Calder & Vance International Sanctions & Compliance Counsel

Cross-Border Transactions & Diligence · UN

Supply-chain sanctions mapping under UN: a practical guide

A trading company sources components from four tiers of suppliers across three continents. Its compliance team screens tier-one vendors. Then, during a transaction-banking review, a tier-three sub-supplier surfaces on the UN Consolidated List (the Security Council's unified list of designated persons and entities subject to UN-mandated measures). The deal has already been partially financed. What are the obligations? Who bears them? These questions are not hypothetical. They arise in cross-border supply chains every week.

Supply-chain sanctions mapping under the UN regime means systematically identifying every node in a commercial supply chain that may be owned, controlled, or materially influenced by a person or entity designated on the UN Consolidated List or subject to a regime-specific UN Security Council committee list. The obligation to map does not arise from a single instrument; it flows from the implementing legislation that each UN member state enacts to give domestic legal force to Security Council resolutions adopted under Chapter VII of the UN Charter. As of January 2026, all major trading jurisdictions – the United States, the United Kingdom, the European Union member states, and others – maintain domestic regimes that reflect, and in many cases exceed, the UN baseline.

This guide sets out a practical, step-by-step method for supply-chain sanctions mapping against UN-based designations, explains where the major implementing regimes diverge, identifies the risk flags that warrant early counsel involvement, and describes how Calder & Vance structures this work for cross-border clients.

Step 1: Understand the governing authority and the UN baseline

The UN Consolidated List is maintained by the Security Council Sanctions Committees and is the authoritative reference point for UN-mandated individual and entity designations. It is not itself directly enforceable in domestic courts; the operative legal instruments are the national or regional regulations that each implementing state enacts to transpose Security Council resolutions into binding domestic law.

This architecture has a critical practical consequence: a UN designation is only the floor. Each implementing jurisdiction may add its own autonomous designations on top of the UN baseline. OFAC in the United States, OFSI in the United Kingdom, and the EU Council each maintain their own lists, which overlap with but are not identical to the UN list. When you map supply-chain sanctions risk, you are mapping against several overlapping lists simultaneously – and the stricter prohibition governs.

For a business operating in or through multiple jurisdictions, the UN Consolidated List is the common denominator. But it is not sufficient. In our practice, we regularly find that a counterparty passes a UN-only screen and fails a regime-specific OFAC or EU check. The mapping exercise must address all lists relevant to the transaction's nexus points: the nationality of the parties, the currency of settlement, the routing of goods, and the jurisdiction of the contracting entity.

A UN Security Council resolution designating an individual or an entity typically triggers an asset freeze, a travel ban, and – in arms-related designations – an arms embargo. The relevant Security Council Sanctions Committee administers the list, and the regime-specific list for each thematic programme (counter-terrorism, non-proliferation, regional stability, or other) is published on the UN's public website. Practitioners should treat the Consolidated List as a minimum baseline and layer the relevant domestic implementing instruments over it.

Step 2: Define the scope of your supply chain map

Effective supply-chain mapping begins with a precise scope definition. The scope determines how far up and down the commercial chain you are obliged – or prudent – to look, and it prevents both under-screening and resource-intensive over-reach.

Start with the transaction's legal nexus points. These are the jurisdictions whose sanctions rules apply to you. A US-incorporated entity, or one that routes payments through the US financial system, is subject to OFAC's rules. A UK-registered company is subject to OFSI's rules. An EU-based entity falls under the relevant Council regulations. Each of those regimes gives domestic legal force to the UN baseline, so the UN Consolidated List is relevant in all of them – but the domestic rules may impose stricter obligations on due diligence, ownership testing, and record-keeping.

Then map the commercial tiers. Best practice distinguishes:

  • Tier one – your direct contractual counterparties. You have the most leverage to obtain information here, and the legal risk is most direct.
  • Tier two and below – sub-suppliers, sub-contractors, freight forwarders, and intermediaries. These are harder to screen but can carry material risk, particularly in high-risk commodity sectors or where the goods involved have dual-use characteristics.
  • Financial intermediaries – banks, payment processors, trade-finance providers. Their own screening applies, but if your transaction is structured in a way that causes a financial intermediary to deal with a sanctioned person, the originating party may bear secondary exposure.

