A UK financial institution is processing a payment for a corporate client. The client's ultimate parent is not on any sanctions list. But one of its minority shareholders has just been designated under the UK's financial sanctions regime. Is the payment prohibited? Does the ownership and control test – OFSI's mechanism for catching non-listed entities that a designated person owns or controls – bring the client itself within the scope of the prohibition? The answer determines whether the transaction is lawful or a potential breach.
Under OFSI's rules, a non-listed entity may itself be subject to the same prohibitions as a designated person if that designated person owns or controls it. The test combines an ownership limb and a control limb, and – critically – it diverges from OFAC's purely mechanical 50 percent threshold. As of August 2026, OFSI applies a broader, judgement-based control analysis that can catch entities even where no single designated person holds a majority stake.
This briefing sets out how the ownership and control assessment works under OFSI, where it diverges from the EU and OFAC positions, what the practical risk flags look like, and when a business needs specialist sanctions counsel.
Who administers the ownership and control test and what is its legal basis?
OFSI – the Office of Financial Sanctions Implementation, a unit of His Majesty's Treasury – administers financial sanctions in the United Kingdom, including the ownership and control rules that determine when a non-listed entity is treated as subject to the same prohibitions as a designated person. The legal basis sits in the Sanctions and Anti-Money Laundering Act (commonly called SAMLA), which empowers the Treasury to make thematic sanctions regulations. Each set of thematic regulations then specifies the prohibitions that apply to designated persons and, by extension, to entities those persons own or control.
The ownership and control concept under SAMLA-derived regulations is not a standalone list entry. It is a status that arises automatically when the conditions are met. A compliance team cannot simply screen against the UK Consolidated List and stop: it must also assess whether any counterparty is owned or controlled by a listed person, even if that counterparty's own name does not appear on the list. In our experience, this second step is the one most frequently skipped, and it is precisely where the exposure sits.
The relevant thematic regulations – whether for the Russia, Belarus, Iran, or other country-specific programmes – share a common definitional structure derived from SAMLA. The prohibitions bite on transactions involving designated persons and entities owned or controlled by them. OFSI publishes guidance on how to apply this test, and that guidance has been updated over successive enforcement cycles. Verify the current version of the guidance before relying on it in a live transaction.
What is the ownership limb and how does it differ from OFAC's 50 percent rule?
The ownership limb under OFSI's rules treats an entity as owned by a designated person when that person holds more than 50 percent of the shares or voting rights, directly or indirectly. That threshold looks similar to OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked), but there are two material differences that affect how a compliance team should run the analysis.
First, OFAC's rule is purely mechanical and aggregates the holdings of multiple blocked persons. If two blocked persons each hold 26 percent, the aggregate exceeds 50 percent and the entity is treated as blocked. OFSI's ownership limb applies similarly to aggregated holdings of multiple designated persons, but the guidance framing is slightly different and practitioners should read the current OFSI guidance on aggregation carefully rather than importing OFAC logic wholesale. Second – and this is the more significant divergence – the OFSI test does not stop at ownership. Even where ownership sits below the threshold, the control limb may still capture the entity.
The EU position under the relevant Council regulations mirrors the OFSI structure more closely than OFAC's approach does. Both OFSI and the EU apply a combined ownership-and-control analysis, whereas OFAC historically focused on the ownership threshold. This means a cross-border business that has satisfied itself under OFAC's test may still face exposure under OFSI rules if a designated person exercises meaningful influence without holding a majority stake. The regimes are not interchangeable. Treating one clearance as sufficient for all three is one of the most common and costly errors we see in our cross-border practice.
What does the control limb capture that ownership misses?
The control limb is where OFSI's analysis becomes genuinely complex, and where the risk for a compliance team is greatest. OFSI's guidance describes control as arising in several ways: the right to appoint or remove a majority of the board; the ability to exercise significant influence over management and policy; voting agreements or contractual mechanisms that give a designated person effective direction over the entity's decisions; or any other mechanism that, in substance, gives the designated person the ability to ensure the entity acts in accordance with that person's wishes.
