Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · UN

Crypto and VASP sanctions compliance under UN: compared

A virtual-asset service provider processing a withdrawal request runs a wallet address through its screening tool. The address returns no direct match on any national list. The beneficial owner, however, appears on the UN Consolidated List (the Security Council's master list of designated individuals and entities subject to asset-freeze and travel-ban measures). The transaction proceeds. A correspondent bank flags it three days later. That sequence – a clean wallet screen followed by a missed ownership link – is the central compliance failure pattern in virtual-asset sanctions work as of mid-2026.

Crypto and VASP sanctions compliance under the UN is governed by Security Council resolutions adopted under Chapter VII of the UN Charter, which impose binding obligations on all member states. Each member state implements those obligations through its own national regime – meaning the UN list is the common floor, and OFAC, OFSI, the EU Council, and their equivalents each layer additional requirements on top. For a virtual-asset business operating across borders, the practical question is not whether the UN list applies, but how each implementing regime translates it into enforceable prohibitions, and which translation is strictest.

This analysis sets out the UN architecture, compares how the major implementing regimes treat crypto and VASP activity, maps the points of divergence, and identifies the risk flags that should trigger external counsel.

What is the UN sanctions architecture for virtual assets?

The UN Security Council imposes sanctions through resolutions binding on all member states under Chapter VII of the UN Charter. The Consolidated List is the operational output: it names designated individuals and entities subject to asset-freeze, travel-ban, and arms-embargo measures across several thematic and country-specific programmes. No member state may lawfully permit a transaction that benefits a listed person, regardless of whether its own national list has caught up.

Virtual assets were not contemplated when the original resolutions were adopted. The Security Council has since addressed that gap through subsequent resolutions dealing with the financing of terrorism and proliferation, making clear that asset-freeze obligations extend to value held in any form – including digital tokens, stablecoins, and wallet balances. The obligation is not conditional on a specific technology. It attaches to the asset.

The Consolidated List is publicly available and updated without notice. In our cross-border practice, we regularly see businesses that maintain a periodic batch-update to their screening database rather than a continuous feed. With the UN list, a batch cycle creates a window of unscreened exposure. A new designation can be effective from the moment of publication. That gap is not a technical detail; it is the mechanism by which enforcement actions begin.

The UN regime does not itself set screening methodology, record-keeping periods, or licensing procedures. Those are left to implementing jurisdictions. This is the structural feature that drives all the divergence described below. The Security Council sets the prohibition; national authorities decide how to operationalise it.

How does OFAC translate UN designations into US obligations for VASPs?

OFAC implements UN designations by adding listed persons to the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) or to one of its other programme-specific lists. Any US person, and any person subject to US jurisdiction, is then prohibited from dealing with that individual or entity in any asset class, including virtual assets.

The US regime applies the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) mechanically to virtual-asset holdings. A wallet controlled by an entity that a blocked person owns at or above that threshold is treated as blocked property, whether or not the wallet address itself appears on any list. This is the feature that defeats address-only screening. OFAC has made clear, through its published guidance on digital assets, that the obligation to block extends to the underlying economic interest regardless of how it is held.

A US-nexus VASP – one incorporated in the United States, using US correspondent services, or serving US persons – must therefore screen at two levels: the counterparty's identity, and the ownership chain behind that identity. Screening only the wallet address satisfies neither requirement. In our experience, most enforcement referrals involving VASPs trace back to a failure to apply the ownership test, not to a failure to check the list at all.

The US regime also imposes a reporting obligation when a VASP blocks or rejects a transaction on sanctions grounds. Blocked property must be reported to OFAC. Rejected transactions – those turned away without blocking – carry a separate, shorter reporting window. Both obligations apply to virtual-asset transactions as to any other form of property. The exact deadlines are set by the applicable programme regulations; verify the current position before relying on any specific figure.

The position above covers the standard case. Your facts – the counterparty, the wallet structure, the route to US jurisdiction, the programme in play – change the analysis materially.

For an assessment of your VASP's exposure under the US regime, contact Calder & Vance at info@caldervance.com.

How does the EU translate UN designations into obligations for crypto businesses?

