A Canadian acquirer signs a letter of intent for a target with operations spanning three continents. Pre-closing screening surfaces a minority shareholder with links to a listed entity. The deal timeline is three weeks. Is the target caught under the Special Economic Measures Act ("SEMA") – the principal instrument for Canadian autonomous sanctions? Can the acquisition proceed at all? And what does the cross-border picture look like when the same transaction also triggers OFAC or EU review?
Sanctions due diligence in M&A under Canada requires a structured review of the target's ownership chain, counterparty relationships, and business flows against the lists and prohibitions administered by Global Affairs Canada ("GAC"), the federal department responsible for implementing and enforcing SEMA and the related regulations. As of January 2026, Canada's autonomous sanctions regime is expanding: new designations under SEMA have accompanied successive multilateral policy developments, and the scope of prohibited dealings has widened. Getting the diligence right before closing is not optional – a post-closing breach can expose both the acquirer and the acquired entity to civil and criminal liability under the applicable Canadian regime.
This guide walks through the diligence process step by step, from initial scope-setting to the confirmatory review at closing, with a cross-regime comparison at each stage to show where Canada's approach diverges from OFAC, OFSI, and the EU.
Step 1: Understand the legal basis and who administers it
Canada's autonomous sanctions regime rests principally on SEMA, which empowers the Governor in Council to enact regulations imposing asset freezes, dealings prohibitions, and related restrictions against designated persons and entities. The regime is administered by GAC, which maintains the list of designated persons and publishes the country-specific regulations that set out the particular prohibitions in force for each programme.
Two further instruments are relevant to M&A diligence. The United Nations Act implements Security Council resolutions as a matter of Canadian law, creating obligations that sit alongside SEMA. The Export and Import Permits Act regulates the movement of controlled goods and technology across Canada's borders, which matters when the target manufactures, exports, or re-exports dual-use items. In a cross-border deal, all three instruments may be simultaneously relevant.
GAC publishes a consolidated list of persons designated under SEMA regulations. Unlike the US SDN List (OFAC's list of Specially Designated Nationals and blocked persons), Canada's list is fragmented across country-specific regulations, and the prohibition language varies between programmes. Practitioners cannot rely on a single unified database; they must check the current text of each applicable country regulation, not merely a central list aggregator.
The cross-border dimension is immediate. Many transactions subject to Canadian review will also require an OFAC analysis for US-nexus elements and an EU Council regulation review where EU-incorporated entities or EU-sourced goods are involved. Where all three regimes apply, the stricter prohibition governs each element of the transaction. That multi-layered exposure is the starting point for scope-setting, not an afterthought.
Step 2: Define the scope of the diligence review
Scope-setting is the stage where most M&A diligence programmes fail before they start. A useful scope definition identifies four dimensions: the entities to be screened, the prohibitions potentially engaged, the data sources available, and the tolerances the acquirer's board and lenders will accept.
Entities to screen include the target, its subsidiaries, its direct and indirect shareholders above a materiality threshold (see Step 3 on the ownership test), its key officers and directors, and its significant counterparties – major customers, suppliers, intermediaries, and joint-venture partners. In a complex corporate group, this list can run into the hundreds. Prioritisation by revenue weight, jurisdictional risk, and ownership proximity to the target is essential.
The prohibition categories under SEMA typically extend to: dealing in property of a designated person; facilitating a transaction related to such property; providing financial services to or for the benefit of a designated person; and making goods available to a designated person. In an M&A context, the acquisition of shares in a company owned or controlled by a designated person is itself a "dealing." That is a point some deal teams miss when they focus only on the target's operations and ignore the upstream ownership chain.
What is the acquirer's nexus with Canada? Even a transaction with no Canadian-incorporated party may engage SEMA if the deal involves a person in Canada, uses a Canadian financial institution, or is routed through Canadian correspondent banking infrastructure. Conversely, a transaction with no Canadian nexus at all may still require OFAC clearance if USD settlement is involved, or EU regulation review if an EU entity is party. Scope the Canadian diligence in conjunction with those parallel analyses from day one.
