Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFSI

Entity List and denied-party screening under OFSI: a compliance guide

A UK-headquartered trading company prepares to ship specialist components to a buyer it has dealt with for three years. The compliance officer runs the counterparty name through the firm's primary screening tool. Nothing flags. The shipment proceeds. Three months later, OFSI writes to ask why the company supplied a party that appears on a consolidated denied-party list under a thematic UK sanctions regime. The buyer had not changed. The list had.

Entity list and denied-party screening under OFSI requires a structured, multi-list approach that goes well beyond a single name-check. The UK Consolidated List (OFSI's published register of designated persons and entities subject to financial sanctions) is the primary reference point, but UK export-control obligations – administered by the Export Control Joint Unit (ECJU) – add a parallel layer of denied-party and end-user controls that a financial-sanctions screen alone will not catch. As of May 2026, the two regimes operate under distinct legal instruments, with different lists, different thresholds, and different consequences for a miss.

This guide walks through the full screening obligation in six steps: the governing authority and legal basis; the lists that must be checked; the ownership and control tests; how OFSI compares with OFAC and the EU on key points; the risk flags that most compliance programmes miss; and when to bring in specialist counsel.

Step 1 – Understand the governing authority and legal basis

OFSI, the Office of Financial Sanctions Implementation, sits within HM Treasury and administers UK financial-sanctions designations under the Sanctions and Anti-Money Laundering Act (SAMLA). SAMLA gives the UK government the power to impose sanctions independently of any UN Security Council mandate, and the thematic regulations made under it – covering financial restrictions, asset freezes, and prohibitions on making funds or economic resources available – are the binding legal instruments a UK-nexus business must observe.

ECJU, the Export Control Joint Unit within the Department for Business and Trade, administers the UK export-control regime separately. Its denied-party and end-user controls derive from the Export Control Order and the UK Strategic Export Licensing Rules. A single counterparty can be captured by both regimes simultaneously, which means a clean OFSI screen does not release a business from its ECJU obligations. In our experience, this two-track structure is the first thing many in-house teams underestimate.

The UN Security Council Consolidated List adds a third layer. UN designations feed into UK domestic law through SAMLA-based instruments, but the timing of that feed is not always simultaneous. Checking the UN list directly remains advisable for businesses operating on tight transaction timelines.

Step 2 – Identify every list you are obliged to screen against

Four lists are relevant to most UK-nexus businesses engaged in cross-border transactions, and each serves a different legal function.

  • The UK Consolidated List – all persons and entities designated under UK financial-sanctions regimes, maintained by OFSI and updated without notice. This is the primary financial-sanctions screen.
  • The UN Security Council Consolidated List – designations by the Security Council, including the ISIL/Al-Qaida list and lists under country-specific committees. UK domestic law incorporates these, but the UN list may move first.
  • The UK Strategic Export Control Lists – product-based controls administered by ECJU, which interact with end-user and end-use screening obligations. A counterparty flagged here triggers licensing requirements regardless of whether it appears on OFSI's list.
  • HM Revenue and Customs trade data and the UK Export Control Organisation's end-user-certificate register – supplementary due-diligence sources relevant for businesses in sectors with elevated diversion risk.

Businesses with a US nexus must also maintain awareness of the BIS Entity List (the US Commerce Department's list of parties subject to additional export-licence requirements under the Export Administration Regulations). The BIS Entity List is a US-law instrument; it carries no direct legal force in UK law. However, a UK exporter using US-origin technology or supplying goods with US-controlled content may face extraterritorial exposure under the EAR's re-export controls. We regularly advise UK clients who discover mid-transaction that their product contains US-controlled components, bringing BIS screening into scope alongside OFSI.

Step 3 – Apply the ownership and control test correctly

The ownership and control test determines whether a non-listed entity is nonetheless caught through its relationship with a designated person, and it is here that the UK and US regimes diverge most sharply.

Under OFAC's mechanical rule, the threshold is 50 percent or more aggregate ownership by blocked persons, directly or indirectly. Control is not part of the test. Ownership at or above that figure triggers the prohibition automatically, regardless of whether the designated person exercises any operational authority.

OFSI's test is broader and more fact-intensive. Under the relevant thematic regulations, a person is "owned or controlled" by a designated person if the designated person holds – directly or indirectly – more than 50 percent of the shares or voting rights, or if the designated person has the right to appoint or remove a majority of the board, or if the designated person can exercise dominant influence over the entity's affairs. That final limb – dominant influence – extends the prohibition well beyond the mechanical ownership count. A designated person holding a minority stake but possessing contractual veto rights, consent rights over material decisions, or structural influence over financing may bring the counterparty within scope even where ownership sits below the threshold.

