Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Sanctions compliance programmes under OFSI: procedure and pitfalls

A UK-headquartered trading company discovers, mid-transaction, that its counterparty's ultimate beneficial owner appears on OFSI's consolidated list of financial sanctions targets. The deal is paused. The compliance team scrambles. The question is not only whether this transaction is prohibited – it is whether the firm's sanctions compliance programme was ever adequate to catch exactly this pattern, and whether that inadequacy itself carries regulatory consequences.

As of July 2026, the UK's Office of Financial Sanctions Implementation (OFSI) – the HM Treasury body responsible for implementing and enforcing UK financial sanctions – operates a disclosure-oriented enforcement regime under the Sanctions and Anti-Money Laundering Act 2018 (SAMLA) and the relevant thematic regulations. A well-structured sanctions compliance programme is not merely good practice: OFSI's published enforcement guidance explicitly treats the quality of a firm's compliance programme as a factor in assessing culpability and penalty level. The absence of a structured programme, or one that is nominally in place but untested, aggravates exposure.

This guide walks through the design, implementation, and testing of a sanctions compliance programme under OFSI authority, identifies the most frequent points of failure, and sets out where the UK position diverges from OFAC and EU equivalents in ways that matter operationally.

Step 1: Understand the legal basis and OFSI's authority before designing anything

A sanctions compliance programme built on the wrong legal assumptions fails at the first audit. OFSI administers UK financial sanctions under SAMLA and the regulations made under it, which impose asset-freezing obligations, prohibitions on making funds or economic resources available, and reporting duties on those who hold or control frozen assets.

The relevant thematic regulations – covering multiple target regimes – create obligations that apply to any person in the UK, and to UK persons acting abroad. That geographic reach is narrower than OFAC's secondary-sanctions architecture, but it is not purely territorial. A UK company's overseas subsidiary may nonetheless trigger OFSI obligations if transactions are routed through the UK parent, cleared in sterling, or otherwise touch a UK nexus. In our experience, firms that design their programme only around their UK domestic operations consistently miss the subsidiary-nexus problem.

Before writing a policy, the compliance team must map the firm's legal entities against the following questions: Which entities are UK persons? Which transactions involve a UK nexus even if booked offshore? Which third-country operations involve a UK parent guarantee or credit line? The answers determine the programme's jurisdictional scope – and that scope is often larger than the group initially assumes.

OFSI does not prescribe a mandatory programme structure in the way some other regulators do. But its enforcement guidance sets out the mitigating factors it considers when deciding whether to impose a monetary penalty and at what level. Those factors are, in substance, the elements of an adequate compliance programme. Designing to that standard is the practical objective.

Step 2: Establish governance and accountability structures

Effective sanctions compliance begins at the board level, not in the compliance department. Governance means clear ownership: a named senior manager accountable for the sanctions compliance function, board-level visibility of the programme's scope and testing results, and documented escalation paths when a potential match or breach is identified.

OFSI's enforcement approach treats the presence of senior-management commitment as a mitigating factor. Conversely, where a breach occurs and no senior individual can demonstrate knowledge of or responsibility for the compliance function, OFSI's assessment of culpability tends toward the higher end. The governance structure is therefore not a formality – it is a direct input into penalty calculations.

In practical terms, governance architecture for an OFSI-focused programme should cover at minimum four elements. First, a designated sanctions compliance officer (or the delegated equivalent) with documented authority to block a transaction. Second, a sanctions policy approved at board or executive-committee level and reviewed on at least an annual cycle. Third, escalation and decision-making procedures that do not allow commercial pressure to override a compliance hold. Fourth, a process for communicating policy changes to relevant staff within a defined window after the change takes effect.

How does this compare with the OFAC model? The US Treasury's Office of Foreign Assets Control has published a framework for an effective sanctions compliance programme built around five components: management commitment, risk assessment, internal controls, testing and auditing, and training. The OFSI standard is functionally similar but is articulated in enforcement guidance rather than in a standalone compliance framework document. The practical consequence is that OFSI-facing programmes need to be calibrated to the enforcement guidance directly, rather than mapped to a published five-element template. We regularly advise compliance teams to cross-reference both frameworks when designing a programme with transatlantic reach – the overlap is substantial, but the gaps are operationally significant.

