Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Name and entity screening under OFSI: scope and obligations

A payment firm processing a wire transfer for a corporate client in the United Kingdom flags a name match against its screening list. Is the match a true positive? Is the underlying entity blocked under the Office of Financial Sanctions Implementation's rules, even if only a shareholder appears on the Consolidated List of Financial Sanctions Targets? The answer shapes whether the firm can proceed, must freeze, or must report. As of August 2026, the stakes have not diminished: OFSI's enforcement posture has hardened, civil monetary penalties have increased in scope, and the expectations placed on firms conducting name and entity screening (the systematic checking of counterparties, beneficial owners, and payment parties against the UK sanctions lists) have moved from best practice to a clearly implied regulatory obligation.

Under the UK sanctions regime, administered by OFSI under powers derived from the Sanctions and Anti-Money Laundering Act ("SAMLA"), financial sanctions prohibitions bite on any person or entity that is designated, or that is owned or controlled by a designated person. Effective name and entity screening is the primary operational mechanism through which firms detect and avoid a breach. Failure to screen adequately is both a compliance gap and, where it results in a prohibited transaction, a direct route to enforcement action.

This briefing sets out who administers OFSI's screening obligations, what the legal prohibitions require, how the ownership and control test extends those prohibitions beyond the Consolidated List, where the UK regime diverges from OFAC and EU equivalents, and what firms should do when a screen produces a hit.

Who administers name and entity screening under OFSI, and what is the legal foundation?

OFSI – the Office of Financial Sanctions Implementation, a unit of His Majesty's Treasury – administers financial sanctions in the United Kingdom and maintains the Consolidated List of Financial Sanctions Targets. OFSI's authority rests primarily on SAMLA and the secondary legislation made under it: the thematic and country-specific financial-sanctions regulations that transpose UN Security Council measures and give effect to UK-autonomous designations.

OFSI does not operate a separate mandatory-screening statute in the way some other regulators do. Instead, the obligation to screen flows from the prohibitions themselves. If you make funds available to a designated person – whether intentionally or because you failed to identify the person – you have committed an act prohibited by the relevant thematic regulations. Screening is the control that prevents that act. Sector supervisors, including the Financial Conduct Authority and the Prudential Regulation Authority, reinforce this by treating screening failures as evidence of inadequate systems and controls.

The regime applies to all persons in the United Kingdom and to all UK persons operating abroad. Non-UK firms can also be caught where they process sterling payments, operate a UK branch, or execute transactions that have a UK nexus. In our cross-border practice, we regularly advise foreign financial institutions and corporates who had not appreciated that a UK-nexus transaction brought them within OFSI's reach.

What does OFSI prohibit, and how does it extend beyond the Consolidated List?

The core prohibitions in UK financial-sanctions regulations are fourfold: making funds or economic resources available to a designated person; dealing with funds or economic resources owned, held, or controlled by a designated person; receiving funds from a designated person; and facilitating any of the above. These prohibitions are strict – intention is relevant to the severity of the penalty, not to whether a breach occurred.

The Consolidated List identifies designated persons by name, aliases, date of birth, and identification details. But the prohibitions do not stop at listed names. The ownership and control test (the rule that non-listed entities owned or controlled by a designated person are themselves subject to the same prohibitions as the designated person) significantly expands the universe of blocked counterparties.

Under OFSI's approach – and the EU's equivalent – the test has two limbs. The ownership limb catches entities where a designated person holds, directly or indirectly, more than 50 percent of the shares or voting rights. The control limb catches entities where a designated person can exercise significant influence or control over the entity's management or decisions, even below the 50 percent ownership threshold. This is broader than OFAC's purely mechanical 50 percent aggregation rule. OFAC does not apply a control test; OFSI does. That difference matters greatly for corporate-structure analysis and for firms screening upstream shareholders.

In our experience, the control limb catches structures that pass a pure ownership screen: a designated individual holding 40 percent of shares but exercising contractual veto rights over major decisions may control the entity within OFSI's meaning. Any firm relying solely on automated list screening, without a manual review of beneficial-ownership and governance data, will miss these cases.

The position above covers the standard case. Your facts – the counterparty's jurisdiction of incorporation, the structure of its shareholding, the nature of the transaction, and the thematic regulation in play – can change the analysis materially.

For an assessment of your OFSI screening obligations, contact Calder & Vance at info@caldervance.com.

How does the OFSI screening obligation compare with OFAC and the EU?

For a business operating across the Atlantic and into continental Europe, the UK, US, and EU screening regimes sit in parallel, each with its own list, its own ownership test, and its own enforcement architecture. Understanding where they diverge prevents the compliance error of treating OFSI as simply a transposition of OFAC logic.

