A trading company with operations in the Asia-Pacific region completes its annual sanctions screen and finds no listed counterparties. Its compliance officer signs off the review. Six months later, DFAT's Autonomous Sanctions regime flags an indirect ownership connection that the screen missed entirely. The audit trail shows no periodic testing, no documented ownership-chain analysis, and no cross-regime check against OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons) or the UN Consolidated List. The question for the board is not whether the company has a compliance programme – it is whether that programme actually works.
As of July 2026, Australia's autonomous sanctions regime, administered by the Department of Foreign Affairs and Trade (DFAT), requires that businesses with exposure to designated persons and entities maintain a compliance posture that goes well beyond annual screening. Compliance audit and testing – the periodic, documented review of whether screening logic, ownership analysis, and transaction-monitoring controls are operating as intended – is the mechanism that distinguishes a defensible programme from a paper one. The consequences of getting this wrong under the autonomous sanctions regime include civil and criminal liability, reputational damage, and the loss of available penalty mitigants.
This analysis sets out the governing regime and authority, the methodology that a well-constructed audit and testing programme should follow, where the Australian regime diverges from OFAC and OFSI, the risk flags practitioners most commonly encounter, and when external counsel should be involved. We draw on our cross-border practice advising businesses with exposure across DFAT, OFAC, OFSI, and the EU Council regulations.
What is the governing regime and who administers it?
Australia's sanctions obligations arise under the autonomous sanctions legislation and the associated regulations, administered by DFAT. DFAT publishes and maintains the consolidated list of designated persons and entities subject to targeted financial sanctions and travel bans. Compliance with those obligations sits with the regulated entity – there is no dedicated sanctions regulator equivalent to OFSI or OFAC. DFAT is the listing authority; enforcement of breaches falls under the relevant criminal provisions of the sanctions legislation.
That structural difference matters for audit and testing. Under OFSI or OFAC, a regulated firm can point to published enforcement guidance, penalty frameworks, and compliance programme expectations to calibrate its internal review. Under the Australian regime, published guidance on programme quality is less prescriptive. Businesses are therefore expected to derive audit standards from first principles – the nature and volume of their sanctions exposure, the sectors they operate in, and the foreign-regime obligations that run alongside their Australian duties.
In our cross-border practice, we regularly advise businesses that assume DFAT's lighter published guidance means a lighter compliance standard. That assumption is a risk in itself. The absence of detailed programme guidance from DFAT does not create a lower threshold for what a court or regulator would regard as adequate due diligence in an enforcement context. If anything, it places a higher burden on the business to document why its programme is proportionate and effective.
What does a compliance audit under the Australian regime actually require?
A compliance audit under the Australian regime is a structured, documented review of whether a business's sanctions controls – its screening coverage, ownership-and-control analysis, transaction-monitoring logic, escalation procedures, and training records – are functioning as designed and are calibrated to the current risk environment. It is not a one-time exercise; it is a recurring cycle whose frequency reflects the business's exposure profile.
The audit has four components that, in our experience, businesses most commonly underweight. First, screening coverage: does the screening tool interrogate all relevant lists – the DFAT consolidated list, the UN Consolidated List, and, where the business has a US nexus, the OFAC SDN List and the relevant BIS restricted-party lists? A screen that covers DFAT but not the UN list will miss designations that Australia implements through UN Security Council resolutions. Second, ownership-and-control mapping: does the business apply an ownership and control test (the test for whether a non-listed entity is caught through a listed person's ownership or control) that accounts for indirect holdings? The Australian regime, like the EU and UK regimes, can catch entities that are not themselves listed but are controlled by a designated person.
Third, testing of the screening logic itself: is the tool tested against known-positive matches to confirm that it is generating alerts as expected? A misconfigured fuzzy-matching threshold can suppress alerts on name variants. Fourth, documented escalation: when an alert is generated, is there a documented, time-stamped escalation path that shows who reviewed it, what they concluded, and why? Absent that documentation, a business cannot demonstrate that a positive screen result was properly handled.
The position above covers the standard case. Your facts – the counterparty, the goods, the sector, the ownership chain, and the regimes in play – change the analysis considerably. For a review of your compliance programme against the Australian regime and its cross-border comparators, contact Calder & Vance at info@caldervance.com.
