A payments operations manager at an Asia-Pacific trading group is reviewing a batch of outgoing transfers. One beneficiary is incorporated in a jurisdiction subject to Australia's autonomous sanctions regime. A second payment routes through a correspondent bank that screens against the DFAT Consolidated List. The first transaction clears internal screening. The second is returned with a compliance query. Both involve the same underlying counterparty – but the controls that stopped one and passed the other are doing different things. Understanding why is the starting point for any serious review of payment-processing controls under Australia.
Payment-processing controls under Australia's autonomous sanctions regime are governed by the Autonomous Sanctions Act and administered by the Department of Foreign Affairs and Trade (DFAT). Businesses processing payments must screen counterparties, payment channels, and underlying transactions against the DFAT Consolidated List and any applicable thematic or country-specific sanctions regulations. Failure to do so exposes the firm – and responsible individuals – to civil and criminal penalties.
This page sets out the legal basis for Australia's payment-screening obligations, the practical steps required to meet them, where the Australian regime diverges from OFAC, OFSI, and the EU, and when specialist compliance counsel adds measurable value.
What does Australia's autonomous sanctions regime require of payment processors?
Australia's autonomous sanctions regime prohibits the direct or indirect use of sanctioned assets, as well as dealings with designated persons and entities, including the processing of payments on their behalf or for their benefit. DFAT publishes and maintains the Consolidated List of designated persons and entities. Any business processing payments through Australian-nexus accounts, Australian-regulated institutions, or AUD-denominated transfers must screen against that list before processing.
The obligation is not limited to banks. Payment processors, money-transfer businesses, e-money institutions, virtual-asset service providers, and any firm that instructs, clears, or settles a payment through the Australian financial system carries the same screening duty. The practical scope is wider than many compliance teams assume: a non-bank fintech processing merchant settlements in Australian dollars is within scope, even if the individual transfers are small in value.
Screening alone is not sufficient. The regime also requires that a business not facilitate a sanctioned transaction indirectly – meaning that beneficial ownership and the ultimate purpose of a payment are relevant to compliance. A transfer that appears clean at the counterparty level but ultimately benefits a designated person is still a breach. In our experience, this is the gap most often missed during technology-led screening implementations: the tool matches the named payee, but does not interrogate the payment purpose or the ownership chain behind the beneficiary.
How is the ownership and control test applied in Australian payments screening?
Australia's thematic sanctions regulations adopt an ownership and control test (the assessment of whether a non-listed entity is effectively controlled by or for the benefit of a designated person) that looks at both formal ownership and practical control. A payment to an entity that is wholly owned by a designated person is prohibited, even if the entity itself does not appear on the DFAT Consolidated List. This is structurally similar to the approach under OFSI and the EU, but differs from OFAC's purely mechanical 50 percent rule (OFAC's rule that treats any entity 50 percent or more owned by blocked persons as itself blocked regardless of control).
The divergence matters. Under OFAC, ownership below 50 percent does not automatically block an entity, though control is assessed separately in certain programmes. Under OFSI and the EU, a lower ownership stake combined with effective control is sufficient to trigger the prohibition. Australia's position sits closer to the OFSI/EU model. In practice, this means that a payment cleared by a US correspondent under OFAC rules may still be prohibited under Australian law if a designated person exercises practical control over the beneficiary – and vice versa.
What does this mean for a payments compliance team? It means that the screening logic and the ownership-mapping workflow must be calibrated to each applicable regime, not simply to the most restrictive threshold. A business subject to both OFAC and Australian obligations needs a combined ownership-and-control analysis for high-risk counterparties, not a sequential tick-box exercise. We regularly advise payments firms on how to structure that combined review without creating duplicative work or false assurance.
What is the practical payment-screening process under the Australian regime?
The screening process under the Australian regime should follow a defined sequence, applied at onboarding, at the point of payment instruction, and on a periodic basis as the DFAT Consolidated List is updated.
- List screening: Screen the counterparty, the beneficiary, and any intermediaries named in the payment instruction against the current DFAT Consolidated List. DFAT updates the list regularly; static snapshots create compliance gaps.
- Ownership and control check: For any counterparty that is a legal entity, verify the ownership chain. Identify any direct or indirect holding by a designated person. Apply the ownership-and-control test to non-listed entities in the chain.
- Purpose and benefit review: Assess the stated and likely purpose of the payment. Identify whether the transaction would, in substance, benefit a designated person even if the nominal counterparty is clean.
- Match review and escalation: Any positive or potential match must be escalated immediately. The payment must be held pending a legal review. Processing a payment while a match is under investigation may itself constitute a breach.
- Reporting: Where a firm identifies or reasonably suspects that it holds or has processed sanctioned funds, it is required to report to the relevant authority. The reporting window under the Australian regime is short; legal advice should be obtained promptly once a potential breach is identified.
- Record-keeping: Maintain records of screening decisions, escalations, ownership-analysis outputs, and reporting actions. The applicable record-keeping period under Australian sanctions obligations is material to any subsequent enforcement review.
The position above covers the standard case. Your facts – the counterparty, the payment route, the regime in play, and whether you have nexus to other jurisdictions – change the analysis. For a structured review of your current payment-processing workflow, contact Calder & Vance at info@caldervance.com.
How does the Australian regime compare with OFAC, OFSI, and EU payment obligations?
Cross-border payment processors rarely face a single regime. A firm processing AUD payments from a London treasury operation with US dollar clearing faces Australian, UK, and US obligations simultaneously. The obligations do not always align.
