A UK payments firm onboards a new corporate client. Screening flags a director who shares a name with a person on OFSI's Consolidated List. The compliance team does not know whether this is a true match, a false positive, or an indirect control issue that reaches the corporate itself. The clock is running. Under the Sanctions and Anti-Money Laundering Act 2018 ("SAMLA") and the relevant thematic regulations, the obligation to freeze and report is strict. Gaps in the programme at this moment can turn a manageable question into an enforcement referral.
As of August 2026, sanctions compliance programmes under OFSI (the Office of Financial Sanctions Implementation, HM Treasury's financial-sanctions authority) are not governed by a single prescribed framework, but OFSI's enforcement guidance and its published compliance expectations define a clear standard. A well-designed programme must address screening quality, ownership-and-control testing, reporting within a short statutory window, record-keeping obligations, and staff training. Programmes that fall short of this standard attract the full range of OFSI's civil monetary powers.
This briefing sets out who administers the regime, what obligations bite, how the ownership-and-control test works compared with OFAC's approach, what OFSI's enforcement posture means in practice, and how the compliance programme design process should be structured for a cross-border business operating under both UK and parallel regimes.
Who administers OFSI and what is its legal basis?
OFSI administers UK financial sanctions on behalf of HM Treasury. It derives its authority primarily from SAMLA and the relevant thematic sanctions regulations made under it. SAMLA provides the enabling power; the thematic regulations – covering asset freezes, prohibitions on making funds or economic resources available, and ancillary obligations – define the specific prohibitions that apply to designated persons and their connected entities.
OFSI's remit is financial: asset freezing, prohibitions on fund transfers, and licensing exceptions. Export licensing sits separately with the Export Control Joint Unit ("ECJU"). The two can interact – a goods transaction may engage ECJU's export controls and OFSI's financial prohibitions simultaneously – but the administering authorities and the compliance obligations are distinct.
Compared with OFAC in the United States, OFSI operates within a different constitutional structure. OFAC derives its authority principally from IEEPA and other executive powers; OFSI operates under primary and secondary legislation subject to parliamentary scrutiny and, in designation challenges, judicial review by the UK courts. That structural difference shapes the enforcement and licensing culture of each authority.
In our cross-border practice, we regularly advise businesses that have encountered OFSI compliance requirements for the first time after years of OFAC-focused programmes. The authorities share broad objectives, but the legal architecture, the enforcement tools, and the licensing procedures differ in ways that matter operationally.
What prohibitions and obligations does a compliance programme need to cover?
A sanctions compliance programme under OFSI must, at a minimum, address five categories of obligation: asset-freezing requirements, the prohibition on making funds or economic resources available to or for the benefit of designated persons, financial-information reporting, licensing conditions (where a specific licence has been granted), and record-keeping. Each category has a distinct compliance workflow.
The asset-freeze obligation requires immediate action when a firm identifies that it holds funds or economic resources owned, held, or controlled by a designated person. Holding does not require any transaction; the obligation to freeze arises at the point of identification. A programme must therefore embed the freeze workflow into its operational procedures, not just its screening checklist.
The prohibition on making funds or economic resources available is broader. It covers indirect benefit – a payment to a third party that confers economic benefit on a designated person can breach the prohibition even if the designated person is not named on the payment instruction. In our experience, compliance teams often focus on direct payments and miss the indirect-benefit analysis.
The reporting obligation requires firms to tell OFSI if they know or reasonably suspect they are holding frozen assets. The reporting window is short and is measured from the point at which the firm forms the relevant knowledge or suspicion. Record-keeping obligations under SAMLA and the relevant thematic regulations require firms to retain relevant documents for a specified period. Both obligations must be built into the programme's standard operating procedures.
The position above covers the standard obligations. Your facts – the sector, the counterparty geography, the goods or services involved, the route the funds take – change the analysis in ways that generic templates do not capture. For an initial assessment of whether your compliance programme addresses OFSI's current expectations, contact Calder & Vance at info@caldervance.com.
How does the OFSI ownership-and-control test differ from OFAC's 50 percent rule?
