A trading company in Singapore signs a freight-forwarding agreement with a counterparty headquartered in a third market. The compliance team runs a name screen. The counterparty clears every list. Three months later, a correspondent bank flags the relationship: a minority shareholder in the counterparty's parent appears on the UN Consolidated List (the Security Council's master list of designated persons and entities). The transaction is frozen. Untangling it takes weeks. Could a structured sanctions risk assessment have caught this earlier?
As of August 2026, businesses operating in or through Singapore must assess their sanctions exposure against two overlapping layers: Singapore's own autonomous sanctions regime, administered through the Monetary Authority of Singapore and relevant trade authorities, and the UN Security Council obligations that Singapore implements as a UN member state. A structured sanctions risk assessment maps both layers against the business's specific counterparties, transaction flows, and goods or services, and produces a prioritised risk register. Neither layer can be assessed in isolation.
This guide walks through the assessment in six sequential steps, identifies the common failure points, and explains where cross-border exposure to OFAC, OFSI, and EU regimes demands parallel analysis alongside the Singapore-specific work.
Step 1 – Establish the legal basis and the authorities that govern your exposure
Singapore's sanctions obligations derive from two distinct sources, and the risk assessment must identify both before any screening or control is designed. The first source is the UN Security Council: Singapore implements all mandatory Security Council resolutions under its domestic legislation, meaning that the UN Consolidated List applies directly to persons and entities operating through Singapore. The second source is Singapore's autonomous sanctions regime, which imposes obligations that go beyond the UN baseline.
The Monetary Authority of Singapore issues regulatory notices and guidelines relevant to financial institutions on sanctions compliance. The relevant trade authorities – including Singapore Customs – administer controls on strategic goods, which interact with sanctions on dual-use and controlled items. A risk assessment that covers only one authority and ignores the other will produce an incomplete picture.
Why does the distinction matter in practice? Because the trigger for a financial institution's obligation under the MAS notices may differ from the trigger for a trading company's obligation under the strategic-goods rules. We regularly advise businesses that have been screening counterparties against the UN list but have not mapped their obligations under Singapore's autonomous measures – and found gaps that required urgent remediation.
The cross-border dimension begins here. Singapore entities with US-dollar payment flows, US-person involvement, or US-origin goods face OFAC jurisdiction concurrently. OFAC's SDN List (the list of Specially Designated Nationals and blocked persons) and the 50 percent rule (OFAC's rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked) apply regardless of where the transaction is booked. A Singapore-law contract denominated in US dollars touches OFAC. The risk assessment must acknowledge this from the outset.
Step 2 – Map your business activities, counterparties, and transaction flows
A sanctions risk assessment is only as useful as the underlying map of what the business actually does. Before any screening tool is opened, the assessment requires a structured inventory of the business's activities, the jurisdictions they touch, the counterparties involved, and the goods or services moving through each channel.
That inventory should address four dimensions. First, geography: which markets does the business source from, sell into, or transit through? Second, counterparty type: are they financial institutions, trading companies, freight operators, state-owned enterprises, or individuals? Third, goods and services: are any items controlled under Singapore's strategic-goods rules, the US Export Administration Regulations, or the EU dual-use regime? Fourth, payment flows: which currencies and correspondent-bank chains are in use?
The freight and logistics sector illustrates the point well. In a recent matter, a Singapore-based freight forwarder had mapped its direct customers but had not traced the consignee chain for re-export cargo. The re-export route passed through a jurisdiction with active UN Security Council restrictions. The gap was not in the screening tool – it was in the scope of the map. We assisted the business in restructuring its counterparty-mapping process to capture the full chain, not only the first-tier relationship.
This mapping exercise also forces the business to address ownership and control (the test for whether a non-listed entity is caught because a listed person owns or controls it). Singapore's regime, like the UN framework, looks through corporate structures where a sanctioned person holds a controlling interest. The map must reach the beneficial-ownership layer, not stop at the immediate counterparty. Have you traced ownership beyond the registered shareholder?
