A multinational treasury team sits down to review its correspondent banking relationships. Three counterparties have indirect connections to entities on the UN Consolidated List. The question is not simply whether those relationships must end. It is whether the business's current compliance programme – its screening logic, its ownership mapping, its escalation protocols – is adequate to detect and manage that exposure across every jurisdiction where it operates. For a business that spans the United States, the United Kingdom, and the European Union, the answer depends on which regime's standards govern, and those standards are not the same.
As of July 2026, sanctions compliance programmes designed around the UN Consolidated List must also satisfy the implementing measures adopted by each jurisdiction that gives the List domestic legal effect. The UN Security Council sets the designation threshold and the listed names; OFAC, OFSI, the EU Council, and their counterparts in Australia, Singapore, Canada, and elsewhere translate those designations into enforceable national law with distinct screening obligations, ownership tests, reporting duties, and record-keeping requirements. A programme calibrated only to the UN List, without mapping those national layers, will fail the stricter national standard – and it is the national standard that produces civil and criminal liability.
This analysis compares how the major implementing regimes structure their sanctions compliance programme requirements, where they diverge in material ways, and what that means for a business operating across borders.
What is the UN Consolidated List and why does it not stand alone?
The UN Consolidated List is the master reference maintained by the Security Council committees for all individuals and entities subject to UN-mandated asset freezes, travel bans, and arms embargoes. Security Council resolutions adopted under Chapter VII of the UN Charter bind all member states. But the List itself creates no directly enforceable obligation on a private business. It creates an obligation on states to enact implementing measures.
That distinction matters enormously for programme design. A bank that screens only against the raw UN List – and ignores the expanded national lists – is operating to a floor, not to a ceiling. OFAC's SDN List (the list of Specially Designated Nationals and blocked persons) captures not only UN-listed parties but also individuals and entities designated under US-only authorities. The EU's asset-freeze lists and OFSI's Consolidated List of Financial Sanctions Targets each incorporate the UN designations and add autonomous designations layered on top.
In our cross-border practice, the most common programme gap is the assumption that a single-list screen covers everything. It does not. The UN List is the common denominator; the national implementing regimes are the operative standard for compliance purposes. Any programme that treats them as equivalent creates a structural blind spot that enforcement authorities have demonstrated they will find.
How the major implementing regimes structure compliance programme obligations
Each of the major jurisdictions has published expectations – in varying degrees of formality – about what an adequate sanctions compliance programme looks like. They converge on a set of core elements, but the weighting, the documentation standards, and the enforcement consequences of falling short differ significantly.
OFAC has articulated a five-element framework: management commitment; risk assessment; internal controls; testing and auditing; and training. OFAC's enforcement guidance indicates that the existence of a well-designed compliance programme is a mitigating factor in a civil penalty calculation. Importantly, programme quality affects the size of a penalty, not whether a violation occurred. The underlying prohibition is strict-liability in most OFAC programmes; the programme is therefore a mitigant, not a defence.
OFSI's approach to programme expectations is expressed through its enforcement and monetary penalties guidance. OFSI adopts a graduated penalty approach that explicitly considers whether the firm had adequate systems and controls at the time of the breach. A business with no documented compliance programme, or one that is clearly inadequate for its risk profile, can expect OFSI to treat that as an aggravating factor. The UK standard therefore integrates programme quality into the breach-severity analysis more directly than OFAC's framework does.
The EU position is reflected across the thematic sanctions regulations and through the enforcement practice of member-state competent authorities, which implement EU-level designations at the national level. There is no single EU-wide compliance programme guidance document equivalent to OFAC's published framework. Programme expectations are inferred from the structure of the obligations – asset-freeze requirements, the prohibition on making funds available, reporting duties to competent authorities – and from the enforcement records of the major member-state authorities. What this means in practice is that a programme adequate for Germany may require supplementation for a Dutch or French regulator operating under the same EU regulation but with different supervisory priorities.
