Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · Australia

Counterparty due diligence under Australia: a practical guide

A freight forwarder based in Sydney wins a significant contract moving industrial equipment to a buyer in a third country. The compliance team runs a name search. Nothing flags immediately. The deal moves forward. Three months later, DFAT updates the Consolidated List and the buyer's parent company appears. Was the freight forwarder exposed throughout? Could an earlier, more thorough review have identified the risk in time? These questions sit at the heart of what counterparty due diligence under Australia's autonomous sanctions regime is designed to answer.

Counterparty due diligence under Australia's autonomous sanctions regime means systematically verifying whether a proposed business partner, their beneficial owners, and associated entities appear on the Australian Sanctions List or the UN Consolidated List – and whether the transaction itself falls within a designated category of prohibited dealings. DFAT administers Australia's autonomous sanctions programme under the Autonomous Sanctions Act. Sanctions obligations are strict liability in character: ignorance of a counterparty's status does not, of itself, constitute a defence.

This guide sets out a step-by-step process for conducting counterparty due diligence under Australia's regime, compares key features with OFAC, OFSI, and EU approaches, identifies common risk flags, and explains when to bring in specialist counsel.

Step 1: Understand the governing regime and authority

Australia's autonomous sanctions programme is administered by DFAT under the Autonomous Sanctions Act and gives effect, through implementing regulations, to both the UN Security Council's targeted measures and Australia's own autonomous measures. The Australian Sanctions List consolidates both streams into a single searchable instrument.

Why does this matter at the outset? Because the two streams carry different legal bases and different updating rhythms. UN-mandated measures are incorporated as a matter of international obligation and tend to be updated in line with Security Council committee decisions. Autonomous measures are adopted by the Australian Government through regulations and can be amended independently of any multilateral process. A counterparty check that treats the List as static – something to run once at onboarding – will miss additions that occur mid-relationship.

DFAT's role extends beyond list maintenance. It is the licensing authority for permit applications and the body to which potential breaches should be reported. In our experience, businesses that understand DFAT's dual function – as the list-keeper and the licensing gate – approach permit and disclosure decisions more efficiently than those who treat the authority purely as a compliance administrator.

One important cross-regime point at this stage: businesses operating in the Australian market often have simultaneous obligations under OFAC, OFSI, or the EU regime, depending on their corporate structure, the nationality of their people, or the currency and routing of their transactions. The Australian Sanctions List does not replicate those regimes in full. A counterparty that appears clean against the Australian list may still be caught by a US secondary-sanctions designation or an EU Council regulation. Effective due diligence starts by mapping which regimes actually apply to the transaction in question.

Step 2: Identify which entities and transactions are in scope

Australia's regime catches a broad range of persons and dealings. The key question at this step is not just "who is the counterparty?" but "who ultimately owns or controls this counterparty, and does the transaction involve a sanctioned good, service, or jurisdiction?"

In scope for screening purposes are:

  • The named counterparty – natural person, corporate entity, vessel, or aircraft.
  • Beneficial owners and controlling interests through the ownership and control chain.
  • Intermediaries involved in the transaction – agents, freight forwarders, banks, correspondent institutions.
  • The goods or services themselves, where sector-specific or goods-based measures apply.
  • The destination and any transit or trans-shipment countries, where geographic restrictions form part of the applicable regime.

On the ownership and control question: unlike OFAC's mechanical 50 percent rule (which treats any entity owned 50 percent or more in the aggregate by designated persons as itself designated), Australia's regime does not apply an identical bright-line aggregation rule in the same statutory form. The obligation is to avoid dealing with designated persons and to avoid conduct that would provide a benefit to them. Whether a non-listed entity is caught depends on the facts of the ownership and control structure and the nature of the dealing. This distinction from OFAC is practically significant. A transaction that would be automatically caught under OFAC's 50-percent rule because a designated person holds exactly half of a counterparty may require a more factual, conduct-based analysis under the Australian regime.

