Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Compliance audit and testing under OFSI: procedure and pitfalls

A UK-based financial institution completes its annual review of correspondent banking relationships. Screening passes clean. Three months later, OFSI writes to ask whether the institution has reviewed its exposure to a newly designated entity – one that holds an indirect stake in a counterparty the institution has been settling payments for since the designation date. The relationship was never re-screened after the designation. The question now is not whether there was a breach, but how serious OFSI will judge the compliance failure to have been.

Compliance audit and testing under OFSI is the structured process by which a business verifies that its financial-sanctions controls work as intended, identifies gaps before OFSI does, and demonstrates to the regulator a culture of active, not passive, compliance. As of July 2026, OFSI's published enforcement guidance makes clear that the quality of a firm's compliance programme is a material factor in penalty decisions – meaning a well-evidenced audit trail can directly affect the severity of any outcome.

This guide sets out the procedure for auditing and testing an OFSI-facing compliance programme, the cross-regime comparisons that matter for cross-border businesses, and the risk flags that most frequently convert a gap into an enforcement matter.

Step 1: Establishing the audit scope and legal basis

The first step is to define what the audit is testing and under which legal authority compliance is owed. OFSI derives its mandate from the Sanctions and Anti-Money Laundering Act ("SAMLA") and the thematic sanctions regulations made under it. The audit scope must therefore map the firm's activities to those instruments – not to a generic sanctions checklist.

In practice, scope definition requires three decisions. First, which designated-person lists are relevant: the UK Consolidated List, sector-specific asset-freeze lists, and any United Nations Consolidated List obligations that are carried through into UK law. Second, which transaction flows, account relationships, or service lines are within the firm's sanctions perimeter. Third, whether the firm has any activities touching non-UK jurisdictions that could bring OFAC or EU rules into concurrent application.

Scope-creep in the opposite direction – auditing only the UK perimeter when the firm has US-dollar clearing or EU-regulated subsidiaries – is a persistent mistake. We regularly advise businesses that discover mid-audit that their UK-facing OFSI review has entirely missed an OFAC secondary-sanctions exposure sitting in the same transaction book. The regimes are parallel obligations; the audit must treat them that way.

A written audit charter, approved at board or senior management level before fieldwork begins, is the documentary foundation that OFSI's enforcement guidance treats as a positive indicator. It should name the auditor, define the population being tested, set the testing methodology, and record the approval date.

Step 2: Mapping ownership and control across the screened population

The most technically demanding part of any OFSI audit is verifying that the ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person's ownership or direction of that entity) has been applied correctly to the firm's counterparty population. OFSI's position mirrors the EU approach: both apply an ownership threshold and a separate control limb, meaning a counterparty can be caught even where no single designated person holds a majority stake.

The audit methodology for this step should include: pulling the beneficial-ownership data used at onboarding; tracing each ownership chain to its ultimate beneficial owner; checking each node in that chain against the UK Consolidated List and the UN Consolidated List; and then asking whether any non-listed intermediary is nonetheless controlled by a designated person through board composition, contractual rights, or other governance mechanisms.

Where does this differ from the OFAC position? Under OFAC, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked) is a mechanical aggregate-ownership test. Control is a secondary consideration. Under OFSI and the EU, control can capture a counterparty independently of ownership percentage. A firm that has built its audit methodology around the OFAC threshold alone will systematically under-screen for UK purposes.

In our experience, the gap most often appears in relationships with complex group structures where a designated person holds, say, thirty-five percent directly but sits on the target entity's board and has contractual approval rights over material transactions. The OFAC test may not be triggered. The OFSI control limb may well be.

Step 3: Testing transaction monitoring and screening logic

Audit fieldwork on screening and transaction monitoring should be structured as a two-part exercise: first, a design-effectiveness test; second, a process-effectiveness test. Neither alone is sufficient.

Design-effectiveness testing asks whether the screening logic is calibrated to catch the right things. This means checking fuzzy-match thresholds against a sample of name variants for listed individuals, verifying that the system ingests list updates within a defensible timeframe after designation, and confirming that beneficial-ownership data feeds into the screening process rather than sitting in a separate database that the screening system cannot read.

Process-effectiveness testing asks whether the controls actually operated as designed during the audit period. Auditors should pull a sample of transactions and trace them through the screening workflow, checking for manual overrides, alert closures without adequate documentation, and cases where a positive match was cleared on the basis of a nationality or date-of-birth field without a full ownership check being completed.

How quickly must a firm act when screening identifies a potential match? The time within which a firm must report knowledge or suspicion of a designated person's assets or sanctions breach to OFSI is defined in the relevant thematic regulations. That window is short; verify the precise current obligation before relying on any figure. The audit should confirm that the firm's escalation procedure is calibrated to meet that window, and that the procedure has actually been followed on each occasion a potential match was escalated during the period under review.

