A mid-sized technology distributor with operations spanning North America and the Asia-Pacific region contracted with a freight intermediary to route a consignment of controlled components. The compliance team had completed its standard counterparty screen. The intermediary was clean. The end buyer was clean. The shipment proceeded. Three months later, a secondary-ownership review surfaced a 50 percent or more aggregate holding by a designated entity in the intermediary's parent structure. The business had cleared the wrong layer of the chain.
This matter illustrates the central failure mode in sanctions risk assessment (the structured process of identifying, measuring, and mitigating exposure to applicable sanctions regimes before and during a transaction): screening tools addressed the direct counterparty but not the ownership chain behind it. Under OFAC's rules, a non-listed entity owned 50 percent or more by blocked persons is itself blocked, regardless of whether it appears on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The distributor had, without knowing it, executed a prohibited transaction.
As of July 2026, this pattern – a clean first-layer screen masking a blocked indirect owner – remains one of the most common triggers for OFAC enforcement reviews. This case comment walks through the situation the distributor faced, the legal question it raised, the analysis it required, and the lessons that apply to any business conducting cross-border transactions where US-nexus jurisdiction is in play.
The situation: a routine screen that missed the ownership chain
The distributor's compliance programme was structured around a direct-counterparty screen – name, address, jurisdiction, registration number – run against the SDN List and a selection of other denied-party databases. The programme had worked without incident for several years. It had never been stress-tested against an indirect-ownership scenario.
The freight intermediary was incorporated in a third-country jurisdiction. It appeared on no list. Its directors and shareholders of record were not designated individuals. What the screen did not surface was that a holding company two tiers up in the structure was 50 percent or more owned, in aggregate, by two designated persons acting through separately registered vehicles.
The distributor's compliance counsel identified the problem during a routine counterparty refresh, not at the point of transaction. By then, multiple shipments had been completed, invoices paid, and the goods delivered. The situation had moved from a pre-transactional risk question to a post-transaction apparent violation. That shift matters, and not just procedurally.
In our experience, the gap between what a screening tool does and what an ownership analysis requires is where most mid-market enforcement problems begin. Screening is a list-check. Ownership analysis is a chain-of-title exercise. They are not the same task, and treating them as interchangeable is the first risk flag.
The legal question: does the 50 percent rule apply, and how far does it reach?
OFAC's 50 percent rule (the rule treating entities owned 50 percent or more by blocked persons as themselves blocked) operates without registration on any list. An entity meets the test, and is therefore blocked, if persons already on the SDN List own it at or above the threshold, whether directly or through a chain of intermediate entities. The controlling instrument is IEEPA, implemented through OFAC's programme regulations and supplemented by published guidance.
Two sub-questions drove the analysis in this matter. First, did the aggregate of two designated persons' indirect holdings reach the 50 percent threshold at the intermediary level – not only at the holding-company level? Second, did the distributor, as a US-nexus business, have the legal obligation to identify that condition before transacting?
On the first question, the answer turned on aggregation. OFAC's position is that holdings of multiple blocked persons are aggregated. Two designated persons each holding 26 percent of an intermediate vehicle, which in turn held 100 percent of the freight intermediary, would, when combined, produce a blocked intermediate vehicle – and that blocke status would flow down to the intermediary itself. The arithmetic, once applied correctly, was unambiguous.
On the second question, the distributor had US-dollar settlements routed through a correspondent bank. That route conferred US-nexus jurisdiction. OFAC's rules reach any transaction that touches the US financial system, regardless of where the goods move or where the parties are incorporated. The obligation to identify blocked-party exposure before transacting was not contingent on the goods being US-origin or the parties being US-persons. The cross-border structure did not insulate the distributor from OFAC jurisdiction – it brought OFAC squarely into the picture.
How does this compare with the equivalent tests in other major regimes? Under OFSI, the UK test looks at both ownership and control (the UK and EU test for whether a non-listed entity is caught through a listed person) – a designated person can cause a non-listed entity to be caught through control levers that do not involve 50 percent ownership. The EU's consolidated test similarly extends to effective control. OFAC's 50 percent rule is, in one sense, narrower: it is a mechanical arithmetic test. In another sense it is stricter: it attaches automatically, with no discretionary element, once the threshold is met. A compliance programme calibrated only to one regime's test will routinely miss the exposure created by another.
