Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Counterparty due diligence under OFSI: the key divergences

A UK-based financial institution is structuring a cross-border trade-finance facility for a corporate group. The compliance team screens the named borrower. It is clean. But one of the borrower's parent companies – several layers up the ownership chain – has a director who sits on a separate listed entity's board. Does that connection matter under OFSI? Would OFAC or the EU analyse it differently? The answer shapes whether the facility can proceed, and on what terms.

Counterparty due diligence under OFSI – the Office of Financial Sanctions Implementation, which administers the UK financial-sanctions regime under the Sanctions and Anti-Money Laundering Act ("SAMLA") – turns on an ownership and control test (the combined assessment of whether a non-listed entity is owned or controlled by a designated person) that is materially broader than OFAC's mechanical 50 percent rule (the US rule treating any entity owned in aggregate 50 percent or more by blocked persons as itself blocked). As of July 2026, that divergence is the most commercially significant gap between the two regimes for cross-border businesses running counterparty screening.

This analysis maps where OFSI's ownership-and-control test diverges from OFAC and the EU, explains the practical steps a business must take to satisfy OFSI's standard, and identifies the risk flags that most frequently surface in cross-border screening.

What is the legal basis for OFSI's counterparty due-diligence obligation?

OFSI administers UK financial sanctions under SAMLA and the thematic regulations made under it. The obligations it enforces are strict-liability prohibitions: a person who deals with the funds or economic resources of a designated person commits a breach regardless of intent, unless an OFSI licence authorises the activity. That strict-liability architecture is the engine that drives counterparty due diligence – because the only reliable defence against inadvertent breach is knowing, before you transact, whether your counterparty is designated or is treated as designated through the ownership-and-control provisions.

OFSI's enforcement guidance describes a knowledge and reasonable cause to suspect standard for the purposes of its civil monetary penalty. That standard means a business that conducts no diligence at all cannot argue ignorance. In our experience, the firms that face enforcement scrutiny first are those whose screening programmes stop at the named counterparty without mapping the ownership chain. OFSI has made clear in its published guidance that de-risking (a financial institution exiting a client relationship to avoid sanctions exposure) is not the only response available; proportionate, documented diligence is also acceptable, provided it actually reaches the relevant ownership layers.

The position above covers the standard case. Your facts – the counterparty's corporate structure, the jurisdiction of incorporation, the nature of the transaction – change the analysis considerably.

For a confidential review of your OFSI due-diligence programme, contact Calder & Vance at info@caldervance.com.

How does the OFSI ownership-and-control test work in practice?

The ownership-and-control test under the UK thematic regulations captures any entity that a designated person owns or controls, whether that ownership is direct or indirect, and whether that control is exercised through legal ownership, voting rights, board composition, or other means of direction. Ownership at 50 percent or more creates a presumption of control, but control can exist at lower ownership levels if the designated person can direct the entity's affairs. That is the fundamental structural difference from OFAC.

OFAC's 50 percent rule is, by contrast, a bright line. Two listed persons each holding 30 percent of an entity together reach the threshold; their individual holdings do not matter separately. OFAC does not formally extend its analysis to control short of that 50 percent mark in the same automatic, regulatory sense – though it does consider control in its broader sanctions programmes and in the context of specific guidance. Under OFSI, a designated person holding 40 percent of an entity combined with rights of appointment over the majority of the board may well bring that entity within scope. The analysis is fact-specific and can require legal judgment, not just automated screening.

What does this mean operationally? A business screening a counterparty under OFSI standards must map:

  • direct and indirect shareholdings, traced at each layer;
  • voting rights, including contractual rights to direct the vote;
  • board composition and appointment rights;
  • veto rights over significant commercial decisions;
  • any other mechanism by which a designated person could direct the entity's conduct.

Automated screening tools are designed primarily to match names and aliases against consolidated lists. They are not designed – and cannot substitute – for this structural analysis. In our cross-border practice, we regularly advise clients whose screening programmes generate a clean result on name-matching but would fail a control-analysis review because the corporate-structure mapping has never been done.

Where does the UK diverge from OFAC and the EU?

The three major regimes – OFAC, OFSI, and the EU – share the same broad objective but apply materially different tests, and those differences have direct consequences for counterparty due diligence in cross-border transactions. Getting the wrong test wrong in the wrong jurisdiction can mean a breach in one regime while remaining technically compliant with another.

OFAC applies the 50 percent rule as a near-absolute threshold. Ownership aggregated at or above that line automatically treats the entity as blocked, regardless of how ownership is structured or who manages the business day to day. Below that line, OFAC does not automatically extend its prohibitions, although it may reach further in specific programme guidance or in more complex structures involving multiple listed persons. The rule is designed for speed of application and certainty of result.

OFSI applies the combined ownership-and-control test. Control is a separate and additional limb. A corporate structure engineered so that a designated person holds 49 percent but controls the board would be caught under OFSI. The same structure might not be automatically caught under OFAC. That divergence is not theoretical: we regularly advise on cross-border transactions where the same counterparty structure generates different screening conclusions under the two regimes.

