Calder & Vance International Sanctions & Compliance Counsel

Cross-Border Transactions & Diligence · UN

Sanctions due diligence in M&A under UN: a practical guide

An acquisition team signs a term sheet for a target operating in multiple markets. The sanctions screening that follows flags a supplier to the target that appears on the UN Consolidated List (the Security Council's master list of designated individuals and entities subject to Chapter VII measures). Does that supplier relationship taint the deal? Does the target itself carry sanctions exposure that the buyer will inherit? These are not hypothetical concerns. In cross-border M&A, they determine whether completion is lawful, whether financing is available, and whether post-closing liability attaches to the acquirer.

Sanctions due diligence in M&A under the UN regime requires a structured review of the target, its ownership chain, its key counterparties, and the jurisdictions it operates in, measured against the UN Consolidated List and the implementing national regulations that give that list binding force. As of January 2026, the UN Consolidated List is maintained by the Security Council's sanctions committees and runs alongside – and in some cases is superseded by – stricter national regimes operated by OFAC, OFSI, and the EU Council. No single screening pass satisfies all of them.

This guide walks practitioners through the seven-step process for conducting UN-anchored sanctions due diligence in an M&A transaction, from scope-setting before signing to post-closing monitoring, with cross-regime comparisons at each stage where the analysis diverges.

Step 1: Scope the diligence mandate before you open a data room

Effective sanctions due diligence in M&A begins before the data room opens, with a written scope document that identifies which regimes apply to the transaction and why. For a deal with a UN dimension, that means identifying which Security Council sanctions committees are relevant to the target's sector, geography, and counterparty profile – and then mapping which jurisdictions implement those measures and in what form.

The UN Security Council does not impose sanctions directly on private parties in the way that OFAC or OFSI do. Its resolutions require member states to implement measures, and it is those national implementing instruments that carry legal force for businesses. A buyer incorporated in the United Kingdom will be subject to the relevant thematic UK regulations that implement UN resolutions. A buyer operating through a US entity will face OFAC's implementing regulations under IEEPA. The EU implements UN measures through Council regulations. Each implementation may add scope: national regimes regularly designate additional persons not on the UN list, and the stricter prohibition governs in every case.

The scope document should record at minimum: the buyer's jurisdiction of incorporation and operational footprint; the target's jurisdiction of incorporation, subsidiaries, and operational footprint; the target's known counterparties by geography; and any sector-specific UN committee mandates that could apply (arms embargoes, commodity restrictions, or sectoral measures). In our experience, deals that skip this step treat UN diligence as a single database check rather than a multi-regime analysis – and that framing consistently produces incomplete results.

Step 2: Map the ownership and control chain of the target

The second step is a full ownership and control mapping of the target, its subsidiaries, and any material joint-venture partners, measured against the UN Consolidated List and each applicable national implementing list. Ownership thresholds vary by regime, and the difference is operationally significant.

Under OFAC's rules, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) operates mechanically on aggregate direct and indirect holdings. Two blocked persons each holding twenty-six percent of a target reach that threshold together. The EU and UK regimes apply an ownership and control test – asking not just whether a listed person owns a defined share but also whether they exercise control through other means, such as the power to appoint a majority of the board or to direct strategy. The UN Consolidated List itself does not contain an equivalent automatic-attribution rule; the effect of a listing on associated entities depends entirely on how the implementing jurisdiction translates the Security Council resolution.

For an M&A buyer, this means that a target subsidiary in a jurisdiction implementing UN measures narrowly may be outside scope where a subsidiary in a jurisdiction applying the OFAC 50 percent rule or the EU control test would be caught. Mapping must therefore record the implementing jurisdiction alongside each entity in the chain. A beneficial ownership registry search, corporate registry filings, and – where the target is in a jurisdiction with limited public disclosure – direct enquiry through the data room are the standard sources. Where the ownership chain passes through a jurisdiction with limited transparency, the gap itself is a risk flag.

Step 3: Screen the target, its people, and its material counterparties

Screening is the most visible part of sanctions due diligence in M&A, but it is also the most frequently misapplied. A single-pass name check against one list does not constitute adequate diligence in a cross-border transaction with UN and national-regime exposure.

The screening universe for a deal with UN dimensions should cover: the UN Consolidated List; OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and sectoral lists; OFSI's consolidated list of asset-freeze targets; the EU consolidated list; and any applicable national lists for the jurisdictions in which the target operates. Where the target has operations in or significant trade flows involving jurisdictions with their own autonomous regimes – Switzerland (SECO), Canada (GAC), Australia (DFAT), Singapore, Japan, or the UAE – those lists should also be checked.

