A virtual-asset service provider operating from the United Kingdom processes a conversion request. The wallet address appears clean. The beneficial owner, three layers up, sits on the OFSI Consolidated List (the UK Treasury's list of designated persons subject to financial sanctions). The transaction settles before anyone notices. That sequence – rapid execution, slow identification – is the defining compliance risk for crypto businesses under the UK's financial-sanctions regime.
As of July 2026, OFSI (the Office of Financial Sanctions Implementation, the UK authority responsible for financial-sanctions enforcement and licensing) applies the same legal prohibitions to virtual-asset service providers as it does to banks and payment firms. A VASP (virtual-asset service provider, a business that exchanges, transfers, or custodies cryptoassets on behalf of others) must screen counterparties, freeze assets belonging to designated persons, and report to OFSI within a short statutory window. Failure to comply carries significant civil and, in the most serious cases, criminal consequences.
This guide works through the obligations step by step, compares the OFSI position with OFAC and the EU, highlights the points where crypto adds complexity, and identifies when specialist counsel is needed.
Step 1 – Understand the legal basis and who is caught
Every VASP with a UK connection – whether registered with the FCA for anti-money-laundering purposes, providing services to UK persons, or processing sterling – falls within the reach of the UK's financial-sanctions regime, which rests on the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic sanctions regulations made under it. The regime applies to conduct by UK persons and to conduct within the United Kingdom, regardless of where the VASP is incorporated.
The prohibitions are broad. No person subject to UK jurisdiction may deal with funds or economic resources owned, held, or controlled by a designated person. A cryptoasset wallet, a staking position, a liquidity-pool share – all qualify as funds or economic resources under the relevant thematic regulations. The question of whether a particular digital asset is caught is not answered by whether it is "decentralised": what matters is whether a designated person can direct its movement or benefit from its value.
Does your business serve retail customers in the UK, or route settlement through UK payment rails? If so, OFSI's reach extends to you even if your entity is incorporated offshore. We regularly advise overseas VASPs that first discover this when a UK-domiciled customer triggers a screening alert.
Step 2 – Map the ownership-and-control test to your counterparty data
The ownership and control test (the UK and EU test for whether a non-listed entity is caught because a listed person owns or controls it) is where most crypto-specific compliance failures originate. Under OFSI, an asset is frozen if it is owned or controlled by a designated person, even if that person does not appear directly on the transaction record. The test does not impose a fixed percentage threshold in the same mechanical way as OFAC's rule.
OFAC's 50 percent rule (the rule that treats any entity owned 50 percent or more in the aggregate by blocked persons as itself blocked) is a hard numerical trigger. OFSI's test is broader: control can arise through ownership below fifty percent, through board representation, through contractual rights, or through any other arrangement that gives a designated person effective authority over an asset. In our experience, businesses that calibrate their screening logic solely to the OFAC ownership threshold underestimate OFSI exposure when the same counterparty is reviewed.
For a VASP, this creates a layered challenge. Wallet addresses do not carry ownership metadata. Beneficial ownership must be inferred from customer due-diligence data, transaction patterns, and third-party attribution tools. A customer who appears unconnected to a designated person at onboarding may become connected through a subsequent acquisition or restructuring. Screening is therefore not a one-time gate; it is a continuous obligation.
The position above covers the standard case. Your facts – the asset type, the customer structure, the jurisdiction of the entity providing the liquidity – change the analysis materially. To assess your OFSI exposure, contact Calder & Vance at info@caldervance.com.
Step 3 – Build and operate the screening programme
An effective VASP screening programme for OFSI compliance operates at three layers: list screening, ownership-chain screening, and behavioural monitoring. Each layer addresses a different vector by which a designated person can interact with the business.
List screening matches customer identifiers – names, wallet addresses where attribution is known, national-identification numbers, and entity names – against the OFSI Consolidated List and the UN Consolidated List (the Security Council's master list of designated persons subject to UN sanctions measures). Automated tools are necessary at volume, but they generate false positives that require human review. A hit must be investigated before a transaction is executed; it cannot be resolved retrospectively without OFSI engagement.
Ownership-chain screening maps the beneficial owner behind each customer entity. For corporate customers, this means tracing to the ultimate beneficial owner and testing each intermediate layer against the designated-persons lists. For wallet-address counterparties, it means using on-chain analytics to identify known attribution, cluster associations, and mixer or tumbler involvement. A tool that returns "no match" on a pseudonymous address but has not traced the address to a known entity is not completing an ownership-chain analysis; it is completing a pattern-match only.
Behavioural monitoring identifies post-onboarding changes. Customers who transact in patterns consistent with layering, who receive funds from wallets attributed to sanctioned entities, or whose ownership changes following onboarding can all trigger a re-screening obligation. The programme should specify the events that require a customer file to be reopened.
Step 4 – Freeze assets and report correctly
When a VASP identifies a match – a customer, a counterparty, or an asset linked to a designated person – two obligations arise simultaneously: the freeze obligation and the reporting obligation. Both are immediate in the sense that they are not subject to a grace period for commercial convenience.
The freeze obligation requires the VASP to ensure that the relevant asset cannot be moved, exchanged, or otherwise accessed by or for the benefit of the designated person. For a custodial VASP holding assets in an omnibus wallet, this requires the ability to segregate and lock specific customer allocations at short notice. For a non-custodial interface that does not hold private keys, the practical analysis is more complex and requires legal assessment of whether the interface has sufficient control over the asset to trigger the obligation.
