Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFAC

How to manage crypto sanctions exposure under OFAC

A payments firm onboards a new business client. The client transacts in cryptocurrency. Screening flags a wallet address with a known link to a listed entity. The firm has minutes, not days, to decide whether to block the transaction – and hours to determine whether prior transfers have already created a reporting obligation. Crypto sanctions exposure under OFAC does not wait for a compliance team to catch up.

Managing crypto and VASP sanctions compliance under OFAC (the US Office of Foreign Assets Control) requires a defined, repeatable programme covering wallet screening, transaction monitoring, ownership and control analysis, and – where a potential violation has occurred – timely reporting. OFAC's jurisdiction extends to US persons and US-dollar transactions regardless of where the virtual-asset service provider is incorporated. As of July 2026, OFAC designates individuals, entities, and wallet addresses under multiple sanctions programmes, and the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) now includes specific blockchain addresses across multiple chains.

This guide sets out the five practical steps a VASP or financial institution should follow to manage crypto sanctions exposure under OFAC, with cross-regime comparisons to OFSI and the EU at each stage where the analysis diverges.

Step 1: Understand what OFAC's jurisdiction actually covers in the crypto context

OFAC's authority over virtual-asset transactions derives from the same statutory basis – principally IEEPA – that governs all US economic sanctions. The scope is broad.

Any US person – which includes US-incorporated entities, US branches of foreign firms, and any person physically in the United States – must comply regardless of where the transaction is denominated or routed. A non-US VASP that processes a transaction denominated in US dollars, or that clears through a US correspondent, is also subject to the rules for that transaction. OFAC has made clear that the prohibition on dealing with blocked persons applies to transactions in digital assets on exactly the same basis as transactions in fiat currency.

Two additional exposure points deserve attention. First, OFAC designates not only persons and entities but also specific wallet addresses. A wallet listed on the SDN List is itself blocked property. Receiving funds from a listed wallet, or sending funds to one, is a prohibited transaction – even if the counterparty behind the wallet is not separately listed by name. Second, OFAC's 50 percent rule (the rule treating entities owned 50 percent or more by blocked persons as themselves blocked) applies to digital-asset businesses in the same way it applies to any other entity. A VASP majority-owned by a listed person is itself blocked, whether or not OFAC has designated it by name.

For a business operating between the United States and the United Kingdom, the interaction between OFAC and OFSI is material. OFSI (His Majesty's Treasury's Office of Financial Sanctions Implementation) applies a different test for non-listed persons: ownership and control (the UK and EU test for whether a non-listed entity is caught through a listed person) requires analysis that goes beyond a mechanical ownership percentage and extends to practical control. A VASP that clears OFAC's 50 percent rule may still be caught by OFSI's control analysis, or vice versa. Managing both requires parallel screening protocols, not a single shared process.

Step 2: Build a wallet screening and transaction monitoring programme that matches the risk

Effective screening in the crypto context requires three distinct layers that work together: pre-onboarding entity screening, real-time wallet address screening, and post-transaction blockchain analytics.

Pre-onboarding entity screening is the baseline. It covers the counterparty's name, its ultimate beneficial owners, the jurisdiction of operation, and any publicly known wallet addresses. The same ownership aggregation logic that applies to fiat-currency counterparties applies here. Two listed persons each holding thirty percent of a VASP client reach the 50 percent threshold together, even though neither triggers it alone. A screening programme that checks only named individuals against the SDN List and stops there will miss this pattern.

Wallet address screening is distinct. OFAC publishes digital-currency addresses as part of SDN designations. Screening tools should check outgoing and incoming wallet addresses against this published list before each transaction settles, not only at onboarding. The published list is updated without advance notice; a wallet address that was clean at onboarding may be listed by the time the next transaction runs.

Blockchain analytics – the third layer – uses transaction-tracing tools to assess the provenance and destination of funds. OFAC guidance makes clear that VASPs are expected to use available blockchain analysis tools to detect exposure to sanctioned addresses even when those addresses are not themselves direct counterparties. The depth of analysis required is proportionate to risk: a retail exchange processing high-volume low-value transactions needs a different calibration than a DeFi protocol or an institutional OTC desk.

The position under EU rules parallels OFAC's in requiring asset freezes and prohibiting the making available of funds. EU rules, however, do not publish wallet addresses in the same structured format as OFAC. EU-focused VASPs therefore rely more heavily on entity-level screening and beneficial-owner analysis, and somewhat less on automated address matching. Firms operating across both regimes need to design for both requirements simultaneously.

The position above covers the standard case. Your facts – the counterparty, the chains involved, the jurisdictions of settlement, and the ownership structure – change the analysis. For an assessment of your VASP's screening programme, contact Calder & Vance at info@caldervance.com.

