Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFAC

Counterparty due diligence under OFAC: the key divergences

A multinational trading house in Singapore has screened its new supplier. The screening tool returns a clean result. Three weeks later, the deal is suspended – a beneficial owner two layers up appears on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). Was the screening adequate? Was the clean result ever reliable? And how does the answer change if OFSI or the EU Council regulations also apply?

Counterparty due diligence under OFAC explained: the standard is not uniform across regimes. OFAC applies a mechanical 50 percent rule (treating any entity owned 50 percent or more in aggregate by blocked persons as itself blocked), while OFSI and the EU Council regulations add a control test that can catch entities even where the ownership threshold is not met. A business that calibrates its screening to one regime and ignores the others runs material, unhedged exposure.

This analysis maps the divergences that matter most for cross-border B2B practice: the ownership and control tests, the depth of diligence expected by each authority, the point at which qualitative indicators become legally relevant, and when a compliance team should escalate to sanctions counsel.

What does counterparty due diligence under OFAC actually require?

OFAC does not publish a single checklist for counterparty due diligence. The obligation is implied from the strict-liability structure of the primary prohibitions and from OFAC's enforcement guidance, which treats the quality of a compliance programme as a central factor in calculating a civil monetary penalty. In our cross-border practice, we characterise the minimum standard in three layers.

The first layer is list screening. A business must screen the counterparty's legal name, known aliases, and principal place of business against the SDN List, the Sectoral Sanctions Identifications List, and any other programme-specific consolidated list that OFAC maintains. Screening tools vary significantly in their update frequency and alias coverage. A tool updated weekly is not the same as one updated daily – and OFAC designations take effect the moment of publication, with no grace period for clearing open transactions.

The second layer is the ownership trace. Under the 50 percent rule, any entity owned in the aggregate by blocked persons at 50 percent or more – directly or through intermediate holding companies – is itself treated as blocked, whether or not it appears on any list. This means a clean list result does not end the analysis. A compliance team must trace beneficial ownership to a level sufficient to detect whether any listed person holds a material stake. In our experience, firms relying solely on first-tier list screening miss precisely this risk.

The third layer is the qualitative assessment. OFAC's enforcement posture – confirmed in its penalty-factor guidance – places value on whether a firm has assessed red flags beyond the list: jurisdiction of incorporation, the nature of the goods or services, payment routing, and prior adverse screening results. This third layer is not discretionary for businesses operating in higher-risk sectors or with counterparties in jurisdictions subject to comprehensive programme coverage.

As of mid-2026, OFAC's guidance on compliance programme elements identifies five components: management commitment, risk assessment, internal controls, testing and auditing, and training. A counterparty due diligence procedure is an internal control. It is assessed against all five elements when a violation comes to OFAC's attention.

How does the OFAC ownership test differ from OFSI and the EU position?

The divergence between the three major Western regimes is one of the most consequential practical issues in cross-border counterparty screening, and it is frequently misunderstood even by experienced compliance teams.

Under OFAC, the test is purely mathematical. Aggregate the direct and indirect ownership interests held by blocked persons. If the total reaches 50 percent or more, the entity is blocked. Full stop. Whether the blocked person exercises management control, votes the shares, or has any operational role in the entity is irrelevant. The threshold triggers the prohibition.

OFSI and the EU Council regulations approach the question differently. Ownership at 50 percent or more by a designated person is also sufficient under both those regimes. But they go further: a non-designated entity can also be caught if a designated person exercises control over it, even where the formal ownership sits below the threshold. Control under those regimes is assessed qualitatively – it can arise from decision-making authority, board composition, veto rights, or economic dependency. A 40-percent stake held alongside board control may be enough to catch the subsidiary. A 25-percent stake in a company whose CEO is a designated person may not be – but it warrants deeper analysis.

What does this mean for a business operating across all three regimes? It means the OFSI and EU tests are broader in at least one dimension. A structure that passes the OFAC 50-percent test – because no blocked person owns 50 percent or more in aggregate – may still fall within the OFSI or EU control test if a designated person shapes the entity's decisions. A cross-border business cannot safely rely on a single regime's result. The stricter prohibition governs. We regularly advise clients to run parallel analyses for each applicable regime, not a single consolidated screen.

