OFAC framework for sanctions compliance commitments: what it asks of a monitoring programme
The OFAC framework for a sanctions compliance programme: screening and interdiction, geographic and sectoral controls, due diligence on ownership, testing and the sanctions compliance officer.
Shown when United States is ticked.
Typologies anchored here
4Every obligation cited, quoted
7 of the 24 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim. Rows the export flags as shared evidence are never shown.
OFAC OFAC-SCP-1.2 Sanctions Compliance Officer AppointmentThe organization must appoint a dedicated, qualified Sanctions Compliance Officer with sufficient authority, independence, and access to senior management to oversee day-to-day program execution.
Where programmes usually fall short: Sanctions duties combined with AML role without sufficient time allocation; No documented escalation path to the board risk committee
Source: OFAC framework for sanctions compliance commitments
OFAC OFAC-SCP-2.2 Customer and Counterparty Due DiligenceThe organization must perform risk-based due diligence on customers, counterparties, and intermediaries to identify direct or indirect connections to sanctioned persons, including ownership analysis under the 50 Percent Rule.
Where programmes usually fall short: Beneficial ownership lookups stop at 25 percent and miss the OFAC 50 percent aggregation rule; No refresh trigger when ownership changes are detected
Source: OFAC framework for sanctions compliance commitments
OFAC OFAC-SCP-3.2 Transaction Interdiction and BlockingThe organization must operate controls that block or reject transactions involving sanctioned persons or property and report blocked or rejected transactions to OFAC within required timeframes.
Where programmes usually fall short: Rejected transactions not reported because firm treats them as declined business; Blocked funds held in non-interest-bearing accounts
Source: OFAC framework for sanctions compliance commitments
OFAC OFAC-SCP-3.3 Country and Comprehensive Sanctions ControlsThe organization must implement geographic controls that prevent prohibited dealings with comprehensively sanctioned jurisdictions including Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine.
Where programmes usually fall short: Reliance on customer-provided country data without independent verification; Web and mobile channels lacking IP-geolocation controls
Source: OFAC framework for sanctions compliance commitments
OFAC OFAC-SCP-3.4 Sectoral Sanctions Identification and ControlsThe organization must identify and apply restrictions arising from sectoral sanctions programs that limit specific activities such as new debt, new equity, or services with named entities even where outright dealings are not prohibited.
Where programmes usually fall short: Front-office systems unable to enforce debt tenor restrictions automatically; Sectoral SSI matches treated identically to SDN matches without sectoral context
Source: OFAC framework for sanctions compliance commitments
OFAC USOFAC-3 Internal Controls (Screening, Interdiction, Recordkeeping)Per OFAC: Policies and Procedures + Transaction Screening + Interdiction and Escalation + Recordkeeping (5 years per OFAC).
Where programmes usually fall short: Screening + testing + training partial
Source: OFAC framework for sanctions compliance commitments
OFAC USOFAC-4 Testing and AuditPer OFAC: independent testing + audit + remediation.
Where programmes usually fall short: Screening + testing + training partial
Source: OFAC framework for sanctions compliance commitments