A multinational treasury team closes the books on a transaction that cleared screening in New York. Two weeks later, the London compliance desk flags the same counterparty under OFSI rules – and the analysis is different. Both programmes prohibit dealings with designated persons. Both trace ownership chains. But the tests, the documentation standards, the licensing routes, and the enforcement posture diverge in ways that can decide whether a transaction is lawful or not, and whether a firm can defend itself if a regulator asks questions.
Sanctions compliance programmes under OFAC and OFSI share a common architecture – screen, escalate, document, report – but differ substantially in how they define ownership and control, what they require firms to record, how they treat voluntary disclosure, and how regulators assess programme quality when an apparent violation occurs. As of mid-2026, both authorities publish framework guidance against which they measure a firm's programme; the criteria overlap but are not identical, and a programme calibrated only to one regime will carry material gaps under the other.
This analysis maps the two regimes criterion by criterion, identifies the points of divergence that create compliance risk for cross-border businesses, and sets out the practical steps a firm should take to build a programme that satisfies both authorities.
What does each authority mean by a "sanctions compliance programme"?
OFAC defines a sanctions compliance programme as the set of policies, procedures, internal controls, and training through which a firm manages its exposure to US sanctions obligations – and the authority has published detailed guidance setting out five essential components it expects to find in any effective programme. OFSI in the United Kingdom takes a similar structural approach, but its published guidance reflects the UK statutory regime under the Sanctions and Anti-Money Laundering Act and the thematic regulations made under it; the emphasis differs in tone and in some requirements.
OFAC's five-component model covers senior management commitment, risk assessment, internal controls, testing and auditing, and training. These components are not formally ranked, but OFAC consistently treats a credible risk assessment – one that maps products, customers, geographies, and transaction types to specific programme risks – as the foundation on which the other four rest. A firm that has invested in sophisticated screening technology but has not documented its risk methodology will struggle to demonstrate an effective programme if OFAC opens an inquiry.
OFSI's framework similarly requires senior-level ownership, written policies, screening procedures, and training. The UK authority places particular emphasis on reporting obligations: a firm that knows or has reasonable cause to suspect that it holds frozen funds must report to OFSI within a short statutory window. That reporting duty sits inside the compliance programme and must be operationalised – it is not satisfied by a generic "escalate to compliance" policy. In our experience, firms that map their obligations from one regime often treat this reporting duty as an afterthought when designing for the other.
How do the ownership and control tests diverge – and why does it matter?
The ownership and control tests are where the two regimes diverge most sharply, and where a single-regime programme creates the most significant gaps. OFAC applies the 50 percent rule (the rule that any entity owned 50 percent or more in the aggregate by one or more blocked persons is itself treated as blocked, regardless of whether it is listed). The test is purely mechanical: if the threshold is reached, the entity is blocked; intention and management control are irrelevant.
OFSI and the EU regimes apply an ownership and control test that goes further. Under the UK and EU approach, a non-listed entity may be caught not only when a designated person owns it at or above a defined threshold but also when a designated person can exercise control through contractual arrangements, board composition, voting rights, or de facto influence. Control without majority ownership can still trigger the prohibition. The practical consequence is significant: a counterparty that passes the OFAC ownership screen can remain caught under OFSI's control limb.
Does your screening programme test for control as well as ownership? Most off-the-shelf screening tools aggregate listed-person ownership percentages. They do not automatically surface control arrangements buried in shareholder agreements or board-composition provisions. A cross-border programme must build that gap into its escalation procedures, with a documented review of governance documents for any counterparty that triggers a partial ownership hit. We regularly advise clients who have passed an OFAC threshold check and then discovered a UK or EU control issue during pre-signing diligence.
Aggregation also requires attention under both regimes. OFAC's rule aggregates the holdings of all blocked persons in a single entity: two listed persons each with a twenty-six-percent stake jointly exceed the threshold. OFSI operates a comparable aggregation principle under its regulations. A programme that screens each beneficial owner in isolation without aggregating related holdings across the ownership chain will miss this pattern. The aggregation logic must be written into the firm's screening policy, not assumed to be handled by the screening vendor.
How do the two regimes compare on programme documentation and record-keeping?
