Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Payment-processing controls under OFSI: procedure and pitfalls

A payment firm receives a wire instruction at 11 p.m. The beneficiary's name is a partial match to an entry on the OFSI Consolidated List. The firm has minutes to decide: freeze, reject, or release. Getting that decision wrong – in either direction – carries consequences that range from an unlicensed dealing charge to a business-critical account suspension. The choice is not always obvious, and the procedure that surrounds it matters as much as the screening logic itself.

Payment-processing controls under OFSI are the internal systems, decision rules, and reporting procedures a firm uses to comply with UK financial-sanctions obligations when handling payments on behalf of customers or counterparties. The governing authority is the Office of Financial Sanctions Implementation, operating under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic sanctions regulations. As of mid-2026, OFSI's enforcement posture has become progressively more active, and firms that rely on screening alone – without documented escalation, ownership-mapping, and reporting procedures – are carrying risk that a stronger programme would eliminate.

This guide walks through the legal basis, the step-by-step control procedure, the cross-regime comparisons that matter most for firms with international business, the risk flags that practitioners see most often, and the point at which internal resources should give way to specialist counsel.

Step 1 – Understand the legal basis and who OFSI expects to comply

OFSI administers UK financial-sanctions law under SAMLA and the relevant thematic regulations, and its reach is broad: any person in the United Kingdom, any UK national or UK-incorporated entity wherever they operate, and any transaction denominated in sterling or cleared through a UK correspondent. That extraterritorial dimension catches firms that do not immediately think of themselves as "UK businesses." A payments processor incorporated outside the UK but routing sterling through London is within scope.

The core prohibition is on making funds available – directly or indirectly – to a designated person, or for their benefit. "Funds" is defined widely to include not just cash and bank balances but also negotiable instruments, letters of credit, payment orders, and electronic money. A firm does not need to be the originating bank; any link in the payment chain that processes, routes, or clears a payment can be implicated.

OFSI's guidance documents – which are updated periodically and should be read alongside the relevant statutory instruments – draw a clear distinction between a firm that has robust controls and one that does not. That distinction affects how OFSI exercises its enforcement discretion. In our experience, OFSI reviewers look first at whether a firm had a written control policy and whether it was followed; the existence of a match that slipped through is a secondary question.

Firms with operations or correspondent relationships in the European Union or the United States should note that EU financial-sanctions obligations and OFAC's programmes operate concurrently. A payment permitted under one regime may be prohibited under another. The stricter prohibition governs, and no licence from OFSI relieves an obligation under an OFAC or EU rule – and vice versa.

Step 2 – Design a screening architecture that matches the payment population

Effective payment-screening architecture begins with an accurate characterisation of the firm's payment population: volume, value, originating and beneficiary jurisdictions, currency mix, and the categories of customer that generate the flows. A firm processing low-value retail remittances faces a different control problem than one handling bilateral corporate wire transfers between correspondent banks. Both need screening; neither should apply a one-size-fits-all threshold.

Screening should run against the OFSI Consolidated List – now maintained as a single list under SAMLA – but also against the UN Security Council Consolidated List and, where relevant, the OFAC SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and the EU Consolidated Sanctions List. A match on the UN list creates an obligation under UN Security Council resolutions independently of domestic implementation. A firm that screens only the OFSI list and misses a UN-only designation is not protected.

Fuzzy-matching logic – transliteration rules, name-variant coverage, date-of-birth and nationality cross-checks – must be calibrated and documented. Calibration means setting the match threshold deliberately, recording the rationale, and testing it against a known-good dataset at defined intervals. "We use a reputable vendor" is not a calibration policy; it is a starting point. In our experience, the weakest link in most firms' screening programmes is the absence of documented threshold rationale rather than the technology itself.

The OFSI Consolidated List does not contain all persons who are effectively blocked. The 50 percent rule (OFSI's rule treating entities owned or controlled by designated persons as themselves subject to the same prohibitions) means the list is a floor, not a ceiling. A payment to an entity that is not on any list can still be a prohibited dealing if a designated person owns or controls it. Ownership-and-control analysis – mapping the beneficial-ownership chain through layers of intermediaries – must sit alongside name-screening, not replace it.

Step 3 – Build a documented escalation procedure for potential matches

When a payment generates a match or a potential match, the firm's escalation procedure determines what happens next – and it is the escalation procedure, not the screening tool, that OFSI tends to scrutinise in a review. A match alert that is cleared in thirty seconds by a junior analyst without documented reasoning provides no protection. A match alert that goes through a defined triage, a senior review, an ownership-chain check, and a written decision is a different matter entirely.

