Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFAC

Payment-processing controls under OFAC: specialist advice

A payments operations team at a mid-sized bank receives a wire-transfer instruction from a correspondent. The beneficiary name is a partial match against a name on OFAC's SDN List (the list of Specially Designated Nationals and blocked persons). The system holds the transaction. Within minutes, the compliance desk must decide: block it, reject it, or release it. That decision – and the underlying controls that shape it – sits at the centre of what payment-processing controls under OFAC legal support means in practice.

Payment-processing controls under OFAC are the policies, screening logic, escalation procedures, and record-keeping obligations that financial institutions and payment businesses must maintain to prevent prohibited transactions from being processed, transmitted, or settled. OFAC administers these requirements under the authority of IEEPA and other enabling statutes. A failure in any layer – inadequate screening, poor ownership analysis, or delayed reporting of blocked property – can constitute an apparent violation and trigger a civil enforcement action.

This page explains the legal basis for payment-controls obligations, how the OFAC standard compares with OFSI and the EU position, where businesses most often fail, and how Calder & Vance assists clients in building and testing the controls that matter.

What does OFAC require of payment processors and financial institutions?

OFAC prohibits US persons – and, in many programmes, non-US persons handling US-dollar transactions or US-correspondent relationships – from processing payments that involve a blocked person, a blocked country regime, or property in which a blocked interest exists. The obligation is not limited to the originator of the payment. It runs to any institution that transmits, clears, or settles the transaction.

That extraterritorial reach is the first thing most non-US clients miss. A European payment institution processing a US-dollar transaction through a US correspondent bank is handling that payment under US jurisdiction for the duration of its dollar leg. The OFAC prohibition applies at each hop along the chain. We regularly advise non-US payment firms who believed that OFAC was a concern only for US-licensed entities – and who discovered otherwise when a correspondent asked them to demonstrate their controls.

The core obligations cluster around three duties. First, the duty to screen: matching payment parties, their ownership chains, and relevant transaction fields against OFAC's lists before the payment is released. Second, the duty to block or reject: where a prohibited nexus is found, to stop the transaction, hold the funds (where the programme requires blocking rather than rejection), and not return the value to the originator without authorisation. Third, the duty to report and keep records: notifying OFAC within a short statutory window after blocking or rejecting, and retaining transaction documentation for a defined period.

None of these duties operates in isolation. A screening system that flags potential hits but has no documented escalation path is not a control; it is a process that creates records of inaction. In our experience, the gap most frequently identified in enforcement actions is exactly this one: a firm that screened adequately but then had no defensible decision logic for what to do next.

How does the OFAC standard compare with OFSI and EU requirements?

The OFAC standard diverges from the UK OFSI and EU positions in two technically significant ways: the ownership test and the treatment of rejected versus blocked payments.

Under OFAC, the 50 percent rule (the rule treating entities owned 50 percent or more by blocked persons in the aggregate as themselves blocked) applies as a bright-line mechanical test. If the ownership threshold is reached, the entity is treated as blocked regardless of who exercises control in practice. OFSI and the EU apply a broader ownership and control test: a non-listed entity can be caught not only because a designated person owns it but also because a designated person controls it – whether through majority shareholding, board appointment rights, contractual dominance, or other means. A payment to an entity that clears the OFAC threshold could still be caught in the UK or EU. The reverse is also true: an entity that a designated person controls but does not own at fifty percent is caught by OFSI and EU rules but is not automatically blocked under OFAC.

The second divergence is in how a prohibited payment is treated once identified. OFAC distinguishes between blocking – where value must be held in a segregated, interest-bearing account pending authorisation or licence – and rejection, where the transaction is turned away without holding the funds. Which treatment applies depends on which sanctions programme governs and whether the payment touches blocked property or simply a restricted counterparty. Under OFSI, the concept of a mandatory freeze and reporting obligation mirrors the OFAC blocking model, but the licensing architecture and the reporting window differ. Under the EU regime, national competent authorities administer freezing and have their own procedural requirements.

For a payment business with correspondent relationships across the US, UK, and EU, all three regimes apply simultaneously to a single transaction. A payment that is permissible under one regime can still be prohibited under another; the stricter prohibition governs the institution's decision. That layered exposure is why cross-regime payment-controls advice is not optional for any firm processing international value flows.

The position above covers the standard case. Your facts – the currency, the correspondent chain, the ownership structure of the counterparty, and the programme in play – change the analysis materially.

For an initial assessment of your payment-controls exposure under OFAC and across regimes, contact Calder & Vance at info@caldervance.com.

What are the main risk flags in OFAC payment-controls compliance?

The risk flags in payment-controls compliance fall into four categories: screening gaps, escalation failures, ownership analysis shortfalls, and record-keeping deficiencies. Each is independently actionable in enforcement.

