediaries, and the jurisdictions where your end users actually sit — which is not always where you ship.
- Inventory your products and services. Flag anything dual-use, export-controlled, or with potential military or surveillance end use.
- Map your geographic footprint. Identify every country your goods, services, parties, and payments touch, including transshipment points.
- Rate inherent risk in each dimension (e.g., low / medium / high) before considering your controls.
- Evaluate existing controls — screening, due diligence, training, monitoring — against each risk you identified.
- Identify the gaps where residual risk (inherent risk minus controls) is still too high.
- Assign remediation with an owner and a deadline for each gap.
- Document the methodology and conclusions, and date the assessment.
- Refresh it on a set cadence and after any material change — a new market, product line, acquisition, or major regulatory shift.
Turning the Assessment Into a Program
The output of the assessment should drive concrete decisions, not sit in a binder. High-risk customer segments get enhanced screening and deeper due diligence; high-risk product lines get tighter end-use checks; high-risk geographies may be off-limits without senior approval or an OFAC license. Frequency follows risk too — the riskier the segment, the more often you re-screen and retrain. Each link in the chain should trace back to a specific finding in the assessment.
Keep It Current — and Keep the Record
A risk assessment is a snapshot, and the picture changes. Re-run it on a defined schedule and whenever the business shifts: a new country, a new product, an acquisition, or a significant change in the sanctions landscape. Keep each version. As of March 12, 2025, OFAC’s recordkeeping period under 31 CFR 501.601 is 10 years, so retain your assessments and the data behind them accordingly. A dated series of assessments is strong evidence of a living, risk-based program if your compliance is ever questioned.
Frequently Asked Questions
How often should we redo the risk assessment? At least annually for most businesses, and immediately after any material change — entering a new market, adding a product line, completing an acquisition, or a major regulatory development.
Who should own the risk assessment? Your sanctions compliance officer or equivalent should own it, with input from sales, operations, and finance — the people who actually know the customers, products, and money flows.
Is a risk assessment legally required? No statute mandates a specific assessment, but OFAC’s enforcement framework treats a risk-based program as the expectation, and the assessment is what demonstrates your program is risk-based. Its absence is itself a red flag.
What is “inherent” versus “residual” risk? Inherent risk is your exposure before controls; residual risk is what remains after your controls are applied. The goal is to bring residual risk to an acceptable level, not to claim zero risk.
A risk assessment is most useful when it leads to the right calls on the gray-area customers, products, and routes — and that is exactly where outside review pays off. Reidel Law Firm prepares flat-fee Import/Export Compliance Memos that evaluate your risk profile and recommend proportionate controls, with direct access to the trade attorney handling your matter. Get an export compliance memo →


