A multinational trading house reviews its compliance programme ahead of a board audit. Screening logs look clean. Policy documents are signed. But when the compliance team maps the ownership chains of its top fifty counterparties against four separate sanctions regimes simultaneously, three entities that passed their own national screening fail under a neighbouring jurisdiction's control test. The deal pipeline freezes. The question is not whether the programme exists – it is whether it actually works.
A compliance audit and testing programme is the mechanism by which a business verifies that its sanctions and export-control controls function as intended across every regime that applies to its operations. Under a cross-border footprint, that means testing against OFAC rules, OFSI and ECJU requirements, EU Council regulations, and – depending on supply chain and counterparty geography – the regimes of Australia, Canada, Switzerland, Singapore, Japan, and the UAE simultaneously. A gap visible only when regimes are read side by side is the most dangerous gap of all.
This guide sets out a structured approach to compliance audit and testing for businesses operating across jurisdictions. It covers the governing authorities, the core test sequence, cross-regime divergences that must be built into the methodology, common risk flags, and the point at which external counsel adds value that internal resource alone cannot replicate.
Step 1 – Establish which regimes actually apply to your operations
The first step in any cross-border compliance audit is to map every sanctions regime that has legal reach over the business before a single control is tested. Scope is not determined by where your headquarters sits; it is determined by where you are incorporated, where you transact, where your goods travel, and what currency you use.
US sanctions administered by OFAC apply to US persons anywhere in the world, to any transaction that touches the US financial system, and – for the most expansive programmes – carry secondary-sanctions risk that can reach non-US parties engaging in defined categories of conduct. BIS export controls under the EAR apply to items of US origin or containing a threshold of US-controlled content, regardless of who ships them or from where. A European exporter shipping goods that contain US-origin components may have EAR obligations without any US office or US person involved in the transaction.
UK obligations under OFSI and the ECJU arise for UK persons and UK-incorporated entities wherever they act, and extend to conduct occurring partly in the United Kingdom. EU Council regulations bind EU persons and entities incorporated under the law of a member state, and cover conduct taking place in the EU. Neither the UK nor the EU regime is simply a mirror of the other; post-2020 divergence has produced material differences in list composition, ownership-and-control tests, and licensing categories.
In our cross-border practice, the most common scoping failure is treating the firm's primary incorporation jurisdiction as the only applicable regime. A shipping company with a Singapore subsidiary, a UK-regulated bank account, and US-dollar invoicing sits within at least three distinct enforcement perimeters simultaneously. The audit scope must reflect that reality before any testing begins.
The position above covers the standard case. Your facts – the counterparty, the goods, the route, the currency, and the ownership chain – change the analysis. For a structured review of which regimes apply to your operations, contact Calder & Vance at info@caldervance.com.
Step 2 – Map ownership and control chains against every applicable list
Once scope is established, the audit must test whether each counterparty, supplier, and beneficial owner is blocked or restricted under each applicable regime – and whether entities that are not themselves listed are caught through ownership or control by a listed person. This is the layer where most audit methodologies under-perform.
The US test is mechanical: under the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked), aggregated ownership across multiple listed persons triggers the prohibition even if no single listed person holds a majority. The UK and EU tests add a control dimension. Ownership and control (the UK and EU test for whether a non-listed entity is caught through a listed person) means that an entity could fall below the ownership threshold and still be caught if a designated person exercises control – through board composition, veto rights, or contractual dependency.
These tests diverge. A counterparty that clears the OFAC 50 percent rule may still be caught under OFSI's control test, or under the equivalent EU analysis. An audit that applies only one jurisdiction's test – typically the auditor's home regime – will return a clean result that a cross-border enforcement authority would not accept.
Practical testing requires three elements. First, identify the full beneficial ownership chain to the natural-person level, not just the first-tier corporate layer. Second, apply each regime's ownership threshold independently and in aggregation. Third, apply the control test under UK and EU rules, examining formal governance documents alongside commercial reality. We regularly advise clients where the commercial documentation and the corporate registry present two different pictures of who actually controls an entity.
List currency matters as much as methodology. All three major lists – OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons), OFSI's Consolidated List, and the EU's list under the relevant Council regulations – are updated without fixed intervals. A counterparty screened on Monday may be listed by Thursday. An audit must test not only whether the screening system works, but whether it ingests list updates in a timeframe that the applicable regime requires.
How does the cross-border ownership test differ from a single-regime approach?
The core difference is that a single-regime audit tests one threshold and one list; a cross-border audit must apply multiple thresholds, multiple lists, and multiple control concepts to the same set of counterparties, and then identify the strictest prohibition that governs. Where regimes diverge, the stricter obligation governs the business's conduct.
