Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · cross-border

A cross-border matter: crypto and VASP sanctions compliance in practice

A virtual-asset service provider with users in six jurisdictions completes a large peer-to-peer transaction. The counterparty wallet passes the firm's automated screening. Two weeks later, an analyst notices that the sending address had previously appeared in a public blockchain analytics alert linked to a designated entity. The transfer has settled. The funds have moved on. What happens next decides whether the business faces a regulatory disclosure, a formal investigation, or worse.

This matter illustrates a central challenge in crypto and VASP sanctions compliance across a multi-regime environment: the legal exposure from a single transaction can simultaneously engage OFAC, OFSI, EU Council regulations, and national fintech regulators in the firm's home jurisdiction. No single screening pass is sufficient. The governing instruments – IEEPA in the United States, SAMLA-derived regulations in the United Kingdom, the relevant Council Regulation in the EU – each impose distinct obligations, distinct reporting windows, and distinct standards of proof for what the firm knew or should have known.

This case comment walks through the situation our cross-border VASP client encountered, the legal analysis applied across the primary regimes, the options that were available, and the lessons that apply to any virtual-asset business operating across multiple jurisdictions. As of July 2026, the regulatory environment for VASPs continues to tighten across every major regime.

The situation: what the firm discovered and when

A mid-size VASP incorporated in one EU member state and providing services to retail users across the EU, the United Kingdom, and Singapore discovered a potential sanctions exposure through its post-transaction monitoring programme, not its real-time screening layer. That sequencing matters.

The business had implemented real-time wallet screening against the major consolidated lists at the point of transaction initiation. The screening tool, however, did not integrate blockchain analytics that could identify whether a counterparty address had transacted historically with a wallet cluster attributed to a designated entity. The transaction in question involved a receiving wallet that had, in the weeks prior, received funds from an address attributed – according to a commercial analytics provider's alert – to an entity on OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons).

The VASP's post-transaction review uncovered the alert. The question was no longer theoretical: the firm had processed a transaction where the receiving side had a documented connection to a sanctioned-entity cluster. Was this a prohibited transaction under the applicable regimes? Did it trigger a reporting obligation? And critically – did the firm have any discretion about whether to disclose?

In our experience, this pattern – discovery through retrospective analytics rather than real-time screening – is among the most common fact patterns for VASPs facing potential sanctions exposure. The analytical capability exists; the integration gap creates the liability.

What did the applicable regimes require?

The cross-border nature of the VASP's user base meant that three distinct regulatory regimes were immediately in play, each with its own test and its own consequence for non-compliance.

Under the US regime, OFAC's authority under IEEPA extends extraterritorially. A non-US VASP that processes a transaction where a US-nexus exists – US dollar settlement, US technology infrastructure, a US-person counterparty – can fall within OFAC's jurisdiction. Where a blocked person has a traceable connection to the transaction, the question becomes whether the VASP "facilitated" a transaction involving blocked property. OFAC's enforcement guidance treats constructive knowledge as relevant: what a reasonably diligent compliance programme should have detected.

Under the UK regime, OFSI operates under SAMLA and the relevant thematic financial sanctions regulations. OFSI's civil enforcement standard is strict liability for the underlying prohibition, but intent and reasonable precautions are relevant to penalty quantum and to whether OFSI issues a monetary penalty at all. OFSI also imposes a specific reporting obligation: where a firm knows or suspects that it holds or has dealt with funds belonging to a designated person, it must report that to OFSI. The reporting window is short and the obligation arises on the formation of the suspicion, not on confirmation.

Under the EU regime, the relevant Council Regulation prohibits making funds available to designated persons and requires member-state competent authorities to be notified where funds are frozen or a transaction is blocked. The EU member state in which the VASP was incorporated had its own national competent authority. That authority had issued sector-specific guidance indicating that VASPs must apply risk-based due diligence calibrated to the specific characteristics of blockchain transactions, including chain-of-custody tracing for higher-risk wallet interactions.

Singapore's Monetary Authority of Singapore regime applied to the firm's Singaporean user base. Though Singapore's designated-persons regime operates independently, the practical effect was that the firm's Singapore-registered entity faced parallel notification obligations under the applicable country regime.

Four regimes. Potentially four distinct obligations. And a single transaction at the centre of each.

How the cross-border legal analysis was structured

The first task was triage: establish which jurisdictions had a legal nexus to the transaction, and prioritise by enforcement risk and reporting window.

The US nexus was the most consequential. The transaction had settled in a stablecoin pegged to the US dollar, and the firm's infrastructure included servers located in the United States. Our analysis was that OFAC's extraterritorial reach applied. That assessment shaped everything that followed, because OFAC's enforcement posture for VASPs – reflected in public guidance and enforcement actions – has made clear that inadequate screening programmes are themselves an aggravating factor in penalty determinations.