OFAC maintains the Specially Designated Nationals and Blocked Persons List (SDN List) and applies its 50 percent rule: entities owned 50 percent or more in the aggregate by one or more SDNs are blocked, automatically, by operation of law. The test is mathematical. Control – governance rights, director appointments, contractual authority – is not separately assessed unless OFAC publishes a specific designation extension.

The EU applies a test that mirrors OFSI's: ownership above 50 percent, or control as defined in the relevant Council regulation, triggers the prohibition. The EU Consolidated List and the UK Consolidated List are no longer identical since the UK's departure from the EU. Divergence is real: the EU may designate a person the UK has not yet listed, and vice versa. A firm screening only against one list carries unexplained gap risk in its compliance programme.

Where the three regimes converge is on the underlying concept: prohibitions extend beyond the named list through indirect ownership or control. Where they diverge is on how the control test is formulated and the thresholds at which it operates. When a transaction involves counterparties in the United States, an EU member state, and the United Kingdom simultaneously, the stricter prohibition governs. Firms must screen against all three lists and apply the broadest applicable test.

Secondary sanctions risk adds a further layer for UK-based firms with US dollar operations. OFAC's secondary-sanctions programmes can target non-US persons who deal with certain designated persons, even without a US nexus. A UK firm that clears a transaction in US dollars through a US correspondent bank, or that deals in sanctioned goods, faces OFAC extraterritorial exposure in addition to its OFSI obligations. We regularly advise clients on the interaction between these two regimes, and the point at which a cross-border transaction requires a US-law opinion alongside the UK analysis.

What does an effective name and entity screening programme look like under OFSI?

An effective screening programme operates across four dimensions: list coverage, matching logic, ownership-chain analysis, and escalation procedures. OFSI has not prescribed a single technical standard, but its enforcement guidance and the approach of sector supervisors set a clear expectation that firms deploy screening that is proportionate to their risk profile and that identifies both listed persons and entities caught through the ownership and control test.

List coverage means screening against, at minimum, the UK Consolidated List. A programme designed around the OFSI list alone will miss EU designations (relevant to EU-currency transactions) and UN Security Council listings. For firms with US operations or US-dollar exposure, the SDN List must be added. The appropriate list set is determined by the firm's business, its counterparty geography, and the currencies and jurisdictions through which it transacts.

Matching logic is where screening tools frequently fail. Name-matching must account for transliteration variants, aliases, and common transcription errors in foreign-language names. A fuzzy-match threshold set too high produces false negatives; set too low it produces unmanageable alert volumes. Calibration is a recurring exercise, not a one-time setting. Have you reviewed your threshold since your last significant counterparty intake?

Ownership-chain analysis is the step that automated screening cannot perform unaided. Once a potential match is identified in the ownership chain above a counterparty, the firm must assess whether the ownership or control threshold is met. This requires beneficial-ownership data – company registry filings, ultimate beneficial owner registers, and in some cases commercial data sources – and a structured legal assessment of whether the control test is satisfied. Screening software produces a flag; the legal analysis determines whether the flag constitutes a prohibited transaction.

Escalation procedures must specify what happens when a true positive is identified. Funds must be frozen. The account must be blocked. OFSI must be notified. Where a firm is uncertain whether a match is a true positive, it should not proceed with the transaction while the analysis is ongoing. Acting on an uncertain match without a resolution is itself a risk.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.

What are the reporting and record-keeping obligations attached to OFSI screening?

The reporting obligation under UK financial-sanctions regulations applies to any person in the regulated sector who knows or has reasonable cause to suspect that a person is a designated person, or that they have committed an offence under the regulations. The obligation to report to OFSI is separate from, and in addition to, any Suspicious Activity Report obligation to the National Crime Agency under the proceeds-of-crime regime.

OFSI expects reports to be made promptly. Although the statutory provisions do not specify a single fixed reporting window expressed in business days, OFSI's enforcement guidance makes clear that delay in reporting, particularly where the firm continues to process transactions in the intervening period, will be treated as an aggravating factor in any subsequent enforcement action. In our experience advising firms on live hits, acting within a matter of days is the working standard that OFSI's enforcement record reflects.

Record-keeping requirements under the relevant thematic regulations require firms to retain documentation relating to a designated person's funds and assets, and to make those records available to OFSI on request. The standard record-keeping period across UK financial sanctions regulations is six years, although firms in regulated sectors will frequently find that their sector supervisor imposes an equivalent or longer retention requirement. Firms should align their sanctions record-keeping to the higher of the two standards.

Quarterly reporting is a separate obligation under certain thematic regulations: regulated firms may be required to report to OFSI on frozen assets they hold. The precise obligation depends on the specific thematic regulation applying to the designated person in question. Compliance counsel should map each listed person held on the books to the applicable regulation and its reporting cycle.

