Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Sanctions risk assessment under OFSI: the key divergences

A UK-headquartered trading group closes a commodity deal through a European subsidiary. The counterparty passes its automated screening. Three weeks later, the group's US bank flags a potential link to a designated person under OFSI's financial-sanctions rules. The trade is already settled. What is the group's exposure? Which set of rules governs? And how does the UK position differ from what OFAC or the EU would require?

A sanctions risk assessment (a structured evaluation of an organisation's exposure to financial-sanctions prohibitions across its activities, counterparties, and geographies) is the foundation of any defensible compliance programme. Under OFSI (the Office of Financial Sanctions Implementation, the UK Treasury's financial-sanctions authority), the assessment turns on an ownership and control test that differs materially from OFAC's mechanical 50 percent threshold and from the EU's parallel but not identical standard. As of July 2026, those divergences carry direct practical consequences for cross-border businesses managing simultaneous exposure to multiple regimes.

This analysis maps the key divergences between OFSI's approach and the approaches taken by OFAC and the EU, explains how those divergences affect practical risk-assessment methodology, and identifies the points at which the gaps are most likely to produce compliance failures.

What is a sanctions risk assessment and why does it matter under OFSI?

A sanctions risk assessment is a structured, documented process by which an organisation identifies, measures, and prioritises its exposure to the prohibitions imposed by one or more sanctions regimes. Under OFSI, it is not merely good practice. OFSI's published enforcement guidance treats the existence and quality of a risk-assessment programme as a central factor when determining the appropriate response to an apparent breach – and when calculating whether a monetary penalty is warranted.

The legal basis for OFSI's authority derives from the Sanctions and Anti-Money Laundering Act ("SAMLA") and the thematic regulations made under it. SAMLA created the architecture through which the UK maintains its own autonomous sanctions regime, independent from the EU system it left on departure. That independence is precisely why the OFSI standards and the EU standards, though they share a common heritage, have diverged in several operationally significant ways.

Why does this matter in practice? Because a business that designs its risk-assessment solely around OFAC's rules will be calibrated to a mechanical ownership test. When it encounters an OFSI question – or an EU question – it will be applying the wrong analytical lens. We regularly advise businesses that have discovered this mismatch only when a transaction is already in difficulty.

The position above covers the standard case. Your facts – the counterparty structure, the goods, the route, the financial institution, the specific regime in play – change the analysis considerably.

For a confidential assessment of your UK sanctions exposure and risk-assessment methodology, contact Calder & Vance at info@caldervance.com.

The OFSI ownership and control test: how does it compare to OFAC's 50 percent rule?

The fundamental divergence between OFSI and OFAC lies in the structure of the entity-capture test. OFAC applies the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked): if designated persons own, directly or indirectly, 50 percent or more in the aggregate, the entity is treated as blocked, regardless of whether any designated person exercises actual control. The test is mechanical. Intention, management, and operational control are irrelevant to it.

OFSI's position is different. Under the relevant thematic regulations made under SAMLA, a non-listed entity can be treated as owned or controlled by a designated person not only through a shareholding threshold but also through broader control indicators. Those indicators include the ability to appoint or remove a majority of the board, the ability to direct the entity's activities through contractual or structural arrangements, and other tests that extend beyond shareholding percentage alone.

This produces a more demanding analytical task. A business applying the OFSI test cannot confine its ownership analysis to counting percentage holdings. It must also ask: does the designated person, or a combination of persons acting in concert, hold rights that give effective control even without majority ownership? In our experience, that question is frequently under-analysed, particularly where ownership is structured through nominee arrangements, preference shares with enhanced voting rights, or contractual veto mechanisms.

The EU position, set out in the relevant Council Regulations and the guidance issued by the European External Action Service, is broadly similar to OFSI's in extending to control, but it is not identical. The EU applies the test across member states under a single instrument. OFSI applies it through UK-specific regulations that have evolved since SAMLA came into force. Subtle differences in drafting mean that an entity that falls outside EU ownership thresholds may still be caught under OFSI, or vice versa. Cross-border businesses must map both analyses separately; they cannot rely on an EU clearance as a proxy for UK clearance.

