Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFAC

Crypto and VASP sanctions compliance under OFAC: procedure and pitfalls

A virtual-asset service provider receives a transaction from a wallet flagged in a third-party screening alert. The compliance officer wants to know: is the transaction blocked, does the firm have a reporting obligation, and what does it do next? These are not abstract questions. They arise in real time, often at the weekend, and the answers have direct legal consequences.

As of July 2026, crypto and VASP sanctions compliance under OFAC requires any US person – and any non-US entity touching US-nexus activity – to screen transactions and counterparties against the SDN List (OFAC's list of Specially Designated Nationals and blocked persons), block property of designated persons, and report blocked or rejected transactions. The obligations are the same in legal structure as those for traditional financial institutions. The practical enforcement differs significantly.

This guide walks through each stage of that process, explains where the major pitfalls sit, and identifies where the OFAC position diverges from those of OFSI, the EU, and SECO – because most VASPs operate across more than one regime.

What legal basis governs OFAC's authority over virtual assets?

OFAC's authority over virtual-asset transactions derives from the same statutory foundation – primarily IEEPA and TWEA – that governs its entire sanctions programme. No special crypto legislation creates a distinct regime. The practical consequence is that the obligations imposed on a VASP are analytically identical to those imposed on a bank: block property in which a designated person has an interest, reject transactions you are not authorised to process, and report promptly.

OFAC has clarified through public guidance that digital currency is "property" for sanctions purposes. That single point resolves most threshold questions. If a wallet address is linked to an SDN, the funds in it are blocked. If a VASP facilitates a transfer involving blocked property without a licence, it has potentially committed a sanctions violation – regardless of whether it knew the counterparty was designated.

The strict-liability element is significant. OFAC enforcement does not require proof of intent to commit a violation. The relevant question for penalty calculation is whether the violation was voluntary and whether the entity had reason to know. That difference in framing shapes the entire compliance architecture a VASP needs to build. We regularly advise VASPs that underestimate this point until they receive a first inquiry.

The position is largely consistent with the UK approach under the Sanctions and Anti-Money Laundering Act and OFSI's enforcement guidance – but OFSI applies a knowledge-or-reasonable-cause standard, and that difference in mens rea matters when assessing comparative exposure for a dual-regulated business.

Step 1 – Identify your nexus: who is actually obligated?

Jurisdiction turns on nexus, and the first step in any crypto and VASP sanctions compliance programme is establishing which regime's obligations attach. For OFAC, the rule is straightforward: US persons everywhere, and non-US persons when a US nexus exists. That nexus can arise through the involvement of US-dollar clearing, US-domiciled servers, US-based developers, or any other connection to the United States.

Where does this catch firms by surprise? A VASP incorporated in the British Virgin Islands, serving European customers, processing transactions denominated in a stablecoin pegged to the US dollar and settled through a US-based smart-contract infrastructure may have a US nexus it has not assessed. In our experience, the nexus analysis is the step most often skipped or compressed in early-stage VASP compliance programmes.

The cross-border dimension compounds quickly. That same firm likely has UK obligations under OFSI if it serves UK-resident customers or holds sterling. It may have EU obligations under the relevant Council regulations if it operates from an EU member state or serves EU-based counterparties. The stricter prohibition governs wherever the rules overlap – and OFAC's strict-liability standard is almost always the most demanding of the three.

Practical first action: produce a written nexus memorandum that maps entity structure, customer geographies, currency exposures, and infrastructure dependencies against each applicable regime. This document becomes the foundation of every subsequent compliance decision. Do you have one that has been reviewed in the last twelve months?

Step 2 – Build a transaction and counterparty screening programme

Once nexus is confirmed, the core obligation is screening – of transactions, of counterparties, and of wallet addresses. OFAC maintains the SDN List and a set of non-SDN lists; the SDN List carries the most severe consequences. OFAC has also designated specific wallet addresses associated with SDNs and publishes those addresses in a machine-readable format alongside the standard list.

