Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · UN

Name and entity screening under UN: compliance counsel

A commodities trader with counterparties across three continents runs its routine screening cycle. A match surfaces on the UN Consolidated List. The counterparty's name is similar – not identical – to a listed entity. Two subsidiary checks have been missed. The compliance officer now faces a decision with potential legal consequences on every side. Does the match hold? Is the related entity caught? And how long does the firm have to act before the commercial window closes?

Name and entity screening under the UN sanctions regime means checking counterparties, beneficial owners, and related structures against the UN Consolidated List (the master list of individuals and entities designated by the Security Council and its committees under Chapter VII of the UN Charter). The obligation is not optional: UN member states are legally required to implement Security Council asset-freeze and dealing prohibitions, and businesses operating across jurisdictions are exposed to parallel enforcement under every national regime that has transposed the UN measures – including OFAC, OFSI, and the EU Council regulations. As of mid-2026, the Consolidated List spans multiple programme-specific committees, and the volume of listed entries continues to grow.

This page sets out what rigorous UN-focused name and entity screening requires, where the cross-regime risks concentrate, and how Calder & Vance assists businesses whose screening programmes need to perform under genuine enforcement pressure.

What authority governs name and entity screening under the UN regime?

The UN Security Council is the primary authority: its resolutions adopted under Chapter VII of the UN Charter impose legally binding obligations on all member states to freeze assets, prevent funds from being made available, and prohibit specified dealings with listed persons and entities. The Consolidated List consolidates designations across the Security Council's various sanctions committees – covering thematic and country-specific programmes – into a single searchable dataset maintained by the UN Secretariat.

That said, the Consolidated List itself does not create direct obligations for private businesses. The operative legal duty flows from each state's implementing legislation. In the United States, OFAC administers UN-derived designations alongside its own programmes, and listed persons frequently appear on both the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and the Consolidated List. In the United Kingdom, OFSI administers the UK's autonomous sanctions regulations, which transpose UN measures under the Sanctions and Anti-Money Laundering Act. In the European Union, the Council publishes regulations that give direct legal effect to UN designations. The consequence for a cross-border business is that a single Consolidated List entry can trigger simultaneous prohibitions under several distinct national regimes.

Understanding which national instrument applies – and which enforcement authority has jurisdiction over a given transaction – is the first analytical step. In our practice, businesses often treat the Consolidated List as a self-sufficient compliance universe when in fact it is the floor, not the ceiling, of their obligations.

How does the UN screening test work, and where does it diverge from OFAC and OFSI?

The screening test under the UN regime requires a match against listed names, aliases, and identifiers; where a match is credible, the business must freeze assets and refrain from making funds or economic resources available, pending verification and, if appropriate, authorisation from the relevant national authority or the Security Council committee.

The critical divergence lies in the ownership and control test applied in each implementing jurisdiction. OFAC applies the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked), which is a mechanical ownership threshold applied in the aggregate. OFSI and the EU apply a broader test that captures both ownership and control: an entity is caught if a listed person owns or controls it, and "control" extends beyond formal equity to practical direction of decisions. This means the same underlying fact pattern – a listed person holding, say, 35 percent of a target company with board influence – may be caught under OFSI and EU rules while falling outside OFAC's bright-line threshold.

For a business with a mixed counterparty book, the practical consequence is that a single screening exercise must run three distinct analytical tests simultaneously. A match against the Consolidated List prompts the question: which jurisdiction's rules govern, and does the entity's ownership or control structure push it into prohibition territory under any of them? Have you mapped that analysis for every counterparty that carries a potential connection to a listed person?

The position above describes the standard case. Your facts – the counterparty's structure, the jurisdiction of the transaction, the goods or services involved, and the regime most likely to assert jurisdiction – change the analysis materially.

For an initial assessment of your screening obligations and exposure under the UN and parallel regimes, contact Calder & Vance at info@caldervance.com.

What is the procedure for effective UN name and entity screening?

Effective UN name and entity screening is not a single-pass database check: it is a structured process with distinct stages, each of which requires documented decision logic.

The first stage is data preparation. The entity being screened must be identified with maximum specificity: legal name, all known aliases and trading names, jurisdiction of incorporation, and – critically – the ultimate beneficial owners and any intermediate holding structures. Incomplete identification at this stage produces false negatives that cannot be caught downstream.

The second stage is list matching. The Consolidated List, and the national implementing lists relevant to the transaction (SDN, UK Consolidated, EU lists), must all be queried. Fuzzy-matching logic should be applied to account for transliteration differences, name order variations, and intentional misspellings. Screening tools that rely on exact-string matching will miss entries where the listed name appears in a different script or a different transliteration standard.

