A trading company closes a supply contract with a buyer in a third market. The goods are dual-use. The buyer's parent company sits in a jurisdiction under active sanctions measures. The shipping agent operates through a transshipment hub flagged in recent enforcement guidance. Three separate regulatory regimes are potentially in play – and the company's compliance team is working from a single-regime checklist designed for domestic transactions.
Effective trade-transaction screening across a cross-border footprint requires a structured, multi-regime approach: mapping every party and every touchpoint against the relevant sanctions lists and export-control registers, applying the correct ownership-and-control test for each regime in scope, and resolving conflicts where one regime's prohibition is stricter than another's. As of January 2026, the OFAC 50 percent rule (the rule that treats any entity owned 50 percent or more in the aggregate by blocked persons as itself blocked), the EU and UK ownership and control tests (the parallel tests under EU Council regulations and the UK Sanctions and Anti-Money Laundering Act – "SAMLA" – that extend prohibitions to entities owned or controlled by designated persons), and BIS export-control requirements each impose obligations that can apply to the same transaction simultaneously.
This guide walks through each stage of a cross-border screening exercise – from pre-transaction preparation through execution and record-keeping – and identifies where the regimes diverge in ways that change the practical outcome.
Step 1: Define the transaction perimeter before screening begins
The first step is to identify every party and every touchpoint that the screening exercise must cover before a single name is run against a list. Missed parties are the most common single source of screening failures in cross-border transactions.
A cross-border trade transaction involves more actors than the buyer and the seller. The perimeter typically includes the end-user of the goods, any intermediary or agent, the freight forwarder, the carrier, the vessel owner (and, where relevant, the flag state), the port of transshipment, the correspondent banks on both sides of the payment, and any insurer or trade-finance provider. Each of these can independently trigger a prohibition under OFAC, OFSI, EU Council regulations, or a national export-control regime.
The practical question is which regimes are in scope. Regime scope is determined by connecting factors: the nationality or location of the exporter; the nationality or location of the buyer; the currency of the payment (US dollar payments clear through US correspondent banks and therefore engage OFAC regardless of the parties' nationalities); the goods' Export Control Classification Number (ECCN – the classification code under the US Commerce Control List that determines whether a US export licence is required); and the routing of the goods through any jurisdiction that administers its own export-control regime. In our experience, firms operating under a single-jurisdiction checklist routinely miss the US-nexus point created by a dollar-denominated payment or by goods that contain US-origin controlled technology.
Map the perimeter onto a transaction diagram before running any list checks. That diagram becomes the working document for the remainder of the screening exercise.
Step 2: Screen all parties against the applicable sanctions lists
Once the transaction perimeter is defined, each identified party is screened against every sanctions list applicable to the regimes triggered by Step 1. The lists are not interchangeable, and a clear status on one does not mean a clear status on another.
The primary lists in cross-border trade are: OFAC's SDN List (the list of Specially Designated Nationals and Blocked Persons), the UN Security Council's Consolidated List (the master list maintained by the Security Council's sanctions committees), the EU's consolidated list of designated persons and entities, the UK OFSI consolidated list, and – where the transaction involves controlled goods – BIS's Entity List (the BIS register of foreign parties subject to enhanced licensing requirements) and the Denied Persons List. Where the goods are destined for or routed through a jurisdiction covered by additional national regimes – Switzerland (SECO), Canada (GAC), Australia (DFAT), the UAE, Singapore, or Japan – those lists must be added to the screening scope.
Name-matching quality is decisive. The lists contain transliterated names, aliases, and date-of-birth variations. A fuzzy-match threshold set too high generates false positives; set too low, it misses genuine hits. The correct threshold is not a universal number – it depends on the data quality of the counterparty information your firm receives and the characteristics of the list population being searched. We regularly advise clients on calibrating their match logic and on building a structured escalation protocol for potential hits.
What happens when a potential hit appears? The first action is to freeze any internal approval of the transaction and record the hit with timestamp and the specific list entry that generated it. Do not proceed with the transaction while a potential hit is being evaluated. Document the evaluation steps taken and the basis for any decision to proceed or to decline.
