A payments firm processes hundreds of thousands of transactions daily across the United States, the European Union, and a dozen emerging markets. Its screening engine flags a corporate counterparty. The match is on a name variant, not an exact entry. Under OFAC's rules, the firm must determine whether the counterparty is itself blocked. Under EU rules, the firm must ask a different question – and the answer may be different too. One screening hit. Two regimes. Potentially two separate legal outcomes.
Name and entity screening under OFAC and EU sanctions follows the same broad objective – preventing prohibited transactions – but differs materially on ownership thresholds, control tests, listing sources, match-quality standards, and what a firm must do after a hit. OFAC applies a mechanical 50 percent rule (the rule that treats any entity owned 50 percent or more in the aggregate by blocked persons as itself blocked, regardless of operational control), while the EU adds a separate ownership and control test (a combined assessment of both formal ownership and effective control over the entity's decisions). The divergence is not academic: a counterparty may be blocked under one regime and clear under the other, or caught under both on different grounds.
This analysis maps the key divergences across five dimensions – legal basis and authority, the ownership and control test, list architecture, match-quality standards, and post-hit obligations – and draws out the practical implications for cross-border businesses running a single screening programme against both regimes.
What are the legal foundations of each screening regime?
OFAC administers US economic sanctions under authority derived principally from the International Emergency Economic Powers Act (IEEPA) and, for certain programmes, the Trading with the Enemy Act (TWEA). OFAC's primary enforcement tool is the SDN List (OFAC's list of Specially Designated Nationals and blocked persons), supplemented by sectoral and geographic designation lists. The SDN List is a direct-prohibition instrument: transacting with, or for the benefit of, any listed person or any entity that falls within the 50 percent rule is prohibited for US persons and, with extraterritorial reach through secondary-sanctions mechanisms, for many non-US parties as well.
EU sanctions rest on a dual legal structure. The Council of the EU adopts a Common Foreign and Security Policy decision, and a directly applicable Council Regulation follows, which imposes the concrete obligations on persons and entities within the EU's jurisdiction. The EU Consolidated List (maintained by the European Commission) records the designated persons and entities under each programme. Unlike OFAC, the EU framework also accommodates the EU Blocking Regulation, which creates a separate and sometimes conflicting layer of obligation for EU operators exposed to US secondary-sanctions risk.
The practical difference from a screening standpoint is significant. OFAC operates a single primary list architecture with well-defined programme codes. The EU operates multiple programme-specific lists consolidated into one searchable dataset, each carrying its own jurisdictional scope and asset-freeze or travel-ban parameters. A screening programme must be calibrated to consume both – and the list update cadence differs too.
How does the ownership and control test differ between OFAC and the EU?
The ownership and control test is the single most consequential divergence for cross-border screening. OFAC's 50 percent rule is arithmetic: if blocked persons own, individually or in the aggregate, 50 percent or more of an entity, that entity is itself blocked, whether or not it appears on the SDN List. The test is indifferent to who runs the business. A listed person may hold 60 percent of a company and play no operational role; the company is blocked nonetheless.
Aggregation matters here in a way that screening tools often miss. Two separately listed persons each holding 30 percent of the same counterparty together reach the threshold. Neither holding alone triggers the rule; the aggregate does. In our experience, firms that rely on single-party flag logic rather than portfolio-level aggregation routinely under-screen at exactly this point.
The EU applies a combined ownership and control standard. Asset-freeze obligations attach to listed persons and to entities owned or controlled by them. Ownership is assessed on a broadly comparable basis to OFAC – the EU generally uses a threshold in a similar range, though the precise level is set out in the applicable Council regulation rather than a standalone rule, and practitioners should verify the current position before relying on it. The critical addition is the control limb: an entity not meeting the ownership threshold can still be caught if a listed person effectively controls its decisions. Control indicators include the power to appoint the majority of the board, the contractual ability to direct strategy, or structural dependence through financing or licensing arrangements.
This means the EU net is, in some respects, wider than OFAC's mechanical rule. A 40 percent stake combined with board-appointment rights may capture an entity under EU rules that OFAC would not reach through ownership alone. Conversely, an entity blocked under OFAC's 50 percent rule because of passive majority ownership may face a less clear outcome under EU law if control indicators point in a different direction. The regimes do not necessarily arrive at the same answer for the same counterparty structure.
What does this mean for a screening programme? It means that an ownership determination cannot stop at list-matching. It must include a second-layer analysis of the beneficial ownership chain and, for EU-scope transactions, an assessment of control indicators. We regularly advise clients whose existing programmes flag SDN ownership accurately but have no mechanism to evaluate EU-style control, leaving a material gap in the compliance posture.
How does list architecture affect the screening design?