Australia's autonomous sanctions regime, administered by DFAT, incorporates the UN designations and imposes its own listing criteria. DFAT has published guidance indicating that businesses should have risk-based processes proportionate to their exposure. For financial institutions and businesses operating in sectors with known sanctions-risk concentrations, this implies a documented programme with identifiable ownership of each element. The programme expectations interact with those of AUSTRAC for AML/CTF purposes, creating a layered compliance environment where gaps in one regime are often visible to supervisors in the other.
Where does the UN ownership and control test diverge across regimes?
The ownership and control question is where the regimes diverge most sharply – and where a compliance programme designed to one regime's standard can be structurally inadequate for another.
Under OFAC, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked, regardless of whether those entities are themselves listed) is mechanical and aggregate. Two blocked persons each owning 26 percent of the same entity together cross the threshold. The test is ownership; control is not independently sufficient to trigger the blocked-entity rule under OFAC's standard guidance. A programme built on the OFAC test will use a 50 percent ownership screen as its primary structural tool.
OFSI and the EU use a different test. The UK and EU concept of ownership and control (the test for whether a non-listed entity is caught through a listed person) looks at both ownership and control. A listed person who can direct the commercial decisions of an entity – even without holding a majority ownership stake – can bring that entity within the asset-freeze obligation. OFSI's guidance makes clear that a minority shareholder with structural rights over operational decisions may suffice to constitute control. The EU position, reflected in the Council's guidelines on the implementation of asset-freeze obligations, extends the analysis to effective control rather than formal ownership alone.
This divergence is not academic. A compliance programme that screens for 50 percent or more ownership and stops there will pass an OFAC-focused review but will fail an OFSI or EU-focused review if the counterparty is controlled by a listed person through board rights, veto provisions, or contractual structures. Have you tested your programme against the control standard, not just the ownership threshold?
For cross-border businesses, the practical answer is to design the programme to the strictest applicable standard. Where both OFAC and OFSI or EU obligations apply to the same relationship, the ownership-and-control analysis under the UK and EU standard should govern the programme's trigger point. The OFAC 50 percent threshold remains relevant for determining whether a blocked-entity designation applies under US law, but the programme architecture should not rely on it as the sole screen.
Reporting obligations: where the regimes impose different timelines and triggers
A sanctions compliance programme is not complete without procedures that match each jurisdiction's specific reporting obligations. The UN regime creates no direct reporting duty for private entities; the obligations flow to states. At the national level, the reporting timelines and triggers vary considerably.
OFSI requires a report where a person knows or has reasonable cause to suspect that a person with whom it is dealing is a designated person, or that it holds funds or economic resources of a designated person. This obligation applies to persons operating in the United Kingdom and, in certain contexts, to persons connected with the United Kingdom operating overseas. The reporting window is defined by statute; programmes must contain a documented escalation path that reaches the reporting obligation within that window. Failing to report is itself a criminal offence in the UK, independent of whether an asset-freeze breach has occurred.
OFAC does not impose a mandatory reporting requirement on the same model. The obligation to block assets arises on knowledge or constructive knowledge of a sanctions nexus, and blocked assets must be reported to OFAC within a short statutory window. OFAC's voluntary self-disclosure (VSD) (a VSD is a proactive report to OFAC of a potential sanctions violation before OFAC identifies it) is not mandatory but is treated as a significant mitigating factor in civil penalty calculations. A programme should therefore contain a VSD decision framework: who holds the authority to authorise a VSD, within what timeframe, and on what evidentiary standard.
Under the EU framework, competent authorities in each member state receive reports of frozen assets and suspected violations. The reporting trigger and form differ between member states, even though the underlying obligation arises from the same Council regulation. A business with operations across multiple EU member states needs programme procedures that are specific to each competent authority, not a single generic "EU" procedure.
In our experience, the reporting gap is particularly acute for mid-market businesses that have built their compliance programmes around one primary jurisdiction and not stress-tested the reporting section against the requirements of every jurisdiction where they have counterparties or assets.
Record-keeping standards across the major regimes
Record-keeping is the operational backbone of a compliance programme: without it, a business cannot demonstrate to a regulator that it took the right steps at the right time, or that a decision was justified on the information available.
