Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFAC

Sanctions risk assessment under OFAC: the key divergences

A technology-distribution group operating across North America, Europe, and Asia-Pacific runs its quarterly counterparty review. Three entities in the supply chain return partial name matches against OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons). One match is clearly false. One is clearly real. The third sits in the grey zone: an intermediate holding company, registered in a neutral jurisdiction, whose ultimate beneficial owner shows up on the list with a combined stake that may or may not clear the threshold. The deal is live. The board wants a decision by end of week.

A sanctions risk assessment under OFAC is the structured process by which a business determines whether a proposed counterparty, transaction, or asset is subject to a US sanctions prohibition, a licensing requirement, or neither. OFAC's authority derives from IEEPA and other enabling statutes; the assessment turns on three interlocking questions: Is a person or entity on the SDN List or a comparable OFAC list? Does the 50 percent rule (OFAC's rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked) extend that status to non-listed parties? And does the transaction touch a comprehensively sanctioned programme? Getting any one of those wrong exposes the business to civil or criminal consequences under the applicable US regime.

As of July 2026, OFAC's risk-assessment methodology has diverged in measurable ways from the approaches taken by OFSI in the United Kingdom and the EU Council. Those divergences – in the ownership test, the control analysis, the extraterritorial reach, and the consequences of a mistaken assessment – are the subject of this analysis. The page works through each divergence, identifies the risk flags that most frequently trigger enforcement scrutiny, and explains when the complexity warrants specialist sanctions counsel.

What is an OFAC sanctions risk assessment and why does it differ?

An OFAC sanctions risk assessment is the methodology a business applies to identify, quantify, and manage the probability that a person, entity, or transaction is subject to a US sanctions prohibition. OFAC operates on a strict-liability basis for civil violations: intent is relevant to penalty calculation, not to liability. That posture distinguishes OFAC from most comparable regimes and sets the baseline standard against which risk must be assessed.

The assessment has three analytical layers. The first is list-based screening: does the person appear on the SDN List, the Non-SDN Menu-Based Sanctions List, or any of OFAC's sectoral or programme-specific lists? Screening tools can address this mechanically, but only if they are calibrated correctly. The second layer is ownership analysis under the 50 percent rule. The third – and the one most frequently underestimated – is programme-level analysis: does the transaction involve a jurisdiction, sector, or instrument covered by a comprehensive or sectoral programme under the applicable OFAC regulations?

What makes OFAC's approach distinctive is the combination of extraterritorial jurisdiction, strict liability for civil violations, and secondary-sanctions risk that falls on non-US persons who deal in certain designated persons or sectors. In our experience, businesses entering US-dollar-denominated transactions or using US financial infrastructure underestimate how those features extend OFAC's reach far beyond US-incorporated entities.

The divergence from OFSI and the EU begins at the ownership test but extends much further. OFSI uses an ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person), which is qualitative and fact-specific. EU Council regulations similarly extend prohibitions to entities "owned or controlled" by listed persons, without a fixed numeric threshold. OFAC's 50 percent rule is, by contrast, mechanical and aggregated. Knowing which regime applies – and whether more than one applies simultaneously – is the first task of any well-constructed risk assessment.

How does the 50 percent rule operate in practice?

Under the 50 percent rule, any entity owned 50 percent or more in the aggregate by one or more blocked persons is itself treated as blocked, even if it is not named on any OFAC list. The rule operates across the full ownership chain, tracing indirect as well as direct holdings.

Aggregation is the mechanism that trips most first-pass screening exercises. Two listed persons each holding a 28 percent stake in the same target together reach the threshold; neither does alone. A single listed person holding 35 percent of an intermediate holding company, which itself holds 60 percent of the operating entity, applies the 50 percent test at each layer. If the intermediate entity clears the threshold because of the listed person's stake, the operating entity – even if its direct shareholders appear clean – may also be blocked through that chain.

Screening tools that flag only first-layer ownership miss this pattern entirely. Have you configured your screening logic to trace multi-layer chains, or only the entities appearing directly in the transaction documents?

