A trading company restructures its supplier base to enter a new market. Weeks into the relationship, a routine document review surfaces a name on the UK Consolidated List (the list of persons and entities subject to financial sanctions under UK law, maintained by OFSI). The question is not whether the supplier appears – it does not. The question is whether a listed person sits behind it, owning enough to make every payment a sanctions breach. That question is answered by supply-chain sanctions mapping under OFSI: a structured exercise that traces ownership, control, and commercial exposure through every layer of a supply chain.
Supply-chain sanctions mapping under OFSI requires a business to identify any person or entity in its supply chain that is designated under UK financial-sanctions regulations, or that is owned or controlled by a designated person, applying OFSI's ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person). The test looks beyond the immediate counterparty to the beneficial-ownership structure behind it. As of January 2026, OFSI has civil monetary-penalty powers that extend to strict-liability breaches – meaning intent is not required for a penalty to issue.
This guide sets out the steps in a practical mapping exercise, the points where the OFSI regime diverges from OFAC and the EU, the risk flags that practitioners see most often, and when to bring in specialist sanctions counsel.
Step 1: Define the scope of the mapping exercise
The first step is to draw the boundary of the mapping exercise before any data is gathered. Scope determines cost, timelines, and – critically – the depth of ownership investigation you will conduct on each counterparty.
Under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic regulations made under it, the prohibitions apply to UK persons anywhere in the world and to all persons operating within the UK. That jurisdictional reach means a UK-registered company must map sanctions exposure across its entire supply chain, not just its UK-facing contracts. A subsidiary incorporated in a third country may still trigger UK obligations if the transaction involves a UK person or passes through the UK financial system.
In practice, scope is usually defined by three variables. First, the commercial perimeter: which supplier tiers are included (tier-one suppliers, tier-two, and so on). Second, the risk-weighting criteria: geography, sector, goods type, and the presence of politically exposed persons in the ownership chain. Third, the applicable regime: for a business with US or EU operations, OFAC and EU sanctions will run alongside OFSI, and the mapping exercise must address all three simultaneously.
A scoped, risk-weighted exercise avoids the trap of conducting surface-level checks on thousands of counterparties and deep checks on none. We regularly advise clients to build a tiering matrix at the outset – a document that records the risk rationale for each counterparty category and the depth of investigation assigned to it. That matrix is itself a compliance record if a question arises later.
Step 2: Gather and structure the ownership data
Ownership data is the raw material of any supply-chain mapping exercise, and its quality determines whether the mapping exercise produces a defensible result. OFSI's enforcement guidance makes clear that the reasonableness of a firm's due-diligence process is a mitigating factor in penalty decisions; a poorly documented data-gathering step undermines that mitigation.
For each counterparty in scope, gather: (a) the legal entity identifier or registered number; (b) the full legal name and any trading names or recent name changes; (c) the registered jurisdiction; (d) the current beneficial-ownership register entry or equivalent disclosure; and (e) the names and nationalities of any individuals holding or controlling more than a defined percentage of the shares or voting rights.
The percentage threshold matters. Under the UK regime, OFSI applies an ownership and control test. A person is treated as owning or controlling an entity if a designated person holds, directly or indirectly, more than 50 percent of the shares or voting rights, or otherwise exercises control over its management. The critical difference from the US position is the control limb: OFSI can treat a company as caught even where ownership sits below 50 percent, if a designated person controls it in fact. OFAC's corresponding test is mechanical – 50 percent or more in the aggregate, with no separate control limb of the same breadth. That divergence directly affects how you assess a counterparty whose ownership chain includes a minority stake held by a listed person.
Document the source of each piece of ownership data, the date it was obtained, and the version of the Consolidated List against which it was checked. Records of this kind serve two purposes: they demonstrate the diligence that was conducted, and they create a baseline for periodic refresh.
Step 3: Apply the ownership and control test across the chain
Applying the ownership and control test is the analytical core of the mapping exercise. For each entity in scope, the question is whether any designated person – on the UK Consolidated List or on a list maintained by a regime that applies alongside it – owns or controls that entity, directly or through one or more intermediate layers.
Direct ownership is usually visible. The difficulty lies in indirect and layered structures. A supplier may have a clean corporate record in the UK Companies House register and yet be owned through a chain that runs through multiple jurisdictions, ending in a holding vehicle associated with a listed person. Screening the counterparty name alone will not surface that exposure.
The mapping step requires walking each ownership chain to its ultimate beneficial owner. Where the chain is opaque – for example, where a vehicle is incorporated in a jurisdiction with restricted corporate-transparency rules – the absence of information is itself a risk flag that must be recorded and escalated. In our experience, the weakest point in most supply-chain mapping exercises is the assumption that a clean company-registry search closes the ownership question. It does not.