How does the Australian regime compare with OFAC and OFSI on compliance audit standards?
The three regimes share the same underlying objective – ensuring that sanctions prohibitions are not defeated by inadequate compliance controls – but they differ in how explicitly they articulate what a good programme looks like, and in the consequences of falling short.
OFAC publishes detailed compliance programme guidance that identifies five essential components: management commitment, risk assessment, internal controls, testing and auditing, and training. Testing and auditing is explicitly named as a core element, and OFAC's enforcement practice makes clear that the presence or absence of a tested programme is a significant factor in determining a penalty response. OFAC's civil penalty authority under IEEPA is based on the greater of a statutory maximum per violation or the value of the underlying transaction, and the existence of a documented compliance programme is a mitigating factor in the enforcement calculus. In our experience, businesses that can demonstrate systematic, documented testing consistently achieve better outcomes in OFAC enforcement proceedings than those that cannot.
OFSI, under the UK's Sanctions and Anti-Money Laundering Act (SAMLA) and the relevant thematic regulations, similarly expects that regulated entities maintain tested, risk-calibrated controls. OFSI's enforcement guidance addresses the aggravating and mitigating factors it considers in assessing a penalty, and the quality of a firm's compliance programme – including whether it was tested – is expressly relevant. OFSI operates a monetary penalty regime and can impose significant civil penalties for breaches. The UK regime also imposes a reporting obligation: where a person knows or suspects that another person is a designated person or has committed a financial-sanctions offence, there is a duty to report. That reporting window is short, and a firm whose monitoring systems are not functioning correctly may miss it entirely.
Against those two detailed regimes, DFAT's approach is comparatively less prescriptive. There is no published DFAT equivalent of OFAC's compliance programme framework or OFSI's enforcement guidance that maps programme quality to penalty outcomes. However, the criminal provisions of Australia's sanctions legislation are serious. A failure to maintain adequate controls does not provide a statutory defence; it may, in the absence of good faith and demonstrable due diligence, leave a business exposed. The cross-regime implication is clear: a business operating in the Asia-Pacific with a US or UK nexus should calibrate its Australian programme to at least the OFAC or OFSI standard, because those regimes' expectations are the higher bar and will apply concurrently.
The EU presents a further reference point. EU sanctions compliance – governed by the relevant Council Regulations and administered nationally, with oversight by the European Commission – increasingly expects documented testing and the identification of a senior compliance officer with accountability for the programme. The EU's approach to penalties varies by member state but has been moving toward greater enforcement intensity. Businesses with EU operations should ensure that the audit methodology they apply under DFAT is consistent with what they would be expected to demonstrate in an EU enforcement context. For a detailed treatment of the EU position, see our analysis at Compliance audit and testing under EU sanctions.
Where does Australian compliance audit and testing diverge from OFAC and OFSI?
The most practically significant divergence between Australia and its US and UK counterparts is the absence of a published, granular compliance programme framework from DFAT. Businesses subject solely to Australian sanctions obligations cannot point to a regulatory document that tells them what a tested programme should look like. They must construct that standard themselves, using DFAT's general published guidance, the nature of their sanctions exposure, and cross-regime comparators.
A second divergence is in the ownership-and-control methodology. OFAC applies a mechanical ownership test: an entity is blocked if designated persons own 50 percent or more in the aggregate, regardless of control. The analysis is numerical and does not require an assessment of whether the designated person actually directs the entity's conduct. The Australian regime, like the EU and UK regimes, captures entities that are owned or controlled by designated persons. The control limb introduces a qualitative assessment: does a designated person direct or influence the entity's decision-making, even without a majority ownership stake? In our experience, this is precisely where businesses conducting their own internal audits create gaps. They apply a numerical ownership check but do not document a control analysis.
A third divergence is in the treatment of voluntary self-disclosure. OFAC's framework for VSD (voluntary self-disclosure to a regulator) is well-developed: there is published guidance on when to self-disclose, what the submission should contain, and the mitigating effect on penalty outcomes. OFSI has a comparable framework. DFAT does not have an equivalent published VSD framework. A business that identifies a potential breach under Australian law must take legal advice on whether and how to approach DFAT, because the procedural pathway is less defined.
