A UK-based financial institution processes a routine payment. The transaction clears. Three weeks later, a compliance analyst notices that one of the counterparties shares a name and jurisdiction of incorporation with an entity on the UK Consolidated List (the list of persons and entities subject to UK financial sanctions). The business now faces a question it cannot afford to answer slowly: is this an apparent violation of the UK financial-sanctions regime, and if so, what happens next?
An apparent violation is a transaction or dealing that, on its face, appears to have breached a UK financial-sanctions prohibition, before any formal determination of fault or penalty is made. The governing authority is OFSI (the Office of Financial Sanctions Implementation, part of His Majesty's Treasury), which administers UK financial sanctions under the Sanctions and Anti-Money Laundering Act 2018 ("SAMLA") and the relevant thematic regulations. As of March 2026, OFSI holds civil enforcement powers including monetary penalties, and the Crown Prosecution Service handles criminal referrals for the most serious cases.
This guide walks through the apparent-violation assessment process step by step, explains where the analysis diverges from comparable regimes such as OFAC and OFSI's EU counterparts, and identifies the risk flags that demand early legal review.
Step 1: Identifying whether a potential breach exists
The first step is to establish whether the activity in question falls within a UK financial-sanctions prohibition at all. OFSI prohibits – broadly – making funds or economic resources available to, or for the benefit of, a designated person, and receiving or dealing with funds or economic resources owned or controlled by a designated person. The question is not simply whether a name matched; it is whether the underlying dealing engaged one of those prohibitions.
Start with the designation itself. Consult the UK Consolidated List directly. Confirm the full legal name, any known aliases, date of birth or registration number, and the thematic sanctions programme under which the person or entity was designated. A name-only match is not sufficient to confirm a prohibited dealing; the identifying details must correspond. In our experience, many apparent violations at this stage resolve as false positives once the identifying information is verified against the List.
Next, characterise the dealing. A payment to a counterparty who is not itself designated but who is 50 percent or more owned or controlled by a designated person is also prohibited. OFSI, like OFAC, applies an ownership and control test: an entity owned or controlled by a designated person is treated as itself subject to the same restrictions. Under OFSI's guidance, the test looks at both legal ownership and effective control – a slightly broader analysis than OFAC's more mechanical 50-percent aggregation rule, which focuses on ownership alone.
What does "control" add here? Under the UK regime, a non-designated entity may be caught even where the designated person holds less than a majority stake, if they can exercise dominant influence over the entity's decisions. This is a materially wider net than the binary OFAC threshold, and it catches structures that US-rules-only screening tools will miss entirely.
Step 2: Scoping the dealing and the relevant prohibition
Once a potential designated-person connection is confirmed, the next step is to scope every dealing that may have occurred: funds transfers, credit extensions, payments under contracts, asset-management instructions, insurance payments, and any other provision of funds or economic resources. OFSI's prohibitions apply to the full range of financial dealings, not only direct payments.
Map the timeline. When was the designation effective? OFSI designations under SAMLA take effect on the date they are published in the Gazette, and any dealing after that date – even if the contract predates it – can constitute an apparent violation. A business that signed a contract before a counterparty was designated but continued performance after the designation date will need to analyse each post-designation payment or delivery separately.
Assess the economic-resources question specifically. Economic resources include assets that are not funds but that can be exchanged for funds or used to obtain goods, services, or benefits. The provision of intellectual-property licences, software access, or certain professional services can constitute a dealing in economic resources. In cross-sector businesses, this is the category most frequently missed in an initial assessment.
At this stage, preserve all relevant documentation: transaction records, SWIFT messages, contracts, invoices, screening records at the time of the dealing, and any compliance-system logs. OFSI expects businesses to maintain records that demonstrate the steps taken at the point of a dealing, not only records assembled retrospectively. Gaps in contemporaneous documentation are a significant aggravating factor in OFSI's enforcement analysis.
Step 3: Applying the OFSI licensing and defence tests
Not every dealing that engages a prohibition is a violation. The applicable test is whether the dealing was covered by a licence (a written authorisation from OFSI permitting an otherwise prohibited dealing), a general licence (a standing authorisation covering a defined category of transactions), or a statutory exception.
