Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · UN

Counterparty due diligence under UN: a compliance guide

A trading company in South-East Asia identifies a new logistics partner. The commercial terms are agreed, the contract is close to signature. Then a compliance officer asks a simple question: has anyone actually checked whether this partner, or a company the partner controls, appears on the United Nations Consolidated List? The question stalls the deal. In our experience, it should have been asked weeks earlier.

Counterparty due diligence under the UN Consolidated List is the process of verifying that a proposed business partner, and the entities it owns or controls, is not subject to Security Council asset-freezing, travel-ban, or arms-embargo measures. The obligation derives from binding Security Council resolutions adopted under Chapter VII of the UN Charter, which member states are required to transpose into national law. Because every major sanctions regime – OFAC, OFSI, the EU Council – builds on or mirrors UN designations, a hit on the Consolidated List typically triggers simultaneous obligations in multiple jurisdictions.

This guide walks through the diligence process step by step: the governing authority, how to run the check, how ownership and control analysis works under the UN regime and its national counterparts, where the risk flags concentrate, and when to involve sanctions counsel.

Step 1: Understand the governing authority and the legal basis

The UN Consolidated List is maintained by the Security Council and its subsidiary committees. It consolidates the designation lists from all active Security Council sanctions regimes into a single searchable resource. Listing decisions are taken by the Security Council committees by consensus, and they bind all 193 UN member states through their national implementing legislation. No treaty opt-out exists; a state that has adopted the UN Charter is bound.

The practical consequence for a business is important. Compliance with the Consolidated List is not voluntary. It is not a matter of best practice. It is a hard legal obligation imposed through whichever national instrument your jurisdiction uses to give effect to Security Council resolutions. In the United Kingdom that is SAMLA (the Sanctions and Anti-Money Laundering Act) and the relevant thematic regulations. In the European Union it is the applicable Council Regulation. In the United States, IEEPA-based OFAC programmes incorporate UN designations or add parallel designations. The legal source is always the national instrument; the Consolidated List is the upstream trigger.

As of July 2026, the active Security Council regimes address a range of thematic areas – non-proliferation, arms controls in specific regions, counter-terrorism – each maintained by its own committee. The Ombudsperson process (relevant to the ISIL / Al-Qaida regime) and the Focal Point for de-listing (relevant to other regimes) are the formal review routes for listed persons or entities that wish to challenge their designation. That architecture matters for diligence purposes: knowing which committee listed a counterparty tells you which review route applies if a dispute arises.

Step 2: Map who you are actually screening

Effective counterparty due diligence begins by defining the screening universe correctly. The entity named in the commercial agreement is rarely the only entity that needs to be checked.

At a minimum, the screening universe for any counterparty should include: the legal entity signing the contract; any parent company owning a controlling or majority stake; key subsidiaries that will perform or receive performance; the ultimate beneficial owners above the relevant ownership threshold; and any individual directors or senior officers with signing authority on the transaction. That list is the starting point, not the end point.

Why does the scope matter so much? Because the UN sanctions regime, when implemented through national law, applies asset-freeze obligations not just to named entities but to funds and assets held by or on behalf of listed persons. A business that pays a listed individual's shell company is, in the eyes of the applicable national regime, dealing with the listed person's assets. The ownership-and-control analysis is where this risk concentrates.

We regularly advise clients who have screened the counterparty name but omitted the beneficial ownership layer. In a recent matter, a financial-services business had passed its standard screening on a proposed partner. A second-layer review identified a listed individual holding an indirect stake through a holding structure in a third jurisdiction. The transaction was restructured before execution. Had the gap been identified post-execution, the remediation options would have been far more limited.

Step 3: Run the consolidated-list check and resolve the ownership-and-control analysis

Searching the UN Consolidated List directly is the baseline. The Security Council maintains a publicly accessible search interface. But a manual search of the UN list alone is insufficient for most commercial diligence purposes, for two reasons.

