Sanctions Incident Response Template
The incident response plan that turns a match into a bounded event.
How to use
How to use: complete when a match is confirmed. The plan turns a match into a documented, bounded event.
The plan
1. Detection. [screening log entry, alert source, timestamp]
2. Containment. [payments blocked, funds held, related parties frozen]
3. Assessment. [match verified? list version, entry, false-positive analysis]
4. Reporting. [blocking report within 10 days; VSD where appropriate]
5. Remediation. [control gap fixed, re-test, training updated]
Post-incident review: [date, owner, lessons]
Why the structure
OFAC's guidelines reward documented, prompt response. The plan is the artifact that shows detection-to-remediation in one file - see the inquiry scenario for the regulator side.