In June 2025, OFAC penalized GVA Capital, a San Francisco venture firm, $215,988,868 for willful violations of Russia sanctions and for failing to answer a subpoena. The fine hit the statutory maximum, and it stands as OFAC’s largest penalty since Binance paid $968.6 million in 2023.

Surfacing that exposure early is the whole job of a sanctions risk assessment questionnaire. It asks structured questions about customers, geographies, products, and counterparties, then converts the answers into a risk rating your compliance program can act on the same quarter.

Key Takeaways for the Sanctions Risk Assessment Questionnaire
OFAC’s 2019 Framework for Compliance Commitments makes risk assessment the second of five pillars, and the questionnaire is how most firms turn that pillar into evidence.
Enforcement escalated sharply: OFAC penalties totaled $48.8 million in 2024, then passed $265 million in 2025, led by GVA Capital’s $215,988,868 statutory-maximum fine.
Cover six domains: customers, geography, products and services, counterparties, transactions, and delivery channels, with ownership traced under OFAC’s 50 Percent Rule.
Score on a risk basis: inherent exposure net of control strength, compared against approved risk appetite, refreshed annually and after every designation wave.
Wire the answers into screening: match thresholds, list scope, and alert routing should all trace back to questionnaire results, mirroring Wolfsberg questionnaire practice.
Attach evidence to every answer; FFIEC examiners retest samples, and GVA Capital paid an extra $1,988,868 for failing to answer an OFAC subpoena.

OFAC penalties jumped from $48.8 million across all of 2024 to more than $265 million in 2025, a jump Sidley Austin’s year-end review attributes largely to a single action against one venture firm. The enforcement math argues for doing this well.

The Job a Sanctions Risk Assessment Questionnaire Actually Does

A sanctions risk assessment questionnaire is a structured set of questions that maps where a business could touch sanctioned parties, places, or goods. OFAC’s Framework for Compliance Commitments names risk assessment as the second of five pillars every sanctions compliance program stands on.

The instrument does two jobs at once. Internally, it feeds the compliance risk assessment cycle that decides where controls and budget go; externally, it answers the diligence packets that banks, insurers, and enterprise customers now send before they will transact with you.

Banks know this format through the Wolfsberg questionnaires. The Wolfsberg Group’s CBDDQ and its shorter FCCQ, last updated in February 2023, are the global standard for financial crime diligence between institutions, and both devote sections to sanctions screening and list management.

The Five Pillars Behind the Sanctions Risk Assessment Questionnaire

Sanctions Risk Assessment as pillar two of OFAC's 2019 five-pillar compliance framework

Figure 1. OFAC’s 2019 framework makes risk assessment pillar two of five. Source: US Treasury, OFAC.

Regulators Who Read Your Sanctions Risk Assessment Questionnaire

Those pillars come with names and case files attached. OFAC sits inside the US Treasury and enforces dozens of country and list-based programs, and its civil penalties page logs every settlement, including GVA Capital’s. Let that enforcement record calibrate the questionnaire’s severity scale.

US exposure rarely stops at OFAC. The FFIEC BSA/AML examination manual tells bank examiners how to test OFAC compliance, FinCEN polices the money laundering side, and the Commerce Department’s Bureau of Industry and Security adds export control lists that screening programs must cover.

The overlap is expensive when ignored. In October 2024, FinCEN assessed a record $1.3 billion penalty against TD Bank for program failures on the laundering side of the same compliance house, a reminder that sanctions questions and AML questions travel together.

Cross-border operations also answer to the UN Security Council sanctions committees, the EU’s restrictive measures, and the UK’s Office of Financial Sanctions Implementation. A questionnaire built only around the SDN list will miss the mismatches that multi-jurisdiction screening has to reconcile.

Authority Remit What the questionnaire must capture
OFAC (US Treasury) SDN and country programs, 50 Percent Rule ownership tracing Customer and counterparty ownership above the 50% threshold
FinCEN BSA/AML programs and reporting How sanctions answers feed suspicious activity monitoring
FFIEC agencies Bank examination standards An evidence trail examiners can retest sample by sample
Commerce BIS Export controls and the Entity List Goods, software, and end-user questions for dual-use items
UN Security Council Global baseline designations Multi-list screening coverage beyond US programs
EU and UK OFSI Restrictive measures and UK designations Jurisdiction conflicts and licensing requirements

Enforcement Landmarks Every Sanctions Risk Assessment Questionnaire Should Reflect

Sanctions Risk Assessment Questionnaire: Questions, Scoring, and the 2026 Enforcement Stakes

Figure 2. Four penalties in two years, from three different agencies. Sources: DOJ, FinCEN, OFAC.

