Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · cross-border

Payment-processing controls across regimes: a compliance guide

A payment operations team at a mid-sized trading house runs its morning batch. Three transfers flag against a screening watchlist. One involves a correspondent bank whose ultimate parent appears on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). Another involves a beneficiary whose controlling shareholder was designated under the relevant EU Council regulation three weeks earlier. The third is a routine supplier payment – but the routing goes through a jurisdiction subject to a comprehensive US programme. Three flags. Three different regimes. Three different consequences.

As of August 2026, payment-processing controls under a cross-border footprint must be calibrated against at least four major regimes simultaneously: OFAC, OFSI, the EU Council regulations, and – for firms routed through correspondent networks – the secondary-sanctions exposure that US dollar clearing creates. No single screening tool or policy solves this without a deliberate, regime-by-regime control architecture. This guide sets out how to build one.

The sections below move from the governing authorities and their obligations, through the practical screening and decision sequence, to cross-regime divergence points, common control failures, and the triggers that make early legal review essential.

Step 1: Map the authorities and their reach before you build any control

The first step in designing payment-processing controls for a cross-border business is to identify every sanctions authority whose rules can reach a given payment – not only the authority in your own jurisdiction. This is the most consequential design decision you will make, and it is the one most often skipped.

Under IEEPA and the associated OFAC regulations, US sanctions have explicit extraterritorial reach wherever a US person is involved, wherever a transaction is denominated in US dollars and cleared through a US correspondent, or wherever the counterparty is itself a US-nexus entity. That last category is broader than it looks. A payment between two non-US entities, in euros, can still create US exposure if it involves a blocked person (an entity or individual on the SDN List or subject to a comprehensive OFAC programme). OFAC's position is that US persons – including US financial institutions acting as correspondents – are prohibited from processing that payment.

OFSI, operating under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic UK regulations, applies to any person in the United Kingdom and to UK persons wherever they are. OFSI's ownership-and-control test looks not only at formal shareholding but at the ability of a designated person to direct or influence the entity receiving funds. The EU position, under the relevant Council regulations, is broadly parallel but the specific prohibition and licensing architecture differs by programme.

The practical implication: a cross-border payments operation serving clients in multiple markets must screen every payment against the OFAC SDN List, the OFSI Consolidated List, and the EU Consolidated Sanctions List as a baseline. For firms active in Australia, Canada, Switzerland, Singapore, the UAE, or Japan, the applicable national regime adds further layers. In our experience, firms that design controls around a single dominant regime and treat the others as supplementary tend to discover the gap only after a flag is raised by a correspondent bank – at which point options narrow.

Step 2: Structure the screening logic across list types and ownership chains

Effective payment screening requires structured logic that covers not just name-matching against published lists, but ownership and control analysis at each leg of the payment chain. List-matching alone is insufficient, and regulators in every major regime know it.

Under OFAC's 50 percent rule (the rule treating entities owned 50 percent or more by one or more blocked persons as themselves blocked), an entity that does not appear on the SDN List by name can still be blocked if the aggregate ownership by listed persons meets or exceeds that threshold. The rule aggregates holdings across multiple blocked persons. Two listed persons each holding 26 percent reach the threshold together; neither does alone. Screening tools that flag only direct SDN matches miss this entirely.

OFSI and the EU apply an ownership and control test (the UK and EU standard for whether a non-listed entity is caught through a listed person's formal or effective control). Under this test, an entity majority-owned by a designated person is subject to the relevant prohibition – but the control limb extends further. A designated person who can direct the entity's decisions, whether through contractual rights, board representation, or other means, may bring that entity within the prohibition even at a minority shareholding. This matters for payment decisions because a beneficiary that clears a 50 percent ownership screen can still be caught under the control limb.

