OFAC Risk Matrix
A framework for assessing an organization's sanctions risk across customers, geographies, products, and channels. Used to calibrate the compliance program.
TL;DR
TL;DR: A risk matrix scores an organization's sanctions exposure across dimensions such as customers, geographies, products, and channels. It calibrates how much screening and due diligence each area needs.
How a risk matrix works
A risk matrix lays out dimensions of exposure and scores each one. A customer in a heavily sanctioned jurisdiction scores higher than one in a low-risk country. A product that moves money internationally scores higher than one that does not. A channel that allows anonymous or self-custodied transfers scores higher than a tightly controlled one. The scores combine into an overall picture of where the organization's sanctions risk is concentrated.
Why it calibrates the program
The matrix decides where resources go. High-risk areas get more rigorous controls: enhanced due diligence, lower screening thresholds, and closer human review. Low-risk areas get lighter, faster treatment so the program stays efficient. Without a matrix, every transaction gets the same treatment, which either over-spends on low risk or under-protects high risk.
The agent payment angle
An AI agent that pays on a user's behalf is itself a channel, and the matrix should score it accordingly. The counterparty's jurisdiction and the type of payment, whether a wallet, an account, or a card, determine how much screening is warranted. A tool such as sanctionsai.dev supports a SCREEN, SCORE, STOP, STAMP protocol, giving a risk_score that helps the matrix operate automatically rather than on paper.
Bottom line
A risk matrix is the reasoning layer behind a compliance program. It explains why some payments get more scrutiny than others, which matters when a regulator asks.