The subjects to screen include: all directors and officers of the target and its material subsidiaries; all ultimate beneficial owners above the applicable ownership threshold; material suppliers and customers where those relationships are significant to the target's business model; financial institutions through which the target conducts significant treasury operations; and shipping and logistics counterparties in sectors with commodity-specific UN measures. What is "material" is a judgment call calibrated to deal size and the target's risk profile, but in our cross-border practice we advise setting the materiality threshold conservatively at the diligence stage because the acquirer's liability position after closing is harder to defend where a counterparty was visible in the data room and not screened.

Screening tools vary considerably in their coverage of the UN list and in their handling of transliteration variants. A tool that lists the UN Consolidated List as a source does not necessarily update in real time with Security Council committee amendments, nor does it automatically map the list to each national implementation. Verification of the tool's update frequency and methodology is part of the diligence process, not a background assumption.

How does the UN Consolidated List differ from OFAC and OFSI in an M&A context?

The UN Consolidated List differs from OFAC's SDN List and OFSI's consolidated list in three structural ways that directly affect how M&A buyers should weight a hit on each list. Understanding those differences is essential to calibrating the transaction risk and to structuring any remediation.

First, the UN list is treaty-based and requires implementation by member states. A listing by the Security Council creates an obligation on member states to act; it does not by itself create a private-law prohibition on a company in London or New York. The prohibition arises from the national implementing instrument. By contrast, OFAC's SDN designation and OFSI's asset freeze operate directly on persons and entities subject to those regulators' jurisdiction, without a further implementing step. In practice this means that the consequence of a UN list hit depends on which jurisdictions' implementing rules apply to the acquirer and its subsidiaries.

Second, the UN list is generally shorter and more narrowly scoped than OFAC's or the EU's lists, which include autonomous national designations beyond the UN base. A person or entity designated by OFAC under a thematic US programme may not appear on the UN list at all, yet that OFAC designation is fully binding on US persons and on non-US persons caught by secondary-sanctions risk. An M&A buyer that screens only the UN list and ignores OFAC's SDN List is operating with a significant gap.

Third, the delisting route differs. Removal from the UN Consolidated List for the ISIL and Al-Qaida committee goes through the Office of the Ombudsperson; for other committees it goes through the relevant Security Council committee, often requiring a petitioning member state to sponsor the request. Removal from the OFAC SDN List goes through OFAC's administrative review process. Removal from the OFSI list involves OFSI directly, with judicial review before the High Court available thereafter. A deal that is blocked because the target or a key counterparty is listed may face very different timelines and procedural routes depending on which list created the block. We regularly advise acquirers on the practical interaction between those routes where a target has overlapping designations.

The position above covers the standard analysis. Your transaction's facts – the target's sector, its counterparty profile, the jurisdictions of incorporation, the deal structure – will change the weight and urgency of each step.

For an early assessment of your exposure under the UN regime and the national implementing regimes applicable to your deal, contact Calder & Vance at info@caldervance.com.

Step 4: Assess inherited liability and transaction structure

Finding a sanctions hit on the target or its counterparties is not the end of the analysis. The next question is whether the buyer will inherit that exposure, and whether the deal can be structured to manage it.

Asset deals and share deals carry different risk profiles. In a share acquisition, the buyer acquires the target's full legal history, including any unlicensed transactions with designated parties that occurred before signing. In an asset deal, the buyer may be able to exclude specific contracts or relationships – but only where the asset can genuinely be separated, and provided the separation itself does not constitute a prohibited transaction. Neither structure eliminates the need for diligence; it changes what the buyer is exposed to and what remediation looks like.

Where the target has had a trading relationship with a party that is now listed – or that was listed at the time of the relevant transaction – the buyer needs to assess whether that relationship amounted to a prohibited transaction under the applicable implementing regime, whether any licence was in place, and whether a VSD (voluntary self-disclosure to a regulator) might be necessary post-closing. The decision on whether to disclose a potential violation to OFAC, OFSI, or the relevant national authority is a significant one. Timing matters: a VSD made before a regulator identifies the issue is treated more favourably under the applicable enforcement guidance of each regime. The window to act narrows quickly after closing, when the acquirer's knowledge of the issue is no longer deniable.

