Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

An OFSI matter: name and entity screening lessons learned

A mid-sized payment processor running cross-border transfers between the United Kingdom and several third markets discovered, during a routine post-implementation review, that its automated screening solution had been generating false negatives for months. Several names matched entries on the UK Consolidated List (OFSI's master register of designated persons and entities under the UK sanctions regime) only when exact-string logic was applied. Variant spellings, transliterated names, and incomplete entity identifiers had slipped through undetected. The firm had continued processing payments. No funds had been reported. And OFSI had not yet been in contact – but the window for voluntary disclosure was narrowing.

Name and entity screening under the OFSI regime requires more than a database subscription. The UK Consolidated List is the authoritative reference, maintained by OFSI under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic regulations. A screening programme that fails to catch variant names, transliterations, and partial entity identifiers can leave a firm holding unreported frozen funds – an exposure that carries significant civil and, in serious cases, criminal consequences. As of mid-2026, OFSI's enforcement posture has hardened, and the adequacy of a firm's screening methodology is itself a factor in penalty mitigation.

This case comment traces the situation as it arose, the legal questions it raised, the cross-regime comparisons that shaped the analysis, and the practical lessons that any business running UK-connected payments or transactions should take forward.

The situation: what the review uncovered

The firm's compliance function had commissioned an internal audit after a peer institution in a neighbouring jurisdiction disclosed a screening failure to its own regulator. The audit revealed three categories of problem. First, the firm's vendor feed was updated on a 24-hour cycle, not in near-real time. Second, the fuzzy-matching threshold had been set conservatively to reduce alert volume, which suppressed matches on names that differed by a single character or a diacritic. Third, the firm had no process for screening entities against the ownership-and-control test: it screened the named counterparty but did not look through to beneficial owners.

The combination was significant. Under the UK sanctions regime, ownership and control (the test for whether a non-listed entity is caught because a designated person owns or controls it) extends the prohibition to companies that a listed person owns or controls, even if those companies are not themselves named on the Consolidated List. OFSI's published guidance addresses this test directly. The firm had been screening names on the Consolidated List, but it had not asked whether any counterparty was owned or controlled by a listed person.

In our experience, this pattern – technically compliant on the face of the tool but operationally inadequate – is one of the most common sources of exposure for payment firms. The tool is sound; the calibration and the scope of the enquiry are not.

What is the OFSI ownership and control test, and how does it compare with OFAC?

The UK ownership-and-control test is a qualitative assessment: a non-listed entity falls within the prohibition if a designated person owns or controls it, with "control" reading broadly to include voting rights, board composition, and the ability to direct the entity's affairs. This differs from the US position in a material respect.

Under OFAC, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) is a quantitative, aggregate ownership test. It is mechanical: if blocked persons own 50 percent or more in aggregate, directly or indirectly, the entity is treated as blocked. Control in the qualitative sense is not independently sufficient under OFAC's standard rule, though specific programme rules can extend further.

Under OFSI, the ownership limb mirrors the OFAC approach at the majority-ownership level, but the control limb goes further. A designated person who holds a minority stake but exercises control through governance arrangements or contractual rights can bring a non-listed entity within scope. For a cross-border business handling both US-dollar and sterling flows, this divergence is material: an entity that clears the OFAC 50 percent threshold may still be caught by OFSI's control test.

What does this mean operationally? A screening programme built to pass OFAC's aggregated-ownership rule will not automatically satisfy OFSI's ownership-and-control standard. The two tests must be run separately, against the governance documents and beneficial ownership records of the counterparty, not merely against the numerical shareholding.

For completeness, the EU regime under the relevant Council regulations applies an analogous ownership-and-control test, though the detailed interpretive guidance differs. Switzerland (SECO) and other like-minded regimes follow broadly similar logic, with local variations in guidance. Where the transaction touches multiple jurisdictions, the stricter prohibition governs.

The legal questions the firm faced

Once the audit findings were clear, the firm faced three connected legal questions. First, had any payments constituted a breach of the financial prohibitions under the relevant thematic regulations? Second, if so, was there an obligation to report the apparent breach to OFSI and to freeze the relevant funds? Third, would a voluntary self-disclosure ("VSD") – a proactive report to OFSI before the regulator became aware – affect the outcome?

