A virtual-asset business receives a transfer from a wallet that its screening system flags as potentially connected to a designated entity. The compliance team pauses the transaction. Is the wallet itself blocked? Does OFAC's 50 percent rule (the principle that entities owned 50 percent or more in the aggregate by blocked persons are themselves treated as blocked) extend to unhosted wallets? And what do equivalent regimes in the UK and EU require by way of comparison? These questions are not hypothetical. As of mid-2026, OFAC treats the virtual-asset sector as a priority enforcement area, and the divergence between the US position and those of OFSI and the EU General Court creates real operational tension for cross-border virtual-asset service providers (VASPs – businesses that exchange, transfer, or custody virtual assets on behalf of customers).
Crypto and VASP sanctions compliance under OFAC is governed by IEEPA-based authority and enforced through the OFAC regulatory regime, which applies to all US persons and to transactions with a US nexus regardless of where the VASP is incorporated. The core obligation is to block transactions involving Specially Designated Nationals (SDNs – persons and entities on OFAC's list of Specially Designated Nationals and blocked persons) and to decline dealings with any entity that SDNs own 50 percent or more in the aggregate. The UK and EU carry parallel but structurally distinct obligations, and the stricter prohibition governs whenever two regimes apply simultaneously.
This analysis sets out the OFAC regime in detail, maps it against OFSI and EU positions, identifies the compliance failures that produce enforcement referrals, and explains when specialist counsel should be engaged.
What authority does OFAC hold over VASPs, and what is its legal basis?
OFAC administers the US economic-sanctions regime using authority delegated under IEEPA and, for older programmes, the Trading with the Enemy Act. Its jurisdiction extends to all US persons – wherever they are located – and to any transaction that touches the United States, including a transaction processed through a US-dollar correspondent account, a server located in the United States, or a US-incorporated entity in the ownership chain of the VASP.
VASPs sit squarely within that perimeter. OFAC has made clear, through enforcement actions and published guidance, that it treats convertible virtual currency as property for sanctions purposes. A VASP that processes a transfer involving blocked property – whether in bitcoin, ether, or a stablecoin – is at risk of a civil penalty under the relevant thematic regulations, regardless of whether it knew the funds were blocked. OFAC's civil-enforcement standard is strict liability: the penalty can attach even where a firm acted in good faith, provided the transaction involved a prohibited counterparty or blocked property.
That strict-liability posture is the first point at which OFAC diverges from OFSI. The UK regime requires OFSI to consider whether the person had reasonable cause to suspect a breach, which introduces a mental-element consideration that OFAC explicitly does not apply to civil violations. For a VASP operating in both markets, the OFAC standard is categorically more demanding at the enforcement level.
The position above covers the standard case. Your facts – the counterparty's wallet structure, the jurisdiction of incorporation, the routing of fiat on- and off-ramps, and the regime in play – change the analysis materially. For an initial assessment of your VASP's exposure, contact Calder & Vance at info@caldervance.com.
How does the 50 percent rule apply to blockchain addresses and wallet structures?
The 50 percent rule captures any entity – including a legal-entity VASP – that blocked persons own 50 percent or more in the aggregate, directly or indirectly. Applied to the virtual-asset sector, the rule operates at the entity level; OFAC does not formally extend it to individual wallet addresses by rule, but it publishes wallet addresses associated with SDNs as identifiers on the SDN List, and transacting with a listed wallet address is prohibited.
The practical consequence is layered. First, a VASP must screen the legal entities it onboards as customers and counterparties against the SDN List and must trace ownership chains to identify aggregate ownership by blocked persons. Second, it must maintain a list of published blockchain addresses and screen incoming and outgoing transactions against those addresses. Third – and this is the layer most frequently missed in our experience – it must consider whether intermediary addresses in a transaction chain have a meaningful nexus to a listed wallet, even if the immediate sender or recipient is not listed.