Do not limit the scope to entity names alone. The ownership and control test (the principle under which an entity may be captured by sanctions not because it is listed, but because a listed person owns or controls it) applies in all major implementing regimes. OFAC applies the 50 percent rule (its rule treating entities owned 50 percent or more by blocked persons in the aggregate as themselves blocked). The UK and EU apply both an ownership threshold and a control test, which can catch entities where a listed person exercises decisive or material influence even without majority ownership.

Step 3: Build the ownership and control map

Mapping beneficial ownership is the most technically demanding part of the exercise. The goal is to determine, for every material supply-chain node, whether any designated person or entity holds or exercises the ownership or control that would bring that node within the scope of a sanctions prohibition.

The OFAC 50 percent rule is mechanical: if designated persons collectively hold 50 percent or more of the equity of an entity, that entity is treated as blocked, whether or not it appears on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) by name. Aggregation across multiple designated holders applies. This test is applied to the direct holding level first, then repeated up the ownership chain.

The UK and EU tests go further. Under OFSI's guidance and the relevant Council regulations, an entity may be caught not only by majority ownership but also by control. Control can arise from contractual arrangements, governance rights, or the practical ability of a designated person to direct the entity's activities. In our experience, the control dimension is where supply-chain mapping exercises most often fall short – a supplier whose equity is held through a nominee structure, or whose board includes a designated individual in an advisory or veto capacity, may not appear on any list by name but is nonetheless captured.

Practical steps for the ownership map:

  1. Obtain the most recent corporate registry extract and beneficial ownership disclosure for each tier-one counterparty.
  2. Run the names of all shareholders holding more than a de minimis stake against the UN Consolidated List and all relevant domestic lists.
  3. Apply the 50 percent aggregation test across all listed holders at each ownership level.
  4. Check for indirect holdings through intermediate entities, using the same test at each tier.
  5. Review governance documents – articles of association, shareholder agreements, management contracts – for control rights held by designated persons.
  6. Document each step and the sources used, with a date stamp. Record-keeping requirements under the applicable domestic regimes typically require retaining compliance records for a defined period after the transaction or relationship ends.

Is the data always available? No. In jurisdictions with limited corporate-registry disclosure or where beneficial ownership information is not publicly filed, gaps in the map are inevitable. We address this below in the section on risk flags.

Step 4: Screen against all relevant lists and apply the stricter prohibition

Once the ownership map is built, the screening step applies each relevant list to every identified person and entity. This is not a single-list exercise.

For a supply chain with nexus to the major trading regimes, you will typically screen against:

  • The UN Consolidated List (the baseline, relevant in all implementing jurisdictions)
  • The OFAC SDN List and sector-specific lists maintained under IEEPA-based programmes (relevant for any US nexus or USD-denominated transaction)
  • The OFSI Consolidated List (relevant for any UK nexus)
  • The EU's regime-specific consolidated lists (relevant for any EU nexus)
  • Other regime-specific lists as dictated by the transaction's routing – for example, the relevant lists maintained by SECO in Switzerland, GAC in Canada, DFAT in Australia, or the competent authorities in Singapore, Japan, or the UAE if the supply chain touches those jurisdictions

Where a designation appears on one list but not another, the legal position in each jurisdiction follows its own implementing instrument. Where two regimes impose conflicting obligations – one permitting a transaction that the other prohibits – the stricter prohibition governs as a practical matter, because proceeding with the transaction exposes you under the prohibiting regime regardless of permission under the other.

Screening tools introduce their own risks. Name-matching algorithms generate false positives (matches that do not involve the listed person) and, more dangerously, false negatives (failures to surface a genuine match because a name variant or transliteration is used). Human review of positive matches is not optional. A documented review of each match, with a clear resolution and the name of the reviewer, is the standard that enforcement authorities in all major regimes expect to see.

The position above covers the standard screening process. Your supply chain's specific features – the goods involved, the jurisdictions traversed, the payment routing – change the analysis and may trigger additional obligations.

For a preliminary assessment of your supply-chain exposure and a discussion of how to structure a mapping exercise for your transaction, contact Calder & Vance at info@caldervance.com.

How does UN differ from other regimes in supply-chain mapping?

The UN regime sets the international floor, but implementing jurisdictions operate above it in several important respects, and these divergences directly affect how a supply-chain map should be structured and what a compliance programme must cover.

