A UK-based trading company has operated for three years with a sanctions policy drafted at inception and never revisited. A new counterparty passes the automated screen. Six weeks later, an updated Consolidated List (the UN Security Council's list of designated persons and entities) shows a beneficial owner that was added during the gap between screen and settlement. OFSI opens an enquiry. The question is no longer whether the policy exists – it is whether it was ever tested.
Compliance audit and testing under OFSI means systematically examining whether a business's financial-sanctions controls actually work: reviewing policy, ownership mapping, screening logic, escalation procedures, and record-keeping against the requirements in OFSI's published enforcement guidance and the relevant thematic sanctions regulations under the Sanctions and Anti-Money Laundering Act ("SAMLA"). A well-tested programme reduces both the risk of a breach and the penalty exposure when things go wrong – because OFSI's enforcement guidance treats a strong compliance culture as a mitigating factor.
This guide walks through the audit in seven steps, addresses the cross-regime dimension that UK businesses routinely underestimate, and identifies the risk flags that most commonly surface in practice.
Step 1: Establish the legal basis and your obligations under OFSI
Before testing anything, a business must be precise about which obligations apply to it. OFSI administers UK financial sanctions under SAMLA and the thematic regulations made under it. The obligations bite on any person in the United Kingdom and any UK-connected person or entity outside it. That jurisdictional reach is wider than most compliance teams assume.
The core prohibitions cover: making funds or economic resources available to a designated person; dealing with property that is owned or controlled by a designated person; and circumventing those prohibitions. "Owned or controlled" – the ownership and control test (the UK standard for treating a non-listed entity as caught where a designated person owns or controls it) – applies across all OFSI regimes. Control is qualitative, not mechanical. A non-listed entity can be caught even where no single designated person crosses a formal threshold.
An audit starts by mapping which of the thematic regimes apply. A business dealing in goods, finance, and professional services may fall under several simultaneously. The audit scope must reflect that. Limiting review to the regime that prompted the last compliance event is one of the most common structural errors we see in businesses entering an audit for the first time.
The position above covers the standard case. Your facts – the sectors you operate in, the jurisdictions of your counterparties, the ownership depth of your corporate group – change the analysis. For a preliminary assessment of which regimes apply to your business, contact Calder & Vance at info@caldervance.com.
Step 2: Map ownership and control across your counterparty population
Ownership and control mapping is the structural core of any OFSI compliance audit. Unlike OFAC's 50 percent rule (OFAC's mechanical rule treating entities owned 50 percent or more by blocked persons as themselves blocked), the OFSI test asks whether a designated person owns or controls the entity. Control is not defined by a single percentage. Voting rights, board composition, contractual rights, and practical dominance can all constitute control.
In practice, this means the audit must go beyond the first layer of corporate structure. A counterparty may have no listed direct shareholder yet still be controlled by a designated person through a nominee arrangement, a trust, or cross-holdings in an intermediate holding company. The audit must trace the chain.
For each material counterparty, the audit should:
- Identify the ultimate beneficial owners to the level of natural persons.
- Run each natural person and each intermediate entity against the OFSI Consolidated List, the UN Consolidated List, and the EU asset-freeze lists (for completeness on the cross-regime picture).
- Document the source of ownership data and the date of verification.
- Record any flags, the escalation decision, and the outcome.
That documentation standard matters. OFSI expects businesses to keep records sufficient to demonstrate the decisions they made and why. A gap in the audit trail is itself an evidence problem in any subsequent enforcement review.
Step 3: Test your screening logic – not just your screening coverage
Most businesses can point to a screening tool. Far fewer can demonstrate that the tool is configured correctly, maintained up to date, and tested against known positives. That distinction is the one OFSI and compliance counsel focus on.
Screening logic testing means running controlled test cases through the live system. The test population should include:
- Names of currently designated persons drawn from the OFSI Consolidated List.
- Transliteration variants and alternative spellings of those names.
- Names of entities that are caught by the ownership and control test even though they are not directly listed.
