Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Sanctions risk assessment under OFSI: a compliance guide

A mid-sized financial institution in London begins onboarding a new corporate client. The counterparty looks clean at first glance. Then a compliance officer traces the ownership chain one level deeper and finds a minority shareholder who appears on a UK sanctions list. Is the client caught? Does a transaction freeze apply? Can the business continue the relationship at all? As of August 2026, OFSI's published enforcement posture makes clear that these questions carry real financial and reputational consequences for firms that answer them late or incorrectly.

A sanctions risk assessment under OFSI – the UK's Office of Financial Sanctions Implementation (the primary enforcement body for financial sanctions under the Sanctions and Anti-Money Laundering Act, commonly called "SAMLA") – is the structured process by which a business identifies, measures, and manages its exposure to UK financial sanctions prohibitions. The assessment should map the firm's activities against the UK sanctions lists, test the ownership and control test (the UK standard for determining whether a non-listed entity is caught through a listed person's interest), and produce a documented record that demonstrates proportionate compliance. Firms that skip this process, or run it superficially, face enforcement risk even where no breach has yet occurred.

This guide takes a compliance practitioner through the process step by step: the legal authority and governing regime, the ownership and control test in depth, the cross-border dimensions that make the UK position more complex than it first appears, the common errors that produce enforcement exposure, and the point at which professional advice materially reduces risk.

What is the legal basis for sanctions risk assessment under OFSI?

SAMLA and the thematic sanctions regulations made under it together form the primary UK legal authority for financial sanctions, and they give OFSI its mandate to enforce compliance. The sanctions risk assessment obligation does not sit in a single statutory provision; it arises from the combination of the financial-sanctions prohibitions themselves, OFSI's published compliance guidance, and the expectations set by the UK's financial-crime supervisory regime. Every business that could plausibly be involved in a transaction with a UK-designated person – a bank, a payment firm, a trade-finance house, a professional services firm handling client funds – is within scope.

OFSI operates under the Treasury. It publishes a consolidated list of designated persons and entities, and it expects regulated firms to screen against that list as a minimum. But formal designation-list screening is only one component of a sanctions risk assessment. OFSI's own compliance guidance goes further: it asks firms to consider the nature of their business, the sectors and geographies in which they operate, the customer and counterparty profiles they deal with, and the services they provide. A commodities trading house has a different sanctions risk profile from a retail lender. The assessment must reflect those differences.

OFSI distinguishes between the specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) and the general licence (a standing authorisation that permits a defined category of transactions without a separate application). Both licences are relevant to risk assessment: a well-run assessment identifies in advance which activities fall within an existing general licence and which would require a specific application. Firms that reach that analysis only after a problem surfaces lose time and options.

The position above covers the standard case. Your facts – the sectors you operate in, the counterparties you face, the volume of cross-border payment flows – change the analysis significantly. For an early assessment of where your business stands under OFSI, contact Calder & Vance at info@caldervance.com.

How does the ownership and control test work under UK sanctions?

The UK ownership and control test determines whether a non-listed entity is itself subject to UK financial-sanctions prohibitions because a designated person owns or controls it. Unlike OFAC's mechanical 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked), the UK position includes a control limb that makes the analysis qualitative as well as quantitative.

Under the relevant UK thematic regulations, a person is treated as owning an entity if designated persons, alone or together, hold more than 50 percent of the shares or voting rights, or the right to appoint or remove a majority of the board. That is the ownership limb – broadly comparable to the OFAC threshold. But the control limb is broader. It captures situations where a designated person holds the right, directly or indirectly, to ensure that the entity's affairs are conducted in accordance with their wishes. Contractual rights, debt covenants, informal dominance of the board, and certain veto rights can all engage the control analysis even where formal equity ownership is below 50 percent.