The OFSI ownership-and-control test differs materially from OFAC's mechanical 50 percent rule, and that difference is one of the most consequential divergences in cross-border sanctions compliance. Under OFSI, a non-listed entity can be caught not only by the ownership percentage held by a designated person but also by the concept of control – and control is a qualitative, fact-specific assessment.
Under OFAC, the position is more mechanical: entities owned 50 percent or more in the aggregate by blocked persons are themselves treated as blocked, regardless of whether the ownership structure was designed to confer control. The OFAC test turns on the arithmetic of ownership. Intention is irrelevant.
OFSI and the EU approach both extend to control. A designated person may hold less than 50 percent of an entity and yet control it – through board composition, veto rights, contractual powers, or practical economic dominance. Under the UK thematic regulations, a firm analysing a counterparty cannot stop at the ownership threshold. It must ask whether the designated person controls the entity by any other means. Where that answer is uncertain, the analysis must go further before the relationship or transaction proceeds.
The EU position under the relevant Council regulations mirrors OFSI's approach in covering both ownership and control, though the precise legal tests and the guidance from EU competent authorities differ in their application. A business operating under both regimes must calibrate its programme to the stricter analysis – and where the regimes diverge, the stricter prohibition governs for the transactions subject to each.
Does your screening system test for control as well as ownership percentage? In our experience, most off-the-shelf screening tools flag listed names and percentage thresholds efficiently, but they do not perform qualitative control analysis. That analysis requires human review, informed by the underlying corporate documents and governance arrangements.
What does OFSI's enforcement posture mean for compliance programme design?
OFSI's enforcement posture is increasingly active. Its published enforcement guidance identifies a range of civil monetary penalty powers, and the authority has demonstrated willingness to use them against financial institutions and non-financial businesses alike. Understanding that posture is essential to calibrating the investment a compliance programme should make.
OFSI distinguishes between cases where a firm had no reasonable compliance measures in place, cases where measures existed but failed, and cases where the firm reported promptly and cooperated fully. The existence and quality of a compliance programme is therefore a direct factor in OFSI's assessment of penalty level. A programme that meets the published standard – and whose documentation demonstrates that it was followed – positions a firm materially differently from one that relied on ad hoc procedures.
Voluntary self-disclosure ("VSD" – a proactive report by a firm to OFSI that it has identified a potential breach before OFSI has contacted it) is expressly recognised in OFSI's enforcement guidance as a mitigating factor. A well-structured compliance programme creates the conditions for an early VSD by building the internal detection, escalation, and reporting pathways that identify issues before they become OFSI-initiated inquiries.
OFSI also has the power to refer matters to law-enforcement authorities where criminal sanctions are indicated. The compliance programme must therefore address both the civil-penalty risk (which OFSI administers directly) and the conditions that could give rise to a criminal referral. Separate reporting lines, legal-privilege considerations, and crisis-response protocols are all elements of a programme designed with enforcement risk in mind.
If a transaction has already been flagged, or if a screening alert has produced a result that the firm has not yet reported, early legal review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.
What are the five core elements of a compliant OFSI sanctions programme?
A compliant sanctions programme under OFSI is built around five practical elements: clear governance and ownership of the sanctions-compliance function; screening that tests name matches, ownership, and control; documented escalation and decision-making procedures; training proportionate to the firm's exposure; and record-keeping that supports both internal review and regulatory inquiry.
Governance is foundational. OFSI's compliance expectations point toward senior management ownership of the sanctions function. That means a named individual accountable for the programme, board-level or executive-level reporting on sanctions risk, and a clear line from the compliance function to the firm's risk appetite. Programmes that exist only at an operational level, without senior accountability, do not meet the standard.
Screening must be fit for purpose, not just present. A firm that uses a screening tool, but has not calibrated it to the relevant lists, not validated its false-positive rate, and not established a documented workflow for resolving alerts, has a programme in name only. OFSI's enforcement record includes cases where screening existed but was demonstrably inadequate. The question OFSI asks is not whether you screen, but how well.
Escalation procedures must be documented and tested. A compliance officer who identifies a potential match and applies informal judgment without a written protocol leaves the firm exposed to the argument that its response was arbitrary. Documented procedures – covering the steps from alert to freeze decision or clearance, the individuals authorised to make each decision, and the record made of it – demonstrate that the programme functions as designed.