How the matter was handled: scope, disclosure, and programme redesign
The first step was to scope the apparent violation accurately. That meant tracing every transaction that had touched the intermediary, quantifying the value of each, identifying the dates, and establishing whether any general licence – a standing authorisation that permits a defined category of transactions without a separate application – could have applied to any of them.
We assessed eligibility for applicable general licences and confirmed that none covered the transactions as structured. The goods had moved; consideration had been paid; no wind-down or emergency authorisation applied retrospectively to the completed shipments. The scope was fixed and determinable.
The second step was to advise on voluntary self-disclosure. A VSD (voluntary self-disclosure to a regulator) is a formal submission to OFAC describing the apparent violation, the facts, the ownership analysis, and the corrective measures taken. OFAC's enforcement guidelines treat a timely, complete, and well-structured VSD as a significant mitigating factor when it determines the appropriate response. The disclosure is not an admission of wilful conduct. It is a documented showing that the business identified the problem, came forward, and took corrective action.
The distributor submitted a VSD. The submission included a full ownership-chain diagram, a transaction schedule, an explanation of the screening failure, and a programme redesign plan. The matter was resolved without a public penalty action. We are not in a position to state – and no one should – that any particular VSD outcome can be predicted or guaranteed. What can be said is that a well-prepared disclosure, submitted promptly, changes the risk profile of the matter materially.
The third step was the programme redesign. We worked with the distributor to map ownership and control through three tiers for each counterparty above a defined transaction-value threshold, redesign the screening logic to aggregate indirect holdings, and introduce a periodic counterparty refresh cycle so that post-onboarding changes in ownership could be captured.
What is the difference between a screen and an ownership analysis?
A screen is a database check against published lists; an ownership analysis is an independent reconstruction of a counterparty's beneficial ownership chain to determine whether any listed or sanctioned person sits within it at a controlling or material threshold.
Sanctions screening tools – even well-configured ones – are designed to check names and identifiers against lists. They do not, by default, reconstruct beneficial ownership chains. A company not on any list will return a clean result, irrespective of who owns it. That is not a deficiency in the tool. It reflects what the tool does. The deficiency is in the compliance programme design if it treats a clean screen as a conclusion rather than a starting point.
Ownership analysis begins where the screen ends. It asks: who owns this entity, at what percentage, directly and through intermediaries, and does that chain include any person appearing on the SDN List or any other applicable list? For OFAC purposes, the arithmetic of aggregation must then be applied. For OFSI and the EU, the analysis must additionally consider whether a designated person could exercise control through non-ownership mechanisms – contractual rights, board appointment powers, or veto rights.
How granular does the ownership analysis need to be? The answer is calibrated to risk. A one-time small-value purchase from a well-known publicly traded supplier requires a different depth of analysis than a recurring high-value supply relationship with a privately held intermediary in a jurisdiction with opaque corporate registers. The risk calibration itself is a compliance judgment, and it should be documented. In our cross-border practice, we regularly advise clients to build a tiered due-diligence matrix: the tier a counterparty falls into determines the depth of the ownership trace and the frequency of refresh.
Does an ownership analysis need to go to the ultimate beneficial owner in every case? Not necessarily – but where the chain includes an entity domiciled in a high-risk jurisdiction, or where the structure is unusually layered, the presumption should be to trace fully and document the stopping point explicitly.
Risk flags: patterns that should prompt deeper review
Several conditions in this matter should have triggered an escalation to full ownership analysis earlier. Each one, standing alone, would have been a reason to look harder. Together, they constituted a pattern that a well-designed compliance programme should have caught.
- The freight intermediary was a newly incorporated entity with limited public footprint – a condition often associated with shell-company structures.
- Its jurisdiction of incorporation had limited corporate-transparency requirements, making beneficial ownership difficult to trace from public sources alone.
- The payment routing included a US-dollar settlement leg – creating US-nexus exposure and bringing OFAC jurisdiction into scope regardless of the location of the parties.
- The counterparty relationship had been established quickly, under commercial time pressure, without a full due-diligence file being assembled before the first shipment.
- The goods being distributed were controlled items – a condition that should always elevate the due-diligence standard, since the intersection of export-control classification and sanctions risk is a documented area of OFAC and BIS enforcement overlap.
