Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

How to manage crypto sanctions exposure under OFSI

A payments firm processes a digital-asset transfer. The counterparty wallet passes an automated screening check. Two days later, the compliance team realises the wallet's beneficial owner is an entity subject to UK financial sanctions. The firm has already settled the transaction. What now?

Managing crypto and VASP sanctions compliance under OFSI – the Office of Financial Sanctions Implementation, the UK authority responsible for financial-sanctions enforcement – requires a structured approach: identify obligations, map the ownership chain, maintain adequate screening, report promptly, and seek a specific licence where any doubt exists. As of July 2026, OFSI's enforcement posture toward virtual-asset service providers remains active, and the statutory reporting obligation applies regardless of whether the asset is fiat or digital.

This guide walks through the practical steps a VASP, payment firm, or digital-asset business should take to manage its exposure, where OFSI's approach diverges from OFAC and the EU, and when to involve specialist sanctions counsel.

Step 1 – Understand what OFSI requires of a VASP

Any person in the United Kingdom, or any UK-established entity operating abroad, that deals in a cryptoasset or facilitates a cryptoasset transfer must comply with the relevant thematic sanctions regulations made under the Sanctions and Anti-Money Laundering Act ("SAMLA"). The obligation is not limited to licensed exchanges. It catches custodian wallet providers, DeFi intermediaries with a UK nexus, and payment firms that route value through digital-asset rails.

The core prohibition is straightforward: a UK person must not make funds – or economic resources – available to a designated person, directly or indirectly. Cryptoassets are "funds or economic resources" under SAMLA-based regulations. That reading is not contested. A firm that processes a token transfer to a wallet beneficially owned by a designated person is, on its face, making funds available to that person.

Two points follow immediately. First, the prohibition applies whether or not the firm knows the underlying owner is designated – strict liability governs the prohibition itself, though knowledge and reasonable-cause tests bear on penalty assessment. Second, OFSI has no de minimis carve-out for small-value cryptoasset transfers. The value of the transaction does not determine whether a breach has occurred.

In our experience advising digital-asset businesses, the single most common starting error is treating the obligations as identical to those of a traditional bank. They are not – the technical architecture of cryptoassets creates ownership-chain and traceability challenges that require specialist solutions rather than a direct transplant of legacy compliance controls.

Step 2 – Map ownership and control through the crypto structure

The ownership and control test – the UK and EU rule that treats an entity as subject to sanctions obligations when a designated person owns or controls it – applies to cryptoasset holdings with the same logic as it does to corporate shares. A wallet or smart-contract position that is beneficially owned 50 percent or more by a designated person is itself subject to asset-freeze obligations.

Mapping that ownership chain in a cryptoasset context is technically harder than tracing corporate registers. Pseudonymous addresses do not declare their beneficial owners. Layered wallet structures, mixer interactions, and chain-hop patterns can obscure the link between a wallet and the person who controls it. But the legal obligation remains. OFSI does not reduce it because the technology makes compliance more demanding.

What does adequate mapping look like in practice? At minimum, a VASP should conduct on-chain analytics on counterparty wallets, cross-reference with commercial watchlist and sanctions-screening data, apply enhanced due diligence where the beneficial owner is not immediately identifiable, and document the steps taken. Where a chain of custody or beneficial ownership cannot be established to a reasonable standard, the safer course is to decline the transaction and record the reason.

The EU parallel is instructive. Under the relevant EU Council regulations, the ownership-and-control test applies to cryptoassets on the same basis. The divergence from OFSI lies in the list: EU designations and UK designations are no longer automatically synchronised following the UK's departure from the EU. A wallet that clears EU screening may not clear OFSI screening, and vice versa. A business with a UK regulatory footprint and EU clients must run both lists in parallel.

Step 3 – Build and maintain a screening programme

An effective screening programme for a VASP is not a single tool but a sequence of controls layered across the client lifecycle and the transaction lifecycle. Neither alone is sufficient.

At the client-lifecycle stage, the controls include: sanctions screening at onboarding against the UK Consolidated List and, where relevant, the OFAC SDN List and the EU Consolidated List; periodic re-screening at a frequency calibrated to the risk rating of the client; and trigger-based rescreening on any material change in the client's ownership or control structure.

At the transaction stage – where the specific challenge of cryptoasset screening sits – the controls must include wallet-address screening against known-malicious-address feeds published by OFAC and by commercial analytics providers, on-chain risk scoring of counterparty wallets, and a documented decision record for each transaction that presents an elevated risk indicator.

One question that arises consistently in our practice: at what point is a partial match a real match? OFSI does not publish a fuzzy-match threshold. Firms that set their own thresholds too low generate unmanageable alert volumes; those that set them too high risk missing real hits. The right answer depends on the specific risk profile of the client population and the asset type. A standardised 80 percent name-match threshold, lifted without adjustment from an AML policy, is not a considered sanctions decision.

