Calder & Vance International Sanctions & Compliance Counsel

Licensing & Authorizations · OFAC

Payment authorisations under OFAC: procedure and pitfalls

A treasury team at a mid-sized trading company receives a payment instruction. The beneficiary is not on any list. The correspondent bank, however, is a US-dollar clearing institution, and somewhere in the payment chain a sanctions concern has been raised. The transaction is blocked. The business has days to respond – and no clear protocol for what happens next.

Payment authorisations under OFAC are the mechanism by which a US person, or any entity using US financial infrastructure, seeks a lawful basis to process an otherwise prohibited payment. The two routes are a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) and a general licence (a standing authorisation that permits a defined category of transactions without a separate application). Identifying which route applies – and acting within the applicable window – determines whether value is recovered or permanently blocked.

This guide sets out the governing rules, the step-by-step procedure for each route, the cross-regime comparisons that matter most for businesses with multi-jurisdiction exposure, and the risk flags that cause applications to fail.

What is the legal basis for OFAC payment authorisations?

OFAC administers US economic sanctions under the authority of IEEPA and, for older programmes, TWEA; its licensing powers derive directly from those statutes and from the programme-specific regulations issued under them. Every blocked payment – whether blocked at a US correspondent bank, at a US-owned subsidiary, or by a US person anywhere in the world – falls under OFAC's jurisdiction. The question is not whether the transaction can proceed, but whether a lawful authorisation exists.

The starting point for any payment authorisation analysis is programme identification. OFAC administers distinct programmes, each with its own regulations and its own general-licence catalogue. A payment that is authorised under one programme may be prohibited under another if a different sanctions nexus exists. In our experience, businesses with multi-regime exposure frequently analyse a payment under the most visible programme and miss a second, equally applicable designation. That is an avoidable error, and it is one that a structured legal review catches before the payment is processed.

General licences are published as part of the programme regulations and require no application. They operate by self-certification: the paying party reviews the conditions, satisfies itself that each condition is met, records that analysis, and processes the payment. Specific licences require a written application to OFAC. OFAC is not bound to a statutory decision period, though published guidance indicates a target review window; applications for complex transactions routinely take longer, and OFAC may return an application with questions before reaching a decision.

Step 1 – Identify the sanctions nexus before anything else

Before any authorisation route can be identified, the sanctions nexus must be located precisely. Is the blocked party the originator, the beneficiary, or an intermediate entity in the payment chain? Is the nexus a US-dollar clearing step, a US correspondent bank, or a US-person employee approving the instruction? The answer changes both the applicable programme and the applicable authorisation route.

Tracing the nexus is not a screening exercise. Screening confirms that a named party appears on a list. Nexus analysis asks why the payment is restricted, through which legal mechanism, and at which point in the chain the restriction bites. These are distinct analytical tasks, and conflating them is one of the most common procedural errors we see. A payment may be restricted because a beneficial owner – not the named counterparty – is a Specially Designated National (an SDN, a person on OFAC's list of Specially Designated Nationals and blocked persons). That fact will not appear in a surface-level screening result.

Apply the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked, whether or not those entities are named on the SDN List) at this stage. If a beneficial owner of the counterparty reaches that threshold, the counterparty is treated as blocked, and the payment authorisation analysis must proceed accordingly. This aggregation step is where non-US businesses most frequently underestimate their exposure.

Step 2 – Check whether a general licence already covers the payment

General licences are the fastest route to a lawful authorisation, and they are often overlooked in favour of a specific-licence application. The correct sequence is always to check the general-licence catalogue for the relevant programme first. A specific-licence application submitted when a general licence was available is both unnecessary and, in some circumstances, a signal to OFAC that the applicant's internal compliance review is incomplete.

General licences commonly cover categories including personal remittances, emergency humanitarian transactions, legal services, certain intellectual-property transactions, and wind-down periods following a new designation. The conditions attached to each licence are specific: payment caps, currency restrictions, reporting requirements, and exclusions for certain categories of SDN. Every condition must be met. A general licence does not authorise the transaction if a single condition is absent.

