A trading company sources components from a supplier network spanning four continents. Its UK subsidiary falls under OFSI's financial-sanctions rules; its Australian arm is subject to DFAT's autonomous-sanctions regime. A tier-two supplier in the chain has a shareholder whose name appears on a consolidated sanctions list – but which list, and under which regime, determines whether the contract can proceed, what disclosure is required, and who bears the liability.
Supply-chain sanctions mapping under OFSI requires identifying whether any entity in the chain is a designated person (a party listed under the relevant UK thematic sanctions regulations made under the Sanctions and Anti-Money Laundering Act 2018, known as "SAMLA") or is owned or controlled by one. Australia's autonomous-sanctions regime, administered by DFAT, applies a materially different test and a distinct list. The two regimes do not mirror each other, and a business that maps only to one will have gaps. As of January 2026, both regimes are active and periodically updated.
This analysis compares the two regimes criterion by criterion – governing authority, scope, the ownership and control test, supply-chain obligations, licensing, and enforcement – and closes with the practical steps a cross-border business should take before it signs or ships.
Governing authority and legal basis: OFSI and SAMLA versus DFAT and the Autonomous Sanctions Act
OFSI administers UK financial-sanctions law under SAMLA, which provides the primary enabling power for the UK's autonomous-sanctions programme following Brexit. Under SAMLA, the UK government enacts thematic sanctions regulations by statutory instrument, each covering a particular regime – geographic, thematic, or individual. OFSI maintains the UK Sanctions List, which is the operational publication of designated persons under each set of regulations. For supply-chain purposes, the operative question is whether a counterparty, supplier, or their owner appears on that list.
Australia's autonomous-sanctions programme derives from the Autonomous Sanctions Act and the associated Autonomous Sanctions Regulations, administered by DFAT. DFAT publishes the Consolidated List, which is the Australian equivalent of the UK Sanctions List. Australia also implements United Nations Security Council measures through separate legislation, and those UN-mandated measures run in parallel with the autonomous programme. A supplier that appears on the UN Consolidated List will trigger obligations under both Australian regimes simultaneously.
The two systems share a common lineage – both adapted from earlier UN-based models – but they have diverged materially in scope, designation criteria, and the legal tests applied to non-listed entities caught through ownership or control. Understanding both starts with the list, but it does not end there.
What does each regime actually prohibit in a supply-chain context?
OFSI's core prohibition covers making funds or economic resources available, directly or indirectly, to or for the benefit of a designated person. The phrase "economic resources" is broad. It includes goods, services, and property that could be exchanged for funds or used to obtain funds or services. In a supply-chain setting, this means that a payment to a supplier that then flows – even partially – to a designated person can constitute a breach. The prohibition extends beyond direct counterparty relationships.
The Australian autonomous-sanctions regime prohibits dealings with targeted persons and their property. "Dealing" includes a range of commercial interactions: acquisition, disposal, movement, export, import, use, and financing. Critically, the Australian statute also prohibits providing assets to or for the benefit of a designated person, which creates a functional parallel with the OFSI "benefit" test. However, the category definitions are not identical, and there is no guarantee that a transaction cleared under one regime will fall outside the other's scope.
Where the regimes align, dual compliance is usually achievable. Where they diverge – for instance, on what constitutes an economic resource versus an asset, or on the breadth of the indirect-benefit prohibition – a business must satisfy the stricter test. In our experience, the safest rule is that the stricter prohibition governs.
The ownership and control test: where do the regimes diverge most sharply?
OFSI applies an ownership and control test to determine whether a non-listed entity is caught because a designated person owns or controls it. A non-listed company is treated as within the prohibition if a designated person owns it, directly or indirectly, or if a designated person otherwise controls it. "Control" under the UK regime encompasses legal control, factual control through board influence, and control through contractual or other means. This is a broader and more fact-intensive test than a purely mechanical ownership threshold.
The Australian regime applies its own control-and-ownership analysis, but the statutory framing is not identical to SAMLA's. DFAT guidance addresses when assets are "owned or controlled" by a designated person, but the specific indicators and thresholds differ from OFSI's published guidance. Australia does not, for example, publish a single authoritative interpretive note equivalent to OFSI's ownership and control guidance that sets out a structured multi-factor test in the same level of detail.