How do the ownership and control tests differ across regimes?
Where a direct list match is not found, the analysis shifts to indirect exposure: is the counterparty owned or controlled by a designated or blocked person? The test differs materially between the three major Western regimes, and that difference changes the outcome for the same transaction.
Under OFAC, the 50 percent rule is mechanical. Any entity owned 50 percent or more in the aggregate by one or more persons on the SDN List is treated as blocked, regardless of whether that entity itself appears on any list. The test looks at ownership only; it does not require that the blocked person exercise day-to-day control. Aggregation applies: two SDN-listed persons each holding twenty-six percent of the same target reach the threshold together.
Under EU Council regulations and UK SAMLA-based regulations, the test extends beyond a fixed ownership threshold to ask whether a designated person owns or controls the entity. Control can be established through a shareholding below fifty percent if the designated person can exercise a dominant influence over the entity through contractual rights, board representation, or voting arrangements. This is a wider test in one respect – it can catch situations that OFAC's mechanical rule would not – and a narrower one in another, because an ownership stake below fifty percent held by a designated person without control rights does not automatically prohibit dealing.
The practical consequence for cross-border screening is this: an entity with a forty-five percent SDN-listed shareholder that exercises operational control is prohibited under EU and UK rules but not automatically blocked under OFAC. Conversely, an entity with two SDN-listed shareholders each holding twenty-six percent may be blocked under OFAC but require a closer control analysis under EU and UK rules. Where both regimes apply to the same transaction, the stricter prohibition governs for each element. Map the ownership structure against both tests. Do not assume that a clearance under one regime extends to the others.
The position above covers the standard case. Your specific facts – the shareholder composition, the jurisdictions involved, the nature of the goods, and the payment route – change the analysis. For a structured review of a specific transaction, contact Calder & Vance at info@caldervance.com.
Step 3: Apply export-control classification checks
Sanctions list screening and export-control classification are distinct exercises. A transaction can be sanctions-clean and still require a licence under export-control rules, or it can be export-control clean and still trigger a sanctions prohibition. Both checks are mandatory for any cross-border trade in goods or technology that could have dual-use applications.
The starting point for US-nexus transactions is the ECCN classification of the goods or technology. If the goods are on the US Commerce Control List under the EAR (the Export Administration Regulations administered by BIS), the classification determines which countries, end-users, and end-uses require a licence, and which licence exceptions (standing authorisations in the EAR permitting certain exports without a separate application) may be available. BIS jurisdiction can apply even where the exporter is not a US company – the de minimis rule and the foreign direct product rule extend EAR controls to non-US goods that incorporate or are derived from controlled US technology, content, or equipment above defined thresholds.
For EU-based exporters, the EU dual-use regulation applies a parallel classification system to goods and technology on the EU common list. Separate national controls may supplement the EU baseline in some member states. UK exporters work under the Strategic Export Licensing rules administered by ECJU, which follow a broadly similar structure to the EU regime post-Brexit but require a separate licence application process.
The end-use declaration is a critical document in the export-control check. Where a licence exception or a general licence is relied upon, the end-use statement must accurately describe the intended use and the end-user. Inaccurate end-use declarations are a recurring source of enforcement actions under BIS and ECJU rules. Where the stated end-use is in a sector associated with diversion risk – defence-adjacent industries, research institutions in certain jurisdictions, technology companies in markets where diversion to controlled programmes has occurred – a heightened level of end-use verification is appropriate before the goods are released.
Step 4: Assess secondary-sanctions and extraterritorial exposure
A transaction can be clear under the primary regime of each party and still carry secondary-sanctions risk. Secondary sanctions are measures that target non-US persons conducting business with designated parties or in designated sectors, without requiring a US nexus in the transaction itself. They are a feature of several US sanctions programmes administered by OFAC, and their potential reach is a central concern for non-US companies operating in cross-border trade.
The practical question for a cross-border screening exercise is whether the transaction – even if lawful under EU, UK, and the local law of the parties – could constitute a "significant transaction" with a designated person or entity, or meaningful activity in a designated sector, under the applicable US secondary-sanctions authority. The answer depends on the specific programme, the nature and value of the transaction, the sector, and the parties involved. Where the risk is real, the options are to restructure the transaction to remove the element that creates secondary-sanctions exposure, to seek OFAC guidance, or to decline.