What does this mean for screening logic? At minimum, your system must: match against all three primary consolidated lists; apply the 50 percent aggregation test across the ownership chain for each counterparty; and flag for human review any entity where the control question is unresolved. The sequence matters. A purely automated decision on an ownership-chain flag carries real regulatory risk. A voluntary self-disclosure (VSD) – a firm's self-initiated report to the regulator of an apparent violation – is available under OFAC, OFSI, and in most EU member-state enforcement practices, but it is a mitigation tool, not a substitute for a control that works.

Step 3: Design the payment-decision sequence for flagged transactions

When a payment flags against the screening logic described above, the firm enters a decision sequence whose steps – and whose timing – are set by the applicable regime. Getting the sequence wrong is itself a compliance failure.

Under OFAC, a US financial institution that identifies a transaction involving blocked property must block the funds and, as a general matter, report the blocked transaction to OFAC within a short statutory window. The report must contain the information specified in the applicable OFAC regulations. Separately, if a transaction is rejected (not blocked) – for example, because it is prohibited but the property is not blocked – a rejection report is also required. These are distinct obligations and the timelines differ. Because the exact deadlines are subject to programme-specific rules and periodic regulatory update, verify the current position before relying on any specific figure.

Under OFSI, a firm that knows or has reasonable cause to suspect it holds designated-person funds, or has information relevant to a designated person's assets, has a reporting obligation. OFSI's guidance sets out what the report must contain and the channel through which it must be submitted. UK firms should also be alert to the requirement – separate from OFSI – to make a Suspicious Activity Report under anti-money laundering rules where a transaction raises a suspicion of money laundering, which can include sanctions-related flows.

The EU position on blocking and reporting obligations is set at programme level in the relevant Council regulation, implemented by each member state. The procedural rules therefore differ across EU jurisdictions. In practice this means a cross-border payments firm operating through, say, three EU member-state entities will have three overlapping – and not always identical – reporting chains. In our experience, this is one of the least-mapped risks in cross-border payment compliance programmes.

A practical decision sequence for a flagged payment looks like this. First, suspend the instruction and preserve the funds in a holding position while the review runs. Second, identify the applicable regime or regimes (a payment can involve obligations under more than one). Third, assess the ownership and control question, including aggregation. Fourth, determine whether a licence or authorisation exists or can be sought within the available window. Fifth, if the prohibition is confirmed and no licence applies, block or reject in accordance with the applicable regime's requirements and file any mandatory report. Sixth, document each step with a contemporaneous record. Record-keeping obligations under OFAC, OFSI, and the EU regimes require firms to retain documentation of blocked or rejected transactions and licensing decisions for a defined period – verify the current requirement for each regime, as the periods differ.

How does the OFAC treatment of cross-border payments differ from OFSI and EU?

The OFAC regime, the OFSI regime, and the EU sanctions regulations are not interchangeable. They share common goals but diverge in three technically significant ways that directly affect payment-processing controls.

The first divergence is the ownership test. OFAC's 50 percent rule is mechanical: if the arithmetic reaches the threshold, the entity is blocked, regardless of whether any listed person actually controls it in a practical sense. OFSI and the EU add a control limb, which means a minority-owned entity can be caught if a designated person has sufficient influence. For payment screening, this means a counterparty that passes the OFAC 50 percent test may still require a control analysis under OFSI or the EU rules.

The second divergence is how licences and authorisations work. Under OFAC, a general licence (a standing authorisation that permits a defined category of transactions without a separate application) or a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) can permit a payment that would otherwise be blocked. The general licences vary significantly by programme. OFSI issues both general and specific licences under UK regulations; the grounds differ from OFAC's and the process is administered by OFSI directly. EU general authorisations are set at Council-regulation level and implemented nationally, which creates the cross-member-state variation noted above.

