A Canadian trading company is mid-close on a new distribution agreement. Its compliance team runs the proposed counterparty through its standard tool and returns a clean result. Two weeks later, the company's bank flags the same entity – the counterparty's parent has just been added to the Canadian list administered by Global Affairs Canada. The deal is now legally problematic, and the team did not catch it. How does that happen, and how do you prevent it?
Effective name and entity screening under Canada's autonomous sanctions regime requires a structured, repeatable process covering four pillars: the right list sources, an ownership and control analysis, an alert-disposition workflow, and a record-keeping discipline. Canada's regime is administered by Global Affairs Canada (GAC) under the Special Economic Measures Act (SEMA) and the Justice for Victims of Corrupt Foreign Officials Act (JVCFOA), and the obligations it imposes are strict-liability in character – intent is not a defence to a prohibition.
As of July 2026, the Canadian list continues to expand across several thematic programmes, and the alignment – and divergence – between SEMA and comparable instruments under OFAC, OFSI, and the EU Council regulations creates real compliance complexity for cross-border businesses. This guide walks through the screening process step by step.
Step 1: Identify Your Canadian Sanctions Obligations
Canada's sanctions regime applies to any person in Canada and to any Canadian anywhere in the world – a broader jurisdictional reach than many businesses realise on first analysis. The Special Economic Measures Act and the Justice for Victims of Corrupt Foreign Officials Act are the two primary legislative instruments. Under SEMA, Governor-in-Council regulations implement specific country or thematic programmes; under JVCFOA, regulations target individuals involved in significant corruption or human-rights violations abroad. Both instruments generate lists of designated persons whose assets must be frozen and with whom transactions are prohibited.
The jurisdictional trigger matters enormously in a cross-border context. A UK parent with a Canadian subsidiary cannot treat the OFSI position as definitive. Where OFSI licensing covers a transaction, the Canadian prohibition may remain in full force – and there is no general principle of mutual recognition between the two regimes. In our experience, multinationals with Canadian entities often discover only at the point of a specific transaction that their group-level screening policy does not address the Canadian list as a discrete source. That gap is the compliance failure most commonly surfaced in our practice.
The first practical step is therefore a jurisdictional mapping exercise: identify every entity in your group that has a Canadian nexus, whether through incorporation, operations, personnel, or financial-institution accounts. Each such entity is a separate obligation-holder under SEMA and JVCFOA.
Step 2: Build Your List-Source Architecture
Canada publishes its consolidated list of designated persons through the GAC website, and this is the authoritative source for SEMA and JVCFOA designations. But screening under Canada in isolation is rarely sufficient for a business with cross-border operations. A coherent screening architecture will typically draw on multiple official list sources simultaneously.
Which lists should a cross-border business screen against? At minimum, the answer includes the Canadian Consolidated List (GAC), the OFAC SDN List (the list of Specially Designated Nationals and Blocked Persons administered by the US Treasury's Office of Foreign Assets Control), the UK Consolidated List of Financial Sanctions Targets (administered by OFSI), and the UN Security Council Consolidated List. Depending on the business's sector and counterparty profile, EU, Swiss (SECO), and Australian (DFAT) lists will also apply.
A critical operational point is that list updates are not synchronised across regimes. A person designated by OFAC may not appear on the Canadian list for weeks or months – or may never appear. The converse is also true. A Canadian designation that does not replicate at OFAC may not trigger your screening tool if the tool is configured to prioritise US sources. List-source architecture must therefore treat each regime as an independent data stream, not as a hierarchy where one list is assumed to subsume another.
The update frequency for each list source must also be formalised in your process. The Canadian list is updated irregularly, sometimes with short notice in the Canada Gazette. Your process should specify the maximum permissible interval between a new Gazette publication and the refresh of your screening database – a gap of more than one business day is generally indefensible on enforcement review.
Step 3: Apply the Ownership and Control Test
Screening the legal counterparty is only the beginning of the analysis. Canada's sanctions regulations prohibit transactions with designated persons and, in practice, with entities owned or controlled by designated persons – which means the ownership chain behind the counterparty must be traced, not just the named entity.
The ownership and control question is where Canada, the UK, and the EU converge in principle but diverge in detail. Under OFAC, the test is primarily mechanical: entities owned at 50 percent or more by one or more blocked persons, in the aggregate, are treated as blocked. Canada and the EU apply a test that encompasses both ownership thresholds and actual or effective control, making the analysis more fact-specific. OFSI's guidance under UK law similarly requires consideration of control in addition to ownership percentage. The practical implication is that a counterparty that passes the OFAC 50 percent test may still be caught under a Canadian or UK analysis if a designated person exercises effective control through other means.
