Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · cross-border

A cross-border matter: sanctions compliance programmes in practice

A mid-sized trading group with entities incorporated in three jurisdictions – one in Western Europe, one in Asia-Pacific, and a holding company in a third – onboards a new commodity counterparty. Its screening tool returns a clean result. Six weeks later, the group's bank flags the same counterparty and suspends settlement. The compliance officer calls legal counsel. The question is no longer whether to proceed. The question is how serious the exposure is, and whether there is a voluntary self-disclosure route.

Sanctions compliance programmes that rely on a single screening check at onboarding, without ongoing monitoring or ownership-chain analysis, regularly fail to detect exposure that a layered, multi-regime review would have surfaced. This case comment sets out how that gap opens, how it can be addressed across the major regimes, and what a cross-border business should put in place before the next counterparty arrives.

This page traces the matter from first identification through to programme redesign, drawing lessons applicable to any business with exposure to OFAC, OFSI, EU, and Asia-Pacific sanctions simultaneously.

What the situation looked like at the start

The trading group had operated a single-list screening tool connected to a consolidated data feed. The tool compared entity names against the most widely used consolidated lists, including the OFAC SDN List (the list of Specially Designated Nationals and blocked persons) and the UN Consolidated List. It returned no match on the counterparty's registered trading name.

What the tool did not examine was the counterparty's ownership structure beyond the first corporate layer. A beneficial owner at the second tier held a significant interest in an intermediate vehicle that in turn held a controlling stake in the counterparty. That beneficial owner appeared on the EU's consolidated financial-sanctions list and, separately, on a thematic list maintained under the relevant OFSI regime. The counterparty itself was not named anywhere.

The group's European entity was the contract counterparty on the commercial invoice. Its Asian-Pacific affiliate had provided a performance guarantee routed through a Singapore-domiciled bank. The holding company had approved the credit limit. Each entity sat in a different regulatory jurisdiction. Each faced a different legal standard for how far down the ownership chain the prohibition reached.

In our experience, this fact pattern – clean name screening, contaminated second-tier ownership – accounts for a significant share of the compliance gaps we are asked to remediate. The screening tool was not broken. The programme around it was incomplete.

What legal standards applied across each entity

Three distinct but overlapping sanctions regimes governed the group's exposure at the moment the bank flagged the counterparty, and each applied a different test for when a non-listed entity becomes a prohibited counterparty.

Under OFAC's regime, the operative rule is the 50 percent rule (the principle that any entity owned 50 percent or more in the aggregate by one or more blocked persons is itself treated as blocked, regardless of whether it appears on the SDN List). The test is mechanical: it counts ownership percentages and aggregates them across all blocked persons holding interests, directly or indirectly. Control, management, and the blocked person's actual influence over the entity are irrelevant to this calculation.

OFSI and the EU apply an ownership and control test. Under both regimes a non-listed entity is captured not only where designated persons own it above a defined threshold but also where a designated person controls it – whether through voting rights, board composition, contractual rights, or other means. The control limb means that a designated person holding a minority stake can still bring an entity within the prohibition if control can be established on other grounds.

Singapore's autonomous sanctions regime and, to the extent applicable, Japan's foreign exchange controls both impose asset-freeze obligations that follow UN Security Council-listed persons and their entities. The precise ownership-capture rules differ from both the OFAC and the OFSI/EU formulations. For the group's Singapore-domiciled guarantee, local counsel in the relevant jurisdiction confirmed the applicable test and whether disclosure to the relevant Singaporean authority was required.

The cross-border lesson here is immediate and practical. The European entity's exposure was governed by EU and OFSI tests, each with a control limb. The Asian-Pacific affiliate's guarantee sat in a jurisdiction with its own statutory formulation. Applying only the OFAC 50 percent rule to the whole group would have produced an incomplete and potentially misleading answer. Any multi-jurisdictional programme must map each entity's obligations to the specific regime that governs it.

