A technology distributor with subsidiaries in three continents receives a routine audit request from its parent's compliance team. The reviewer opens the screening logs and finds gaps: ownership chains assessed only to the first legal layer, no documentation of how the control test was applied under OFSI, and a dual-use classification review that was last updated four years ago. The deal pipeline is live. The exposure is real.
A cross-border compliance audit and testing exercise maps every active obligation – OFAC's asset-freeze and dealing prohibitions, OFSI's financial-sanctions controls, the EU Council regulations, BIS export-control requirements, and the relevant national regimes – against the organisation's actual controls, screening logic, and decision records. As of mid-2026, no single testing methodology satisfies all regimes simultaneously, because the ownership, control, and licensing tests diverge materially between jurisdictions. A disciplined, regime-by-regime audit structure is the only reliable starting point.
This guide walks through six stages of a cross-border sanctions and export-control compliance audit: scoping the regulatory perimeter, stress-testing screening and ownership analysis, reviewing licensing and authorisation records, examining the control architecture, testing the reporting and record-keeping posture, and deciding when to escalate to external counsel.
Stage 1 – How do you scope the regulatory perimeter before an audit begins?
Scoping the perimeter means identifying every sanctions and export-control regime that applies to the organisation before a single control is tested. A business with a US nexus – a dollar clearing account, a US-incorporated parent, US-origin goods, or US persons in the transaction chain – is subject to OFAC's jurisdiction, regardless of where it is domiciled. OFSI's jurisdiction follows the UK nexus test: a UK person, a UK-incorporated entity, or conduct partly carried out in the United Kingdom. EU obligations follow the entity's registration or the currency of the transaction in certain regimes. Failing to identify the full perimeter at the outset means testing the wrong controls.
In our experience, the most common scoping failure is treating the regulatory perimeter as static. Regimes change their scope through new designations, amended general licences, and revised guidance – sometimes within weeks. The audit inventory should record not just which regimes apply today but what triggered each obligation. That record becomes the baseline for the next review cycle.
For businesses with operations in Australia, Canada, Singapore, or Japan, the perimeter widens further. Each jurisdiction operates its own autonomous sanctions instrument and its own export-control list. A shipment that clears the US Commerce Control List may still require a separate authorisation under the applicable country regime. Map the nexus first; test the controls second.
The position above covers the standard case. Your specific nexus – the counterparty, the goods classification, the payment route, the nationality of the personnel approving the transaction – changes the analysis materially. For a scoping review of your regulatory perimeter, contact Calder & Vance at info@caldervance.com.
Stage 2 – Stress-testing screening logic and the ownership and control analysis
Screening and ownership analysis are the technical core of any sanctions compliance programme, and they are also the area most likely to produce hidden gaps. The SDN List (OFAC's list of Specially Designated Nationals and blocked persons) must be screened against counterparties, beneficial owners, and intermediaries. Under OFAC's 50 percent rule (the rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked), the screen must reach indirect as well as direct holdings. A target held 30 percent by one SDN and 25 percent by another crosses the threshold on aggregation – 50 percent or more in total – even if neither listed person would trigger a hit individually.
OFSI and the EU apply a different test. Both combine an ownership and control analysis (the test for whether a non-listed entity is caught through a listed person's ownership or direction of that entity). Under these regimes, a listed person holding below 50 percent can still cause an entity to be caught if they exercise control through board composition, veto rights, contractual arrangement, or other means. The practical consequence is significant: a transaction that passes the mechanical OFAC ownership screen may still be prohibited under OFSI or EU rules because of a control relationship that screening tools do not flag automatically.
Testing the screening logic means running the system against known-positive and known-negative cases. Known-positive cases should include indirect ownership scenarios and control-relationship scenarios, not just direct name matches. Testing against fuzzy-name variants and transliteration differences is essential: screening databases use different transliteration standards, and a listed name may appear in several forms. How many name variants is your system configured to catch?
We regularly advise on screening architecture. The weakest points we see are: ownership chains assessed only to the first legal layer, no systematic aggregation calculation across listed co-owners, and a control-relationship flag that depends on the analyst recalling to apply it rather than a workflow that requires it. Each of these is a testable control gap.
Stage 3 – Reviewing licensing, authorisations, and general-licence reliance
Every transaction that relies on a licence or authorisation needs a documented decision trail. A general licence (a standing authorisation that permits a defined category of transactions without a separate application) has conditions and temporal limits. Reliance on a general licence is only protected if the transaction genuinely meets the conditions at the time it is executed – not at the time the general licence was first identified. When conditions change and the reliance record is not updated, the protection falls away.
For specific licences (case-by-case authorisations to conduct otherwise prohibited transactions), the audit should verify that each licence was in effect at the time of the transaction, that the transaction fell within its terms, and that any reporting conditions attached to the licence were discharged. Under OFSI's licensing regime, licensed transactions often carry ongoing reporting obligations. Under OFAC's regime, the terms of a specific licence define the scope of permitted activity precisely; activity outside those terms is prohibited notwithstanding the licence's existence.
