A multinational trading house operates across three continents. Its US affiliate clears payments through correspondent banks with OFAC exposure. Its European subsidiary buys dual-use components. Its Singapore entity sources from a supplier whose ultimate beneficial owner recently changed. The compliance team asks: does the programme that passed last year's internal audit still hold? The answer depends on which regime you measure it against – and how the regimes compare.
Sanctions compliance programmes under OFAC are measured against the five-element framework set out in OFAC's published compliance guidance: management commitment, risk assessment, internal controls, testing and auditing, and training. That structure is the US benchmark. It is not identical to the standards applied by OFSI, the EU, or Australia's DFAT regime – and the differences carry material consequences for any business operating across more than one jurisdiction.
This analysis sets the OFAC standard against the comparable positions of OFSI, the EU, the UN framework, and selected Asia-Pacific regimes, identifies the divergences that create compliance gaps, and maps the practical steps a cross-border business should take to close them.
What is the OFAC five-element standard, and why does it matter?
OFAC's compliance guidance establishes five elements that, taken together, define an effective sanctions compliance programme: senior management commitment, risk assessment, internal controls, testing and auditing, and training. These five elements are not a legal safe harbour, but OFAC treats the existence and quality of a compliance programme as a significant factor in assessing penalties and in deciding whether a voluntary self-disclosure (a proactive disclosure of a potential violation to the regulator, known as a VSD) warrants reduced treatment. A business without a documented programme enters any enforcement conversation at a disadvantage.
The weight OFAC places on management commitment is deliberate. Compliance teams that cannot point to board-level ownership of the programme – formal policies, delegated authority, documented escalation lines – face an argument that the violation was not merely inadvertent but systemic. In our experience, that characterisation reliably produces a harder outcome in an enforcement review. The converse is also true: a well-documented, genuinely implemented programme, tested against the actual transaction population, routinely features in the narratives that accompany voluntary disclosures and produce meaningful reductions in penalty exposure.
The risk-assessment element is where many programmes fail in practice. OFAC expects the assessment to be tailored to the business: its counterparty base, its products, its geographies, its payment routes. A generic template borrowed from a peer institution, unamended, does not satisfy the expectation. Does your current risk assessment actually reflect the routes your transactions take, or does it describe a different business?
How does OFSI's compliance standard compare to OFAC's?
OFSI, the UK's financial-sanctions regulator, applies a compliance standard that shares structural features with OFAC's five-element model but diverges on several points that matter operationally. The most significant divergence is the ownership and control test. OFAC applies a mechanical threshold: an entity is treated as blocked when blocked persons own 50 percent or more in the aggregate. OFSI applies an additional control limb – a listed person who controls a non-listed entity, without necessarily meeting the ownership threshold, can bring that entity within the prohibition. For a business with both US and UK exposure, the practical answer is to screen for control as well as ownership, because the UK rule is broader on that dimension.
OFSI also operates a reporting obligation that has no direct OFAC equivalent for non-financial-institution businesses. Under the UK financial sanctions regime, a relevant firm that knows or has reasonable cause to suspect that a person it deals with is a designated person, or has committed an offence, must report that knowledge to OFSI. The obligation bites on a wide range of businesses, not only banks. OFAC's reporting obligations for blocked property and rejected transactions are structured differently and run on distinct timelines. A cross-border compliance programme must accommodate both sets of obligations and cannot assume that satisfying one satisfies the other.
Record-keeping diverges as well. OFSI's enforcement guidance references a five-year retention period for records relevant to a financial-sanctions investigation. OFAC's record-keeping expectations for blocked and rejected transactions operate on their own terms. A programme designed for one regime must be checked against the other's retention requirements before it is adopted firm-wide.
Where does EU sanctions compliance diverge from the US and UK models?
EU sanctions compliance operates through the Council regulations that implement each sanctions programme, supplemented by national competent authority guidance across the Member States. There is no single EU-wide document equivalent to OFAC's compliance framework publication. That absence creates a structuring challenge: a business with EU exposure must map the requirements of the applicable Council regulation and assess them against the guidance issued by the relevant national authority – which may differ between Germany, France, the Netherlands, and other Member States.