First, national implementation layers add designations. OFAC, OFSI, and the EU Council each maintain their own lists that extend beyond UN designations. A counterparty that does not appear on the UN Consolidated List may nonetheless appear on the OFAC SDN List (the list of Specially Designated Nationals and blocked persons) or on the EU's consolidated sanctions list. Your diligence must cover all regimes relevant to the transaction.

Second, the Consolidated List names entities and individuals – it does not name every company those individuals own. The ownership and control test (the principle that obligations extend to entities owned or controlled by a listed person, even if that entity is not itself named) operates through national implementing legislation. The precise formulation varies. Under OFAC, the 50 percent rule (the rule that any entity owned 50 percent or more in aggregate by blocked persons is itself treated as blocked) is mechanical: if the threshold is met, the entity is blocked regardless of whether it is named. Under OFSI and the EU, a control test supplements the ownership threshold – a listed person who controls an entity through other means, such as board composition or veto rights, can cause that entity to fall within the scope of the asset freeze even where the ownership percentage is below the threshold.

What does this mean operationally? Confirm the ownership chain at each layer to the ultimate beneficial owners. Where ownership data is incomplete or opaque – a common challenge in markets with weak corporate-registry disclosure – document the steps taken and assess the residual risk. Where a listed person is identified in the chain at any level, escalate immediately. Do not assume that sub-threshold ownership is automatically clear: the control test means it may not be.

Step 4: Apply the cross-regime comparison and identify the strictest prohibition

A cross-border transaction rarely sits within a single sanctions regime. A UK-headquartered buyer, a Singapore-incorporated seller, goods originating in Germany, and a payment routed through a US correspondent bank – that one transaction may engage OFSI, the EU regime, OFAC (through the US correspondent), and Singapore's autonomous sanctions regime simultaneously. The guiding principle here is that the strictest prohibition governs. Where regimes diverge, a business must satisfy all of them.

Consider a practical divergence. The UN Consolidated List may designate an individual. OFAC may have designated the same individual under a programme whose scope differs. OFSI's asset-freeze regulations may impose a reporting obligation on the UK-nexus party to the transaction. The EU regime may require the goods themselves to be reported to a national competent authority. Each obligation runs in parallel; satisfying one does not discharge the others.

For exporters, an additional layer applies. Goods with dual-use potential may require export licences under the EAR (administered by BIS in the United States) or under EU dual-use rules, independently of whether the counterparty is listed. In our cross-border practice, we see transactions that clear the sanctions screening but stall on the export-licence assessment because the end-use question was not integrated into the diligence workflow from the outset. These two strands of analysis – sanctions status and export-control classification – should run in parallel, not in sequence.

Does your diligence workflow capture both? And does it surface the applicable national regime for every jurisdiction with a nexus to the transaction?

Step 5: Assess red flags and risk indicators

A clean screening result is necessary but not sufficient. Sanctions compliance counsel routinely encounter counterparties that are not themselves listed but whose profile concentrates risk indicators that warrant enhanced diligence or, in some cases, a decision not to proceed.

The following indicators are not exhaustive, but they represent the categories we see most frequently in cross-border matters.

  • Opaque or layered ownership structures with no commercially obvious rationale – for example, multiple holding companies across jurisdictions with weak beneficial-ownership registries.
  • A counterparty that recently changed its name, jurisdiction of incorporation, or principal officers without a disclosed commercial reason.
  • Requests for unusual payment routes – third-party payments, payments to an account in a jurisdiction unconnected to the commercial transaction, or an insistence on specific correspondent banking arrangements.
  • A counterparty whose stated business activity does not align with the goods or services being procured.
  • Connections to individuals or sectors that appear in adverse-media reports relating to sanctions, export-control violations, or related financial-crime matters.
  • Resistance to providing beneficial-ownership information or to accepting standard know-your-counterparty documentation requirements.

Any one of these factors may have an innocent explanation. The task is not to presume a violation; it is to document the analysis and satisfy yourself – and your institution's compliance function – that the residual risk is acceptable. Where multiple indicators converge, the threshold for involving external sanctions counsel lowers significantly.