Step 3: Apply the ownership and control test
Canada's SEMA regulations extend prohibitions to entities that are owned or controlled by a designated person, not merely to the designated person themselves. This is the ownership-and-control extension, and it is where diligence most frequently underestimates exposure.
The Canadian regime does not apply a single mechanical percentage threshold in the same way that OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) operates. Under SEMA, the prohibition on dealings extends to entities owned or controlled by a designated person as a matter of the regulation's drafting in each country programme. Control can be established by ownership of a majority of shares, by the ability to appoint a majority of the board, or by the ability to direct the conduct of the entity. The analysis is therefore both a percentage exercise and a qualitative control assessment.
This diverges materially from the OFAC 50 percent rule. Under OFAC, the test is purely arithmetic: aggregate the blocked persons' ownership stakes; if they reach 50 percent or more, the entity is treated as blocked regardless of actual control. Under SEMA, a designated person holding 49 percent with effective veto rights over key decisions may still bring the entity within the prohibition. The OFSI and EU position is closer to SEMA in its control-sensitivity, though the precise tests differ between those regimes as well.
In practice, this means the diligence must do two things. First, map the ownership chain of the target and every material subsidiary, going upstream to the ultimate beneficial owner and checking each layer against the GAC list and any applicable UN list. Second, review the constitutional documents – shareholders' agreements, articles, voting agreements, any side arrangements – to identify control rights that may not be visible from the share register alone. In our experience, this second step is routinely omitted in time-pressured deals and is the single most common source of post-closing sanctions surprises.
A cross-border deal may require simultaneous application of the OFAC 50 percent rule, the EU ownership-and-control test under the relevant Council regulation, and the SEMA control extension. The results can diverge. An entity that is not caught under OFAC's arithmetic threshold may still be prohibited under SEMA's control extension. Sound diligence documents each regime's analysis separately.
Step 4: Screen counterparties and business flows
Ownership analysis establishes whether the target entity itself is caught. Counterparty screening establishes whether the target's ongoing business relationships create derivative exposure – transactions with or for the benefit of designated persons that would themselves be prohibited dealings under SEMA, or that generate secondary-sanctions risk under OFAC.
The screening programme at this stage should cover the target's top customers and suppliers by revenue, its financial institution relationships, its logistics and intermediary network, and any government or state-linked counterparties. State-linked entities in jurisdictions subject to comprehensive SEMA programmes warrant heightened scrutiny: the line between a private company and a state entity is not always clear in every jurisdiction, and GAC's programme may extend to state-owned enterprises without separately listing each one by name.
Business flows matter separately from counterparty identity. Where the target's products or technology reach end-users in a jurisdiction subject to SEMA prohibitions, there may be a facilitation risk even if the immediate buyer is not itself designated. This is the point of intersection between sanctions diligence and export-control diligence under the Export and Import Permits Act. The two are conceptually distinct but in a manufacturing or technology business they must be reviewed in parallel.
A practical note on data quality: M&A counterparty data is rarely complete in the target's records. Customer and supplier information held in ERP systems frequently contains errors, outdated addresses, and missing ultimate-beneficial-owner data. The diligence programme should account for data remediation as a step in its own right, not assume the data is reliable from the outset. In our practice, we regularly advise acquirers to use the due diligence period to require the target to produce current KYC-grade data on its major counterparties, which the acquirer's team then screens independently.
Step 5: Assess secondary-sanctions and cross-border risk
A business running sanctions due diligence in M&A under Canada cannot assess exposure in isolation. Canadian companies and their affiliates frequently have US-dollar-denominated obligations, US-incorporated subsidiaries, or US-person employees. Each of those connections creates a parallel OFAC exposure that is independent of and additional to the SEMA analysis.