A specific aggregation point deserves attention. Under both the OFSI test and its EU counterpart, the holdings of multiple designated persons in the same entity are considered together. If two designated persons each hold 26 percent of a supplier, their combined holding exceeds 50 percent, and the entity is caught. Screening tools calibrated to flag only entities with a single listed-person stake above 50 percent will miss this pattern entirely. Have you configured your screening logic to aggregate holdings across multiple designated persons in the same target?
The EU regime runs the same aggregation logic. OFAC does too, but the control limb is narrower in the US context, meaning an entity caught under OFSI may not be blocked under OFAC. That divergence matters for cross-border transactions: the stricter prohibition governs, so a US company working with a UK entity should apply whichever test produces the more restrictive outcome.
The position above covers the standard case. Your facts – the jurisdiction of incorporation, the structure of the ownership chain, the goods involved, and the specific regime in play – change the analysis materially. For a confidential review of a potential supply-chain exposure under OFSI, contact Calder & Vance at info@caldervance.com.
Step 4: Screen against the applicable lists
Once the ownership data is structured and the chains are mapped, each identified person – both entities and individuals – must be screened against the applicable sanctions lists. For a UK-regulated exercise, the primary list is the UK Consolidated List. For businesses with cross-border exposure, OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons), the EU consolidated list, and the UN Security Council Consolidated List must be added to the screening run.
Screening is not a one-time event. The UK Consolidated List is updated without advance notice. A counterparty that was clean at the outset of a contract may be designated mid-performance. The mapping exercise must therefore establish a refresh cycle and a trigger mechanism for out-of-cycle re-screening when a material change occurs – for example, a change in the counterparty's ownership, a change in the designated status of a known associate, or a public report of regulatory interest in the counterparty's sector.
Name-matching logic introduces a further layer of risk. Designations are recorded against the name as known at the time of listing, but counterparties may operate under transliterations, aliases, former names, or related-entity names not separately listed. Effective screening requires fuzzy-matching configured to surface close variants, cross-checked against any aliases recorded in the list entry. A firm that relies on exact-name matching will generate false-negative results.
The records generated in this step – the lists checked, the date of each check, the version of the list, the match result, and the disposition of any hit – form the core of the compliance file for the transaction. OFSI's enforcement posture, as set out in its published guidance, treats the adequacy of a firm's screening records as a relevant factor in any subsequent enforcement assessment.
What are the most common risk flags in OFSI supply-chain mapping?
Ownership opacity is the single most common risk flag. A counterparty that cannot or will not provide full beneficial-ownership documentation presents a structural compliance problem. The inability to complete the mapping exercise is itself a red flag requiring escalation. Proceeding without adequate ownership data, in the hope that no listed person is present, is not a defensible compliance posture under OFSI's guidance.
A second pattern that practitioners see regularly is the interposition of an intermediate entity in a low-transparency jurisdiction between the buyer or seller and the ultimate beneficial owner. These structures are not presumptively improper, but they require enhanced scrutiny and, typically, independent verification of beneficial-ownership from a source other than the counterparty itself.
Third, sector and goods exposure can raise the risk level of an otherwise clean counterparty. Where the goods being traded are subject to trade sanctions, licensing requirements, or strategic export controls under the relevant dual-use rules, the mapping exercise must also address those instruments. A UK-domiciled supplier trading in controlled goods requires dual-use classification and end-use verification in addition to the OFSI sanctions check. Viktor Lindqvist's export-controls practice at Calder & Vance addresses this intersection.
Fourth, recent changes in corporate structure – a change of ownership, a merger, or a change in the beneficial owner's jurisdiction of residence – are reliable indicators of increased risk and trigger an out-of-cycle mapping refresh.
A common myth in supply-chain compliance is that tier-one supplier checks are sufficient. They are not. OFSI's obligations extend to all transactions in which a designated person has a beneficial interest, regardless of how many layers of the supply chain separate that person from the UK business. If a payment passes through a structure in which a listed person ultimately benefits – even as a minority ultimate owner of a sub-tier supplier – the UK business may be in breach. That is the practical effect of the ownership and control test applied to complex supply chains.
If a transaction has already been flagged – a payment rejected, a banking query raised, or an OFSI enquiry initiated – early engagement with counsel can preserve options that narrow with time. For a confidential review, contact Calder & Vance at info@caldervance.com.
How does OFSI differ from OFAC and the EU in supply-chain mapping?
OFSI, OFAC, and the EU apply broadly similar ownership tests but diverge in ways that matter for the practical conduct of a supply-chain mapping exercise. Understanding those divergences is essential for any business operating across more than one jurisdiction.
OFSI applies a two-limb test: ownership of more than 50 percent of shares or voting rights, or control over management. The control limb is flexible and fact-sensitive. OFAC's test is ownership-based: the 50 percent or more aggregate rule, without a standalone control limb of comparable breadth in most programme contexts. The EU test mirrors the OFSI structure closely, capturing both ownership above the threshold and effective control. For a cross-border supply chain, the EU and OFSI tests may catch an entity that OFAC would not.
