A US-headquartered financial institution begins a periodic review of its sanctions screening programme. The exercise starts as routine. Within a week, the internal audit team surfaces a pattern it did not expect: a cluster of transactions processed over a prior period had passed automated screening despite involving an entity whose ultimate beneficial owner appeared on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The entity itself was not listed. The ownership chain was two layers deep. The screening tool had never been configured to aggregate holdings above the first layer.
This case comment examines how a compliance audit and testing exercise under OFAC exposed a systematic screening gap, how the business managed the regulatory position, and what the situation reveals about the design of a defensible programme. The governing authority is OFAC, operating under IEEPA and the relevant blocking-programme regulations. The audit surfaced an aggregation failure – not a rogue transaction, but an architectural defect.
The sections below follow the matter from discovery through analysis, the options considered under the applicable regime, the cross-border dimension that complicated the picture, and the operational lessons for any business that runs a periodic compliance audit and testing programme.
The situation: a routine audit that changed scope quickly
A routine annual review became something materially different on the third day. The compliance team at a mid-sized financial institution had tasked an external adviser – Calder & Vance – with conducting an independent compliance audit and testing exercise against its OFAC screening programme. The brief was to test configuration logic, re-screen a sample of processed transactions, and assess the adequacy of documentation practices. Standard scope. Short timetable.
The re-screening sample was structured in tiers. Tier one covered recent transactions with counterparties in jurisdictions subject to active OFAC programmes. Tier two covered transactions where the counterparty had a complex ownership structure. Tier three – the catch-all – covered the statistical remainder. The finding emerged in tier two. Four counterparty entities, each transacted with over the prior period, traced to a common beneficial owner. That owner held between 24 and 31 percent of each entity individually. Aggregated across all four, the exposure was materially different.
Had any of those entities been a single vehicle owned outright by a blocked person, the screening tool would have caught it. The problem was precisely that the holdings were distributed. The tool was configured to flag only where a single blocked person held 50 percent or more in a single entity. OFAC's aggregation guidance, which applies that threshold across indirect holdings and across multiple vehicles when the same blocked person controls them, had not been reflected in the configuration logic. That gap was the defect.
In our experience, this pattern is not unusual. The most common compliance failures we identify in audit and testing work are not deliberate. They are configuration errors – tools deployed with factory defaults, or with bespoke rules that have not been updated to reflect current OFAC guidance on aggregation and control.
What does the OFAC ownership test actually require?
OFAC applies the 50 percent rule (the rule that any entity owned 50 percent or more in the aggregate by one or more blocked persons is itself treated as blocked, regardless of whether it appears on the SDN List) as a bright line. The figure is the threshold. Intention, day-to-day management, and the absence of any listed name on the entity's corporate documents are all irrelevant to whether the rule bites.
Critically, the rule operates on an aggregate basis. Where two blocked persons each hold 26 percent of the same entity, the entity is caught. Where one blocked person holds 30 percent of entity A and 25 percent of entity B, each entity must be tested independently – but the analysis must examine whether further holdings in A or B, from the same or other blocked persons, push either above the threshold. Screening tools that test only single-person, single-entity direct ownership will miss layered aggregation structures.
The institution in this matter had four separate counterparties, each appearing clean in isolation. The shared beneficial owner's aggregate position across the four was not automatically calculated. The tool was not wrong, precisely – it answered the question it had been asked. The question had been posed too narrowly.
What the audit identified was not a systems failure in the sense of a malfunction. It was a programme design failure: the compliance architecture had not been built to test the question that the OFAC rule actually asks. That distinction matters when it comes to assessing enforcement posture and voluntary self-disclosure strategy, because the presence of a systematic defect – as opposed to a one-off processing error – bears on how OFAC characterises the apparent violation.
How does the position differ under UK and EU rules?
The cross-border dimension complicated the analysis. The institution maintained a subsidiary in a European jurisdiction subject to EU Council regulations and operated a branch in the United Kingdom regulated by OFSI. Each of those entities had processed a subset of the same counterparty transactions. Resolving the OFAC position alone was therefore insufficient.
Under EU Council regulations, the test for whether a non-listed entity is caught is framed not only around ownership but also around ownership and control (the EU test for whether a non-listed entity is effectively directed by a listed person, which extends beyond formal ownership percentage to actual direction and dominance). Where a listed person holds less than 50 percent but exercises operational control through board representation, veto rights, or contractual direction, EU rules may still treat the entity as subject to restrictions. The EU test is broader than the OFAC bright line in its control dimension, though the ownership threshold itself is similarly pegged to majority ownership in the basic case.
