Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

OFSI vs EU: Crypto and VASP sanctions compliance compared

A payment firm operating across London and Amsterdam processes stablecoin settlements for a B2B client base. Its compliance team runs transaction monitoring and screens wallet addresses against the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and the UK asset-freeze list. Then a counterparty wallet triggers a flag on the EU consolidated list but not on the OFSI register. The deal is live. The clocks are running. Which regime governs? What must the firm do, and by when?

Crypto and VASP sanctions compliance under OFSI and the EU shares a common goal – preventing designated persons from accessing value through digital-asset channels – but the two regimes differ in their legal architecture, their ownership-and-control tests, their reporting obligations, and their enforcement posture. As of July 2026, both regimes treat virtual-asset service providers as obligated persons, yet the threshold at which a non-listed entity is treated as caught, the licensing route for otherwise-prohibited activity, and the penalty basis diverge in ways that matter operationally.

This analysis maps those divergences criterion by criterion, identifies the risk flags that a cross-border VASP must manage simultaneously, and sets out when to involve sanctions counsel.

How the Legal Foundations Differ: OFSI, the EU Council, and the VASP Definition

OFSI administers UK financial sanctions under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the thematic regulations made under it; the EU's sanctions obligations for VASPs flow from successive Council Regulations implementing Council Decisions under the Common Foreign and Security Policy. Both instruments are, in terms of their core prohibition, very similar: they freeze assets and prohibit dealings with designated persons. The legal architecture, however, is not the same.

Under SAMLA and the relevant thematic UK regulations, a virtual-asset service provider (a firm providing exchange, transfer, custody, or related services in crypto-assets) is a relevant firm for the purposes of the financial-sanctions regime. OFSI's guidance makes clear that VASPs are expected to apply the same asset-freeze and dealing-prohibition obligations as a bank. The EU regime reaches the same destination through a different route: the successive Council Regulations designating individuals and entities under the various sanctions programmes each contain a general prohibition on making funds and economic resources available, and that prohibition applies to any person subject to EU jurisdiction who deals in crypto-assets as much as it does to a correspondent bank.

The practical divergence begins here. OFSI publishes its asset-freeze list as a searchable register tied to the UK's own designation decisions. After the UK left the EU, the two lists diverged. A name that appears on one may not appear on the other; a wallet that is attributable to a designated person under EU law may be associated with a person whose UK designation has not yet been made, or has been made with a different legal basis. For a VASP with EU and UK customers, running a single consolidated list is not a compliance programme – it is the starting point of one.

The Ownership-and-Control Test: Where the Regimes Pull Apart

The single most consequential technical divergence for VASPs is the test that catches non-listed entities through their connection to a designated person. Under OFSI and the EU, the applicable test is ownership and control (the test for whether a non-listed entity is caught because a designated person owns or controls it): both regimes use a combined ownership-and-control standard rather than OFAC's purely mechanical 50-percent ownership trigger.

Under OFSI, an entity that is owned or controlled by a designated person is itself caught by the asset-freeze, even if it does not appear on the OFSI register by name. Ownership means a holding of more than 50 percent of the shares or voting rights. Control is broader: it covers the ability to ensure that the entity's affairs are conducted in accordance with the designated person's wishes, whether through contractual rights, board control, or other means. A VASP that processes a transaction for a wallet attributable to a non-listed subsidiary of a designated individual has, in principle, dealt with a frozen asset.

The EU standard is substantively similar in its ownership limb but the control analysis can, in practice, reach further because of the way different Council Regulations define it and because the EU General Court has considered the scope of the control concept in annulment proceedings. In our cross-border practice, we regularly find that the two regimes reach the same entity through slightly different analytical paths, which means a VASP's legal analysis cannot simply apply one regime's test and assume the other is satisfied.