The extraterritorial dimension of US export controls creates a parallel exposure. Where goods, software, or technology of US origin are incorporated into a product that is subsequently re-exported, the EAR may continue to govern that re-export regardless of where the re-exporting party is located. In our cross-border practice, we regularly see this issue arise in supply chains where a non-US integrator incorporates US-sourced components without tracking their EAR classification status through the downstream sale.
If a transaction has already been flagged under a secondary-sanctions alert, or a shipment has been stopped at a port of entry, an early review preserves options that narrow considerably once enforcement has been formally opened. For a confidential review of a specific exposure, write to info@caldervance.com.
Step 5: Document the screening decision and manage record-keeping obligations
A screening exercise that is not documented is a liability rather than a protection. Regulators assessing a compliance programme look for evidence of a systematic, repeatable screening process. The absence of contemporaneous records is itself treated as an indicator of inadequate compliance controls.
The documentation standard for a cross-border trade screening exercise should include: the date and version of each sanctions list consulted; the exact search terms used and the logic applied; the result of each search, including potential hits reviewed and the basis for any decision to proceed; the ownership analysis undertaken for any party where indirect exposure was a live question; the export-control classification and any licence or licence exception relied upon; and the identity of the compliance officer who took the screening decision and their seniority level. Where a voluntary self-disclosure (VSD – a proactive report of a potential violation to the relevant regulator, made before enforcement action is taken) is later considered, this contemporaneous record is among the most significant factors assessed by OFAC, OFSI, and BIS in determining the treatment of the disclosure.
Record-keeping obligations vary by regime. Under the EAR, exporters must retain export-control records for five years from the date of the transaction. OFSI guidance requires that financial-sanctions compliance records be maintained for a similar period, and UK AML rules impose parallel document-retention requirements. EU record-keeping obligations under the relevant Council regulations follow a comparable standard. Where a firm operates across multiple regimes, the practical approach is to set a single retention period at the highest required standard across all applicable regimes and apply it uniformly.
Transaction records should be stored in a form that permits retrieval during a regulatory enquiry without requiring reconstruction from memory. Screening decisions taken by committee or by a senior compliance officer should include a brief written record of the reasoning, not merely the outcome.
Risk flags and when to involve counsel
Certain transaction features raise the risk profile of a cross-border screening exercise to a level where qualified sanctions and export-control counsel should be involved before the transaction proceeds. Compliance teams operate under time pressure; knowing which risk flags warrant an escalation to counsel – rather than internal sign-off – is itself a compliance skill.
The clearest escalation triggers are: a potential SDN or EU/UK designated-person match that the screening team cannot resolve with confidence; an ownership structure where a designated or blocked person holds a material but sub-threshold stake and the control analysis is genuinely uncertain; dual-use goods or technology destined for an end-user in a jurisdiction associated with diversion risk; a payment route that passes through a correspondent bank in a jurisdiction under sector or country sanctions; a request from the buyer to ship to an address or consignee different from the one originally identified; and any indication that an intermediary in the supply chain may be acting as a front for a designated person.
There is a common myth that involving external sanctions counsel signals weakness or implies a problem to the regulator. The opposite is closer to accurate. Documented engagement of specialist advice on a genuinely complex screening question is treated by OFAC, OFSI, and BIS as evidence of a good-faith compliance effort. Early involvement is cheaper and more effective than crisis management after enforcement has been opened.
In a recent matter, a logistics firm operating between two continents identified a potential ownership-chain issue involving a freight forwarder. The question was whether a minority shareholder of the forwarder, who appeared on a non-US list but not the SDN List, created secondary-sanctions exposure for the client's US-dollar invoicing. We mapped the ownership structure against both the OFAC 50 percent rule and the EU control test, assessed the secondary-sanctions programme in scope, and provided a documented opinion that permitted the client to proceed with appropriate mitigating measures. The matter was resolved before any transaction was executed.
Related practices