Under OFSI, the UK position under SAMLA and the relevant thematic regulations applies an ownership and control test in similar terms to the EU, with guidance from OFSI clarifying that both formal ownership and effective control are relevant. The threshold for ownership is consistent at 50 percent or more, but the control dimension means that a structure designed to sit just below 50 percent may still be caught if a designated person exercises de facto control.
For the institution in this matter, the EU and UK legs of the analysis produced a slightly different picture than the OFAC analysis. Under OFAC's mechanical rule, the aggregate position of the shared beneficial owner across the four entities did not reach 50 percent in any single entity. The four were therefore not automatically blocked under OFAC's rule when tested entity by entity. The problem was the control dimension under EU and OFSI guidance: there was credible evidence that the beneficial owner directed the commercial decisions of at least two of the four entities despite holding a sub-50-percent position in each. That evidence brought those two entities within the EU and UK prohibitions, even while the OFAC analysis remained more nuanced.
The practical consequence was that the compliance fix was not uniform across jurisdictions. A configuration adjustment that addressed the OFAC aggregation gap was necessary but not sufficient. The EU and UK screening logic required a separate control-indicator module – one that flagged structural indicators of beneficial direction beyond the ownership percentage.
We regularly advise institutions with multi-jurisdictional operations that designing a programme to the lowest common denominator of a single regime creates exactly this exposure. A programme calibrated only to OFAC's 50 percent bright line will underperform against the EU and UK control tests. The reverse is also true: a programme calibrated only to the broader EU control test may still miss OFAC aggregation across multiple vehicles owned by the same blocked person.
For further analysis of how compliance programme design works across jurisdictions, see our matter note on cross-border compliance programme design.
The options considered: disclosure, remediation, and timing
Once the findings were documented, the institution faced three questions in sequence. First, did the transactions constitute apparent violations requiring disclosure? Second, if disclosure was appropriate, what form should it take and when? Third, what remediation was required before the firm could represent to its regulators that the programme was adequate?
On the first question, the legal analysis turned on whether the counterparty entities were in fact blocked under the 50 percent rule. As noted, the entity-by-entity OFAC analysis for the four counterparties did not produce a clear positive answer, because the shared owner's aggregate position in any single entity remained below 50 percent. The EU and UK analysis was different for two of the four. This asymmetry had direct consequences for the disclosure question: apparent violations identified under EU or UK rules required separate reporting under those regimes' mandatory reporting obligations, on timelines that differ from the OFAC voluntary self-disclosure process.
On the OFAC side, the question of whether a VSD (voluntary self-disclosure to OFAC of an apparent violation) was appropriate required assessment of whether there was an apparent violation at all. Where the legal analysis of the ownership question is genuinely uncertain, OFAC guidance is that institutions should document the analysis and not assume a violation exists. The institution was therefore not in a position of clear apparent violation on the OFAC leg. It was, however, in a position of clear programme deficiency – a distinction that mattered for remediation planning.
OFAC's framework for assessing programme adequacy gives significant weight to whether a firm has a compliance programme that is, among other things, subject to periodic testing and audit. The irony in this situation was that the compliance audit and testing exercise itself – the very activity that OFAC expects – had produced the finding. That fact, carefully documented, would form part of the remediation narrative.
On timing, the decision matrix was as follows. The EU and UK reporting obligations, where the analysis indicated apparent violations, ran on statutory timelines. These are not negotiable, and delay compounds the regulatory risk. The OFAC remediation, by contrast, was not driven by a mandatory reporting deadline on these facts, but was shaped by the principle that proactive remediation before any regulatory inquiry is treated more favourably than remediation undertaken in response to an inquiry.
The institution chose a course of proactive remediation: fix the programme, document the analysis, and prepare a written record demonstrating that the audit had identified a configuration gap, that the gap did not produce clear apparent violations on the OFAC analysis, and that the programme had been redesigned to reflect current OFAC aggregation guidance and EU/UK control tests.
What are the risk flags that other businesses should take from this matter?
Several patterns in this matter recur frequently across the institutions we advise, and they are worth naming directly.
The first is over-reliance on the SDN List name-match as a complete screening methodology. The SDN List is the foundation, not the ceiling. OFAC's ownership guidance, the EU and UK control tests, the UN Consolidated List, and the various other authorities that comprise a complete screening architecture sit above and around the SDN name-match. A firm that screens only for exact name matches against the SDN List is not screening against the rule; it is screening against a subset of it.
The second risk flag is configuration drift. Screening tools are configured at a point in time. OFAC guidance, EU implementing regulations, and OFSI enforcement practice all evolve. A configuration set up correctly three years ago may not reflect current guidance on aggregation, control indicators, or the treatment of complex ownership structures. The only way to detect drift is periodic testing – which is precisely the audit and testing function that the institution in this matter had commissioned.