Compare both to the OFAC position. Under OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked), the ownership test is 50 percent or more in the aggregate. The OFAC test is largely mechanical. OFSI and Australia both require a broader control analysis, which makes the cross-border mapping exercise considerably more demanding. A supply chain cleared against OFAC's ownership threshold may still require additional analysis under OFSI and Australian rules before it is clear.
Does your supply-chain screening tool apply all three tests, or only the OFAC threshold? This is the single most common gap we identify in cross-border compliance reviews.
Supply-chain mapping obligations: what each regime requires you to do
Neither OFSI nor DFAT prescribes a mandatory supply-chain mapping methodology by regulation. The obligations arise instead from the underlying prohibitions and from the standard of reasonable due diligence that regulators expect in enforcement proceedings. The practical content of those obligations varies by sector, counterparty profile, and transaction value.
Under the OFSI regime, a person who knows or has reasonable cause to suspect that they are dealing with a designated person has a potential reporting obligation. OFSI's enforcement approach takes into account whether a firm had adequate procedures in place at the time of the breach. That assessment necessarily looks at what screening and mapping the firm conducted before transacting. A firm that failed to map even the first tier of its supply chain will receive less credit than one that mapped thoroughly and missed a well-concealed link.
Australia's approach similarly rewards proportionate diligence. DFAT and the Australian Federal Police share enforcement responsibility; criminal sanctions can follow a knowing breach. The Australian regime's "dealing" prohibition requires a business to be confident it is not transacting with a targeted person or their property. Courts and regulators will assess whether due diligence was proportionate to the risk profile of the relationship.
What does proportionate mapping look like in practice? In a recent matter, a logistics business operating between the UK and Australia undertook a full-chain mapping exercise across six supply tiers following a contract review. We assisted in designing the ownership-and-control analysis for each tier, applying both the OFSI multi-factor test and the Australian ownership indicators. The mapping identified two intermediate entities requiring enhanced scrutiny at tier three. Neither was designated; both were cleared after documentation review. The process itself became the compliance record for the client's file.
Licensing and derogations: can a prohibited supply-chain step be authorised?
Both regimes offer a licensing route that can authorise an otherwise prohibited transaction. Under OFSI, a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) can permit a dealing that would otherwise be caught by the financial-sanctions prohibition. OFSI also issues general licences (standing authorisations that permit a defined category of transactions without a separate application). In a supply-chain context, general licences most commonly cover pre-existing contracts, legal fees, and basic needs transactions. A specific licence application to OFSI requires a clear statement of the transaction, the designated person's involvement, and the grounds for authorisation.
Australia does not operate a licensing system in the same form. Under the Australian autonomous-sanctions regime, the Minister may issue a permit authorising a transaction that would otherwise constitute a contravention. Permit applications go to DFAT. The grounds and procedures differ from OFSI's licensing criteria; the two systems are not interoperable. An OFSI licence does not authorise a transaction under Australian law, and an Australian permit does not authorise conduct under UK sanctions. A cross-border business that needs both must apply to each authority separately.
The position above covers the standard case. Your facts – the goods, the counterparty relationship, the regime in play, and the sanctions list in question – change the analysis materially. For an assessment of your licensing options under OFSI or the Australian regime, contact Calder & Vance at info@caldervance.com.
Reporting, record-keeping, and breach disclosure compared
OFSI imposes a reporting obligation on certain persons who know or suspect they hold funds or economic resources belonging to a designated person. Financial institutions, in particular, are subject to the reporting requirement. The obligation is not restricted to confirmed knowledge; reasonable suspicion triggers it. Record-keeping obligations accompany the reporting duty, and OFSI's enforcement guidance makes clear that records should be retained for a period sufficient to support an audit of the firm's sanctions compliance. Practitioners advising on OFSI matters note that five years is a well-established marker for document-retention programmes, though the precise requirement under any specific set of thematic regulations should be verified.
Australia's Autonomous Sanctions Act does not contain a standalone suspicious-transaction reporting duty equivalent to OFSI's in its general form; reporting obligations primarily arise through the AML/CTF regime administered by AUSTRAC and through specific reporting requirements in the autonomous-sanctions regulations. A business that holds property connected to a designated person under Australian law must seek a permit or risk a contravention. The integration of AML and sanctions obligations at the enforcement level means that a suspicious-matter report under AUSTRAC rules can simultaneously engage DFAT and potentially the Australian Federal Police.
If a supply-chain mapping exercise surfaces a potential breach – whether a payment has already been made or is about to be – an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential initial assessment.
