A mid-sized financial services group with operations in the United Kingdom and across several European markets runs a routine internal audit. The audit surfaces a problem: the group's screening systems have been calibrated to match only exact-name spellings, with no fuzzy-logic tolerance, against the UK financial sanctions list maintained by OFSI (His Majesty's Treasury's Office of Financial Sanctions Implementation, the authority responsible for licensing, enforcement, and guidance on financial sanctions in the United Kingdom). Three counterparty payments, processed over fourteen months, have passed through to entities whose names appeared on that list under transliterated variants. The group has not identified a licence that would have covered the transactions. The compliance team is unsure whether to report, how to frame the matter, and whether the underlying compliance programme is defensible.
Under the Sanctions and Anti-Money Laundering Act (SAMLA) and the relevant thematic financial-sanctions regulations, a business that knows or has reasonable cause to suspect that it holds, or has dealt with, funds or economic resources belonging to a designated person must report to OFSI without delay. The strength of a pre-existing sanctions compliance programme – the documented, tested set of policies, controls, and governance arrangements a firm uses to identify and manage sanctions obligations – is the primary mitigant that OFSI weighs when it considers whether, and how severely, to respond. Where the programme is materially deficient, the exposure is direct and can be significant.
This case comment walks through the situation the group faced, the legal questions it had to answer, the route it took, and the lessons that apply to any business running payment operations under OFSI jurisdiction.
The situation: how a screening gap became a compliance matter
The audit finding landed without warning. Three payments, none individually large, had cleared internal controls and reached their counterparties. Each counterparty had an entry on the UK sanctions list. The group's screening tool had not matched them because each had been onboarded under a romanised spelling that differed, by one or two characters, from the list entry. The tool's settings required an exact match.
The first question compliance raised was factual: were these counterparties, as screened, the same legal persons as the listed entities? That question required a look at underlying documentation – registration numbers, addresses, beneficial ownership records, correspondent banking data. It also required a legal assessment of whether the ownership and control test (the UK test for whether a non-listed entity is itself caught because a listed person owns or controls it) extended the prohibition further up or down the ownership chain.
The second question was procedural. OFSI's published guidance makes clear that the obligation to report arises on knowledge or reasonable suspicion. The audit finding created, at minimum, reasonable suspicion. The window for voluntary reporting is not open indefinitely. Delay compounds the exposure. In our experience, the single most damaging step a business can take in this position is to spend weeks on internal deliberation before lodging anything with OFSI – by which point the voluntary character of the report is undermined and the opportunity to frame the disclosure positively is gone.
The group had not previously experienced an OFSI matter of this kind. Its compliance leadership understood screening as a technical function. The broader five-element architecture that a defensible programme requires – governance, risk assessment, policies and procedures, training, and monitoring and testing – had never been formally assembled in a written document that the group could place before a regulator.
The legal question: what does OFSI actually assess?
OFSI's enforcement approach distinguishes between cases where a business has deliberately dealt in breach and cases where controls failed despite good-faith effort. That distinction is operationalised through an assessment of the compliance programme in place at the time of the breach. A strong programme does not eliminate liability, but it is a material factor in determining whether OFSI pursues monetary penalty, issues a warning, or takes no further action.
The relevant thematic financial-sanctions regulations in force under SAMLA establish the civil monetary penalty regime. OFSI can impose a penalty on the civil standard of proof – balance of probabilities. Under the current enforcement posture, penalty levels reflect both the monetary value of the breach and the quality of the firm's controls. OFSI's enforcement guidance, which is publicly available and which OFSI has updated to signal its expectations for firms across the financial sector, identifies several factors it weighs: the seriousness of the breach, whether it was deliberate or inadvertent, the quality of the compliance programme, and whether voluntary disclosure was made.
What counts as a "quality" compliance programme? OFSI's published guidance, and the broader international regulatory consensus reflected in guidance from OFAC in the United States and from EU competent authorities, converges on a five-element model: governance arrangements that assign clear ownership of the sanctions function; a risk assessment that identifies the firm's exposure across its products, counterparties, and geographies; policies and procedures that operationalise the risk assessment; training that is current and documented; and monitoring and testing that checks the programme is working as designed. The group, on examination, had partial versions of several of these elements but had never integrated them into a single documented programme.