Export-control authorisations require parallel treatment. The ECCN (Export Control Classification Number under the US Commerce Control List) must be verified at the product level before any reliance on an exception or licence exception is asserted. In practice, we see classification records that reflect the product as it existed at initial launch, not as modified by subsequent firmware or software updates. A classification that was accurate three years ago may be incorrect today. The audit should test the currency of the classification record, not just its existence.
What does testing the control architecture actually involve?
Testing the control architecture means moving beyond whether a policy document exists and examining whether the controls described in that document operate as designed in practice. A compliance programme that exists on paper but is not embedded in the transaction-approval workflow is not a programme – it is a document. Regulators across all major regimes distinguish between the two.
Effective control-architecture testing covers four dimensions. First, does the transaction workflow require sanctions and export-control clearance before the relevant commitment is made? Second, do the people executing that clearance have the authority, tools, and training to make a defensible decision? Third, is there a documented escalation path for novel or borderline cases? Fourth, are exceptions to standard controls logged, reviewed, and subject to a defined remediation timeline?
The cross-border dimension adds a layer of complexity that a single-regime test will miss. A dual-use item shipped from a European facility by a US-owned parent operating under a BIS export-control requirement must satisfy both the EU dual-use instrument and the EAR. The control that clears one may not address the other. In our practice, the gap appears most often at the level of documentation: the EU end-use statement is present, but there is no record of the BIS export-control analysis.
A micro-scenario: in a recent matter, a manufacturing business with facilities in both Europe and North America had a well-designed sanctions-screening workflow for its North American operations. Its European entities applied a different screening vendor with different list coverage. A counterparty appeared on an EU regime list but not on the vendor used by the North American entity that booked the contract. We identified the gap at audit stage, before any transaction completed, and redesigned the centralised screening architecture. The matter closed without a reportable event.
Stage 5 – Testing reporting obligations and record-keeping
Reporting and record-keeping obligations differ materially across regimes, and a cross-border audit must test each separately. Under the US regime, a US person who identifies blocked property must report the blocking to OFAC within a defined statutory window and must maintain records of blocked transactions for a minimum period. Under OFSI, a relevant firm (a person or entity subject to UK financial-sanctions obligations) that has knowledge or reasonable cause to suspect a sanctions breach must report to OFSI. The reporting obligation under OFSI does not require a confirmed breach; reasonable suspicion is sufficient. The two tests differ, and compliance teams managing both regimes must apply both.
Record-keeping requirements similarly diverge. The audit should establish, for each regime in scope, the required retention period and the required content of the record. A record that satisfies the minimum content requirement of one regime may be deficient under another. In our cross-border practice, we see records maintained to the shortest applicable standard rather than to the most demanding one. Where multiple regimes apply, the stricter requirement governs the record-keeping design.
Transaction records should capture not just the final clearance decision but the decision process: which lists were screened, what ownership analysis was performed, which licence or authorisation was relied upon, and who made the determination. A clearance record that says only "cleared – no hit" is of limited value in an enforcement defence. A record that sets out the screening tool used, the ownership assessment performed, and the basis for any exception or licence reliance is a genuine compliance asset.
If a transaction has already been flagged, or a potential reporting obligation has been identified, an early review can preserve options that narrow with time. To discuss a specific reporting question or a potential breach, contact Calder & Vance at info@caldervance.com.
Stage 6 – When should a business involve external compliance counsel?
External compliance counsel should be involved at the point where the internal team's objectivity, expertise, or capacity is insufficient for the scope of the audit. A routine annual testing exercise against well-understood controls can often be managed internally. But a business that has recently expanded into a new jurisdiction, acquired an entity with an unknown compliance history, received a regulatory inquiry, or identified a potential breach needs outside expertise before it commits to a course of action.
The AUDIENCE_MYTH here is that external counsel is only useful after something has gone wrong. In our experience, the most valuable interventions occur before a transaction completes or before a filing is made. The cost of identifying a control gap at the design stage is a fraction of the cost of addressing it after a regulator has raised it. Preventive audit work is less visible than enforcement defence, but it is where most compliance value is generated.
Decision matrix: if a business faces a routine periodic review with no recent transactions in high-risk sectors and no new regulatory nexus, an internal audit against a structured template is appropriate, with external review of the findings before sign-off. If the business has a new dual-use product line, a counterparty in a high-risk jurisdiction, a recent acquisition, or a suspected miss-screening, external counsel should be engaged to scope and lead the audit. Where a potential breach is identified, legal privilege considerations mean that external counsel should be instructed before the investigation begins.
The cross-border dimension itself is a reason to involve external counsel. A team expert in one regime will not necessarily know the divergent ownership test under another, the different reporting window that applies, or the interaction between two licensing regimes. Missing a cross-regime obligation during an audit gives a false assurance that can be more damaging than no audit at all.
Related practices
- Compliance audit and testing – Australia – specialist support for businesses with an Australian sanctions nexus
- Compliance audit and testing cross-border guide (part 3) – advanced topics in multi-regime audit design and governance
- Compliance audit and testing – EU guide – structured analysis of EU sanctions and dual-use audit obligations