A virtual-asset service provider processes hundreds of thousands of transactions a day. Its automated screening passes a wallet address that, on manual review, resolves to a counterparty owned by a person on OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The transfer has already settled. The compliance team now faces a potential apparent violation, a reporting question, and the possibility of a civil penalty – all before breakfast.
As of July 2026, OFAC treats virtual-asset transactions with the same legal force as dollar transfers: a VASP (virtual-asset service provider) that processes a transaction involving blocked property, or that deals with a person on the SDN List, commits a potential sanctions violation regardless of whether it knew the counterparty was designated. The governing authority is IEEPA and the relevant programme regulations, applied through OFAC's published guidance on virtual currencies. Strict liability applies: intent is irrelevant to the violation, though it is central to penalty calculation.
This guide sets out the six steps a VASP or crypto business needs to work through to manage OFAC exposure, from initial programme design to breach response. It also maps where OFSI and the EU diverge from OFAC – because most operators serving international customers face more than one regime at once.
Step 1: Understand what OFAC's rules require of a virtual-asset business
OFAC's jurisdiction reaches any US person, any transaction that touches the US financial system, and any business – wherever incorporated – that deals in US-dollar-settled assets or operates through US infrastructure. For a VASP, the practical reach is broad: a non-US exchange that uses a US correspondent, settles in USDC, or has US-resident customers is within scope.
The core prohibition is straightforward. No US person, and no person within OFAC's reach, may deal in property in which a blocked person has an interest – directly or indirectly. In the virtual-asset context, "property" includes cryptocurrency wallets, token holdings, and smart-contract balances. A transfer of value involving any of these constitutes "dealing in" blocked property if a designated person sits at either end of the chain.
OFAC has made clear that de-risking (a financial institution exiting a relationship to avoid sanctions exposure) is not a required response to every compliance question, but it is sometimes the only safe answer where the ownership chain cannot be verified. The tension between financial-inclusion objectives and sanctions compliance sits at the heart of every VASP risk programme.
What does strict liability mean in practice? It means that a VASP that processes a transaction with a blocked address violates OFAC rules even if its compliance team acted in good faith. Good faith and a strong compliance programme are, however, the two most powerful mitigants at the penalty-calculation stage.
Step 2: Map your exposure – the ownership and control question in a crypto context
The 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) applies to virtual-asset businesses as fully as to any other counterparty. An exchange, a protocol operator, or a custodian that is 50 percent or more owned by a designated person is itself blocked, even if it does not appear on the SDN List.
Mapping this in a crypto context raises particular challenges. Token-based governance means that "ownership" can be distributed across pseudonymous wallet holders. A blocked person may hold governance tokens at a level that triggers the rule without appearing in any company registry. In our experience, the firms that miss this are those that screen legal-entity ownership chains but ignore token distribution.
The aggregation point matters here just as it does in conventional corporate structures. Two listed persons each holding 28 percent of the governance tokens of the same protocol reach the 50 percent threshold together, even if neither does alone. Has your programme mapped token holdings as well as equity?
The cross-border dimension adds another layer. Under OFSI and the EU test, the question is ownership and control (the UK and EU test for whether a non-listed entity is caught through a listed person). Control – the ability to direct decisions, even without a majority equity stake – can capture entities that the OFAC 50 percent rule would not. A VASP with UK or EU nexus must run both tests. Where the two tests produce different results, the stricter prohibition governs.
Step 3: Design a screening programme that reaches wallet-level risk
Entity-level screening – checking the names of customers and counterparties against the SDN List – is necessary but not sufficient for a VASP. OFAC's guidance makes clear that virtual-currency businesses should screen blockchain addresses as well as legal-entity names. An SDN-listed person can hold assets at an address that has never been formally linked to their legal name in any registry.
Effective wallet screening uses blockchain analytics tools to identify addresses that OFAC has specifically identified as blocked (OFAC publishes wallet addresses alongside designations) and to trace transaction histories that connect a target address to a known blocked address. Neither step is trivial. The first requires a direct feed from OFAC's published data; the second requires a tool calibrated to your risk tolerance for indirect connections.
The position above covers the standard case. Your facts – the asset class, the chain architecture, the customer profile, and the regimes in play – change the analysis significantly.
For an initial review of your screening architecture and its gaps, contact Calder & Vance at info@caldervance.com.
Three design questions drive the programme:
- At what points in the transaction lifecycle does screening run – pre-transaction, at settlement, or both?
- What is the threshold for a "hit" – exact match, fuzzy match, or blockchain-proximity score?
- Who in the compliance team has authority to release, block, or escalate a flagged transaction, and within what timeframe?
The answers to these questions must be documented in a written policy. OFAC treats the absence of a documented programme as an aggravating factor at the penalty stage.
Step 4: Handle a potential apparent violation – what to do in the first 72 hours
A VSD (voluntary self-disclosure to a regulator) to OFAC is a significant mitigant: OFAC treats a timely VSD as a factor that can reduce the base penalty substantially. The decision whether to self-disclose is legal in nature and should be taken with sanctions counsel, not by the compliance team alone.
The first 72 hours after identifying a potential violation are operationally critical. The steps, in order, are:
- Freeze the flagged transaction or wallet interaction pending review. Do not release funds or continue processing.