- Names of individuals who appear on one regime's list but not another (OFAC-only designations, for example), to verify that the tool's scope matches the business's actual obligations.
The last category is important for businesses with US counterparties or US-dollar transactions. An OFAC-only designation does not trigger a UK obligation directly – but secondary-sanctions risk may mean the business needs to know about it anyway. A properly scoped audit documents which lists the tool covers and which it does not, so that gaps in coverage are a deliberate risk decision rather than an invisible blind spot.
Fuzzy-matching thresholds deserve particular attention. A threshold set too high will miss variants. A threshold set too low will generate so many false positives that genuine alerts are buried. We regularly advise businesses where the alert-to-review ratio has created de facto non-screening: every alert is cleared in seconds because volume has normalised dismissal. That pattern is a significant risk flag in any audit.
How does the OFSI audit differ from an OFAC or EU compliance review?
The OFSI audit shares structural features with an OFAC or EU review, but the differences in ownership test, enforcement posture, and reporting obligations are material enough that a single-template audit designed for one regime will underserve the others.
Under OFAC, the ownership test is the 50 percent rule: mechanical, aggregated, and percentage-driven. Under OFSI and the EU, control is the operative concept alongside ownership, and it is assessed qualitatively. An OFAC-compliant screen that stops at percentage thresholds will not capture control-based catch within the OFSI perimeter. In our experience, this is the most common gap in businesses that have adopted a US-designed compliance template across their UK operations.
Enforcement posture also differs. OFSI has the power to impose a monetary penalty on a strict-liability basis for certain breaches – meaning intent is not a prerequisite. A business can be penalised for a breach it did not know about if it could reasonably have known. The audit therefore needs to test not only whether controls caught known risks but also whether they were capable of catching reasonably foreseeable ones.
On the EU side, the relevant Council regulations impose their own reporting obligations and their own ownership-and-control test. The EU test is largely aligned with the OFSI approach, but there are points of divergence in how "control" is interpreted across member-state competent authorities. Businesses with EU operations should treat the EU audit as a parallel but distinct exercise. A single finding can trigger obligations under both regimes if the business has a UK entity and an EU-established subsidiary.
Switzerland (SECO), Canada (Global Affairs Canada), and Australia each operate their own financial-sanctions regimes with distinct list management and enforcement procedures. For a business with supply chains in those jurisdictions, the audit scope should address those regimes explicitly. We have acted for businesses that passed an OFSI-only audit and subsequently discovered a SECO exposure that had been invisible throughout.
If a transaction has already been flagged under one of these regimes, or a compliance review has surfaced a potential breach, time matters. An early review preserves options that narrow as the matter develops. Contact Calder & Vance at info@caldervance.com to discuss the position.
Step 4: Review escalation procedures and decision records
An escalation procedure that exists only in a policy document has not been tested. The audit must trace actual decisions: pick a sample of screening alerts from the past twelve months and reconstruct what happened.
For each sampled alert the audit should confirm:
- Who received the alert and when.
- What information was gathered before a clearance or escalation decision was made.
- Who made the final decision and at what seniority level.
- Whether the decision was documented, with the reasoning recorded.
- Whether any OFSI reporting obligation arose and, if so, whether the report was made.
OFSI's enforcement guidance makes clear that voluntary disclosure of a breach, and cooperation with OFSI's enquiries, are mitigating factors in penalty assessment. But voluntary disclosure can only be made if the business knows a breach occurred. An escalation procedure that is never tested may mean that a breach passes through the system without triggering the review that would have identified it. That failure compounds the original violation.
The reporting obligation itself merits discrete attention. UK financial sanctions law imposes an obligation on certain persons in the financial sector to report knowledge or reasonable cause to suspect that a person is a designated person or that a breach has occurred. The audit must identify which personnel are subject to that obligation, confirm that they understand it, and test whether the business's procedures would cause the report to be made within the applicable window.
Step 5: Assess record-keeping and documentary compliance
Record-keeping is often the element of an OFSI compliance programme that audit most readily identifies as deficient – not because the business has made the wrong decisions, but because it has not retained the evidence of the right ones. OFSI's guidance and the requirements under SAMLA set minimum standards for record retention. The audit must verify that those standards are met in practice, not only in policy.
