A payments firm processing stablecoin transfers discovers, mid-settlement, that a wallet address matches an entry on a sanctions list. The transaction is already in flight. The compliance team must decide, in minutes, whether to freeze, reverse, or escalate – and they must do so across three jurisdictions whose rules diverge in ways that matter. This is not a theoretical problem. As of July 2026, virtual-asset service providers face overlapping and sometimes contradictory obligations under OFAC, OFSI, the EU Council regulations, and a growing set of national regimes in Asia and the Gulf.
Crypto and VASP sanctions compliance across regimes requires a structured, step-by-step approach that maps each obligation to its governing authority, tests ownership and control at the wallet level, and embeds real-time screening into transaction flows. A single compliance programme that is calibrated to one regime will routinely miss the extraterritorial reach of another. The cross-border dimension is not optional: most VASPs operate across multiple regulatory perimeters simultaneously.
This guide walks through the compliance steps in sequence – from legal-basis mapping through wallet screening, ownership analysis, licensing, breach response, and record-keeping – and flags where the major regimes diverge for a VASP with an international footprint.
Step 1: Map your legal obligations before you screen a single wallet
Before any VASP runs its first wallet address through a sanctions list, it must know precisely which regimes govern its activity. The governing authorities differ by jurisdiction, and the trigger for application is not always intuitive: OFAC's rules can apply to a non-US business if the transaction has a US-dollar leg, touches US infrastructure, or involves a US person anywhere in the chain. OFSI applies where a firm is incorporated or operating in the United Kingdom, or where the transaction involves the property of a UK-listed person. The EU Council regulations apply to EU-incorporated entities, EU nationals, and transactions conducted within EU territory.
Start with a jurisdiction matrix. For each entity in your group, list the regimes that apply by reason of incorporation, currency, correspondent banking relationships, and the nationality of key personnel. A Singapore-incorporated VASP clearing USD-denominated stablecoin transactions through a US correspondent bank will almost certainly sit within OFAC's reach, regardless of whether it has a US office. In our experience, firms that skip this mapping step design screening programmes that are technically sophisticated but jurisdictionally incomplete.
The mapping exercise should also capture second-order applicability. Canada's sanctions regime under the applicable national instruments, Australia's Autonomous Sanctions regime administered by DFAT, and the UAE's Cabinet resolutions each carry their own territorial triggers. A VASP with users, liquidity providers, or settlement partners in those countries needs to understand when those regimes bite. Equally, the UN Security Council Consolidated List underpins many national regimes: a party on the Consolidated List is usually captured under all of the above, though the asset-freeze mechanics differ by jurisdiction.
The position above covers the standard framing. Your specific group structure, the currencies you settle, and the location of your node operators change this analysis materially. If you are building or rebuilding a VASP compliance programme and you are not certain which regimes apply to which entities in your group, contact Calder & Vance at info@caldervance.com for an initial assessment.
Step 2: Build a screening infrastructure that matches the wallet, not just the name
Effective VASP sanctions screening operates at the wallet address level, not only at the counterparty-name level – and that distinction drives most of the compliance gap between traditional financial-institution screening and crypto-native compliance. OFAC, for example, has published specific wallet addresses associated with designated persons and entities. Those addresses are on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) as distinct identifiers, meaning a VASP must screen against the address itself, not only against the name of the controlling person.
The practical challenge is that wallets proliferate. A single SDN may control dozens or hundreds of addresses. A screening tool that checks only a static list of published addresses will miss newly created wallets linked to the same person. Blockchain analytics – tracing transaction histories and clustering addresses by behavioural patterns – is therefore a necessary supplement to list-based screening, not an alternative to it.
Under OFSI's guidance, a UK-regulated VASP must take reasonable steps to identify whether it holds or controls funds belonging to a designated person. "Reasonable steps" in the crypto context means more than running a name through a list: it means tracing beneficial ownership through the wallet chain and applying the ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person's ownership or direction). Where a listed person holds an interest in a wallet through an intermediate smart contract or a layered DeFi protocol, that intermediation does not break the chain of control for sanctions purposes.
EU-supervised VASPs face equivalent obligations under the relevant Council regulations. The EU ownership and control test applies to legal persons, and regulators have indicated that entities structured through decentralised governance tokens may still be caught if a listed person exercises effective control over the protocol's decision-making. This is an area where regulatory interpretation is still developing, and a compliance programme should be calibrated to the more conservative reading until clearer guidance is available.
How does the 50 percent rule apply to crypto wallets and token holdings?
The 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) applies to legal entities, not directly to wallet addresses. However, its practical effect on VASPs is significant. If a blocked person owns or controls 50 percent or more of a legal entity that in turn holds a wallet, that wallet is treated as blocked property – even if the wallet address itself does not appear on any published list.
