Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Counterparty due diligence under OFSI: compliance counsel

A British logistics company is about to sign a long-term freight agreement with a trading partner in a third market. Its in-house team runs a basic sanctions check. Nothing flags. Six months later, an OFSI enforcement enquiry arrives: a beneficial owner sitting two layers up the counterparty's structure was designated the week before the contract was signed. The question is no longer whether to do business – it is whether the business has a reportable breach.

Counterparty due diligence under OFSI is the process of screening a prospective or existing business partner against the UK financial sanctions lists, mapping their ownership and control structure, and identifying whether any designated person's interest – direct or indirect – catches the relationship under the UK's ownership and control (the test under the relevant thematic sanctions regulations by which a non-listed entity can be caught through a listed person's interest) standard. OFSI administers the UK financial sanctions regime under the Sanctions and Anti-Money Laundering Act ("SAMLA"), and the obligations it enforces bite on any transaction with a UK nexus, including those of non-UK businesses with UK counterparties, sterling payments, or UK-incorporated subsidiaries.

This page explains how OFSI's ownership-and-control test works, where UK rules diverge from OFAC and EU positions, what risk flags practitioners see most often in cross-border diligence, and how Calder & Vance assists businesses that need robust, legally grounded counterparty screening before a transaction closes.

What does counterparty due diligence under OFSI require?

Counterparty due diligence under OFSI requires a business to establish, before engaging in any transaction or arrangement with a counterparty, that no designated person holds a relevant interest in that counterparty and that the transaction itself does not involve making funds or economic resources available to a designated person. The duty is not aspirational. OFSI can impose a civil penalty for conduct that a business "knew or had reasonable cause to suspect" was prohibited – and it publishes its enforcement guidance setting out the factors that determine the monetary penalty. That standard captures businesses that failed to check, not only those that checked and decided to proceed regardless.

In practice, the diligence obligation covers four elements. First, list screening: the counterparty's name, aliases, and any known identifiers must be checked against the UK Consolidated List and relevant thematic designations. Second, ownership mapping: the ultimate beneficial owners and any intermediate holding entities must be traced. Third, the control test: even where no designated person meets a formal ownership threshold, OFSI's rules ask whether a designated person controls the entity by other means – through voting rights, board composition, contractual arrangements, or any other mechanism. Fourth, ongoing monitoring: a counterparty that was clean at onboarding can become prohibited if a beneficial owner is designated mid-relationship. Do you have a process for catching that change before a payment is made?

In our experience, the control test is where the most significant exposure lies for clients whose onboarding process is otherwise sound. A counterparty may have no designated majority shareholder, yet be operationally directed by a designated individual through a management contract or informal influence. OFSI's guidance does not treat the absence of formal listed ownership as conclusive.

How does the UK ownership-and-control test differ from OFAC and EU positions?

The UK ownership-and-control test differs from the OFAC 50 percent rule in one structurally important respect: UK rules look beyond a mechanical ownership threshold and require an assessment of whether a designated person controls the entity by any means. Under OFAC's position – set under IEEPA – an entity owned 50 percent or more in the aggregate by one or more blocked persons is treated as blocked, whether or not those persons exercise active control. The UK test applies the ownership dimension too, but supplements it with a genuine control enquiry that has no fixed numeric floor.

The EU position under the relevant Council regulations is structurally closer to the UK approach than to OFAC's. Both the EU and OFSI require an assessment of "owned or controlled" – but the precise articulation differs between Council regulations, and individual EU member states apply the standard with varying emphasis. A business operating across the UK and the EU must therefore run two parallel analyses and cannot assume that passing one satisfies the other.

Three practical divergences matter most. First, the aggregation question: OFAC aggregates holdings of multiple blocked persons to test the 50 percent threshold; UK and EU rules both address indirect ownership chains but phrase the control overlay differently. Second, the presumption of blocking: OFAC's rule deems the entity blocked automatically when the threshold is met; OFSI's position is that a transaction involving such an entity is prohibited but the entity is not itself "designated" – the distinction matters for licensing and reporting steps. Third, the reporting obligation: OFSI requires a person who holds or controls funds belonging to a designated person to report that fact to OFSI as soon as practicable; there is no direct OFAC equivalent for persons who are not US financial institutions. That cross-regime gap means a UK-US joint venture needs separate legal mapping rather than a single combined analysis.

We regularly advise businesses whose compliance teams have applied the OFAC 50 percent logic to a UK-nexus transaction and concluded that a sub-threshold holding is safe. That conclusion is not always correct under OFSI's control test.

What are the risk flags that practitioners see most often?

The risk flags that most consistently produce exposure in counterparty diligence under OFSI fall into four categories: ownership structure complexity, payment routing, sector concentration, and temporal gaps in screening. None of these individually guarantees a breach, but each increases the probability that a transaction has an undisclosed prohibited element.