OFAC's secondary-sanctions programmes – measures that restrict access to the US financial system for non-US persons who deal with certain designated persons or in certain jurisdictions – are a live risk for any cross-border acquirer. A Canadian parent acquiring a target with revenue from a jurisdiction subject to OFAC's secondary-sanctions architecture may find that the post-closing entity cannot maintain USD correspondent banking access or cannot deal with US-person suppliers. That is a commercial risk as much as a legal one, and it must be quantified for the deal team before closing.
The EU picture adds a further layer. If the target has EU-incorporated subsidiaries or EU-person shareholders, the relevant EU Council regulation applies to those entities' dealings. EU regulations on asset freezes and prohibition of funds and economic resources have direct effect and do not require transposition into member state law. A post-closing integration plan that assumes the Canadian parent can direct an EU subsidiary to continue a previously compliant relationship may need revision if that relationship has been caught by a subsequent EU designation.
For deals with a UK dimension, OFSI licensing and the ownership-and-control analysis under the relevant UK thematic regulations must also be run. OFSI's approach to the ownership and control test is qualitative – consistent with the SEMA approach and distinct from OFAC's arithmetic threshold. Where the same counterparty appears on both the GAC list and the UK Consolidated List, both sets of prohibitions apply independently.
The cardinal rule across all regimes: where two or more sanctions regimes apply to the same transaction or relationship, the stricter prohibition governs. Clearance under one regime does not excuse a breach of another.
Related practices
- Correspondent banking and de-risking under OFAC – managing financial-institution access and USD correspondent risk in cross-border deals.
- M&A sanctions diligence: cross-border guide – multi-regime framework for acquisitions spanning OFAC, OFSI, EU, and other regimes.
- Sanctions due diligence in M&A under the EU – EU Council regulation analysis, ownership and control under EU rules, and the General Court route.
Step 6: Document, red-flag, and report to the deal team
Diligence findings are only useful if they reach the decision-makers in time to affect the deal. The output of a Canadian sanctions diligence review should be structured as a risk report, not a list of screening alerts.
A well-structured report distinguishes three categories. First, clear findings: entities or relationships that are, on the available evidence, prohibited dealings under SEMA or under a parallel regime, requiring either a licensing step, a restructuring of the deal, or a no-go recommendation. Second, amber findings: relationships or ownership structures that create an elevated risk requiring further information or confirmatory analysis before the acquirer can take a reasoned position. Third, residual risk: areas where the diligence has been completed to a reasonable standard but where, given data limitations, a residual unquantified exposure remains – and where the acquirer should consider representations and warranties, indemnities, or hold-back arrangements in the SPA.
The report should also set out the remediation steps available for each amber and red finding. Can a SEMA-caught relationship be terminated before closing without triggering other liabilities? Is a GAC licence available to permit the deal to proceed? Is a restructuring of the target's ownership chain feasible? These are questions for counsel, not for the deal team to determine unassisted. The position above covers the standard case. Your facts – the counterparty, the goods, the route, the regimes in play – change the analysis materially.
If a transaction has already been flagged by a financial institution, or a filing has been refused or queried, an early review by specialist counsel can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment of your position.
Step 7: Closing confirmations and post-closing integration
Diligence conducted at the outset of a deal can go stale. Sanctions designations happen rapidly – GAC has issued new designations under SEMA at short notice in response to evolving international developments – and a counterparty that was clean at the signing date may be designated before closing. A confirmatory screening run, conducted against the current GAC list and the applicable UN Consolidated List, in the week immediately before closing is not optional. It is standard practice and, in our experience, occasionally identifies material changes that the opening review could not have anticipated.
Post-closing, the acquirer becomes responsible for the target's compliance programme. For targets that have operated in jurisdictions subject to SEMA programmes, or that have significant counterparty exposure in higher-risk markets, a post-closing programme review should be treated as a day-one integration deliverable. That review should assess the target's screening tools, their logic and update cadence, the ownership-and-control mapping of the target's own counterparties, and the target's procedures for reporting apparent violations to GAC.
