A payment firm onboards a new institutional client. The client holds cryptocurrency in a self-hosted wallet and routes settlements through a virtual-asset service provider registered outside the United Kingdom. Mid-onboarding, a screening alert fires on the client's beneficial owner. The compliance team faces an immediate question: does UK financial-sanctions law reach this transaction, and does it matter that the asset is digital rather than fiat? The answer, under the Office of Financial Sanctions Implementation, is an unambiguous yes.
Crypto and VASP sanctions compliance under OFSI rules is governed by the Sanctions and Anti-Money Laundering Act 2018 ("SAMLA") and the thematic regulations made under it. The prohibitions apply to cryptoassets in the same way they apply to fiat funds. A business that processes, transfers, or holds digital assets for or on behalf of a designated person – or that makes those assets available to one – commits a breach, regardless of the blockchain on which the transaction settles.
This briefing sets out who administers the regime, what the core prohibitions are, how the ownership-and-control test applies to cryptoasset structures, what reporting obligations bite, and how OFSI's enforcement posture has developed. It closes with a cross-regime comparison and the practical steps a VASP or financial institution should take now.
Who administers OFSI and what is its legal authority over cryptoassets?
OFSI administers UK financial-sanctions law as an executive agency of His Majesty's Treasury, deriving its authority from SAMLA and the thematic regulations made under it. The regime is autonomous: post-2021, UK sanctions designations are no longer automatically aligned with EU or UN lists, and OFSI can list persons that OFAC or the EU Council have not, and vice versa.
OFSI's formal guidance confirms that the prohibitions on dealing with funds and economic resources extend to cryptoassets. The guidance treats a cryptoasset as an "economic resource" capable of being exchanged for funds, goods, or services. That classification is not limited to stablecoins or tokenised securities. It covers any digital representation of value that a designated person holds or to which a designated person has access.
The practical effect is wide. A UK-based exchange, a UK-connected payment firm, a UK wallet provider, and any foreign VASP with a UK nexus must all treat their cryptoasset obligations identically to their fiat obligations. The question of jurisdiction – is this firm "in" the UK? – is discussed below. For now, the starting point is clear: where OFSI has reach, digital assets are fully in scope.
What does OFSI prohibit in practice for VASPs and cryptoasset firms?
The core prohibition is making funds or economic resources available, directly or indirectly, to or for the benefit of a designated person. Applied to cryptoassets, this captures: executing a transfer of tokens to a designated address, processing a stablecoin payment where the beneficiary is designated, operating a wallet or custody service for a designated person, and providing exchange or conversion services that benefit a designated person.
Two dimensions of the prohibition deserve particular attention for VASPs. First, the "indirectly" limb. A transaction that passes through an intermediary wallet or a mixing protocol does not escape the prohibition simply because the final designated address is several hops away. OFSI expects firms to exercise judgment about the economic substance of what is happening, not to rely on technical distance.
Second, the "benefit" limb. A designated person need not be the direct counterparty. If a transaction financially advantages a designated person – for example, repaying a debt owed to them, or increasing the value of an asset they own – the prohibition may be engaged. In our experience, compliance teams at crypto exchanges frequently under-read this limb, focusing only on wallet addresses that appear on the UK Sanctions List.
There is also a dealing prohibition. Acquiring cryptoassets from a designated person, or disposing of assets in a way that benefits one, is caught. This matters for secondary market transactions: a firm buying tokens from a counterparty that is itself designated, or that is owned or controlled by a designated person, risks a breach even if its own wallet address is clean.
How does the ownership-and-control test apply to cryptoasset structures?
Under OFSI and the relevant thematic regulations, a non-listed entity is treated as itself caught by the prohibitions if it is owned or controlled by a designated person. The UK test looks at both ownership and control, unlike the US approach, which focuses primarily on the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked).
In the cryptoasset context, the ownership-and-control question arises in several layers. A VASP may be incorporated in a jurisdiction that does not require disclosure of beneficial owners. Its token treasury may be held by a decentralised autonomous organisation with pseudonymous governance token holders. A DeFi protocol may have smart-contract administrators who are themselves unlisted but whose wallets are funded by a designated person.