In our cross-border practice, we regularly advise clients on situations where a counterparty holds a clean result on automated screening – because no individual shareholder exceeds the ownership threshold – yet a control analysis under the Canadian or EU standard reveals a designated person directing the entity's operations. That gap is not a tool failure. It reflects a genuine difference in the legal standard, and a process relying solely on automated name-matching against threshold-triggered ownership will not close it.
The ownership trace for a Canadian screening should proceed as follows. First, identify the ultimate beneficial owners of the counterparty at or above a defined threshold – typically 10 or 25 percent, depending on the risk profile of the transaction. Second, screen each identified owner against the Canadian list and the other applicable list sources. Third, assess whether any owner exercises control through contractual rights, board representation, veto rights, or other means, even below an ownership threshold. Fourth, document the analysis and the conclusion, with reference to the sources consulted and the date of review.
Step 4: Configure and Calibrate Your Screening Tool
Screening tools produce two categories of output that compliance teams must handle: true positives (genuine matches to a designated person) and false positives (apparent matches that do not withstand review). The calibration question – how sensitive to set the matching algorithm – is one of the most consequential decisions in programme design, and it receives less attention than it deserves.
Set the algorithm too loosely and you generate an unmanageable volume of alerts, most of them false positives. Analysts become fatigued, disposition quality falls, and genuine hits are more likely to be cleared incorrectly. Set it too tightly and the tool misses transliteration variants, name-order differences, or abbreviations that a designated person or associated entity may use in the market. Neither failure mode is acceptable.
For a Canadian screening programme specifically, the configuration must account for the bilingual character of Canadian designations. GAC publishes designated-person names in both English and French, and in some programmes the regulated text in the Canada Gazette may contain transliterated Arabic, Cyrillic, or other scripts. A tool calibrated only against English romanisation of names drawn from a US-centric database is structurally underperforming for Canadian compliance purposes.
Beyond the name-matching parameters, the tool configuration should specify: the list sources and update schedule (Step 2); the data fields submitted for matching (full legal name, trading name, aliases, registration numbers, address); the minimum score threshold for generating an alert; and the escalation pathway once an alert is generated. Each of these configuration decisions should be documented and subject to periodic review – annually at minimum, and following any material change in the risk profile of the business or in the regulatory regime.
Step 5: Build a Disciplined Alert-Disposition Workflow
An alert from a screening tool is the beginning of an analysis, not a conclusion. The disposition workflow – the process for reviewing an alert, determining whether it represents a genuine match, and either clearing or escalating it – is where many programmes fail in practice. A screening programme is only as strong as the weakest link in its disposition chain.
What does a sound disposition process look like? Each alert should be assigned to an analyst with defined authority to clear or escalate. The analyst should have access to: the underlying alert data; the relevant list entry in full, including all aliases and identifying information; the counterparty's registration documents, ownership structure, and any available commercial intelligence; and guidance on the applicable legal standard under SEMA and the other regimes in scope.
A genuine match – a true positive – requires immediate escalation to a senior compliance officer or legal counsel. The prohibited transaction must not proceed. In most cases the next step will be to consider whether a licence or ministerial authorisation is available. Under SEMA, the Governor-in-Council has the power to issue permits allowing otherwise prohibited transactions in defined circumstances. The licensing process is administered by GAC, and the criteria and timelines are set out in the relevant programme regulations and GAC guidance. Verify the current position on permit availability before relying on it, as the criteria differ by programme and may change.
A false positive – an alert that, on review, does not match the counterparty – should be documented in full: the alert, the review, the sources consulted, the conclusion reached, and the name of the analyst who cleared it. This documentation is the primary evidence of the programme's effectiveness in the event of a regulatory inquiry. Clearing alerts without a written record is the single most common process failure we see in compliance-programme reviews.
In a recent matter, a financial-services business operating across North America had accumulated a large backlog of undisposed alerts from its automated screening tool. On review, the majority were false positives driven by common surnames in the tool's database. We worked through the backlog systematically, redesigned the disposition workflow to include tiered review based on risk scoring, and documented the outcomes. The programme returned to a functional state within a defined remediation window, and the business was able to demonstrate to its regulator that the historical gap had been identified and closed.