A minimally compliant screening programme for a VASP should address four elements. First, name screening of customers and beneficial owners at onboarding and periodically thereafter, matched against the SDN List and applicable consolidated lists. Second, wallet-address screening of sending and receiving addresses at the point of transaction. Third, IP-address and geolocation screening to detect connections to comprehensively sanctioned jurisdictions. Fourth, a process for handling screening alerts, including a clear escalation path and a documented disposition record.

The wallet-address element is operationally the most demanding. OFAC publishes addresses as a supplement to the SDN List, but the published list is not exhaustive of all addresses a designated person may control. Third-party blockchain analytics tools provide attribution data that extends beyond the published list. Whether a firm is required to use such tools is a matter of reasonable diligence – and OFAC has considered the use of analytics software as a mitigating factor in enforcement matters where the published list alone would not have identified the counterparty.

Under OFSI, wallet-address screening is not yet the subject of the same level of published guidance, though the underlying legal obligation – not to deal with a designated person's property – is identical in effect. SECO in Switzerland and the EU share the same substantive prohibition. The operational question of what tooling is sufficient differs, however, and a VASP operating across all three regimes should assess each standard independently.

The position above covers the standard case. Your facts – the customer base, the chain architecture, the transaction volume, the regime mix in play – change the analysis materially. For a structured review of your screening design, contact Calder & Vance at info@caldervance.com.

Step 3 – Respond to a screening hit: block, reject, or investigate?

A screening alert is not the same as a confirmed sanctions hit, and the correct response to an alert depends on the outcome of a structured investigation. This step is where many VASPs make their most consequential procedural errors.

When a screening system returns an alert, the first question is whether the match is a true positive – meaning the counterparty is actually designated or the wallet address is actually associated with blocked property – or a false positive generated by name similarity or stale data. Most compliance teams experience a high volume of false positives. The risk is that, in handling volume quickly, they process a transaction that should have been blocked.

For a confirmed hit, the obligation forks. Property in which an SDN has an interest must be blocked: the transaction is halted and the funds are placed in a blocked account. A transaction that would benefit a sanctioned jurisdiction or SDN but does not involve property already in the firm's custody is rejected rather than blocked. The distinction matters because blocking triggers a specific reporting requirement – and failing to report a blocked transaction is itself a violation.

OFAC requires reporting of blocked property. The reporting window is defined in the applicable programme regulations; verify the current deadline before relying on it. OFSI requires equivalent reporting under SAMLA, and the UK regime imposes its own timeline. Where a VASP is subject to both, it must meet both deadlines independently.

A practical protocol: when the escalation team identifies a potential true positive, it should immediately suspend the transaction, document the basis for the suspicion, initiate a formal investigation, and notify the designated compliance officer. If the investigation confirms a hit, legal counsel should be involved before any communication with the customer or counterparty. Early disclosure to the customer of the reason for suspension can compromise a subsequent voluntary self-disclosure to OFAC.

If a transaction has already been processed and a subsequent review suggests it may have involved a blocked person, the timeline for remediation and potential voluntary self-disclosure narrows quickly. An early assessment can preserve options that close with delay. For a confidential review of a potential breach, contact us at info@caldervance.com.

Step 4 – Voluntary self-disclosure and penalty mitigation

A VSD (voluntary self-disclosure to a regulator) is OFAC's primary mechanism for acknowledging an apparent violation before enforcement action is initiated. Filing a timely and complete VSD is the single most significant factor in reducing a civil penalty, and OFAC treats it as a substantial mitigating consideration in its penalty calculation.

The decision whether to file a VSD is a legal judgment, not a compliance formality. It requires an assessment of whether a violation has actually occurred, the severity of the conduct, whether the entity had reason to know, whether the affected transactions were egregious, and whether the violation is likely to come to OFAC's attention through another channel. Filing prematurely – before an internal investigation has produced a clear factual record – can result in an incomplete disclosure that creates additional exposure.