Enforcement posture and penalty exposure
OFSI's enforcement posture has become significantly more active since the expansion of its monetary-penalty powers. OFSI can impose civil monetary penalties on a strict-liability basis for breaches, meaning that a firm need not have known it was breaching the regulations for a penalty to be imposed. The civil standard – on the balance of probabilities – applies to the liability determination, though OFSI takes mitigating factors, including adequate due diligence and voluntary disclosure, into account when calculating the penalty amount. OFSI publishes its enforcement decisions and methodology guidance, giving the market a degree of transparency on how the authority applies its powers.
Australia's enforcement framework involves both civil and criminal exposure. The Autonomous Sanctions Act provides for significant criminal penalties for knowing contraventions, and the Australian Federal Police can investigate and prosecute. Civil penalties are also available. Unlike OFSI, Australia does not currently publish a regular series of enforcement decisions with the same public profile, which makes calibrating exposure on the basis of precedent more challenging. In our cross-border practice, we frequently advise clients that the absence of published decisions does not mean enforcement is rare; it means the observable precedent base is smaller.
The UN dimension adds a further layer. Where a designated person also appears on the UN Security Council Consolidated List, both OFSI and Australian measures apply concurrently. The UN-based obligation is non-derogable; no domestic licensing procedure can authorise a transaction in breach of a Chapter VII Security Council resolution.
Common myths and the objection we hear most often
The most persistent myth in cross-border supply-chain compliance is this: if the first-tier supplier is clean, the chain is clean. It is not. Both OFSI and the Australian regime reach indirect dealing. A payment to a clean first-tier entity that passes funds through the chain to a designated person can constitute a breach by the originating party, provided the requisite knowledge or constructive knowledge is established.
A related misconception is that a UK compliance programme built around OFSI covers Australia, because "the lists are similar." They are not the same. The UK Sanctions List and Australia's Consolidated List are maintained independently. Designation decisions diverge; a person designated by the UK may not appear on the Australian list, and vice versa. The legal tests differ. The licensing routes differ. Running only one list against a counterparty and relying on it for both jurisdictions creates an undocumented gap.
We regularly advise on matters where the gap was discovered after a transaction had settled. At that point, the options available – voluntary disclosure, remedial mapping, licensing – are fewer and more expensive than they would have been before the transaction. The due-diligence exercise is an investment in optionality.
Practical steps for a cross-border business
A structured supply-chain sanctions-mapping programme for a business subject to both OFSI and Australian rules should address the following elements in sequence.
- Identify the universe of regimes in play. Before mapping, confirm which sanctions regimes apply to the business, its counterparties, and the goods or services being traded. For supply chains touching the UK and Australia, the starting point is OFSI and DFAT. Add OFAC if any US-nexus element is present, and UN Consolidated List obligations in any case.
- Map the ownership and control chain for each material supplier. Apply the OFSI multi-factor control test and the Australian ownership indicators. Do not stop at the first tier. Where ownership chains are opaque, document the steps taken to obtain information and the basis for the conclusions reached.
- Screen against all applicable lists. Run each identified entity against the UK Sanctions List, Australia's Consolidated List, and the UN Consolidated List at a minimum. Where US-nexus exists, include the OFAC SDN List.
- Apply the stricter prohibition where the regimes diverge. If OFSI's control test catches an entity that Australia's test would not, treat the entity as within scope for both unless a specific legal opinion permits differentiation.
- Document the mapping process. Maintain records sufficient to demonstrate, in an enforcement review, what was mapped, when, on what basis, and with what outcome. This documentation is the firm's primary mitigant in any subsequent inquiry.
- Establish a refresh cycle. Sanctions lists change. A mapping exercise that was accurate at the time of contract can become inaccurate within weeks if a new designation is made. A periodic refresh – aligned to the transaction cycle and to list-update frequencies – is a basic programme requirement.
- Involve counsel when a hit or near-miss arises. A positive screening result – even one that appears to be a false positive – should be reviewed before the transaction proceeds. The cost of early advice is almost always less than the cost of remediation after a breach.
Related practices
- Correspondent banking and de-risking under OFAC – US sanctions exposure in financial-institution supply chains and correspondent relationships
- Trade transaction screening: BIS/EAR versus EU dual-use rules – cross-regime comparison of export-control screening for traded goods
- Trade transaction screening: OFAC versus BIS/EAR – how financial sanctions and export controls interact at the transaction level