Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Name and entity screening under OFSI: a practical guide

A UK-based trade finance bank is processing a syndicated loan to a European trading group. Routine screening returns a partial name match against the OFSI Consolidated List (the United Kingdom's Office of Financial Sanctions Implementation's published register of designated persons and entities). The operations team escalates. Is this a true hit, a false positive, or something in between? The answer shapes whether the transaction proceeds, whether the bank must report, and whether a frozen-funds obligation has already crystallised.

Effective name and entity screening under OFSI requires more than running a name through a database. It demands a structured methodology: understanding what the UK Consolidated List covers, applying the correct ownership-and-control test, resolving ambiguous matches systematically, and knowing when a result requires legal review rather than a compliance-officer decision. As of July 2026, OFSI's enforcement posture treats inadequate screening as a factor that can elevate a penalty, not merely a process gap.

This guide walks through the practical steps, explains how the UK regime compares with OFAC and the EU on the critical ownership question, and identifies the risk flags that should prompt counsel involvement.

Step 1: Understand what the OFSI Consolidated List contains – and what it does not

The OFSI Consolidated List is the authoritative public record of persons and entities subject to UK financial sanctions. It derives its legal force from designations made under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic sanctions regulations made under it. The list includes full legal names, aliases, known addresses, nationality data, and – where available – identifiers such as date of birth or registration numbers.

Understanding the list's boundaries matters as much as understanding its contents. The Consolidated List records only directly designated persons. It does not automatically extend to entities that a designated person owns or controls. That extension is a matter of legal analysis under the ownership-and-control test (the UK rule that treats an entity as subject to financial sanctions when a designated person owns or controls it, even if the entity itself is not named on the list). A business that screens only against named entries – and stops there – is not meeting OFSI's expectation of a thorough sanctions check.

In our experience, financial institutions often treat the Consolidated List as a checklist. In practice, it is a starting point. The real analytical work begins when a name clears the list but an ownership structure does not.

OFSI publishes the Consolidated List in multiple formats and updates it without a fixed schedule. Firms should use a feed-based integration rather than periodic manual downloads, because a designation can be added on any business day and takes effect immediately. The window between a designation and a firm's next scheduled update is a live exposure period.

Step 2: Apply the ownership-and-control test correctly

An entity is caught by UK financial sanctions if a designated person, alone or together with other designated persons, owns or controls it. This is where the analysis becomes operationally complex and where the UK regime diverges meaningfully from its counterparts.

Under OFAC, the test is mechanical: 50 percent or more aggregate ownership by blocked persons triggers the rule, regardless of operational control or management. The UK ownership test also uses a majority-ownership threshold as one indicator, but it adds a control limb. Control under the UK regime can arise through the ability to direct or influence the entity's activities by other means – including voting rights, contractual arrangements, board representation, or practical dominance. This is a broader and more fact-sensitive inquiry.

The EU position is similar to the UK on the control limb, which matters when a transaction involves both UK and EU-nexus parties. Where a UK-designated person also appears on the EU list, both the UK ownership-and-control test and the EU equivalent apply. In our cross-border practice, we regularly advise clients who assume that clearing one regime means they have cleared the other. That assumption is incorrect and has caused real-world compliance failures.

Practical application of the ownership-and-control test requires three inputs:

  • A verified ownership chart showing all layers above and below the counterparty, traced to ultimate beneficial owners
  • A list of all direct and indirect owners who appear on the OFSI Consolidated List
  • An assessment of whether any non-listed person exercises de facto control through means other than registered ownership

If any designated person holds or shares control – or if the ownership chart cannot be verified to sufficient depth – the position requires legal review before the transaction proceeds. The position does not improve by proceeding on hope.

Step 3: Build a match-resolution process that distinguishes true hits from false positives

Screening tools return matches; human and legal judgment resolves them. This distinction is fundamental to an effective programme. A hit on a name-screening system is an alert, not a determination. The determination – true match, potential match requiring further enquiry, or false positive – must follow a documented process.

A workable resolution process has four stages.

