Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Sanctions risk assessment under OFSI: what businesses must know

A mid-sized financial services firm operating across the United Kingdom and the Gulf discovers, mid-transaction, that one of its counterparty's principal shareholders appears on a UK-designated-persons list maintained by OFSI (the Office of Financial Sanctions Implementation, the UK authority responsible for licensing, enforcement, and guidance on financial sanctions). The deal team pauses. The compliance lead asks: how exposed are we, and how do we know what we don't know? The answer begins with a sanctions risk assessment – and under the OFSI regime, that assessment has a specific shape.

A sanctions risk assessment (a structured review of where a business's activities, counterparties, geographies, and products intersect with financial-sanctions prohibitions) is not a statutory form in the UK. It is, however, the foundation that OFSI expects to see when it examines whether a firm has adequate controls. As of mid-2026, OFSI's published enforcement guidance makes clear that the quality of a firm's risk identification directly affects how a breach is assessed and what licensing or penalty route follows. The assessment must be calibrated to the firm's actual exposure, not a generic template.

This guide walks through every stage of a sanctions risk assessment under the OFSI regime: the legal basis, the ownership-and-control test, the cross-regime divergences a UK-facing business must track, and the triggers that move a paper exercise into live counsel territory.

What legal authority governs OFSI sanctions risk assessment?

OFSI derives its authority from the Sanctions and Anti-Money Laundering Act 2018 (SAMLA), the primary statute under which UK sanctions are now imposed, and the thematic regulations made under it – covering asset-freeze and financial-sanctions prohibitions across multiple country and thematic programmes. The duty to comply sits on any person within the UK's jurisdiction, including UK persons acting abroad. SAMLA's civil penalty standard is strict liability for monetary penalties: intent is irrelevant to liability, though it is highly relevant to the penalty calculation.

This is where the risk-assessment function earns its value. A business that has conducted a documented, proportionate, and regularly updated assessment can demonstrate that any breach was not the product of inadequate systems. That demonstration goes directly to mitigation. In our experience, firms that present OFSI with no contemporaneous risk documentation tend to face the upper range of the civil-penalty scale, regardless of how quickly they self-report.

Two instruments sit alongside SAMLA as the practitioner's reference points. OFSI's published enforcement and monetary-penalty guidance sets out the aggravating and mitigating factors it applies. Its general licensing guidance explains when a prohibited transaction may proceed under a standing authorisation. Both are public. Neither replaces the need for a business-specific analysis of where the firm's exposure actually lies.

Step 1 – Define the scope: who and what is in scope of the UK financial-sanctions prohibitions?

The first step is mapping which legal prohibitions apply to the business. UK financial sanctions under SAMLA prohibit, broadly, making funds or economic resources available to a designated person, and dealing in property owned or controlled by one. The prohibitions apply to UK persons and to conduct within the UK. But scope can extend further: secondary-sanctions risk from other regimes – most critically OFAC in the United States – may overlay the UK exposure, particularly for businesses with US-dollar accounts or US-nexus counterparties.

In practice, scope means answering three questions. First: which OFSI thematic programmes are live and relevant to the firm's sector and geography? Second: which products, services, or transaction types could constitute making funds available? Third: which counterparties, beneficial owners, or jurisdictions sit in elevated-risk territory? Scope definition is not a once-a-year exercise. OFSI's designated-persons list is updated without notice, and material changes in business activity require a fresh scope review.

A cross-border point that firms regularly underestimate: where a business also operates under EU Council regulations, the EU ownership-and-control test applies alongside the UK test, and the two are not identical. An entity that passes the UK analysis may still be caught under the EU rules, or vice versa. Mapping scope means mapping all applicable regimes, not just the primary one.

Step 2 – Apply the ownership-and-control test: how does OFSI assess whether a non-listed entity is caught?

Under the UK regime, an entity that is owned or controlled by a designated person is treated as if it were itself designated, even if it does not appear on any list. This ownership-and-control test differs from the OFAC mechanical threshold. Under OFSI, control is assessed through a multi-factor lens: the ability to ensure that the entity acts in accordance with the designated person's wishes, whether through voting rights, board appointment powers, contractual arrangements, or otherwise.

