OFAC's compliance framework names five components — management commitment, risk assessment, internal controls, testing, training. What it doesn't require is a bank's apparatus inside a fifty-person company. Right-sizing is the craft.
Tools flag; someone must decide, document, and occasionally call the question: is this a false positive, a blockable transaction, a license application, or a walk-away? Those calls are legal judgment applied to lists that change weekly — and having the judgment retained before the interesting hit arrives is what turns a crisis into a Tuesday. When the framework has to be shown — to a bank, an acquirer, or OFAC itself — the program's paper trail is the deliverable.
You need screening proportionate to where you sell and through whom — for many companies that's genuinely modest. The risk assessment tells you the size; skipping the assessment is the unforced error.
OFAC's guidelines score program quality explicitly, and published settlements credit it. It's also the difference between catching an issue for self-disclosure and reading about it in a subpoena.
Gap reviews against the five-component framework are standard scope — short, privileged, and usually ending in a punch list rather than a rebuild.