Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Payment-processing controls under OFSI: specialist advice

A payment firm receives an inbound transfer. The originating account sits three layers behind a UK-designated person. The funds are already in the correspondent banking chain. Does OFSI require the firm to freeze them? Can any part of the transaction continue? Every second of uncertainty multiplies the risk.

Payment-processing controls under OFSI are the rules, procedures, and technical measures a payment business must maintain to detect, freeze, and report transactions that touch UK-designated persons or entities they own or control. The governing authority is the Office of Financial Sanctions Implementation, operating under powers conferred by the Sanctions and Anti-Money Laundering Act (SAMLA). A failure to freeze is a strict-liability criminal offence; intention is not a defence, and the civil penalty regime allows OFSI to impose significant monetary penalties even where no deliberate breach is shown.

This page sets out the legal basis for OFSI payment controls, explains the ownership-and-control test that extends obligations beyond the designated-persons list, describes the detection and freezing procedure, compares the UK position with OFAC and the EU, identifies the risk flags that most commonly produce enforcement exposure, and explains how Calder & Vance assists payment businesses in building controls that are demonstrably fit for purpose. As of August 2026, OFSI's enforcement posture remains active; recent penalty decisions have confirmed that procedural gaps, not only intentional breaches, attract civil sanctions.

What is the legal basis for OFSI's payment-processing obligations?

SAMLA is the primary statutory authority for UK financial sanctions, and it empowers the Treasury to make thematic sanctions regulations that impose the specific prohibitions applicable to each regime. Payment businesses are squarely within OFSI's regulatory perimeter. The prohibitions are not limited to banks: any person who processes, routes, or enables a financial transaction in the United Kingdom – or, in certain circumstances, where the transaction is denominated in sterling – can fall within OFSI's reach.

Three prohibitions are central to payment operations. First, the making available of funds or economic resources to or for the benefit of a designated person is prohibited. Second, the dealing in funds or economic resources owned, held, or controlled by a designated person is prohibited. Third, bypassing these prohibitions by routing through an intermediary or using a complex ownership chain does not cure the violation; OFSI applies an ownership and control test (the UK test for whether a non-listed entity is caught through a listed person's ownership or direction of it) that can extend liability well beyond the designated-persons list itself.

Understanding which regime covers a given transaction is not always straightforward. The thematic regulations – which address different designated populations – each carry their own schedules of prohibited conduct, and a payment firm operating across multiple payment corridors may be subject to obligations under several different instruments simultaneously. Practitioners advising on OFSI matters note that firms that treat OFSI as a single, undifferentiated list frequently under-screen because they apply only the consolidated UK sanctions list without checking the underlying regime-level prohibitions.

The position above covers the standard case. Your facts – the currencies involved, the correspondent chain, the jurisdictions of the parties, the thematic regime in play – change the analysis significantly. For a preliminary assessment of your payment-processing obligations under OFSI, contact Calder & Vance at info@caldervance.com.

How does the ownership-and-control test work for payment firms?

A payment directed to a company that a designated person owns or controls is treated as a payment to or for the benefit of that designated person, even though the company itself does not appear on the UK sanctions list. The UK ownership-and-control test is therefore the most operationally significant extension of payment obligations beyond the published list, and it is the area where firms most frequently discover gaps in their screening architecture.

Under SAMLA and the relevant thematic regulations, the test has two limbs. The ownership limb asks whether a designated person holds, directly or indirectly, more than 50 percent of the shares or voting rights, or the right to appoint or remove a majority of the board. The control limb is broader: it catches entities that a designated person can direct, either formally (by contract or agreement) or informally (through dominant influence over business decisions).

The control limb creates particular screening difficulty. It does not reduce to a fixed numerical threshold. Informal control can arise without a majority stake, without a formal board seat, and without documentation of the arrangement. In our experience, corporate-intelligence searches and enhanced due-diligence reports frequently surface the commercial reality of control – supply agreements on non-commercial terms, exclusive distribution arrangements, financing structures with subordination provisions – that standard company-registry checks miss entirely.

Compare this with the US position. Under OFAC, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) is mechanical and ownership-based; control alone does not trigger blocking if the ownership threshold is not met. The divergence matters acutely for payment firms with cross-border operations: a transaction involving a counterparty that clears the OFAC ownership test may still engage UK obligations through the control limb, or vice versa. EU sanctions regulations contain an analogous control test, making the UK and EU positions more closely aligned than either is with OFAC – though the precise scope of "control" has been interpreted differently across Member States.

What does a compliant payment-processing control programme require?

A compliant OFSI payment-processing control programme has five identifiable components, each of which OFSI expects a firm to be able to evidence on demand: screening against current lists, pre-transaction checks on ownership and control, a clear escalation and freeze procedure, timely reporting of frozen assets and of apparent violations, and record-keeping that supports a post-incident audit.

Screening must be conducted against the consolidated UK sanctions list and against any additional thematic-regime schedules relevant to the firm's payment corridors. List currency is a recurrent risk: the consolidated list is updated without advance notice, and a same-day designation can convert a queued, not yet settled, payment into a prohibited transaction. Firms that batch their screening checks on a daily or weekly cycle carry an interval during which a newly designated counterparty goes undetected.