OFAC applies a 50 percent or more aggregate-ownership rule: if blocked persons own half or more, the entity is blocked regardless of control factors. OFSI and the EU look beyond that number. A designated person holding 40 percent of the shares but exercising effective control through governance documents can still trigger the UK prohibition. Have you assessed the counterparty's governance documents, not just the share register?

Aggregation matters under both regimes. Where two designated persons together own more than 50 percent, or where a single designated person exercises control through a minority stake, the entity is caught. Screening tools that check only direct holdings against a sanctions list will miss both patterns. A robust ownership trace requires going behind the register to understand voting arrangements, loan terms, and board composition. In our experience, this is precisely where mid-market businesses have gaps – and where OFSI finds them.

Under the EU regime, the concept of control extends further in certain programmes, and the Council's guidance documents on the ownership-and-control question are regime-specific. A business that operates across the Channel should not assume that a UK analysis can be directly transposed. The analysis must be run separately under each applicable regime.

Step 3 – Identify risk factors and calibrate to the business

Risk identification under OFSI goes beyond list-matching. The structured assessment should examine: the geographic footprint (which markets carry elevated sanctions exposure); the counterparty base (which clients, suppliers, intermediaries, or beneficial owners are high-risk by geography, sector, or ownership profile); the product and service set (which offerings, if misused, could make funds available to a designated person); and the transaction types (which payment corridors, financing arrangements, or trade flows carry the greatest exposure).

OFSI's own guidance draws a distinction between firms that have simply checked a name against a list and firms that have conducted proportionate risk identification. The former satisfies a screening requirement. The latter is what OFSI describes when it explains what adequate sanctions controls look like. The difference is material when OFSI decides whether a breach reflects a systemic failure or an isolated slip.

Risk calibration means weighting these factors against the firm's actual activity. A small domestic business with no foreign clients and no cross-border payments carries a very different risk profile from an international trading house handling commodity finance across multiple jurisdictions. The assessment document should reflect that difference explicitly. A generic risk matrix copied from another firm's template is not calibration; it is box-ticking, and OFSI does not treat it as equivalent.

One risk factor that businesses in financial services, payments, and virtual assets frequently underweight is de-risking exposure: the reputational and regulatory cost of maintaining a relationship that later turns out to have a sanctions link. We regularly advise financial institutions on how to document their risk decisions in real time, so that a decision to maintain or exit a relationship is evidenced at the point it is made, not reconstructed after a problem arises.

Step 4 – Design and test the controls

A sanctions risk assessment is only as valuable as the controls it generates. Once the risk map is drawn, the assessment must specify what controls are in place to address each identified risk. Under OFSI's expectations, those controls should cover: screening (which lists are checked, at what frequency, and with what tool); ownership tracing (how beneficial-ownership information is obtained and verified); customer or counterparty due-diligence procedures; payment-screening parameters; escalation routes when a potential match is identified; and record-keeping.

Record-keeping is not an afterthought. OFSI expects firms to retain records of their screening, their match-investigation decisions, and their licensing or exemption reliance. The duration for which records should be kept will depend on the applicable sectoral rules as well as OFSI's enforcement expectations; verify the current position for your sector before finalising your policy.

Controls should be tested. A documented control that has never been stress-tested against a live scenario – a simulated match, a deliberate false-positive injection, a walk-through of the escalation path – is a paper control. OFSI's civil-penalty guidance treats the quality of controls as a direct input to the penalty calculation: a business that had controls but failed to test them is in a different position from one that had no controls at all, but both are in a worse position than one that can demonstrate regular, documented testing.

Cross-regime testing is equally important. If the same screening logic handles OFSI lists, OFAC's SDN List, and the EU Consolidated List, the tester should verify that the tool is drawing from each correctly and is updated after each regime's list amendments. A tool that is calibrated correctly for one regime but is delayed on another creates a window of undetected exposure.

Step 5 – Record, review, and update

A sanctions risk assessment is a living document, not an annual certificate. Three categories of event should each trigger a review: a change in the firm's activity or counterparty base; a material update to the OFSI designated-persons list or to OFSI's guidance documents; and a potential breach or near-miss within the firm.

