Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFSI

Entity List and denied-party screening under OFSI: a practical guide

A UK-based technology distributor prepares to fulfil an export order. The buyer has cleared initial due diligence. Then a compliance officer notices that one of the buyer's group companies appears on a denied-party register. Does the export proceed? Is a licence required? Is the UK importer also caught? These questions do not resolve themselves – and the window to answer them correctly is short.

Entity List and denied-party screening under OFSI is the process by which businesses identify whether a counterparty, owner, or intermediate entity is designated under UK financial sanctions or subject to export-control restrictions before a transaction proceeds. As of May 2026, the primary UK lists include the OFSI Consolidated List of designated persons, the UK Strategic Export Controls Licensing system administered by the ECJU, and, for dual-use goods, the relevant country-control and end-user undertaking requirements under the UK's own export-control rules. The screening obligation bites on the transaction, the parties, and the ownership chain – not merely the named buyer.

This guide sets out how to run that screening process correctly, where the OFSI regime diverges from its US and EU counterparts, what the common failure points are, and when to involve specialist counsel.

Step 1: Understand which lists apply and who administers them

The first step is mapping the applicable lists – because OFSI and the export-control regime administered by the ECJU operate on different legal bases and catch different persons and items, and a business that screens only for one set of restrictions may miss the other entirely.

OFSI – the Office of Financial Sanctions Implementation – administers UK financial sanctions. Its Consolidated List designates individuals and entities subject to asset freezes and dealing prohibitions under the Sanctions and Anti-Money Laundering Act (SAMLA) and the regulations made under it. The list is publicly available and updated without a fixed timetable; a designated person can be added at any time, including on the same day a transaction is scheduled to close.

The ECJU – the Export Control Joint Unit – administers UK strategic and dual-use export licensing. It does not maintain a single "entity list" in the US sense. Instead, the ECJU works through the Open General Licences, the Consolidated Criteria, and country schedules that determine whether a specific item destined for a specific end-user in a specific country requires an individual export licence. A denied-party check under the ECJU regime requires assessing the end-user's identity and intended end-use, not merely cross-referencing a named list.

Internationally, the US Entity List (the BIS register of parties subject to licence requirements under the Export Administration Regulations) is a separate instrument entirely. It does not bind UK exporters as a matter of UK law. But a UK exporter dealing in US-origin goods, or goods containing US technology above de minimis thresholds, may still face EAR obligations in parallel. In our experience, exporters routinely underestimate this extraterritorial reach. We regularly advise clients who discovered mid-transaction that a buyer's group entity appeared on the BIS Entity List, triggering US re-export controls even for a shipment from the UK.

The EU maintains its own lists under the relevant Council Regulations. Post-Brexit, OFSI's Consolidated List and the EU's consolidated list are no longer identical; divergences have grown, and a UK business dealing with EU counterparties or routing goods through EU member states must screen against both.

Step 2: Map the ownership and control chain before screening

Screening the named counterparty is necessary but rarely sufficient. Under OFSI's ownership and control rules – derived from SAMLA and the relevant thematic regulations – a non-designated entity can still be caught if it is owned or controlled by a designated person, and the financial-sanctions prohibition extends to dealing with that entity.

Ownership and control (the UK test for whether a non-listed entity is caught through a listed person) under OFSI follows a dual test: direct or indirect ownership of more than 50 percent of the shares or voting rights, or the practical ability to direct or control the entity's activities. The control limb is broader than the ownership threshold alone and has no precise numerical trigger. This is a point of divergence from OFAC's approach, where the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) is mechanical and does not separately extend to control short of that ownership level.

What does this mean in practice? A buyer in which a designated person holds 40 percent of the shares may still be caught under the OFSI control test if that person can, in fact, direct the buyer's commercial decisions – for instance through board appointment rights or consent provisions in a shareholders' agreement. We have acted for exporters who had screened ownership correctly but had not reviewed the governance documents; the control analysis had been missed entirely.

To map the chain correctly, a business should:

  • Obtain the current beneficial ownership register or equivalent disclosure for the counterparty and each intermediate holding company;
  • Identify any designated persons in the ownership chain, regardless of the percentage held;
  • Apply the ownership test and, separately, the control test to each layer;
  • Document the conclusions and the sources reviewed, including the date of the search.

The EU's ownership and control standard is broadly comparable to OFSI's, though the precise articulation in the relevant Council Regulation differs, and EU General Court case law has refined the analysis in ways that are not always mirrored in OFSI guidance. Cross-border businesses should not assume that an OFSI-clean analysis automatically satisfies the EU regime, or vice versa.

Step 3: Run the denied-party check against the correct registers

Once the ownership chain is mapped, the denied-party check itself involves screening each identified person and entity against the applicable registers in a documented, reproducible way.

For OFSI purposes, the minimum registers to check are:

  • The OFSI Consolidated List (the primary UK financial-sanctions list);
  • The UN Security Council Consolidated List, which the UK incorporates by reference under SAMLA;
  • Any regime-specific schedules under the relevant thematic regulations that apply to the transaction.

