A digital-asset exchange operating across four jurisdictions processes a token transfer routed through a self-hosted wallet. The sending address does not appear on any list. But the beneficial owner of that wallet is a designated person. The transfer settles in seconds. The compliance team discovers the connection three days later. As of mid-2026, this scenario repeats itself across the VASP sector with unsettling regularity – and the regulatory response in each major jurisdiction is hardening.
Crypto and VASP sanctions compliance across regimes requires a virtual-asset service provider or crypto-native business to screen every transaction, counterparty, and wallet address against the applicable sanctions lists in each jurisdiction where it operates, holds users, or processes transfers. The obligation is not theoretical: OFAC, OFSI, and EU authorities have all confirmed that sanctions prohibitions apply in full to virtual-asset transactions. A cross-border VASP cannot satisfy one regime and assume the others are covered.
This guide walks through the governing regimes and their practical differences, the core compliance steps a VASP must implement, the risk flags that attract regulatory attention, and when to engage specialist sanctions counsel.
Which regimes govern VASP sanctions obligations – and who enforces them?
Every major sanctions authority has confirmed that virtual-asset transactions fall within its general prohibitions, and enforcement competence sits with the same agencies that regulate conventional financial institutions.
In the United States, OFAC administers the sanctions programmes under IEEPA and other statutory authorities. Its guidance makes clear that all US persons – including those operating digital-asset platforms – are prohibited from transacting with specially designated nationals (SDNs, persons listed on OFAC's Specially Designated Nationals and Blocked Persons list) or with entities caught by the 50 percent rule (OFAC's rule treating any entity owned in the aggregate at 50 percent or more by one or more blocked persons as itself blocked, regardless of whether it appears on the SDN List). The SDN List includes digital-currency addresses as identifiers, making on-chain screening an explicit regulatory expectation.
In the United Kingdom, OFSI (the Office of Financial Sanctions Implementation) administers financial sanctions under the Sanctions and Anti-Money Laundering Act and the thematic regulations made under it. OFSI's guidance applies to all persons in the United Kingdom and to UK persons abroad. Its licensing and enforcement posture applies equally to transactions denominated in virtual assets.
In the European Union, financial-sanctions obligations under the relevant Council regulations bind all persons in the EU and all EU-incorporated entities globally. Member-state competent authorities enforce them. The EU's ownership and control test – under which a non-listed entity may still be caught if a designated person effectively controls it, even below a 50 percent ownership threshold – applies to crypto holdings and VASP relationships in the same way it applies to bank accounts.
Beyond these three, a VASP with users or settlement flows touching Singapore, the UAE, Japan, Australia, or Canada must also assess the applicable country regime in each of those jurisdictions. We regularly advise multi-licensed VASPs that hold regulatory authorisations in five or more jurisdictions and face a patchwork of list-screening and transaction-monitoring obligations that do not map neatly onto one another.
Step 1: Map your jurisdictional footprint before you screen anything
The first compliance step is not screening – it is determining which regimes apply and why, because that answer controls what lists you must screen against and what conduct is prohibited.
A VASP triggers sanctions obligations through several distinct connecting factors. Physical presence or incorporation in a jurisdiction creates obligations under that jurisdiction's rules. Processing a transaction that involves a person located in or a wallet address associated with a jurisdiction may engage its prohibitions. Holding a virtual-asset service licence in a jurisdiction typically brings full regulatory compliance obligations, including sanctions screening, as a licence condition.
The practical complexity arises at the intersection. A Singapore-licensed exchange that serves European users and settles dollar-denominated stable-coin transactions through US-correspondent banking infrastructure is simultaneously within reach of MAS guidance, EU regulations, and OFAC. Each regime has its own list, its own ownership-and-control test, and its own reporting timeline. Mapping the footprint before building the screening architecture prevents gaps that would otherwise only surface in an enforcement review.
In our practice, the footprint mapping exercise should produce a jurisdiction matrix: one row per regime, columns for the relevant list(s), the ownership test, the licence requirement, the reporting obligation, and the designated contact authority. That matrix then drives the technical and operational compliance build.
Step 2: Build a screening architecture that works for on-chain and off-chain activity
Sanctions screening for a VASP covers two distinct layers – the counterparty (the person or entity behind the wallet or account) and the wallet address or transaction itself.
Counterparty screening applies at onboarding and on a continuous basis thereafter. A VASP must screen the legal name, aliases, date of birth, and jurisdiction of residence for individual users, and the legal name, registration number, jurisdictions of incorporation, and beneficial-ownership chain for corporate clients, against each applicable list. OFAC's SDN List, OFSI's consolidated list, and the EU Consolidated List must each be screened separately: they do not contain identical entries, and a designation by one authority is not automatically mirrored by the others.
On-chain screening adds a layer that has no close analogue in traditional financial services. OFAC has published blockchain addresses as identifiers on the SDN List. A VASP is expected to block transactions involving those addresses. But the list of published addresses is not exhaustive. Blockchain-analytics tools can surface addresses with high-risk attribution – association with known sanctions-related clusters, mixing services, or darknet markets – that warrant enhanced due diligence even where no exact-match list entry exists.
The interaction between these two layers creates a practical tension. On-chain screening returns probabilistic risk scores, not binary matches. Counterparty screening produces match/no-match outputs. A VASP's compliance programme must define the escalation and decision logic that applies when blockchain analytics flag a transaction at a given risk level. That logic should be documented, tested, and reviewed at least annually.
Cross-regime divergence matters here too. What triggers a mandatory block under OFAC may, under the EU regime, trigger an obligation to freeze and report rather than simply reject. Under OFSI, a reporting obligation arises once a firm knows or has reasonable cause to suspect that it is holding funds belonging to a designated person. The response to a positive match is not identical across regimes, and a uniform "decline and forget" policy will not satisfy every jurisdiction.