Record-keeping is non-negotiable at this stage. OFAC regulations require that records of transactions conducted under a general licence are maintained. The standard period cited in the regulations is five years. That record must be complete enough to demonstrate, in a later enforcement review, that each condition of the licence was satisfied at the time of the transaction. Businesses that process payments under general licences without contemporaneous documentation create the exact evidential gap that an enforcement review will exploit.

The position above covers the standard case. Your facts – the counterparty, the currency, the payment route, the programme in play – change the analysis. To assess which general licences are available for your transaction, contact Calder & Vance at info@caldervance.com.

Step 3 – Prepare and submit a specific-licence application

Where no general licence applies, a specific-licence application to OFAC is the only lawful route to process the payment. The application is submitted through OFAC's licensing portal and must contain, at minimum: a clear identification of the applicant and all parties to the transaction; a description of the goods, services, or funds involved; the sanctions nexus and the relevant programme; the requested authorisation in precise terms; and a statement of the policy basis on which OFAC should grant the licence.

The policy basis is the part of the application that most often receives insufficient attention. OFAC has published policy statements on which categories of transaction it views favourably – humanitarian considerations, overhang obligations from pre-designation contracts, legal and administrative proceedings, and certain categories of divestiture. Framing the application around an established policy ground materially improves the prospect of approval and reduces the likelihood of a return-with-questions. In our cross-border practice, applications that engage with the policy record in detail move through review more predictably than those that describe only the commercial facts.

Once submitted, the application is assigned to an OFAC licensing officer. OFAC may seek additional information. Providing a thorough, well-organised response to any OFAC query – promptly and without omission – is critical. An incomplete response extends the review period and, in some programmes, may be treated as a signal that the licence request lacks a sound basis. Where a transaction has a genuine time constraint, OFAC may accept a request for expedited review, though there is no guarantee that the timeline will be shortened.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss the position.

How does OFAC differ from OFSI, the EU, and other regimes on payment authorisations?

For any business operating across more than one jurisdiction, the divergence between OFAC's payment authorisation rules and those of OFSI (the UK's Office of Financial Sanctions Implementation) and the EU Council regulations is not a technical footnote – it is a material operational risk. A payment authorised by OFAC under a general licence may still require a separate specific licence from OFSI if the transaction involves a UK credit institution or a UK person. The regimes do not grant mutual recognition.

Three divergences are particularly significant in practice. First, the ownership and control test: OFAC's 50 percent rule is a bright-line ownership test. OFSI and the EU apply an ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person) that includes de facto control, direction, and influence – a broader and inherently more judgement-dependent analysis. A counterparty that passes the OFAC 50 percent test may still be caught under OFSI or EU rules.

Second, the licensing procedure: OFSI operates a specific-licence process with a defined statutory framework under SAMLA (the Sanctions and Anti-Money Laundering Act 2018). The EU operates through national competent authorities, each of which applies the Council regulation but may have procedural differences in how applications are handled and how quickly decisions are reached. Neither regime has an equivalent to OFAC's general-licence catalogue for most sanctions programmes, though both publish certain standing authorisations for defined categories.

Third, secondary-sanctions risk: a non-US bank processing a payment between two non-US parties, using non-US currency, may nonetheless be exposed to US secondary-sanctions risk if the transaction involves a designated entity in a programme where OFAC has announced a secondary-sanctions posture. That risk does not arise under OFSI or EU rules in the same way. We regularly advise non-US financial institutions on secondary-sanctions exposure precisely because the extraterritorial reach of OFAC's programmes is routinely underestimated.

Where a payment involves parallel obligations under OFAC, OFSI, and the EU, the stricter prohibition governs. Obtaining authorisation under one regime does not discharge the obligation to analyse and, where required, obtain authorisation under each other applicable regime.

What are the common risk flags that cause payment authorisations to fail?

Most specific-licence applications that are denied, or that are returned with substantial questions, share a small number of identifiable failure modes. Recognising them in advance – before the application is submitted – is the most effective way to improve the outcome.

