Category: Burning Questions

  • Sanctions practitioners routinely face three intertwined licensing problems: general licenses that overlap, authorizations that expire on hard deadlines, and the question of when a specific license is still required on top of a general one. Each reflects a core principle – an OFAC general license authorizes only what its text says, and nothing more.

    Overlapping general licenses

    A general license (GL) authorizes a category of transactions without any individual application to OFAC. Overlap arises when more than one GL could bear on the same transaction, and the practitioner must confirm which applies and whether each one’s conditions are satisfied.

    The Russia program shows how GLs interlock. Russia-related GL 6D authorizes transactions related to the production, sale, transport, or provision of agricultural commodities, medicine, and medical devices. It is notable because, unlike most agricultural/medical authorizations, it is designed principally to permit these dealings even where an otherwise-blocked person is involved – clearing the blocked-counterparty obstacle for humanitarian-type goods.

    But GL 6D’s reach is bounded by its own paragraph (c), which excludes several things even for otherwise-covered goods: opening or maintaining a correspondent or payable-through account for any entity subject to Directive 2 under E.O. 14024; any debit to a U.S.-institution account of the Central Bank of the Russian Federation, the National Wealth Fund, or the Russian Ministry of Finance; and transactions prohibited by E.O. 14066, 14068, or 14071 (subject to narrow carve-outs). So an authorized medical-device sale whose payment leg runs through a Directive 2 correspondent account is not cleared by GL 6D alone – that leg needs its own authorization. OFAC reinforces the point in its guidance: the agricultural/medical authorizations do not extend to prohibitions applied to persons sanctioned under other OFAC authorities.

    The practice point is that general licenses are not additive by default. Each authorizes only what its text says, subject to its own conditions and exclusions. Where a transaction has two problematic features – a blocked counterparty and an excluded payment channel, or a second program’s designation – each feature needs its own authorization.

    Expiring authorizations

    Many general licenses, particularly wind-down authorizations, carry hard expiration dates and times. OFAC’s standard convention is 12:01 a.m. eastern on the stated date. Once that moment passes, the transaction reverts to prohibited unless another authorization applies.

    The June 12, 2024 designation of Russia’s core financial-market infrastructure illustrates the mechanics, including how staggered the deadlines can be. Alongside blocking a group of entities, OFAC issued a cluster of wind-down GLs:

    • GL 98 authorized wind-down of transactions involving the entities blocked that day, through 12:01 a.m. EDT on July 27, 2024.
    • GL 99 and GL 100 authorized wind-down, divestment, and related debt/equity transactions involving MOEX, NCC, and NSD, through August 13, 2024.
    • Those two were subsequently extended by GL 99A and GL 100A to October 12, 2024.

    A payment authorized the day before a GL’s deadline is prohibited the day after; the authorization does not roll over. Because these deadlines do not move in lockstep – GL 98 expired more than two weeks before GLs 99 and 100 – practitioners track each separately.

    The practice point is that wind-down GLs authorize the termination of pre-existing dealings, not new business. OFAC has been explicit that wind-down activities do not include the continued processing of funds transfers, securities trades, or other transactions involving a blocked person that were part of ongoing business prior to the imposition of sanctions, unless separately authorized.

    When a specific license is still required “on top”

    The clearest illustration of a specific license required on top of a general one comes from the Trade Sanctions Reform and Export Enhancement Act of 2000 (TSRA) framework in the Iranian Transactions and Sanctions Regulations (ITSR), because the residual specific-license requirement is written into the licensing architecture itself rather than triggered by an exception.

    Section 560.530 of the ITSR sets out a favorable general license for the export and reexport of agricultural commodities, medicine, and medical devices to Iran. But the general license does not stand alone – its own text conditions the authorization. The export is authorized provided that, unless otherwise authorized by specific license, payment terms and financing are limited to, and consistent with, those authorized by § 560.532.

    Section 560.532, in turn, generally authorizes only a defined menu of payment mechanisms: cash in advance; sales on open account (where the receivable is non-transferable); financing by non-U.S., non-Iranian third-country financial institutions (which U.S. institutions may confirm or advise); or a letter of credit issued by an Iranian financial institution whose property is not blocked. A practitioner who needs payment or financing terms outside that menu is not covered by the general license – and a specific license is required on top of the general authorization that already covers the goods.

    The same structure recurs across the agricultural/medical provisions. Under § 560.533, brokering is authorized only where the underlying sale is itself authorized, either by a one-year specific license under § 560.530(a)(1)(i) or by one of the general licenses in § 560.530(a)(2), (a)(3), or (a)(4); brokering by U.S. persons on behalf of non-U.S., non-Iranian persons may be permitted only by case-by-case specific license. Sections 560.530, 560.532, and 560.533 are meant to be read together: one governs the export, one the payment and financing, one the brokering.

    A separate dimension is cross-agency. An OFAC authorization does not resolve a licensing requirement administered by another federal agency. OFAC says so in the licenses themselves – the note to Russia-related GL 25D, for instance, states that nothing in the general license relieves any person from compliance with the export, reexport, and transfer licensing requirements maintained by the Department of Commerce’s Bureau of Industry and Security under the Export Administration Regulations. An OFAC GL and a BIS/EAR authorization are distinct; satisfying one does not satisfy the other.

    The practice point is that a general license never obligates OFAC to grant a related specific license. OFAC evaluates specific-license applications case-by-case against the relevant program’s stated licensing policy.

    The common thread

    All three problems reduce to the same discipline: read the general license against the specific transaction, feature by feature. Identify every prohibited element – the counterparty, the goods, the payment channel, the timing, the agency whose rules are implicated – and confirm that some authorization covers each one. A general license that resolves one obstacle does not resolve the others, its authorization ends when its text says it ends, and where the license’s own terms carve out a category, the specific-license process is the path.


    Sources: 31 CFR §§ 560.530, 560.532, 560.533 (ITSR); Russia-related General Licenses 6D, 8J, 25D, 98, 99, 100 (89 FR 65994, Aug. 14, 2024) and 99A/100A; OFAC Russian Harmful Foreign Activities Sanctions FAQ topic page.

  • My initial prompt to Claude (had to re-orient its audience and remind it not to include anything related to ownership):

    First, look at the “ownership and control” regulations and guidance across the major sanctions regulators, including the US, UN, EU, UK, Switzerland, Canada, Australia, Singapore, New Zealand and Japan. Provide a list of what these regulators say constitutes “control” – don’t need to know differences between them, just give me a comprehensive list. Secondly, tell me how one would identify these elements of “control” in one’s research, including any commercial providers of such information. Check your work against your sources – identify anything in the response not supported by the sources, and then correct them. Finally, list your sources.

    and the final response:

    The control problem, in one paragraph

    Ownership is arithmetic. Control is judgment. Every major regime that extends sanctions beyond the named party does it through some version of “owned or controlled” – and while the ownership half has converged on a 50% math problem, the control half is where the regimes actually diverge, where the screening tools run out, and where the interesting compliance work lives. One clarification up front on the US: OFAC’s 50 Percent Rule speaks only to ownership and not to control – an entity controlled but not majority-owned by blocked persons is not automatically blocked, though OFAC may designate it and urges caution when dealing with entities that blocked persons control by means other than majority ownership. So for the US, control is a designation-risk and prudence question, not a legal test you apply yourself. Everywhere else below, it’s a test you apply yourself. Office of Foreign Assets Control

    And a status change that most compliance programs haven’t caught up with: for a decade, the EU’s control criteria lived only in non-binding Council guidance. As of 23 October 2025, they’re law. Council Regulation (EU) 2025/2037, part of the 19th Russia package, amended Regulation 269/2014 on the reasoning that it is appropriate to harmonise terminology across Union legal acts, that such coherence is essential to avoid ambiguity, enhance legal certainty and ensure the effectiveness of Union restrictive measures across various sanctions regimes, and that it is therefore appropriate to include in Regulation 269/2014 definitions of “owning” and “controlling” a legal person, entity or body, aligned with the definitions used in Regulation (EC) No 2580/2001. The control criteria quoted below are now Article 1(j) of the EU’s flagship asset-freeze regulation – directly applicable law in 27 member states. Global Investigations Review

    Part 1: What counts as “control” – the master list

    Pulling from the primary texts of the EU, UK, Canada, and Switzerland, plus the fact-based standards in Australia, Singapore, New Zealand, and the UN resolutions, here is everything the regulators say can constitute control without majority ownership.

    Voting power without equity

    • Now codified as Article 1(j)(iii) of Regulation 269/2014: controlling alone, pursuant to an agreement with other shareholders in or members of a legal person, entity or body, a majority of shareholders’ or members’ voting rights in that legal person, entity or body. The same concept appears in OFSI’s guidance examples. The point: a shareholder pact can hand someone majority voting power their share certificate doesn’t show. Global Investigations Review
    • Switzerland’s version drops the shareholder-agreement qualifier and adds two words that do a lot of work: per SECO FAQ 1.11(b), control exists where the person holds, formally or de facto, the majority of the voting rights of the company or organisation – with a footnote explaining that “de facto” includes acting through a straw person (Strohperson). SECOSECO
    • The UK counts majority voting rights under its first condition, and its Schedule 1 quietly extends the concept to entities that don’t vote at all: in relation to a person that does not have general meetings at which matters are decided by the exercise of voting rights, a reference to holding “more than 50% of the voting rights” is to be read as a reference to holding the right under the constitution of the person to block changes to the overall policy of the person or to the terms of its constitution. Read that again: for foundations, trusts-adjacent structures, and anything else without a general meeting, a blocking right is deemed equivalent to majority voting control. Schedule 1 also strips out treasury shares – voting rights in a person are to be reduced by any rights held by the person itself – which can push a designated holder over the line without them acquiring a thing. Legislation.gov.ukLegislation.gov.uk
    • Canada folds voting rights into its 50% prong rather than treating them as a separate control criterion.

    Board power

    • Article 1(j)(i): having the right or exercising the power to appoint or remove a majority of the members of the administrative, management or supervisory body of a legal person, entity or body. The UK’s first-condition version, from regulation 7(2)(c) as enacted: the person holds the right directly or indirectly to appoint or remove a majority of the board of directors of C. Global Investigations ReviewLegislation.gov.uk
    • The EU adds a backward-looking variant most people miss, Article 1(j)(ii): having appointed solely as a result of the exercise of one’s voting rights a majority of the members of the administrative, management or supervisory bodies who have held office during the present and previous financial year. Track record of appointments counts, not just the right on paper. Global Investigations Review
    • The UK legislation defines its board terms with unusual precision in Schedule 1: the right to appoint or remove a majority of the board means the right to appoint or remove directors holding a majority of the voting rights at board meetings on all or substantially all matters; where a person has no board, read it as the equivalent management body; and a person is treated as having the right to appoint a director if any person’s appointment as director follows necessarily from their appointment as a director of that person. A board seat that comes automatically with a parent-company directorship counts. Legislation.gov.ukLegislation.gov.uk
    • Canada’s board prong is the broadest in the world: the person is able, directly or indirectly, to change the composition or powers of the entity’s board of directors – SEMA s. 2.1(2)(b), verbatim from the consolidated statute. No “majority” qualifier at all. Commentators have flagged that read literally, the ability to appoint even one director out of many could arguably mean the person can “change the composition” of the board. Justice Laws WebsiteDentons
    • Switzerland, FAQ 1.11(a): the person can formally or de facto appoint and/or remove the majority of the members of the administrative or management body. SECO

    Dominant influence – contractual, de facto, and (in Switzerland) creditor-based

    • Article 1(j)(iv): having the right to exercise a dominant influence over a legal person, entity or body, pursuant to an agreement entered into with that legal person, entity or body or to a provision in its Memorandum or Articles of Association, where the law governing that legal person, entity or body permits its being subject to such agreement or provision. Control written into the corporate documents themselves. Switzerland mirrors this at FAQ 1.11(c). Global Investigations Review
    • And its shadow twin, Article 1(j)(v): having the power to, de facto, exercise the right to exercise a dominant influence referred to in point (iv), without being the holder of that right. This is the criterion that captures the person who sold the shares but still runs the show. One drafting note: the Best Practices version of this criterion carries a footnote – “including, for example, by means of a front company” – which the codified regulation text does not reproduce; the guidance example survives as interpretive color rather than statutory text. Switzerland’s FAQ 1.11(d) is the same provision, footnoted to the straw-person example. Global Investigations ReviewEuropean Union
    • Here’s one the law firm summaries missed entirely – SECO FAQ 1.11(h): control exists where the person, as a lender, formally and/or de facto exercises a dominant influence over the decisions of the management. A creditor-control criterion. If your debt covenants let you run the company, Switzerland says you control it. No EU, UK, or Canadian equivalent states this expressly. SECO

    The catch-alls: “wishes” and “direction”

    • The UK’s second condition is the famous one, and here it is straight from regulation 7 as enacted: a person who is not an individual (“C”) is “owned or controlled directly or indirectly” by another person (“P”) if either of the following two conditions is met (or both are met)… The second condition is that it is reasonable, having regard to all the circumstances, to expect that P would (if P chose to) be able, in most cases or in significant respects, by whatever means and whether directly or indirectly, to achieve the result that affairs of C are conducted in accordance with P’s wishes. The same wording appears across UK regimes – the quotation above is from the Misappropriation Regulations, identical to the Russia Regulations’ version. Note “if P chose to” – OFSI’s recent call for evidence spells out the implication: evidence that a designated person has not exercised control does not mean they lack the ability to do so; this may be referred to as hypothetical control. Legislation.gov.ukBlog
    • How far can “by whatever means” stretch? The UK courts spent late 2023 finding out, and the saga is worth telling properly because it’s the best available case study in what an open-textured control test does under pressure. In Mints v PJSC National Bank Trust, the question was whether a bank 99% owned by the Central Bank of Russia – itself not sanctioned – was nonetheless “owned or controlled” under regulation 7 by two designated persons: Mr Putin and Ms Nabiullina, the Central Bank’s governor. The Court of Appeal’s view, per Sir Julian Flaux C: the provision has no limit as to the means or mechanism by which a designated person is able to achieve the result of control, and the Court found that “in a very real sense… Mr Putin could be deemed to control everything in Russia.” When counsel objected that this was absurd, the Court’s answer was brutal: the absurd consequences arise not from giving the Regulation its clear and wide meaning but from the subsequent designation by the Government of Mr Putin without having thought through the consequences of Mr Putin being at the apex of a command economy – that he “called the shots.” BAILII + 4
    • The correction came in three waves. First, the FCDO issued a statement within days: the case was “not decided on this point” – emphasizing the control commentary was obiter – and “there is no presumption on the part of the Government that a private entity based in or incorporated in Russia or any jurisdiction in which a public official is designated is in itself sufficient evidence to demonstrate that the relevant official exercises control over that entity.” Second, the High Court in Litasco narrowed the test’s temporal reach: even though Putin had the power to place the Russian parent company under his control should he wish to, for the purposes of regulation 7(4) it is the current state of affairs of the entity and any existing influence that matters, not the state of affairs that an individual – including Putin – could bring about. Third, the government made it formal guidance: FCDO does not generally consider designated public officials to exercise control over a public body in which they hold a leadership function; the UK government does not consider that President Putin exercises indirect or de facto control over all entities in the Russian economy merely by virtue of his occupation of the Russian Presidency; and a person should only be considered to exercise control over private entities where this can be supported by sufficient evidence on a case-by-case basis. Where does that leave a practitioner? With a statutory test that is capability-based (“if P chose to”), a leading judgment reading it at maximum width, a follow-on judgment insisting on existing influence, and official guidance carving out political office – which is precisely why OFSI’s call for evidence (closing 13 April 2026) is now asking industry about its experience with the control test, while separately signposting that it continues to explore alignment with EU and US partners on aggregation and on moving the “more than 50%” threshold to a “50% or more” standard. The UK control test is, officially, under review. Matrix Chambers + 3
    • OFSI’s guidance gives the operational example of the catch-all in action: having the ability to direct another entity in accordance with one’s wishes, through any means, directly or indirectly – for example, a designated person may have control or use of another person’s bank accounts or economic resources and may be using them to circumvent financial sanctions. And note the individual-as-front example: if Person A is a family member or friend of designated Person B and there is evidence Person B is using Person A to enter into transactions, Person A is also subject to the same restrictions as Person B. Control isn’t only over companies. GOV.UKGOV.UK
    • Canada’s equivalent: it is reasonable to conclude, having regard to all the circumstances, that the person is able, directly or indirectly and through any means, to direct the entity’s activities – SEMA s. 2.1(2)(c). Global Affairs Canada has taken the position in its guidance scenarios that “considerable influence over strategic decision-making” is enough to trigger it – language that appears nowhere in the statute and arguably broadens its plain wording, and GAC’s updated guidance also appears to take the view that the mere presence of a listed person on an entity’s board could amount to control. Justice Laws Website + 2

    Asset and finance-based control

    These are now Article 1(j)(vi)-(viii) of Regulation 269/2014, mirrored in Switzerland’s FAQ 1.11 – and they have no UK or Canadian equivalent, which matters if you’re building one control checklist for a multi-regime program:

    • Having the right to use all or part of the assets of a legal person, entity or body; Switzerland’s version is broader – the person can formally or de facto dispose of all or part of the funds and economic resources of the company or determine their use (FAQ 1.11(e)). Global Investigations ReviewSECO
    • Managing the business of a legal person, entity or body on a unified basis, while publishing consolidated accounts; (Switzerland FAQ 1.11(f) matches.) Global Investigations Review
    • Sharing jointly and severally the financial liabilities of a legal person, entity or body, or guaranteeing them. (Switzerland FAQ 1.11(g) matches.) Global Investigations Review

    Plain-English translation of that last pair: if the books are consolidated, or if someone is on the hook for the company’s debts, that’s a control signal. The codified EU list is expressly open-ended – “controlling” a legal person, entity or body means, but is not limited to the eight criteria – and note what the regulation did not import from the guidance: the Best Practices’ rebuttable-presumption language stayed behind. The guidance says if any of these criteria are satisfied, it is considered that the entity is controlled, unless the contrary can be established on a case by case basis – Switzerland states the same presumption-and-rebuttal at the close of FAQ 1.11: if one of these criteria is met, it is to be assumed that the company or organisation is controlled, unless the contrary can be demonstrated in the individual case – but the regulation’s definition is silent on rebuttal. Whether that silence changes anything in practice is exactly the kind of question the EU courts will eventually get. Global Investigations Review + 2

    Fact-based regimes with no criteria list

    • Australia has no entity-level control test at all – the question is control of the asset: ownership and control of an asset is determined according to the factual circumstances, including the kind of asset and the laws of the jurisdiction in which it was created, and it is not necessary for the asset to be directly held by the designated person. ASO guidance adds that control can be indicated by a designated person’s command or direction over the asset – for example, through possession or the ability to dictate how it may be dealt with – and the guidance does not reveal whether any particular percentage is indicative. Australian Government Department of Foreign Affairs and TradeMinterEllison
    • Singapore’s statutory hook is simply funds, financial assets or economic resources owned or controlled, directly or indirectly, by a designated individual or entity, with no published criteria for what “controlled” means. Monetary Authority of Singapore
    • New Zealand’s regime is likewise asset- and dealing-based with minimal control guidance; one industry survey notes that APAC government bodies provide very limited guidance, and in practice the finance industry there tends to observe the OFAC approach when dealing with OFAC frameworks. SymphonyAI
    • Japan effectively drops out of a control-only analysis: its extension of Russia/Belarus asset freezes runs on 50% or more of shares directly held – pure ownership, no qualitative control test. Global Investigations Review

    The UN layer underneath everything

    UN resolutions are where the “owned or controlled” formula originates, and they add the third leg every practitioner should treat as part of this family. UNSCR 1373’s designation criteria cover any entity owned or controlled directly or indirectly by designated persons, and any person or entity acting on behalf of, or at the direction of, them – and Singapore’s IMC-TD applies exactly those criteria domestically. The UN never defines control or sets criteria; the ownership and control requirements sit in the asset freeze sections of the individual regime resolutions (the Haiti regime under Resolution 2653 is one example) and are implemented by all UN member states. IMF eLibrary + 2

    Part 1b: The non-ownership concepts that aren’t quite “control”

    Three adjacent doctrines deserve their own entries, because they catch parties the control criteria miss.

    “Acting on behalf of or at the direction of.” The EU treats this as a distinct concept whose effects can be placed on an equal footing with ownership and control, but which should be determined in and of itself. Since the concept has no definition, the EU offers four assessment criteria: the precise ownership/control structure including links between the parties; the nature and purpose of the transaction, coupled with the stated business duties of the entity; previous instances of acting on behalf or at the direction of the listed party; and disclosure from credible, reliable and independent sources and/or factual evidence indicating that directions were given. Switzerland bakes the same idea into the freeze itself – Article 15(1) of the Ukraine Ordinance freezes assets of natural persons, companies and organisations acting on behalf of or on the instructions of listed parties. And it shows up in specific UK prohibitions – the Russia regime’s “prohibited persons” definition covers a person owned or controlled directly or indirectly by the Central Bank of the Russian Federation, the National Wealth Fund, or the Ministry of Finance, or a person acting on behalf of or at the direction of these entities. European Union + 3

    “Holding or controlling” someone else’s funds. Separate from controlling an entity, the EU freezes funds a designated person merely holds or controls: all situations where, without having a title of ownership, a designated person is able lawfully to dispose of or transfer funds or economic resources he, she or it does not own, without any need for prior approval by the legal owner – including holding bearer instruments, having powers of representation allowing them to order transfers from accounts they don’t own, or administering a bank account as a parent or guardian. A power of attorney over a non-sanctioned relative’s account is squarely in scope. This is the mechanism behind the classic “assets parked with family” evasion pattern. European Union

    Transfers to third parties – Switzerland’s test for whether the assets ever really left. SECO FAQ 1.12 addresses the scenario head-on: where there is reasonable suspicion at the time of assessment that funds or economic resources were formally transferred to third parties – for example, sales of company shares or gifts to family members or other connected natural persons – but the sanctioned person still exercises control over them, those funds must be frozen; and it is not decisive when the transfer took place. That last clause deserves a highlight: a transfer completed before sanctions ever existed can still leave the assets under the sanctioned person’s control. SECO’s non-exhaustive assessment criteria: the closeness of the relationship (family, business, personal) between the sanctioned person and the third party; the economic and/or professional independence of the third party who is now nominal owner; the value and frequency of the transfers compared with transfers made to that person before the sanctions; the existence and content of formal agreements between them; and whether the transfer respected the arm’s length principle – for example, the sale conditions of company shares. The footnote grounds this in case law: the Federal Administrative Court’s judgment B-3925/2023 of 29 July 2024 on the concept of indirect control. SECO + 2

    The EU’s control red flags. The 2024 Best Practices added a set of circumstances that don’t establish control but tell you to go check the criteria above – and note these red flags stayed in the guidance rather than moving into the regulation. Verbatim from paragraph 67: a designated person who is the largest shareholder compared to others (the worked example is 40% against 10% holders); a management buyout where the designated previous owner can buy back the company under favourable conditions; a transfer of a relevant number of shares shortly before or after designation – where “relevant” includes smaller transfers that let the seller fall below the ownership threshold; front persons – a new owner closely connected to the designated previous owner such as a family member or former employee or business partner, possibly with an abnormal sale price, or an advisor with ultimate decision power even though the title doesn’t suggest it, or a written agreement giving a non-shareholder sole authority over the business, or nominal managers whose decisions are made by designated persons; and needlessly complex structures involving shells, LLCs or trusts linked to a designated person, especially ones set up or renamed around the time of designation or with no credible business activity. European Union

    One structural note worth internalizing: the UK does not aggregate for the ownership prong the way the EU does, but its guidance immediately pivots to control as the backstop – if each designated person’s holding falls below 50% and there’s no joint arrangement, the company isn’t owned by a designated person – but ownership and control also relates to voting rights, board appointment rights, and it being reasonable to expect a designated person could ensure the company’s affairs are conducted per their wishes. If any of these apply, the company could be controlled. And Schedule 1 quietly claws back some of what the no-aggregation position gives away: shares or rights held jointly are treated as held by each holder; shares or rights subject to a “joint arrangement” – an arrangement that the holders will exercise all or substantially all their rights jointly in a pre-determined way – are treated as the combined holding of each party; a share held by a nominee is treated as held by the principal; and where a person controls a right, the right is treated as held by that person rather than by whoever formally holds it. Nominees and voting pacts don’t launder control in the UK. Where the math clears, the control test is what’s left standing. GOV.UKLegislation.gov.uk

    Part 2: How you actually find this stuff

    The awkward truth about control research is that most of the evidence lives in documents, not databases. Here’s the map from criterion to source.

    Match the criterion to its paper trail. Voting rights that diverge from equity – through dual-class shares, voting agreements, or proxies – are evidenced by the articles of association, the shareholder register, and shareholder agreements; a board-control right can sit with a minority shareholder as a contractual term. Consolidated accounts and guarantee arrangements (EU Article 1(j)(vii)-(viii), SECO 1.11(f)-(g)) live in audited financial statements and their notes. Dominant-influence agreements live in the constitutional documents – and for UK purposes, so do the blocking rights that Schedule 1 deems equivalent to majority voting control in entities without general meetings. Switzerland’s creditor-control criterion points at loan agreements and covenants. The “wishes” and “direct the activities” tests live in the messier record: who actually shows up in board minutes, who signs, who the press says runs the place – and, post-Litasco, evidence of current influence carries more weight in the UK than evidence of what a designated person could theoretically do. SECO’s third-party transfer test points at a distinctive evidence set: relationship mapping, the transferee’s own economic standing, pre- versus post-designation gift patterns, and whether the sale price would survive an arm’s length comparison. Adjuvanto

    Use OFSI’s due diligence list as your evidence checklist. When OFSI updated its enforcement guidance, it listed what it considers relevant research, and it reads like a control-investigation template: the circumstances of board and management appointments including backgrounds, relevant experience, and relationships with designated persons; board or shareholders’ meeting minutes concerning recent changes in ownership and control; ongoing financial liabilities directly related to a designated person such as personal loans, loan guarantees, property or equipment; shareholder agreements, voting agreements, put or call options or other coordination agreements; and any benefits conferred to the designated person by the entity or transactions between them. OFSI also lists as mitigating examination of formal ownership and control mechanisms, examination of actual or potential de facto control, open-source research on persons able to exercise control, and – because ownership and control is not static – regular checks and ongoing monitoring. DLA PiperDLA Piper

    Ask the questions the EU Helpdesk says to ask. Collect information from the counterparty and public sources – corporate registries, beneficial ownership records, financial statements, governance documents – then verify when you see red flags, and ask targeted questions on beneficial ownership, voting rights, board appointment powers, shareholder agreements, financing and guarantees, consolidated accounting, and rights to use assets. Document your steps, findings, and decisions. That documentation line isn’t filler – in a strict-liability environment like the UK’s, the file you build is the mitigation. Financialcrime

    Layer the workflow. A sensible sequence: screen against the relevant sanctions lists; request beneficial ownership disclosure, ideally certified or backed by corporate registry extracts, down to natural persons for high-risk jurisdictions; consult corporate registries and data aggregators for shareholder information; then screen every identified owner against the lists – then extend beyond ownership with checking board members’ biographies for links to sanctioned persons, reviewing shareholder agreements and trust documents for hidden control mechanisms, and analyzing funding flows. Accept the known obstacles going in: nominee shareholders and layered holding companies, registries that are unreliable or unavailable in some countries, and structures that shift quickly – so one-off checks aren’t enough. One field report on this kind of research is worth quoting for realism: ownership relationships sometimes don’t appear in the subsidiary’s own corporate documents and have to be established from the parent’s website, news stories, or shared directors; registry addresses turn out to be out of date or belong to a school; and private citizens can be listed anonymously in corporate documents, totally obscuring their beneficial ownership. Sanctions Lawyers + 3

    Commercial providers. The vendor landscape splits roughly into three layers:

    • Curated sanctions-nexus datasets – built specifically to answer “is this unlisted entity caught anyway?” Kharon offers Sanctions 50-Plus and Control datasets identifying entities that may be considered blocked under US, EU, and UK regulations, built by collecting and analyzing corporate records, securities and regulatory filings, company websites and press releases, global media, and social media to trace chains across jurisdictions, with analyst-verified ownership chains mapped down to the securities level by ISIN and CUSIP. Dow Jones Risk & Compliance offers Sanctions Control and Ownership (SCO) data for identifying indirect links to sanctioned individuals or entities. These products are strongest on ownership math; the “Control” components are the part to interrogate in a demo, since control determinations are exactly what resists automation. Kharon + 2
    • Ownership-graph platforms – Sayari uses graph analytics to pre-compute ownership structures and flag indirect or beneficial owners on sanctions lists, supporting 50% rule and “shadow SDN” compliance and EU equivalents, with an entity resolution and ownership graph covering 500M+ companies across 250+ jurisdictions. SayariSayari
    • Registry aggregators and raw corporate data – OpenCorporates, Orbis, and Refinitiv are the aggregators typically cited for shareholder information alongside national registries. Sanctions Lawyers

    Flagged plainly as general knowledge rather than something verified against this session’s sources: LSEG World-Check, LexisNexis WorldCompliance, and Moody’s Grid also serve this market, though they are primarily screening lists rather than ownership-graph products (Orbis, in the Moody’s stable, is the ownership dataset). And a structural caveat that applies to every vendor: databases are built from filings, and criteria like “de facto dominant influence,” creditor control, blocking rights, or “affairs conducted per their wishes” often leave no filing at all. Vendor data narrows the field; it doesn’t finish the job.

    Part 3: Source re-check

    Comparing this version against the primary texts now in hand:

    1. EU codification – now verified from EUR-Lex. Regulation (EU) 2025/2037 is quoted directly: recital 6 (the harmonization rationale and the 2580/2001 alignment), the full Article 1(j)(i)-(viii) control definition, and the “means, but is not limited to” open-endedness. Comparing the codified text against the Best Practices confirmed three things the secondary memos glossed over: the criteria are substantively identical to guidance paragraph 64; the front-company footnote did not travel into the regulation; and neither did the rebuttable-presumption language of paragraphs 65-66 or the paragraph 67 red flags, which all remain guidance-level. Also note scope: the codification is to Regulation 269/2014 (the Russia/Ukraine asset-freeze regulation); the Best Practices remain the cross-regime articulation.
    2. UK regulation 7 – now sourced to legislation.gov.uk directly, replacing the law firm consolidation used in the prior pass (the wording matched). The identical reg 7 text across regimes is confirmed by the Misappropriation Regulations on the same site. New Schedule 1 findings from the primary text: the blocking-rights deeming rule for entities without general meetings, and the treasury-share reduction – neither appeared in any secondary source consulted.
    3. Mints – substantially verified, one honest limitation. BAILII refused a direct fetch, but the search index returned text from the judgment itself (including the reg 7 wording as set out in it and the case posture), and the official judiciary.uk PDF is linked in the sources. The Flaux quotations (“no limit as to the means or mechanism,” “called the shots,” the “absurd consequences” passage, “control everything in Russia”) are sourced to four independent law firm and chambers commentaries that agree with each other; the FCDO statement is quoted via Matrix Chambers, which reproduces it verbatim; Litasco is sourced to commentary, not the judgment. For publication, paragraph-level pinpoints (the control discussion sits at [225]-[233]) should be checked against the judiciary.uk PDF.
    4. The Mints-to-guidance arc – corrected and completed. The prior pass compressed this into one sentence sourced to a single commentary. It’s now told in sequence with the FCDO statement, Litasco, and the public officials guidance quoted from gov.uk directly – including the government’s explicit position that Putin’s presidency alone does not establish control over the Russian economy, which is the operative counterweight to the Mints dicta.
    5. SEMA s. 2.1 – verified against the consolidated statute, including the foreign-state carve-out. GAC’s “considerable influence” position remains framed as an interpretive stance that arguably outruns the statute.
    6. SECO FAQ – verified from the document itself (FAQ 1.10-1.13), including criterion (h) (creditor control) and the FAQ 1.12 transfer criteria that the English-language secondary literature missed. Translations from the German are mine and should be checked before publication. One residual note: the fetched edition is the “Korrekturmodus” (tracked-changes) version showing the February and June 2026 states; the control criteria at 1.11 are not among the marked changes, but the clean current PDF should be the citation of record.
    7. OFSI call for evidence – the closing date (13 April 2026) and the aggregation/”50% or more” alignment exploration are sourced to Crowell commentary on the call for evidence, consistent with the OFSI blog post.
    8. Japan remains characterized as having effectively no control test, per the GIR chapter. Provider claims – Kharon, Sayari, Dow Jones SCO, and the OpenCorporates/Orbis/Refinitiv trio are source-backed; World-Check, WorldCompliance, and Grid remain explicitly labeled as unverified general knowledge.
    9. Nothing now rests on an unfetched primary except the Mints and Litasco judgments themselves (commentary-corroborated, with the Mints PDF located) and the Best Practices’ cross-checks noted above.

    Sources

    Primary texts fetched and quoted verbatim this session

    Case law

    Regulator and official sources

    Commentary and secondary sources

    Vendor materials

  • Eleven Questions Practitioners Keep Asking OFAC

    OFAC’s FAQ database now runs to roughly 985 entries spread across 38 topic pages, from a single FAQ under Balkans-Related Sanctions to 243 under Iran. Read across the whole set, the same handful of question types show up again and again, program after program. Below are the eleven categories that emerged from that review, ordered from most to least common, with a rough sense of how much of the database each one accounts for.

    A caveat up front: these categories aren’t mutually exclusive. A single FAQ interpreting a Russia general license is very often also a secondary-sanctions question and a wind-down question at the same time. The counts below are estimates based on which category each FAQ most centrally addresses, not a mechanical tag count, so treat them as directional rather than exact.

    1. What does General License X authorize? (~340 FAQs, the largest category by far)

    This is the single most common reason an OFAC FAQ exists. A general license gets issued, and OFAC follows it with one or more FAQs spelling out exactly what it covers, what it doesn’t, and how long any wind-down window runs. These FAQs are almost never abstract – they’re triggered by one specific GL and answered in narrow, GL-specific terms. Belarus GL 4 and GL 5 (the Belaruskali wind-down), Russia GL 8L (energy wind-down) and GL 116 (entities linked to a specific designated individual), and the Afghanistan GLs 14 through 20 are all typical examples. If you’re trying to predict where OFAC will publish its next FAQ, a newly issued GL is usually the leading indicator.

    2. Secondary sanctions and non-U.S. person exposure (~100 FAQs)

    Concentrated heavily in Iran and Russia. These FAQs work through when a non-U.S., non-Iranian, or non-Russian person or financial institution can be exposed to U.S. sanctions for dealing with a blocked party – CISADA, the NDAA “significant transaction” test, and the Russia-related CAPTA Directive all generate this type of question repeatedly. A cluster of these FAQs exists purely to define the operative terms (what counts as “significant,” what “knowingly” means) because those definitions are what determine whether a foreign bank loses U.S. correspondent account access.

    3. Wind-down and divestment mechanics (~100 FAQs)

    Distinct from the general GL-scope questions above: these are about the lifecycle of a transaction after a designation happens – closing a correspondent account, paying down an outstanding loan, or negotiating the sale of a now-blocked entity. The recent Lukoil-related FAQs on divesting LIG entities are a good current example of this pattern.

    4. Humanitarian and agricultural/medical carve-outs (~80 FAQs)

    Nearly every country program has its own version of this question, because food, medicine, and medical device exports are treated as a standing exception that industry keeps asking about program by program – Afghanistan, Iran, Russia, Cuba, Venezuela, and Sudan all have a meaningful cluster here.

    5. Highly bespoke, single-entity FAQs (~80 FAQs)

    Especially visible in Iran and Russia: FAQs that read more like case notes on one company or one enforcement action than generalizable guidance – the Bank of Kunlun CISADA finding is a good example. This pattern is likely a big part of why Iran (243 FAQs) and Russia (159 FAQs) so heavily outweigh every other topic: long-running programs accumulate a one-off FAQ per major action rather than folding it into a general rule.

    6. Definitional FAQs (~70 FAQs)

    A surprising share of FAQs exist purely to pin down a term used in a statute or executive order – “significant financial transaction,” “knowingly,” “Iranian financial institution,” “Russia’s military-industrial base.” These read like industry asked for definitional certainty before OFAC ever issued formal regulatory text on the point, and OFAC answered by FAQ instead.

    7. The 50 Percent Rule and entity ownership (~50 FAQs)

    Some version of “is this entity blocked because a blocked person owns 50 percent or more of it, directly or indirectly through another entity” shows up in nearly every topic – Basic Information, Belarus, Iran, Russia, Afghanistan, and its own dedicated topic (Entities Owned by Blocked Persons). This is clearly one of the more persistently confusing mechanics in the whole sanctions regime, and OFAC keeps restating the same core rule with slightly different fact patterns each time.

    8. Correspondent and payable-through account mechanics (~50 FAQs)

    A process-level companion to the secondary sanctions category above: what a U.S. financial institution must actually do if it holds an account, or receives a wire, touching a blocked or listed party – block it, reject it, report it to OFAC within 10 business days, and hold it in an interest-bearing account pending further action.

    9. SDN List mechanics and name-matching (~50 FAQs)

    Assessing OFAC Name Matches is an entire topic devoted to this question, and it recurs elsewhere too – what the bracketed program tags on an SDN List entry mean (e.g., [IRAN], [IFSR], [SDGT]), how the delisting and reconsideration process works, and OFAC’s consistent point that it does not publish or endorse any kind of “safe list.”

    10. Building and running a compliance program (~40 FAQs)

    A separate cluster from the transaction-specific questions above – Starting an OFAC Compliance Program is its own topic, and there are sector-specific versions for insurance and for internet/web-based activity. These are less about a specific designation and more about internal controls generally.

    11. Sector determinations (~30 FAQs)

    “OFAC identified Sector X of a country’s economy – does that mean everyone in that sector is blocked?” Burma’s jet fuel sector, Russia’s metals and mining sector, and Belarus’s potash sector all generate this question. OFAC’s answer follows the same pattern each time: identifying a sector puts persons operating in it on notice of sanctions risk, but it does not automatically block everyone in that sector – only persons OFAC actually designates.


    A note on the numbers. The estimates above add up close to the full 985-FAQ database, but they shouldn’t be read as an exact partition – plenty of individual FAQs genuinely straddle two or three of these categories.

  • The spreadsheet lists all OFAC Frequently Asked Questions Topics and the number of FAQs for each topic, sorted in descending order. Not totally surprising, but Iran sanctions (243) and Russia sanctions (159) top the list.

  • The prompt to Claude:

    What is the purpose of OFAC’s use of “Linked To” in its designations? What informational, practical and/or legal implications are there to this information? How does it inform data analytics and KYC/CDD efforts – and where do those fall in the range from requirement to nice to have for even the most high-profile firms? Is there anything else we ought to know about this data? Write your response for sanctions profesionals who are not lawyers.

    The response:

    The “Linked To” field is one of the more misunderstood pieces of SDN metadata, so it’s worth unpacking carefully.

    What “Linked To” actually is

    When OFAC designates a party, it frequently establishes a relationship between that party and an existing sanctions target or program. In the SDN data, this surfaces as a “Linked To” relationship – typically visible in the consolidated data files and on the SDN Search interface as a note that Entity A is “Linked To” Entity B (or to a specific program).

    The core purpose is to document why a party was designated and to whom or what they connect. OFAC rarely designates in a vacuum. A person gets added because they own or control a blocked entity, act on behalf of a designated party, materially assist a sanctioned regime, are a family member operating as a front, and so on. “Linked To” is OFAC’s way of preserving that connective tissue in the structured data.

    The critical distinction: derivative vs. standalone designation

    Here’s the nuance that trips people up. “Linked To” is a relationship attribute; it is not itself the legal basis for blocking. Every party on the SDN List is blocked in its own right by virtue of being on the list, regardless of what it’s linked to. The linkage tells you the narrative and often the authority under which OFAC acted, but the legal consequence – block the property, reject or freeze the transaction – flows from the SDN listing itself, not from the link.

    This matters because practitioners sometimes treat a “Linked To” entry as if it were a secondary target that also needs screening. It isn’t a screening target on its own; the linked party is either already an SDN in its own entry (in which case it’s screened directly) or it’s a program/authority reference. Don’t confuse the relationship pointer with an actionable name.

    Informational implications

    The field gives you three useful things:

    Attribution and context. It answers “why is this party here?” That’s valuable for alert adjudication, narrative building in SARs, and explaining a hit to a business line that wants to know the story.

    Network mapping. Aggregated across the list, “Linked To” relationships let you reconstruct the designation networks OFAC sees – the web of ownership, control, and agency around a primary target. This is the raw material for understanding a sanctioned oligarch’s corporate structure or a proliferation network’s front companies.

    Program inference. The linkage often clarifies which program or authority is in play, which affects how you handle related risk (e.g., a party linked to a Russia-program target carries different downstream implications than one linked to a counter-narcotics target).

    Practical and legal implications

    The practical caution: “Linked To” does not substitute for a 50 Percent Rule analysis. OFAC’s 50 Percent Rule blocks entities owned 50% or more, in aggregate, by one or more blocked persons – even if those entities are not on the SDN List and have no “Linked To” entry pointing at them. The “Linked To” field captures relationships OFAC chose to document; it does not capture every ownership relationship that triggers derivative blocking. Treating the field as a complete ownership map is a real compliance failure mode. The regulator’s position is that the obligation to identify 50%-owned entities rests with the filer, using ownership data that frequently lives entirely outside the SDN metadata.

    The legal reality, stated plainly: the block attaches to the listed party. “Linked To” is descriptive metadata, not an operative legal element you act on independently. You don’t “unblock” something because its link looks tenuous, and you don’t gain a separate blocking obligation because a link exists.

    Data analytics and KYC/CDD – requirement vs. nice-to-have

    Let me separate the layers, because the answer differs sharply by layer.

    Screening the SDN List itself: requirement, full stop. Every US person and most firms with US touchpoints must screen against the SDN List. That’s non-negotiable and doesn’t depend on “Linked To” at all – you screen the names, you resolve the hits.

    Using “Linked To” for alert adjudication and enrichment: strongly expected, effectively a de facto requirement at scale. For a high-profile firm, examiners and regulators expect a risk-based program that uses available context to make sound decisions. The field isn’t itself mandated, but a sophisticated institution that ignored readily available OFAC-provided context in its adjudication would struggle to defend that as reasonable. So in practice it sits closer to “requirement” than “nice to have” for large, high-risk firms – not because a rule names the field, but because using it is part of what a defensible risk-based program looks like.

    Network analytics / graph analysis built on “Linked To”: genuinely nice-to-have, but increasingly table stakes for the top tier. Reconstructing designation networks to get ahead of 50% Rule exposure, identify likely front companies before they’re listed, and map beneficial ownership risk is advanced practice. No rule requires you to build a graph database of OFAC linkages. But for globally systemic institutions and firms with heavy exposure to Russia, Venezuela, or proliferation-finance risk, this kind of analytics has moved from differentiator toward expected capability. The honest framing: not a legal requirement, but the gap between “compliant” and “credible at the frontier” increasingly runs through exactly this work.

    The through-line: the listing drives requirements; “Linked To” drives quality of judgment. Regulators assess programs on reasonableness and risk-sensitivity, and richer use of context is how you demonstrate both.

    Other things worth knowing

    A few practical cautions:

    Coverage is uneven. Not every designation carries a fully populated “Linked To” set, and the granularity varies across programs and vintages. Older entries were built under different data conventions. So don’t assume the absence of a link means the absence of a relationship.

    It’s directional and curated. The field reflects the relationships OFAC decided to memorialize for a given action, not an exhaustive relationship graph. It’s a lens on OFAC’s reasoning, not a complete intelligence picture.

    It appears in the enhanced/consolidated data, not the legacy flat SDN file in the same way. If your screening feed only ingests basic name/ID fields, you may not be capturing “Linked To” at all – worth confirming with your data vendor exactly which fields flow into your system versus your analytics environment.

    Finally, don’t over-read tenuous links. A documented linkage tells you OFAC saw a relationship material enough to note; it doesn’t quantify the strength or the current status of that relationship, and relationships decay over time while the metadata may not.

  • My editing of Claude’s responses is pretty minimal, and I want to explain it, in the service of full transparency.

    What I do edit out is basically three things:

    • In a chatbot, any process-type discussion (couldn’t access this document, now fetching this) appears as part of the response block – and gets picked up if you hit the Copy button. The process of how a chatbot tries to gather information, as a general matter, doesn’t add that much value, IMHO, to most of my intended audience – even the more AI-curious. So, I leave these out. Ditto for any discussion as it refines its thinking – what we largely care about is the final response. A good example is the (upcoming) Burning Questions post on the “secondary risk” wording in OFAC listings, where Claude prefixes the final response with this (none of which appears in my post):
      • This is the sharper version of the “Burning Questions” angle from before — whether the field is being read as a rating rather than a citation, and whether that misreading clusters anywhere. Let me search for evidence rather than reason from priors, because the honest answer may be that this specific behavior is under-documented.
      • That gave me adjacent material (screening mechanics, one vendor that tags secondary sanctions as a labeling feature) but not direct evidence of firms misreading the field as a rating. Let me look specifically at the de-risking / over-compliance pattern, which is where any geographic or asset-class clustering would show up.
      • I now have solid material on the de-risking pattern and where it clusters, but I want to be honest about a distinction: the question asks specifically whether firms treat the wording as a rating, and most of what I’ve found is about firms reacting to the underlying risk. Those aren’t the same thing, and I don’t want to conflate them. Let me do one more targeted search on the data-field-as-signal angle.
      • I have enough to give an honest, well-bounded answer.
    • Sometimes, as part of its source checking, Claude will point out things where the difference between its initial drafting and its checking – semantically and in a practical sense – is not worth correcting, or where the discussion of the review itself doesn’t illuminate the response. Those I remove. If there is a real difference, by the way, I have Claude correct it – so I don’t post the original response.
    • Often, Claude will propose I ask a follow-up question. These I remove.

    Now, I do leave in some of Claude’s commentary from time to time. I do that for a number of reasons:

    • I think the reasoning, and the natural language production of the “conversation”, is fascinating
    • I think the back and forth of postulating something, posting a caveat and then proceeding, is more nuanced and informative to the audience (and, to be perfectly frank, to me as well)
    • As much as this is a sanctions blog, it’s also a “AI in sanctions” blog. Some of these peeks behind the curtain inform us as we make decisions about how to use AI in our field

    As always, I invite your comments, criticisms and suggestions.

  • The prompt:

    please explain, in layperson’s terms, how OFAC travel sanctions (barring entry to the US) are actually enforced. Check your response against your sources and correct anything that is not well-supported by the sources. List your sources, too, please.

    The response:

    How “OFAC Travel Sanctions” Actually Work: A Layperson’s Explanation

    Before anything else, there’s an important framing note: OFAC itself doesn’t bar people from entering the United States. That’s not OFAC’s job. OFAC is a Treasury Department office whose core business is financial and economic sanctions — blocking assets, prohibiting transactions. The travel-entry piece is handled by a different set of legal authorities and different agencies. The phrase “OFAC travel sanctions” is a bit of a shorthand that bundles together several distinct mechanisms.

    Here’s how those mechanisms actually work.


