By SanctionsAI team · Updated 2026-08-09

How to document your OFAC compliance program

An undocumented compliance program is not a compliance program. OFAC expects written policies, procedures, and evidence of execution.

The five pillars

PillarDocumentation
Management commitmentBoard-approved policy, designated officer, budget
Risk assessmentDocumented, updated annually
Internal controlsScreening procedures, blocking procedures, escalation
Testing and auditIndependent audit report, findings, remediation
TrainingCurriculum, completion records, content updates

Document hierarchy

Tier 1: Policy (board-approved, high-level). Tier 2: Procedures (operational, detailed). Tier 3: Records (evidence of execution).

For AI agents: Document API integration architecture, screening logic, audit trail format, and escalation triggers.

Screen your agent's next payment

Check any wallet, name, or entity against OFAC, EU, UN sanctions lists in real time.

Free wallet checker

Frequently Asked Questions

What are the five pillars?
Management commitment, risk assessment, internal controls, testing/audit, and training.
How often should policies be updated?
Annually and when significant changes occur. Document the review.
What is the compliance officer's responsibility?
Owns the OFAC program: risk assessment, procedures, screening oversight, training, reporting.
How long must records be kept?
OFAC recommends 5 years. FinCEN requires 5 years for SAR/BSA records.

← Back to how-to · SanctionsAI