That list is not exhaustive. The analysis is intentionally broad. A minority shareholder who controls the board composition through a shareholders' agreement, or a creditor whose loan terms give it veto rights over major transactions, may well satisfy the control test even if their equity stake is modest. In our experience advising on cross-border transactions with UK counterparties, the control limb regularly produces results that a conventional screening pass – focused on name and ownership percentage – will not surface.
What should a compliance team document when assessing control? At a minimum: the corporate structure chart showing all holding layers; the shareholders' agreement and any voting arrangements; the composition of the board and any rights to appoint or remove directors; loan agreements or credit facilities that carry governance conditions; and any side letters or operational agreements that channel instruction from a designated person to the entity's management. If any of those instruments give a designated person the ability to direct the entity, the control test is engaged.
The EU General Court has addressed analogous control questions in the context of annulment actions against Council designations. Those judgments do not bind OFSI, but they illuminate the structural analysis that courts apply to ownership-and-control questions more broadly. Cross-regime practitioners draw on that body of reasoning when advising on OFSI assessments that involve contested or ambiguous control arrangements.
How does the indirect ownership and layered-structure problem arise in practice?
The ownership and control test applies through layers of corporate structure. A designated person who owns 60 percent of a holding company, which in turn owns 80 percent of an operating subsidiary, triggers the test at both levels: the holding company is owned by the designated person, and the operating subsidiary is owned – indirectly – by the designated person through the holding company. The prohibitions under the relevant thematic regulations apply to both entities.
The layered-structure problem becomes acute in three common scenarios. First, complex group structures where intermediate holding companies are registered in multiple jurisdictions and ownership data is incomplete or out of date. Second, joint ventures where a designated person holds an indirect stake through a nominee or a trust structure. Third, recently acquired stakes – where a person was designated after the corporate structure was put in place and the compliance team has not refreshed the ownership mapping.
Consider this pattern from our practice: a trading company in the manufacturing sector had completed its initial sanctions screening on a distributor and found no direct designations. Eighteen months later, a minority shareholder of the distributor's parent was designated under the applicable thematic programme. The distributor was not re-screened because it was treated as a known, cleared counterparty. Ongoing monitoring for new designations affecting existing relationships is not optional – it is a core element of a functioning sanctions compliance programme.
The indirect chain analysis also interacts with the control limb. A designated person who does not directly own any shares in an entity may still control it through influence over an intermediate vehicle. Mapping the control rights at each layer of the structure – not merely the ownership percentages – is the only way to complete a defensible assessment.
How does OFSI enforce ownership and control breaches, and what are the consequences?
OFSI has civil enforcement powers under SAMLA that allow it to impose monetary penalties on persons who breach UK financial sanctions, including breaches that arise from failures to identify that a counterparty is owned or controlled by a designated person. The penalty standard under SAMLA includes a knowledge-or-reasonable-cause-to-suspect test, but OFSI's civil enforcement powers under SAMLA were extended to include a strict civil liability standard for certain cases, meaning that a breach may be penalised even where the person did not know and could not reasonably have been expected to know of the prohibited act.
OFSI can also refer matters to law enforcement where it identifies evidence of a criminal breach. Criminal sanctions under SAMLA-derived regulations can extend to individuals responsible for the breach within a corporate entity, including officers and directors where the breach occurred with their consent or connivance.
A critical operational consequence is the reporting obligation. Where a person knows or has reasonable cause to suspect that they hold, or have held, funds or economic resources belonging to or owned or controlled by a designated person, they are required to report that to OFSI. This reporting obligation runs independently of whether a transaction has been refused or processed. A firm that screens a counterparty, forms a reasonable suspicion that the control test is met, processes the payment anyway, and then fails to report is exposed on two fronts: the substantive breach and the reporting failure.
In our practice, the pattern of failure most often seen in OFSI investigations is not a wholesale disregard of sanctions rules. It is a screening programme that runs name-match checks against the UK Consolidated List but does not conduct a structured ownership and control analysis at all, or that does so only at onboarding and not on an ongoing basis. OFSI's enforcement guidance makes clear that regulators expect an active, iterative compliance posture, not a one-time gate check.
