Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Sanctions compliance programmes under OFSI: step by step

A UK-based financial institution onboards a new correspondent banking relationship. Six months later, a periodic screening run flags a beneficial owner two tiers above the counterparty. The compliance team asks: does our current programme actually tell us what to do next? Do we have the right ownership-mapping methodology? Is our reporting obligation already triggered? For many cross-border businesses, the honest answer is that the programme was designed quickly, tested rarely, and has never been stress-tested against a live OFSI scenario.

An effective sanctions compliance programme under OFSI (the Office of Financial Sanctions Implementation, the UK authority responsible for financial sanctions licensing and enforcement under the Sanctions and Anti-Money Laundering Act 2018, "SAMLA") rests on five elements: governance and ownership, risk assessment, screening and detection, response and reporting, and record-keeping. As of July 2026, OFSI's enforcement posture has sharpened considerably – the authority now issues monetary penalties on a strict-liability basis for the most serious breaches – which means a programme built on good intentions rather than documented controls no longer satisfies the standard OFSI expects.

This guide walks through each design step in sequence, compares the OFSI approach with equivalent requirements under OFAC and the EU Council regulations, and identifies the risk flags that most commonly indicate a programme is not fit for purpose.

Step 1: Establish governance and senior ownership

No compliance programme operates effectively without a named senior owner who carries formal accountability for it. Under OFSI's enforcement guidance, the quality of a firm's compliance arrangements is a factor in how the authority assesses culpability and, therefore, in how it approaches a potential penalty. That creates a direct commercial reason – beyond the legal obligation – to get governance right from the outset.

In practice, governance means three things. First, a board-level resolution or equivalent governing document that identifies the sanctions compliance function, allocates its resources, and commits to periodic review. Second, a named individual – usually a Chief Compliance Officer, a Money Laundering Reporting Officer, or equivalent – with a clear mandate to maintain and report on the programme. Third, a reporting line that goes to the board or audit committee, not merely to a management-level committee with no escalation path.

We regularly advise businesses that believe a line in the group-wide compliance policy is sufficient. It is not. OFSI looks for evidence that senior management has actually engaged with sanctions obligations – that the person at the top of the reporting line understands what the programme requires and has approved the resources to run it. A policy that no executive has read and no board has discussed is, from an enforcement standpoint, close to no policy at all.

Cross-border businesses face an additional challenge here. A UK subsidiary of a multinational may sit inside a group governance structure designed primarily for OFAC or EU obligations. The group framework may be strong, but if it does not capture OFSI-specific requirements – including the UK's own ownership-and-control test, its licensing routes, and its voluntary self-disclosure ("VSD") mechanism (the formal process of self-reporting a potential breach to OFSI before the authority discovers it independently) – then the subsidiary's programme is incomplete whatever the group policy says.

Step 2: Conduct and document the sanctions risk assessment

A documented sanctions risk assessment is the foundation on which all subsequent programme decisions rest. Without it, screening scope, customer-risk ratings, and transaction-monitoring thresholds are guesses rather than calibrated controls.

The risk assessment should map four dimensions of the firm's exposure. First, customer base: which jurisdictions, sectors, and ownership structures appear in the portfolio and how does that overlap with OFSI's current designations and the regimes they implement? Second, products and services: which offerings create the greatest risk of touching a designated person or blocked asset – trade finance, correspondent banking, payment processing, and securities settlement all carry different profiles. Third, geography: does the business have operations, counterparties, or transaction flows that bring it into contact with territories subject to UK financial sanctions? Fourth, third-party relationships: suppliers, distributors, and agents can all create indirect exposure that a customer-focused assessment will miss entirely.

The output of the assessment should not be a spreadsheet. It should be a written document, approved by the senior owner identified in Step 1, with a clear residual-risk rating and a set of programme enhancements that flow from it. That document becomes the primary evidence in any future OFSI interaction that the business approached its compliance obligations thoughtfully.

How often should the assessment be refreshed? The honest answer is: whenever the firm's risk profile changes materially and, as a minimum, on an annual cycle. A merger, a new product line, an expansion into a higher-risk jurisdiction, or a significant change to OFSI's designated-persons lists can each alter the risk picture faster than a calendar-driven review would catch it.

Step 3: Design and calibrate the screening and detection controls

Screening is the point at which most programmes either succeed or fail at the operational level. A programme can have excellent governance and a thorough risk assessment, and still permit a prohibited transaction because its screening logic is wrongly configured.

OFSI financial sanctions prohibit dealing with a designated person's funds or making funds available to them, directly or indirectly. The "indirectly" limb is what makes screening difficult. It requires that the programme look beyond the immediate counterparty to the ownership and control structure above it. Under the UK test, ownership and control (the standard that catches non-listed entities through their relationship to a listed person) encompasses not only entities owned 50 percent or more by a designated person but also entities that a designated person controls by other means – a broader test than OFAC's purely mechanical ownership rule.

