What a program is expected to do
OFAC has published a framework describing what it expects from a sanctions compliance program, and it considers the existence and quality of a program when deciding how to respond to an apparent violation. The framework stresses that a program should be tailored to the company's own risk profile and supported by senior management, rather than living only in the legal department. A program written for a large bank will not fit a mid-size manufacturer, and a template copied from elsewhere often misses the risks that actually matter. The Justice Department also looks at compliance programs when it evaluates corporate criminal cases, including sanctions cases.
Where programs drift
Programs tend to weaken quietly. Screening lists may stop updating, ownership checks may be skipped for long-standing customers, and alerts may be cleared without a documented reason. New business lines, acquisitions, and staff turnover can leave procedures that no longer match how the company operates. Training that is generic rather than tied to each role is another common weakness. Collect the current policy, the screening settings, escalation records, and any audit findings, because comparing what the program says with what staff actually do is often the most revealing part of a review.
Building or rebuilding with you
We start by understanding your operations and the risk assessment behind the program, or by helping you prepare one if it does not exist. From there we discuss practical controls: who screens, at what point in a transaction, and who decides when something is flagged. We look at how the program is tested and how often it is updated, and we help write procedures in language staff can follow. If the review reveals a gap that may have allowed a past violation, we discuss how to address it, including whether disclosure should be considered. The goal is a program that fits the business and can be shown to work if a regulator asks.