This creates a diligence obligation that extends beyond the address screen. For institutional counterparties – exchanges, OTC desks, liquidity providers – a VASP must map the beneficial ownership of the counterparty entity and apply the aggregation rule. Two blocked persons each holding a minority stake can together reach the threshold. In our cross-border practice, this aggregation point is one of the most frequently overlooked compliance gaps for VASPs onboarding institutional participants.
Under OFSI and the EU rules, the equivalent concept is the ownership and control test. It is broader than OFAC's purely mechanical threshold. A listed person who does not own 50 percent of an entity may nonetheless bring it within the freeze obligation if they direct its activities or hold decision-making rights over its assets. For a DAO or a multi-signature wallet structure, this question requires legal analysis of the governance documents, not just a percentage calculation. Have you mapped the decision-making rights of your institutional counterparties, or only their equity stakes?
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss a confidential review of a potential exposure.
Step 3: Handle transaction freezes and blocking obligations correctly across regimes
When a VASP identifies a match – a wallet address on the SDN List, a counterparty that triggers the 50 percent rule, or a transaction involving a designated person – the obligations that follow differ by regime, and a single incorrect step can produce a breach in a jurisdiction where the firm was otherwise compliant.
Under OFAC, US-nexus transactions involving blocked property must be frozen and the funds held in a blocked account. The VASP must then file a report with OFAC within a short statutory window – the exact current deadline should be verified against OFAC's published guidance, as filing timelines can be updated. Critically, the obligation is to block the property, not to reject the transaction and return the funds to the sender. Returning blocked funds without OFAC authorisation is itself a potential violation.
OFSI's approach differs. Under the UK rules, a firm that holds, controls, or is involved in a transaction involving a designated person's funds must freeze those funds and report to OFSI. OFSI's reporting obligation under the relevant thematic sanctions regulations requires prompt notification; the current reporting window should be confirmed against OFSI's published enforcement guidance before any action is taken. The UK rules do not have an exact equivalent to OFAC's blocked-account mechanism, and the interaction between the freeze obligation and a VASP's operational wallet custody requires specific legal analysis.
EU-regulated VASPs must freeze and notify the competent national authority. The relevant Council regulation and the applicable national implementing law determine which authority receives the notification. For a group operating across multiple EU member states, the picture can be complex: notifications may be owed in several jurisdictions simultaneously if the VASP holds assets in those member states.
One practical discipline: maintain a clear internal playbook for the sequence – identify, freeze, notify, escalate to counsel. The sequence is the same across regimes even if the mechanics differ. Firms that have the playbook rehearsed will execute correctly under time pressure; those that do not will make procedural errors that compound the substantive problem.
What is the licensing route when a blocked transaction has a legitimate purpose?
A specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) is available under OFAC, OFSI, and the EU Council regulations where a transaction involving designated property has a recognised legitimate purpose – humanitarian assistance, legal fees, an existing contractual obligation, or a winding-down arrangement, for example. VASPs encounter this issue most commonly when a user account is frozen following a designation and the user seeks to recover assets for a lawful purpose.
Under OFAC, a specific licence application requires a detailed factual submission, a clear statement of the purpose, and often supporting documentation from the counterparty. OFAC evaluates applications on a case-by-case basis; there is no guaranteed timeline, and a VASP should not commit to any payment or release of assets before the licence is granted. In our experience, applications that clearly articulate the public-interest or humanitarian ground, and that demonstrate the applicant's own compliance history, move faster than those that do not.
OFSI grants licences under the relevant thematic sanctions regulations using a defined set of licensing grounds. The grounds are statutory, not discretionary in the broad sense, and an application outside those grounds will not succeed. OFSI also has a reporting obligation: if a VASP applies for a licence and OFSI grants it, the firm must then comply with any conditions attached. Breach of a licence condition is treated as seriously as an underlying sanctions breach.
Under the EU rules, licensing is handled at the member-state level by the competent authority designated under the relevant Council regulation. For a VASP operating across the EU, this may mean separate applications in each member state where assets are held. A general licence (a standing authorisation that permits a defined category of transactions without a separate application) exists under some EU and UK thematic regimes and can address recurring low-risk transaction types without repeated applications.
Step 4: Design your record-keeping and audit trail to the most demanding standard
Across every major sanctions regime, the obligation to maintain records of screening decisions, blocked-property holdings, licence applications, and transaction data runs in parallel with the substantive compliance obligations. The record-keeping requirement is not an administrative afterthought: it is the evidence base for any regulatory examination, voluntary self-disclosure, or enforcement defence.