  1. Initial alert review. The screener compares the matched entry's identifiers (date of birth, nationality, address, registration number) against the counterparty's known data. Where identifiers align on multiple fields, the alert escalates. Where they diverge on all fields, the false-positive determination is documented with reasons.
  2. Enhanced due diligence. Where identifiers are partial or ambiguous, additional source data is sought: company registry records, passports or government-issued identification, beneficial-ownership registers, or commercially available identity data. The goal is to achieve or rule out sufficient identifying convergence.
  3. Legal review. Where enhanced due diligence does not resolve the match, or where it reveals that a designated person may own or control the counterparty, the matter escalates to counsel. This is not a discretionary step for high-risk matches – it is mandatory. A compliance team is not the right decision-maker for ambiguous ownership questions.
  4. Decision documentation. Every match resolution is documented with the data reviewed, the conclusion reached, and the name of the person who authorised the decision. Documentation is the primary means of demonstrating due diligence to OFSI in any subsequent enquiry.

The position above covers the standard case. Your facts – the counterparty's jurisdiction, the ownership layers involved, the nature of the transaction, and the specific designation at issue – change the analysis materially. For a confidential review of a potential match, contact Calder & Vance at info@caldervance.com.

How does OFSI differ from other regimes on the ownership-and-control question?

The OFSI ownership-and-control test is broader in scope than OFAC's mechanical 50 percent rule, but it operates within a national-law context that differs from the EU's supranational enforcement structure. Understanding this divergence is essential for cross-border businesses.

Under OFAC, the analysis is relatively predictable. If aggregate blocked-person ownership reaches the threshold, the entity is blocked. Below the threshold, OFAC ownership analysis is satisfied. Control, as a separate ground, is less developed in OFAC guidance than in the UK and EU regimes.

Under OFSI, the control limb is explicit. An entity that a designated person controls through board appointments, veto rights, or a contractual arrangement may be caught even where no majority-ownership threshold is reached. OFSI's published guidance makes clear that firms should not treat the absence of majority ownership as a safe harbour. Have you assessed control as well as ownership for every tier of your counterparty's structure?

Under the relevant EU Council regulations, the position is functionally similar to the UK on control, but the EU list and the UK Consolidated List are separate instruments maintained by different authorities. Divergences in designation coverage are common. A person listed by the EU may not yet be listed by OFSI, or vice versa. For UK-nexus transactions with EU parties, both lists must be screened independently.

Singapore, the UAE, and Japan each maintain separate national lists. Where a counterparty has activities in those jurisdictions, screening against OFSI and OFAC alone is insufficient. The applicable country regime applies concurrently, and where two regimes impose conflicting requirements, the stricter prohibition generally governs the conduct of a firm subject to both.

If a transaction has already been flagged under one regime, or if a filing has been refused, an early cross-regime review can preserve options that narrow with time. Write to us at info@caldervance.com for an assessment of your position.

What are the risk flags that require counsel involvement?

Not every screening question requires external legal input. Many alerts are resolved quickly against clear identifier data. But certain patterns consistently indicate that internal resolution is insufficient and that a sanctions lawyer should be engaged before a decision is made.

The clearest risk flags are:

  • A name match where identifiers are absent, inconsistent, or unavailable – for example, a counterparty in a jurisdiction with poor registry disclosure
  • An ownership chain that cannot be traced to ultimate beneficial owners beyond a certain layer, or where nominee structures are in use
  • A counterparty in a jurisdiction that is itself subject to a thematic sanctions programme under SAMLA, even where no specific entity is named
  • A transaction involving a sector – energy, arms, financial services – that is subject to sector-specific restrictions under the relevant thematic regulations
  • A match that clears the OFSI list but raises a question under the EU list or the OFAC SDN List, creating a cross-regime exposure
  • Any situation where the counterparty cannot or will not provide documentation to support beneficial-ownership verification
  • A post-transaction discovery that a counterparty may have been designated at the time of the transaction

The last scenario carries particular urgency. A post-transaction discovery triggers a potential reporting obligation under the relevant thematic sanctions regulations and may require a voluntary self-disclosure (a VSD – a proactive report to OFSI of a potential breach, made before a regulatory enquiry begins). In our experience, early VSD preparation, handled carefully and with legal advice, gives a firm the best available position in any subsequent OFSI enforcement process. Acting without advice in this window is a common and costly mistake.