Enforcement posture also differs. OFSI introduced a strict-liability civil-penalty regime under SAMLA, meaning that a breach can be penalised even in the absence of knowledge or intent, subject to OFSI's discretion on the amount. OFAC's civil penalties also do not require wilful intent, but the US programme applies a different matrix of aggravating and mitigating factors. In our cross-border practice, we advise clients to apply the most restrictive test across all applicable regimes and to map that test explicitly in the compliance file.
Licensing and reporting requirements also differ. OFSI requires a business that becomes aware it holds frozen assets to report to OFSI promptly. The reporting window is short and the obligation arises as soon as the business has reasonable grounds to suspect that it holds or controls frozen funds. OFAC has a similar reporting obligation for blocked property. The EU requires reporting to the competent authority in the member state in which the assets are held. All three timelines are short; a business that delays reporting while investigating the position internally risks a separate breach.
Singapore, Japan, and the UAE each operate national sanctions regimes that may apply to supply-chain transactions involving counterparties or goods in those jurisdictions. The mapping exercise for a business with exposure in those markets should incorporate the applicable country regime alongside OFSI, OFAC, and the EU – and note that the strictest prohibition governs where the regimes overlap.
When should a business bring in sanctions counsel?
Specialist sanctions counsel adds value at four points in the supply-chain mapping process, and earlier engagement produces better outcomes than later.
The first point is scope design, before data gathering begins. Getting the risk-weighting criteria and the tier structure right at the outset saves significant cost and avoids either an over-broad exercise that consumes disproportionate resource or an under-broad one that misses the exposure that matters.
The second point is when the ownership chain is opaque or when the mapping exercise surfaces a potential match. A provisional match – a name that is close but not identical, a structure that is suggestive but not conclusive – requires a legal analysis of whether the match is a hit and what the consequences are if it is. That analysis is the practitioner's work, not the compliance team's screening tool.
The third point is when a transaction or payment has already been processed and a question arises about whether it was sanctionable. The analysis at that stage shifts: it involves OFSI's enforcement guidance, the question of voluntary self-disclosure, and the assessment of aggravating and mitigating factors. Early legal advice at this stage materially affects the outcome.
The fourth point is programme design: setting up the mapping exercise as a repeatable, documented process with defined refresh cycles, clear escalation paths, and an audit trail that satisfies OFSI's expectations for a well-designed compliance programme. We have acted for businesses at each of these four stages and the pattern is consistent – engagement before the problem is cheaper and more effective than engagement after it.
Related practices
- Correspondent banking and de-risking under OFAC – sanctions-driven de-risking analysis and correspondent-banking compliance
- Supply-chain sanctions mapping under SECO – Swiss sanctions regime: scope, ownership test, and mapping steps
- Supply-chain sanctions mapping under the Singapore regime – MAS and applicable Singapore national sanctions in supply-chain context
Frequently asked questions on supply-chain sanctions mapping under OFSI
What are the steps to map sanctions risk in the supply chain under OFSI?
The core steps are: define scope and risk-tier the counterparty population; gather structured ownership data for each counterparty in scope; apply OFSI's ownership and control test across the full chain, including aggregated holdings; screen each identified person against the UK Consolidated List and any co-applicable lists (OFAC SDN, EU consolidated, UN Consolidated); and document each step with source, date, and version of the list used. Establish a refresh cycle for the ongoing supply relationship. Where a potential match arises, escalate to legal counsel before proceeding.
What is the most common mistake in supply-chain sanctions mapping?
The most common mistake is limiting the screening exercise to the immediate tier-one counterparty and relying on name-matching alone. OFSI's ownership and control test reaches through intermediate entities to the ultimate beneficial owner, meaning a clean company-registry result for the direct supplier does not close the question. Aggregating the holdings of multiple designated persons in the same target entity – a pattern that screening tools routinely miss – is the specific technical failure we see most often in supply-chain mapping exercises that are later reviewed under enforcement scrutiny.
How does OFSI differ from other regimes in supply-chain mapping?
OFSI applies a two-limb ownership and control test – ownership above 50 percent or effective control of management – giving it a broader reach than the OFAC test, which focuses primarily on the 50 percent ownership threshold. The EU regime mirrors OFSI closely. OFSI also operates a strict-liability civil-penalty regime under SAMLA, meaning a breach can attract a penalty even without knowledge of the designated person's involvement. A business mapping a cross-border supply chain should apply the most restrictive test across all applicable regimes and document that choice.
About the author
Henry Ashworth advises on UK financial sanctions and export controls, including OFSI licensing and enforcement, and judicial-review challenges to designations. His practice covers supply-chain diligence, ownership and control analysis under SAMLA and the relevant thematic regulations, and the interaction between UK and EU sanctions in cross-border transactions. Calder & Vance – International Sanctions & Export Control Counsel.
About Calder & Vance
Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.
Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.