Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFAC

Entity List and denied-party screening: OFAC and OFSI compared

A US-headquartered technology exporter screens its distributor network before a major shipment. The checks clear. Two weeks later, a compliance officer notices that one distributor's parent company appears on the Entity List (the US Commerce Department's list of foreign entities subject to licence requirements under the Export Administration Regulations) – a list the screening tool had not been configured to catch. The shipment has already left the warehouse. That gap, between the tools a business runs and the lists those tools actually cover, is where enforcement actions are made.

Entity list and denied-party screening under OFAC and OFSI involves materially different list architectures, legal tests, and compliance obligations. OFAC administers the SDN List (the Specially Designated Nationals and Blocked Persons List) alongside a suite of other restricted-party lists; the US Commerce Bureau of Industry and Security ("BIS") separately administers the Entity List and the Denied Persons List under the Export Administration Regulations ("the EAR"). OFSI, the UK's Office of Financial Sanctions Implementation, maintains its own Consolidated List under the Sanctions and Anti-Money Laundering Act ("SAMLA"). The regimes diverge on ownership tests, the nature of the prohibitions, and the triggers for a licence obligation.

This analysis maps those divergences across the US and UK regimes, identifies the risk flags that arise when a business operates across both, and sets out when cross-border counsel should be involved.

What lists must a cross-border business actually screen against?

The answer is not a single list – it is a layered architecture that differs materially between the US and UK regimes, and a screening programme that covers only one layer will miss enforceable obligations on another.

On the US side, the relevant lists span two regulatory authorities. OFAC administers the SDN List (blocking the property of designated persons), the Sectoral Sanctions Identifications List ("SSI List", restricting defined categories of transaction with listed entities without full blocking), the Foreign Sanctions Evaders List, and the Non-SDN Menu-Based Sanctions List. BIS administers the Entity List (imposing licence requirements on exports to named foreign end-users), the Denied Persons List (persons debarred from export privileges following a final order), the Unverified List (foreign parties where BIS could not verify bona fides), and the Military End User List. These lists are legally distinct. A party may appear on the BIS Entity List without appearing on any OFAC list. An exporter that screens against OFAC lists alone – a common configuration in financial-sector compliance tools – will not catch Entity List entries at all.

On the UK side, OFSI maintains a single Consolidated List of designated persons subject to financial-sanctions prohibitions. The UK's Export Control Joint Unit ("ECJU") administers the arms embargo and strategic goods controls, with its own restricted-party considerations. There is no UK analogue to the BIS Entity List as a standalone instrument. The practical consequence is that a UK-only compliance programme, built around the OFSI Consolidated List, will not replicate the export-control dimension that the BIS lists impose.

As of April 2026, a defensible cross-border screening programme for a business with US and UK exposure must cover, at minimum: the OFAC SDN List, the OFAC SSI List, the BIS Entity List, the BIS Denied Persons List, and the OFSI Consolidated List. The UN Security Council Consolidated List underlies many of those national designations and should also be checked where the underlying transaction involves a UN-sanctioned regime. Do your screening tools cover all of these, or only the lists that were easiest to integrate at the time of implementation?

How do the OFAC and BIS list-entry standards differ?

An OFAC SDN designation blocks all property of the named person in the United States or in the possession or control of a US person; a BIS Entity List addition imposes a licence requirement on exports, re-exports, and transfers of items subject to the EAR to that party – the legal consequence and the triggering test are structurally different.

OFAC acts under IEEPA and related authorities. A designation results in the full blocking of property and a prohibition on most transactions. The SDN List entry may be based on a person's own conduct or on their ownership or control relationship with a blocked entity. OFAC's 50 percent rule (the rule treating any entity owned 50 percent or more in the aggregate by SDN-listed persons as itself blocked, even without a separate listing) operates independently of whether the downstream entity appears on any list. This is a critical point: a clean screening result for the named entity does not rule out SDN exposure if its ownership chain has not been verified.

