Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFAC

Counterparty due diligence under OFAC: what businesses must know

A trading company in a mid-market economy closes a multi-year supply arrangement with a distributor it has worked with for years. Three months later, its bank flags a payment: a new shareholder in the distributor's parent appears on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The transaction is now potentially prohibited. The company has no compliance record to show it asked the right questions before signing.

Counterparty due diligence under OFAC means establishing, before any transaction, that no party in the ownership and control chain is a blocked person, a sanctioned country national, or an entity caught by the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked). As of July 2026, OFAC enforces an objective strict-liability standard for most violations: not knowing does not remove exposure, though it can reduce a penalty. A well-documented diligence process is the primary line of defence.

This guide walks through the diligence process step by step, identifies where businesses most often fall short, and explains how the OFAC standard compares with the parallel requirements under OFSI, the EU, and other regimes.

Step 1: Understand what OFAC actually requires of businesses

OFAC does not publish a single statutory checklist for counterparty diligence, but its enforcement guidelines make the expectation clear: a business must take reasonable steps – proportionate to the risk of the transaction – to establish that no blocked person benefits from it. The underlying authority is IEEPA and the relevant programme regulations.

Proportionality is the operative concept. A one-off, low-value purchase from a domestic supplier requires less scrutiny than a long-term distribution arrangement with a counterparty that has owners in multiple jurisdictions. In our practice, we regularly advise clients that the trigger for enhanced diligence is not only the counterparty's location but also the goods involved, the payment route, and the end use. A manufacturer of dual-use components shipping to a complex ownership structure in a high-risk jurisdiction sits in a different risk band than a domestic services provider.

OFAC also expects firms to keep records of what they checked and when. A documented, dated diligence file showing the searches conducted, the ownership structure reviewed, and any escalation decisions taken can be the difference between a finding of no action warranted and a civil penalty referral. Treat diligence not as a one-time gate but as a live process that should be refreshed when ownership changes, when a material new transaction arises, or when a list update occurs.

Step 2: Screen the counterparty and map the ownership chain

Screening the counterparty's legal name against the SDN List and the other OFAC-maintained lists is the starting point – not the end point. The 50 percent rule means that an entity which is not itself listed can still be fully blocked if listed persons own it 50 percent or more in the aggregate, directly or through intermediate layers.

Aggregation catches firms by surprise. Two listed persons, each holding a minority stake, can combine to meet the threshold. OFAC's guidance is clear that the arithmetic operates across all listed owners regardless of whether they are related. A screening tool that checks only the immediate counterparty against the SDN List will miss this entirely. What is needed is a structured review of the counterparty's beneficial ownership chain – ideally to a level that satisfies you that no listed person sits, directly or indirectly, above the threshold.

Practical starting points include corporate registry filings, commercial ownership databases, and the counterparty's own representations. None of these is sufficient alone. Registry data can be out of date; commercial databases carry their own lag; a counterparty's self-certification is only as reliable as the contractual consequences attached to a false statement. In our experience, the combination of at least two independent sources – cross-checked against any information already known about the counterparty's sector or geography – provides a defensible baseline.

One discipline that experienced compliance teams apply is to document not only what was found but what was searched. If a future enforcement inquiry asks why a particular beneficial owner was not identified, the answer "we ran searches on the following databases on the following dates and found no hits" is far more useful than a bare assertion that diligence was completed.

Step 3: Apply enhanced scrutiny to higher-risk ownership structures

Where ownership is opaque, layered through trusts or nominees, or includes persons in jurisdictions associated with elevated sanctions risk, a standard database search is insufficient. Enhanced diligence at this stage means going beyond automated screening and applying analytical judgment to the ownership picture as a whole.

Consider the following indicators, each of which should prompt a more detailed review:

  • Beneficial ownership that cannot be independently verified through public or commercial sources
  • Nominee directors or shareholders that obscure the ultimate beneficial owner
  • Ownership chains that pass through jurisdictions subject to comprehensive OFAC programmes
  • Counterparties in sectors that OFAC has identified, through published guidance, as carrying heightened risk – defence, energy, financial services, technology
  • Ownership changes that have occurred shortly before or after a sanctions designation event

In a recent matter, a logistics business was structuring a services arrangement with a company whose ownership included a trust registered in a jurisdiction with limited public disclosure requirements. The beneficial ownership of the trust could not be confirmed through standard commercial databases. We advised the client to obtain direct written representations from the counterparty as to the identity of trust beneficiaries, to include contractual warranties and a termination right triggered by any sanctions listing, and to document the limits of what the independent search had returned. That approach produced a defensible record without requiring the client to refuse the business outright.

How does the OFAC ownership test compare with OFSI and EU requirements?

The OFAC 50 percent rule is mechanical: ownership of 50 percent or more by blocked persons means the entity is blocked, regardless of who controls day-to-day operations. The test is purely arithmetic. OFSI and the EU add a parallel concept: ownership and control (the UK and EU test for whether a non-listed entity is caught through a listed person), which means an entity can be caught even where the listed person's ownership falls below 50 percent, if the listed person controls the entity by other means.

That divergence matters in practice. A structure where a designated individual holds 40 percent of the equity but has board appointment rights, a casting vote, or effective veto power over major decisions may fall outside the OFAC 50 percent rule while still being caught under OFSI's ownership-and-control test or the equivalent EU standard. A business that clears its counterparty under OFAC and then pays a European subsidiary of that counterparty from a UK bank account has not necessarily cleared the OFSI position.