The contrast with the UK and EU positions is instructive. OFSI's guidance provides that an entity may be owned or controlled by a designated person through means that do not require 50 percent shareholding – for example, through the right to appoint a majority of the board, or through contractual arrangements that give effective direction over the entity's affairs. EU Council regulations similarly extend to "control" without specifying a numeric floor. The result is that a transaction cleared by a mechanical OFAC 50 percent analysis can still be caught under OFSI or EU rules because a listed person exercises practical direction over the counterparty, even with a minority stake.

For a business making a single assessment that is meant to satisfy multiple regimes, relying on the OFAC threshold alone is structurally insufficient. A proper cross-border risk assessment applies both tests to the same ownership chain and flags any discrepancy between the two conclusions.

Where does extraterritorial reach change the risk profile?

OFAC's extraterritorial reach is the most significant variable in a cross-border sanctions risk assessment. US sanctions prohibitions bind US persons wherever located; they also bind non-US persons in defined circumstances, most notably through secondary-sanctions programmes and through the use of US financial infrastructure.

Secondary-sanctions risk arises when a non-US person engages in a transaction with a party that is subject to a US sectoral or designation-based programme, in a manner that triggers the risk of being designated or denied access to the US financial system. The mechanism does not require that the non-US person itself violate a primary prohibition. It operates as a deterrent, and the risk materialises through the threat of future US market access loss rather than through a direct enforcement action under the applicable statute.

In our cross-border practice, we regularly advise clients on transactions where the primary jurisdiction of the parties is not the United States but where US-dollar clearing, US-domiciled correspondent banks, or US-incorporated technology intermediaries create a compliance obligation that is effectively indistinguishable from that of a US person. The question "does this transaction touch the US financial system?" is not a checkbox; it requires mapping the full payment and service chain to identify every point of US nexus.

OFSI and the EU do not operate secondary-sanctions programmes in the same sense. Their prohibitions bind persons subject to the UK or EU legal order. A non-UK, non-EU business transacting with an OFSI- or EU-designated person faces no direct legal exposure under UK or EU law unless it is itself subject to those regimes. That asymmetry has practical consequences: a risk assessment prepared for a European bank typically carries a lower extraterritoriality burden from the OFSI and EU angle than from the OFAC angle, even if the underlying designated persons are the same.

The position of third-country regimes – Singapore's MAS-administered regime, the UAE's autonomous and UNSC-implementing sanctions, Japan's Ministry of Finance sanctions – is different again. These regimes track UN Security Council designations closely and apply their own autonomous designations. None operates a secondary-sanctions mechanism comparable to OFAC's. However, the interaction between these regimes and OFAC risk is non-trivial: a business routing goods or payments through Singapore or the UAE that are ultimately destined for an OFAC-sanctioned end-user carries both a local-law obligation and an OFAC exposure that must be assessed on its own terms.

What are the common risk flags in an OFAC assessment that other regimes handle differently?

Five risk flags recur across the cross-border matters we handle. Each one is handled materially differently by OFAC compared with OFSI and the EU, and each creates a divergence point in a multi-regime assessment.

Layered ownership structures. OFAC's 50 percent rule applies mechanically at each layer of an ownership chain. OFSI and the EU apply a qualitative control test at each layer. A minority stake held by a listed person that does not trigger the OFAC threshold may still satisfy the OFSI or EU control criterion if that person appoints key management or holds veto rights.

Sectoral prohibitions. OFAC's sectoral programmes restrict defined categories of transaction – specific financial instruments, specific industries, specific goods – without necessarily listing every entity in that sector on the SDN List. OFSI and EU sectoral restrictions broadly track the same categories but the scope of each prohibition, and its carve-outs, differ. A debt instrument cleared under one regime's sectoral prohibition may be caught by another's.

The knowledge and intent standard. OFAC's civil enforcement operates on a strict-liability basis. OFSI requires proof of knowledge or reasonable cause to know in respect of certain penalties, though the highest penalty tier is available for the most serious violations regardless. EU member-state enforcement standards vary, though criminal liability generally requires intent. These differences affect the probability-weighting of a risk finding and the appropriate response when exposure is identified.

Blocking obligations. Under OFAC, blocked property must be held in a blocked interest-bearing account and reported to OFAC within a short statutory window. OFSI's reporting obligation on holding frozen assets differs in its mechanics. EU Council regulations impose reporting through member-state competent authorities. A single business holding assets that may be blocked across all three regimes simultaneously must satisfy three separate procedural obligations, not one.

