Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Compliance audit and testing under OFSI: step by step

A UK-headquartered trading group has operated a sanctions compliance programme for three years. The programme has a policy, a screening tool, and annual training. On paper, it looks complete. Then OFSI opens a review. Within days, the compliance team discovers that the screening tool has not been updated to reflect new designations, that ownership-chain checks stop at the first layer, and that no one has tested whether the policy matches actual practice. The programme existed – but it had never been audited.

Compliance audit and testing under OFSI is the structured process by which a business verifies that its sanctions controls actually work, not merely that they exist. OFSI's enforcement guidance makes clear that the quality and effectiveness of a firm's compliance programme is a material factor in its assessment of any apparent breach. As of July 2026, OFSI has the power to impose civil monetary penalties on a strict-liability basis, meaning that a well-evidenced compliance programme is one of the few levers available to a business seeking to mitigate exposure.

This guide walks through the audit and testing process step by step, compares OFSI's expectations with those of OFAC and the EU, and identifies the risk flags that most commonly surface during a review.

Step 1: Understand what OFSI expects from a compliance programme

OFSI's enforcement guidance describes a compliance programme in terms of five elements: senior management commitment, a written policy, risk assessment, screening and due-diligence procedures, and ongoing monitoring and training. Any audit must measure the existing programme against each of those elements before testing can begin.

The governing legal basis is the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic regulations made under it. OFSI administers UK financial sanctions and publishes both its consolidated list and its licensing and enforcement guidance. The guidance is not a regulation, but OFSI treats adherence to it as evidence of good-faith compliance. In our experience, firms that have not read the enforcement guidance before an OFSI review are consistently behind in their preparation.

A gap analysis at this stage – comparing the written programme against OFSI's published five-element standard – is the foundation of every audit. Where a gap exists in writing, testing will almost certainly confirm it in practice. The reverse is also true: a gap that appears minor on paper can be critical in a live transaction, particularly where counterparty ownership structures are complex.

Step 2: Scope the audit – assets, counterparties, and reporting lines

An OFSI audit must cover every asset type the business holds or controls, every counterparty category it transacts with, and every reporting line through which a sanctions concern might travel. Scoping is the stage most often compressed under time or cost pressure – and the compression is almost always a mistake.

The correct scope starts with the legal perimeter: which entities in the corporate group are subject to UK financial sanctions law? Under SAMLA and the relevant thematic regulations, the territorial reach extends to persons in the United Kingdom and to UK persons wherever they are located. For a multinational, that typically means that UK-incorporated entities and UK nationals sitting on overseas subsidiaries are within scope, even if the relevant transaction is booked offshore.

A cross-border group must also consider whether activities that fall outside OFSI's direct perimeter are caught by OFAC or an EU Council regulation. In our practice, we regularly see situations where a non-UK affiliate is transacting in a way that would be prohibited under OFAC's secondary sanctions reach, without any corresponding OFSI exposure. The audit scope must identify that overlap clearly and decide which regime governs each entity. Where both regimes apply – and the stricter prohibition governs – the audit should record that conclusion and the reasoning behind it.

Once the legal perimeter is confirmed, the audit team should map: payment flows, trade-finance instruments, securities holdings, loan books (where the firm is a financial institution), and any material service agreements. Each category requires a separate testing methodology.

Step 3: Test screening controls – logic, data, and update cadence

Screening-control testing is the technical core of the audit. Its purpose is to verify that the firm's screening tool is calibrated to detect the names it is required to detect, at the right point in each business process, using current data.

Three failure modes recur. First, stale data: the OFSI consolidated list is updated on a rolling basis, sometimes with very short notice after a new designation. A tool that draws on a weekly batch feed will miss designations made in the intervening days. The audit must establish the update frequency, compare it against OFSI's designation cadence, and determine whether the gap creates a realistic exposure window. Second, fuzzy-matching calibration: too narrow a threshold produces missed hits; too broad a threshold creates an unworkable volume of false positives, which in turn leads to "alert fatigue" and genuine hits being dismissed. Third, coverage gaps: many firms screen at onboarding but not at the point of payment. OFSI's regime prohibits dealing with a designated person even if that person was not designated at the time of the original contract. Payment-point screening is not optional.

How do you test fuzzy matching? The most direct method is a seeded-name test: introduce controlled variants of known listed names – spelling variants, transliterations, reversed name orders – and record which variants the tool surfaces. Document the results. If variants that would be considered close matches by a human reviewer are not surfacing, the threshold requires adjustment.

