A payments firm processing cross-border settlements discovers, mid-transaction, that one name in its batch matches three separate sanctions lists – one OFAC, one EU, and one OFSI. The lists do not perfectly overlap. The name appears with different transliterations on each. The firm has thirty seconds before the settlement window closes. What does it do?
Name and entity screening across multiple jurisdictions requires a single, coordinated process that simultaneously checks each applicable list, applies the correct ownership and control test for each regime, and resolves name-matching ambiguity against verified identity data. As of July 2026, the major regimes – OFAC, OFSI, the EU Council, and the UN Security Council – maintain separate consolidated lists with different update frequencies, different transliteration conventions, and different legal tests for when a non-listed entity is caught through a listed person. No single commercial screening tool addresses all of these differences without configuration and human review.
This guide walks through the practical steps for building and operating a cross-border screening programme, identifies the points where regimes diverge most sharply, and explains when a compliance question needs legal counsel rather than a system configuration change.
Step 1: Map your regime obligations before you configure any tool
The first step in any cross-border screening programme is a clear-eyed map of which regimes legally apply to your organisation – because each regime imposes its own list-checking obligation, and the consequences of missing one are independent of whether you were diligent under the others.
Most internationally active businesses face at least three concurrent obligations. A US-incorporated entity, a US-person employee, or a US-dollar clearing leg triggers OFAC jurisdiction regardless of where the transaction originates. A business incorporated or operating in any EU member state must screen against all EU autonomous sanctions lists and the UN Consolidated List as transposed into EU law. A UK nexus – a UK entity, a UK person, or sterling clearing – brings OFSI into scope. Each of these regimes has extraterritorial reach that extends well beyond its home jurisdiction.
In our experience, the most damaging configuration errors arise not from screening the wrong names but from failing to realise that a particular regime applies at all. A Singapore-based trading house may consider OFAC a US concern; but if any of its payments clear in US dollars through a US correspondent bank, OFAC jurisdiction almost certainly applies. The regime map must be done before any tool is configured, not after.
Practical questions to answer at this stage include: which legal entities in your group are subject to which regimes; which currencies and clearing routes you use; which jurisdictions your customers and suppliers operate in; and whether any of your staff, directors, or shareholders are themselves US persons, UK persons, or EU persons who could extend a regime's reach through their individual involvement in a transaction.
Step 2: Understand the list architecture across regimes
Each major regime maintains its own designated-persons list, and those lists differ in scope, structure, update cadence, and the legal effect they produce – so screening against one list does not discharge your obligations under the others.
OFAC maintains the SDN List (OFAC's list of Specially Designated Nationals and blocked persons), which is updated on a rolling basis and can change multiple times in a single day. It also maintains several non-SDN lists – including the Non-SDN Menu-Based Sanctions List and the Sectoral Sanctions Identifications List – each with a different legal effect. A transaction that is not prohibited by an SDN designation may still be restricted under a sectoral programme. Screening tools that check only the SDN List miss this dimension entirely.
The EU maintains separate consolidated lists for each autonomous sanctions programme, with the overall list accessible through the EU Financial Sanctions Files published by the European Commission. The UN Security Council Consolidated List sits beneath all of these; EU and UK law give it domestic legal effect, but the UN list itself is narrower and less frequently updated than the autonomous EU and UK lists. OFSI publishes its own UK financial-sanctions list, which diverged from the EU list following the UK's departure from the EU and has continued to diverge as both regimes have added designations independently.
Do your screening tools pull from all of these sources, or only the most visible one? In a cross-border programme, the answer to that question is the difference between a defensible compliance position and a blind spot.
Step 3: Apply the correct ownership and control test for each regime
Whether a non-listed entity is caught because a listed person owns or controls it is one of the most consequential – and most frequently misapplied – questions in cross-border screening, because the answer differs by regime.
Under OFAC, the applicable test is the 50 percent rule (OFAC's rule treating entities owned 50 percent or more in aggregate by blocked persons as themselves blocked). The rule is mechanical. It does not matter whether the blocked person exercises management control; if the ownership threshold is met, the entity is treated as blocked whether or not it appears on the SDN List. Aggregation applies: two listed persons each holding 30 percent of the same target together reach the threshold, even if neither does so alone.
