Calder & Vance International Sanctions & Compliance Counsel

Cross-Border Transactions & Diligence · OFSI

Supply-chain sanctions mapping under OFSI: the essentials

A UK-headquartered trading company is mid-negotiation on a multi-tier supply agreement. Its lawyers run the primary supplier through OFSI's Consolidated List. Clean. The deal proceeds. Six months later, a sub-contractor two tiers down is added to the UK sanctions list – and the trading company has already paid several invoices that passed through that entity's account. Was there a prohibited transaction? Could the business have found this exposure earlier? These are not rhetorical questions for a compliance officer facing an OFSI enforcement review.

Supply-chain sanctions mapping under OFSI – the UK's Office of Financial Sanctions Implementation – requires businesses to identify, at each tier of a supply chain, whether a counterparty is designated under the relevant UK thematic sanctions regulations, owned or controlled by a designated person, or otherwise caught by OFSI's financial-sanctions prohibitions. As of January 2026, OFSI operates under the Sanctions and Anti-Money Laundering Act 2018 ("SAMLA") and enforces a strict-liability civil-penalty regime, meaning that a business need not have known of the prohibited link to face a penalty.

This briefing sets out who administers the regime, what the ownership-and-control test demands, how supply-chain mapping works in practice, where it diverges from OFAC and EU rules, and when to bring in specialist sanctions counsel.

Who administers supply-chain sanctions mapping under OFSI?

OFSI administers UK financial sanctions under the authority of HM Treasury, acting on powers conferred by SAMLA and the relevant thematic sanctions regulations that implement designations. It maintains the UK Consolidated List of asset-freeze and other financial-sanctions targets, publishes enforcement guidance, and issues specific licences authorising otherwise prohibited transactions.

OFSI is distinct from the Export Control Joint Unit (ECJU), which governs trade and export licensing. For supply-chain work the relevant authority is OFSI, though a supply chain involving dual-use goods will also attract ECJU oversight. In our practice, multi-regime exposures – a UK-based logistics business moving controlled goods through a third market – are the norm rather than the exception. Treating OFSI and ECJU as silos is one of the most common structural errors we see in cross-border diligence programmes.

OFSI publishes a revised version of its monetary-penalty and enforcement guidance periodically. Compliance teams should treat that guidance as a live document, not a settled text. The key point for supply-chain mapping is that OFSI's enforcement posture has hardened: the strict-liability standard means intent is irrelevant to the civil question of whether a breach occurred; it is relevant only to the quantum of a penalty.

What prohibitions drive the supply-chain mapping obligation?

The core OFSI prohibition is on making funds or economic resources available, directly or indirectly, to or for the benefit of a designated person. The phrase "directly or indirectly" is the engine of supply-chain exposure. A payment to a clean, non-designated supplier is still caught if part of that payment flows onward to, or provides a material benefit for, a designated entity further up or down the chain.

Two specific concepts anchor the analysis. First, "economic resources" is defined broadly – it extends beyond cash to goods, services, property, and anything that can be converted into funds or used to obtain value. Second, there is no de minimis threshold in the OFSI regime. A marginal benefit delivered to a designated person can constitute a breach.

This breadth has a practical consequence for supply-chain mapping: the mapping obligation does not end at the primary counterparty. It extends, in principle, to every tier from which a designated person could derive a benefit. What does "every tier" mean for a business with a hundred-supplier network? In practice, OFSI's guidance supports a risk-based approach. Businesses are expected to map with intensity proportionate to the risk profile of the goods, the geography, and the counterparties involved. The mapping obligation is not boundless; it is proportionate and documented.

The position above covers the standard case. Your specific facts – the structure of the supply arrangement, the nationalities of the entities, the nature of the goods, and the jurisdiction of each payment leg – will change the analysis materially.

For a preliminary review of your supply-chain exposure under OFSI, contact Calder & Vance at info@caldervance.com.

How does OFSI's ownership-and-control test work across a supply chain?

Under OFSI and the underlying UK regulations, a non-designated entity is treated as caught by the prohibitions where a designated person owns or controls it. Ownership means a holding of more than 50 percent of the shares or voting rights; control is a broader concept that encompasses the right to appoint or remove directors, the ability to direct the affairs of the entity, or any other means by which a designated person can secure that the entity acts in accordance with their wishes.

The control limb is the more operationally demanding. An entity may be wholly free of designated ownership but nonetheless controlled through board composition, contractual consent rights, or commercial dependence. In cross-border supply chains involving corporate structures in multiple jurisdictions, control can be obscured by nominee arrangements and holding-company layers.

