Updating Your Sanctions Compliance Guidance, Part 1: The 2019 Framework Is Still Your Foundation, But It’s No Longer the Whole Picture

If you built your sanctions compliance program around OFAC’s 2019 Framework for Compliance Commitments and haven’t revisited it since, you’re not alone, and you’re also overdue for an update. The 2019 Framework remains the foundational document for how OFAC evaluates a sanctions compliance program, and every one of its five pillars is still good law today. But federal sanctions enforcement has fundamentally changed shape since 2019. It’s no longer just an OFAC conversation. The Department of Justice, the Department of Commerce’s Bureau of Industry and Security, and OFAC now routinely coordinate through joint “Tri-Seal” compliance notes that layer substantial new expectations on top of the 2019 baseline. This is the first of a two-part series. Part 1 revisits what the 2019 Framework actually requires and why it remains your starting point. Part 2 covers the specific multi-agency updates you need to build on top of it.

Why the 2019 Framework Still Matters

OFAC built the 2019 Framework around five essential components of compliance: management commitment, risk assessment, internal controls, testing and auditing, and training. These aren’t abstract principles. OFAC uses them directly when it evaluates a civil monetary penalty case, considers whether an existing compliance program should mitigate a penalty under the agency’s General Factors, and even assesses whether a violation should be deemed egregious. A genuinely effective program built on these five pillars at the time of a violation can meaningfully change the outcome of an enforcement action. That’s not theoretical; OFAC’s own enforcement guidelines build this consideration directly into how penalties get calculated.

Management Commitment Is Still the Foundation of Everything Else

The Framework places senior management commitment first for a reason. OFAC looks for concrete evidence that leadership has actually reviewed and approved the program, not just signed off on a document someone else wrote. It wants to see that compliance functions have real authority and autonomy, with direct reporting lines to senior management and routine, not occasional, engagement between the two. It wants adequate resourcing, meaning a dedicated OFAC sanctions compliance officer, qualified personnel who understand both the regulations and the underlying business, and the technology infrastructure to support the program. And critically, OFAC wants to see a genuine culture of compliance, one where employees can report concerns without fear of reprisal and where leadership visibly discourages misconduct rather than merely tolerating a policy that says so on paper.

Risk Assessment Has to Be an Ongoing Discipline, Not a One-Time Exercise

The Framework calls for a holistic, top-to-bottom review of an organization’s touchpoints with the outside world: customers, supply chain, intermediaries, counterparties, the products and services offered, and the geographic footprint of the business and everyone it deals with. This isn’t a static exercise. OFAC expects risk assessments to evolve as the organization learns, particularly in response to root causes identified through audits, testing, or actual violations. The Framework also flags mergers and acquisitions specifically as a recurring source of sanctions risk, noting that compliance functions need to be integrated into the M&A process itself, not bolted on after a deal closes, with particular attention warranted when a transaction involves a non-U.S. target.

Internal Controls Need to Keep Pace With a Moving Target

U.S. sanctions programs change constantly: new SDN and sectoral sanctions list entries, new executive orders, amended regulations, newly issued general licenses. The Framework requires that an organization’s internal controls be built to absorb that pace of change, with written policies and procedures that are actually usable by the people who need to follow them, functioning escalation and reporting chains, and recordkeeping that meets OFAC’s requirements. It also requires organizations to treat any identified weakness seriously: implementing compensating controls immediately while the root cause gets addressed, not waiting for a convenient moment to fix what’s broken.

Testing, Auditing, and Training Close the Loop

The Framework’s final two pillars work together. A testing and audit function needs real independence and authority, reporting to senior management rather than to the business units it’s reviewing, and needs to actually drive remediation when it finds something. Training needs to be more than an annual checkbox: it has to be tailored to actual job function and risk exposure, cover the organization’s specific products, customers, and geographic footprint, and hold people accountable through real assessment rather than a passive click-through.

The Framework’s Own Appendix Already Warned Us

What’s striking, revisiting the 2019 Framework now, is how much of it anticipated exactly the risk areas that multi-agency guidance has since sharpened. The Framework’s appendix on root causes of past violations already flagged facilitation of sanctioned transactions through overseas subsidiaries, re-exportation of U.S.-origin goods to sanctioned destinations, use of the U.S. financial system in third-country transactions, decentralized compliance functions, and individual liability for employees who conceal misconduct from their own compliance teams. Every one of these root causes is central to the multi-agency priorities now being emphasized through Tri-Seal guidance. The 2019 Framework wasn’t wrong; it was simply written before enforcement coordination across agencies had matured into the systematic, joint approach we see today.

Why That Matters for What Comes Next

The upshot is this: if your program genuinely reflects the five pillars of the 2019 Framework, you have the right foundation. What you likely don’t have yet, unless you’ve updated your program recently, is the layer of multi-agency expectations that DOJ, BIS, and OFAC have been building jointly since 2023: coordinated rules on voluntary self-disclosure, sharper expectations around global jurisdiction and foreign subsidiary liability, granular supply chain and evasion-detection requirements, and a materially longer enforcement look-back period. Part 2 of this series walks through each of those updates and what they mean for how you need to adjust your program today.

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *