A virtual-asset business onboards a corporate client, processes a series of transactions, and only later discovers that a beneficial owner appears on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The property has moved. Reporting obligations have been missed. The window for a voluntary self-disclosure (a VSD – a proactive report to OFAC of an apparent violation) is open, but it narrows with every passing day. This pattern is not hypothetical. As of mid-2026, OFAC has made clear that virtual-asset service providers are fully within its enforcement perimeter, subject to the same obligations that govern banks and payment firms.
Crypto and VASP sanctions compliance under OFAC requires any business that transmits, exchanges, or custodies virtual assets and has a US nexus to screen customers, beneficial owners, and transactions against OFAC's lists; block or reject prohibited transactions; and report blocked property. The legal basis is IEEPA and the relevant programme regulations. Non-compliance can attract significant civil penalties, and OFAC has demonstrated a clear willingness to bring enforcement actions against virtual-asset businesses.
This guide walks through the obligations step by step, maps the points where OFAC's approach diverges from the UK and EU regimes, and flags the operational gaps that most frequently lead to enforcement exposure. Each section pairs the primary OFAC rule with at least one comparator regime so that businesses operating across borders understand the full picture.
Step 1: Establish whether OFAC jurisdiction applies to your VASP
OFAC jurisdiction attaches to any person or entity with a US nexus – and that nexus is broader than many virtual-asset businesses assume. A non-US VASP can be caught if it processes transactions that touch the US financial system, uses a US-domiciled server or cloud provider, has US-resident employees, or accepts US-person customers. The jurisdictional reach of IEEPA is extraterritorial in this respect.
In our cross-border practice, we regularly advise overseas crypto businesses that have assumed OFAC does not apply to them because they hold no US licence and serve no US customers directly. That assumption is often wrong. A payment route through a US correspondent bank, a smart-contract deployment on a protocol with US-based validators, or a token issuance marketed to US persons can each create the nexus that pulls the business into OFAC's perimeter.
The threshold question is therefore not "are we a US company?" but "does any part of our business touch a US person, US institution, or the US financial system?" If the answer is yes in any material way, the full OFAC compliance obligation applies. Document that jurisdictional analysis. Regulators expect to see it.
Related practices
- Sanctions compliance audit and testing – programme stress-testing and gap analysis across major regimes
- Crypto and VASP sanctions compliance under OFSI – how the UK regime applies to virtual-asset businesses
Step 2: Build a screening programme that covers the full ownership chain
OFAC's 50 percent rule (the rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked, even if the entity is not separately listed) applies in full to the virtual-asset context. A VASP that screens only the named account holder and ignores beneficial ownership is operating a materially deficient programme.
For crypto businesses, the operational challenge is acute. Wallet addresses do not carry corporate registrations. Counterparty identity may be asserted rather than verified. Layering through decentralised protocols can obscure ownership. OFAC's guidance acknowledges these technical constraints, but it does not relax the underlying obligation: if a business cannot verify that a counterparty is not a blocked person or owned by one, it must assess the risk and, in many cases, decline the transaction.
A properly designed screening programme for a VASP covers the following elements:
- Name screening of customers, beneficial owners, and authorised signatories against OFAC's SDN List and all relevant programme lists.
- Wallet-address screening using blockchain analytics tools against known addresses associated with designated persons or entities.
- Screening of the beneficial-ownership chain, not only the immediate account holder, to catch 50 percent ownership thresholds.
- Transaction monitoring for behavioural patterns indicative of sanctions exposure – geography, counterparty clustering, and rapid layering.
- Periodic rescreening of the existing customer base whenever OFAC updates a relevant list.
Have you tested your screening logic against a case where the sanctioned person is two ownership layers removed from the wallet holder? That is the scenario that enforcement actions turn on.
The position above covers the standard case. Your facts – the counterparty, the blockchain protocol, the ownership structure, the jurisdiction – change the analysis. For a review of your screening programme, contact Calder & Vance at info@caldervance.com.
