A multinational procurement team has mapped its Tier 1 suppliers with care. Screening is automated, ownership charts are updated quarterly, and the compliance officer is confident. Then an audit surfaces a Tier 3 raw-materials supplier whose ultimate beneficial owner appears on both the OFAC SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and the EU consolidated list – but under different names, with different ownership percentages recorded in each regime's files. The deal flow continues. The exposure does not.
Supply-chain sanctions mapping under OFAC and the EU starts from a common objective – identifying prohibited counterparties before a transaction completes – but diverges sharply on the ownership test, the extraterritorial reach, the licensing architecture, and the record-keeping obligations that follow. As of January 2026, OFAC applies a mechanical 50 percent or more aggregate ownership threshold; the EU applies an ownership-and-control test that can catch entities where ownership alone falls short. A business operating across both regimes must satisfy both simultaneously, and the stricter prohibition governs at every decision point.
This analysis maps the principal divergences across six dimensions: the ownership and control tests, extraterritorial reach, the licensing and authorisation architecture, due-diligence obligations, enforcement posture, and the practical workflow implications for cross-border supply chains.
What is supply-chain sanctions mapping, and why does the OFAC–EU divergence matter?
Supply-chain sanctions mapping is the structured process of identifying every node in a supply chain – supplier, sub-supplier, logistics provider, freight forwarder, payment intermediary – that may be owned, controlled, or otherwise connected to a sanctioned person or entity, and then assessing whether that connection triggers a legal prohibition under the applicable regime.
The process is not simply a list-screening exercise. Screening against the SDN List or the EU consolidated list identifies direct hits. Supply-chain mapping goes further: it traces the beneficial-ownership chain behind each node, applies the relevant ownership and control tests, identifies secondary-sanctions exposure even where no direct hit exists, and produces a documented record of the analysis. That record matters both as evidence of good-faith compliance and as the foundation for a licensing or authorisation application if a route forward exists.
The divergence between OFAC and the EU matters for two reasons. First, many supply chains run through entities incorporated in the United States, the European Union, or third-country jurisdictions where both regimes simultaneously apply. A European subsidiary of a US parent is subject to US sanctions by virtue of being a US-owned entity, and subject to EU sanctions by virtue of being incorporated in an EU member state. Second, the regimes apply different thresholds and tests, so an entity that is not captured under one regime may nonetheless be blocked under the other. Compliance counsel advising on a transaction must map the analysis through each regime independently and then apply the stricter result.
In our cross-border practice, the most common failure mode is not a missed SDN hit – automated screening catches those. It is a failure to apply the EU control test to entities that sit just below the OFAC 50 percent threshold, or a failure to recognise that a US parent's ownership of a European affiliate creates SDN taint that the affiliate's EU-only screening would not surface.
How do the OFAC and EU ownership and control tests diverge?
The OFAC ownership test is mechanical: any entity owned 50 percent or more in the aggregate by one or more SDN-listed persons is itself treated as blocked, whether or not that entity appears on the SDN List. The test runs through the ownership chain – if a listed person owns 60 percent of Company A, and Company A owns 60 percent of Company B, Company B is blocked. The test does not turn on control, on management, on economic benefit, or on intention. Ownership percentage alone drives the result. OFAC's guidance under IEEPA makes this explicit.
The EU test is wider and more fact-sensitive. Under the relevant Council regulations, an entity is caught not only where listed persons own it at the applicable threshold but also where listed persons control it – and control can arise through rights, contracts, or other means that fall short of majority ownership. In our experience, this control limb catches arrangements that an OFAC ownership analysis would miss entirely: nominee structures, joint-venture agreements giving a listed person a veto over strategic decisions, or loan agreements with covenants that confer effective economic dominance.
The practical implication is that a business conducting supply-chain mapping cannot stop its analysis at the 50 percent line. An entity owned 45 percent by a listed person is not automatically blocked under OFAC – but the remaining analysis, covering the control test and the EU position, may well conclude that it is blocked under EU law. What happens when the OFAC and EU tests produce different answers? The obligation is to satisfy both: if either regime blocks the transaction, the transaction cannot proceed without a licence or authorisation from the relevant authority.