Building the Sanctions Risk Assessment Questionnaire: Six Question Domains

Regulator expectations translate into six question domains. OFAC’s framework tells firms to assess customers, products, services, supply chain, intermediaries, counterparties, transactions, and geographic touchpoints. The questionnaire is simply that instruction turned into fields a business owner can answer without a law degree.

Domain Example questions Red flags the answers expose
Customers Who are the highest-risk customers by geography and ownership? Any state-owned or politically exposed links? Ownership chains touching SDN-listed parties
Geography Which countries do you sell into, buy from, or route payments through? Embargoed or high-risk jurisdictions in the footprint
Products and services Could your goods or software be diverted to military or dual-use ends? Items appearing on BIS control lists
Counterparties Who sits between you and the end user? Agents, resellers, freight forwarders? Intermediaries based in known transshipment hubs
Transactions What payment rails, currencies, and volumes move value in and out? Payments routed through high-risk corridors
Delivery channels How much business is non-face-to-face or closed through third parties? Anonymity that defeats screening at onboarding

Ownership and intermediaries take the most drafting time. OFAC’s 50 Percent Rule blocks entities majority-owned by sanctioned parties on the SDN list even when the entity itself appears on no list, so the questionnaire must ask who owns whom, at what percentage, and through which holding companies. The GVA Capital case grew from business done for a sanctioned investor.

Freight forwarders and resellers carry the freshest lessons. OFAC’s June 2025 action against Unicat Catalyst, a Texas supplier, settled at $3,882,797 over Iran and Venezuela sales, and the third-party risk management framework you already run should share data with the sanctions file.

Question formats matter as much as coverage. Yes-no questions produce clean scoring but flatten detail. Pair them with volume fields and free text; our vendor risk assessment questionnaire template and NIST vendor risk assessment questionnaire show the mixed format working in adjacent domains.

Scoring a Risk-Based Sanctions Risk Assessment Questionnaire

Collected answers only matter once they are scored. A risk-based approach weights each domain by inherent exposure, nets off control strength, and lands on a residual rating the board can compare against the risk appetite statements it has already approved.

Scoring Logic Inside the Sanctions Risk Assessment Questionnaire

Sanctions Risk Assessment Questionnaire: Questions, Scoring, and the 2026 Enforcement Stakes

Figure 3. Inherent exposure net of control strength drives the residual rating and its escalation path.

Rating Inherent drivers Control tests Action
Low Domestic customers, low-risk payment corridors Annual screening refresh and attestation Standard monitoring
Moderate Some cross-border volume, indirect foreign exposure Quarterly list updates, sample retests Enhanced review of flagged answers
High High-risk jurisdictions, layered ownership Real-time screening, independent testing Enhanced due diligence, senior sign-off
Critical Potential SDN or 50 Percent Rule exposure Immediate escalation and legal review Halt transactions, consider voluntary disclosure

Scoring borrows from the standard method. The same severity-and-likelihood logic in our guide on how to conduct a risk assessment applies here, and banks typically wire the output into the RCSA template their second line already maintains for operational risk.

OFAC expects the assessment to update when the business or the sanctions programs change, which in the Russia era means at least annually, with event-driven reruns for new products, markets, acquisitions, and designation waves. Refresh cadence is a scored decision too.

Feed the residual ratings upward as well. A sanctions score that lives only in compliance never shapes strategy, so route it through the enterprise risk management framework and track movement with compliance risk key risk indicators between formal reruns of the questionnaire.

From Answers to Screening: Where the Sanctions Risk Assessment Questionnaire Meets Technology

High scores have to change what the software does. Questionnaire output should set screening intensity: which lists, what fuzzy-match thresholds, how often batches rerun, and which alerts route to a human before a payment leaves the building. Interactive Brokers paid $11,832,136 in July 2025 after thousands of apparent violations slipped through its controls.

Questionnaire answer Screening consequence Tooling layer to evaluate
High-risk corridor payment volume Real-time payment screening, tighter match thresholds Screening engine and payment filters
Majority foreign or layered ownership Beneficial-ownership tracing against the 50 Percent Rule Ownership and registry data services
Dual-use product lines BIS Entity List added to the match sets Export control modules
Third-party sales channels Intermediary screening plus contract clauses TPRM platform integration
Non-face-to-face onboarding Identity verification plus adverse media checks KYC and onboarding platforms
Manual or legacy screening Batch rescreening on every list update Automated list management

Tool selection needs its own diligence pass. Our comparison of top sanctions screening software and the anti-money laundering software roundup walk the market, and the compliance management software review covers the workflow layer that stores questionnaire evidence for the examiner.

