Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFAC

Counterparty due diligence under OFAC: scope and obligations

A US-headquartered technology exporter routes a licensing deal through a Singapore distributor. Before the contract closes, the compliance team flags an anomaly: one of the distributor's indirect shareholders appears on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). Does the distributor itself become blocked? Can payment proceed? Does the exporter face criminal exposure simply for having run the transaction? These are not theoretical questions. As of mid-2026, OFAC continues to enforce counterparty due diligence obligations actively across sectors ranging from financial services to manufactured goods to software distribution.

Counterparty due diligence under OFAC rules requires any US person – and certain non-US persons with a US nexus – to screen each counterparty, its beneficial owners, and its affiliates against OFAC's sanctions lists before transacting. The obligation is not codified in a single instrument; it flows from the strict-liability prohibition on dealing with blocked persons under the authorities OFAC administers, primarily the International Emergency Economic Powers Act (IEEPA) and the Trading with the Enemy Act (TWEA). The 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) extends the analysis well beyond the immediate counterparty. Businesses that screen only the named entity, without tracing its ownership chain, remain exposed.

This briefing sets out who must conduct counterparty due diligence under OFAC, the legal basis, the ownership-and-control test, the cross-regime picture, enforcement posture, and the risk flags that counsel see most frequently.

Who administers counterparty due diligence under OFAC – and on what legal basis?

The Office of Foreign Assets Control, a bureau of the US Department of the Treasury, administers and enforces counterparty due diligence requirements as part of its broader sanctions mandate. OFAC derives its authority primarily from IEEPA and TWEA, supplemented by programme-specific executive orders and legislative mandates. Each of those instruments delegates to the President – and in turn to OFAC – the power to block transactions and property with designated persons and targeted regimes. The obligation to avoid such transactions carries with it an implicit obligation to identify them.

OFAC's jurisdiction is personal in two dimensions. First, it applies to US persons (US citizens and permanent residents wherever located, entities organised under US law, and any person within the United States). Second, extraterritorial reach attaches where a transaction has a US nexus – the involvement of US-origin goods, US dollar clearing, or a US financial institution anywhere in the payment chain. In our cross-border practice, this dollar-clearing point is the most commonly misunderstood aspect of OFAC jurisdiction. A wholly European transaction denominated in euros and settled through European banks has no OFAC nexus. The same transaction re-denominated in dollars and cleared through a US correspondent bank acquires one, even if neither counterparty has a US presence.

OFAC publishes and updates the SDN List and several other lists – the Consolidated Sanctions List, the Sectoral Sanctions Identifications (SSI) List, and the Foreign Sanctions Evaders (FSE) List, among others. Counterparty due diligence encompasses all of them, not only the SDN List. Each list carries different prohibitions, and conflating them generates both false positives (over-blocking) and false negatives (missed restrictions).

The 50 percent rule: when does a counterparty become blocked?

A non-listed entity is treated as blocked – and therefore subject to the same prohibitions as a listed person – when one or more SDN-listed persons own it 50 percent or more in the aggregate, directly or indirectly. OFAC's guidance, issued under its IEEPA authorities, makes this test mechanical. Intent is irrelevant. The entity need not itself be named on the SDN List. The threshold, once reached, triggers the full set of blocking obligations.

Aggregation is where most tracing errors occur. Two SDN-listed individuals each holding a 27-percent stake in the same target reach the threshold together, even though neither does so individually. Intermediate holding layers compound the problem: a listed person may hold 60 percent of a holding company that itself holds 60 percent of an operating subsidiary. The subsidiary is blocked. Screening tools that query only the immediate counterparty record will not surface this pattern.

Does the 50 percent rule have a corresponding test for non-ownership influence? The short answer is that OFAC addresses control separately. Even below the 50 percent ownership threshold, OFAC has authority to designate an entity that a blocked person controls – and once designated, that entity appears on the SDN List directly. The due diligence implication is that a counterparty operating in a sector or geography associated with active designation activity warrants enhanced scrutiny of governance arrangements, not only share registers.

One data point practitioners return to repeatedly: 50 percent is the aggregate owned interest across all blocked persons. A five-person ownership group containing two blocked persons holding 25 percent each has crossed the threshold. A business relying on a simple majority-shareholder check will miss this.

Scope of the screening obligation: what must a business check?

The scope of counterparty due diligence under OFAC is risk-proportionate but comprehensive. OFAC's enforcement guidance – published as part of its Framework for OFAC Compliance Commitments and accompanying enforcement guidelines – describes a five-element standard: management commitment, risk assessment, internal controls, testing and auditing, and training. Within the internal-controls element, counterparty screening is a core component. The framework is qualitative in nature; OFAC does not prescribe a single workflow or tool.

In practice, the screening obligation extends to the following layers:

  • The named counterparty (legal entity or individual).
  • Beneficial owners identified through the 50 percent ownership test, at each level of the ownership chain.
  • Key management, where OFAC designations in the relevant sector or programme target managers rather than owners.
  • Vessels, aircraft, and financial institutions where those are identifiable parties to the transaction.
  • Jurisdiction of incorporation and operating jurisdiction, for country-programme risk.