Aggregation is a further point of divergence in practice. OFAC aggregates holdings across all listed persons, so two listed persons holding 26 percent each reach the threshold together. The EU rules approach aggregation similarly for ownership but the control analysis remains entity-specific and more contextual. Cross-border mapping must therefore run the aggregation calculation for both regimes, because the composition of the listed-person group can differ between the SDN List and the EU consolidated list – the same individual may be listed under one programme but not the other.
Where does extraterritorial reach create asymmetric risk in supply chains?
OFAC's extraterritorial reach is a defining feature of US sanctions that the EU, in its primary sanctions posture, does not replicate. US primary sanctions apply to US persons – citizens, permanent residents, US-incorporated entities, and entities operating within the United States – regardless of where a transaction occurs. US secondary sanctions go further: they target non-US persons who engage in activity with designated parties, even where no US nexus exists in the transaction itself, by threatening the loss of access to the US financial system or market.
The EU does not impose secondary sanctions in the US sense. EU sanctions bind EU persons and entities, and EU-incorporated companies wherever they operate. A non-EU company transacting with a listed person does not automatically breach EU sanctions. However, that non-EU company may be a supplier into the EU supply chain of a business that is subject to EU rules, and the EU party in that chain bears the obligation to ensure its counterparties do not create prohibited exposures.
This asymmetry creates a two-level problem for supply-chain mapping. At the first level, a US parent conducting mapping must assess whether any node in the supply chain creates US-person liability – and because US secondary sanctions reach non-US entities transacting in non-US markets, that assessment must extend to nodes with no apparent US connection. At the second level, a European business sourcing from the same supply chain must assess EU-person liability – a narrower jurisdictional perimeter, but with a wider ownership-and-control test. The union of those two analyses is the minimum scope of a properly conducted cross-border mapping exercise.
We regularly advise on situations where a European business has concluded, correctly, that it has no EU-law exposure to a particular supply-chain node, but has failed to assess whether its US parent's participation in funding or directing the procurement creates secondary-sanctions risk. The answer is almost always that the parent's involvement brings the full OFAC analysis back into scope. Have you assessed whether your group structure imports a US-person analysis into what appears to be a purely European transaction?
How do the licensing and authorisation architectures differ across the two regimes?
Where supply-chain mapping surfaces a prohibited connection, the question becomes whether a licence or authorisation permits the transaction to continue. OFAC and the EU both operate licensing architectures, but the structure, terminology, and practical timelines differ.
OFAC issues two categories of authorisation. A general licence (a standing authorisation that permits a defined category of transactions without a separate application) covers a range of humanitarian, journalistic, official-government, and wind-down transactions. A specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) requires a formal application to OFAC, setting out the parties, the goods or services, the nexus to the sanction programme, and the policy basis for relief. OFAC processing times vary by programme and volume; applicants should not assume approval on any timeline and should plan transactions accordingly.
The EU licensing architecture operates at member-state level. Each member state's competent authority issues licences under its national implementation of the relevant Council regulation. This means that a business with operations in multiple EU member states may need parallel applications in each jurisdiction, and that the standards for assessment and the processing timelines can differ between member states even under the same Council regulation. In our practice, this fragmentation is a consistent source of delay for businesses that discover a supply-chain problem late in a transaction.
One cross-cutting point applies to both regimes: a licence application does not suspend the underlying prohibition. While the application is pending, the transaction remains prohibited. Supply-chain mapping that surfaces a potential issue mid-transaction must therefore immediately assess whether a wind-down or pause is available under an existing general licence, or whether the transaction must stop until a specific licence is granted. The earlier mapping identifies the issue, the more options remain open.
For a business that has already contracted and then discovers a supply-chain problem, the decision matrix runs roughly as follows. Where a relevant general licence covers the situation, the business can proceed within the licence's conditions immediately, provided it documents the analysis. Where no general licence applies, the business must either suspend performance and apply for a specific licence, or terminate the contract and notify the relevant authority of the blocked property or interest. A mis-step at this junction – continuing to perform without a licence, or failing to report blocked property within the applicable window – creates the enforcement exposure. That window is short; verify the current reporting requirement before relying on any stated deadline.
What due-diligence obligations does each regime impose on supply-chain participants?
Neither OFAC nor the EU mandates a specific supply-chain due-diligence standard by name, but enforcement practice and regulatory guidance from both authorities make clear that a business is expected to exercise reasonable care proportionate to the risk profile of its supply chain. What that means in practice has been shaped by enforcement patterns – and the records of enforcement proceedings on both sides of the Atlantic indicate that "we screened the direct counterparty" is not, by itself, sufficient for a high-risk supply chain.
OFAC's enforcement guidelines adopt a mitigating-factor analysis. A business that has implemented a risk-based compliance programme (a structured system for identifying, assessing, and reducing sanctions exposure proportionate to the firm's business model) stands in a materially better position when an apparent violation is discovered. The programme should, at minimum, cover management commitment, risk assessment, internal controls, testing and auditing, and training – the five elements that OFAC's guidance identifies as essential. A supply-chain mapping exercise that is documented, regularly updated, and escalated when it produces a hit contributes to several of those elements simultaneously.
The EU compliance framework operates similarly in substance, though the formal expression differs. EU guidance and enforcement practice emphasise proportionality: a large trading house sourcing from high-risk jurisdictions is held to a higher standard of investigation than a small manufacturer sourcing from established European suppliers. Record-keeping obligations under the relevant Council regulations require businesses to retain documentation of transactions, holdings, and due-diligence steps, typically for a multi-year period – verify the applicable period for the regime in question before relying on any specific figure.
The record-keeping dimension of supply-chain mapping is often underestimated. The documentation of a mapping exercise – the ownership chart, the screening records, the analysis of ambiguous cases, the rationale for a decision to proceed or to seek a licence – is the primary defence in an enforcement enquiry. In our experience, businesses that have conducted substantive mapping but failed to document it systematically are in a weaker position than the quality of their actual analysis would warrant. Documentation is not administrative overhead; it is the compliance record.
How do enforcement postures differ, and what risk flags should supply-chain managers watch for?
OFAC's enforcement posture is among the most active of any sanctions authority globally, with a track record of civil penalty actions against businesses that have transacted through supply chains without adequate mapping. OFAC's enforcement guidelines assess apparent violations across a matrix of factors – egregious or non-egregious, wilful or reckless versus inadvertent – and a VSD (voluntary self-disclosure to a regulator) of a non-egregious violation typically receives a reduction in the base civil penalty amount. The key word is "non-egregious": a supply-chain failure that is systemic, or that involves recklessness, is assessed at a materially higher base.
EU enforcement occurs at member-state level, and the intensity and speed of enforcement varies between jurisdictions. Some member states have active, well-resourced enforcement programmes; others are at an earlier stage of building enforcement capacity. This divergence in enforcement intensity does not mean that EU sanctions are less legally binding – the Council regulations have direct effect across all member states – but it does mean that the practical enforcement risk of a supply-chain failure is not uniform across the EU. A business with operations in multiple member states should not calibrate its compliance posture to the least active jurisdiction.
The risk flags that supply-chain managers should treat as triggers for enhanced mapping include: a counterparty with complex or opaque beneficial ownership; a supply-chain node in a jurisdiction associated with a major sanctions programme; a payment routed through a jurisdiction whose financial institutions are subject to correspondent-banking restrictions; a goods or technology category that appears on a dual-use or military-use control list; and any change in counterparty ownership – a merger, an acquisition, or a private-equity entry – that has not been reflected in the most recent ownership chart.
Is your supply-chain mapping triggered only at the point of contracting, or does it run continuously against your existing supplier base? A counterparty that was clean on screening twelve months ago may have changed ownership since then, and a new designation can be added to either the SDN List or the EU consolidated list without advance notice. The mapping exercise must be treated as a continuous programme, not a transaction-by-transaction checklist.
In a recent matter, a manufacturing business in the technology sector discovered, through a periodic re-screening of its existing supply base, that an intermediate component supplier had been acquired by a holding company whose ultimate beneficial owner had been designated under a major OFAC programme. The acquisition had closed without the sanctions position being assessed. We assisted the client in scoping the apparent violation, advising on voluntary self-disclosure, and restructuring the supply relationship on a compliant basis. The matter was resolved without escalation to a penalty proceeding, in part because the voluntary disclosure and the quality of the remediation record supported a mitigating-factor analysis. No outcome of that kind is guaranteed, but early identification and a documented response are consistently the most important variables.
What is the practical workflow for a cross-border supply-chain mapping exercise?
A well-structured cross-border supply-chain mapping exercise runs in four phases, each of which must be adapted to address both the OFAC and EU positions simultaneously.
The first phase is scoping. The business defines the perimeter of the exercise: which product lines, which supplier tiers, which jurisdictions, which entity types. For a business subject to both OFAC and EU regimes, the scope must cover all direct and indirect suppliers whose goods, services, or financing touch US persons, EU persons, or the US or EU financial systems. That perimeter is typically wider than businesses initially expect.
The second phase is data collection. The business obtains beneficial-ownership information for each supplier within scope. This means corporate-registry searches, questionnaires to suppliers, and – for higher-risk nodes – third-party database searches and, where the risk profile justifies it, on-the-ground enquiries. The ownership data must be current: a chart that is eighteen months old does not support the due-diligence record.
The third phase is analysis. For each node, the business applies both the OFAC 50 percent ownership test and the EU ownership-and-control test. Where the two tests produce different results, the stricter conclusion governs. The analysis also addresses extraterritorial reach: for each node that is not directly captured by either test, the business assesses whether a US-person involvement – funding, direction, technical services – re-imports OFAC exposure. Nodes that produce ambiguous results are escalated for legal review.
The fourth phase is documentation and action. The business records the analysis for each node – the ownership data, the test applied, the conclusion, and the basis for it. Nodes that produce a positive result (a prohibited connection) are referred for a licensing analysis or for a relationship termination. The record is retained in accordance with the applicable record-keeping obligation – verify the required period for the regime in question.
For businesses running this exercise for the first time, or revisiting a mapping programme that has not been updated in over a year, we recommend beginning with a risk-based prioritisation: the highest-risk nodes (high-value suppliers, complex ownership, high-risk jurisdictions, dual-use goods) receive the most intensive analysis first. This is not a substitute for comprehensive mapping, but it ensures that the most acute exposures are identified before the broader exercise is complete.
Related practices
- Correspondent banking and de-risking under OFAC – sanctions risk assessment for financial-institution relationships and correspondent exposure.
- Supply-chain sanctions mapping: OFSI vs Australia – comparative analysis of UK and Australian supply-chain obligations and enforcement posture.
- Trade transaction screening: BIS/EAR vs EU – export-control screening obligations under US and EU dual-use rules for goods and technology in cross-border supply chains.
Frequently asked questions on supply-chain sanctions mapping: OFAC and the EU
Where do the regimes diverge on supply-chain sanctions mapping?
The primary divergences are the ownership and control tests, extraterritorial reach, and licensing architecture. OFAC applies a mechanical 50 percent aggregate ownership threshold; the EU adds a control test that can catch entities below that threshold. OFAC secondary sanctions reach non-US parties transacting in non-US markets; EU sanctions do not replicate that reach. EU licensing operates at member-state level, creating potential for parallel applications across jurisdictions where OFAC licensing is centralised through a single federal authority.
Which regime is stricter on supply-chain sanctions mapping?
Neither regime is universally stricter. OFAC's extraterritorial secondary-sanctions reach is broader, and its enforcement posture is among the most active globally. The EU's control test is wider than OFAC's ownership-only threshold, and can catch arrangements that a purely mechanical ownership analysis would miss. For any given supply-chain node, the regime that produces the most restrictive conclusion governs the business decision. A compliant supply-chain programme must satisfy both regimes simultaneously; it cannot optimise for one at the expense of the other.
What should a cross-border business do about supply-chain sanctions mapping?
A cross-border business should treat supply-chain mapping as a continuous programme rather than a transaction-by-transaction checkpoint. The minimum components are: a defined scope covering all supplier tiers with US or EU exposure; current beneficial-ownership data; documented application of both the OFAC and EU tests; escalation procedures for ambiguous or positive results; and a record-keeping system that preserves the analysis. Where a positive result is identified, the business should immediately assess whether a licence or authorisation is available and seek legal advice before continuing to perform any related contract. For a review of your supply-chain mapping programme, contact Calder & Vance at info@caldervance.com.
About the author
J. M. Aldridge advises multinationals and financial institutions on US sanctions and export controls, with a focus on OFAC licensing, secondary-sanctions risk, and BIS classification. Calder & Vance – International Sanctions & Export Control Counsel.
About Calder & Vance
Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.
For a confidential review of your supply-chain mapping programme under OFAC and EU sanctions, contact Calder & Vance at info@caldervance.com.
Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.