In our experience, the control limb is where businesses make the most consequential errors. A private equity fund may hold 35 percent of a target company, with a designated person also holding 35 percent and a board seat. The fund focuses on the equity percentage, sees no issue, and proceeds. The question it has not answered is whether the designated person's board seat, together with a consent right over significant transactions, amounts to control. That question requires legal analysis, not just screening.

The EU position – under the Council regulations that impose asset-freeze obligations in comparable terms – mirrors the UK control limb in structure, though the two regimes are not identical and diverge in certain details. A business subject to both sets of rules should not assume that a UK ownership-and-control clearance resolves its EU position, or vice versa. We regularly advise clients on precisely this divergence, where a structuring decision that is defensible under one regime creates a residual question under the other.

Step-by-step: carrying out an OFSI sanctions risk assessment

A well-structured OFSI sanctions risk assessment follows a defined sequence. The steps below apply to businesses of any size, though the proportionality principle means that a small professional-services firm will execute each step at a different depth than a large bank or commodities trader.

  1. Scope the business and identify exposure vectors. Before running a single name through a screening tool, the compliance function should map the categories of person and entity it deals with – customers, suppliers, counterparties, investors, beneficiaries. This scoping exercise determines where sanctions risk could enter the business and which parts of it are highest-risk.
  2. Screen against the OFSI Consolidated List and comparator lists. Screen every relevant name against the UK Consolidated List. For businesses with cross-border exposure, this should also include OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and the EU's asset-freeze lists, at minimum. Secondary-sanctions considerations – the risk that a transaction with a non-US person could engage US sanctions on that person – require OFAC screening even for businesses that are not US-connected.
  3. Apply the ownership and control test to entity counterparties. List screening is necessary but not sufficient. For each corporate counterparty, trace the ownership chain to identify any direct or indirect interest held by a designated person. Apply the UK ownership limb (above 50 percent in the aggregate) and then, for any material interest below that threshold, consider the control limb. Document the analysis and the evidence gathered.
  4. Assess sector and product risk. Some sectors carry elevated sanctions risk by regulatory design – financial services, energy, defence-adjacent technology, shipping, and certain professional services among them. OFSI's guidance identifies high-risk sectors. Map your firm's products and services against those sectors, and flag any activities that are subject to specific sectoral restrictions under the UK thematic regulations.
  5. Review and test transaction monitoring and screening tools. A risk assessment is not complete without testing whether the systems that execute the policy actually work. This means checking that screening tools are updated in a timely way when the Consolidated List is amended, that fuzzy-matching logic captures name variants and transliterations, and that alerts are being reviewed by appropriately qualified staff with a clear escalation path.
  6. Document the assessment and record remediation steps. OFSI expects firms to keep records of their compliance work. Document the methodology used, the scope of persons and entities reviewed, the results, and any remediation decisions taken. Good documentation is the first line of defence in an enforcement inquiry and demonstrates the good faith that OFSI treats as a relevant factor.
  7. Set a review cycle. Sanctions designations are added, varied, and removed on an ongoing basis. A risk assessment that was accurate when produced becomes stale. Build in a formal review cycle – at minimum annually, and triggered by any material change in the business, in the counterparty profile, or in the UK sanctions regime relevant to your sectors.

Each of these steps generates evidence. Taken together, they produce a defensible record that the firm took its sanctions obligations seriously, which is directly relevant to OFSI's published approach to penalties.

What are the cross-border dimensions every UK business should consider?

OFSI's jurisdiction operates on a UK nexus: UK persons and UK-incorporated entities are bound wherever they are in the world; and any person, wherever incorporated, is bound when they act within the United Kingdom or use UK-clearing infrastructure. But the cross-border dimension of sanctions risk assessment extends beyond that nexus, and it is where many businesses underestimate their exposure.

