A sanctions compliance program is everything your organisation does to make sure it never does business with someone a government has blacklisted. It covers who is accountable, how you check names, what happens when a match comes up, and what evidence you keep.
Screening software is one part of it. It is not the whole thing.
Smoke detectors are not fire safety. Fire safety is the detectors, plus the person responsible for them, plus the drill everyone does twice a year, plus the log proving the batteries were checked in March. If the building burns down, no inspector asks whether you bought good detectors. They ask who was responsible and what you can show them.
Sanctions works the same way. You can buy excellent screening software and still fail an examination, because the examiner is not assessing your vendor. They are assessing you.
What Is a Sanctions Compliance Program?
Sanctions are restrictions governments place on specific people, companies, ships, industries or whole countries. If someone is listed, you cannot take their money, send them money, or sell to them. The lists are public, they change constantly, and ignorance is not a defence.
A sanctions compliance program, often shortened to SCP, is your system for making sure that never happens by accident. An auditor boils it down to four questions:
- 1. Who is responsible, and can they actually stop a transaction?
- 2. Where is your risk, and how did you work that out?
- 3. What are you doing about it, and how do you know it works?
- 4. Show me.
That last one catches more organisations than the first three combined. A program that exists as a policy document but produces no paper trail is, from the regulator's side of the table, the same as no program at all.
The authorities you answer to usually include the US Office of Foreign Assets Control (OFAC), the UN, the EU, the UK's Office of Financial Sanctions Implementation (OFSI), and in Nigeria the Central Bank of Nigeria (CBN) and the Nigeria Sanctions Committee (NIGSAC).
Why Does Your Sanctions Compliance Program Matter More Than Your Screening Tool?
Because the failures that produce fines are hardly ever failures of the software.
In March 2026 TradeStation Securities paid OFAC $1,110,661. Nobody stole anything. Nobody took a bribe.
TradeStation used geo-blocking, a control that checks where a user is logging in from and blocks anyone in a sanctioned country. On 21 June 2021 an employee switched it off to install a software update. Routine maintenance. They never switched it back on, and it stayed off until at least 15 June 2022. The backup control had been broken since an April 2018 update that made it read the wrong IP address. So for a year both layers were down, and users in Iran, Syria and the Crimea region of Ukraine placed 481 trades worth $4,442,645.
Then the part that should make every compliance officer uncomfortable. The tool that tested whether blocking worked had stopped functioning and was abandoned rather than replaced. The daily OFAC alert subscription expired, someone got the renewal notice in September 2021, and nobody renewed it. And for over eight months the compliance team received no alerts at all and never once asked why it had gone so quiet.
Sit with that. A screening system firing zero alerts looks exactly like one that has been switched off. A smoke detector with a dead battery looks exactly like a working one. The only way to tell them apart is to test.
TradeStation is not an outlier. OFAC lists ten root causes of sanctions compliance program breakdowns, covering everything from no formal program at all, to overseas subsidiaries processing what head office would have blocked, to beneficial owners nobody ever identified and therefore never screened. Exactly one of the ten is a technology problem. The other nine are governance problems, which is the whole case for treating this as a management exercise rather than a shopping trip.
Your vendor can give you accurate matching. Only your program can tell you it is still switched on. For how the checking itself works, see our guide to sanctions screening.
What Are the Five Pillars of a Sanctions Compliance Program?
On 2 May 2019 OFAC published A Framework for OFAC Compliance Commitments. It is not law, and OFAC says plainly it does not tell you which controls to buy. But examiners use it as a yardstick, OFAC weighs your program when deciding penalties, and it has become the default benchmark for OFAC sanctions compliance worldwide.
1. Management commitment:
Leadership backs the program with real authority and real money. The practical test: can your sanctions officer stop a large payment at 4pm on a Friday without asking the sales director? If not, you have a policy, not a commitment.
2. Risk assessment:
You work out honestly where you are exposed, across customers, products, suppliers, countries and transaction types. A Nigerian bank's answer looks nothing like a German one's.
3. Internal controls:
What you actually do about those risks: screening at onboarding, re-screening when lists change, filtering payments, identifying who really owns a corporate customer, and the procedure telling a human what to do when a name matches.
4. Testing and auditing:
Someone independent, who knows enough to spot a real problem, checks whether the controls work. This is the pillar TradeStation failed.
5. Training:
Everyone whose job touches sanctions risk, trained yearly on what they actually do. Sanctions compliance training for a relationship manager should look nothing like training for an alert analyst. Training you cannot evidence did not happen.
How Do You Build a Sanctions Compliance Program Step by Step?
The pillars tell you what a program contains. They do not tell you what to do on Monday. This sequence does, and each step leaves you holding a document.
Step 1: Work Out Where Your Risk Actually Is
List your customer types, products, countries, payment routes and third parties. For each, ask how likely sanctions exposure is and how bad it would be. Write down why you answered that way, because an examiner who cannot follow your reasoning will assume you guessed.
Produces: a dated risk assessment, signed off by senior management, with a review date in the diary.
Step 2: Decide Which Lists You Check, and How Often
Most institutions need OFAC's SDN list (Specially Designated Nationals, the main US blacklist), the UN Consolidated List, the EU and UK lists, and any domestic one. Nigerian institutions must include the Nigeria Sanctions List. OFAC screening requirements follow the dollar, so they reach you whether or not you are a US company.
