By SanctionsAI team · Updated 2026-08-09
How to conduct a sanctions risk assessment
A sanctions risk assessment identifies your organization's exposure and prioritizes compliance controls. OFAC expects every regulated entity to conduct one.
Risk categories
| Category | Risk factors | Scoring |
| Geographic | Customer locations, payment routes | 1-5 |
| Customer | Customer types, PEPs, high-risk industries | 1-5 |
| Product/Service | Wire transfers, crypto, trade finance | 1-5 |
| Transaction | Volume, velocity, cross-border % | 1-5 |
Process
Step 1: Map all products, services, customer segments, and markets.
Step 2: Score each category (inherent risk before controls).
Step 3: Assess existing control effectiveness.
Step 4: Calculate residual risk (inherent minus controls).
Step 5: Document gaps and create remediation plan.
OFAC expectation: Risk assessments should be documented, reviewed annually, and updated for business changes.
Screen your agent's next payment
Check any wallet, name, or entity against OFAC, EU, UN sanctions lists in real time.
Free wallet checker
Frequently Asked Questions
- How often should I conduct a risk assessment?
- Annually at minimum, and when significant business changes occur.
- What is residual risk?
- Inherent risk minus control effectiveness. Shows actual exposure after mitigations.
- What if residual risk is high?
- Implement additional controls: enhanced screening, more monitoring, additional training.
- Does a risk assessment protect against penalties?
- A documented assessment with remediation plan demonstrates good-faith compliance. OFAC considers it mitigating.
← Back to how-to · SanctionsAI