How to build a sanctions risk assessment

How to build a sanctions risk assessment

A sanctions risk assessment is the foundation of your compliance program. It identifies where your organization is exposed to sanctions risk and how to prioritize controls.

Step 1: Map your exposure

List every customer type, geographic market, product, and transaction channel. For each, ask: does this touch a sanctioned jurisdiction, entity, or sector?

Step 2: Score risk (Low/Medium/High)

High-risk indicators: crypto payments, cross-border transactions, high-risk jurisdictions, PEP customers, automated/agent payments. Low-risk: domestic only, screened counterparties, limited payment methods.

Step 3: Document controls

For each risk, document what control is in place: screening tool, manual review, geographic blocking, transaction limits. Where controls are missing, flag a remediation item.

Try SanctionsAI →