The UK analysis centred on OFSI's reporting obligation. The firm had UK-resident users who had transacted through the same platform during the relevant period. We advised that once the firm had identified a reasonable suspicion – not certainty, but reasonable suspicion – that funds connected to a designated person had passed through the platform, the reporting clock began. Delay in reporting is itself an aggravating factor under OFSI's enforcement approach.

For the EU member-state competent authority, the analysis required mapping the firm's obligations under the specific implementing regulation for the relevant sanctions programme. The designated entity in question fell within a programme administered by the EU, meaning the prohibition on making funds available applied directly. The competent authority notification route was distinct from the OFSI route, and the procedural requirements differed.

We regularly advise VASPs on exactly this sequencing challenge: when multiple regimes each impose a reporting obligation but with different triggering standards and different deadlines, the firm must run parallel tracks, not a sequential process. Waiting to resolve the US position before notifying the UK authority is a common and costly mistake.

The risk flags that determined the exposure level

Not every connection to a designated entity's wallet cluster carries identical legal risk. The analysis turned on a set of risk factors that, taken together, determined where on the enforcement spectrum the firm's position sat.

First, directness of exposure. The firm had not transacted directly with a wallet attributed to a designated entity. The connection was one step removed: the counterparty had received funds from such a wallet in a prior transaction. Under OFAC's guidance, this distinction matters – but it does not create a safe harbour. OFAC has taken the position that indirect exposure can still constitute facilitation where the firm had reason to detect the risk.

Second, the adequacy of the screening programme. This was the firm's most significant vulnerability. The gap between its real-time list screening and its retrospective blockchain analytics meant that the programme was not calibrated to the risk profile of the transaction type. For a peer-to-peer crypto transfer, OFAC's guidance indicates that a risk-based programme should include enhanced due diligence for high-risk transaction types. A programme that screens only against consolidated lists at the point of transaction initiation does not meet that standard for higher-risk wallet interactions.

Third, the response after discovery. How quickly and comprehensively a firm responds once it identifies a potential violation is a material factor in every major regime's penalty calculus. A prompt, well-structured voluntary self-disclosure – a VSD (voluntary self-disclosure to a regulator) – demonstrating that the firm investigated thoroughly, contained the exposure, and reported in good faith, typically receives more favourable treatment than a disclosure made in response to a regulator's enquiry.

Fourth, prior compliance history. The firm had no previous enforcement history with any of the relevant regulators. That was a mitigating factor across all three primary regimes.

The options considered and the route taken

Once the legal analysis was complete, we presented the firm's senior management with a structured decision framework. The core choice was between a proactive, multi-regime voluntary disclosure and a more limited notification strategy directed only at the jurisdiction with the clearest legal nexus.

The proactive route involved coordinated disclosure to OFAC, OFSI, and the relevant EU member-state competent authority. The disclosure package would set out the facts of the transaction, the firm's screening methodology at the time, the manner in which the potential exposure was identified, and the remediation steps already underway. A coordinated disclosure allows a firm to control the narrative and demonstrate systemic good faith across all relevant regulators simultaneously.

The limited-notification route – disclosing only to the most clearly applicable regime – carried the risk that a separate regulatory enquiry in another jurisdiction would discover the transaction independently, eliminating the VSD credit and transforming the firm's position from proactive discloser to late-stage respondent. In a multi-regime environment, that risk is not theoretical. Regulators in different jurisdictions share information through formal cooperation channels, and blockchain analytics are available to enforcement authorities.

The firm elected the coordinated disclosure route. We prepared the disclosure packages, managed the sequencing of submissions across regimes to avoid conflicting representations, and structured the remediation programme that formed the core of the mitigation evidence. The matter proceeded through the relevant review processes without a formal monetary penalty being imposed in any jurisdiction, though we make no representation that this outcome is available in every comparable situation.

If you are managing a similar cross-border exposure, early assessment of the reporting obligations across each applicable regime is essential. The window for a credible proactive disclosure can narrow significantly within days of the initial discovery. Contact Calder & Vance at info@caldervance.com for a confidential review of your position.

The compliance remediation programme

Disclosure without remediation is incomplete. Regulators across all three primary regimes make clear that demonstrated systemic improvement is a material mitigating factor. The firm's remediation programme addressed the specific gaps that the matter had exposed.

The primary gap – the absence of integrated blockchain analytics at the point of transaction initiation – was closed through the implementation of a commercial analytics tool capable of assessing wallet risk in near-real time. The tool was configured to flag transactions where the counterparty wallet had a demonstrated transaction history with addresses attributed to designated entities, not merely where the wallet address itself appeared on a consolidated list. This distinction is central to effective VASP sanctions compliance: list screening catches direct exposure; blockchain analytics catches indirect exposure through the ownership and transaction chain.