For export-control purposes under the ECJU regime, the check is different in character. Rather than simply cross-referencing a list, the exporter must assess the end-user and end-use against the Consolidated Criteria, the relevant country schedules, and any applicable Open General Licence conditions. A business relying on an Open General Licence must confirm that the end-user falls within the scope of that licence and that no conditions exclude the proposed transaction.

Should a business also check the BIS Entity List? For goods that are solely UK-origin and contain no US-controlled technology, the BIS Entity List does not, as a matter of law, impose obligations. In practice, however, many financial institutions and freight forwarders apply it as a matter of internal policy. If a transaction involves US-origin components or software above the relevant de minimis threshold, the EAR applies in parallel, and the BIS check becomes legally mandatory. For advice on classifying goods and assessing US re-export obligations, our deemed-export and BIS EAR advisory service sets out the relevant analysis.

What is the standard of care for a compliant screen? OFSI's enforcement guidance indicates that a screen conducted in good faith, at the time of the transaction, against the then-current lists, and documented adequately, is material to its assessment of any apparent breach. A screen that was adequate yesterday is not adequate today if the list has been updated overnight. That point – the need for real-time or near-real-time screening at the point of transaction – is one that static, periodic checks systematically miss.

How does the OFSI regime differ from OFAC and EU screening obligations?

OFSI, OFAC, and the EU regime share the broad objective of preventing designated persons from accessing economic resources. Their mechanics diverge in ways that matter for a business running a single cross-border compliance programme.

First, the penalty basis. OFSI can impose civil monetary penalties for financial-sanctions breaches without requiring proof of knowledge or intent – it operates on a strict-liability basis for civil penalties, subject to a "reasonable excuse" defence. OFAC also operates strict liability for civil penalties, calculated by reference to a penalty matrix that includes the apparent severity of the violation, whether a VSD (voluntary self-disclosure to a regulator) was made, and the transaction value. The EU regime enforces through member-state authorities, so the standard varies by jurisdiction.

Second, the ownership and control test. As noted, OFSI's control limb captures situations that OFAC's mechanical 50 percent rule does not. A business that has concluded a counterparty is not blocked under OFAC must not assume the same conclusion holds for OFSI without separately applying the control test.

Third, licensing. OFSI issues specific licences (case-by-case authorisations) and operates a set of General Licences covering defined transaction categories. OFAC issues both specific and general licences, often regime-specific. The EU regime operates through member-state competent authorities for specific licences, and through regime-level derogations (rather than general licences in the OFAC sense) for defined permitted transactions. The procedural requirements, timelines, and the strength of the "reasonable reliance" argument for a general licence differ across regimes.

Fourth, reporting. OFSI requires that a person who knows or has reasonable cause to suspect that they hold frozen assets or have information relevant to the designation of a sanctioned person must report to OFSI as soon as practicable. OFAC imposes its own reporting obligations, including on blocked transactions. The triggers and the addressees are different; a compliance programme designed for OFAC reporting alone will not satisfy OFSI.

Finally, enforcement posture. In our cross-border practice, we observe that OFSI has become progressively more active in investigating and publicising apparent breaches. Businesses that have dealt confidently with OFAC for many years sometimes underestimate the pace of change in OFSI's enforcement approach. The position that "we have always done it this way for OFAC" is not a defence before OFSI.

Related practices

The position above covers the standard case. Your facts – the specific goods, the counterparty's jurisdiction, the ownership structure, the route of export, and the regimes in play – change the analysis significantly. For a confidential assessment of your screening process and exposure under the OFSI regime, contact Calder & Vance at info@caldervance.com.

Step 4: Record, escalate, and decide

A denied-party screening process is only as strong as the decisions it produces and the records it leaves. Many businesses screen correctly but fail at the escalation and documentation stage – and it is at that stage that enforcement authorities form their view of whether the business had adequate procedures in place.

When a screen returns a potential match – a name that is similar to, but not clearly identical to, a designated person – the business must make a matching assessment. The factors relevant to that assessment include: the degree of similarity in name, date of birth, nationality, and address; the nature of the transaction and the goods involved; the plausibility of the match given the commercial context; and whether the potential match is a common name in the relevant region.

A potential match that cannot be ruled out on these factors should be escalated to a compliance officer or to external counsel before the transaction proceeds. The business should document the assessment, the information reviewed, the conclusion reached, and the time at which each step was taken.

Where a transaction is blocked or a match is confirmed, the business must:

  1. Freeze the funds or economic resources in question (if it has them in its possession, custody, or control) or decline to transfer them;
  2. Report to OFSI as soon as practicable – the reporting obligation under the relevant regulations does not specify a fixed number of days but attaches promptly on knowledge or reasonable suspicion;
  3. Preserve all records relating to the transaction and the screening process;
  4. Take legal advice before making any further dealing in the matter.

If a transaction has already been flagged, or a filing has been refused, the time available to manage the position narrows quickly. An early review can preserve options – including the possibility of a VSD – that are harder to access once an investigation has opened. We regularly advise businesses at exactly this stage, including on the preparation of voluntary disclosures and the assessment of whether a specific licence application is viable.

Contact Calder & Vance at info@caldervance.com for a confidential review of a potential breach or a blocked transaction.

