Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

OFSI vs EU: Sanctions risk assessment: the key divergences

A London-headquartered financial institution is onboarding a new corporate client. The client's majority shareholder appears on an EU sanctions list but not on OFSI's Consolidated List of Financial Sanctions Targets. The compliance team asks the obvious question: does that EU designation create an obligation under UK law? The answer is not straightforward – and the risk assessment methodology a firm applies in that moment determines whether it catches the exposure or walks past it.

A sanctions risk assessment (a structured evaluation of a business's exposure to sanctions prohibitions across the counterparties, products, and jurisdictions it touches) must, as of mid-2026, be calibrated separately for OFSI and for the EU regime. The two authorities share a common origin in UN Security Council obligations and a broadly similar designation architecture, but they diverge in their ownership-and-control tests, their licensing postures, their reporting requirements, and their enforcement priorities. A single, unified risk assessment methodology that treats them as equivalent is likely to misstate exposure under at least one of them.

This analysis works through the key divergences systematically: the legal basis and governing authority for each regime; the ownership-and-control tests; the approach to risk scoring and due diligence; the licensing and reporting obligations; and the enforcement posture. It closes with practical risk flags and a decision sequence for cross-border businesses managing dual exposure.

What legal authority governs each regime, and why does that matter for risk assessment?

OFSI – the Office of Financial Sanctions Implementation, part of HM Treasury – administers UK financial sanctions under the Sanctions and Anti-Money Laundering Act (SAMLA) and the thematic regulations made under it. The EU regime is administered through Council Regulations, with designations made by Council Decision and directly applicable across all EU member states. Since the UK's departure from the EU, the two regimes have operated independently. The lists are not identical, the tests differ, and enforcement is carried out by separate authorities with distinct procedural rules.

Why does the legal basis matter for risk assessment? Because the jurisdictional trigger for each regime is different. OFSI's prohibitions apply to persons in the United Kingdom and to UK persons wherever they are located. The EU prohibitions apply to persons in EU territory, to EU nationals, and to transactions in EU currency where there is a sufficient connection to the EU. A business with operations in both jurisdictions – or with a euro-denominated facility and a UK parent – sits under both regimes simultaneously, and its risk assessment must map each trigger separately.

In our experience, compliance teams that built their screening and assessment programmes before 2021 sometimes retain a combined UK-EU category in their risk registers. That approach has not reflected the legal position since the UK's departure from the EU took full effect for sanctions purposes. The first step in any credible risk assessment is to confirm that the two regimes are treated as distinct legal environments.

How do the ownership-and-control tests diverge – and which generates more risk?

The ownership-and-control test is the single most consequential divergence between the two regimes for a standard counterparty risk assessment. Under OFSI, a non-listed entity is caught by the financial-sanctions prohibition when a designated person owns or controls it – but the UK ownership test requires that the designated person holds, directly or indirectly, more than 50 percent of the shares or voting rights, or has the right to appoint or remove a majority of directors. The EU test is framed in similar aggregation terms, but EU guidance places greater weight on the concept of control through other means: indirect influence over business decisions can bring a non-listed entity within scope even where the numerical ownership threshold is not clearly met.

That divergence is operationally significant. Consider a target company in which a designated person holds exactly forty-nine percent of the shares through an intermediate holding vehicle and exercises influence through contractual arrangements over supply, pricing, and key personnel. Under OFSI's predominantly numerical test, the target may not be treated as owned by the designated person. Under the EU's broader framing, the control element is more likely to bite. A risk assessment that applies only the OFSI ownership test to an EU-connected transaction will understate the risk.

Aggregation rules create further complexity. Both regimes aggregate holdings across multiple designated persons when assessing whether the threshold is met. A company held by two designated persons – one at thirty percent and one at twenty-two percent – is treated as owned by designated persons in aggregate. The arithmetic is the same; the underlying control analysis around the remaining shares differs in how each regime treats indirect influence. We regularly advise on counterparty structures where the numerical ownership analysis clears both thresholds but the control inquiry under EU guidance opens a different question entirely.

Where does the risk-scoring methodology diverge in practice?

Risk scoring – the process of assigning a risk rating to a counterparty, product, or jurisdiction and calibrating due-diligence intensity accordingly – looks superficially similar across the two regimes but diverges at the level of the factors each regulatory authority regards as material.

OFSI's published enforcement guidance and its approach to monetary penalties make clear that it treats knowledge and intent as relevant to the severity of an enforcement response but not to whether a prohibition is breached. A breach is a strict liability matter; the risk-scoring implication is that a firm cannot reduce its legal exposure by demonstrating that it was unaware of a designated person's interest. The risk assessment must therefore focus on detection – what processes would have identified the interest? – rather than on the subjective risk appetite of the business.

