Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Name and entity screening under OFSI: compliance counsel

A financial institution operating across UK and European markets onboards a new corporate client. The ultimate beneficial owner does not appear on the OFSI Consolidated List (the UK government's list of designated persons subject to financial sanctions) – but a subsidiary two layers up does. The screening tool returns a clean result. The transaction proceeds. Six months later, a routine audit surfaces the connection, and the firm is staring at a potential breach of UK financial sanctions with no voluntary disclosure filed.

Name and entity screening under OFSI is the process by which a business identifies whether a counterparty, owner, or associated person appears on the UK Consolidated List of financial sanctions targets or is otherwise caught through the UK's ownership and control test (the standard that treats a non-listed entity as subject to sanctions where a designated person owns or controls it). Under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic sanctions regulations, screening is not merely good practice – it is the operational mechanism that supports the legal prohibition on dealing with designated persons, and failures in it have drawn OFSI enforcement action.

This page sets out the governing regime, the UK screening standard and how it diverges from OFAC and EU approaches, the most common points of failure, and how Calder & Vance supports businesses in building and testing screening that holds up under regulatory scrutiny. As of August 2026, OFSI's enforcement posture has intensified, and the cross-regime complexity of UK, EU, and US obligations means that a screen adequate for one regime may leave gaps in another.

What does OFSI-compliant name and entity screening actually require?

OFSI-compliant screening requires a business to check counterparties, beneficial owners, and associated parties against the UK Consolidated List before entering into a relevant arrangement, and to maintain that check on an ongoing basis as the list updates. The governing obligation sits in SAMLA and the relevant thematic regulations that implement each UK sanctions programme. OFSI's published guidance makes clear that firms should not limit their checks to direct counterparties alone.

The UK Consolidated List is updated frequently – sometimes multiple times in a single day in a period of active designations. A firm that runs a one-off check at onboarding and does not re-screen when the list changes will be exposed the moment a previously clean counterparty is designated. Ongoing monitoring, not static onboarding checks, is the operational standard OFSI expects.

What does that mean in practice? At minimum, it means an automated feed that reflects list changes in near real time, a workflow for resolving potential matches, a documented process for escalation, and clear record-keeping. Manual processes built on periodic downloads of the list are unlikely to satisfy that standard in a regulated financial institution. For non-financial businesses with lower volumes, the bar is proportionality – but proportionality is not the same as informality, and OFSI will assess what was reasonable for the size and nature of the business.

The position above covers the baseline UK obligation. Your specific facts – the counterparty sectors, the jurisdictions involved, the volume of transactions, and the other regimes in play – will shift the analysis considerably. To discuss how the OFSI screening standard applies to your business, contact Calder & Vance at info@caldervance.com.

How does the UK ownership and control test shape screening design?

The UK ownership and control test extends the sanctions prohibition to entities that are owned or controlled by a designated person, even where that entity is not itself on the Consolidated List. This is the single most consequential aspect of UK screening that firms underestimate. Under the relevant thematic regulations, ownership means a stake of more than 50 percent, while control covers a broader set of circumstances including the ability to direct the affairs of the entity or to appoint its directors.

The control limb is the more difficult to screen for. It is not reducible to a percentage threshold. A minority shareholder may exercise control through a shareholders' agreement, a veto right, or by being the sole supplier of a critical input. Screening tools that flag only named entities or direct ownership stakes will systematically miss this category. In our cross-border practice, we regularly see firms that have invested significantly in screening technology but have not addressed the control question at all.

This diverges from the OFAC position in a meaningful way. OFAC's 50 percent rule (the rule treating any entity owned in aggregate 50 percent or more by blocked persons as itself blocked) is a bright-line ownership test. There is no control limb with the same open-ended character. Under the EU regime, the analysis is closer to the UK – but the EU instruments defining ownership and control are not identical to the UK formulations, and the post-Brexit divergence between them has grown with successive rounds of amendments. A business relying on EU-oriented screening governance to cover its UK OFSI obligations is taking a risk it may not have priced.

Where do name and entity screening programmes most frequently fail?

The most common failure in OFSI-facing screening programmes is not a technology gap – it is a design gap. The tool covers what it was configured to cover, but the configuration decisions were made without a full analysis of the UK ownership and control standard, the relevant entity types, and the specific risk profile of the business.

We advise businesses across a range of sectors. The failure patterns are consistent. First, beneficial ownership data is stale. Corporate registry information in many jurisdictions updates months after the underlying change occurs. Firms rely on it as if it were current. Second, the match-review workflow has no escalation logic. A potential match is flagged, reviewed by a junior analyst, closed on a close-but-not-exact name basis, and never reaches a decision-maker with the legal context to assess it correctly. Third, the screening programme covers legal entities but not natural persons who are beneficial owners or authorised signatories. Fourth, the programme covers new clients but does not re-screen the existing book when a new designation round occurs.