Step 3: Apply the correct ownership and control test for each regime
Getting the ownership and control analysis right is where many VASPs fall short – particularly in cross-border situations involving corporate or DAO-adjacent structures.
Under OFAC, the 50 percent rule is mechanical. If blocked persons hold 50 percent or more in the aggregate – whether directly or through layers of intermediate entities – the entity is itself treated as blocked, even if it does not appear on any list. The test does not require any showing of actual control over operations.
Under OFSI and the EU, the position is materially different. The UK and EU apply an ownership and control test: a non-listed entity can be caught if a designated person owns it, controls it through formal governance rights, or exercises effective control in fact, even where numerical ownership sits below 50 percent. Control can be established through voting rights, board appointment powers, contractual rights, or the practical ability to direct the entity's activities without formal legal authority.
For a VASP, this matters in two directions. First, a VASP must assess whether any of its institutional counterparties – liquidity providers, custodians, over-the-counter desks, bridge operators – are caught by the ownership or control test in each regime. Second, a VASP must assess whether designated persons exercise control, in the relevant sense, over any portion of the VASP itself – including through token-holder governance rights in a decentralised structure.
There is a persistent myth in the sector that decentralised protocols and token governance structures fall outside the reach of sanctions law because there is no central entity. Regulators have consistently rejected this view. Where a person or a group of persons with sufficient connection to a jurisdiction operates or controls a protocol, obligations can attach. The legal answer depends on the specific structure and the specific regime. We have acted for VASP clients at precisely this point of uncertainty, and the answer is rarely "you are clearly outside the regime."
What risk flags attract regulatory attention to a VASP's sanctions programme?
Regulators and enforcement authorities are not examining whether a VASP has a sanctions policy – they are examining whether the policy functions in practice. Several recurring failure modes account for the large majority of regulatory scrutiny in this sector.
The first is list coverage gaps. A VASP that screens only the SDN List but operates in the EU and the UK is screening against one of at least three lists it needs. Regulators in each jurisdiction assess compliance against their own list, not against OFAC's.
The second is stale onboarding data. Designations are issued without prior notice. A counterparty screened clean at onboarding may be designated a year later. Continuous screening – re-screening the customer book against updated lists on a defined cycle – is now a baseline expectation in each major regime. A VASP that relies solely on point-in-time onboarding screening has a structural gap.
The third is inadequate beneficial-ownership look-through. Many VASPs accept self-certified ownership declarations without independent verification. Where a corporate client is owned through multiple layers, a shallow review will miss a designated beneficial owner. The 50 percent rule and the EU/UK control test both require a view through intermediate layers.
The fourth is the absence of a documented escalation path. When a screening hit arises, a VASP needs a clear internal procedure: who reviews it, at what level, in what timeframe, and what the reporting obligation is in each relevant jurisdiction. Absence of that procedure signals to regulators that the programme is theoretical rather than operational.
A fifth area is travel rule compliance. The travel rule (the obligation to collect and transmit originator and beneficiary information for virtual-asset transfers above specified thresholds) sits adjacent to sanctions compliance. A VASP that cannot identify the originator or beneficiary of a transfer also cannot effectively screen them. Gaps in travel rule implementation are routinely surfaced in the same regulatory reviews that assess sanctions controls.
How does the cross-border dimension differ from a single-regime approach?
A single-regime VASP can build its compliance architecture around one set of lists, one ownership test, and one reporting regime. A cross-border VASP cannot. The differences are not merely technical – they create genuine conflicts of obligation that require deliberate design choices.
Consider a VASP that identifies a counterparty as a close associate of a designated person. Under one regime, a close associate relationship may not itself trigger a freeze obligation. Under another, it may be sufficient to engage an enhanced due diligence obligation or, depending on the facts, a freeze-and-report duty. The VASP must apply the stricter obligation where both regimes apply simultaneously.
Reporting timelines also diverge. Each jurisdiction specifies its own window within which a suspicion or a confirmed hit must be reported to the competent authority. Where a VASP operates under multiple licences, it may face concurrent reporting obligations with different deadlines running from the same trigger event. Compliance calendars must map each obligation explicitly.
The interaction between the EU Blocking Regulation and US secondary-sanctions risk is a recurring cross-border tension. The Blocking Regulation prohibits EU persons from complying with certain listed US extraterritorial measures in specified circumstances. A VASP incorporated in an EU member state but operating in the US market may face a direct conflict between EU and US obligations. This is not a theoretical issue, and it requires jurisdiction-specific legal analysis before any compliance decision is made.
Does your current compliance architecture reflect each regime's list, ownership test, reporting obligation, and blocking statute position? If not, the gap is not a minor calibration issue. In our experience, cross-regime gaps are precisely where enforcement exposure concentrates.
Related practices
- Sanctions compliance audit and testing – structured review of screening controls, ownership analysis, and programme gaps across regimes
- Crypto and VASP sanctions compliance: EU regime guide – detailed analysis of EU Council regulation obligations for virtual-asset businesses
- Crypto and VASP sanctions compliance: OFAC guide – OFAC's SDN List, the 50 percent rule, and licensing for virtual-asset service providers
The position above covers the standard case. Your facts – the jurisdictions where you are licensed, the users you serve, the blockchain infrastructure you rely on, and the specific counterparties in question – change the analysis materially. The difference between a programme that satisfies OFAC and one that also satisfies OFSI and the relevant EU authority is often in the design detail, not in the intent.
If a transaction has already been flagged, or a suspicious match has surfaced that your programme has not resolved, an early legal review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential initial assessment.