The EU position is structurally similar in outcome but operationally different in mechanism. EU regulations require asset-freezing of funds and economic resources owned or controlled by designated persons, and the control limb – which is absent from OFAC's mechanical 50 percent test – can bring in entities that a blocked person directs even at sub-50 percent ownership. A VASP subject to both regimes must run both analyses: the OFAC ownership test and the EU control assessment. Where the two regimes produce a different result, the stricter prohibition governs for the relevant jurisdiction.
Does your screening system capture the published blockchain-address identifiers as well as entity names? And does it aggregate holdings across all known beneficial-owner relationships before comparing to the 50 percent threshold? In our cross-border practice, those two gaps account for a disproportionate share of the near-misses we review.
Where does OFSI's regime diverge most sharply from OFAC on crypto compliance?
OFSI administers the UK financial-sanctions regime under the Sanctions and Anti-Money Laundering Act, and its obligations for VASPs differ from OFAC's in three structurally significant ways: the ownership-and-control test, the licensing architecture, and the reporting trigger.
On ownership and control, OFSI applies a combined test. An entity is caught if a designated person owns it 50 percent or more, or if a designated person otherwise controls it – whether through formal voting rights, contractual arrangements, or de facto influence. OFAC's rule is purely arithmetic: ownership at or above the threshold triggers the block. Control, in the OFSI and EU sense, is a broader and more judgement-intensive analysis, and it can capture a VASP counterparty that would pass OFAC screening. We regularly advise VASPs that are screening for OFAC compliance and discover, on a UK-law review, that a counterparty they would have cleared is in fact caught by the OFSI control limb.
On licensing, OFSI issues specific licences (case-by-case authorisations for otherwise prohibited transactions) under purposes set out in the relevant thematic regulations. OFAC issues specific licences and general licences (standing authorisations for defined categories of transactions) under its programme regulations. The two systems are not interchangeable: a general licence issued by OFAC for a limited category of transactions with a sanctioned programme does not authorise the same transaction under OFSI, and vice versa. A VASP processing a payment that touches both regimes must check both licensing positions before relying on any authorisation.
On reporting, OFSI imposes a statutory obligation on persons who know or have reasonable cause to suspect that they hold frozen assets or have dealt with a designated person. The reporting window is short – verify the current period before relying on it – and failure to report is itself an offence independent of the underlying breach. OFAC requires the holder of blocked property to file a report within a defined period of the blocking (verify the current period before relying on it). Both obligations can apply to the same transaction if the VASP has a UK and a US nexus.
For a detailed comparison of the OFSI regime's treatment of VASPs, see our analysis at Crypto and VASP sanctions compliance under OFSI.
How does the EU's approach compare – and where does the General Court's jurisprudence matter?
The EU regime is built on Council regulations adopted under the EU Treaty, supplemented by Council Decisions, and enforced by member-state competent authorities rather than a single central body equivalent to OFAC or OFSI. For VASPs, this means that the obligation to screen, freeze, and report may be enforced by a different authority depending on where the VASP is licensed – the German BaFin, the French AMF, the Dutch DNB – each with its own enforcement posture and its own interpretive approach to the same EU text.
The EU control test, as interpreted through the practice of the EU General Court in annulment proceedings brought by designated persons, is broader than OFAC's mechanical threshold. The Court has examined what "controlled by" means in the context of complex ownership structures and has taken a functional approach: where a designated person can determine or significantly influence the decisions of an entity, that entity may fall within the freeze obligation even without a majority stake. For VASPs processing transfers involving complex wallet structures and multi-party custody arrangements, this functional control analysis requires legal input that a pure name-matching screen cannot provide.
EU dual-use export-control rules under the applicable EU regulation can also intersect with VASP activity where the VASP facilitates the transfer of funds for the acquisition of controlled goods or technology. That intersection is relatively narrow but has become more relevant as certain cryptocurrency mining hardware has been subjected to export-licensing requirements in multiple regimes. Where it arises, the VASP's compliance counsel and the exporter's export-control team need to coordinate.
