A mid-size trading company operating between the United Kingdom and several emerging markets discovers, mid-transaction, that a beneficial owner of its counterparty appears on the UK Consolidated List (OFSI's public register of designated persons whose assets are frozen under UK law). The compliance team has no written programme. There is no ownership-mapping protocol, no screening policy, no escalation path. The deal is live. The clock is running. What happens next is decided almost entirely by what the business had – or had not – put in place beforehand.
A sanctions compliance programme under OFSI is the structured set of controls, policies, and procedures that a UK-nexus business uses to identify, manage, and report exposure to the financial sanctions regime (the prohibition on dealing with designated persons and their controlled entities) administered by the Office of Financial Sanctions Implementation. As of July 2026, OFSI operates under the Sanctions and Anti-Money Laundering Act ("SAMLA") and publishes detailed compliance guidance that sets expectations for firms of all sizes. No statutory minimum programme is prescribed, but OFSI's enforcement posture – and its power to impose significant civil monetary penalties – means that an absent or inadequate programme is itself a risk factor.
This guide walks through the six practical stages of building or stress-testing a sanctions compliance programme under OFSI, compares the OFSI position with the OFAC and EU approaches where the regimes diverge, and identifies the risk flags that most frequently require legal input.
Step 1: Understanding who OFSI's regime reaches – and why the answer is broader than most businesses expect
OFSI's financial sanctions apply to any person in the United Kingdom and to any UK person wherever they are in the world, which means the regime follows the UK passport and the UK corporate registration, not just the physical transaction. A UK parent, a UK subsidiary, a UK-incorporated special-purpose vehicle, or a UK-resident director signing a contract abroad – all are within scope.
The first task in any programme design is a precise scope-mapping exercise. Which entities in your group are UK persons? Which contracts are governed by English law and therefore potentially performed by a UK person? Which payment channels route through UK-correspondent banks? In our experience, groups with diverse holding structures regularly undercount their UK exposure at this stage.
The OFSI regime also applies to activities that facilitate a breach, not only to direct dealings. That facilitation limb means that a UK-based holding company that approves a transaction at board level – even if the operating subsidiary is incorporated elsewhere – can itself be exposed. Programme design must therefore map the decision-makers, not only the transacting entities.
This scope question also has a cross-border dimension. Where a business is simultaneously within reach of OFAC (as a US person, a US-dollar transaction, or a US-nexus entity), it must manage a parallel set of obligations. The OFSI and OFAC ownership and control tests differ materially: OFAC uses the mechanical 50 percent rule (aggregate blocked-person ownership at or above that threshold treats the entity as blocked), whereas OFSI – like the EU – applies a broader ownership-or-control test that can catch an entity in which a designated person holds less than 50 percent but exercises effective control. A programme that is calibrated only to the OFAC threshold will miss OFSI exposures. We regularly advise cross-border groups on exactly this divergence, and it is one of the most consistent sources of undetected risk in mid-market compliance programmes.
Step 2: Mapping the legal basis and OFSI's enforcement authority
OFSI derives its authority from SAMLA and the thematic regulations made under it – instruments covering specific geographic or sectoral programmes, each setting out the categories of designated persons and the applicable prohibitions. The legal basis matters for programme design because each thematic instrument can impose different prohibitions and carve-outs. A programme that treats all UK financial sanctions as uniform will misread the scope of any given licence or exemption.
OFSI has the power to impose civil monetary penalties without a criminal conviction. The civil standard of proof is the balance of probabilities, which is a significantly lower bar than the criminal standard. OFSI can also publicly disclose enforcement actions – a reputational consequence that can be as damaging as any monetary penalty for a financial institution or a publicly listed group. In our practice, the reputational risk is consistently the factor that most focuses board-level attention on the adequacy of compliance arrangements.
One feature of the OFSI regime that distinguishes it from OFAC is the reporting obligation: where a person knows or has reasonable cause to suspect that they hold a frozen asset or have information about a designated person relevant to financial sanctions, they are required to report to OFSI. This is not a voluntary self-disclosure parallel to OFAC's VSD (voluntary self-disclosure to a regulator) programme – it is a statutory duty with a defined trigger. Building that reporting obligation into escalation protocols is a mandatory element of any UK programme.
