A financial institution headquartered in Singapore closes a trade-finance transaction with a counterparty it has screened against the United Nations Consolidated List and its own internal watchlists. Three weeks later, a correspondent bank in New York flags the transaction under US secondary-sanctions rules. The Singapore entity believed it had done everything right. It had – under Singapore law. But the question it should have asked first was whether US, EU, or UK rules also applied to its conduct.
Sanctions risk assessment under Singapore is governed primarily by the Monetary Authority of Singapore and the relevant domestic instruments, including the United Nations Act and the Terrorism (Suppression of Financing) Act. The domestic regime requires firms to screen against the applicable consolidated lists and to apply a risk-based approach calibrated to their exposure. That is the floor. Extraterritorial reach from OFAC, OFSI, and the EU Council regulations routinely raises the practical ceiling far above it.
This analysis maps where the Singapore regime sits relative to OFAC, OFSI, and the EU on the core elements of a sanctions risk assessment: governing authority, scope, ownership and control tests, the risk-based approach, reporting obligations, and enforcement posture.
What governs sanctions risk assessment in Singapore?
The primary legal basis for financial-sanctions compliance in Singapore is the United Nations Act, which gives domestic legal force to UN Security Council resolutions, and the Terrorism (Suppression of Financing) Act, which implements the obligations arising from counter-terrorism measures. The Monetary Authority of Singapore – MAS – is the competent authority for financial institutions. MAS issues notices, guidelines, and circulars that set the expected standard for sanctions risk assessment (the process by which a firm identifies, measures, and mitigates its exposure to sanctions-related risk).
MAS requires financial institutions to implement policies and procedures that align with a risk-based approach. This means a firm must assess the nature and level of its sanctions exposure before calibrating its controls. The obligation is not a binary screening exercise: MAS expects firms to consider the products they offer, the clients they serve, the channels they use, and the geographies they touch. That multi-factor calibration is what separates a compliant programme from a simple list-check.
In our experience advising financial institutions and trading firms across the Asia-Pacific region, the MAS regime is capable and increasingly assertive. But it operates against a narrower list universe than OFAC or OFSI. Singapore's mandatory screening universe is anchored in UN designations. It does not automatically incorporate US, UK, or EU unilateral lists. That is the structural divergence that catches cross-border businesses most frequently.
How does the Singapore risk-based approach differ from OFAC and OFSI?
The risk-based approach under MAS shares its conceptual DNA with the five-element compliance programme that OFAC describes in its guidance and with the principles underlying OFSI's enforcement guidance in the United Kingdom. All three frameworks ask: does this firm understand its exposure, has it designed controls proportionate to that exposure, and does it test whether those controls work? The architecture looks similar on paper. The content diverges sharply in practice.
OFAC's approach is fundamentally list-driven and rule-based. The SDN List (OFAC's list of Specially Designated Nationals and blocked persons) must be screened against for virtually every US-nexus transaction. The 50 percent rule (OFAC's rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked) operates automatically, regardless of whether the entity itself appears on any list. A firm cannot satisfy OFAC by confirming a counterparty is not named; it must map the ownership chain.
OFSI and the EU apply an ownership and control test (the UK and EU standard for determining whether a non-listed entity is caught through a listed person's direct or indirect ownership or effective control). The control limb is wider than OFAC's mechanical ownership test. A listed person who can direct the commercial policy of an entity may cause that entity to be treated as covered, even without majority ownership. This distinction matters for Singapore firms dealing with EU or UK counterparties, because a structure that passes the OFAC ownership screen may still fail the EU or UK control test.
Singapore's domestic standard applies an ownership and influence analysis, but the thresholds and the approach to control are calibrated to the UN framework, which is itself narrower than the autonomous US, UK, and EU lists. A Singapore compliance programme built only around MAS guidance will therefore under-screen for US and EU autonomous designations unless the firm has consciously layered those lists into its process.
Which sanctions lists must a Singapore firm screen against?
The mandatory floor under Singapore law requires screening against the lists published under UN Security Council resolutions that have been given domestic force. This means the UN Consolidated List, the ISIL (Da'esh) and Al-Qaida list, and any lists activated under specific Security Council regimes that MAS has implemented. MAS publishes a consolidated list on its website that firms are expected to use as a baseline.
The mandatory floor is not the practical ceiling for most Singapore firms with cross-border business. Whether additional lists must be screened depends on the firm's nexus to other jurisdictions. Relevant triggers include:
- US dollar clearing or correspondent banking relationships with US institutions: firms in this position are exposed to OFAC's SDN List and the sectoral restrictions regardless of where they are incorporated.
- Transactions touching EU-regulated entities, EU-registered goods, or EU-origin technology: the EU consolidated list and, where applicable, EU sectoral restrictions are in play.
- UK-currency or UK-counterparty exposure: OFSI's consolidated list and the UK autonomous designations apply.
