Sanctions Audit Readiness Checklist [2026]
Sanctions Audit Readiness Checklist [2026]
This checklist covers the minimum viable preparation for an OFAC sanctions compliance audit. Complete each section and maintain supporting documentation. Most organizations complete the full checklist in under 2 hours.
Section 1: Screening Infrastructure
- Document your screening tool and integration method (API, MCP, CLI)
- Verify SDN list sync date is within 24 hours
- Confirm all transaction types are covered (payments, refunds, payouts)
- Test screening with known sanctioned wallets — confirm blocking works
- Document screening rate: X transactions screened out of Y total
Section 2: Documentation
- Written sanctions compliance policy (dated, signed, <12 months old)
- Screening procedure document (step-by-step operational guide)
- Risk assessment: jurisdictions served, transaction types, risk levels
- Incident response plan: what happens on a sanctions match
- Third-party vendor due diligence for screening tools
Section 3: Audit Trail
- Screening logs are timestamped and stored for minimum 5 years
- Each log entry includes: counterparty identifier, screening result, timestamp
- Logs are searchable by date range and counterparty
- Match events are logged separately with resolution actions
- Export capability confirmed (CSV or JSON for auditor requests)
Section 4: Training & Governance
- Team received sanctions compliance training within last 12 months
- Training records maintained (dates, attendees, content)
- Designated compliance officer identified (name and contact documented)
- Annual review process defined for compliance program
- Escalation procedure documented for potential matches
Section 5: Remediation Readiness
- Voluntary self-disclosure procedure documented
- Legal counsel contact identified for sanctions matters
- Blocked property reporting procedure in place
- License application procedure documented (if applicable)