Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFAC

Crypto and VASP sanctions compliance under OFAC: legal support

A payment platform processes thousands of transactions daily. Its screening tools flag wallet addresses against the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). One morning, a cluster of transactions routes through a wallet that sits two hops from a designated entity. The platform's compliance officer asks: is this a blocked transaction? Does the firm need to file a report? How does the virtual-asset context change the standard OFAC analysis? These are not academic questions. They are the questions that decide whether a regulator opens an inquiry.

Crypto and VASP sanctions compliance under OFAC legal support covers the full range of obligations that apply when a virtual-asset service provider (VASP – any platform that exchanges, transfers, or custodies digital assets) operates within US jurisdiction or touches US-person transactions. OFAC applies the same legal framework to digital assets as to conventional finance: prohibited transactions remain prohibited regardless of the payment rail. The ownership and control test, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked), the reporting obligation, and the voluntary self-disclosure (VSD) route all apply in full. What changes is the technical environment – pseudonymous wallets, DeFi protocols, cross-chain bridging – and the specific guidance OFAC has issued to address that environment.

This page explains the governing legal regime, the procedure for managing a VASP sanctions exposure, the cross-border dimensions that affect platforms with non-US operations, the most common risk flags our team identifies in VASP compliance programmes, and how Calder & Vance structures its engagement for firms at this intersection of technology and sanctions law.

What legal regime governs OFAC crypto and VASP sanctions obligations?

OFAC's authority over virtual assets rests on the same statutes that govern conventional financial sanctions: principally IEEPA and, for certain programmes, TWEA. OFAC's published guidance on virtual currency confirms that the economic sanctions programmes it administers apply to all US persons and to transactions that touch the United States, regardless of whether value moves on a blockchain or through a correspondent bank. The instrument is the same; the delivery mechanism is different.

OFAC has also designated digital wallet addresses directly on the SDN List. When a wallet address is listed, any US person – or any non-US person transacting in a way that touches US jurisdiction – is prohibited from dealing with it. A VASP that processes a transfer to or from a listed wallet has conducted a prohibited transaction, even if no human counterparty name appeared in its screening queue. This is the feature of the crypto environment that catches platforms unprepared: the designated property is not always a named entity behind a corporate veil. Sometimes it is an address string.

The second pillar is the 50 percent rule. If one or more SDN-listed persons own, directly or indirectly, 50 percent or more of the entity that controls a wallet or a VASP platform, that entity is treated as blocked even if it is not itself named. Applying this test to a decentralised protocol – where ownership is represented by governance token holdings – is one of the more technically demanding questions in current OFAC practice. In our experience, most VASP compliance programmes handle the named-entity and wallet-address screens adequately; the ownership aggregation test across token-based governance structures is where gaps appear.

OFAC also requires that blocked property be reported. When a VASP blocks a transaction or freezes an asset, a report to OFAC is required within a short statutory window. Record-keeping obligations attach to every blocked or rejected transaction.

The position above covers the standard legal basis. Your facts – the wallet, the counterparty, the protocol, and the jurisdictions involved – will refine the analysis materially.

For an initial assessment of your VASP's exposure under OFAC, contact Calder & Vance at info@caldervance.com.

How does OFAC's approach to VASPs compare with the UK and EU positions?

OFAC, OFSI, and the EU each reach digital-asset activity through their own instruments, but the underlying obligation – do not deal with a designated person or entity – is consistent across all three. The divergences lie in how each authority tests ownership and control, how reporting works, and what the licensing route looks like.

Under OFAC, the ownership test is mechanical: 50 percent or more aggregate ownership by blocked persons triggers automatic blocked status for the downstream entity, wallet included. Control short of 50 percent does not automatically apply the same result, though OFAC will look at the full facts.

OFSI – the UK's Office of Financial Sanctions Implementation – applies an ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person) that explicitly includes control as a separate limb. A listed person with less than 50 percent ownership can still cause an entity to be treated as caught if they control it. For a VASP operating in both jurisdictions, this means a counterparty that clears the OFAC threshold screen may still be caught under the OFSI analysis.