The EU ownership and control test resembles OFSI's more than it resembles OFAC's. The EU position treats an entity as caught if a listed person owns or controls it. Control can arise through means other than shareholding – board composition, contractual arrangements, economic dependency – and the analysis is qualitative rather than mechanical. For a multinational running a single screening programme across US, UK, and EU exposure, the lowest-common-denominator approach is to apply the broader test (control as well as ownership) to all counterparties. That produces false positives, but it does not produce undetected exposure.
The EU Blocking Regulation adds a layer that has no OFAC equivalent. It is directed at certain US extraterritorial measures and creates, in principle, an obligation on EU persons not to comply with certain designated US sanctions. The practical tension between that obligation and OFAC's requirements is one that EU-based multinationals with US operations regularly bring to us. Managing the conflict requires careful jurisdictional mapping rather than a firm-wide policy choice. We regularly advise on exactly this tension.
How does secondary-sanctions risk change the compliance programme design?
Secondary sanctions – US measures that can apply to non-US persons for conduct occurring outside the United States with no US nexus beyond the sanctions programme itself – are the feature of the US regime that most consistently surprises non-US compliance teams. OFAC's authority under IEEPA extends the reach of certain programmes well beyond the traditional US-person and US-nexus triggers. A European bank that processes a payment in euros, between two non-US counterparties, can face secondary-sanctions exposure if the payment relates to a programme with secondary-sanctions provisions.
The compliance implication is structural. A programme designed only to screen for US-person obligations – transactions processed through New York, US-dollar payments, US-incorporated entities – will not capture secondary-sanctions exposure. The risk-assessment element must include a secondary-sanctions sweep: which programmes in OFAC's current list include secondary-sanctions authorities? Which of those programmes are relevant to the business's counterparty base? What is the US nexus analysis for each product line?
OFSI and the EU do not maintain secondary-sanctions mechanisms of equivalent scope. That asymmetry means that the OFAC-driven secondary-sanctions analysis sits on top of, not inside, a UK- or EU-calibrated programme. In our cross-border practice, we see businesses that treat their EU programme as the floor and their OFAC programme as an add-on. That hierarchy is defensible if the secondary-sanctions layer is genuinely assessed; it creates exposure if it is not.
What do Asia-Pacific regimes require, and how do they interact with OFAC?
Singapore, Japan, and Australia each maintain autonomous sanctions regimes that impose their own compliance obligations, independent of OFAC. Australia's DFAT regime, administered under the relevant autonomous sanctions legislation, requires businesses with Australian operations to screen against the Australian Consolidated List and to observe the prohibitions applicable under the regulations in force. The standard expected of a compliance programme under the Australian regime reflects a risk-based approach comparable in intent to OFAC's five-element model, though the specifics of the testing and reporting obligations differ.
Singapore's MAS has issued detailed guidance on financial-sanctions compliance for financial institutions operating within its jurisdiction. Japan's METI administers export-control and sanctions obligations through the applicable national instruments. For a business with operations across the Asia-Pacific region, none of these regimes can be satisfied by a programme calibrated solely to OFAC. The cross-regime gap analysis – mapping which elements of the OFAC programme do and do not satisfy each additional regime – is a foundational step before a firm-wide compliance programme can be deployed.
The interaction with OFAC is not only additive. Where an Asia-Pacific regime is less restrictive than OFAC on a particular point, the principle that the stricter prohibition governs means that OFAC's position controls for US persons and for businesses with the relevant US nexus. Understanding the direction of divergence on each programme element is essential to designing a programme that passes scrutiny in each jurisdiction where it operates.
What are the practical risk flags in a cross-regime compliance programme?
The five risk flags that most consistently produce compliance gaps in a cross-regime programme are: reliance on a single consolidated list without regime-specific supplementation; ownership screening that stops at direct holdings without tracing the chain to the ultimate beneficial owner; a risk assessment that was completed at implementation and has not been updated to reflect changes in the counterparty base or the regulatory environment; training that is generic rather than role-specific; and testing that measures whether the programme exists rather than whether it works.