This is also where the EU and UK regimes diverge in a different direction. Under OFSI's guidance and the EU Council regulations, ownership and control (the test for whether a non-listed entity is caught through a listed person) encompasses not just ownership percentage but also the ability to exercise decisive influence. That is a broader test than a pure ownership threshold and, in our practice, frequently catches holding structures that a mechanical 50-percent screen would clear.

Step 3: Run the screening process

Screening against the Australian Sanctions List and the UN Consolidated List is the core operational step. Done properly, it is not a single database query. It is a multi-layered process that maps the counterparty's ownership chain, runs each relevant entity, and documents the results.

A defensible screening process typically includes the following elements:

  1. Collect identity data. Full legal name, any aliases or trading names, jurisdiction of incorporation, registered address, date of incorporation, and the identities of directors and beneficial owners above the relevant ownership threshold. For natural persons: full name, date of birth, nationality, and any known aliases.
  2. Screen against the Australian Sanctions List and the UN Consolidated List. DFAT publishes both in machine-readable formats. Screen the counterparty, its beneficial owners, and any identified intermediaries. Record the date and version of the list used.
  3. Apply fuzzy matching. Exact-match searches miss transliterations, name variations, and alias structures that are common in cross-border counterparty data. Any screening tool should apply approximate-match logic and require human review of near-matches.
  4. Screen against applicable third-regime lists. If the transaction has a US nexus (USD payments, US-origin goods, US persons involved), screen against the OFAC SDN List and the BIS Entity List. If there is a UK or EU nexus, run the relevant consolidated lists. Do not assume that a clean result on the Australian list resolves the global picture.
  5. Assess the transaction type. Confirm whether the proposed dealings involve goods or services subject to sector-specific measures. Where the applicable regime restricts dealings in particular sectors regardless of whether the counterparty is listed, the goods and services analysis runs in parallel with the name screening.
  6. Document, escalate, and review. Record every search, every result, and every decision to proceed or decline. Where a hit arises – whether a confirmed match or a near-match requiring resolution – escalate to the compliance function or to counsel before the transaction moves forward.

How frequently should this process run? At minimum, at onboarding and at contract renewal. In practice, for ongoing relationships with counterparties in sectors that attract frequent designation activity, a periodic re-screening schedule – aligned to DFAT's update cycle – is appropriate. A relationship that was clean at inception can become non-compliant mid-term without any change in the counterparty's own behaviour.

Step 4: Assess ownership and control – the harder question

List screening identifies designated persons directly. The more demanding analytical task is to determine whether a non-listed counterparty is effectively under the control of a designated person – and therefore whether dealings with that counterparty carry sanctions exposure even in the absence of a direct list hit.

Under Australia's regime, the relevant question is whether a dealing with the non-listed entity would confer a direct or indirect benefit on a designated person. Answering that question requires understanding the beneficial ownership structure of the counterparty. Where is the economic benefit of the transaction going? Who controls the entity's decisions?

In practice, the ownership and control analysis involves:

  • Obtaining or constructing a corporate structure chart showing all entities in the ownership chain above and below the counterparty.
  • Identifying natural persons who are ultimate beneficial owners, regardless of the number of holding layers.
  • Assessing whether a designated person exercises de facto control – through board composition, contractual rights, or financing arrangements – even where their ownership percentage falls below a simple majority.
  • Reviewing publicly available corporate registry data, and where that data is limited, using reputable commercial intelligence sources to fill the gap.

Is this level of analysis proportionate for every transaction? It depends on the risk profile. A high-value transaction with a counterparty incorporated in a jurisdiction with limited corporate transparency, in a sector that has been the subject of recent designation activity, warrants deeper investigation than a routine supply of low-value goods to a long-established and well-documented partner. Proportionality is a legitimate design principle; but it should be documented, not assumed.

We regularly advise clients who discover, mid-transaction, that a counterparty's majority shareholder has been listed since an update that post-dates their last screening run. The ownership analysis at that point becomes urgent. Acting before the transaction closes or funds transfer preserves significantly more options than acting after.

