Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Payment-processing controls under OFSI: what businesses must know

A mid-sized UK payments firm processes thousands of transactions daily. Its screening tool flags a beneficiary name that resembles an entry on the OFSI Consolidated List (HM Treasury's list of persons subject to UK financial sanctions). The transaction is live. The processing window is measured in seconds. What does the business do, what does the law require, and what happens if it gets this wrong?

Payment-processing controls under OFSI are governed by the Sanctions and Anti-Money Laundering Act 2018 ("SAMLA") and the relevant thematic sanctions regulations made under it. Any UK person – and any business processing sterling or operating through UK correspondent infrastructure – must screen payments, freeze funds belonging to designated persons, and report to OFSI. As of August 2026, OFSI holds powers to impose substantial civil penalties and to refer cases for criminal prosecution.

This guide walks through the legal foundation, the operational control sequence, the ownership-and-control test that catches unlisted entities, the most significant cross-regime divergences, common points of failure, and the practical steps for engaging with OFSI when a problem surfaces.

Step 1 – Understand the legal foundation and who it reaches

OFSI enforces UK financial sanctions, and its reach is broader than many businesses expect. The obligation to freeze, not to deal with, and not to make funds available applies to UK persons wherever they are, to bodies incorporated or constituted in the United Kingdom, and to conduct within UK territory. The "making available" limb is critical for payment firms: routing a payment that would benefit a designated person, even as an intermediary, can engage liability whether or not the firm itself is party to the underlying commercial contract.

The legal basis sits in SAMLA and the thematic regulations – the instruments that create the specific prohibitions relevant to each sanctions programme. Those instruments define "designated person", set the scope of the financial restrictions, and create the licensing gateway through which authorised transactions must pass. Understanding which instrument applies to a given counterparty or transaction is the first operational task; the rules are not identical across different UK sanctions programmes, and the prohibited conduct under one programme may differ subtly from another.

For payment-processing firms in particular, the "making funds available" prohibition requires attention to the full payment chain, not only the direct counterparty. In our experience, firms that treat sanctions screening as a bilateral customer-due-diligence exercise, rather than a transaction-level obligation covering payees, intermediary banks, and correspondent relationships, routinely miss exposure that OFSI's enforcement guidance identifies as a priority.

Step 2 – Build the screening control: scope, lists, and matching logic

Effective payment-processing controls begin with screening every payment against the OFSI Consolidated List – and, in most cross-border operations, the SDN List (OFAC's list of Specially Designated Nationals) and the EU Consolidated List simultaneously, because a single payment chain may engage more than one regime. The lists are not identical. A person designated by OFSI may not appear on the SDN List, and vice versa; running only one list is a structural gap.

Matching logic matters as much as list coverage. Name-matching algorithms must account for transliteration variants, abbreviations, aliases, and name-order conventions across scripts. A firm that screens only on exact matches will generate a false-comfort result. Fuzzy matching introduces false positives, which create operational drag – but that drag is manageable, whereas missed matches are not. The calibration of the threshold between these outcomes is a judgment call that should be documented, reviewed periodically, and stress-tested against known alias patterns.

Screening must also cover the ownership chain, not only the named parties to the payment. The next step explains why.

Step 3 – Apply the UK ownership-and-control test

Under UK sanctions regulations, the financial prohibitions extend beyond persons who are themselves listed: they reach entities owned or controlled by a designated person. This is the ownership-and-control test, and it differs meaningfully from the OFAC approach.

Under OFAC's 50 percent rule (the rule treating entities owned 50 percent or more in aggregate by blocked persons as themselves blocked), the test is mechanical: aggregate the ownership percentages and compare against the threshold. OFSI's and the EU's standard is broader. Control can be established without a majority ownership stake. A designated person who can direct the commercial or financial decisions of an entity – through board composition, contractual rights, or other influence – may bring that entity within the prohibition even with a minority shareholding. Determining whether an unlisted entity is caught therefore requires a genuine assessment of governance and decision-making, not only a share-register search.

In our cross-border practice, this divergence causes real operational difficulty. A payment firm that screens against the SDN List using ownership aggregation and concludes a counterparty is clear may be applying the wrong test for UK purposes. The stricter prohibition governs: where OFSI's control test catches an entity that the mechanical OFAC threshold would not, the UK prohibition must be followed for UK-connected transactions. Have you documented which test your controls apply – and confirmed it is the right one for each regime in scope?