There is also a divergence in secondary-sanctions risk. OFAC's secondary-sanctions programmes – those that can reach non-US persons dealing in certain categories of goods, services, or finance involving designated parties – impose obligations that have no direct equivalent under OFSI or EU regulations. A non-US firm that never touches a dollar clearing account may still face OFAC secondary-sanctions exposure depending on the subject matter of the transaction. Under OFSI and the EU, the jurisdictional hook is different: the regulations reach conduct within the UK or EU, conduct by UK or EU persons anywhere, and conduct connected to goods passing through UK or EU territory. The geographic scope of the obligation is regime-specific, and a compliance procedure designed only for one set of jurisdictional hooks will leave gaps.

Where does the 50 percent rule most commonly produce unexpected results?

The aggregation mechanism of the 50 percent rule produces results that consistently surprise compliance teams encountering it for the first time. The rule does not require a single blocked person to hold a majority stake. Two blocked persons each holding 30 percent of the same target reach the threshold together. Three blocked persons each holding 20 percent do so as well. The sum of all blocked-person interests, however fragmented, is what determines the result.

Layered structures add a further dimension. If a blocked person owns 60 percent of a holding company, and that holding company owns 60 percent of an operating subsidiary, the blocked person effectively owns 36 percent of the subsidiary. That is below the 50-percent threshold for the subsidiary directly. But OFAC's guidance – and the position we advise clients to treat as authoritative – traces the ownership through the chain. The holding company is itself blocked because a blocked person owns it at 60 percent. And because a blocked entity is treated the same as a listed person for 50-percent-rule purposes, its 60-percent stake in the operating subsidiary is then a blocked-person interest. The operating subsidiary is blocked as well.

This chain reaction is the source of most of the counterparty screening surprises we encounter in practice. A four-layer corporate structure with a single listed person at the apex can block every entity in the chain, provided the ownership percentages at each level remain above 50 percent. The implication for due diligence is direct: tracing must go to the top of every relevant ownership chain, not just to the first natural person encountered.

Joint ventures present a separate aggregation issue. If two unrelated parties each hold 50 percent of a joint-venture vehicle, and one of those parties is a blocked entity, does the 50-percent rule apply? The answer depends on whether the blocked entity's interest is at or above 50 percent: at exactly 50 percent, OFAC's guidance treats the entity as blocked. A compliance team that screens only majority stakes and misses a 50-percent-exactly result is making a significant error. The threshold in the rule is "50 percent or more" – not "more than 50 percent."

What qualitative indicators should a diligence procedure capture?

List screening and ownership tracing answer the binary question – blocked or not blocked. But OFAC's enforcement-factor analysis rewards a richer investigation, and in our practice the qualitative layer is where the difference between a clean enforcement outcome and a significant penalty often lies.

Jurisdictional red flags come first. A counterparty incorporated in a jurisdiction subject to a comprehensive sanctions programme, or in a jurisdiction with a documented history of being used to obscure the ultimate ownership of assets, warrants enhanced scrutiny regardless of list results. The incorporation address is not the same as the operational address, and compliance teams should verify both.

Transaction-level indicators matter as well. Atypical payment routing – funds passing through a third-country correspondent, a mismatch between the currency of the contract and the currency of the payment, or a payment instruction that originates from a jurisdiction different from the counterparty's stated place of business – are flags that a diligence procedure should capture and escalate. These are not dispositive of a violation. But OFAC's enforcement guidance treats a firm's response to such flags as evidence of either a good compliance programme or its absence.

The nature of the goods or services is a further dimension. Dual-use items, energy commodities, financial services, and shipping services each carry their own secondary-sanctions sensitivity under one or more OFAC programmes. A counterparty diligence procedure for a commodity trader is not identical to one for a software exporter. The procedure should be calibrated to the product category.

Finally, prior screening history: if a counterparty or a connected entity has previously appeared as a potential match – even a false positive that was cleared – that prior result should be documented and its resolution retrievable. OFAC's record-keeping expectations, supported by its penalty-factor guidance, extend to the paper trail of decisions taken inside the compliance programme. A cleared result is only as credible as the analysis behind it.