Under OFSI and the EU, the applicable test is ownership and control (the UK and EU test for whether a non-listed entity is caught through a listed person). Both the UK and EU regimes look beyond formal ownership to consider whether a listed person controls an entity through other means – board influence, contractual rights, power to direct financial flows, or de facto decision-making authority. An entity owned only 35 percent by a listed person may still be caught if that person effectively controls it. This is a more demanding analytical exercise than the OFAC ownership calculation, and it requires actual information about governance, not just a cap-table spreadsheet.
Screening tools generally cannot perform the control analysis. They can flag that a known SDN or listed person appears in an ownership chain; they cannot assess whether that person exercises board control, appoints key management, or holds veto rights over material decisions. That analysis is a legal and factual judgment. In a complex ownership structure, it is one we regularly advise on directly.
For Singapore, Japan, and the UAE, ownership and control analysis under the applicable country regime will differ further. Businesses operating into those markets should obtain jurisdiction-specific legal input rather than assume that the OFAC mechanical test or the EU control analysis transfers directly.
Step 4: Handle name-matching and transliteration systematically
Name-matching is the technical heart of any screening programme, and it is where the volume of false positives – and the risk of false negatives – is highest in a cross-border context.
The core problem is that the same individual or entity may appear on different lists under different name variants. An Arabic name transliterated into English may appear in four or five different spellings across the OFAC, EU, UN, and OFSI lists. A Cyrillic name may appear in multiple romanisation conventions. A Chinese entity name may appear in both simplified and traditional characters, with an official pinyin transliteration and one or more common English trade-name variants. A screening system that matches only exact strings will generate both false positives and false negatives at high volume.
Effective matching logic uses fuzzy matching with a configurable threshold, phonetic matching algorithms for the relevant scripts, and a defined process for escalating ambiguous matches for human review. The threshold question is genuinely difficult: a lower threshold catches more true positives but generates more false positives requiring manual review; a higher threshold reduces review volume but increases the risk of a genuine match being missed. There is no universally correct threshold – it depends on the risk profile of your business, the volume of your screening, and the resources you have for review.
Transliteration tables published by the major sanctions authorities offer some standardisation, but they are not comprehensive and they are not static. When a name appears on multiple lists in genuinely different forms, the correct approach is to maintain a local alias database that captures all known variants, updated whenever a new designation or list update is published.
Aliases, also known as "a.k.a." entries, are part of each formal designation and are published on the lists themselves. Your screening tool should ingest alias data, not only primary names. We have seen cases where a business successfully screened the legal name of a counterparty but failed to flag the trade name under which that counterparty actually operated – which was listed as an alias on the relevant regime's published list.
Step 5: Build a defensible escalation and decision process
A screening hit is not a compliance outcome. It is the start of a structured decision process – and the quality of that process, documented at every stage, is what a regulator will examine if a transaction later comes into question.
When a screening alert is generated, the first question is whether the match is a genuine potential match or a false positive. This requires a comparison of every available identifier: full name, date of birth, nationality, country of incorporation, registration numbers, address, and any other data point that can confirm or distinguish identity. A match on name alone, without any corroborating identifier, is a weak match; a match on name plus date of birth plus nationality is a strong one.
If the match cannot be resolved as a false positive on the available information, the transaction should be held and a legal review initiated. Acting on an unresolved hit – proceeding anyway, or refusing without documented analysis – carries its own risk. Proceeding with an unresolved hit against a genuine listed person could constitute a sanctions violation. Refusing without documented analysis is commercially damaging and potentially exposes the business to claims from the counterparty.
The escalation process should define: who has authority to clear a potential match as a false positive; who has authority to escalate to senior management or legal counsel; what documentation is required at each stage; and what the record-retention obligation is. Under most major regimes, record-keeping obligations extend for five years from the date of the transaction or the decision – but verify the current position under each applicable regime before relying on this.