OFAC's guidance requires that records relating to compliance decisions, screening results, blocked-property reports, and licence applications be maintained for a defined period. OFSI's enforcement guidance similarly places significant weight on contemporaneous documentation as evidence of adequate systems and controls. The EU thematic regulations impose record-keeping obligations directly, requiring that documentation of transactions and of the grounds for compliance decisions be retained for a period prescribed by the applicable regulation.
In practice, the longest applicable retention period should govern the programme. If a business holds licences or has reported blocked assets under OFAC, UK, and EU obligations simultaneously, it should retain the associated records for the longest of the three applicable periods, not the shortest. Programmes that delete records on the shortest available timeline create a gap that, should a later review arise, cannot be reconstructed.
For the UN List specifically, the record-keeping obligation arises through the national implementing measures. A business screening against the UN Consolidated List should document each screening run, the version of the list used, the result, and the disposition decision. If a false positive is cleared, the rationale should be recorded. If a potential match is escalated, the full escalation chain should be preserved. These records defend the programme in any subsequent enforcement review.
Risk assessment: the foundation that the major regimes share
Risk assessment is the one element on which all major implementing regimes converge – and where the UN framework's general-purpose design creates the most significant practical challenge for programme designers.
The UN Consolidated List covers programmes ranging from counter-terrorism to proliferation financing to country-specific measures. A business's exposure to each programme type depends on its sector, its counterparty geography, its product or service type, and its transaction volumes. OFAC's five-element framework places the risk assessment at the foundation: without a documented risk assessment, there is no principled basis for calibrating the depth of screening, the frequency of re-screening, or the escalation threshold.
OFSI adopts a risk-based approach under which the proportionality of a firm's programme is assessed against the risk profile of its activities. A payments business processing high volumes of cross-border transactions carries a materially higher risk profile than a domestic manufacturer with a small number of long-standing suppliers. The programme depth – the number of data points screened, the frequency of periodic re-screening, the ownership-chain depth investigated – should reflect that difference.
What a risk assessment must address in a multi-regime programme:
- Which UN programme types are relevant to the business's counterparty and geographic profile
- Which national implementing regimes apply to the business's operations and which add autonomous designations beyond the UN List
- Whether the business is subject to secondary-sanctions risk from OFAC's extraterritorial reach, even if not US-domiciled
- Whether the ownership-and-control analysis under OFSI and the EU requires a deeper ownership investigation than the OFAC 50 percent screen
- Which reporting obligations are triggered by which findings, and whether the escalation path meets each jurisdiction's timelines
A well-constructed risk assessment maps each of these dimensions to the business's actual activities and documents the design choices that follow. It is not a generic template. In our practice, we regularly advise businesses that have adopted an off-the-shelf risk matrix that has not been calibrated to their specific counterparty population – and that fails to capture the UN programmes most relevant to their sector.
Cross-border extraterritoriality and secondary-sanctions risk
For a business whose primary obligations arise under UK or EU law, the most consequential cross-regime consideration is OFAC's extraterritorial reach and the risk of secondary sanctions.
OFAC administers several sanctions programmes that can affect non-US persons – businesses incorporated outside the United States, operating outside the United States, and transacting in non-US currency. The risk arises through US-dollar clearing, US-person involvement in a transaction chain, or direct exposure to a programme with extraterritorial effect. A compliance programme designed solely around OFSI or EU obligations will not, in general, address this exposure adequately.
The practical implication for programme design is a secondary-sanctions risk layer. The programme should contain a documented assessment of whether any counterparty, goods type, or transaction route creates OFAC exposure for the business, even though the business is not US-domiciled. Where that exposure exists, the screening protocol should include the SDN List and the relevant OFAC programme lists, not only the OFSI Consolidated List or the EU's designations.
The converse challenge arises for US businesses operating in the EU or the UK. Certain EU measures – including the EU Blocking Regulation – restrict compliance with specified third-country sanctions laws in defined circumstances. A US-group entity operating through an EU subsidiary may face a regulatory tension between OFAC compliance and the EU Blocking Regulation's requirements. A compliance programme that does not map and document this tension is incomplete for a US-EU group. Have you reviewed where your programme's obligation hierarchy produces a conflict between regimes?
The position above covers the standard multi-regime case. Your specific facts – the counterparty's domicile, the goods or services type, the transaction currency, and the route – change the analysis materially.
