Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

OFSI vs Australia: Payment-processing controls: what businesses miss

A payment-operations team at a mid-sized European trading firm processes a batch of supplier invoices. One payment routes through a London correspondent bank; a second clears through an Australian institution. Both counterparties pass automated screening. Both payments are, in fact, prohibited. The gap is not in the screening logic – it is in a fundamental difference in how the United Kingdom's Office of Financial Sanctions Implementation and Australia's autonomous sanctions regime define the act of "making funds available." That definitional gap is where payment-processing controls fail.

Payment-processing controls under OFSI and Australia's Autonomous Sanctions regime diverge on three axes: the scope of the prohibition, the ownership-and-control test that determines whether a non-listed counterparty is caught, and the reporting obligations triggered when a prohibited payment is identified. Neither regime is simply "stricter" across the board – each is more demanding in different respects, and the stricter prohibition governs for any entity with dual exposure. As of July 2026, both regimes are actively enforced and neither provides a good-faith reliance defence for inadequate screening.

This analysis sets out where the two regimes converge, where they diverge, and what that means for the practical design of payment-processing controls in a business operating across both jurisdictions.

How Each Regime Defines the Payment Prohibition

The prohibition that payment-processing controls must address is not the same word-for-word in London and Canberra, and that matters. Under OFSI, the core prohibition under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic regulations is on making funds available – directly or indirectly – to or for the benefit of a designated person. Under Australia's Autonomous Sanctions regime, administered by the Department of Foreign Affairs and Trade (DFAT), the prohibition extends to dealing in assets that are "owned or controlled" by a designated person, and to making assets available to such a person.

The phrase "for the benefit of" in the UK formulation is wider than it first appears. A payment that does not reach a designated person directly can still constitute making funds available for their benefit if the economic benefit flows to them through an intermediary. In our experience, payment-operations teams frequently treat the prohibition as satisfied once the immediate counterparty is clear on a sanctions list. That is not correct under either regime.

Australia's "dealing in assets" language sweeps in a broader category of transactional activity. Processing a payment instruction, collecting a debt on behalf of a counterparty, or holding funds pending transfer can all constitute a "dealing" under the applicable country regime. Businesses that have configured their controls to the UK model – asking only "is this counterparty designated?" – will miss the additional conduct scope in the Australian rules.

One practical consequence: a netting arrangement or a multilateral payment facility that offsets obligations can route value to a designated person without any single payment being obviously identifiable as prohibited. Both regimes can catch this. The analytical question is whether the economic substance of the arrangement makes value available to a designated person, not whether any individual payment line shows a sanctions hit.

The Ownership-and-Control Test: Where the Real Divergence Sits

The ownership-and-control test is the deepest structural difference between the two regimes, and it is the one most likely to produce a gap in payment-processing controls. Under OFSI, an entity is treated as owned or controlled by a designated person if a designated person holds a majority interest, exercises control through other means, or the entity is otherwise controlled by a designated person – applying the ownership and control test set out in the relevant thematic regulations. This is a two-limb test: ownership and a functional control limb that can catch entities where formal ownership is below the threshold.

Under the Australian Autonomous Sanctions regime, the ownership test focuses on whether the designated person has effective control over the relevant assets. DFAT guidance indicates that "controlled by" extends to practical or factual control, not merely legal ownership. The two formulations overlap substantially in their effect, but they differ in one operationally significant respect: the UK rules include a specific provision treating entities owned or controlled by multiple designated persons cumulatively, while the Australian approach focuses more holistically on effective control at the asset level.

What does this mean for payment-processing controls? It means that a counterparty-level screen – asking only "is this legal entity designated?" – is insufficient under both regimes, but for slightly different reasons. Under OFSI, you must trace ownership upward through the chain to identify whether any designated person holds a controlling or majority interest. Under the Australian regime, you must additionally ask whether any designated person effectively controls the assets being transferred, even if legal ownership is dispersed.

Consider a payment to a property-management company. Under OFSI, you must establish that no designated person owns or controls the company. Under the Australian regime, you must additionally establish that no designated person effectively controls the specific funds or property at issue. A clean corporate screen may satisfy the first question and still leave the second unanswered. We regularly advise payment-operations teams to build a second-layer ownership prompt into their payment-release workflow precisely to address this point.

Reporting Obligations: Timelines and Consequences

Both regimes impose reporting obligations when a business identifies a potential breach or holds funds that may be subject to a prohibition, but the mechanics differ and the consequences of missing a deadline are serious under both. Under OFSI's reporting requirement, a relevant firm that knows or reasonably suspects that a person is a designated person, or has committed an offence, must report that knowledge or suspicion to OFSI as soon as practicable. The obligation applies to the financial sector broadly and extends to payment-service providers and e-money institutions.

Australia's regime imposes a reporting obligation on persons who hold "controlled assets" – assets that are owned or controlled by a designated person – to report those holdings to DFAT. The timing language differs from OFSI's formulation, and the scope of who is required to report differs too. Payment processors and financial intermediaries are within scope under both regimes, but the threshold for triggering the obligation – "reasonable suspicion" in the UK, "knowledge" of controlled assets in the Australian rules – is calibrated differently.