The third stage is ownership and control mapping. Once a potential match is identified – or where a counterparty has any connection to a listed person – the ownership chain must be mapped to at least the ultimate beneficial owner level. The applicable thresholds (see above on OFAC, OFSI, and EU divergence) are applied in turn. This stage frequently reveals that the real exposure is not the direct counterparty but an intermediate entity two or three layers up the chain.

The fourth stage is escalation and decision. Where a credible match is confirmed, the business must freeze the relevant assets, notify the appropriate national authority within the applicable reporting window, and refrain from further dealings pending authorisation. Where a match is uncertain – a "possible hit" rather than a confirmed designation – the business must document its analysis, apply the appropriate standard of proof for that jurisdiction's rules, and reach a reasoned conclusion. That conclusion must be retrievable on demand.

The fifth stage is record-keeping. Compliance records relating to screening decisions must be maintained for the period required under the applicable national regime. In our experience, it is the record-keeping stage that most often fails an enforcement review: the decision was correct, but the audit trail is absent.

What are the risk flags that signal a screening programme is under-performing?

Screening programmes fail in predictable ways. Identifying the failure mode early is what allows a business to act before an enforcement authority does.

The first and most common risk flag is list currency. The Consolidated List is updated as the Security Council's committees act. National implementing lists – OFAC's SDN List, the UK Consolidated List, the EU restrictive measures database – are updated on their own schedules, sometimes with a short lag after the UN designation. A programme that refreshes its underlying data source infrequently will screen against a list that no longer reflects the current legal position. The gap between a UN designation and its reflection in all national implementing measures is precisely the window in which transactions proceed on the basis of outdated data.

The second risk flag is entity-level gaps. Many screening programmes are calibrated for individual persons. Entities – companies, vessels, aircraft – are structurally different: they have registration numbers, flag states, beneficial owners, and corporate histories that all feed into the matching logic. A programme that applies the same name-match algorithm to a company as it does to an individual will produce unreliable results for both.

The third risk flag is the failure to screen intermediaries. A payment that routes through a correspondent bank touches the correspondent's own screening obligations. A trade finance transaction involves the issuing bank, the confirming bank, the freight forwarder, the port agent, and the insurer – each with its own screening duty. A business that screens its direct counterparty but not the intermediaries in the chain creates exposure at every node it has not checked.

The fourth risk flag is unresolved possible hits. Screening tools generate alerts; not every alert is a confirmed match. A programme that closes alerts without documented, reasoned analysis – or that systematically overrides alerts without escalation – creates both legal risk and an audit-trail problem. In our experience, regulators reviewing a compliance programme pay close attention to how the business handles the space between "no match" and "confirmed match".

If a transaction has already been flagged, or a screening alert has been escalated internally without resolution, an early external review preserves options that narrow significantly as time passes. Contact Calder & Vance at info@caldervance.com for a confidential review.

How does UN screening interact with OFAC, OFSI, EU, and other parallel regimes?

The UN Consolidated List is the legally binding baseline for all implementing jurisdictions, but it is the narrowest layer of a business's actual screening obligation. OFAC, OFSI, and the EU Council each maintain additional designations that go beyond what the Security Council has listed. A person or entity can appear on the OFAC SDN List without appearing on the Consolidated List; a business that screens only against the UN list will miss that exposure entirely.

Extraterritorial reach compounds the analysis. OFAC's secondary-sanctions architecture means that a non-US business transacting with a non-listed person can still attract US enforcement attention if that person is connected to a listed programme in a way that implicates US correspondent relationships or US-dollar settlement. The practical consequence is that even a purely non-US transaction may require an OFAC-level review in addition to the UN-level check.

For businesses with operations or counterparties in Australia, Singapore, Canada, or the UAE, additional national regimes add further layers. Australia's autonomous sanctions regime, administered by DFAT, maintains its own consolidated list. Singapore's Monetary Authority issues notices that incorporate UN designations but also applies additional criteria. Canada's Global Affairs Canada administers sanctions regulations that incorporate UN measures alongside autonomous Canadian designations. Each regime has its own screening obligation, its own reporting window, and its own licensing route for authorised dealings.

The principle that applies across all of these is that the stricter prohibition governs. Where two regimes cover the same transaction and one imposes a broader prohibition than the other, a compliant business must satisfy both. There is no safe harbour in the fact that one regime would permit the dealing if another prohibits it.

In our cross-border practice, we regularly advise businesses that have calibrated their screening to one regime – typically OFAC or the EU – and have not assessed whether parallel UN obligations, or the obligations of a third-country regime, create additional exposure. The gap is rarely obvious until a transaction touches the wrong counterparty.