The second element of the programme addressed governance. The firm's escalation procedures had not specified a clear chain of responsibility for sanctions-alert review, nor had they established a maximum review-to-decision timeline. We recommended a documented escalation matrix specifying the compliance officer responsible for sanctions alerts, the deputy, and the timeline within which an alert must be resolved or escalated to senior management. In our practice, the absence of documented escalation procedures is consistently identified by regulators as an indicator of systemic deficiency rather than an isolated error.

Third, the firm's record-keeping practice was reviewed. Across OFAC, OFSI, and EU frameworks, firms are expected to maintain records of transactions, screening results, alerts, and the decisions made in response to alerts for a defined period. The firm's documentation practice had been adequate for routine transactions but had not been adapted to capture the full decision trail for screened-and-cleared transactions where an analytics alert had been raised and dismissed. That gap was remediated by updating the transaction management system to retain the full alert trail, not just the screening result.

A related area – compliance audit and testing – became a standing element of the firm's annual compliance calendar. An independent annual test of the screening logic, the analytics integration, and the escalation procedures provides evidence of ongoing systemic improvement and creates a documented baseline should a regulator require one.

What this means for VASPs operating across jurisdictions

The practical lesson of this matter is not that blockchain analytics eliminate sanctions risk. They do not. The lesson is that a VASP operating across multiple regimes faces a multi-layered compliance obligation, and that the weakest layer determines the firm's enforcement exposure.

A common misconception among VASP compliance teams is that the relevant test is whether a wallet address appears on a consolidated designated-persons list. That test is necessary but not sufficient. OFAC's guidance, OFSI's enforcement approach, and the EU regulatory environment each indicate that a risk-based programme for virtual assets must account for the chain of custody behind a wallet, not merely the wallet's current designation status. A wallet that is not itself designated but has recently transacted with a designated wallet cluster creates a traceable indirect exposure that well-resourced enforcement authorities can and do identify.

The cross-regime dimension adds a further layer. A VASP that resolves its OFAC exposure through a well-managed VSD may still face separate obligations under OFSI or an EU competent authority. Treating the US disclosure as the end of the matter – rather than as one track in a parallel multi-regime process – is a structural error. Our practice maintains current familiarity with the relevant procedures for each of the primary regimes in which our VASP clients operate, and with the information-sharing mechanisms between those regulators.

We have also acted for VASPs facing related questions in the Japanese regulatory environment, where the crypto and VASP compliance obligations present their own set of procedural requirements distinct from those of OFAC, OFSI, and the EU. The multi-regime dimension is not only a transatlantic question.

If your business has identified a potential screening gap or a transaction that may require review, the most valuable first step is a structured legal assessment before any communication is made to regulators. Regulators in each jurisdiction treat the quality and timing of disclosure as a central factor in their enforcement response. For a confidential discussion, write to info@caldervance.com.

Related practices

Frequently asked questions

What went wrong in this crypto and VASP sanctions compliance matter?
The firm's real-time screening checked counterparty wallet addresses against consolidated designated-persons lists but did not integrate blockchain analytics capable of detecting indirect exposure through prior transactions with designated-entity clusters. The gap meant a transaction with a traceable sanctions connection passed through automated screening undetected, with the exposure only identified through retrospective post-transaction review. That sequencing – detection after settlement rather than before – meant the legal obligation shifted immediately to disclosure rather than prevention. The screening logic was technically operational but not calibrated to the risk profile of peer-to-peer virtual-asset transactions in a multi-regime environment.
How was the cross-border issue resolved?
A coordinated voluntary self-disclosure was prepared and submitted to the relevant authorities across the primary regimes simultaneously. The disclosure packages set out the factual circumstances, the state of the firm's compliance programme at the time of the transaction, the manner of discovery, and the remediation steps already underway. The firm also implemented an integrated blockchain analytics tool, a documented escalation matrix, and updated record-keeping procedures. No formal monetary penalty was imposed in any jurisdiction, though outcomes in any individual matter depend on the specific facts and cannot be predicted in advance.
What is the lesson for similar businesses?
A VASP operating across multiple jurisdictions faces simultaneous and distinct obligations under each applicable regime. List screening at the point of transaction initiation is necessary but not sufficient: blockchain analytics addressing the transaction history of counterparty wallets must be integrated for higher-risk transaction types. Where a potential exposure is identified, reporting obligations in each relevant jurisdiction run in parallel and on different timelines. Treating the most prominent regime's disclosure as the end of the matter, rather than as one track in a multi-regime process, is a structural error that narrows options and can convert a proactive discloser into a late-stage respondent.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.