How does the OFSI risk-assessment standard differ from the EU's approach?

Beyond the ownership-and-control test itself, OFSI and the EU diverge on the wider standards they impose when evaluating whether a compliance programme is adequate. OFSI's enforcement guidance identifies several factors relevant to penalty decisions, including whether an organisation had a risk-based compliance programme in place, whether it applied due diligence proportionate to the risk, and whether it acted promptly on identifying an issue. The EU framework – implemented through individual member-state competent authorities – does not operate to a single enforcement standard. Penalty decisions in Germany, France, and the Netherlands, for example, reflect distinct national approaches to the weight given to compliance history.

That divergence is operationally significant. A business that is subject to OFSI enforcement will be assessed against OFSI's own stated criteria. A business subject to an EU member-state authority will be assessed against that authority's practice – which may be more or less forgiving than OFSI's. For a cross-border group managing simultaneous exposure, the practical implication is that a single compliance programme is unlikely to be optimally calibrated for all relevant authorities unless it is explicitly designed to address the strictest applicable standard at each point of risk.

OFSI's position on voluntary self-disclosure (a VSD – the proactive reporting of an apparent breach to the regulator before it is otherwise discovered) is relevant here. OFSI treats a genuine, timely VSD as a significant mitigating factor in any penalty assessment. The EU framework again varies by member state. OFAC similarly treats timely VSD as a substantial mitigating factor, and the comparison is instructive: all three systems incentivise self-reporting, but the mechanics and the weight given to the disclosure differ, and the window for effective action is not uniform across regimes.

What are the key risk flags in a cross-regime sanctions risk assessment?

Certain structural and transactional features consistently generate heightened risk under OFSI's rules. Identifying them early is the purpose of a well-designed risk assessment.

  • Layered ownership structures: multi-tier holding chains that obscure beneficial ownership are the most common source of unexpected sanctions exposure. The OFSI control test reaches through layers; a clean first-level screen does not clear the risk.
  • Nominee and trust arrangements: where legal ownership is separated from economic interest, the analysis of control becomes fact-intensive. OFSI's rules require an assessment of who effectively controls the entity, not simply who appears on the share register.
  • Contractual control rights: veto rights, board appointment powers, and consent rights in shareholder agreements can constitute control even where the contractual party holds no shares. These are frequently missed in automated screening processes that focus on named entities.
  • Dual-nationality and third-country counterparties: where a counterparty is incorporated in one jurisdiction but managed from another, different regimes may apply simultaneously. A UK business dealing with such a counterparty must assess OFSI exposure; its US correspondent bank will assess OFAC exposure; any EU-regulated intermediary will assess its own member state's position. Each assessment must be conducted under the rules of the relevant regime.
  • Secondary-sanctions risk from US correspondent relationships: a transaction that falls outside OFSI's prohibitions may nonetheless expose a UK entity to secondary sanctions (US measures that can restrict non-US persons' access to the US financial system when they deal with designated persons under certain US programmes) if routed through a US correspondent bank or if a US person is involved in the transaction. A UK-only sanctions analysis is insufficient for any business with US financial relationships.
  • Crypto and virtual-asset transactions: OFSI's financial-sanctions rules apply to virtual-asset service providers (VASPs – firms providing exchange, transfer, or custody services for cryptoassets) registered in the UK. A risk assessment for a VASP must address both OFSI's specific guidance on crypto assets and the parallel requirements under OFAC's framework, which has taken enforcement action in the digital-asset sector.

In a recent matter, a financial institution conducting a portfolio review identified that a minority shareholder in a target company held contractual veto rights over material decisions. The shareholding, at well below 50 percent, had cleared automated screening against the OFAC threshold. The OFSI control analysis produced a different result. We assessed the position across both regimes, mapped the control rights against OFSI's published criteria, and advised on the steps required to restructure the position on a lawful basis before completion. The matter demonstrates that the two analyses must run in parallel, not sequentially.

