What is risk-based OFAC compliance?
Risk-based compliance allocates screening resources according to the assessed risk of each counterparty and channel.
TL;DR
TL;DR: Risk-based OFAC compliance is the approach OFAC expects, where stronger controls go to higher-risk transactions and lower-risk flows get lighter, documented controls.
The principle
Risk-based compliance recognizes that not every transaction carries the same sanctions risk. OFAC expects organizations to assess risk and allocate controls accordingly, rather than applying a single, uniform procedure to everything. The goal is to put the strongest screening where a violation is most likely and most costly.
How to tier risk
Tiering starts with the counterparty and the channel. A payment to a new wallet in a high-risk jurisdiction warrants a full check, while a routine, previously-screened flow may need only periodic re-screening. The underlying primitive is the same either way: a screening call that returns ALLOW or BLOCK in under 100 ms, covering the 19,218 SDN names and 947 OFAC-listed crypto wallets, plus the 50 Percent Rule.
Documenting the approach
What makes the approach defensible is documentation. Write down how risk is assessed, which controls map to which tier, and record every screening decision. Under strict liability, intent is not required, so a documented risk-based program is the evidence that screening was proportionate and actually performed.
A tiering example
A simple tiering model might look like this: low risk gets a standard check before payment, medium risk adds a risk score review, and high risk, such as a new wallet in a high-risk jurisdiction, triggers a full stop and manual review. The same screening call underlies all three tiers; only the response differs.