A cryptocurrency exchange operating from Toronto processes a transaction routed through a non-custodial wallet. The wallet address appears on neither Canada's SEMA-based consolidated list nor its own internal screening database. Two weeks later, a correspondent bank in New York flags the same transaction: the wallet resolves to an entity on OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The compliance team is now managing a potential violation under two distinct regimes simultaneously – with different legal bases, different reporting obligations, and different enforcement postures.
As of July 2026, crypto and VASP sanctions compliance under OFAC and Canada's sanctions regime diverges materially across four dimensions: the legal basis for digital-asset prohibitions, the treatment of unhosted wallets and blockchain-native instruments, the ownership and control test (the test for whether a non-listed entity is caught through a listed person), and the licensing and reporting architecture. OFAC treats all property in which a blocked person has any interest as blocked, regardless of the asset class or the ledger on which it sits. Canada's regime operates through the Special Economic Measures Act ("SEMA") and associated regulations, which impose prohibitions that are functionally broad but structured differently and administered by Global Affairs Canada ("GAC") rather than a dedicated financial-sanctions office. Where the two regimes overlap, the stricter prohibition governs for any business with US nexus.
This analysis works through each dimension of divergence in sequence, identifies the risk flags that most frequently catch cross-border VASPs off-guard, and sets out the practical steps a compliance team should take before the next transaction is processed.
What is the legal basis for crypto sanctions under each regime?
OFAC's authority to prohibit dealings in digital assets derives from the same statutory instruments that govern all OFAC programmes – principally IEEPA and, for older programmes, TWEA. No separate digital-asset statute is required. OFAC's position, stated clearly in its guidance, is that virtual currency is "property" for the purposes of US sanctions law. That single classification carries the full weight of the blocking regime: receipt, transmission, conversion, or custody of a blocked person's virtual currency is a prohibited transfer of blocked property. The prohibition is strict-liability in character; intent is relevant only to penalty quantum, not to the existence of the violation.
Canada's prohibitions rest on SEMA and the regulations enacted under it for each sanctioned regime. The regulations impose asset freezes and dealings prohibitions on persons and entities listed by the Canadian government. Digital assets are not treated as a categorically separate asset class; they fall within general "property" and "funds" language in the regulations. However, the drafting of individual regulations matters. Where a regulation refers to "property, wherever situated, held by or on behalf of" a designated person, the coverage of crypto held on a non-Canadian exchange is arguable but not yet definitively resolved through enforcement. OFAC faces no such ambiguity: its SDN-List designations operate globally and the nexus rules – US persons, US-dollar clearing, US-hosted infrastructure – pull in transactions that a Canadian-only analysis might not catch.
The practical consequence is that a VASP with Canadian registration but US correspondent relationships, US-dollar settlement rails, or cloud infrastructure hosted in the United States is subject to OFAC's regime regardless of where it incorporates. In our experience, this extraterritorial dimension is the most frequently underestimated risk for Canadian crypto businesses entering US markets.
How do the ownership and control tests compare?
OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked, whether or not the entity is itself listed) is the single most operationally significant concept in crypto sanctions compliance. It applies automatically. A wallet held by an unlisted company that is majority-owned by a listed person is blocked property. The rule aggregates holdings: two SDN-listed persons each holding 30 percent of the same entity together cross the threshold. No designation of the subsidiary or wallet address is needed.
Canada's ownership-and-control analysis follows a similar logic under SEMA-based regulations but is applied by GAC, which has published less granular public guidance than OFAC on the mechanics of aggregation in layered structures. The regulations typically prohibit dealings with persons acting on behalf of, or at the direction of, designated persons – language that captures control arrangements but requires a factual determination about direction rather than a purely mathematical ownership test. For a VASP, this means that the Canadian analysis may require more legal judgment on each set of facts, whereas the OFAC analysis begins with a bright-line ownership percentage.
Where do the two regimes agree? Both treat indirect ownership through intermediate vehicles as within scope. Both require that the full ownership chain – not just the immediate counterparty – be traced. Both regimes would capture a smart contract deployed by or for the benefit of a blocked person, though the enforcement posture on decentralised finance ("DeFi") protocols differs: OFAC has publicly addressed DeFi and autonomous protocols; GAC's public guidance on this point is less developed.