That calibration difference has a direct operational consequence. A payment-processing firm that sets its escalation threshold at "near certainty" will satisfy neither regime reliably. OFSI's "reasonable suspicion" standard is materially lower. In practice, this means that an automated screening alert that a compliance team mentally files as a "probable false positive" and releases without documented review can, if the hit later proves valid, constitute a failure to report under the UK rules. The Australian threshold, focused on "knowledge," is harder to trigger on a system-generated alert alone – but knowledge can be imputed from what a properly run compliance function ought to have established.

A further divergence concerns what happens after the report. OFSI has a published enforcement posture that distinguishes between firms that report proactively and co-operate with its enquiries and those that do not. That posture is material to the penalty outcome. DFAT's enforcement approach under the Australian regime is less extensively published, which means that the benefit of early reporting is less quantifiable – but the obligation to report is no less real.

The position above covers the standard case. Your specific facts – the counterparty structure, the payment route, the applicable thematic regime, the currency and correspondent bank – change the analysis materially.

For a confidential review of your payment-processing controls against both OFSI and the Australian regime, contact Calder & Vance at info@caldervance.com.

Licensing and Authorisation: How Relief Differs Between the Two Regimes

When a payment is prohibited under either regime, the only lawful route to proceeding is a licence or authorisation. The licensing mechanisms differ structurally, and understanding those differences is essential to building payment-processing controls that preserve options when a hit is identified.

OFSI issues two types of licence: a general licence (a standing authorisation that permits a defined category of transactions without a separate application) and a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction). General licences under the UK regime cover categories such as payments for basic needs, legal fees, and certain prior contractual obligations. The categories and conditions are set by the relevant thematic regulations and are subject to change. A payment-processing firm cannot assume that a general licence applicable last month still covers the transaction today.

Australia's regime provides for permit-based relief through DFAT. The grounds on which a permit can be granted are set by the Autonomous Sanctions Act and the relevant legislative instruments. The categories broadly parallel OFSI's licensing grounds – humanitarian need, prior contracts, legal fees – but the procedural requirements and assessment criteria differ. There is no direct Australian equivalent of OFSI's general licence concept in all thematic areas; some relief that is available as a standing authorisation in the UK requires an individual permit application in Australia.

For a payment-processing firm operating in both jurisdictions, this creates a practical risk. A payment covered by a UK general licence may require an individual Australian permit to proceed lawfully at the Australian leg of the transaction. A firm that clears the OFSI leg without checking the Australian position has not completed its compliance analysis. We have acted for payment-service providers that discovered this gap mid-transaction, when the Australian bank in the payment chain requested sight of the applicable permit. Early-stage licensing analysis – before the payment instruction is accepted – is the correct control.

What Businesses Consistently Miss: Five Risk Flags

Payment-processing controls that are calibrated to one regime and assumed to work across both consistently produce the same failure patterns. The following five risk flags are the ones we see most frequently in practice.

Indirect payments and "for the benefit of" flows. A payment routed through a non-designated intermediary that ultimately benefits a designated person is prohibited under both regimes. Screening the immediate payee is a necessary but not sufficient control. Payment-purpose analysis – asking who ultimately receives economic value – must be part of the release process.

Aggregation of ownership across multiple designated persons. Two or more designated persons each holding a minority interest in a counterparty can cumulatively reach a controlling or majority threshold. Screening tools that flag individual ownership concentrations but do not aggregate across multiple designated holders will miss this pattern. The UK regime addresses this expressly; the Australian regime reaches the same result through its effective-control analysis.

Stale ownership data. A counterparty that was clean at onboarding may no longer be clean twelve months later. Designations are made and amended with no advance notice to affected businesses. Payment-processing controls must include a periodic refresh of ownership and control data – not just a screen at the point of payment release against the current version of the SDN List or the Australian Consolidated List.

Currency and correspondent-bank exposure. A payment denominated in USD clears through the US correspondent banking system regardless of whether the originating firm is UK or Australian. OFAC's jurisdiction attaches at the point of USD clearing. A firm that has analysed its OFSI and Australian exposure thoroughly may still face OFAC exposure on a USD-denominated payment to the same counterparty. Payment-processing controls must reflect the currency and the correspondent-bank chain, not only the jurisdiction of the originating firm.

Crypto and virtual-asset payments. OFSI's scope extends to virtual assets under the relevant thematic regulations, and OFSI has issued guidance specifically addressing virtual-asset service providers (VASPs). Australia's regime applies to assets in the broad sense and has been interpreted to extend to digital assets. A payment-processing firm that handles crypto transactions cannot assume that the OFSI and Australian payment-prohibition analysis is different in kind from fiat. The same ownership-and-control analysis applies; the practical challenge is the pseudonymity of wallet addresses and the pace at which new addresses are used by sanctioned actors.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for an assessment of your position.