Representations, warranties, and indemnities in the acquisition agreement should reflect the specific risks identified in diligence. Generic sanctions warranties are inadequate for a deal with identified UN-regime exposure. The warranty package should address the target's compliance history, the accuracy of ownership disclosure, the absence of current relationships with listed parties, and the absence of unlicensed activity in jurisdictions implementing UN measures. Where a clean warranty cannot be given, an escrow or a price adjustment tied to a defined regulatory outcome may be the appropriate structure.

What are the most common risk flags in M&A sanctions diligence under the UN?

Experience before multiple regulators shows that the same categories of risk flag appear repeatedly in M&A transactions with UN-regime exposure. Identifying them early reduces the cost of remediation and preserves options that close as the deal progresses.

The first and most common is incomplete beneficial ownership disclosure. Where the target's ownership chain passes through a jurisdiction with limited public registry data, the buyer cannot confirm whether a beneficial owner at the top of the chain appears on the UN Consolidated List or any implementing national list. This is not a reason to abandon the deal, but it is a reason to require express beneficial ownership warranties and to conduct enhanced due diligence on the gap.

The second is sector-specific UN committee exposure that the initial scoping missed. UN measures are thematic: arms embargoes, commodity restrictions, and travel bans apply in specific sectors. A target with supply-chain exposure in relevant commodities or dual-use goods may sit within the scope of a Security Council committee mandate that did not surface in the initial database check.

The third is secondary-sanctions exposure that the buyer misread as purely a UN-regime question. A counterparty that appears only on the UN Consolidated List and not on any OFAC list may still give rise to OFAC risk if that counterparty operates in a sector subject to OFAC's sectoral sanctions. The UN list is the floor; OFAC's rules may raise the level considerably above it. We have acted for buyers who assumed UN-only exposure and discovered mid-diligence that the same counterparty also created OFAC sectoral risk requiring a full OFAC analysis.

The fourth is inadequate post-closing monitoring obligations. Sanctions lists change after closing. A counterparty that was clean at signing may be listed three months later. Without a post-closing monitoring programme, the buyer has no mechanism to identify that change before it becomes a violation.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.

Step 5: Address the cross-border dimension – secondary sanctions and multiple-regime exposure

A transaction with UN-regime dimensions almost always has national-regime dimensions too, and the interaction between those regimes can create obligations that neither the UN measures nor any single national programme would impose on its own. Managing that cross-border dimension is where the practical complexity of sanctions due diligence in M&A is highest.

Secondary-sanctions risk (the risk that a non-US person's dealings outside US jurisdiction trigger OFAC action against their access to the US financial system) is the most significant cross-border multiplier. A European buyer acquiring a target with significant trade flows touching certain thematic OFAC programmes faces secondary-sanctions risk even if neither the buyer nor the target is a US person. That risk does not arise under the UN implementing regime; it arises under OFAC's autonomous designation authority. The diligence process must assess it separately.

Where the target has operations in multiple jurisdictions each implementing UN measures, the diligence team must apply the strictest applicable prohibition in each jurisdiction. The EU regime and OFAC's regime regularly go further than the UN base. OFSI's regime applies UK-specific designations in addition to UN-derived ones. In a deal touching five jurisdictions, the buyer may be managing five different lists, five different ownership tests, and five different licensing routes simultaneously.

Coordination between the buyer's internal teams and local counsel in each relevant jurisdiction is a structural requirement, not an optional add-on. The engagement model that works in our experience is a central diligence workstream that sets the scope and methodology, draws on local-counsel input for jurisdiction-specific list checking and threshold analysis, and consolidates findings in a single matrix that maps each risk to the implementing regime that creates it and the remediation option available under that regime.

Step 6: Document, remediate, and design the post-closing programme

Documentation is both a legal requirement and a practical defence. Where regulators later question whether an acquirer conducted adequate diligence, the quality and completeness of the diligence record is often the decisive factor in their assessment of the buyer's good faith.

The diligence file should record: the scope document prepared at Step 1; the list of subjects screened, the lists checked, and the date and version of each list at the time of the check; the methodology used to resolve potential matches; the ownership and control analysis for each entity in the target group; the legal analysis of any identified hits or near-matches; and the remediation steps taken. Each of those elements should be retained for the period required under the applicable record-keeping rules. Under OFAC's guidance, five years is the standard record-keeping period for transaction records; OFSI and EU implementing rules carry equivalent obligations. Verify the current requirements before relying on any specific period.

