A payments firm processing sterling transfers on behalf of a European correspondent bank discovers – mid-batch – that one beneficiary matches a name on the OFSI Consolidated List. The batch is queued. The compliance team has minutes to decide: freeze, reject, or continue? Getting that call wrong in either direction carries real legal cost. That is the daily reality of payment-processing controls under OFSI rules.
OFSI – the Office of Financial Sanctions Implementation, part of His Majesty's Treasury – administers the United Kingdom's financial sanctions regime under the Sanctions and Anti-Money Laundering Act 2018 ("SAMLA"). Payment-processing controls sit at the centre of that regime: they require firms to screen transactions, freeze funds belonging to designated persons, and report relevant matches to OFSI, often within a tight statutory window. As of August 2026, the regime applies to all persons operating in the UK and to UK-established firms acting abroad, making it one of the broadest jurisdictional catches in the major Western sanctions regimes.
This briefing covers who administers the regime, what the prohibitions require of payment firms, how the ownership-and-control test applies to counterparty screening, where the UK position diverges from OFSI's closest comparators – OFAC and the EU – and what enforcement looks like in practice. A brief section addresses the practical risk flags that, in our experience, most commonly generate OFSI compliance failures.
Who administers OFSI and what is the legal basis for payment-processing controls?
OFSI administers UK financial sanctions on behalf of His Majesty's Treasury. The primary legal authority is SAMLA, which provides the enabling power for all UK autonomous sanctions regulations made since the United Kingdom's departure from the EU. Country-specific and thematic prohibitions are set out in statutory instruments – each covering a distinct sanctions programme – that designate individuals and entities and specify the financial prohibitions that apply.
For payment-processing controls, the operative prohibitions typically come in two forms. First, a prohibition on making funds or economic resources available to, or for the benefit of, a designated person. Second, a prohibition on dealing with the funds or economic resources of a designated person. Both capture payment-processing activity. A firm that routes a payment to a beneficiary who is a designated person, or that processes a transfer on behalf of a designated sender, will prima facie breach the prohibition, whether or not it intended to do so.
Strict liability is the working standard. OFSI does not need to show that a firm knew the counterparty was designated. Knowledge is relevant to penalty level, not to whether a breach occurred. That is a significant difference from some other legal systems and one that surprises firms entering the UK market for the first time.
The position above describes the statutory baseline. Your facts – the specific programme, the nature of the funds, and the relationship between your firm and the payment chain – will affect the analysis considerably.
For an initial assessment of your exposure under OFSI, contact Calder & Vance at info@caldervance.com.
What are the core prohibitions bearing on payment firms?
The central prohibition for a payment-processing business is the making-available prohibition: no firm may make funds, or economic resources that can be converted into funds, available to a designated person or for that person's benefit. In a payment context, this means that processing a credit transfer whose ultimate beneficiary is a designated person triggers the prohibition – even if the firm's immediate counterparty is a non-designated correspondent bank.
The "for the benefit of" limb is broader than it looks. A payment to a non-designated company that is majority-owned by a designated person, or whose proceeds will be passed to a designated person, can fall within the prohibition. OFSI's published guidance makes clear that firms should look through the immediate counterparty where they have reason to believe that a designated person will benefit. That "reason to believe" standard creates a due-diligence obligation that is fact-specific and requires human judgment, not just automated screening.
A second prohibition bars dealing with the funds of a designated person. This captures a payment firm that holds, manages, or transfers funds that are already the property of a designated person – for example, processing a withdrawal request from an account that belongs to a sanctioned individual. Where dealing and making-available overlap, the stricter prohibition governs.
The freeze obligation attaches immediately on designation. A firm that becomes aware that it holds funds belonging to a designated person must freeze those funds and must not release them without an OFSI licence. There is no grace period. In our experience, the gap between the moment of designation and the moment a firm's screening system generates an alert is the single highest-risk interval in payment-processing compliance.
How does the ownership-and-control test apply in practice?
UK financial sanctions extend beyond directly designated persons to entities that a designated person owns or controls. This is the ownership-and-control test (the UK and EU standard for determining whether a non-listed entity is caught through a listed person's interest). It differs materially from OFAC's approach, and that difference matters for any firm operating across both regimes.
