A freight-forwarding group based in Sydney wins a new lane serving a trading hub in South-East Asia. Its compliance officer runs the end-customer through the firm's screening tool, which returns no hits on the Consolidated List. The goods ship. Three months later, DFAT writes to ask why the consignment reached a party whose beneficial owners appear on the Australian Autonomous Sanctions list. The goods have already been delivered. What now?
A sanctions risk assessment under Australia's Autonomous Sanctions regime – administered by the Department of Foreign Affairs and Trade (DFAT) – is a structured review of a business's counterparties, goods, services, and transaction routes against the prohibitions contained in the relevant autonomous sanctions regulations and the instruments that give effect to United Nations Security Council measures. As of August 2026, Australia maintains autonomous sanctions programmes targeting a range of country situations, individuals, and entities, alongside its obligations under binding UN Security Council resolutions. A properly scoped assessment does not stop at screening the named party: it maps ownership and control, identifies goods classification requirements, and tests the transaction route for secondary-sanctions risk under the regimes of key trading partners.
This guide walks through the assessment procedure step by step, compares the Australian position with the approaches taken by OFAC, OFSI, and the EU, and identifies the pitfalls that most frequently convert a compliance gap into an enforcement problem.
Step 1: Understand what the Australian Autonomous Sanctions regime actually prohibits
The Australian Autonomous Sanctions regime prohibits a defined set of dealings – financial transactions, supply of goods, provision of services, travel facilitation – with designated persons and entities, and with parties connected to designated country programmes. The prohibitions are set out in the Autonomous Sanctions Act and the relevant thematic regulations made under it; the regulator is DFAT, which maintains the Consolidated List of designated persons and entities. The starting point for any assessment is a precise understanding of which prohibitions apply to the transaction in question.
Two categories of obligation are commonly conflated. The first is the prohibition on dealing with a specifically designated party – an individual or entity whose name appears on the Australian Consolidated List or on the UN Security Council Consolidated List, which Australia implements through its Charter of the United Nations Act obligations. The second is the country-programme prohibition: restrictions that apply to a defined class of activity regardless of whether the counterparty is named, because the transaction relates to a particular sector, goods type, or territory covered by a country-specific programme. Failing to distinguish these two layers is the single most common structural error we see in assessments prepared without specialist input.
The position above covers the standard case. Your facts – the goods, the counterparty's sector, the route, and the programmes in force – change the analysis. For guidance on scoping the prohibitions that apply to your transaction, contact Calder & Vance at info@caldervance.com.
Step 2: Map ownership and control – the test that standard screening misses
Standard screening tools check whether a counterparty's registered name matches an entry on a sanctions list. They do not, by default, check whether the counterparty is owned or controlled by a designated person – and under Australian law, as under most comparable regimes, a non-listed entity can still be caught where a listed person exercises effective ownership or control over it.
The Australian Autonomous Sanctions regime uses an ownership and control concept similar to that applied by OFSI and the EU, though with important differences in how the test is formulated and applied. Under the ownership and control test (the principle that prohibitions extend to entities effectively owned or controlled by a designated party, not only to the designated party itself), DFAT's guidance does not set a hard numeric threshold in the same way that OFAC applies its 50 percent or more rule. The Australian position looks at effective control in substance, which is both broader and, in some respects, less predictable than the mechanical US rule. For a business accustomed to running its compliance programme against the OFAC bright-line threshold, this difference is consequential.
In practice, the ownership and control analysis requires the assessor to trace the beneficial ownership chain through all intermediate layers, identify any person with the practical ability to direct the actions of the counterparty, and consider indirect indicators of control such as board appointment rights, veto rights, and economic dependency. We regularly advise businesses that this analysis is not a one-time exercise: ownership structures change, and a counterparty that was clean at the time of contract can become problematic if a designated person acquires a controlling stake later.