The EU position under the relevant Council regulations mirrors OFSI's broader approach. Both require a genuine assessment of control, not merely a cap-table review. In our experience, UK businesses that rely on automated screening tools calibrated to the OFAC threshold will miss control-based exposure under OFSI and EU regimes.

For export-control purposes, ECJU applies an end-user and end-use focus that is analytically distinct from the ownership test. The question for ECJU purposes is not who owns the counterparty but what the goods or technology will be used for and whether there is a risk of diversion to a prohibited end-use or a third-party recipient subject to control.

The position above covers the standard analysis. Your facts – the counterparty's ownership structure, the goods, the intended destination, the route of shipment – can change the outcome substantially.

For an assessment of your exposure under OFSI and the ECJU export-control regime, contact Calder & Vance at info@caldervance.com.

Step 4 – Run the screening procedure: a decision sequence

Effective denied-party screening under OFSI follows a defined decision sequence, not a single database query. Each stage addresses a distinct question, and a clean result at one stage does not eliminate the need for the next.

  1. Name matching and fuzzy logic – Run the counterparty's legal name, all known trading names, and all transliterations against the UK Consolidated List and the UN list using a tool with configurable fuzzy-matching. A score-only result without human review of near-matches is insufficient. The OFSI list includes phonetic variants and aliases; a tool calibrated to exact-match only will produce false negatives.
  2. Ownership chain review – Map the counterparty's ownership structure to the ultimate beneficial owner level. Apply the OFSI ownership and control test at each layer. Flag any shareholder holding more than 25 percent for a targeted designated-person check, and apply the dominance-influence test to any party with structural rights over the counterparty's decisions.
  3. Product and technology classification – Identify whether the goods or services being supplied are on the UK Strategic Export Control Lists. If so, confirm whether a licence is required and whether the counterparty or end-user is subject to any ECJU denial or restriction. An item that is not caught by OFSI's financial-sanctions designation may still require an ECJU licence before export.
  4. Secondary-sanctions check – Assess whether the counterparty, its ultimate beneficial owner, or the destination jurisdiction gives rise to secondary-sanctions risk under the OFAC regime. A UK company is not automatically subject to US law, but a transaction involving US-dollar clearing, US-origin goods, or US-person involvement may bring OFAC's reach into the picture.
  5. Adverse-information and open-source review – Check corporate registries, public filings, and commercial intelligence sources for indicators of designation risk or diversion risk not yet reflected on a formal list. Lists are not updated in real time; a counterparty under designation review may not yet appear.
  6. Escalation decision – Where any step produces a hit, a near-match, or an unresolved ownership question, escalate to compliance counsel before proceeding. OFSI's enforcement posture rewards proactive identification and prompt reporting. Proceeding on an unresolved match without escalation is one of the most common aggravating factors in OFSI enforcement cases.

If a transaction has already been flagged, or an internal review has surfaced an apparent match, an early legal assessment can preserve options that narrow significantly with time. Contact Calder & Vance at info@caldervance.com to arrange a confidential review.

Step 5 – Understand where OFSI differs from OFAC and the EU, and why it matters

For a business managing obligations across multiple regimes, the points of divergence between OFSI, OFAC, and the EU are operationally significant. Treating them as interchangeable produces compliance gaps.

Licensing architecture. OFSI issues specific licences (case-by-case authorisations for otherwise prohibited transactions) and general licences (standing authorisations for defined categories of activity). OFAC's general-licence programme is more extensive; a transaction permissible under an OFAC general licence may require a separate OFSI specific-licence application for the UK-law dimension. Practitioners acting on complex cross-border transactions must verify the licensing position under each applicable regime independently.

Reporting obligations. OFSI imposes a mandatory reporting obligation on persons who know or have reasonable cause to suspect that a person is designated, or that a breach has occurred. The statutory window for that report is short, and the obligation sits on any person in the UK or a UK national overseas – not only on regulated firms. OFAC's voluntary self-disclosure regime is structurally different: it operates on a cost-benefit basis, and the decision to disclose is informed by an apparent-violation analysis rather than a statutory mandate. A business that applies its OFAC disclosure reasoning directly to an OFSI situation may find itself out of time and out of compliance.

Enforcement powers. OFSI has civil monetary penalty authority under SAMLA. Its published enforcement guidance describes a structured assessment of the severity of a breach and the presence of aggravating or mitigating factors. OFAC's penalty calculation follows a different methodology, with its own framework of base amounts, aggravating and mitigating factors, and a separate track for egregious cases. The EU position varies by member state, since sanctions enforcement in the EU remains a national-law matter notwithstanding the Council regulation that creates the underlying obligations.