Under OFAC, the test is largely mechanical: an entity is treated as blocked if one or more blocked persons own it 50 percent or more in the aggregate, directly or indirectly. Intent and day-to-day management are irrelevant to the trigger.
OFSI's test goes further. UK regulations can catch entities that a designated person controls, even where the ownership stake falls below any specific threshold. Control includes the ability to direct or influence the decisions of an entity – for example, through board appointment rights, veto powers, or contractual arrangements that give the designated person effective authority. A firm that holds a 30 percent stake but can block any board resolution may still be caught.
The EU position is substantively aligned with the UK on the control limb, though the two regimes diverge in procedural implementation. Where an EU-regulated firm and a UK-regulated firm are both in the payment chain for a single transaction, each must apply its own regime's test independently. If the EU test produces a different answer from the UK test – which can happen at the margins – the stricter prohibition governs for the entity subject to that stricter regime.
What does this mean for payment-processing controls? It means that a screening result that returns no match against OFAC's SDN List is not conclusive for UK purposes. Firms operating under OFSI must run a separate control analysis that addresses control as well as ownership, and that review cannot be outsourced to an automated name-screening tool alone. In our practice, we regularly advise clients who have discovered this gap only after a OFSI inquiry has started.
What are the reporting obligations and timelines?
OFSI imposes two distinct reporting obligations on firms that handle financial sanctions matters, and both are time-bound. Missing either creates a secondary compliance failure that sits alongside any underlying breach.
The first is the obligation to report to OFSI as soon as practicable when a firm knows or has reasonable cause to suspect that it is holding funds or economic resources belonging to a designated person, or that a designated person has tried to obtain funds from it. The report must be made to OFSI directly. Financial institutions regulated by the Financial Conduct Authority and the Prudential Regulation Authority are also required to report simultaneously to their sectoral regulator. A firm that reports to its regulator but not to OFSI has still failed the OFSI reporting obligation.
The second is the annual frozen-assets reporting requirement, under which firms that hold frozen funds must notify OFSI of the frozen balance as at a specified date each year. This is an ongoing obligation that persists for as long as funds remain frozen.
Cross-border dimension: OFAC imposes its own blocking and reporting requirements, with a 10 business day reporting deadline once a US-nexus firm identifies blocked property. Where a transaction has both a US nexus and a UK nexus – common in dollar-denominated correspondent banking – both OFAC's 10-business-day window and OFSI's "as soon as practicable" standard apply concurrently. The timelines are not harmonised, and a firm that prioritises one may inadvertently miss the other.
If a transaction has already been flagged, or a filing has been missed, an early review preserves options that narrow with every day of delay. For a confidential review of a potential breach, contact us at info@caldervance.com.
How does OFSI enforce payment-processing controls?
OFSI can impose civil monetary penalties without a criminal conviction. That enforcement power – added by the Economic Crime (Transparency and Enforcement) Act 2022 and the Policing, Crime, Sentencing and Courts Act 2022 – significantly expanded OFSI's reach. Before the 2022 amendments, OFSI had to refer serious cases to law enforcement. Now it can act directly, on a civil standard, with penalties that can reach a significant multiple of the transaction value or a fixed cap, whichever is higher. The precise current caps are set by the relevant thematic regulations and should be verified before reliance.
OFSI applies a monetary penalty range based on culpability factors. The highest penalties attach where a firm knew or deliberately disregarded the sanctions position. Reduced penalties – or a finding with no financial sanction – may follow where the firm had reasonable grounds for its actions and disclosed promptly. A VSD (voluntary self-disclosure to OFSI) before enforcement action begins is a recognised mitigation factor under OFSI's published enforcement guidance, and it is one of the most consequential decisions a firm makes in the early stages of a breach.
OFSI publishes enforcement decisions. Named decisions carry reputational as well as financial cost, and correspondent banks and payment-scheme operators routinely review published enforcement records when assessing counterparty risk. In our practice, we have seen firms lose correspondent relationships as a direct consequence of a published OFSI finding, independent of any penalty.
Record-keeping requirements support enforcement: firms subject to OFSI obligations are required to retain records relating to sanctions screening, compliance decisions, and frozen-asset holdings for a period specified in the applicable regulations. Verify the current retention period before reliance, as it varies by instrument and has been subject to amendment.