Step 4 – Manage a screening hit: the triage and freeze sequence

When a payment screen returns a potential match, the firm faces a time-sensitive decision sequence. The default position under UK financial sanctions is that funds belonging to, held by, or controlled by a designated person must be frozen immediately; there is no grace period to investigate before the obligation bites. The freeze applies to "funds and economic resources" as defined in the applicable regulations, and that definition is broad – it covers payment obligations and credits in transit, not only cash balances.

The triage sequence in practical terms runs as follows. First, assess the match quality: is this a genuine hit or a false positive? Document the analysis in real time, because OFSI may later scrutinise the process. Second, if the match is credible, apply the freeze and take no further action to transfer or make available the funds. Third, notify the relevant internal function – compliance, legal, and senior management as appropriate. Fourth, consider whether a report to OFSI is required.

The reporting obligation under OFSI is separate from the freeze obligation. A regulated-sector business that knows or has reasonable cause to suspect that it holds frozen funds is required to report that fact to OFSI. The timeline for that report is a short statutory window that varies by the specific instrument; firms should verify the current position before relying on any generic statement. Do not assume the same window applies across all UK sanctions programmes.

In a recent matter, a payments-infrastructure business identified a potential match during an intra-day batch run. The match involved a beneficial owner of the payee entity rather than the payee itself. The business froze the relevant instruction, documented its analysis of the ownership chain, reported to OFSI, and sought guidance on next steps. Because the freeze and report were timely and the documentation was clear, OFSI's review was resolved without an enforcement referral. Prompt, documented action is the consistent theme in favourable outcomes we have observed.

Step 5 – Understand the OFSI licensing route for authorised payments

Not every payment involving a designated person is permanently blocked. OFSI has power to issue specific licences (case-by-case authorisations to conduct an otherwise prohibited transaction) and, in some programmes, general licences (standing authorisations for defined categories of transaction that do not require a separate application). Both routes are available to payment-processing firms and their customers.

The grounds for licensing differ by programme. Common licensing grounds in UK sanctions regimes include: basic needs and extraordinary expenses; legal fees and costs; prior contractual obligations; and humanitarian purposes. The applicable thematic regulations specify what grounds are available under a particular programme. A firm processing a payment that might otherwise be prohibited should assess, before rejecting the instruction outright, whether a licence ground applies and whether the customer can be directed to apply for one.

Applying for a specific licence under OFSI requires a clear legal argument grounded in the applicable licensing grounds, evidence of the transaction's purpose and amounts, and information about the designated person's interest. The application process takes time – OFSI does not guarantee a decision within a fixed window, though it publishes target service standards for different licence types. Firms should factor this into their customer communications and transaction-management processes. An application that arrives before funds are committed is easier to manage than one submitted after a cross-border payment has stalled mid-chain.

The position above covers the standard licensing sequence. Your facts – the counterparty, the programme, the ground, the amount – change the analysis. For an early assessment of whether a licensing route is available for a specific payment, contact Calder & Vance at info@caldervance.com.

Step 6 – Record-keeping, audit trails, and compliance programme design

Payment-processing controls are only as reliable as the records that support them. OFSI's enforcement posture places significant weight on documentation: the screening log, the match-assessment record, the freeze decision, the report, and any licence application must all be retained and producible on request. Industry standards and OFSI's own guidance point to a five-year minimum record-retention period for sanctions-related records, though firms should confirm the current requirement under each applicable instrument.

A sound compliance programme for payment-processing businesses incorporates five elements: clear policies governing the screening trigger and escalation path; calibrated screening technology with documented logic; trained first-line operators who can exercise judgment on a potential match; a second-line function that reviews match dispositions and threshold settings; and periodic independent testing against scenarios that include control-chain designations and alias patterns. We regularly advise firms that have the first three elements in place but have not yet built the testing and independent review components. Those gaps are precisely where OFSI enforcement guidance focuses.

Cross-border payment firms must also map their obligations under parallel regimes. A sterling payment routed through a US correspondent bank will engage OFAC's rules in addition to OFSI's. The EU Blocking Regulation may be relevant for EU-incorporated subsidiaries in the same group. Swiss SECO, Australian DFAT, and other regimes each add their own layer where there is a relevant nexus. A control design that isolates UK obligations and ignores the surrounding architecture leaves the group exposed at the points of overlap.