A Cross-Regime Scenario: What a Compliant Payment-Release Process Looks Like

Consider the position of a payment-services firm with a UK licence and an Australian financial-services authorisation. It processes a payment from a corporate client to a counterparty incorporated in a third jurisdiction. The counterparty's immediate owner is a clean entity. A secondary shareholder in that owner holds a minority stake and is listed on both the UK Consolidated List and the Australian Consolidated List. The payment denomination is USD.

A controls process adequate to both regimes would proceed as follows. First, screen the immediate counterparty against all applicable consolidated lists – UK, Australian, OFAC, and UN. Second, trace the ownership chain upward to identify all natural persons and entities with a material ownership interest. Third, screen each identified owner against the same lists. Fourth, apply the aggregation analysis: do listed persons in the ownership chain collectively hold a controlling or majority interest? Fifth, assess the currency: a USD-denominated payment adds OFAC jurisdiction. Sixth, identify any applicable general licence or permit that covers the payment category. Seventh, if no licence or permit applies, treat the payment as prohibited pending an escalation decision.

In a recent matter, a payment-services business with dual OFSI and Australian authorisation identified at step four that two minority-listed shareholders aggregated to a controlling interest in a counterparty that had passed its initial screen cleanly. The firm escalated the payment, applied for a specific licence under the UK regime and a DFAT permit in parallel, and suspended the payment pending their grant. The transaction ultimately proceeded under the licences granted. The lesson is not about the outcome – no outcome can be promised – but about the control that made a lawful resolution available. Without the ownership-aggregation step, the firm would have processed a prohibited payment, and neither the OFSI nor the Australian good-conduct analysis at enforcement stage would have been available to it.

Common Misconceptions About Cross-Regime Payment Controls

One misconception we encounter frequently is that compliance with one regime is broadly sufficient for the other. The two regimes share a common origin – UN Security Council obligations and the broader international sanctions consensus – and their prohibited-party lists overlap substantially in the categories they target. But overlap in the lists is not identity in the rules. The ownership-and-control tests, the licensing mechanisms, the reporting timelines, and the enforcement posture are all calibrated differently. A firm that has a well-tested OFSI compliance programme and assumes it can "map across" to the Australian requirements without a dedicated gap analysis is carrying unquantified exposure on the Australian side.

A second misconception concerns the role of correspondent banks. Firms sometimes treat a correspondent bank's AML and sanctions screening as a backstop that removes their own obligation to screen. It does not. Each participant in a payment chain is responsible for its own compliance with the applicable prohibitions. A correspondent bank's screening is run against its own regulatory obligations, not against yours. If the correspondent bank releases a payment that you should have stopped, you remain in breach of your own obligations. The correspondent's release is not a safe harbour.

A third misconception is that the Australian regime is less enforced and therefore carries lower risk. Enforcement activity under the Australian Autonomous Sanctions regime has increased over the review period and DFAT's published statements indicate a continued commitment to enforcement. The fact that the regime's enforcement history is shorter than OFSI's does not mean the risk is lower – it may mean the consequences of early enforcement actions, which tend to set the precedent for penalty levels and expectations, have not yet been priced into the compliance decisions of firms in the market.

Related Practices

Related practices

Frequently asked questions

Where do the regimes diverge on payment-processing controls?
The deepest divergence is in the ownership-and-control test and in the licensing relief available. OFSI's control limb and Australia's "effective control" formulation overlap in scope but are not identical, and they produce different outcomes in structures where legal ownership and effective control are separated. Licensing also differs: OFSI issues general licences as standing authorisations for defined categories, while Australian relief in some categories requires an individual DFAT permit rather than a general instrument. The reporting-obligation threshold – "reasonable suspicion" under OFSI versus a knowledge-based trigger in Australia – is a further practical divergence that affects how escalation decisions should be documented.
Which regime is stricter on payment-processing controls?
Neither regime is uniformly stricter. OFSI's "reasonable suspicion" reporting threshold is lower than Australia's knowledge-based trigger, making the UK more demanding on when a report must be made. Australia's "dealing in assets" prohibition is potentially broader in conduct scope, capturing a wider range of transactional activity beyond straightforward fund transfers. On licensing, OFSI's general-licence mechanism can provide faster relief for defined categories than an individual DFAT permit. The correct approach is to apply the stricter prohibition wherever the two regimes diverge – which is standard multi-regime compliance practice.
What should a cross-border business do about payment-processing controls?
A cross-border business with OFSI and Australian exposure should take three concrete steps. First, conduct a gap analysis comparing its existing controls against the requirements of both regimes – including the ownership-aggregation analysis, the currency and correspondent-bank overlay for USD payments, and the licensing inventory. Second, document its escalation and reporting procedures against both reporting-obligation standards. Third, review its licensing position periodically: general licences and permits are amended, and a covered category from one quarter may no longer be covered the next. For a structured review, contact Calder & Vance at info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.