We regularly advise clients at this decision point. The internal investigation should precede the disclosure. It should produce a chronological factual record, a root-cause analysis, and a description of the remedial measures already implemented or planned. OFAC's guidance on what a complete disclosure should contain is instructive, and the quality of the submission significantly affects how the matter is received.

For VASPs, two characteristics of crypto enforcement deserve attention. First, blockchain transaction records are permanent and publicly verifiable. OFAC can reconstruct a VASP's transaction history from on-chain data independently of what the firm produces. A VSD that is inconsistent with the on-chain record creates a credibility problem that is difficult to repair. Second, a VSD filed in relation to OFAC does not discharge obligations under OFSI or the EU. If the same transactions breach multiple regimes, disclosures to each authority must be managed separately and consistently.

Step 5 – Programme design: the five-element compliance standard

OFAC's published framework for an effective sanctions compliance programme identifies five core elements: management commitment, risk assessment, internal controls, testing and auditing, and training. These elements apply equally to VASPs as to traditional financial institutions, and OFAC has consistently used a firm's compliance-programme quality as a factor in enforcement decisions.

For a crypto and VASP sanctions compliance programme, each element has specific operational content.

Management commitment requires board-level endorsement of the compliance programme, a designated compliance officer with appropriate authority, and documented accountability for sanctions obligations. In our experience, governance deficiencies at this level are the most common finding in post-incident reviews. A compliance officer without the authority to halt a transaction unilaterally cannot run an effective programme.

Risk assessment for a VASP should address customer risk (geography, volume, transaction type), product risk (peer-to-peer transfers, privacy coins, cross-chain bridges), delivery-channel risk, and third-party provider risk. The output should be a written, scored risk assessment reviewed at defined intervals. Blockchain analytics providers, fiat on-ramp partners, and smart-contract counterparties all sit within the relevant scope.

Internal controls encompass the screening infrastructure, the alert-management process, the blocking and rejection procedures, the record-keeping system, and the escalation protocol. Record-keeping obligations are not a minor procedural matter: OFAC requires retention of records related to sanctions compliance. Five years is the standard record-retention period under OFAC rules; verify the applicable period for each specific programme.

Testing and auditing requires periodic review of the screening logic and the alert-disposition process. Transaction samples should be tested against the SDN List independently of the production system to verify that the live system is returning accurate results. Audit findings should be documented and tracked to remediation. Our practice includes testing and audit work specifically calibrated to VASP screening environments.

Training must be tailored. Generic AML training does not address the OFAC-specific obligations a VASP team needs to understand – the strict-liability standard, the difference between blocking and rejecting, the VSD decision, and the wallet-address screening requirements.

Related practices

Common pitfalls: where VASP compliance programmes fail

Seven patterns account for the majority of VASP sanctions compliance failures that reach enforcement level. Recognising them in advance is less costly than remedying them after a breach.

The first is the false assumption of territorial insulation. A non-US VASP that has not completed a nexus analysis may believe OFAC does not apply to it. OFAC's guidance on this point is clear: US-dollar clearing, US-person staff, and US-infrastructure exposure each create nexus independently.

The second is over-reliance on the published SDN List without blockchain analytics. The published list captures designated wallet addresses that OFAC has identified; it does not capture the full address space controlled by an SDN. A VASP that screens only against the published list may process transactions involving an SDN's unlisted wallets.

The third is inadequate ownership and control mapping. The 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) applies to corporate counterparties in the crypto sector just as in any other. A VASP that has not traced beneficial ownership through intermediate layers may unknowingly process transactions for a blocked entity.

The fourth is customer communication after a hit. Notifying a customer that their transaction has been suspended because of a sanctions alert before counsel has assessed the situation can constitute tipping off and may prejudice both the enforcement position and the VSD.

The fifth is single-regime thinking. A VASP that manages only its OFAC exposure and has not assessed its OFSI or EU obligations is running an incomplete programme. The same transaction can breach multiple regimes simultaneously, and the penalties are independent.

