Sanctions Risk Factor Disclosure in SEC Filings: 2026 Practitioner Walkthrough
If your company has any exposure to Russia, Iran, China, or a dozen other sanctioned jurisdictions, your Item 1A risk factor section is under more scrutiny right now than at any point in the past decade. The SEC's Division of Corporation Finance has made sanctions risk factor disclosure one of its highest-priority comment letter areas since February 2022, and the staff's expectations have grown considerably more specific since then.
This walkthrough tells you exactly what the SEC wants to see, what triggers a comment letter, and how to draft a sanctions risk factor that holds up.
Key takeaway: A boilerplate "we may be subject to sanctions" statement is not a risk factor. It is an invitation for an SEC comment letter demanding a complete rewrite.
What Item 105 Actually Requires for Sanctions Risk Factors
Item 105 of Regulation S-K requires registrants to disclose only material risks, organized under descriptive headings, and to explain how each risk specifically affects the registrant. The SEC amended Item 105 in August 2020 (effective February 9, 2021), explicitly prohibiting generic disclosures that "could apply to any registrant."
For sanctions, this means the risk factor must do more than recite that OFAC administers sanctions programs. It must explain:
- Which specific sanctions programs apply to the company (Russia Harmful Foreign Activities Sanctions, Iran Sanctions, CMIC designations, etc.)
- How those programs affect the company's revenue, operations, supply chain, or financing
- What the company is doing about it, and whether those measures are adequate
- What the financial magnitude of the exposure is, if material
The SEC's 2020 final rule states that risk factors should explain "how the risk affects the registrant or the securities being offered" -- not just that the risk exists. The staff applies this standard aggressively to sanctions disclosures.
For a deeper grounding in the materiality threshold that governs whether a sanctions risk factor is required at all, see The SEC Materiality Standard for Risk Disclosure: 2026 Guide.
How the SEC Staff Actually Finds Generic Sanctions Risk Factors
The staff's cross-referencing methodology is the mechanism that catches companies off guard. Here is how it works in practice:
- A staff reviewer searches EDGAR full-text for the registrant's geographic revenue disclosures in MD&A or segment footnotes.
- The reviewer identifies revenue from a sanctioned or restricted jurisdiction -- say, Russia, Iran, or a Xinjiang-sourced supply chain.
- The reviewer then reads the risk factor section. If the risk factor is generic while the MD&A shows material exposure, a comment letter goes out.
The SEC's EDGAR full-text search system makes this cross-referencing trivial. Staff can search for "Russia" or "Iran" across all filings and instantly identify companies whose risk factors do not match their geographic disclosures.
This is why burying sanctions exposure in a geographic segment footnote while maintaining a boilerplate risk factor does not work. The staff will find the inconsistency, and the comment letter will demand both a revised risk factor and an explanation of why the prior disclosure was adequate.
PwC's SEC comment letter analysis identifies sanctions and geopolitical risk as among the fastest-growing comment letter categories in 2022 through 2024, with the staff particularly focused on whether companies have quantified their exposure and whether the risk factor is consistent with geographic segment disclosures.
The Six Elements the SEC Staff Demands in a Sanctions Risk Factor
Based on the SEC's March 2022 staff statement on Russia-Ukraine disclosure and the Division's comment letter practice since then, a defensible sanctions risk factor must address all of the following:
1. Named Jurisdictions and Applicable Sanctions Programs
Do not write "certain countries subject to sanctions." Name them. If you have Russia exposure, say Russia. If you have Iran exposure, say Iran. Identify the specific programs: the Russia Harmful Foreign Activities Sanctions, the Iran Sanctions program, the CMIC (Chinese Military-Industrial Complex) designations, or whatever applies to your business.
OFAC administers more than 30 active sanctions programs covering dozens of countries, entities, and individuals. A company with any meaningful international footprint almost certainly has at least one program requiring a materiality assessment.
2. Quantified Financial Exposure
The SEC staff expects registrants to quantify revenue or assets attributable to sanctioned or restricted jurisdictions if the exposure is material. This does not mean disclosing every dollar figure -- it means being specific enough that an investor can assess the magnitude of the risk.
If your Russia-related revenue was 8% of total revenue before the 2022 sanctions wave, say so. If your Xinjiang supply chain accounts for a material portion of your cost of goods sold, say so. The staff will compare whatever you disclose here against your geographic segment note, so the numbers must be consistent.
