Sanctions Compliance Program: How to Build One That Passes Audit
ByTemitope Lawal
•5mins Read
Key Takeaways
A sanctions compliance program is everything around your screening software: who owns it, how it is tested, and what proof you keep. The software alone is not a program.
Regulators look for five things: leadership backing, a risk assessment, written controls, independent testing, and training.
Of the ten reasons OFAC says sanctions programs fail, only one is a software problem. The other nine are people and process problems.
In March 2026, a US brokerage paid $1,110,661 because a switch got turned off and nobody noticed for a year.
Nigerian institutions carry obligations that no American or European guide mentions, including a duty to freeze accounts immediately and without warning the customer.
Build in this order: risk assessment, list policy, matching settings, escalation path, testing, records.
A sanctions compliance program is everything your organisation does to make sure it never does business with someone a government has blacklisted. It covers who is accountable, how you check names, what happens when a match comes up, and what evidence you keep. Screening software is one part of it. It is not the whole thing.
Here is the simplest way to see the difference. Smoke detectors are not fire safety. Fire safety is the detectors, plus the person responsible for them, plus the drill everyone does twice a year, plus the log proving the batteries were checked in March. If the building burns down, no inspector asks whether you bought good detectors. They ask who was responsible and what you can show them.
Sanctions works the same way. You can buy excellent screening software and still fail an examination, because the examiner is not assessing your vendor. They are assessing you.
This guide covers how to build the rest of it, what regulators actually look for, and the rules Nigerian institutions face that global guides leave out.
What Is a Sanctions Compliance Program?
Sanctions are restrictions governments place on specific people, companies, ships, industries or whole countries. If someone is on a sanctions list, you cannot take their money, send them money, or sell to them. The lists are public, they change constantly, and ignorance is not a defence.
A sanctions compliance program, often shortened to SCP, is your system for making sure that never happens by accident.
An auditor will boil it down to four questions:
Who is responsible for this, and can they actually stop a transaction?
Where is your risk, and how did you work that out?
What are you doing about it, and how do you know it is working?
Show me.
That last one catches more organisations than the first three combined. A program that exists as a policy document but produces no paper trail is, from the regulator's side of the table, the same as no program at all.
The authorities you will need to satisfy usually include the US Office of Foreign Assets Control (OFAC), the United Nations Security Council, the European Union, the UK's Office of Financial Sanctions Implementation (OFSI), and for Nigerian institutions, the Central Bank of Nigeria (CBN) and the Nigeria Sanctions Committee (NIGSAC).
Why Does Your Sanctions Compliance Program Matter More Than Your Screening Tool?
Because the failures that produce fines are hardly ever failures of the software.
Consider what happened to TradeStation Securities. In March 2026 the brokerage paid OFAC $1,110,661. Nobody stole anything. Nobody took a bribe. Here is the whole story.
TradeStation used geo-blocking, a control that checks where a user is logging in from and blocks anyone in a sanctioned country. On 21 June 2021 an employee switched it off to install a software update. Routine maintenance. They never switched it back on, and it stayed off until at least 15 June 2022. The backup control had been quietly broken since an April 2018 update that made it read the wrong IP address.
So for a year, both layers were down. In that window, users in Iran, Syria and the Crimea region of Ukraine placed 481 trades worth $4,442,645.
Now the part that should make every compliance officer uncomfortable. Three safety nets failed at once. The tool that tested whether blocking worked had stopped functioning and was abandoned rather than replaced. The daily OFAC alert subscription expired, someone received the renewal notice in September 2021, and nobody renewed it. And for over eight months the compliance team received no alerts at all and never once asked why it had gone so quiet.
Sit with that last one. A screening system that fires zero alerts looks exactly like a screening system that has been switched off. A smoke detector with a dead battery looks exactly like a working smoke detector. The only way to tell the difference is to test it.