Where do OFSI, OFAC, and the EU diverge – and why does that matter for cross-border businesses?
For a business operating across the UK, US, and EU, the ownership and control rules under each regime present a distinct compliance obligation that cannot be collapsed into a single test. The divergences are not cosmetic; they can determine whether the same transaction is prohibited in one jurisdiction and permitted in another.
Under OFAC, the focus is primarily on the ownership threshold: 50 percent or more aggregate direct or indirect ownership by blocked persons triggers the rule. OFAC's guidance acknowledges the possibility of control-based analysis in specific contexts, but the dominant operational test is the ownership figure. Under OFSI, both ownership and a broad control test apply, and OFSI's guidance explicitly recognises that control can exist in the absence of majority ownership. The EU position under the relevant Council regulations is structurally close to OFSI: both an ownership limb and a control limb apply, and significant influence is a recognised ground for control.
The practical consequence for a cross-border compliance team is this: a counterparty cleared under OFAC's ownership test may still require a full control analysis under OFSI and EU rules before a UK- or EU-nexus transaction proceeds. The stricter prohibition governs: where the UK rules apply, the UK control test must be satisfied on its own terms. Passing one regime's test does not create a presumption of clearance under the others.
Switzerland (SECO), Canada (GAC), and Australia (DFAT) each maintain their own sanctions regimes with ownership and control provisions that share broad structural similarities with the UK and EU approach but differ in their specific drafting and administrative guidance. A transaction with counterparties across those jurisdictions requires regime-specific analysis, not a one-size-fits-all clearance. If a transaction has UK, US, and one of these secondary-regime nexuses simultaneously, the analysis compounds quickly.
What are the risk flags that should trigger an escalated ownership and control assessment?
Most compliance programmes handle clear cases reasonably well: a counterparty whose name is on the list is declined, and a counterparty with no connection to any designated person is processed. The risk sits in the middle ground, and these are the patterns that should trigger an escalated, documented assessment.
- A counterparty's direct ownership structure is clear, but one intermediate holding company is registered in a jurisdiction with limited public corporate-registry disclosure.
- A new designation is issued affecting a person who appears in the ownership chain of an existing, cleared counterparty.
- A counterparty has recently changed ownership or undergone a restructuring, and the updated structure has not been mapped.
- A shareholders' agreement or voting arrangement gives any party rights over board composition or material decisions, and the identity of all parties to that agreement has not been confirmed.
- A loan or credit facility from an unknown or opaque counterparty is secured against the business, with governance conditions attached.
- A counterparty's beneficial ownership declaration is missing, incomplete, or relies on a legal person rather than an individual.
- A transaction involves a jurisdiction where corporate-registry data is unreliable or unavailable.
The position above covers the standard assessment triggers. Your facts – the structure of the counterparty, the regime in play, the jurisdiction, the nature of the transaction – will change the analysis and the depth of work required. Where any of the above flags is present, an escalated and documented ownership and control assessment is not optional.
For a confidential review of a specific counterparty or transaction, contact Calder & Vance at info@caldervance.com.
A common misconception: passing the ownership threshold means the entity is clear
One of the most persistent myths in cross-border compliance is that the ownership and control analysis ends once you have confirmed that no designated person holds more than 50 percent of the counterparty. This misreads the UK rules. OFSI's test does not require majority ownership. It requires either ownership above the threshold or control, and control can arise from governance rights that carry no ownership stake at all.
A counterparty in which a designated person holds 30 percent – a significant minority – may be fully controlled by that person through a combination of board appointment rights, weighted voting, and operational contractual terms. Under OFSI's rules, that entity is subject to the same prohibitions as the designated person. The 50 percent threshold is a sufficient condition for ownership, not a necessary condition for the overall test. Treating it as a safe harbour when the control question has not been examined is a compliance failure, not a compliance defence.
If a transaction has already been flagged, or a filing has been refused on ownership and control grounds, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com.