The EU position mirrors OFSI's dual-limb approach. The relevant Council regulations apply to entities owned or controlled by listed persons. EU competent authorities have published guidance on applying these tests to digital-asset contexts, though the degree of specificity is less developed than OFAC's virtual-currency guidance. A VASP with EU-licensed operations must apply the stricter prohibition where regimes overlap: where the EU control test catches a counterparty that the OFAC test does not, the EU prohibition governs for those operations.

Switzerland (SECO), Singapore (MAS), and the UAE also regulate VASP activity and align their sanctions frameworks with the regimes of their respective international partners to varying degrees. A cross-border VASP cannot assume that clearing OFAC automatically clears every other regime. We regularly advise platforms with multi-jurisdictional licences on mapping these divergences into a single, workable compliance architecture.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact us at info@caldervance.com.

What does a VASP sanctions compliance assessment cover?

A sanctions compliance assessment for a VASP examines the five elements that OFAC considers when evaluating whether a compliance programme is effective: management commitment, risk assessment, internal controls, testing and audit, and training. For a VASP, each element has a technical dimension that a conventional financial-institution assessment does not.

The risk assessment must address the specific exposure vectors of the platform. These include: the blockchain networks the platform supports, the degree of anonymity permitted at onboarding, whether the platform operates a custodial or non-custodial model, the jurisdictions from which users connect, and whether the platform interacts with DeFi protocols that may have governance structures that create SDN exposure through the 50 percent rule.

Internal controls cover screening logic. OFAC's virtual-currency guidance makes clear that screening should include wallet addresses on the SDN List, not only named-entity matches. A platform that screens only against names and does not query blockchain analytics for wallet-address hits has a gap in its internal controls. The assessment maps that gap and defines the remediation steps.

Testing and audit – examined in more detail in our compliance audit and testing service – is the element most often under-resourced at growth-stage VASPs. A written policy that is not periodically tested against live transaction data provides limited assurance. We test screening logic against a curated set of scenarios drawn from the current SDN List and OFAC's virtual-currency guidance.

Training must address the specific tools and workflows the platform uses. Generic AML training that does not address blockchain analytics, wallet-address screening, or the 50 percent rule as applied to token ownership does not satisfy OFAC's expectations for a platform in this sector.

What are the most common risk flags in VASP sanctions programmes?

In our practice, the risk flags that recur most frequently in VASP sanctions assessments fall into four categories. Identifying them early is the difference between a manageable compliance gap and an enforcement inquiry.

First, over-reliance on name-only screening. A platform that screens counterparty names against the SDN List but does not integrate blockchain analytics for wallet-address matching will miss the wallet-address designations that OFAC has placed directly on the list. The list includes both entity names and specific digital-asset addresses; both must be screened.

Second, incomplete ownership-chain analysis. The 50 percent rule aggregates holdings across all blocked persons. Where a DeFi protocol or a VASP subsidiary is partly owned by token-holders, the platform must assess whether any of those token-holders are themselves designated, and whether their aggregate holdings reach the threshold. Most screening tools are not calibrated for this analysis without manual supplementation.

Third, delayed or absent blocking reports. When a VASP blocks a transaction involving an SDN-listed wallet, a report to OFAC is required. In our experience, many platforms have a blocking workflow but lack a reliable trigger for the reporting obligation. A transaction rejected by the screening tool may not automatically generate a report. The gap between the technical block and the regulatory report is a common source of inadvertent violation.

Fourth, geographic IP screening treated as a substitute for sanctions screening. Some platforms restrict access by IP address as a proxy for jurisdiction. This is a useful control, but it is not a sanctions screen. A user in a non-sanctioned jurisdiction may still be a designated person or may transact on behalf of one. IP-based controls supplement but do not replace SDN screening and ownership analysis.

