Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Counterparty due diligence under OFSI: what businesses must know

A UK trading company is three weeks from closing a distribution agreement with a new supplier in the Gulf. The compliance team has screened the supplier's name against the OFSI Consolidated List (the Office of Financial Sanctions Implementation's list of designated persons and entities) and found no direct match. The legal team signs off. Two months later, internal audit discovers that a majority shareholder of the supplier has been on the UK sanctions list throughout. The deal is now an apparent breach. This scenario plays out more often than most businesses expect – and the fix is procedural, not technical.

Counterparty due diligence under OFSI requires more than a name-check against the Consolidated List. Under UK financial sanctions law, a non-listed entity whose ownership or control rests with a designated person is itself caught by the prohibition. The test is not purely numerical: the UK's ownership and control standard reaches beyond the 50 percent ownership threshold and extends to persons who exert decisive influence over the counterparty. As of July 2026, OFSI's enforcement posture has sharpened markedly, with monetary penalties available on a strict-liability basis for breaches without a licence.

This guide walks through the OFSI due-diligence process step by step, flags where the UK rules diverge from OFAC and EU positions, and identifies the points at which specialist counsel should be brought in.

Step 1 – Understand who OFSI can reach and why counterparty screening matters

OFSI enforces UK financial sanctions by prohibiting dealings with designated persons and with entities owned or controlled by them. The legal basis sits in SAMLA – the Sanctions and Anti-Money Laundering Act – and in the thematic regulations made under it for each sanctions programme. Crucially, the prohibition does not require knowledge of the designation: the UK regime now operates on a strict-liability basis for the civil monetary penalty, meaning a business can be penalised even if it did not know the counterparty was caught.

That strict-liability exposure is the single most important reason counterparty due diligence must be thorough and documented. It is not enough to ask "is the counterparty on the list?" The real question is: "does a designated person own or control the counterparty?" In our experience, businesses that run only a name-match at the entity level miss a significant proportion of the actual risk – particularly in supply chains with opaque holding structures.

The practical scope of OFSI's reach covers financial sanctions: asset freeze, dealing prohibitions, and restrictions on making funds or economic resources available. Export controls sit with a different authority (ECJU), but a transaction can engage both regimes simultaneously, and a competent due-diligence process checks both channels. From the outset, any business with UK-nexus dealings – whether in goods, services, finance, or professional advice – must treat OFSI screening as a standing obligation, not a one-off transaction check.

Step 2 – Map the ownership and control chain before running the screen

Before you screen a counterparty, you need to know what you are screening. A name-match against OFSI's Consolidated List is only as good as the ownership data behind it. This step is where most due-diligence programmes fail: they screen the entity they can see but never map the persons behind it.

For each counterparty, build an ownership chart that captures every natural person or entity holding a 50 percent or more stake at any level of the chain, and also any person who exercises control – meaning the ability to direct decisions, appoint a majority of the board, or veto material transactions. The UK ownership and control test is deliberately broad. It does not require formal legal ownership. Informal influence, contractual veto rights, or practical operational control can all suffice. This is a meaningful divergence from the purely arithmetic US approach, and it catches structures that would pass the OFAC ownership test.

Practical sources for building the chain include company registries, beneficial-ownership registers (where available), constitutional documents, shareholder agreements, and representations obtained directly from the counterparty. Where those sources are incomplete – as they often are in private-company transactions – the gap itself is a risk flag. A counterparty that will not disclose its ownership chain in response to a reasonable request warrants heightened scrutiny and, in most cases, a hold on the transaction pending clarification.

Document every step. If challenged by OFSI, the business's best defence is a contemporaneous record showing that it identified the relevant persons, screened them, and reached a reasoned conclusion. An incomplete record – even one reflecting genuine effort – weakens that position considerably.

Step 3 – Run a structured screen against the right lists and with the right logic

The screen itself must cover the OFSI Consolidated List and the UN Security Council Consolidated List, because UK sanctions implement UN obligations and the programmes overlap. For counterparties with US or EU connections, a complete screen also covers the OFAC SDN List (Specially Designated Nationals and Blocked Persons) and the EU's Common Foreign and Security Policy asset-freeze lists – this is the cross-border dimension that businesses most frequently omit.