How does this compare with OFAC? Under OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked), the test is purely mechanical and ownership-based – 50 percent or more aggregate ownership triggers the same restrictions as a direct designation. OFAC does not apply a control test in the same statutory sense, although OFAC retains the discretion to designate an entity on control grounds separately. The EU regime mirrors the UK position: both ownership and control can bring an entity within scope, and the thresholds and analytical framework track the respective Council regulations closely.

For a cross-border supply chain touching US, UK, and EU counterparties – which describes a substantial share of the transactions we advise on – a business must satisfy all three tests simultaneously. A structure that clears OFAC's ownership test may still be caught under OFSI's control limb. The stricter prohibition governs the permissibility of the transaction.

How does supply-chain mapping work in practice under OFSI?

Supply-chain mapping under OFSI is a structured diligence process, not a single-point screening event. It has four distinct phases: tier identification, ownership-and-control tracing, sanctions-list screening, and risk-proportionate documentation.

Tier identification means establishing who the parties are at each level of the supply chain, including sub-contractors, agents, freight forwarders, and financial intermediaries handling payment flows. In complex supply arrangements, the party receiving the purchase order is rarely the only entity that touches the transaction.

Ownership-and-control tracing applies OFSI's test to each identified entity. For privately held companies in opaque jurisdictions, this may require obtaining beneficial-ownership documentation, reviewing corporate registries, and – where public records are insufficient – commissioning third-party due-diligence reports.

Sanctions-list screening then cross-checks every identified entity and individual against the UK Consolidated List, the OFAC SDN List (OFAC's list of Specially Designated Nationals and blocked persons) where US-nexus exists, the EU Consolidated List, and any other regime-specific list relevant to the transaction's geography.

Risk-proportionate documentation records the steps taken, the sources consulted, and the conclusions reached. This documentation serves two functions: it supports a potential due-diligence defence in any OFSI enforcement review, and it creates the audit trail that senior management and boards increasingly require. OFSI's published guidance places significant weight on whether a business had reasonable procedures in place at the time of the alleged breach. Contemporaneous records are not optional; they are the evidence of compliance.

A question we are often asked: how frequently does the mapping need to be refreshed? The UK Consolidated List changes when the government makes, amends, or revokes designations. There is no fixed interval; additions can occur at any time. A mapping exercise completed at contract signature but not updated throughout performance provides only partial protection. Ongoing transaction monitoring and periodic refresh cycles – calibrated to the risk level of the supply relationship – are the standard we apply with our clients.

Where does OFSI supply-chain mapping diverge from OFAC and EU requirements?

The three major regimes share a common purpose but differ in ways that matter for cross-border supply-chain management.

OFAC operates an extraterritorial reach that extends to non-US persons transacting in US dollars or through US financial infrastructure. A supply chain that has no US-incorporated party may nonetheless have OFAC exposure if any payment leg routes through a US correspondent bank. For businesses operating between the UK and third markets, this creates a layered obligation: OFSI governs the UK nexus; OFAC may govern the dollar payment. We regularly advise clients on managing both simultaneously – and on the specific risk that arises when the two regimes designate different persons on different timetables. A counterparty that OFSI has not yet designated may be on the SDN List, and vice versa.

The EU regime, administered through Council regulations and enforced by member-state competent authorities, applies to EU-incorporated entities and to transactions with an EU nexus. Post-Brexit, UK and EU designation lists are maintained separately. They overlap substantially but are not identical. A business trading between the UK and EU markets must maintain parallel screening processes and cannot assume that a clean OFSI result clears EU exposure. Our briefing on trade transaction screening under the EU regime covers the EU mechanics in detail.

Switzerland, through SECO, operates its own autonomous sanctions ordinances, which again may diverge from UK and EU lists. For supply chains running through Swiss intermediaries or Swiss financial channels, SECO screening is a distinct and separate obligation. Our analysis of supply-chain mapping under SECO sets out the Swiss-specific requirements.

One structural divergence that carries practical weight: the UK strict-liability civil standard under OFSI means that a business can incur a penalty even without knowledge of the designated link. OFAC similarly can impose a civil penalty on a strict-liability basis for apparent violations. The EU member-state enforcement regimes vary in their knowledge requirements. This means that for the UK and US legs of a cross-border supply chain, a business cannot rely on good faith as a complete defence to civil liability – it must demonstrate reasonable procedures and documented diligence.

If a transaction has already been flagged, or a payment has passed through a counterparty that may be caught, an early review can preserve options that narrow quickly with time.

For a confidential review of a potential breach or a supply-chain mapping gap, contact Calder & Vance at info@caldervance.com.

What are the principal risk flags in supply-chain sanctions mapping?

Certain fact patterns generate disproportionate sanctions exposure in supply chains, and recognising them early determines whether a business manages the risk or inherits it.