Common risk flags in OFSI entity screening

Several patterns recur across the businesses we advise, and recognising them early materially reduces enforcement risk.

Relying on a single data source. No single commercial screening tool covers every list, every alias, and every transliteration of a designated person's name. A business that relies entirely on one automated provider and treats a "no match" result as a clean screen has misunderstood the standard. The tool narrows the field; it does not substitute for the ownership and control analysis or for cross-referencing the primary lists directly.

Name variations and transliterations present a related problem. A designated person whose name appears in a non-Latin script may appear under multiple transliterations in different lists and databases. A screen that catches one transliteration may miss another. The risk is highest for names transliterated from Arabic, Russian, Persian, or Chinese scripts.

Treating screening as a one-off event. The OFSI list changes without warning. A counterparty that was clean at contract signature may be designated before the transaction closes or during an ongoing commercial relationship. The OFSI regime does not grandfather pre-existing relationships; a designation triggers the prohibition from the moment it takes effect, regardless of when the underlying contract was signed. Businesses with long-term supply or financing arrangements need to screen at each payment, drawdown, or delivery event – not only at onboarding.

Failing to screen intermediaries and facilitators. The financial-sanctions prohibition covers providing financial services to a designated person, not only direct dealings. A payment routed through a correspondent bank, a freight forwarder arranging onward carriage, or a professional services firm providing advice in connection with the transaction can each constitute a "dealing" if the designated person is a beneficiary. Screening must extend to the parties in the transaction chain who touch the funds or goods, not only to the named buyer and seller.

A common myth in this area is that OFSI screening is relevant only to financial institutions. In fact, the financial-sanctions prohibitions under SAMLA apply to all persons in the United Kingdom (and, in some cases, to UK persons operating abroad), regardless of sector. A manufacturer, a logistics company, a software provider, or a professional services firm can all be caught. The obligation to screen is not a banking-sector obligation alone. We regularly advise non-financial businesses that have discovered this only when a transaction has already been blocked – and the cost of discovery at that stage is always higher than the cost of building screening into the process from the start.

For a deeper examination of screening methodology for multi-regime structures, including the SECO regime in Switzerland, see our entity list screening guide for the SECO regime.

When to involve sanctions counsel and what to expect

Specialist counsel adds clearest value at three points: before a transaction, when a potential match arises, and when an apparent breach has occurred.

Before a transaction, counsel can review the ownership chain analysis, assess whether the goods or technology require an export licence under the ECJU or EAR, and advise on whether any OFSI general licence applies. The cost of that pre-transaction review is typically modest relative to the cost of a blocked transaction or an enforcement inquiry.

When a potential match arises, counsel can conduct or supervise the matching assessment, advise on whether a freeze obligation has been triggered, and prepare any required reporting to OFSI. The analysis is fact-specific and time-sensitive; it is not a process well suited to internal-only resolution when the match is plausible.

When an apparent breach has occurred, counsel can scope the violation, assess the options for a voluntary self-disclosure, and prepare the disclosure or the penalty defence. In our experience, OFSI's published enforcement guidance indicates that cooperation, the quality of a business's compliance programme, and the promptness of a VSD are all taken into account in the enforcement assessment. These factors are not abstract; they are the levers available to a business in that position.

What a sanctions lawyer cannot do – and what no competent practitioner will do – is advise on how to structure a transaction to defeat the screening process, disguise beneficial ownership, or route goods through intermediary jurisdictions to avoid a prohibition. This firm does not advise on circumventing or evading sanctions. The function of proper entity screening is to detect those patterns and stop them, not to replicate them.

Related practices

Frequently asked questions

What are the steps to screen against the Entity List under OFSI?
The steps are: first, map the full ownership and control chain for each counterparty; second, screen each identified person and entity against the OFSI Consolidated List, the UN Security Council Consolidated List, and any applicable thematic regime schedules; third, make and document a matching assessment for any potential match; fourth, escalate confirmed or unresolved matches to compliance counsel before the transaction proceeds; and fifth, retain all records of the search, the data sources used, and the conclusions reached. Screening must be repeated at each material transaction event, not only at onboarding.
What is the most common mistake in Entity List and denied-party screening?
The most common mistake is treating a "no match" result from a single automated screening tool as a complete and sufficient check. Commercial tools do not cover every alias, transliteration, or indirect ownership path. A business must cross-reference the primary lists directly, apply the OFSI ownership and control test to the counterparty's ownership chain, and screen intermediaries in the transaction – not only the named buyer or seller. Relying on a single source leaves gaps that enforcement authorities will identify.
How does OFSI differ from other regimes here?
OFSI's control test is broader than OFAC's mechanical 50 percent ownership threshold: a non-designated entity can be caught where a designated person has practical control, even below 50 percent ownership. OFSI also imposes a prompt reporting obligation on knowledge or reasonable suspicion of a designated person's involvement, without a fixed-day deadline. Its civil penalty regime operates on a strict-liability basis, subject to a "reasonable excuse" defence. These features make OFSI structurally different from both OFAC and the EU regime, and a screening programme designed for one will not automatically satisfy the others.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.