On the first question: the audit identified a small number of transactions where a counterparty or an intermediary appeared, on further review, to be owned or controlled by a designated person. The payments had been processed. That constituted, on a conservative reading, a prima facie breach of the financial prohibition.

On the second: OFSI's published guidance makes clear that where a person believes they hold frozen funds, or that a breach has occurred, there is a reporting obligation. The precise window is statutory and runs from the point at which the person "knows or has reasonable cause to suspect" a breach. In our cross-border practice, the question of when that knowledge or suspicion crystallises is often the first issue counsel must advise on, because the reporting clock starts at that point.

On the third: OFSI's enforcement framework distinguishes between breaches that are voluntarily disclosed and those that come to the regulator's attention through other means. A VSD, promptly and completely made, is a factor that OFSI expressly takes into account in determining both whether to impose a monetary penalty and the level of any penalty. The mitigation benefit is real – but it depends on the VSD being full, accurate, and timely.

The position above covers the standard case. Your facts – the counterparty, the goods or funds, the route, the regime in play – change the analysis. For an assessment of your exposure under OFSI, contact Calder & Vance at info@caldervance.com.

How the matter was handled: from audit finding to resolution

We were instructed shortly after the firm received the internal audit report. The first task was scoping: reviewing the transaction data, the vendor configuration, and the firm's screening policy to identify which, if any, payments had touched a counterparty within the OFSI prohibition. This was not a straightforward matching exercise. The ownership-and-control assessment required reviewing corporate registry filings, beneficial ownership registers, and, in two cases, direct requests to the counterparties for updated shareholder information.

The scoping exercise produced a defined population of transactions. The firm then froze the residual funds still held. We prepared a comprehensive VSD to OFSI, setting out the transactions, the nature of the screening failure, the root cause, and the remediation steps the firm had already taken or was committed to taking. The VSD was structured to address all of the factors that OFSI's enforcement guidance identifies as relevant to mitigation: cooperation, identification of the cause, absence of deliberate intent, and remediation.

In a recent matter of this type, a financial-services business had processed transactions through a correspondent network without screening the intermediary chain against the Consolidated List. We assessed the ownership-and-control position, prepared the voluntary disclosure, and supported the firm through OFSI's review. The matter was resolved without a public monetary-penalty notice; the outcome reflected the quality and completeness of the VSD rather than the absence of a breach.

One practical point deserves emphasis. OFSI's review of a VSD is not a passive exercise. The regulator may ask supplementary questions, request additional transaction data, or seek clarification on the ownership structure. The firm must be in a position to respond promptly and consistently. Gaps in the VSD that emerge in correspondence are harder to manage than gaps addressed proactively in the original submission.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. To discuss a voluntary disclosure or an ongoing OFSI enquiry, write to info@caldervance.com.

Screening programme failures: the five risk patterns

The case illustrated several risk patterns that recur across OFSI-related screening failures. Each pattern is operationally distinct, but in our experience they tend to appear together, which is why a single tool misconfiguration can produce cascading exposures.

The first is update latency. The UK Consolidated List is updated when OFSI makes a new designation or amends an existing entry. A screening feed on a 24-hour or longer cycle will miss designations made between updates. Near-real-time feeds are technically available from most reputable vendors; the choice to use a slower feed is a cost and workflow decision, not a technical constraint.

The second is fuzzy-match calibration. Designated persons and entities are listed with known aliases and variant spellings, but the list does not exhaustively record every possible transliteration. Setting the fuzzy-match threshold too high to reduce false positives will also reduce true positives. The calibration decision must be documented, reviewed periodically, and justified in the firm's screening policy.

The third is scope limitation. Screening only the named counterparty – the direct legal person in the transaction – without examining beneficial owners or the intermediary chain is a structural gap. For payment firms, the intermediary chain is frequently the point of risk.

The fourth is static ownership data. A beneficial ownership assessment conducted at onboarding will become stale. OFSI designations can occur at any point in the life of a relationship. A periodic refresh of ownership data for higher-risk counterparties is not optional; it is part of an effective screening programme.

The fifth is inadequate governance. Where a screening alert is generated and then cleared without adequate escalation or documentation, the firm cannot demonstrate, in a later OFSI enquiry, that the alert was properly considered. Alert-disposition governance – who clears alerts, on what basis, and with what documentation – is a core element of a defensible programme.

