A multinational with supply chains touching South-East Asia, the Pacific, and the Middle East discovers that a counterparty appears on Australia's autonomous sanctions list. The compliance team is unsure whether the company's current screening programme covers DFAT-administered controls, whether its ownership analysis meets Australian standards, and whether a recent payment may constitute a reportable dealing. That uncertainty – and the cost of getting it wrong – is precisely why a structured compliance audit and testing programme under the Australian regime matters.
Compliance audit and testing under the Australian autonomous sanctions regime, administered by the Department of Foreign Affairs and Trade (DFAT), is the process of independently verifying that a business's policies, screening tools, ownership-and-control analysis, and reporting procedures satisfy the obligations imposed by the Autonomous Sanctions Act and the relevant thematic regulations. As of mid-2026, DFAT's enforcement posture has hardened, and the consequences of an undetected gap range from civil penalties to criminal liability for responsible officers. Businesses seeking compliance audit and testing Australia legal support should treat the process as a standing programme, not a one-time exercise.
This page explains what an Australian-regime audit covers, how the procedure runs, where it diverges from the OFAC, OFSI, and EU equivalents, and when specialist counsel is essential. It also addresses the risk flags that recur most often in our cross-border practice.
What does the Australian autonomous sanctions regime require, and who administers it?
The Australian autonomous sanctions regime is established under the Autonomous Sanctions Act and gives effect to the thematic and country-specific measures adopted by the Australian Government independent of UN Security Council resolutions. DFAT is the administering authority: it maintains the Consolidated List, issues permits, and refers suspected violations for investigation. The regime sits alongside Australia's UN Charter Act obligations, which implement Security Council sanctions directly.
The prohibitions are broadly drawn. They cover making an asset available to, or dealing with an asset held by or on behalf of, a designated person or entity. They extend to supply and procurement controls on sanctioned goods and services. Ownership-and-control questions arise when a designated person holds an interest in a non-listed entity – the regime does not use the same mechanical fifty-percent rule as OFAC, but the analysis of effective control can reach deeper into corporate structures.
For a business with operations in Australia or transacting with Australian entities, compliance obligations attach to the entire group where the Australian nexus is sufficient. That nexus question – how far the regime reaches into a non-Australian parent or subsidiary – is one of the most frequent issues in our practice, and it cannot be answered without mapping both the corporate structure and the transaction flow against the regime's jurisdictional triggers.
What should a compliance audit under the Australian regime examine?
A well-constructed Australian-regime compliance audit examines six discrete areas, each of which can harbour gaps invisible to a compliance team that has relied on tools calibrated for OFAC or EU screening alone.
First, the legal basis and coverage: does the programme identify the correct instruments – the Autonomous Sanctions Act, the relevant thematic regulations, the UN Charter Act – and does it monitor DFAT's Consolidated List updates in near-real time? The Australian list is updated without a fixed publication schedule, and delayed uptake creates exposure windows.
Second, the ownership and control analysis: the Australian regime requires assessment of whether a non-listed entity is effectively controlled by a designated person, even where the designated person's ownership stake falls below any bright-line figure. This is a more judgement-intensive test than the OFAC fifty-percent rule, and it demands documented analysis, not just a list match.
Third, screening tool calibration: does the tool cover the Australian Consolidated List, not merely the UN list or the OFAC SDN? Do transliteration and alias-matching settings catch the variant spellings used in Australian designations? In our experience, off-the-shelf tools frequently under-index on DFAT data.
Fourth, goods and services controls: Australia's sanctions extend to prohibited goods and services tied to specific programmes. An audit must confirm that procurement and export teams are applying the correct controls, that classification decisions are documented, and that permit requirements are identified before a transaction closes rather than after.
Fifth, reporting and escalation procedures: when a business identifies a dealing with a designated person, it must stop the dealing and take steps consistent with the regime's requirements. The audit examines whether the escalation path is clear, whether legal privilege is preserved in the investigation process, and whether the notification obligations to DFAT are understood and timed correctly.
Sixth, record-keeping: the regime's enforcement framework relies on contemporaneous records. The audit confirms that transaction records, screening outputs, ownership-analysis memoranda, and correspondence with DFAT are retained in the manner and for the period the law requires – verify the current retention period before relying on any internal policy that was drafted to a different standard.
How does Australian compliance audit procedure compare with OFAC, OFSI, and EU equivalents?
The cross-regime comparison is not academic. Most businesses that need Australian-regime compliance counsel also have OFAC, OFSI, or EU exposure. Understanding where the regimes converge and diverge allows a single audit programme to be designed that satisfies all of them – or, equally important, to identify where an approach sufficient under one regime is insufficient under another.
