US OFAC Sanctions Compliance Framework
Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Internal Controls
The organization must operate controls that block or reject transactions involving sanctioned persons or property and report blocked or rejected transactions to OFAC within required timeframes.
- Blocking and rejection procedures
- Evidence of blocked property segregation in interest-bearing accounts
- Initial reports of blocked or rejected transactions filed within 10 business days
- Annual report of blocked property filed by 30 September each year
- Rejected transactions not reported because firm treats them as declined business
- Blocked funds held in non-interest-bearing accounts
- Annual blocked property report missed or filed late
The organization must implement geographic controls that prevent prohibited dealings with comprehensively sanctioned jurisdictions including Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine.
- Geographic block list configuration in onboarding and payment systems
- IP-geolocation and shipping address controls for digital channels
- Trade finance and letter of credit screening procedures
- Evidence of denial of service for prohibited jurisdictions
- Reliance on customer-provided country data without independent verification
- Web and mobile channels lacking IP-geolocation controls
- No control covering occupied or contested regions within otherwise permitted countries
The organization must identify and apply restrictions arising from sectoral sanctions programs that limit specific activities such as new debt, new equity, or services with named entities even where outright dealings are not prohibited.
- Sectoral Sanctions Identifications (SSI) List screening procedures
- Directive-specific control matrices (e.g., debt tenor limits)
- Training records for front-office staff on sectoral restrictions
- Documented legal review of new product lines against sectoral programs
- Front-office systems unable to enforce debt tenor restrictions automatically
- Sectoral SSI matches treated identically to SDN matches without sectoral context
- No periodic review when OFAC issues new directives or general licenses
The organization must establish procedures to identify when activity requires a specific license, to apply correctly for licenses, and to track adherence to the conditions of any general or specific license relied upon.
- Inventory of general licenses relied upon with expiration tracking
- Specific license applications and OFAC correspondence
- Procedures for monitoring license conditions and reporting
- Records of license-related transactions and quarterly reporting where required
- General licenses relied upon after expiration or amendment
- No tracking of reporting conditions attached to specific licenses
- Licensing decisions made by business without compliance review
The organization must retain records of transactions, licenses, screening alerts, blocked property, and program activities for at least five years to support OFAC examination and enforcement.
- Records retention schedule covering five-year minimum for OFAC records
- Storage and retrieval procedures for blocked property records
- Audit logs for screening platforms covering alert disposition history
- Evidence of immutable or write-once storage for regulatory records
- Five-year retention applied from transaction date instead of last activity date
- Screening alert history purged by vendor archive policies
- Records dispersed across systems without consolidated retrieval procedure
Per OFAC: Policies and Procedures + Transaction Screening + Interdiction and Escalation + Recordkeeping (5 years per OFAC).
- OFAC evidence for USOFAC-3
- screening + testing + training partial
Management Commitment
The organization must appoint a dedicated, qualified Sanctions Compliance Officer with sufficient authority, independence, and access to senior management to oversee day-to-day program execution.
- Job description and appointment letter for the Sanctions Compliance Officer
- Qualifications and training records for the appointed officer
- Reporting line documentation showing independence from revenue-generating functions
- Charter defining authority to halt transactions and escalate
- Sanctions duties combined with AML role without sufficient time allocation
- No documented escalation path to the board risk committee
- Officer lacks formal authority to block or unwind transactions
Management Commitment (Pillar 1)
Senior management must review and approve the sanctions compliance program and allocate adequate resources.
- Senior management food safety policy statement
- Management review minutes
- Food safety and quality culture plan
- Dedicated SQF practitioner or compliance officer appointment letter
- Resource allocation records (budget, headcount)
- Culture plan not measurable
- Reviews skipped quarterly
- Resource gaps unaddressed
- Policy not signed by senior leader
Management must promote a culture of compliance including the ability to report misconduct without reprisal.
- Senior management food safety policy statement
- Management review minutes
- Food safety and quality culture plan
- Dedicated SQF practitioner or compliance officer appointment letter
- Resource allocation records (budget, headcount)
- Culture plan not measurable
- Reviews skipped quarterly
- Resource gaps unaddressed
- Policy not signed by senior leader
A qualified compliance officer must be appointed with sufficient authority, stature, and independence.
- Senior management food safety policy statement
- Management review minutes
- Food safety and quality culture plan
- Dedicated SQF practitioner or compliance officer appointment letter
- Resource allocation records (budget, headcount)
- Culture plan not measurable
- Reviews skipped quarterly
- Resource gaps unaddressed
- Policy not signed by senior leader
Adequate human capital, expertise, IT systems, and other resources must be allocated to the compliance function.
