OFAC Risk Matrix

A framework for assessing an organization's sanctions risk across customers, geographies, products, and channels. Used to calibrate the compliance program.

TL;DR

TL;DR: A risk matrix scores an organization's sanctions exposure across dimensions such as customers, geographies, products, and channels. It calibrates how much screening and due diligence each area needs.

How a risk matrix works

A risk matrix lays out dimensions of exposure and scores each one. A customer in a heavily sanctioned jurisdiction scores higher than one in a low-risk country. A product that moves money internationally scores higher than one that does not. A channel that allows anonymous or self-custodied transfers scores higher than a tightly controlled one. The scores combine into an overall picture of where the organization's sanctions risk is concentrated.

Why it calibrates the program

The matrix decides where resources go. High-risk areas get more rigorous controls: enhanced due diligence, lower screening thresholds, and closer human review. Low-risk areas get lighter, faster treatment so the program stays efficient. Without a matrix, every transaction gets the same treatment, which either over-spends on low risk or under-protects high risk.

The agent payment angle

An AI agent that pays on a user's behalf is itself a channel, and the matrix should score it accordingly. The counterparty's jurisdiction and the type of payment, whether a wallet, an account, or a card, determine how much screening is warranted. A tool such as sanctionsai.dev supports a SCREEN, SCORE, STOP, STAMP protocol, giving a risk_score that helps the matrix operate automatically rather than on paper.

Bottom line

A risk matrix is the reasoning layer behind a compliance program. It explains why some payments get more scrutiny than others, which matters when a regulator asks.

Screen your agent’s next payment

Free OFAC sanctions screening — 5 checks/day, no signup.

Check a wallet →