Do your current controls cover all four of these categories? If there is any doubt, a structured assessment is the fastest route to an answer.

How does the escalation and reporting workflow operate for a VASP?

When a VASP's screening system identifies a potential hit – whether a wallet-address match, a name match, or a flagged counterparty – the escalation workflow must move through defined steps within a short window. The precise reporting deadline varies by programme and by whether the transaction is blocked or merely rejected; verify the current position before relying on any specific timeframe.

The first step is hit adjudication: determining whether the screen alert represents a true match against a listed person or a false positive. For wallet-address alerts, this requires querying the SDN List directly and, where the alert comes from blockchain analytics, reviewing the clustering methodology used by the analytics provider. A false positive cleared without a documented adjudication trail creates its own risk: OFAC may ask to see the record if it later investigates the same wallet.

The second step, where a true match is confirmed, is blocking the transaction and preserving the relevant records. Blocked property must be held in an account that makes clear its blocked status. For a VASP, this means the asset must not be commingled with unblocked assets and must be identifiable as blocked for reporting and any future licensing purposes.

The third step is submitting the report. OFAC requires a report for each blocking action. The report covers the identity of the parties, the nature and value of the blocked property, and the basis for the blocking. Our escalation and reporting service covers the procedural requirements and the drafting of compliant reports. We also advise on the parallel reporting obligations that may arise under OFSI and EU competent-authority regimes for platforms with multi-jurisdictional operations.

The fourth step is record-keeping. OFAC requires that records relating to blocked transactions be retained for a defined period. Sanctions and export-control obligations do not expire when the transaction is processed; the record must survive for the requisite retention period and be retrievable on request.

For platforms that use third-party blockchain analytics providers, there is a fifth consideration: vendor oversight. The quality of wallet-address screening depends on the accuracy and currency of the analytics provider's clustering data. A VASP is not absolved of an OFAC obligation because its vendor missed a designation. The responsibility remains with the platform.

When should a VASP consider voluntary self-disclosure?

A VSD (voluntary self-disclosure to a regulator) is the procedural mechanism by which a person who believes it may have committed a violation proactively reports that conduct to OFAC. OFAC's enforcement guidelines treat VSD as a significant mitigating factor when calculating a civil penalty. Whether to file a VSD is a judgment that depends on the facts of the potential violation, the firm's prior compliance history, and a careful assessment of what is known and what remains uncertain.

For a VASP, the VSD decision arises most commonly in three scenarios. First, a retrospective audit reveals that wallet-address screening was not in place during a period when SDN-listed wallets were active on the platform, and transactions may have been processed to or from those wallets. Second, a blockchain analytics review of historical transactions surfaces a cluster of transactions connected to a designated entity that was not identified at the time. Third, a compliance programme upgrade reveals a past gap in the ownership analysis that may have caused the platform to transact with a blocked entity under the 50 percent rule.

In each scenario, the platform faces a choice between voluntary disclosure and the risk of an OFAC-initiated inquiry without the mitigation benefit. The analysis is not mechanical. OFAC weighs the nature of the violation, whether it was wilful or reckless, the harm caused, and the cooperation of the subject. A well-prepared VSD, with a root-cause analysis and a concrete remediation plan, positions the firm differently than an unsupported disclosure. We regularly advise VASPs on VSD strategy and preparation – scoping the apparent violation, advising on the disclosure itself, and preparing the penalty defence if enforcement proceedings follow.

Equally, not every identified gap requires a VSD. Some apparent violations are not violations on proper analysis. Some are violations but fall below the materiality threshold at which a disclosure is strategically warranted. That assessment requires experienced sanctions counsel, not a default to disclosure. Our escalation and reporting practice for enforcement contexts covers the full range of these decisions.