Consider a concrete illustration. A trading entity is owned forty-five percent by a party listed under OFSI but not listed by OFAC. Under the OFAC 50 percent rule, the entity clears. Under OFSI, the question turns on whether that forty-five percent ownership, combined with any other indicia of control, brings the entity within the UK prohibition. If the listed party also has a right to appoint the majority of the board, a control finding under OFSI is a real risk – even though the same transaction might proceed lawfully under OFAC's mechanical test.
This divergence is not a theoretical edge case. In our experience, the entities most likely to produce divergent results are those with diffuse ownership across multiple jurisdictions, where no single shareholder crosses a visible threshold but aggregated or indirect holdings tell a different story. Testing must be designed to surface those structures, not simply to confirm that no listed person appears as a direct, majority shareholder.
The EU regime adds a further consideration. EU asset-freeze provisions apply to persons and entities owned or controlled by designated parties, and the assessment of control is contextual – it looks at the ability to direct the entity's actions rather than formal ownership percentages alone. An audit methodology that stops at ownership will not satisfy a regulator assessing EU-law compliance.
For a comparison of how the EU approach to ownership and control testing is applied in practice, see our detailed analysis at Compliance audit and testing: EU guide. The methodological differences between the initial EU approach and its subsequent refinements are addressed in Compliance audit and testing: EU guide 2.
Step 3 – Test the transaction screening and payment-filtering logic
The third phase of a cross-border compliance audit tests whether the technology and processes that sit between a prohibited party and an approved transaction actually intercept the match. A screening system that lists the right names in its configuration but fails to match transliterations, name variants, or aliases is not a functioning control – it is a documented gap waiting to be exploited.
Transaction screening operates differently across business types. Banks and payment firms apply sanctions filters to individual payment instructions, often in real time, against a ruleset that must cover OFAC, OFSI, EU, and UN Consolidated List entries as a minimum. Exporters apply screening at the counterparty-onboarding and order-acceptance stages, and again at point of shipment. Each of these touch-points has a different data quality problem: payment screening works with free-text fields that may be truncated or coded; counterparty screening works with legal-entity names that may vary across registries.
The audit test for screening logic should include: a sample of known-blocked names in variant forms to verify match rates; a test of the system's response to a partial name match (does it queue for review, or does it clear automatically?); and a review of the threshold settings that determine whether a fuzzy match generates an alert. Systems calibrated for low false-positive rates often have elevated false-negative rates – meaning genuine hits pass undetected.
For virtual-asset businesses and payment firms, the cross-border screening challenge is compounded by the speed of settlement and the volume of transactions. A VASP (virtual asset service provider) operating across jurisdictions must reconcile OFAC's strict-liability approach to screening errors with OFSI's reporting obligations and EU rules on fund-freezing. The compliance audit must test whether the alert management process – the human review that follows a system flag – is calibrated for each regime's legal requirements, not only for the firm's operational preferences.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss a confidential review.
Step 4 – Audit export-control classification and end-use controls
For any business that ships physical goods, technology, or software, a complete cross-border compliance audit must include export-control classification and end-use testing as a distinct phase. Sanctions screening and export-control compliance are related but separate obligations; a gap in either can produce enforcement exposure regardless of how well the other is managed.
Under the EAR, every item that is not specifically excluded must be assessed for an ECCN (Export Control Classification Number under the US Commerce Control List) or confirmed as EAR99 – the classification for items subject to the EAR but not listed on the Commerce Control List. An item classified as EAR99 may still require a licence to a sanctioned destination or to a party on OFAC's SDN List or BIS's Entity List. The audit must test whether the firm's classification records are current, accurate, and applied consistently across product lines.
The EU dual-use regime operates on a parallel basis. Items appearing on the EU Common List of dual-use goods require authorisation for export to defined destinations, and the applicable country regime for the destination adds a further layer. The UK, post-2020, administers its own export control list through the ECJU; it is substantially similar to the EU list but is now maintained and updated independently, meaning firms exporting from both the UK and the EU must verify classification under each list separately.
End-use controls are the component of export-control compliance most frequently omitted from compliance audits. A business may correctly classify its goods and obtain the correct authorisation, then fail to implement the post-shipment verification required by the licence conditions or by the applicable end-use undertaking. The audit should test whether end-use certificates are collected, whether post-shipment checks are conducted where required, and whether red-flag indicators – a customer requesting removal of technical markings, a shipment routed through an unexpected transit point, a buyer whose stated business does not match the goods ordered – trigger a defined escalation process.
Our practice covers export-control audit and classification review for manufacturers, freight forwarders, and technology exporters. See our service page covering the Australia regime for context on how a multi-regime audit is structured in practice: Compliance audit and testing: Australia service.
What are the most common risk flags that a compliance audit uncovers?
The most consistent risk flag across cross-border compliance audits is the gap between the documented compliance programme and the controls as actually operated. Policies exist; training records are filed; but the day-to-day decisions are made by reference to habit and convenience rather than to the written procedure. The audit must test behaviour, not only documentation.
