Skip to content

Evidence request lists

US OFAC Sanctions Compliance Framework

Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Internal Controls

OFAC-SCP-3.2
Transaction Interdiction and Blocking

The organization must operate controls that block or reject transactions involving sanctioned persons or property and report blocked or rejected transactions to OFAC within required timeframes.

Artefacts an auditor will ask for
  • Blocking and rejection procedures
  • Evidence of blocked property segregation in interest-bearing accounts
  • Initial reports of blocked or rejected transactions filed within 10 business days
  • Annual report of blocked property filed by 30 September each year
Where this commonly fails
  • Rejected transactions not reported because firm treats them as declined business
  • Blocked funds held in non-interest-bearing accounts
  • Annual blocked property report missed or filed late
OFAC-SCP-3.3
Country and Comprehensive Sanctions Controls

The organization must implement geographic controls that prevent prohibited dealings with comprehensively sanctioned jurisdictions including Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine.

Artefacts an auditor will ask for
  • Geographic block list configuration in onboarding and payment systems
  • IP-geolocation and shipping address controls for digital channels
  • Trade finance and letter of credit screening procedures
  • Evidence of denial of service for prohibited jurisdictions
Where this commonly fails
  • Reliance on customer-provided country data without independent verification
  • Web and mobile channels lacking IP-geolocation controls
  • No control covering occupied or contested regions within otherwise permitted countries
OFAC-SCP-3.4
Sectoral Sanctions Identification and Controls

The organization must identify and apply restrictions arising from sectoral sanctions programs that limit specific activities such as new debt, new equity, or services with named entities even where outright dealings are not prohibited.

Artefacts an auditor will ask for
  • Sectoral Sanctions Identifications (SSI) List screening procedures
  • Directive-specific control matrices (e.g., debt tenor limits)
  • Training records for front-office staff on sectoral restrictions
  • Documented legal review of new product lines against sectoral programs
Where this commonly fails
  • Front-office systems unable to enforce debt tenor restrictions automatically
  • Sectoral SSI matches treated identically to SDN matches without sectoral context
  • No periodic review when OFAC issues new directives or general licenses
OFAC-SCP-3.5
Licensing and General License Management

The organization must establish procedures to identify when activity requires a specific license, to apply correctly for licenses, and to track adherence to the conditions of any general or specific license relied upon.

Artefacts an auditor will ask for
  • Inventory of general licenses relied upon with expiration tracking
  • Specific license applications and OFAC correspondence
  • Procedures for monitoring license conditions and reporting
  • Records of license-related transactions and quarterly reporting where required
Where this commonly fails
  • General licenses relied upon after expiration or amendment
  • No tracking of reporting conditions attached to specific licenses
  • Licensing decisions made by business without compliance review
OFAC-SCP-3.6
Recordkeeping

The organization must retain records of transactions, licenses, screening alerts, blocked property, and program activities for at least five years to support OFAC examination and enforcement.

Artefacts an auditor will ask for
  • Records retention schedule covering five-year minimum for OFAC records
  • Storage and retrieval procedures for blocked property records
  • Audit logs for screening platforms covering alert disposition history
  • Evidence of immutable or write-once storage for regulatory records
Where this commonly fails
  • Five-year retention applied from transaction date instead of last activity date
  • Screening alert history purged by vendor archive policies
  • Records dispersed across systems without consolidated retrieval procedure
USOFAC-3
Internal Controls (Screening, Interdiction, Recordkeeping)

Per OFAC: Policies and Procedures + Transaction Screening + Interdiction and Escalation + Recordkeeping (5 years per OFAC).

Artefacts an auditor will ask for
  • OFAC evidence for USOFAC-3
Where this commonly fails
  • screening + testing + training partial

Management Commitment

OFAC-SCP-1.2
Sanctions Compliance Officer Appointment

The organization must appoint a dedicated, qualified Sanctions Compliance Officer with sufficient authority, independence, and access to senior management to oversee day-to-day program execution.

