Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

An OFSI matter: payment-processing controls a closer look

A payment-services firm operating across three time zones ran a routine sanctions refresh. One transaction batch, already processed, showed a flag on a correspondent bank account. The underlying beneficiary was not on a list. The intermediary was. The firm had ten days to decide whether it had a reporting obligation – and no clear owner for the decision.

Payment-processing controls under OFSI are a live compliance pressure point. The UK financial-sanctions regime, administered by the Office of Financial Sanctions Implementation under the Sanctions and Anti-Money Laundering Act (SAMLA), requires payment-processing businesses to have controls sufficient to prevent, detect, and report prohibited transactions in real time. A control gap at the intermediary layer – not just at the direct counterparty level – can constitute a breach, trigger a reporting obligation, and expose the firm to civil monetary penalty even where no funds ultimately reached a designated person.

This case comment draws on an anonymised matter we handled involving a payment processor, a flagged correspondent, and a contested reporting question. It sets out the legal position under OFSI, compares the position under OFAC and the EU, and identifies the risk flags that distinguish a manageable disclosure situation from a contested enforcement one.

The situation: what the firm discovered and when

The payment processor – a regulated e-money institution with a customer base across the European Economic Area – identified the issue during a retrospective transaction monitoring review. Its primary screening tool covered direct counterparties. The correspondent bank used to settle a batch of cross-border transfers appeared on OFSI's Consolidated List of designated persons as a result of a designation made some weeks earlier.

The processor had not failed to screen the correspondent bank at the point of onboarding. The designation had occurred after the relationship was established. No automated alert had fired because the re-screening cadence for correspondent relationships was quarterly, not continuous. By the time the review surfaced the flag, the relationship had been active under the designation for a material period.

Two questions immediately arose. First, had the processor made funds available to a designated person, or merely processed transfers routed through a designated institution? Second, was the firm obliged to report to OFSI, and if so, within what window? Both questions turned on technical readings of the applicable thematic sanctions regulations and OFSI guidance, not on the commercial character of the payments. In our experience, the gap between onboarding-point screening and continuous or frequent re-screening of existing correspondent relationships is the single most common structural failure in payment-processing control environments.

The legal question: what does OFSI's regime require of a payment processor?

OFSI's regime requires persons in the United Kingdom – and in relevant cases those conducting business with a UK nexus – to refuse transactions that would make funds or economic resources available, directly or indirectly, to a designated person. The obligation is not limited to the moment of execution: the relevant thematic regulations impose a continuing duty to monitor and a specific obligation to report to OFSI as soon as practicable once a person knows or has reasonable cause to suspect it holds funds belonging to, or that a person with whom it deals is, a designated person.

The designated person test (an individual, entity, or body listed on OFSI's Consolidated List, against which asset-freezing and funds-making-available prohibitions apply) extends beyond direct counterparties. Where a payment is routed through a correspondent that is itself designated, the question is whether the processor has made funds available to that correspondent in the course of processing – for example, by permitting the settlement of a nostro balance.

OFSI's enforcement guidance distinguishes between a strict-liability breach and the degree of culpability relevant to penalty calculation. The strict-liability point is clear: if funds were made available to a designated person, a breach occurred regardless of intent. Culpability – and therefore the quantum of any civil monetary penalty – depends on whether the firm took reasonable steps, acted promptly on discovering the issue, and cooperated fully with OFSI. This is where control quality becomes a penalty-reduction argument, not merely a compliance aspiration.

The reporting obligation operates on a separate track. A firm that suspects it holds funds of a designated person, or that has dealt with one, must report to OFSI. The obligation arises on reasonable suspicion, which is a lower threshold than proof of breach. Prompt self-identification, careful documentation, and a clear narrative of what happened and why are the tools that convert a reporting moment into a credible compliance story.

Cross-regime comparison: how OFAC and the EU treat the same gap

OFAC's treatment of a payment-processor correspondent failure differs from OFSI's in two important respects, both of which matter for any cross-border payment business with US dollar flows. Under OFAC's rules, where a US dollar payment passes through a US correspondent – or where a non-US processor routes a USD transfer through the US banking system – OFAC has jurisdiction over the transaction regardless of where the processor is incorporated. The 50 percent rule (OFAC's rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked) also applies: a correspondent that is majority-owned by a Specially Designated National is itself treated as blocked even if it does not appear on the SDN List by name.

This creates an asymmetry for processors that run parallel screening against OFSI's Consolidated List and OFAC's SDN List. A correspondent might be listed by OFSI but not OFAC, or vice versa, or captured by OFAC's 50 percent rule without appearing on any published list. A control architecture designed around list-matching alone will miss the third category entirely. In our cross-border practice, we regularly advise payment processors on building a layered approach: name-list matching first, then ownership-chain analysis for significant correspondents, then periodic reassessment when publicly available ownership information changes.

The EU position, under the relevant Council regulations, applies a comparable funds-making-available prohibition and an ownership and control test (the EU and UK standard that captures non-listed entities sufficiently controlled by a designated person, assessed by reference to both legal and de facto control). The EU's test is explicitly control-sensitive, whereas OFSI's primary test mirrors the ownership threshold and separately addresses control. The practical divergence is modest for most correspondent relationships, but it matters when the designated person holds a minority stake with disproportionate governance rights.

For any processor operating between UK, EU, and US rails simultaneously, the strictest applicable prohibition governs any given transaction. Where OFAC captures a transaction that OFSI does not – or the EU captures an entity that neither list names directly – a single-regime compliance posture leaves material residual risk.

The risk flags that made this matter harder than it needed to be

Three structural gaps aggravated the compliance position in this matter. Each was correctable before the event; each created unnecessary difficulty after it.