The EU approach to risk scoring is informed by both the Council Regulation text and the guidance issued by the European Banking Authority and national competent authorities. EU supervisory guidance has over time placed increasing weight on sectoral and geographical risk factors: the nature of the goods or services, the jurisdictions involved, the payment routes, and the use of intermediaries. A well-designed risk assessment under the EU regime therefore assigns specific risk drivers to sectors and geographies, not only to named counterparties.

The practical divergence is this. An OFSI-oriented risk assessment is heavily list-centric: screen the counterparty, screen the ownership chain, confirm the list status, escalate where there is a match. An EU-oriented risk assessment layers sector risk and geography risk on top of that list-centric screen. For a business operating across both regimes, the EU layer will almost always be the broader one – and calibrating the OFSI assessment to EU standards is both permissible and advisable where the operational cost is manageable.

The position above covers the standard methodology. Your specific facts – the sectors your business touches, the jurisdictions through which payments flow, the structure of your counterparty relationships – will determine which risk drivers are most material in your case. For a review of your risk assessment approach under both regimes, contact Calder & Vance at info@caldervance.com.

How do licensing and authorisation routes differ between OFSI and the EU?

Both regimes provide for licensing – a mechanism by which an otherwise prohibited transaction is specifically authorised – but the licensing architectures differ in ways that affect the risk calculus for a cross-border business.

OFSI issues specific licences (case-by-case authorisations to conduct an otherwise prohibited transaction under defined conditions) and, in certain programmes, general licences covering defined categories of activity. OFSI's licensing function is centralised at HM Treasury. The grounds on which OFSI will consider granting a licence are set out in the relevant thematic regulations and include humanitarian grounds, legal expenses, pre-existing contractual obligations, and other specified purposes. Licence decisions are not automatic, and OFSI has emphasised that applying for a licence does not suspend the prohibition while the application is pending.

The EU licensing architecture is administered at member-state level. Each member state's national competent authority has jurisdiction over persons and transactions within its territory, and the grounds for licensing follow the Council Regulation text but may be applied with varying degrees of latitude by different national authorities. A business with operations in, say, three EU member states may need to engage with three separate competent authorities if it is seeking authorisation for a multi-jurisdictional transaction. There is no single EU licensing window equivalent to OFSI's centralised process.

For risk assessment purposes, the licensing divergence matters in two ways. First, a business that holds an OFSI licence has no automatic protection under the EU regime for the same transaction, and vice versa. A transaction licensed by OFSI must still be assessed for EU compliance, and the applicable EU competent authority must separately authorise it if required. Second, the variance in national-authority practice within the EU creates a risk that a transaction authorised in one member state might be treated differently if executed through another.

What are the reporting and record-keeping obligations, and where do they create divergent risk?

Reporting and record-keeping generate some of the most practically significant divergences for a cross-border compliance programme.

Under the UK regime, relevant firms – broadly, financial institutions and certain other regulated businesses – are required to report to OFSI as soon as practicable after they know or have reasonable cause to suspect that they hold funds belonging to, or are dealing with, a designated person. This obligation sits alongside the existing suspicious-activity-reporting obligations under the Proceeds of Crime Act. The two reporting channels are distinct, and a report to one authority does not substitute for a report to the other. OFSI's guidance on reporting has been updated periodically to address questions about the timing and content of a report; verify the current position before relying on it.

The EU reporting obligation is structured similarly in its basic architecture – report as soon as possible where a firm knows or suspects that funds belong to a designated person – but the national competent authority to which the report is made, and the precise procedural requirements, differ across member states. In some jurisdictions the reporting timeframe is defined with greater precision in national implementing legislation; in others it follows the general "as soon as practicable" standard. A firm with branches in multiple EU member states must map the reporting obligations of each relevant national regime.

Record-keeping obligations under both regimes require firms to retain transaction records for a defined period, but the standard period differs. In our experience, compliance programmes that adopt the higher standard across all jurisdictions – where operationally feasible – reduce the risk of a record-keeping gap during an enforcement review. If a transaction has already been flagged by a counterparty or by an internal screening alert, or if a regulatory enquiry is underway, an early review of the record-keeping position can preserve options that narrow with time. Contact us at info@caldervance.com to discuss.

How does enforcement posture differ, and what does that mean for a dual-exposure business?

Enforcement posture – the approach each authority takes to identifying, investigating, and penalising breach – is the downstream product of the risk assessment. Where a business understates its exposure, an enforcement action is the mechanism by which that understatement becomes consequential.

OFSI's enforcement approach has developed significantly since it began issuing monetary penalties under SAMLA. OFSI has confirmed that it takes into account factors including the seriousness of the breach, the benefit obtained, and whether the person self-disclosed. OFSI's guidance on voluntary self-disclosure makes clear that a VSD (voluntary self-disclosure to a regulator) can be a material mitigating factor in penalty determination. That creates a concrete incentive structure: a well-functioning risk assessment that catches a potential breach early preserves the option of self-disclosure, which may reduce the ultimate penalty significantly.