The position above covers the standard case. Your facts – the counterparty structure, the goods or services involved, the relevant thematic instrument, and the UK nexus in play – change the analysis. For a preliminary assessment of your programme's gaps against the OFSI standard, contact Calder & Vance at info@caldervance.com.
How should a business structure the five core elements of its OFSI compliance programme?
OFSI's compliance guidance identifies a five-element model for an effective sanctions compliance programme, and each element must be operational – not merely documented – to carry meaningful weight in any enforcement assessment. The five elements are: senior management commitment; risk assessment; internal controls; testing and audit; and training.
Senior management commitment means documented board or executive-level ownership of the sanctions compliance function. A policy signed by a compliance officer but never ratified at board level will not satisfy the standard. The commitment must be evidenced in governance records, not just in the text of a policy document.
Risk assessment is the analytical core. It requires the business to map its customer and counterparty base, its product and service flows, its transaction corridors, and its ownership exposure, and to assign a calibrated risk rating to each. A trading firm exporting industrial goods to high-risk jurisdictions carries a different exposure profile from a professional-services firm with a purely domestic client base. The risk assessment is not a one-time exercise; it must be reviewed when the business's activities or the regulatory environment changes materially.
Internal controls are the operational measures that flow from the risk assessment: screening procedures, transaction-approval workflows, escalation authorities, and the protocols for handling a potential match. Controls must be proportionate to the assessed risk. A small business with a limited counterparty base does not need the same architecture as a global bank, but it does need documented, functioning controls at whatever scale is appropriate.
Testing and audit close the loop. It is not sufficient to have controls on paper; they must be tested for effectiveness. In a recent matter, a financial services business had screened counterparties against the Consolidated List for several years using a tool that had not been updated to include OFSI's expanded designated-person categories under a newer thematic instrument. The controls existed. They did not work. We assessed the screening gap, identified the un-screened exposure window, and advised on the voluntary reporting decision. The matter underscored a point we see repeatedly: the audit stage is where programmes either earn their credibility or expose their weaknesses.
Training completes the cycle. Policies and controls are only as effective as the people applying them. Training must be role-specific – the escalation obligation for a relationship manager differs from that for a payment-processing team member – and it must be documented and current.
What does the cross-regime comparison reveal about divergent obligations?
Designing a programme only to the OFSI standard is insufficient for most businesses with cross-border operations. The three major autonomous regimes – OFSI, OFAC, and the EU – share the same headline prohibitions but diverge in several operationally significant ways.
On the ownership and control test: as noted above, OFAC applies a purely arithmetic threshold, while OFSI and the EU both require an assessment of effective control even where the ownership percentage falls below any fixed trigger. This means that due-diligence processes calibrated to a 50-percent ownership screen will miss OFSI-relevant exposures where a designated person exercises control through board appointment rights, veto provisions, or contractual means. Programmes must build a control-assessment layer on top of any ownership screen.
On the licensing route: OFSI issues specific licences (case-by-case authorisations for otherwise prohibited transactions) across several named licence grounds, including for basic needs, legal fees, and prior obligations. OFAC issues both specific and general licences (standing authorisations for defined categories of transactions that do not require a separate application). The EU issues authorisations under comparable grounds but the competent authority differs by member state, creating a more fragmented licensing environment for groups operating across the EU. A cross-border programme must map which licensing route is available in each relevant regime and build that into the transaction-clearance workflow.
On record-keeping: OFSI's guidance, consistent with the general UK anti-money laundering regime, requires that records of compliance activity be retained. The applicable retention period should be verified against the current guidance for the specific activity type; as a general working assumption, practitioners treat a five-year retention standard as a reasonable baseline, though the precise obligation depends on the relevant instrument and activity. OFAC also imposes record-keeping requirements; the specific periods should similarly be verified before reliance.
On the secondary-sanctions dimension: OFAC's secondary-sanctions programmes can reach non-US persons transacting in non-US markets with certain designated persons. OFSI has no direct equivalent of OFAC's secondary-sanctions architecture. However, a UK business that maintains a US correspondent relationship, or that has US-person employees involved in decision-making, can find itself within OFAC's reach even for transactions that do not touch the United States at the primary level. A complete programme therefore requires at least a secondary-sanctions risk assessment alongside the primary OFSI analysis.
