A virtual-asset service provider operating between the United Kingdom and a third market receives a withdrawal request. The originating wallet shows a flag in its blockchain analytics tool. Is the asset holder a designated person under OFSI rules? Does the transaction require a specific licence, or does it fall within a general permission? And – critically – what happens if the same wallet triggers a match under OFAC rules as well? These questions arrive without notice, and the window for a lawful response is short.
Crypto and VASP sanctions compliance under OFSI explained: the UK's Office of Financial Sanctions Implementation requires virtual-asset businesses to freeze assets, refuse transactions, and report to OFSI when a customer or counterparty is a designated person under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic regulations. The obligation applies regardless of whether the asset is held in a custodial wallet or transacted on-chain. Parallel obligations arise under OFAC in the United States and under EU Council regulations – and those regimes do not always reach the same answer on the same set of facts.
This analysis sets out how OFSI's rules apply to virtual-asset businesses, where they diverge from the OFAC and EU positions, what the common risk points are, and when to involve specialist sanctions counsel.
What does OFSI's authority over virtual-asset businesses rest on?
OFSI's authority over VASPs derives from SAMLA and the thematic financial-sanctions regulations made under it. Those regulations prohibit – among other things – making funds or economic resources available to a designated person, or dealing with funds or economic resources belonging to a designated person. The definition of "funds" in the relevant instruments covers assets in digital form, which means that tokens, stablecoins, and other virtual assets fall within the prohibition where a designated person holds or controls them.
OFSI is the UK government body responsible for implementing and supervising financial sanctions. It issues licences, publishes guidance, conducts enforcement, and maintains the UK Consolidated List. For VASPs, OFSI's practical reach is substantial: the obligation is not limited to firms that are UK-incorporated. A business providing services to UK-resident customers, or processing transactions that clear through a UK entity, can face OFSI exposure even if its headquarters are abroad.
The Financial Conduct Authority registration requirement for UK-operating crypto businesses adds a further layer. FCA-registered VASPs are expected to have sanctions controls that are at least equivalent in effectiveness to those applied by regulated financial institutions. OFSI and the FCA do not operate identical enforcement tracks, but a compliance failure at a registered VASP is likely to attract attention from both.
In our cross-border practice, the most common misunderstanding is the assumption that OFSI's rules apply only when a pound-sterling transaction is involved. They apply whenever funds or economic resources within OFSI's reach – wherever denominated – move to or from a designated person. The denomination of the asset is not the test. The identity of the counterparty is.
How does OFSI's ownership and control test apply to crypto holdings?
Under OFSI – and under the EU Council regulations – the operative test for indirect exposure is ownership and control: an entity that is owned or controlled by a designated person is itself treated as caught by the prohibition, even if the entity is not itself listed. The UK position follows the pattern set at EU level: ownership is assessed by a majority-holding or effective-direction analysis, not by the mechanical threshold that OFAC applies.
OFAC, by contrast, applies the 50 percent rule (the rule treating entities owned 50 percent or more by blocked persons as themselves blocked). The threshold is arithmetic. OFSI and the EU look beyond arithmetic: a designated person who directs or controls the decisions of a company – even without majority equity – can bring that company within the prohibitions. For a VASP screening a corporate account or a multi-signature wallet arrangement, this matters considerably.
Consider a wallet controlled by a limited partnership. OFAC asks whether designated persons hold 50 percent or more of the partnership interests in the aggregate. OFSI asks, in addition, whether a designated person effectively controls the partnership's decisions. The same structure can produce a clear answer under OFAC and an uncertain answer under OFSI, requiring closer analysis of governance documents and beneficial-ownership records.
Blockchain analytics tools are generally calibrated to the OFAC threshold. They will flag a wallet that analytics providers associate with a designated person. They will not always surface the OFSI or EU control analysis. That gap is where VASPs face residual risk even after a clean analytics screen.
Where do the screening and due-diligence obligations sit?
OFSI does not prescribe a specific technical standard for VASP screening – but the expectation, reflected in its published guidance, is that a financial-sanctions compliance programme is effective, proportionate to the firm's risk profile, and capable of catching designations in close to real time. That expectation maps to three practical obligations: screening against the UK Consolidated List at onboarding and on an ongoing basis, investigating potential matches before transacting, and reporting to OFSI when a match is confirmed.