Consider a UK-based group with a subsidiary in the United Arab Emirates conducting a transaction that clears through a US correspondent bank. The transaction involves a counterparty whose beneficial owner sits on no UK list, but appears on the OFAC SDN List. The subsidiary may have no direct OFAC obligation – it is not a US person and does not conduct business in the United States. But the US correspondent bank will freeze or reject a payment involving an SDN. The transaction fails. The group's exposure is operational, reputational, and potentially a trigger for the US bank to exit the correspondent relationship entirely.

This is the secondary-sanctions and banking-channel risk that a UK-only OFSI assessment does not catch. In our practice, we regularly advise clients operating between UK, EU, and Middle East jurisdictions to layer at least three screening tests: the UK Consolidated List, the OFAC SDN List (for correspondent-banking and USD-payment risk), and the EU asset-freeze list (for EU-counterparty and EU-subsidiary risk). Where the business has connections to Singapore or Japan – both of which have autonomous sanctions regimes aligned in structure to UN Security Council measures – those regimes add a further layer.

The UN Security Council Consolidated List is the baseline. All major regimes implement UN-mandated measures. But autonomous measures – UK, OFAC, EU – go further and differ from each other. A counterparty clean on the UN list may still be designated under OFAC's autonomous programme or under UK-specific designations. The safest screening posture covers all relevant lists, with the applicable country regime's rules governing when the obligation bites.

Does your current compliance programme reflect all the regimes that could affect your business – not just the one where you are incorporated? That question is worth asking before the next transaction, not after it.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.

What are the most common risk flags in OFSI sanctions assessments?

Certain patterns generate disproportionate enforcement exposure, and recognising them early is the practical value of a risk assessment. In our experience advising firms across financial services, commodities trading, and professional services, the following flags appear most frequently.

Incomplete beneficial ownership mapping. Screening the direct counterparty and missing the ownership layer above it is the single most common failure. A corporate counterparty presents a clean name to the world. Its parent, or the parent's parent, holds the risk. The UK ownership and control test requires going up the chain until you have identified every natural person with a significant interest, or have confirmed that no such person appears on a relevant list.

Stale screening data. The OFSI Consolidated List is updated without notice when a new designation is made. A screening run on Monday may be accurate; the same result on Friday may miss a designation made on Wednesday. Firms that run periodic batch-screening rather than real-time or near-real-time screening carry a time-window gap that can catch them out.

Failure to assess existing counterparties after list updates. New business is typically screened. Existing relationships frequently are not rescreened when the Consolidated List changes. If a long-standing client or supplier is designated mid-relationship, the business continues to deal with them by inertia, not by decision. That is the factual pattern that produces enforcement exposure.

Underestimating the control limb. As discussed above, the UK control test is broader than a simple equity threshold. Firms that set their screening policy to "flag anything where a listed person holds more than 50 percent" are not compliant with UK law. The control limb requires separate analysis.

No documented response procedure for screening alerts. A screening tool that generates alerts is only useful if the firm has a documented procedure for reviewing them, escalating live hits, and recording the outcome of each review. OFSI enforcement inquiries routinely examine whether the firm had a procedure and whether it was followed. Absence of a procedure is itself an aggravating factor.

Treating OFSI compliance as an annual exercise. The annual compliance review is a minimum, not a standard. The risk assessment should be a living document, updated when the business changes – new products, new sectors, new geographies, new counterparty types – and reviewed whenever a relevant sanctions designation is made.

A common misconception: when does a voluntary self-disclosure reduce risk?

A persistent myth in OFSI compliance is that voluntary self-disclosure is relevant only to large, systemic breaches. The thinking runs: "We're a small firm; we had one potential issue; a voluntary self-disclosure will attract more scrutiny than it deflects." That view misunderstands how OFSI's enforcement discretion operates.

OFSI's published approach to enforcement identifies good faith and cooperation as factors that can reduce a penalty or lead to a case being handled at a lower level of enforcement response. A VSD (voluntary self-disclosure to a regulator) – a formal report to OFSI of a potential or apparent breach – demonstrates both. It does not guarantee a particular outcome, and it does not preclude enforcement. But it materially affects the starting position. A firm that self-reports promptly and cooperates fully is treated differently from one that is discovered through external reporting or a supervisory inspection.