A well-designed escalation procedure contains at minimum five elements. First, a documented triage step that assesses whether the alert is a possible true match or a clear false positive, with the analyst recording the basis for the determination. Second, a named escalation path – the senior person or committee with authority to make a release or freeze decision. Third, an ownership-chain check for any non-trivial potential match, covering at least two levels of beneficial ownership. Fourth, a time limit within which the decision must be made or escalated further; open alerts that sit unresolved for days create compounding risk. Fifth, a record of the decision and the reasoning, retained for the applicable period under the relevant regulations.

What happens when the firm cannot resolve the match? The answer is not to release the payment and hope. OFSI has published guidance on what constitutes an appropriate freeze pending investigation. A payment that cannot be cleared with reasonable confidence should be held and, where the evidence points toward a true match, a suspicious activity report may also be required under the proceeds-of-crime regime. That obligation sits alongside – not instead of – the OFSI reporting obligation. Do firms in your sector have a single policy document that covers both simultaneously? In our cross-border practice, the gap between the AML reporting policy and the sanctions escalation policy is one of the most consistently exploited weaknesses.

Step 4 – Manage the reporting obligation to OFSI

The reporting obligation is statutory and arises in two situations: first, when a firm knows or suspects that it holds frozen assets belonging to a designated person; and second, when a firm knows or suspects that it has dealt with a designated person. The obligation to report is not discretionary and is not contingent on a prior freeze. A firm that identifies a possible dealing must report; the investigation that follows is a separate matter.

OFSI's reporting form must be completed with specific information: the identity of the designated person so far as known, the nature and value of the assets, the circumstances of the dealing or freeze, and the firm's own details. Incomplete reports are noticed and can themselves become a focus of OFSI's inquiry. In a recent matter, a financial institution submitted an initial report within the required window but provided insufficient detail on the ownership chain, resulting in a prolonged follow-up process that could have been avoided with a more complete initial filing.

Timing is critical. OFSI's guidance specifies that reports should be made as soon as reasonably practicable. That phrase has no precise statutory definition, but practitioners advising on OFSI matters consistently observe that delays measured in weeks rather than days attract scrutiny. The expectation in the market is prompt reporting once a firm has a reasonable basis for suspicion – not perfect certainty.

Firms operating under OFAC jurisdiction simultaneously face a different reporting window and a different reporting form. OFAC's reporting requirements for blocked transactions carry a specific deadline; that figure is published in OFAC guidance and should be verified before reliance. The important operational point is that a payment blocked under OFSI and also implicating an OFAC programme triggers two parallel reporting obligations with different addressees, different forms, and potentially different deadlines. Tracking both requires a procedure that is cross-regime by design, not by improvisation.

Step 5 – Apply for a licence where a payment legitimately cannot wait

A financial-sanctions licence from OFSI is a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) and is the only route by which a firm can lawfully process a payment that would otherwise be prohibited. OFSI has power to issue licences under a range of grounds set out in the relevant thematic regulations – including humanitarian grounds, legal expenses, and prior obligations in some circumstances. Obtaining a licence does not require a designated person to consent.

The application must set out the ground on which the licence is sought, the parties to the proposed transaction, the purpose of the payment, and any supporting evidence. OFSI exercises the discretion on grounds and conditions; the firm's role is to present the application accurately and completely. An incomplete application will be returned or refused. In our experience, applications that set out the legal ground precisely – citing the applicable licence category without invented certainty about the outcome – move faster through OFSI's review process than those framed in commercial rather than legal terms.

How does OFSI licensing compare to the equivalent process under OFAC? OFAC issues both specific and general licences (standing authorisations that permit a defined category of transactions without a separate application). OFSI's general-licence mechanism exists but has historically been used less extensively than OFAC's. For a firm that is dually regulated – handling both sterling and dollar flows that could be blocked under both regimes – the strategic question is whether a general licence under one regime can be structured to cover the largest volume of routine payments, leaving only the genuinely exceptional cases to the specific-licence queue. That structuring question is one we regularly advise on.

Step 6 – What are the risk flags that practitioners see most often?

Six risk flags appear consistently in payment-processing controls reviews across the financial-institution sector.

  • Ownership-chain gaps. Screening matches the named beneficiary but does not trace beneficial ownership through layers of intermediary holding companies. The 50 percent rule bites at each layer; the gap is the layer the firm did not check.
  • Currency-triggered blind spots. A firm correctly screens dollar and sterling payments but applies lighter controls to euro-denominated flows processed through non-UK entities. If the UK entity is in the chain – even as a technology provider or messaging bank – OFSI's reach may extend to it.
  • Static list-update schedules. Designations can happen at any time. A list-refresh that runs overnight means a designation made at 3 p.m. is not in the screening system until the following morning. High-volume real-time payment environments need intra-day or continuous list updates.
  • Inadequate correspondent-bank data. For payments in the correspondent-banking chain, the firm may receive only minimal identifying information on the originator or beneficiary. Straight-through processing of thin data creates a structural blind spot.
  • No escalation time limit. Alerts that are left open without a defined resolution deadline can accumulate. A queue of unresolved alerts is not a control; it is a liability.
  • AML-only reporting culture. Firms with strong AML programmes sometimes treat OFSI reporting as an AML sub-set. It is not. OFSI reporting has its own trigger, its own addressee, and its own form. Conflating the two produces incomplete filings under both regimes.