The first was re-screening cadence. Correspondent relationships were reviewed quarterly rather than continuously or upon each new designation event. The designation that triggered the issue was publicly notified on OFSI's website in a weekly update. A monitoring subscription – which is operationally straightforward and available through multiple commercial providers – would have flagged it within hours. Instead, the gap ran for weeks. That gap directly affected the culpability analysis and the firm's ability to characterise the breach as a narrow-window detection failure rather than a systemic omission.

The second was ownership of the reporting decision. The compliance function had identified the flag. Legal had been asked to advise on whether a reportable breach had occurred. Treasury had a separate view on the counterparty relationship. Three weeks passed before a single decision-owner was identified. OFSI's guidance is explicit that the obligation to report arises on reasonable suspicion, not after internal debate has resolved all doubt. Delay in reporting – whatever its internal cause – is itself a factor in penalty calculation.

The third was documentation of the original onboarding screening. The processor could demonstrate that the correspondent had been screened at onboarding, but the records did not confirm the date, the list version, or the output. When OFSI requested the onboarding file as part of its information-gathering exercise, the gap in records meant the processor could not demonstrate a clean onboarding baseline. Record-keeping of screening outputs – including the date, the list used, and the result – is a basic control that the applicable thematic regulations and OFSI guidance both presuppose.

What does effective payment-processing controls architecture actually look like in practice? The answer has four elements: continuous list monitoring with automated designation-event alerts; a written correspondent-screening policy with defined re-screening triggers; a documented escalation and reporting protocol with a named decision-owner; and systematic record-keeping of every screening output. These are not aspirational – they are the baseline that OFSI will look for when it assesses whether a firm has taken adequate steps.

How the OFSI issue was resolved: the disclosure route

Once a single decision-owner was in place, the firm moved quickly. A voluntary self-disclosure (VSD) – a self-initiated report to OFSI of a potential or confirmed breach, made before the regulator has initiated enquiries – was prepared and submitted. The VSD set out the facts in chronological order, identified the structural cause of the re-screening gap, confirmed that the correspondent relationship had been immediately suspended, and described the remediation steps already taken and those planned.

OFSI's approach to VSD treatment is not a formal penalty-mitigation system in the way that some other regulators operate. However, OFSI's published enforcement guidance makes clear that cooperation, prompt disclosure, and self-identification of the breach are factors that reduce the penalty assessment, and in a significant number of cases result in no monetary penalty being imposed where the breach is narrow, the harm is limited, and the firm takes immediate remediation. The processor in this matter received a formal case-closure letter without a financial penalty being imposed. That outcome was not guaranteed and cannot be promised in any similar matter; it reflected the specific facts, the quality of the VSD, and the speed of remediation.

If a transaction has already been flagged, or an internal review has surfaced a potential correspondent-level breach, an early review of the reporting position preserves options that narrow with time. Contact info@caldervance.com for a confidential review of your position.

The lesson: what similar payment-processing businesses should audit now

The lesson is not that correspondent-level breaches are inevitable. It is that the structural conditions for this type of breach are present in a material number of payment-processing compliance programmes, and that the controls required to prevent it are defined, proportionate, and implementable without significant operational cost.

There is a common assumption among payment businesses that screening at onboarding is the core obligation, and that the ongoing monitoring requirement is met by periodic file reviews. That assumption is incorrect under OFSI, under OFAC, and under the EU regime. The obligation is continuous. The re-screening cadence for active relationships must reflect the pace at which designations can occur.

Separately, the internal escalation and reporting pathway for a potential financial-sanctions breach must be documented, tested, and owned before an issue arises. A compliance programme that identifies a breach and then takes three weeks to produce a reporting decision has failed – not in its detection capability, but in its response architecture. OFSI's guidance is clear that the threshold for reporting is reasonable suspicion, not internal certainty. The reporting decision should be made by a named owner, within a defined window, on a documented basis.

We regularly advise payment processors, e-money institutions, and banking correspondents on the adequacy of their screening and re-screening controls. We have acted for businesses at the point of discovery, at the point of VSD preparation, and in the subsequent engagement with OFSI. The earlier counsel is involved, the more options are available.

A common objection we hear is that full continuous re-screening of correspondent networks is operationally disproportionate for smaller processors. The objection has some force for the very smallest firms, but the relevant question is not the absolute volume of correspondents – it is the volume of correspondents in high-designation-risk categories. OFSI does not apply a proportionality exemption to the substantive obligation; it does take firm size and resource into account in penalty calibration. Designing a tiered re-screening policy – continuous for high-risk correspondents, monthly for lower-risk ones, with designation-event triggers for all – is both proportionate and defensible.

Related practices

Frequently asked questions

What went wrong in this payment-processing controls matter?
The core failure was a re-screening gap: the processor screened the correspondent at onboarding but not continuously thereafter. A subsequent designation of that correspondent was not captured until a retrospective review weeks later. Compounding the problem were insufficient documentation of the original screening output and the absence of a defined internal owner for the reporting decision, both of which delayed the firm's ability to respond promptly once the flag was identified.
How was the OFSI issue resolved?
The firm submitted a voluntary self-disclosure to OFSI once a decision-owner was in place. The VSD documented the breach clearly, confirmed immediate suspension of the correspondent relationship, and set out a remediation plan. OFSI closed the matter without imposing a financial penalty. That outcome reflected the specific facts of the case and the quality of the disclosure; it is not a guaranteed result in any similar matter.
What is the lesson for similar businesses?
Payment processors should audit three things immediately: first, the re-screening cadence for active correspondent relationships and whether it captures designation events in near real time; second, the documentation of past screening outputs, including date, list version, and result; and third, the escalation and reporting pathway for a potential financial-sanctions breach, confirming a named decision-owner and a defined response window aligned with the reasonable-suspicion threshold in OFSI's guidance.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.