The practical implication for risk assessment is this: when the assessment surfaces an apparent historic breach – a payment made before the current screening programme was in place, a counterparty that was subsequently designated – the firm faces a decision. Does it investigate further, document the finding, and consider whether a self-disclosure is appropriate? Or does it note the issue and move on? Getting that decision right requires legal advice, not just compliance judgment.

In a recent matter, a professional-services firm running its first structured OFSI risk assessment identified a past engagement where a client had been designated under UK sanctions regulations during the course of the engagement. The firm had continued to issue invoices and receive payment after the designation date. We scoped the apparent violation, advised on the voluntary self-disclosure process, and prepared the disclosure to OFSI. The matter was handled through a reduced enforcement response, in part because of the promptness and quality of the disclosure.

When should a business involve sanctions counsel for an OFSI assessment?

Many businesses treat sanctions risk assessment as an internal compliance function, and in routine cases that is appropriate. But there are situations where legal advice before or during the assessment is not optional – it is the difference between closing a gap and creating a documentary record that makes a later problem worse.

Involve external sanctions counsel when:

  • The ownership and control analysis involves a complex structure – multiple layers, mixed jurisdiction, contractual control mechanisms, or disputed beneficial ownership.
  • The assessment surfaces a potential historic breach or a current transaction that may be prohibited.
  • The business is entering a new sector or jurisdiction with elevated sanctions risk, and the existing programme has not been designed with that exposure in mind.
  • OFSI has made contact – a request for information, a preliminary enquiry, or a formal notice.
  • The business is a transaction counterparty to a deal where another party's sanctions compliance is in question.
  • The firm's supervisory authority (the FCA, PRA, or another sector regulator) has indicated that sanctions compliance is an area of focus in an upcoming review.

These are not exceptional circumstances. In our practice across financial institutions, commodities businesses, and professional-services firms, at least one of the above applies to the majority of structured risk assessments we assist with. Identifying the legal question early – before the risk assessment has already documented a response – is almost always the better posture.

Related practices

Frequently asked questions

What are the steps to carry out a sanctions risk assessment under OFSI?
An OFSI sanctions risk assessment follows seven principal steps: scoping the business and identifying exposure vectors; screening against the OFSI Consolidated List and relevant comparator lists; applying the UK ownership and control test to corporate counterparties; assessing sector and product risk; reviewing and testing screening tools and transaction monitoring; documenting the assessment and any remediation; and setting a structured review cycle. Each step should produce a written record. OFSI's compliance guidance sets out the expectations in more detail, and proportionality applies – a large financial institution will execute each step at greater depth than a small professional-services firm.
What is the most common mistake in sanctions risk assessment?
The most common mistake is treating list-screening as the whole assessment. Screening the direct counterparty name is necessary but not sufficient. Firms routinely miss the ownership layer above the direct counterparty – a parent or beneficial owner who is designated but whose name does not appear on the counterparty's own record. The second most common error is failing to apply the UK control limb: looking only at equity percentages and missing the qualitative control analysis that UK sanctions regulations require. Both gaps are addressable through a structured ownership mapping exercise, combined with legal analysis of the control position where the result is ambiguous.
How does OFSI differ from other regimes here?
OFSI's ownership and control test includes a qualitative control limb that goes beyond OFAC's mechanical 50 percent ownership rule. Under the UK thematic regulations, a non-listed entity can be caught where a designated person has the right to ensure that its affairs are conducted in accordance with their wishes, even without majority equity ownership. The EU test is broadly comparable in structure but the two regimes are not identical. OFSI also operates its own licensing regime independent of OFAC and the EU: a licence from one authority does not authorise activity under another, and a business with multi-regime exposure must address each regime separately.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.