A BLUF for this step: document everything, retain it, and make the decision trail auditable. A regulator investigating a potential violation will look at the process as much as the outcome.
How does a cross-border programme differ from a single-regime programme?
A cross-border screening programme is not simply the sum of several single-regime programmes run in parallel; it requires active management of the points where regimes diverge, because the stricter prohibition governs any transaction that touches multiple jurisdictions.
The divergence most likely to create operational difficulty sits at three points. First, list coverage: a person or entity may be listed under one regime but not another. A transaction that is permissible under OFAC because the counterparty is not on any OFAC list may still be prohibited under EU law if the counterparty is listed under an EU autonomous programme. Running each list in isolation does not solve this; the cross-border programme must consolidate results across all applicable lists before a clearance decision is made.
Second, the ownership threshold: as noted above, the OFAC 50 percent mechanical test and the EU/UK control test can produce different answers for the same counterparty. A compliance decision that is correct under one regime may be incorrect under the other. Where the regimes diverge, the stricter analysis should govern.
Third, licensing: a transaction that is prohibited under one regime may be licensable under that regime but may separately require a licence under another. An OFAC specific licence does not authorise a transaction under OFSI or the EU, and vice versa. In a multi-regime matter, the licensing analysis must be conducted for each jurisdiction that applies.
There is also the question of secondary-sanctions risk. OFAC's secondary sanctions programmes can expose non-US businesses to designation or to loss of US market access if they engage in significant transactions with primary-sanctioned parties, even where those transactions are not subject to US primary jurisdiction. A screening programme that addresses only primary sanctions exposure, without assessing secondary-sanctions risk, is incomplete for any business with meaningful US market exposure.
The bridge question for any cross-border compliance officer is this: is your programme designed to answer the hardest question any one of your applicable regimes would ask, or only the question your primary jurisdiction asks? If it is the latter, the programme has a systematic gap.
The position above covers the standard case. Your facts – the counterparty, the goods, the route, the regimes in play – will change the analysis materially. For an assessment of your cross-border screening exposure, contact Calder & Vance at info@caldervance.com.
Common risk flags that indicate a screening programme needs review
Several patterns in the operation of a screening programme consistently signal that the programme is underperforming, based on what we regularly see when we review client arrangements.
A high rate of false positives that are cleared without documented identity analysis is one of the clearest indicators. When analysts clear matches quickly to reduce queue backlogs, the decision trail tends to lack the identity-verification step. If a regulator subsequently questions a transaction, a cleared match without documented distinguishing analysis is very difficult to defend.
A programme that has not been re-configured following a significant list update is another. Designations and de-listings change the risk profile of a counterparty population overnight. A programme whose list sources are updated on a weekly or monthly schedule, rather than in near-real time, may be operating on stale data. The major sanction authorities publish list updates that can take effect immediately; the compliance process needs to match that cadence.
Absence of periodic re-screening of existing customers is a structural gap many programmes carry. Onboarding screening checks a counterparty against the list at the moment of onboarding; it does not catch a designation that occurs during the relationship. Most major regimes require ongoing monitoring, not just point-in-time checks, as part of a reasonable compliance standard.
Failure to screen ultimate beneficial owners separately from the legal entity counterparty is a gap that directly exposes a business to the ownership-and-control risk described above. The entity-level check and the UBO-level check are both required; they are not the same check.
Finally, programmes that cover only the SDN List – and not sectoral sanctions lists, the EU financial-sanctions files, the OFSI UK list, and the UN Consolidated List – have a fundamental scope problem. The most widely known list is not the most comprehensive one.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. For a confidential review of a potential screening issue, contact Calder & Vance at info@caldervance.com.
Related practices
- Compliance audit and testing (Australia) – systematic testing of screening and compliance controls against regulatory expectations
- Name and entity screening: EU regime guide – in-depth analysis of EU list architecture, ownership and control tests, and escalation procedures
- Name and entity screening: OFAC guide – OFAC SDN and non-SDN list coverage, the 50 percent rule, and licensing considerations