The EU applies a broadly comparable ownership-and-control standard to OFSI. The EU's thematic regulations – made under relevant Council Regulations and Council Decisions – similarly extend prohibitions to entities owned or controlled by designated persons, and the EU's treatment of indirect ownership chains mirrors the UK position in most respects. However, there are meaningful differences in the guidance materials, the definitions applied in particular programmes, and the administrative practice of the competent authorities in individual Member States. The EU regime also introduces an additional layer of complexity where listed persons hold ownership interests across multiple jurisdictions within and outside the EU.

One cross-cutting principle applies across all three regimes: where two regimes apply to the same transaction, the stricter prohibition governs. A transaction that is permissible under OFAC because ownership sits at 48 percent may still be prohibited under OFSI or the EU if control is established through other means. A business subject to all three regimes – a common position for a UK-headquartered entity with US operations and EU clients – must satisfy the most demanding standard applicable.

If a transaction has already been flagged, or a screening result has produced a potential match, an early legal review can preserve options that narrow with time.

To discuss a specific counterparty structure, write to Calder & Vance at info@caldervance.com.

What are the procedural steps for OFSI-standard counterparty due diligence?

OFSI-standard counterparty due diligence is not a single check; it is a structured, documented process that should produce a defensible paper trail if OFSI ever reviews the transaction. The following sequence reflects the steps we apply and advise on in practice.

  1. Initial list-screening: run the named counterparty and all known principals against the UK Consolidated List, the OFAC SDN List, the EU Consolidated List, and the UN Security Council Consolidated List. Automated screening is appropriate at this stage, provided the tool is configured correctly for the relevant lists and is updated at an interval sufficient to catch recent designations.
  2. Ownership-chain mapping: obtain reliable corporate-structure information to at least two layers above the named counterparty, and deeper where the structure is complex or the jurisdiction of incorporation presents elevated risk. This step is not automated: it requires verification of the source documents, not only the counterparty's self-reported structure.
  3. Control analysis: apply the OFSI ownership-and-control test to each layer identified. The question at each layer is: could a designated person direct or materially influence the entity's affairs? Document the analysis and the conclusion, including where control is ruled out and why.
  4. Adverse-media and public-record review: supplement the list-screening with targeted adverse-media searches. OFSI designations can be preceded by a period in which a person is publicly associated with designated parties without yet appearing on a list. That association may be relevant to a knowledge-or-reasonable-cause-to-suspect analysis.
  5. Escalation and legal review: where any step produces an unresolved question – a name resemblance that cannot be ruled out, an ownership layer that cannot be verified, a control mechanism that is unclear – escalate to legal review before proceeding. The cost of an early legal opinion is proportionate to the risk of a breach.
  6. Documentation and record-keeping: retain all records supporting the diligence conclusion. OFSI's published guidance makes clear that a voluntary self-disclosure (VSD – a proactive report of a potential breach to OFSI before enforcement contact) supported by complete records of the diligence process will be treated more favourably in the penalty process than a breach with no documentary trail.
  7. Periodic refresh: due diligence at the point of onboarding is not sufficient for an ongoing relationship. Designations can occur after a relationship is established. A programme that screens only at the point of onboarding leaves the business exposed to any subsequent designation of a counterparty or its controllers.

The practical challenge is step 2. Corporate registries in some jurisdictions are incomplete, delayed, or do not capture beneficial ownership. Where verification is not achievable to the required standard, the right question is not whether to proceed but whether a licence is required or whether the transaction can be structured to reduce the exposure.

What are the most common risk flags in OFSI counterparty screening?

Cross-border counterparty screening under OFSI produces a recognisable set of risk flags. The following are the patterns we encounter most frequently in our practice. None is automatically a breach; each is a trigger for deeper analysis.

Layered structures with opaque intermediate holding companies. A counterparty incorporated in a jurisdiction with limited beneficial-ownership disclosure, sitting below several intermediate holding vehicles, is a structural red flag. The risk is not the structure itself but the inability to verify who controls it. Where verification fails, the screening conclusion is incomplete.

Shared beneficial ownership with listed entities. A counterparty that shares an ultimate beneficial owner with a separately designated entity may be caught through the control limb of the OFSI test, even if the counterparty itself is not listed. This pattern is common in conglomerate structures where a listed individual has interests in multiple operating businesses.

Directorship by a person with listed-entity connections. A director who sits on the board of a listed entity – or who has done so within the recent past – is not automatically a basis for refusing a transaction. But it is a basis for enhanced diligence on whether that person exercises control over the counterparty and whether the counterparty is thereby brought within scope.

Geographic risk factors. Counterparties registered or operating in jurisdictions subject to comprehensive or thematic sanctions programmes present elevated base risk, not because the counterparty is necessarily caught but because the density of designated persons in those environments makes the ownership-chain analysis more likely to surface a connection.

