AML Scenario Gap Finder
Regime

OFAC framework for sanctions compliance commitments: what it asks of a monitoring programme

The OFAC framework for a sanctions compliance programme: screening and interdiction, geographic and sectoral controls, due diligence on ownership, testing and the sanctions compliance officer.

Shown when United States is ticked.

Typologies anchored here

4
TypologyObligation
Sanctions name screeningOFAC OFAC-SCP-3.2 ยท OFAC USOFAC-3
Sanctioned ownership and controlOFAC OFAC-SCP-2.2
Comprehensively sanctioned geographiesOFAC OFAC-SCP-3.3
Sectoral sanctionsOFAC OFAC-SCP-3.4

Every obligation cited, quoted

7 of the 24 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim. Rows the export flags as shared evidence are never shown.

OFAC OFAC-SCP-1.2 Sanctions Compliance Officer Appointment

The organization must appoint a dedicated, qualified Sanctions Compliance Officer with sufficient authority, independence, and access to senior management to oversee day-to-day program execution.

What an examiner asks to see: Job description and appointment letter for the Sanctions Compliance Officer; Qualifications and training records for the appointed officer; Reporting line documentation showing independence from revenue-generating functions; Charter defining authority to halt transactions and escalate
Where programmes usually fall short: Sanctions duties combined with AML role without sufficient time allocation; No documented escalation path to the board risk committee
Source: OFAC framework for sanctions compliance commitments
OFAC OFAC-SCP-2.2 Customer and Counterparty Due Diligence

The organization must perform risk-based due diligence on customers, counterparties, and intermediaries to identify direct or indirect connections to sanctioned persons, including ownership analysis under the 50 Percent Rule.

What an examiner asks to see: Customer due diligence procedures referencing OFAC obligations; Beneficial ownership records covering ownership thresholds; Enhanced due diligence files for higher-risk customers; Evidence of periodic refresh tied to risk rating
Where programmes usually fall short: Beneficial ownership lookups stop at 25 percent and miss the OFAC 50 percent aggregation rule; No refresh trigger when ownership changes are detected
Source: OFAC framework for sanctions compliance commitments
OFAC OFAC-SCP-3.2 Transaction Interdiction and Blocking

The organization must operate controls that block or reject transactions involving sanctioned persons or property and report blocked or rejected transactions to OFAC within required timeframes.

What an examiner asks to see: Blocking and rejection procedures; Evidence of blocked property segregation in interest-bearing accounts; Initial reports of blocked or rejected transactions filed within 10 business days; Annual report of blocked property filed by 30 September each year
Where programmes usually fall short: Rejected transactions not reported because firm treats them as declined business; Blocked funds held in non-interest-bearing accounts
Source: OFAC framework for sanctions compliance commitments
OFAC OFAC-SCP-3.3 Country and Comprehensive Sanctions Controls

The organization must implement geographic controls that prevent prohibited dealings with comprehensively sanctioned jurisdictions including Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine.

What an examiner asks to see: Geographic block list configuration in onboarding and payment systems; IP-geolocation and shipping address controls for digital channels; Trade finance and letter of credit screening procedures; Evidence of denial of service for prohibited jurisdictions
Where programmes usually fall short: Reliance on customer-provided country data without independent verification; Web and mobile channels lacking IP-geolocation controls
Source: OFAC framework for sanctions compliance commitments
OFAC OFAC-SCP-3.4 Sectoral Sanctions Identification and Controls

The organization must identify and apply restrictions arising from sectoral sanctions programs that limit specific activities such as new debt, new equity, or services with named entities even where outright dealings are not prohibited.

What an examiner asks to see: Sectoral Sanctions Identifications (SSI) List screening procedures; Directive-specific control matrices (e.g., debt tenor limits); Training records for front-office staff on sectoral restrictions; Documented legal review of new product lines against sectoral programs
Where programmes usually fall short: Front-office systems unable to enforce debt tenor restrictions automatically; Sectoral SSI matches treated identically to SDN matches without sectoral context
Source: OFAC framework for sanctions compliance commitments
OFAC USOFAC-3 Internal Controls (Screening, Interdiction, Recordkeeping)

Per OFAC: Policies and Procedures + Transaction Screening + Interdiction and Escalation + Recordkeeping (5 years per OFAC).

What an examiner asks to see: evidence guidance not held for this clause
Where programmes usually fall short: Screening + testing + training partial
Source: OFAC framework for sanctions compliance commitments
OFAC USOFAC-4 Testing and Audit

Per OFAC: independent testing + audit + remediation.

What an examiner asks to see: evidence guidance not held for this clause
Where programmes usually fall short: Screening + testing + training partial
Source: OFAC framework for sanctions compliance commitments