Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · cross-border

Payment-processing controls across regimes: step by step

A payment operations team at a mid-size trading company receives a wire instruction from a correspondent bank. The beneficiary name is a close match to an entry on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The instruction also routes through a jurisdiction subject to a secondary-sanctions advisory. The team has minutes to decide. Is this a block, a hold, a rejection, or a false positive?

Payment-processing controls under a cross-border footprint require a layered, sequential approach: screen at the point of instruction, apply the ownership and control tests of each relevant regime, determine the governing prohibition, and act within the statutory reporting window. As of August 2026, firms operating across US, UK, EU, and Asia-Pacific regimes face materially different obligations at each stage – and the strictest prohibition governs the transaction.

This guide walks through the required steps, identifies where major regimes diverge, and explains when a business must involve sanctions counsel rather than resolve the question internally.

Step 1: Identify which regimes apply to your payment

Before any screening takes place, a firm must establish which sanctions regimes have jurisdiction over the specific transaction. Jurisdiction is not limited to the location of the payer or payee. It extends to the currency of the transaction, the routing banks, the nationality of the parties, and the nature of the underlying goods or services.

US dollar transactions clear through US correspondent banks, bringing OFAC's rules into play regardless of where the instructing firm is incorporated. That extraterritorial reach is one of the most consequential features of the US regime. A European firm sending a dollar payment between two non-US counterparties can still trigger an OFAC obligation if the payment clears in New York.

UK and EU rules apply to persons and entities within their jurisdictions, to conduct within their territories, and – for UK rules under the Sanctions and Anti-Money Laundering Act ("SAMLA") – to UK persons wherever located. EU Council regulations bind EU nationals and entities globally, as well as any transaction conducted in whole or in part in EU territory. The practical consequence is that a single cross-border payment can attract simultaneous obligations under OFAC, OFSI, and one or more EU Council regulations.

Singapore's MAS, Japan's METI and MOF, the UAE's CBUAE and SCA, Australia's DFAT, Canada's GAC, and Switzerland's SECO each operate distinct regimes. Where a transaction touches those jurisdictions – through a local entity, a local currency, or a local routing bank – their rules add a further layer. In our experience, many compliance teams map the counterparty but not the payment route. The route is where the exposure hides.

Practical step: before screening, complete a jurisdiction map for each payment type in your book. Record the currency, every routing institution, the location of the paying and receiving entities, the nationality of their ultimate beneficial owners, and the nature of the underlying transaction. That map tells you which watchlists to run and which ownership tests to apply.

Step 2: Screen counterparties, intermediaries, and underlying parties

Effective screening means checking all parties to the payment – not only the named payee – against the consolidated lists of every applicable regime. That includes the instructing party, the beneficiary, intermediary and correspondent banks, the ultimate beneficial owner where known, and any named underlying customer in a commercial payment.

The core US list is the SDN List, maintained by OFAC. BIS maintains a separate Entity List (a list of entities for which a licence is required for specific exports) and the Denied Persons List. The UK uses OFSI's financial-sanctions list, updated under SAMLA regulations. The EU maintains its own consolidated list under the relevant Council regulations. The UN Security Council Consolidated List is the baseline for most national regimes. Switzerland (SECO), Canada (GAC), Australia (DFAT), Japan, Singapore, and the UAE each publish national lists.

Screening quality is the first control failure point. Common deficiencies include: running only the UN list rather than regime-specific lists; failing to screen intermediary banks; using name-matching logic that misses transliteration variants and aliases; and screening at the point of onboarding but not at the point of each transaction. Regime obligations differ on the frequency requirement – some require transaction-by-transaction screening, others periodic refresh – but the standard of practice for cross-border payments is transaction-level screening across all applicable lists.

Where a firm uses an automated screening tool, it must understand the tool's matching logic, threshold settings, and list-coverage. A tool set to a high fuzzy-match threshold will reduce false positives but increase the risk of missed true positives. We regularly advise firms that discover their screening configuration was set for operational convenience rather than regulatory compliance. The discovery is rarely pleasant.

Practical step: document which lists your screening tool covers, the match-score threshold in use, and the rationale for that threshold. Review the configuration at least annually and whenever a new regime becomes applicable to your payment flows.

Step 3: Apply the ownership and control test for each regime

A counterparty that does not appear on any list may still be caught if it is owned or controlled by a listed person. The test differs across regimes, and applying only one test to a multi-regime payment is a material compliance gap.

Under OFAC, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) is the operative standard. The rule is aggregate: two blocked persons each owning 25 percent of an entity together meet the threshold. The test is mechanical and does not require evidence of actual control. Entities that meet this threshold are treated as blocked even if they do not appear on any published list.

The UK and EU tests are broader. OFSI and the EU Council regulations extend prohibitions to entities owned or controlled by a designated person. Control is assessed qualitatively: whether the designated person can direct or influence the entity's activities, not only whether they hold a specified ownership percentage. An entity owned at 40 percent by a designated person may still be caught if the ownership structure gives that person effective control.

