ChecklistGeopolitics
Sanctions compliance program checklist for US, EU and UK expectations
A sanctions compliance program is judged on whether it fits the organization's real risk and can show that its controls work. This checklist follows the five components of OFAC's compliance framework, namely management commitment, risk assessment, internal controls, testing and auditing, and training, then adds what EU and UK regimes require differently, from ownership and control tests to contract clauses against diversion, recordkeeping and disclosure decisions.
On this page
- The framework behind this checklist
- Management commitment and resourcing
- Inputs to the sanctions risk assessment
- Ownership and control tests compared
- Screening configuration and alert handling
- Goods, trade and diversion controls
- Testing, training and recordkeeping
- Root causes that undo sanctions programs
- Questions and answers
- Sources
The framework behind this checklist
In May 2019 OFAC published A Framework for OFAC Compliance Commitments, which sets out five essential components of a sanctions compliance program and lists root causes found in past enforcement cases1. It remains the clearest single statement of what a US authority expects, and EU and UK supervisors look for broadly similar elements even though their legal bases differ.
EU restrictive measures are adopted as Council regulations that apply directly in every member state and are enforced by national authorities. UK sanctions regulations are made under the Sanctions and Anti-Money Laundering Act 2018, with OFSI enforcing financial sanctions2. A program serving all three regimes should meet the strictest relevant requirement for each control and record where the regimes diverge.
Sanctions compliance program design is one of the offerings of ColdAI's geopolitics practice, alongside sanctions screening and export control advisory3. This checklist is the structure we work from, and your own team can use it directly.
Management commitment and resourcing
Inputs to the sanctions risk assessment
Ownership and control tests compared
Screening names is not enough: each regime also restricts entities that listed persons own or control, and the tests differ.
| Question | US (OFAC) | EU | UK (OFSI) |
|---|---|---|---|
| Ownership threshold | Ownership of 50 percent or more, directly or indirectly, by one or more blocked persons4 | Ownership of more than half of the proprietary rights, or a majority interest | More than 50 percent of the shares or voting rights, directly or indirectly5 |
| Aggregation across listed persons | Yes: stakes held by different blocked persons are added together4 | Check the Council's best-practice guidance and national authority views on joint ownership | Holdings are not simply added together unless there is a joint arrangement or one party controls the other's rights5 |
| Control without majority ownership | Does not by itself block the entity, but OFAC warns that dealings carry risk and the entity may be designated4 | A separate test, judged on criteria such as the power to appoint or remove most board members | A separate test, met where it is reasonable to expect the designated person could ensure the entity's affairs follow their wishes5 |
| What it means in practice | Collect ownership chains and add up blocked stakes | Assess ownership and control separately, with documented reasoning | Assess board rights and practical influence, not only shareholdings |
Summaries of public guidance at this page's review date. Ownership questions in complex structures, such as trusts or nominee holdings, need legal review.
Screening configuration and alert handling
Goods, trade and diversion controls
Testing, training and recordkeeping
Root causes that undo sanctions programs
Screening set up once and never tuned
Early signalThresholds date from implementation and there are no tuning records.
MitigationTest against known name variants on a schedule and keep the evidence.
Counterparties checked by name only
Early signalOnboarding files show the counterparty but no ownership chain.
MitigationCollect beneficial ownership data and screen each owner against the relevant tests.
Non-US subsidiaries assuming US rules cannot reach them
Early signalDollar payments, US-origin goods or US staff appear in deals booked abroad.
MitigationMap US nexus points for each business line and set controls accordingly.
Decentralized compliance
Early signalBusiness units run their own screening with different lists and thresholds.
MitigationSet central standards and oversight while letting local teams operate them.
Questions and answers
What are the five components of an OFAC compliance program?
OFAC's framework names management commitment, risk assessment, internal controls, testing and auditing, and training. OFAC expects each to be tailored to the organization's size, products, customers and geographic footprint, and it weighs the existence and quality of such a program when deciding how to respond to an apparent violation. A policy document alone does not satisfy the framework; evidence that controls operate is what counts.
Do non-US companies need an OFAC compliance program?
Many do. OFAC sanctions can apply to non-US companies that cause US persons to violate them, for example by routing dollar payments through US banks or exporting US-origin goods to sanctioned destinations, and secondary sanctions can target non-US firms directly. A company with no US nexus at all may need less, but it should reach that conclusion through a documented risk assessment rather than assume it.
How often should a sanctions risk assessment be updated?
Update it whenever the business or the rules change materially, for instance when entering a new market, launching a product, acquiring a company or responding to a major new sanctions package, and review it on a regular cycle, commonly once a year. Each update should show what changed, how controls were adjusted and who approved the result.
How is a sanctions compliance program different from AML transaction monitoring?
Sanctions controls are prohibitions: they stop dealings with listed persons, owned or controlled entities and restricted goods or destinations, mostly before a transaction happens. Anti-money laundering monitoring looks for suspicious patterns after transactions occur and leads to reporting. The two share data and teams, and AI can help with both, as our AML alert triage use case shows, but they need separate controls and evidence.
Sources
- A Framework for OFAC Compliance Commitments — US Department of the Treasury, Office of Foreign Assets Control · checked 10 October 2026
- Sanctions and Anti-Money Laundering Act 2018 — legislation.gov.uk · checked 10 October 2026
- Geopolitics capability: sanctions and trade compliance offering — ColdAI
- Entities Owned by Blocked Persons (50% Rule): frequently asked questions — US Department of the Treasury, Office of Foreign Assets Control · checked 10 October 2026
- UK financial sanctions general guidance — Office of Financial Sanctions Implementation, HM Treasury · checked 10 October 2026
- Council Regulation (EU) No 833/2014 concerning restrictive measures in view of Russia's actions destabilising the situation in Ukraine (consolidated) — EUR-Lex · checked 10 October 2026
- U.S. Treasury Extends Recordkeeping Requirement for Economic Sanctions Compliance to 10 Years — Greenberg Traurig · checked 10 October 2026