Key areas for the audit to assess:
- Screening records: are the results of each screen retained, including the date, the lists screened against, the tool version, and the outcome?
- Ownership and control investigations: are the underlying documents (corporate registry extracts, UBO declarations, trust deeds where obtained) retained alongside the analysis?
- Licence records: where the business has relied on a general licence (a standing authorisation permitting a defined category of transactions without a separate application) or a specific licence (a case-by-case authorisation from OFSI), are the licence, the reliance decision, and the transaction records retained together?
- Reporting records: are copies of any reports made to OFSI retained, with evidence of timely submission?
Five years is the retention period cited in a number of UK financial-crime and sanctions contexts. Businesses should ensure that their records policy reflects applicable requirements and is reviewed periodically. Verify the current position before relying on any stated period.
Step 6: Identify risk flags and common audit failures
What does a compliance audit under OFSI most commonly find? The pattern across businesses of different sizes and sectors is more consistent than the variety of their operations would suggest. Risk flags cluster around four recurring failures.
Policy staleness. The policy was written at incorporation or at the last funding round and has not been updated since. The thematic regulations have changed; the ownership-and-control guidance has been clarified; OFSI's enforcement posture has sharpened. The policy reflects none of it.
Screening coverage gaps. The tool covers OFSI's Consolidated List and perhaps the UN list. It does not cover EU asset-freeze lists or OFAC's SDN List. For a business with EU or US counterparties, those gaps are material – not because EU and OFAC designations directly create OFSI obligations, but because secondary-sanctions exposure and the business's own contractual warranties may require broader coverage.
Ownership investigation depth. The business screens entity names but does not investigate beneficial ownership beyond the first corporate layer. The OFSI ownership and control test requires depth. The audit should verify that the procedure requires investigation to the level of natural persons.
Training recency. Staff who handle screening or make escalation decisions have not received updated training since the policy was last reviewed. OFSI's enforcement guidance treats staff training as a component of a compliant programme. An audit that finds no training records for the past two years is recording a structural deficiency, not a minor gap.
Is your compliance programme up to date, or is it the version that was good enough three years ago? That question should prompt a review before OFSI asks it on your behalf.
Step 7: When to involve external compliance counsel
Many businesses conduct initial compliance reviews using internal resources. That is reasonable for a first-pass gap analysis. External compliance counsel adds most value in four situations.
First, where the audit has surfaced a potential breach. Internal teams are poorly positioned to assess whether a breach occurred, whether it is reportable, and whether voluntary disclosure is advisable. Those are legal judgments. They carry consequence. A decision not to disclose – if it later turns out a breach occurred and reporting was required – can convert a civil matter into a more serious one.
Second, where the business has cross-regime exposure. A business operating under OFSI, EU Council regulations, and OFAC simultaneously needs an audit that can assess all three. The tests differ. The reporting obligations differ. The enforcement consequences differ. An audit that addresses only OFSI is accurate as far as it goes and incomplete for the business's actual risk.
Third, where the business is entering a new sector or jurisdiction. Sanctions obligations can attach unexpectedly. A payments business expanding into a new corridor, a manufacturer adding a new product line with dual-use characteristics, a fund acquiring a target with complex ownership – each of these warrants a fresh assessment before the activity begins.
Fourth, where a regulator has been in contact. OFSI communications, including voluntary-disclosure acknowledgements, requests for information, and enforcement notices, should be handled with legal assistance from the outset. The decisions made in the early stages of a regulatory engagement affect every stage that follows.
Related practices
- Compliance audit and testing – Australia – DFAT-regime sanctions audit and compliance review for Australian-connected businesses.
- OFSI compliance audit: advanced issues – deeper treatment of licensing reliance, voluntary disclosure, and enforcement-phase audit considerations.
- OFSI compliance testing: sector-specific approaches – tailored audit frameworks for financial institutions, payment firms, and professional-services businesses.