Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Sanctions risk assessment under OFSI: scope and obligations

A trading company based in London receives a payment instruction from an overseas subsidiary. The counterparty has changed ownership twice in the past year. One of the new shareholders appears on a European list, though not yet on the OFSI Consolidated List (the United Kingdom's list of designated persons and entities subject to financial sanctions). The compliance team is uncertain whether to proceed. Is there a UK financial-sanctions exposure here? What does OFSI actually require the business to do before it acts?

As of August 2026, OFSI (His Majesty's Treasury's Office of Financial Sanctions Implementation) administers the UK's financial-sanctions regime under the Sanctions and Anti-Money Laundering Act 2018 ("SAMLA"). Every person and business operating in the United Kingdom, or carrying on business there, must ensure they do not deal with designated persons or make funds or economic resources available to them. A structured sanctions risk assessment – mapping counterparty ownership, jurisdiction of operation, and transaction type against the OFSI Consolidated List and the relevant thematic regulations – is the practical mechanism through which that obligation is discharged.

This briefing sets out who OFSI regulates, what the core prohibitions require, how the ownership and control test differs from the OFAC standard, what reporting and record-keeping apply, how enforcement is structured, and how the UK regime interacts with the EU and US frameworks that often apply in parallel.

Who does the OFSI sanctions regime cover?

The OFSI sanctions regime covers any person or body that is located in the United Kingdom or carries on business there, as well as UK nationals wherever they are in the world. The geographic and personal scope is therefore broad. A UK-incorporated subsidiary of a non-UK parent, a UK-registered branch of a foreign bank, and a UK national serving as a director of an overseas entity can all fall within the regime.

The relevant thematic regulations – enacted under SAMLA – define the categories of persons subject to designation and the prohibitions that apply to those who deal with them. Separate regulations exist for each sanctions programme. All operate under OFSI's operational oversight. OFSI publishes the Consolidated List, which remains the authoritative reference for UK designation status. A person who appears on that list is a designated person (an individual, entity, or body named in the relevant thematic regulations as subject to asset-freeze and other financial restrictions).

The personal scope catches not only direct counterparties but also those who act on behalf of a designated person, or who hold or control funds for one. This breadth means that a business transacting with an agent or intermediary must look through the immediate relationship to the underlying beneficial owner. In our experience, firms that screen only the named counterparty – and not the instruction chain behind it – carry a materially higher exposure than they appreciate.

What are the core prohibitions the regime imposes?

The core OFSI prohibitions are the asset-freeze obligations: a person subject to the regime must not deal with funds or economic resources owned, held, or controlled by a designated person, and must not make funds or economic resources available – directly or indirectly – to or for the benefit of such a person. Both direct and indirect benefit are prohibited.

The phrase "economic resources" is wider than it first appears. It includes assets of every kind – not only cash, securities, and bank balances, but also property, intellectual-property rights, and any asset that could be used to obtain funds, goods, or services. A supplier extending credit or allowing deferred payment to a designated entity may be making an economic resource available within the meaning of the prohibition, even if no cash changes hands at the outset.

There is a separate prohibition on circumventing the regime. A person who deliberately structures a transaction to defeat the asset-freeze obligations commits an offence. The rules also prohibit enabling or facilitating a breach by another person. These provisions have direct compliance implications: a UK bank processing a payment for a client who is, in turn, channelling funds to a designated entity may be exposed even if the bank's immediate counterparty is not itself listed.

Is the firm's transaction-monitoring logic built to catch indirect benefit as well as direct transfer? That question should be answered before the next payment cycle runs.

How does the OFSI ownership and control test differ from the OFAC standard?

The OFSI ownership and control test applies a dual criterion – ownership and control – whereas the OFAC standard is a mechanical 50 percent or more ownership threshold. This difference is consequential for cross-border businesses that screen counterparties against both regimes simultaneously.

Under OFAC, an entity is treated as blocked if blocked persons own it, in the aggregate, 50 percent or more, directly or indirectly. The ownership figure is the trigger. Control and management are irrelevant to whether the entity is treated as blocked.

Under OFSI and the EU equivalent, a non-listed entity is caught by the relevant prohibitions if a designated person owns or controls it. "Control" can arise through shareholding, voting rights, rights over assets, the power to appoint or remove the majority of directors, or a right to exercise dominant influence. An entity with a designated person holding, say, forty-five percent of the shares may still be caught if that person exercises effective control through other mechanisms – board composition, contractual rights, or shareholder agreements.

In practice, this divergence means that a counterparty may clear the OFAC 50 percent test and still be caught under OFSI's control analysis. We regularly advise clients who discover this precisely when a deal that has passed US screens is then reviewed under the UK or EU regime. The safer approach is to apply the more demanding test as a starting position – and to document the analysis for both regimes separately.

The EU regime under the relevant Council regulations operates on substantially similar logic to OFSI's control test, though the specific definitions and interpretive guidance issued by competent authorities differ in detail. Cross-border businesses must check the position under each applicable regime independently. One test does not substitute for the other.

What must a business do to discharge its obligations – and what does a sanctions risk assessment involve?