Step 6: Document, decide, and monitor

Sanctions diligence is not a point-in-time event. It is an ongoing obligation. A counterparty that is clean at onboarding can become a problem if a beneficial owner is designated after the relationship commences. Compliance programmes that screen only at onboarding miss exactly this risk.

Documentation standards matter for two reasons. First, if a regulator or enforcement authority later questions a transaction, the quality of the contemporaneous diligence record is often the decisive factor in determining whether a violation was wilful, reckless, or the product of a good-faith compliance programme. Second, documented diligence is itself a form of institutional knowledge: it enables a firm to explain its decisions consistently if the counterparty relationship is revisited months later.

A diligence file for a significant counterparty should record: the date and scope of the screen; the databases and sources consulted; the results, including any partial-match analysis; the ownership-and-control assessment; any red flags identified and how they were resolved; the decision reached; and the name of the approver. If external counsel reviewed the matter, that advice should be retained. Record-keeping obligations under the applicable national regimes typically require relevant documentation to be maintained for a defined period after the conclusion of the business relationship – verify the specific requirement in the jurisdiction.

Periodic re-screening is the minimum for live counterparty relationships. Trigger-based screening – checking a counterparty immediately when a new designation in the relevant thematic area is published – provides a higher standard. Automated monitoring tools, calibrated to the risk level of the counterparty, are the practical means for most organisations.

Related practices

A common myth: passing one regime check satisfies all obligations

One assumption we regularly encounter – and one that creates significant exposure for businesses – is that screening against a single consolidated list is enough. The logic goes: "We checked OFAC. If it were a UN designation, OFAC would have it."

That assumption is incorrect for two reasons. First, OFAC designations and UN designations are issued by separate authorities and do not always match. A person can be designated by OFAC under a unilateral US programme without being on the UN Consolidated List, and vice versa. Second, even where an individual appears on both lists, the obligations differ by regime. The asset-freeze in the UK under OFSI may be wider or narrower in scope than the blocking under OFAC, depending on the definitions in the applicable national instrument. The reporting trigger may differ. The licensing route certainly will.

Comprehensive counterparty due diligence checks every regime with a nexus to the transaction. For most cross-border businesses, that means the UN Consolidated List, the OFAC SDN List, the EU consolidated list, and the OFSI list as a baseline – supplemented by the relevant autonomous regimes in the jurisdictions of the parties, the goods, the payment route, and the financial institutions involved. The cost of the additional checks is modest compared to the cost of a regulatory inquiry.

Frequently asked questions

What are the steps to run counterparty due diligence under UN?
Start by identifying the full screening universe: the counterparty entity, its parent companies, key subsidiaries, ultimate beneficial owners, and key individuals. Search the UN Consolidated List directly. Supplement with the OFAC SDN List, the EU consolidated list, the OFSI list, and any other regime with a nexus to the transaction. Conduct an ownership-and-control analysis for any partial matches. Document all steps and decisions. Establish a monitoring schedule for the ongoing relationship. Involve sanctions counsel where any flag is unresolved.
What is the most common mistake in counterparty due diligence?
The most common mistake is screening only the named contracting entity and not the full beneficial ownership chain. A listed individual holding an indirect stake through intermediate companies is not captured by a surface-level name check. A related mistake is treating diligence as a one-time exercise at onboarding. Designations change; a counterparty that is clean at the start of a relationship can present a compliance problem months later if a shareholder or officer is subsequently listed. Periodic re-screening is not optional.
How does UN differ from other regimes here?
The UN Consolidated List is the multilateral upstream layer. It is produced by Security Council committees and binds all member states. What differs is how each jurisdiction implements it. OFAC applies the 50 percent rule mechanically to entities owned by blocked persons. OFSI and the EU add a control test that can catch entities below that ownership threshold. Autonomous national programmes – in the US, UK, EU, Australia, Singapore, Canada, and others – add their own designations beyond the UN list. A clean UN result does not clear a counterparty under autonomous regime designations; all applicable lists must be searched.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.