Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Name and entity screening under OFSI: procedure and pitfalls

A UK-regulated payments firm receives a transfer instruction from a corporate client. The beneficial owner matches a name on the OFSI Consolidated List – or does it? The name is a partial match, the spelling differs by one character, and the nationality field is blank. Stopping the payment costs the client a commercial opportunity. Releasing it may breach a statutory prohibition that carries both civil and criminal consequences. This is not an edge case. It is the daily reality of name and entity screening under OFSI, and the decision window is short.

Effective name and entity screening (the systematic process of checking individuals, companies, and other entities against sanctions lists before entering into or continuing a transaction) under OFSI requires a structured, documented procedure: confirm the applicable list, apply a calibrated match-rate threshold, investigate potential hits, determine whether ownership and control (the UK test for capturing non-listed entities connected to a designated person) extends the prohibition, and record the outcome. A false negative can constitute an unreported breach; a false positive triggers de-risking costs and compliance liability of its own.

This guide sets out the procedure step by step, identifies the most common operational pitfalls, and compares the OFSI position with the parallel tests under OFAC and the EU so that cross-border businesses can manage divergence rather than be caught by it.

Step 1: Identify the applicable OFSI list and legal basis

Screening under OFSI begins with the correct list – and in the UK there is more than one. The OFSI Consolidated List (the primary instrument, updated in near-real time on the UK government's financial sanctions register) covers all persons designated under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the thematic regulations made under it. A separate UN-derived list may apply concurrently for entities captured by Security Council resolutions implemented into UK law. Both must be checked.

The legal basis for the prohibition differs by list. For SAMLA-derived designations, the obligation is statutory: no UK person and no person in the UK may make funds or economic resources available to or for the benefit of a designated person, directly or indirectly. For UN-derived measures, the same broad reach applies, but the licensing routes differ. Knowing which legal basis applies to a specific match is not a formality – it determines the licence pathway, the reporting obligation, and the defence available if a breach is later alleged.

In our cross-border practice, we regularly advise businesses that screen only one list. That is a systematic gap. A counterparty may be designated under a thematic UK regulation but not yet appear on the consolidated list extract that a screening tool ingests, because update frequencies vary between providers and the official register. The raw legal position is the register; third-party tool delays are a compliance risk, not a safe harbour.

Step 2: Set a calibrated match-rate threshold

OFSI does not mandate a single numerical match-rate threshold for name screening; the obligation is to take reasonable steps to avoid a breach, and what is reasonable is assessed against the risk profile of the business and the transaction. That flexibility is, paradoxically, the source of one of the most common compliance failures we encounter.

A threshold set too high (say, requiring a near-exact name match) will produce false negatives on transliterated names, Arabic or Cyrillic script variants, diacritical differences, and aliases. A threshold set too low will flood compliance teams with false positives, creating alert fatigue – and alert fatigue, in practice, is one of the principal causes of genuine hits being cleared without adequate investigation.

Calibration requires a minimum of three decisions. First, what script-normalisation logic applies: does the tool transliterate names before comparison, and does it apply a standardised transliteration scheme? Second, what fuzzy-match algorithm is in use, and has it been tested against the specific name-types common in the firm's counterparty population? Third, at what alert level does a potential hit escalate from an automated rule to a human reviewer? Each of these decisions should be documented, reviewed periodically, and tested against known-match datasets. Have you tested your screening tool against the aliases listed on the OFSI Consolidated List for your highest-risk counterparty categories?

Step 3: Investigate a potential hit before clearing or escalating

A potential hit is not a confirmed match, and a confirmed match is not always a prohibition – but neither can be cleared on the basis of a superficial name check alone. The investigation step is where most operational failures occur, and it is the step that OFSI scrutinises most closely in enforcement reviews.

For individual counterparties, the investigation should confirm at minimum: full name and any known aliases, date of birth, nationality and country of residence, and any identification number where available. For corporate counterparties, the investigation should map the full ownership chain: who owns the entity, at what percentage, and whether any owner or controller appears on a relevant list.

This is where the OFSI ownership and control test becomes critical. Under the relevant thematic regulations made under SAMLA, a non-designated entity is captured by the prohibition if it is owned or controlled by a designated person. Ownership means holding, directly or indirectly, more than 50 percent of the shares or voting rights, or the right to appoint or remove a majority of directors. Control is a broader concept: it can be established through contractual arrangements, economic dependency, or effective operational dominance, even without a majority shareholding. The control limb is the harder test to apply, and it is where investigation must go beyond company registry data.