Screening logic matters as much as list coverage. The screen must handle name variants, transliterations, aliases, and alternative spellings. A designated individual may be listed under multiple romanisations of the same name. A corporate entity may trade under a name that differs from its registered legal name. Screening tools that match only on exact strings will produce false-negative results. Configure your tool – or your manual process – to apply fuzzy matching with a threshold that generates manageable false positives without missing true matches.

Date of birth and nationality fields reduce false positives when screening natural persons. Registered address and jurisdiction of incorporation help disambiguate entities. Where fields are missing from your counterparty data, do not simply run the screen without them: obtain the missing data or flag the gap for senior review.

Periodic re-screening is as important as the initial check. Designations are made at any time. A counterparty that was clean at onboarding may be designated three months later. Any business with ongoing commercial relationships must maintain a re-screening cycle. The appropriate frequency depends on the risk profile of the relationship: higher-risk sectors and counterparties in higher-risk jurisdictions warrant more frequent review. There is no universally mandated cycle in the OFSI guidance, but many regulated firms screen monthly and re-run on an event-driven basis whenever a new designation list is published.

Step 4 – Assess the result and decide whether a licence is needed

A positive screen result – a potential match – does not automatically mean the transaction is prohibited. It means you have a hit that requires assessment. The first task is to confirm whether the match is genuine: compare the identifying data on the list against the data you hold on the counterparty and reach a documented conclusion. A false positive, properly recorded, closes the issue. A confirmed match requires the next step.

Where the match is confirmed, or where the ownership analysis reveals a designated person in the chain, the transaction is presumptively prohibited. At this point the business has essentially two options. First, decline or restructure to remove the prohibited nexus. Second, apply for a specific licence (a case-by-case authorisation from OFSI to conduct an otherwise prohibited transaction) if a licensing ground applies. OFSI issues licences under defined grounds set out in the relevant thematic regulations: humanitarian purposes, legal expenses, prior obligations, personal maintenance, and others depending on the programme.

The licence application process takes time. In our cross-border practice, we regularly advise clients on the preparation of OFSI licence applications, and the timeline from submission to decision varies materially by case complexity and the ground invoked. Businesses should not assume a licence will be granted or that it will arrive before a commercial deadline. Where a transaction cannot proceed without a licence and the timeline is uncertain, early application and transparent communication with the counterparty are both essential.

The position above covers the standard pathway. Your specific facts – the counterparty's jurisdiction, the goods or services involved, the route of funds, and the programme in play – can change the analysis materially. For an initial assessment of your counterparty's risk profile under OFSI, contact Calder & Vance at info@caldervance.com.

How does the UK ownership and control test differ from OFAC and the EU?

The UK, US, and EU regimes each apply a test for when a non-listed entity is caught through a listed person – but they do not use the same test, and the differences are operationally significant for any cross-border business.

Under OFAC, the test is largely mechanical. An entity is treated as blocked when one or more blocked persons own 50 percent or more of it in the aggregate, directly or indirectly. Aggregation applies across multiple blocked persons. Control is relevant to OFAC's analysis in certain contexts, but the primary rule is the ownership threshold. If ownership falls below 50 percent and there is no direct listing, the prohibition does not automatically extend to the entity – though a specific licence or a cautious commercial decision may still be warranted.

Under UK law, the test is broader. The SAMLA ownership and control standard captures entities owned 50 percent or more by designated persons and also entities that a designated person controls. Control is defined to include the ability to ensure that the entity conducts its affairs in accordance with the designated person's wishes, whether through shareholding, voting rights, board appointment powers, or other means. That last category – "other means" – is deliberately open-ended and has practical implications for joint-venture arrangements, franchise models, and contractual relationships that give one party de facto decision-making authority.

The EU position under the relevant Council regulations is broadly similar to the UK on ownership and control: it captures entities owned or controlled by listed persons and applies aggregation logic consistent with UK practice. The EU and UK regimes diverged on listing following the end of the Brexit transition period, meaning a person may be listed under one regime but not the other. A business that screens only one list is exposed on both fronts.

The practical consequence for a business operating across these regimes is that the UK and EU ownership tests can catch a counterparty that would pass the OFAC ownership screen. Where a deal involves all three jurisdictions, the stricter prohibition governs. Assume UK and EU positions will catch more entities, and design the due-diligence process accordingly.

Risk flags that warrant enhanced due diligence or counsel involvement

Standard due diligence is the baseline. Certain features of a counterparty or transaction should trigger a more intensive review – and, in several cases, direct involvement of sanctions counsel before any decision is made.