The EU implements UN designations through Council regulations that have direct effect in all member states. Once a person is listed in the relevant Council regulation – either by direct EU designation or by implementation of a UN listing – all funds and economic resources belonging to, owned by, or controlled by that person must be frozen immediately and without prior notice.

The EU uses an ownership and control test (the EU test for whether a non-listed entity is caught through a listed person), which goes further than the mechanical US ownership threshold in one respect: control can catch entities even where the listed person's formal ownership stake is below any numerical threshold. A virtual-asset business that screens only for majority ownership will miss this. Effective EU compliance requires an assessment of whether a listed person can direct the disposal of assets, whether through formal governance rights or through informal influence over the entity's decision-making.

EU-regulated crypto asset service providers operating under the EU's market infrastructure regulation for crypto assets are subject to sanctions compliance as a licence condition. Their competent national authorities can take enforcement action for sanctions failures independently of any action by the Council. This means a VASP can face supervisory consequences even when no breach of the underlying criminal prohibition has been established.

One practical divergence from the US position is that the EU regime provides a mechanism for unfreezing funds where a listed person has a legitimate claim to payment of basic expenses or professional fees, subject to strict conditions and prior authorisation. The US regime has general licences that can achieve a similar effect in specific programme contexts, but the procedural routes differ significantly. A VASP handling an account freeze that involves a basic-needs payment must identify which regime applies and use the correct authorisation route for that regime.

How does the UK OFSI regime treat virtual-asset sanctions compliance?

OFSI (the Office of Financial Sanctions Implementation) administers UK financial sanctions under powers derived from the Sanctions and Anti-Money Laundering Act, commonly called SAMLA. UK sanctions designations implement UN obligations and add UK-autonomous designations, which may not always mirror the UN or EU lists exactly. This divergence became operationally significant after the UK began maintaining its own regime independently following the end of the Brexit transition period.

Under the UK regime, the prohibition on making funds or economic resources available to a designated person extends to virtual assets and wallet balances. OFSI has published guidance confirming that crypto assets fall within the definition of funds and economic resources for financial-sanctions purposes. A UK-regulated VASP – or any VASP with a UK nexus through its customers, its payment rails, or its corporate structure – is bound by this.

OFSI's ownership and control test follows a similar logic to the EU's: it looks at whether a designated person owns or controls the entity, and control is assessed by reference to influence as well as formal ownership. Critically, the UK and EU tests for control are not identical in every detail. In our practice, we treat them as operationally similar but legally distinct, and we advise clients not to assume that a clean UK analysis automatically satisfies EU requirements.

OFSI requires that a person who knows or suspects that they are holding funds belonging to a designated person must report that fact to OFSI. This obligation applies to virtual-asset firms as to any other regulated entity. The reporting window is short, and failure to report is itself a strict-liability criminal offence under the relevant thematic regulations. In our experience, this reporting obligation is the most frequently overlooked element of UK VASP compliance – often because the business focuses on transaction blocking and does not recognise that a wallet balance already held may trigger a separate duty.

Where do the regimes diverge on crypto and VASP sanctions compliance?

The most significant points of divergence are the ownership threshold, the control test, the licensing route, the reporting obligations, and the treatment of secondary-sanctions risk. Each of these can produce a different outcome on the same set of facts.

On the ownership threshold, the US regime uses a bright-line 50 percent rule in the aggregate. The EU and UK regimes use an ownership-and-control test that can catch entities below that threshold if the listed person exercises effective control. A VASP with a counterparty whose ownership structure is complex – multiple layers, nominee arrangements, dispersed holdings – faces a higher standard under EU and UK rules than under the US rule alone.

On the licensing route, OFAC issues specific licences for individual transactions and general licences for categories of activity. OFSI issues specific licences case by case; there is no general-licence mechanism in the UK comparable in breadth to OFAC's. The EU provides for humanitarian and other exceptions through the Council regulation itself, with competent national authorities handling individual authorisations. A VASP that holds virtual assets on behalf of a recently designated person cannot use the same authorisation route in London, New York, and Frankfurt. It must open three separate processes.

