Podcasts
Watch videos featuring supply chain experts
Most trade compliance programs don't fail because a company ignored the rules. They fail because the program existed on paper, but nobody funded it, tested it, or updated it once it was written.
Regulators have noticed this pattern too. When OFAC and the Bureau of Industry and Security (BIS) evaluate a company after a violation, they're not just asking whether a policy document existed. They're asking whether it was actually followed, resourced, and current.
This matters because both agencies have published their own expectations for what an effective program looks like. That gives compliance teams something rare in this field: a fairly specific, publicly available answer to "what does good actually look like here."
Two agencies have published detailed guidance on program structure, and most effective compliance programs are built around one or both.
OFAC's 2019 Framework for Compliance Commitments identifies five essential components of a sanctions compliance program: management commitment, risk assessment, internal controls, testing and auditing, and training. These aren't a legal requirement, but OFAC explicitly considers them when deciding how to treat a company after a violation.
Management commitment includes senior leadership reviewing and approving the program, delegating real authority to compliance staff, and allocating adequate resources, including a dedicated compliance officer. A program run by one under-resourced analyst with no executive sponsor rarely survives contact with a real violation.
BIS takes a similar approach for export controls. Its Export Compliance Guidelines set out eight elements of an effective Export Compliance Program (ECP), starting with strong and continuous management commitment and including regular risk assessments, conducted at least annually.
The underlying elements BIS expects, whether framed as the eight-part ECP or the longer-standing nine-part Export Management and Compliance Program, include management commitment, risk assessment, a written program, training, screening across the transaction lifecycle, recordkeeping, audits, and a process for handling violations and corrective action.
The overlap between OFAC's and BIS's frameworks isn't a coincidence. Both are describing the same underlying discipline: commitment from the top, a clear-eyed view of risk, controls that match that risk, and a way to catch and fix failures.
A compliance program with no executive sponsor is a document, not a program. Real commitment looks like specific, visible actions.
This matters more than it sounds. In enforcement actions, agencies specifically look at whether compliance staff had the authority and resources to act, not just the responsibility to try.
A generic compliance policy copied from a template doesn't hold up because it wasn't built around your specific products, customers, and geography. Risk assessment is where a program starts to fit the company that owns it.
A useful risk assessment maps exposure across several dimensions:
| Risk Dimension | Questions to Answer |
|---|---|
| Products | Which products carry export control classifications? Which have complex or shifting HS classifications? |
| Customers and Counterparties | Do we deal with resellers, distributors, or intermediaries whose end customers we can't fully see? |
| Geography | Which countries do we ship to or source from that carry sanctions, export control, or forced labor exposure? |
| Transaction Structure | Do we use freight forwarders, drop-shipments, or third-party logistics providers that reduce our visibility into the full transaction? |
| Ownership Complexity | Do our counterparties have ownership structures that could trigger affiliate-level restrictions? |
This assessment should run at least annually, and sooner after a material change: a new product line, a new market, or a regulatory change like BIS's 2025 rule extending export restrictions to affiliates 50% or more owned by listed parties.
Internal controls are the actual mechanics of compliance: the screening process, the classification workflow, the licensing determination steps. They should be sized to the risk identified in step two, not applied uniformly regardless of exposure.
Core controls most programs need:
Trademo sanctions and PEP screening, ownership and control screening, HS classification, and ECCN classification capabilities support several of these controls directly.
Generic annual compliance training satisfies a checkbox but doesn't change behavior at the point where decisions actually get made. Effective training is role-specific.
Training that's identical for every employee regardless of role tends to be forgotten quickly, because most of it doesn't apply to any given person's actual job.
Testing and auditing exist to answer one question: does the program actually work the way it's documented to work? This is the step most programs skip, usually because it requires admitting something might be broken.
Findings from testing should feed back into the risk assessment and controls. A testing program that never changes anything isn't testing, it's documentation for its own sake.
Step 6: Define a Violation Response and Corrective Action Process
Every program eventually finds a problem: a missed screening hit, a misclassified product, a shipment that went out before a license was confirmed. What happens next matters as much as prevention.
Agencies distinguish clearly between a company with an isolated failure and effective remediation, and a company with a systemic gap it never addressed. The response to a known issue often matters more in enforcement outcomes than the issue itself.
A compliance program built once and left alone degrades quietly. Regulations change independently across jurisdictions, and reference data, tariff schedules, sanctions lists, entity lists, goes stale without anyone necessarily noticing until it causes a problem.
Programs that hold up over time typically build in:
Trademo global trade content capability, covering regulatory intelligence across 140+ countries, and its supply chain mapping and forced labor compliance capabilities, support this kind of ongoing program maintenance.
An effective trade compliance program isn't defined by the thickness of its policy manual. It's defined by whether leadership actually backs it, whether it's built around the company's real risk, and whether anyone checks that it's working.