Calder & Vance International Sanctions & Compliance Counsel

Cross-Border Transactions & Diligence · cross-border

Supply-chain sanctions mapping across regimes: a practical guide

A global electronics distributor sources components from a network spanning twelve countries. Its compliance team screens direct suppliers weekly. Then a tier-two manufacturer – a company the distributor has never contracted with directly – appears on a newly updated designation list. The distributor's goods are mid-transit. Does the shipment need to stop? Who bears liability? These are not hypothetical concerns. As of January 2026, the pace of list updates across OFAC, OFSI, the EU Council, and multiple parallel regimes means that supply chains mapped six months ago may no longer reflect the current legal position.

Supply-chain sanctions mapping is the structured process of identifying, assessing, and recording sanctions exposure across every node of a commercial supply chain – from raw-material suppliers through to distributors and end-users. No single regime governs the whole chain; a shipment touching the United States, the United Kingdom, and the European Union simultaneously engages three distinct ownership tests, three sets of list-screening obligations, and potentially divergent export-control classification requirements.

This guide sets out a practical, step-by-step process for cross-border supply-chain sanctions mapping, explains where the major regimes diverge, and identifies the risk flags that call for specialist counsel.

Step 1: Define the mapping perimeter before any screening begins

The first step in cross-border supply-chain sanctions mapping is to establish which nodes of the chain are in scope and which regimes apply to each – because the regimes in play are determined by the nexus of persons, goods, currencies, and financial flows, not by where the contract is signed.

A useful starting question: which jurisdictions have a connection to this transaction? OFAC's jurisdiction follows US persons, US-origin goods and technology, and US-dollar clearing. OFSI's jurisdiction follows UK persons, UK-incorporated entities, and sterling or GBP-denominated transactions. The EU Council regulations apply to EU persons, EU-incorporated entities, and transactions touching EU territory. These three tests overlap substantially but are not identical, and where they diverge, the stricter prohibition governs in practice.

In our cross-border practice, the most common mapping failure at this stage is scoping based on the primary contracting parties only. A supply chain that looks straightforward – a UK buyer, a Swiss manufacturer, a Taiwanese component supplier – may nonetheless engage US jurisdiction because the Swiss factory uses US-origin machine tools or the settlement goes through a New York correspondent bank. The perimeter must be drawn around all potential nexus points, not just the headline names.

Practical output of Step 1: a written nexus map listing each regime triggered, the basis for its application, and the tier of the supply chain to which it applies. This document becomes the reference point for every subsequent step.

Step 2: Identify and tier the supply-chain nodes

Once the perimeter is set, each node in the chain must be identified and assigned a risk tier – because screening effort should be proportionate to the sanctions exposure each node represents, and unlimited resources are not available to any compliance function.

Risk tiering typically runs on two axes: proximity to the buyer or exporter, and the sensitivity of the goods or services involved. Tier-one nodes are direct contractual counterparties; they receive the most intensive screening. Tier-two nodes – suppliers to suppliers – receive periodic review. Tier-three and beyond receive threshold-based monitoring, triggered by new designation activity or adverse-media events.

Export-control classification intersects here. Under the US Export Administration Regulations (the EAR), an Export Control Classification Number (ECCN – the alphanumeric code on the Commerce Control List identifying the control parameters of a dual-use item) determines which countries and end-users require a licence. High-ECCN items call for deeper supply-chain visibility, because a re-export through an unlicensed intermediate party can engage BIS jurisdiction even if the original US exporter did not control that onward movement.

The EU dual-use rules operate on a comparable logic: items on the EU list require authorisation before export, and transit through an EU member state engages the rules for the EU exporter, not merely the nominal seller. Viktor Lindqvist, who leads our export-controls practice, notes that tiering decisions for dual-use goods must account for all potential re-export destinations, not only the immediate consignee.

Practical output of Step 2: a tiered supply-chain register – at minimum: entity name, jurisdiction of incorporation, tier, goods or services supplied, applicable regimes, and screening frequency.

Step 3: Apply the ownership and control test for each regime

Screening a named entity against a consolidated list is necessary but not sufficient. Each major regime extends its prohibitions to unlisted entities through an ownership and control test – and those tests differ in ways that matter operationally.

Under OFAC, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked, regardless of whether they appear by name on the SDN List) is mechanical. Aggregate the ownership stakes held by all SDN-listed persons in a given entity; if the total reaches or exceeds that threshold, the entity is blocked. Control – board composition, contractual dominance, de facto decision-making – is separately relevant to a different OFAC analysis, but it does not substitute for the ownership calculation.

Under OFSI and the EU Council regulations, the test is ownership and control – a designated person's ownership of 50 percent or more, or the designated person's control through other means, can make a non-listed entity subject to the same restrictions. Control includes the ability to direct management decisions, even where the ownership stake is below the threshold. This is a materially broader test than OFAC's in one direction – it can catch entities where ownership is, say, 35 percent but board control is demonstrable. It is also a more fact-intensive analysis, because control is not read from a share register alone.

