An OFAC compliance program template for a small business
OFAC regulations do not require a formal sanctions compliance program, but OFAC encourages one and weighs it when it decides penalties (OFAC Framework, 2019). OFAC's Framework says a program should rest on at least five components: management commitment, risk assessment, internal controls, testing and auditing, and training. The template below covers each one in plain language that a 5 to 50 person dealership, title agency, distributor or exporter can adapt, sign and file this week.
Why write it down
- OFAC lists the lack of a formal program as a root cause in numerous penalty cases, and frequently as an aggravating factor (OFAC Framework).
- OFAC considers the existence, nature and adequacy of a risk-based compliance program when it weighs a penalty (31 CFR Part 501, Appendix A), and says it will consider favorably those that had an effective program at the time of an apparent violation (OFAC Framework).
- OFAC generally enforces on a strict liability basis (OFAC guidance, October 2021, p. 6). A program and its records are how you show what you did.
The template
Replace everything in angle brackets. Keep the signed copy and every revision.
<COMPANY NAME> OFAC SANCTIONS COMPLIANCE POLICY
Version <n>, adopted <date>, approved by <owner or senior manager>
1. MANAGEMENT COMMITMENT
<Name, title> is responsible for this policy and has the authority
and resources to apply it. Management reviews it at least <yearly>.
2. RISK ASSESSMENT
We deal with: <customers / vendors / employees / counterparties>.
Our exposure: <domestic retail sales / closings / foreign suppliers /
exports to ...>. Higher-risk cases: <third-party payers, entity buyers,
foreign parties, new vendors>. Reviewed <yearly> and after any change
in what we sell or where.
3. INTERNAL CONTROLS
3.1 Who we screen: <every party to every deal / every vendor / ...>.
3.2 When: <before each transaction>; full list re-screened <monthly>;
new vendors before first payment.
3.3 Lists: OFAC SDN and Consolidated lists <plus the Consolidated
Screening List for exports>.
3.4 Hits: reviewed by <role> using OFAC's FAQ 5 steps. Every
decision recorded with a written reason.
3.5 True matches: transaction stopped; property blocked or
transaction rejected as required; reported to OFAC within
10 business days.
3.6 Records: each screening and decision kept at least 10 years.
4. TESTING AND AUDITING
<Role or outside reviewer> checks a sample of <n> screenings
<quarterly>, confirms the lists used were current, and reports
findings to <owner>. Weaknesses are fixed and the fix recorded.
5. TRAINING
Everyone who opens deals, closes files or pays vendors is trained
at hire and <yearly>. Attendance is logged with date and name.Where each line comes from
- Management commitment, risk assessment, internal controls, testing and auditing, training: the five components in OFAC's Framework. The Framework asks for written policies and procedures, internal controls that identify, interdict, escalate, report and keep records, and training at a frequency set by your risk assessment.
- Screening frequency: OFAC leaves it to your own policies and procedures (OFAC FAQ 28).
- Hits: OFAC's six steps for assessing a potential match (OFAC FAQ 5). See how to clear an OFAC false positive.
- Reporting within 10 business days: 31 CFR 501.603 for blocked property and 31 CFR 501.604 for rejected transactions.
- Ten-year records: 31 CFR 501.601.
- Software that keeps up with list changes: the Framework names screening software that was not updated to include list changes, or that missed alternative spellings, as a root cause of violations (OFAC Framework).
A template is a starting point, not legal advice. Have counsel review it if your business has foreign customers, foreign suppliers or exports.
Put section 3 to work
Run a free OFAC check against the current SDN and Consolidated lists, and file the result under section 3.6.