Screening gaps are the most common entry point. They arise when a firm screens only the named principal parties and ignores nested ownership, when the screening system uses outdated list data, or when the matching algorithm is calibrated so loosely that it produces unmanageable false-positive volumes – which then leads staff to dismiss genuine hits to clear the queue. Effective screening covers the originator, the beneficiary, any intermediaries named in the payment, and the beneficial-ownership chain of each party. It also accounts for the specific list architecture of the programme in play: the SDN List, the Sectoral Sanctions Identifications List, and the Foreign Sanctions Evaders List each carry different legal consequences.

Escalation failures occur when a potential match is identified but there is no clear, documented procedure for who reviews it, what information they consider, what the decision criteria are, and how quickly the decision must be made. In a payment context, speed matters. Correspondent banks have cut-off times. A hold that is not resolved within the correspondent's window may be returned, creating a second exposure. In our experience, firms that have documented escalation matrices – with named roles, decision criteria, and time limits – handle these moments far more consistently than those relying on informal practice.

Ownership analysis shortfalls are particularly acute for payment firms that handle commercial payments on behalf of corporate clients. If the client's ultimate beneficial owner is a designated person, and the firm's onboarding documentation does not capture the full ownership chain to the required depth, the firm may process payments for a blocked entity without knowing it. That is not a defence; OFAC operates a strict-liability standard for many violations, meaning that the absence of knowledge does not by itself establish a mitigating factor sufficient to eliminate civil liability.

Record-keeping deficiencies close the loop. OFAC requires that blocked property records and transaction documentation be maintained for a defined period. Firms that cannot produce the original payment instruction, the screening result, the escalation decision, and the blocking or rejection record when OFAC requests them are materially disadvantaged in any subsequent examination or enforcement proceeding.

How does OFAC enforcement apply to payment-processing failures?

OFAC assesses apparent violations through a published framework that considers whether the conduct was egregious or non-egregious, whether it was voluntarily self-disclosed, and a range of aggravating and mitigating factors. The distinction matters enormously in practice.

A voluntary self-disclosure (VSD) – a proactive disclosure to OFAC before the agency has opened an inquiry – is formally recognised as a significant mitigating factor in determining both the penalty base and the enforcement response. In our cross-border practice, we advise clients to assess the VSD question as early as possible once a potential violation is identified, because the window within which a disclosure is treated as voluntary closes as soon as OFAC has independent notice of the conduct.

Aggravating factors that are particularly relevant to payment-controls cases include: a pattern of conduct rather than an isolated error; the processing of a high volume or high value of prohibited transactions; the concealment or non-reporting of blocked funds; and the failure to maintain or produce adequate records. Each of these maps directly onto one of the four risk-flag categories described above. A firm that has documented its escalation decisions and can demonstrate consistent screening practice is in a materially stronger position than one that cannot, even where the underlying violation is the same.

Does your institution know, today, whether its payment-controls documentation would withstand an OFAC examination? That question is worth answering before rather than after a hit is identified.

If a transaction has already been flagged, or a filing has been refused, an early review preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.

What is the procedure for addressing a potential OFAC payment-controls violation?

Where a payment institution identifies a potential OFAC violation – whether through internal audit, a correspondent query, or a direct approach from OFAC – the procedural response follows a defined sequence, and the order of steps affects the outcome.

The first step is scoping. Before any external communication, the institution needs to understand what happened: what transactions are in scope, over what period, involving which parties, under which programme. Scoping should be done under legal-professional privilege from the outset, and it should result in a documented scope memorandum that defines the population of potentially affected transactions.

The second step is legal analysis. Not every identified transaction will constitute an apparent violation. Some may be covered by a general licence (a standing authorisation that permits a defined category of transactions without a separate application). Others may involve parties that do not in fact meet the blocked-person standard. The legal analysis filters the scoped population to the set of transactions that carry genuine exposure.

The third step is the VSD decision. If the filtered population produces a credible apparent violation, the institution must decide whether to self-disclose and, if so, to whom and in what form. Where the transaction has a UK or EU dimension, there may be a parallel OFSI or national-competent-authority reporting obligation running on its own shorter timeline. The VSD strategy needs to account for all applicable regimes simultaneously.

The fourth step is remediation. OFAC expects that institutions self-disclosing or responding to an inquiry will simultaneously demonstrate that the underlying controls gap has been identified and addressed. A credible remediation plan – one that maps the root cause to a specific control enhancement – is a material mitigating factor. Submitting a VSD without a remediation plan leaves an institution exposed to a more adverse enforcement response.

In a recent matter, a non-US payment firm processing US-dollar commercial payments discovered that a small number of transactions had reached a beneficiary whose parent company was on the SDN List. We scoped the apparent violation, advised on the VSD filing, and prepared a remediation plan that included redesigned beneficial-owner screening and enhanced correspondent controls. The matter resolved without an enforcement action.

How do we assess and strengthen payment-processing controls?