Review every general licence in force at the time of the dealing. General licences under the UK regime cover categories such as certain legal fees and expenses, basic living expenses of designated individuals, and specific programme-by-programme exceptions. They are published on the OFSI website and are updated periodically. A dealing covered by a valid general licence at the time it occurred is not a violation, even if the general licence was subsequently revoked.
If a specific licence was in place, confirm that the dealing fell strictly within its terms. OFSI specific licences are narrow and condition-laden. A payment that falls outside the scope of the licence's permitted purpose, counterparty, or value ceiling is not covered. In our cross-border practice, we regularly advise on matters where a licence existed but the dealing exceeded one of its stated parameters – a gap that requires a fresh assessment of exposure.
For the position under OFAC: the US regime offers a broadly comparable licensing system, but the categories of general licence differ materially and the specific-licence process is administered separately by OFAC's Licensing Division. A dealing that was covered by an OFAC general licence at the time may not have been covered by an OFSI general licence in the same period. Where a transaction touches both regimes, both licence analyses must be run independently.
The position above covers the standard case. Your facts – the counterparty's ownership structure, the nature of the dealing, the timing relative to the designation, and the regimes in play – change the analysis. For an assessment of your exposure under OFSI, contact Calder & Vance at info@caldervance.com.
Step 4: Deciding whether to report to OFSI – and when
A decision about reporting to OFSI is one of the most consequential steps in an apparent-violation assessment. Relevant persons – including financial institutions, credit institutions, and certain other regulated entities – face a mandatory obligation to report to OFSI as soon as practicable once they know or have reasonable cause to suspect that they hold funds or economic resources belonging to or controlled by a designated person. Breach of the reporting obligation is itself an offence under SAMLA.
Beyond the mandatory reporting obligation, voluntary disclosure to OFSI – sometimes referred to as a VSD (voluntary self-disclosure to a regulator) – is a significant mitigating factor in OFSI's enforcement methodology. OFSI's published enforcement guidance makes clear that prompt, complete, and candid voluntary disclosure is weighed positively in the penalty assessment. A business that self-reports before OFSI becomes aware of a potential breach from another source is in a materially better position than one that waits for an enquiry.
The timing question is acute. There is no fixed statutory deadline for voluntary disclosure to OFSI in the same way that, for example, OFAC's standard request-for-reconsideration periods work. However, OFSI's guidance indicates that delay weighs against the firm, and the evidential benefit of contemporaneous documentation diminishes as time passes. In our experience, a business that takes more than a few weeks to report a self-identified apparent violation without a clearly documented justification for the delay will find that OFSI treats the delay as an aggravating factor.
How should the report itself be framed? A VSD to OFSI should include: a factual account of the dealing, the designation details of the counterparty, the timeline of events, the steps the business took to screen at the time of the dealing, and the measures the business has taken or will take to prevent recurrence. It should not include speculative legal conclusions and it should not make concessions on fault that go beyond what the facts support. The framing of a VSD requires care; a poorly drafted report can create evidentiary problems in a subsequent penalty process.
If a transaction has already been flagged by OFSI, or if a business has received an OFSI information request, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss the position before making a formal approach to OFSI.
Step 5: The cross-regime dimension – OFAC, EU, and other parallel obligations
A dealing that constitutes an apparent violation under OFSI frequently has a parallel dimension under OFAC or the EU regime. The UK, US, and EU designations lists overlap substantially but are not identical, and the licensing regimes, reporting obligations, and enforcement expectations differ in ways that matter operationally.
Under OFAC, the governing legislation for most non-country-specific programmes is IEEPA. OFAC's civil penalty base differs structurally from OFSI's: OFAC can impose penalties up to the greater of a statutory per-transaction maximum or the value of the transaction, and the settlement process is separate from any UK enforcement process. A UK business with US-dollar payments or US-person counterparties, or with subsidiaries incorporated in the United States, must consider its OFAC exposure independently of its OFSI exposure. The existence of a VSD to OFSI does not satisfy any OFAC reporting or disclosure expectation.