The depth of screening scales with risk. A one-time low-value payment to a supplier in a low-risk jurisdiction warrants a different level of diligence than a long-term distribution arrangement with a counterparty in a sector associated with active OFAC enforcement. We regularly advise clients on calibrating these levels: the objective is not exhaustive screening of every transaction at the deepest level, but a programme that demonstrably matches depth to risk.

What about screening timing? OFAC requires screening at onboarding and, for ongoing relationships, at intervals consistent with the risk level. Critically, it also requires screening against updated lists throughout the relationship. An SDN designation can be issued on any business day. A counterparty clean at onboarding may be designated twelve months later. Businesses that screen only at account opening, and never re-screen, carry accumulated exposure silently.

The position above covers the standard workflow. Your specific facts – the counterparty's jurisdiction, the goods or services involved, the payment route, the sector – change the analysis. For an assessment of your screening obligations under OFAC's counterparty due diligence rules, contact Calder & Vance at info@caldervance.com.

How does OFAC's approach compare with OFSI and the EU regime?

OFAC's ownership test is mechanical: 50 percent or more triggers blocked status automatically. The UK's Office of Financial Sanctions Implementation (OFSI) and the EU Council regime both add a control test alongside the ownership test. Under those regimes, an entity may be caught even where no single blocked person or group of blocked persons holds 50 percent or more, if a designated person controls the entity through governance rights, contractual arrangements, or other means.

This divergence has direct transactional consequences. A counterparty that clears OFAC's 50 percent test – because no blocked person or combination holds a sufficient stake – may still be caught under OFSI or EU rules if a designated person exercises control. For a business operating across the Atlantic, a clean OFAC screen does not automatically produce a clean UK or EU screen. Cross-border legal analysis is not a relay race in which one regime hands off to the next. The regimes run in parallel, and the stricter prohibition governs.

A second divergence concerns the scope of the list itself. OFAC administers multiple lists with different prohibition profiles. OFSI maintains its own UK Sanctions List, which since the UK's departure from the EU has diverged from the EU Consolidated List on a growing number of designations. A counterparty may be designated under one regime but not another. Where a transaction has both US and European dimensions, practitioners must check all applicable lists. In our experience, firms that run only an OFAC screen on transactions with a UK or EU nexus face residual exposure that a single consolidated search would have identified.

For comparison of OFAC and OFSI counterparty due diligence obligations in parallel, see our regime briefing: Counterparty due diligence under OFSI: scope and obligations. For the Southeast Asian dimension, particularly for businesses with Singapore-based counterparties, see: Counterparty due diligence under Singapore's sanctions regime.

Enforcement posture: how does OFAC treat due diligence failures?

OFAC operates a strict-liability standard for most violations of its sanctions programmes. A business need not have known that its counterparty was blocked; the failure to prevent a prohibited transaction is itself the violation. This is why the quality of a counterparty due diligence programme matters so directly at the penalty stage: it is the primary determinant of how OFAC characterises a violation and what mitigation credit it extends.

OFAC's enforcement guidelines distinguish between egregious and non-egregious violations. The distinction turns substantially on whether the respondent had a functioning compliance programme. A business with a documented, tested, and regularly updated counterparty screening programme that suffers a single hit through an obscure ownership chain is in a different position from one that has no screening programme at all. The former may receive a finding of a non-egregious violation and a reduced civil penalty. The latter faces the base penalty calculation without mitigation.

Voluntary self-disclosure (VSD – disclosure of a potential violation to OFAC before the agency identifies it independently) is a further mitigant. OFAC's enforcement guidelines treat a timely, thorough VSD as a significant factor in reducing the penalty base. The combination of a VSD and a well-documented compliance programme, including evidence of pre-existing counterparty due diligence, produces the most favourable outcome OFAC's enforcement process permits – though no outcome is guaranteed.

If a transaction has already been flagged, or a potential violation has been identified internally, an early review of the disclosure question preserves options that narrow with time. To discuss an apparent violation or a VSD assessment, contact Calder & Vance at info@caldervance.com.

Common risk flags in OFAC counterparty due diligence

Certain patterns appear repeatedly in OFAC enforcement actions and in the counterparty screening reviews we conduct. None is determinative on its own, but each warrants additional inquiry.

  • Layered ownership in high-risk jurisdictions. Holding companies incorporated in jurisdictions associated with opacity – and operating subsidiaries in the counterparty's home market – are a standard structure in enforcement matters. Beneficial ownership registers, where available, are a starting point; they are not a substitute for active tracing.
  • Mismatched business profiles. A counterparty whose stated business does not match the goods or services being procured, or whose end-use description is inconsistent with its sector, is a red flag for diversion risk as well as sanctions exposure.
  • Unusual payment routing. Payment through third-country intermediaries, requests to alter the payment currency mid-transaction, or instructions to pay into accounts not associated with the named counterparty are all patterns that OFAC's enforcement guidance identifies as indicative of potential sanctions risk.
  • Similarity to a listed name. Fuzzy matching – identifying names that are phonetically or typographically similar to SDN-listed names – is a standard capability of screening tools. It is also a source of significant false positives. A clear escalation protocol for potential matches prevents both under-investigation and over-blocking.
  • Correspondent banking exposure. For financial institutions, the counterparty in a payment message is not always the ultimate beneficiary or the originator. OFAC's guidance on correspondent banking makes clear that the screening obligation extends through the payment chain, not only to the direct instructing bank.