The position above covers the technical standards. Your facts – the specific ownership percentages, the nature of the control rights, the entity's place of incorporation, and the regime in play – change the analysis materially.

For an initial assessment of your cross-border exposure, contact Calder & Vance at info@caldervance.com.

How the compliance gap was identified and scoped

The bank's alert did not, on its own, confirm a breach. It confirmed a potential match requiring immediate investigation. The group's first obligation was to freeze action on any pending settlements and to initiate an internal review before taking any further steps. Speed mattered. A short reporting window applies in many regimes once knowledge of a potential breach is established.

We were instructed within 48 hours of the bank's notification. Our initial review covered four questions in sequence. First: did the beneficial owner at the second tier meet the threshold for captured-entity status under each applicable regime? Second: had any funds, property, or economic resources been transferred or made available in breach of the applicable prohibitions? Third: what was the precise timeline of the commercial relationship, from onboarding through to the flagged settlement? Fourth: which regulatory authorities would need to be notified, and on what timescales?

On the ownership question, we mapped the full corporate structure using available registry data and the group's own onboarding file. The beneficial owner's stake, routed through the intermediate vehicle, reached a level that triggered the EU's prohibition when aggregated across direct and indirect holdings. Under OFSI's test the same owner's position, combined with the structural evidence of control, satisfied both the ownership and the control limb. OFAC's mechanical 50 percent rule was also met on the direct aggregation of the owner's interests.

The settlement that the bank had suspended had not been completed. That fact was important. No funds had moved at the point of identification. The group's exposure was to a past period of commercial engagement rather than to a completed prohibited transfer on the flagged transaction. This distinction matters when assessing the appropriate regulatory response and the likely weight of any enforcement consideration.

We noted that the group's onboarding file contained a beneficial-ownership declaration signed by the counterparty at formation of the relationship. That declaration did not disclose the second-tier beneficial owner. Whether to rely on a counterparty declaration – and how to verify it – is a recurring risk factor in multi-jurisdictional due diligence. A declaration is a useful starting point; it is not a substitute for independent ownership-chain analysis.

What options were considered and which route was taken

Once the scope of the exposure was established, the group faced a structured set of decisions rather than a single binary choice. Three routes were available in principle: voluntary self-disclosure to the relevant authorities, a wait-and-see approach, and an immediate termination of the relationship without disclosure. The third route was not viable; in most jurisdictions, continued possession of knowledge of a potential breach without disclosure carries its own legal risk, and it does nothing to remediate the underlying programme gap.

A voluntary self-disclosure (VSD – a proactive report of an apparent violation to the relevant regulatory authority before that authority opens its own investigation) is consistently recognised across OFAC, OFSI, and EU enforcement regimes as a significant mitigating factor in any penalty assessment. The weight given to a VSD differs by regime, and the procedural requirements differ too: OFAC operates a specific VSD process; OFSI has its own reporting and licensing architecture; and the EU's enforcement operates at the level of member-state competent authorities under the relevant Council Regulation. Coordinating a multi-regime VSD across these structures requires careful sequencing to avoid presenting inconsistent narratives or triggering investigation in one jurisdiction while another is still under review.

The group elected to submit a coordinated disclosure to the applicable authorities, guided by a single timeline that we managed across the three relevant jurisdictions. The disclosures were filed in the order that minimised timing overlap and presented consistent factual narratives. The matters were resolved through engagement with the relevant authorities without formal enforcement proceedings being opened. We do not represent that outcome as guaranteed for any other matter: enforcement responses depend on the specific facts, the authority, and the remediation steps taken.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact us at info@caldervance.com to discuss a confidential review of a potential breach.

What was wrong with the existing programme – and how it was redesigned

The group's existing sanctions compliance programme had five identifiable gaps. Identifying them is the analytical starting point for any redesign, and similar gaps appear across a majority of the programmes we review for multi-entity trading groups.