BIS Entity List additions are made by the End-User Review Committee on the basis that the listed party poses an unacceptable risk of diversion for items subject to the EAR. The effect is a licence requirement, not an automatic prohibition. Whether a licence would be granted, and what policy applies, depends on the item, the end-use, and the listed reason for the entry. The Denied Persons List is more severe: a Denied Persons order is a final administrative penalty that forbids the named person from participating in exports subject to the EAR. Exporting to a Denied Person is an absolute prohibition; there is no licence route.

OFSI designations under SAMLA operate on a financial-sanctions basis. They prohibit dealing with the designated person's funds and economic resources and impose a requirement not to make funds available to them. The OFSI Consolidated List entry is the trigger. Unlike the BIS framework, there is no UK equivalent of the Denied Persons concept as an export-control instrument; UK export prohibitions operate through denial of licence under ECJU authority.

The practical divergence for a compliance officer is this: an OFAC SDN hit triggers an immediate freeze obligation; a BIS Entity List hit triggers a licence-or-stop obligation on covered items; an OFSI Consolidated List hit triggers a freeze and a reporting obligation. Three different lists, three different legal consequences, three different remedial actions. In our cross-border practice, we regularly advise businesses that have conflated these obligations and built a single "sanctions hit" workflow that fits none of them precisely.

Where does the ownership and control test diverge between OFAC and OFSI?

OFAC applies a mechanical 50 percent ownership threshold; OFSI and the EU apply an ownership-and-control test that can catch entities owned below that threshold where a designated person exercises control by other means.

Under OFAC's 50 percent rule, ownership is aggregated across all SDN holders. If two SDN-listed persons each hold 26 percent of a target company, the combined 52 percent triggers the rule and the target is treated as blocked. The analysis is arithmetic. Management, voting rights, and economic influence that falls short of ownership are not the primary test under OFAC's published guidance; ownership percentage is the operative figure.

OFSI's ownership and control test (the test for whether a non-listed entity is caught through a listed person's relationship with it) goes further. Under the relevant thematic regulations made under SAMLA, a non-listed entity can be treated as owned or controlled by a designated person where that person holds a majority stake, is entitled to a majority of profits, has the power to appoint or remove the majority of directors, or – critically – exercises control by other means. That final limb has no precise metric. It requires a qualitative assessment of the actual relationship. A company owned 35 percent by a designated person but managed exclusively by that person's nominees, with no independent board function, could be caught under OFSI's test in circumstances where OFAC's 50 percent rule would not apply to it.

For the EU, the position under the relevant Council Regulation is materially similar to OFSI's: ownership above 50 percent triggers the prohibition, and a control analysis can extend it below that level. EU General Court judgments have examined the control concept in annulment actions, and the jurisprudence reinforces that the test is not merely arithmetical.

The operational consequence is that a cross-border business cannot apply a single ownership-threshold filter across all three regimes. A party that clears OFAC's 50 percent test may still be caught by OFSI or EU control analysis. Screening tools that apply only a percentage filter will not surface this. Have your tools been configured to flag control relationships, or only direct ownership percentages?

What are the BIS extraterritorial considerations for non-US businesses?

The EAR reaches beyond US borders. Non-US businesses that re-export or transfer items that originated in the United States, contain a threshold percentage of US-controlled content, or are produced using certain US technology may be subject to the EAR's licence requirements – including the obligation to screen against the BIS Entity List.

The de minimis rule under the EAR sets a percentage threshold for US-controlled content in a foreign-made item below which the EAR does not apply; the foreign direct product rule extends US jurisdiction to foreign-made items that are the direct product of certain US-origin technology or software. These rules mean that a UK manufacturer supplying items to a BIS Entity-Listed party may have EAR obligations even if the goods are entirely assembled outside the United States, depending on the content and production process.

In our experience advising UK and European exporters, this extraterritorial dimension is the most frequently misunderstood aspect of US export-control compliance. The assumption that BIS requirements apply only to US persons exporting from US territory is incorrect for a significant category of goods and technology. The applicable items and thresholds are set out in the EAR; the Export Control Classification Number ("ECCN", the classification number that identifies an item's control parameters under the US Commerce Control List) determines whether those rules are triggered.

