Trackers
2026-07-09 00:00 Trackers

Sanctions Compliance in USA: 2026 Update

Sanctions compliance in the USA is one of the most consequential legal obligations facing international businesses today. The Office of Foreign Assets Control (OFAC) administers a broad and actively enforced framework of economic and trade restrictions that applies not only to US persons and entities but also, in many circumstances, to foreign companies with any US nexus. Penalties for violations can reach into the tens of millions of dollars, and enforcement actions have increased in frequency and scope. This guide covers the current regulatory framework, recent developments, key compliance obligations, export control intersections, and practical steps for businesses operating in or connected to the United States.

Understanding the US sanctions framework and OFAC';s role

OFAC is the primary US government body responsible for administering and enforcing economic and trade sanctions. It operates under the authority of the US Department of the Treasury and derives its powers from a combination of presidential executive orders and statutory authority, including the International Emergency Economic Powers Act (IEEPA) and the Trading with the Enemy Act (TWEA). OFAC maintains several distinct sanctions programmes, each targeting specific countries, regions, individuals, or sectors.

The framework divides broadly into two categories. Comprehensive sanctions programmes impose near-total prohibitions on transactions involving designated countries or territories. List-based sanctions programmes target specific individuals, entities, and vessels, regardless of their nationality or location. The Specially Designated Nationals and Blocked Persons List (SDN List) is the central tool for list-based restrictions, and any person or entity appearing on it is effectively cut off from the US financial system.

A critical concept for international businesses is the "50 percent rule." Under OFAC guidance, any entity owned 50 percent or more - directly or indirectly - by one or more SDN-listed parties is itself treated as blocked, even if it does not appear on the SDN List by name. This rule creates significant due diligence obligations for companies engaged in cross-border transactions, mergers, or joint ventures. Many foreign companies underestimate the reach of this rule when structuring deals involving complex ownership chains.

OFAC also issues general licences, which authorise categories of transactions that would otherwise be prohibited, and specific licences, which authorise individual transactions on a case-by-case basis. Understanding which licences apply to a given transaction is a core element of any compliance programme.

Recent regulatory developments and current enforcement priorities

The US sanctions landscape has evolved considerably in recent periods. Executive orders have expanded the scope of several programmes, adding new sectoral restrictions and broadening the categories of persons subject to designation. OFAC has also issued updated guidance clarifying its expectations for compliance programmes across industries, including financial services, technology, and commodities trading.

Enforcement actions in recent periods have highlighted several recurring themes. First, OFAC has pursued cases involving apparent violations by non-US financial institutions that processed dollar-denominated transactions through US correspondent banks. Even brief, incidental contact with the US financial system can create exposure. Second, the agency has focused on the use of intermediaries and shell structures to obscure the involvement of sanctioned parties. Third, OFAC has coordinated increasingly with the Department of Justice (DOJ) and the Financial Crimes Enforcement Network (FinCEN), resulting in parallel civil and criminal proceedings in significant cases.

The current enforcement environment also reflects a broader trend toward secondary sanctions. Secondary sanctions do not require a US nexus in the underlying transaction; instead, they target foreign persons who engage in specified conduct with sanctioned parties. This extraterritorial reach has become a major compliance concern for European, Asian, and other non-US businesses that have no direct US operations but maintain relationships with US financial institutions or use US-dollar clearing.

OFAC';s Framework for Compliance Commitments, published as guidance, sets out five essential components of an effective sanctions compliance programme: management commitment, risk assessment, internal controls, testing and auditing, and training. Regulators treat the presence or absence of a formal compliance programme as a significant factor in determining penalties and whether to pursue enforcement.

Export controls and their intersection with sanctions compliance usa

Sanctions compliance in the USA cannot be understood in isolation from export controls. The two regimes overlap significantly and are often triggered by the same transactions. The primary export control frameworks are the Export Administration Regulations (EAR), administered by the Bureau of Industry and Security (BIS) within the Department of Commerce, and the International Traffic in Arms Regulations (ITAR), administered by the Directorate of Defense Trade Controls (DDTC) within the Department of State.