The UK Consolidated List is updated without a fixed schedule. A designation can be added at any time, including outside business hours. A VASP that screens only at onboarding – a common gap we identify during compliance reviews – will miss the designation of an existing customer. The firm then faces potential liability for transactions processed after the designation date, even if those transactions preceded the firm's own awareness.
OFSI's reporting obligation is firm. When a VASP knows or has reasonable cause to suspect that a customer is a designated person, or that it holds funds belonging to a designated person, it must report to OFSI without delay. "Without delay" is not defined in calendar days in OFSI's guidance, but it is treated as a short statutory window. Delay in reporting, even where no transaction is processed, can itself constitute an enforcement concern.
OFAC imposes a parallel reporting obligation: a US-nexus VASP must report blocked transactions to OFAC within 10 business days, and submit an annual report on assets held blocked. That 10-business-day deadline is a hard figure confirmed by OFAC guidance. Under OFSI, the equivalent window is expressed as "as soon as practicable" – qualitatively similar but without the precise calendar anchor. The practical standard is prompt action measured in days, not weeks.
How does the OFSI position compare with OFAC and EU rules on transaction monitoring?
The cross-regime divergences on crypto transaction monitoring are material. OFAC has issued specific guidance addressing the virtual-asset sector, including statements on the application of IEEPA-based asset-freeze obligations to DeFi protocols, unhosted wallets, and mixing services. OFSI's formal guidance on virtual assets is less granular, though the underlying statutory obligations are equally broad in their terms.
On DeFi specifically: OFAC's position – as of June 2026, verify before reliance – is that a US nexus creates OFAC exposure even for a permissionless protocol interaction, if the counterparty is a blocked person. OFSI has not issued equivalent protocol-level guidance. A UK-based firm building on DeFi infrastructure faces the OFAC position as a practical matter when US persons or assets are in scope, and faces OFSI's general prohibition analysis in parallel.
The EU Council regulations impose obligations structurally similar to OFSI's: freeze, do not make available, report. The EU Consolidated List and the UK Consolidated List have diverged since the UK's departure from the EU single sanctions framework. A person who is designated in the EU is not automatically designated in the UK, and vice versa. A VASP that maintains a single list-screening process calibrated to one regime will routinely miss designations under the other. We regularly advise VASPs that operate in both markets to run parallel list-screening with separate update feeds.
Switzerland presents a further comparison point. SECO (the State Secretariat for Economic Affairs) administers Swiss financial sanctions, which are applied through SECO ordinances. Swiss VASPs licensed by FINMA are subject to those ordinances. The Swiss list is again separate from the UK and EU lists, and update cadences differ. A VASP processing transactions involving Swiss-based counterparties should not assume that a clean UK-list result resolves the Swiss position.
The practical implication: a VASP with customers in the UK, the EU, and Switzerland faces three distinct lists, three distinct reporting obligations, and three ownership-and-control analyses that may reach different outcomes on the same set of facts. Consolidating those into a single compliance programme requires careful design rather than a lowest-common-denominator approach.
The position above covers the standard case. Your facts – the counterparty jurisdiction, the asset type, the wallet structure, the route of the transaction, and the regimes in play – change the analysis substantially. For a review of your programme's cross-regime coverage, contact Calder & Vance at info@caldervance.com.
What are the common risk flags in VASP sanctions compliance?
Six patterns generate most of the exposure we see in VASP sanctions compliance matters, across regimes and firm sizes. None is novel. All are preventable with the right programme design.
- Onboarding-only screening. Screening a customer once at onboarding and not rescreening the book when a new designation is issued. A designation added after account opening creates frozen-asset obligations from the designation date, not from the firm's next scheduled review.
- Indirect exposure through intermediaries. A transaction routed through a custodian or liquidity provider that itself has a designated-person relationship. The VASP at the end of the chain can still be "making funds available" to the designated person, depending on how the chain is structured.
- Wallet-cluster misreading. Treating a blockchain analytics flag as binary. A "low-risk" score from a blockchain analytics provider is not a legal conclusion. Where the analytics suggest any connection to a known designated-person cluster, the VASP is expected to investigate further, not to transact on the basis of a score alone.
- Control analysis gaps. Applying the OFAC 50-percent-rule threshold as the standard for OFSI and EU screening. OFSI and the EU require a control analysis that goes beyond shareholding percentages.
