A trading company operating between Australia and South-East Asia structures a new supply arrangement. Its compliance team screens the counterparty against the UN Consolidated List and the Australian autonomous sanctions list maintained by DFAT. The name returns no direct hit. But one of the counterparty's upstream shareholders sits on a designated-persons register administered by a different regime – one with extraterritorial reach into Australian financial channels. Does the deal proceed? The answer depends on which regime's ownership and control test applies, and whether the Australian regime's prohibition catches the entity at all.
Counterparty due diligence under Australia's autonomous sanctions regime requires screening against the DFAT-administered Consolidated List, assessing ownership and control under the applicable regulations, and mapping secondary-sanctions risk from the US, UK, and EU regimes that reach Australian transactions. As of July 2026, Australia's autonomous sanctions rules operate under the Autonomous Sanctions Act 2011 and associated regulations, administered by DFAT; divergences in the ownership and control test, enforcement posture, and record-keeping obligations mean that a screen adequate under one regime may be materially deficient under another.
This analysis maps the key divergences across the Australian, US, UK, and EU regimes on counterparty due diligence – the tests that apply, the risk flags practitioners encounter, and the stages at which legal counsel adds the most value.
How does Australia's autonomous sanctions regime govern counterparty screening?
Australia's autonomous sanctions regime catches any person or entity whose name appears on the DFAT Consolidated List, as well as any transaction or dealing that falls within a designated category under the applicable country-specific sanctions regulations. The governing authority is DFAT, which administers the list and issues permits under the regime. A counterparty that is directly listed is prohibited; the question that occupies most of our practice is whether a non-listed entity is caught through its relationship with a listed person.
Unlike the US regime, Australia does not publish a single threshold rule equivalent to OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked). The Australian regulations focus on whether a non-listed entity is "owned or controlled" by a designated person. That phrase is not mechanically defined by a single numerical threshold. Practitioners therefore conduct a qualitative control analysis that looks at shareholding, board composition, voting rights, and the ability to direct commercial decisions.
What does that mean operationally? It means a single-layer screen against the DFAT Consolidated List is rarely enough. A counterparty may pass the name-check, and still be caught if a designated person sits on its board or exercises effective operational control. We regularly advise clients that the ownership and control enquiry must extend at least two ownership layers up from the contracting entity, and – for higher-risk counterparties – further still.
Where do the US, UK, and EU ownership tests diverge from Australia's approach?
The most significant divergence for cross-border practitioners is between Australia's qualitative ownership-and-control standard and OFAC's mechanical 50 percent aggregate threshold. Under OFAC's guidance – issued under IEEPA and the relevant executive orders – if blocked persons own an entity at 50 percent or more in the aggregate, directly or indirectly, the entity is itself blocked regardless of who runs it. Two listed persons each holding 25 percent of the same target reach the threshold together. Intention, management, and day-to-day control are irrelevant to the calculation.
The UK's OFSI operates on a different formulation. Under SAMLA and the relevant thematic regulations, an ownership and control test applies: a non-listed entity is caught if it is owned or controlled by a designated person. "Control" under the UK rules encompasses both direct and indirect shareholding and the ability to direct or influence the entity's activities. There is no single bright-line percentage. In our experience, the absence of a numerical floor makes the UK test harder to apply in automated screening – it demands a factual analysis that pure list-matching cannot perform.
EU Council regulations use a similar ownership-or-control formulation. The EU General Court has considered, in a line of annulment actions, what "control" means for the purposes of asset freeze obligations. The practical position is that entities substantially controlled by designated persons may be caught even without majority shareholding, where the designated person can determine commercial policy. Australia's formulation sits closest to the UK and EU approach – but without the body of formal regulatory guidance and case-law that UK and EU practitioners rely on.
For a business with operations or financial flows touching both the Australian and US regimes, the stricter prohibition governs. A transaction that passes Australia's ownership-and-control test may still be prohibited under OFAC's 50 percent rule because the US numerical threshold is lower than the effective Australian control threshold in a given structure. The reverse is also possible: a deal that clears OFAC's test may still raise questions under DFAT's qualitative analysis. Neither regime can be treated as a proxy for the other.
What are the key risk flags in an Australian counterparty screen?
Several recurring risk patterns emerge in Australian-nexus counterparty diligence. Practitioners who treat the DFAT Consolidated List as a comprehensive screen – rather than as one input among several – routinely miss exposure points that regulators and correspondent banks then surface.
The first risk flag is jurisdictional concentration. Where a counterparty has significant ownership or operational ties to a jurisdiction subject to comprehensive measures under any of the major regimes – not only Australia's – the financial flows tied to that counterparty carry cross-regime risk. Australian entities that pay or receive US dollars through correspondent banking relationships are exposed to OFAC's reach regardless of whether the underlying transaction has any US nexus beyond the currency. That extraterritorial dimension is not replicated in the Australian regime itself, but it is very much present for Australian businesses.