Step 5: Recognise the risk flags and escalation triggers

Certain patterns in a counterparty profile or a transaction structure should prompt immediate escalation regardless of screening results. These are not automatic evidence of a sanctions breach; they are signals that warrant heightened scrutiny before proceeding.

Red flags in counterparty profile:

  • Incorporation in a jurisdiction with limited corporate transparency or high rates of shell-company activity.
  • Ownership chain that terminates in nominee holders, bearer-share structures, or opaque trusts rather than identifiable natural persons.
  • Recent change of name, registered address, or director roster without a clear commercial explanation.
  • Counterparty has no obvious business purpose consistent with the goods or services being purchased.
  • Ultimate beneficial owner is a national of a country subject to comprehensive measures under any of the major regimes.

Red flags in transaction structure:

  • Payment routed through a third-country financial institution with no obvious commercial rationale.
  • Request for an unusual payment currency, or routing that passes through a jurisdiction subject to comprehensive measures.
  • End-use address differs materially from the counterparty's declared place of business.
  • Transaction involves goods with a high dual-use risk profile – advanced electronics, precision manufacturing equipment, materials with military applications.
  • Counterparty is reluctant to provide beneficial ownership documentation or seeks to close the transaction on an unusually compressed timeline.

When a red flag arises, the question is not whether to proceed on intuition. It is whether the business can document a rational, evidence-based conclusion that the risk is sufficiently understood and mitigated. Where it cannot, seeking a permit from DFAT or withdrawing from the transaction are both preferable to proceeding on incomplete analysis.

The position above covers the standard risk-assessment stage. Your specific facts – the counterparty's sector, the goods involved, the payment route, the jurisdictions touched, the regimes in play – change the analysis materially. For a structured review of a specific transaction or counterparty, contact Calder & Vance at info@caldervance.com.

Step 6: Determine whether a permit is required and how to apply

Where due diligence reveals that a proposed dealing would be prohibited under the applicable regime, or where there is genuine uncertainty about whether a prohibition applies, the route forward is to assess whether DFAT will issue a sanctions permit authorising the dealing.

A sanctions permit under Australia's regime is the equivalent of a specific licence under OFAC or OFSI – a case-by-case authorisation to conduct an otherwise prohibited transaction. DFAT has discretion to grant a permit on grounds specified in the applicable regulations, which vary by programme. The grounds typically include humanitarian need, legal proceedings, certain official activities, and transactions that are in the national interest.

The permit application process requires the applicant to:

  • Identify the specific prohibition that applies and the regulatory basis for the permit request.
  • Set out the facts of the proposed transaction in sufficient detail for DFAT to assess the ground being invoked.
  • Provide supporting documentation – commercial agreements, identity documents, ownership structure evidence, end-use certificates where relevant.
  • Explain why the dealing cannot be structured to avoid the prohibited element entirely.

Timeline for permit applications is not fixed by statute in the same way as some other regimes. DFAT's processing time varies by complexity and programme. In our experience, applicants who submit well-prepared, complete applications with clear supporting documentation materially reduce the risk of delay or requests for further information. An incomplete application that triggers multiple rounds of DFAT correspondence can extend the timeline significantly – and in time-sensitive transactions, that delay can itself be commercially decisive.

A cross-regime point that frequently arises at this stage: a DFAT permit covers the Australian legal position only. If the same transaction requires an OFAC specific licence, an OFSI licence, or an EU authorisation under the applicable Council regulation, each of those must be sought separately. We advise on coordinating multi-regime permit applications to align the content and the timing, so that a business does not find itself authorised under one regime while still in breach of another.

Step 7: Record-keeping and ongoing monitoring

A due diligence process that produces no records provides little protection in an enforcement context. The obligation to maintain adequate records is both a regulatory requirement and a practical defence. In our experience, the businesses that handle enforcement enquiries most efficiently are those whose compliance team can produce a contemporaneous record of what was screened, on which date, against which version of the list, by whom, and what the result was.