On secondary-sanctions risk, the US regime imposes exposure on non-US VASPs that facilitate transactions involving SDN-listed persons or those subject to certain OFAC programme measures, even where the transaction has no direct US nexus beyond the currency or a US correspondent. The EU and UK regimes operate territorially, although their extraterritorial reach is expanding through correspondent and settlement dependencies. A VASP that is not US-incorporated but settles in USD or uses a US-regulated custodian inherits OFAC exposure regardless of its own jurisdiction.

On record-keeping, all major regimes impose an obligation to retain transaction records and the basis for any compliance decision. The retention period varies by regime and by sector. Verify the current position in each applicable jurisdiction before designing a unified record-keeping policy.

If a transaction has already been flagged or a wallet has been blocked, an early review can preserve options that narrow with time.

For a confidential review of a potential breach or a blocked transaction, contact Calder & Vance at info@caldervance.com.

What does effective VASP sanctions screening actually require?

Effective screening for a VASP operating across multiple regimes requires a layered methodology that addresses identity, ownership, control, and transaction routing simultaneously. Address-only screening fails all of these requirements.

The minimum standard, in our view, involves four elements. First, identity verification at onboarding: the VASP must know its customer sufficiently to run a meaningful name screen, which means collecting and verifying beneficial-ownership information before account opening, not after. Second, ongoing monitoring: the UN Consolidated List and the major implementing lists are updated without advance notice. A screening architecture that depends on batch updates will have a structural gap. Continuous or near-real-time list feeds, with exception alerts, close that gap. Third, ownership and control mapping: for any counterparty that is a legal entity, the VASP must trace the ownership chain to identify whether any listed person holds 50 percent or more (the US threshold) or exercises effective control (the EU and UK test). In practice this means obtaining and verifying corporate structure documentation, not relying on self-certification. Fourth, transaction routing review: a transfer from a clean wallet to a clean beneficiary can still create exposure if the routing passes through a jurisdiction-specific programme prohibition. Knowing the origin, destination, and routing of each transaction is not optional.

In a recent matter, a payments business with a virtual-asset subsidiary had onboarding controls that satisfied the requirements of its home jurisdiction but did not capture the ownership chain to the depth required by OFAC guidance. When a counterparty was designated under a US programme, the business had incomplete documentation to demonstrate that it had applied the 50 percent rule at onboarding. We assisted in reconstructing the compliance record, advised on the voluntary self-disclosure analysis, and helped redesign the ownership-verification workflow. The matter was resolved without a public enforcement action, but the remediation process was resource-intensive and protracted.

Periodic compliance testing is a discipline distinct from day-to-day screening. Testing asks whether the screening logic actually works as designed. It involves running known positive and negative test cases through the live system, verifying that the system catches what it should and does not over-block what it should not. A well-designed programme that has never been tested is not, in fact, a well-designed programme. See our work on compliance audit and testing for how this discipline applies in cross-border contexts.

Risk flags that should trigger external counsel involvement

Not every sanctions question in a VASP requires external counsel. Some do. Identifying the threshold between internal handling and external advice is itself a risk-management question.

Certain situations have a consistent pattern in our practice. A wallet-blocking event that involves a potential UN-listed person – as opposed to a national-list-only designation – should trigger counsel involvement early, because the UN obligation is implemented differently across jurisdictions and the reporting obligations in each may be triggered simultaneously. Attempting to satisfy three reporting regimes with a single internal process usually results in at least one being missed.

A transaction that has already cleared screening and settled, and is subsequently identified as potentially sanctions-implicated, requires an immediate decision about VSD (voluntary self-disclosure to a regulator). The VSD calculus differs between OFAC, OFSI, and EU competent authorities. OFAC has published guidance indicating that a timely VSD is a significant mitigating factor in penalty calculation. OFSI's enforcement guidance similarly treats proactive disclosure favourably. The EU framework leaves more to national competent authorities, but the same principle applies. The decision about whether, when, and how to self-disclose is not one that should be made without advice – it has direct consequences for the penalty range and the public posture of the enforcement.