Calibrate match thresholds against your questionnaire’s risk tiers so a low-risk domestic customer does not generate the same alert volume as a freight forwarder in a transshipment hub, then write the calibration down where an examiner can find it. False positives are where screening programs quietly die.

The Penalty Curve a Sanctions Risk Assessment Questionnaire Defends Against

Sanctions Risk Assessment Questionnaire: Questions, Scoring, and the 2026 Enforcement Stakes

Figure 4. OFAC penalties went from $48.8 million in 2024 to more than $265 million in 2025. Sources: OFAC; Sidley Austin.

Sanctions Risk Assessment Questionnaire FAQs Boards and Executives Keep Asking

Who should complete a sanctions risk assessment questionnaire?

Compliance owns the template, but the answers come from the people who touch the risk: sales on customers and markets, treasury on payment rails, procurement on suppliers and intermediaries. A questionnaire filled out solely by the compliance team measures what compliance believes, and examiners notice the difference.

How often should a sanctions risk assessment questionnaire be refreshed?

Annually at minimum, with event-driven reruns for new markets, products, acquisitions, and major designation waves. OFAC’s framework expects the assessment to track the business as it changes, and 2022 through 2025 showed sanctions programs moving faster than any annual cycle.

What separates a sanctions risk assessment questionnaire from sanctions screening?

The questionnaire measures exposure; screening checks names against lists. One decides how aggressive the other should be, which lists apply, and where enhanced due diligence has to start. The two form one control loop rather than competing tools fighting for budget.

Does a small company need a sanctions risk assessment questionnaire?

Yes, scaled to its footprint. OFAC penalized GVA Capital, a small venture firm, $215,988,868 in 2025, and strict liability applies regardless of headcount. A ten-question version covering customers, countries, ownership, and intermediaries beats no assessment at every audit and in every enforcement negotiation.

Can the sanctions risk assessment questionnaire be outsourced?

Vendors can supply the template, the screening data, and even the interviews, and the compliance risk analysis behind it still belongs to you. OFAC holds the firm accountable for its own program, so treat outsourced questionnaires as inputs your team validates and signs.

What documentation should support sanctions risk assessment questionnaire answers?

Every answer needs an evidence pointer: customer data extracts, ownership registers, payment corridor reports, screening configurations, and training logs. Our compliance risk assessment template shows the evidence-column format, and examiners under the FFIEC manual will retest a sample of answers against source records.

Sanctions Risk Assessment Questionnaire Mistakes That End in Penalties

Enforcement files repeat themselves. Read a full year of OFAC settlements and identical program failures surface in case after case, most of them visible well in advance to anyone managing compliance risks with a current questionnaire and an honest scoring pass.

Mistake Why it happens The fix
One-time assessment, never refreshed Treated as an audit artifact, not a control Calendar triggers plus event triggers tied to change control
Ownership questions stop at the counterparty 50 Percent Rule tracing feels like overkill Trace ownership above 50% through holding structures
Screening divorced from the questionnaire Tools bought before risks were scored Let risk tiers set thresholds and list scope
Answers without evidence Speed prioritized over support Require an evidence pointer for every answer
Compliance answers its own questions Business lines never engaged Domain owners answer, compliance validates
Subpoenas and inquiries handled slowly No escalation protocol for regulator contact GVA Capital’s $1,988,868 subpoena lesson: respond fast

What 2026-2028 Will Ask of the Sanctions Risk Assessment Questionnaire

Designation waves arrive with each geopolitical turn, and 2025 proved a single administration change can redirect enforcement priorities inside months, so questionnaires that hard-code today’s country list will age badly before the next refresh. Volatility is the planning assumption now.

By 2026, ownership tracing is the hard technical problem. Sanctioned parties layer shell companies faster than lists update, which pushes questionnaires toward beneficial-ownership data feeds and makes the 50 Percent Rule question a living control instead of an annual checkbox.

AI screening will draw regulator attention next. FATF’s work on digital transformation points at machine-learning match engines, and firms should expect examiners to ask how model thresholds were validated, questions your legal and compliance KRIs should already be answering in the monthly pack.

Banking supervisors are converging on one file. Basel-era operational risk management in banking already treats sanctions failures as an operational loss category, and the definition of financial risk assessment keeps widening to include them. One questionnaire increasingly serves several masters.

 

Put Your Sanctions Risk Assessment Questionnaire in Front of Risk Publishing

A questionnaire drafted in the pre-2022 sanctions world is measuring a market that no longer exists. Risk Publishing builds and pressure-tests sanctions risk assessment questionnaires against OFAC’s five pillars for US firms; start with our services page, then use the contact form to schedule the gap review.

Index