How to build a sanctions risk assessment
How to build a sanctions risk assessment
A sanctions risk assessment is the foundation of your compliance program. It identifies where your organization is exposed to sanctions risk and how to prioritize controls.
Step 1: Map your exposure
List every customer type, geographic market, product, and transaction channel. For each, ask: does this touch a sanctioned jurisdiction, entity, or sector?
Step 2: Score risk (Low/Medium/High)
High-risk indicators: crypto payments, cross-border transactions, high-risk jurisdictions, PEP customers, automated/agent payments. Low-risk: domestic only, screened counterparties, limited payment methods.
Step 3: Document controls
For each risk, document what control is in place: screening tool, manual review, geographic blocking, transaction limits. Where controls are missing, flag a remediation item.