OFAC publishes its lists in a structured, machine-readable format through its Sanctions List Service. Entries include aliases (alternative name spellings and transliterations recorded on the SDN entry), date-of-birth indicators, entity identifiers, and programme codes. The SDN List is the primary instrument. OFAC also maintains the Sectoral Sanctions Identifications List (SSI), which imposes transaction-type restrictions rather than a full asset freeze, and several geographic and programme-specific lists. A screening programme that ingests only the SDN List and ignores the SSI – and the sectoral restrictions that come with it – is incomplete.
The EU Consolidated List aggregates designations across all active programmes into a single downloadable dataset. The data model includes entity type, programme identifier, identification documents, and known aliases. One practical challenge is that EU entries for the same underlying person or entity may appear under multiple programmes with different restriction types – an asset freeze under one regulation, a travel ban under another. Screening engines must parse programme-level restrictions, not just flag on name match, to determine what transaction restrictions actually apply.
A further divergence concerns list update frequency and the notification architecture. OFAC updates the SDN List and associated lists on a rolling basis, often without pre-announcement. EU list updates follow the publication of Council implementing regulations in the Official Journal of the EU. Both processes can produce same-day obligations, but the procedural path differs, and the window between a Council decision and Official Journal publication – during which operators may face uncertainty about whether a designation is in force – is a known operational risk point. Firms running near-real-time transaction screening must have a feed that captures both list changes with minimal latency.
Where do OFAC and the EU diverge on match-quality standards?
Match quality is the engineering layer beneath the legal layer, and the regimes provide different amounts of formal guidance on it. OFAC's published framework on screening methodology addresses what a sanctions compliance programme should include, and OFAC's enforcement posture distinguishes between a firm that had effective screening and produced a false negative, and one that had inadequate screening from the outset. The former may access mitigating factors; the latter faces a harder enforcement position.
OFAC's guidance on name matching accepts that transliterated names, name variants, and aliases require fuzzy-logic or phonetic matching rather than exact-string comparison. What the guidance does not do is specify a minimum match-score threshold in numerical terms. That determination is left to the operator, informed by the risk profile of its business. A high-volume, lower-risk payment processor and a low-volume correspondent bank handling complex structured transactions will set different thresholds – and both can be defensible if calibrated and documented.
The EU does not publish a comparable body of screening-methodology guidance at the central level. Member state competent authorities – the bodies responsible for administering and enforcing the EU's asset-freeze obligations – take different approaches to what constitutes adequate screening and adequate documentation of the screening process. This produces a jurisdiction-by-jurisdiction variability within the EU that has no clean parallel in the OFAC system, where enforcement is centralised. A firm operating across several EU member states may face materially different supervisory expectations in each, even when running an identical screening programme.
In our practice, we see this divergence produce real compliance gaps for firms that design their screening programme to the OFAC standard, assume EU compliance follows, and discover – typically on a supervisory inquiry – that the member state competent authority expected additional layers of documentation, escalation procedures, or human-review steps that the firm had not built in.
What post-hit obligations apply, and where do they diverge?
A screening hit under OFAC triggers a clear set of obligations. Blocked property must be frozen immediately and, if it is held by a US financial institution or similar obliged person, reported to OFAC within a short statutory window. The obligation to report continues: annual reports on blocked property are required. The holder of blocked property cannot release, transfer, or provide services in respect of it without an OFAC authorisation – either a general licence (a standing authorisation covering a defined category of transactions) or a specific licence (a case-by-case authorisation applied for directly with OFAC).
The EU framework imposes comparable asset-freeze and reporting obligations, but the reporting channel runs to the relevant member state competent authority rather than a central EU body. This means that a firm with operations in, say, three EU member states that identifies frozen assets may face three separate reporting obligations – to three separate authorities – with potentially different deadlines and form requirements. The absence of a single central EU reporting window is an operational complexity with no OFAC analogue.
Licensing also diverges at the procedural level. Under OFAC, specific-licence applications are submitted to OFAC directly, and OFAC publishes general licences that can authorise whole categories of otherwise prohibited transactions. Under EU programmes, licensing (or the grant of a derogation from the asset-freeze obligation) is administered at the member state level, through the national competent authority. The criteria and the process may differ by member state, even under the same underlying Council regulation. An EU operator seeking to conduct a transaction that would otherwise be prohibited must identify the correct national authority and satisfy its specific procedural requirements.
For a cross-border business, this structural difference has a direct implication for the escalation path built into the screening programme. OFAC hits escalate to a single counterparty (OFAC) for licensing or blocking determinations. EU hits require identification of the relevant national authority in each member state with jurisdiction over the asset or transaction – a step that itself requires legal analysis in complex structures.
The position above covers the standard case for established screening programmes. Your specific facts – the counterparty's jurisdiction of incorporation, the asset type, the transaction route, and the member states whose competent authorities have jurisdiction – will change the analysis. For an assessment of your firm's screening posture across both regimes, contact Calder & Vance at info@caldervance.com.