For a UK business, the consequence is that ECJU obligations and BIS obligations may both apply to the same shipment. ECJU controls under the Export Control Order cover strategic goods and dual-use items on the UK Strategic Export Controls list. BIS controls under the EAR cover items on the Commerce Control List. The two lists are not identical. A UK exporter that classifies its goods for ECJU purposes and stops there may be omitting the BIS classification step entirely – and screening against the BIS Entity List may not even be on its radar.

The stricter prohibition governs. Where a shipment is caught by both a BIS licence requirement and an OFSI or ECJU prohibition, the more restrictive obligation takes precedence. Cross-border counsel needs to map all applicable regimes before advising on a transaction.

What are the key risk flags in a screening programme?

The most consequential screening failures are structural, not operational: they arise from a programme that was correctly built for one regime and never extended to cover the others that apply to the business.

The risk flags we see most frequently in practice include the following.

  • List coverage gaps. A screening tool configured to query OFAC lists only will not surface BIS Entity List entries or Unverified List entries. If the business exports or re-exports items subject to the EAR, this is an enforcement gap, not just a process gap.
  • Ownership chain truncation. Screening the named counterparty but not its direct and indirect ownership chain will miss OFAC's 50 percent rule and OFSI's control analysis. Screening must extend to the ultimate beneficial owner.
  • SSI List misclassification. Parties on the SSI List are not fully blocked. Transactions with them may be permitted in categories that do not touch the restricted activities. A system that treats an SSI hit identically to an SDN hit will generate false positives and may cause the business to exit compliant relationships.
  • Static screening on dynamic lists. The SDN List, the OFSI Consolidated List, and the BIS Entity List are updated continuously. A screening programme that screens at onboarding but not periodically thereafter will not catch mid-relationship additions. As of April 2026, designations and Entity List additions have been made at pace; the gap between onboarding and the first periodic re-screen is a window of undetected exposure.
  • Transliteration and name-variation mismatches. Designated persons with names that can be transliterated from non-Latin scripts in multiple ways will not be caught by a literal-match tool. Fuzzy-match calibration is a compliance question, not only a technology question: too loose, and the business drowns in false positives; too tight, and it misses real matches.
  • No alert-disposition workflow. Generating a screening alert is not compliance. The alert must be reviewed, the match assessed, the outcome documented, and any required action – freeze, report, licence application – taken within the applicable window. A pile of unreviewed alerts is an aggravating factor in enforcement.

A micro-scenario illustrates the combined effect. In a recent matter, a financial institution in the payments sector had robust OFAC and OFSI screening in place but had not integrated BIS list coverage. A counterparty was added to the BIS Entity List based on diversion concerns. Payments continued because no OFAC or OFSI alert was generated. The institution identified the gap during an internal audit triggered by a separate transaction review. We were instructed to scope the exposure, assess the voluntary self-disclosure ("VSD", a proactive disclosure to the regulator that can reduce penalties) position, and redesign the list-coverage architecture. The matter resolved without a formal enforcement proceeding, but the remediation programme required investment in tooling, governance, and records reconstruction that significantly exceeded what a preventive review would have cost.

How does the OFSI reporting obligation compare with OFAC requirements?

OFSI imposes a specific statutory reporting obligation on certain regulated persons who know or suspect that they hold frozen assets or have transacted with a designated person; OFAC's blocking-report obligation applies to US persons who hold or receive property that must be blocked, and the reporting window is operationally tight.

Under OFSI's enforcement approach, a regulated sector firm that identifies a possible match against the OFSI Consolidated List must assess the match and, where it relates to a designated person, report to OFSI. The reporting obligation is not conditional on certainty; a reasonable suspicion is sufficient to trigger the duty in applicable regulated sectors. OFSI's guidance makes clear that the obligation to report is separate from and does not displace the obligation to freeze. Both must be done.