Ownership-and-control checks require more than a list-match tool. The firm must have a process for enquiring into the beneficial ownership of counterparties above a defined threshold and for assessing whether any identified beneficial owner is designated. For high-risk corridors or higher-value transaction categories, a static check at onboarding is insufficient; periodic refresh is required because designation status changes.

The escalation procedure must be written, tested, and understood by all staff with payment-decisioning authority. The procedure must specify: who makes the freeze decision, on what authority, within what timeframe, and how the frozen funds are held and segregated. OFSI's guidance indicates that a frozen-asset report must be submitted promptly once a freeze is applied, and that a report of a suspected violation carries its own separate obligation. Missing the reporting window is itself a breach, independent of the underlying transaction question.

Record-keeping obligations under OFSI and SAMLA require firms to retain documentation of the screening results, the ownership-and-control analysis, the escalation decision, and any communication with OFSI for a defined period. Verify the current retention period against OFSI's published guidance before relying on any specific figure, as the applicable period may be set in the thematic regulations rather than in SAMLA itself.

Where do payment firms most often incur OFSI enforcement exposure?

Most enforcement exposure in payment operations does not arise from deliberate violations. It arises from three procedural gaps that OFSI consistently identifies in its published enforcement materials: screening that is not calibrated to the right population, escalation procedures that exist on paper but have not been tested under realistic conditions, and a reporting cycle that operates on a delay that OFSI considers too slow.

The first gap – screening population – affects firms that operate across multiple jurisdictions and have not separated their UK-obligations screening from their broader AML or group-wide screening. A tool tuned to OFAC's SDN List, or to the EU's consolidated list, may miss designations that are specific to the UK list. The UK, the EU, and the US have maintained broadly aligned designations in major thematic regimes, but divergences exist, and a firm that relies on one list as a proxy for the others carries a structural screening gap.

The second gap – escalation procedures – produces some of the most avoidable enforcement outcomes. In our cross-border practice, we regularly find that a firm's written procedure specifies one escalation chain while day-to-day operations have evolved a different, informal one. When OFSI investigates, it maps the actual process against the documented one, and the discrepancy itself becomes evidence of a control failure. Procedure testing – a structured simulation of a screening hit and the steps that follow – is the only reliable check on whether the documented procedure reflects operational reality.

The third gap – reporting timing – reflects the tension between a firm's internal investigation cycle (which typically runs through legal, compliance, and senior management before a report is made) and OFSI's expectation that a report follows promptly after a firm has reasonable grounds to suspect a violation. Firms that run extended internal reviews before reporting can find that what would have been treated as a voluntary disclosure, attracting mitigation, is re-characterised as a delayed report.

If a transaction has already been flagged, or a freeze has been applied and a report has not yet been made, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.

How does OFSI's approach compare with OFAC and the EU on payment controls?

OFSI, OFAC, and the EU each require payment businesses to maintain effective financial-sanctions controls, but the architecture of those controls differs across regimes in ways that matter for multi-currency payment firms.

OFAC operates a strict blocking regime for US persons and for dollar-denominated transactions touching US correspondent banks. The 50 percent ownership rule is the primary extension mechanism; the control test plays a secondary role. OFAC's general licences (standing authorisations permitting defined categories of transactions without a separate application) are more numerous and operationally important than their UK equivalents. A payment firm processing dollar flows must comply with OFAC requirements independently of its OFSI obligations. The two regimes can bite simultaneously on the same transaction: a payment denominated in US dollars between two non-US parties, if routed through a US correspondent, engages OFAC; if one party is UK-designated, it also engages OFSI.

The EU regime requires payment firms established in EU Member States, or processing Euro-denominated transactions, to screen against the EU's consolidated list and apply the ownership-and-control test set out in the relevant Council regulations. The EU General Court has adjudicated numerous challenges to designations and has interpreted the ownership-and-control test in ways that broadly align with the UK position. However, Member-State implementation varies, and a firm operating across several EU jurisdictions may face different national-level procedural requirements on top of the common EU rules.

For a payment firm operating across UK, US, and EU payment corridors, the practical implication is that a single set of controls designed to the most stringent applicable standard on each element – list currency, ownership analysis, reporting timing – will generally satisfy all three regimes. But the design requires a regime-by-regime mapping: extrapolating from one regime to the others produces gaps precisely at the points where the regimes diverge. Experience before OFSI and in advising on OFAC and EU-regulation matters indicates that the cross-border interaction between these regimes is where multi-jurisdiction payment businesses most commonly discover that their controls, which passed a single-regime audit, leave them exposed.

A common myth: full OFSI compliance is achieved by screening the consolidated list

A persistent misconception among payment firms is that maintaining a current match against the UK's consolidated sanctions list is the whole of the OFSI compliance obligation for payment processing. It is the starting point, not the end point.

