OFAC Compliance Program Framework

OFAC's five-pillar framework for sanctions compliance: management commitment, risk assessment, internal controls, testing and audit, and training.

TL;DR

TL;DR: The compliance framework is OFAC's five-pillar model for a sanctions program, covering management commitment, risk assessment, internal controls, testing and audit, and training. It is the standard against which programs are judged.

What the framework covers

OFAC published the framework to describe what a credible sanctions compliance program looks like. The pillars are management commitment, a risk assessment, internal controls, testing and audit, and training. Enforcement actions repeatedly reference these pillars, so a program that cannot show them is treated as weaker when a violation is reviewed.

Why it matters for agent payments

An agent-payment operator builds the framework into software. The internal controls pillar is where screening lives: a check wired into the payment path so every transaction is verified. Testing and audit is where the operator verifies the check actually runs, and training becomes documentation of how the agent's decisions are reviewed. Each pillar maps to something concrete in an automated system.

The five pillars

How the pillars connect

The pillars are meant to be read together, not as a checklist of separate items. A risk assessment informs internal controls, testing verifies the controls, and training makes the commitments real. A program that scores well on one pillar but ignores another still fails the overall test. For an automated system, the pillars connect through the same data: the risk assessment defines what to screen, and the controls and testing prove the screening runs.

Screen your agent’s next payment

Free OFAC sanctions screening — 5 checks/day, no signup.

Check a wallet →