Both OFAC and OFSI expect a firm to maintain records sufficient to demonstrate, after the event, what it did, when it did it, and on what basis. The standard period for sanctions-related record-keeping under the US regime runs to five years from the date of a transaction or the date on which blocked property was reported. UK requirements under the applicable thematic regulations impose comparable retention obligations; verify the precise period applicable to your sector and transaction type before relying on a single figure.
The form of the documentation matters as much as the retention period. OFAC expects a firm facing an apparent violation to be able to produce evidence of: the risk assessment that was in place at the time; the screening result and the disposition of any alert; the escalation and decision log; and the internal communication trail. A programme that screens and resolves alerts in a vendor system without exporting and retaining the decisioning data to the firm's own records will find it difficult to reconstruct that trail months or years later.
OFSI's documentation expectations are broadly comparable, but the UK authority also looks at the quality of the firm's reporting documentation. If a firm has identified a potential frozen-funds situation and escalated internally, the written record of that escalation – who knew, what was assessed, what was decided, and why – forms part of the compliance picture. A sparse internal file, even one that led to a correct decision, will not serve the firm well if OFSI subsequently examines whether the reporting obligation was triggered and met.
In our cross-border practice, we find that documentation standards are the most common single area where a programme that is adequate under one regime falls short under the other. The solution is not to over-document everything but to build a records-management protocol that satisfies the higher of the two standards as the baseline. Where the firm operates in multiple jurisdictions, that baseline should then be stress-tested against the requirements of each applicable regime.
Where do the voluntary-disclosure regimes differ, and what are the risks?
Both authorities offer a voluntary self-disclosure (VSD) mechanism through which a firm that identifies an apparent violation can report to the regulator and, in most cases, receive credit that reduces the penalty. The two mechanisms differ in how they are structured, what they require, and what credit they deliver.
OFAC's VSD process is well-established. A timely, accurate, and complete VSD is treated as a significant mitigating factor in the penalty calculation; OFAC guidance specifies that it can result in a substantial reduction of the base civil-monetary penalty. The disclosure must be submitted promptly after the firm discovers the apparent violation, must include a full account of the relevant facts, and must be followed by any required remedial action. A disclosure that is late, incomplete, or submitted only after OFAC has opened its own inquiry does not receive the same treatment.
OFSI's disclosure mechanism operates under a different statutory basis. The UK authority has published guidance on the factors it considers in enforcement decisions, and voluntary disclosure is listed among the mitigating factors. However, OFSI also has a monetary-penalty regime under which a designated officer can impose a civil penalty without the same graduated notice-and-comment process that characterises OFAC enforcement. The interaction between OFSI's disclosure process and its penalty regime means that timing and the completeness of the disclosure are at least as important as they are in the US context, but the procedural pathway looks different.
A cross-border firm that discovers an apparent violation touching both regimes faces a sequencing question. Disclosing to OFAC and not to OFSI, or vice versa, can create an asymmetric record. In our experience, the safest approach is to map the full jurisdictional perimeter of the apparent violation before deciding on a disclosure strategy, and to engage counsel with experience before both authorities before submitting anything. The disclosure documents themselves – the narrative, the timeline, the scope of the population of transactions – will be seen by both regulators and must be consistent.
The position above covers the standard case. Your facts – the counterparty, the goods, the transaction structure, the regimes in play, and the timeline from discovery to disclosure – change the analysis. For a confidential review of a potential breach or a pre-submission assessment of a proposed VSD, contact Calder & Vance at info@caldervance.com.
What common myths undermine cross-border programme design?
The most persistent myth we encounter is that a programme built to OFAC standards automatically satisfies OFSI. The logic is understandable: OFAC's framework guidance is detailed, widely disseminated, and treated by many compliance functions as the global gold standard. If the programme satisfies OFAC, the reasoning goes, it must be adequate elsewhere.
The control test gap described above disproves that assumption. So does the reporting-obligation gap: OFSI imposes a duty to report a reasonable suspicion of frozen-funds holdings that is structurally different from the blocked-property reporting duties under the US regime. A programme designed to the OFAC model may not have operationalised the OFSI reporting trigger at all. A firm that relies on its OFAC programme to cover its UK obligations and later faces an OFSI inquiry will find that the two programmes are assessed against different criteria.