Step 3: Conduct a risk assessment calibrated to OFSI's exposure map

A sanctions risk assessment is not a screening exercise: it is a structured analysis of where, across the firm's business model, sanctions risk is most likely to arise and in what form. Under OFSI's approach, the adequacy of a firm's risk assessment is one of the factors examined in enforcement proceedings. A general, template-driven risk assessment that does not reflect the firm's actual counterparties, geographies, products, or transaction flows carries little weight as a mitigating factor.

The risk assessment should identify: the firm's counterparty base and the jurisdictions in which those counterparties operate; the goods, services, or funds involved in transactions and whether any fall within thematic sanctions categories; the channels through which payments or settlements are processed; and any third-party intermediaries (agents, distributors, freight forwarders) who sit between the firm and the ultimate counterparty. Each of these dimensions can carry distinct risk profiles under different OFSI thematic regulations.

A point that surprises many non-specialist compliance teams: OFSI's asset-freezing prohibitions extend to economic resources as well as funds. Economic resources are assets of any kind, whether tangible or intangible, which are not funds but can be used to obtain funds, goods, or services. Intellectual property licences, software access rights, and commodity supply agreements can all constitute economic resources. A risk assessment that looks only at money flows will miss a material category of prohibited activity.

Cross-regime calibration matters here. OFAC's equivalent concept covers essentially the same ground under its property and property-interests prohibition. The EU position, under the relevant Council regulations, tracks closely. But the boundary cases – where a transaction involves an asset that might or might not be an economic resource – are resolved by different guidance in each regime, and the answer is not always the same. Where a transaction sits near that boundary, a multi-regime analysis is essential.

The risk assessment should be documented, dated, and updated when the firm's business model changes, when a new thematic sanctions regulation enters into force, or when an OFSI enforcement action signals a new regulatory priority. A living document, reviewed at least annually, carries far more weight in an enforcement context than a static assessment produced at programme launch.

Step 4: Build internal controls around screening, ownership tracing, and reporting

Internal controls translate the risk assessment into operational procedures. For an OFSI-focused programme, three areas of internal control consistently generate the most enforcement exposure: screening, ownership and control tracing, and the mandatory reporting obligation.

Screening means checking counterparties, beneficial owners, and transaction intermediaries against OFSI's consolidated list and, where relevant, against UN, EU, and US lists for secondary-risk purposes. Screening alone is not sufficient. A firm that screens only the named counterparty and ignores the ownership chain is exposed to exactly the pattern described at the opening of this guide. OFSI's list contains the names of designated persons; it does not automatically flag entities owned or controlled by those persons. That work falls to the firm.

The ownership and control test under UK financial sanctions regulations is the mechanism by which OFSI's prohibitions extend beyond the named designated person to entities that person owns or controls. Unlike OFAC's bright-line 50 percent aggregate ownership threshold, the UK test also captures control that does not depend on majority ownership. A designated person who holds a minority stake but can direct the management of an entity may still bring that entity within the prohibition. In practice, this means that a UK firm screening a counterparty must go beyond the share-register and examine governance rights, board appointment powers, and contractual control mechanisms. We have acted for businesses where the ownership-register screen returned clear results, but a review of shareholder agreements revealed veto rights that triggered the control test.

The mandatory reporting obligation is one of the most frequently overlooked elements of an OFSI compliance programme. Persons who know or reasonably suspect that they hold, or have held, frozen assets must report to OFSI as soon as practicable. The obligation is not conditional on a formal determination that the assets are frozen; reasonable suspicion is enough to trigger it. Firms that treat reporting as something done only after a full internal investigation – a process that can take weeks – run a real risk of having failed to report as soon as practicable. Designing a clear internal escalation procedure that produces a provisional OFSI notification within a short, defined window is a core internal-control requirement.

Record-keeping underpins all three areas. OFSI expects firms to maintain records of their compliance steps – screening runs, ownership analysis, escalation decisions, and any OFSI correspondence – for a period consistent with the applicable statutory retention requirements. The absence of contemporaneous records, even where the compliance steps were actually taken, leaves the firm unable to demonstrate what it did in any subsequent enforcement review.

Step 5: Design training that is tested, not just delivered

Training is the element of a sanctions compliance programme that firms most commonly execute poorly. Annual, generic, e-learning-style sanctions training delivered to all staff satisfies a box-ticking requirement. It does not produce the operational competence that OFSI's enforcement approach rewards.