OFAC's rules require records to be maintained for five years from the date of the transaction. OFSI's guidance sets an equivalent retention standard. EU Council regulations impose a comparable requirement under the applicable national implementing law. In our cross-border practice, we recommend calibrating record-keeping to the most demanding standard across all applicable regimes, and storing records in a format that is retrievable on short notice.
For VASPs, the record-keeping challenge is compounded by the pseudonymous nature of blockchain transactions. A compliance programme must be able to link a wallet address to an identified counterparty through the VASP's customer due-diligence records, and to reconstruct the screening decision that was made at the time of onboarding and at the time of each material transaction. Where a VASP relies on a third-party blockchain analytics provider for its screening, the record must include the output of that provider's analysis, not just the final decision.
Audit trails should also capture the rationale for any decision not to freeze or report. Regulators examining a VASP's compliance programme after an incident will focus as much on documented false-positive decisions – cases where the firm decided a match was not a true hit – as on confirmed breaches. A well-documented false-positive decision is a defensible position; an undocumented one is not.
Risk flags and when to involve sanctions counsel
Certain fact patterns generate elevated sanctions risk for VASPs, and recognising them early is the most efficient risk-management tool available. The following are the most common flags we encounter in practice.
- Nested exchange relationships. Where a VASP provides liquidity or settlement services to another exchange, and that exchange has its own onboarding weaknesses, the first VASP may be processing transactions on behalf of persons it has never screened. This is an extraterritorial risk under OFAC in particular.
- Peer-to-peer withdrawal requests to unhosted wallets. Transfers to unhosted wallets carry higher risk of sanctions evasion by the underlying user. A compliance programme should apply enhanced scrutiny to large-value or high-frequency P2P withdrawals to addresses with limited transaction history.
- DeFi protocol interaction. Where a VASP's users interact with decentralised protocols, the VASP may still bear a compliance obligation if it has a sufficient degree of control over or involvement in the protocol. This question is regime-specific and is currently under active regulatory development.
- NFT and tokenised-asset platforms. The designation of a person who holds or mints NFTs raises novel questions about whether the NFT itself constitutes blocked property. OFAC has taken the position that property held by a blocked person is blocked; the application to non-fungible tokens requires case-specific analysis.
- Cross-chain bridge transactions. Bridging assets across blockchain networks can obscure transaction history and complicate the screening of wallet clusters. A compliance programme that screens on the destination chain only may miss a sanctioned-origin wallet.
Involve sanctions counsel when: your screening returns a confirmed or probable match and you are unsure of the freeze or reporting obligation; you receive a regulatory enquiry or examination notice; you are considering a licence application; your analytics provider indicates a counterparty wallet has a high-risk sanctions cluster; or your programme has not been tested against the current OFAC, OFSI, and EU screening expectations in the last twelve months. Early legal involvement narrows risk and preserves options. Late involvement, after a breach has compounded, narrows them.
A common myth in VASP compliance is that decentralisation provides a regulatory safe harbour. It does not. Regulators have consistently taken the position that the relevant question is not the technical architecture of a protocol but whether a person or entity is exercising sufficient control or involvement to be subject to regulation. A VASP cannot outsource its sanctions obligations to a smart contract.
How Calder & Vance advises on crypto and VASP sanctions compliance
We advise VASPs, crypto exchanges, DeFi platforms, and institutional digital-asset businesses on sanctions risk across the major regimes. Our work in this area spans programme design, wallet-level screening architecture review, ownership and control analysis for institutional counterparties, licence applications following a transaction freeze, and enforcement defence where a potential breach has been identified.
In a recent matter, a cross-border digital-asset business identified a cluster of wallets linked to a counterparty that had not been flagged by its automated screening tool. We conducted an ownership and control analysis across the relevant OFAC, OFSI, and EU regimes, mapped the beneficial-ownership chain through three intermediary entities, and advised on the firm's reporting obligations in two jurisdictions. The matter resolved through prompt voluntary notification and a structured remediation programme.
We test screening logic, map ownership and control chains, and redesign compliance programmes to the standards that regulators are currently applying – not the standards that were sufficient two years ago. Our team covers the US, UK, EU, and Asian regimes under one roof, which means you receive a single, consistent analysis of a cross-border fact pattern rather than disconnected advice from separate specialists.
Related practices
- Sanctions compliance audit and testing – independent audit and gap analysis of your VASP sanctions programme against current regulatory expectations.
- Crypto and VASP sanctions compliance: advanced cross-border issues – deeper treatment of DeFi, NFT, and tokenised-asset sanctions questions across regimes.
- EU crypto and VASP sanctions compliance guide – step-by-step guide to EU Council regulation obligations for digital-asset businesses.