Artefacts an auditor will ask for
  • Job description and appointment letter for the Sanctions Compliance Officer
  • Qualifications and training records for the appointed officer
  • Reporting line documentation showing independence from revenue-generating functions
  • Charter defining authority to halt transactions and escalate
Where this commonly fails
  • Sanctions duties combined with AML role without sufficient time allocation
  • No documented escalation path to the board risk committee
  • Officer lacks formal authority to block or unwind transactions

Management Commitment (Pillar 1)

MC-1
Senior Management Support

Senior management must review and approve the sanctions compliance program and allocate adequate resources.

Artefacts an auditor will ask for
  • Senior management food safety policy statement
  • Management review minutes
  • Food safety and quality culture plan
  • Dedicated SQF practitioner or compliance officer appointment letter
  • Resource allocation records (budget, headcount)
Where this commonly fails
  • Culture plan not measurable
  • Reviews skipped quarterly
  • Resource gaps unaddressed
  • Policy not signed by senior leader
MC-2
Compliance Culture

Management must promote a culture of compliance including the ability to report misconduct without reprisal.

Artefacts an auditor will ask for
  • Senior management food safety policy statement
  • Management review minutes
  • Food safety and quality culture plan
  • Dedicated SQF practitioner or compliance officer appointment letter
  • Resource allocation records (budget, headcount)
Where this commonly fails
  • Culture plan not measurable
  • Reviews skipped quarterly
  • Resource gaps unaddressed
  • Policy not signed by senior leader
MC-3
Dedicated Compliance Officer

A qualified compliance officer must be appointed with sufficient authority, stature, and independence.

Artefacts an auditor will ask for
  • Senior management food safety policy statement
  • Management review minutes
  • Food safety and quality culture plan
  • Dedicated SQF practitioner or compliance officer appointment letter
  • Resource allocation records (budget, headcount)
Where this commonly fails
  • Culture plan not measurable
  • Reviews skipped quarterly
  • Resource gaps unaddressed
  • Policy not signed by senior leader
MC-4
Resource Allocation

Adequate human capital, expertise, IT systems, and other resources must be allocated to the compliance function.

Artefacts an auditor will ask for
  • Senior management food safety policy statement
  • Management review minutes
  • Food safety and quality culture plan
  • Dedicated SQF practitioner or compliance officer appointment letter
  • Resource allocation records (budget, headcount)
Where this commonly fails
  • Culture plan not measurable
  • Reviews skipped quarterly
  • Resource gaps unaddressed
  • Policy not signed by senior leader

Risk Assessment

USOFAC-2
Risk Assessment

Per OFAC: risk assessment including customer + product + geographic risk + ongoing review.

Artefacts an auditor will ask for
  • OFAC evidence for USOFAC-2
Where this commonly fails
  • screening + testing + training partial

Risk Assessment and Due Diligence

OFAC-SCP-2.2
Customer and Counterparty Due Diligence

The organization must perform risk-based due diligence on customers, counterparties, and intermediaries to identify direct or indirect connections to sanctioned persons, including ownership analysis under the 50 Percent Rule.

Artefacts an auditor will ask for
  • Customer due diligence procedures referencing OFAC obligations
  • Beneficial ownership records covering ownership thresholds
  • Enhanced due diligence files for higher-risk customers
  • Evidence of periodic refresh tied to risk rating
Where this commonly fails
  • Beneficial ownership lookups stop at 25 percent and miss the OFAC 50 percent aggregation rule
  • No refresh trigger when ownership changes are detected
  • EDD files lack documented rationale for accepting high-risk relationships
OFAC-SCP-7.2
Mergers and Acquisitions Sanctions Due Diligence

The organization must perform sanctions due diligence during mergers, acquisitions, and material investments and integrate acquired entities into the SCP within a defined timeframe.

Artefacts an auditor will ask for
  • M&A sanctions due diligence checklist
  • Pre-close diligence reports on target customer and counterparty exposure
  • Post-close integration plan with milestones
  • Look-back screening of acquired books of business
Where this commonly fails
  • Diligence limited to AML without specific sanctions scope
  • No look-back screening of historical activity within the target
  • Integration milestones exceed 12 months without compensating controls

Senior Commitment

USOFAC-1
Senior Management Commitment

Per OFAC Sanctions Compliance Framework: Senior Management Commitment to Sanctions Compliance + Board oversight + resources + clear accountability.