Each of these gaps can be traced to a documented failure pattern in OFSI's published enforcement materials. The common thread is that firms treat screening as a compliance checkbox rather than as a genuine risk-detection mechanism. OFSI's enforcement guidance makes clear that the adequacy of a firm's screening programme is a factor it weighs when assessing culpability and determining whether a monetary penalty is appropriate.

There is also a secondary-sanctions dimension. A UK firm with US-dollar settlement, or with US-person counterparties, must consider OFAC's SDN List and the broader OFAC regime in parallel. A transaction that clears the OFSI check may still be prohibited under OFAC if a US nexus exists. In our experience, the firms most exposed to dual-breach risk are those that run separate UK and US screening processes with no integration layer to catch transactions caught by both.

Cross-regime considerations: OFSI, OFAC, and the EU in a multi-jurisdictional business

A business with operations or counterparties in more than one jurisdiction faces a cross-regime screening obligation that is more complex than the sum of its parts. The UK, US, and EU regimes each maintain their own lists, their own ownership and control tests, and their own definitions of what constitutes a prohibited dealing. A consolidated approach – screening against all three lists simultaneously – is the minimum. But list-screening alone does not resolve the regime differences in how the prohibition is defined.

The extraterritorial reach of the OFAC regime is the most significant cross-border complication for UK businesses. OFAC's rules apply to all US persons and to transactions denominated in US dollars that clear through the US financial system, regardless of where the parties are located. A UK exporter settling in dollars, or a UK bank with a US correspondent, is exposed to OFAC's regime on those transactions even if the parties are entirely non-US. Secondary sanctions – OFAC designations and restrictions that can reach non-US businesses engaging with certain categories of targets – add a further layer. Our practice regularly advises UK-headquartered firms that are not US persons but whose trade finance, dollar clearing, or US-investor structures bring them within scope of OFAC scrutiny.

The EU position is relevant for UK firms with EU subsidiaries, EU counterparties, or EU-currency transactions. Since the UK's departure from the EU, the UK and EU lists have diverged – not dramatically, but meaningfully. The EU regime applies to persons acting within the EU, EU nationals wherever located, and EU-incorporated entities. A UK parent with an EU subsidiary must ensure that both the UK-facing and the EU-facing screening processes cover the respective lists, and that the ownership and control tests applied in each entity reflect the relevant regime's standard, not simply a shared template.

Switzerland (administered by SECO), Canada (Global Affairs Canada), Australia (DFAT), and the UAE, Singapore, and Japan each maintain their own sanctions regimes and lists. For businesses with supply chains or customer bases in those jurisdictions, the question is whether local screening obligations apply – and in most cases they do, at least to transactions touching those jurisdictions. We advise on integrated screening architecture that maps each regime's list and ownership test to the relevant entity in the group structure.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss your position.

What does a well-designed OFSI screening programme look like in practice?

A well-designed OFSI screening programme has five components: an accurate and current data source, a proportionate screening scope, a documented match-resolution workflow, an escalation and reporting path, and record-keeping that satisfies the regulatory standard. Each component has both a technical dimension and a governance dimension, and neither is sufficient without the other.

The data source must be connected to the UK Consolidated List (and, for multi-regime programmes, to the other lists in scope) with a feed that reflects updates promptly. The scope must cover the correct population – not just named counterparties but ultimate beneficial owners, directors, authorised signatories, and, for certain transaction types, the ultimate end-users of a product or service. For businesses in scope of the UK money laundering rules, the beneficial ownership data from customer due diligence feeds directly into the screening obligation; the two processes need to be integrated rather than run in parallel silos.

The match-resolution workflow is where most operational failures occur. When a potential match is flagged, the workflow should produce a documented decision – name the specific factors that were considered, identify who made the decision, and record the basis for clearing or escalating. A decision made on the basis of "slightly different spelling" needs to be defensible if OFSI examines it. It is not sufficient to log only the outcome; the reasoning must be recoverable.

Record-keeping under UK financial sanctions obligations must be maintained for a period sufficient to satisfy OFSI's inspection requirements and any subsequent enforcement review. In our cross-border practice, we frequently find that firms with strong front-end screening have poor record-keeping at the back end – decisions are made and not documented, or documents are held locally and not recoverable on a group-wide basis.

In a recent matter, a payments business operating across three jurisdictions had deployed a market-leading screening platform. The platform was configured correctly for EU-list screening. The UK OFSI configuration had not been updated to reflect a revised ownership and control standard following a statutory amendment. We conducted a diagnostic review, identified the configuration gap, worked with the firm's technology team to close it, and redesigned the match-review workflow to capture the control-limb analysis. The matter was resolved before any regulatory contact was required.