The EU regime – administered by EU member states with Council designation decisions as the legal basis – imposes its own prohibitions on EU-incorporated entities and transactions executed within EU territory. Post-Brexit, UK sanctions and EU sanctions are legally separate. A dealing that is permitted under an OFSI licence is not thereby permitted under an EU Council Regulation. Where a transaction involves an EU-based entity, an EU-incorporated subsidiary, or clearing through an EU financial institution, a separate EU analysis is required.
For businesses with exposure to the Swiss regime (SECO), the Canadian regime (Global Affairs Canada / GAC), or the Australian autonomous-sanctions regime (DFAT), the same point applies: each regime administers its own list and its own licensing process, and a VSD to OFSI does not constitute disclosure to those authorities. We have acted for multi-entity groups where a UK-entity apparent violation had simultaneous reporting implications in two or three other jurisdictions, each with a different statutory mechanism and a different disclosure timeline.
See also our analysis of apparent-violation assessment under EU sanctions and our guide to apparent-violation assessment under SECO for the detailed position under each of those regimes.
Risk flags that demand early counsel
Not every apparent violation carries the same risk profile. Several features, when present, indicate that the exposure is at the higher end of OFSI's enforcement spectrum and that external legal advice should be obtained before any communications with OFSI are made.
The first is repeated conduct. OFSI's enforcement guidance treats a pattern of similar failures as substantially more serious than a single isolated event. If an internal review reveals more than one dealing with the same designated counterparty, or a systemic screening failure that affected multiple transactions, the enforcement exposure is qualitatively different and the voluntary-disclosure strategy will need to address the systemic issue directly.
The second is value. OFSI's civil monetary-penalty powers are graduated. Higher-value dealings attract proportionally larger potential penalties, and the penalty assessment will scrutinise whether the business had adequate controls relative to the risk profile of the relevant transaction or relationship. A business that processed a high-value dealing with only basic screening in place will face hard questions about its compliance adequacy.
The third is awareness. If there is any indication that any person within the business was aware of the designated status of the counterparty at the time of the dealing and the dealing proceeded regardless, the criminal-referral threshold becomes relevant. Criminal liability under SAMLA requires knowledge or reasonable cause to suspect designation. The question of what individuals knew, and when, is one that must be handled with particular care and should not be addressed without legal advice.
The fourth is the interaction with anti-money-laundering obligations. Financial institutions subject to the Money Laundering Regulations will often find that an OFSI apparent violation also engages their AML reporting obligations. The two reporting chains – OFSI and the National Crime Agency – are separate and must each be considered on their own terms. Missing either one is independently consequential.
Is your business confident that its screening logic would catch not only direct designees but also entities caught through the ownership-and-control test? Have you tested whether your general-licence awareness is current across all the thematic programmes relevant to your counterparty base? These are not rhetorical questions; they are the two most common gaps we identify in compliance-programme reviews.
A common myth: "We screened at onboarding, so we are covered"
The most persistent misconception we encounter is that a clean screening result at onboarding provides a continuing defence against a sanctions breach. It does not. Designations are made on an ongoing basis and can take effect at any time. An entity that was not listed at the date of onboarding may have been designated since, and the obligation to comply with UK financial sanctions is continuous, not a one-time check.
OFSI expects businesses to have a screening programme that includes periodic re-screening of existing counterparties, not only screening at the point of a new relationship or transaction. The frequency of re-screening is a risk-based question: higher-risk sectors and counterparty profiles demand more frequent checks. In our practice, we regularly advise businesses that discovered an apparent violation only because a counterparty had been designated many months earlier and no re-screening had occurred in the interim.
The myth also extends to the scope of what is screened. Screening the direct counterparty without screening its ownership chain is insufficient. The OFSI ownership-and-control test means that a clean result at entity level can co-exist with a designation at shareholder level that catches the entity within the prohibition. Effective screening requires mapping the ownership structure to a sufficient depth to surface any designated person holding a controlling or majority stake.
Related practices
- Apparent-violation assessment under EU sanctions – cross-regime comparison for EU-exposed transactions and entities
- Apparent-violation assessment under SECO – Swiss-regime guide for businesses with CHF or Swiss-nexus dealings
- Apparent-violation assessment under Singapore sanctions – MAS-regime obligations for APAC-connected compliance programmes