A common myth in the payments sector is that sanctions exposure is primarily a large-bank problem. In our experience, that view underestimates the exposure of mid-tier payment firms, e-money institutions, and embedded-finance providers. OFSI's enforcement activity has broadened beyond tier-one banks, and the volume of a firm's payment flows does not reduce its legal obligation – only its resource base for managing it.

The position above covers the standard control architecture. Your facts – the payment types your firm handles, the jurisdictions in the flow, the ownership structures of your corporate customers, the currency mix – change the analysis significantly.

For an initial assessment of your payment-controls programme against OFSI's current expectations, contact Calder & Vance at info@caldervance.com.

How does OFSI's approach compare to OFAC and the EU?

OFSI and OFAC both prohibit dealing with designated persons and apply an ownership-and-control test to catch non-listed entities. The tests diverge in important respects. OFAC's 50 percent rule is triggered by aggregate ownership at or above that threshold, regardless of control. OFSI's ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person) extends beyond numerical ownership to consider whether a designated person effectively controls an entity through other means – board composition, veto rights, or economic dependence. An entity that falls below the ownership threshold but is demonstrably controlled by a designated person can still be caught under UK and EU rules in a way it might not be under OFAC's mechanical test.

The EU position, implemented through the relevant Council regulations, follows a similar control-inclusive approach to the UK. However, EU and UK lists diverge in content. Since the UK developed an autonomous sanctions regime under SAMLA, the two lists are maintained separately. A person delisted by the EU is not automatically delisted under UK law, and vice versa. For a firm processing euro and sterling payments to the same customer base, the practical consequence is that two list-checks are mandatory, not one.

Singapore, the UAE, and Japan each maintain their own national sanctions lists and implementing procedures. For a payment firm with correspondent relationships across Asia, those regimes apply domestically in those jurisdictions. A sterling or euro payment routed through a correspondent in Singapore is subject to Singapore's financial-sanctions rules at the Singapore end. Cross-border payment-control programmes must be designed to account for the regime at each node in the payment chain, not only the regime of the originating firm.

Switzerland operates through SECO, and its list tracks UN designations closely while also implementing autonomous measures in certain programmes. Canadian and Australian regimes – administered respectively through Global Affairs Canada and DFAT – similarly impose obligations on entities with nexus to those jurisdictions. A firm with a Canadian dollar book or Australian dollar clearing is within scope of those regimes. Multi-currency payment processors should map each currency's regulatory home jurisdiction as part of their control architecture.

If a transaction has already been flagged under OFSI, or a prior filing has drawn a follow-up inquiry, early specialist review can preserve options that narrow with time.

Contact Calder & Vance at info@caldervance.com for a confidential review of a potential breach or a flagged transaction.

Related practices

Frequently asked questions

What are the steps to control sanctions risk in payments under OFSI?
The core steps are: establish the scope of OFSI's reach for your firm; design a screening architecture that covers the OFSI Consolidated List, the UN list, and any other relevant lists; implement a documented escalation procedure with defined time limits and ownership-chain checks; satisfy the statutory reporting obligation as soon as reasonably practicable when a match is confirmed or reasonably suspected; and apply for a specific licence when a payment legitimately needs to proceed despite an apparent prohibition. Each step requires written documentation that OFSI can review. Firms that treat screening as a technological exercise rather than a procedural one consistently find the gaps during an enforcement review rather than before it.
What is the most common mistake in payment-processing controls?
The single most common mistake is treating the OFSI Consolidated List as a complete picture of who is blocked. The 50 percent rule means that entities owned or controlled by designated persons are subject to the same prohibitions even if they appear on no list. A firm whose screening programme does not include beneficial-ownership mapping through at least two layers of intermediaries is operating with a structural gap. The second most common mistake is failing to maintain a documented record of alert decisions – particularly decisions to release a payment after review – so that, when OFSI asks, the firm cannot demonstrate the reasoning that justified the release.
How does OFSI differ from other regimes here?
OFSI's ownership-and-control test extends beyond a fixed numerical ownership threshold to include effective control through non-ownership means, such as veto rights or board dominance. OFAC's 50 percent rule is more mechanical: aggregate ownership at or above the threshold triggers the prohibition, regardless of control. The EU follows an approach similar to the UK. Additionally, the UK and EU maintain separate autonomous lists; a designation removed from one list is not automatically removed from the other. For payment firms operating across these regimes simultaneously, this means separate list-checks are mandatory and a single cleared payment under one regime may still be prohibited under another.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.