A multinational with procurement, treasury, and distribution operations spread across four jurisdictions runs a routine transaction check. The payment clears screening. Six weeks later, an indirect ownership review surfaces a listed beneficial owner in the counterparty chain. The question is no longer whether the transaction was permissible – it is whether the compliance programme that missed it will survive regulatory scrutiny.
A cross-border compliance audit and testing programme evaluates whether a business's controls, screening tools, ownership-analysis procedures, and record-keeping actually detect the risks the applicable regimes impose. As of July 2026, a business operating across OFAC, OFSI, EU sanctions, and export-control regimes must test its programme against each regime's distinct standards – because a control that satisfies one authority may leave a gap that another will pursue.
This guide sets out a step-by-step approach to auditing and testing a cross-border sanctions and export-control compliance programme: from scoping the regulatory perimeter, through testing each control layer, to producing findings that withstand regulatory review.
Step 1: Scope the regulatory perimeter before you test anything
The first action in any compliance audit is to map which regimes actually apply to the business – because testing controls against the wrong perimeter produces findings that miss the real exposure. A business with US-dollar payments, US-person employees, or US-origin goods in its supply chain is subject to OFAC's jurisdiction regardless of where it is incorporated. OFSI financial-sanctions obligations apply to activities connected to the United Kingdom. EU Council regulations apply to any activity within EU territory, to EU nationals, and to transactions processed through EU entities. Where those three perimeters overlap, the stricter prohibition governs.
In our cross-border practice, the scoping step regularly reveals that a business has been auditing against its home-country regime alone – and has never mapped extraterritorial reach. A European exporter may be auditing its EU dual-use controls thoroughly while leaving its US re-export exposure entirely untested. The perimeter map should be documented, owner-assigned, and treated as a living record that is refreshed whenever the business enters a new market, adds a new product line, or processes a new payment currency.
Practical outputs from this step include a jurisdictional matrix – listing each regime, the nexus that triggers it, the administering authority (OFAC, OFSI, the Council, BIS, ECJU, and others as relevant), and the primary prohibitions in scope. That matrix becomes the audit's terms of reference. Without it, you cannot know which gaps matter.
Step 2: Review the governance structure and written programme documentation
Before testing any operational control, an audit must establish whether the governance architecture that is supposed to own those controls actually exists and functions. The core question is whether senior management has formally adopted a compliance programme, assigned responsibility for it, and resourced it at a level proportionate to the business's risk profile.
OFAC's published guidance on the five essential elements of an effective compliance programme identifies management commitment, risk assessment, internal controls, testing and auditing, and training as the components regulators will examine in an enforcement context. OFSI and the EU Commission's enforcement guidance express comparable expectations, though the framing and documentation requirements differ in emphasis. An audit that finds only a policy document with no evidence of board ownership, no dedicated resource, and no testing history is already identifying a significant structural gap.
Document review in this step should cover: the written sanctions and export-control policy; the risk assessment; escalation and reporting procedures; screening tool configuration records; training completion logs; and any prior audit findings with evidence of remediation. The absence of remediation evidence for prior findings is itself a red flag – it suggests that testing is producing output that management is not acting on.
The position above covers the structural baseline. Your facts – the size of the business, the volume of transactions, the jurisdictions in play – change what "adequate" looks like in practice.
For an initial assessment of your programme's governance structure across the applicable regimes, contact Calder & Vance at info@caldervance.com.
Step 3: Test the screening controls – lists, tools, and ownership chains
Screening control testing is the operational core of a cross-border compliance audit. It examines whether the tools, lists, and procedures in place actually identify the names and entities the applicable regimes require the business to catch.
The first dimension is list coverage. OFAC's SDN List (the list of Specially Designated Nationals and blocked persons) is the central reference for US sanctions, but a complete cross-border screening programme must also cover the Entity List (administered by BIS), OFSI's consolidated list, the EU Consolidated List, and the UN Security Council Consolidated List. A business relying on a single-feed tool without confirming which lists it covers may be screening against an incomplete universe.
The second dimension is the ownership and control analysis. The 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) operates mechanically: it applies even where no listed entity appears on the face of the transaction. The EU and UK regimes apply an ownership and control test that extends to entities a listed person owns or controls, with control interpreted broadly – including through board influence, contractual rights, or veto powers over strategic decisions. Testing must verify that the business's tools and procedures surface indirect ownership, not just direct name matches.
In our experience, screening tools that flag only first-layer direct holdings consistently miss the aggregation pattern: two listed persons each holding a sub-threshold stake that together cross the 50 percent line. Have you run a structured ownership-chain test on your highest-volume counterparties in the last twelve months?
The third dimension is configuration accuracy: fuzzy-matching thresholds, transliteration settings, and the handling of aliases. A tool set to a very high confidence threshold will produce fewer alerts – but it will also miss phonetic variants and partial matches. Testing should include a set of synthetic test names that approximate known list entries, run blind to verify that the tool actually catches them.
Step 4: Audit the export-control classification and licence-management process
For businesses that manufacture, transfer, or procure goods, software, or technology with a potential military, dual-use, or controlled-technology dimension, the export-control layer of the audit is distinct from the financial-sanctions layer – and the two interact. A shipment that clears sanctions screening may still require a licence under the EAR, the UK Export Control Order, or the EU dual-use rules.
ECCN (Export Control Classification Number under the US Commerce Control List) classification must be confirmed for each product, and the audit should verify that classification decisions are documented, owner-assigned, and subject to review when a product is modified or a new destination market is added. Classification gaps are common where a business has grown rapidly and the classification process has not kept pace with product development.