On the first: no single consolidated list captures the full scope of designations under all relevant regimes. The UN Consolidated List, OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons), OFSI's consolidated list, the EU consolidated list, and the national lists of Singapore, Japan, and Australia are related but not identical. A business that screens only against one list will not detect designations that appear on others. The practical solution is a screening system that draws from each relevant list and updates on each list's own publication cycle.
On ownership tracing: the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) applies to indirect ownership. A blocked person who holds forty-nine percent of an intermediate holding company that in turn holds sixty percent of the target does not trigger the OFAC rule at the target level. But a blocked person who holds sixty percent of the intermediate company does. Screening tools that operate at the registered-name level, without beneficial-ownership data, will miss exactly this structure. Have you tested your screening system against a layered ownership case?
The position above covers the standard programme. Your facts – the transaction types, the counterparty geographies, the product classifications, the payment routes – change the specific analysis. For an initial assessment of your programme's cross-regime coverage, contact Calder & Vance at info@caldervance.com.
When is a VSD the right response, and how does it interact with programme credit?
A VSD – voluntary self-disclosure – is a decision, not a reflex. OFAC's enforcement guidance makes clear that a timely, complete, and accurate VSD is treated as a significant mitigating factor in the penalty analysis. The benefit is meaningful. It does not eliminate exposure, and the underlying violation remains an apparent violation to be resolved. But a business that has a well-documented compliance programme, discloses voluntarily, and remediates effectively enters the enforcement process in a materially different position than one that does not.
The compliance programme's quality is directly relevant to the VSD narrative. OFAC looks at whether the violation was isolated or systemic; whether the programme had the controls to detect it; whether those controls were operating; and whether management responded appropriately on discovery. A programme that was genuinely implemented – tested, trained against, and maintained by committed senior management – supports each of those points. A nominal programme, documented but not operational, does not.
OFSI operates a comparable voluntary-disclosure route under UK financial-sanctions law, and the EU's national competent authorities maintain their own enforcement and disclosure procedures. The decision whether to disclose, and in which jurisdiction, is a legal strategy question that depends on the facts of the apparent violation, the regulatory relationships at stake, and the remediation actions already taken. We have acted for businesses navigating simultaneous US and UK enforcement exposure, and the sequencing of that process is as important as the substance of the disclosure itself.
If a transaction has already been flagged, or an internal review has surfaced a potential violation, an early review preserves options that narrow with time. Contact us at info@caldervance.com for a confidential initial assessment.
A common misconception: can one programme satisfy all regimes?
The most persistent myth we encounter at the mid-market level is that a single well-drafted compliance programme, calibrated to the most demanding regime, automatically satisfies all others. The OFAC five-element model is sophisticated. It does not, however, address OFSI's control test, the EU's national-competent-authority divergences, the Australian Consolidated List cycle, or the MAS guidance applicable in Singapore. A programme that is genuinely comprehensive under OFAC may still have gaps under each of those regimes.
The converse error is equally damaging: a programme calibrated to a less demanding regime, supplemented by an untested OFAC overlay, will typically fail at the secondary-sanctions risk-assessment stage and at the ownership-tracing depth that OFAC expects. Neither a single-regime programme nor a programme assembled by layering overlays without testing them against the actual transaction population is an adequate answer for a cross-border business.
What is required is a structured gap analysis: take the OFAC five-element model as the primary architecture; map each element against the requirements of each additional regime; identify the gaps; and fill them with regime-specific controls rather than generic language. That process is repeatable, documentable, and produces a programme that can be defended in each jurisdiction where it applies.
Related practices
- Compliance audit and testing – Australia – sanctions programme audit and testing under Australia's autonomous sanctions regime
- Sanctions compliance programmes: OFAC compared with OFSI – detailed comparison of US and UK compliance programme standards
- Sanctions compliance programmes under OFSI – OFSI compliance programme design and enforcement risk analysis