First, extraterritorial reach. The United States applies OFAC sanctions with broad extraterritorial effect through secondary-sanctions risk – the risk that a non-US person transacting with a US-sanctioned target becomes itself subject to designations or loss of US market access. The UN regime itself has no equivalent secondary-sanctions mechanism; secondary-sanctions risk is a feature of autonomous US (and, in limited forms, EU and UK) designations layered on top of the UN baseline. A supply chain that passes a pure UN-list screen may still carry secondary-sanctions risk under the US regime.

Second, the ownership and control test. As noted above, OFAC's 50 percent rule is a mechanical ownership threshold. OFSI and the EU use both an ownership threshold and a control test. The UN regime itself does not prescribe a universal ownership test; that is left to implementing jurisdictions. This means the same supply-chain node may be captured under OFSI or EU rules but not directly under OFAC's 50 percent rule – or vice versa.

Third, licensing and authorisations. The UN regime does not itself grant licences to permit otherwise-prohibited transactions; that function belongs to each implementing jurisdiction's authority. OFAC grants specific licences (case-by-case authorisations to conduct an otherwise prohibited transaction) and publishes general licences (standing authorisations for defined categories of transactions). OFSI and the ECJU handle UK licensing; the EU licensing route runs through member-state competent authorities under the relevant Council regulation. A business seeking to continue a supply-chain relationship despite a designation hit must pursue the appropriate licence from the competent authority in each relevant jurisdiction.

Fourth, enforcement posture. OFAC and OFSI are active enforcement authorities with published penalty frameworks. UN Security Council Sanctions Committees do not themselves impose penalties on private actors; enforcement is a function of domestic implementing authority. This means the practical risk of a UN sanctions violation is realised through domestic enforcement – but that enforcement can be severe. Penalties under OFAC, OFSI, and the EU are set by domestic legislation and can be substantial. A violation of a UN-derived prohibition is, in effect, a violation of the domestic instrument, and it is the domestic authority that investigates and penalises.

What are the key risk flags in supply-chain mapping?

Risk flags are features of a supply chain, counterparty, or transaction that, in our experience, indicate elevated sanctions exposure and warrant deeper investigation or early counsel involvement.

The most significant risk flags include:

  • Opacity in beneficial ownership: a counterparty that cannot or will not provide verifiable ownership information is a material risk flag, regardless of whether any listed person has been identified. Opacity in itself may indicate control by a person who does not wish to be identified.
  • Jurisdictional exposure: supply-chain nodes located in or routing through jurisdictions that are subject to comprehensive or thematic UN sanctions programmes carry inherently higher risk. Even where the entity itself is not listed, the jurisdictional exposure elevates the probability of an indirect connection.
  • High-risk commodities: goods that are subject to arms embargoes, proliferation-related controls, or dual-use restrictions attract specific scrutiny under both the UN regime and the major implementing domestic regimes. The EAR (the Export Administration Regulations administered by BIS in the United States) and equivalent EU dual-use rules impose controls that may interact with and supplement sanctions prohibitions.
  • Unusual payment routing: payments routed through multiple intermediary jurisdictions, or through financial institutions in jurisdictions with limited AML/CFT oversight, increase the risk that a sanctioned person is connected to the flow of funds.
  • Undisclosed intermediaries: the presence of an intermediary whose role is not commercially explained – a trading company inserted between a manufacturer and end-buyer without adding demonstrable value – is a recognised indicator of sanctions circumvention risk. We address this as a compliance detection topic: the question for the compliance team is whether the structure could be used to obscure a sanctioned party.
  • Recent change of ownership: a transfer of equity shortly before or after a designation, or during a period of escalating sanctions activity, warrants investigation into whether the transfer was intended to place assets beyond the reach of a designation.

If a transaction has already been flagged – by a screening tool, a correspondent bank, or a regulator – the options available narrow quickly. An early review can preserve options and shape the response. Contact Calder & Vance at info@caldervance.com to discuss a specific situation in confidence.

Step 5: Document, escalate, and review

A supply-chain mapping exercise that produces no written record is, from a compliance standpoint, an exercise that did not happen. Documentation is not a procedural nicety; it is the primary evidence that a business exercised reasonable care, which is central to penalty mitigation and enforcement defence in all major regimes.