Step 3: Classify goods and services for export-control purposes alongside the sanctions screen
A sanctions risk assessment that looks only at the identity of the counterparty – and not at the nature of the goods or services being supplied – is incomplete. Australia's export-control regime, administered primarily through the Department of Defence and the relevant autonomous sanctions instruments, restricts or prohibits the supply of certain goods and services to designated countries and persons, and requires permits for the export of controlled goods even where no sanctions designation is involved.
The intersection between sanctions and export controls is particularly acute for dual-use goods: items that have legitimate commercial uses but can also be applied to military or proliferation-relevant purposes. Where a transaction involves goods of this type, the assessment must examine both the sanctions-based prohibition and the separate export-control licensing requirement. Treating these as separate workstreams – one for the compliance team, one for the trade team – is a structural pitfall. In our experience, the gap between the two workstreams is exactly where control failures accumulate.
Cross-border comparison matters here. Under the US Export Administration Regulations (EAR) administered by BIS, goods are classified by reference to an ECCN (Export Control Classification Number under the US Commerce Control List). Australia does not use the ECCN system, but Australian exporters supplying goods to the United States, or re-exporting US-origin goods, remain subject to US re-export controls. A complete assessment for a business in either jurisdiction must address both regimes simultaneously. For a practical guide to how the US export-control classification system operates, see our BIS / EAR sanctions risk assessment guide.
Step 4: Assess secondary-sanctions risk from OFAC and the EU
Australian businesses operating internationally face an additional layer of risk that the Australian regime itself does not impose: the extraterritorial reach of US primary and secondary sanctions administered by OFAC, and the broad jurisdictional scope of EU Council regulations that apply to transactions conducted in euros, through EU-incorporated entities, or by EU nationals wherever located.
OFAC's secondary-sanctions programmes do not require a US nexus in the conventional sense. A non-US business that knowingly facilitates a significant transaction with a party targeted by a US secondary-sanctions programme can be designated itself, losing access to the US financial system. For Australian businesses with USD correspondent banking relationships, US-origin goods in their supply chain, or US investors on their shareholder register, this exposure is not theoretical.
How should an Australian business calibrate this risk? The answer depends on the transaction's connection to the United States – through currency, technology, personnel, or routing. In our cross-border practice, we treat the secondary-sanctions screen as a separate analytical step, run in parallel with the Australian autonomous-sanctions analysis, precisely because the triggers are different and the consequences of a miss are severe. A business that passes the Australian screen but ignores OFAC's extraterritorial reach has completed only part of the assessment.
The EU position adds a further dimension for businesses with European counterparties or supply-chain nodes in the EU. EU sanctions apply to transactions processed in euros, to EU-incorporated intermediaries, and to EU nationals acting as directors or agents. Where a transaction routes through a European correspondent or involves an EU-based service provider, the relevant EU Council regulation must be read alongside the Australian instrument.
If a transaction has already been flagged, or a filing has been refused or queried by a regulator, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss your situation.
Step 5: Document the assessment and establish the review cycle
A sanctions risk assessment is not a document produced once and filed. It is a living analytical record that must be updated when the relevant sanctions programmes change, when the counterparty's ownership or control structure changes, or when the goods, services, or transaction route changes. DFAT updates the Australian Consolidated List and the relevant programme instruments without fixed intervals; OFAC and the EU do the same. A business that relies on an assessment carried out twelve months ago is not compliant: it is exposed.
The documentation requirement has practical force. In an enforcement context, a business that can show a contemporaneous, written, and reasoned assessment – one that identified the risks, tested each element of the transaction, and recorded the conclusions – is in a materially better position than one that relied on an informal screen and a verbal sign-off. DFAT's enforcement guidance, like OFSI's approach in the United Kingdom, treats the existence and quality of documented compliance procedures as a factor in determining whether and how to pursue an apparent breach.