A point of practical convergence: both OFAC and the EU impose civil penalties on a per-transaction basis. The aggregation of even low-value crypto transactions into an enforcement action can produce a significant aggregate civil-penalty exposure. In our experience, enforcement authorities in both jurisdictions treat the number of violating transactions as an aggravating factor, making early detection and voluntary self-disclosure – where appropriate – important considerations.
What are the highest-risk compliance failures in VASP operations?
Five failure patterns account for the majority of VASP sanctions-compliance deficiencies we encounter in programme reviews and enforcement-defence work.
First, incomplete wallet-address screening. VASPs that screen customer identities but do not maintain and refresh a live database of OFAC-published blockchain-address identifiers are exposed to every subsequent addition OFAC makes to that list. OFAC updates the SDN List without advance notice. A transaction processed the day after a wallet address is added is a prohibited transaction, regardless of when the VASP last ran its batch screen.
Second, aggregation failures in the 50 percent analysis. Where a VASP's largest institutional customer is a fund or exchange with multiple listed beneficial owners, each below 50 percent individually, the VASP may clear the entity on a line-by-line basis without aggregating the listed holdings. The entity is blocked. The VASP has processed transactions with it. This pattern has appeared in multiple enforcement contexts across regimes.
Third, reliance on a single-jurisdiction licence. A VASP that obtains a specific licence from OFAC for a defined category of transactions assumes that licence also clears the transaction under OFSI. It does not. Each regime must be assessed separately. The converse also applies.
Fourth, inadequate travel-rule implementation. The travel rule (the requirement that VASPs pass originator and beneficiary information to the next VASP in the chain) is a compliance mechanism that intersects with sanctions screening. A VASP that receives a transfer without the required originator information cannot effectively screen the originator. Gaps in travel-rule data are therefore gaps in sanctions screening, and both OFAC and OFSI treat inadequate screening as a potential basis for enhanced scrutiny.
Fifth, failure to manage unhosted-wallet risk. Transactions with unhosted wallets (wallets not held at a custodial VASP) present a screening challenge because there is no intermediary VASP to supply originator information. OFAC's published guidance on the virtual-asset sector addresses the risk that unhosted wallets are used to layer funds through otherwise-clean VASPs. A VASP with no enhanced-due-diligence procedure for high-value unhosted-wallet transactions is operating with a significant gap.
If a transaction has already been flagged, or a compliance programme has been identified as deficient in a regulatory examination, an early legal review can preserve options that narrow quickly. Contact Calder & Vance at info@caldervance.com to discuss.
What does a defensible VASP sanctions-compliance programme look like across regimes?
A defensible programme under OFAC – and one that stands up to equivalent OFSI and EU scrutiny – rests on five elements that regulators across the major regimes consistently apply when assessing voluntary self-disclosures and enforcement referrals.
The first element is written policies and procedures that are specific to the VASP's product range and customer base. A generic anti-money-laundering policy with a one-line sanctions reference does not constitute a sanctions-compliance programme. The policy must address, at a minimum: the scope of screening (entities, individuals, wallet addresses, and jurisdictions); the process for handling a potential match; the escalation route; and the procedure for blocking and reporting.
The second element is a screening system calibrated to the regime. For OFAC compliance, that means real-time or near-real-time screening of transactions against the SDN List and the published blockchain-address identifiers, with a documented process for adding newly published identifiers within a defined period of OFAC publication. For OFSI compliance, it means equivalent screening against the UK consolidated list of financial sanctions targets, with the additional control-limb assessment where the ownership picture is complex.
The third element is ownership-and-control mapping for institutional counterparties. For each VASP counterparty that is not a natural person, the compliance team should maintain a documented ownership map, updated at least annually and on any material corporate change, tracing beneficial ownership to the point at which the 50 percent threshold analysis can be definitively run.
