OFAC Risk-Based Approach
Allocating compliance resources according to assessed risk rather than treating every transaction identically.
TL;DR
TL;DR: A risk-based approach directs the most screening effort at the highest risk counterparties and channels, instead of spreading identical checks across every transaction.
How the approach works
A risk-based approach starts with assessing where sanctions exposure is highest. Risk factors include the counterparty, the geography, the product, and the payment channel. Higher risk transactions receive more scrutiny, while routine, low risk flows are handled more efficiently. The goal is proportionate controls, not uniform ones. The approach does not mean low risk flows go unscreened; it means the depth of review, documentation, and escalation scales with the risk score.
Why risk matters
Uniform screening can waste effort on low risk flows while leaving high risk channels under controlled. A risk based method makes that tradeoff explicit and auditable, which is what regulators expect a mature compliance program to demonstrate. The key is that risk scoring is documented and consistently applied. A documented methodology also shows regulators that resource allocation is deliberate rather than random.
Risk scoring for agent payments
For AI agents, a risk score per counterparty supports this approach. sanctionsai.dev offers a risk_score tool alongside sanctions_check, so an agent can screen and score each counterparty before paying. The 4-Gate Agent Payment Protocol, SCREEN, SCORE, STOP, and STAMP, makes the risk decision an explicit step in every payment, rather than a uniform pass or fail. For high risk counterparties, a score can trigger additional checks such as ownership review under the 50 Percent Rule.