Back to Frameworks

US OFAC Sanctions Compliance Framework

United States (Treasury/OFAC)
v2019 (Framework)
10 domains
24 controls

The US Office of Foreign Assets Control (OFAC), within the Treasury Department, administers and enforces economic and trade sanctions programmes. OFAC published its Framework for Compliance Commitments (2019) outlining the five essential components of an effective sanctions compliance programme. Sanctions programmes include the Specially Designated Nationals (SDN) List, sectoral sanctions, and comprehensive country embargoes. OFAC sanctions have significant extraterritorial reach through secondary sanctions. Violations can result in civil penalties up to $330,000+ per violation or criminal penalties up to $20M and 30 years imprisonment.

Verified

US OFAC Sanctions Compliance Framework is a compliance framework from United States (Treasury/OFAC) with 10 domains and 24 controls that map to 13 other frameworks. The largest domains are Internal Controls (6 controls), Management Commitment (Pillar 1) (4 controls), Training (Pillar 5) (4 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (10)

Internal Controls

6 controls
Controls in the Internal Controls domain of US OFAC Sanctions Compliance Framework6 controls
CodeTitle
OFAC-SCP-3.2Transaction Interdiction and Blocking
OFAC-SCP-3.3Country and Comprehensive Sanctions Controls
OFAC-SCP-3.4Sectoral Sanctions Identification and Controls
OFAC-SCP-3.5Licensing and General License Management
OFAC-SCP-3.6Recordkeeping
USOFAC-3Internal Controls (Screening, Interdiction, Recordkeeping)

Management Commitment

1 controls

Management Commitment

Controls in the Management Commitment domain of US OFAC Sanctions Compliance Framework1 controls
CodeTitle
OFAC-SCP-1.2Sanctions Compliance Officer Appointment

Management Commitment (Pillar 1)

4 controls
Controls in the Management Commitment (Pillar 1) domain of US OFAC Sanctions Compliance Framework4 controls
CodeTitle
MC-1Senior Management Support
MC-2Compliance Culture
MC-3Dedicated Compliance Officer
MC-4Resource Allocation

Risk Assessment

1 controls
Controls in the Risk Assessment domain of US OFAC Sanctions Compliance Framework1 controls
CodeTitle
USOFAC-2Risk Assessment

Risk Assessment and Due Diligence

2 controls

Risk Assessment and Due Diligence

Controls in the Risk Assessment and Due Diligence domain of US OFAC Sanctions Compliance Framework2 controls
CodeTitle
OFAC-SCP-2.2Customer and Counterparty Due Diligence
OFAC-SCP-7.2Mergers and Acquisitions Sanctions Due Diligence

Senior Commitment

1 controls
Controls in the Senior Commitment domain of US OFAC Sanctions Compliance Framework1 controls
CodeTitle
USOFAC-1Senior Management Commitment

Testing

1 controls
Controls in the Testing domain of US OFAC Sanctions Compliance Framework1 controls
CodeTitle
USOFAC-4Testing and Audit

Testing and Auditing

2 controls

Testing and Auditing

Controls in the Testing and Auditing domain of US OFAC Sanctions Compliance Framework2 controls
CodeTitle
OFAC-SCP-4.2Issue Identification and Root Cause Analysis
OFAC-SCP-8.2Management Information and Metrics

Training

2 controls
Controls in the Training domain of US OFAC Sanctions Compliance Framework2 controls
CodeTitle
OFAC-SCP-5.2Senior Management and Board Training
USOFAC-5Training and Voluntary Self-Disclosure

Training (Pillar 5)

4 controls
Controls in the Training (Pillar 5) domain of US OFAC Sanctions Compliance Framework4 controls
CodeTitle
TR-1Periodic Training Program
TR-2Job-Specific Training
TR-3Accountability for Training
TR-4Training Updates

Your Compliance Coverage

If you comply with US OFAC Sanctions Compliance Framework, you already cover:

Maps to 13 other frameworks

24 total controls
NIST SP 800-53 Rev 5
4 source controls mapped|1 target controls covered
17%
US ITAR and EAR - Export Control and Data Security
4 source controls mapped|1 target controls covered
17%
ISO/IEC 29147:2018
4 source controls mapped|1 target controls covered
17%
US Automated Commercial Environment (ACE) - CBP Trade Data Requirements
4 source controls mapped|1 target controls covered
17%
IAIS Insurance Core Principles (ICPs)
4 source controls mapped|1 target controls covered
17%
Sweden Data Protection Act (Dataskyddslag, 2018:218)
4 source controls mapped|1 target controls covered
17%
UAE Virtual Asset Regulatory Authority (VARA) Regulations
4 source controls mapped|1 target controls covered
17%
Uganda Data Protection and Privacy Act (2019)
4 source controls mapped|1 target controls covered
17%
Singapore Payment Services Act (PSA) - Digital Payment Token Regulation
4 source controls mapped|1 target controls covered
17%
French Sapin II Law (Law No. 2016-1691)
1 source controls mapped|1 target controls covered
4%
ISO 31000:2018
1 source controls mapped|1 target controls covered
4%
ISO 22301:2019
1 source controls mapped|2 target controls covered
4%
ISO/IEC 23894:2023
1 source controls mapped|2 target controls covered
4%

What is US OFAC Sanctions Compliance Framework and who does it apply to?

US OFAC Sanctions Compliance Framework is a compliance framework from United States (Treasury/OFAC) with 10 domains and 24 controls. The US Office of Foreign Assets Control (OFAC), within the Treasury Department, administers and enforces economic and trade sanctions programmes. OFAC published its Framework for Compliance Commitments (2019) outlining the five essential components of an effective sanctions compliance programme. Sanctions programmes include the Specially Designated Nationals (SDN) List, sectoral sanctions, and comprehensive country embargoes. OFAC sanctions have significant extraterritorial reach through secondary sanctions. Violations can result in civil penalties up to $330,000+ per violation or criminal penalties up to $20M and 30 years imprisonment. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does US OFAC Sanctions Compliance Framework actually require?

US OFAC Sanctions Compliance Framework has 24 controls organised across 10 domains. The largest domains are Internal Controls (6 controls), Management Commitment (Pillar 1) (4 controls), Training (Pillar 5) (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of US OFAC Sanctions Compliance Framework do I already cover?

US OFAC Sanctions Compliance Framework maps to 13 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (17% coverage), US ITAR and EAR - Export Control and Data Security (17% coverage), ISO/IEC 29147:2018 (17% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement US OFAC Sanctions Compliance Framework?

Start your US OFAC Sanctions Compliance Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about US OFAC Sanctions Compliance Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required