Effective training under an OFSI-calibrated programme has three characteristics. It is role-specific: a relationship manager screening counterparties needs different practical knowledge from a finance team member processing payments. It is scenario-based: abstract legal principles have limited impact compared with worked examples drawn from the firm's actual transaction types and counterparty base. And it is tested: a training module that ends without any verification of comprehension does not demonstrate that staff understood what they were taught.

Documentation of training is as important as the training itself. A record that a member of staff completed a specific module on a specific date, and the result of any comprehension assessment, is the form of evidence that carries weight in an enforcement context. Anecdotal accounts of "we briefed the team" do not.

The training schedule should be responsive. When OFSI adds a new designation, amends a thematic regulation, or publishes new enforcement guidance, the relevant staff should receive a prompt update – not wait until the next annual training cycle. In practice, a standing process for translating regulatory changes into training communications is one of the structural elements that distinguishes a programme that functions from one that merely exists on paper.

Step 6: Test and audit the programme before OFSI does

Testing is the stage that separates a designed programme from a functioning one. Internal testing – periodic reviews of whether the programme's controls are operating as intended – is essential. External testing – independent review by advisers with specific sanctions expertise – provides the evidence of rigour that an OFSI investigation will scrutinise.

What does testing look like in practice? At minimum: periodic sample-based reviews of screening outputs to confirm that the screening tool is catching the right names and aliases; ownership-tracing exercises on a representative sample of the firm's higher-risk counterparties; a review of escalation records to confirm that the documented procedure was actually followed; and a review of reporting activity against the firm's own risk-assessment predictions. If the firm's risk assessment identifies a category of transaction as high risk but the escalation log shows no matters reaching the compliance officer from that category, the mismatch requires investigation – either the risk assessment is wrong, the controls are not working, or both.

Audit findings must be actioned. A compliance programme that identifies deficiencies through testing and does not address them is, in OFSI's enforcement view, worse than one that has not been tested at all: it demonstrates that management was on notice of the problem and chose not to fix it. Every audit or testing exercise should produce a tracked action plan with accountable owners and defined timescales.

For firms operating across multiple regimes, external testing should be calibrated to the full jurisdictional scope of the programme. An OFSI-only audit that does not consider whether the firm's controls also meet OFAC and EU requirements leaves gaps that can be exploited by enforcement authorities in other jurisdictions. We regularly advise on testing exercises designed to assess compliance simultaneously against OFSI, OFAC, and EU standards – a single testing exercise structured to identify regime-specific gaps is substantially more efficient than three separate audits.

Related practices

Common pitfalls: where OFSI-facing programmes most often fail

Across our practice, certain failure patterns recur with enough consistency to merit a dedicated analysis. The following are the most operationally significant.

Treating the consolidated list as exhaustive. OFSI's consolidated list names designated persons. It does not list entities owned or controlled by those persons. A programme that screens only against the list, without applying the ownership and control test to beneficial-owner information, is structurally incomplete. This gap is the single most common cause of inadvertent breach in UK-facing compliance programmes.

Relying on a screening tool without validating its quality. Not all commercially available screening tools are equal in their coverage of OFSI designations, their alias-matching logic, or their speed of updating when OFSI adds or removes a designation. A firm that deploys a screening tool without periodically verifying its performance against the current OFSI list takes a risk that the tool – rather than a deliberate decision – creates the gap.

Designing for the static state of the programme, not its ongoing maintenance. OFSI's designation activity is continuous. Thematic regulations are amended. Enforcement guidance evolves. A programme designed against the regulatory position at a specific moment and then left unchanged degrades in effectiveness. The absence of a structured process for incorporating regulatory changes is itself a compliance deficiency.

Confusing a group policy with a group programme. Many firms have a group-level sanctions policy, sometimes drafted by a US or EU parent to reflect OFAC or EU standards. That policy may not translate accurately to the OFSI regime, particularly on the ownership-and-control test, the economic resources definition, and the specific reporting obligations under SAMLA and the thematic regulations. Applying a group policy as if it were an OFSI-calibrated programme creates gaps that enforcement proceedings will expose.