Step 7 – Divergences between OFSI, OFAC, and the EU: where the gaps create risk

The three major Western sanctions regimes share a common objective but differ in ways that matter operationally for payment firms. Understanding where they diverge is not an academic exercise; it is a precondition for designing controls that work across borders.

On the ownership-and-control question, OFSI and the EU apply a control test alongside an ownership assessment. OFAC's test is primarily mechanical ownership aggregation. A transaction cleared by one test may be prohibited under another. The conservative approach – which we recommend for businesses operating in multiple jurisdictions – is to apply the strictest test across the board for any transaction that has a nexus to more than one regime.

On licensing, OFAC issues general licences that are published and publicly available, creating certainty for broad categories of transaction. OFSI operates general licences but also relies heavily on case-by-case specific licences. The EU operates through national competent authorities of member states, which introduces variation across the bloc that a single-jurisdiction approach would miss.

On reporting, OFSI requires reports from regulated-sector firms and from persons in the UK who hold or control frozen funds. OFAC's reporting obligations apply to US persons and to non-US firms with a US nexus. The triggers, recipients, and windows differ. A compliance programme that addresses only one regime's reporting requirements will have reporting gaps for transactions with a cross-border dimension.

Extraterritorial reach is the final divergence to map. US secondary sanctions – prohibitions on non-US persons that deal with certain designated persons or in certain sectors – can catch a UK payment firm's transactions even where the payment has no obvious US nexus, if it involves sufficient US-currency clearing or US-correspondent-bank intermediation. We have acted for UK businesses that believed their OFSI compliance programme was the full picture, only to discover that a US secondary-sanctions analysis was also required. That analysis is a distinct step and should be built into the programme design.

If a transaction has already been flagged across multiple regimes, or a licence application has been refused, early specialist review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.

Common mistakes and how to avoid them

Screening errors cluster around a small number of recurring patterns. Awareness of them is the first line of defence.

  • Single-list screening: running only the OFSI list and missing OFAC or EU designations that are also relevant to the transaction.
  • Shallow ownership checks: screening only the named payee and missing a designated person holding a controlling interest through intermediate companies.
  • Applying the wrong test: using OFAC's 50 percent aggregation rule for UK-connected transactions instead of OFSI's ownership-and-control standard.
  • Delayed reporting: treating the freeze and the report to OFSI as sequential tasks separated by days of internal review, rather than near-simultaneous obligations.
  • Undocumented false-positive disposals: clearing a match without recording the analysis, leaving no audit trail if OFSI later investigates.
  • Stale threshold settings: not revisiting the screening algorithm's fuzzy-match threshold when new lists are published or when alias patterns change.

There is a persistent assumption among smaller payment firms that OFSI enforcement targets only large banks. In our experience, that assumption is incorrect. OFSI has demonstrated a willingness to open investigations across a range of business sizes and sectors. The relevant question is not size but whether a firm had adequate controls and took appropriate action when a match was identified.

Related practices

Frequently asked questions

What are the steps to control sanctions risk in payments under OFSI?
Effective payment-processing controls under OFSI follow a defined sequence: map which UK sanctions regulations apply to your business and your payment types; screen every transaction against the OFSI Consolidated List and any other regime lists with a nexus to the transaction; apply the UK ownership-and-control test to unlisted entities connected to the payment; freeze immediately where a credible match is identified; report to OFSI within the applicable window; and retain full documentation of each decision. The licensing route should be assessed before rejecting any instruction permanently, because OFSI grounds may authorise the payment under a specific or general licence.
What is the most common mistake in payment-processing controls?
The most common failure in our practice is shallow screening that reaches only the named payment counterparty and misses a designated person in the ownership chain. UK sanctions regulations prohibit making funds available to entities owned or controlled by a designated person, not only to the designated person directly. A payee that passes a name-screen can still be caught if a listed person controls it through intermediate companies or contractual rights. Screening without a structured ownership inquiry is an incomplete control.
How does OFSI differ from other regimes here?
OFSI's ownership-and-control test is broader than OFAC's 50 percent mechanical aggregation rule: OFSI can catch an entity through a control relationship even without majority ownership. OFSI issues both specific and general licences, but relies more heavily on case-by-case authorisation than OFAC's published general-licence system. OFSI's reporting obligations are distinct in trigger, recipient, and timing from OFAC's requirements. For a cross-border payment business, treating OFSI compliance and OFAC compliance as interchangeable is a structural error; each regime requires its own analysis.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.