Where diligence identifies a relationship that creates genuine sanctions exposure, remediation options before closing include: termination of the identified contract (subject to whether termination itself requires a licence under the applicable regime), escrow of proceeds pending regulatory clearance, a price adjustment tied to a clean post-closing regulatory outcome, or a conditional closing structure where the condition precedent is completion of a licensing process. Not all of these are available in every deal; the applicable regime's licensing route and timeline will determine which are realistic.

Post-closing, the buyer should implement a monitoring programme that covers at minimum: periodic re-screening of the acquired entity's material counterparties against updated lists; a process for identifying new designations within the target's sector; integration of the target's screening controls into the acquirer's enterprise-wide programme; and a reporting line for potential violations that reaches the compliance function within a defined window. An acquisition that imported sanctions risk and then failed to monitor it is harder to defend before a regulator than one that imported the same risk but detected and managed it promptly.

Step 7: When to involve specialist sanctions counsel

Specialist sanctions counsel should be engaged at the earliest stage of a transaction that presents meaningful UN or national-regime exposure – ideally at or before the scope-setting step rather than after a hit has been identified in the data room. Early involvement changes the nature of the advice from reactive triage to transaction management.

There is a persistent misconception in the M&A market that sanctions diligence is a screening-tool exercise that in-house teams or generalist corporate counsel can run without specialist input. That position may be adequate for a domestic deal with limited cross-border exposure. It is not adequate for a deal that involves a target operating in sectors subject to UN committee mandates, in jurisdictions implementing UN measures through multiple national regimes, or with a counterparty profile that creates secondary-sanctions risk. The regime is too fragmented and the consequence of error – inherited liability for unlicensed transactions, civil penalties under the applicable implementing regime, exclusion from US correspondent banking access – too significant to treat as a background item.

In our cross-border practice, we assess eligibility for any required licences, prepare and submit licence applications, and manage regulators' queries where the deal requires a licensing step. Where diligence identifies a potential historical violation, we scope the apparent breach, advise on voluntary self-disclosure, and prepare the regulatory engagement. Where the deal is blocked by a listing that the target or a key counterparty believes is incorrect, we build the evidence package for a petition or annulment action and manage the review through the applicable route – whether that is the Security Council Ombudsperson, OFAC's administrative process, or the EU General Court.

Does your transaction involve a target or counterparty that appears on any sanctions list? Is the deal crossing jurisdictions where multiple UN implementing regimes apply? These are the questions that determine whether specialist counsel adds value or merely adds cost – and in our experience, the answer is almost always the former.

Related practices

Frequently asked questions

What are the steps to run sanctions diligence in a deal under UN?
Effective sanctions due diligence in M&A under the UN requires seven steps: (1) scope the applicable implementing regimes before opening the data room; (2) map the full ownership and control chain of the target against the UN Consolidated List and each national implementation; (3) screen the target, its directors, its beneficial owners, and its material counterparties across all relevant lists; (4) assess whether identified hits create inherited liability and how the deal structure affects that exposure; (5) address cross-regime and secondary-sanctions risk in each jurisdiction; (6) document the process, remediate identified exposure, and design a post-closing monitoring programme; and (7) engage specialist counsel at the earliest stage where meaningful UN or national-regime exposure is present. Each step must be calibrated to the specific implementing regimes applicable to the buyer, the target, and their respective counterparty profiles.
What is the most common mistake in sanctions due diligence in M&A?
The most common mistake is treating sanctions diligence as a single-list screening exercise. Running the target and its principals against the UN Consolidated List alone misses OFAC SDN List hits, EU autonomous designations, OFSI-specific listings, and secondary-sanctions risk that does not appear on any list but arises from the counterparty's sector or conduct. A close second is incomplete beneficial ownership mapping: screening only directors and first-layer shareholders while ignoring indirect ownership chains that aggregate to the relevant threshold under OFAC's 50 percent rule or the EU and UK control test. Both errors produce a diligence result that appears clean but does not reflect the actual risk the acquirer is inheriting.
How does UN differ from other regimes here?
The UN Consolidated List differs from OFAC's SDN List and OFSI's consolidated list in three key ways for M&A purposes. First, UN listings require national implementation to create binding legal obligations; OFAC and OFSI designations operate directly. Second, the UN list is narrower than OFAC's and the EU's lists, which include extensive autonomous designations beyond the UN base; screening only the UN list leaves a significant gap. Third, the delisting route is procedurally distinct for each regime – through the Security Council Ombudsperson or committee for UN listings, through OFAC's administrative process for SDN removals, and through OFSI or the High Court for UK designations – meaning a deal blocked by overlapping designations may require parallel remediation tracks on different timelines.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.