The general-licence ecosystem. OFAC maintains an extensive set of general licences (standing authorisations that permit a defined category of transactions without a separate application) across its programmes. Many routine activities – humanitarian transactions, personal maintenance payments, wind-down periods after a new designation – are covered by general licence. OFSI's general-licence architecture is less dense. EU Council regulations provide derogations through member-state competent authorities, with less uniformity across the bloc. A transaction that is automatically authorised under an OFAC general licence may require a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) from OFSI or a derogation from the relevant EU competent authority.

How should a cross-border business structure its risk assessment methodology?

A well-structured cross-border sanctions risk assessment operates in three phases: scope determination, identification, and mitigation. The output of each phase feeds directly into the next, and the whole sequence must be documented to serve as evidence of a compliance process in the event of a later review.

Phase one determines which regimes apply to the business, the transaction, and the counterparty. The governing factors are: the nationality and registration of each party; the jurisdiction of incorporation of each entity in the chain; the currency of the transaction; the payment routing and correspondent-bank infrastructure; the nature of the goods, services, or technology; and the end-use and end-user. A transaction that clears a US-person analysis may still attract OFAC jurisdiction through secondary-sanctions risk if it involves a US-dollar payment or US-domiciled service provider. Phase one often reveals that a business believed to face only one regime in fact faces three or four simultaneously.

Phase two is the substantive identification exercise. For OFAC, this means: screening all parties against current OFAC lists; applying the 50 percent rule across all direct and indirect ownership layers; assessing whether the transaction type falls within a sectoral prohibition; and evaluating whether any applicable general licence authorises the activity. For OFSI and the EU, the same counterparties must be screened against their respective lists and the control test must be applied to any ownership chain where a listed person holds a significant minority stake.

Phase three is mitigation and documentation. Where a risk is identified, the options include: restructuring the transaction to remove the sanctioned element; applying for a specific licence; using an available general licence; declining the transaction; and – where an apparent violation has already occurred – considering a VSD (voluntary self-disclosure to a regulator). Documentation at this phase must capture the risk identified, the analysis applied, the mitigation chosen, and the rationale for that choice. In our experience, businesses that document this sequence carefully are materially better positioned in any subsequent OFAC or OFSI inquiry than those that maintain only a screening log.

The position above covers the standard case. Your facts – the counterparty, the goods, the route, the regimes in play, and the ownership chain behind the beneficial owner – change the analysis. For an assessment of your exposure under OFAC and the applicable parallel regimes, contact Calder & Vance at info@caldervance.com.

What are the OFAC-specific risk flags in sectors with elevated cross-border exposure?

Certain sectors consistently generate a higher frequency of OFAC risk flags in cross-border transactions. Understanding why those sectors are elevated – and what makes OFAC's treatment of them different from OFSI and the EU – is a prerequisite for calibrating a sector-appropriate risk assessment.

Financial institutions and correspondent banking. Banks operating in US dollars maintain a correspondent relationship with US-domiciled institutions and are therefore subject to OFAC jurisdiction for every US-dollar transaction they process, regardless of where the payment originates. OFSI's reach does not extend to non-UK institutions in the same structural way. The OFAC exposure of a bank with no US presence but a US-dollar clearing account is a well-established point of enforcement focus, and the risk assessment methodology for such an institution must treat every USD transaction as carrying a US-person nexus question.

Virtual-asset service providers. OFAC has made clear through its guidance that sanctions obligations apply to virtual-asset transactions and that VASPs are required to screen wallet addresses against OFAC lists, not merely the names of customers. The technical challenge of implementing that screening – across multiple blockchains, with pseudonymous addresses, and at transaction speed – is specific to this sector. OFSI has issued comparable guidance for UK-registered VASPs. EU member states apply the relevant EU Council regulations through their national competent authorities. A VASP operating across all three jurisdictions must implement a screening architecture that satisfies the most demanding of the three standards, not merely the most convenient.

Trade finance and commodities. Documentary letters of credit and commodity finance transactions involve multiple parties across the payment chain, each of which may independently carry OFAC exposure. The issuing bank, the confirming bank, the freight forwarder, the vessel owner, the flag state, and the end-buyer each present a distinct OFAC risk question. OFSI and the EU apply comparable analysis to the same chain, but their general-licence ecosystems are less developed, and the interaction between OFAC secondary-sanctions risk and EU Blocking Regulation obligations creates a genuine conflict-of-laws question for European banks involved in transactions touching certain OFAC-designated sectors.