Good record-keeping practice for Australian counterparty due diligence includes:

  • Retaining a copy of the screening result for each search run, including the date and the list version consulted.
  • Documenting escalation decisions: who reviewed a near-match or a red flag, what the conclusion was, and the basis for it.
  • Retaining beneficial ownership documentation provided by the counterparty.
  • Recording the outcome of any permit application, including DFAT's response.
  • Maintaining a re-screening schedule and recording that scheduled reviews were completed.

On the question of how long to retain records: the applicable regime under Australian law specifies record-keeping periods that businesses should verify against the current regulations. As a working assumption, aligning with the longer of the periods specified in the applicable national law and those required under any other regime governing the transaction (OFAC and OFSI both require multi-year retention) is the more defensible posture.

If a transaction has already been flagged, or a filing has been refused or queried by DFAT, an early review of the records and a structured assessment of disclosure options can preserve choices that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.

Common misconceptions and the objection we hear most often

The most persistent myth in Australian sanctions compliance is that the regime applies only to businesses with obvious connections to a listed country – a commodity exporter, an arms supplier, or a financial institution with cross-border correspondent relationships. General commercial businesses operating domestically, the reasoning goes, are unlikely to need a structured due diligence process.

That reasoning is incorrect. Australia's regime applies to Australian persons and entities, to persons in Australia, and to dealings that confer a benefit on a designated person regardless of geography. A business with no direct export activity can still breach the regime if it provides a service, extends credit, or makes a payment to a structure that ultimately benefits a designated person. The global reach of designation lists – and the frequency with which intermediary and holding companies are added to them – means that the risk is not confined to obviously international or high-risk sectors.

We regularly advise businesses in professional services, real estate, logistics, and technology who have discovered, in the course of a transaction, that a counterparty or its ultimate beneficial owner is subject to measures they had not previously considered applicable to their sector. A structured, proportionate due diligence process is not a regulatory burden exclusive to banks and exporters. It is the baseline that any business engaging in cross-border or complex domestic transactions should maintain.

Related practices

Frequently asked questions

What are the steps to run counterparty due diligence under Australia?
Counterparty due diligence under Australia's autonomous sanctions regime follows seven core steps: identifying which regimes apply to the transaction; defining the full scope of persons and entities to be screened; running name searches against the Australian Sanctions List and the UN Consolidated List; applying fuzzy matching and reviewing near-hits; conducting a beneficial ownership and control analysis; documenting all results and escalation decisions; and scheduling periodic re-screening throughout the relationship. Where a potential match is identified, the process stops for review before the transaction proceeds. A permit application to DFAT is the route forward where a prohibited dealing cannot be restructured.
What is the most common mistake in counterparty due diligence?
The most common mistake is treating name screening as a one-time event completed at onboarding. Lists change – sometimes significantly – and a counterparty that was clean when a relationship began may become designated mid-contract. Equally common is screening only the named counterparty while overlooking beneficial owners and controlling interests further up the ownership chain. A compliance function that screens the trading entity but not the parent structure, and that does not re-screen at regular intervals, carries substantially higher exposure than a proportionate, ongoing programme would produce.
How does Australia differ from other regimes here?
Australia's regime differs from OFAC primarily in the ownership and control analysis. OFAC applies a mechanical 50 percent rule – any entity owned 50 percent or more in the aggregate by designated persons is automatically treated as designated. Australia's regime frames the test in terms of whether a dealing confers a benefit on a designated person, which requires a more fact-specific assessment. The EU and UK regimes add a control dimension that can catch entities even below a 50-percent ownership threshold where a designated person exercises decisive influence. For businesses with multi-regime exposure, each regime's test runs in parallel – the stricter applicable prohibition governs the transaction's permissibility under that regime, and a clean result under one does not determine the position under another.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.