Step 4: Design ongoing screening for a live sanctions environment

Screening is not a point-in-time event. Designations happen without advance notice and take effect immediately under SAMLA. A counterparty that cleared screening in January may be designated in March. A supply-chain partner screened at contract execution may not be screened again until the next audit cycle. Both scenarios create exposure.

An effective ongoing-screening programme has three components.

First, a real-time or near-real-time feed from the OFSI Consolidated List and the other regime lists relevant to the business's counterparty and geographic footprint. The feed must integrate with the firm's customer and counterparty data at a frequency that the business's risk profile demands. A high-volume payment firm and a quarterly-cycle commodity trader have different update-frequency requirements, but neither should rely on periodic manual downloads.

Second, a trigger-based rescreening protocol. Certain business events should automatically initiate a fresh screen: a change in counterparty ownership, a new beneficial-ownership disclosure, an extension of credit, a material change in the scope of a transaction, or entry into a new jurisdiction. Waiting for the annual compliance cycle to catch these events is not proportionate to the risk.

Third, a record-keeping discipline that covers both the screening results and the methodology. OFSI and other UK enforcement authorities expect firms to be able to demonstrate, retrospectively, that a screening programme was in place, was calibrated appropriately, and was applied consistently. Records should be retained for the period prescribed under the applicable regime – verify the current requirement before setting a deletion policy, as minimum retention periods differ across the major regimes and the specific thematic regulations in scope.

A single mis-configured screening parameter – a fuzzy-match threshold set too low, a data-field exclusion that misses transliterated names, a refresh cycle misaligned with the firm's transaction volume – can produce a systematic gap that a later OFSI enquiry will surface. We regularly advise clients who discover such gaps during a compliance audit. Identifying and closing them before an enquiry is materially better than discovering them in correspondence with OFSI.

A common myth: passing a name through a commercial database satisfies the screening obligation

A persistent misconception among firms new to UK sanctions compliance is that subscribing to a commercial screening platform and running names through it constitutes a complete screening programme. It does not.

Commercial databases are a useful component of a screening programme. They aggregate multiple lists, provide transliteration coverage, and enable systematic alert generation. But they are not the programme itself. They do not apply the ownership-and-control test. They do not resolve matches. They do not assess sector restrictions. They do not flag a counterparty whose majority shareholder – not listed directly – exercises control through a holding structure that has a designated person at its apex.

OFSI's enforcement guidance makes clear that the responsibility for an effective screening programme lies with the regulated entity, not with the technology it uses. A technology failure or a vendor gap is not a defence to a sanctions breach. The firm is responsible for ensuring that its programme – including any third-party tool – is calibrated to catch the risks its business actually faces.

This matters practically. A bank processing cross-border payments faces a different risk profile from a commodity trader structuring a long-term offtake agreement. The screening parameters, the match-resolution thresholds, and the escalation protocols should reflect that profile. A one-size-fits-all subscription does not do that work for you.

Related practices

Frequently asked questions

What are the steps to set up effective screening under OFSI?
Effective OFSI screening requires five foundational steps: integrate a real-time or near-real-time feed from the OFSI Consolidated List; apply the UK ownership-and-control test to all counterparty structures, not only named entries; build a documented match-resolution process with clear escalation triggers; implement trigger-based rescreening for material business events; and maintain records sufficient to demonstrate the programme's calibration and consistent application to OFSI. Technology is a component, not a substitute for this structure.
What is the most common mistake in name and entity screening?
The most common mistake is treating a clear name-screen result as the end of the analysis. Firms regularly clear a counterparty against the OFSI Consolidated List and proceed without applying the ownership-and-control test to the layers above. A counterparty that passes a name screen can still be subject to UK financial sanctions if a designated person controls it – through majority ownership, board appointments, or contractual dominance. That analysis requires ownership data and legal judgment, not only a database query.
How does OFSI differ from other regimes here?
OFSI's ownership-and-control test is broader than OFAC's mechanical 50 percent ownership rule because it includes a control limb: an entity can be caught even where no designated person holds majority ownership, if a designated person exercises practical control. The EU equivalent is functionally similar, but the EU list and the UK Consolidated List are separate instruments and can diverge in their coverage. Firms with cross-border exposure must screen against both independently and assess control under each regime's own standard.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.