Training must be role-specific. Front-line relationship managers who receive generic sanctions awareness training are not the same as trade-finance teams trained on specific document-review obligations, or treasury staff trained on payment screening and indirect-benefit risk. The programme must map the training to the actual exposure of each function.
Record-keeping must support both the freeze and reporting obligations and the firm's ability to demonstrate compliance in a regulatory review. Records of screening decisions, escalation steps, licence conditions, and reporting correspondence must be retained for the period specified under the relevant regulations. Five years is the general record-keeping period under UK financial-sanctions rules, though the firm should verify the current requirement under the applicable thematic regulations before relying on that figure.
How does a cross-border compliance programme handle multiple regimes simultaneously?
A cross-border compliance programme operating under OFSI, OFAC, and the EU regime must address the points at which the regimes overlap and the points at which they diverge. Where they overlap – the same designated person appearing on multiple lists – the practical compliance obligation is broadly consistent, though the procedural steps (reporting, freeze timing, licensing routes) differ by authority. Where they diverge, the stricter prohibition governs for the transactions subject to each regime.
For a UK-headquartered financial institution with US dollar-clearing operations and EU-regulated subsidiaries, the compliance programme cannot be built around a single list or a single ownership test. It must map: which entity within the group is subject to which regime; which transactions trigger which reporting obligations; how the licensing processes of OFSI and OFAC interact where a licence is sought for the same underlying transaction under both authorities; and how conflicting obligations – for example, where one regime permits a transaction that another prohibits – are handled by the group's governance structure.
We regularly advise on exactly this configuration. The cross-regime mapping exercise is not a one-time project; it requires updating whenever a regime issues new guidance, adds a new designation programme, or changes its licensing criteria. The programme's governance structure must include a mechanism for capturing regulatory change and translating it into updated procedures.
Secondary-sanctions risk is a particular cross-border concern. OFAC's secondary-sanctions programmes can affect non-US businesses that have no direct US nexus but conduct transactions of a type that OFAC has identified as triggering secondary risk. A UK business with OFSI obligations may also face OFAC secondary-sanctions exposure on certain transaction types. The OFSI compliance programme must address this risk explicitly, even though OFSI does not administer US secondary sanctions. Ignoring the cross-regime dimension leaves a structural gap that an enforcement review would quickly identify.
Common risk flags and when to involve counsel
The most common risk flags in OFSI compliance programmes fall into four categories: gaps in the ownership-and-control analysis, inadequate escalation for indirect-benefit questions, absence of a documented VSD protocol, and a compliance programme that has not been updated to reflect changes in the applicable thematic regulations or OFSI's published guidance since it was first designed.
Ownership-and-control gaps arise most often where the programme has been designed to screen counterparties at onboarding but has not been extended to cover post-onboarding changes in ownership, new designations affecting existing relationships, or the ownership chains of intermediate entities in complex structures. The obligation does not freeze at the onboarding date.
Indirect-benefit analysis is frequently absent from programmes designed primarily for direct-payment screening. A payment to a supplier who is then required to pass the funds, in any form, to a designated person, raises indirect-benefit issues regardless of whether the designated person appears in the firm's transaction records.
A myth that we encounter regularly is that only financial institutions need a formal OFSI compliance programme. In fact, the prohibitions under SAMLA and the thematic regulations apply to all persons subject to UK jurisdiction, including non-financial businesses, professional-services firms, and individual traders. The complexity and formality of the programme should be proportionate to the firm's exposure, but the obligation to comply is universal. OFSI's enforcement record now includes non-financial businesses, not only banks and payment firms.
Counsel should be involved whenever a firm identifies a potential match that has not been resolved within its standard operational procedures, when OFSI makes a direct inquiry, when a licence condition may have been breached, or when the firm is considering a VSD and needs to assess scope and timing. Early involvement does not increase the firm's exposure; it structures the response to protect both the firm and the individuals within it who bear compliance responsibilities.
Related practices
- Sanctions compliance audit and testing – structured review and gap analysis of your existing programme against current regulatory expectations.
- Counterparty due diligence under BIS/EAR – US export-control diligence obligations and their interaction with financial-sanctions screening.
- Counterparty due diligence under EU sanctions – ownership-and-control testing and diligence requirements under EU Council regulations.