Under OFAC, the ownership test is mechanical: 50 percent or more aggregate ownership by blocked persons triggers blocked-property treatment, regardless of control. The Australian regime does not replicate this bright line. It asks instead whether a person is effectively controlled by a designated person – a standard that requires documented reasoning and, in borderline cases, external legal review. A business that has passed OFAC screening for a counterparty has not automatically passed the Australian analysis.
Under OFSI (the UK regime) and the EU Council regulations, an ownership-and-control test applies that is conceptually closer to the Australian approach than to OFAC's mechanical rule. However, the specific designated-person lists differ, the licensing routes differ, and the reporting timelines differ. OFSI's voluntary self-disclosure (VSD) mechanism and its civil monetary penalty powers operate under SAMLA; the Australian enforcement route runs through the Commonwealth criminal law, with criminal penalties for individuals a live risk in serious cases.
The EU regime adds a layer of complexity for businesses with European operations: EU operators are prohibited from participating in circumventing the EU measures, and the EU Blocking Regulation may apply where a business is subject to conflicting demands from third-country sanctions. An audit designed for an Australian-only lens will not surface these intersections. Our practice is structured to address all of them concurrently – in our cross-border work, we regularly find that a single transaction touches three or four regimes simultaneously.
For businesses with US operations or US-origin goods and technology in their supply chain, the BIS export control rules under the EAR add a further dimension. Classification of dual-use goods, end-user screening against the Entity List, and licence exception eligibility all require separate analysis that runs alongside, not instead of, Australian-regime screening.
The position above covers the standard case. Your facts – the counterparty's jurisdiction, the goods or services involved, the corporate structure, and the regimes in play – change the analysis materially. For a cross-regime assessment tailored to your situation, contact Calder & Vance at info@caldervance.com.
What does a structured testing programme look like in practice?
Audit without testing is incomplete. A compliance programme that has never been stress-tested against realistic transaction scenarios gives a false sense of assurance. The testing phase of an Australian-regime engagement typically runs in three stages.
The first stage is desk-based testing: reviewing the legal coverage of the programme documentation, the screening-tool configuration, and the escalation procedures against the current DFAT Consolidated List and the applicable thematic regulations. This stage surfaces policy gaps and outdated provisions without touching live transaction data.
The second stage is transactional sampling: selecting a representative set of completed transactions – across geography, counterparty type, and goods or service category – and tracing each through the programme's controls as if it were being processed today. Sampling should be stratified, not random, to ensure that higher-risk transaction types (payments to complex corporate structures, shipments to sensitive destinations, dealings with financial intermediaries in multiple jurisdictions) are adequately represented.
The third stage is scenario testing: presenting the compliance team with a set of novel fact patterns designed to probe the programme's edges. Does the escalation procedure work when the designated person is a minority shareholder rather than a majority owner? What happens when a counterparty appears on the Australian list but not on OFAC or EU lists? How does the programme handle a retrospective designation – where a counterparty is listed after a transaction has been partially completed?
In a recent matter, a logistics business operating across the Asia-Pacific region had invested substantially in OFAC-compliant screening. When we conducted an Australian-regime testing exercise, we identified that the company's screening tool was not configured to pull DFAT Consolidated List updates on the same cycle as the SDN, and that its ownership-analysis procedure contained no step for the Australian control test. We redesigned the programme to address both gaps, including revised escalation procedures and a documented standard for control analysis. The matter proceeded to satisfactory closure without enforcement involvement.
What are the most common risk flags in Australian sanctions compliance programmes?
Six risk flags recur across the Australian-regime compliance mandates we handle. Identifying them early is the purpose of the audit; allowing them to persist is the route to enforcement.
The first is list-coverage gaps. A programme that screens only against the UN Consolidated List and the OFAC SDN misses a material portion of Australian designations, because Australia operates its own autonomous list with persons and entities not designated by either of those authorities.
The second is inadequate ownership-chain analysis. Where a counterparty has a complex or opaque ownership structure, the programme must document a reasoned conclusion on effective control – not simply confirm that no entity in the first layer of ownership appears on a list. Shell structures, trust arrangements, and nominee shareholdings all require deeper analysis.
The third is inconsistent goods and services classification. Businesses that have classified goods for EAR purposes sometimes assume that the same classification satisfies Australian-regime controls. It does not; the Australian permitted-goods and prohibited-goods regime operates on its own legal basis and its own list of controlled items.