The third divergence is the secondary-sanctions risk. OFAC's secondary-sanctions programmes expose non-US firms to designation risk for engaging in significant transactions with designated persons under certain programmes – even if those transactions have no direct US nexus. This risk is distinct from a primary prohibition. A European or Asian payment business that processes a transaction through USD clearing involving a target of a relevant OFAC secondary programme may face exposure not only through the US correspondent bank but as a potential target of secondary designation. The other major regimes – OFSI, the EU, the UN – do not operate secondary-sanctions mechanisms of this kind. For cross-border payments firms, this asymmetry means OFAC secondary-sanctions risk must be assessed separately and cannot be addressed by EU or UK controls alone.

Does your current control architecture treat OFAC, OFSI, and EU prohibitions as equivalent? If so, the control analysis for the control limb – and the secondary-sanctions question – may be producing false negatives.

Step 4: Apply cross-regime licensing strategy where a payment can be authorised

Not every flagged payment is permanently prohibited. In many cases a licence, authorisation, or specific derogation is available – and pursuing one quickly preserves the commercial relationship while maintaining compliance. Knowing when and how to apply is a distinct skill set.

Under OFAC, the licensing enquiry begins by identifying whether any general licence already covers the transaction. General licences in a given programme can authorise categories of payments that might otherwise be prohibited – humanitarian transactions, personal remittances, certain overflight fees, and others – without the need for a separate application. Where no general licence applies, a specific-licence application to OFAC sets out the transaction, the parties, the purpose, and the policy grounds for relief. OFAC's processing times vary by programme and by the complexity of the application. We regularly advise clients on the preparation and submission of specific-licence applications, and in our experience the quality of the initial submission is the single largest determinant of processing time and outcome. No outcome can be guaranteed.

OFSI's licensing regime operates under grounds set out in the relevant UK thematic regulations. The grounds include, among others, prior obligations, extraordinary situations, legal expenses, and personal maintenance. A licence application to OFSI must demonstrate the applicable ground clearly; a vague or incomplete application will be returned. OFSI publishes guidance on its licensing process, and OFSI decisions can in principle be challenged by judicial review before the High Court if the licensing decision is flawed.

At the EU level, the licensing authority is the competent authority of the relevant member state. This means that a payment firm needing authorisation for a payment flowing through three EU jurisdictions may, in practice, need three separate licensing assessments. In our cross-border practice, we co-ordinate these assessments and, where necessary, work with local counsel in the relevant jurisdiction to ensure that applications to each competent authority are consistent and that no gap arises between them.

What are the most common failures in cross-border payment-processing controls?

Five control failures recur across the cross-border payments matters we handle. Each is avoidable, and each has produced enforcement action or regulatory adverse findings in the payment-processing sector.

The first is single-list screening. A compliance programme that screens only against the OFAC SDN List – or only against its home-jurisdiction list – is systematically blind to designations under the other regimes. The firm's USD clearing correspondent will screen against OFAC; that does not satisfy the firm's own OFSI or EU obligations.

The second is shallow ownership analysis. Automated name-matching at the first layer of ownership misses the aggregation required by the 50 percent rule and the control analysis required by OFSI and the EU. In a recent matter, a financial technology firm had a robust name-matching process but no workflow for reviewing beneficial ownership when a partial match was returned. The firm continued processing payments to an entity that was blocked under the 50 percent rule because two listed persons together held the threshold.

The third is stale data. Sanctions lists change frequently. An entity that was clear at onboarding may be designated by the time the next payment is processed. Periodic re-screening at onboarding only is not sufficient. How frequently does your system re-screen existing counterparties against current lists?

The fourth is mis-calibrated fuzzy-matching thresholds. A threshold set too low produces alert fatigue, leading reviewers to clear flags without adequate analysis. A threshold set too high causes true matches to pass unnoticed. Both are control failures, and both have been cited in enforcement outcomes.

The fifth is undocumented decisions. A firm that clears a flag after a human review but keeps no record of the analysis – the list checked, the ownership information reviewed, the reasoning for the clearance – cannot demonstrate reasonable care if the decision is later challenged. Contemporaneous records are the foundation of any enforcement defence, and of any VSD filing. Five years is a widely cited record-keeping benchmark for sanctions-related documentation; verify the current requirement for each applicable regime before setting your retention policy.