Calder & Vance approaches payment-controls engagements through a structured assessment that moves from legal-standard mapping to gap identification to remediation design. The work is not generic compliance consulting; it is sanctions-specific legal analysis applied to the operational reality of how the client processes payments.

The assessment begins with a controls inventory. We review the client's screening configuration, list-management procedures, escalation matrices, ownership-verification protocols, and record-keeping practices against the OFAC standard and, where the client has correspondent relationships or operations in the UK or EU, against the OFSI and EU standards in parallel. We identify which controls are present and effective, which are present but untested, and which are absent.

The gap analysis produces a prioritised findings register. Not all gaps carry equal risk. A gap in screening for a high-volume, low-value retail payment stream carries a different risk profile than a gap in beneficial-owner verification for a low-volume, high-value correspondent payment. The register reflects this: it ranks findings by the likely enforcement consequence of a failure at that point, not alphabetically or by control category.

Remediation design translates the findings register into a control-enhancement plan. We specify what needs to change, in what sequence, and to what standard. Where the client requires a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) to continue processing a particular payment type during a transition period, we assess eligibility and prepare the application.

We also assist with the documentation that supports an institution's ability to demonstrate compliance in an examination or enforcement proceeding: escalation-decision logs, screening-parameter records, beneficial-owner certification standards, and record-keeping policy updates. The goal is that if OFAC asks for the file, the file tells a coherent and defensible story.

Common misconceptions about OFAC payment-processing obligations

A persistent misconception among non-US payment firms is that OFAC controls apply only to US-incorporated entities or US-licensed financial institutions. That belief is incorrect and, in the payment context, materially dangerous.

OFAC's jurisdiction extends to transactions processed in US dollars, transactions cleared through US correspondent banks, and transactions in which a US person participates at any stage. A payment institution incorporated in Singapore, Frankfurt, or Dubai that processes US-dollar payments through a US correspondent bank is subject to OFAC's requirements for the dollar leg of every transaction it routes through that correspondent. The correspondent's own OFAC compliance programme will typically include provisions that require the non-US institution to certify the adequacy of its own controls. Where that certification is absent or inadequate, the correspondent may terminate the relationship – an outcome known as de-risking (a financial institution exiting a relationship to avoid sanctions exposure), which is operationally damaging regardless of whether any violation has occurred.

A second misconception is that screening against the SDN List alone is sufficient. It is not. The Sectoral Sanctions Identifications List identifies entities subject to targeted prohibitions that differ in scope from the full blocking that applies to SDN-listed parties. The Foreign Sanctions Evaders List carries its own consequences. And the ownership rules – the fifty percent rule and the aggregation principles – mean that an entity not directly named on any list may still be treated as blocked. A screening programme that matches only listed names, without an ownership-chain analysis, is operating below the standard OFAC expects and below the standard that a credible internal audit should be willing to sign off on.

We regularly advise firms that have invested significantly in screening technology but whose legal analysis layer – the human, documented, decision-authority layer that sits above the system output – is absent or underdeveloped. Technology identifies; legal analysis decides. Both are required.

Related practices

Frequently asked questions

How long does controlling sanctions risk in payments take under OFAC?
The timeline depends on the scope of the engagement and whether a potential violation has already been identified. A controls-assessment and gap-analysis engagement for a mid-sized payment firm typically runs over several weeks, from initial inventory through to a prioritised findings register and a remediation plan. Where a VSD filing is required, the scoping, legal analysis, and submission preparation adds further time. An apparent-violation inquiry from OFAC has its own externally imposed response timeline. Early engagement with specialist counsel compresses the critical phases and prevents procedural errors that are difficult to correct later. Verify the applicable deadlines before relying on any estimate.
What are the main risks in payment-processing controls under OFAC?
The four principal risk areas are screening gaps (missed ownership-chain matches, outdated list data, or an algorithm calibrated to avoid false positives at the expense of genuine hits), escalation failures (a potential match identified but no documented decision path), ownership analysis shortfalls (failure to verify beneficial-owner chains at onboarding or during transaction processing), and record-keeping deficiencies (inability to produce transaction documentation, screening results, and decision records when OFAC requests them). Each is independently actionable. A fifth and underweighted risk is correspondent-relationship exposure: a non-US institution whose controls are deemed inadequate by its US correspondent faces de-risking as well as direct OFAC exposure.
Do we need specialist counsel for payment-processing controls?
General compliance consultants can map process flows and document procedures. Specialist sanctions counsel does something different: it applies the current OFAC legal standard to the specific facts of your payment types, ownership structures, and correspondent relationships, identifies the points at which your controls do not meet that standard, and produces analysis that is defensible before OFAC. In our experience, firms that engage specialist counsel after an enforcement inquiry rather than before it consistently face higher remediation costs, longer resolution timelines, and less favourable enforcement outcomes than those that address the controls analysis before a problem materialises. The question is not whether specialist counsel is needed; it is when in the process to bring them in.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.