Step 6: Manage Record-Keeping and Reporting Obligations
Canada's sanctions regulations impose specific record-keeping and reporting obligations that are distinct from the screening obligation itself. Under SEMA, any person who has in their possession or control property owned or controlled by a designated person must, in general terms, report that fact to GAC and must not deal with the property. The reporting obligation arises as soon as the person becomes aware of the relevant property. Verify the specific timing and form requirements against the current GAC guidance and the relevant programme regulations before acting.
Record-keeping under the applicable regime requires that records supporting compliance decisions be retained for a prescribed period. The prompt is to treat sanctions compliance records consistently with anti-money-laundering records in your document-management policy – a minimum retention period of several years is standard across major regimes, though the precise requirement should be confirmed against the current Canadian text.
The cross-border record-keeping question becomes acute when a group uses a shared service centre for screening across multiple jurisdictions. Where records are held in a non-Canadian entity for transactions that engage Canadian obligations, the business should consider whether those records would be accessible to GAC in the event of a regulatory inquiry, and whether the group's data-governance arrangements are consistent with the requirements of all applicable regimes.
The position above covers the standard record-keeping case. Your facts – the type of property, the designated programme, the structure of your group, and the route through which the obligation arose – will change the analysis materially.
If a transaction has already been flagged, or a regulatory inquiry has been received, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential first review.
Step 7: Align the Programme with Cross-Border Regime Requirements
For most businesses reading this guide, Canada is one regime among several. The practical question is not only how to comply with SEMA and JVCFOA but how to design a single integrated programme that satisfies the requirements of all applicable regimes without duplicating work unnecessarily.
Three points of divergence between Canada and its major counterpart regimes deserve particular attention in programme design.
First, list-update timing and content. As noted in Step 2, the Canadian list does not mirror OFAC, OFSI, or EU designations automatically. A programme that assumes convergence will have structural gaps. The solution is a list-source matrix that maps each regulatory obligation to its authoritative source and update schedule, and that treats each source independently in the screening configuration.
Second, the licensing and authorisation route. OFAC general licences and OFSI general licences operate differently from GAC permits under SEMA. A transaction covered by a US general licence is not automatically covered in Canada – and vice versa. In our experience, this is a particularly common source of error in trade-finance transactions where a relationship bank has cleared the position under OFAC but the Canadian-entity borrower has not assessed its own obligations separately.
Third, the treatment of control in the ownership analysis. As described in Step 3, Canada applies a control test that goes beyond ownership percentages. A programme calibrated to flag only entities meeting a mechanical ownership threshold will under-perform against the Canadian standard. The control element requires human judgment and cannot be fully automated – it must be embedded in the disposition workflow rather than delegated entirely to the screening tool.
We regularly advise clients on programme design that covers all three of these points. The goal is a programme that is defensible under each applicable regime on its own terms, while avoiding the inefficiency of entirely siloed processes for each jurisdiction.
Common Risk Flags and When to Involve Counsel
Certain indicators consistently signal a higher risk of screening failure or of a genuine match being missed. In our experience, these are the patterns that most frequently surface in enforcement reviews and compliance-programme assessments.
A counterparty with a complex or opaque ownership structure – multiple layers of intermediate holding companies, bearer shares, nominee arrangements, or structures that pass through high-risk jurisdictions – is a screening risk regardless of the result produced by an automated tool. The tool screens the legal entity presented; it does not trace the ownership chain unless that chain has been separately analysed and submitted as input.
A counterparty that is newly incorporated, or that has recently changed its name or legal form, warrants enhanced scrutiny. Designation evasion through corporate restructuring is a pattern that enforcement authorities across all major regimes have identified explicitly. Your screening and due-diligence process should flag corporate-history anomalies for manual review.
A transaction that is unusual in its structure, route, or commercial terms – not because it is necessarily suspicious, but because it differs from the established pattern for the counterparty or sector – should trigger enhanced due diligence, including a fresh screening review at the time of the anomaly rather than relying on a periodic re-screen.
Counsel should be involved whenever: a genuine match or potential match has been identified and requires a legal assessment; a permit or licence application is under consideration; a report to GAC is required; a regulatory inquiry has been received; or the business is considering a transaction in a sector or counterparty profile that carries elevated sanctions risk across any of the applicable regimes.
Related practices
- Sanctions compliance audit and testing (Australia) – assessing and strengthening screening programmes against the Australian autonomous-sanctions regime
- Name and entity screening: cross-border guide – a regime-comparative analysis of screening obligations across the major sanctions programmes
- Name and entity screening: cross-border guide (part 2) – advanced topics in multi-regime screening programme design