When should a cross-border payments firm involve sanctions counsel?

There are six situations in which a cross-border payments business should involve specialist sanctions counsel promptly rather than treating the issue as a routine compliance matter.

The first is a correspondent bank freeze or query. When a USD correspondent holds a payment and raises a sanctions question, the clock is running. The correspondent needs a response, and the underlying facts need rapid legal analysis. We regularly advise on these situations and can provide a same-day preliminary view on the applicable regime and the options.

The second is an OFAC, OFSI, or EU apparent-violation finding. If an internal review concludes that a payment was processed in apparent violation of a sanctions obligation, the voluntary self-disclosure question must be assessed immediately. A VSD – submitted before the regulator initiates its own enquiry – is a significant mitigating factor under OFAC, OFSI, and most EU enforcement frameworks. The window to make that choice is short.

The third is a licensing requirement in a complex cross-border transaction. Licence applications that involve multiple regimes, novel fact patterns, or humanitarian grounds benefit from structuring by counsel familiar with each authority's stated policy.

The fourth is a material change in the ownership or control of a key counterparty. A merger, acquisition, or restructuring that alters who ultimately controls a counterparty can change the sanctions analysis overnight. Proactive review before the transaction closes is almost always cheaper than a post-closing remediation.

The fifth is a designation affecting your own entity. If your firm, a group entity, or a key director is designated or is under investigation, the payment-processing obligations of every counterparty change immediately. This is a category where early legal engagement is essential.

The sixth is a programme review or audit by a correspondent bank or a regulator. Requests for information about your sanctions controls, your screening logic, or your historical payment records require a coordinated response that does not inadvertently create new exposure.

The position above covers the standard patterns. Your facts – the counterparties, the currencies, the clearing routes, the jurisdictions in play – change the analysis. If a payment has already been flagged, or a correspondent bank has asked questions, early review preserves options that narrow with time.

For a review of your payment-processing controls across regimes, contact Calder & Vance at info@caldervance.com.

Related practices

Frequently asked questions

What are the steps to control sanctions risk in payments under cross-border?
Controlling sanctions risk in cross-border payments requires five sequential steps. First, identify every regime whose rules reach each payment leg. Second, screen every party and intermediate entity against all applicable consolidated lists, applying the 50 percent aggregation test and the control limb. Third, when a flag is returned, suspend the instruction and begin the decision sequence – regime identification, ownership analysis, licence availability. Fourth, block or reject as required by each applicable regime and file any mandatory report within the required window. Fifth, document every decision contemporaneously and retain records for the full required period under each regime.
What is the most common mistake in payment-processing controls?
The most common mistake is designing the control around a single regime – typically OFAC or the firm's home-jurisdiction list – and treating the others as secondary checks. This produces systematic blind spots: an entity blocked under the EU control limb but not on the OFAC SDN List will pass an OFAC-only screen. Equally, ownership-chain analysis that stops at the first layer misses the 50 percent aggregation that OFAC requires and the control analysis that OFSI and the EU apply. Alert-fatigue from mis-calibrated fuzzy-matching thresholds, and stale counterparty data, compound the problem.
How does cross-border differ from other regimes here?
A cross-border payments operation faces a layered exposure that a single-jurisdiction firm does not. The OFAC regime adds a secondary-sanctions dimension – the risk of designation for non-US firms that engage in significant transactions with certain designated persons, even without a US nexus – that the EU and UK regimes do not replicate. At the same time, OFSI and the EU apply a control limb in their ownership tests that goes beyond OFAC's mechanical 50 percent threshold. Licensing grounds, reporting timelines, and enforcement approaches also differ materially across regimes. A control designed for one jurisdiction will have gaps when applied to payments that touch three or four simultaneously.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.