Step 3: Map ownership and control across the wallet and entity layers

The ownership-and-control analysis in the crypto context is more complex than in traditional finance, because the layers between a beneficial owner and a wallet can be invisible without active tracing.

Start with the entity layer. Map the full ownership chain of each significant counterparty to identify any person that holds – directly or indirectly – 50 percent or more in the aggregate. This is OFAC's 50 percent rule applied to corporate entities. Under OFSI and the EU, the inquiry extends to control: a listed person who does not reach the 50 percent threshold but who holds a right to appoint a majority of directors, or who can direct the use of funds, may still cause the entity to be caught. The divergence between OFAC's mechanical ownership threshold and the control-based approach of OFSI and the EU is one of the most practically significant differences in the regime landscape for VASPs operating across jurisdictions.

Move to the wallet layer. A single individual may control multiple wallet addresses. Those addresses may be linked to each other through blockchain tracing but may not be individually listed on the SDN List. OFAC's position is that all property and property interests of a blocked person are blocked, which extends to wallets the person controls even if those specific addresses are not individually published. This means a VASP cannot rely solely on address-list matching; it must conduct periodic reviews to assess whether counterparty wallets have become associated with newly listed persons.

In our experience, firms that maintain only a static ownership mapping at onboarding accumulate silent exposure over time. Counterparty ownership structures change. Listed persons acquire stakes in new entities. A quarterly review cycle for high-risk counterparties – and an event-triggered review whenever a new designation is published in a relevant programme – is the minimum standard we recommend for a well-run VASP compliance programme.

What happens when screening produces a potential match?

A potential match requires a defined escalation and decision process. Acting too slowly can itself constitute a violation if the transaction settles in the interim.

The immediate step is to freeze or block the transaction pending review. For inbound transfers, this means holding the funds in a blocked account. For outbound transfers, it means suspending the instruction. OFAC requires that blocked property be held in an account that is identifiable as containing blocked assets.

The next step is the match review itself. Not every screening alert is a true match. A common surname, an incomplete transliteration, or a shared address can produce a false positive. The review should assess whether the details of the counterparty align with the SDN entry across multiple identifiers – name, date of birth, nationality, associated addresses, and, where relevant, known wallet addresses. A single-field match is not sufficient to confirm a true positive.

If the review confirms a true match, two obligations arise in parallel. First, the transaction must remain blocked. Second, OFAC requires that a report be submitted within a short statutory window after the blocking event. A second annual report is due if the property remains blocked. These reporting obligations are separate from any voluntary self-disclosure that may be appropriate if the match reveals that prior transactions were processed in error.

Under OFSI, the reporting obligation after a freeze is structured differently and the deadlines differ from OFAC's. A firm operating under both regimes must comply with both reporting timelines independently. The stricter obligation governs for any activity that falls within both jurisdictions' reach simultaneously.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.

Step 4: Assess and respond to apparent violations – the voluntary self-disclosure question

An apparent violation occurs when a transaction has been processed that appears to involve a blocked person or blocked property. The question every compliance officer faces is whether to file a VSD (voluntary self-disclosure to OFAC) and, if so, how quickly and in what form.

OFAC's enforcement guidelines treat VSD as a significant mitigating factor. A timely, accurate, and complete VSD can substantially reduce the civil penalty that would otherwise apply. The penalty base for sanctions violations is set by statute and can be very significant; even relatively minor apparent violations in the crypto context can attract attention given the level of public visibility OFAC now applies to digital-asset enforcement. That said, no outcome is guaranteed by a VSD, and the decision to self-disclose is one that requires legal assessment of the specific facts before it is made.

The analysis before a VSD turns on several factors: the nature and number of the transactions, the approximate aggregate value, whether the apparent violation was systemic or isolated, what compliance measures were in place and whether they were followed, and whether the relevant counterparty was listed at the time of the transaction or only listed subsequently. OFAC's egregious-case framework and its general enforcement factors both bear on the analysis.

In our practice, we regularly advise VASPs and financial institutions through the VSD process. The most common error we see is delay. Firms that conduct an internal investigation for weeks before deciding whether to disclose can find that the window for maximum mitigation has narrowed. A preliminary scoping conversation with sanctions counsel – before a formal investigation begins – is often the most cost-effective step.

The interaction with UK and EU enforcement is also relevant. Where the same transactions are potentially reportable to OFSI and to OFAC, disclosures need to be co-ordinated rather than filed independently and sequentially. Discrepancies between filings in different jurisdictions can create additional regulatory risk. This is one area where cross-border sanctions counsel adds direct value.

Step 5: Design the compliance programme to reduce future exposure

A reactive posture – screening when a transaction arrives, investigating when a flag is raised – is not sufficient for a VASP with meaningful transaction volume or cross-border reach. The programme needs to be designed around a forward-looking architecture.