A cross-regime note: OFAC's reporting obligations follow a different timeline and are routed through OFAC directly, not through a domestic AML-style suspicious-activity report channel. EU firms face obligations routed through national competent authorities. A business operating across all three perimeters should audit each reporting channel separately and confirm that staff know which channel applies to which event.

What is the most common mistake in compliance audit and testing?

The single most common failure we observe is treating the compliance audit as a documentation exercise rather than a controls test. Firms produce policies, procedures, and training records – all of which are genuine compliance artefacts – but do not run the transaction sample, do not test the screening logic against known variants, and do not verify that the escalation chain actually functioned. When OFSI later reviews the same period in the context of an apparent breach, it looks past the policy documents and asks whether the controls worked in practice.

A second, closely related failure is the one-person compliance function that both designs the controls and audits them. Independence of the audit function is not a formality. OFSI's published enforcement guidance on compliance programmes treats it as a structural requirement. Where a firm's resource constraints genuinely prevent full independence, the audit charter should record the limitation and explain the compensating control – typically an annual independent review by external compliance counsel.

A third failure is the static audit. An annual audit completed in January that is not revisited when a major new designation package is issued in October provides comfort that expired before the risk materialised. The audit programme should include a trigger-based review component: when a new sanctions package is issued in a relevant regime, a targeted review of the affected counterparty population is conducted within a defined number of business days.

For businesses concerned about whether their current programme could withstand regulatory scrutiny, the position above covers the standard picture. Your sector, the volume and nature of your transactions, and the jurisdictions in which you operate will all change the analysis. To discuss a confidential review, contact Calder & Vance at info@caldervance.com.

Step 4: Record-keeping, evidence assembly, and the five-year obligation

OFSI's record-keeping requirements are set out in the relevant thematic sanctions regulations. The audit must verify that records are retained for at least five years from the date of the relevant transaction or the end of the business relationship, whichever is later. This figure is drawn from the UK sanctions record-keeping obligation and should be verified against the specific regulation applicable to the firm's sector.

What counts as a record for this purpose? The audit should test whether the firm's document-retention policy captures screening outputs and the data used as the basis for the screen (not just the final alert decision), beneficial-ownership documentation obtained at onboarding and at any subsequent refresh, escalation and closure records for every alert generated during the period, all correspondence with OFSI including any licensing applications or reports made, and board and senior-management papers approving the compliance programme and any material changes to it.

Evidence assembly matters not only for a future OFSI review but for the firm's own ability to demonstrate what it knew, when it knew it, and what it did about it. In a matter we handled for a payment-services business, the records were complete on the screening side but contained no documentation of the ownership-chain analysis for a counterparty group that was later the subject of a OFSI inquiry. The absence of that record made it impossible to demonstrate that the analysis had been conducted, even though the compliance team's recollection was that it had been.

Cross-regime consideration: OFAC's record-keeping expectations operate on a similar multi-year timeframe, and BIS under the Export Administration Regulations ("the EAR") has its own record-keeping obligations for export-controlled transactions. A business subject to multiple regimes should align its retention policy to the longest applicable period so that a single retention schedule covers all obligations.

Step 5: Escalation, remediation, and voluntary self-disclosure

When audit fieldwork identifies an apparent failure – a transaction that should have been blocked was not, a designated person's assets were not frozen on the correct date, a report that should have been made to OFSI was not – the question of what to do next is often more consequential than the underlying gap itself.

The first decision is scope of the failure. Before any external communication, the firm should conduct an internal investigation sufficient to understand the population of affected transactions, the date range, and the approximate value. OFSI's enforcement guidance is explicit that the quality of the firm's internal investigation before contact with OFSI is a factor it weighs in determining penalty.

The second decision is whether to make a voluntary self-disclosure (VSD, a voluntary disclosure to the regulator of an apparent sanctions breach before the regulator becomes aware of it independently). Under OFSI's published guidance, a VSD is a mitigating factor in the penalty calculation. It is not an amnesty; it does not extinguish liability. But the difference between a co-operative early disclosure and a breach discovered through a third-party tip or a OFSI-initiated review can be material to the outcome.

Timing is critical. A VSD made before OFSI becomes aware of the breach carries greater mitigation weight than one made after OFSI has already begun a review. The audit process, if well-designed, will surface issues while there is still time to make an early VSD. An audit that completes, files its report, and then delays remediation action forfeits part of that advantage.

If a transaction has already been flagged, or a filing has already been made without adequate basis, an early review of the remediation options can preserve choices that narrow as time passes. For advice on a live OFSI compliance issue, contact us at info@caldervance.com.

How does OFSI differ from OFAC and EU regulators on compliance programme assessment?

The three major regimes – OFSI, OFAC, and the EU national competent authorities – each assess compliance programmes, but the emphasis, the published guidance, and the enforcement levers differ in ways that matter for a cross-border business designing a single audit methodology.