What common objections to specialist counsel are worth correcting?

There is a persistent belief among compliance teams that name and entity screening is a technology problem, not a legal one. The argument runs: buy a good screening tool, connect it to the right data sources, and the compliance obligation is met. This is the wrong framing.

Screening technology identifies potential matches. It does not determine whether a possible hit is a confirmed match under the applicable legal test. It does not apply the ownership-and-control analysis required by OFSI or the EU. It does not assess whether an intermediate entity in the counterparty's ownership chain is caught by the 50 percent rule. It does not determine which national regime governs, or whether an unresolved alert requires notification to a regulator. All of those determinations are legal judgments, and they are the determinations that enforcement authorities scrutinise when they review a compliance failure.

A second common objection is that the UN regime is less actively enforced than OFAC or OFSI, and therefore the consequences of under-investment in UN-specific screening are limited. The enforcement risk under the UN regime is indirect but real. Because every major national regime transposes UN designations, a failure to screen against the Consolidated List almost always means a failure to screen against the national implementing list as well. The enforcement action, when it comes, will cite the national regime – but the root cause will be the gap in UN-level screening.

We have acted for businesses that discovered their screening tool was checking the national implementing list but not the Consolidated List itself, creating a period of exposure between the UN designation date and the national list update. Closing that gap retroactively requires a documented look-back review and, in some cases, a voluntary disclosure to the relevant authority.

How does Calder & Vance assist with UN name and entity screening?

Our screening advisory work covers the full range of UN and parallel-regime obligations for cross-border businesses. We assist at every stage: from first-time programme design through to enforcement-driven look-back reviews.

For businesses building or redesigning a screening programme, we test the screening logic against the relevant list sources, map the ownership and control analysis required under OFAC, OFSI, and EU rules in parallel, and redesign the programme to the five-element standard that enforcement authorities use when assessing whether a compliance programme is adequate. We also advise on the specific additional requirements of the Australian, Singaporean, Canadian, and UAE regimes for businesses with exposure in those markets.

For businesses that have received an alert, a regulatory enquiry, or an internal escalation that cannot be resolved through the normal process, we scope the apparent issue, advise on voluntary self-disclosure where appropriate, and prepare the response or penalty defence. We work to the timelines that regulators set – which are short.

For M&A, trade-finance, and high-value commercial teams, we screen the counterparty and ownership chain, surface secondary-sanctions risk, and structure the transaction to manage the identified exposure. We do not advise on circumventing or evading sanctions.

In a recent matter, a financial institution identified a possible-hit alert on a corporate counterparty that its screening tool had flagged against a transliteration of a name on the Consolidated List. We reviewed the ownership chain, applied the ownership-and-control tests under each relevant regime, determined that the corporate was not caught, and produced a documented analysis the institution could rely on for its audit trail. The matter resolved without regulatory referral.

Related practices

Frequently asked questions

How long does set up effective screening take under UN?
Setting up effective UN-focused screening typically takes several weeks from initial scoping to a tested, operational programme. The timeline depends on the number of data sources being connected, the complexity of the business's counterparty book, and how many parallel national regimes need to be incorporated. A programme covering only the Consolidated List can be scoped quickly; one that integrates OFAC, OFSI, EU, and additional national lists alongside robust ownership-and-control logic requires more structured implementation and documented testing before it is relied upon for live transactions. Verify the current regulatory expectations before setting a programme timeline.
What are the main risks in name and entity screening under UN?
The main risks are: stale list data (screening against a Consolidated List that has not been refreshed since the most recent Security Council action); inadequate transliteration matching that misses aliases in different scripts; failure to map the ownership chain beyond the direct counterparty; and the absence of documented analysis for possible-hit alerts that were closed without a reasoned determination. Each of these failure modes is a finding that an enforcement authority can identify in a programme review, and each can support an adverse finding even where the underlying transaction was not a genuine sanctions violation.
Do we need specialist counsel for name and entity screening?
Specialist counsel is not required for routine screening of low-risk counterparties in a single jurisdiction. It becomes necessary – and, in our view, the prudent choice – in four situations: where a possible hit cannot be resolved through the normal internal process; where a counterparty's ownership chain involves intermediate entities that may fall within the ownership-and-control test of one or more regimes; where the business's screening programme is being reviewed by a regulator; and where the transaction is high-value or operates across multiple jurisdictions, each of which applies its own implementing measures and enforcement standards.
About the author
Renata Costa advises banks, payment firms, and virtual-asset businesses on sanctions screening, compliance-programme design, and financial-crime controls. Calder & Vance – International Sanctions & Export Control Counsel.
About Calder & Vance
Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.