OFSI does not provide a safe harbour for cryptoasset structures simply because they are technically decentralised. If a designated person exercises effective control over a protocol, treasury, or platform – whether through governance tokens, administrative keys, or economic dominance – the assets connected to that structure may be subject to the prohibitions. The analysis is fact-specific, and it is rarely resolved by a single database check.
How do you assess control in a pseudonymous environment? The answer requires combining on-chain analytics with off-chain corporate intelligence. Wallet-clustering tools, transaction-graph analysis, governance forum participation, and entity registry searches in multiple jurisdictions are all relevant. This is not screening in the traditional sense; it is a structured investigation that draws on compliance, legal, and forensic skills simultaneously.
The divergence from OFAC's position is practically significant for cross-border platforms. Under OFAC, a foreign VASP might conclude that a 40-percent holding by a blocked person does not trigger US prohibitions. Under OFSI, if that 40-percent holder also exercises de facto control over the platform's operations, the UK analysis may reach a different conclusion. A platform operating across both regimes needs to run both tests.
What reporting and record-keeping obligations apply to VASPs under OFSI?
Where a VASP or financial institution knows or suspects that a person is a designated person, or that a transaction involves the funds or economic resources of a designated person, OFSI imposes a statutory obligation to report that knowledge or suspicion to OFSI without delay. The obligation is not discretionary; it does not depend on whether the firm has frozen assets or whether the transaction has been blocked.
The reporting duty is separate from and in addition to the Suspicious Activity Report obligations that arise under anti-money-laundering rules. Both may apply simultaneously to the same set of facts. Firms that file an SAR but fail to report to OFSI are not compliant with the financial-sanctions regime.
Record-keeping obligations require firms to retain documentation of their screening processes, the decisions they made, and the basis for those decisions. OFSI's enforcement guidance places weight on whether a firm maintained adequate records at the time of a potential breach. In a post-event review, the absence of contemporaneous documentation is itself a serious aggravating factor.
The position above covers the standard case. Your facts – the counterparty, the blockchain, the asset class, the jurisdiction of the VASP, the nature of the underlying smart contract – change the analysis in ways that matter. We regularly advise crypto and VASP businesses on mapping these obligations before a reporting event arises, not after.
For a confidential review of your current reporting and screening arrangements, contact Calder & Vance at info@caldervance.com.
How does OFSI enforce financial sanctions against cryptoasset businesses?
OFSI has a civil enforcement power to impose monetary penalties for breaches of financial-sanctions regulations, including those involving cryptoassets. The civil penalty regime operates on a strict-liability basis for most purposes: it is not necessary for OFSI to prove that a firm knew it was dealing with a designated person in order to establish that a breach occurred. Knowledge and intention are relevant to the quantum of the penalty and to whether OFSI exercises its discretion to pursue enforcement.
OFSI's enforcement guidance distinguishes between cases where a firm had reasonable cause to suspect a designated-person connection and cases where no such reason existed. Firms that conducted no screening, held no sanctions policy, or relied on screening tools that did not cover cryptoassets are likely to be assessed as having inadequate controls. That assessment carries weight in the penalty decision.
OFSI also has a power to refer cases to the Crown Prosecution Service for criminal prosecution. Criminal liability requires knowledge or reasonable cause to suspect a designated-person connection. In the cryptoasset context, senior managers and compliance officers at VASPs should be aware that personal liability is possible, not only entity-level liability.
If a transaction has already been flagged, or if a potential breach has come to light through an internal review, an early assessment of the position can preserve options that become harder to exercise once OFSI has opened a formal inquiry. We have acted for financial institutions in the early stages of OFSI-related reviews, and the benefit of rapid legal triage is consistently material. Immediate engagement with the potential obligation – including consideration of whether a voluntary disclosure is appropriate – is the single most important first step.
For a confidential review of a potential breach or a pending OFSI inquiry, contact us at info@caldervance.com.