Record-keeping requirements under the applicable regime should be confirmed against the current instruments, as they vary by programme and transaction type. As a general discipline – consistent with the approach taken by OFAC, OFSI, and the EU – we advise maintaining the full assessment file, including screening records, ownership-mapping analysis, and the legal conclusions reached, for a minimum of five years from the date of the transaction. Verify the current position under the applicable Australian instrument before relying on any specific retention period.
A well-designed assessment also builds in a review trigger: a calendar prompt, a transaction-alert workflow, or a change-in-counterparty flag. For a practical view of how compliance audit and testing supports the ongoing review cycle under Australian sanctions, see our compliance audit and testing service.
Common pitfalls and risk flags in Australian sanctions risk assessment
Several structural errors account for most of the gaps we see in Australian sanctions risk assessments. The following are the most consequential.
- Screening only the named counterparty. As noted in Step 2, screening the registered entity name without mapping its ownership and control chain misses the most common vector by which designated persons operate through apparently clean vehicles.
- Treating the UN Consolidated List as the only relevant list. The Australian Consolidated List includes designations that do not appear on the UN list. The UN list includes measures that are separately implemented in Australian law. Both must be checked, and they are not co-extensive.
- Ignoring goods classification. Where the transaction involves physical goods or technical data, failure to consider export-control classification – separately from the sanctions screen – creates a parallel compliance gap that is often discovered only at the enforcement stage.
- Assuming geographic distance eliminates OFAC exposure. OFAC's secondary-sanctions programmes do not require the transaction to be conducted in the United States. The nexus is the party or the conduct targeted by the secondary measure, not the location of the parties.
- Treating the assessment as complete when no hits are returned. A clean screen is not a clean assessment. It means no named parties were identified. It does not mean no prohibitions apply, no control analysis is needed, and no export-control requirements exist.
- No documented review cycle. An assessment without a scheduled review is an assessment that will become stale. The triggering events for a reassessment – list updates, ownership changes, goods changes – must be built into the compliance programme design.
One objection we frequently hear from in-house teams is that these steps describe a process appropriate for large financial institutions, not for a mid-sized exporter or a trading house with limited compliance resource. That is a misreading of the regime. DFAT's enforcement posture, like OFSI's in the UK, applies to all persons subject to Australian law – there is no size-based safe harbour. The calibration lies in the depth of the assessment, not in whether one is required. A proportionate, well-documented assessment of a lower-risk transaction is still a compliant process. An absent or perfunctory one is not.
When should a business involve external sanctions counsel?
A business should involve external sanctions counsel at the earliest point at which the transaction presents a question that cannot be answered by reference to the standard screening output alone. That point arrives sooner than most in-house teams expect.
The following situations are the clearest signals that specialist input is warranted before a transaction proceeds:
- The counterparty is incorporated in, or routes goods or funds through, a jurisdiction subject to a comprehensive country-programme prohibition under the Australian regime or under OFAC.
- The ownership or control chain cannot be fully traced from publicly available sources.
- The goods being supplied are dual-use in character, and the end-use has not been independently verified.
- The transaction involves a correspondent bank, a payment intermediary, or a logistics provider that is itself subject to a secondary-sanctions risk.
- A screening hit has been returned – even a partial match or an alias match – and the business needs to assess whether the match is a true positive and what the consequences are.
- DFAT or another regulator has made contact, whether by way of an inquiry, a request for information, or a notification of a potential breach.
In our experience, the cost of involving counsel early – to scope the assessment, advise on the ownership analysis, and review the goods classification – is a fraction of the cost of managing an enforcement process after the fact. The regulatory window for voluntary self-disclosure, where it is available, closes quickly; the options that exist before a formal inquiry are broader than those that exist once one has begun.
For a comparative view of how the US assessment process differs in structure and scope, see our further BIS / EAR sanctions risk assessment analysis.
Related practices
- Compliance audit and testing – Australia – testing screening logic and programme design against the Australian sanctions regime
- BIS / EAR sanctions risk assessment guide – step-by-step assessment process under US export controls and OFAC