US OFAC Sanctions Compliance Framework
The US Office of Foreign Assets Control (OFAC), within the Treasury Department, administers and enforces economic and trade sanctions programmes. OFAC published its Framework for Compliance Commitments (2019) outlining the five essential components of an effective sanctions compliance programme. Sanctions programmes include the Specially Designated Nationals (SDN) List, sectoral sanctions, and comprehensive country embargoes. OFAC sanctions have significant extraterritorial reach through secondary sanctions. Violations can result in civil penalties up to $330,000+ per violation or criminal penalties up to $20M and 30 years imprisonment.
US OFAC Sanctions Compliance Framework is a compliance framework from United States (Treasury/OFAC) with 10 domains and 24 controls that map to 13 other frameworks. The largest domains are Internal Controls (6 controls), Management Commitment (Pillar 1) (4 controls), Training (Pillar 5) (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (10)
Internal Controls
| Code | Title |
|---|---|
| OFAC-SCP-3.2 | Transaction Interdiction and Blocking |
| OFAC-SCP-3.3 | Country and Comprehensive Sanctions Controls |
| OFAC-SCP-3.4 | Sectoral Sanctions Identification and Controls |
| OFAC-SCP-3.5 | Licensing and General License Management |
| OFAC-SCP-3.6 | Recordkeeping |
| USOFAC-3 | Internal Controls (Screening, Interdiction, Recordkeeping) |
Management Commitment
Management Commitment
| Code | Title |
|---|---|
| OFAC-SCP-1.2 | Sanctions Compliance Officer Appointment |
Management Commitment (Pillar 1)
Risk Assessment
| Code | Title |
|---|---|
| USOFAC-2 | Risk Assessment |
Risk Assessment and Due Diligence
Risk Assessment and Due Diligence
| Code | Title |
|---|---|
| OFAC-SCP-2.2 | Customer and Counterparty Due Diligence |
| OFAC-SCP-7.2 | Mergers and Acquisitions Sanctions Due Diligence |
Senior Commitment
| Code | Title |
|---|---|
| USOFAC-1 | Senior Management Commitment |
Testing
| Code | Title |
|---|---|
| USOFAC-4 | Testing and Audit |
Testing and Auditing
Testing and Auditing
| Code | Title |
|---|---|
| OFAC-SCP-4.2 | Issue Identification and Root Cause Analysis |
| OFAC-SCP-8.2 | Management Information and Metrics |
Training
| Code | Title |
|---|---|
| OFAC-SCP-5.2 | Senior Management and Board Training |
| USOFAC-5 | Training and Voluntary Self-Disclosure |
Your Compliance Coverage
If you comply with US OFAC Sanctions Compliance Framework, you already cover:
NIST SP 800-53 Rev 5
17%
4 controls mapped
Compare →US ITAR and EAR - Export Control and Data Security
17%
4 controls mapped
Compare →ISO/IEC 29147:2018
17%
4 controls mapped
Compare →+ 10 more: US Automated Commercial Environment (ACE) - CBP Trade Data Requirements (17%), IAIS Insurance Core Principles (ICPs) (17%)
See all 13 mapped frameworks ↓Maps to 13 other frameworks
What is US OFAC Sanctions Compliance Framework and who does it apply to?
US OFAC Sanctions Compliance Framework is a compliance framework from United States (Treasury/OFAC) with 10 domains and 24 controls. The US Office of Foreign Assets Control (OFAC), within the Treasury Department, administers and enforces economic and trade sanctions programmes. OFAC published its Framework for Compliance Commitments (2019) outlining the five essential components of an effective sanctions compliance programme. Sanctions programmes include the Specially Designated Nationals (SDN) List, sectoral sanctions, and comprehensive country embargoes. OFAC sanctions have significant extraterritorial reach through secondary sanctions. Violations can result in civil penalties up to $330,000+ per violation or criminal penalties up to $20M and 30 years imprisonment. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does US OFAC Sanctions Compliance Framework actually require?
US OFAC Sanctions Compliance Framework has 24 controls organised across 10 domains. The largest domains are Internal Controls (6 controls), Management Commitment (Pillar 1) (4 controls), Training (Pillar 5) (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of US OFAC Sanctions Compliance Framework do I already cover?
US OFAC Sanctions Compliance Framework maps to 13 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (17% coverage), US ITAR and EAR - Export Control and Data Security (17% coverage), ISO/IEC 29147:2018 (17% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement US OFAC Sanctions Compliance Framework?
Start your US OFAC Sanctions Compliance Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about US OFAC Sanctions Compliance Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required