OFAC counted an earlier 2021 cautionary letter about other geo-blocking problems as an aggravating factor. It counted TradeStation's decision to report itself and fix the problem as mitigating. The settlement said plainly that testing and auditing is an essential part of any effective program.
This is the whole argument in one case. Your vendor can give you accurate matching. Only your program can tell you the matching is still switched on.
If you want the mechanics of how the checking itself works, see our guide to sanctions screening.
What Are the Five Pillars of a Sanctions Compliance Program?
On 2 May 2019, OFAC published a document called A Framework for OFAC Compliance Commitments. It is not a law, and OFAC is careful to say it does not tell you which controls to buy. But examiners use it as a yardstick, OFAC weighs how good your program is when it decides how much to fine you, and it has become the default benchmark for OFAC sanctions compliance worldwide.
It names five things every program needs.
Management Commitment
Senior leadership has to back the program with real authority and real money. This is not a signature on a policy.
The practical test: can your sanctions officer stop a large payment at 4pm on a Friday without asking the sales director for permission? If not, you have a policy, not a commitment.
It also means compliance does not report to the business line whose revenue it exists to constrain. That reporting line is one of the first things an examiner traces.
Risk Assessment
A risk assessment is you working out, honestly, where you are actually exposed. OFAC expects you to look across customers, products, services, suppliers, intermediaries, countries and transaction types.
A Nigerian bank's answer looks nothing like a German one's. Remittance corridors, correspondent banking relationships, trade finance touching sanctioned shipping routes and customers connected to designated regional groups all carry different weight.
Write down your reasoning, not just your conclusion. An examiner who cannot follow how you reached a score will assume you guessed.
Internal Controls
Controls are what you actually do about the risks you found: checking names at onboarding, re-checking when lists change, filtering payments, identifying who really owns a corporate customer so you can screen them too, and the procedure telling a human what to do when a name matches.
Every control needs to be written down, owned by a named person, and capable of leaving a record.
Testing and Auditing
Testing means someone independent checks whether the controls work, and that someone knows enough to spot a real problem.
This is the pillar TradeStation failed, and it is the one most often treated as a box-ticking exercise once a year.
Good testing asks awkward questions. If we put a known sanctioned name through onboarding right now, does it get stopped? If someone switched a control off this morning, when would we find out? When did an alert last fire, and was it a real one?
Training
Training has to reach everyone whose job touches sanctions risk, be relevant to what they actually do, and happen at least once a year. Sanctions compliance training for a relationship manager who meets customers should look nothing like training for an analyst who clears alerts all day. Generic annual e-learning satisfies nobody.
Keep the attendance records and the test scores. Training you cannot evidence did not happen.
How Do You Build a Sanctions Compliance Program Step by Step?
The five pillars tell you what a program contains. They do not tell you what to do on Monday morning. This sequence does, and each step leaves you holding a document you can hand to an examiner.
Step 1: Work Out Where Your Risk Actually Is
Start here, because everything else depends on the answer.
List your customer types, products, countries, payment routes and third parties. For each one ask two questions: how likely is sanctions exposure here, and how bad would it be? Write down why you answered the way you did.
You should end up with: a dated risk assessment, signed off by senior management, with a date in the diary to review it.
Step 2: Decide Which Lists You Check, and How Often
Name every sanctions list you screen against and how fast updates reach your system.
Most institutions need OFAC's SDN list (Specially Designated Nationals, the main US blacklist), the UN Consolidated List, the EU list, the UK list, and any domestic one. Nigerian institutions must include the Nigeria Sanctions List. Note that OFAC screening requirements follow the dollar, so they reach you whether or not you are a US company.
Then the awkward question: what happens when a list changes at 11am on a Tuesday? OFAC adds names without warning. If your system refreshes weekly, you have a six-day window where you are screening against yesterday's world.
You should end up with: a written sanctions compliance policy naming each list, where it comes from, how often it refreshes, and who checks that it did.