We have acted for businesses across manufacturing, financial services, and technology distribution where a single one of these patterns was the gateway to a wider exposure. The practical response is not to terminate every relationship where a flag appears, but to investigate, document, and reach a reasoned conclusion that the business records.

How should a business structure its counterparty due diligence programme?

OFAC's compliance framework identifies five elements: management commitment, risk assessment, internal controls, testing and auditing, and training. For counterparty due diligence specifically, the internal controls and testing elements are the most operationally demanding.

A programme adequate for OFAC purposes should, at a minimum:

  1. Map the business's jurisdictional and product exposure to identify which OFAC programmes and lists are relevant.
  2. Define the counterparty population that requires screening – direct customers, suppliers, intermediaries, and financial-institution correspondents – and the list set against which each population is screened.
  3. Establish a documented escalation pathway for potential matches, including who holds authority to clear a match, on what basis, and with what record-keeping.
  4. Set re-screening intervals calibrated to risk level, with a mechanism for accelerated screening when OFAC publishes new designations in a relevant programme.
  5. Test the screening logic periodically – including fuzzy-match sensitivity and the adequacy of ownership-chain tracing – and document the results.

That final step is where many programmes fall short. A compliance programme that has never been tested against a synthetic SDN match, or that has never run an ownership-chain tracing exercise on a complex counterparty, cannot demonstrate to OFAC that it was functioning. Demonstration requires records, not assertions.

For businesses that want an independent assessment of their counterparty due diligence controls – including testing of screening logic and ownership-chain analysis – our compliance audit practice can assist. See: Sanctions compliance audit and testing services.

A common misconception: "we have no US operations so OFAC does not apply"

This is the most persistent myth we encounter from non-US clients. The reasoning runs: the entity is not a US person, it has no offices in the United States, and its goods are not US-origin. Therefore, OFAC's rules are irrelevant.

The myth fails on several grounds. First, dollar clearing. A non-US business that invoices in US dollars and routes payment through a US correspondent bank has introduced a US nexus into the transaction. The US correspondent is itself a US person and is directly prohibited from processing a payment that involves a blocked person, regardless of where the originator or beneficiary is located. Counterparty due diligence by the non-US originating business is therefore commercially necessary: a transaction blocked at the correspondent bank level creates contractual disruption, reputational harm, and potential secondary-sanctions exposure.

Second, secondary sanctions. Certain OFAC programmes carry secondary-sanctions provisions that restrict access to the US financial system for non-US persons who transact with specified targets – even in non-dollar transactions with no other US nexus. The practical consequence is that a non-US business conducting counterparty due diligence only under its home regime may be exposed to US secondary-sanctions risk that a more thorough analysis would have surfaced.

Third, US-origin goods and technology. The EAR (the Export Administration Regulations, administered by BIS) imposes re-export controls on US-origin items. A non-US distributor of US-origin technology is subject to BIS rules on its downstream customers. Where that distributor also has OFAC-relevant counterparties, the two bodies of US law apply simultaneously. We regularly advise non-US exporters and distributors on exactly this interaction.

Related practices

Frequently asked questions

Who administers counterparty due diligence under OFAC?
The Office of Foreign Assets Control, a bureau of the US Department of the Treasury, administers and enforces counterparty due diligence requirements as part of its sanctions mandate. OFAC derives its authority from IEEPA, TWEA, and programme-specific executive orders. It publishes the SDN List and related lists, issues enforcement guidance, and conducts civil enforcement proceedings. DOJ handles criminal enforcement of wilful violations, but the civil counterparty-screening regime is OFAC's domain exclusively.
What does OFAC prohibit in relation to counterparty due diligence?
OFAC prohibits US persons – and, through extraterritorial provisions and dollar-clearing mechanics, certain non-US persons – from engaging in transactions with blocked persons, blocked entities, or entities caught by the 50 percent rule. The prohibition is strict-liability: absence of knowledge does not eliminate the violation. OFAC does not mandate a specific screening tool or method, but requires that a business maintain internal controls adequate to prevent prohibited transactions, which in practice means documented counterparty screening against all relevant OFAC lists.
How is counterparty due diligence enforced under OFAC?
OFAC enforces through civil penalty proceedings, with penalty amounts calculated by reference to the value of the transaction and statutory maxima set under the relevant programme. The agency's enforcement guidelines distinguish egregious from non-egregious violations and extend substantial credit for a functioning compliance programme and for timely voluntary self-disclosure. OFAC may also issue cautionary letters, no-action findings, or refer matters to DOJ for criminal prosecution in cases involving wilful conduct. The quality of the counterparty due diligence programme is the central variable in the enforcement outcome.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.