The OFSI enforcement posture and what it means for your programme

OFSI operates under SAMLA and the relevant thematic regulations. Its enforcement powers include the ability to impose a civil monetary penalty without a criminal conviction, on a strict liability basis in respect of the financial prohibition. Strict liability means that the absence of knowledge or intention does not, of itself, preclude a penalty. A firm that processes a payment in breach of the prohibition because its screening failed will not avoid liability merely by pointing to the tool.

OFSI's published enforcement guidance sets out a mitigation framework. Factors including cooperation, early disclosure, the adequacy of the compliance programme, and the absence of profit from the breach are all relevant to the penalty determination. The guidance does not cap the mitigating benefit of a VSD, but it does make clear that partial or late disclosures attract less credit than complete and timely ones.

For cross-border businesses, one additional dimension warrants attention. OFSI operates within the broader UK sanctions architecture, and its designations align with – but are not always identical to – those under EU and UN regimes. A business that screens only against the EU or UN Consolidated List may miss UK-specific designations that do not have direct EU or UN equivalents, and vice versa. Since the UK's autonomous sanctions programme expanded significantly after the divergence from the EU regime, this is a live operational risk, not a theoretical one.

From a multi-regime perspective, a business processing US-dollar transactions faces OFAC jurisdiction in parallel. OFAC's enforcement programme operates on a different basis: civil penalties there can be calculated per transaction and, in egregious cases, at figures that significantly exceed the transaction value. We regularly advise businesses that face simultaneous OFSI and OFAC exposure from the same payment stream; the two regulators do not coordinate, and a VSD to one does not discharge any obligation to the other.

What the common myth gets wrong about screening

A recurring misconception among mid-market businesses is that a commercially licensed screening tool, correctly integrated, is sufficient for OFSI compliance. This misreads the regulatory position.

The tool is an input, not a compliance programme. OFSI assesses the adequacy of the entire screening regime: the scope of the screening (which parties, which lists, which ownership layers), the configuration of the tool (update frequency, match threshold), the governance around alert disposition, and the documentation of decisions. A firm that demonstrates it purchased a reputable tool but cannot explain how it was calibrated, who cleared alerts, or whether ownership chains were reviewed is not in a strong position before OFSI.

The stronger position is one where the firm can show a documented, risk-proportionate screening policy, periodic testing of the tool's performance against known-match test cases, clear escalation procedures, and a record of decisions. This is not an unreachable standard. It is the standard that well-run compliance functions already maintain – and it is the standard against which OFSI's enforcement guidance measures a firm's conduct.

Related practices

Frequently asked questions

What went wrong in this name and entity screening matter?
The firm's screening tool was misconfigured in two ways: it operated on a 24-hour update cycle rather than near-real time, and its fuzzy-match threshold was set too high to catch variant spellings and transliterations. In addition, the programme screened only named counterparties, not beneficial owners or intermediaries. This combination produced false negatives – missed matches against the UK Consolidated List – that were not identified until an internal audit prompted a retrospective review. The result was a population of payments processed in apparent breach of the UK financial sanctions prohibitions.
How was the OFSI issue resolved?
Once the scope of the apparent breaches was established through a structured review of transaction data and ownership structures, the firm submitted a voluntary self-disclosure to OFSI. The disclosure was comprehensive: it set out the transactions, the root cause, the ownership-and-control analysis, and the remediation steps already taken. OFSI's published guidance treats the completeness and timeliness of a VSD as a positive mitigation factor, and this influenced the outcome. Residual funds were frozen pending OFSI's review, and the firm upgraded its screening programme to near-real-time feeds and a recalibrated match threshold.
What is the lesson for similar businesses?
The central lesson is that a screening tool, however reputable, is not a compliance programme. Businesses should ensure their programme addresses update latency, fuzzy-match calibration, beneficial ownership screening, intermediary chain review, and alert-disposition governance. Periodic testing against known-match cases – rather than relying on the vendor's assurances – is the most reliable way to identify misconfiguration before OFSI does. Where a potential breach is identified, early legal advice on the reporting obligation and the voluntary disclosure process can materially affect the outcome.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.