- Trade in goods subject to export controls: the relevant export-control lists of the exporting jurisdiction – including the US Commerce Control List, the EU dual-use list, and Singapore's own Strategic Goods Control regime – must be checked separately from financial-sanctions lists.
We regularly advise Singapore-headquartered clients whose internal policy references only the MAS list. When we map their transaction flows against their correspondent-bank relationships and their goods and services, the gap between their listed screening universe and the universe that actually applies to their business is substantial. The risk sits in that gap.
Where do the ownership and control tests create the sharpest divergence?
The ownership and control question is where the divergence between Singapore and the major Western regimes creates the most acute practical risk. Under OFAC, 50 percent or more aggregate ownership by blocked persons triggers automatic blocking, regardless of the ownership tier at which the blocked person sits. A structure with two listed minority shareholders who together hold fifty percent is blocked under OFAC. A structure where a listed person holds forty-nine percent is not automatically blocked – though OFAC may still pursue it on other grounds.
Under OFSI and the EU rules, the control test adds a layer above and beyond ownership. Effective control can arise from the right to appoint the majority of the board, from veto rights over commercial decisions, or from economic dependence on a listed person. In our practice, the control analysis under the EU standard in particular requires a structured assessment of shareholder agreements, management arrangements, and financial terms – not a simple percentage check.
Singapore's framework does not apply the OFAC 50 percent rule as a domestic mandatory standard. It does not automatically incorporate the EU control test. A Singapore firm assessing a prospective counterparty therefore faces a situation in which the entity may be clean under domestic rules and blocked under one or more applicable foreign rules simultaneously. The cross-border risk assessment must resolve which rules apply to each transaction and then apply the stricter prohibition where conflicts arise.
This is not a theoretical edge case. In a recent matter, a Singapore-based commodity trading firm assessed a proposed joint-venture partner against the MAS consolidated list and found no hit. A parallel review run on behalf of the firm's European financing bank under EU rules identified a listed person holding a controlling position through a series of intermediate entities – none of which appeared on any list. The transaction required restructuring before the financing could proceed. The divergence between the Singapore and EU standards created the problem; the cross-regime review identified it in time.
How does extraterritorial reach from OFAC and OFSI affect Singapore firms?
Extraterritorial reach is the feature of US and UK sanctions that Singapore firms most frequently underestimate. OFAC's rules apply to US persons wherever located, to transactions processed through the US financial system, and – for certain comprehensive programme transactions – to any person who causes a US person to violate the rules. The last category is the source of secondary-sanctions risk for Singapore firms with no physical US presence.
Secondary sanctions (measures that create exposure for non-US persons who conduct significant transactions with parties already subject to US primary sanctions) are not a formal part of Singapore domestic law. Singapore firms are not directly subject to OFAC jurisdiction in most cases. But their US correspondent banks are. A Singapore firm that routes a transaction through a US dollar account at a US bank causes that bank to process a payment. If the payment involves a designated party or a blocked transaction, the US bank faces liability – and will, in practice, exit the relationship rather than carry the risk. The practical effect on the Singapore firm is the same as a direct prohibition.
OFSI's extraterritorial reach under SAMLA – the Sanctions and Anti-Money Laundering Act – is structured differently. OFSI's jurisdiction extends to conduct by UK persons and conduct connected with the United Kingdom, including transactions processed through UK financial infrastructure or involving UK-registered entities. For Singapore firms, the exposure arises most commonly where the counterparty or the financing bank has a UK connection, or where the goods are of UK origin.
The EU Blocking Regulation adds a further layer for Singapore firms that are EU subsidiaries or that have EU-regulated parents. The Blocking Regulation prohibits EU persons from complying with certain foreign (principally US) extraterritorial sanctions without authorisation. This creates a compliance conflict for Singapore entities within EU corporate groups: following OFAC guidance may put the EU parent in breach of the Blocking Regulation, and following the Blocking Regulation may put the US-correspondent relationship at risk.
Managing these conflicts requires a clear analysis of which entity is the primary obligor for each transaction, what the applicable rules require of that entity, and where the rules pull in opposite directions. That analysis is not achievable through a single-jurisdiction compliance programme.
The position above covers the structural issues. Your facts – the transaction type, the counterparty's ownership, the currency and correspondent bank, the nature of the goods or services – determine which of these regimes actually applies to your business. For an assessment of your extraterritorial exposure, contact Calder & Vance at info@caldervance.com.
What are the reporting and record-keeping obligations under Singapore and comparator regimes?
Singapore financial institutions are required to report knowledge or suspicion of sanctions violations to the relevant authorities, including MAS and, for terrorism-financing matters, the Suspicious Transaction Reporting Office. The reporting obligation arises when a firm identifies a match or has reasonable grounds to suspect a connection to a designated party or a prohibited transaction. MAS expects firms to maintain records that allow them to demonstrate the basis for their screening decisions and their reporting.