Where does the UK regime diverge from OFAC and the EU – and why does it matter for payment firms?
For a payment firm processing cross-currency flows, three divergence points create practical compliance complexity. Understanding them is not an academic exercise. Each divergence can produce a different answer to the question: "Is this payment prohibited?"
First: the ownership-and-control test. As noted above, OFAC applies a bright-line 50 percent aggregate ownership threshold. OFSI and the EU apply an ownership-or-control test that can catch entities below 50 percent where a designated person exercises effective control. A EUR/GBP payment where the beneficiary is 40 percent owned by a designated person and subject to that person's board-veto may be prohibited under OFSI and the EU but not under OFAC. The reverse situation – majority ownership with no control – produces the opposite divergence.
Second: the benefit test. OFSI's "for the benefit of" prohibition has been applied by OFSI broadly. The EU equivalent – making funds available directly or indirectly to a listed person – is similarly wide, but the analytical approach differs between EU member states. OFAC's standard for indirect benefit is more heavily fact-specific and, in practice, more narrowly applied. A chain of payments that passes through multiple correspondent accounts may trigger the UK prohibition at an earlier link than the US one.
Third: disclosure and reporting. OFAC requires initial blocking reports within 10 business days of a US-nexus firm becoming aware of blocked property, with annual reporting thereafter. OFSI requires reporting "as soon as practicable," which, while undefined numerically, is interpreted strictly in practice. The EU has no single harmonised blocking-report deadline; member states implement the reporting obligation differently. A payment firm in a multi-currency, multi-correspondent chain must track all three timelines simultaneously.
Does your screening architecture account for these three divergence points across every corridor you operate in? If not, the gap is a live compliance risk, not a theoretical one. We regularly advise payment firms on exactly this question – mapping the divergent obligations regime by regime and testing whether existing controls detect the edge cases each regime is most likely to pursue.
Common risk flags and when to involve counsel
Payment-processing controls under OFSI generate a distinct pattern of failure modes. The following are the risk flags we see most frequently in our cross-border compliance practice.
De-risking (a financial institution exiting a client relationship to avoid sanctions exposure) is sometimes applied too broadly, and sometimes not broadly enough. A firm that exits a client relationship because of a false positive – without conducting the ownership-and-control analysis properly – may lose a compliant customer and create a discrimination-law exposure. A firm that retains a client despite a genuine control link to a designated person has the opposite problem. The analysis matters in both directions.
Batch-processing architecture creates timing vulnerabilities. Firms that screen payments at the point of instruction but not at the point of settlement may miss a designation that occurs in the interval. OFAC designations and OFSI designations do not always occur simultaneously or in the same direction. A payment screened as clean at 09:00 may be prohibited by 14:00 on the same day if a new designation is published.
Nested correspondent structures compress the information available to the processing bank. A payment firm that sees only its immediate counterparty – without visibility into the originator or the ultimate beneficiary – is relying on its counterpart to have screened correctly. Under OFSI, reliance on a third party's screening does not eliminate the processing firm's own strict-liability exposure. Contractual warranties from correspondents are a mitigation, not a complete defence.
Currency of screening data is a recurring failure mode. Firms that update their sanctions lists weekly – rather than at least daily – in a regime environment where designations occur without advance notice are operating with a known gap. OFSI can designate at any time. The obligation attaches from the moment of designation, not from the moment the firm's system updates.
Involve counsel early when: (a) a screening alert has generated a freeze and there is uncertainty about whether the ownership-and-control test is met; (b) a payment has been processed and a subsequent check suggests the beneficiary may have been designated at the time; (c) a correspondent bank has raised a query about a transaction; or (d) OFSI has written to the firm, even if the letter is described as a "request for information" rather than a formal notice of investigation. The distinction between a request for information and the opening of an investigation can be legally significant, and the response to the first letter often shapes the trajectory of everything that follows.
Related practices
- Sanctions compliance audit and testing – stress-test your screening logic and controls against live regime requirements
- Payment-processing controls under the UN regime – how Security Council obligations interact with national implementing measures
- Sanctions contract clauses under EU regulations – structuring representations, warranties, and termination rights for cross-border transactions