Step 3 – Screen counterparties, owners, and transaction elements against the applicable lists
Screening is the most visible part of a sanctions risk assessment, but it is not the most important. List matching catches only what the lists contain; the quality of the map in Step 2 determines whether the right inputs reach the screening tool. A well-designed screening process for Singapore must cover the UN Consolidated List, Singapore's autonomous designations, the OFAC SDN List and other OFAC lists where US-person or US-dollar nexus exists, and – for businesses with EU or UK connections – the EU consolidated financial-sanctions list and the OFSI list.
Screening frequency matters as much as coverage. A one-time check at onboarding is not adequate for high-risk or long-duration relationships. Designations are added without advance notice; a counterparty that was clean at onboarding may be listed two months later. Periodic re-screening – calibrated to the risk level of the relationship – is standard practice for businesses that take their Singapore sanctions obligations seriously.
Name-matching quality is a persistent operational problem. Transliteration variants, use of aliases, and partial name matches all produce false negatives if the screening logic is set too narrowly, and false positives in volume if set too broadly. In our experience, firms that rely on exact-match screening and do not apply fuzzy-matching logic miss a material proportion of true hits. The reverse is also true: poor fuzzy-matching logic generates so many false positives that compliance staff begin approving alerts without proper investigation.
The position above covers the standard onboarding case. Your facts – the counterparty's jurisdiction, the ownership structure, the goods in transit, the payment route – change the analysis. For an assessment of your screening coverage under Singapore and the intersecting regimes, contact Calder & Vance at info@caldervance.com.
Step 4 – Apply the ownership and control test across all relevant regimes
A counterparty that does not itself appear on any list may still be prohibited if a designated person owns or controls it. Applying the ownership and control test is therefore a mandatory element of any complete sanctions risk assessment, and the test varies significantly between Singapore, OFAC, OFSI, and the EU.
Under OFAC, the ownership test is mechanical: any entity owned 50 percent or more in the aggregate by one or more SDN persons is itself treated as blocked, automatically, whether or not it is separately listed. The aggregation principle means that two SDN shareholders each holding 26 percent would together trigger the rule. Control – however extensive – does not independently trigger the rule under OFAC; ownership is the test.
Under OFSI and the EU regime, the position is broader. Both regimes apply an ownership and control test: an entity is caught not only where a designated person holds a majority ownership interest, but also where a designated person exercises control through other means – through voting rights, contractual arrangements, or the ability to direct management. This is a materially wider net than the OFAC rule, and it is the rule that applies where the Singapore business has a UK or EU nexus.
Singapore's autonomous regime applies an ownership and control analysis that, in its current published form, is closer in structure to the UN and OFSI approach than to OFAC's purely mechanical ownership threshold. Where the Singapore regime and OFAC apply concurrently – as they frequently do for Singapore-based businesses with US-dollar payment flows – the stricter prohibition governs. The risk assessment must document which regime produces the more restrictive outcome and apply that outcome.
How thoroughly are you tracing the ownership chain beyond the first corporate layer? Experience before multiple regimes shows that ownership chains of three or four layers are not uncommon in the trading and logistics sectors that dominate Singapore's economy. A risk assessment that stops at the immediate counterparty and does not reach the ultimate beneficial owner is structurally incomplete.
Step 5 – Evaluate cross-border exposure to OFAC, OFSI, and EU regimes
Singapore-based businesses are not insulated from OFAC, OFSI, or EU sanctions simply because their contracts are governed by Singapore law. Each of those regimes asserts jurisdiction on the basis of connection to its territory, currency, or persons – and those connections are common in Singapore's trade and financial environment.
OFAC asserts jurisdiction over any transaction that involves a US person (including US-incorporated entities and US citizens wherever located), that is denominated in US dollars and cleared through a US correspondent bank, or that involves US-origin goods or technology. In practice, the US-dollar clearing point is the most frequent OFAC touchpoint for Singapore businesses. Even a Singapore-to-Singapore transaction can touch OFAC if payment clears through a New York correspondent. The risk assessment must identify every transaction that touches any of these jurisdictional hooks.
OFSI and the UK regime are relevant where the Singapore business has UK-person involvement, sterling payment flows, or goods that constitute UK-controlled items under the Export Control Order. As of August 2026, the UK maintains autonomous designations under the Sanctions and Anti-Money Laundering Act (SAMLA) across multiple thematic programmes, and those designations do not always mirror the UN or EU lists. A business that screens only the UN list and assumes UK alignment will have a gap.