Common myths about OFSI name and entity screening

The most persistent myth we encounter is that OFSI screening is essentially the same as OFAC screening, and that a firm already compliant with OFAC need not do additional work for OFSI. This is incorrect on three distinct grounds.

First, the lists differ. The UK Consolidated List and the OFAC SDN List are not identical. Post-Brexit, the UK has maintained, added to, and in some cases departed from the EU list it inherited. The OFAC list reflects US policy. A firm screening only against the SDN List will miss persons designated under the UK regime alone.

Second, the ownership and control tests differ, as set out above. OFAC's 50 percent rule is a bright-line ownership test; the UK control limb is not. A firm whose ownership analysis was designed around the OFAC standard may systematically miss UK-caught entities.

Third, the enforcement and licensing environment differs. OFSI has its own penalty powers, its own licensing process, and its own voluntary disclosure framework. Relying on OFAC compliance processes to satisfy OFSI obligations – without mapping the specific differences – is a structural gap that has produced real enforcement outcomes. The two regimes run in parallel; they are not interchangeable.

A second myth is that small or medium-sized businesses outside the financial sector have no meaningful OFSI screening obligation. The prohibition on dealing with designated persons under UK financial sanctions applies broadly. It is not limited to regulated financial institutions. Any business entering into a contract, accepting a payment, or delivering goods or services must satisfy itself that the counterparty is not a designated person or caught through the ownership and control test. The threshold for what is reasonable will be calibrated to the size and risk profile of the business – but the obligation to screen exists regardless.

How Calder & Vance supports name and entity screening under OFSI

We advise businesses at each stage of the screening lifecycle: initial design, diagnostic review of an existing programme, incident response where a potential match has been identified, and ongoing support for complex cases that require legal analysis of the ownership and control question.

For a business building or restructuring its OFSI screening programme, our work typically covers: mapping the counterparty population to the correct scope of the UK obligation; analysing the ownership and control position for high-risk relationships; assessing the adequacy of the technology configuration against the UK legal standard; designing the match-resolution workflow and escalation logic; and advising on record-keeping to satisfy OFSI's requirements.

Where a potential match requires legal analysis, we assess whether the ownership or control test is engaged under the relevant thematic regulations, advise on whether a transaction should be paused pending OFSI guidance, and if necessary assist with a voluntary disclosure or a licence application. Our cross-regime capability means we can simultaneously analyse the OFAC and EU positions where those are also in play – the realistic position for most of the UK businesses we advise.

We also conduct programme audits: a structured review of an existing screening programme against the five-component standard, producing a written report with a gap analysis and a prioritised remediation plan. For businesses preparing for a regulatory review or responding to an OFSI enquiry, the audit report provides the documented baseline that regulators require.

Related practices

Frequently asked questions

How long does set up effective screening take under OFSI?
There is no fixed statutory deadline for implementing a screening programme, but the obligation to screen arises immediately on the coming into force of each UK sanctions designation. For a business deploying or restructuring a programme from scratch, the timeline depends on the size of the counterparty population, the existing technology infrastructure, and the complexity of the ownership and control analysis required. In our experience, a baseline programme covering the UK Consolidated List with an automated feed, a documented match-resolution workflow, and adequate record-keeping can be implemented within a matter of weeks for a business with a defined counterparty population. Programmes for larger institutions with complex group structures and multi-regime requirements take longer. The risk during any implementation gap is real: OFSI does not grant a grace period, and the prohibition applies from the date of designation.
What are the main risks in name and entity screening under OFSI?
The primary risk is a transaction with a designated person or a controlled entity that screening failed to catch – triggering a potential breach of UK financial sanctions and exposure to OFSI civil monetary penalties and, in serious cases, criminal liability. Secondary risks include: over-reliance on a screening tool configured for a different regime (typically OFAC); failure to apply the control limb of the UK test to counterparties where a minority stake is held by a designated person; inadequate record-keeping that cannot demonstrate a good-faith match-resolution process to OFSI; and cross-regime gaps where a transaction clears the OFSI check but is prohibited under OFAC or the EU regime. Each of these risks has produced regulatory consequences for UK businesses in the current enforcement climate.
Do we need specialist counsel for name and entity screening?
Not every screening decision requires specialist counsel. A firm with a well-designed programme and a competent compliance team can handle routine screening in-house. Specialist legal input is appropriate in four situations: when designing or restructuring the programme to ensure it reflects the current UK legal standard, including the ownership and control test; when a potential match requires a legal analysis of whether the OFSI designation or control test is engaged; when a transaction has been flagged and the firm is considering whether to proceed, pause, or report to OFSI; and when a potential breach is under review and voluntary disclosure or a penalty defence is in contemplation. For cross-regime matters – where OFAC, EU, and UK obligations all apply to the same transaction – specialist cross-border counsel is consistently more efficient than managing three separate advisory relationships.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.