Step 3: Block, freeze, and report – the correct sequence when a hit occurs
When screening produces a match that, after investigation, is confirmed as a blocked person or an entity caught by the 50 percent rule, the VASP must block the property, record it, and report it to OFAC within a short statutory window. The reporting obligation runs from the point of blocking; it is not deferred to a convenient filing date.
In practice, the sequence is: suspend the transaction or freeze the account; document the basis for the decision with contemporaneous records; file the required report with OFAC; and, where the circumstances involve a past transaction that was not blocked, seek legal advice on VSD. Firms that reverse a block or release funds before completing this sequence create the conditions for a wilful violation finding.
Record-keeping matters enormously here. OFAC's guidance requires that records relating to blocked property and to rejected transactions be maintained for a defined period. We advise clients to retain all relevant documentation – screening outputs, ownership analysis, internal communications, and the blocking or rejection decision – in a format that can be produced quickly in response to a regulatory enquiry.
A common procedural failure we see in our practice is the firm that blocks correctly but files its report late because the compliance team is unsure which reporting window applies or which OFAC programme is engaged. That procedural delay, even where the underlying block was timely, becomes a separate basis for enforcement attention.
What is the cross-border picture – and how does OFAC differ from OFSI and the EU?
OFAC's ownership test is mechanical: the 50 percent threshold triggers the block regardless of whether the blocked person exercises operational control. Under OFSI (the UK's Office of Financial Sanctions Implementation) and the EU's ownership-and-control test, control is an additional, independent ground for capture. A non-US VASP operating between the US, UK, and EU must satisfy all three regimes simultaneously, and the strictest prohibition governs the transaction where they diverge.
Three practical divergences matter most for VASPs:
- Ownership threshold: OFAC uses a strict 50 percent aggregate-ownership rule. OFSI and the EU also apply a 50 percent threshold but add a control limb that can catch sub-50 percent holdings where a designated person exercises operational dominance. In our experience, transactions that clear the OFAC test sometimes still require a OFSI or EU analysis on the control question.
- Reporting windows: OFAC's reporting obligation runs on a fixed timeline from the blocking event. OFSI requires reporting of known or suspected sanctions breaches and of any assets frozen under UK designations. The EU regime imposes similar notification requirements under the relevant Council regulation. The deadlines are not identical; a cross-border VASP must calendar each one separately.
- Licensing: An OFAC specific licence (a case-by-case authorisation for an otherwise prohibited transaction) does not authorise the same transaction under OFSI or the EU. Each regime has its own licensing authority. A VASP that obtains one licence but proceeds across all three jurisdictions without the others is unlicensed in the uncovered regimes.
For a detailed comparison of the OFSI regime for virtual-asset businesses, see our guide at crypto and VASP sanctions compliance under OFSI and the companion analysis at crypto and VASP sanctions compliance under OFSI (part two).
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.
Step 4: Address the risk flags specific to virtual-asset businesses
Virtual-asset businesses carry a set of sanctions-risk indicators that do not map directly onto the traditional financial-institution model. OFAC and other regulators have published guidance identifying these, and in our cross-border practice we see them surface regularly in compliance reviews and enforcement contexts.
The highest-risk operational patterns include:
- Anonymity-enhancing services: Mixers, tumblers, and privacy-coin transactions are treated by OFAC as high-risk on their face. OFAC has designated several mixing services, meaning any VASP that processes transactions routed through them may be interacting with blocked property. The designation of a mixing service does not excuse a VASP that failed to screen for it.
- Peer-to-peer platforms without KYC: Platforms that permit transactions between unverified parties without any know-your-customer process have been a focus of OFAC attention. The absence of identity information is a risk, not a defence.
- High-risk geographies: Transactions originating from or destined for jurisdictions subject to comprehensive OFAC programmes require enhanced scrutiny. IP-address geo-blocking alone is not sufficient; it is a risk-reduction tool, not a compliance programme.
- Rapid layering patterns: Rapid conversion of large holdings between different virtual assets or rapid movement across multiple wallet addresses is a standard typology for sanctions evasion. Transaction-monitoring rules should be calibrated to flag it.