The second risk flag is layered or nominee ownership structures. Australia's qualitative control test means that a counterparty held through a series of intermediate entities – each individually unlisted – may still be controlled by a designated person at the apex. Screening tools that check the contracting entity and its direct shareholders, and stop there, will miss this pattern consistently. Beneficial ownership data in some markets is limited; that limitation does not reduce the legal risk, it increases the diligence burden.
The third flag is dual-use goods and technology. Australia's export controls – administered under the Defence Export Controls framework, operating alongside the autonomous sanctions regime – impose separate obligations on exporters of goods and technology that appear on the relevant control lists. A counterparty that passes a sanctions screen may still be a prohibited end-user for controlled technology. These two regimes are legally distinct but practically interdependent; a compliance review that addresses only one of them is incomplete. For detailed analysis of the BIS and EAR dimension of this question, see our counterparty due diligence analysis under BIS and the EAR.
A fourth and increasingly prominent flag is virtual-asset and payment-channel exposure. Counterparties that use non-bank settlement mechanisms, or that operate as intermediaries in payment chains, may interact with sanctioned persons or jurisdictions at a layer removed from the contracting entity. The Australian sanctions regime applies to dealing in assets, and that obligation extends to transactions conducted through payment channels as much as to conventional banking.
How does Australia's enforcement posture compare with OFAC, OFSI, and the EU?
Australia's sanctions enforcement posture has historically been less aggressive in terms of publicly disclosed penalty actions than OFAC's. That observation is not a ground for reducing diligence; it reflects differences in enforcement infrastructure and the volume of international financial flows through Australian institutions, not a policy of leniency. Regulatory posture can shift quickly when a high-profile breach comes to light.
OFAC's enforcement record is extensive and well-documented. Civil penalty settlements for financial-institution breaches have reached hundreds of millions of dollars in individual cases (though specific figures from non-registry sources are not cited here). OFAC's settlement process involves a range of factors, including the quality of the offending firm's compliance programme at the time of the violation, voluntary self-disclosure, and the degree of harm caused. The programme-quality assessment gives well-designed compliance functions a concrete penalty-reduction incentive.
OFSI has increased its use of public disclosure as a regulatory tool and has the power to impose civil monetary penalties for financial-sanctions breaches. The UK regime also imposes a reporting obligation: a relevant firm that knows or suspects it holds funds belonging to a designated person must report that to OFSI within a short statutory window. Missing that reporting deadline is itself a breach, separate from the underlying breach that created the obligation.
EU enforcement is a member-state function; competent authorities across the EU operate with different levels of resource and different enforcement traditions. The principle that the stricter regime governs is therefore not only a cross-regime principle between Australia and the US – it is also a practical reality within the EU itself. For a detailed comparison of EU and SECO approaches to the same question, see our EU versus SECO counterparty due diligence analysis.
The key practical divergence in enforcement posture is the role of voluntary self-disclosure (VSD) – the practice of proactively reporting an apparent violation to the regulator before the regulator discovers it. OFAC's enforcement guidelines formally recognise VSD as a significant mitigating factor that can halve the base civil penalty calculation. OFSI's guidance also acknowledges voluntary disclosure as a mitigating consideration. DFAT's approach to VSD is less explicitly codified, but early engagement with the regulator after discovering a potential breach is – in our practice – consistently better than waiting for the regulator to make first contact.
What does a sound counterparty due diligence process look like across these regimes?
A sound counterparty due diligence process for an Australian-nexus transaction with cross-border elements has six identifiable stages, each of which addresses a distinct layer of risk.
The first stage is list-screening. The contracting entity, its known principals, and its direct owners are checked against the DFAT Consolidated List, the UN Consolidated List, OFAC's SDN List, the UK Consolidated List, and the EU consolidated list. This stage is necessary but not sufficient.
The second stage is ownership mapping. Beneficial ownership is traced through at least two layers of corporate structure, applying both the mechanical OFAC 50 percent threshold and the qualitative control test required under the Australian, UK, and EU regimes. Where corporate registry data is incomplete, additional sources – commercial databases, regulatory filings, correspondent bank information – supplement the analysis.
The third stage is sector and geography risk assessment. The counterparty's business sector and the jurisdictions in which it operates are assessed against the thematic and country-specific measures in force under each relevant regime. A counterparty in a sector subject to sectoral sanctions (energy infrastructure or financial services, for example) faces a higher risk of catching a prohibition even where no individual is listed.
The fourth stage is product and technology classification. Where goods, software, or technology are being traded, export-control classification is applied in parallel. The Australian Defence Export Controls framework, the US EAR, and the EU dual-use rules may each impose separate licence requirements or prohibited-end-user checks. These classifications are specific to the good and the destination; they must not be assumed.