Discharging the OFSI obligation requires a systematic, documented process: identifying the counterparty and any persons behind it, checking against the OFSI Consolidated List and any other applicable lists, assessing the nature of the transaction against the prohibitions, and determining whether a licence is required before proceeding.

A sanctions risk assessment (the structured analysis of a firm's exposure to sanctions risk, covering counterparties, geographies, transaction types, and products or services) performs three functions in this process. First, it identifies where the firm's activities could intersect with a designated person or a prohibited transaction. Second, it creates a documented record that demonstrates the firm acted with due care. Third, it establishes a baseline against which the firm can detect whether its risk profile changes as the business or its counterparty relationships evolve.

A structured assessment for an OFSI context typically covers the following sequence:

  1. Identify all counterparties, beneficial owners, and intermediaries involved in the transaction or relationship.
  2. Screen each against the OFSI Consolidated List, using exact and fuzzy matching to manage spelling variants and transliteration differences.
  3. Map the ownership and control chain for any entity counterparty, applying the OFSI test for designated-person control.
  4. Assess the transaction type against the applicable thematic regulations – are the funds, goods, or services within the scope of a prohibition?
  5. Determine whether any general licence or specific licence applies to authorise an otherwise prohibited act.
  6. If a match is found and no licence applies, freeze the relevant funds or economic resources and report to OFSI.
  7. Document every step, the data sources used, and the conclusion reached.

The specific licence route (a case-by-case authorisation that OFSI may grant to permit an otherwise prohibited transaction, subject to conditions) is available where the applicable regulations provide for it. Common licensing grounds include enabling humanitarian activity, preserving access to legal representation, or unwinding a pre-designation contractual obligation. OFSI's guidance sets out the grounds and the application process.

What are the reporting obligations and record-keeping requirements?

A person who knows or suspects that they are holding funds or economic resources belonging to, held by, or controlled by a designated person must report that suspicion to OFSI as soon as practicable. This obligation applies regardless of whether the business intends to proceed with any transaction. It is a positive duty to report, not merely a right to do so.

The reporting obligation extends to information about a designated person that a business comes across in the course of its activities. Regulated-sector firms – banks, payment institutions, credit institutions, and others subject to the Money Laundering Regulations – face an enhanced version of this duty by virtue of their regulatory status. They must also report annually to OFSI on the accounts they hold for designated persons. Failure to report is itself an offence under the relevant thematic regulations.

On record-keeping, OFSI's enforcement guidance emphasises that businesses should maintain clear documentation of their screening decisions, their ownership and control analysis, and the basis on which they concluded that a transaction was or was not prohibited. OFSI has made clear in its guidance that a business that cannot demonstrate it acted with reasonable care – because it has no records – faces a more difficult position in any enforcement review. Good record-keeping is not administrative tidiness; it is a substantive defence.

The bridge from analysis to action matters here. Once a potential match is identified, the business has a narrow practical window in which to freeze funds, conduct further verification, and report. That window does not suspend the prohibition. Acting promptly, and documenting each step as it is taken, is the operative standard OFSI applies.

How does OFSI enforce the regime, and what is the penalty exposure?

OFSI enforces the UK financial-sanctions regime through civil monetary penalties and, in serious cases, referral to law-enforcement authorities for criminal prosecution. The civil-penalty power is exercisable where OFSI determines, on a balance of probabilities, that a person has breached a financial-sanctions prohibition and knew or had reasonable cause to suspect that the prohibition applied.

The civil-penalty cap is set in the relevant thematic regulations by reference to a percentage of the value of the breach or a fixed maximum, whichever is higher. OFSI's published enforcement guidance sets out the factors it weighs: the seriousness of the breach, the degree of knowledge or recklessness, the value of the transaction, whether the breach was self-reported, the quality of the firm's pre-existing compliance programme, and its co-operation with OFSI's investigation. A voluntary self-disclosure ("VSD") – proactively reporting an apparent breach to OFSI before OFSI identifies it independently – can materially reduce the penalty outcome, though it is not a guarantee of any specific reduction. The decision to make a VSD requires careful legal assessment of the facts, the applicable regulations, and the firm's current relationship with the regulator.

Criminal exposure arises where a breach is deliberate or involves knowing circumvention. Prosecutions are rare in practice but the risk is real for cases involving egregious facts. DOJ in the US, the Crown Prosecution Service and the National Crime Agency in the UK, and Europol in an EU context can all become involved where a sanctions breach intersects with financial crime or export-control violations.

OFSI has stated publicly that it will take a stronger enforcement posture for firms that lack documented compliance programmes and for those that fail to report known or suspected breaches. The enforcement trend since SAMLA's entry into force has been toward larger penalties and greater use of naming powers – the power to publicise a breach without imposing a monetary penalty, which carries its own reputational consequences.

If a transaction has already been flagged, or a potential breach has been identified, an early legal review can preserve options that narrow materially as time passes. For a confidential review of a potential breach, contact Calder & Vance at info@caldervance.com.

How does the OFSI regime interact with OFAC and EU sanctions?

