Drafts a board-ready sanctions compliance program framework organized by a five-pillar compliance framework that identifies the root cause of prior incidents, requires screening tool reconfiguration, integrates export-control and sanctions screening for dual-use goods, addresses conflicts between U.S. sanctions compliance obligations and foreign blocking or antiboycott-type restrictions, and establishes a direct board reporting line for the compliance function.
Scanned 9/11/2026
Install to Claude Code
npx -y skills add sunyifeisb-art/legalwork --skill draft-sanctions-compliance-program-framework --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Draft Sanctions Compliance Program Framework?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/sunyifeisb-art-draft-sanctions-compliance-program-framework)More formats (shields.io, HTML) on the badges page.
---
name: its-draft-sanctions-compliance-program-framework
task_id: international-trade-sanctions/draft-sanctions-compliance-program-framework
description: Drafts a board-ready sanctions compliance program framework organized by a five-pillar compliance framework that identifies the root cause of prior incidents, requires screening tool reconfiguration, integrates export-control and sanctions screening for dual-use goods, addresses conflicts between U.S. sanctions compliance obligations and foreign blocking or antiboycott-type restrictions, and establishes a direct board reporting line for the compliance function.
activates_for: [planner, solver, checker]
---
# Skill: Draft Sanctions Compliance Program Framework
## 1. Subject-matter triage
- Treat the attached risk assessment, voluntary disclosure, bank inquiry, operations data, and compliance materials as the factual record for the framework; do not invent a separate incident narrative.
- Determine whether the company operates through foreign subsidiaries, moves dual-use goods, uses international payments, or faces local blocking-style restrictions, because those facts change the compliance architecture.
- Identify whether the prior miss was a screening failure, an ownership-analysis failure, a list-maintenance failure, a payment-monitoring failure, or a governance failure; the framework must remediate the actual failure mode, not a generic one.
- If multiple business lines, geographies, or customer channels are in scope, map them separately before drafting controls so the program matches the actual risk surface.
## 2. Failure modes the skill is correcting
- Listing remediation measures without tying each measure to the root cause of the prior incident, which leaves the framework aspirational instead of corrective.
- Treating name screening as sufficient when beneficial ownership, alias logic, list freshness, or transaction context were part of the failure.
- Separating export-control review from sanctions screening for dual-use products, which can leave high-risk transactions outside both controls.
- Ignoring the tension between U.S. sanctions compliance expectations and foreign-law blocking or similar restrictions in the group structure.
- Placing sanctions compliance under the business chain of command without a direct escalation path to the board or audit committee.
- Failing to address correspondent-banking routing and bank follow-up processes where the company relies on cross-border payments.
- Drafting controls that sound strong but do not specify ownership, cadence, testing, and recordkeeping.
## 3. Legal frameworks / domain conventions that apply
- Base the framework on recognized sanctions-compliance program principles: management commitment, risk assessment, internal controls, testing/auditing, and training.
- Tie every remediation element to the applicable sanctions authority and, where relevant, export-control authority, recordkeeping rule, or blocking-regulation constraint.
- For list-based screening controls, include identity matching, alias logic, ownership and control analysis, and list-refresh governance.
- For dual-use goods, coordinate sanctions review with export-classification and end-user/end-use review so the same transaction is not cleared by one function while blocked by the other.
- For foreign subsidiaries, specify a local-law-compliant structure that preserves local compliance while allocating U.S.-person obligations to the relevant entities and obtaining local authorization where required.
- For board oversight, require direct reporting to the board or audit committee with documented escalation authority and periodic reporting.
- For banking controls, address wire-message review, intermediary-bank routing, sanctions-hit escalation, and bank inquiry response protocols.
- For records, require retention aligned to applicable sanctions and export-control recordkeeping rules and any stricter internal retention standard.
- Cite controlling authorities for each substantive proposition used in the framework, including the applicable sanctions regulations, export-control regulations, recordkeeping requirements, and any recognized guidance the framework relies on.
## 4. Analytical scaffolds
1. Identify the specific root cause from the incident materials, then draft a short root-cause section that states the failure and the exact controls that prevent recurrence.
2. Convert each identified remediation into a binding program requirement, with policy owner, procedure, monitoring method, and testing cadence.
3. For screening controls, require configuration for name variations, ownership look-through, list refresh, escalation review, and exception handling.
4. For dual-use transactions, state how sanctions screening, export classification, end-use review, and shipment release decisions are sequenced and documented.
5. For foreign affiliates, state how obligations differ by entity type and jurisdiction, and how the group resolves local-law conflicts without leaving gaps in U.S.-person compliance.
6. For governance, require a direct board or audit committee reporting line, define report content, and specify when escalations occur.
7. For banking, address intermediary-bank monitoring, payment-message review, and how the company responds to a bank’s sanctions inquiry or hold.
8. For jurisdictional risk, assign tiers by geography and customer/channel risk, including transshipment-risk jurisdictions that require enhanced review.
9. For records, specify what is kept, by whom, where, and for how long, using the controlling retention rule as the baseline.
10. Finish with concrete implementation steps so the framework reads as an operating program, not a summary of observations.
## 5. Vertical / structural / temporal relationships
- The investigation record establishes what failed first; the framework should trace control design from that starting point outward.
- Operations data should drive the jurisdiction, product, and customer risk tiers, not the other way around.
- The bank inquiry and payment records inform the payments-control section and should be reflected in escalation and documentation requirements.
- The compliance materials define the current governance structure and the delta needed to reach a board-ready program.
- If a deadline appears in the source record, use it; if not, anchor timing to implementation phases, reporting cycles, or regulatory milestones.
## 6. Output structure conventions
- Draft a board-ready sanctions compliance program framework in a conventional five-pillar format.
- Use section headings that read like a policy framework, such as: governance and accountability, risk assessment, controls and procedures, monitoring and testing, training and reporting, and records and escalation.
- Within each pillar, include: policy requirement, operating procedure, accountable role, monitoring/testing, and recordkeeping.
- Include a concise root-cause subsection near the front of the document.
- Where the facts support it, include a separate section for foreign affiliates and a separate section for banking and payments controls.
- Write in directive, programmatic language suitable for board approval; avoid narrative explanation that does not become a control requirement.
- End with practical implementation steps and reporting expectations so the document can be adopted as a living compliance framework.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!