Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Sanctions compliance programmes under OFSI: a practical guide

A mid-sized UK trading company receives an alert. Its payment-screening tool has flagged a counterparty against the OFSI Consolidated List (the Office of Financial Sanctions Implementation's list of designated persons and entities). The compliance officer knows there is a match. What happens next depends entirely on whether the company has a functioning sanctions compliance programme – or a collection of disconnected policies that have never been tested.

As of July 2026, OFSI operates under the Sanctions and Anti-Money Laundering Act and the relevant thematic regulations. A sanctions compliance programme under OFSI must address six elements: governance and ownership, risk assessment, screening, transactional controls, reporting obligations, and training. Firms without a documented and tested programme face significantly reduced prospects of a favourable enforcement outcome if a breach occurs.

This guide walks through each design step in sequence, compares the OFSI standard with those applied by OFAC and the EU, and identifies the risk flags that most commonly cause well-intentioned programmes to fail.

Step 1: Understand the OFSI regime and its legal basis

OFSI is the UK's authority for financial-sanctions implementation and enforcement, operating under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic sanctions regulations made under it. Its remit covers financial prohibitions: making funds and economic resources available to designated persons, and receiving funds from them. A business is caught if it is a UK person, is incorporated in the United Kingdom, or conducts any relevant activity in the United Kingdom – regardless of where the counterparty sits.

The ownership and control test (the UK standard for determining whether a non-listed entity is caught through a listed person) turns on both ownership and control. This is a meaningful distinction from the OFAC position, where the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) operates as a purely mechanical threshold. Under OFSI and the EU, control can bite even where ownership sits below the equivalent threshold. That divergence has direct design implications: a screening programme calibrated only to the OFAC ownership test will miss entities caught solely under a UK control analysis.

The legal basis also determines the record-keeping obligation. Under the applicable UK regulations, firms must maintain adequate records of their sanctions-compliance activity for a prescribed period. Where a business is also subject to EU financial-sanctions rules – for instance, because it has a subsidiary in a member state – the relevant Council regulation imposes parallel obligations. A properly designed programme maps both sets of requirements, rather than treating UK and EU compliance as identical.

The position above covers the standard case. Your facts – the counterparty's jurisdiction, the nature of the relationship, and the specific thematic regime engaged – change the analysis.

For a confidential assessment of your programme's OFSI exposure, contact Calder & Vance at info@caldervance.com.

Step 2: Conduct a risk assessment calibrated to the OFSI standard

A risk assessment is the architectural document of any compliance programme; without it, all subsequent controls are unanchored. Under OFSI's published enforcement guidance, the quality of a firm's risk assessment is one of the factors the office considers when determining the appropriate enforcement response to a breach. A superficial or undated assessment is treated as evidence of inadequate governance.

The assessment must cover four dimensions. First, customer and counterparty risk: what categories of person does the business deal with, and what is the exposure to designated individuals or entities across those categories? Second, jurisdictional risk: which thematic regimes are engaged by the firm's activity? A business that operates across a broad geography will engage multiple programme-specific designations. Third, product and services risk: are any goods or services capable of providing an economic benefit to a designated person? Fourth, channel risk: does the payment or delivery route pass through an intermediary that itself carries sanctions exposure?

Where a business is also subject to US secondary-sanctions risk – because it deals in US-dollar instruments, involves a US-person counterparty, or operates in a sector flagged under IEEPA – the risk assessment must capture that layer separately. We regularly advise clients whose UK programme was designed in isolation, only for a US secondary-sanctions question to arise at the point of transaction. Identifying that dimension at the risk-assessment stage, rather than after a deal closes, is materially cheaper.

Step 3: Design screening controls that match the risk

Screening is the operational core of a sanctions compliance programme, but it is also the component most likely to generate both false positives and false negatives if it is not calibrated correctly. OFSI's guidance makes clear that automated screening alone does not discharge the obligation to take reasonable steps to identify a sanctions breach. The tool must be configured correctly, and its outputs must be reviewed by a person with the authority and knowledge to make a judgment.

The screening logic must address three distinct lists at a minimum: the OFSI Consolidated List, the UN Security Council's Consolidated List, and – for firms with US-nexus activity – the OFAC SDN List (the list of Specially Designated Nationals and blocked persons). Many UK firms screen only the OFSI list and assume the UN list is captured within it. The two lists are maintained separately and are not always synchronised at the point of a new designation.