OFAC requires that US persons who hold blocked property submit a report, typically within a short statutory window after the blocking occurs, and thereafter submit annual reports for as long as the block is maintained. The operational challenge is that the obligation to block and the obligation to report arise simultaneously on identification of the match. In our experience, firms that discover a historic match – one that should have been blocked earlier – face both the remediation question and the question of whether a late blocking report creates additional exposure. Early counsel involvement is essential at that point.

Record-keeping obligations under both regimes require that records of blocked transactions and relevant communications be maintained for a defined period. The applicable period under OFAC is five years. Verify the corresponding OFSI and ECJU periods under the current regulations before relying on them for your jurisdiction.

The divergence matters for a cross-border business managing both US and UK relationships. A single "freeze and report" workflow needs to be calibrated to two different reporting destinations, two different obligation triggers, and two different document-retention standards. Treating them as equivalent creates compliance gaps in both directions.

A common misconception: is OFAC or OFSI the stricter regime?

The premise of the question contains the misconception. Neither regime is categorically stricter; each is stricter in specific respects, and the answer changes depending on the transaction, the counterparty, and the item.

A common belief, particularly among UK compliance teams, is that OFAC is always the harder regime – that if a transaction clears OFAC, it will clear OFSI. This is not correct. OFSI's control test, as noted above, can catch entities that OFAC's 50 percent ownership rule does not. OFSI's reporting obligations in regulated sectors apply to a broader range of "reasonable suspicion" situations than OFAC's blocking-report trigger. And OFSI has enforcement powers under SAMLA that include civil monetary penalties and, for the most serious cases, referral for criminal prosecution, without any US nexus being required.

Conversely, OFAC's SDN List is broader in some respects: secondary-sanctions risk – the risk that a non-US person who transacts with an SDN-listed party in a way that falls outside US jurisdiction may still be exposed to OFAC consequences – has no direct OFSI analogue. A European business transacting with a party that does not trigger OFSI obligations may nonetheless create secondary-sanctions exposure under the relevant OFAC programme, depending on the programme's extraterritorial reach.

The correct framing for a compliance officer is not "which regime is stricter?" but "which prohibitions apply to this transaction, under which regime, and what does each require?" Where two regimes apply simultaneously, the stricter prohibition governs for each element of the obligation. Cross-border compliance counsel works through each regime in sequence before advising on whether the transaction can proceed.

We regularly advise businesses that have resolved this question by reference to a single regime and later discovered that the other imposed an obligation they had not mapped. The cost of that discovery – remediation, reporting, and potential enforcement – is invariably higher than the cost of a regime-mapping exercise before the transaction closes.

Related practices

Frequently asked questions

Where do the regimes diverge on entity list and denied-party screening?
The primary divergences are list architecture, ownership tests, and the nature of the prohibition triggered. OFAC's SDN List imposes full blocking; BIS's Entity List imposes a licence requirement; BIS's Denied Persons List imposes an absolute prohibition. OFSI's Consolidated List imposes a financial-sanctions freeze and a reporting obligation. OFAC applies a mechanical 50 percent ownership threshold; OFSI and the EU apply a broader control test that can catch entities below that threshold. A single screening workflow cannot correctly handle all four obligations without regime-specific configuration.
Which regime is stricter on entity list and denied-party screening?
Neither is categorically stricter. OFAC's secondary-sanctions reach and its aggregate-ownership rule create exposure that has no direct OFSI equivalent. OFSI's control test can catch entities that OFAC's 50 percent rule does not. BIS's Denied Persons prohibition is absolute; there is no licence route. The correct approach is to identify every regime that applies to the transaction and map its specific requirements before advising on whether a screening result generates a compliance obligation or only a procedural step.
What should a cross-border business do about entity list and denied-party screening?
A cross-border business should first audit its list coverage: which lists does its screening programme query, and which does it miss? It should then verify that the ownership-chain analysis extends to the ultimate beneficial owner and that the tool's fuzzy-match calibration is documented and defensible. Periodic re-screening should be scheduled at a frequency that reflects the pace of list updates. Alert-disposition workflows should be regime-specific. Where a possible match is identified, a compliance counsel review before action or inaction is advisable; the reporting window under some regimes is short.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.