What are the common risk flags in OFSI name and entity screening?

Several patterns recur in OFSI enforcement inquiries and in the compliance reviews we conduct. Recognising them early materially reduces the risk of a breach.

The first is de-risking gaps: a firm exits a relationship with a designated person but does not screen that person's related entities or associates at the same time. A subsidiary of the designated person, or a company under common control, may remain as a counterparty. This is not de-risking; it is a continued prohibited relationship one step removed.

The second is stale screening. A customer passes screening on onboarding. It is not re-screened when a new designation is issued that captures its majority shareholder. The transaction proceeds; the breach follows. Screening must be event-driven as well as periodic. New designations trigger re-screening for the relevant counterparty population, not just for future new intake.

The third is incomplete alias coverage. OFSI's Consolidated List includes aliases and alternative spellings. A screening system configured to match only the "primary name" field will miss a counterparty presenting under an alias. Alias matching must be enabled and regularly audited.

The fourth is currency-route mismatch. A firm screens its customer-facing book against the UK list but fails to apply OFAC screening to dollar-denominated payment instructions routed through a US correspondent. The two screen sets must be applied to the same transaction population, not to different slices of the book.

The fifth is a common misconception we address regularly: that OFSI screening is only relevant to banks. In fact, the legal prohibitions in SAMLA and the thematic regulations apply to all persons in the United Kingdom and to UK persons abroad – not solely to the regulated sector. Commercial businesses, trading companies, and professional services firms are all within scope. What differs is the sector-supervisor layer and the intensity of supervision; the underlying prohibition is universal.

How is name and entity screening enforced under OFSI, and when should a firm involve counsel?

OFSI has both civil and criminal enforcement tools. Civil monetary penalties can be imposed by OFSI directly, without a court process, at the higher of a percentage of the value of the breach or a prescribed maximum – with the current maximum for the most serious cases standing at a significant absolute figure under powers introduced by the Economic Crime (Transparency and Enforcement) Act. Criminal prosecution for deliberate or wilful evasion can be pursued by His Majesty's Revenue and Customs or the Crown Prosecution Service. OFSI can also refer matters to the sector supervisor for parallel disciplinary action.

A voluntary self-disclosure (VSD – a firm's proactive report to OFSI of a potential breach, made before OFSI initiates an inquiry) is a significant mitigation factor. OFSI's published enforcement guidance identifies VSD as one of the primary criteria for a reduced penalty. It does not guarantee a particular outcome, and the decision to disclose requires careful analysis of what has occurred, what the applicable regulation requires, and what evidence is available. Counsel should be involved before a disclosure is made, not after.

Firms should involve sanctions counsel when: a screen produces a hit that cannot be resolved to a clear false positive; a transaction has been processed and a subsequent screen has produced a match against one of its parties; a customer or counterparty has received a designation notice and the firm holds assets for that person; or a regulator or OFSI has made an inquiry. Each of these situations has a defined response sequence; delay in each case narrows the options.

In a recent matter, a payments business identified through a post-transaction review that a payment it had processed three weeks earlier had been received by an entity whose majority shareholder had been designated shortly before the value date. We assessed the applicable thematic regulation, evaluated whether the control test was met, and advised on the VSD process. The matter proceeded to a discounted resolution. No specific outcome is guaranteed; the facts of each case determine the options available.

Related practices

Frequently asked questions

Who administers name and entity screening under OFSI?
OFSI – the Office of Financial Sanctions Implementation, part of His Majesty's Treasury – administers the UK financial-sanctions regime and publishes the Consolidated List of Financial Sanctions Targets. OFSI does not prescribe a single screening standard by statute; instead, the obligation to screen derives from the prohibitions in SAMLA and the relevant thematic regulations. Sector supervisors, including the Financial Conduct Authority, reinforce the obligation through their own supervisory expectations about systems and controls.
What does OFSI prohibit in relation to name and entity screening?
OFSI's financial-sanctions prohibitions cover making funds or economic resources available to, or dealing with assets owned or controlled by, a designated person. These prohibitions extend to entities owned more than 50 percent by a designated person or over which a designated person exercises control – even where the entity itself is not on the Consolidated List. Screening is the primary operational control through which firms identify and avoid such prohibited counterparties before a transaction is executed.
How is name and entity screening enforced under OFSI?
OFSI enforces financial sanctions through civil monetary penalties, which it can impose directly without court proceedings, and through referrals to criminal prosecution authorities for deliberate breaches. A voluntary self-disclosure made promptly before OFSI initiates an inquiry is a recognised mitigating factor under OFSI's published enforcement guidance. Sector supervisors may impose parallel disciplinary action where a screening failure also evidences inadequate systems and controls under the applicable supervisory regime.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.