ChecklistGeopolitics

Sanctions compliance program checklist for US, EU and UK expectations

A sanctions compliance program is judged on whether it fits the organization's real risk and can show that its controls work. This checklist follows the five components of OFAC's compliance framework, namely management commitment, risk assessment, internal controls, testing and auditing, and training, then adds what EU and UK regimes require differently, from ownership and control tests to contract clauses against diversion, recordkeeping and disclosure decisions.

Reviewed 6 min read

On this page
  1. The framework behind this checklist
  2. Management commitment and resourcing
  3. Inputs to the sanctions risk assessment
  4. Ownership and control tests compared
  5. Screening configuration and alert handling
  6. Goods, trade and diversion controls
  7. Testing, training and recordkeeping
  8. Root causes that undo sanctions programs
  9. Questions and answers
  10. Sources

The framework behind this checklist

In May 2019 OFAC published A Framework for OFAC Compliance Commitments, which sets out five essential components of a sanctions compliance program and lists root causes found in past enforcement cases1. It remains the clearest single statement of what a US authority expects, and EU and UK supervisors look for broadly similar elements even though their legal bases differ.

EU restrictive measures are adopted as Council regulations that apply directly in every member state and are enforced by national authorities. UK sanctions regulations are made under the Sanctions and Anti-Money Laundering Act 2018, with OFSI enforcing financial sanctions2. A program serving all three regimes should meet the strictest relevant requirement for each control and record where the regimes diverge.

Sanctions compliance program design is one of the offerings of ColdAI's geopolitics practice, alongside sanctions screening and export control advisory3. This checklist is the structure we work from, and your own team can use it directly.

Management commitment and resourcing

0 of 5 checked

Inputs to the sanctions risk assessment

0 of 6 checked

Ownership and control tests compared

Screening names is not enough: each regime also restricts entities that listed persons own or control, and the tests differ.

QuestionUS (OFAC)EUUK (OFSI)
Ownership thresholdOwnership of 50 percent or more, directly or indirectly, by one or more blocked persons4Ownership of more than half of the proprietary rights, or a majority interestMore than 50 percent of the shares or voting rights, directly or indirectly5
Aggregation across listed personsYes: stakes held by different blocked persons are added together4Check the Council's best-practice guidance and national authority views on joint ownershipHoldings are not simply added together unless there is a joint arrangement or one party controls the other's rights5
Control without majority ownershipDoes not by itself block the entity, but OFAC warns that dealings carry risk and the entity may be designated4A separate test, judged on criteria such as the power to appoint or remove most board membersA separate test, met where it is reasonable to expect the designated person could ensure the entity's affairs follow their wishes5
What it means in practiceCollect ownership chains and add up blocked stakesAssess ownership and control separately, with documented reasoningAssess board rights and practical influence, not only shareholdings

Summaries of public guidance at this page's review date. Ownership questions in complex structures, such as trusts or nominee holdings, need legal review.

Screening configuration and alert handling

0 of 6 checked

Goods, trade and diversion controls

0 of 5 checked

Testing, training and recordkeeping

0 of 5 checked

Root causes that undo sanctions programs

Screening set up once and never tuned

Early signalThresholds date from implementation and there are no tuning records.

MitigationTest against known name variants on a schedule and keep the evidence.

Counterparties checked by name only

Early signalOnboarding files show the counterparty but no ownership chain.

MitigationCollect beneficial ownership data and screen each owner against the relevant tests.

Non-US subsidiaries assuming US rules cannot reach them

Early signalDollar payments, US-origin goods or US staff appear in deals booked abroad.

MitigationMap US nexus points for each business line and set controls accordingly.

Decentralized compliance

Early signalBusiness units run their own screening with different lists and thresholds.

MitigationSet central standards and oversight while letting local teams operate them.

Questions and answers

What are the five components of an OFAC compliance program?

OFAC's framework names management commitment, risk assessment, internal controls, testing and auditing, and training. OFAC expects each to be tailored to the organization's size, products, customers and geographic footprint, and it weighs the existence and quality of such a program when deciding how to respond to an apparent violation. A policy document alone does not satisfy the framework; evidence that controls operate is what counts.

Do non-US companies need an OFAC compliance program?

Many do. OFAC sanctions can apply to non-US companies that cause US persons to violate them, for example by routing dollar payments through US banks or exporting US-origin goods to sanctioned destinations, and secondary sanctions can target non-US firms directly. A company with no US nexus at all may need less, but it should reach that conclusion through a documented risk assessment rather than assume it.

How often should a sanctions risk assessment be updated?

Update it whenever the business or the rules change materially, for instance when entering a new market, launching a product, acquiring a company or responding to a major new sanctions package, and review it on a regular cycle, commonly once a year. Each update should show what changed, how controls were adjusted and who approved the result.

How is a sanctions compliance program different from AML transaction monitoring?

Sanctions controls are prohibitions: they stop dealings with listed persons, owned or controlled entities and restricted goods or destinations, mostly before a transaction happens. Anti-money laundering monitoring looks for suspicious patterns after transactions occur and leads to reporting. The two share data and teams, and AI can help with both, as our AML alert triage use case shows, but they need separate controls and evidence.

Sources

  1. A Framework for OFAC Compliance Commitments — US Department of the Treasury, Office of Foreign Assets Control · checked 10 October 2026
  2. Sanctions and Anti-Money Laundering Act 2018 — legislation.gov.uk · checked 10 October 2026
  3. Geopolitics capability: sanctions and trade compliance offering — ColdAI
  4. Entities Owned by Blocked Persons (50% Rule): frequently asked questions — US Department of the Treasury, Office of Foreign Assets Control · checked 10 October 2026
  5. UK financial sanctions general guidance — Office of Financial Sanctions Implementation, HM Treasury · checked 10 October 2026
  6. Council Regulation (EU) No 833/2014 concerning restrictive measures in view of Russia's actions destabilising the situation in Ukraine (consolidated) — EUR-Lex · checked 10 October 2026
  7. U.S. Treasury Extends Recordkeeping Requirement for Economic Sanctions Compliance to 10 Years — Greenberg Traurig · checked 10 October 2026

More in Geopolitics

Back to Geopolitics

Next step

Have your sanctions program reviewed against this checklist

Share your current policy, risk assessment and screening setup. We will tell you where the gaps against US, EU and UK expectations are likely to be and what to fix first, working alongside your counsel.

Discuss a program review