By SanctionsAI team · Updated 2026-08-09
How to document your OFAC compliance program
An undocumented compliance program is not a compliance program. OFAC expects written policies, procedures, and evidence of execution.
The five pillars
| Pillar | Documentation |
| Management commitment | Board-approved policy, designated officer, budget |
| Risk assessment | Documented, updated annually |
| Internal controls | Screening procedures, blocking procedures, escalation |
| Testing and audit | Independent audit report, findings, remediation |
| Training | Curriculum, completion records, content updates |
Document hierarchy
Tier 1: Policy (board-approved, high-level). Tier 2: Procedures (operational, detailed). Tier 3: Records (evidence of execution).
For AI agents: Document API integration architecture, screening logic, audit trail format, and escalation triggers.
Screen your agent's next payment
Check any wallet, name, or entity against OFAC, EU, UN sanctions lists in real time.
Free wallet checker
Frequently Asked Questions
- What are the five pillars?
- Management commitment, risk assessment, internal controls, testing/audit, and training.
- How often should policies be updated?
- Annually and when significant changes occur. Document the review.
- What is the compliance officer's responsibility?
- Owns the OFAC program: risk assessment, procedures, screening oversight, training, reporting.
- How long must records be kept?
- OFAC recommends 5 years. FinCEN requires 5 years for SAR/BSA records.
← Back to how-to · SanctionsAI