A related myth is that the stricter prohibition always governs, so calibrating to the strictest applicable standard solves the problem. In some respects this is true – where OFAC prohibits a transaction, the fact that OFSI does not will rarely allow a US-nexus firm to proceed. But the "stricter governs" logic does not resolve documentation, reporting, or programme-architecture requirements. Those must be addressed regime by regime. A firm cannot substitute OFAC's programme documentation standard for OFSI's reporting protocol; they are different obligations.
A third myth is that secondary-sanctions risk is exclusively a US concern. It is true that OFAC administers the major secondary-sanctions programmes, under which non-US persons and entities can face consequences for certain transactions with designated persons even without a US nexus. But the UK and EU regimes also extend to conduct occurring partly outside those jurisdictions in defined circumstances, and a business that dismisses UK or EU exposure because it has no UK or EU operations may be taking a narrower view of the rules than those regimes support. The extraterritorial dimensions of each regime should be mapped explicitly in the risk assessment, not assumed away.
How should a cross-border business structure its programme to satisfy both authorities?
A programme that satisfies both OFAC and OFSI is built around the higher of the two standards for each individual requirement, not around either framework as a whole. The practical way to achieve this is to run the two framework criteria side by side and, for each element, identify which regime imposes the more demanding requirement, then design to that requirement as the floor.
For the ownership and control test, the higher standard is the UK/EU control limb: design the programme to test for control as well as ownership, and document the methodology. That will exceed OFAC's mechanical threshold requirement and satisfy OFSI's more expansive test. For the reporting obligation, design the internal escalation and reporting protocol to satisfy OFSI's statutory window; if the US reporting trigger is reached first, comply with both. For record-keeping, use the five-year baseline where APPENDIX E data supports it for the US regime, and verify the applicable UK period for your specific sector.
The risk assessment deserves particular attention. Both authorities treat a documented, current, and product-specific risk assessment as foundational to an effective programme. A single consolidated risk assessment that maps each of the firm's material products, services, customer segments, and geographies to the applicable sanctions regimes – and that is updated when the firm enters a new market, launches a product, or a major designation event occurs – will satisfy both authorities more effectively than two parallel assessments maintained in separate silos.
Training must address both regimes. Staff who handle cross-border transactions need to understand that the analysis under OFAC and under OFSI is not identical, that a clean result in one system does not terminate the inquiry, and that escalation procedures exist for a reason. A training programme that presents "sanctions" as a single unified set of rules, without flagging regime-specific differences, is a gap waiting to be exploited.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Write to Calder & Vance at info@caldervance.com for an assessment of your programme's cross-regime coverage.
What does a cross-regime gap analysis look like in practice?
In a recent matter, a financial services group with operations in New York and London had maintained its sanctions programme to OFAC's five-component standard for several years. An internal review ahead of a regulatory examination identified that the programme had not operationalised the OFSI reporting obligation as a distinct, triggered process; instead, the firm relied on a general escalation policy that did not specify the statutory window or the information required for a compliant report to the UK authority.
We assessed the programme against both frameworks, mapped the gaps, and worked with the firm's compliance team to redesign the escalation and reporting workflow. We also reviewed the ownership and control methodology used by the screening team and identified that control-related indicators were not being surfaced by the vendor's standard output; the escalation criteria were updated to require a governance-document review for any counterparty where a listed person appeared at any level of the ownership structure. The revised programme was documented and presented to the regulatory examination team with a written gap-analysis memorandum explaining the changes and their basis.
The outcome of an examination is never guaranteed. What the matter illustrates is that a programme gap of this kind is not a theoretical risk; it is the type of finding a regulator looks for when assessing whether a firm's controls are genuine or cosmetic. Identifying and closing the gap before the examination was the decision that made the difference.
Related practices
- Sanctions compliance audit and testing – independent testing of screening logic, ownership methodology, and programme documentation against applicable regime standards.
- OFSI sanctions compliance programmes: analysis – detailed analysis of the UK OFSI framework, reporting obligations, and enforcement posture for cross-border businesses.
- UN sanctions compliance programmes: analysis – how the UN Consolidated List interacts with national implementation and what it means for programme design.