Japan, Singapore, and the UAE follow ownership and control standards that broadly track the UN approach, but with local procedural variations. Where a transaction involves a counterparty in one of those jurisdictions, the applicable country regime's test must be applied separately.

What happens when the tests produce different results? If the entity clears the OFAC 50 percent rule but is caught by the OFSI control test, the UK prohibition still applies to any UK person or UK-routed element of the transaction. The principle that the strictest prohibition governs applies across the multi-regime analysis.

Practical step: for any counterparty that produces a potential match or that operates in a high-risk ownership structure, run the ownership chain through all applicable regime tests. Document the chain, the test applied, and the conclusion reached. Where the chain is opaque – for example, in nominee-held or trust-structured entities – escalate to compliance counsel before proceeding.

Step 4: Classify the transaction and determine the applicable prohibition

Once the counterparty analysis is complete, the next step is to classify the transaction itself. The prohibition may attach to the counterparty, to the underlying goods or services, to the jurisdiction of destination, or to the currency and routing.

Under OFAC, the prohibitions are transaction-specific: the relevant instruments prohibit dealings in property and interests in property of blocked persons, the provision of services (including financial services) to blocked persons, and – under certain country-specific programmes – any transaction involving a designated jurisdiction regardless of counterparty identity. The EAR (the Export Administration Regulations administered by BIS) adds a parallel layer for payments that relate to controlled-technology transactions.

EU sanctions under the relevant Council regulations distinguish between asset-freezing obligations and broader sectoral restrictions. A sectoral restriction may prohibit a specific type of transaction – such as a capital-market transaction, a loan, or a payment for a specific category of goods – even where neither party is designated. This distinction is frequently underweighted in payment controls designed only around counterparty screening.

UK sanctions under SAMLA and the relevant thematic regulations similarly layer asset-freezing prohibitions on top of sectoral and trade restrictions. OFSI's enforcement guidance notes that firms are expected to understand the full scope of the restriction, not merely to screen names.

Practical step: for each payment category in your business, produce a transaction classification map. Identify whether the prohibition could arise from counterparty status, underlying goods or services classification, jurisdiction of destination, or currency and routing. Flag categories that require enhanced review.

The position above covers the standard case. Your facts – the counterparty, the goods, the route, the regime in play – change the analysis materially. For a confidential assessment of your payment-control exposure across regimes, contact Calder & Vance at info@caldervance.com.

Step 5: Act on the match – block, reject, hold, or release

When screening produces a potential match that survives the ownership and control analysis and the transaction classification, the firm must take a defined, regime-compliant action within the applicable timeframe. The action required depends on which regime governs and what the match produces.

Under OFAC, where property of a blocked person is identified, the obligation is to block the funds – to freeze them in a specifically designated account – and to file a report with OFAC. The reporting obligation arises within a short statutory window; firms must be aware of the applicable deadline under the relevant programme, verify the current position before relying on it, and have a process in place to meet it without manual escalation causing a delay.

OFSI requires firms to report knowledge or reasonable cause to suspect that a person is a designated person, or that a breach of a financial-sanctions prohibition has occurred or is about to occur. The reporting obligation runs to OFSI directly. OFSI's enforcement guidance sets out that prompt reporting is a factor taken into account in enforcement decisions. Record-keeping requirements under OFSI guidance extend to the documents that evidence the match, the decision made, and the steps taken.

EU obligations under the relevant Council regulations similarly require that assets of designated persons be frozen and reported to the competent national authority of the member state. The competent authority varies by member state. For a cross-border payment involving multiple EU entities, the reporting may need to be made to more than one authority.

Where a potential match is identified but the analysis does not confirm designation – a close name match with different identifiers, or an entity that nearly meets the 50 percent threshold – the correct action is to hold the payment, escalate, and complete the analysis before releasing or returning. Releasing a payment on an unresolved match is a material compliance failure. So is holding a clean payment indefinitely. The discipline is in the process.

Practical step: produce a decision matrix for your payment operations team. For each possible outcome of the screening and ownership analysis – confirmed match, probable match, possible match, clear – define the mandatory action, the responsible party, the escalation path, and the documentation requirement. Test the matrix in a tabletop exercise at least once a year.

Step 6: Manage false positives and release processes

False positives are operationally costly and carry their own risk if handled incorrectly. Releasing a payment that is actually a true positive, on the basis of an inadequate false-positive analysis, is an enforcement-grade compliance failure. The release process must be as disciplined as the block process.

The standard for clearing a potential match requires: positive identification that the screened party is not the listed party (different date of birth, different identification number, different address where the list entry provides those details); or confirmation that the listed party does not own or control the screened entity to the degree required by the applicable regime test; or confirmation that the underlying transaction falls within a general licence or other authorisation. Each of these conclusions must be documented and retained.

A general licence (a standing authorisation that permits a defined category of transactions without a separate application) can authorise certain categories of payment that would otherwise be prohibited. General licences are regime-specific, and a general licence under one regime does not authorise the transaction under another. For a multi-regime payment, each applicable regime must be checked separately for an available general licence or other authorisation.