- Preserve all records – transaction logs, screening-tool outputs, communications, and any internal escalation trail. Record-keeping obligations under OFAC require retention for a period that, as currently in force, practitioners treat as five years from the date of the transaction; verify the current requirement before relying on it.
- Conduct a rapid internal scope review: how many transactions are affected, over what period, and does the issue appear systemic or isolated?
- Assess the VSD question with qualified sanctions counsel. The window for a VSD to carry maximum mitigating weight is short.
- If the situation involves blocked property that must be reported, consider the reporting obligation in parallel with the VSD question – these are separate obligations.
If a transaction has already been flagged, or a filing has been refused, an early review preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss a confidential review of the position.
How does OFAC's crypto regime differ from OFSI and the EU?
The three major Western regimes – OFAC, OFSI, and the EU – all apply their sanctions rules to virtual assets, but they diverge in ways that matter operationally for a firm serving international customers.
OFAC's reach is broadest in extraterritorial terms. Secondary-sanctions risk – the risk that a non-US firm dealing with a US-designated person in a transaction that has no US nexus still faces OFAC consequences – is a live issue for any VASP with US-dollar exposure or US-resident investors. OFAC has shown willingness to act against non-US entities in the virtual-asset space.
OFSI's regime under the Sanctions and Anti-Money Laundering Act ("SAMLA") applies to UK persons and UK-nexus transactions. The ownership and control test under OFSI is broader than OFAC's 50 percent rule: a person can be caught through control without holding a majority interest. OFSI has an active licensing function and a mandatory reporting obligation: a person who knows or suspects that a person is a designated person, or has committed an offence, must report. The reporting window under OFSI is short and, as currently in force, practitioners note it runs from the date of knowledge; verify the precise period before relying on it.
EU sanctions under the relevant Council regulations apply to EU persons and EU-nexus transactions. The EU ownership-and-control test is similar to OFSI's in its breadth. One practical divergence from OFAC: the EU has, through the EU Blocking Regulation, taken the position that EU persons should not comply with certain US secondary-sanctions measures. For a VASP operating in both the US and EU markets, this creates a genuine conflict-of-laws risk that requires careful legal structuring, not a choice between regimes.
In our cross-border practice, the firms that manage this well are those that run a single consolidated risk taxonomy – mapping OFAC, OFSI, and EU obligations side by side – rather than treating each regime as a separate programme.
Common risk flags in crypto and VASP sanctions compliance
Most OFAC enforcement actions in the virtual-asset sector trace to a small number of recurring failures. Understanding them is the starting point for a useful risk review.
Reliance on name-only screening. Screening the customer's legal name but not their wallet address is the single most common gap. OFAC publishes wallet addresses as part of designations; a VASP that does not ingest those addresses into its screening logic is exposed regardless of how good its name-matching is.
Inadequate aggregation analysis. As described above, two listed persons can jointly reach the 50 percent threshold without either triggering a single-entity screen. Programmes that do not aggregate ownership across related designated persons will miss this.
Geolocation gaps. OFAC maintains country-based restrictions under certain programme regulations. A VASP that serves customers in a jurisdiction subject to a comprehensive programme – and relies on a customer's self-declared location rather than independent geolocation checks – is exposed to the transactions those customers route through the platform.
Inadequate travel-rule compliance. The Financial Action Task Force travel rule requires originator and beneficiary information to travel with a virtual-asset transfer above the applicable threshold. Gaps in travel-rule data are also gaps in sanctions screening data. We regularly advise clients that these two obligations are inseparable in practice.
No documented escalation path. A compliance alert that a screener cannot resolve does not stop the clock. If there is no documented escalation path to a person with authority to block a transaction, the alert stalls and the transaction proceeds. That is an operational sanctions breach, not a compliance system working as intended.
When does a crypto business need to involve sanctions counsel?
Not every screening alert requires external lawyers. But there are situations where a call to sanctions counsel on day one is the right step – and where waiting makes the position materially worse.
Involve counsel immediately when:
- A transaction has processed and you have identified a potential OFAC violation. The VSD window is time-sensitive.
- A customer or counterparty has been designated after a transaction commenced. The position on how to handle in-flight obligations is not intuitive.
- You are building or redesigning a compliance programme ahead of a product launch in a new market – particularly one with secondary-sanctions risk.
- A regulator (OFAC, OFSI, a national financial supervisor) has contacted you with an enquiry related to a customer or transaction.
- You are conducting M&A diligence on a target VASP and need to scope its sanctions exposure before closing.
The myth that some businesses hold is that sanctions rules do not really apply to decentralised protocols or to firms that "do not touch fiat". OFAC's position is the opposite: it has assessed that virtual-asset businesses are "financial institutions" for sanctions purposes and has pursued enforcement in the sector. The absence of fiat in a transaction does not remove OFAC jurisdiction where a US person or US infrastructure is involved.
We have acted for VASPs at each of these stages – from programme design to enforcement response. Our practice covers OFAC, OFSI, and EU obligations under one roof, which matters when a client's counterparty sits in a jurisdiction that triggers more than one regime.
Related practices
- Sanctions compliance audit and testing – structured testing of screening logic, escalation paths, and programme design across multiple regimes.
- Crypto and VASP sanctions compliance: deeper dive – extended analysis of wallet-level screening, travel-rule interaction, and cross-border licensing.