The position above covers the standard case. Your facts – the token type, the wallet architecture, the ownership chain, the settlement rail, and which regime's nexus rules are triggered – change the analysis materially.
For a rapid assessment of your cross-regime exposure, contact Calder & Vance at info@caldervance.com.
What are the screening obligations for VASPs under each regime?
OFAC does not prescribe the precise technology a VASP must use to screen, but its enforcement guidance and the Compliance Commitments framework make clear that screening must be risk-based, current, and applied both at onboarding and at the point of each transaction. OFAC expects VASPs to screen wallet addresses, not only named counterparties. A transaction-screening programme that checks customer names against the SDN List but does not screen the destination or source wallet address is, in OFAC's view, materially deficient. The SDN List is updated in real time; a screening programme that refreshes only daily creates a gap during which a newly added address could be processed.
Canada's regime imposes asset-freeze and dealings prohibitions through SEMA-based regulations but does not prescribe a specific compliance programme structure equivalent to OFAC's five-element Compliance Commitments framework. Federally regulated financial institutions in Canada are subject to FINTRAC guidance on sanctions screening as part of anti-money-laundering obligations. For crypto businesses that are registered as money services businesses with FINTRAC, sanctions screening is expected as part of a broader compliance programme. However, the prescription on wallet-address screening and on the frequency of list updates is less granular under Canadian guidance than under OFAC's published materials.
What does this mean in practice? A VASP serving both US and Canadian customers should design its screening programme to the higher OFAC standard, because that standard will govern any transaction with US nexus. Running two parallel screening programmes – one for OFAC and one for GAC – creates operational complexity without reducing risk where the programmes overlap. We regularly advise VASPs to adopt a single, unified screening architecture calibrated to the most demanding applicable regime, with a documented rationale for each design choice.
How do the licensing and authorisation routes differ?
OFAC issues two types of authorisation: a general licence (a standing authorisation that permits a defined category of transactions without a separate application) and a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction). Both instruments apply to crypto assets in exactly the same way as to fiat transactions. OFAC has issued general licences covering certain categories of personal communications, humanitarian transactions, and intellectual-property dealings in specific programmes; some of these licences explicitly extend to digital-asset platforms used for covered purposes. A VASP that believes a transaction may be covered by a general licence must assess the licence's terms carefully before relying on it – misreading a general licence is itself a potential violation.
Canada's licensing regime under SEMA allows the Minister of Foreign Affairs to issue permits authorising otherwise prohibited transactions. The Canadian permit process is less formalised in its public-facing guidance than OFAC's licensing regime. Response timelines are not formally prescribed in the same way, and the volume of publicly documented crypto-specific permits is limited. Businesses that require a Canadian permit for a crypto-related transaction involving a GAC-designated person should expect the process to require a detailed factual submission and, in many cases, engagement with GAC well before the transaction is intended to close.
One point of practical alignment: both regimes allow authorisation for certain humanitarian and legal-services transactions, though the scope of each authorisation differs. A VASP processing humanitarian payments through a crypto rail should assess the applicable general licence or permit under each relevant regime independently before proceeding. Assuming that a US general licence also satisfies the Canadian prohibition – or vice versa – is a common and potentially costly error.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact us at info@caldervance.com to discuss the position.
What are the reporting and record-keeping obligations?
OFAC requires a US person who holds blocked property – including blocked virtual currency – to report the blocked property to OFAC and to maintain the blocking until OFAC authorises otherwise. The reporting obligation arises quickly after the property is blocked; the specific window is defined in each programme's regulations, and businesses should verify the current deadline before relying on it. Record-keeping obligations require that relevant records be maintained for a defined period following the transaction or the blocking, as the case may be.
Canada's SEMA-based regulations impose a reporting obligation on persons who hold property of a designated person or who have information about such property. The obligation to report runs to the RCMP and CSIS as well as to GAC in some regulatory frameworks. For a VASP holding crypto assets that it identifies as potentially belonging to a GAC-designated person, the immediate obligation is to freeze the asset and report; the precise mechanics vary by the applicable country regulation. Failure to report is itself an offence under SEMA.