The first gap was screening depth. The programme screened entity names at onboarding and on a periodic refresh cycle. It did not systematically screen beneficial owners at the second and subsequent tiers, and it did not apply the applicable ownership-capture rules to determine whether indirect interests pushed a counterparty above the relevant threshold under each governing regime.

The second gap was regime mapping. The programme applied a single standard – broadly equivalent to the OFAC 50 percent rule – across all entities in all jurisdictions. It did not distinguish between the OFAC formulation, the OFSI/EU control-inclusive test, and the Singapore or Japan applicable standards. A group with entities in multiple jurisdictions must maintain a regime map that assigns the correct legal standard to each entity and each transaction.

The third gap was trigger events. Beneficial-ownership structures change. A designated person can acquire an interest in a counterparty after onboarding. The programme had no defined set of trigger events – corporate restructuring notices, press-coverage alerts on the counterparty, changes in the counterparty's beneficial-ownership declarations – that would prompt a re-screen outside the periodic cycle.

The fourth gap was escalation. When the bank flagged the counterparty, the compliance officer initially treated it as a standard false-positive requiring a quick clearance note. There was no documented escalation protocol requiring legal-counsel notification within a defined period when a match could not be immediately resolved by reference to readily available public information.

The fifth gap was record-keeping. The programme did not require retention of the supporting analysis behind each clearance decision. Retaining screening records, the ownership-analysis methodology, and the clearance rationale is important for demonstrating good-faith compliance to a regulator and for defending the quality of the process if it is later questioned. Record retention obligations apply across the major regimes, and maintaining records consistently across a multi-entity group requires a single document-retention standard applied regardless of the entity's jurisdiction. Five-year retention is a common benchmark across several of the major regimes, though the applicable rule varies: five years is frequently cited, but verify the specific obligation for each relevant jurisdiction before relying on it.

The redesigned programme addressed each gap through a five-element structure: beneficial-ownership screening to the second tier as a minimum with flag-led escalation to the third tier; a jurisdiction-by-jurisdiction regime map updated on a defined review cycle; a trigger-event protocol covering fourteen defined categories of counterparty-change alert; a tiered escalation matrix requiring external-counsel notification within a defined period for unresolved alerts; and a standardised record-keeping template applied across all entities with a consistent retention period. We also assisted the group in preparing an internal programme assessment document for presentation to its board, evidencing the gap identification, the remediation steps, and the programme's current status.

Cross-border risk flags this matter illustrates

Several risk patterns in this matter appear regularly across similar cross-border compliance reviews. Practitioners advising on multi-regime exposure consistently observe the same failure modes.

The first flag is reliance on a single-list consolidated feed without regime-specific calibration. A consolidated feed is a starting point. It does not apply ownership-capture logic, and it does not distinguish between the mechanical OFAC test and the control-inclusive OFSI/EU standard. Every business operating across more than one sanctions jurisdiction needs to understand which standard applies to which entity and build that distinction into its screening logic.

The second flag is counterparty declarations used as a substitute for independent verification. A declaration signed by the counterparty confirming its beneficial ownership is useful corroboration. It is not independent verification. Where a counterparty has an incentive to present a particular ownership structure, reliance on the declaration alone creates a gap that can be exploited – and that regulators will scrutinise in an enforcement context.

The third flag is the absence of a trigger-event review protocol. Ownership structures change. Designations are added to lists at any time. A programme that reviews only on a calendar cycle, without any mechanism for ad hoc re-review when defined events occur, will systematically miss changes that occur between cycles.

The fourth flag is inconsistent escalation thresholds across jurisdictions. A group whose European compliance team applies a different escalation threshold from its Asia-Pacific team will produce inconsistent documentation. Inconsistency makes it harder to demonstrate a coherent programme to a regulator and creates the risk that a matter serious enough to require external counsel in one jurisdiction is cleared at the desk in another.