Artefacts an auditor will ask for
  • OFAC evidence for USOFAC-1
Where this commonly fails
  • screening + testing + training partial

Testing

USOFAC-4
Testing and Audit

Per OFAC: independent testing + audit + remediation.

Artefacts an auditor will ask for
  • OFAC evidence for USOFAC-4
Where this commonly fails
  • screening + testing + training partial

Testing and Auditing

OFAC-SCP-4.2
Issue Identification and Root Cause Analysis

The organization must perform root cause analysis on identified deficiencies, near misses, or breaches and implement corrective actions that address systemic weaknesses rather than isolated symptoms.

Artefacts an auditor will ask for
  • Issue management procedure with root cause methodology
  • Sample root cause analyses for material findings
  • Trend analysis of repeat findings
  • Evidence of management committee review of systemic themes
Where this commonly fails
  • Root cause analyses default to human error without deeper analysis
  • Repeated findings across years not aggregated into systemic remediation
  • No linkage between root cause findings and risk assessment updates
OFAC-SCP-8.2
Management Information and Metrics

The organization must produce management information that allows leadership to monitor sanctions program performance, including screening volumes, alert handling times, audit findings, and emerging risk indicators.

Artefacts an auditor will ask for
  • Sanctions dashboard with key risk and performance indicators
  • Periodic management reports presented to risk committees
  • Threshold and tolerance settings approved by management
  • Trend analysis on alert volumes and disposition outcomes
Where this commonly fails
  • Dashboards focused on activity counts without effectiveness measures
  • No documented tolerances or escalation triggers
  • Reports not retained as a discrete record series

Training

OFAC-SCP-5.2
Senior Management and Board Training

Senior management and the board must receive sanctions training appropriate to their oversight role, including emerging risks, recent enforcement actions, and program performance.

Artefacts an auditor will ask for
  • Board education materials covering sanctions topics
  • Attendance records for executive briefings
  • Annual sanctions program report presented to the board
Where this commonly fails
  • Board briefings limited to AML with sanctions treated as a subtopic
  • No documented training plan for new directors
  • Executive committees rely on summaries lacking enforcement context
USOFAC-5
Training and Voluntary Self-Disclosure

Per OFAC: training + Voluntary Self-Disclosure + cooperation + enforcement.

Artefacts an auditor will ask for
  • OFAC evidence for USOFAC-5
Where this commonly fails
  • screening + testing + training partial

Training (Pillar 5)

TR-1
Periodic Training Program

All appropriate employees must receive sanctions compliance training on a periodic basis.

Artefacts an auditor will ask for
  • Training plan
  • Skills matrix
  • Local talent pipeline records
Where this commonly fails
  • Sparse country adaptation
  • Local workforce data missing
  • Training records incomplete
TR-2
Job-Specific Training

Training must provide role-specific knowledge based on each employee's exposure to sanctions risks.

Artefacts an auditor will ask for
  • Training plan
  • Skills matrix
  • Local talent pipeline records
Where this commonly fails
  • Sparse country adaptation
  • Local workforce data missing
  • Training records incomplete
TR-3
Accountability for Training

Employees must be held accountable for completing training and applying compliance knowledge.

Artefacts an auditor will ask for
  • Training plan
  • Skills matrix
  • Local talent pipeline records
Where this commonly fails
  • Sparse country adaptation
  • Local workforce data missing
  • Training records incomplete
TR-4
Training Updates

Training materials must be updated to reflect changes in OFAC regulations, sanctions programs, and enforcement trends.

Artefacts an auditor will ask for
  • Training plan
  • Skills matrix
  • Local talent pipeline records
Where this commonly fails
  • Sparse country adaptation
  • Local workforce data missing
  • Training records incomplete
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the US OFAC Sanctions Compliance Framework framework page.