The divergence that catches businesses most frequently is the difference in reporting recipients. Under OFAC, the report goes to OFAC. Under SEMA-based frameworks, it may go to multiple Canadian agencies. A VASP that identifies a potential OFAC-reportable blocking and a potential SEMA-reportable freezing from the same transaction must manage two parallel reporting tracks. The timelines may differ; the content requirements will differ; and legal privilege over the report may differ depending on how it is prepared and to whom it is addressed. Cross-border VASPs should have pre-planned response procedures for exactly this scenario.
Where are the most significant risk flags for cross-border VASPs?
Six risk patterns recur across our practice when advising VASPs on OFAC and Canadian sanctions exposure.
First, US-dollar settlement rails. A VASP that settles in US dollars – even if it operates outside the United States – creates OFAC nexus for every transaction that touches a US correspondent bank. Many Canadian VASPs underestimate this. The US-dollar leg of a crypto-to-fiat conversion is a US-nexus transaction.
Second, unhosted-wallet screening gaps. Screening programmes that are built around named-customer screening do not catch transactions involving unhosted wallets held by or for SDN-listed persons. Blockchain analytics tools are not optional for a VASP with OFAC exposure; they are a baseline expectation.
Third, aggregation errors in ownership analysis. A counterparty that is not itself listed may still be blocked property under OFAC's 50 percent rule if the ownership chain, taken in aggregate, reaches a blocked person. Screening the entity name without tracing the ownership chain is a systematic blind spot.
Fourth, DeFi protocol interactions. A VASP that routes transactions through a decentralised protocol without screening the protocol's governance token holders, treasury addresses, or smart-contract deployers for SDN-list matches may be processing blocked property. OFAC's position on autonomous protocols has been stated publicly; the Canadian position is less developed but the underlying statutory prohibition is broad.
Fifth, token-standard ambiguity. Wrapped tokens, stablecoins, and synthetic assets can represent an economic interest in an underlying asset. If the underlying issuer or collateral pool is connected to a blocked person, the wrapped token may itself be blocked property. This analysis requires both legal and technical input.
Sixth, parallel regime gaps. A VASP that completes a SEMA-compliance review but does not separately consider OFAC nexus – or vice versa – is not compliant with both regimes. The regimes require independent analysis.
A common misconception: does compliance with one regime satisfy the other?
A persistent myth in our cross-border compliance practice is that a VASP which has passed a GAC-required compliance review, or which holds a Canadian money-services-business registration, is thereby compliant with OFAC requirements. It is not.
OFAC compliance is a US-law obligation. It applies to any business with US nexus – US persons, US-dollar transactions, US-hosted infrastructure, or US beneficial owners – regardless of whether that business is Canadian-registered or Canadian-regulated. A Canadian VASP that settles in US dollars, uses AWS or Google Cloud infrastructure hosted in a US region, or has US-citizen employees with control over compliance decisions is a US person for relevant purposes and must maintain an independent OFAC compliance programme.
The converse is also true. OFAC compliance does not satisfy Canadian sanctions obligations. The SDN List and the GAC consolidated list are not identical. Persons listed under one regime may not be listed under the other. A VASP that screens only against the SDN List may miss GAC-listed persons; a VASP that screens only against the GAC list will certainly miss SDN-listed persons not captured by Canadian designations. Both lists must be screened independently, and the screening must be updated when either list changes.
We have acted for VASPs that believed a combined screening pass gave them dual-regime coverage. It does not. The lists differ, the legal tests differ, the reporting obligations differ, and the enforcement risks differ. The only safe approach is independent compliance analysis for each applicable regime.
Related practices
- Sanctions compliance audit and testing – risk-based audit and testing of screening programmes against regulatory standards
- OFSI crypto and VASP sanctions compliance analysis – practitioner analysis of UK financial-sanctions obligations for virtual-asset businesses
- OFSI vs EU crypto sanctions compliance compared – comparative analysis of UK and EU obligations for cross-border VASPs