For an assessment of your exposure under the UN framework and its national implementing measures, contact Calder & Vance at info@caldervance.com.
Common programme failures and the risk flags that signal them
Enforcement records across the major regimes reveal a consistent set of programme failures. Recognising them in advance allows a business to address them before they produce a reportable incident.
The first and most common failure is single-list screening. A programme that runs counterparties against one list – whether the UN Consolidated List, the SDN List, or the OFSI Consolidated List – and treats a clean result as a clean counterparty is operating below the minimum adequate standard. All three lists capture different populations, and all three implement the UN designations in combination with domestic-only designations. The programme must screen against all lists relevant to the jurisdictions of the business's obligations.
The second failure is static screening without re-screening. Lists change. The UN Security Council adds and removes individuals. OFAC, OFSI, and the EU Council issue new designations, sometimes with immediate effect on asset-freeze obligations. A programme that screens at onboarding but does not re-screen periodically – or that does not trigger a re-screen on a major news event or regulatory alert – will miss designations that arise after the initial screen.
The third failure is inadequate ownership mapping. A clean result on the named counterparty does not resolve the ownership question. The 50 percent rule and the OFSI and EU ownership-and-control standard require an investigation of the counterparty's ownership chain to a depth proportionate to the risk. For a low-risk, domestic counterparty with publicly available ownership information, a basic register search may suffice. For a high-risk counterparty with complex or opaque ownership structures, a deeper investigation – including ultimate beneficial owner mapping across multiple jurisdictions – is required.
The fourth failure is the absent or undocumented escalation path. When a screening tool produces a potential match, the programme must specify who reviews it, what information is gathered to resolve it, who has authority to clear it or escalate it, and within what timeframe. If the escalation path is not documented and tested, the practical experience in enforcement reviews is that the absence of documentation is treated as the absence of process.
A myth worth addressing directly: many businesses believe that using a reputable third-party screening vendor is itself sufficient to establish programme adequacy. It is not. The vendor provides a tool; the programme provides the obligation architecture – the risk assessment, the escalation logic, the ownership-investigation standard, the record-keeping, and the training. Regulator reviews in both the UK and the US have found that firms with well-known screening vendors still had inadequate programmes because the surrounding architecture was absent or untested.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com.
How Calder & Vance assists with multi-regime compliance programme design
Designing a compliance programme that satisfies the UN framework and its national implementing measures across multiple jurisdictions requires more than a checklist. It requires a structured analysis of the specific obligations that apply to the business, the risk profile that drives the programme depth, and the testing methodology that demonstrates adequacy to regulators.
We regularly advise financial institutions, multinationals, payment firms, and exporters on compliance programme design and remediation. Our approach covers:
- Mapping the applicable obligations across each jurisdiction – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, EU Council regulations, and the relevant national regimes for Australia, Singapore, Canada, the UAE, and Japan – against the business's actual operations and counterparty population
- Testing the screening logic against the ownership-and-control standard of each applicable regime, not only the OFAC 50 percent threshold
- Redesigning the programme to the five-element standard where gaps are identified, including the escalation path, the VSD decision framework, and the record-keeping architecture
- Preparing and conducting training specific to the business's risk profile and the regimes in scope
- Advising on the secondary-sanctions risk layer for non-US businesses with OFAC exposure
In a recent matter, a financial-sector business with operations in three jurisdictions discovered that its screening programme had been calibrated to one regime's ownership threshold and had not mapped the control standard of the other two regimes. We tested the screening logic, mapped the ownership-and-control exposure across the full counterparty population, and redesigned the escalation and re-screening protocols. The matter resolved without a reportable incident.
We have acted for businesses at every stage of the programme lifecycle – from initial design through regulatory review to post-enforcement remediation. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. We do not advise on circumventing or evading sanctions.
Related practices
- Sanctions compliance audit and testing (Australia) – testing and validation of compliance programmes against the Australian autonomous sanctions regime
- Counterparty due diligence under the Australian sanctions regime – ownership mapping and risk assessment for Australia-connected transactions
- Counterparty due diligence under BIS and the EAR – screening and end-use analysis for US export-control obligations