OFAC's approach to cryptoassets is useful as a cross-regime reference point. BIS, in its guidance concerning digital assets and export-control obligations, and OFAC, in its published guidance on virtual currency, have both emphasised that the blockchain-analytics capability of a firm must be proportionate to its exposure. OFSI has not published equivalent quantitative standards, but the underlying principle – that capability must match risk – is consistent with OFSI's general enforcement approach under SAMLA.

The position above covers the standard compliance design. Your specific facts – the asset types you custody, the jurisdictions of your clients, the volume and speed of transactions, the counterparty types you face – change the calibration significantly.

For an assessment of your OFSI exposure or a gap analysis of your screening programme, contact Calder & Vance at info@caldervance.com.

Step 4 – Recognise and handle a potential breach

A potential breach arises the moment a firm has reasonable cause to suspect that it holds frozen funds or has dealt with a designated person. At that point, two distinct obligations crystallise: the obligation to report to OFSI, and the obligation not to compound the breach by further dealing.

The reporting obligation under SAMLA-based regulations requires the firm to inform OFSI as soon as practicable. The relevant thematic sanctions regulations set the statutory window; verify the current position before relying on any specific figure, as the rules differ by programme and the window is short. Failure to report is itself a criminal offence, separately from any liability for the underlying breach.

What should the report contain? OFSI expects: a description of the relevant funds or economic resources, the identity of the designated person where known, the value of the holding or transfer, and the steps the firm has taken or proposes to take. A well-prepared report is not a confession; it is also the firm's best opportunity to demonstrate the adequacy of its controls and the speed of its response.

Two practical points follow from experience acting for financial institutions in this position. First, freeze immediately and completely. Do not allow any further outbound transfer from the account or wallet pending the report and OFSI's instructions. Second, preserve all records – blockchain transaction data, internal communications, screening logs, client-identification documents – in a form that can be produced to OFSI without further processing. OFSI may request those records, and their integrity at the point of request matters.

A voluntary self-disclosure ("VSD") – an approach to OFSI before the regulator identifies the breach independently – is a recognised mitigating factor in OFSI's published enforcement guidance. A VSD does not guarantee a reduced penalty or no enforcement action, but OFSI's guidance confirms that a prompt, complete disclosure will be taken into account. The window for a disclosure that is still genuinely voluntary closes the moment OFSI opens its own enquiry.

If a transaction has already been flagged, a potential VSD window is open, or a filing has been refused, early counsel involvement can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com.

Step 5 – Apply for a specific licence where a transaction is blocked

A specific licence – a case-by-case authorisation issued by OFSI to permit an otherwise prohibited transaction – is available for a range of purposes, including legal fees, basic expenses, humanitarian payments, and certain pre-designation contractual obligations. The licensing regime applies to cryptoasset transactions on the same basis as fiat transactions.

The application process requires the firm to identify the designated person, describe the proposed transaction, specify the licensing ground under the relevant thematic sanctions regulations, and provide supporting evidence. OFSI considers applications on the specific facts; a generic application unsupported by evidence will not succeed. The processing timeline varies by the complexity of the matter and the licensing ground; OFSI does not publish a guaranteed turnaround, and in practice timelines can extend substantially for contested or complex cases.

One licensing issue specific to cryptoassets arises where the underlying asset has appreciated or depreciated significantly between the date of designation and the date of the licence application. The licence may permit a transaction at a specified value. If the asset value has moved, the firm must address how the permitted amount is calculated. That is not a question OFSI answers in its general guidance; it requires a submission specific to the transaction.

How does OFSI's licensing posture compare to OFAC's? OFAC issues both specific and general licences – standing authorisations that permit defined categories of transaction without a separate application. OFSI does not operate a general-licence system in the same way; its standing authorisations are built into the relevant regulations as general permissions, and any transaction outside those permissions requires a specific application. That distinction matters for businesses operating across the UK and US simultaneously: a transaction permitted under an OFAC general licence is not automatically permitted under OFSI, and a dual-regime analysis is required.

Step 6 – Address cross-regime exposure: OFSI, OFAC, and the EU

A VASP with a UK regulatory footprint rarely faces OFSI exposure alone. Most digital-asset businesses operate across multiple jurisdictions, use US-dollar settlement rails, hold assets on infrastructure that falls within US jurisdiction, or serve clients in EU-regulated markets. Each of those connections can independently trigger obligations under OFAC, EU Council regulations, or both.

The OFAC exposure for a non-US firm is real. OFAC asserts jurisdiction over any transaction that clears through the US financial system, over any US-dollar-denominated transfer regardless of clearing route, and over any entity that uses US-origin software or infrastructure in a manner that falls within OFAC's interpretation of "facilitation". For cryptoassets, the question of whether a blockchain transaction involves US-nexus infrastructure is not always straightforward. The analysis is fact-specific and, in our experience, cannot safely be conducted without reference to current OFAC guidance on virtual currency.

The EU dimension adds a third list and a third regulatory authority. The EU Consolidated List and the UK Consolidated List are no longer synchronised. EU sanctions regulations also contain no-circumvention provisions that prohibit deliberate structuring to avoid an obligation – a provision that OFSI similarly enforces under SAMLA. A business that removes a UK-regulated step from a transaction to avoid a UK screening requirement, while retaining an EU-regulated step, does not thereby escape the obligation; it potentially implicates both regimes.