None of these flags required proof of wrongdoing. They required escalation. The compliance programme as designed did not have an escalation trigger calibrated to any of them.
A further risk flag that practitioners should note: counterparty relationships that begin as a test transaction or a pilot and then scale into a recurring commercial relationship. In our experience, the due-diligence standard applied at onboarding is often not revisited as the relationship grows. The first transaction gets the most scrutiny; the tenth runs on the file from the first. Ownership structures change. Beneficial owners are designated. The counterparty that was clean at onboarding may not be clean eighteen months later.
The position above covers the standard pattern. Your facts – the counterparty structure, the goods, the payment route, the jurisdictions in play – change the analysis. If you are uncertain whether a counterparty relationship requires deeper ownership review, contact Calder & Vance at info@caldervance.com for an initial assessment.
Cross-regime considerations: when OFAC exposure means more than one regime
A US-nexus transaction that triggers OFAC exposure will frequently carry implications under other regimes as well. The distributor in this matter had operations in an Asia-Pacific jurisdiction subject to its own sanctions obligations, and the goods were classified under the EAR (the Export Administration Regulations, administered by the US Bureau of Industry and Security). The OFAC apparent violation sat alongside potential BIS exposure and a separate reporting obligation under the distributor's operating jurisdiction.
BIS's enforcement posture is distinct from OFAC's. The relevant instrument is the Export Administration Regulations, and the enforcement authority is the BIS Office of Export Enforcement. Where a transaction involves controlled goods – items with an ECCN (Export Control Classification Number under the US Commerce Control List) – the analysis of whether a licence was required runs through BIS separately from the OFAC blocked-party question. In this matter, the goods had an applicable ECCN. The end-use and end-user controls that BIS requires were also in question.
The interaction between OFAC and BIS exposure matters for how a voluntary disclosure is structured. A combined OFAC-BIS apparent violation should be disclosed to both agencies, in a coordinated manner and with a consistent factual record. Submitting separate disclosures that describe the same facts differently – even inadvertently – creates its own risk.
In jurisdictions such as Singapore, Australia, and the UAE, autonomous sanctions regimes impose independent obligations on businesses operating there. Singapore's MAS guidance on sanctions compliance sets out expectations for financial institutions that closely track the OFAC ownership-analysis standard, and the intersection of a US-nexus OFAC matter with a Singapore-regulated entity creates a dual-reporting question that needs to be resolved with reference to both regimes concurrently. We advise on the US side of such matters and, where local counsel in the relevant jurisdiction is required, coordinate the cross-border analysis so that disclosures are consistent and timely.
If a transaction has already been flagged, or an apparent violation has been identified, an early multi-regime review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss the position.
The lesson: compliance programme design, not screening tool selection
The most durable lesson from this matter is not about which screening tool to buy. It is about how a compliance programme is designed and what it is designed to do.
A screening tool is an input to a compliance programme. It is not the programme. The compliance programme must define what questions are asked, at what depth, for which counterparties, and at which points in the relationship lifecycle. The ownership-analysis question – who ultimately owns this entity, and does that chain include any blocked person at or above the applicable threshold? – is a programme-design question. It must be answered by a documented process, not delegated to a list-check.
There is a myth that circulates in mid-market compliance teams: that OFAC violations are a concern primarily for large financial institutions and that a non-financial business transacting outside the United States is unlikely to face enforcement attention. This is wrong on both counts. OFAC's jurisdictional reach extends to any transaction that touches the US financial system – including US-dollar settlements, US-bank correspondent relationships, and US-incorporated intermediate entities. The distributor in this matter was not a financial institution. It was a technology company that settled invoices in US dollars. That was enough.
The correct frame is not "are we the kind of business that OFAC comes after?" The correct frame is "does our transaction have a US-nexus, and if so, have we conducted the ownership analysis that OFAC's rules require?" If the answer to the first question is yes and the answer to the second is no – or not properly – the compliance programme needs redesign, not a new tool.
Related practices
- Sanctions compliance audit and testing – independent testing of screening logic, ownership-analysis processes, and programme documentation.
- Sanctions risk assessment: a Singapore matter – how an Asia-Pacific business managed autonomous-sanctions exposure alongside US-nexus OFAC risk.
- Trade finance controls: an Australia matter – sanctions and export-control due diligence in a trade-finance context.