Step 3: Tune How Closely Names Have to Match
This step decides more about your program's success than any other, and almost nobody writes about it.
Screening systems use fuzzy matching, which means they catch near-misses rather than only exact spellings. "Mohammad" and "Muhammed" should both flag against the same person. How near a miss has to be before the system reacts is a setting someone chooses.
Think of a spam filter. Too strict and real emails vanish into junk. Too loose and you stop reading the folder at all, so you miss the phishing attempt sitting in it.
Sanctions screening fails both ways. Too tight and someone slips through on a spelling variation. Too loose and your team drowns in false alarms, starts clearing them on autopilot, and the one real match goes out with the rest.
So test it. Run known sanctioned names through with deliberate spelling variations, record what the system catches and what it wrongly flags at each setting, then write down which setting you chose and who signed off. That setting is a risk decision, not an IT preference.
You should end up with: a record of your test results, your chosen setting, and the name of the person who approved it.
Step 4: Decide What Happens After the Alarm Goes Off
An alert is not an answer. It is a question. Someone has to work out whether the John Adeyemi who just opened an account is the John Adeyemi on the list.
Map that journey the way a hospital maps triage. Who looks first, and how fast? What evidence lets them say "different person", such as date of birth, nationality or ID number? Who can make that call, who do they escalate to, when do you stop investigating and freeze, and how does a confirmed match become a regulatory report?
Then do the maths nobody enjoys: how many alerts can one analyst genuinely clear in a day, and what happens when volume doubles? A backlog is not an inconvenience. It is a control failure nobody has found yet.
You should end up with: a written procedure naming roles, time limits and who decides what.
Step 5: Build the Habit of Checking It Still Works
Design your testing before you go live, not after your first bad examination.
Cover three questions. Does it catch a known bad name? Is every control still switched on? Are the lists current, complete and loaded properly?
Whoever tests should not be whoever runs the screening. And set the one alert almost nobody thinks of: an alert for the absence of alerts. If your system normally flags twenty names a week and this week flagged none, someone should hear about it by Tuesday. That single control would have saved TradeStation over a million dollars.
You should end up with: a testing calendar, the scripts you test with, and a log of what you found and fixed.
Step 6: Keep Proof of Everything
Every decision needs a record: what was checked, against which version of which list, on what date, what came up, who reviewed it, what they decided and why. Retention rules vary, but five years after the relationship ends is a common floor. Store it so you can pull it up by customer, by date, or by alert, because those are the three ways an examiner will ask.
You should end up with: a record keeping policy, and the ability to reconstruct any single decision from the last five years without a panic.
What Does a Sanctions Compliance Program Look Like Under Nigerian Law?
Almost every guide you will read online describes American and European obligations. If you run a Nigerian institution and you screen only against OFAC and UN lists, you are compliant abroad and exposed at home.
Which Lists Must Nigerian Institutions Check?
On 17 April 2025, the Central Bank of Nigeria wrote to banks, payment service banks and fintechs telling them to tighten up.
The CBN required screening against the United Nations Consolidated Sanctions List and the Nigeria Sanctions List. It also told institutions to react promptly when any list changes, to stop their platforms being used by designated parties, and to screen customers, transactions and beneficial owners in real time.
What Does the Terrorism (Prevention and Prohibition) Act 2022 Require?
The Nigeria Sanctions List comes from section 50 of the Terrorism (Prevention and Prohibition) Act 2022. It is maintained by the Nigeria Sanctions Committee, set up under section 9 of the same Act.
Section 54 is the one that should change how you design your process. Section 54(1)(a) requires all natural and legal persons in Nigeria, including financial institutions and designated non-financial businesses and professions (DNFBPs, meaning lawyers, accountants, estate agents and similar), to immediately identify and freeze, without prior notice, all funds, assets and other economic resources belonging to a designated person or entity in their possession, and report it to the Sanctions Committee.
Read that again slowly. Immediately. Without prior notice.