If a transaction has already been flagged, or if a filing has been refused, an early review can preserve options that narrow with time. Write to Calder & Vance at info@caldervance.com for a confidential assessment.
What are the most common risk flags that indicate a programme needs urgent attention?
In our cross-border practice, the same patterns of programme failure recur across sectors and firm sizes, and recognising them early can prevent a routine compliance gap from becoming an enforcement matter.
The first and most frequent failure is relying on a screening tool without governance over it. Screening technology is only as effective as its list coverage, its update frequency, and the quality of the fuzzy-matching logic applied to partial name matches. We have seen businesses that screen diligently and nonetheless hold relationships with counterparties that fall within the OFSI ownership and control test, because the tool screens for names on the Consolidated List and does not extend to entities whose control by a designated person has been publicly identified.
The second risk flag is an absent or stale risk assessment. A programme designed in a different regulatory environment – before a new thematic sanctions instrument was introduced, or before the business expanded into a new market – may be structurally sound but misaligned with the current risk profile. Risk assessments must be living documents with a clear review trigger.
The third flag is the escalation gap: the business has an escalation protocol on paper, but the people responsible for escalating a potential match have never been trained on what constitutes a match requiring escalation, and the protocol has never been tested against a real or simulated hit. In our experience, the escalation gap is the element most likely to produce a delayed or missed report to OFSI, which is itself a regulatory risk distinct from the underlying exposure.
The fourth flag is senior management disengagement. Where the compliance function sits entirely below board level and the board receives no periodic reporting on sanctions risk, the "senior management commitment" element of OFSI's five-element model is not satisfied. An enforcement investigation that reveals this gap will weigh against any mitigation argument.
The fifth flag is a failure to address the cross-regime dimension. A business that has designed a programme exclusively against the OFSI standard – without considering OFAC secondary-sanctions risk, EU ownership-and-control obligations, or the requirements of other regimes relevant to its markets – has a structurally incomplete programme. Do you know whether your counterparty-screening process covers not just who is on the UK Consolidated List, but also who is an entity controlled by a UK-designated person within the meaning of the OFSI test?
When does a business need legal counsel for its compliance programme?
Not every compliance programme requires external legal input at every stage, but there are defined points at which specialist legal advice is likely to be cost-effective and, in some cases, essential.
The first is programme inception or redesign after a material change – a new market, a new product, an acquisition, or a significant regulatory development. At this stage, the risk assessment is the foundational document and getting it right at the outset is materially cheaper than correcting a misdirected programme later.
The second is where a potential match or a transaction question cannot be resolved within the internal escalation framework. A partial name match against the Consolidated List, a counterparty with a complex ownership structure that may engage the OFSI control test, or a proposed transaction that may require a specific licence – these are the inflection points at which experienced sanctions counsel can resolve the question definitively and document the analysis in a way that is defensible before OFSI if the matter is later reviewed.
The third is where a breach – or a potential breach – has been identified. The reporting obligation under the UK regime means that delay in assessing and reporting is itself a risk. We advise regularly on the scope of the reporting obligation, the content of an adequate report to OFSI, and the question of whether a VSD to OFAC is also required where there is a US nexus.
A common misconception is that a compliance programme is a one-time investment that, once built and signed off, satisfies the regulatory expectation indefinitely. It does not. OFSI's guidance makes clear that a programme must be maintained and kept current as the regime evolves. The myth that compliance is a project, rather than an ongoing function, is the single most dangerous assumption we encounter in initial client conversations. Sanctions designations are made and revoked frequently; thematic instruments are amended; guidance is updated. A programme that was adequate at inception can become inadequate within months without active maintenance.
Related practices
- Sanctions compliance audit and testing – independent testing of live screening and control architecture
- OFSI compliance programme design: advanced considerations – deeper analysis of licence grounds, enforcement posture, and cross-regime alignment
- Sanctions compliance programmes under SECO – how Switzerland's regime interacts with OFSI and EU obligations for cross-border groups