How do secondary-sanctions obligations affect a non-US business's diligence duty?

Non-US businesses face a diligence question that sits at the intersection of two different legal obligations: the direct prohibitions of their home regime, and the extraterritorial reach of OFAC's secondary-sanctions programmes.

Secondary sanctions do not make OFAC's primary prohibitions apply to foreign persons. A French company is not subject to the primary prohibitions on US persons unless it uses US persons, US financial infrastructure, or US-origin goods in the transaction. What secondary sanctions do is create a separate US-law consequence – typically the risk of being designated or losing access to the US financial system – for engaging in certain defined categories of conduct with certain designated parties or in certain sectors, even entirely outside the United States.

The practical diligence implication is twofold. First, a non-US business dealing in sectors that carry secondary-sanctions exposure – energy, financial services, shipping, metals, in various programme-specific contexts – must understand whether the counterparty falls within the designated categories, not merely whether the counterparty is on the SDN List. The secondary-sanctions trigger is often broader than the primary-prohibition trigger. Second, the non-US business must assess whether its own exposure to the US financial system – dollar-clearing, US-investor relationships, US-listed affiliates – makes the secondary-sanctions consequence a live commercial risk, even if the primary prohibitions technically do not apply.

We have acted for non-US clients in multiple sectors where this secondary question was the decisive factor in whether a counterparty relationship was viable. The analysis is not binary. It involves weighing the nature of the conduct, the level of OFAC programme coverage, the depth of the firm's US-system connectivity, and the availability of any licensing relief. That combination of factors makes it a matter for counsel familiar with both the applicable primary regime and OFAC's secondary programme architecture.

Under OFSI and the EU Council regulations, there is no direct equivalent of the secondary-sanctions mechanism – but both regimes impose obligations on UK and EU persons and entities that can reach conduct outside the home territory. A UK person anywhere in the world is subject to OFSI's prohibitions. An EU person, wherever they are incorporated, falls within the scope of the relevant Council regulation if they are connected to a member state. A counterparty diligence procedure for a business with UK and EU nexus must address all three sets of obligations concurrently.

The bridge from secondary-sanctions analysis to primary compliance is short. If the counterparty presents a secondary-sanctions concern, the first step is to confirm whether any of the firm's actual dealings – payments, goods, services, access to infrastructure – go through a US nexus. If they do, the analysis may shift from secondary exposure to primary prohibition. At that point, a licensing assessment becomes necessary.

The position above covers the analytical framework. Your facts – the counterparty, the goods, the regime in play, and the structure of the transaction – will shift the analysis. Contact Calder & Vance at info@caldervance.com for a structured assessment of your counterparty exposure.

What is a compliant counterparty diligence procedure in practice?

A compliant procedure under OFAC's five-element compliance standard is not a single step. It is a documented process with a defined trigger, a defined scope, a decision tree, an escalation path, and a record-keeping trail.

The trigger is the starting point. A diligence procedure should define precisely which counterparty categories activate enhanced screening: new counterparties above a defined transaction threshold, counterparties in defined higher-risk jurisdictions, counterparties in sectors with secondary-sanctions exposure, and any counterparty where a screening tool returns a potential match. The trigger definition is a management decision. It should be proportionate to the firm's risk profile, documented in policy, and approved at a level of seniority consistent with OFAC's management-commitment expectation.

The scope covers what information is collected and verified. Minimum scope for a straightforward counterparty includes: legal name, jurisdiction of incorporation, principal operating address, known trade names and aliases, and beneficial ownership to a level sufficient to apply the 50-percent rule. For higher-risk counterparties, scope extends to ownership structure documentation, details of key principals, and a review of publicly available adverse-information sources.

The decision tree maps the outputs: clean result with documented basis; potential match requiring escalation to a designated reviewer; confirmed match triggering a hold and legal escalation; inconclusive result requiring enhanced diligence before proceeding. Each branch should have a defined owner and a defined response time. A potential match that sits unresolved in a queue for two weeks is a compliance failure, regardless of whether the ultimate result is a false positive.