The third flag is jurisdictional siloing. Where an institution operates under multiple regimes, a finding under one regime will almost always have implications under the others. A programme designed around one jurisdiction's rules will produce gaps when tested against another's. The compliance audit and testing exercise in this matter was framed as an OFAC review, but the findings had immediate UK and EU dimensions that could not be addressed in isolation.
Fourth: documentation of the analysis. In sanctions compliance, the quality of the documented reasoning matters alongside the quality of the decision. OFAC, OFSI, and the relevant EU authorities all assess, in enforcement contexts, whether the institution approached the question in a structured and documented way. An institution that identified a complex ownership structure, ran an analysis, reached a considered conclusion, and documented its reasoning is in a materially different position from one that ignored the question or reached the same conclusion without leaving any record.
Is your screening programme configured to test aggregation across multiple vehicles? Does your testing methodology include a re-screening of processed transactions, or only forward-looking controls? These are the questions a compliance audit and testing exercise should be able to answer.
How Calder & Vance structured the remediation
Our role in this matter moved through three phases. The first was audit and finding: independent re-screening of the transaction sample, ownership and control mapping of the four counterparty entities across all three jurisdictions, and a written finding setting out the configuration gap and its consequences under OFAC, EU, and OFSI analysis.
The second phase was legal analysis: assessing whether the transactions constituted apparent violations under each applicable regime, determining the disclosure obligations and their timelines, and producing a written memorandum documenting the analysis so that the institution had a contemporaneous record of its reasoning. This memorandum was not produced for regulatory submission. It was produced to establish that the institution had approached the question seriously, on advice, and had reached a considered position.
The third phase was remediation: working with the institution's compliance and technology teams to redesign the screening configuration logic to incorporate aggregation testing across multiple vehicles, add a control-indicator module to address the EU and UK control dimension, and establish a testing schedule that would re-run the tier-two re-screening methodology on a periodic basis going forward.
In a recent matter, a financial institution operating across three jurisdictions commissioned a compliance audit and testing exercise following a regulatory examination. We screened a three-year transaction sample against current OFAC, EU, and UK rules, mapped ownership chains to the ultimate beneficial-owner level, and identified a configuration gap in the aggregation logic. We redesigned the programme architecture, documented the legal analysis for the compliance record, and assisted with the EU and UK reporting obligations where apparent violations were identified. The matter concluded with a programme that had been tested against all three regimes and was documented as such.
The position above covers the standard case. Your facts – the counterparty structure, the jurisdictions in play, the transaction type, the screening tool in use – change the analysis substantially. For an assessment of your exposure under OFAC or the other major regimes, contact Calder & Vance at info@caldervance.com.
A common misconception: screening a list is the same as screening the rule
We encounter a persistent misconception in compliance audit work. It is that a firm which screens against the SDN List, the EU Consolidated List, and the UN Consolidated List has discharged its obligations under the major sanctions regimes. In some compliance circles, this view is framed as "we screen the lists, we're covered." The assumption is understandable – the lists are the most visible part of the regime. But it conflates the list with the rule.
The SDN List is the output of OFAC's designation process. The 50 percent rule is an extension of that list by operation of OFAC's own guidance: entities that are not listed but are owned 50 percent or more by listed persons are treated as if they were listed. The EU and UK ownership and control tests operate similarly. None of these extensions appear on the lists themselves. They are tested by analysis, not by name-match.
A firm that has sophisticated name-matching logic, fuzzy-match thresholds properly calibrated, and excellent list-update frequency is doing list screening well. But it is not doing full sanctions screening unless it also applies the ownership and aggregation tests that the regimes require. The institution in this matter had invested heavily in its list-screening infrastructure. That investment was well-placed. The gap was at a different level: the ownership analysis layer above the list match.
Correcting this misconception is one of the most practically valuable things a compliance audit and testing exercise can do. It reframes the question from "are we screening the right lists?" to "are we applying the right tests?" Those are different questions, and they produce different answers.
For an understanding of how compliance audit and testing applies under a comparable national regime, see our service note on compliance audit and testing under the Australian autonomous sanctions regime.
Related practices
Related practices
- Compliance audit and testing – Australia – independent testing of screening logic against the Australian autonomous sanctions regime
- Cross-border compliance programme design – how multi-jurisdictional programmes are structured to cover OFAC, OFSI, and EU rules together
- Compliance programme design – Japan – the Japanese sanctions regime and its interaction with OFAC and EU screening requirements