By SanctionsAI team · Updated 2026-08-09

How to conduct a sanctions risk assessment

A sanctions risk assessment identifies your organization's exposure and prioritizes compliance controls. OFAC expects every regulated entity to conduct one.

Risk categories

CategoryRisk factorsScoring
GeographicCustomer locations, payment routes1-5
CustomerCustomer types, PEPs, high-risk industries1-5
Product/ServiceWire transfers, crypto, trade finance1-5
TransactionVolume, velocity, cross-border %1-5

Process

Step 1: Map all products, services, customer segments, and markets.

Step 2: Score each category (inherent risk before controls).

Step 3: Assess existing control effectiveness.

Step 4: Calculate residual risk (inherent minus controls).

Step 5: Document gaps and create remediation plan.

OFAC expectation: Risk assessments should be documented, reviewed annually, and updated for business changes.

Screen your agent's next payment

Check any wallet, name, or entity against OFAC, EU, UN sanctions lists in real time.

Free wallet checker

Frequently Asked Questions

How often should I conduct a risk assessment?
Annually at minimum, and when significant business changes occur.
What is residual risk?
Inherent risk minus control effectiveness. Shows actual exposure after mitigations.
What if residual risk is high?
Implement additional controls: enhanced screening, more monitoring, additional training.
Does a risk assessment protect against penalties?
A documented assessment with remediation plan demonstrates good-faith compliance. OFAC considers it mitigating.

← Back to how-to · SanctionsAI