Overlooking the interaction with the UK's export control regime. OFSI administers financial sanctions. The Export Control Joint Unit (ECJU) administers UK export controls. In practice, many transactions that trigger OFSI considerations also carry ECJU licensing implications – particularly where goods with dual-use characteristics are involved. Compliance programmes that treat these as entirely separate workstreams, to be managed by different teams without coordination, miss the interaction between them. What is the point of clearing a transaction under OFSI analysis if the goods involved require an export licence that has not been obtained?

A point worth addressing directly, because it is a persistent misconception among compliance teams new to the OFSI regime: OFSI's monetary penalty power is civil, not criminal. That distinction sometimes leads firms to underweight OFSI enforcement risk compared with the risk of criminal prosecution under the sanctions regulations. This is a mistake. Civil monetary penalties under SAMLA can be substantial, and the reputational consequences of an OFSI penalty notice – which OFSI publishes – are significant regardless of the penalty amount. OFSI also refers cases to law enforcement where it identifies evidence of criminal conduct. The civil/criminal distinction is relevant to procedure, not to the seriousness with which the regime should be treated.

When to involve sanctions counsel

Not every sanctions compliance question requires external advice. Routine screening, standard counterparty onboarding, and updating a policy to reflect a new designation are operational tasks that a well-structured internal team can manage. But certain situations consistently benefit from – and in practice require – the involvement of specialist sanctions counsel.

Counsel involvement is warranted when: a firm is designing or overhauling its compliance programme for the first time, or following a material change in its business (acquisition, new market entry, change in product scope); a screening exercise has produced a potential match that the internal team cannot resolve; a transaction involves a counterparty whose ownership structure raises ownership or control questions under OFSI's test; a potential breach has been identified and the firm is assessing its reporting obligations and whether to make a voluntary self-disclosure (VSD – a notification to OFSI of an apparent breach, which may be considered as a mitigating factor in enforcement proceedings); or OFSI has issued a request for information, opened a compliance case, or initiated a penalty review.

Speed matters in each of these scenarios. OFSI's reporting obligation requires action as soon as practicable. The window in which a VSD can be made before OFSI becomes aware of a breach through its own investigation is finite and narrows quickly. The internal escalation procedure should include a step that triggers external counsel engagement within a defined, short period when any of these trigger events is identified.

If a transaction has already been flagged, or a compliance assessment has identified a potential gap, an early review of the position can preserve options that close as time passes. To discuss a specific situation or to obtain an assessment of your programme's adequacy under OFSI standards, contact Calder & Vance at info@caldervance.com.

Frequently asked questions

What are the steps to design a sanctions compliance programme under OFSI?
Designing an effective sanctions compliance programme under OFSI requires six sequential steps: establishing the programme's jurisdictional scope under SAMLA and the relevant thematic regulations; building governance and accountability structures with named senior-management ownership; conducting a documented risk assessment calibrated to the firm's specific counterparty base and transaction types; implementing internal controls covering screening, ownership and control tracing, and mandatory reporting; delivering role-specific and tested training; and establishing a testing and audit cycle that produces tracked, actioned findings. Each step should be documented to demonstrate adequacy in any enforcement review. OFSI's enforcement guidance treats the strength of a firm's compliance programme as a mitigating factor in penalty decisions, so the design objective is to meet the standard that guidance describes.
What is the most common mistake in sanctions compliance programmes?
The single most common mistake in OFSI-facing compliance programmes is treating the OFSI consolidated list as exhaustive. The list names designated persons; it does not automatically capture entities that those persons own or control. Firms that screen only against the named entries, without applying the ownership and control test to beneficial-owner information – including governance rights and contractual control mechanisms, not just share-register data – are structurally exposed to inadvertent breach. A secondary but equally prevalent failure is deploying a screening tool without periodically validating its coverage, alias-matching quality, and update speed against the current OFSI list.
How does OFSI differ from other regimes here?
OFSI's ownership and control test differs from OFAC's in a material way. OFAC applies a mechanical 50 percent aggregate ownership threshold: if blocked persons own 50 percent or more of an entity, that entity is treated as blocked. OFSI's UK test also captures control exercised through means other than majority ownership – board appointment rights, contractual veto powers, and similar mechanisms can bring a minority-owned entity within the prohibition. This makes the UK due-diligence exercise broader than a pure share-register review. The EU position tracks closely to the UK on control, but enforcement practice and licensing procedure differ. A cross-border programme must be calibrated to each regime's specific test rather than applying one standard across all three.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.