In a recent matter, a financial institution's screening flagged a corporate counterparty as a potential hit on a partial name match. The name was a common variant spelling of the listed person's name, and the entity's registered jurisdiction was a standard commercial location. Initial review suggested a false positive. Extended investigation revealed a majority shareholding held through two intermediate holding companies in separate jurisdictions, both ultimately tracing to a designated individual. The institution paused the transaction, made the required report to OFSI, and applied for a specific licence. Without the extended ownership investigation, the transaction would have proceeded – and the breach would have been unreported.

How does the OFSI ownership test compare with OFAC and the EU?

The OFSI ownership and control test diverges from the parallel tests under OFAC and EU sanctions in ways that matter for cross-border businesses operating under multiple regimes simultaneously. Understanding the divergence avoids both under-compliance and unnecessary over-blocking.

Under OFAC, the relevant rule is the 50 percent rule (OFAC's rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked, whether or not the entity is separately listed). The OFAC test is mechanical: aggregate the direct and indirect ownership by blocked persons, and if the combined holding reaches or exceeds the threshold, the entity is blocked. Control, in the OFSI and EU sense, is not a separate limb under OFAC – the ownership arithmetic decides the question.

Under EU sanctions (the relevant Council regulation applicable to each thematic programme), the position is closer to OFSI: both ownership above 50 percent and control through other means can capture a non-listed entity. The EU General Court has addressed the scope of the control test in a number of annulment proceedings, confirming that structural control and effective control are distinct grounds and that either can suffice. In our experience advising on EU-UK divergence post-transition, the practical difference is that OFSI's guidance on the control limb is less elaborated than the body of EU General Court authority. That creates interpretive uncertainty for businesses that need a single consistent answer across both regimes.

For a business operating across the US, UK, and EU, the result is that an entity may be blocked under one regime and not another. The stricter prohibition governs for any transaction element subject to that regime's jurisdiction. A US-person employee of a UK firm, for example, brings OFAC jurisdiction to an otherwise UK-law transaction. Screening and the ownership investigation must reflect the most demanding applicable test.

The position above covers the standard structural comparison. Your specific transaction – the counterparty's ownership chain, the goods or services involved, the bank clearing the payment – will change the analysis. For an assessment of your screening procedure against the applicable regimes, contact Calder & Vance at info@caldervance.com.

Step 4: Record-keeping and the reporting obligation

Screening generates two distinct obligations once a match is confirmed or a suspicion arises, and businesses that treat the two as optional or sequential rather than mandatory and immediate expose themselves to a separate category of enforcement risk.

The first obligation is a freeze. Where a firm determines that it holds funds or economic resources belonging to, owned by, held by, or controlled by a designated person, those assets must be frozen immediately. The prohibition is self-executing: it does not require a direction from OFSI, and the firm cannot wait for OFSI confirmation before acting.

The second obligation is a report to OFSI. Under the relevant thematic regulations, an asset freeze report must be submitted to OFSI as soon as practicable. OFSI's published guidance indicates that it expects this report to be made promptly; significant delay – even delay attributable to internal escalation processes – has been treated as an aggravating factor in enforcement assessments. The report must describe the nature of the assets, the basis for the belief that the prohibition applies, and the steps taken to freeze.

Record-keeping is the evidence base for both the freeze decision and the report. Every step of the screening process – the list version consulted, the match rate generated, the investigation steps taken, the ownership mapping completed, the decision made, and by whom – must be documented and retained. OFSI can request this documentation in any subsequent review, and the quality of the record directly affects whether a firm can demonstrate the reasonable steps required to avoid liability or to support a favourable enforcement outcome.

If a transaction has already been released without adequate investigation, or a report has not been made when one was required, an early review of the position preserves options that narrow significantly with time. For a confidential review of a potential breach, contact us at info@caldervance.com.

Step 5: Apply for a specific licence where a transaction is blocked

A confirmed prohibition does not always mean a transaction cannot proceed. OFSI has the power to grant a specific licence (a case-by-case authorisation permitting an otherwise prohibited transaction) under a set of licensing grounds that vary by thematic programme. Common licensing grounds across the UK regimes include humanitarian assistance, legal expenses, and basic living expenses for designated individuals; specific thematic programmes contain additional grounds tailored to their scope.