The EAR governs the export, re-export, and transfer of dual-use goods, software, and technology. Items subject to the EAR are classified on the Commerce Control List (CCL), and their export may require a licence depending on the destination, end-user, and end-use. BIS maintains its own restricted party lists, including the Entity List, the Denied Persons List, and the Unverified List. Appearing on any of these lists imposes specific restrictions on transactions involving the listed party.

ITAR controls defence articles and defence services listed on the United States Munitions List (USML). The ITAR regime is notably strict: it applies to US persons worldwide and imposes registration requirements on manufacturers and exporters of defence articles, regardless of whether any actual export has occurred. A common mistake among foreign companies acquiring US defence-related businesses is failing to account for ITAR obligations that transfer with the acquisition.

The intersection of sanctions and export controls creates a layered compliance challenge. A transaction may be permissible under OFAC rules but still require a BIS licence, or vice versa. In practice, compliance teams must screen against multiple lists simultaneously and apply the most restrictive applicable rule. Recent enforcement actions have involved companies that satisfied one regime while inadvertently violating the other.

If your business involves cross-border technology transfers, supply chain relationships with US entities, or investments in US companies, a coordinated review of both sanctions and export control obligations is essential. Contact info@vlolawfirm.com - we can help structure the setup correctly the first time.

Building an effective sanctions compliance programme in the USA

An effective compliance programme for the US sanctions environment requires more than list screening. OFAC';s published guidance makes clear that regulators assess the totality of a company';s compliance efforts, not merely whether a specific transaction was screened. The following elements are central to a programme that will withstand regulatory scrutiny.

Risk assessment is the foundation. Companies must identify their specific exposure based on their industry, customer base, geographic footprint, transaction types, and counterparty relationships. A financial institution processing international wire transfers faces different risks than a technology company licensing software to foreign distributors. The risk assessment should be documented, updated regularly, and used to calibrate the intensity of controls applied to different business lines.

Screening processes must be robust and current. OFAC updates the SDN List and other restricted party lists frequently, sometimes multiple times per week. Compliance programmes that rely on periodic batch screening rather than real-time or near-real-time checks create gaps that regulators have cited in enforcement actions. Screening must cover not only direct counterparties but also beneficial owners, intermediaries, and, where relevant, vessels and aircraft involved in transactions.

Internal controls should include clear escalation procedures for potential matches, documented decision-making processes for borderline cases, and mechanisms for reporting potential violations internally before they become enforcement matters. OFAC';s voluntary self-disclosure programme offers meaningful penalty mitigation for companies that identify and report apparent violations promptly and cooperate fully with the agency';s investigation.

Training must be tailored to the roles of the individuals receiving it. Front-line staff who onboard customers or process transactions need practical, scenario-based training. Senior management and board members need a clear understanding of the legal exposure and the company';s overall risk posture. Generic annual training that is not role-specific is a common gap identified in enforcement proceedings.

Testing and auditing close the loop. Independent reviews of screening processes, transaction monitoring, and escalation procedures allow companies to identify weaknesses before regulators do. Many companies conduct annual audits; higher-risk businesses should consider more frequent reviews or targeted transaction testing.

Practical compliance scenarios and common mistakes

Two scenarios illustrate the practical complexity of sanctions compliance in the USA.

In the first scenario, a European technology company sells software to a distributor in a third country. The distributor has no apparent US connection, and the software is not subject to ITAR. However, the software contains US-origin components that bring it within the scope of the EAR';s de minimis rules, and the distributor';s ultimate parent is majority-owned by an SDN-listed entity. Under the 50 percent rule, the distributor is itself blocked. The European company, which processes payments through a US correspondent bank, has now created OFAC exposure for itself and potentially for the correspondent bank. A common mistake here is assuming that the absence of a direct US counterparty eliminates US sanctions risk.