Ownership structure complexity is the leading source of missed designations. Corporate chains that pass through multiple jurisdictions – particularly where beneficial ownership disclosure standards vary – can conceal a designated person whose interest would otherwise trigger the prohibition. The problem is not confined to opaque offshore structures. A mid-market manufacturer with a private equity backer that is itself majority-owned by an investment fund may have a designated LP that none of the standard list-screening steps would catch.

Payment routing matters because the UK financial sanctions prohibitions are transaction-based as well as counterparty-based. A payment instruction routed through a correspondent bank with a UK nexus can trigger an OFSI obligation even where the originating party has no other UK connection. Financial institutions handling such payments regularly ask their corporate clients for additional beneficial ownership information. If your organisation cannot produce that information promptly, the payment may be frozen and the enquiry escalated.

Sector concentration risk is a factor in industries where designated persons have historically held significant assets: energy, metals, shipping, and real estate. A supplier in one of these sectors operating in a jurisdiction with a substantial designated-persons population warrants a more intensive ownership review than a standard counterparty in a low-risk sector would.

Temporal gaps are underappreciated. Sanctions lists update with no advance notice. A counterparty screened at the initial onboarding stage and then not re-screened for twelve months has, in effect, not been screened for every transaction that occurred in that period. OFSI's enforcement guidance makes clear that continuing transactions with a party who has since been designated will be assessed as if each payment were a separate decision.

What is the procedure for carrying out legally sound due diligence?

Legally sound counterparty due diligence under OFSI follows a five-step sequence that mirrors the structure of OFSI's published enforcement approach: define scope, screen lists, map structure, apply the control test, and document the analysis. The sequence is not optional – OFSI's penalty framework expressly considers whether a business maintained adequate records of its diligence process.

Step one: scope definition. Identify which legal entities and individuals fall within the counterparty relationship – the contracting party, its immediate parent, ultimate beneficial owners, and any intermediary through which economic benefit will flow. The scope should also capture any payment intermediary, guarantor, or security provider whose involvement makes funds available to the counterparty.

Step two: list screening. Screen all in-scope entities and individuals against the UK Consolidated List, the OFSI-maintained financial sanctions targets list, and any thematic designations relevant to the sector or geography. Automated tools help at volume, but they require human review of any fuzzy matches or transliteration variants.

Step three: ownership mapping. Obtain current corporate registry data, ultimate beneficial owner filings where available, and – for counterparties in jurisdictions with limited public disclosure – enhanced due diligence documentation directly from the counterparty. Map the full chain to the ultimate individual owners.

Step four: control test. Consider whether any designated person, regardless of ownership percentage, holds a control position through voting arrangements, management agreements, security interests, or other mechanisms. This step requires legal judgment, not only data aggregation. A compliance officer running a list check cannot, without legal input, reach a reliable conclusion on the control question in a complex structure.

Step five: documentation and review cycle. Record the sources consulted, the conclusions reached, and the date of the analysis. Set a review trigger – whether periodic (quarterly for high-risk counterparties, annually for lower-risk relationships) or event-driven (a new designation in the relevant sector, a change in the counterparty's ownership, a new payment instruction from an unexpected account).

The position above covers the standard procedure. Your facts – the counterparty's jurisdiction, the sector, the payment structure, and the regime in play – change the analysis materially. For a structured review tailored to your counterparty relationship, contact Calder & Vance at info@caldervance.com.

What happens when due diligence identifies a potential match?

When counterparty due diligence identifies a potential match against the UK sanctions list, the immediate obligation is to stop: no funds or economic resources should be made available to the counterparty while the match is unresolved, and any funds already held for the counterparty's account should not be transferred without a licence or a confirmed determination that the match is a false positive. Acting through a hit without clearing it is precisely the "reasonable cause to suspect" standard that OFSI's penalty regime is designed to capture.

The first operational decision is whether the match is a true positive. Name-matching tools generate false positives, particularly where common names, transliteration variants, or data-quality issues produce a coincidental correspondence. The analysis of whether a match is genuine requires comparison of the identifying information in the listing – date of birth, nationality, address, associated entities – with the counterparty's verified identity documentation. This is a legal and evidentiary exercise, not a data-entry task.

If the match is confirmed, two further steps arise. First, the funds-freezing and reporting obligation: any funds or economic resources held for the designated person's account must be frozen, and OFSI must be notified as soon as practicable. The report must set out the nature and value of the assets concerned. Failure to report is itself a breach. Second, the licence question: OFSI can issue a specific licence to permit a particular transaction that would otherwise be prohibited. Licence grounds include financial hardship, legal fees, prior contractual obligations, and grounds that OFSI has set out in its published guidance. The licence application is a formal submission – it requires a clear description of the proposed transaction, an explanation of how it meets a licensing ground, and supporting evidence.