Complex or opaque ownership structures are the single most common source of missed exposure. Where a supplier is owned through a chain of holding companies registered in jurisdictions with limited public beneficial-ownership records, the surface-level screening result can be clean while the actual beneficial owner is designated. The mapping obligation requires going behind the registered ownership, not simply checking the first corporate layer.

Geography is a material risk indicator. Supply chains running through or near high-risk jurisdictions – whether defined by the applicable country regime's sanctions list, OFAC programme scope, or EU Council designations – warrant heightened mapping intensity at every tier touching that geography. This is not a judgment on the jurisdiction; it is a factual observation about where sanctions exposure concentrates.

Payment routing is frequently underweighted. A supply chain with clean counterparties can still generate OFSI and OFAC exposure if the payment flows through a financial intermediary that is designated, or through a correspondent relationship that triggers US-dollar jurisdiction. Transaction mapping must include the payment architecture, not only the commercial parties.

Sector-specific risk deserves attention. Supply chains in energy, defence-adjacent manufacturing, advanced technology, and financial services carry elevated exposure because sanctions programmes are heavily concentrated in those sectors. A business in one of these sectors that applies generic, non-sector-calibrated screening is likely to under-detect. In our experience, sector-calibrated screening parameters identify materially more relevant hits than generic list-screening alone.

Finally, change events – mergers, acquisitions, restructurings, and new beneficial owners at a supplier – reset the mapping obligation. A supplier that was clean at onboarding can become caught following a corporate transaction in which a designated person acquires a stake. Periodic re-screening and change-event triggers in supplier-management processes are not optional features of a well-designed programme.

When should a business involve sanctions counsel?

The myth is that external sanctions counsel is needed only when an enforcement notice lands. In our experience, the businesses that manage OFSI supply-chain risk most effectively involve specialist counsel much earlier – at the programme-design stage, before new supply relationships are entered, and when a potential hit is first identified rather than after it has been escalated internally several times.

There are four specific trigger points at which counsel adds the most value. First, when the supply chain enters a new geography or sector where sanctions programmes are active. Second, when a screening tool returns a potential match that the internal team cannot resolve with confidence. Third, when a transaction involves multi-tier or complex ownership structures that require bespoke beneficial-ownership tracing. Fourth – and critically – when a business suspects or discovers that a payment has already been made to, or for the benefit of, a designated person. At that point the questions of voluntary self-disclosure (a VSD – a proactive report to OFSI of a suspected breach) and penalty mitigation are live, and the window for action is short.

Counsel's role in those situations is to assess eligibility, scope the apparent violation, advise on voluntary self-disclosure, and prepare any penalty defence. Early involvement also preserves the documentary record that supports a due-diligence argument. For businesses with US-dollar payment flows, coordinating OFSI and OFAC analysis simultaneously – rather than sequentially – avoids the gap between the two regimes' timelines that can compound the exposure. Our service page on correspondent banking and de-risking under OFAC explains how the US-nexus dimension of cross-border transactions is managed.

A practical scenario: in a recent matter, a manufacturing group with operations across multiple jurisdictions was mid-way through a supply-chain due-diligence review when its screening tool returned a potential match against a component supplier in a third market. The internal team had cleared the top-tier entity but had not mapped through to the supplier's parent. We conducted the ownership-and-control trace, identified that the parent held a relevant stake, advised on the steps available to the business, and documented the outcome. The matter was managed before any prohibited payment was made. The difference between that outcome and an OFSI enforcement review was a structured mapping process applied at the right point in the transaction lifecycle.

Related practices

Frequently asked questions

Who administers supply-chain sanctions mapping under OFSI?
OFSI – the Office of Financial Sanctions Implementation, part of HM Treasury – administers UK financial sanctions under SAMLA and the relevant thematic sanctions regulations. It maintains the UK Consolidated List, issues licences for otherwise prohibited transactions, and enforces the prohibitions through a civil-penalty regime. ECJU governs export licensing separately; supply chains involving dual-use goods engage both authorities.
What does OFSI prohibit in relation to supply-chain sanctions mapping?
OFSI prohibits making funds or economic resources available, directly or indirectly, to or for the benefit of a designated person. In a supply chain, this prohibition extends beyond the primary counterparty to any tier through which a designated person could derive a material benefit. The prohibition is wide: "economic resources" includes goods and services, not only cash payments. There is no statutory de minimis threshold.
How is supply-chain sanctions mapping enforced under OFSI?
OFSI enforces through a strict-liability civil-penalty regime: a business need not have known of the designated link to face a penalty for an apparent violation. Penalties are proportionate to the seriousness of the breach and whether the business had reasonable compliance procedures. A voluntary self-disclosure of a suspected breach can be a significant mitigating factor in penalty assessment. Criminal enforcement requires knowledge or reasonable cause to suspect.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.