The fourth element is a training programme that reaches the compliance team and the operational staff who handle transaction monitoring. OFAC has treated inadequate training as an aggravating factor in civil-penalty assessments. OFSI's enforcement guidance similarly identifies management failure and inadequate training as considerations in penalty determinations.
The fifth element is a testing and audit cycle. A programme that was adequate when designed may be inadequate following a significant designation event, a product change, or a change in applicable guidance. Programme testing should be conducted at least annually by a function independent of the compliance team that designed the controls. Our compliance-audit work consistently identifies gaps between the written programme and its operational implementation.
For structured compliance-programme testing calibrated to current OFAC and cross-regime requirements, see our compliance audit and testing service.
A myth corrected: "DeFi and non-custodial protocols are outside OFAC's reach"
A significant proportion of the VASPs and Web3 projects we advise initially operate on the assumption that decentralised finance protocols and non-custodial arrangements fall outside OFAC jurisdiction because there is no "person" in the chain who can be held to account. This assumption is incorrect, and OFAC has addressed it directly in its published guidance.
OFAC's jurisdiction attaches to US persons. A US person who develops, maintains, or derives economic benefit from a decentralised protocol is a US person for OFAC purposes. If that protocol facilitates transactions involving blocked persons or blocked property, the US person's involvement in the protocol creates exposure. The fact that the protocol operates through smart contracts does not eliminate the nexus.
More directly: OFAC has designated smart-contract addresses. A designated address is blocked property. Any US person – including a VASP that routes liquidity through that contract – is involved in a prohibited transaction. This is not a theoretical risk. It is an enforcement posture that OFAC has signalled clearly and that any VASP or Web3 project with US-person connections must address.
The equivalent EU position, as interpreted by the relevant competent authorities, is similarly functional: a protocol that processes transactions on behalf of EU-nexus users may trigger the EU freeze obligation regardless of whether a legal entity in the traditional sense sits behind it. The analysis is developing rapidly, and the absence of clear case law does not mean the absence of risk.
For a cross-border comparison of how OFAC's crypto-compliance obligations map against the Canadian regime, see our analysis at Crypto and VASP sanctions compliance: OFAC vs Canada.
When should a VASP engage specialist sanctions counsel?
Four situations require counsel engagement rather than in-house resolution: a potential match or blocked-property identification, a regulatory enquiry or examination, a voluntary self-disclosure assessment, and a cross-border transaction that implicates two or more regimes simultaneously.
A potential match is time-sensitive. OFAC's blocking-report obligation runs from the date of the blocking, not from the date legal advice is first sought. OFSI's reporting obligation is similarly short. A VASP that holds a suspicious transaction while it conducts an extended internal investigation risks a separate reporting failure alongside the original apparent breach. In our practice, the first call to counsel should follow within hours of a credible match, not days.
A voluntary self-disclosure – where a VASP identifies a potential violation and considers whether to report it to OFAC before the authority identifies the breach independently – is a decision that requires legal input on the facts, the applicable programme, the likely penalty calculation, and the mitigation credit that a timely disclosure typically attracts. OFAC's enforcement framework treats a timely and complete VSD as a significant mitigating factor. The decision whether to disclose, and how to frame the disclosure, is not one that should be taken without counsel.
A cross-border transaction that simultaneously implicates OFAC, OFSI, and an EU member-state competent authority requires a coordinated legal review. The licensing positions, reporting obligations, and penalty frameworks differ between regimes. A VASP that clears the transaction under one regime without checking the others is carrying residual risk it has not measured. We have acted for VASPs that had a well-designed OFAC programme and significant gaps under OFSI and the EU, and vice versa.
Related practices
- Compliance audit and testing – structured testing of sanctions screening against live regulatory requirements across regimes
- OFAC vs Canada: VASP sanctions compliance compared – how the US and Canadian crypto-sanctions obligations diverge on key compliance questions
- VASP sanctions compliance under OFSI – the UK regime's treatment of virtual-asset businesses, licensing, and enforcement posture