The licence-management process should also be tested. This means verifying that any existing licences – whether general licences (standing authorisations permitting a defined category of transactions) or specific licences (case-by-case authorisations) – are current, that usage is being tracked against any permitted value or volume limits, and that the post-shipment reporting or end-use-certificate obligations attached to those licences are being met.
Cross-border complexity is acute here. A product may qualify for a licence exception under the EAR but still require a separate ECJU licence for a UK export. The audit must test whether the business's procedures address each applicable regime, not just the one with which the relevant team is most familiar.
What are the most common risk flags a cross-border compliance audit surfaces?
The most consistent findings across cross-border compliance audits fall into five categories, each representing a point where a control that appeared adequate on paper failed under operational conditions.
First, screening-list gaps. Businesses that implemented a tool several years ago and have not reviewed its list configuration frequently discover that new lists – or new list categories within an existing regime – are not covered. The EU and UK have added significant thematic and geographic list categories in recent years; an audit verifies that the tool's list feed reflects current scope.
Second, ownership-chain blind spots. As noted above, indirect ownership through intermediate holding companies – particularly in jurisdictions with limited beneficial-ownership disclosure – is the most common mechanism by which listed-person exposure enters a counterparty relationship undetected. Periodic enhanced due diligence on counterparties with complex ownership structures is the primary control against this risk.
Third, secondary-sanctions risk not assessed. Businesses headquartered outside the United States sometimes operate on the assumption that OFAC's secondary-sanctions programmes do not affect them. In our practice, this is one of the most significant misconceptions we address. Correspondent banking relationships, US-dollar clearing, and US-person involvement in a transaction can each create OFAC jurisdiction regardless of where the contracting parties are located.
Fourth, training records that do not match the operational population. A compliance audit that finds excellent training completion rates among the legal and compliance team but no training records for treasury, procurement, or logistics staff has identified a gap that an enforcement authority will also find. Training must reach the functions that actually make the decisions the controls are designed to govern.
Fifth, record-keeping that does not meet the applicable retention standard. OFAC's record-keeping requirements apply to a broad range of transaction documents and compliance records. OFSI and the EU impose comparable obligations. Where a business cannot produce documentation to support a past screening decision, it cannot demonstrate to a regulator that the decision was made – and that absence of evidence is treated as evidence of an absence of control.
If a transaction has already been flagged, or if a prior audit has produced findings that have not been fully remediated, an early review by specialist counsel can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.
Step 5: Assess the voluntary self-disclosure posture and incident-response readiness
An effective compliance programme includes a clear, tested procedure for what happens when a potential violation is identified. The audit of this procedure is often neglected – businesses focus on preventive controls and give less attention to detective and responsive controls. Regulators do not share that priority.
VSD (voluntary self-disclosure to a regulator) is a formal mechanism in the OFAC, OFSI, and EU enforcement regimes. OFAC's enforcement guidelines treat a timely, complete, and well-documented VSD as a significant mitigating factor in penalty calculation. OFSI's enforcement guidance reflects a similar approach. The benefit of a VSD is, however, conditional on the quality of the disclosure: an incomplete or delayed disclosure may not receive the same mitigation credit as a comprehensive one made promptly after the apparent violation is identified.
The audit should test: whether the business has a written incident-response procedure; whether that procedure assigns clear responsibilities for the decision to escalate, investigate, and disclose; whether it sets an internal timeline that is compatible with any applicable statutory or regulatory reporting window; and whether the procedure has been rehearsed – through a table-top exercise or a simulated escalation – within the past audit cycle.
Cross-border complexity applies here too. A matter that triggers a disclosure obligation under OFAC may simultaneously require reporting to OFSI and notification under an EU regulation. The procedures must address each regime's requirements, and the firm's external counsel should be identified in advance so that privilege can be established from the outset of an internal investigation.
Step 6: Produce findings and drive the remediation cycle
A compliance audit produces value only if its findings drive change. The final step is the production of a findings report that is precise enough to be actioned, prioritised by risk severity, and assigned to an owner with a defined remediation deadline.
Findings should be categorised by severity: critical gaps that represent immediate regulatory exposure; significant gaps that require remediation within a defined period; and observations that represent good-practice improvements. The critical and significant categories should each carry a recommended remediation action, an owner, and a target date. A findings report without those three elements is a description of a problem, not a plan to solve it.
Regulators examine remediation evidence, not just findings documentation. In an enforcement context, a business that can show that a prior audit identified a gap and that the gap was remediated – with dated evidence – is in a materially different position from one that identified the gap and took no action. The audit cycle has no value unless the remediation cycle closes the loop.
The review cycle for a cross-border compliance programme should be calibrated to the business's risk profile: high-risk profiles (high-volume cross-border transactions, exposure to multiple regimes, products with dual-use potential) warrant more frequent testing cycles. Lower-risk profiles may sustain an annual audit cycle. In all cases, a triggered review – outside the standard cycle – should follow any material change to the business's operations, counterparty base, or the regulatory environment.
Related practices
- Sanctions compliance audit and testing – Australia service – programme review under the Australian autonomous sanctions regime and its cross-border interactions.
- Compliance audit and testing cross-border guide (Part 2) – deeper coverage of screening-tool configuration, testing methodology, and audit documentation standards.
- Compliance audit and testing cross-border guide (Part 3) – remediation planning, escalation procedures, and managing a multi-regime incident response.