The documentation record for each supply-chain node should include:

  1. The sources used to establish identity and ownership (corporate registry, commercial database, primary documents)
  2. The lists screened and the date of each screen
  3. The outcome of the ownership and control analysis, with the test applied stated explicitly
  4. The resolution of any positive match, with the reviewer's name and the basis for clearance or escalation
  5. Any residual risk flags identified, with a record of the business decision taken

Escalation procedures matter. A positive match that is not escalated to a decision-maker is the most common single point of failure in supply-chain compliance programmes. The escalation path should be defined in writing before the transaction, not improvised after a hit.

Periodic review is equally important. Designations are added to all major lists without advance notice. A counterparty that was clean at on-boarding may be designated six months later. Ongoing monitoring – re-screening at defined intervals or on trigger events such as a change in ownership, a new designation announcement in a relevant regime, or a news report linking the counterparty to a newly active enforcement area – is a standard element of a well-designed supply-chain compliance programme.

Record-keeping requirements under the major domestic implementing regimes typically require that compliance records be retained for a defined period after the transaction or relationship ends. Verify the applicable retention period under each relevant regime before disposing of records.

Common mistakes in supply-chain sanctions mapping

Screening only the named contract party is the single most common mistake. It misses designated persons in the ownership chain, control relationships that do not appear in equity registers, and intermediary nodes that carry the actual exposure.

A second frequent error is relying on a single list. The UN Consolidated List is the international baseline, but a counterparty may be subject to autonomous OFAC, OFSI, or EU designations that have no UN equivalent. Treating a clean UN screen as a complete clearance is a category error with potentially serious consequences.

Third, screening without post-match review. Automated screening tools produce matches that require human judgment to resolve. A match that is dismissed as a false positive without documented analysis is not a cleared match – it is an undocumented decision that will be scrutinised in any subsequent enforcement review. We regularly advise clients whose screening programmes are technically well-configured but whose match-review processes are underdeveloped.

There is also a persistent myth that the UN regime is less practically significant than OFAC or OFSI because UN-level designations are comparatively fewer in number and the UN itself does not enforce. This is inaccurate. The UN Consolidated List is the foundation from which all major implementing regimes derive their baseline obligations. A designation on the UN list triggers legal obligations in every implementing jurisdiction simultaneously, without any further domestic designation being required. The practical consequence is not diminished; it is multiplied across jurisdictions.

Related practices

Frequently asked questions

What are the steps to map sanctions risk in the supply chain under UN?
Mapping supply-chain sanctions risk under the UN regime involves five principal steps: defining the transaction's jurisdictional nexus points to identify all applicable implementing regimes; establishing the scope of the commercial supply chain across all material tiers; building a beneficial ownership and control map for each counterparty; screening every identified person and entity against the UN Consolidated List and all relevant domestic lists; and documenting the entire exercise with dated records and a defined escalation path. Each step must address the ownership and control test applied by each relevant implementing jurisdiction, because those tests diverge between OFAC, OFSI, and the EU.
What is the most common mistake in supply-chain sanctions mapping?
The most common mistake is screening only the named contract party and failing to map the ownership and control chain behind it. A counterparty that does not itself appear on any list may nonetheless be captured – under OFAC's 50 percent rule if designated persons collectively own it at that threshold or above, or under OFSI and EU rules if a designated person exercises control. A second equally common error is relying on the UN Consolidated List alone and treating a clean UN screen as a full clearance, when the transaction may also be subject to autonomous OFAC, OFSI, or EU designations with no UN equivalent.
How does UN differ from other regimes here?
The UN regime is the international baseline: Security Council resolutions adopted under Chapter VII impose obligations on all member states, and the UN Consolidated List is the common denominator for all major implementing regimes. However, the UN regime does not itself prescribe a universal ownership test, does not grant licences, and does not directly enforce against private parties. Each implementing jurisdiction – OFAC, OFSI, the EU, and others – applies its own ownership and control standard, maintains autonomous designations beyond the UN baseline, operates its own licensing regime, and conducts its own enforcement. Secondary-sanctions risk is a US-regime feature with no UN equivalent. In practical terms, the UN list sets the floor and the domestic implementing instruments raise it.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.