Switzerland (SECO), Singapore, the UAE, and Japan each operate their own financial-sanctions programmes. Where a VASP has clients or infrastructure in those jurisdictions, the applicable country regime must be checked in addition to the UK, EU, and US positions. The principle that the stricter prohibition governs the transaction is a practical starting point: if any applicable regime would prohibit the transaction, the default should be to decline unless a licence is obtained from each relevant authority.

Related practices

Common risk flags and the myths that compound them

Six risk flags arise consistently in OFSI-focused cryptoasset reviews. Each is worth stating plainly.

  • Wallet-address-only screening: screening the destination address without tracing the beneficial owner of that address leaves the most significant exposure unchecked.
  • Stale rescreening cycles: a client screened at onboarding twelve months ago may have been designated since. Rescreening must be periodic and trigger-based, not onboarding-only.
  • Unverified source-of-funds data: a client's self-certification that their cryptoassets are not proceeds of a sanctioned transaction is not a control. It is a record of a representation.
  • Untested match-rate assumptions: many firms set fuzzy-match thresholds without testing recall against known designated-person names. The threshold should be calibrated, not assumed.
  • No clear escalation path: when a potential hit is identified at transaction processing speed, the decision logic must already exist. An undocumented escalation path produces inconsistent decisions.
  • Single-regime list checking: for a firm with any US or EU nexus, checking only the UK Consolidated List is insufficient. The obligation is to check each applicable list.

A persistent myth in this sector is that OFSI is less focused on cryptoasset businesses than on traditional financial institutions. That position is not supported by OFSI's published enforcement record or its published guidance on digital assets. OFSI has made clear that virtual-asset businesses carrying on activity in or from the United Kingdom are subject to the same financial-sanctions obligations as any other regulated firm. The technology is different; the obligation is not.

We regularly advise VASPs that have assumed their FCA registration is a proxy for sanctions compliance. It is not. FCA authorisation governs conduct and prudential matters; it does not confer any licence or authorisation under financial-sanctions law. The two regimes are parallel, not hierarchical.

When to involve specialist sanctions counsel

Specialist counsel should be engaged at any of five points in the lifecycle of a cryptoasset sanctions matter: at programme design; when a potential breach is identified; before submitting a VSD to OFSI; when preparing a specific-licence application; and when a business is expanding into a new jurisdiction where additional sanctions obligations may apply.

At programme design, counsel can map the applicable regime – OFSI, OFAC, EU, and any applicable country regime – against the firm's actual business model and identify the points of exposure that a generic compliance policy will miss. The cost of getting this right at design is a fraction of the cost of a breach investigation.

At the potential-breach stage, the legal privilege question is material. Internal investigation documents prepared under legal-professional privilege before a decision on disclosure are protected from production to OFSI in a way that documents prepared by compliance staff without counsel involvement are not. That protection is not automatic; it requires that counsel is instructed before the investigation begins, and that the investigation is conducted in the right form.

Our practice covers the full range of OFSI engagement: screening programme assessment, ownership-and-control analysis, VSD preparation, specific-licence applications, and enforcement-defence work. We also advise on the OFAC and EU dimensions that most UK-focused VASPs encounter. To discuss your matter, contact us at info@caldervance.com.

Frequently asked questions

What are the steps to manage crypto sanctions exposure under OFSI?
Managing cryptoasset sanctions exposure under OFSI requires six sequential steps: understand the statutory obligations under SAMLA-based regulations; map the beneficial ownership of counterparty wallets through any layered structure; build and maintain a multi-stage screening programme covering both client lifecycle and transaction level; identify and report any potential breach promptly to OFSI; apply for a specific licence where a blocked transaction is involved; and conduct a cross-regime analysis covering OFAC, EU, and any other applicable country regime where the business has a relevant nexus. Each step requires documented decisions capable of production to OFSI.
What is the most common mistake in crypto and VASP sanctions compliance?
The most common mistake is screening only wallet addresses without tracing the beneficial owner behind those addresses. A wallet-address screen identifies addresses linked to known sanctioned entities in commercial databases, but it will not catch a wallet whose beneficial owner is a designated person whose association with that address has not yet been identified in any database. Effective OFSI compliance requires on-chain analytics, enhanced due diligence for unverifiable beneficial owners, and documented decision records – not address screening alone.
How does OFSI differ from other regimes here?
OFSI operates a specific-licence system rather than the general-licence architecture used by OFAC, meaning that each blocked cryptoasset transaction requires a separate application. OFSI's designations list is no longer synchronised with the EU Consolidated List. OFSI's enforcement guidance on voluntary self-disclosure is a codified mitigating factor, similar in structure to OFAC's framework but applied under UK statutory authority. For a firm subject to both OFSI and OFAC, the applicable regime with the more restrictive position on a given transaction will govern the practical decision.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.