Technology and dual-use goods. The intersection of OFAC sanctions and BIS export controls is a specific category of cross-border risk that does not have a precise structural equivalent in the UK or EU regimes. A technology transaction that is compliant with EU dual-use rules and OFSI financial-sanctions requirements may nonetheless require an OFAC licence if the end-user is subject to a US sanctions programme. Conversely, a transaction cleared by OFAC may still require an ECJU export licence under the UK's Export Control Order. For exporters of dual-use technology operating across multiple markets, the risk assessment must treat OFAC sanctions and BIS controls as a combined US-regulatory analysis, not two separate checks.

If a transaction has already been flagged, or if a filing has been refused or a match has been escalated by a correspondent bank, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential initial review.

A common misconception: "our business has no US operations, so OFAC does not apply"

The most persistent misconception we encounter in cross-border compliance practice is that OFAC's rules are a domestic US matter – that if a business is not incorporated in the United States, has no US employees, and holds no US assets, it sits outside OFAC's reach. This is not accurate, and relying on it is one of the more consequential compliance errors a multinational can make.

OFAC's jurisdiction extends to: any US person (including overseas branches of US-incorporated entities); any transaction that processes through the US financial system, including US-dollar clearing; any transaction involving US-origin goods, services, or technology; and, under secondary-sanctions programmes, any non-US person whose dealings with certain OFAC-designated parties create the risk of US designation or loss of US market access.

In a recent matter, a technology distributor based entirely outside the United States processed a payment through a US correspondent bank. The payment, which related to a services contract with a counterparty whose ultimate beneficial owner held a significant stake in an OFAC-listed entity, was flagged and frozen by the correspondent bank. The business had no OFAC compliance programme because it believed it had no US nexus. We assisted with the licence application, the engagement with the correspondent bank, and the review of the ownership chain. The matter was resolved, but the business lost several months of operational access to its primary payment corridor while the process ran.

The practical lesson is that a business whose transactions touch US dollars, US technology, or US-domiciled intermediaries at any point in the chain has a US-person nexus question and must apply OFAC's rules to its counterparty and ownership analysis as rigorously as any US-incorporated entity would.

Related practices

Frequently asked questions: sanctions risk assessment under OFAC

Where do the regimes diverge on sanctions risk assessment?

The principal divergences are in the ownership test, the control analysis, and extraterritorial reach. OFAC applies a mechanical 50 percent aggregate ownership threshold; OFSI and the EU apply a qualitative ownership-and-control test that can catch minority-stake situations where practical control is established. On extraterritoriality, OFAC's secondary-sanctions programmes extend risk to non-US persons transacting with certain designated parties in a way that OFSI and the EU do not replicate. The general-licence architectures also differ materially in density and scope.

Which regime is stricter on sanctions risk assessment?

No single regime is unambiguously stricter across all dimensions. OFAC operates strict-liability civil enforcement and has the broadest extraterritorial reach; that combination makes it the dominant compliance driver for most cross-border businesses. OFSI and the EU, however, apply a broader control test that can catch structures that OFAC's mechanical threshold would release. The applicable principle across all regimes is that the stricter prohibition governs: where two regimes reach inconsistent conclusions on the same transaction, the analysis that produces the higher restriction controls the compliance decision until a licence or derogation is obtained.

What should a cross-border business do about sanctions risk assessment?

A cross-border business should implement a three-phase assessment methodology: scope determination (which regimes apply), identification (list screening, ownership analysis, programme assessment), and mitigation (restructuring, licensing, or VSD). The methodology must be documented at each phase and updated when the ownership structure of a key counterparty changes or when a new designation is published. Where the assessment produces an uncertain or adverse finding, specialist sanctions counsel should be involved before the transaction closes, not after.

About the author

J. M. Aldridge advises multinationals and financial institutions on US sanctions and export controls, with a focus on OFAC licensing, secondary-sanctions risk, and BIS classification. Calder & Vance – International Sanctions & Export Control Counsel.

About Calder & Vance

Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.

Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.