ComplyFactor helps U.S. Money Services Businesses, fintechs, payment companies, and remittance and digital-asset businesses assess their sanctions exposure, design or strengthen OFAC compliance controls, and remediate gaps a review or partner has identified.
Sanctions risk isn't the same for every business β a remittance company sending funds to a handful of corridors and a payments platform onboarding customers globally don't carry the same exposure, and their controls shouldn't look identical either.
OFAC administers and enforces U.S. economic and trade sanctions programs. ComplyFactor is an independent compliance advisor, not affiliated with OFAC or the U.S. Treasury.
Sanctions engagements can start from one of a few places: a business building its first sanctions compliance framework, one reviewing controls that haven't kept pace with its growth, or one working through a specific gap a bank partner or internal review flagged. ComplyFactor supports each of these β assessing exposure, designing or revising the policies and controls that address it, and helping put changes into practice. None of this amounts to a guarantee of regulatory approval or a promise that a program prevents every future issue; it's practical work aimed at building a defensible, risk-based program.
Office of Foreign Assets Control β the federal authority administering and enforcing U.S. sanctions programs.
U.S. citizens and permanent residents wherever located, entities organized under U.S. law and their foreign branches, and persons physically present in the United States must comply.
Non-U.S. persons can be subject to specific OFAC prohibitions, including restrictions on causing a U.S. person to violate sanctions or engaging in sanctions-evasion activity.
Additional exposure can arise under particular sanctions programs. The analysis depends on the facts and the relevant program β not a blanket rule.
Whether a specific business has meaningful OFAC exposure is usually where a sanctions risk assessment starts.
OFAC does not prescribe a single sanctions compliance program suitable for every organization. Its Framework for OFAC Compliance Commitments strongly encourages a risk-based program and identifies five components it considers essential β not universal statutory requirements or fixed legal pillars:
Senior-level support and ownership of the program.
Identifying where sanctions exposure actually sits.
Policies and procedures that put the risk assessment into practice.
Checking whether the program actually works as designed.
Making sure relevant staff understand their role in it.
What each component actually needs to say depends on the organization's size, products and services, customers and counterparties, geographic exposure, business model, and sanctions risk β components identified in OFAC's Framework, not a fixed template.
A sanctions risk assessment maps where exposure could actually arise. The point isn't to produce a document that restates OFAC's own guidance β it's to translate these risk factors into the specific controls a business needs.
Who your customers are and their ownership structures.
Who else touches the transaction chain.
What's actually being offered.
Transaction types and how funds move.
Where the business and its customers operate.
Any other parties in the chain.
This is where ComplyFactor's work on this typically sits: running the assessment, then building the screening, escalation, and policy framework the findings actually call for.
Not every engagement includes every item below β scope is set during onboarding around the exposure the risk assessment actually identifies.
Where relevant.
Including 50 Percent Rule analysis, where relevant.
Where agreed.
Screening is one control among several, not the entire program. A potential name match is not automatically a sanctions violation β it should be reviewed against relevant identifiers, ownership information, and the applicable sanctions restrictions before a decision is made.
Flagged by the process
Against identifiers & restrictions
Where it can't be ruled out
By someone with authority
Blocked, rejected, or reported
Decision and reasoning retained
A program that worked at launch doesn't necessarily hold up as a business changes. Triggers include:
Any one of these is a reasonable prompt to revisit whether the existing controls still match the actual risk.
A gap assessment reviews existing controls against the business's actual sanctions exposure, identifies where they've fallen short, and assesses the risk each gap represents before prioritizing what gets fixed first.
Where things stand today
Against actual exposure
Ranked, not treated equally
Revised controls, sequenced
Where agreed
This is advisory work. It is not an OFAC examination, a regulatory certification, or a guarantee that a violation won't occur in the future.
Useful gaps to test for include:
Understanding the business behind the risk.
Mapping where exposure actually sits.
Where controls already exist.
Building or revising what's needed.
Sequencing the fixes by risk.
Where agreed as part of the engagement.
Deliverables depend on the agreed scope β a full program build and a targeted screening-control review don't produce the same set of documents.
The two overlap operationally β a transaction that raises a sanctions concern often runs through the same monitoring system that flags money-laundering risk. Depending on its activities and exposure, a business may need both, and the controls should be coordinated rather than built in isolation.
Not a generalist sanctions practice.
Tied to your actual exposure, not a standard checklist.
Aligned with the broader compliance work most MSBs also need.
Coordinated within the agreed engagement scope.
Set before the engagement starts.
U.S. persons β U.S. citizens and permanent residents wherever located, entities organized under U.S. law and their foreign branches, and persons physically present in the United States β must comply. Non-U.S. persons can also be subject to specific OFAC prohibitions, such as causing a U.S. person to violate sanctions or engaging in sanctions-evasion activity, and additional exposure can arise under particular sanctions programs β the analysis depends on the facts and the relevant program.
OFAC doesn't prescribe a single program suitable for every organization, but it expects businesses to comply with its sanctions rules regardless, and it treats the absence of a reasonable, risk-based program as a factor that can work against a business in an enforcement matter. Whether β and what β a program should cover depends on the business's own sanctions exposure, which a risk assessment identifies.
No. OFAC's guidance describes the internal controls a program should have, including screening, but it doesn't mandate specific software or technology. What matters is that whatever process a business uses actually identifies and addresses potential matches consistently.
Yes β where appropriate, the engagement can be scoped to a specific control area rather than requiring a full sanctions-program rebuild.
ComplyFactor can support the review of ownership and control information where relevant to sanctions exposure and screening. This isn't legal advice, and not every engagement includes detailed ownership analysis β it's scoped based on what the risk assessment identifies.
Typically current sanctions policies and procedures (if any), an overview of the business model, the customer and counterparty profile, products and services, geographic exposure, the existing screening and escalation process, and any relevant findings or partner requests. The exact scoping request depends on what the engagement covers.
Yes β where appropriate, the engagement can focus on the specific findings, gaps, or control areas identified during partner due diligence or review, rather than a broader program assessment.
Tell us about your sanctions risk, current program design, screening controls, or any gaps that need remediation β we support U.S. MSBs, fintechs, and payment businesses at any of those stages.