How does the OFSI regime compare with OFAC and EU requirements for VASPs?
For any VASP or crypto business operating across the UK, US, and EU simultaneously, understanding regime divergence is as important as understanding any single set of rules. Three areas of divergence are most significant in practice.
Ownership and control: As noted above, OFAC applies a primarily ownership-based test at the 50 percent threshold. OFSI and the EU apply an ownership-and-control test that can capture entities at lower ownership levels if a designated person exercises effective control. A platform with a 45-percent holding by a designated person is not automatically blocked under OFAC but may be caught under OFSI or the relevant EU regulations.
Territorial reach: OFAC's secondary-sanctions regime is notably broader. It can reach non-US VASPs that facilitate significant transactions for certain designated persons, even without a US nexus. OFSI and the EU do not operate an equivalent secondary-sanctions mechanism, though both apply to UK and EU persons and entities respectively, as well as to activities conducted within the UK and EU. A Singapore-incorporated VASP with UK resident directors, UK users, and a UK bank account is likely to have a UK nexus sufficient to engage OFSI's rules. A US nexus – a single US dollar correspondent relationship – can engage OFAC's rules even for a non-US firm.
Licensing routes: OFSI operates a specific-licence system that allows a firm to seek a case-by-case authorisation to conduct an otherwise prohibited transaction. OFAC operates both general licences (standing authorisations for defined categories) and specific licences. The EU licensing position is determined by member-state competent authorities under the relevant Council regulation. For a cross-border cryptoasset transaction that may be prohibited under two or more regimes, each licensing route must be pursued separately. There is no single "multi-regime licence."
Our practice regularly handles matters where a crypto or VASP business has managed the OFAC dimension of a transaction without considering the OFSI or EU position. The stricter prohibition always governs in practice: if a transaction is blocked under OFSI even though OFAC would permit it, the transaction cannot proceed for the UK leg without an OFSI licence.
What are the principal risk flags for VASPs and cryptoasset businesses?
Six risk flags recur across our work with VASPs, exchanges, and crypto-native financial institutions. None is individually conclusive, but each warrants a structured response rather than a single database screen.
- Unhosted or self-custodied wallets where beneficial ownership has not been verified. The absence of a verified counterparty makes sanctions screening materially less reliable.
- Transactions involving privacy coins or mixing protocols, where the transaction graph is deliberately obscured. These do not automatically trigger a breach, but they raise the evidential bar for demonstrating that screening was adequate.
- VASPs operating in or connected to high-risk jurisdictions subject to broad thematic sanctions programmes. The applicable country regime may prohibit all or substantially all dealings, not merely those with specific designated persons.
- Governance token distributions or DAO treasury transactions where participants have not been verified against sanctions lists. The DAO structure does not remove the obligation.
- Stablecoin or tokenised-asset issuers whose redemption process involves a fiat leg routed through a correspondent bank that may apply a different sanctions regime to the same underlying transaction.
- NFT platforms where high-value transfers could be used to move economic value to or from a designated person in a way that is less visible than a direct cryptoasset transfer.
The AUDIENCE_MYTH worth addressing directly here is the assumption that sanctions compliance is satisfied by running wallet addresses through a public list-screening tool. It is not. The UK Sanctions List is the floor, not the ceiling. Ownership-and-control analysis, on-chain investigation, beneficial-owner verification, and a considered assessment of the "benefit" limb of the prohibition are all required for a defensible programme.
We have seen compliance teams at VASPs invest heavily in automated screening tools while maintaining no documented process for escalating uncertain cases, no training on the control limb of the ownership test, and no protocol for OFSI reporting. The tool provides a false confidence that the programme is adequate. OFSI's enforcement posture makes clear that it is not.
Related practices
- Sanctions compliance audit and testing – independent testing of screening logic, policy, and governance against regulatory standards.
- Escalation and reporting obligations – understanding when and how to report potential sanctions breaches to the competent authority.
- Escalation and reporting under BIS and the EAR – the US export-control dimension of escalation obligations for dual-use and technology businesses.