What does this mean operationally? A VASP conducting blockchain analytics (the use of on-chain data to attribute wallets to real-world entities) must map the full ownership and control chain behind a wallet cluster, not merely check whether the immediate wallet holder is listed. Two hops back in the ownership chain, a designated person's stake may aggregate past the threshold. Have you built that mapping into your transaction-monitoring logic, or does your screening stop at the first layer?

Reporting Obligations: Timelines and Substance

Both OFSI and the EU require prompt reporting when a firm identifies a match – that is, when it has reasonable grounds to suspect that a customer or a counterparty is a designated person or is owned or controlled by one. The timelines and the substance of what must be reported differ, and those differences carry real operational weight for a VASP processing high volumes of transactions.

Under OFSI's enforcement guidance, a relevant firm that identifies a potential match must report to OFSI without delay. OFSI's guidance sets an expectation that reporting happens promptly after identification, not after internal investigation is complete. Firms are also required to freeze assets immediately upon identification of a match; the report follows, but the freeze does not wait for the report to be filed. This sequencing matters: a VASP that continues to process transactions while it investigates an internal alert, before it has ruled out a genuine match, runs enforcement risk.

The EU regime imposes a reporting obligation to the competent national authority in the member state where the VASP is established or registered. Because VASPs may be passporting across multiple member states, the question of which authority receives the report – and whether the reporting obligation is triggered simultaneously in more than one jurisdiction – is not always straightforward. In our experience, VASPs with multi-member-state footprints frequently under-report because they assume that a report to the authority in their home member state satisfies all obligations. That assumption should be verified against the relevant national implementing legislation in each jurisdiction before it is relied upon.

Record-keeping obligations apply under both regimes. OFSI's regime requires relevant firms to maintain records sufficient to enable compliance to be demonstrated. The EU regime imposes comparable record-keeping requirements under the relevant Council Regulations and the national implementing measures. Both regimes' records must be retained for a significant period; verify the precise retention period applicable to your registration jurisdiction before relying on a single figure.

Licensing: Can a VASP Get Authorisation for an Otherwise-Prohibited Transaction?

A VASP occasionally faces a situation where a transaction that would otherwise be prohibited may qualify for a licence: for example, where a designated person needs access to frozen assets to pay legal fees, or where a humanitarian organisation requires access to funds held in a crypto wallet. Both OFSI and the EU provide licensing routes, but the architecture differs.

OFSI grants specific licences (case-by-case authorisations to conduct an otherwise-prohibited transaction) across a range of statutory grounds, including legal costs, maintenance payments, and extraordinary expenses. It also issues general licences (standing authorisations permitting a defined category of transaction without a separate application). A VASP relying on a general licence must satisfy the conditions of that licence precisely; general licences are not blanket permissions, and a transaction that falls outside the conditions is not authorised. OFSI has shown willingness to engage with the digital-assets sector on licensing questions, but response timelines are not guaranteed and urgent applications require early engagement.

The EU licensing regime operates through the competent national authority of the relevant member state. The grounds for a licence – legal costs, basic needs, extraordinary expenses, prior contractual obligations – are broadly comparable to those under OFSI, but the precise grounds and the procedural steps differ between member states because implementation is national. A VASP with a customer affected by both an OFSI and an EU designation needs two separate licence applications, potentially before two different authorities applying two distinct procedural rules.

The position above covers the standard licensing case. Your specific facts – the nationality of the counterparty, the asset type, the member-state registration, the transaction purpose – change the analysis materially. For an early assessment of whether a licence application is viable under OFSI or the relevant EU authority, contact Calder & Vance at info@caldervance.com.

Enforcement Posture: How OFSI and EU Authorities Treat VASP Breaches

Enforcement risk for VASPs is real under both regimes, and the two authorities have signalled clearly that the digital-assets sector is within scope of active enforcement. Understanding the enforcement posture of each authority is essential for a firm calibrating its compliance investment.