The fourth is a broken or untested escalation path. A policy that says "refer to legal" without defining who, on what timeline, and with what documentation is not a functioning escalation procedure. Enforcement investigations regularly reveal that notional procedures were never operationalised.
The fifth is a failure to account for retrospective designations. When DFAT designates a person or entity who is already party to an existing contract or relationship, the business must act promptly. A compliance programme that has no procedure for this scenario – no monitoring of the counterparty list between transaction initiation and completion – creates a window of exposure that is difficult to defend.
The sixth is inadequate record-keeping. In any enforcement context, the quality of contemporaneous records determines whether a business can demonstrate that it took reasonable steps to comply. Screening logs, ownership-analysis memoranda, permit applications, and escalation records must be preserved and retrievable. A programme that relies on email archives without structured retention is unlikely to meet this standard.
If a transaction has already been flagged, or a potential violation has come to the business's attention, early legal review preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.
When should a business involve specialist compliance counsel?
Specialist counsel is not needed for every routine screening decision. It is needed at four specific points in the compliance lifecycle – and at each of those points, the cost of delay is measurable.
The first point is programme design or redesign. When a business first establishes an Australian-regime compliance programme, or substantially changes its operations (a new market, a new counterparty type, a merger or acquisition), the programme must be recalibrated. In-house teams with OFAC or EU experience will correctly identify much of what is needed – but the divergences set out above mean that specialist review of the Australian-specific elements is prudent.
The second point is a complex ownership or control question. Where a counterparty's structure is opaque, where a designation has recently been made against a company in the ownership chain, or where the effective-control test may be engaged, a documented legal opinion is the appropriate output. That opinion is also potentially the basis for a due-diligence defence if the analysis later proves incorrect in good faith.
The third point is a permit application. The Australian regime provides for permits (the equivalent of a specific licence under other regimes) authorising dealings that would otherwise be prohibited. Preparing a well-evidenced permit application, anticipating DFAT's queries, and managing the regulatory dialogue requires familiarity with the authority's practice. We regularly advise clients through this process.
The fourth point is when a potential breach has been identified. Whether to make a voluntary disclosure, what to preserve, how to scope the apparent violation, and how to structure the business's communications during an investigation are questions that must be answered with legal advice, not internal policy alone. The enforcement consequences of an unmanaged disclosure differ materially from those of a well-structured one.
A common misconception in this area is that a strong OFAC compliance programme – one that has passed a big-four review or an internal audit – is sufficient for Australian-regime purposes. It is not. The lists differ, the ownership-and-control test differs, the goods controls differ, and the enforcement authority differs. We correct this misconception regularly. A programme built to OFAC standards is a solid foundation; it is not a substitute for Australian-specific design and testing.
How does Calder & Vance structure an Australian-regime compliance audit and testing engagement?
Our approach to Australian-regime compliance audit and testing is structured around five deliverables, each produced with a fixed scope so that the engagement can be planned and budgeted in advance.
The first deliverable is a legal coverage memorandum: a written assessment of which instruments apply to the business, which lists must be screened, and where the regime's jurisdictional reach extends into the client's corporate group. This gives the compliance team a documented legal baseline.
The second deliverable is a gap analysis: a section-by-section review of the existing programme documentation against the legal baseline, identifying the specific provisions that require amendment, addition, or deletion. The gap analysis is structured as a prioritised action register, not a discursive report.
The third deliverable is a testing report: the output of the transactional sampling and scenario testing exercises described above, with findings classified by severity and accompanied by recommended remediation steps.
The fourth deliverable is revised programme documentation: updated or new policy text, screening procedures, ownership-analysis templates, escalation procedures, and record-keeping standards, drafted to satisfy the Australian regime and, where the client has multi-regime exposure, designed for compatibility with OFAC, OFSI, and EU standards.
The fifth deliverable is a training session: a structured briefing for the relevant compliance, legal, and operational teams, covering the key obligations, the revised procedures, and the risk flags that the audit identified. Training is the mechanism by which a revised programme becomes an operational reality rather than a document.
We work within a defined timeline and a fixed-fee structure for each stage. The engagement is scoped before it begins, so the client knows what it will receive and when.
Related practices
- Compliance audit and testing under BIS/EAR – US export control compliance audit, classification review, and Entity List screening.
- Compliance audit and testing under EU sanctions – EU Council regulation coverage, ownership-and-control analysis, and General Court awareness.
- Compliance audit and testing under OFAC – US sanctions programme review, 50 percent rule analysis, and voluntary self-disclosure support.