Aggregation is where businesses regularly underestimate exposure. Two separately designated persons each holding a 28-percent stake in a supply-chain counterparty cross the OFAC threshold in combination, even though neither triggers it individually. In our experience, automated screening tools that match only against direct listed-person holdings miss this aggregation entirely, because the calculation requires mapping ownership chains rather than names.

For Singapore, Japan, and the UAE, the ownership and control tests are set out in the applicable country regime. Singapore's MAS guidelines on financial sanctions and Japan's Foreign Exchange and Foreign Trade Act each carry list-based obligations; the UAE's domestic regime under the relevant Cabinet resolution extends to entities controlled by listed persons. Where these regimes apply in parallel to OFAC and the EU, the conservative approach is to apply the broadest applicable prohibition, because the regimes do not subordinate themselves to each other.

Practical output of Step 3: for each tier-one and tier-two node, a documented ownership analysis: the shareholders identified, the percentage stakes established to the extent possible from available records, the conclusion on OFAC 50-percent status, and the EU/OFSI ownership-and-control assessment.

Step 4: Screen across regimes and manage the consolidated list

With the ownership analysis complete, list screening itself can proceed meaningfully – because the entity list is now populated not only with the direct contractual counterparties but also with the ownership chain entities surfaced in Step 3.

The principal lists for cross-border screening are: OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and its consolidated non-SDN lists; the UK Consolidated List (maintained by OFSI); the EU Consolidated List (maintained by the Council); and the UN Consolidated List (the list of individuals and entities subject to measures under UN Security Council resolutions, maintained by the 1267/1988/1989 Committee and related committees). BIS maintains the Entity List and the Denied Persons List as separate instruments with distinct consequences for US-origin goods.

The cadence of list updates differs between regimes. OFAC updates its lists without prior notice; a counterparty that screens clean at contract signature may be designated before delivery. The EU Council publishes designations in the Official Journal, typically with some notice period for assets already in transit, though no such grace period is guaranteed. OFSI's practice has aligned increasingly with OFAC's pace following legislative changes under SAMLA.

A cross-border supply chain therefore cannot rely on a point-in-time screen. The practical minimum is a continuous automated feed against all four lists for tier-one and tier-two nodes, supplemented by event-triggered rescreening for all tiers when a major designation tranche is announced. What triggers your event-based rescreening? If the answer is only a supplier's legal team calling you, the programme has a gap.

The position above covers the standard screening architecture. Your specific chain – the counterparties, the goods, the payment routes, the intermediary jurisdictions – may surface additional regime triggers not captured in a generic model. For an assessment of your supply-chain screening architecture, contact Calder & Vance at info@caldervance.com.

Step 5: Assess secondary-sanctions and extraterritorial risk

A supply-chain node may be clean under every applicable primary-sanctions regime and still represent material risk if it generates secondary-sanctions exposure – most commonly under US secondary-sanctions programmes that can restrict access to the US financial system for non-US parties that transact with designated parties, even outside US jurisdiction.

Secondary sanctions operate through a different legal mechanism than primary sanctions: they do not prohibit a transaction outright for a non-US person, but they authorise OFAC to designate, or restrict dealings with, non-US entities that engage in defined categories of transactions with certain designated persons or entities. For a European or Asian business operating in sectors such as energy, shipping, financial services, or defence, the secondary-sanctions risk profile of a supply-chain counterparty can be as consequential as its primary-sanctions status.

In our cross-border practice, we regularly advise logistics and commodities businesses where the headline transaction looks permissible under EU law but where a shipping intermediary in the chain has a transaction history with a person subject to US secondary-sanctions provisions. The EU Blocking Regulation – the EU instrument that prohibits EU persons from complying with certain extraterritorial US sanctions and provides for recovery of damages caused by such compliance – adds a further layer of tension. Compliance with one regime's demands can, in specific circumstances, create liability under another. Mapping that conflict is a necessary part of any thorough assessment.

BIS extraterritorial jurisdiction deserves equal attention for goods-intensive supply chains. The EAR's de minimis and foreign direct-product rules mean that US-origin content or US-origin technology embedded in a foreign-made product can bring the product within BIS jurisdiction, even if the exporting entity has no US connection. The threshold for US-origin content that triggers EAR jurisdiction differs by destination and commodity classification; for items on certain control lists, the threshold is very low.

Practical output of Step 5: a secondary-sanctions and extraterritoriality assessment for each supply-chain node where the primary screen is clean but a material risk indicator is present – transaction history with designated-party-adjacent entities, presence in a sensitive sector, or sourcing of US-origin inputs above relevant thresholds.

Step 6: Document, test, and maintain the mapping programme

A supply-chain sanctions map is not a one-time exercise; it is a living compliance instrument that must be tested, updated, and documented to a standard that can withstand regulatory scrutiny or, if necessary, serve as evidence in an enforcement response.

Documentation should capture the methodology (which lists were screened, the date and time of each screen, the data sources used for ownership analysis), the conclusions reached, and the sign-off trail. OFSI's enforcement guidance places weight on the quality of compliance systems and processes when assessing proportionality in enforcement. OFAC's general approach to voluntary self-disclosure – the process of proactively disclosing an apparent violation to the regulator – assigns significant mitigation value to the existence of a well-documented compliance programme. Both positions reinforce the same operational conclusion: written records matter, and a compliance programme that exists only in the memory of the compliance officer carries no evidential value.