3. Direct and Indirect Exposure
KPMG's SEC comment letter guidance notes that the staff frequently asks companies to clarify whether their sanctions risk factor covers only direct exposure or also indirect exposure through subsidiaries, joint ventures, and supply chain partners. Companies that disclose only direct exposure while having material indirect exposure through non-consolidated entities receive comments demanding expansion.
This matters particularly for companies with European subsidiaries that transact with Russian counterparties, or companies with Asian joint ventures that source from Xinjiang.
4. Compliance Program Adequacy
The SEC staff expects a description of the company's sanctions screening and compliance processes -- not just that a program exists, but whether it is adequate. Law firms including Cleary Gottlieb have noted that the staff increasingly treats sanctions disclosure like environmental liability disclosure: disclose the risk, the financial magnitude, the mitigation steps, and an assessment of whether those steps are sufficient.
This does not mean disclosing privileged compliance details. It means stating, for example, that the company screens counterparties against the OFAC SDN list and Consolidated Sanctions List, that it has implemented transaction monitoring for high-risk jurisdictions, and that it cannot guarantee those measures will prevent all violations.
5. Secondary Sanctions Risk
Secondary sanctions -- the risk that non-US entities face US sanctions consequences for dealing with sanctioned parties -- are a disclosure challenge that most generic risk factors ignore entirely. The SEC staff has asked foreign private issuers to explain whether their non-US subsidiaries conduct business with sanctioned parties and whether secondary sanctions could affect the company's ability to access US capital markets, clear dollar transactions, or maintain US-person employees.
For US companies with significant non-US operations, the analysis is similar: if a non-US subsidiary is transacting with a Russian or Iranian counterparty in a way that could trigger secondary sanctions exposure, that risk belongs in the risk factor.
6. OFAC Licenses and Their Conditionality
This is the element most generic risk factors omit entirely. If the company holds an OFAC general or specific license that permits otherwise-prohibited transactions, the SEC staff has specifically asked companies to disclose this -- and to flag whether the license is subject to conditions or expiration that could affect the company's ability to continue those activities. A license that expires in 18 months is a material risk; it needs to be disclosed as such.
Before and After: Generic vs. Tailored Sanctions Risk Factor
The difference between a risk factor that draws a comment letter and one that does not is specificity. Here is what that looks like in practice.
Generic (will draw a comment letter):
We are subject to various laws and regulations relating to economic and trade sanctions administered by OFAC and other governmental authorities. Violations of these sanctions could result in significant penalties, reputational harm, and adverse effects on our business and financial condition.
The SEC staff's comment letter language for this type of disclosure is direct: "The risk factors that you present appear to apply to nearly any issuer in any industry. Please significantly revise the risk factors to ensure that they are tailored to the registrant's business."
Tailored (defensible against SEC review):
We generate approximately [X]% of our consolidated revenue from operations in [named jurisdiction], which is subject to the [specific sanctions program] administered by OFAC. Following the expansion of sanctions in [year], we wound down [specific activity] but continue to [describe remaining exposure]. Our non-US subsidiary [name] maintains [describe relationship] with counterparties in [jurisdiction], which creates secondary sanctions exposure if those counterparties are or become designated under the SDN list. We screen all counterparties against the OFAC Consolidated Sanctions List and the SDN list prior to onboarding and on a [frequency] basis thereafter, but we cannot guarantee that our compliance program will identify all sanctioned parties, particularly given the 50 Percent Rule, under which entities owned 50% or more by a sanctioned person are themselves blocked even if not named on the SDN list. If we are found to have violated applicable sanctions, we could face civil monetary penalties, loss of access to US dollar clearing, and reputational harm that could materially affect our business, financial condition, and results of operations.
This is longer, but it is what the SEC staff expects. Every sentence answers a specific question the staff would otherwise ask in a comment letter.
The OFAC 50 Percent Rule: A Disclosure Gap Most Companies Miss
OFAC's 50 Percent Rule means that entities owned 50% or more by a sanctioned person are themselves blocked, even if they are not named on the SDN list. This rule has significant implications for supply chain and joint venture disclosure that most sanctions risk factors fail to address.
A company with a joint venture partner in Russia, Iran, or another sanctioned jurisdiction needs to assess whether that partner -- or any entity in its ownership chain -- is or could become an SDN-listed person. If so, the JV itself may be blocked under the 50 Percent Rule, and that exposure belongs in the risk factor.