The fifth flag is the assumption that a clean screen on the trading name is sufficient. The registered trading name of a counterparty is one data point. The operative legal question in every major regime is whether a blocked or designated person has an interest in or control over the entity – not whether the entity's name appears on a list. Programmes designed around name-matching alone are systematically incomplete.

A common misconception among in-house teams at smaller multi-entity groups is that sanctions compliance programmes of this depth are proportionate only for large financial institutions. That is not accurate. OFAC, OFSI, and the EU all apply the same legal standards regardless of the size of the business. The proportionality principle affects how regulators calibrate enforcement – factors such as company size, resources, and sophistication are routinely considered in penalty assessments. But the underlying prohibition applies equally. A trading group with ten employees and a commodity contract is as capable of breaching the applicable regime as a multinational bank, and the reputational and operational consequences of a breach are often proportionally more severe for a smaller business. We regularly advise businesses of all sizes on programme design that is both legally adequate and operationally proportionate to their scale and risk profile.

When to involve external sanctions counsel

External counsel should be involved at any of five points in a cross-border sanctions compliance matter. The earlier the instruction, the wider the options available.

The first point is programme design or material redesign. A programme built without input from external counsel experienced in all the applicable regimes is likely to contain the kind of regime-mapping gaps illustrated in this matter. A documented external review of the programme, updated when the group's jurisdictional footprint or the applicable regulatory landscape changes materially, is itself evidence of good-faith compliance effort.

The second point is an unresolved screening alert. When an alert cannot be cleared quickly by reference to publicly available information, or when the ownership analysis produces a result close to the applicable threshold under any of the governing regimes, external counsel should be involved before the clearance decision is documented. A premature clearance that is later found to be incorrect is harder to defend than a clearance that records a considered analysis.

The third point is a bank notification or a regulatory enquiry. A bank that suspends settlement on sanctions grounds, or a regulatory authority that issues an information request, is a signal that the matter has moved beyond an internal compliance function. The window between notification and a required response is short in many regimes.

The fourth point is a potential breach requiring a self-disclosure assessment. The decision whether to submit a VSD, to which authority or authorities, and in what sequence, carries legal and strategic weight. It should not be made by the compliance function alone.

The fifth point is a programme audit or board-level sanctions assessment. Boards of directors increasingly require documented assurance that the group's sanctions compliance programme is adequate for its jurisdictional and counterparty risk profile. An external programme assessment, prepared by counsel with cross-regime expertise, addresses that requirement and creates a contemporaneous record.

For a confidential review of your compliance programme or to discuss a potential matter, reach our team at info@caldervance.com.

Related practices

Frequently asked questions

What went wrong in this sanctions compliance programmes matter?
The compliance programme screened counterparty names at onboarding but did not analyse beneficial ownership beyond the first corporate tier. A designated person held an interest through an intermediate vehicle that, when aggregated, triggered the applicable prohibition under three separate regimes simultaneously. The screening tool returned a clean result because the counterparty itself was not listed. The gap was structural, not a failure of the tool.
How was the cross-border issue resolved?
After scoping the exposure across the applicable OFAC, OFSI, EU, and Singapore standards, we coordinated a voluntary self-disclosure to the relevant authorities in a sequenced order that maintained a consistent factual narrative across jurisdictions. The matters were resolved through regulatory engagement without formal enforcement proceedings. Disclosure sequencing and narrative consistency across multiple simultaneous VSD filings are critical to managing multi-regime matters of this kind.
What is the lesson for similar businesses?
Sanctions compliance programmes that apply a single regulatory standard to a multi-jurisdictional group, or that screen only at the first corporate tier, are structurally inadequate. The lesson is to map the applicable standard for each entity separately, screen beneficial ownership to at least the second tier, establish trigger-event re-review protocols, and maintain a documented escalation matrix that requires external-counsel notification before an unresolved alert is cleared.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.