A regulatory enquiry or inspection by a supervisory authority, including one that does not initially frame itself as an enforcement matter, is another trigger. Regulators in major jurisdictions have increased their focus on VASP sanctions compliance specifically. An inspection that begins as a routine supervisory visit can develop into a formal investigation if the examiner identifies programme gaps. Having counsel engaged before the inspection, not after the finding, is the more effective posture.

Finally, a proposed acquisition of or by a VASP should prompt a sanctions due-diligence review of the target's compliance programme, its counterparty base, and its historical transaction data. An acquirer inherits the target's compliance history. Prior violations that were not self-disclosed do not disappear on a change of ownership. For the analytical framework applicable to escalation and reporting in cross-regime contexts, see our analysis of escalation reporting under BIS/EAR compared to EU and the companion piece on EU escalation and reporting obligations.

A common misconception corrected: "the UN list is enough to screen against"

A persistent belief among VASP compliance officers – particularly those operating primarily in non-US, non-EU jurisdictions – is that screening against the UN Consolidated List alone satisfies their obligations. It does not. The UN list is the common minimum floor. Every major implementing regime adds to it.

OFAC lists SDNs who are not on the UN Consolidated List. OFSI designates persons under UK-autonomous programmes with no UN counterpart. The EU Council has adopted autonomous designations under several thematic programmes that do not map to any UN resolution. A VASP that screens against the UN list only will miss all of these.

The converse is also important. A person can be on the UN Consolidated List and not yet reflected on every national implementation list, particularly where national authorities have administrative backlogs. The UN list is updated first; national transposition follows. During that gap, the obligation exists at the UN level and, depending on how the implementing state's legislation is drafted, may already be binding even without formal national transposition. Screening that covers only the national list and not the UN source list creates exposure during that window.

The correct approach screens against all applicable lists simultaneously: UN, OFAC SDN and consolidated, OFSI consolidated, EU consolidated, and any other national list relevant to the VASP's regulatory nexus. For a VASP with a broad international customer base, that is typically at least five lists, with different update frequencies and different data structures. Unifying that into a single, reliable screening feed is an infrastructure investment. It is also a regulatory baseline.

We regularly advise VASPs and their compliance functions on how to design and test screening infrastructure that satisfies multi-regime obligations without over-blocking legitimate transactions. The tension between completeness and proportionality is real, and managing it requires both legal and operational judgement.

Related practices

Frequently asked questions: crypto and VASP sanctions compliance under the UN

Where do the regimes diverge on crypto and VASP sanctions compliance?

The principal divergences are the ownership threshold (a mechanical 50 percent rule in the US against a broader ownership-and-control test in the EU and UK), the licensing route (OFAC general licences versus OFSI specific licences versus EU Council-regulation exceptions), the reporting obligations (which trigger differently and have different deadlines in each regime), and secondary-sanctions risk (which is distinctly broader under the US regime). A VASP operating across these regimes cannot use a single compliance procedure for all three.

Which regime is stricter on crypto and VASP sanctions compliance?

No single regime is uniformly stricter across all dimensions. The US regime imposes the broadest extraterritorial reach and the most significant secondary-sanctions risk. The EU and UK ownership-and-control tests can capture entities that fall below the US 50 percent ownership threshold. The UK strict-liability reporting offence creates criminal exposure for failure to report a suspected freeze obligation, with no intent requirement. In practice, a VASP with US dollar exposure, EU customers, and UK regulatory authorisation operates at the intersection of all three, and the strictest rule on any given question governs.

What should a cross-border business do about crypto and VASP sanctions compliance?

A cross-border VASP should first map its regulatory nexus accurately: which regimes apply based on jurisdiction of incorporation, customer location, currency, and settlement infrastructure. It should then screen against all applicable lists – UN, OFAC, OFSI, EU, and relevant national lists – with continuous or near-real-time feeds. Ownership mapping to the depth required by the strictest applicable regime should be embedded in onboarding. Periodic testing of the live screening programme confirms that the design works in practice. When a blocking event or a potential breach occurs, involve sanctions counsel before making reporting or self-disclosure decisions.

Renata Costa advises banks, payment firms, and virtual-asset businesses on sanctions screening, compliance-programme design, and financial-crime controls. Calder & Vance – International Sanctions & Export Control Counsel.

About Calder & Vance

Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.

Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.