The same analysis applies to supply chain counterparties. If a supplier is majority-owned by a sanctioned entity, purchasing from that supplier may itself be a sanctions violation, regardless of whether the supplier appears on any list.
How China, UFLPA, and Export Controls Complicate the Disclosure
China-related sanctions disclosure has become substantially more complex since 2022. Three overlapping regimes now require coordinated disclosure:
| Regime | Key Risk | SEC Disclosure Focus |
|---|---|---|
| CMIC Designations | Transacting with Chinese military-industrial companies | Named counterparties, revenue exposure |
| UFLPA (effective June 2022) | Xinjiang supply chain rebuttable presumption of forced labor | Supply chain assessment, import disruption risk |
| BIS Export Controls (EAR) | Semiconductor and dual-use technology restrictions | Revenue from restricted Chinese customers, compliance costs |
The SEC staff has asked companies with China operations to address all three: whether supply chains include Xinjiang-sourced materials, whether any counterparties are on the CMIC or Entity List, and whether export control restrictions affect their ability to sell products or technology to Chinese customers.
The Uyghur Forced Labor Prevention Act creates a rebuttable presumption that goods produced in Xinjiang involve forced labor and are prohibited from US import. CBP has detained goods worth hundreds of millions of dollars since the law's June 2022 effective date. If your supply chain has Xinjiang exposure, the SEC staff expects you to have assessed it and disclosed the financial impact of any potential supply chain disruption.
The intersection of OFAC sanctions and BIS Export Administration Regulations creates a disclosure complexity the SEC staff increasingly treats as a single risk domain. Treating them as entirely separate risks in separate risk factors can create gaps that the staff flags. For companies with rare earth or semiconductor supply chain exposure, the segment-specific analysis in Rare Earth Export Controls in Your 10-K Risk Factor covers the export control side in detail.
Coordinating Sanctions Disclosure Across the Filing
Inconsistency across sections is one of the most common comment letter triggers. Sanctions exposure that appears in one section of the filing must be consistent with every other section that touches it.
Here is how the sections interact:
- Item 1A (Risk Factors): Disclose the nature, magnitude, and mitigation of the sanctions risk. This is where the tailored narrative lives.
- Item 7 / Item 303 MD&A: If sanctions are already affecting revenue or are reasonably likely to affect future results, Item 303 requires disclosure of that known trend or uncertainty. The numbers here must match the risk factor narrative.
- Item 103 (Legal Proceedings): If the company is under OFAC investigation or has received a subpoena related to sanctions compliance, Item 103 may require disclosure as a legal proceeding. Companies sometimes disclose one without the other, and the staff flags the inconsistency.
- Financial Statement Footnotes: Geographic segment disclosures and revenue disaggregation must be consistent with the risk factor's description of sanctioned-jurisdiction exposure.
For a decision framework on what goes in the risk factor versus MD&A, see Risk Factor vs. MD&A Disclosure Requirements: What Goes Where in 2026.
Key takeaway: If your Russia revenue appears in the geographic segment note but not in the sanctions risk factor, the SEC staff will find it. The cross-referencing is systematic.
When to Update the Sanctions Risk Factor Mid-Year
Sanctions regimes move fast. A counterparty added to the SDN list mid-year, a new executive order expanding the Russia sanctions program, or a material UFLPA enforcement action against a key supplier can all make a previously adequate risk factor stale by the next 10-Q.
Item 105 requires registrants to evaluate their risk factors each quarter and include additional disclosures needed to reflect material changes. The SEC's cybersecurity disclosure rules, which require disclosure of material incidents within four business days, establish the general principle: material risk developments require prompt, specific disclosure. The same logic applies to material sanctions developments.
Practically, this means your disclosure controls and procedures should include a sanctions monitoring trigger: if a material sanctions event occurs between annual filings, the next 10-Q risk factor section needs to reflect it. The CLM advisory principle applies directly here: "Issuers must maintain efficient disclosure controls to ensure [their disclosures] are accurate, tailored to the specific threat and continuously updated whenever any event materializes."
The Securities Litigation Risk From Inadequate Disclosure
The stakes go beyond SEC comment letters. The "bespeaks caution" doctrine -- which historically provided some protection for forward-looking statements accompanied by adequate risk factor disclosure -- does not protect companies from securities fraud claims if the risk factor is materially misleading because it omits known, specific sanctions exposure.