Testing means more than annual reviews. In our experience advising manufacturing and commodities businesses, the most effective programmes run periodic sampling exercises – selecting a random subset of tier-two and tier-three nodes and repeating the full ownership-and-control analysis from scratch, to verify that the initial mapping has not been overtaken by ownership changes. Corporate ownership changes without notice; a supplier acquired by a new holding company may cross the OFAC 50-percent threshold without any change to the supply-chain contract.

Record-keeping obligations across the major regimes are not identical, but the practical minimum is to retain all screening records, ownership analysis documents, and any licence or authorisation obtained, for a period that satisfies the longest applicable retention requirement across all triggered regimes. Verify the current requirement for each regime before finalising your programme.

If a transaction has already been flagged, or a node has screened positive and the correct course of action is not clear, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.

Risk flags that call for specialist counsel

Most supply-chain mapping exercises can be carried out within a well-structured in-house compliance function, but specific risk patterns consistently exceed the capacity of standard internal processes and call for external specialist input.

The first is a positive match or a close-name match against any tier-one node – a direct contractual counterparty that appears on, or is flagged as a potential match for, any of the major lists. The legal position turns quickly on precise facts: jurisdiction, ownership chain, the nature of the goods, the payment structure. A wrong call either way – transacting with a blocked party or ceasing a legitimate transaction unnecessarily – carries operational and legal consequences.

The second is a discovered ownership-chain connection to a designated person at any tier. The 50-percent rule is not satisfied only at tier one; an indirect ownership chain through multiple intermediaries that aggregates to the threshold is legally equivalent to a direct holding. Tracing that chain requires not only screening skill but access to corporate-registry data and, in some jurisdictions, beneficial-ownership filings that are not publicly searchable.

The third is a conflict between regime obligations. Where OFAC's rules and the EU Blocking Regulation point in opposite directions – as they can for non-US businesses in certain sectors – the analysis requires jurisdiction-specific counsel and, potentially, local counsel in the relevant jurisdiction, before a decision is made.

The fourth is a supply-chain node that requires a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) under one regime while being permissible without authorisation under another. The licensing route, the timelines, and the conditions attached to any licence differ substantially between OFAC, OFSI, and the EU Council; managing parallel licensing applications across regimes is a distinct specialist task.

A common objection we hear is that supply-chain mapping at tier two and beyond is disproportionate cost for a business that is not itself a financial institution. The objection misreads the risk. Goods exporters, freight forwarders, and manufacturers of dual-use items are subject to their own primary-sanctions obligations and, crucially, to BIS end-use and end-user controls that run through the supply chain, not just to the first buyer. An enforcement action for a knowing violation does not require proof that the exporter checked a list; it requires proof that the goods reached a prohibited destination or person.

In a recent matter, a mid-sized industrial equipment manufacturer faced an apparent violation query from a regulatory authority after a distributor in a third market on-sold goods to an entity subsequently designated under the applicable regime. We reviewed the ownership chain, assessed the voluntary self-disclosure position, and prepared the compliance documentation package. The early identification of the programme gaps was what made the response credible. Outcomes in such matters are never guaranteed; early action does, however, consistently preserve more options than delayed response.

Related practices

Frequently asked questions

What are the steps to map sanctions risk in the supply chain under cross-border?
Cross-border supply-chain sanctions mapping follows six steps: define the regime-nexus perimeter; identify and tier all supply-chain nodes; apply the ownership and control test for each applicable regime; screen all nodes and their ownership chains against the principal consolidated lists; assess secondary-sanctions and extraterritorial risk for clean-screening nodes that present other risk indicators; and document, test, and maintain the mapping programme to a standard that withstands regulatory scrutiny. The starting point is always the perimeter question – which regimes apply – because screening before that question is answered will miss material exposure.
What is the most common mistake in supply-chain sanctions mapping?
The most common mistake is scoping the exercise to direct contractual counterparties only, then running a single point-in-time screen. This approach misses two critical risk vectors: indirect ownership connections that cross the 50-percent threshold through aggregated holdings at tier two or beyond, and list updates that occur between contract execution and delivery. An effective programme screens continuously, maps the full ownership chain for tier-one and tier-two nodes, and has a clear event-triggered rescreening procedure for all tiers when significant designation tranches are published.
How does cross-border differ from other regimes here?
A cross-border supply-chain analysis differs from a single-regime exercise primarily in the need to resolve divergences between ownership tests, list-update cadences, and extraterritorial rules that do not align across OFAC, OFSI, the EU Council, and parallel regimes in Singapore, Japan, or the UAE. Where those regimes conflict – most visibly between US extraterritorial measures and the EU Blocking Regulation – the analysis cannot be reduced to applying the most conservative rule mechanically; it requires a considered legal position on which obligation governs in the specific factual circumstances, which is a matter for specialist counsel.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.