OFSI publishes explicit guidance on what a compliance programme should contain and how the existence of a programme will be weighed in enforcement decisions. The guidance identifies governance structure, senior management responsibility, risk assessment, due diligence, screening, record-keeping, and training as the core elements. Critically, OFSI's enforcement approach under SAMLA allows it to impose a monetary penalty on a strict-liability basis for certain breaches – meaning that the absence of knowledge is not a complete defence, though it may affect penalty quantum. The existence of a demonstrably effective compliance programme is one of the factors OFSI considers when exercising its discretion on whether to impose a penalty and at what level.

OFAC's framework for assessing compliance programmes is set out in its published compliance guidance, which describes five essential components: management commitment, risk assessment, internal controls, testing and auditing, and training. OFAC's Enforcement Guidelines treat the existence of a sanctions compliance programme as a mitigating factor, and the absence of one as an aggravating factor. The structural parallel with OFSI is real, but the specifics of what counts as adequate differ – particularly on the ownership test and on the handling of information from non-US group entities.

EU national competent authorities – the bodies in each member state responsible for enforcing the Council regulations – apply the EU framework, which does not have a single consolidated compliance-programme standard equivalent to the OFSI or OFAC published guidance. Practice varies by member state. A business with EU-regulated entities should audit each against the standard applicable in that jurisdiction, which may be articulated through national law, supervisory circulars, or case-by-case enforcement decisions rather than a single published document.

In our cross-border practice, we frequently advise businesses that have built their programme around the OFAC five-component model and assumed it will satisfy OFSI. The overlap is significant but not complete. The ownership-and-control test, the reporting-channel structure, and the interaction with AML obligations under the Proceeds of Crime Act all require OFSI-specific treatment that a pure OFAC design will miss.

Risk flags and when to involve compliance counsel

Certain indicators in the audit fieldwork should prompt immediate escalation to legal counsel rather than being handled as routine remediation items. Recognising these flags early determines whether a firm retains the benefit of a VSD and controls the narrative of any regulatory engagement.

The first flag is a transaction gap of any size involving a designated person or an entity that the ownership-and-control test captures. Any apparent breach, however small in value, creates a reporting obligation under the relevant regulations and triggers OFSI's enforcement jurisdiction. The appropriate response is not to monitor and wait; it is to scope the position and advise on disclosure.

The second flag is a pattern of alert closures without documented ownership-chain analysis. A series of screening hits that were closed with the notation "not same person" but with no record of how that conclusion was reached will not satisfy OFSI's expectation of a documented and defensible decision. A pattern of such closures, once identified in audit fieldwork, should be treated as a systemic control failure rather than an individual error.

The third flag is management override of compliance recommendations without documented rationale. In our experience, the most acute enforcement risk in financial institutions arises not from technical screening failures but from commercial pressure that overrides a compliance recommendation. If the audit surfaces instances of this, legal review is required before any external communication about the programme is made.

A common myth in this area is that a compliance audit is primarily a reputational exercise – something firms do to show regulators they are trying. That framing misunderstands OFSI's enforcement posture. OFSI uses compliance-programme evidence actively: a well-documented and independently tested programme can reduce a penalty; a poorly documented or untested one can increase it. The audit is not window-dressing. It is evidence.

Related practices

Frequently asked questions

What are the steps to audit and test a compliance programme under OFSI?
An OFSI compliance audit proceeds in five structured phases: defining the audit scope against the applicable thematic sanctions regulations; mapping ownership and control across the screened counterparty population; testing the design and operational effectiveness of screening and transaction-monitoring controls; verifying that record-keeping meets the statutory retention period (at least five years under the relevant regulations); and assessing escalation and remediation procedures, including the capacity to make a timely voluntary self-disclosure. Each phase should be documented in writing and approved by senior management. The output is an audit report setting out findings, remediation actions, and a timeline for closure.
What is the most common mistake in compliance audit and testing?
The most common mistake is auditing policy rather than controls. Firms produce compliant-looking documents – written procedures, training logs, screening-system records – but do not test whether those controls actually prevented a prohibited transaction or correctly identified a designated person during the audit period. OFSI's enforcement guidance is explicit that a demonstrated commitment to compliance requires evidence that controls functioned, not merely that they existed. A second frequent error is failing to apply the OFSI control limb of the ownership-and-control test, relying instead on the OFAC mechanical-threshold approach, which does not capture control exercised through governance rather than majority ownership.
How does OFSI differ from other regimes here?
OFSI publishes detailed compliance-programme guidance under SAMLA and assesses a firm's programme as a material factor in enforcement decisions, including penalty quantum. This is broadly comparable to OFAC's published five-component framework. The key differences are: OFSI applies both ownership and control limbs, whereas OFAC's primary test is a mechanical 50 percent ownership aggregate; OFSI's penalties operate on a strict-liability basis for certain breaches, making the programme's documented effectiveness directly relevant to outcome; and OFSI's reporting obligations are channelled through its own process rather than through an AML-reporting parallel. EU national competent authorities operate without a single consolidated programme standard, so the applicable benchmark varies by member state.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.