Name-matching algorithms raise their own risks. Too narrow a matching threshold produces false negatives; too broad a threshold generates an unmanageable volume of alerts. In our experience, the firms that manage screening most effectively have documented their matching threshold decisions, review those decisions at defined intervals, and keep records of how each alert was resolved. That documentation becomes the firm's first line of defence if OFSI investigates.

One further point that is frequently overlooked: screening must cover not just direct counterparties but the ownership chain behind them. The UK ownership-and-control test means that a non-listed entity can be caught through a listed controlling person even where the entity itself does not appear on any list. A screening programme that terminates at the entity level, without tracing ownership and control, will not satisfy that standard.

Step 4: Build transactional controls and a decision sequence

Screening identifies potential matches. Transactional controls determine what happens next. The programme must specify a clear decision sequence: who reviews a screening alert, what information they must gather, what escalation path applies if the alert cannot be resolved at the first level, and at what point a transaction must be paused pending review. Without a documented sequence, firms tend to make inconsistent decisions across transactions – a pattern that regulators read as structural weakness rather than isolated error.

The decision sequence should distinguish between three outcomes. First, a clear negative match: the alert arises from a name coincidence and can be resolved on the available information. The resolution and the reasoning must be recorded. Second, a possible match requiring further information: the transaction must be paused while the firm obtains clarifying information from the counterparty or from public sources. Third, a confirmed or probable match: the transaction must not proceed and the obligation to report to OFSI is triggered.

Reporting to OFSI is not discretionary where a firm knows or has reasonable grounds to suspect that a person is a designated person. The obligation bites on suspicion, not certainty. Firms consistently underestimate how early in the decision sequence that threshold is reached. In a recent matter, a financial-services business had paused a transaction correctly but delayed its OFSI report while seeking additional information. The delay itself became the focus of the enforcement conversation. Acting promptly – even where the investigation is incomplete – is the safer route.

Cross-border transactions introduce a parallel obligation layer. A firm making a payment through a US-correspondent bank may need to consider whether the transaction also triggers a reporting or blocking obligation under OFAC's rules. Where a transaction is subject to both OFSI and OFAC jurisdiction, and the two regimes reach different conclusions on whether the activity is prohibited, the stricter prohibition governs. The programme must build that logic in at the transactional-controls stage.

If a transaction has already been flagged, or a report has been delayed, an early review can preserve options that narrow with time.

For a confidential review of a potential breach or a delayed report, contact Calder & Vance at info@caldervance.com.

Step 5: Establish governance, training, and a record-keeping structure

Governance is where OFSI's enforcement approach diverges most sharply from its US counterpart. OFAC's published enforcement guidance scores a compliance programme against five elements including senior-management commitment. OFSI does not publish an equivalent scoring matrix, but its enforcement guidance makes clear that senior management engagement – and evidence of it – is material to penalty calculations. A programme that exists on paper but lacks documented senior review will not attract the same mitigation credit as one with a clear governance trail.

Three governance elements are non-negotiable. First, a named owner at or close to board level with responsibility for the programme. Second, a defined escalation pathway from compliance staff to that owner. Third, periodic management-information reporting that captures screening volumes, alert resolution times, and any near-misses or confirmed breaches. That reporting creates the audit trail OFSI expects to see if it investigates.

Training is the mechanism that keeps governance real. Written policies are static; training is the point at which the firm tests whether its people actually understand what the policies require. OFSI expects firms to train not just compliance staff but any employee involved in the transaction or payment process. Frequency matters: a training programme delivered once at induction, without refreshers, will not adequately capture updates to designations or shifts in regulatory expectation.

Record-keeping must cover every element of the programme's operation: risk-assessment documents, screening-alert records with resolution notes, transaction-hold decisions, OFSI reports, and training records. The relevant UK regulations specify a minimum retention period for sanctions-related records; verify the current period before designing the retention schedule. EU subsidiary entities will face parallel retention requirements under the applicable Council regulation.

Step 6: Test, audit, and update the programme

A compliance programme that has never been tested has an unknown reliability. OFSI's enforcement guidance explicitly recognises the quality of a firm's compliance controls as a mitigating factor in penalty decisions. The corollary is that evidence of untested controls, or of identified weaknesses that were not remediated, can aggravate the penalty. The testing cycle is therefore not optional maintenance; it is a material component of the firm's legal position.