Where no general licence applies and the analysis is not conclusive, the correct step is to seek a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) before proceeding. In our experience, firms that attempt to release payments on a borderline analysis without seeking a specific licence often face the harder question later, in an enforcement context, with fewer options available.

Practical step: document your false-positive release standard. Define the evidence required, the seniority of approval needed, and the retention requirement. Treat releases above a defined risk threshold as requiring sign-off from a senior compliance officer or from legal counsel.

If a transaction has already been flagged, or a payment has been blocked on an unresolved match, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.

Step 7: Record-keeping, programme review, and voluntary self-disclosure

Compliance does not end with the payment decision. Record-keeping, programme review, and – where a breach has occurred – a disciplined approach to voluntary self-disclosure (VSD, the process of proactively reporting an apparent violation to a regulator) are the final steps in a sound payment-control cycle.

Across regimes, the record-keeping standard requires firms to retain the documentation that evidences the screening decision, the ownership and control analysis, the classification of the transaction, the action taken, and any communications with the regulator. Retention periods differ by regime; as a working default for multi-regime operations, retaining records for at least five years covers most major programme requirements, but verify the current position for each applicable regime before relying on any specific period.

Programme review is not optional. Payment-control programmes degrade as counterparty structures change, as new regimes are introduced or extended, and as payment products evolve. A programme designed for correspondent banking may not address the obligations that arise in real-time payments, virtual asset transfers, or embedded finance structures. In our practice, we see compliance programmes that were well-designed at inception but have not been updated to reflect the current regime environment.

Where an apparent violation is identified – a payment that was released, a block that was not filed, a report that was not made – the question of whether to file a VSD arises. Regulators across major regimes, including OFAC and OFSI, treat a timely and thorough VSD as a mitigating factor in enforcement. OFAC's enforcement guidelines treat voluntary self-disclosure as a significant mitigating factor in calculating the base civil penalty. The decision to disclose, and the timing and content of that disclosure, is one of the most consequential compliance decisions a firm can make. It should be made with legal advice, not by the operations team alone.

Practical step: build a periodic programme-review schedule into your compliance calendar. Include a review of the jurisdiction map, the watchlist coverage, the ownership-and-control test methodology, the decision matrix, the record-keeping standard, and the VSD policy. Where a review reveals a gap that may constitute an apparent violation, escalate to legal counsel promptly.

Common mistakes and the myth of single-regime sufficiency

The single most common failure we observe in payment-processing controls is the assumption that compliance with one regime is sufficient for a cross-border payment. A firm that screens only against the OFAC SDN List for a dollar-denominated payment involving EU-incorporated entities and UK-correspondent banks has satisfied, at most, a fraction of its obligations.

A second persistent error is the conflation of the ownership test with the screening result. Screening tells you whether a name appears on a list. The ownership and control analysis tells you whether an unlisted entity is caught by the rules. These are sequential steps, not alternatives. Many compliance programmes treat a clean screening result as the end of the analysis. It is the beginning.

A third failure pattern is the absence of a documented decision matrix for operational staff. Without a defined process, payment decisions under time pressure default to the lowest-risk operational action – usually an indefinite hold – rather than the regime-compliant action. Indefinite holds create their own exposure, particularly where a counterparty has a legitimate claim on timely payment.

The myth that compliance counsel is needed only when something goes wrong is worth addressing directly. By the time a blocked payment generates a regulatory inquiry, the options available to the firm have narrowed significantly. Early engagement – at the point of programme design, at the point of a difficult match, or at the point of a potential breach – consistently produces better outcomes than late engagement in a defined enforcement context.

Related practices

Frequently asked questions

What are the steps to control sanctions risk in payments under cross-border?
The steps are sequential: map which regimes apply to the payment; screen all parties against every applicable watchlist; apply the ownership and control test of each relevant regime; classify the transaction to identify any sectoral or goods-based prohibition; take the correct regime-compliant action on a match within the applicable reporting window; document the decision; and maintain the programme through periodic review. No single step substitutes for the others, and the strictest applicable prohibition governs throughout.
What is the most common mistake in payment-processing controls?
The most common mistake is treating a clean screening result as the end of the compliance analysis. Screening identifies listed names. It does not identify entities owned or controlled by listed persons but not themselves listed – a gap that the 50 percent rule under OFAC and the broader ownership-and-control tests under OFSI and EU regulations are specifically designed to address. Firms that do not perform a separate ownership and control analysis are exposed to a significant enforcement risk that their screening result does not detect.
How does cross-border differ from other regimes here?
A purely domestic payment is subject to one regime and one set of tests. A cross-border payment can simultaneously attract obligations under OFAC (for USD transactions or US-person involvement), OFSI (for UK persons or UK routing), EU Council regulations (for EU entities or EU-routed payments), and one or more Asia-Pacific regimes. The tests, thresholds, reporting windows, and competent authorities differ across each. Where two regimes apply and produce different results, the stricter prohibition governs. That interaction – and the absence of a single harmonised standard – is the defining feature of cross-border payment-sanctions compliance.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.