In the second scenario, a US financial institution processes a series of transactions for a foreign corporate client. The client';s name does not appear on any restricted party list. However, a subsequent audit reveals that the client was acting as an agent for a blocked entity, routing payments through the corporate structure to obscure the ultimate beneficiary. OFAC';s guidance on evasion makes clear that facilitating transactions on behalf of blocked parties - even unknowingly - can constitute a violation. The institution';s liability turns on whether it had adequate controls to detect the underlying structure and whether it self-disclosed upon discovery.

Several mistakes recur across enforcement cases. Many companies fail to screen for the 50 percent rule beyond the first tier of ownership. Others apply inconsistent screening standards across business units or geographies. Some rely on contractual representations from counterparties as a substitute for independent due diligence, which OFAC does not accept as a complete defence. And many underestimate the compliance obligations that arise when US persons - including employees, directors, or shareholders - are involved in transactions that would otherwise have no US nexus.

A non-obvious requirement is the obligation to maintain records of all transactions subject to OFAC regulations, including transactions that were screened and cleared. OFAC may request records in connection with an investigation, and the inability to produce them can itself be treated as an aggravating factor.

Frequently asked questions

Does US sanctions law apply to non-US companies with no US operations?

US sanctions can apply to non-US companies in several circumstances. Secondary sanctions target foreign persons who engage in specified conduct with sanctioned parties, regardless of any US nexus. Additionally, any transaction that touches the US financial system - including dollar-denominated payments cleared through US correspondent banks - can create OFAC exposure. Non-US companies that employ US citizens or permanent residents, or that have US shareholders or directors, may also find that those individuals are subject to US sanctions obligations in their personal capacity. The practical reach of US sanctions is therefore considerably broader than the formal jurisdictional rules suggest.

How long does it take to build a compliant sanctions programme, and what does it cost?

The timeline and cost depend heavily on the size and complexity of the business. A small company with a straightforward business model and limited international exposure can implement a basic compliant programme within a few months, with professional fees typically in the low to mid thousands of dollars. A large financial institution or multinational with complex transaction flows, multiple jurisdictions, and high-risk counterparties may require a programme build-out spanning twelve months or more, with costs running into the hundreds of thousands. Ongoing costs include screening technology, staff training, periodic audits, and legal advisory fees. Many companies underestimate the cost of maintaining a programme once built, particularly as regulatory requirements evolve and lists are updated.

What is the difference between a general licence and a specific licence, and when do you need each?

A general licence is a standing authorisation issued by OFAC that permits a defined category of transactions without requiring individual approval. General licences are published in the Code of Federal Regulations and in OFAC';s programme-specific regulations. If a transaction falls within the terms of a general licence, no application is required. A specific licence, by contrast, is an individual authorisation that a person or company must apply for when a transaction is not covered by a general licence but may nonetheless be permissible on the specific facts. OFAC reviews specific licence applications on a case-by-case basis, and the process can take several months. Businesses should identify applicable general licences before applying for specific licences, as the latter process is resource-intensive and not guaranteed to succeed.

Conclusion and how VLO Law Firms can assist

Sanctions compliance in the USA is a dynamic, high-stakes area of law that demands continuous attention. The regulatory framework spans multiple agencies, applies extraterritorially in significant ways, and intersects with export controls to create layered obligations. Enforcement is active, penalties are substantial, and the reputational consequences of a violation can outlast the financial ones. Businesses operating internationally must treat sanctions compliance as a core governance function, not a back-office checkbox.

VLO Law Firms advises international clients on sanctions compliance in the USA. We can assist with compliance programme design and review, restricted party screening frameworks, licence applications, voluntary self-disclosure, and export control analysis under the EAR and ITAR. To request a consultation, contact: info@vlolawfirm.com