Ownership-chain testing is a related but distinct exercise. The ownership and control test under UK financial sanctions (the test for whether a non-listed entity is caught through a listed person's ownership or control) requires the firm to look through layers of intermediate companies. A screening tool that flags only direct listed-person matches will not perform this analysis. A manual or semi-manual ownership-chain review is necessary for higher-risk counterparties, drawing on corporate registry data, beneficial-ownership registers, and, where warranted, third-party intelligence providers.

The position under OFAC is instructive by comparison. OFAC's 50 percent rule (the rule treating entities owned 50 percent or more by blocked persons as themselves blocked) is mechanical and aggregative. OFSI's equivalent test requires an assessment of both ownership and control. Control is not defined by a single percentage threshold; it can arise through contractual arrangements, board composition, or voting rights. A firm that has calibrated its controls to catch OFAC's 50 percent rule only may well miss a control-based exposure under OFSI. The audit must verify which test applies to each counterparty and whether the screening methodology matches.

Step 4: Review licensing, reporting, and record-keeping

The audit's fourth step moves from detection to response: what does the firm do when it identifies a potential match or a blocked asset, and does that procedure meet OFSI's requirements?

OFSI issues both general licences (standing authorisations that permit a defined category of transactions without a separate application) and specific licences (case-by-case authorisations). The audit should confirm that any general licence the firm is relying on has been properly identified, that its conditions are being met, and that the firm is recording its reliance on it. A general licence is not a blank permission; most carry conditions on use, reporting, and record-keeping. Where a specific licence has been granted, the audit should verify that transactions are being conducted within its exact terms and that any reporting conditions are met on time.

Reporting obligations under OFSI's regime apply both to financial institutions that hold or are aware of funds belonging to a designated person and to any person that contravenes a prohibition. The audit must map the firm's incident-identification process and confirm that escalation paths lead to a timely report. There is a statutory obligation to report; it is not discretionary.

Record-keeping is often treated as an administrative function. In enforcement, it becomes critical. OFSI and, for comparison, both OFAC and the EU Council regulations require firms to maintain records of transactions, screening results, due-diligence conclusions, and licensing activity for a defined period. The audit should verify that records are being made contemporaneously, that they are retrievable, and that retention schedules are being applied. A firm that cannot produce records to demonstrate that it screened a counterparty is in a materially different enforcement position from one that can.

The position under OFAC is that firms are expected to maintain records for five years from the date of a transaction or the date of a licence, whichever is later. EU practice is broadly similar. The OFSI expectation should be confirmed against the relevant thematic regulations currently in force; verify the current period before relying on it.

The position above covers the standard case. Your facts – the asset types, the counterparty mix, the group structure, and the licensing position – change the analysis materially. For a structured review of your programme's compliance with OFSI's expectations, contact Calder & Vance at info@caldervance.com.

Step 5: Assess training, governance, and senior-management accountability

Sanctions controls fail most often not because the policy is wrong, but because the policy is not followed. Testing training and governance effectiveness is therefore as important as testing the screening tool itself.

The audit should establish: who receives sanctions training, how frequently, and whether the content is specific to the firm's risk profile or a generic module purchased from a provider. Generic training demonstrates awareness; role-specific training demonstrates that the firm has understood its exposure. OFSI's enforcement guidance refers to the quality of the compliance programme as a whole; a training record full of ticked boxes but lacking any evidence that staff can apply the rules to real situations will not carry the weight the firm assumes it will.

Senior management commitment is the first of OFSI's five elements for good reason. An audit should verify that sanctions risk appears on the board or executive risk agenda, that senior management has approved the policy in writing, and that there is a named individual – typically a senior compliance officer or Money Laundering Reporting Officer equivalent – with clear accountability for the sanctions programme. Where that accountability is diffuse or unrecorded, it is a gap that OFSI and, in cross-border matters, OFAC and the EU authorities will each note.

Governance testing often surfaces a structural problem: the compliance function is adequately resourced in normal conditions, but there is no escalation path or contingency when the named individual is unavailable. A designation can be issued on any business day. The response window matters. We regularly advise firms to test their escalation procedure explicitly – including out-of-hours scenarios – rather than assuming it will work when the moment comes.

Step 6: Document findings, remediate, and plan the next review cycle

An audit without a documented output has limited value. The written audit report is the evidence that a serious compliance effort was undertaken – and in an OFSI enforcement context, it is one of the most important documents the firm can produce.

The report should record: the scope of the audit, the methodology used for each testing exercise, the findings by category (policy, screening, licensing, reporting, training, governance), the risk rating applied to each finding, and the remediation steps agreed. Risk ratings need not be complex; a three-point scale (high, medium, low) applied consistently is more useful than an elaborate matrix applied inconsistently.