Where does the OFSI reporting obligation fit into the risk-assessment cycle?

An often-under-appreciated element of the OFSI compliance obligation is the duty to report. Under SAMLA and the relevant thematic regulations, a person who knows or has reasonable cause to suspect that they hold or control funds or economic resources owned, held, or controlled by a designated person is required to tell OFSI. The reporting obligation is not triggered only by a completed transaction; it is triggered by knowledge or reasonable suspicion.

This has direct consequences for risk-assessment design. A risk assessment that identifies a potential OFSI issue must feed into a reporting protocol. The business must determine, as a matter of urgency, whether reasonable suspicion has arisen – and if it has, the reporting window is short. Delay in reporting, where an obligation exists, is itself a potential breach.

The interaction with OFAC is instructive here. OFAC does not impose a general obligation to report suspected sanctions exposure in the same way. OFAC's VSD mechanism is voluntary and incentivised, but it is not a mandatory reporting obligation in the same structural sense as OFSI's. For a cross-border group, this means that a risk-assessment event may trigger a mandatory UK reporting obligation even when no equivalent US obligation arises. The compliance protocols for the two regimes must be separated accordingly.

Record-keeping is the other side of this coin. OFSI requires that adequate records are maintained to demonstrate compliance with the financial-sanctions rules. In our experience, businesses frequently maintain transaction records but do not maintain the contemporaneous analysis that supported a clearance decision – meaning that, if a transaction is later questioned, the reasoning that justified it cannot be reconstructed. A well-designed risk assessment includes a record-keeping discipline that captures both the conclusion and the analytical steps that reached it.

How does the OFSI licensing process interact with a risk assessment?

Where a risk assessment identifies that a proposed transaction is, or may be, subject to OFSI's prohibitions, the immediate question is whether a licence is available. OFSI issues specific licences (case-by-case authorisations to conduct an otherwise-prohibited transaction) and operates a set of general licences (standing authorisations that permit defined categories of transactions without a separate application) under the relevant thematic regulations.

The assessment of whether a licence is required, and which type applies, is itself part of the risk-assessment exercise. A business that identifies a potential prohibition must determine: is a general licence already in force that covers this transaction? If not, does OFSI's published licensing policy indicate that a specific licence application has a realistic prospect of success? And what is the realistic timeline for a decision?

The comparison with OFAC's specific-licence process is instructive. Both authorities operate a case-by-case licensing system, and both require the applicant to demonstrate that the transaction serves a legitimate purpose. However, OFSI and OFAC licence decisions are not mutually binding. A business that holds an OFAC specific licence for a transaction has no automatic OFSI clearance, and vice versa. If a transaction requires authorisation from both authorities – which is frequently the case for transactions with a transatlantic dimension – applications must be made to each separately, and the timelines will not align.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time.

To discuss a licence application or to map the interaction between OFSI and OFAC authorisations, write to Calder & Vance at info@caldervance.com.

A common misconception: is a clean automated screen sufficient for OFSI compliance?

The most persistent myth we encounter in advising cross-border businesses on OFSI compliance is that a clean result from an automated screening tool against the UK Consolidated List constitutes adequate sanctions due diligence. It does not.

Automated screening tools match names and identifiers against designated-persons lists. They do not assess ownership structures, control relationships, or contractual arrangements. They do not evaluate secondary-sanctions risk. They do not apply the OFSI control test to entities that are not themselves listed. And they do not identify when a general licence condition has been breached or when a reporting obligation has been triggered.

The OFSI control test is a legal and factual analysis, not a database query. For counterparties with complex or opaque ownership, the test requires a structured review of corporate documentation, beneficial-ownership registers, shareholder agreements, and, in some cases, information obtained directly from the counterparty. A risk-assessment methodology that treats a clean automated screen as the end of the analysis is not compliant with OFSI's stated expectations.

