Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Sanctions risk assessment under OFSI: step by step

A mid-sized UK trading company signs a distribution agreement with a European counterparty. Several months later, an internal review flags that one of the distributor's directors was designated under UK financial sanctions after the contract was executed. The compliance team faces an immediate question: was the company already captured at signing? Does continued performance constitute a breach? And what should the board do now? As of mid-2026, OFSI's enforcement posture has hardened considerably, making these questions anything but academic.

A sanctions risk assessment (a structured review of a business's exposure to the prohibitions administered by the Office of Financial Sanctions Implementation, known as OFSI) is the starting point for any defensible UK sanctions compliance programme. OFSI operates under the Sanctions and Anti-Money Laundering Act – "SAMLA" – and the relevant thematic regulations, which prohibit dealing with the funds or economic resources of designated persons and impose reporting obligations on businesses that know or suspect they hold such assets. Without a properly constructed risk assessment, a business cannot calibrate its controls, cannot demonstrate due diligence to OFSI, and cannot confidently advise its board.

This guide sets out the steps of a practical OFSI sanctions risk assessment, the tests that govern ownership and control, the points at which the UK position diverges from OFAC and EU approaches, and the risk flags that warrant early legal advice.

Step 1: Understand what OFSI regulates and who it can reach

OFSI's prohibitions apply to any person in the United Kingdom, and to any UK person wherever located – which means a UK-incorporated subsidiary operating in Singapore or Dubai is subject to the same rules as a London bank. The reach is wider than many compliance teams assume. A UK-registered holding company sitting above an international group structure can trigger OFSI exposure even when the operational entities are incorporated and functioning entirely abroad.

The prohibitions operate at two levels. First, there is the asset-freeze: no dealing with the funds or economic resources owned, held, or controlled by a designated person, and no making funds or economic resources available to them. Second, there are sector-specific and thematic measures – restrictions on financial services, capital markets activity, correspondent banking, and, in the context of certain regimes, restrictions on technical assistance and insurance. The scope of each thematic set of regulations must be checked separately; a risk assessment that treats all OFSI measures as identical will miss gaps.

A critical early task is to map exactly which legal entities and relationships within your group are caught by the UK personal and territorial nexus. Do your contracts run through a UK entity? Does a UK employee authorise payments? Is your parent company UK-registered? Each positive answer extends OFSI's reach further into the transaction chain.

Step 2: Map your counterparties and beneficial ownership chains

OFSI applies an ownership and control test – under which a non-listed entity can be caught if a designated person owns or controls it – but the UK test is broader than the mechanical OFAC threshold and requires examining both ownership and actual control. Under OFSI's approach, a business must assess whether a designated person holds a majority interest, whether they exercise control through other means such as the right to appoint management or direct strategy, and whether indirect chains produce the same result. This is not a box-tick exercise; it is a factual investigation that requires documentary verification.

In our experience, ownership mapping is where most compliance programmes fall short. A screening alert on a counterparty's name is a starting point, not a conclusion. The real risk sits one or two layers behind the legal entity that appears on the contract. We regularly advise businesses that have cleared a counterparty at the entity level, only to find on deeper review that a designated person holds a minority stake in an intermediate holding company that, combined with contractual control rights, places the whole structure within OFSI's reach.

Practical steps at this stage:

  • Collect constitutional documents, shareholder registers, and UBO declarations for material counterparties.
  • Screen all natural persons identified as owners or controllers against the UK Consolidated List, the EU Consolidated List, and – where the transaction has a US nexus – OFAC's SDN List.
  • Map any contractual control rights: board appointment, veto rights over material decisions, drag-along provisions that could be exercised by a designated person.
  • Document the methodology and the outcome. If OFSI investigates, it will want to see both what you checked and how you checked it.

The position above covers the standard counterparty review. Where your transaction involves a target or counterparty in a higher-risk jurisdiction, or where ownership information is limited or opaque, the threshold for seeking specialist input is lower.

Compliance audit and testing – practical testing of screening logic and ownership-mapping methodology across the major regimes.

Step 3: Assess your products, services, and transaction flows against the prohibitions

A sanctions risk assessment must go beyond counterparty screening. OFSI's prohibitions extend to the nature of the transaction itself: making funds available, making economic resources available, and providing a financial service or technical assistance connected to a designated person. A business may deal with an entirely clean counterparty and still breach OFSI rules if the ultimate beneficiary of a payment, or the end-user of goods or services being financed, is designated.

At this step, assess the following:

  • Payment chains: does any leg of the transaction pass through a correspondent bank, payment agent, or intermediary with a designated nexus?
  • Goods and services: could the goods or services you supply reach a designated person as an ultimate beneficiary, even indirectly?
  • Financing and insurance: is any element of trade finance, insurance, or re-insurance provided by or to a designated entity?
  • Professional services: do legal, accountancy, or consulting services provided to the counterparty constitute making economic resources available?