The reporting obligation under OFSI applies within a short statutory window from the point at which the VASP has information or reasonable cause to suspect that a person is a designated person or has committed a financial-sanctions offence. This is not a post-investigation deadline; it runs from the moment of suspicion, not from the conclusion of an internal inquiry. Firms that investigate fully before reporting – and thereby miss the reporting window – face a separate regulatory risk from the underlying match. We have acted for financial-services businesses caught in exactly this position.
If a transaction has already settled before the match was identified, an early review can preserve options that narrow with time. Voluntary disclosure to OFSI at that stage is a factor that OFSI takes into account in its enforcement response. Contact us at info@caldervance.com to discuss a confidential assessment.
Step 5 – Apply for a licence where a freeze would cause hardship
OFSI can grant a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) to permit dealings with a designated person's assets where a licensing ground applies. Relevant grounds in the crypto context include transactions for basic needs, legal fees, and – in some thematic regimes – prior contractual obligations.
A licence application requires the VASP to identify the precise prohibition engaged, the specific assets involved, the licensing ground, and the supporting evidence. OFSI does not grant licences speculatively. An application that does not identify the legal basis with precision will not succeed, and a prolonged back-and-forth with the regulator during which assets remain frozen can impose serious commercial and reputational costs on innocent counterparties.
The processing time for a specific licence application varies by thematic regime and by the complexity of the case. OFSI's published guidance indicates target timescales, but in practice more complex applications take longer. The timeline should be factored into any contingency plan drawn up at the freeze stage. For a VASP, the governance implication is significant: a frozen customer account generates ongoing customer-service obligations and potential legal exposure to the customer if the freeze was applied incorrectly.
How does OFSI's approach compare with OFAC and the EU?
The three major Western sanctions regimes – OFSI, OFAC, and the EU Council-regulation regime – apply broadly similar prohibitions to virtual assets, but they diverge in three technically important ways that affect how a cross-border VASP should structure its compliance programme.
On the ownership-and-control test, OFAC's rule is numerical and mechanical: 50 percent or more aggregate ownership by blocked persons triggers automatic blocking of the owned entity. OFSI and the EU apply a qualitative control test that extends to ownership below fifty percent where the designated person exercises effective authority. A VASP that operates under both OFAC and OFSI authority – for example, because it serves US persons and holds a UK registration – must apply both tests, and where the results diverge, the stricter prohibition governs.
On reporting, OFAC requires that blocked property be reported within a short period of the blocking event, with a follow-up annual report while the blocking remains in place. OFSI's reporting obligation triggers on suspicion rather than on a formal blocking event. The EU position under the relevant Council regulations requires member-state competent authorities to be notified of frozen assets, with timescales that vary by member state. A VASP operating across these jurisdictions needs a reporting calendar that respects all three windows simultaneously.
On licensing, the grounds available under OFSI, OFAC, and the EU differ by thematic regime and do not map neatly onto each other. A licence granted by OFSI does not authorise the transaction under OFAC or under the relevant EU regulation. Each regime requires its own application, and the evidential standard differs. Cross-border VASPs that assume a US general licence covers their UK exposure, or vice versa, create a significant unaddressed gap in their authorisation.
Singapore's MAS and the UAE's relevant supervisory authorities have also issued guidance on digital-asset sanctions compliance. Those regimes are distinct from OFSI and require separate analysis for VASPs with a presence in those jurisdictions.
Common risk flags and when to involve sanctions counsel
Crypto-specific sanctions risk concentrates in a small number of recurring patterns. Identifying them early is the primary purpose of a monitoring programme; acting correctly when they appear is where counsel adds the most value.
The most common risk flags in our cross-border practice are: wallet addresses with prior attribution to sanctioned entities or their close associates; customers whose beneficial ownership cannot be verified to the required standard; high-volume transfers that fragment into many smaller transactions across jurisdictions without a clear commercial rationale; and customers who, during onboarding, produce documentation from jurisdictions subject to comprehensive sanctions programmes without being able to account for their assets' origin.
A common myth is that the VASP's obligation ends at the point of onboarding due diligence – that if the customer passed KYC at the time of registration, the business is protected from sanctions liability. This is incorrect. OFSI's enforcement guidance is clear that sanctions compliance is an ongoing obligation. A customer who passed screening at onboarding and subsequently becomes a designated person (through a new designation that post-dates their registration) is still a designated person; the VASP's obligation to freeze and report arises from the moment of the new designation, not from a fresh onboarding cycle.
Counsel should be involved at the point at which an alert cannot be resolved by the firm's internal compliance function with confidence. That threshold is reached: when a match on an ownership-chain review is not a direct name-list hit but turns on a control analysis; when a transaction has already settled and the firm is considering whether to make a voluntary disclosure; when OFSI has made contact requesting information; when a licence application involves an unusual ground or contested facts; or when the firm's screening tool produces a result that the team cannot interpret with certainty. In each of those situations, the cost of acting without advice is disproportionate to the cost of a focused legal review.
Related practices
- Sanctions compliance audit and testing – stress-testing screening logic and programme design against live regime requirements
- Crypto VASP sanctions compliance: advanced topics – deeper analysis of ownership mapping, DeFi exposure, and cross-regime gaps
- VASP licensing and OFSI authorisations – guidance on applying for specific licences for frozen digital assets