- Senior management food safety policy statement
- Management review minutes
- Food safety and quality culture plan
- Dedicated SQF practitioner or compliance officer appointment letter
- Resource allocation records (budget, headcount)
- Culture plan not measurable
- Reviews skipped quarterly
- Resource gaps unaddressed
- Policy not signed by senior leader
Risk Assessment
Per OFAC: risk assessment including customer + product + geographic risk + ongoing review.
- OFAC evidence for USOFAC-2
- screening + testing + training partial
Risk Assessment and Due Diligence
The organization must perform risk-based due diligence on customers, counterparties, and intermediaries to identify direct or indirect connections to sanctioned persons, including ownership analysis under the 50 Percent Rule.
- Customer due diligence procedures referencing OFAC obligations
- Beneficial ownership records covering ownership thresholds
- Enhanced due diligence files for higher-risk customers
- Evidence of periodic refresh tied to risk rating
- Beneficial ownership lookups stop at 25 percent and miss the OFAC 50 percent aggregation rule
- No refresh trigger when ownership changes are detected
- EDD files lack documented rationale for accepting high-risk relationships
The organization must perform sanctions due diligence during mergers, acquisitions, and material investments and integrate acquired entities into the SCP within a defined timeframe.
- M&A sanctions due diligence checklist
- Pre-close diligence reports on target customer and counterparty exposure
- Post-close integration plan with milestones
- Look-back screening of acquired books of business
- Diligence limited to AML without specific sanctions scope
- No look-back screening of historical activity within the target
- Integration milestones exceed 12 months without compensating controls
Senior Commitment
Per OFAC Sanctions Compliance Framework: Senior Management Commitment to Sanctions Compliance + Board oversight + resources + clear accountability.
- OFAC evidence for USOFAC-1
- screening + testing + training partial
Testing
Per OFAC: independent testing + audit + remediation.
- OFAC evidence for USOFAC-4
- screening + testing + training partial
Testing and Auditing
The organization must perform root cause analysis on identified deficiencies, near misses, or breaches and implement corrective actions that address systemic weaknesses rather than isolated symptoms.
- Issue management procedure with root cause methodology
- Sample root cause analyses for material findings
- Trend analysis of repeat findings
- Evidence of management committee review of systemic themes
- Root cause analyses default to human error without deeper analysis
- Repeated findings across years not aggregated into systemic remediation
- No linkage between root cause findings and risk assessment updates
The organization must produce management information that allows leadership to monitor sanctions program performance, including screening volumes, alert handling times, audit findings, and emerging risk indicators.
- Sanctions dashboard with key risk and performance indicators
- Periodic management reports presented to risk committees
- Threshold and tolerance settings approved by management
- Trend analysis on alert volumes and disposition outcomes
- Dashboards focused on activity counts without effectiveness measures
- No documented tolerances or escalation triggers
- Reports not retained as a discrete record series
Training
Senior management and the board must receive sanctions training appropriate to their oversight role, including emerging risks, recent enforcement actions, and program performance.
- Board education materials covering sanctions topics
- Attendance records for executive briefings
- Annual sanctions program report presented to the board
- Board briefings limited to AML with sanctions treated as a subtopic
- No documented training plan for new directors
- Executive committees rely on summaries lacking enforcement context
Per OFAC: training + Voluntary Self-Disclosure + cooperation + enforcement.
- OFAC evidence for USOFAC-5
- screening + testing + training partial
Training (Pillar 5)
All appropriate employees must receive sanctions compliance training on a periodic basis.
- Training plan
- Skills matrix
- Local talent pipeline records
- Sparse country adaptation
- Local workforce data missing
- Training records incomplete
Training must provide role-specific knowledge based on each employee's exposure to sanctions risks.
- Training plan
- Skills matrix
- Local talent pipeline records
- Sparse country adaptation
- Local workforce data missing
- Training records incomplete
Employees must be held accountable for completing training and applying compliance knowledge.
- Training plan
- Skills matrix
- Local talent pipeline records
- Sparse country adaptation
- Local workforce data missing
- Training records incomplete
Training materials must be updated to reflect changes in OFAC regulations, sanctions programs, and enforcement trends.
- Training plan
- Skills matrix
- Local talent pipeline records
- Sparse country adaptation
- Local workforce data missing
- Training records incomplete
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the US OFAC Sanctions Compliance Framework framework page.