A common misconception: OFAC only applies to US-incorporated entities

The most persistent myth our team encounters in VASP compliance work is this: "We are not a US company, so OFAC does not apply to us." This is incorrect. OFAC's jurisdiction extends to all US persons – wherever they are located – and to all transactions that touch the United States. A non-US VASP that processes a transaction for a US-person customer, that routes value through a US correspondent, or that allows a US-person employee to approve a transaction has touched US jurisdiction. The sanctions obligation applies.

OFAC has in addition imposed secondary-sanctions risk in certain programmes. Secondary sanctions do not technically apply OFAC's primary legal regime to non-US persons, but they create the risk that a non-US VASP conducting certain transactions may itself face designation or lose access to the US financial system. For a VASP with a significant US user base or US investor relationships, secondary-sanctions risk is a practical constraint even where the primary legal reach of OFAC is debated.

The practical implication is that virtually every VASP operating at any scale needs a credible OFAC compliance posture, regardless of where it is incorporated. The question is not whether OFAC applies; it is whether the platform's current controls are calibrated to the level of exposure its business model creates.

Related practices

How Calder & Vance assists VASPs on OFAC sanctions compliance

We work with virtual-asset platforms at different stages of their compliance development – from initial programme design through periodic audit, enforcement response, and VSD preparation. Our engagement is structured to the firm's specific risk profile, not a generic financial-institution template.

For platforms building or rebuilding their compliance programme, we: test the screening logic against current SDN List data including wallet addresses; map the ownership and control chain for any counterparty where the 50 percent rule may apply, including token-based governance structures; and redesign the programme to the five-element standard that OFAC applies in enforcement assessments.

In a recent matter, a growth-stage digital-asset exchange recognised that its screening covered named entities but not wallet addresses on the SDN List. We reviewed the platform's transaction history against current OFAC designations, assessed whether any apparent matches constituted true violations, and designed a remediated screening architecture that integrated blockchain analytics directly into the compliance workflow. The matter concluded without a disclosure event.

For firms facing a potential enforcement inquiry or considering a VSD, we scope the apparent violation, advise on whether a disclosure is warranted and how to frame it, and prepare the penalty defence. We also coordinate with local counsel in relevant jurisdictions for platforms with OFSI or EU reporting obligations that arise from the same events.

For platforms in the scaling phase, we advise on how to structure onboarding controls, geographic restriction policies, and third-party vendor oversight to ensure that a growing transaction volume does not outpace the compliance infrastructure.

We do not advise on circumventing or evading sanctions.

Frequently asked questions

How long does managing crypto sanctions exposure take under OFAC?
There is no single answer: the timeline depends on the scope of the review and whether an apparent violation has been identified. An initial compliance assessment of a VASP's screening architecture and programme design can typically be scoped and completed within a defined number of weeks. Where a VSD is under consideration, the scoping and preparation process takes longer, as a thorough root-cause analysis and remediation plan must accompany any disclosure. OFAC's review of a submitted VSD operates on its own timeline; verify the current position before relying on any expectation of resolution speed.
What are the main risks in crypto and VASP sanctions compliance under OFAC?
The principal risks are: processing a transaction involving an SDN-listed wallet address that name-only screening missed; failing to apply the 50 percent rule across token-based ownership structures; omitting or delaying the blocking report required when a transaction is frozen; and a non-US VASP underestimating the reach of OFAC's jurisdiction through US-person customers or US-routed transactions. Each risk is manageable with the right controls; each becomes significantly harder to address once an OFAC inquiry has opened.
Do we need specialist counsel for crypto and VASP sanctions compliance?
Specialist counsel is most valuable at three points: when building or reviewing the compliance programme against OFAC's published expectations for virtual-asset platforms; when a screening alert raises a genuine question about whether a blocked transaction has occurred and whether a report is required; and when considering a VSD or responding to an OFAC inquiry. Generic AML or financial-crime counsel may cover some of the ground, but the wallet-address designation regime, the 50 percent rule applied to token ownership, and the multi-regime interaction for cross-border platforms are areas where VASP-specific sanctions experience matters materially.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.