The cross-regime comparison matters here. Under OFAC's framework, the quality of a compliance programme is treated as a factor in the severity and financial quantum of a civil penalty, following OFAC's published compliance commitments guidance. The EU competent authorities operate similarly, treating the presence or absence of adequate controls as a mitigating or aggravating factor in national enforcement. The consistent message – from London, Washington, and Brussels – is the same: the programme is not optional paperwork. It is the primary evidence base by which a regulator judges your firm's good faith.
The position above covers the standard enforcement calculus. Your own facts – the nature of your business, the counterparties involved, the revenue lines that touch regulated jurisdictions, and the specific gaps in your existing controls – change the analysis.
For a confidential assessment of your current programme's readiness under OFSI's criteria, contact Calder & Vance at info@caldervance.com.
What steps did the matter require?
The group took five sequential steps once it had determined the audit finding required external counsel. The order was deliberate: each step conditioned the next.
- Scoping the breach. Before any report went to OFSI, the group needed a defensible factual picture. That meant tracing the three transactions fully: counterparty identity against original source documents, ultimate beneficial ownership, correspondence between the entities as screened and the entries on the UK sanctions list. This was not a search for ways to avoid the conclusion. It was a search for the accurate answer, because an incomplete or inaccurate voluntary disclosure can be worse than none.
- Legal characterisation. Once the facts were assembled, the group needed advice on whether the dealings engaged the prohibition – and if so, on what basis. The ownership and control question had to be worked through the UK test carefully. The EU operations of the group also fell within the scope of EU financial-sanctions regulations that, in some cases, applied to the same counterparties. The applicable regime analysis therefore covered two jurisdictions simultaneously.
- Preparing the voluntary disclosure. A voluntary disclosure to OFSI is a structured document. It sets out the facts, the legal analysis of the breach, the firm's current compliance programme, and the remedial steps already taken or committed to. The disclosure must be accurate in every material respect. OFSI treats the completeness and candour of the report as a factor in its own right.
- Programme remediation. Parallel to the disclosure preparation, the group commissioned a review of its screening configuration and broader programme architecture. The review produced a gap analysis against the five-element model and a prioritised remediation plan. Steps that could be completed quickly – screening configuration changes, an immediate all-staff refresher on the reporting obligation – were implemented before the disclosure was submitted, so they could be reported as completed actions rather than intentions.
- OFSI engagement. Once submitted, the matter moved to OFSI's enforcement team. The group's disclosure included a clear point of contact, a complete record of the remedial actions taken, and a projected timeline for the remaining programme improvements. OFSI acknowledged receipt. The matter proceeded through OFSI's standard review process.
In a recent matter of this type, a financial services business facing a similar screening failure was able to demonstrate, through a programme-remediation record compiled in parallel with its disclosure, that the gap was systemic rather than deliberate and had been closed before any regulator inquiry. The matter was resolved without a public enforcement outcome. We do not promise that result; the facts of each matter determine the outcome. But the sequence above is what a well-prepared disclosure looks like.
Where the compliance programme gaps typically arise
Screening configuration is the most common point of failure, but it is rarely the only one. In practice, programme gaps tend to cluster in four areas.
Name-matching logic. Exact-match screening against any version of the UK consolidated list will miss transliterations, abbreviations, aliases, and common alternative romanisations. OFSI does not specify a single technical standard for screening, but it expects firms to calibrate their tools in a manner proportionate to their risk profile. A firm processing payments to or from higher-risk jurisdictions that uses exact-match only has a gap it cannot easily explain.
Risk assessment currency. A risk assessment produced three years ago and never updated is not a functioning risk assessment. It is a historical document. The obligation runs to the current risk environment. Counterparty profiles change. Sanctions lists change. New designations can affect a firm's existing book of business overnight. Have you reviewed your risk assessment in the last twelve months?
Ownership and control mapping. Screening a legal entity without screening its ownership chain is a well-documented gap. The 50 percent rule in the OFAC context – treating any entity owned 50 percent or more in aggregate by blocked persons as itself blocked – is mirrored by the UK ownership and control test under OFSI, though the UK test also incorporates a control limb that can catch entities below the ownership threshold. Both tests require ownership-chain mapping, not just entity-level screening.
Training documentation. Training that happens but is not recorded is training that cannot be demonstrated. OFSI expects firms to show that relevant staff have received sanctions training appropriate to their role. Attendance records, training materials, and assessments are the evidence. Without them, the training may as well not have occurred for enforcement purposes.
If a transaction has already been flagged, or a disclosure has become necessary, early legal review can preserve options that narrow with time. Reach out to Calder & Vance at info@caldervance.com to discuss the position confidentially.