- Nested accounts and correspondent VASP relationships: A VASP that provides services to other VASPs (nested accounts) inherits the sanctions risk of the underlying VASP's customer base. Due diligence on correspondent VASPs must reach the ultimate beneficial owners of their customers, not only the correspondent entity itself.
Is your transaction-monitoring ruleset calibrated to virtual-asset typologies, or has it been carried over unchanged from a fiat-payments model? The two risk profiles differ materially.
Step 5: Build the five-element compliance programme that OFAC expects
OFAC's published guidance sets out five elements that it expects to see in a sanctions compliance programme: management commitment, risk assessment, internal controls, testing and auditing, and training. For VASPs, each element requires adaptation to the virtual-asset context.
Management commitment means that the board and senior leadership have formally adopted a sanctions compliance policy, designated a compliance function with adequate resources, and are briefed on material sanctions risk at regular intervals. OFAC looks for evidence of this in enforcement cases; its absence is an aggravating factor.
The risk assessment for a VASP must address the specific products and services the business offers, the customer segments it serves, the geographies it touches, and the delivery channels it uses – including smart-contract-based services where the VASP may have limited visibility into end-user identity. A generic financial-crime risk assessment does not satisfy this requirement.
Internal controls cover the screening tools, the blocking and reporting procedures, the escalation path when a compliance officer identifies a potential match, and the controls around nested-account relationships. These must be documented and version-controlled. If the controls change because a screening vendor updates its methodology, that change must be recorded.
Testing and auditing is the element most frequently underweighted by smaller VASPs. OFAC expects periodic independent testing of the screening logic, the transaction-monitoring rules, and the overall programme effectiveness. In our practice, we regularly advise clients whose internal testing has been limited to confirming that the screening tool is running, rather than verifying that it would catch the scenarios that matter.
Training must be tailored to role. A customer-onboarding team needs to know how to escalate a name-screening hit. A product team designing a new DeFi service needs to understand how OFAC's rules apply to permissionless protocols. One-size-fits-all annual training rarely satisfies either requirement.
A common myth: OFAC does not pursue crypto businesses below a certain size
A widely held assumption in the virtual-asset industry is that OFAC focuses its enforcement resources on large centralised exchanges and that smaller VASPs, peer-to-peer platforms, and DeFi protocols sit below its enforcement threshold. This is incorrect, and acting on it is a material compliance risk.
OFAC's public enforcement record includes actions against small operators. Its guidance makes clear that the size of a business is one mitigating factor in penalty calculation, not a threshold below which the obligations do not apply. A small VASP that processes a transaction involving blocked property has committed an apparent violation regardless of its balance sheet. The penalty may be smaller; the violation is the same.
The practical implication is that every VASP with a US nexus, however small, must operate a programme that is proportionate to its risk profile but present in all five elements. A one-person peer-to-peer exchange cannot implement the same controls as a major centralised exchange, but it can screen wallet addresses, maintain records, and know how to block and report. The absence of any programme is what OFAC treats as aggravating.
Step 6: Voluntary self-disclosure and enforcement defence
When a VASP identifies an apparent violation – a transaction that should have been blocked but was not, a report that was filed late, or a screening gap that allowed a prohibited relationship to persist – the question of VSD arises. A VSD (voluntary self-disclosure to OFAC of an apparent violation) is a mitigating factor in OFAC's penalty framework. It is not a guarantee of a reduced penalty, and it is not available in every situation.
The decision to file a VSD requires careful legal analysis. Filing prematurely, before the scope of the apparent violation is understood, can extend the disclosure to matters that a more precise review would have bounded differently. Filing late, after OFAC has become aware of the violation through other means, does not attract the same mitigation. In our cross-border practice, we advise on both the scoping of apparent violations and the timing and content of VSD filings.
Where a VASP receives an OFAC subpoena, a request for information, or a notice of an investigation, the immediate priority is to preserve all relevant records, engage counsel, and avoid any further dealings with the subject of the enquiry. Responses to OFAC must be accurate; incomplete or misleading responses can convert a civil matter into a criminal referral.
For a confidential review of a potential breach or an apparent violation, contact Calder & Vance at info@caldervance.com.