That means no courtesy call to the customer. No three-day investigation queue. If a name hits the Nigeria Sanctions List, the money stops today.
Most screening processes are not built that way. They are built to investigate first and act second, which is correct for a possible false alarm and wrong for a domestic designation. Your escalation design from Step 4 needs a separate, faster lane for these.
Who Do You Report To?
Two places, not one.
Suspicious activity and confirmed matches go to the Nigerian Financial Intelligence Unit (NFIU) as suspicious transaction reports. Freezing actions, attempted transactions by designated persons and name matching cases go to the Nigeria Sanctions Committee secretariat.
Build both routes into your written procedure. Do not leave an analyst at 6pm working out which report goes where.
Sitting alongside all of this are the CBN AML/CFT/CPF Regulations 2022, formally the Central Bank of Nigeria (Anti-Money Laundering, Combating the Financing of Terrorism and Countering Proliferation Financing of Weapons of Mass Destruction) Regulations, 2022. In practice AML and sanctions compliance are run by the same team from the same risk assessment, so treat them as one programme with two reporting duties rather than two separate projects.
What Are the Most Common Sanctions Compliance Program Failures?
OFAC lists ten reasons sanctions programs break down. Read it as a diagnostic. Anywhere you flinch is worth a closer look.
What goes wrong
What it looks like on a normal Tuesday
No formal program
Screening happens, but nobody owns it and nothing is written down
Assuming the rules do not apply to you
"We are not a US company, so OFAC is not our problem"
Overseas entities doing what the parent cannot
A subsidiary processes the transaction head office would have blocked
Goods reaching sanctioned destinations
Products routed through a third country to a restricted buyer
Touching the US financial system
Any dollar payment clears through the US, which brings OFAC with it
Screening software or filter faults
Wrong list loaded, control switched off, settings badly tuned
Weak customer due diligence
You never found out who really owns the company, so you never screened them
Inconsistent standards across the group
Lagos applies one rule, the Accra branch applies another
Unusual payment practices
Payment messages stripped of the details that would trigger a match
Individuals acting outside policy
Someone decides the rule does not apply to their client
Count them. Exactly one is a technology problem. The other nine are governance problems, which is the entire case for treating this as a management exercise rather than a shopping trip.
Go through this before someone else does. Anywhere you cannot point at a document is a gap.
Can you produce a dated, board-approved risk assessment from the last twelve months?
Can you name the person accountable, and show who they report to?
Can you list every sanctions list you check and prove when each last updated?
Can you show your matching setting, the tests behind it, and who approved it?
Can you pull one alert from six months ago and show who reviewed it and why they closed it?
Has anyone independent tested your screening in the last year?
Would you know within a day if a control were switched off?
Do you have training records for every relevant employee?
Can you reconstruct any screening decision from the last five years?
For Nigerian institutions: can you show a freeze that happened immediately, with no notice to the customer?
Every "no" on that list is a finding waiting to be written up.
How Youverify Helps You Build and Run a Sanctions Compliance Program
Most of what this guide describes is work no vendor can do for you. Nobody else can write your risk assessment or sit in your escalation meetings.
What technology should do is make the evidence collect itself. That means covering the lists your own regulator names, not just the famous ones. Matching settings you can adjust and explain to an examiner, rather than a black box. Checking names at onboarding and continuing afterwards, because a customer who is clean today may be designated next month. Recording every decision automatically. And failing loudly rather than quietly, so silence sets off an alarm instead of a false sense of safety.
Youverify's PEP and sanctions screening solution checks customers and beneficial owners against global sanctions lists, politically exposed person (PEP) databases and adverse media in real time, with ongoing monitoring and a full record of every decision. It covers the Nigeria Sanctions List and CBN requirements alongside OFAC, UN, EU and UK lists, which matters when you answer to more than one regulator at a time.
If you want to know whether your current setup would hold up under a CBN examination, book a demo with our compliance experts and we will go through it with you.