INTERNATIONAL TRADE LAW

Trade Compliance Risk Assessment Cheat Sheet

A trade compliance risk assessment is a structured review of your import and export activity to find where you are most likely to break a rule — so you can fix it before a regulator does. It is the foundation of every credible compliance program: you cannot allocate limited time and budget sensibly until you know which transactions, products, and counterparties carry the most exposure. This cheat sheet explains the framework regulators expect, where the risk usually hides, and how to run the assessment.

Why a Risk Assessment Comes First

Risk assessment is not an optional flourish — it is one of the components U.S. regulators look for when they judge whether a program is real. OFAC’s 2019 publication, A Framework for OFAC Compliance Commitments, identifies five essential components of a risk-based sanctions compliance program:

  1. Management commitment
  2. Risk assessment
  3. Internal controls
  4. Testing and auditing
  5. Training

Risk assessment sits at position two for a reason: the other components are supposed to be calibrated to the risks it surfaces. The same logic carries over to the customs side, where the reasonable-care standard expects an importer to know — and address — where its declarations are most likely to be wrong.

Where the Risk Usually Hides

A useful assessment maps your actual transactions against the categories regulators care about. Most exposure clusters in a handful of places.

Risk areaWhat to examine
ProductsAre any items controlled (ECCN-listed), dual-use, or subject to antidumping/countervailing duties?
CounterpartiesCustomers, suppliers, end users, and intermediaries — screened against sanctions and denied-party lists?
GeographyDo you touch sanctioned or high-risk destinations, or transship through them?
Classification & valuationHow confident are you in your HTS codes, declared values, and origin determinations?
Licensing & end useDo any shipments need a license, and do you confirm end use?
Records & controlsCan you produce the documents on demand, and who is accountable?

For each area, the question is the same: how likely is a problem, and how bad would it be?

Scoring Risk: Likelihood × Impact

The standard method rates each identified risk on two axes and multiplies them.

  • Likelihood — how probable is the violation, given your volume, controls, and history?
  • Impact — how severe is the consequence, from a shipment delay to a six- or seven-figure penalty?

A high-likelihood, high-impact item (for example, exporting a controlled item to a high-risk destination with no screening step) is where your first dollars of remediation should go. A low-likelihood, low-impact item can be monitored rather than rebuilt. The goal is not to eliminate every risk; it is to put your controls where they matter most.

A Step-by-Step Assessment

  1. Map your trade flows. List products, destinations, and counterparties on both the import and export side.
  2. Identify the risks in each flow using the categories above.
  3. Score each risk for likelihood and impact.
  4. Prioritize — rank by combined score and focus resources on the top tier.
  5. Remediate — add controls: screening, classification review, a recordkeeping fix, training.
  6. Document and repeat. Write down what you found and did, and re-run the assessment when your products, customers, or the regulations change.

Step six matters most. A risk assessment is a snapshot; trade rules and your own business both move, so a one-time exercise goes stale fast. Most companies revisit it at least annually and after any major change in suppliers, markets, or product lines.

Frequently Asked Questions

What is a trade compliance risk assessment?

It is a structured review of your imports and exports that identifies where a violation is most likely, scores each risk by likelihood and impact, and ranks them so you can direct controls and budget to the highest-exposure areas first.

What framework should I follow?

OFAC’s 2019 Framework for OFAC Compliance Commitments is the most widely cited. It names five components of a risk-based program — management commitment, risk assessment, internal controls, testing and auditing, and training — and treats risk assessment as the basis for the rest.

How often should we redo it?

At least annually, and whenever something material changes — a new supplier or market, a new product line, an acquisition, or a significant change in the regulations. Risk assessments go out of date as your business and the rules evolve.

Does this apply to importers, or only exporters?

Both. Sanctions and export-control risk get the most attention, but importers face their own exposure in classification, valuation, origin, and special duties — all of which a sound assessment should cover.

A risk assessment only pays off if it leads to the right controls, records, and training. Reidel Law Firm helps importers and exporters assess their exposure and build practical programs on flat-fee terms. Get an import/export compliance memo.

← All articles