For most cross-border businesses, OFSI does not operate in isolation. The same counterparty, the same transaction, and the same goods may simultaneously engage OFAC's US sanctions rules and the EU's relevant Council regulations. Each regime has independent legal force. Compliance with one does not satisfy the other, and a breach of one may occur without a breach of another – the regimes designate different persons, use different tests, and provide different licensing routes.

The extraterritorial reach of OFAC is the single most significant cross-regime risk for UK businesses. OFAC asserts jurisdiction over transactions that clear through the US financial system, over transactions denominated in US dollars that pass through US correspondent banks, and over activities of US-person employees or directors wherever they are located. A UK firm with a US subsidiary, a US-person officer, or a dollar-clearing relationship with a US bank may face OFAC exposure even on a transaction that has no other US connection.

The EU regime, applying to EU-incorporated entities and their activities worldwide, and to transactions conducted within the EU, creates a parallel set of obligations for groups with European operations. Post-Brexit, the UK regime and the EU regime are legally separate instruments. They frequently – though not always – designate the same persons, particularly under UN-derived programme. Where they diverge, the stricter prohibition governs the conduct of a firm that is subject to both.

Switzerland, through SECO, operates an autonomous sanctions regime that shadows the EU in many respects but must be verified independently. Canada, Australia, and Singapore each maintain their own lists and their own prohibition structures. A multinational exporter or financial institution cannot safely assume that clearing one list equates to clearing all. We regularly advise groups that discover, mid-transaction, that their compliance architecture was built around one regime and was never calibrated to the others that apply to their actual business.

The position above covers the general framework. Your specific facts – the counterparties involved, the nature of the transaction, the jurisdictions engaged, and the group's ownership structure – determine which regime analysis takes priority and where the exposure concentrates. For an assessment of your exposure under the OFSI regime and its cross-border interactions, contact Calder & Vance at info@caldervance.com.

Common misconceptions and risk flags in OFSI compliance

A recurring misconception is that only banks and regulated financial institutions face meaningful OFSI risk. In fact, the prohibitions apply to all persons in the UK or carrying on business there. A manufacturer extending trade credit, a law firm holding client funds, a technology business providing access to a platform, and a property company receiving rent can all trigger the prohibition if the counterparty or beneficial owner is a designated person. The sector of the business does not limit the obligation.

A second misconception is that matching against the OFSI Consolidated List is sufficient for compliance. The list is necessary but not sufficient. The control analysis – looking through the ownership chain of an entity counterparty to assess whether a designated person controls it – goes beyond list-matching. So does the assessment of whether a transaction confers indirect benefit on a designated person even when the immediate counterparty is not listed. Both analyses require human judgment and documented reasoning; automated list-screening cannot substitute for them.

The practical risk flags that most frequently present in the matters we handle include:

  • Counterparty ownership structures that are complex, multi-layered, or recently changed – particularly where changes post-date a designation event.
  • Transactions routed through intermediaries or agents in jurisdictions with limited transparency of beneficial ownership.
  • Payment instructions that differ from the original contractual counterparty, or that arrive from a third-party account without clear explanation.
  • Goods, technology, or services that could fall within dual-use or export-control categories, creating an intersection between the financial-sanctions and export-control regimes.
  • Contractual counterparties in jurisdictions that are themselves the subject of thematic sanctions programmes, where the programme may impose prohibitions that extend beyond specifically designated persons.

Each of these flags, individually, is manageable with a documented process and timely advice. In combination, they raise the risk profile significantly. The question is whether the firm's current sanctions risk assessment is calibrated to detect them.

Related practices

Frequently asked questions

Who administers sanctions risk assessment under OFSI?
OFSI – the Office of Financial Sanctions Implementation, a unit of His Majesty's Treasury – administers the UK financial-sanctions regime. OFSI publishes the UK Consolidated List of designated persons, issues licensing decisions under the relevant thematic regulations, and exercises the civil monetary-penalty power for financial-sanctions breaches. The Export Control Joint Unit (ECJU), a separate body within the Department for Business and Trade, handles UK export-licensing. The two regimes interact but are administered independently.
What does OFSI prohibit in relation to sanctions risk assessment?
OFSI's core prohibitions prevent any person subject to UK jurisdiction from dealing with funds or economic resources owned, held, or controlled by a designated person, and from making such assets available – directly or indirectly – to or for the benefit of a designated person. There is also a prohibition on circumvention and on enabling a breach by another person. These prohibitions apply regardless of whether the business was aware of the designation at the point of the transaction, though knowledge affects the degree of penalty exposure.
How is sanctions risk assessment enforced under OFSI?
OFSI enforces the regime through civil monetary penalties where it finds, on a balance of probabilities, that a breach occurred and the person knew or had reasonable cause to suspect that the prohibition applied. OFSI also has a power to publish details of a breach without imposing a monetary penalty – a naming outcome that carries reputational consequences. In cases involving deliberate breach or knowing circumvention, OFSI may refer the matter to law-enforcement authorities for criminal investigation. Voluntary self-disclosure of a breach, where appropriate and properly prepared, is a mitigating factor in OFSI's enforcement guidance.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.