The EU regime matters where EU-incorporated entities, EU nationals, or EU-origin goods are involved. The EU's autonomous designations under the relevant Council regulations are likewise not always coextensive with the UN or UK lists. For Singapore businesses active in European supply chains, a complete risk assessment therefore requires parallel coverage of the EU consolidated financial-sanctions list.
If a transaction has already been flagged – by a correspondent bank, a counterparty, or an internal alert – an early review can preserve options that narrow with time. For a confidential review of a potential cross-border exposure, contact Calder & Vance at info@caldervance.com.
Step 6 – Document findings, assign risk ratings, and design proportionate controls
The output of a sanctions risk assessment is a documented risk register, not a binary clean/blocked finding. A risk register records the methodology, the lists screened, the ownership-and-control analysis applied, the conclusions reached for each material counterparty or transaction type, and – critically – the risk rating assigned to each finding.
Risk ratings calibrate the response. A counterparty assessed as low risk requires periodic re-screening but no enhanced due diligence. A counterparty assessed as high risk – because of its sector, its jurisdiction, its ownership structure, or its payment-route complexity – requires enhanced due diligence, senior sign-off, and potentially a transaction-specific legal opinion before proceeding. A clear and proportionate escalation path from each risk category is an essential design feature of the control architecture.
Proportionality is the operating principle throughout. Singapore's MAS guidance emphasises a risk-based approach: controls should be calibrated to the actual risk profile of the business, not applied uniformly regardless of the risk level of each relationship. A small commodities trader with one trading corridor has a materially different risk profile from a major financial institution with global correspondent-bank relationships. The risk assessment must reflect the actual business, not a generic template.
Record-keeping is a compliance obligation in its own right. A well-maintained risk assessment file – showing the date of each screen, the lists covered, the results obtained, and the decisions taken – is the primary defence document in any regulatory inquiry. Retain records in a form that allows the assessment to be reconstructed and reviewed. We advise clients to build record-keeping into the risk assessment workflow from the outset, rather than reconstruct it after a query arrives.
What are the common risk flags – and when should you involve counsel?
Certain patterns in a risk assessment consistently indicate elevated exposure. Recognising them early allows a business to seek advice before a transaction completes, when the options for managing the position are widest.
The first risk flag is opacity in the counterparty's ownership structure. Where a counterparty declines to disclose its beneficial owners, uses nominee structures in high-risk jurisdictions, or presents a corporate structure with an unusual number of intermediate holding entities, the ownership-and-control analysis becomes harder to complete and the residual risk is higher. Opacity does not itself establish a violation, but it demands additional scrutiny.
The second is transaction routing that does not follow the natural commercial logic. Re-routing of goods through multiple third countries before reaching the declared end destination, use of a payment intermediary in a jurisdiction with a high sanctions exposure profile, or a mismatch between the goods' technical classification and the stated end use are all patterns that experienced sanctions counsel look for. These patterns can have innocent explanations; they can also indicate a risk that the counterparty itself has not disclosed.
The third flag is dual-use goods moving through sectors or corridors with active UN or Singapore restrictions. Where a product has both a civilian and a military application – an ECCN (Export Control Classification Number under the US Commerce Control List) or a Singapore strategic-goods classification – the risk assessment must address not only sanctions list hits but also the end-use and end-user controls required by the applicable export-control regime. Sanctions and export controls frequently interact in exactly this way.
A common myth in this area is that a clean name-screen result ends the inquiry. It does not. The sanctions risk assessment is not complete when no name match is found; it is complete when the ownership chain has been traced to the beneficial-ownership layer, the cross-border jurisdictional hooks have been evaluated, the transaction pattern has been assessed for red flags, and a documented conclusion has been reached and signed off by an appropriate level of management. A name screen is Step 3 of a six-step process. Treating it as the whole process is the most common compliance failure we encounter.
Related practices
- Compliance audit and testing (Australia) – structured audit methodology for testing sanctions controls against the Australian regime
- Sanctions risk assessment under the UN regime – step-by-step guide to assessing exposure against the UN Consolidated List
- Trade finance controls (Australia) – sanctions and export-control considerations for trade-finance transactions involving Australia