The professional services question deserves particular attention. OFSI's guidance addresses the provision of legal and other professional services and confirms that they can constitute economic resources. In our practice, we advise professional services firms – law firms, accountancies, consultancies – to run the same ownership and control analysis on their clients that a bank would run on a payment counterparty.

Sector-specific restrictions add another layer. Certain OFSI regimes restrict activity in capital markets, correspondent banking, oil services, and transport, even where no individual counterparty is designated. These sector measures require a separate assessment against the relevant thematic regulations.

How does the UK ownership and control test differ from OFAC and EU approaches?

The UK test for whether a non-designated entity is caught through a designated person differs from both the OFAC and EU approaches in ways that can determine whether a transaction is permitted or prohibited. Understanding the divergence is essential for any cross-border business operating under multiple regimes simultaneously.

Under OFAC, the 50 percent rule is mechanical: if designated persons own, individually or in aggregate, 50 percent or more of an entity, that entity is treated as blocked, regardless of whether any designated person actually exercises control. Ownership below the threshold does not automatically block the entity under OFAC, though OFAC retains the authority to designate that entity separately.

Under OFSI and the EU, the test adds a control limb. An entity can be caught even if designated persons own less than a majority, provided they exercise control through other means. What counts as control? Board appointment rights, veto powers over significant decisions, and economic control through financing arrangements have all been treated as relevant factors. The EU General Court has addressed this question in a number of annulment proceedings, and the emerging picture is that control is assessed holistically against the facts of the specific structure.

What does this mean for a business running a multi-regime compliance programme? It means that an entity cleared under OFAC because designated persons hold only forty percent of the shares may still be caught under OFSI or EU rules if those designated persons have contractual rights giving them effective control. The stricter prohibition governs the transaction in practice. A cross-border risk assessment must apply each regime's test in turn and then operate to the most restrictive standard the business is exposed to.

This divergence also affects how you document your analysis. An OFAC-style ownership chart that stops at the fifty percent threshold is incomplete for OFSI purposes. The UK assessment requires a narrative on control as well as a chart on ownership. If a transaction has a US nexus and a UK nexus simultaneously, both analyses should appear in the same file so that any subsequent review by either authority can see the full picture.

Step 4: Identify reporting obligations and internal escalation triggers

A sanctions risk assessment is not complete until it maps the reporting obligations that arise from the risks identified. OFSI imposes a duty to report on all persons in the UK who know or have reasonable cause to suspect that they hold funds or economic resources belonging to or controlled by a designated person, or that a designated person has tried to deal with them. The reporting obligation is mandatory; it is not contingent on a confirmed breach.

The obligation to report arises at the point of reasonable suspicion, not at the point of certainty. In our experience, businesses routinely delay reporting while they continue internal investigations, seeking to confirm the position before contacting OFSI. That approach carries risk: if OFSI investigates and finds that a firm held a reasonable suspicion earlier than the report date, the delay itself becomes a compliance issue. The practical rule is: if the internal investigation has reached the point where you are genuinely asking whether you need to report, you probably do.

Internal escalation triggers should be defined in writing, assigned to specific roles, and tested regularly. Who receives a screening alert? Who has authority to pause a transaction pending review? Who decides whether to report to OFSI and within what timeframe? These decision rights should be documented in a sanctions escalation protocol, not left to informal practice.

Adjacent to OFSI reporting, consider whether the same facts trigger obligations under anti-money laundering rules – which run in parallel and are enforced by separate authorities. A business that reports under OFSI but fails to consider the AML dimension has addressed only part of the problem.

Step 5: Document the assessment and integrate it into ongoing monitoring

A sanctions risk assessment is a point-in-time document. Designation lists are updated continuously, ownership structures change, and new thematic regulations are made. An assessment that is accurate today can be out of date within weeks. The final step of any structured assessment is to build the monitoring and review cycle that keeps it current.

Documentation requirements under SAMLA and OFSI's enforcement guidance are not prescriptive about form, but the substance is clear: OFSI will look for evidence that a business undertook a genuine, proportionate, and timely assessment of its exposure. A printed name-screening result with no analysis of ownership or control, no product and transaction review, and no escalation mapping will not satisfy that standard. Defensible documentation records the methodology, the sources consulted, the conclusions reached, and the basis for those conclusions.

Record-keeping should cover the full audit trail: the screening tools used, the version of the sanctions list consulted, the date of the check, the identity of the reviewer, and any escalation decisions made. Where a transaction was permitted to proceed after a flag was raised, the rationale for that decision – and who authorised it – should be preserved. Completeness here protects the business if OFSI raises questions later.

Ongoing monitoring should be event-driven as well as periodic. A new designation in a sector where you have active counterparties should trigger an immediate re-screening of those relationships, not a wait for the next scheduled review. Systems that receive automatic list updates and generate alerts on existing counterparty populations are the baseline standard for any business with significant sanctions exposure.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. For a confidential review of a potential breach, contact us at info@caldervance.com.

Common risk flags that warrant legal advice before proceeding

Certain fact patterns consistently produce the highest-risk findings in an OFSI sanctions review. Identifying them early – before a transaction is executed – is far less costly than addressing them after the fact.