OFSI has civil enforcement powers and can impose monetary penalties for financial-sanctions breaches. Its enforcement guidance sets out an aggravation and mitigation framework: firms that self-report, cooperate, and demonstrate genuine compliance investment receive more favourable treatment than those where a breach is detected externally. A voluntary self-disclosure or VSD (a voluntary self-disclosure to the regulator before a breach is independently discovered) is a meaningful mitigating factor in the OFSI penalty calculation, though it does not guarantee a reduction and does not preclude referral to law enforcement for criminal sanctions matters. OFSI has made clear in its published guidance that financial-sanctions breaches in the digital-assets sector are treated with the same seriousness as breaches by traditional financial institutions.

The EU enforcement picture is more varied because enforcement is a matter for national competent authorities in each member state. Penalty bases, investigative powers, and prosecutorial appetite differ between member states. A VASP that processes transactions in Germany, the Netherlands, and Ireland faces three distinct enforcement environments under a single Council Regulation. In our cross-border practice, we regularly advise VASPs on mapping their enforcement exposure across multiple EU jurisdictions and calibrating their compliance programme accordingly.

If a transaction has already been flagged, or an internal alert has been escalated without resolution, an early review of the exposure and the VSD question can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss the position confidentially.

Blockchain Analytics and Transaction Screening: The Operational Gap Between the Two Regimes

The most practically consequential question for a VASP compliance team is not the legal text but the screening architecture: how do you operationalise two different ownership-and-control tests, two different designated-person lists, and two different reporting timelines in a single transaction-monitoring system?

Under OFSI, the obligation is to screen against the UK consolidated list, to apply the ownership-and-control test to non-listed entities, and to freeze and report promptly on a match. Under the EU regime, the obligation is to screen against the EU consolidated list (and the applicable programme-specific annex), to apply the EU ownership-and-control test, and to report to the competent national authority. The two lists do not mirror each other. Post-Brexit divergence means that a name may appear on one and not the other, or may be designated under different criteria.

Blockchain analytics tools can attribute wallets to real-world entities, but their coverage of the full ownership and control chain varies by vendor and by asset class. A tool that identifies a wallet as associated with a listed exchange does not, on its own, answer the question of whether the transaction counterparty is an entity owned or controlled by a designated person two layers up the chain. VASPs must understand the limitations of their tooling and supplement automated screening with manual ownership analysis where the chain is complex.

The travel rule (the obligation on VASPs to pass originator and beneficiary information along with a crypto-asset transfer) introduces an additional dimension. Under the UK's implementation and the EU's equivalent regime, travel-rule data creates a record that can be used by both the VASP and the regulator to trace the beneficial owner behind a wallet. That data must be retained. It also creates an affirmative obligation: if the travel-rule data reveals information that triggers a sanctions match, the VASP cannot proceed simply because automated wallet screening did not flag the transaction. The two screening layers must be integrated.

In a recent matter, a payments firm in the e-money sector received travel-rule data indicating that the originator of a stablecoin transfer was a legal entity with a majority shareholder who appeared on the OFSI register under a thematic programme. The firm's automated wallet screening had not flagged the transaction because the wallet itself was not listed. We were instructed to scope the exposure, advise on the freeze and reporting obligation, and prepare the OFSI report. The matter turned on the control analysis – whether the listed shareholder's majority holding gave the control required under the SAMLA thematic regulations. The analysis required mapping the full ownership chain and the shareholder agreement terms. No outcome of any kind is promised in a comparable matter.

Where the Regimes Converge and Where a Stricter Standard Governs

Both OFSI and the EU impose an asset-freeze and a dealing prohibition on the same categories of person; both treat VASPs as relevant obligated entities; and both provide a licensing route for specifically defined humanitarian, legal, and extraordinary-expense categories. Where the two regimes apply simultaneously to a single VASP, the stricter prohibition governs. A transaction that is prohibited under OFSI but not yet the subject of an EU designation must not proceed on the grounds that the EU list has not been updated; the UK prohibition applies in full to UK-connected activity.