Representations and warranties in the SPA do not substitute for diligence. They are a contractual remedy after the event; they do not prevent the breach, and they do not prevent regulatory action by GAC against the post-closing entity. The indemnity structure should reflect the residual risk identified in the diligence report, but it is a second-order protection, not a substitute for getting the pre-closing analysis right.
A brief illustrative example: in a recent matter, a financial services business was acquiring a mid-market payments processor with correspondent banking relationships across several higher-risk jurisdictions. We mapped the payments processor's ownership chain, identified a minority shareholder connected to a person on the GAC list, confirmed that the control test under the applicable SEMA country programme was engaged, and assessed the parallel OFAC and OFSI position. The acquirer restructured the deal to effect a pre-closing transfer of the relevant shareholding. The matter proceeded to closing with clear confirmatory screening on the revised structure.
Common risk flags in Canadian sanctions diligence for M&A
Several patterns appear repeatedly in sanctions diligence reviews under Canada. Recognising them early reduces the cost of remediation and the risk of a last-minute deal failure.
- Fragmented list architecture. Canada's SEMA list is maintained as a series of country-specific schedules, not a single unified list. Screening tools calibrated to the US SDN or EU consolidated list formats may not capture all current Canadian designations. Verify that the screening database in use is updated to the current GAC country-regulation schedules.
- Nominee and trust structures. The control extension under SEMA means that nominee shareholders holding shares on behalf of a designated person, or trust arrangements where a designated person is the beneficial owner, can bring the target within the prohibition. Constitutional-document review and beneficial-ownership searches are essential, not elective.
- State-linked entities in programme jurisdictions. A target that supplies goods or services to a government agency in a jurisdiction subject to a comprehensive SEMA programme may have a direct prohibition issue, even where the government agency is not individually named on the GAC list. The applicable SEMA regulation's prohibition language must be read carefully.
- Pre-existing licences. A target may be operating under an existing GAC authorisation permitting otherwise-prohibited dealings. That authorisation is typically non-transferable and lapses on a change of control. Acquirers must identify any such authorisation and confirm whether a fresh application will be needed post-closing.
- USD-settlement exposure. Even a transaction with no US-person parties may engage OFAC's jurisdiction through USD settlement. This is the secondary-sanctions mechanism that most frequently catches non-US acquirers by surprise.
The myth that Canadian sanctions diligence is lighter than OFAC or EU review
A persistent misconception among deal teams is that Canadian sanctions diligence is a lighter exercise than its OFAC or EU equivalent – that GAC enforcement is less active, that the lists are shorter, and that the practical risk of a breach is lower. This is not an accurate picture.
GAC's enforcement capacity has developed significantly. SEMA confers the power to impose civil and criminal penalties. The criminal penalty provision under SEMA for wilful breaches carries substantial exposure. GAC has signalled, and in successive enforcement cycles demonstrated, an intention to use those powers. Compliance counsel should not advise a deal team that Canadian sanctions risk is manageable because Canada has historically been less publicly active in enforcement than OFAC: that position does not reflect the current enforcement posture, and the regulatory environment is changing.
Additionally, the interaction between SEMA and the UN Act means that UN Security Council-mandated measures apply in Canada as a matter of law, independently of GAC's autonomous designation decisions. A target with exposure to UN-listed persons must be assessed against both the UN Consolidated List and the GAC schedules. These are not duplicative; the coverage differs.
We regularly advise acquirers who have conducted an OFAC and EU review and then treat the Canadian leg as a mechanical list check. That approach understates the risk. The control extension, the fragmented list structure, and the interaction with the UN Act together create a diligence requirement that is qualitatively comparable in rigour to the OFAC and EU analyses, even if the volume of designations in some programmes is smaller.