This is not to diminish the value of automated screening. It is a necessary first step. But it is only a first step. The analytical work that follows – the ownership mapping, the control assessment, the secondary-sanctions check, the reporting-obligation determination – requires human judgment applied to specific facts. In our practice, we test client screening and due-diligence protocols against OFSI's published standards and identify the gaps that automated tools consistently miss.

The same critique applies, with different emphasis, to OFAC and EU screening. OFAC's mechanical threshold makes automation more tractable for the ownership question, but aggregation across multiple blocked persons, indirect holdings, and layered structures remains a manual exercise. The EU's control test, as applied across member states, is at least as fact-intensive as OFSI's. Businesses that rely on a single screening platform calibrated to one regime's thresholds are, in effect, applying a partial analysis to a multi-regime risk.

Decision map: which route applies to your cross-regime exposure?

The practical question for a compliance officer managing simultaneous OFSI and OFAC exposure is which analytical route governs a given situation. The answer depends on the facts of the transaction.

Where the counterparty is a UK-registered entity and the transaction is conducted in sterling through a UK-regulated institution, OFSI's rules are the primary applicable regime. The OFSI control test applies. A UK reporting obligation may arise. OFAC's rules apply to any US-person element of the transaction, including US correspondent-bank involvement.

Where the counterparty is incorporated outside the UK but the transaction involves a UK-regulated firm, OFSI's rules still apply to the UK firm's side of the transaction. The counterparty's home-jurisdiction rules apply separately. Neither analysis displaces the other.

Where the transaction has both a UK and a US dimension – a common scenario for cross-border commodity trades, financial products, or services involving US dollar clearing – both OFSI and OFAC apply. The stricter prohibition governs. A business cannot rely on one regime's clearance to satisfy the other.

Where the EU dimension is also present – a European subsidiary, an EU-regulated financial intermediary, or goods transiting an EU member state – the relevant Council Regulation applies to the EU-regulated entity. The EU control test must be applied separately, and its outcome may differ from both OFSI's and OFAC's.

In each scenario, the risk-assessment output must identify: which regimes apply, which entity within the group is the regulated party, what the applicable test is under each regime, what the result of applying that test is, and whether a reporting obligation, a licence application, or a VSD is required. A single-regime risk assessment is structurally inadequate for cross-border groups.

Related practices

Frequently asked questions

Where do the regimes diverge on sanctions risk assessment?
The principal divergence is in the entity-capture test. OFAC applies a mechanical 50 percent ownership threshold. OFSI and the EU extend to control, which requires a fact-specific analysis of voting rights, board-appointment powers, and contractual arrangements. OFSI and the EU also diverge from each other in drafting and enforcement practice, meaning that an EU clearance is not a proxy for OFSI clearance. Secondary-sanctions risk under OFAC adds a further layer that a UK-only or EU-only analysis does not address.
Which regime is stricter on sanctions risk assessment?
Strictness depends on the dimension being measured. OFSI's control test is broader than OFAC's ownership threshold, capturing entities where a designated person holds effective control without majority ownership. OFAC's secondary-sanctions regime imposes extraterritorial reach that neither OFSI nor the EU replicates directly. For a business with US-dollar correspondent relationships, the OFAC dimension often produces the most operationally constraining result. For a business managing board-level control risks, OFSI's and the EU's tests are more demanding. Where regimes apply simultaneously, the stricter prohibition governs.
What should a cross-border business do about sanctions risk assessment?
A cross-border business should, as a first step, map the regimes that apply to each material activity, counterparty category, and transaction type. It should then assess whether its current screening and due-diligence methodology is calibrated to the rules of each applicable regime – not only to the regime with which it is most familiar. Where gaps exist, it should document the remediation plan, ensure that reporting and VSD protocols are in place for each regime, and maintain contemporaneous records of the analysis supporting each clearance decision. Where the exposure is material, early involvement of specialist sanctions counsel is advisable before a transaction is completed rather than after.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.