OFSI does not set a fixed review cycle in its published guidance. What it does say is that firms should have controls that are proportionate and kept up to date. In practice, most compliance counsel advise a minimum annual review of the full assessment, combined with a standing process for list-change monitoring that operates continuously. Where the firm operates in a high-risk sector – financial services, shipping, commodities, virtual assets – the continuous process needs to be genuinely continuous, not a weekly batch run.

The update obligation has a cross-regime dimension. OFAC issues updated guidance and list changes independently of OFSI. EU Council regulations are amended by Council Decisions that appear in the Official Journal without advance notice. If the business is subject to multiple regimes, the monitoring function must cover all of them. A single list-change in one regime that the firm misses can create liability across its entire counterparty exposure in that programme.

What happens when the assessment identifies a potential breach? The answer depends on the facts, but the decision point arrives quickly. OFSI operates a voluntary self-disclosure (VSD) mechanism – a route by which a firm that identifies a potential violation reports it proactively to OFSI. The availability of a VSD, and the credit OFSI gives for it in its penalty calculation, is a direct incentive to maintain a sanctions risk assessment that is current enough to catch problems early. A firm that identifies a breach through its risk process and discloses promptly is in a materially better position than one that OFSI discovers first.

Common risk flags that lead to OFSI enforcement

Enforcement patterns suggest that certain failure modes recur. The most common is screening limited to the direct counterparty without any trace of the beneficial-ownership chain. The second is an assessment that was accurate at the time of initial onboarding but was never updated when circumstances changed – a change of shareholder, a new designation, a corporate restructuring. The third is a reliance on a general licence without confirming that the specific transaction falls within its terms.

A frequently encountered misconception is that OFSI's strict-liability civil standard requires proof of fault. It does not. A business can be entirely unaware of a sanctions link and still be liable for a monetary penalty. What the assessment does is address the mitigation side of the equation: a well-documented assessment, properly maintained and honestly applied, is one of the most effective arguments available when OFSI is calibrating a penalty. There are no guarantees of outcome, but the quality of the assessment is always in play.

Another misconception is that OFSI only pursues banks. In our practice, we advise businesses across professional services, commodities, technology, and real estate on OFSI exposure. The regulated-sector firms carry reporting obligations that create an additional compliance layer, but the underlying financial-sanctions prohibitions apply across all sectors. Any UK-nexus business that makes funds available to a designated person is at risk, regardless of whether it is regulated for anti-money-laundering purposes.

Finally: the interaction with OFAC. A UK business with US-dollar accounts, US investors, or US subsidiaries must consider whether an OFAC secondary-sanctions risk sits alongside the OFSI primary risk. The two regimes are administered independently and do not automatically notify each other. A business that resolves an OFSI matter is not thereby cleared under OFAC. The reverse also holds. Treating the two as separate compliance requirements – with separate assessment workstreams – is the correct approach.

Related practices

Frequently asked questions

What are the steps to carry out a sanctions risk assessment under OFSI?
A sanctions risk assessment under OFSI has five core stages: define the scope of applicable prohibitions; apply the ownership-and-control test to counterparties; identify and weight business-specific risk factors across geography, product, and counterparty base; design and test controls against each identified risk; and document, review, and update the assessment continuously. Each stage should be recorded contemporaneously. OFSI treats the quality of that documentation as a direct input when assessing compliance adequacy and, where relevant, calculating any penalty.
What is the most common mistake in sanctions risk assessment?
The most common mistake is limiting the assessment to direct-name screening without tracing the beneficial-ownership and control chain behind the counterparty. Under the UK ownership-and-control test, a non-listed entity can be fully caught by the prohibition if a designated person exercises effective control, even through a minority stake or contractual arrangement. A second common failure is allowing a completed assessment to become stale – particularly when the designated-persons list is updated or when the counterparty's ownership structure changes.
How does OFSI differ from other regimes here?
OFSI applies a multi-factor control test that extends beyond OFAC's mechanical 50 percent or more ownership threshold. Under OFSI, a designated person holding a minority stake can still trigger the prohibition if that person exercises effective control through governance, contractual, or other means. Additionally, OFSI's civil-penalty standard is strict liability – intent is not required for a finding of liability, though it remains relevant to the penalty quantum. OFAC's framework applies a harder numerical threshold but can impose both civil and criminal penalties in the most serious cases.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.