The reverse is also true. An EU designation that has not yet been mirrored in a UK designation does not release a UK-registered VASP from any obligation: the EU designation applies to the firm's EU-connected activity, while the UK register governs UK-connected activity. A VASP with dual connectivity cannot manage this exposure by applying only one list.

What a compliance programme must therefore contain, for a cross-border VASP, is a dual-list screening architecture, a unified ownership-and-control mapping process capable of applying both the OFSI and the EU tests to the same entity, integrated travel-rule and wallet-screening workflows, a jurisdiction-specific reporting matrix for each authority in scope, and a documented VSD readiness process. These are not optional enhancements; they are the minimum to demonstrate genuine compliance investment under both regimes' enforcement guidance.

Related practices

Common Myths and Risk Flags: What VASP Compliance Teams Get Wrong

The most persistent myth in VASP sanctions compliance is that a transaction is safe if the wallet address is not directly listed. It is not. The ownership-and-control test catches non-listed wallets attributable to non-listed entities that are themselves caught through a designated person's stake. Automated screening is a necessary but not sufficient condition for compliance.

A second common assumption is that a crypto-asset transaction is less traceable than a fiat transfer and therefore less likely to trigger enforcement scrutiny. Regulators and enforcement authorities have invested significantly in blockchain analytics capability. The reverse is increasingly true: on-chain transactions leave a durable record that a regulator can reconstruct long after the event.

Risk flags that should escalate to sanctions counsel include: a counterparty that declines to provide travel-rule originator information; a wallet attributed by analytics tooling to an entity domiciled in a jurisdiction subject to a comprehensive sanctions programme; a shareholder or ultimate beneficial owner identified in the course of due diligence whose name does not appear verbatim on the list but who shares identifying characteristics with a listed person; and any transaction where the stated business purpose is inconsistent with the blockchain record of prior transactions.

The interaction between the OFSI regime and the broader UK anti-money-laundering obligations adds a further layer: a suspicious-activity report triggered by AML screening does not discharge the OFSI reporting obligation, and vice versa. Both reports may be required, to different authorities, on different timelines. In our experience, firms that conflate the two obligations consistently under-report to OFSI.

For a stress-test of your screening logic, ownership-mapping process, and reporting workflows against both regimes, reach our team at info@caldervance.com.

Frequently asked questions

Where do the regimes diverge on crypto and VASP sanctions compliance?
The principal divergences are: the designated-person lists are not identical and have drifted since the UK left the EU; the control test is applied through slightly different analytical paths under OFSI and the EU Council Regulations; licensing applications must be made to separate authorities under distinct procedural rules; EU enforcement is decentralised across member-state competent authorities with variable penalty frameworks; and travel-rule implementation differs in its detailed requirements. A VASP active in both jurisdictions cannot rely on a single compliance architecture designed around one regime.
Which regime is stricter on crypto and VASP sanctions compliance?
There is no universal answer. On ownership and control, the EU standard can reach further in practice because of the way the control concept has been interpreted across different Council Regulations. On enforcement, OFSI applies a single, centralised penalty framework with published aggravation and mitigation factors, which provides more predictability than the multi-authority EU enforcement environment. Where both regimes apply, the stricter prohibition governs on each point. Businesses should assume both regimes apply unless they can positively exclude one.
What should a cross-border business do about crypto and VASP sanctions compliance?
A cross-border VASP should maintain dual-list screening covering both the OFSI register and the EU consolidated list, implement an ownership-and-control mapping process capable of applying both tests to the same entity, integrate travel-rule and wallet-screening workflows, document a jurisdiction-specific reporting matrix for each authority in scope, and prepare a VSD readiness process. Where a transaction triggers an alert under either regime, the freeze obligation applies immediately; the report follows without delay. Counsel should be involved at the first sign that an alert cannot be resolved through automated screening alone.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.