Courts have held that a risk factor saying "we may be subject to sanctions" is misleading if the company already knows it is conducting business in a sanctioned jurisdiction. The SEC's Division of Enforcement brought actions in 2023 and 2024 against companies that disclosed generic sanctions risk while simultaneously conducting business in Iran or Russia through non-US subsidiaries, treating the failure to disclose the specific exposure as a violation of Exchange Act Section 13(a) and Rule 13a-1.
For a broader look at how the SEC enforces against misleading risk factor language, see Hypothetical Risk Factor SEC Enforcement: The Disclosure Trap Catching Public Companies in 2026.
Using EDGAR's Comment Letter Database as a Drafting Tool
This is the most underutilized research tool available to practitioners drafting sanctions risk factors. All SEC comment letters and company responses are posted on EDGAR after the review closes, typically within 20 days. You can search EDGAR for comment letters on sanctions disclosure to see exactly what language the staff found inadequate and what revised language satisfied them.
Searching for "OFAC" or "sanctions" in the UPLOAD form type on EDGAR will surface dozens of real comment letter exchanges. Reading five or ten of these is more instructive than any general guidance document, because you see the actual back-and-forth: what the staff asked for, what the company provided, and whether the staff accepted it.
Sanctions Risk Factor Drafting Checklist
Before filing, run your sanctions risk factor against this checklist:
- Named the specific sanctions programs applicable to the company (not just "OFAC regulations generally")
- Identified the specific jurisdictions by name (Russia, Iran, China CMIC, etc.)
- Quantified revenue or assets from sanctioned jurisdictions, or explained why quantification is not material
- Addressed both direct exposure and indirect exposure through subsidiaries, JVs, and supply chain partners
- Described the company's sanctions screening and compliance program, including its limitations
- Addressed the OFAC 50 Percent Rule if the company has JV partners or supply chain counterparties in high-risk jurisdictions
- Disclosed any OFAC licenses held, including their conditions and expiration dates
- Addressed secondary sanctions risk for non-US subsidiaries, if applicable
- Addressed UFLPA and Xinjiang supply chain exposure, if applicable
- Addressed the intersection of OFAC sanctions and BIS/DDTC export controls, if both apply
- Confirmed consistency with MD&A geographic revenue disclosures and segment footnotes
- Confirmed consistency with any Item 103 legal proceedings disclosure related to OFAC investigations
- Confirmed the risk factor reflects the most current sanctions developments, not the state of the regime at the prior annual filing
- Confirmed that any OFAC investigation or voluntary self-disclosure is reflected in both the risk factor and Item 103, if material
FAQ
Does every public company need a sanctions risk factor? No. The obligation is triggered by materiality. If the company has no meaningful exposure to sanctioned jurisdictions, counterparties, or programs, a standalone sanctions risk factor is not required. But given that OFAC administers more than 30 active programs, virtually every large multinational should conduct a materiality assessment before concluding no disclosure is needed.
How specific does the revenue quantification need to be? The SEC staff does not require a precise dollar figure in every case, but it expects enough specificity for an investor to assess the magnitude of the risk. A percentage of revenue, a description of the affected business segment, or a statement that the exposure is below a specified threshold are all acceptable approaches, provided they are consistent with the financial statements.
Should we disclose our OFAC compliance program in detail? Not in detail. The risk factor should describe the program's general scope and acknowledge its limitations, not expose privileged compliance procedures. The goal is to give investors confidence that the company takes the risk seriously while being honest that no compliance program eliminates all risk.
What if we are under OFAC investigation? An OFAC investigation or voluntary self-disclosure is likely a material legal proceeding requiring disclosure under Item 103, and the risk factor should be updated to reflect the heightened risk. Disclosing one without the other is a common comment letter trigger.
Do foreign private issuers need to address US sanctions in their 20-F risk factors? Yes, if the exposure is material. The SEC staff has asked FPIs to explain whether their non-US subsidiaries conduct business with sanctioned parties and whether secondary sanctions could affect the company's access to US capital markets or dollar clearing. FPIs listed on US exchanges are subject to the same Item 105 materiality standard as domestic registrants.
How do we handle disclosure when we are uncertain whether a counterparty is sanctioned? Uncertainty is itself a risk worth disclosing. If the company cannot confirm with confidence that all counterparties are sanctions-clean -- particularly given the OFAC 50 Percent Rule -- the risk factor should acknowledge that limitation. Stating that the company screens counterparties but cannot guarantee complete compliance is both accurate and defensible.