Calibration decisions include: the name-matching threshold (too tight misses variants; too loose generates volume that overwhelms the alert-review team); the data sources connected to the screening tool (is the UK Consolidated List current, and does the tool also carry the UN Consolidated List, EU designations, and OFAC's SDN List for businesses with multi-regime exposure?); and the periodic re-screening frequency for existing relationships. New-customer screening catches designations at onboarding. It does not catch a person who is designated after the relationship has begun.

In our experience, two gaps appear more often than any other. First, screening tools that are not connected to the OFSI list directly but rely on a consolidated data feed updated on a delay – sometimes days behind the live list. For a business operating at volume, that lag creates real exposure. Second, ownership data that is sourced only from Companies House or an equivalent registry and does not reflect the actual beneficial-ownership chain as disclosed by the customer or mapped through open-source research. Registry data is a starting point, not an answer.

The position above covers the standard case. Your facts – the counterparty's jurisdiction of incorporation, the depth of the ownership chain, the nature of the transaction – change the analysis considerably. For a confidential assessment of your screening architecture, contact Calder & Vance at info@caldervance.com.

How does OFSI's approach compare with OFAC and EU requirements?

OFSI, OFAC, and the EU Council regulations share a common prohibitions architecture but diverge significantly in their ownership and control tests, their licensing mechanisms, and their enforcement calculus. For any business with operations or counterparties in more than one of these regimes, a programme designed for one will not automatically satisfy the others.

The ownership threshold under OFAC is mechanical: entities owned 50 percent or more in aggregate by one or more blocked persons are themselves blocked, regardless of whether they appear on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). OFSI's test extends beyond ownership to control, meaning that a designated person who holds less than fifty percent of an entity but can direct its decisions may still render that entity subject to the prohibition. The EU Council regulations similarly apply an ownership-and-control test, though the precise formulation differs across the individual country-programme regulations.

Licensing also diverges. OFSI operates a case-by-case specific-licence regime and a set of general licences for defined categories of activity. OFAC issues both specific and general licences (standing authorisations that permit a defined category of transactions without a separate application) and its general-licence practice is considerably more developed, with a larger volume of standing permissions in force at any given time. EU competence for issuing licences rests with member-state competent authorities rather than a single central body, which creates a further layer of procedural complexity for multi-jurisdiction matters.

Enforcement posture differs as well. OFAC has long operated on a strict-liability basis with a penalty structure that references the value of the underlying transaction. OFSI, since the powers introduced under SAMLA were brought into force, can also impose civil monetary penalties on a strict-liability basis for certain breaches, with penalties that can reach a significant percentage of the transaction value or a fixed amount – whichever is higher. The EU framework delegates enforcement to member states, producing variation in enforcement rigour and penalty levels across the bloc.

For businesses caught between these regimes, the practical implication is clear: where two regimes impose divergent obligations on the same transaction or relationship, the stricter prohibition governs. A programme that maps only the home-jurisdiction rules is incomplete wherever the firm touches a second regime.

Step 4: Build the response, reporting, and escalation process

What happens when the screening tool produces a match? The answer to that question is where many programmes falter. Detection is valuable only if it is followed by a documented, consistently applied response process.

The response process should specify: who reviews a potential match at first instance (the alert-review team); what evidence they gather to confirm or dismiss it; who has authority to approve continued processing of a transaction that has been reviewed and cleared; and who is notified if the match is confirmed. That last step is the beginning of the OFSI reporting question.

Under SAMLA, certain regulated firms – broadly, those in the financial and professional-services sectors – carry a statutory obligation to report to OFSI when they know or suspect that a person is a designated person or that they hold frozen funds or economic resources. The reporting window under the applicable legislation is short. Practitioners must verify the precise deadline applicable to their firm type before relying on any general statement, but the window is measured in days, not weeks. Missing it is itself a breach.

Separately, OFSI has a VSD mechanism. A voluntary self-disclosure, filed promptly and in good faith, is a mitigating factor in how OFSI approaches the penalty calculation. It does not guarantee a reduced outcome – no sanctions counsel should promise that – but it is consistently treated as evidence of a co-operative compliance posture. In our experience, firms that identify a breach and wait to see whether OFSI notices independently fare significantly worse in enforcement than those that disclose promptly.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential discussion.

Step 5: Record-keeping, testing, and the annual review cycle

A programme that is built but not tested and documented provides weaker protection than one that is systematically verified. Record-keeping under OFSI's guidance requires that firms retain evidence of their compliance decisions – screening results, ownership-mapping analysis, licence applications and responses, and reports made to OFSI – for a period sufficient to respond to any future enforcement inquiry. The applicable period under the relevant OFSI guidance is five years; verify the current position before relying on this figure as applicable to your firm type.