- Delayed reporting. Identifying a probable designated person and then conducting extended internal review before notifying OFSI. The reporting obligation triggers on reasonable suspicion, not certainty. Delay in reporting while certainty is sought is itself a risk.
- Inadequate record-keeping. OFSI expects firms to retain records of their sanctions-related decisions and investigations. "Good record-keeping is a cornerstone of demonstrating compliance" appears in OFSI's enforcement guidance. A firm that cannot show its decision trail is poorly placed in any enforcement review.
A recurring theme: the gap between what a VASP's written compliance programme says and what its operational controls actually do. Programme documentation that describes real-time screening is not the same as a system that delivers it. Periodic testing of whether controls function as documented is essential – not a nice-to-have.
The myth that blockchain traceability substitutes for sanctions due diligence
A widely held view in the virtual-asset sector holds that the public and immutable nature of distributed ledgers provides a form of inherent transparency that reduces the need for traditional sanctions due diligence. The argument runs: because transactions are traceable on-chain, a VASP can always identify where funds came from and where they went. Therefore, the argument concludes, the risk of unknowingly transacting with a designated person is lower for a VASP than for a bank.
That analysis is wrong, and it misunderstands both the technology and the legal obligation.
The traceability of a transaction on a public blockchain is not the same as the identifiability of the person behind an address. Wallet addresses are pseudonymous. A VASP cannot determine from the ledger alone whether a wallet is controlled by a designated person, a sanctioned entity, or an entity caught by the ownership-and-control analysis. Blockchain analytics can raise the probability of a match; they cannot discharge the legal screening obligation.
Moreover, OFSI's obligation is not satisfied by post-transaction tracing. The obligation is prospective: before making funds or economic resources available, the VASP must have taken reasonable steps to determine that the counterparty is not a designated person. A blockchain record that, in retrospect, shows a transaction originated from a designated-person wallet is evidence of a breach, not a defence to one.
In our experience, VASPs that have relied on blockchain analytics as a primary – rather than supplementary – compliance tool are the ones most likely to face residual exposure when designations are updated or when new address attributions are published. Analytics are a necessary input. They are not a substitute for sanctions screening against the applicable lists.
If a transaction has already been flagged, or a filing has been refused, an early review of your position can preserve options that narrow with time. Contact us at info@caldervance.com to discuss your matter on a confidential basis.
When should a VASP involve sanctions counsel?
Specialist sanctions counsel adds the most value at three points in the VASP compliance lifecycle. The earlier counsel is involved at each of those points, the more options are available.
The first is programme design and testing. Before a VASP launches – or significantly expands into a new market or asset class – a review of the sanctions compliance programme against the OFSI, OFAC, and EU standards identifies gaps that are inexpensive to close at design stage and expensive to remediate after a regulatory enquiry. Our practice includes testing screening logic, mapping ownership and control, and advising on the programme architecture required by each regime.
The second is transaction screening decisions. When a screening alert cannot be cleared through standard investigation – because the counterparty structure is opaque, because multiple regimes are in scope, or because the analytics return an ambiguous result – a legal opinion from sanctions counsel establishes a documented, defensible basis for the decision taken. That documentation matters in an enforcement context.
The third is enforcement response. OFSI has a civil monetary penalty power. The maximum penalty is the higher of £1 million or 50 percent of the value of the breach. The factors OFSI weighs in setting a penalty include the quality of the firm's compliance programme at the time of the breach, the speed and quality of its cooperation, and whether it voluntarily self-disclosed. A voluntary self-disclosure (a proactive report to OFSI of an apparent breach before the regulator becomes aware) is a significant mitigating factor in OFSI's enforcement guidance. Involving counsel before making a VSD – to scope the apparent breach, assess the disclosure's content, and manage the regulator's queries – is strongly advisable.
What if the VASP faces a concurrent OFAC investigation for the same set of transactions? The OFAC and OFSI positions do not always converge, and the disclosure strategy, the information provided to each regulator, and the licensing routes available may differ significantly. A cross-border enforcement response managed without co-ordinated legal advice across both regimes is a foreseeable source of additional exposure.
Related practices
- Sanctions compliance audit and testing – assessment of screening logic, programme gaps, and multi-regime coverage
- Crypto and VASP sanctions compliance: OFSI vs EU – side-by-side analysis of UK and EU obligations for virtual-asset businesses
- Crypto and VASP sanctions compliance under the UN regime – analysis of Security Council obligations and the Consolidated List for VASPs