How does secondary-sanctions risk interact with EU screening obligations?
A dimension that purely EU-focused screening programmes sometimes underweight is OFAC's extraterritorial reach through secondary-sanctions mechanisms. Secondary sanctions create the risk that a non-US entity, conducting a transaction that does not involve US persons, US territory, or US-origin goods, may nonetheless face OFAC action – including the risk of being designated itself – if the transaction involves a person or entity targeted by certain OFAC programmes.
The EU's response to this risk is itself a source of legal tension. The EU Blocking Regulation, as updated, prohibits EU operators from complying with certain extraterritorial sanctions measures and requires them to notify the European Commission of any conflict. This creates a structural tension for an EU operator that screens against OFAC lists and identifies a counterparty targeted by a US secondary-sanctions programme but not listed on the EU Consolidated List: declining the transaction may satisfy OFAC's expectations while potentially exposing the firm to Blocking Regulation liability; proceeding may satisfy the Blocking Regulation while creating OFAC secondary-sanctions exposure.
This tension is not hypothetical. We have acted for EU financial institutions whose screening programmes flagged OFAC secondary-sanctions targets precisely because the firms had calibrated their lists to include OFAC SSI-type designations. The question of whether and how to act on those flags has a legal answer, but it requires analysis of both regimes in parallel – not a single-list compliance decision. The interaction between OFAC extraterritoriality and EU blocking obligations is a standing feature of the cross-border compliance environment, and any screening programme that ignores it is operating with an incomplete risk model.
What are the common risk flags in cross-border screening programmes?
Across the businesses we advise, certain failure patterns recur with enough regularity to be treated as known risk flags rather than exceptional incidents. Identifying them in advance is more effective than discovering them in an enforcement context.
The first risk flag is single-list dependency. Firms that screen against a single consolidated feed – even a high-quality commercial data product – without checking whether the feed captures OFAC's full list architecture (SDN plus SSI and programme-specific lists) and the EU's full programme dataset are running incomplete screening from day one. The gap typically shows up on sectoral-restriction entries rather than full-designation entries.
The second is static ownership data. The 50 percent rule and the EU ownership-and-control test both require current beneficial ownership information. Firms that screen a counterparty at onboarding and do not refresh the ownership analysis periodically are exposed to changes in a listed person's stake that post-date the initial review. Ownership structures change; lists change; a counterparty that was clear on day one may not be clear today.
The third is threshold calibration without documentation. Setting a fuzzy-match threshold without a documented rationale – tied to the firm's risk appetite, the nature of its customer base, and the volume and type of transactions – leaves the firm unable to explain its screening logic to a regulator. OFAC's enforcement guidance treats a well-calibrated, documented programme very differently from one that cannot articulate why it was set the way it was.
The fourth is failure to test. A screening programme that has never been subjected to adversarial testing – deliberate insertion of known SDN names, name variants, and transliterations to verify that the engine flags them – provides far weaker assurance than one that has been tested, documented, and remediated. Regulators on both sides of the Atlantic increasingly expect firms to demonstrate, not merely assert, that their screening works. Our compliance audit and testing service is designed precisely for this purpose.
If a transaction has already been flagged, a compliance escalation has stalled, or a supervisory inquiry has arrived, an early legal review preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential discussion.
A common misconception: "OFAC compliance covers our EU obligations"
The most persistent myth we encounter among cross-border businesses is that a screening programme calibrated to OFAC's standards automatically satisfies EU obligations. It does not, for reasons that should be apparent from the analysis above. The ownership test differs. The list architecture differs. The post-hit reporting structure differs. The licensing channel differs. The interaction with the EU Blocking Regulation has no OFAC parallel at all.
The converse error also occurs: firms operating primarily within the EU that treat EU Consolidated List compliance as sufficient for OFAC purposes. This misunderstands the extraterritorial scope of OFAC's rules. An EU operator handling US-dollar transactions through a US correspondent bank is subject to OFAC's jurisdiction over those transactions. An EU operator selling goods with US-origin content may be subject to both OFAC jurisdiction and BIS export-control rules, adding a further layer. For a structured analysis of the BIS and EAR dimension, see our related analysis on ownership and control assessment under BIS and the EAR.
A genuinely cross-border screening programme must be designed from both ends simultaneously. That means mapping the legal obligations of each regime applicable to the firm's business before designing the technical architecture – not building to one regime and patching the others in later.
For a more detailed treatment of OFSI's screening obligations and how they compare, our companion analysis on name and entity screening under OFSI covers the UK position in full.
Related practices
- Compliance audit and testing – stress-test your screening logic against live list data and documented risk parameters
- Name and entity screening: OFSI analysis – the UK OFSI ownership, control, and post-hit framework compared
- Ownership and control under BIS and the EAR – how export-control classification intersects with sanctions ownership tests