So, I asked Gemini:
Assume you are a sanctions officer. What do firms benchmark their programs against? If there is a difference between typical practice and best practice, note it and explain it, if possible, using publicly-available thought leadership sources. List sources
And this was its response:
As a sanctions officer, I view benchmarking not as a “tick-box” exercise to satisfy regulators, but as the primary mechanism to defensibly demonstrate that our program is commensurate with our risk profile.
If we are asked by a regulator (like OFAC or OFSI) to defend a compliance failure, our strongest defense is proving our program aligned with industry standards before the breach occurred.
Here is what we benchmark against, and where the market is moving regarding “typical” versus “best” practice.
1. The Core Benchmarks (The “Must-Haves”)
Every credible program is built on a few foundational documents. These are the standards against which we will be audited.
- The “Gold Standard”: OFAC’s 5 PillarsThe primary benchmark globally is the Department of the Treasury’s “A Framework for OFAC Compliance Commitments” (2019).1 Even non-US firms benchmark against this because of the extraterritorial reach of the USD.2
- The 5 Pillars: Management Commitment, Risk Assessment, Internal Controls, Testing/Auditing, and Training.3
- Financial & Screening Standards: The Wolfsberg GroupFor screening specifically (the technical engine of our program), we benchmark against the Wolfsberg Guidance on Sanctions Screening.4 This defines what “good” looks like for fuzzy logic, list management, and resolving alerts.
- ISO Standards (ISO 37301)While broader than just sanctions, ISO 37301 (Compliance Management Systems) provides the structural benchmark for how the compliance function is governed and independent.
2. Typical Practice vs. Best Practice
This is where the gap exists. “Typical” practice is often compliant on paper but fragile in reality. “Best” practice (often called “Optimized” or “Proactive” in maturity models) is what protects the firm from enforcement actions when things go wrong.
Program Element Typical Practice (Defensible) Best Practice (Optimized) Risk Assessment Static & Annual. Conducted once a year using a spreadsheet. Focuses heavily on customer geography. Dynamic & Trigger-Based. Updated continuously based on “trigger events” (e.g., new product launch, M&A, geopolitical shift). Integrates real-time transaction data rather than just policy inputs. Screening Logic Rules-Based. Uses standard fuzzy logic (e.g., “Levenshtein distance”) to catch misspellings. High false-positive rates (95%+) are accepted as the cost of doing business. AI/ML Enhanced. Uses Machine Learning to “learn” from past false positives and auto-close low-risk alerts. Includes Network Analysis to catch not just listed entities, but the shadow networkof shell companies owned by them (addressing the “50% Rule”). Training General & Annual. One generic “Sanctions 101” e-learning module assigned to all staff. Completion is tracked by signature. Role-Specific & Scenario-Based. The trading desk gets different training than HR. Training includes “red flag” scenarios relevant to their specific job function. Effectiveness is measured by post-training testing, not just attendance. Testing & Audit Internal Review. The compliance team “self-checks” or Internal Audit does a periodic review every 18-24 months. Independent Validation. An external third party validates the screening technology (Model Validation) annually to prove the software is actually catching what it claims to catch (e.g., testing against “synthetic” sanction data). Culture “Tone from the Top”. The CEO sends an annual email stressing the importance of compliance. “Echo from the Bottom”. Compliance metrics are tied to executive compensation. There is a documented “safe harbor” for employees to self-report near-misses without fear of retaliation. 3. Key Insight for Leadership
The biggest differentiator right now is Data Lineage.
- Typical practice trusts the screening vendor blindly.
- Best practice demands to know exactly how the list data moves from the UN/OFAC website into the internal screening engine. If there is a “latency” (delay) of 24 hours between a designation and our system update, a Best Practice program has a manual stop-gap control for that window.
Sources
- US Dept. of Treasury: A Framework for OFAC Compliance Commitments (May 2019)5
- The Wolfsberg Group: Wolfsberg Guidance on Sanctions Screening (2019)6
- Deloitte: Sanctions Compliance Programs: A Maturity Model Approach
- KPMG: OFAC Framework for Sanctions Compliance Programs (Thought Leadership Series)
It’s not a bad start, I guess – just not complete. While I’m neither a lawyer nor have experience as a sanctions officer, I think that, to stay current, you should also be looking at the regulatory expectations that crop up in enforcement actions, the behaviors underlying the sanctions violations (and tied back to the General Factors in the Enforcement Guidelines), and the improvements to compliance programs made by the subjects of enforcement actions. Perhaps it’s just a matter of level of detail… and that seasoned sanctions officers can likely add to this list further.

Leave a Reply