What should prompt enhanced review? Consider the following patterns. The counterparty is incorporated in a jurisdiction with limited company-registry transparency, making ownership verification dependent on representations alone. The counterparty has recently changed its name, jurisdiction of incorporation, or ultimate beneficial owner without a clear commercial explanation. There are multiple layers of holding companies between the trading entity and the natural persons ultimately in control. The counterparty's ownership structure includes trusts, foundations, or nominee arrangements that obscure the identity of beneficial owners. The counterparty is unwilling to provide beneficial-ownership information despite a direct request. There is a geographic nexus – in the counterparty's shareholders, directors, or trading counterparties – to jurisdictions that are subject to broad sectoral or comprehensive sanctions programmes under any of the major regimes.

Beyond ownership, product and transaction features also raise risk. Goods or technology that appear on dual-use control lists, items with military or surveillance applications, and financial flows that are structured in a way inconsistent with the underlying commercial purpose all warrant closer examination. We regularly advise clients in the manufacturing, shipping, and financial-services sectors where these features combine and the risk profile is genuinely elevated.

If a transaction has already been flagged internally, or a payment has been blocked by a correspondent bank on sanctions grounds, the clock is running. Options that exist at day one narrow with time. Early counsel involvement – to scope the issue, assess whether a voluntary self-disclosure (a VSD, a proactive report to OFSI) is warranted, and preserve the firm's position – is materially more useful at the outset than after the regulator has been notified by a third party.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. To discuss a matter in confidence, contact Calder & Vance at info@caldervance.com.

A common myth: screening software is sufficient on its own

A persistent misunderstanding in the market is that deploying a screening tool satisfies the counterparty due-diligence obligation. It does not. Screening software is a detection mechanism for direct matches against published lists. It does not build ownership chains, it does not assess control, it does not flag the gap between what a counterparty discloses and what public registers show, and it does not produce the documented analysis that OFSI would expect to see in any enforcement inquiry.

In our experience, businesses that rely solely on their screening tool – without a documented ownership-mapping process, without a clear escalation procedure for hits, and without periodic review of re-screening frequency – carry significantly higher residual risk than they realise. The tool confirms that the counterparty's registered name is not on a list. It says nothing about the shareholder sitting two layers up.

Effective counterparty due diligence under OFSI is a documented process, not a piece of software. The tool is one element. The process – ownership mapping, list coverage, hit assessment, escalation, record-keeping, and periodic re-screen – is the obligation. Where the process is undocumented, even a genuine compliance effort may not mitigate penalty exposure in an enforcement context.

Related practices

Frequently asked questions

What are the steps to run counterparty due diligence under OFSI?
The process has five core steps. First, map the counterparty's full ownership and control chain to identify every natural person or entity with a relevant interest. Second, screen all identified persons and entities against the OFSI Consolidated List, the UN Consolidated List, and any other applicable lists given the transaction's jurisdictional footprint. Third, assess every hit to determine whether it is a true match or a false positive. Fourth, where a true match is identified, determine whether the transaction is prohibited and whether a specific licence ground applies. Fifth, document the entire process and retain the records – OFSI's guidance and general UK sanctions practice strongly support multi-year retention. Repeat the screen on a scheduled and event-driven basis for ongoing relationships.
What is the most common mistake in counterparty due diligence?
The most common mistake is screening only the counterparty's registered name without mapping the ownership chain behind it. A designated person who owns the counterparty through intermediate holding companies will not appear in a simple name-check of the trading entity. The UK ownership and control test catches that structure, but the screen will miss it if the ownership map was never built. The second most common mistake is failing to re-screen: a counterparty that was clean at onboarding may be designated at any later point, and the obligation to avoid prohibited dealings is continuous.
How does OFSI differ from other regimes here?
OFSI's ownership and control test is broader than OFAC's primarily arithmetic approach. Where OFAC focuses on whether blocked persons hold 50 percent or more of the entity in aggregate, OFSI additionally catches entities that a designated person controls through other means, including contractual rights and practical decision-making authority. OFSI also operates on a strict-liability basis for its civil monetary penalty, meaning intent is not required for the penalty to apply – though it can affect the amount. The EU position is broadly similar to the UK on control, but the two regimes have diverged on listing since the end of the Brexit transition period, so both must be checked independently.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.