If a transaction has already been flagged or a filing has been refused, an early legal review can preserve options that narrow with time. Reach our team at info@caldervance.com for a confidential initial assessment.

How does counterparty due diligence interact with the broader UK export-control regime?

Counterparty due diligence under OFSI sits alongside – but is legally distinct from – the UK export-control regime administered by ECJU. For a business that trades in goods, technology, or software with a potential dual-use dimension, clearing a counterparty under OFSI's financial sanctions does not discharge the separate export-licensing obligations. The two regimes catch different prohibited elements: OFSI prohibits making funds or economic resources available to a designated person; ECJU prohibits exporting controlled items to certain destinations or end-users without a licence.

In practice, the diligence exercise for a cross-border goods transaction must ask both questions. A counterparty may be entirely clear on the UK financial sanctions lists yet be a prohibited end-user under the export-control rules because of the stated end-use of the goods, the destination country's status, or the buyer's involvement in a weapons programme. The two enquiries require different documentation – sanctions diligence produces a compliance memo; export-control diligence produces an end-user undertaking (a formal declaration by the buyer of the intended end-use of the goods) – but they should run in parallel for any transaction that involves physical goods with a potential controlled classification.

The cross-border picture extends further. A transaction with a UK counterparty that involves a US-origin component may also engage OFAC's primary sanctions prohibitions and, depending on the item, BIS's export-control jurisdiction under the EAR. The stricter prohibition governs. Our practice advises on the interaction between OFSI and OFAC requirements, between OFSI and EU Council regulation obligations, and between financial sanctions and export-licence requirements across these regimes.

A common misconception: does passing a list check mean the transaction is clear?

A common misconception among in-house compliance teams – and one we correct regularly – is that a clean result on a standard list-screening tool means a transaction is cleared under OFSI. It does not. List screening answers a narrow question: does this name appear on a designated persons list? It does not answer the ownership-and-control question, the payment-routing question, or the ongoing-monitoring question. All three can produce a breach even where the counterparty's name has never appeared on any list.

The practical consequence is that businesses that rely solely on automated name-matching tools carry residual exposure that their compliance reports do not reflect. OFSI's enforcement cases – described in its public statements without reference to specific penalty notice numbers – consistently show that it is the second and third layers of the ownership chain, not the direct counterparty, that produce the prohibited connection. A tool that does not map those layers cannot tell you that you are clear.

In our cross-border practice, we have assisted clients whose existing screening programmes were technically operational but legally insufficient under OFSI's published standard. The gap between "we screen" and "we screen adequately" is where enforcement risk lives.

Related practices

Frequently asked questions

How long does counterparty due diligence take under OFSI?
The timeline depends on the complexity of the counterparty's ownership structure and the availability of beneficial ownership documentation. For a straightforward counterparty with a transparent single-jurisdiction structure, a legally reviewed diligence exercise can be completed within a small number of business days. Where the structure involves multiple jurisdictions, nominee arrangements, or limited public disclosure, the exercise may take longer – principally because obtaining verified documentation from the counterparty or from non-UK registries takes time. We advise clients to build diligence timelines into their transaction timetables rather than treating it as a parallel fast-track exercise. Rushed due diligence is one of the most consistent factors in enforcement findings that a business lacked "reasonable cause" to believe the transaction was permitted.
What are the main risks in counterparty due diligence under OFSI?
The main risks are: missing a designated beneficial owner sitting above the legal counterparty in the ownership chain; failing to apply the control test where ownership is sub-threshold; not re-screening a counterparty after a new designation cycle; and failing to document the analysis in a form that demonstrates a reasonable and systematic process. The reporting obligation – which requires a business holding funds connected to a designated person to report to OFSI as soon as practicable – is a distinct risk for financial institutions and corporates holding counterparty deposits or advance payments. OFSI's penalty framework is graduated but can be substantial; the civil monetary penalty base for the most serious cases is set by reference to the value of the breach, not a fixed statutory cap.
Do we need specialist counsel for counterparty due diligence?
For straightforward, low-risk counterparties with transparent structures, a well-designed internal programme may be sufficient for ongoing screening. Specialist counsel adds most value in three situations: first, where the counterparty's ownership structure is complex or involves jurisdictions with limited disclosure standards; second, where a potential match has been identified and a true-positive determination is required before a transaction can proceed; and third, where the transaction involves both OFSI financial sanctions and ECJU export-control obligations, or where a parallel OFAC or EU analysis is required. In our experience, the cost of specialist input at the diligence stage is a small fraction of the cost of an OFSI enforcement enquiry or a frozen payment dispute.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.