The cross-border dimension: OFSI, OFAC, and EU competent authorities
Few businesses operate in a single sanctions jurisdiction. The group in this matter had UK-domiciled entities processing payments and EU-registered subsidiaries dealing with overlapping counterparties. That meant the same underlying transaction could engage both UK financial-sanctions regulations and the relevant EU Council regulation, depending on the entity processing it.
The divergences between regimes matter operationally. OFSI's enforcement posture, its licensing process, and its reporting timeline are UK-specific. An EU competent authority – the relevant national authority in the EU member state where the subsidiary is registered – applies the EU regulation and its own procedural rules. A voluntary disclosure to OFSI does not automatically satisfy a parallel reporting obligation in the EU jurisdiction. The two reports need to be drafted consistently but need to address each regime's specific requirements separately.
The OFAC dimension arises wherever US-person nexus exists – a US-domiciled group company, a correspondent banking relationship with a US bank, or goods or technology of US origin. OFAC's reach extends extraterritorially to transactions that touch US jurisdiction in any of those ways. OFAC's compliance commitments framework, like OFSI's enforcement guidance, treats programme quality as a central mitigating factor. But the specific elements OFAC emphasises, and the way it weights senior management commitment as a standalone factor, differ in emphasis from the UK approach. A programme designed only to satisfy OFSI may leave material gaps against OFAC criteria – and vice versa.
In our cross-border practice, we advise clients to map the full jurisdictional perimeter of their operations before designing their sanctions compliance architecture. A programme that covers only the jurisdiction where the group is headquartered is a programme that will fail a transaction review the first time it crosses a border.
Switzerland, Canada, and Australia operate their own financial-sanctions regimes – administered by SECO, Global Affairs Canada, and DFAT respectively – each with reporting and licensing requirements that do not automatically mirror the UK or EU position. For groups with significant operations in those markets, the compliance programme needs to reflect each applicable regime.
The myth: a compliance programme only matters after a breach
A persistent assumption among boards and finance committees is that investing in a documented sanctions compliance programme is a defensive exercise – useful only when something has gone wrong. That framing inverts the logic of the regulatory position. OFSI, OFAC, and the EU competent authorities all treat the programme as evidence of the firm's pre-breach posture. A firm that has a well-documented, tested programme in place before a compliance failure occurs is in a materially better position than a firm that constructs one in response to an inquiry.
The practical implication is straightforward. A programme that pre-dates the breach can be shown to the regulator as contemporaneous evidence of good faith. A programme assembled after the fact is evidence of remediation – which is valuable, but which does not carry the same mitigating weight. The difference, in enforcement terms, can be the difference between a warning and a penalty.
We regularly advise boards and compliance committees that the time to build the programme is before the audit finding, before the transaction is flagged, and before the letter arrives from the regulator. That counsel is sometimes difficult to act on when the immediate business pressure is elsewhere. But the cost of a well-designed programme, relative to the cost of an enforcement process, is not a close comparison.
When to involve external sanctions counsel
There are five situations in which external counsel should be involved early rather than late.
- On discovery of a potential breach. The reporting obligation can be triggered quickly. Counsel can help scope the facts, characterise the legal position, and advise on the timing and framing of any disclosure before internal deliberation creates delay.
- When a programme review is overdue. If the programme has not been formally documented and tested within the last year, or if the business has entered new markets or product lines without updating its risk assessment, a programme review is appropriate. External review provides a basis for telling the regulator, if asked, that the programme was independently assessed.
- On a significant counterparty or ownership change. Mergers, acquisitions, and new distribution arrangements frequently introduce sanctions exposure that the existing programme has not been designed to catch. Sanctions due diligence at the transaction stage is faster and cheaper than remediation after closing.
- When a licence application is needed. OFSI licensing – both specific licence applications for individual transactions and the interpretation of available general licences – requires careful preparation. An incomplete application, or one that does not address the relevant licence criteria, will be refused or returned for further information.
- On receipt of a query or information request from OFSI. OFSI's engagement is formal and consequential. Responding without legal advice, or responding in a way that is incomplete or inconsistent with the voluntary disclosure previously made, creates additional risk. Counsel should review any OFSI correspondence before a response is submitted.
Related practices
- Sanctions compliance audit and testing – independent programme review, gap analysis, and remediation planning across major regimes.
- Counterparty due diligence: an OFSI matter – how ownership-chain screening failures arise and how they are addressed.
- Counterparty due diligence: a SECO matter – Swiss financial-sanctions screening in a cross-border transaction context.