Testing should operate at three levels. First, periodic transaction-sample review: a defined sample of completed transactions is reviewed to check that the screening and decision-sequence was followed correctly. Second, system-configuration testing: the screening tool is checked against a set of known-designated names to verify that the matching logic and threshold settings are producing the expected outputs. Third, programme-level audit: the whole programme – governance, risk assessment, screening, transactional controls, reporting, and training – is reviewed against the current OFSI standard and against the firm's own risk-assessment findings.

The frequency of each testing level should be proportionate to the firm's risk profile. A high-volume payment firm with broad jurisdictional exposure will need more frequent sample reviews than a specialist manufacturer whose counterparty base is narrow and well-known. Whatever the frequency, it must be documented in advance, and the results of each test must be recorded with a note of any remediation actions taken.

What does the audit cycle look like in practice? In our practice, we approach a compliance audit as a structured gap analysis: we map what the programme currently does against what the OFSI standard, the UN standard, and any applicable OFAC or EU standard requires, and produce a prioritised remediation list. The most common gaps are in the transactional-controls documentation, in the ownership-chain screening logic, and in the evidence trail for senior-management oversight. Those gaps are almost always addressable before a regulator looks.

Related practices

Common myths and risk flags in OFSI compliance

The most persistent myth we encounter in practice is that OFSI enforcement is rare, and that the probability of being investigated is low enough to justify a minimal programme. This significantly misreads the current enforcement environment. OFSI has materially increased both its investigative activity and its public enforcement output in recent years, and the relevant UK legislation gives it the power to impose substantial monetary penalties on a strict-liability basis for certain breaches. Waiting for a regulatory inquiry before investing in the programme is precisely the sequence of events that OFSI's penalty guidance is designed to discourage.

A second myth is that AML compliance and sanctions compliance are functionally equivalent. They share some tools – customer due diligence, transaction monitoring – but the legal tests differ, the obligations differ, and the defences differ. A firm that has passed an AML audit has not thereby demonstrated OFSI compliance. The programmes are complementary, not interchangeable.

Three risk flags we observe repeatedly across programme reviews:

  • Ownership-chain screening that terminates at the direct counterparty, leaving the control-test exposure unexamined
  • Reporting obligations that are treated as triggered only on a confirmed match, not on reasonable grounds for suspicion
  • Training records that record attendance but not competency – so that the programme cannot demonstrate that employees understood the material

A fourth and cross-cutting flag arises in cross-border transactions: firms that have designed their programme exclusively against the OFSI standard without asking whether the transaction is also within OFAC's extraterritorial reach. A UK firm transacting in US dollars, through a US correspondent, with a counterparty in a sector subject to OFAC's secondary-sanctions architecture, may be subject to OFAC jurisdiction even without a US-person element in the transaction. That question must be answered at the risk-assessment stage, not at the point of a compliance failure.

Frequently asked questions

What are the steps to design a sanctions compliance programme under OFSI?
Designing an OFSI sanctions compliance programme requires six sequential steps: establishing the legal basis and jurisdictional scope, conducting a risk assessment calibrated to OFSI's enforcement guidance, building screening controls that cover the OFSI Consolidated List and the UN Consolidated List, creating a documented transactional-controls and decision sequence, putting in place governance structures with a named senior owner and record-keeping obligations, and testing and auditing the programme at defined intervals. Each step should be documented and linked to the firm's specific risk profile rather than copied from a generic template.
What is the most common mistake in sanctions compliance programmes?
The most common mistake is treating screening as the whole programme rather than one component of it. Firms configure a screening tool, run counterparty names against a list, and assume their obligation is discharged. In practice, OFSI's enforcement guidance expects the programme to address governance, risk assessment, decision-sequence documentation, reporting discipline, and training alongside screening. A programme that excels at list-checking but lacks documented alert-resolution records and a senior ownership trail will not attract the mitigation credit OFSI attaches to effective compliance controls.
How does OFSI differ from other regimes here?
OFSI's ownership-and-control test extends to entities controlled by a designated person, not only those they own outright. This is broader in some respects than the purely mechanical OFAC 50 percent ownership threshold, and it requires firms to analyse the control dimension of any counterparty relationship, not only the ownership stake. OFSI also operates a strict-liability civil penalty power, meaning that intent is not a precondition for a penalty – unlike the criminal standard. Compared with the EU regime, the OFSI approach to mitigating factors in enforcement decisions places particular weight on the quality of the firm's compliance controls at the time of the breach.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.