Remediation should be assigned to named individuals with defined completion dates. Findings that require investment – a new screening tool, additional headcount, a board-level policy review – should be escalated with a business case rather than parked. In our experience, firms that fail to act on audit findings are in a significantly worse enforcement position than firms that identified the same finding and remediated it, even if the remediation was not complete at the time of the apparent breach. OFSI's enforcement guidance treats the existence and quality of the compliance programme as a mitigating factor; a remediation plan that was underway is evidence of that quality.

The audit cycle should be formally scheduled. A single audit completed once is evidence of a point-in-time review. An audit programme with documented cycles – annual, or triggered by material changes in the firm's risk profile or in the designated-persons list – is evidence of an ongoing commitment. Material triggers that should prompt an ad-hoc review include: a significant new designation in a relevant sector; a change in the firm's business that extends its sanctions exposure; any apparent breach or near-miss; and any change in the firm's ownership or senior-management structure.

If a transaction has already been flagged, or if an OFSI enquiry has been received, an early review of the programme's documented record can preserve options that narrow with time. For a confidential review of a potential breach or a gap in your compliance record, contact us at info@caldervance.com.

Cross-regime comparison: how OFSI's audit expectations differ from OFAC and the EU

OFSI's approach to compliance-programme assessment shares a common structure with OFAC's five-element framework and the EU's supervisory expectations, but there are practical differences that affect audit design for cross-border businesses.

OFAC's compliance programme guidance, issued under IEEPA, sets out five components that mirror OFSI's structure: management commitment, risk assessment, internal controls, testing and auditing, and training. The language of "testing and auditing" as a discrete component is explicit in OFAC's published guidance in a way that OFSI's guidance frames more broadly. For a US-nexus business, this means that an OFAC-aligned audit programme will almost always cover the technical testing exercises described above; the firm simply needs to verify that the same rigour is applied to the OFSI perimeter.

The EU position is administered at member-state level through competent authorities, with the relevant Council regulation and Council Decision setting the prohibitions. There is no single EU-level compliance-programme standard equivalent to the OFAC or OFSI guidance; supervisory expectations vary by member state and by sector. A firm that operates both a UK entity and an EU entity will need to confirm that the audit covers each perimeter separately and records the divergence between ownership-and-control tests, licensing routes, and reporting obligations.

One substantive divergence deserves emphasis. The UN Security Council Consolidated List operates as the baseline for most national regimes, including OFSI's. A firm that screens against the UN list only will not be compliant with OFSI, which maintains its own consolidated list that includes autonomous UK designations – persons designated by the UK alone, not mirrored on the UN list. After the UK's departure from the EU, autonomous UK designations and autonomous EU designations have diverged. An audit that does not specifically test for coverage of autonomous designations across each applicable regime is incomplete.

Is your screening tool drawing on all three lists – UN, OFSI, and EU – where they are each relevant to your business? In our cross-border practice, the answer is more often "no" than compliance teams initially expect.

Related practices

Frequently asked questions

What are the steps to audit and test a compliance programme under OFSI?
An OFSI compliance audit runs in six steps: (1) gap-analysis against OFSI's five-element standard; (2) scoping the audit perimeter – entities, assets, and counterparties within UK financial-sanctions reach; (3) testing screening controls for data currency, fuzzy-matching calibration, and ownership-chain coverage; (4) reviewing licensing, reporting, and record-keeping procedures; (5) assessing training, governance, and senior-management accountability; and (6) documenting findings, remediating gaps, and scheduling the next review cycle. Each step should produce a written output that forms part of the firm's compliance record.
What is the most common mistake in compliance audit and testing?
The most common mistake is treating the existence of a policy and a screening tool as evidence that the programme works, without testing whether either actually performs in practice. Screening tools that are not updated to reflect new OFSI designations, ownership-chain checks that stop at the first layer, and training records that show completion but not comprehension are the three failure modes we encounter most regularly. An audit that tests only documentation rather than operational performance will miss all three.
How does OFSI differ from other regimes here?
OFSI's ownership-and-control test extends beyond ownership percentage to encompass control through contractual or structural means, unlike OFAC's mechanical 50 percent aggregation rule. OFSI also maintains its own consolidated list of UK autonomous designations that is distinct from the UN Consolidated List and, since the UK's departure from the EU, has diverged from EU autonomous designations. A firm calibrated to OFAC's rule only, or screening solely against the UN list, will not meet OFSI's standard. The audit must test coverage of each list separately where multiple regimes apply.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.