The sixth is static screening lists. An SDN designation can be added at any point. A VASP that updates its screening lists infrequently – weekly or monthly rather than daily – runs the exposure gap. OFAC designations are effective immediately on publication.

The seventh is the myth that small transaction size reduces sanctions risk. OFAC has no de minimis threshold for sanctions violations. A ten-dollar transfer to an SDN is legally a violation in the same way as a ten-million-dollar transfer, though transaction size and aggregate value are relevant to penalty calculation. This misconception is particularly widespread in retail-facing crypto businesses. We address it directly when designing compliance programmes for consumer-oriented VASPs.

How does OFAC differ from OFSI and the EU on crypto obligations?

The three major Western regimes share the same fundamental prohibition – do not deal with designated persons' property – but their operational requirements, enforcement postures, and mens rea standards differ in ways that matter for cross-border VASPs.

OFAC operates a strict-liability civil standard. Intent is not required for a civil violation. The regime is the most prolific in terms of public enforcement actions in the virtual-asset sector, and it has the widest extraterritorial reach. Secondary-sanctions risk – the risk that a non-US firm loses access to the US financial system by dealing with a sanctioned person in a prohibited jurisdiction – adds a further layer that OFSI and EU do not replicate in the same form.

OFSI under SAMLA applies a knowledge-or-reasonable-cause standard for most civil penalties. The enforcement posture has become materially more active in recent years, and OFSI has published sector guidance on the virtual-asset sector. The OFSI licensing regime for financial sanctions includes a specific route for humanitarian and other purposes; the analysis of whether a VASP activity requires a licence is broadly parallel to the OFAC analysis but the specific conditions differ.

The EU regime under the relevant Council regulations applies to EU persons and to transactions with an EU nexus. The ownership and control test under EU regulations extends to entities where a designated person exercises control – not merely ownership – and this can capture a non-majority-owned subsidiary in ways that OFAC's 50 percent rule would not. The EU General Court provides a judicial route to challenge a designation, distinct from the administrative review process before OFAC.

For a VASP managing all three regimes, the operational implication is that the compliance programme must accommodate three different screening standards, three different reporting timelines, three different licensing regimes, and three different enforcement responses. A single compliance manual written to one regime's standard will not be sufficient.

SECO in Switzerland, GAC in Canada, and DFAT in Australia each impose their own obligations on VASPs operating in or from those jurisdictions. Singapore's MAS and Japan's FSA have published specific guidance on virtual-asset sanctions compliance, and the UAE's CBUAE framework addresses VASP obligations within the FATF-aligned national programme. Any VASP with a multi-jurisdictional footprint should map each regime separately before consolidating its programme design.

Frequently asked questions

What are the steps to manage crypto sanctions exposure under OFAC?
The steps are: establish jurisdictional nexus, build and test a screening programme covering the SDN List and designated wallet addresses, implement a hit-response protocol that distinguishes blocking from rejecting, maintain a record-keeping and reporting process aligned to OFAC's requirements, and review the programme against OFAC's five-element compliance standard at defined intervals. Each step requires documented procedures, not just operational practice, because documentation is the primary evidence in any enforcement review.
What is the most common mistake in crypto and VASP sanctions compliance?
Over-reliance on the published SDN List without supplementary blockchain analytics is the single most frequently cited control gap in VASP enforcement contexts. The published list captures only addresses OFAC has specifically designated. An SDN controls many additional addresses that are not on the list but are still legally blocked. A firm that screens only the published list may process transactions involving blocked funds without the alert that a broader analytics tool would have generated.
How does OFAC differ from other regimes here?
OFAC applies a strict-liability civil standard: a violation can occur without intent. OFSI requires knowledge or reasonable cause. The EU standard is broadly similar to OFSI but extends the ownership test to control, which can capture entities OFAC would not treat as blocked. OFAC also has the widest extraterritorial reach and is the most enforcement-active regime in the virtual-asset sector. Secondary-sanctions risk – the risk of losing US market access by dealing with a designated person – is an OFAC-specific exposure that OFSI and the EU do not replicate in the same form.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.