EU enforcement is carried out at member-state level, and the variance in enforcement intensity across member states is real and documented. Some national competent authorities have active enforcement programmes with publicly announced penalty decisions; others have historically been less active. The Court of Justice of the European Union and the EU General Court are the primary judicial review forums for EU designation challenges and for annulment actions. A business exposed to enforcement in multiple EU jurisdictions simultaneously faces potentially divergent procedural requirements and sanction levels – a risk that a unified, EU-level risk score can obscure.

The practical implication for a dual-exposure business is that its risk assessment should model the enforcement posture of both OFSI and the relevant national competent authority (or authorities) within the EU. Assuming that enforcement will follow the same pattern in both jurisdictions produces a systematically incomplete risk picture. Where the two regimes are calibrated differently – OFSI more centralised and numerically predictable; the EU more distributed and variable – the risk assessment must capture that variance rather than average it away.

What risk flags should a cross-border business prioritise in a dual OFSI-EU assessment?

The risk flags below are drawn from our cross-border practice and reflect the points at which a combined OFSI-EU risk assessment most frequently fails to capture actual exposure.

The first flag is list divergence. Because OFSI and the EU Council make independent designation decisions, a person may be designated under one regime and not the other. Risk assessments that screen against only one list – typically because the business's primary operations are in one jurisdiction – will miss the gap. A robust counterparty screen should run both lists at the outset and maintain both checks on a periodic refresh cycle.

The second flag is currency exposure. EU sanctions apply to euro-denominated transactions where there is a sufficient connection to the EU, regardless of where the transacting parties are incorporated. A UK business making payments in euro through a eurozone correspondent bank creates EU nexus. Its risk assessment must include the EU prohibitions even if the counterparty and the product are both non-EU.

The third flag is the control question. As discussed above, the EU's broader control analysis can catch non-listed entities that the OFSI numerical test would not. Any counterparty subject to a control inquiry under EU guidance should be treated as higher risk under OFSI as well, even if OFSI's ownership test does not formally require it. This is a conservative but defensible position.

The fourth flag is the licensing assumption. Firms sometimes proceed with a transaction on the assumption that a licence can be obtained quickly if needed. Neither OFSI nor the relevant EU competent authority is obliged to grant a licence, and neither publishes binding timelines for licence decisions. A risk assessment that treats licensing as a routine backstop rather than as an uncertain, time-consuming process will systematically underweight the risk of a position where the licence is refused or delayed.

The fifth flag is the secondary-sanctions dimension. OFSI and the EU impose their own primary sanctions obligations. However, OFAC's secondary-sanctions provisions – which can restrict access to the US financial system for non-US entities that deal with certain designated persons – operate independently of both. A European business engaged in a transaction that would be lawful under both OFSI and EU rules may still face secondary-sanctions risk under the applicable OFAC programme. A credible cross-border sanctions risk assessment must address all three regimes, not only the two primary ones.

Are your internal screening and ownership-chain analysis processes designed to catch each of these flags? If you are reviewing your risk assessment methodology now, that is the right question to start with.

Related practices

Frequently asked questions

Where do the regimes diverge on sanctions risk assessment?
The most significant divergences lie in the ownership-and-control test, the licensing architecture, and the enforcement posture. OFSI applies a primarily numerical ownership threshold and administers licensing centrally. The EU applies a broader control analysis, licenses transactions through national competent authorities across member states, and enforces at national level with variable intensity. List divergence – designations under one regime but not the other – is also a consistent practical issue. A risk assessment that does not map these divergences separately will produce an incomplete exposure picture.
Which regime is stricter on sanctions risk assessment?
Neither regime is categorically stricter across all dimensions. The EU's control analysis is broader than OFSI's ownership test and more likely to capture non-listed entities. OFSI's enforcement has become increasingly active and its centralised structure produces greater predictability for UK-based firms. For a business with euro-denominated payment flows and EU-jurisdiction counterparties, the EU regime will usually generate the higher compliance burden. For a UK-registered firm with purely domestic operations, OFSI will be the primary regulatory concern. The honest answer is that the stricter regime depends on the specific transaction, the structure of the counterparty, and the jurisdictions in play.
What should a cross-border business do about sanctions risk assessment?
A cross-border business should first confirm that its risk assessment treats OFSI and the EU as legally distinct regimes, not as a single programme. It should then map the specific divergences – ownership-and-control analysis, list screening against both lists, licensing routes in each jurisdiction, and reporting obligations by national authority. Secondary-sanctions risk from OFAC should be layered on top. Where a transaction involves both UK and EU nexus, a dual-regime legal review at the assessment stage is the most effective way to manage the residual uncertainty. Periodic refresh – at least annually and after any significant regulatory change – is essential in an environment where designation decisions and guidance are updated frequently.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.