The most common risk flags we see in our practice include:

  • Opaque beneficial ownership: a counterparty that cannot or will not provide complete UBO information is a material risk indicator, regardless of whether a name-screen alert has fired.
  • Nominee arrangements: structures where directors or shareholders act in a nominee capacity without clear disclosure of the underlying principals require enhanced scrutiny.
  • Rapid ownership changes: transfers of interest in counterparty entities shortly before or after a designation event warrant investigation.
  • Cross-regime pressure: a transaction that appears clear under OFSI but sits closer to the line under OFAC or EU rules, or vice versa, signals that the most restrictive regime has not been fully analysed.
  • Indirect geographic exposure: payments or services that route through jurisdictions subject to enhanced scrutiny, even where the named counterparty is in a lower-risk location.
  • Contractual control rights held by unscreened persons: side agreements, option arrangements, or financing commitments that give a third party effective control over a counterparty's decisions.

Where one or more of these flags is present, the appropriate step is not to proceed with the standard review but to obtain specialist advice before the transaction closes. The cost of an advisory review at this stage is a fraction of the cost of an enforcement response after OFSI opens an inquiry.

A common misconception is that OFSI only investigates regulated financial institutions. That is not the case. OFSI's enforcement jurisdiction extends to any person in the UK or any UK person worldwide, and recent enforcement actions have covered professional services firms, trading companies, and corporate service providers, as well as banks. If your business has a UK nexus and touches the counterparty, goods, or payment chains in scope of the relevant thematic regulations, you are within OFSI's reach.

How does this assessment connect to multi-regime compliance?

For most cross-border businesses, OFSI is one of several regimes in play simultaneously. A trade between a UK seller and a buyer in Singapore, financed by a US bank, routed through a European intermediary, potentially involves OFSI, OFAC, EU regulations, and the Singaporean Monetary Authority's framework. Each regime applies its own ownership and control test, its own licensing requirements, and its own reporting obligations.

The key cross-border principle is that the most restrictive applicable prohibition governs the transaction. A UK-established business cannot proceed on the basis that OFSI permits something if OFAC prohibits it and the transaction has a US nexus. Secondary-sanctions risk – the risk that a transaction that is technically lawful under UK law exposes a counterparty bank or intermediary to OFAC exposure – is a live commercial concern, not a theoretical one. Banks subject to US primary jurisdiction routinely decline to process payments for transactions that fall within OFAC's secondary-sanctions reach, even where the originating parties have no direct US nexus.

We regularly advise businesses on multi-regime assessments that map OFSI obligations alongside OFAC primary and secondary sanctions, EU restrictive measures, and the applicable country regimes in Singapore, the UAE, and the other major trade hubs. The practical output of such an assessment is a transaction-level decision matrix: which regime applies, what the standard is, whether a licence or general authorisation is available, and what residual risk remains after controls are applied.

Sanctions risk assessment – Singapore guide – applying the Monetary Authority of Singapore's regime alongside OFSI and OFAC for cross-border transactions.

Sanctions risk assessment under OFSI: advanced issues – licensing, reporting, and enforcement-response steps for businesses with an active exposure.

Related practices

  • Compliance audit and testing – structured testing of screening controls and ownership-mapping methodology against the applicable regimes.
  • OFSI advanced issues guide – licensing routes, voluntary disclosure, and enforcement-defence considerations under the UK regime.

Frequently asked questions

What are the steps to carry out a sanctions risk assessment under OFSI?
A defensible OFSI sanctions risk assessment runs through five stages: establishing the legal and territorial scope of OFSI's reach for your specific group structure; mapping beneficial ownership and control of material counterparties against the UK Consolidated List and the ownership-and-control test; assessing products, services, and payment flows against the full range of prohibitions in the applicable thematic regulations; identifying reporting obligations and escalation triggers; and documenting the methodology and integrating the output into an ongoing monitoring cycle. Each stage must be completed and recorded before the business can state that it has assessed its OFSI exposure.
What is the most common mistake in sanctions risk assessment?
The most common failure is treating name-screening as a complete assessment. Screening a counterparty's legal name against the UK Consolidated List is the first step, not the last. It does not capture designated persons holding interests through intermediate structures, it does not assess contractual control, and it does not evaluate whether the transaction type itself – the payment chain, the insurance leg, the technical assistance – independently engages a prohibition. Businesses that rely solely on a name-screen and find no alert often conclude they are clear when a more thorough assessment would reveal material exposure.
How does OFSI differ from other regimes here?
OFSI's ownership and control test is broader than OFAC's mechanical fifty-percent rule because it captures control through means other than majority ownership: board appointment rights, veto powers, and economic control through financing can all bring a non-designated entity within the prohibition. OFSI also operates mandatory reporting obligations – any person who knows or has reasonable cause to suspect they hold designated assets must report to OFSI, a duty that is not dependent on a confirmed breach. By comparison, OFAC has no equivalent mandatory reporting obligation of this type for non-financial-institution businesses in most contexts.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.