Escalation paths define who receives what information and when. A confirmed SDN match should reach the compliance officer and, depending on the business type, the legal team within a defined window. Where the business is a financial institution subject to OFAC's reporting obligations, the escalation path must connect to the reporting function as well. Record-keeping closes the loop: every screening result, every escalation, and every decision taken at each stage should be retained for the period required under the applicable regime's record-keeping rules.

In a recent matter, a financial-services business had a formally documented diligence procedure but had not updated its trigger definitions for over two years. A new OFAC programme had extended secondary-sanctions exposure to a sector the procedure did not cover. We reviewed the procedure, mapped the gap, and redesigned the trigger logic to capture the new programme's scope. The revised procedure was stress-tested against a sample of live counterparties before it was adopted. No violation had crystallised – the gap was closed before exposure became enforcement.

Common myths about counterparty due diligence under OFAC

One myth we encounter frequently is that a clean screening result from a reputable tool is sufficient to establish a compliance defence. It is not. A clean result is evidence that the counterparty's name and known aliases did not match a listed person on the date of the screen. It is not evidence that the counterparty is free of sanctions risk. The 50-percent-rule ownership analysis, the qualitative red-flag review, and the secondary-sanctions assessment are all analytically separate from the list screen. A firm that stops at the list result has completed one of three required layers, not all of them.

A second myth is that non-US businesses have no meaningful OFAC exposure if they do not use US persons or dollars in their transactions. Secondary-sanctions programmes complicate this significantly. The risk does not require a US nexus in every case. Certain programmes impose consequences for conduct involving designated parties, regardless of the currency or the nationality of the parties, if the conduct falls within the defined scope. The correct position is: assess the applicable programme's scope, determine whether the conduct falls within it, and then assess the US-connectivity of the business before concluding on the level of risk.

A third myth is that ownership diligence is only necessary for counterparties in high-risk jurisdictions. The 50-percent rule applies universally. A counterparty incorporated in a low-risk jurisdiction may still be owned by a blocked person through a multi-layer structure. The jurisdiction of incorporation is a risk factor, not a safe-harbour indicator. In our experience, counterparty screening failures that lead to enforcement referrals most often involve structures where the sanctioned interest is several layers removed from the obvious counterparty – not where it is directly visible.

Related practices

Frequently asked questions

Where do the regimes diverge on counterparty due diligence?
The primary divergence is between OFAC's mechanical ownership threshold and the broader ownership-plus-control test applied by OFSI and the EU Council regulations. OFAC blocks any entity owned at 50 percent or more in aggregate by blocked persons; the test is mathematical, not qualitative. OFSI and the EU add a control dimension: a designated person exercising decisive influence over an entity may cause that entity to be caught even where formal ownership sits below the threshold. A second divergence is secondary-sanctions exposure: OFAC operates secondary-sanctions programmes with extraterritorial reach that have no direct equivalent under OFSI or EU regulations, creating an additional diligence obligation for businesses with US-system connectivity.
Which regime is stricter on counterparty due diligence?
No single regime is uniformly stricter. OFAC's 50-percent rule is precise and automatic, but it does not extend to control without ownership. OFSI and the EU Council regulations catch control-based relationships that OFAC would miss. For secondary sanctions, OFAC's reach is broader in scope and geographic reach than either the UK or the EU position. The practical answer for a cross-border business is that the strictest prohibition governs each element of the analysis: apply the ownership-plus-control test for entity-level assessment, and apply OFAC's secondary-sanctions scope where US-system connectivity exists. Running parallel analyses is not optional where multiple regimes apply concurrently.
What should a cross-border business do about counterparty due diligence?
A cross-border business should first map which regimes apply to each counterparty relationship – based on the nexus of each party, the currency and routing of payments, and the nature of the goods or services involved. It should then design a diligence procedure that addresses each regime's ownership, control, and qualitative obligations. For OFAC, that means a 50-percent-rule ownership trace, a list screen with appropriate update frequency, and a red-flag review calibrated to the sector. For OFSI and the EU, the procedure must add a control assessment. Where secondary-sanctions exposure is a live risk, the firm's US-system connectivity should be formally assessed. Any procedure should be documented, tested against live counterparties, and reviewed when a new sanctions programme is introduced or materially amended. Involvement of sanctions counsel is appropriate at the design stage and whenever a potential match or an unresolved qualitative concern arises.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.