Then the awkward question: what happens when a list changes at 11am on a Tuesday? OFAC adds names without warning, so a system refreshing weekly spends six days screening against yesterday's world.
Produces: a written sanctions compliance policy naming each list, its source, its refresh rate, and who checks it happened.
Step 3: Tune How Closely Names Have to Match
This decides more about your program than any other step, and almost nobody writes about it.
Screening systems use fuzzy matching, catching near-misses rather than exact spellings, so "Mohammad" and "Muhammed" both flag. How near a miss must be before the system reacts is a setting somebody chooses.
Think of a spam filter. Too strict and real emails vanish into junk. Too loose and you stop reading the folder, so you miss the phishing attempt in it. Sanctions screening fails both ways. Too tight and someone slips through on a spelling variation. Too loose and your team drowns in false alarms, starts clearing them on autopilot, and the real match goes out with the rest.
So test it. Run known sanctioned names through with deliberate spelling variations, record what the system catches and wrongly flags at each setting, then record your choice and who approved it. That is a risk decision, not an IT preference.
Produces: your test results, your chosen setting, and a named approver.
Step 4: Decide What Happens After the Alarm Goes Off
An alert is a question, not an answer. Someone must work out whether the John Adeyemi who just opened an account is the John Adeyemi on the list.
Map it like hospital triage. Who looks first, and how fast? What evidence lets them say "different person", such as date of birth, nationality or ID number? Who makes that call, who do they escalate to, and when do you stop investigating and freeze?
Then the maths nobody enjoys: how many alerts can one analyst genuinely clear in a day? A backlog is not an inconvenience. It is a control failure nobody has found yet.
Produces: a written procedure naming roles, time limits and who decides what.
Step 5: Build the Habit of Checking It Still Works
Design testing before you go live. Does it catch a known bad name? Is every control still switched on? Are the lists current and correctly loaded?
Whoever tests should not be whoever runs the screening. And set the alert almost nobody thinks of: an alert for the absence of alerts. If your system normally flags twenty names a week and this week flagged none, someone should hear by Tuesday. That one control would have saved TradeStation over a million dollars.
Produces: a testing calendar, test scripts, and a log of what you found and fixed.
Step 6: Keep Proof of Everything
Every decision needs a record: what was checked, against which list version, when, what came up, who reviewed it and why. Five years after the relationship ends is a common minimum. Store it so you can retrieve by customer, by date, or by alert, because those are the three ways an examiner asks.
Produces: a record keeping policy, and the ability to reconstruct any decision from the last five years.
For the practical side of checking names against lists, see our guide on how to perform effective sanction list checks.
What Does a Sanctions Compliance Program Look Like Under Nigerian Law?
Almost every guide online describes American and European obligations. If you run a Nigerian institution and screen only against OFAC and UN lists, you are compliant abroad and exposed at home.
On 17 April 2025 the Central Bank of Nigeria wrote to banks, payment service banks and fintechs telling them to tighten up. It required screening against the UN Consolidated Sanctions List and the Nigeria Sanctions List, prompt reaction when any list changes, and real-time screening of customers, transactions and beneficial owners. We broke it down in our analysis of the CBN's warning to banks on sanction screening.
The Nigeria Sanctions List comes from section 50 of the Terrorism (Prevention and Prohibition) Act 2022, and is maintained by the Nigeria Sanctions Committee set up under section 9 of the same Act.
Section 54 is the one that should change your process design. Section 54(1)(a) requires all natural and legal persons in Nigeria, including financial institutions and designated non-financial businesses and professions (DNFBPs), to immediately identify and freeze, without prior notice, all funds and economic resources belonging to a designated person in their possession, and report it to the Sanctions Committee.
Read that again. Immediately. Without prior notice. No courtesy call to the customer, no three-day investigation queue. Most screening processes investigate first and act second, which is right for a possible false alarm and wrong for a domestic designation. Your escalation design from Step 4 needs a separate, faster lane.
Reporting also splits two ways. Suspicious activity and confirmed matches go to the Nigerian Financial Intelligence Unit (NFIU). Freezing actions and name matching cases go to the Nigeria Sanctions Committee secretariat. Build both routes into the procedure rather than leaving an analyst at 6pm to work it out. The CBN AML/CFT/CPF Regulations 2022 sit alongside all this, and since AML and sanctions compliance run off the same team and risk assessment, treat them as one programme with two reporting duties.
How Youverify Helps You Build and Run a Sanctions Compliance Program
Most of what this guide describes is work no vendor can do for you. Nobody else writes your risk assessment or sits in your escalation meetings. What technology should do is make the evidence collect itself.
Youverify's PEP and sanctions screening solution checks customers and beneficial owners against global sanctions lists, politically exposed person (PEP) databases and adverse media in real time, with ongoing monitoring and a full record of every decision. It covers the Nigeria Sanctions List and CBN requirements alongside OFAC, UN, EU and UK lists. Matching settings are yours to adjust and explain to an examiner rather than a black box, and the system fails loudly, so silence sets off an alarm instead of a false sense of safety.
To find out whether your setup would hold up under a CBN examination, book a demo with our compliance experts.