If a transaction has already been flagged, or a compliance review has uncovered a potential breach, an early assessment can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.
What do businesses most commonly miss in their compliance audit and testing?
Businesses miss predictable things. The gaps cluster around four areas that recur across the cross-border compliance engagements we handle.
The first is multi-list coverage. A business with Australian operations but no US nexus may screen only against the DFAT consolidated list. That screen will miss UN-list designations that Australia has not yet reflected domestically, and it will miss OFAC designations that could trigger secondary-sanctions risk for correspondent banks or US-dollar payment chains. The audit question is not merely "did we screen against DFAT?" but "did we screen against every list relevant to the transaction, the counterparty's ownership chain, and the payment rails used?"
The second is dormant escalation paths. Many businesses have written escalation procedures that describe what should happen when a screen generates a positive result. Fewer have tested those procedures. Does the nominated reviewer receive the alert in practice? Does the escalation reach a senior decision-maker before the transaction executes? Testing the escalation path against a known positive is a basic step that a significant proportion of the businesses we review have not taken.
The third is record-keeping. A well-tested programme that is not documented provides almost no protection in an enforcement context. Every screening run should generate a dated, retained record. Every escalation decision should be documented with a reasoned outcome. Every periodic audit should produce a written report that is reviewed, signed off, and stored. The Australian regime, like OFAC and OFSI, will ask for those records if a breach is investigated. A business that cannot produce them has already lost part of the argument.
The fourth is the interaction between sanctions controls and export-control obligations. Businesses that export goods, technology, or software with potential dual-use application need to assess whether their compliance audit covers the export-control dimension as well as the financial-sanctions dimension. Australia maintains export controls under its strategic goods legislation. DFAT administers both regimes. A compliance audit that covers financial sanctions but not export controls creates a gap that may not become visible until an enforcement inquiry. For the treatment of export controls alongside financial sanctions in the US context, see our analysis at Compliance audit and testing under BIS and the EAR.
When should a business involve external counsel in its compliance audit?
External counsel should be involved at three distinct points. The first is when the business is designing or redesigning its sanctions compliance programme. An independently scoped audit methodology, calibrated to the business's actual exposure profile across the regimes that apply to it, is more defensible than an internally designed checklist. It demonstrates that the business sought expert input and applied it – a factor that matters in enforcement contexts across OFAC, OFSI, and the Australian regime.
The second is when the audit itself uncovers a potential breach or a material gap. A gap that a business identifies and remediates voluntarily, with documented evidence of the identification and the corrective action, is treated very differently from a gap that comes to light through a regulatory inquiry. The window between identification and disclosure – where one is appropriate – is short. A business that manages that window without legal advice may inadvertently weaken its position.
The third is when the business is entering a new market, acquiring a new entity, or onboarding a category of counterparty that introduces material sanctions exposure. Pre-transaction due diligence that is scoped and documented by counsel provides a baseline that the ongoing compliance audit can test against. In a recent matter, a financial services business expanding into the Asia-Pacific region asked us to scope its sanctions compliance programme for the Australian and Singapore regimes simultaneously. We assessed the screening coverage, mapped the ownership-and-control methodology against both regimes, and identified a gap in the escalation documentation that the business's internal team had not detected. The matter was resolved through programme redesign and a documented remediation plan before any transaction was affected.
A common myth in the market is that a compliance programme designed for OFAC or OFSI will automatically satisfy the Australian regime. That is not correct. The regimes share structural similarities – designated-person lists, asset-freeze and dealing prohibitions, ownership-and-control concepts – but the listed persons differ, the thematic programmes differ, and the procedural pathways for licensing and voluntary disclosure differ. A firm that cross-maps its OFAC programme onto its Australian obligations without verification may be compliant under one regime and exposed under another. We have acted for businesses in exactly that position. The solution is a regime-specific gap analysis, not an assumption of equivalence.
Related practices
- Compliance audit and testing – Australia (service) – end-to-end programme review and testing for Australian-regime exposure
- Compliance audit and testing under BIS and the EAR – US export-control programme audit methodology and cross-regime considerations
- Compliance audit and testing under EU sanctions – Council-regulation compliance standards and programme design for EU-exposed businesses