The specific-licence application must be submitted to OFSI in the form it specifies, with supporting evidence. OFSI's published guidance sets out its approach to processing and the factors it considers. Processing times are not uniform across programmes or application types; more complex or novel cases take longer. Businesses that need to maintain a commercial relationship with a counterparty connected to a designated person – for example, through a pre-existing contract with a non-designated but controlled entity – should seek legal advice on whether a licence ground is arguable before assuming the deal is dead.

OFSI may also issue general licences (standing authorisations permitting a defined category of transactions without a separate application) for specific purposes in specific programmes. General licences are programme-specific, time-limited, and often carry reporting conditions. A business relying on a general licence must confirm that it squarely covers the transaction in question and that any conditions attached are met. Assumptions about scope have been a recurring source of compliance failures in our practice.

Common pitfalls and risk flags in OFSI screening programmes

Experience across financial institutions, payment processors, and multinational corporates shows that OFSI screening failures cluster around a small number of recurring patterns. Knowing these patterns allows compliance teams to test their own procedures against them before an enforcement review does it for them.

List currency gaps. Screening against a list that is not updated in near-real time creates a window during which a newly designated counterparty is invisible to the screening tool. The OFSI Consolidated List is updated without notice. Automated feeds from the official source, with a defined maximum update lag, are the minimum standard for regulated businesses and are increasingly expected of unregulated businesses with significant sanctions-exposure sectors.

Alias blind spots. The OFSI Consolidated List includes aliases for designated individuals and entities. Screening tools that match only the primary name and not the alias field will miss a material proportion of true positives. This is particularly common for designations of individuals who routinely operate under anglicised or transliterated name variants.

Partial ownership mapping. The ownership and control test requires mapping the full chain, not only the immediate counterparty. Stopping at the first layer of ownership is a systematic gap for corporate counterparties in jurisdictions with limited public registry data. Enhanced due diligence processes – including commercial data providers, adverse media, and direct information requests – are necessary for higher-risk counterparties.

Alert fatigue from miscalibrated thresholds. As noted above, a threshold that generates excessive false positives is itself a compliance risk. When reviewers clear alerts routinely without substantive investigation, the screening programme stops functioning as a control. Periodic false-positive audits and alert-quality metrics are a structural corrective.

Inadequate documentation of clear decisions. OFSI can review not only the decisions to freeze or report but also the decisions to clear. A clear decision that is not documented – or that is documented with a single line stating "reviewed, no match" without supporting reasoning – cannot demonstrate the reasonable steps required under the statute. Document the basis for every clear decision, including the version of the list consulted and the investigation steps taken.

Myth: if a counterparty is not on the OFSI list, there is no screening obligation. This is incorrect. The ownership and control test can capture an entity that is not itself designated. The obligation is to screen and investigate, not merely to check for a direct list hit. Compliance programmes that treat a "not on list" result as a complete clearance miss the second stage of the analysis entirely.

Related practices

Frequently asked questions

What are the steps to set up effective screening under OFSI?
Effective OFSI screening requires five sequential steps: confirm the applicable list or lists and their update frequency; set a calibrated match-rate threshold documented by reference to your counterparty population and risk profile; establish an investigation procedure for potential hits that includes full ownership and control mapping; define escalation, freeze, and reporting pathways with clear ownership and timelines; and maintain comprehensive records of every screening decision, including clear decisions, for the period required under the applicable regulations. Periodic testing against known-match datasets is a structural requirement, not an optional exercise.
What is the most common mistake in name and entity screening?
The most common mistake is treating a direct list check as a complete screen. A counterparty that does not appear on the OFSI Consolidated List may nonetheless be captured by the ownership and control test if a designated person holds or controls it. Stopping the screen at the first-layer name match – without mapping the ownership chain and assessing the control limb – produces a systematic false-negative risk for corporate counterparties. This gap is the single most frequently identified deficiency in compliance reviews that we conduct across financial institutions and corporate treasuries.
How does OFSI differ from other regimes here?
OFSI's ownership and control test has a broader qualitative control limb than OFAC's purely mechanical 50 percent ownership arithmetic. OFAC blocks an entity when blocked persons own 50 percent or more in the aggregate; OFSI can capture an entity through control even where the designated person's ownership share is below majority. The EU position is broadly similar to OFSI on the control limb but is supported by more developed General Court authority. For cross-border businesses, the practical consequence is that OFSI may capture entities that pass an OFAC ownership screen, requiring separate analysis for each applicable regime and a conservative position where they diverge.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.