A second persistent flag is the treatment of legacy relationships. Counterparties onboarded before the current screening system was implemented often lack the complete ownership documentation that the system now requires. They pass periodic re-screening because their name does not appear on a list, but the underlying ownership chain has never been mapped. A designation that occurs after an undisclosed change in beneficial ownership will not be caught by a name-matching screen that has no knowledge of who the beneficial owners are.
Third, and particularly relevant under a cross-border footprint: the assumption that a clean result from one regime's screening covers the position under all regimes. We have acted for businesses that operated effective OFAC-aligned screening and had no parallel process for EU or OFSI lists – a position that created material exposure in European-law-governed transactions without the compliance team being aware of it.
A fourth flag is inadequate escalation and record-keeping. A screening match that generates an alert, is reviewed, and is cleared as a false positive is an event that must be documented. If the same name generates repeated alerts that are repeatedly cleared without review of whether the facts have changed, the record sequence becomes a liability rather than a defence. Under OFSI's enforcement approach, documented decision-making supports the reasonable steps defence. Under OFAC's strict-liability framework, documentation matters in the penalty assessment, where cooperation and remediation are assessed factors.
The fifth flag is the absence of a tested escalation path for a genuine hit. What does the firm actually do when a counterparty is confirmed as listed? Who decides whether to freeze, to report, to seek a licence, to exit the relationship? An untested escalation plan is not a functioning control. The audit should include a tabletop exercise that walks the response sequence from alert to decision in a realistic scenario.
Step 5 – Voluntary self-disclosure, reporting obligations, and record-keeping
The final phase of a cross-border compliance audit assesses whether the firm has met its affirmative reporting obligations and is positioned to manage a VSD (voluntary self-disclosure to a regulator) if the audit surfaces an apparent violation. These are distinct issues, but they share the same underlying requirement: an accurate and complete record of what was done, when, and by whom.
Reporting obligations differ by regime. OFSI requires a person who knows or suspects that they hold funds belonging to, or for the benefit of, a designated person to report that fact within a defined statutory period. The obligation is strict and applies even where the firm does not itself hold the funds, if it becomes aware of the relevant fact. OFAC does not impose the same affirmative reporting obligation in all programmes, but blocked property must be reported under the applicable regulations. EU member states apply their own reporting requirements under the relevant Council regulation. A cross-border business must audit its reporting process against each regime separately.
Record-keeping requirements similarly vary. The general standard across regimes is that records supporting compliance decisions – screening logs, ownership-and-control analysis, licence applications, end-use certificates, VSD correspondence – should be retained for a period sufficient to cover the applicable limitation period and the regime's express requirements. Where APPENDIX E figures are not injected for a specific regime's retention period, the prudent standard is to retain records for a period that covers the longest applicable requirement across all relevant regimes, and to verify the current position before relying on any single number.
A VSD is not a guaranteed mitigant, and we do not present it as one. However, timely and thorough disclosure, combined with a credible remediation plan, is an assessed factor in penalty determinations under OFAC and in OFSI's enforcement approach. The audit should confirm that the firm knows the VSD process for each relevant regime, has a defined trigger for initiating it, and has identified the legal-privilege protections that apply to the investigation phase.
When should external compliance counsel be engaged?
External compliance counsel adds value at four specific points in the audit and testing cycle. First, at scoping: external counsel can identify regime-reach questions that in-house teams, trained primarily in one jurisdiction, may not recognise as live issues. Second, at ownership-and-control analysis for complex or opaque structures: where beneficial ownership is obscured by layers of holding companies, trust arrangements, or nominee structures, an independent legal analysis of the ownership chain adds weight that a purely internal review cannot provide.
Third, when the audit surfaces an apparent violation. At that point, the privilege question – whether the audit findings are protected from compelled disclosure – becomes immediately material. An audit conducted entirely by the internal compliance function may not attract the same privilege protections as one conducted under legal professional privilege. Engaging counsel at or before the point when a potential violation is identified protects the position. The decision to escalate to a VSD, to approach the regulator informally, or to manage the matter through remediation alone is a legal judgment that should not be taken without independent advice.
Fourth, when a major transaction or a new market entry is under consideration. A pre-transaction compliance audit – testing whether the target's programme, its counterparties, and its export-control classifications meet the acquirer's standards – is materially different from a routine periodic audit. The stakes are higher, the timeline is shorter, and the analysis must anticipate the post-closing position across every regime that will apply to the combined entity.
In our experience, businesses that invest in an external compliance review before a problem arises spend significantly less time and resource managing the problem than those who engage counsel only after enforcement action has begun.
Related practices
- Compliance audit and testing: Australia service – sanctions compliance audit and testing under the Australian autonomous sanctions regime
- Compliance audit and testing: EU guide – how EU sanctions obligations apply to ownership, control, and transaction screening
- Compliance audit and testing: EU guide 2 – updated EU compliance audit methodology addressing post-2022 regulatory developments