The consolidated list contains designated persons. It does not contain the full range of entities that a payment firm is prohibited from dealing with. The ownership-and-control test extends that prohibition to any entity a designated person owns or controls – and those entities are not listed anywhere. Identifying them requires active enquiry into counterparty ownership structures, not a list match.

Furthermore, the prohibitions imposed by the thematic regulations extend to transactions "for the benefit of" a designated person, which is a wider concept than a direct payment to a named entity. A payment that funds a designated person's lifestyle, satisfies a debt owed to a designated person, or enables a business over which a designated person has informal control can all engage the prohibition, even if the immediate payment counterparty does not appear on any list. In our practice, firms that discover this gap after an enforcement enquiry begins find that the list-only screening approach is very difficult to defend as a reasonable compliance programme.

Related practices

How Calder & Vance assists payment businesses on OFSI payment-processing controls

We act for payment institutions, e-money businesses, correspondent banks, and payment processors at every stage of the OFSI compliance cycle. Our work is specific and action-oriented rather than advisory in the abstract.

For businesses building or redesigning their payment-processing control architecture, we test the screening logic against the correct population (UK consolidated list plus thematic-regime schedules), map the ownership and control of high-risk counterparties, and redesign the escalation procedure and reporting chain to align with OFSI's published expectations. Where a firm's controls have never been formally tested under simulated-hit conditions, we design and run that test and document the outcomes in a form that can be produced to OFSI if needed.

For businesses that have identified a potential issue – a screening miss, a payment that should have been frozen, a reporting window that has been missed – we scope the apparent violation, advise on whether a voluntary self-disclosure (VSD) (voluntary self-disclosure to OFSI as the regulator) is appropriate and what it should contain, and prepare any penalty defence documentation. We also advise on the interaction between OFSI reporting obligations and parallel reporting obligations to the firm's prudential supervisor or financial-intelligence unit, which can pull in different directions on timing.

In a recent matter, a mid-size payment processor identified, during an internal review, that a series of transactions had been processed without adequate ownership-and-control checks on a counterparty subsequently found to have been owned by a UK-designated person. We scoped the full transaction history, assessed the enforcement exposure under OFSI's civil-penalty guidance, prepared a voluntary self-disclosure package, and managed OFSI's enquiries through to resolution. The matter closed without the firm being required to accept the full penalty sought in OFSI's initial assessment, reflecting the mitigation credit OFSI gave for early and complete disclosure.

We also advise on the cross-regime interaction described above: where a payment firm's obligations under OFSI, OFAC, and the EU Council regulations pull in different directions on the same transaction type, we map the applicable rules, identify the most stringent requirement on each control element, and document the resulting control standard in a form that is auditable across all three regimes.

What can you do right now? If your payment-processing controls have not been tested against a live-fire simulation of an OFSI screening hit in the last twelve months, that is the first question to answer. To discuss an assessment of your programme, or to obtain support on an existing enforcement matter, write to Calder & Vance at info@caldervance.com.

Frequently asked questions: OFSI payment-processing controls

How long does control sanctions risk in payments take under OFSI?

There is no single statutory timetable for an OFSI compliance review, because the scope depends entirely on the firm's payment corridors, counterparty volumes, and existing control architecture. A targeted gap-analysis for a single payment corridor can be completed within a few weeks. A full programme review – covering list-screening calibration, ownership-and-control mapping, procedure testing, and reporting-chain documentation – typically runs over a period of several weeks to a few months. Enforcement investigations that follow an apparent breach operate on OFSI's own timetable, which can extend considerably beyond the firm's initial disclosure, particularly where OFSI seeks supplementary information. Early engagement with specialist counsel shortens the response cycle at every stage.

What are the main risks in payment-processing controls under OFSI?

The three most significant risk areas are: (1) screening that is calibrated only to the consolidated list and misses entities caught by the ownership-and-control test; (2) escalation procedures that have not been stress-tested and therefore break down on the first live screening hit; and (3) delayed reporting to OFSI, which converts a potentially mitigated voluntary disclosure into a late report that OFSI treats as an aggravating factor. A secondary but growing risk is the interaction between OFSI obligations and obligations under OFAC or EU Council regulations on the same transaction – firms that optimise for one regime while ignoring the others carry structural exposure at the points of divergence between them.

Do we need specialist counsel for payment-processing controls?

For a straightforward controls review at a firm with limited exposure and well-tested procedures, an in-house team with strong sanctions expertise may be sufficient. However, specialist external counsel adds clear value in four situations: where the firm operates across multiple payment corridors subject to different regimes simultaneously; where a potential enforcement matter has been identified; where the firm is designing its controls for the first time or substantially redesigning them after a screening failure; and where the cross-regime interaction between OFSI, OFAC, and EU rules is a live operational issue. In each of these situations, the cost of a mis-step – a late report, an inadequate VSD, a control architecture that fails an OFSI examination – substantially exceeds the cost of early specialist advice.

About the author

Renata Costa advises banks, payment firms, and virtual-asset businesses on sanctions screening, compliance-programme design, and financial-crime controls. Calder & Vance – International Sanctions & Export Control Counsel.

About Calder & Vance

Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.

Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.