The most frequent risk flag is an incomplete nexus analysis. An application that misidentifies the programme, fails to address the 50 percent rule in the ownership chain, or applies for an authorisation under a programme that does not cover the transaction will be returned or denied. OFAC's licensing officers are experienced practitioners; an application that mischaracterises the legal basis of the restriction signals a compliance programme that has not performed adequate due diligence.

A second common failure is an insufficient policy basis. Applicants who describe the commercial facts in detail but do not identify and engage with OFAC's published policy grounds for the type of transaction are asking OFAC to construct the policy argument on their behalf. That is not how the process works. The policy basis must be stated by the applicant, supported by evidence, and connected to the category of transaction OFAC has indicated it will consider.

Third: missing or incomplete supporting documentation. OFAC routinely requests contracts, payment records, corporate ownership charts, and evidence of the applicant's compliance programme. Applicants who do not assemble this documentation before submitting create delays that, in time-sensitive transactions, can be fatal to the deal. We have acted for businesses where the primary obstacle to a successful licence was not the legal merits of the application, but the absence of organised records that the applicant should have had at hand. Do you have a documentation protocol that would support a licence application on short notice?

Fourth, timing. A specific-licence application submitted after a payment has already been processed does not retroactively authorise the transaction. OFAC's licensing process is prospective. Where a payment has been made without authorisation – whether through inadvertence or a gap in the screening process – the relevant mechanism is a VSD (voluntary self-disclosure to a regulator), not a retroactive licence. Those are governed by different procedures and carry different risk profiles.

When should a business involve sanctions counsel?

Sanctions counsel should be involved at the point where the sanctions nexus is identified, not after the application has been submitted or the transaction has been processed. The difference in outcome between a well-prepared application and a reactive one is substantial.

A common myth in this area is that OFAC payment authorisations are a form-filling exercise that an in-house team can manage without specialist support. They can be, for a straightforward transaction where a general licence clearly applies and the conditions are unambiguous. For any transaction involving: a novel or complex ownership chain; a party designated under multiple programmes; a concurrent OFSI or EU licensing obligation; a time constraint; or a secondary-sanctions dimension, that assumption is wrong. The application is a legal document that will be reviewed by enforcement-experienced officers. It should be prepared to that standard.

In a recent matter, a financial institution identified a payment that had been processed under a general licence but where one condition of that licence had not been documented at the time of the transaction. We assessed the exposure, prepared a VSD submission, and structured the remediation programme to address the systemic documentation gap. The matter was resolved without escalation to formal enforcement proceedings. Outcomes of that kind are not guaranteed – but early, structured intervention consistently produces better results than late, reactive response.

Related practices

Frequently asked questions

What are the steps to authorise a restricted payment under OFAC?
The procedure has four stages. First, identify the sanctions nexus precisely and confirm which OFAC programme applies. Second, check whether a general licence already covers the payment and satisfies each of its conditions. Third, if no general licence applies, prepare and submit a specific-licence application through OFAC's portal, with a clear policy basis and full supporting documentation. Fourth, maintain records of the analysis and the authorisation for at least five years. Where the transaction also involves a UK or EU nexus, a parallel licensing analysis under OFSI or the relevant national competent authority is required.
What is the most common mistake in payment authorisations?
The single most common mistake is treating screening as equivalent to a sanctions analysis. Screening confirms whether a named party appears on a published list. It does not apply the 50 percent rule to the full beneficial-ownership chain, identify secondary-sanctions risk, or determine which general licence applies. Businesses that rely on a screening result as the authorisation analysis – without a structured legal review of the ownership chain and the applicable programme – routinely miss the restriction that matters most.
How does OFAC differ from other regimes here?
OFAC differs from OFSI and the EU in three material ways. First, OFAC uses a bright-line 50 percent ownership threshold; OFSI and the EU apply a broader ownership and control test that includes de facto influence. Second, OFAC maintains an extensive general-licence catalogue for most programmes; OFSI and EU competent authorities are more reliant on specific authorisations. Third, OFAC's secondary-sanctions posture can expose non-US entities to restriction even where no US person or US-dollar step is involved – a risk that does not arise in the same form under OFSI or EU rules.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.