Other regimes introduce further variation. Under the applicable country regime in several jurisdictions – including Australia (DFAT), Canada (GAC), and Singapore – the tests for indirect exposure differ in their precise formulation and in the enforcement posture of the relevant authority. Cross-border businesses cannot assume that a clean OFAC result transfers automatically. We regularly advise clients on how to design a single diligence workflow that satisfies the primary OFAC standard while capturing the additional markers required under OFSI, the EU Council regulations, and the other regimes relevant to their counterparty and payment flows.

Is your diligence workflow calibrated to the regimes that are actually in play for your business – or just to the one that is most familiar?

Step 4: Handle hits, escalations, and false positives

A screening alert – a potential name match between a counterparty and a listed person – is not itself a finding of a violation. It is a trigger for a structured escalation process. Businesses that treat every alert as a binary pass/fail create unnecessary friction and, paradoxically, increase the risk of genuine matches being processed as false positives because the team is fatigued by noise.

The standard escalation framework involves three stages. First, the compliance team runs a primary review: comparing the alert data point by point against the SDN List entry, using all available identifiers (date of birth, nationality, aliases, known addresses, entity type). Second, if the primary review cannot clear the alert, the matter is escalated to a named senior reviewer. Third, if the senior reviewer cannot clear it, the transaction is paused and, depending on the business type and the regulatory relationship, OFAC may need to be contacted for guidance or a licence application may need to be prepared.

Record each stage. A documented escalation trail – showing who reviewed what, on what basis, and at what time – is the foundation of any voluntary self-disclosure or enforcement defence if the matter is later revisited. A VSD (voluntary self-disclosure to a regulator) is most persuasive when the firm can show it had a process, identified the problem through that process, and acted promptly.

Timing also matters. OFAC's enforcement guidelines recognise prompt action and co-operation as mitigating factors. A business that identifies a potential issue and continues to transact while deciding what to do loses that mitigation. Equally, a business that freezes all transactions indiscriminately on the basis of unresolved false positives creates operational disruption without legal necessity.

Step 5: Build ongoing monitoring into the compliance programme

Counterparty diligence is not completed at onboarding. OFAC list updates can, and do, designate persons who were previously unlisted. A counterparty that was clean at the point of contract may have a beneficial owner added to the SDN List months later. Without ongoing monitoring, a business can find itself mid-performance on a contract with a newly blocked counterparty and no record that it identified the change.

Effective ongoing monitoring involves three connected elements. Automated list scanning should run against the active counterparty population on a frequency that reflects the risk profile: daily or near-real-time for financial flows, weekly as a minimum for trade counterparties in sensitive sectors. Ownership refresh should be triggered by specific events: a change of control notification, a new ownership filing, a press report of a regulatory action against the counterparty or a related person. Contractual controls should require the counterparty to notify immediately of any change in ownership that could affect its sanctions status, with a clear termination right if they do not.

The interaction between ongoing monitoring and record-keeping is important. OFAC expects businesses to retain relevant compliance records. A well-maintained counterparty file – showing the original diligence, the ongoing monitoring runs, any alerts and their resolution, and any ownership updates – is the documentary evidence base for any subsequent compliance review or enforcement inquiry.

Common risk flags that escalate exposure

Across our cross-border practice, a consistent set of indicators reappears in matters where diligence has fallen short. These are not rules; they are patterns that experienced compliance counsel use to calibrate when standard process is not enough.

  • Unusual payment routing: a counterparty requesting payment to a third party, or through a jurisdiction with no apparent commercial connection to the deal, is a well-documented red flag under OFAC guidance
  • Reluctance to provide beneficial ownership information or to give representations as to sanctions status
  • Counterparty names or addresses that closely resemble those of listed entities without being identical (transliteration variants, minor spelling differences)
  • Transactions that combine multiple elements of risk – goods with a dual-use classification, a counterparty in a high-risk sector, and payment through a correspondent banking chain
  • Last-minute changes to deal structure, counterparty identity, or payment terms after initial diligence was completed

None of these flags is determinative on its own. But each one, particularly in combination, is a signal that the standard diligence level is not adequate and that escalation to sanctions counsel – rather than the compliance team alone – is warranted. What looks like a commercial decision about whether to proceed is, at that point, a legal question about whether the transaction is lawful at all.

Related practices

Frequently asked questions

What are the steps to run counterparty due diligence under OFAC?
The process runs in five stages: (1) assess the risk profile of the transaction and counterparty; (2) screen the counterparty's name against OFAC-maintained lists; (3) map the full beneficial ownership chain to check the 50 percent rule; (4) apply enhanced scrutiny where ownership is opaque or any indicator of elevated risk is present; and (5) document each stage. If a match or an unresolved alert is found, pause the transaction, escalate to a senior reviewer, and consider whether OFAC guidance or a licence is needed. Ongoing monitoring then applies for the life of the relationship.
What is the most common mistake in counterparty due diligence?
The single most common failure is treating a clean automated name-screen as complete diligence. A counterparty that does not appear on any OFAC list can still be blocked if a listed person or persons own it 50 percent or more in the aggregate. Firms that do not map the ownership chain – including indirect and aggregated holdings – miss this entirely. The second most frequent error is completing diligence once, at onboarding, and not refreshing it when list updates occur or when the counterparty's ownership changes during the life of a contract.
How does OFAC differ from other regimes here?
OFAC's ownership test is purely arithmetic: 50 percent or more held by blocked persons means the entity is blocked, without regard to control. OFSI in the UK and the EU Council regulations add a separate control limb: a non-listed entity can be caught even where the listed person's ownership is below the threshold, if the listed person controls it by other means. Businesses with UK or EU banking relationships, subsidiaries, or counterparties must clear both tests, not just the OFAC one. Several other regimes – including those of Australia, Canada, and Singapore – have their own formulations that require independent analysis.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.