Under OFAC, the primary nexus test is US-person involvement and USD clearing. A non-US firm processing a payment outside US channels with no US-person involvement may fall outside OFAC's reach – though secondary-sanctions risk in certain programmes can extend that reach significantly. OFAC's ownership threshold is 50 percent or more in the aggregate; control is assessed separately under specific programme guidance.
Under OFSI, a UK nexus (a UK-regulated firm, sterling clearing, a UK-resident party) triggers the obligation. The control test is broader than OFAC's ownership rule: OFSI can find a non-listed entity subject to the prohibition where a designated person exerts practical control, even below a 50 percent stake. The EU position is substantively similar. Australia aligns more closely with the OFSI/EU approach to control, which means that US-cleared transactions may carry residual Australian-law risk if the beneficiary structure involves designated-person control.
The cardinal compliance principle in cross-regime work is this: where two applicable regimes diverge, the stricter prohibition governs the business's conduct. A payments compliance team should not assume that clearance under one regime confers protection under another. We have acted for payments firms that have relied on US-correspondent clearance as de facto compliance sign-off – only to face questions from Australian or UK authorities about the same transaction.
Switzerland (SECO), Canada (under the relevant autonomous regime administered by Global Affairs Canada), and Singapore also maintain payment-related sanctions obligations that can apply to cross-border transfers depending on the routing and the parties. For a business with regional payment operations, the multi-regime picture is the baseline; single-regime analysis is a starting assumption, not a finishing point.
If a transaction has already been flagged, or a payment has been returned by a correspondent with a compliance query, an early review preserves options that narrow with time. Contact our team at info@caldervance.com.
What are the primary risk flags for payment-processing controls under the Australian regime?
Payment-processing risk under Australia's autonomous sanctions regime clusters around five recurring patterns. Identifying them early is the difference between a manageable compliance issue and an enforcement referral.
- Nested payment structures: Payments routed through an intermediary that is not itself designated, but that is owned or controlled by a designated person. The intermediary clears screening; the underlying beneficiary does not.
- Stale or partial list coverage: Screening against a list snapshot that has not been refreshed after a DFAT designation update. Designated persons added to the list after the last system update will not be caught.
- Purpose-blind matching: Screening logic that flags the counterparty name but does not assess the purpose or the ultimate beneficiary of the payment. A clean payee can be a conduit.
- Correspondent-bank reliance: Treating a correspondent bank's acceptance of a payment as evidence of sanctions compliance. Correspondents screen for their own obligations; their clearance does not satisfy the originating firm's separate duty.
- Incomplete ownership data: Onboarding processes that collect legal-entity data but do not refresh it. Ownership structures change. A counterparty that was clean at onboarding may be controlled by a designated person two years later.
A recurring issue in our practice is the gap between what a firm's written screening policy requires and what its technology actually executes. A policy that mandates ownership-chain analysis is not satisfied by a tool that screens only the payee name. The gap between policy and practice is frequently what enforcement reviews expose.
What is commonly misunderstood about Australian payment-screening obligations?
A widely held assumption in payments compliance is that Australia's regime is materially less demanding than OFAC or OFSI, and that resources should be directed primarily toward US and UK compliance. This misreads the Australian regime.
Australia's autonomous sanctions regulations carry criminal penalties for individuals and significant civil exposure for entities. The regime is not confined to a narrow list of designated states; it includes individuals and entities across a range of thematic programmes, and the DFAT Consolidated List is updated as global sanctions positions evolve. Firms that maintain a US-first compliance posture often find, when the question is properly examined, that their Australian-nexus payment flows have never been subjected to a systematic screening review calibrated to DFAT's actual list and the ownership-and-control test the regime applies.
A second misconception is that small-value payments carry low sanctions risk. Under the Australian regime, there is no de minimis exception to the prohibition on dealing with a designated person. A small payment to a controlled entity is no less a breach than a large one. Enforcement attention may focus on the larger transactions, but the legal exposure does not scale with payment size.
In our experience, firms that revisit these assumptions during a structured compliance audit regularly identify gaps they were not aware of – and are better positioned to close them before those gaps attract regulatory attention.
How does Calder & Vance assist with payment-processing controls under the Australian regime?
Our team provides targeted legal and compliance support across the full lifecycle of a payment-processing controls engagement under the Australian autonomous sanctions regime.
For firms building or revising their screening programme, we assess the current screening logic, map the ownership-and-control methodology against Australian regime requirements, and identify gaps between written policy and operational practice. We design or review the escalation workflow, the match-review procedure, and the reporting protocol.
For firms with an active compliance question – a potential match, a returned payment, or a correspondent query – we scope the apparent issue, advise on immediate steps, and assess whether a voluntary report to DFAT is required and, if so, how to structure it.
Where a business operates across multiple regimes, we provide a cross-regime analysis that maps the Australian obligation alongside OFAC, OFSI, EU, and other applicable regimes. We identify where the obligations diverge and advise on the combined compliance posture that satisfies the stricter standard in each area.
We also advise on the interaction between payment-processing controls and broader sanctions due diligence in the context of M&A, trade finance, and correspondent banking relationships. Sanctions risk in payments does not sit in isolation; it connects to onboarding, transaction monitoring, and counterparty review. Our team works across those boundaries. To discuss a structured review of your payment-screening programme, contact Calder & Vance at info@caldervance.com.
Related practices
- Compliance audit and testing – Australia – structured review of screening logic and programme gaps under DFAT obligations
- Payment-processing controls – BIS/EAR – US export-control considerations for payment and settlement flows
- Payment-processing controls – Canada – autonomous-sanctions screening obligations under the applicable Canadian regime