Under OFAC rules, US persons and entities are required to report blocked transactions and to maintain records for a defined period. OFSI requires UK persons to report to OFSI when they hold funds or economic resources belonging to a designated person, and to provide information when requested. The EU regime imposes equivalent reporting obligations under the relevant Council regulations, with the competent authority in each member state as the recipient.
The record-keeping expectations across these regimes converge on a common principle: the firm must be able to reconstruct its decision-making after the fact. What list was screened? What version of the list? Who made the decision? On what basis was a hit dismissed as a false positive? For how long are those records kept? Under OFAC practice, a five-year record-keeping period is the standard applied to most transactions. OFSI and the EU regimes apply comparable record-keeping periods under their respective instruments.
For a Singapore firm operating under MAS guidance, the practical question is whether the firm's record-keeping infrastructure – its screening logs, its escalation records, its transaction documentation – is capable of satisfying a query from OFAC, OFSI, or an EU competent authority as well as from MAS. In our experience, the answer is often no. MAS-focused programmes store records in formats and for periods calibrated to domestic requirements. When a US or UK query arrives, the firm cannot produce the documentation that the foreign authority expects.
What are the enforcement postures and penalty consequences?
MAS has moved toward a more active enforcement posture over recent years. It has the power to impose civil penalties, to restrict or revoke licences, and to refer cases for criminal prosecution under the underlying legislation. MAS enforcement action in the sanctions and financial-crime space has signalled an expectation that financial institutions will treat compliance as a substantive obligation rather than a box-checking exercise.
OFAC's civil penalty framework imposes a base penalty for each violation. For wilful or egregious conduct, OFAC applies an enhanced methodology that can produce penalties considerably larger than the base. The penalty can be calculated on a per-transaction basis, meaning that a programme failure affecting many transactions can generate a large aggregate exposure. OFAC also applies a mitigating framework that gives credit for voluntary self-disclosure, a strong prior compliance record, and cooperation.
VSD (voluntary self-disclosure to OFAC) is a well-established mechanism that, when handled correctly, can materially reduce the penalty outcome. OFSI operates a comparable licensing and reporting regime in the UK, with OFSI's enforcement guidance setting out the factors that increase or reduce a civil penalty. Under both regimes, early legal advice – before the disclosure is made – is critical to preserving the benefit of the disclosure and avoiding procedural errors that can complicate the case.
The EU enforcement regime is applied at the member-state level, meaning that the competent authority in the relevant EU member state (rather than a central EU body) handles enforcement. This fragmentation means that the enforcement posture and penalty levels differ across member states, even for violations of the same Council regulation.
A Singapore firm that faces a query from any of these authorities will be assessed against the standards of the authority that is asking the question – not the standards of MAS. Understanding that dynamic in advance, and designing a programme that can demonstrate compliance to any of the relevant authorities, is the practical objective of a cross-regime sanctions risk assessment.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.
Common myths and risk flags in Singapore sanctions risk assessment
The most persistent myth we encounter is that a Singapore business with no US offices, no US shareholders, and no US assets has no OFAC exposure. This is incorrect. US dollar transactions, US bank correspondent relationships, US-person employees, and goods that incorporate US-origin technology can each create a nexus that brings OFAC rules into the picture. The nexus test is functional, not territorial.
A related misconception is that screening the MAS consolidated list satisfies the firm's sanctions obligations across all its business lines. It satisfies the domestic floor. It does not satisfy the obligations that arise from a USD correspondent relationship, an EU financing bank, or UK-origin goods in the supply chain. The compliance counsel question is not "what does MAS require?" but "what does every applicable regime require, given how this business operates?"
Risk flags that we identify most frequently in Singapore-headquartered programme reviews include:
- Screening only against the MAS list when the transaction flow touches US dollar clearing.
- No ownership-chain mapping beyond the first layer of a counterparty structure.
- Reliance on a counterparty's self-certification without independent verification of beneficial ownership.
- No escalation protocol for partial-name matches or fuzzy-logic alerts from screening tools.
- Record-keeping that does not capture the list version screened or the basis for dismissing an alert.
- A compliance programme that has not been tested since the underlying regulatory guidance was last updated.
Each of these gaps creates a discrete enforcement risk under one or more of the applicable regimes. A structured sanctions risk assessment – one that maps each business line against each applicable regime and tests the controls that are in place – is the mechanism for identifying and closing them.
Related practices
- Sanctions compliance audit and testing – structured testing of screening logic, escalation, and record-keeping controls across multi-jurisdiction programmes.
- Trade finance and US export controls – analysis of how BIS and the EAR apply to trade-finance transactions and supply-chain structures.
- Trade finance controls: BIS/EAR vs EU – comparative analysis of the US and EU export-control regimes for trade-finance practitioners.