Testing means more than asking whether the screening tool is switched on. It means periodically running a set of test scenarios – including known-designated names, ownership-chain permutations, and deliberate false-positive cases – to verify that the tool produces the expected output. It means reviewing the alert-resolution log to confirm that dismissals are documented and consistent. It means checking whether the ownership-and-control methodology applied by the alert-review team matches the written procedure.

The annual review cycle should produce a written assessment, approved by the senior owner, that identifies what was tested, what was found, and what remediation has been agreed. That document is a core component of the evidence base that OFSI would examine in any enforcement inquiry. It is also the document that a board or audit committee needs to satisfy itself that the programme is fit for purpose.

In a recent matter, a payments business had operated its sanctions programme for three years without a formal testing cycle. When a potential breach surfaced, the absence of any testing record meant the firm could not demonstrate that its controls had been functioning correctly during the period in question. We assisted by reconstructing the compliance history from available records, mapping the control gaps, and preparing the VSD submission to OFSI. The matter reached a documented outcome, though the absence of prior testing records was a complicating factor throughout. The lesson is straightforward: test, document, and retain.

What are the risk flags that indicate a programme needs urgent attention?

Certain indicators consistently signal a programme that is likely to fail at the moment it is most needed. Recognising them early is materially less costly than discovering them during an enforcement interaction.

The first risk flag is a programme that has not been updated since SAMLA's civil monetary penalty powers came into force. The legal environment for UK financial sanctions has changed significantly since those powers were activated, and a programme written to a pre-enforcement standard is not calibrated to the current risk.

The second is a screening tool connected only to a single consolidated data feed without a documented process for checking the OFSI Consolidated List directly after a major designation event. OFSI can add names at any time, including outside normal business hours. A programme that screens only on a nightly batch may miss a same-day designation for an entire trading day.

The third is an ownership-mapping methodology that stops at the direct shareholder level. As noted above, OFSI's control test reaches beyond ownership. An entity that is not majority-owned by a designated person may nonetheless be caught if that person can direct its commercial or financial decisions. This is the question that the EU General Court has also considered in the context of EU designations, and practitioners across regimes have noted the same pattern: control through board composition, contractual rights, or operational dependence can catch entities that a pure-ownership analysis would clear.

The fourth risk flag is a common myth that deserves direct correction: the belief that a small business or a firm with only occasional sanctions exposure does not need a formal programme. OFSI's civil monetary penalty powers apply on a strict-liability basis. The size of the business is not a shield from liability, though it may be a factor in how OFSI calibrates the penalty. The obligation to screen, to report, and to avoid prohibited transactions applies to any person or firm subject to UK law, regardless of how infrequently the issue arises in practice.

Related practices

Frequently asked questions

What are the steps to design a sanctions compliance programme under OFSI?
An OFSI-compliant programme requires five sequential steps: establishing governance and senior ownership; conducting and documenting a sanctions risk assessment; designing and calibrating screening and detection controls; building the response, reporting, and escalation process; and maintaining a record-keeping and testing cycle with an annual review. Each step should produce a written output approved by the named senior owner, so that the programme can be evidenced in any future OFSI interaction. The cross-regime dimension – particularly for businesses also touching OFAC or EU Council regulations – requires additional calibration at the screening and ownership-mapping stage.
What is the most common mistake in sanctions compliance programmes?
In our cross-border practice, the most common failure is an ownership-mapping methodology that stops at the first layer of the counterparty's share register. OFSI's test for whether a non-listed entity is caught by a designation extends to control as well as ownership, meaning a designated person who can direct an entity's decisions may render it subject to the prohibition even without majority ownership. Screening tools calibrated only to direct shareholdings will systematically miss this exposure. The second most common failure is a programme that has never been formally tested – built once, never verified, and therefore unable to demonstrate its own effectiveness when it matters most.
How does OFSI differ from other regimes here?
OFSI applies both an ownership test and a control test to determine whether a non-listed entity is caught by a designation – broader than OFAC's mechanical fifty-percent ownership rule. OFSI's licensing regime operates on a case-by-case specific-licence basis, supplemented by general licences for defined categories; OFAC's general-licence practice is more extensive. On enforcement, OFSI can impose civil monetary penalties on a strict-liability basis under SAMLA, without needing to prove knowledge or intent for the most serious breaches, a standard that aligns OFSI more closely with OFAC's enforcement approach than was true under the pre-SAMLA regime. EU member-state competent authorities handle licensing, producing additional variation for multi-regime businesses.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.