The stricter prohibition governs. A cross-regime principle that applies regardless of which regime a business is primarily focused on: where two or more regimes apply to the same transaction, the most restrictive prohibition controls. A transaction cleared under OFSI but prohibited under the applicable EU regime – for instance, because a transaction route passes through an EU-person intermediary – is still a breach. Compliance programmes must be designed to identify the strictest applicable standard, not the most convenient one.

Step 6 – Identify the risk flags most screening programmes miss

In our cross-border practice, the compliance failures we see most frequently share a small number of structural features. These are not exotic edge cases; they arise in ordinary trading and financing relationships.

Alias and transliteration gaps. OFSI's list includes aliases, former names, and transliterated variants for designated persons and entities. A screening tool set to match only the primary legal name will miss aliases. This is a particularly common failure point for counterparties whose names appear in multiple scripts or where the counterparty uses a trading name distinct from its registered name.

Indirect ownership through multiple holding layers. Beneficial-ownership registers reflect what counterparties have declared; they do not always reflect what is true. A designated person may hold interests through nominee structures or through a chain of holding companies that individually appear clean. Ownership mapping must go to the ultimate beneficial owner level, with the OFSI dominance-influence test applied at each layer.

Stale screening. A screen run at onboarding is not a screen run at transaction. Designations occur without notice, and the UK Consolidated List is updated at any time. A counterparty that was clean at onboarding twelve months ago may carry a designation today. Periodic rescreening – aligned to transaction frequency and risk level – is not optional. It is the standard that OFSI's enforcement guidance presupposes.

Goods and technology misclassification. A product classified as EAR99 (outside the US Commerce Control List) still requires export-licence analysis under the UK Strategic Export Control Lists. The two lists are not identical. A business that relies on its US export classification to determine its UK obligations may be holding an invalid assumption.

Correspondent and intermediary exposure. A transaction that appears clean at the counterparty level may pass through a correspondent bank, payment processor, or logistics intermediary that is itself subject to sanctions restrictions. The obligation to screen applies to all parties involved in a transaction, not only the named buyer or seller.

Whether your screening programme is encountering any of these patterns is a question worth answering before OFSI does.

Related practices

A common myth: one clean screen is enough

The most persistent misconception we encounter is that a single pass through a primary screening database at the outset of a relationship satisfies the obligation. It does not.

OFSI's guidance and the underlying statutory obligations presuppose a continuous, multi-list, ownership-aware screening process. A screen that checks only the UK Consolidated List, runs only at onboarding, and does not extend to the ownership and control analysis is materially incomplete. It may also be insufficient to establish the reasonable-steps defence that OFSI's civil-penalty regime recognises. A business that can show structured, documented, periodic screening across all relevant lists is in a materially different position from one that cannot – and that difference is most visible when OFSI raises a query.

We have acted for businesses that arrived with a record of regular screening but an incomplete list set. In those matters, the documentation of the process – what was checked, when, and against which list – proved to be the most important asset in the OFSI dialogue. Compliance is not just a matter of having the right tool. It is a matter of being able to demonstrate that you used it correctly.

Frequently asked questions

What are the steps to screen against the Entity List under OFSI?
Effective OFSI screening follows six steps: name-match against the UK Consolidated List and the UN Consolidated List using fuzzy logic; ownership-chain mapping to apply the OFSI ownership-and-control test; product and technology classification against the UK Strategic Export Control Lists; secondary-sanctions assessment for OFAC exposure; open-source and adverse-information review; and escalation of any unresolved hit to compliance counsel before the transaction proceeds. A clean result at one step does not eliminate the obligation to complete the others.
What is the most common mistake in Entity List and denied-party screening?
The most common mistake is treating a single database check – run once, at onboarding, against one list – as a complete screen. In our experience, this produces three types of failure: alias and transliteration misses, ownership-chain gaps where a designated person holds an indirect interest below a superficial threshold, and stale data where the screen was clean at onboarding but a designation has occurred since. Periodic rescreening across all relevant lists, with documented ownership mapping, is the standard OFSI's enforcement guidance presupposes.
How does OFSI differ from other regimes here?
OFSI's ownership and control test is broader than OFAC's mechanical 50-percent rule: it extends to dominant influence, which captures designated-person control even where ownership sits below the threshold. OFSI's reporting obligation is a statutory duty, not a voluntary disclosure calculation. Its licensing architecture – specific licences and general licences – operates independently of OFAC's; a transaction covered by an OFAC general licence may still require a separate OFSI authorisation. Businesses managing both regimes must verify the position under each independently and apply the stricter prohibition where they diverge.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.