Contractual structures that would benefit a designated person. A transaction where the economic benefit – the payment, the goods, the service – would, through any chain of payment or delivery, reach a person on a relevant list engages the prohibition on making funds or economic resources available. Due diligence must address not only the counterparty but the ultimate economic beneficiary of the transaction.

Does your current screening programme address each of these patterns? If any are not covered, the programme has a gap that creates exposure under OFSI's knowledge-and-reasonable-cause standard.

How does secondary-sanctions risk affect UK businesses under OFSI?

Secondary-sanctions risk – the risk that a non-US person faces US enforcement action for dealings with certain designated parties, even where no US nexus is present – is a distinct and additional layer of exposure that OFSI counterparty due diligence alone does not address. It is a US regime question, not a UK one, but it arises in almost every significant cross-border transaction a UK business undertakes.

OFAC administers secondary-sanctions programmes under IEEPA and other authorities. These programmes can designate non-US persons for conduct that is wholly outside US jurisdiction, and the consequence is that US financial institutions and others subject to OFAC authority may be required to cut off the designated party. For a UK business, secondary designation by OFAC can effectively exclude it from the US financial system, regardless of whether it is subject to any OFSI or EU action.

The practical interaction is this: a UK business whose counterparty is clean under OFSI screening but presents secondary-sanctions risk under OFAC may face consequences if it proceeds. US dollar-denominated payments, US-person employees involved in the transaction, and goods with a US-origin or US-content element all create a nexus that may engage OFAC's jurisdiction even where the primary contracting parties are non-US. We regularly advise on transactions where the OFSI analysis is straightforward but the secondary-sanctions overlay changes the risk profile entirely.

The interaction with the EU Blocking Regulation adds a further complication for some transactions. Where that instrument applies, EU persons may face conflicting obligations – a prohibition on complying with certain secondary-sanctions measures on one side, and exposure to OFAC action on the other. Managing that tension requires legal advice that addresses both regimes simultaneously.

What is the common misconception businesses hold about OFSI due diligence?

The most persistent misconception we encounter is that running a counterparty name through a commercial screening tool constitutes satisfactory OFSI due diligence. It does not. A clean screening result is necessary but not sufficient. The OFSI ownership-and-control test requires a structural analysis that no automated list-check can produce.

A related misconception is that OFSI due diligence is only relevant for financial institutions. In fact, the financial-sanctions prohibitions under SAMLA apply to any person in the UK, or any UK person anywhere, not only to regulated firms. A manufacturer exporting goods that involve a payment term, a professional-services firm invoicing a client, a commercial landlord receiving rent – all are within scope if the counterparty is designated or controlled by a designated person. The obligation to screen, map, and document is not sector-specific.

A third misconception is that a counterparty that has passed enhanced due diligence in a previous transaction remains clean. Designations can and do occur during ongoing relationships. A programme without a refresh cycle – whether triggered by designation announcements, by the periodic review calendar, or by material changes in the counterparty's ownership structure – is a programme that will eventually miss a live exposure.

In our cross-border practice, we have acted for businesses that held entirely reasonable compliance programmes and still faced an OFSI query. The common thread was not bad faith but a gap between the screening tool's capability and the standard OFSI applies. The two are not the same thing, and the gap between them is where breaches occur.

Related practices

Frequently asked questions

Where do the regimes diverge on counterparty due diligence?
The most significant divergence is between OFAC's mechanical 50 percent ownership rule and the broader ownership-and-control test applied by OFSI and the EU. OFAC treats a non-listed entity as blocked only when designated persons own it in aggregate at or above 50 percent. OFSI and the EU extend their prohibitions to entities that a designated person controls at any ownership level, through board composition, voting rights, or other means. A structure that passes the OFAC threshold test may still be caught under OFSI or the EU on control grounds. Where two or more regimes apply, the stricter prohibition governs.
Which regime is stricter on counterparty due diligence?
No single regime is stricter in every dimension, but OFSI's and the EU's control limb is broader in scope than OFAC's ownership-only rule. OFSI can reach entities where a designated person holds a minority ownership stake combined with effective control. OFAC's bright-line threshold is simpler to apply but can leave structures involving control without majority ownership outside automatic designation. For businesses subject to multiple regimes simultaneously, the practical answer is that the most demanding applicable standard always governs – and that standard varies by fact pattern.
What should a cross-border business do about counterparty due diligence?
A cross-border business should treat OFSI counterparty due diligence as a structured, documented process: name-screen against all relevant consolidated lists; map the ownership and control chain to depth; apply the ownership-and-control test to each layer; conduct targeted adverse-media review; escalate unresolved questions to legal review before transacting; retain full records; and refresh the analysis periodically and on designation alerts. Where any layer of the chain cannot be verified to the required standard, take legal advice before proceeding. Automated screening alone does not meet OFSI's standard.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.