OFAC has described five elements that characterise an effective sanctions compliance programme: management commitment, risk assessment, internal controls, testing and auditing, and training. For VASPs, each element has specific operational content.

Management commitment means that sanctions compliance is a board-level and senior-management agenda item. It is not sufficient for a compliance function to maintain a programme that senior management neither reviews nor resources. OFAC's enforcement analysis considers the degree to which senior management was aware of, or should have been aware of, compliance deficiencies.

The risk assessment must be tailored to the VASP's specific product lines, customer base, transaction volumes, and geographic reach. A retail crypto exchange serving customers in low-risk jurisdictions has a different risk profile than a peer-to-peer trading platform with users across multiple high-risk regions. The assessment should map each product or service against the applicable sanctions programmes and identify the specific vectors of exposure – wallet-level risk, counterparty-entity risk, jurisdiction risk, and correspondent or settlement risk.

Internal controls cover the operational steps: onboarding procedures, transaction screening configuration, alert management, escalation protocols, blocked-property handling, and reporting procedures. Controls must be documented. Undocumented controls that work in practice provide much weaker mitigation value in an enforcement proceeding than documented controls that are consistently applied.

Testing and auditing – a distinct element from internal controls – requires periodic independent review of whether the controls are actually functioning as designed. We advise on and conduct compliance audit and testing services that apply an external lens to the programme, checking for gaps between policy and practice, and for changes in the regulatory environment that the programme has not yet absorbed.

Training is the final element. Staff who handle transactions, manage customer relationships, or make credit decisions must understand when and why a transaction should be escalated. Training that was delivered once at onboarding and never refreshed does not satisfy OFAC's expectation of a functioning programme.

Cross-regime risk flags: where OFAC, OFSI, and the EU diverge on crypto

Three practical divergences between OFAC, OFSI, and the EU create specific risk flags for multi-jurisdictional VASPs and financial institutions.

First, the ownership-versus-control split. OFAC's 50 percent rule is mechanical. OFSI and the EU assess both ownership and control, and the control analysis can reach an entity where the ownership test does not. A VASP that maintains a single shared ownership-and-control process for all three regimes will tend to apply either the broadest test (EU/UK control) or the narrowest (OFAC ownership), but not both correctly in each regime. Separate analysis tracks are needed.

Second, the structure of the designations list. OFAC publishes wallet addresses directly on the SDN List. EU and UK designations typically name persons and entities; wallet addresses associated with designated persons may be identified in guidance or supplementary material but are not always as directly accessible in a machine-readable format. A firm whose screening tool is configured only for OFAC-style address matching will have a gap in its EU and UK coverage.

Third, licensing architecture. OFAC issues both general licences (standing authorisations for defined categories of transactions) and specific licences (case-by-case authorisations). OFSI's licensing regime operates on a different set of categories, with named licence purposes set out in the applicable thematic regulations. The EU general-authorisation regime differs again. A VASP that identifies a potentially blocked counterparty and believes a licence may be available cannot assume that a route available under one regime is available under another. Advice must be sought for each regime in scope.

Are your screening and escalation protocols calibrated for all three regimes, or only for the primary jurisdiction where your firm is regulated? That question is worth asking before an enforcement action makes it unavoidable.

Related practices

Frequently asked questions

What are the steps to manage crypto sanctions exposure under OFAC?
Managing crypto sanctions exposure under OFAC requires five sequential steps: (1) mapping the full scope of OFAC's jurisdiction over your transactions and counterparties; (2) building a wallet screening and transaction monitoring programme with three distinct layers – entity screening, address matching, and blockchain analytics; (3) mapping ownership and control across both the entity and wallet layers; (4) defining a clear escalation and reporting procedure for potential matches and apparent violations; and (5) designing a forward-looking compliance programme against OFAC's five-element standard. Each step must be documented and periodically tested.
What is the most common mistake in crypto and VASP sanctions compliance?
The most common mistake is relying solely on name-based screening at onboarding and not maintaining a real-time wallet address screening layer or a periodic ownership-refresh cycle. SDN designations are updated without advance notice; a counterparty that was clean at onboarding can become listed while the relationship is live. A second common error is treating the OFAC 50 percent rule as exhaustive when OFSI and EU ownership-and-control tests may capture entities that OFAC's mechanical threshold does not – and vice versa.
How does OFAC differ from other regimes here?
OFAC differs from OFSI and the EU in three main ways for VASPs. First, OFAC publishes blockchain wallet addresses directly on the SDN List; OFSI and EU designations are primarily entity-based. Second, OFAC's ownership test is purely mechanical at the 50 percent threshold; OFSI and the EU also apply a control test. Third, OFAC's general licence architecture differs structurally from OFSI's named licensing categories and from EU general authorisations. A firm operating across all three regimes needs tailored analysis for each, not a single unified process.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.