Updating Your Sanctions Compliance Guidance, Part 2: The Four Multi-Agency Priorities You Need to Build Into Your Program Now

Part 1 of this series revisited the 2019 OFAC Framework for Compliance Commitments and made the case that its five pillars, management commitment, risk assessment, internal controls, testing and auditing, and training, remain the right foundation for any sanctions compliance program. But a foundation isn’t a finished structure. Since 2023, DOJ, BIS, and OFAC have been issuing joint “Tri-Seal” compliance notes that build substantial new expectations on top of that 2019 baseline, reflecting a genuinely coordinated, multi-agency approach to sanctions and export control enforcement. Part 2 walks through the four priority areas driving that evolution and what each one means for how you need to update your program.
Priority One: Global Jurisdiction and the Expanding Reach of “U.S. Nexus”
A joint compliance note issued in March 2024 made unusually explicit something that had been building for years: U.S. sanctions and export control enforcement increasingly targets foreign-based entities and individuals, not just U.S. companies operating domestically. The concept of a “U.S. nexus” has expanded well beyond the obvious case of a direct transaction with a U.S. person. It now reaches foreign businesses whose activity touches U.S. financial clearing systems, routes communications through U.S.-based servers, or involves goods containing U.S.-origin components, even when none of that was the primary purpose of the underlying transaction.
This matters enormously for companies with foreign subsidiaries, because U.S. parent companies face real exposure for the conduct of those subsidiaries, and that exposure doesn’t require direct involvement by U.S.-based personnel. A foreign subsidiary that facilitates a transaction with a sanctioned party can create liability back at the U.S. parent, particularly where approvals, contracts, or procurement decisions flowed through or were ratified by U.S.-based functions. The practical response is centralizing compliance architecture across cross-border operations rather than letting foreign subsidiaries operate their own, locally designed sanctions programs. A decentralized compliance function, with personnel and decision-makers scattered across offices with inconsistent application of policy, has been a recurring root cause in OFAC enforcement actions for years, and the multi-agency guidance makes clear that this risk hasn’t gone away; if anything, it has gotten sharper given the resources authorities are now dedicating to identifying it.

Priority Two: Harmonized Expectations Around Voluntary Self-Disclosure
A July 2023 Tri-Seal note coordinated how DOJ, BIS, and OFAC expect companies to handle voluntary self-disclosure when an internal audit or investigation surfaces a potential violation. Under DOJ’s Corporate Enforcement Policy, a company that voluntarily self-discloses, cooperates fully, and remediates appropriately can realistically expect a presumption of non-prosecution, a significant incentive structure that rewards getting ahead of a problem rather than waiting to see if it surfaces on its own.
BIS added real teeth to this framework with a dual-track disclosure system designed to let companies resolve minor administrative violations more quickly, while reserving its full enforcement process for more significant matters. But the more consequential change sits on the other side of that coin: BIS now treats a company’s decision not to disclose a significant violation as an aggravating factor in any subsequent enforcement action. In other words, staying silent about something material is no longer a neutral choice; it’s a decision that can affirmatively increase your exposure if the conduct is later discovered through other means. Any sanctions compliance program needs clear, documented internal protocols for how a potential violation gets evaluated for disclosure, who makes that call, and how quickly, because the harmonized guidance across all three agencies now rewards speed and penalizes hesitation.
Priority Three: Supply Chain Due Diligence and “Know-Your-Cargo” Evasion Detection
A March 2023 Tri-Seal note, followed by a multi-agency maritime advisory later that year, pushed compliance programs toward a much more granular, active approach to detecting third-party evasion tactics within supply chains. This goes well beyond traditional name-matching screening against the SDN list. Programs are now expected to actively track red flags associated with transshipment evasion, including routing through high-risk diversion points such as China, Hong Kong, Turkey, the UAE, and Armenia, jurisdictions that have become common waypoints for goods attempting to obscure their true destination.

Beyond geography, the guidance highlights specific corporate obfuscation tactics that should trigger enhanced scrutiny: frequent or last-minute changes to shipping instructions, the use of shell companies with no discernible business purpose, structural anomalies in shipping and commercial documentation, and mismatches between a counterparty’s stated location and the IP address or digital footprint associated with their actual business activity. Building this kind of detection into a compliance program requires integrating BIS’s Export Administration Regulations and the Foreign Direct Product Rule directly into the sanctions risk assessment framework, rather than treating export control risk and OFAC risk as separate workstreams handled by different teams using different tools.
Priority Four: A Dramatically Longer Enforcement Window
Perhaps the most consequential change, from a pure risk-management standpoint, is procedural rather than substantive: OFAC has formally integrated an extended ten-year statute of limitations for sanctions violations arising under the International Emergency Economic Powers Act and the Trading with the Enemy Act, doubling what had previously been a five-year window. This isn’t a minor technical adjustment. It fundamentally changes the risk calculus for how long conduct can come back to haunt an organization, and it requires a corresponding adjustment to recordkeeping and data retention architecture. A program built around five-year retention schedules is now structurally inadequate; organizations need to ensure transaction records, due diligence files, and compliance documentation are preserved for at least a decade, and that look-back reviews conducted in response to a newly discovered issue account for this extended window rather than stopping short of it.

Translating These Four Priorities Into Program Changes
Mapped against the 2019 Framework’s five pillars, these multi-agency priorities require concrete action in three areas specifically. Risk assessment needs to expand to formally incorporate export control considerations, including BIS’s Export Administration Regulations and Foreign Direct Product Rule, directly alongside OFAC list screening, rather than evaluating sanctions risk and export control risk through separate processes. Internal controls need to move beyond simple name-matching screening toward systems capable of flagging geographic routing risk, complex supply chain structures, and the specific intermediary red flags described above. And testing, auditing, and recordkeeping protocols need to be rebuilt around a ten-year data lookback window rather than the five-year assumption many programs were originally designed around.
None of this replaces the 2019 Framework. It builds directly on top of it, and a program that never properly implemented the original five pillars will struggle badly trying to layer these newer, more technical requirements on top of a weak foundation. But for organizations that already have a mature program built around management commitment, risk assessment, internal controls, testing, and training, this is a clear roadmap for exactly where to focus your next update cycle.