The fifth stage is payment-channel analysis. The proposed settlement mechanism – the banks, the currency, the correspondent relationships – is reviewed for sanctions touchpoints. US-dollar transactions processed through US correspondent banks carry OFAC jurisdiction regardless of where the contracting parties are incorporated. That fact alone is one of the most consistently underappreciated sources of cross-regime risk we see in practice.
The sixth stage is documentation and escalation. The findings from each stage are recorded, conclusions are reached as to whether the transaction is prohibited, whether a licence or permit is required, and whether any reporting obligation has been triggered. Clear records of the diligence process are essential for any subsequent regulatory inquiry. Australia's regulations impose record-keeping requirements that align broadly with the five-year retention standard that practitioners use across regimes as a working rule; verify the current requirement before relying on it.
The position above describes the standard case. Your facts – the counterparty structure, the goods, the settlement route, and the regimes in play – will change the analysis at each stage.
For a confidential assessment of your counterparty diligence process against Australian and cross-regime requirements, contact Calder & Vance at info@caldervance.com.
A common misconception: the DFAT screen is enough for an Australian business
A persistent misconception among Australian-based compliance teams is that screening against the DFAT Consolidated List satisfies their obligations in full. It does not. The misconception arises from a reasonable starting premise – the Australian Autonomous Sanctions Act applies to Australian persons and Australian-nexus dealings, and DFAT administers the relevant list. But several extensions operate outside that frame.
First, Australian entities with US-dollar payment flows, US counterparties, or US-incorporated subsidiaries are subject to OFAC's jurisdiction. OFAC's enforcement does not require that the primary transaction be US-located; it requires only that a US nexus – a US person, a US correspondent bank, US-dollar clearing – be involved. Most Australian businesses in international trade have at least one of those nexuses.
Second, where the counterparty relationship involves a UK or EU-regulated financial institution – as it often does for trade finance – the financial institution's own compliance obligations under OFSI or the EU regime will determine whether it processes the transaction. A business whose counterparty diligence does not address those regimes may find that its transaction is refused at the banking level, regardless of Australian legal clearance.
Third, secondary-sanctions risk operates at the relationship level. An Australian business that maintains an ongoing commercial relationship with an entity subject to secondary-sanctions measures under the US regime may find its access to US financial markets restricted, even if each individual transaction is structured to avoid a primary prohibition. In our experience, secondary-sanctions risk is the most frequently underweighted factor in Australian cross-border diligence reviews.
Correcting that gap requires extending the diligence scope – not increasing the complexity of any single screen, but ensuring that the screen addresses each regime that can reach the transaction. That is precisely the function of a structured, multi-regime diligence process.
If a transaction has already been flagged by a bank or a counterparty has raised compliance concerns, early legal review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.
When should an Australian business involve sanctions counsel?
Sanctions counsel adds the most value at four identifiable points in a cross-border transaction or compliance programme.
The first is at the counterparty onboarding stage for high-risk relationships. Where the counterparty's ownership structure is opaque, where it operates in a sector subject to thematic measures, or where the transaction involves technology with potential dual-use applications, a structured legal analysis at the outset is materially cheaper than managing a compliance failure after the relationship is operational.
The second point is when a screening hit or a potential match arises and the compliance team is uncertain whether the match is a false positive, a confirmed hit, or something in the indeterminate middle. False-positive management is a skilled process. Escalating every potential match to the regulator without analysis exposes the firm to unnecessary disclosure risk; dismissing a genuine match without proper analysis is worse. An experienced practitioner can work through the ownership analysis, apply the applicable tests, and reach a reasoned conclusion that the file can support.
The third point is when a transaction is refused by a bank or counterparty on sanctions grounds and the business believes the refusal is mistaken. Banks sometimes refuse transactions on the basis of conservative internal screening policies rather than a genuine legal prohibition. Establishing whether the refusal is legally required or commercially discretionary requires an analysis of the applicable regime's prohibitions.
The fourth point is when the compliance programme itself is being reviewed or redesigned. A diligence process built to DFAT standards alone will not satisfy the requirements of a correspondent bank, a trade-finance provider, or a regulator in another jurisdiction. Aligning the programme to the five-element compliance standard that is recognised across the major regimes – governance, risk assessment, controls, testing, and training – provides a defensible baseline regardless of which regime's enforcement authority is looking. For our service on compliance audit and testing under the Australian regime, see our compliance audit and testing practice.
Related practices
- Compliance audit and testing – Australia – sanctions programme testing and gap analysis under the Australian autonomous sanctions regime
- Counterparty due diligence under BIS and the EAR – US export-control screening and entity-list analysis for cross-border transactions
- Counterparty due diligence: EU versus SECO – comparative analysis of EU and Swiss diligence requirements for cross-border businesses