    1. The SDN List Does Not, By Itself, Bar Entry

    When OFAC designates someone as a Specially Designated National, their assets are blocked and U.S. persons are generally prohibited from dealing with them. That’s the core legal effect. The SDN List is a financial/transactional prohibition tool, not an immigration tool.

    The primary purpose of the SDN List is to combat threats to national security and foreign policy objectives by isolating and financially constraining the listed parties. The designations prevent these individuals and entities from accessing the U.S. financial system and conducting business with U.S. persons.


    2. The Entry Ban Comes from a Different Legal Source: Presidential Proclamations and Executive Orders

    The actual legal hook that bars entry is separate, and it traces back to Section 212(f) of the Immigration and Nationality Act (INA). Under Section 212(f), whenever the President finds that the entry of any aliens or of any class of aliens into the United States would be detrimental to the interests of the United States, he may by proclamation, and for such period as he shall deem necessary, suspend the entry of all aliens or any class of aliens as immigrants or nonimmigrants, or impose on the entry of aliens any restrictions he may deem to be appropriate.

    For people designated under OFAC sanctions programs, the key legal instrument is Presidential Proclamation 8693, signed in 2011. The State Department’s own Foreign Affairs Manual — its internal instruction book for consular officers — is explicit: PP8693 suspends entry of applicants designated under IEEPA. OFAC implements and enforces IEEPA sanctions. Designated individuals and organizations are listed on OFAC’s searchable SDN list.

    In practice, most OFAC sanctions programs are built on IEEPA (the International Emergency Economic Powers Act), so this proclamation connects OFAC designations to a formal entry bar. Additionally, many individual executive orders that create specific OFAC programs have their own travel suspension language. A typical executive order finds that the unrestricted immigrant and nonimmigrant entry into the United States of aliens determined to meet one or more of the criteria in the order would be detrimental to the interests of the United States, and suspends entry into the United States, as immigrants or nonimmigrants, of such persons, except where the Secretary of State, or the Secretary of State’s designee, determines that the person’s entry is in the national interest of the United States. Such persons shall be treated in the same manner as persons covered by section 1 of Proclamation 8693.

    So the pipeline is: OFAC designates → the executive order or PP 8693 kicks in the entry suspension → State Department and DHS enforce it.


    3. The Secretary of State Has Independent Authority Too

    Separate from all of that, the Secretary of State has power under INA Section 212(a)(3)(C) to declare anyone inadmissible whose entry would have potentially serious adverse foreign policy consequences for the United States. The State Department actively uses this in sanctions-adjacent contexts. For example, when Secretary Rubio authorized travel sanctions on Colombian government officials in early 2025, the announcement cited INA 212(a)(3)(C), under which the Secretary of State can render inadmissible to the United States any alien whose entry “would have potentially serious adverse foreign policy consequences for the United States.”


    4. How It’s Actually Enforced at the Border

    The practical enforcement chain runs through two agencies: the State Department (for visa issuance) and Customs and Border Protection (CBP) (for border entry).

    Before arrival — visa denial. If a designated person applies for a U.S. visa, consular officers check watchlists. Under INA Section 213(g), no visa or other documentation shall be issued to an alien if the consular officer knows or has reason to believe that such alien is ineligible to receive a visa or such other documentation under section 212, or any other provision of law. The entry suspension under PP 8693 and applicable executive orders makes them ineligible. Visa denied.

    If they already have a visa — revocation. The Department of State’s Visa Office of Screening, Analysis, and Coordination (CA/VO/SAC) can revoke visas of individuals in, or en route to, the United States.

    At the border — database checks. CBP obtains certain information about individuals traveling to the U.S. on commercial or private aircraft through CBP’s Advance Passenger Information System (APIS). The information obtained from APIS is screened against TECS Records and other law enforcement databases in order for CBP to ascertain if any security or law enforcement risks exist. These pre-arrival TECS queries include checks against lookouts, watchlist matches, etc. TECS is CBP’s primary enforcement database.

    If they show up anyway. When an individual presents for inspection, the CBP officer receives an alert leading to secondary screening. During this detailed review, the traveler may be temporarily detained and subjected to extensive questioning. For non-citizens, a watchlist match can result in a finding of inadmissibility and denial of entry into the United States.


    5. What About Waivers?

    The entry bar isn’t absolute. Executive orders typically include an exception where the Secretary of State can allow entry if it’s in the national interest. No waiver is available for immigrants or nonimmigrants ineligible under INA 212(f) in the standard sense — but proclamations and executive orders typically carve out a national-interest exception administered by the Secretary of State. When the Department of State, in consultation with the Department of the Treasury, designated a person for sanctions, the Department of State will also be the adjudicating agency for delisting.


    The Bottom Line

    “OFAC travel sanctions” is a shorthand for a multi-agency, multi-legal-authority mechanism. OFAC does the designating. The Presidential Proclamations (especially PP 8693) and executive order travel suspension provisions do the formal legal work of making entry inadmissible. The State Department enforces it at the visa stage. CBP enforces it at the border. It’s a coordinated system, not a single switch — which means there are also more moving parts where things can go wrong (or be worked around).


    Sources

    • OFAC SDN List FAQ, ofac.treasury.gov — on what the SDN list actually does
    • State Department Foreign Affairs Manual, 9 FAM 302.14, fam.state.gov — the authoritative consular instruction connecting PP 8693 and OFAC/IEEPA designations to entry ineligibility
    • Presidential Proclamation 8693 (July 24, 2011, referenced throughout executive orders) — the standing proclamation suspending entry of IEEPA-designated individuals
    • Example OFAC executive orders (Cuba, Russia, ICC-related), ofac.treasury.gov — showing the “entry suspended / treated as PP 8693 persons” boilerplate in individual programs
    • INA Section 212(f), 8 U.S.C. § 1182(f), uscode.house.gov — the statutory authority for presidential entry suspensions
    • INA Section 212(a)(3)(C), as discussed by the State Department (fam.state.gov and nafsa.org) — the Secretary of State’s separate foreign policy inadmissibility authority
    • CBP TECS Privacy Impact Assessment, dhs.gov — on how border screening databases work in practice
    • NAFSA, nafsa.org — on travel bans and restrictions, including the 3(C) authority
    • State Department, 9 FAM 403.11, fam.state.gov — on visa revocation procedures
  • My prompt:

    Read today’s Notice to Exporters: https://www.gov.uk/government/publications/notice-to-exporters-202614-announcing-the-dual-use-ogel/nte-202614-announcing-the-dual-use-ogel . How unusual is using general licenses for dual-use goods? What alternatives do other major regulators (US, EU countries, Switzerland, Canada, Australia, Japan, etc.) use? Speak to me like I’m a professional but not an expert control expert.

    Claude responds:

    \What this notice actually does

    The UK has published a new Open General Export Licence (OGEL) for dual-use goods. The mechanism here is the key thing to understand: a general licence is a pre-published, standing authorization that any exporter can use once they register, rather than something you apply for shipment-by-shipment. This new licence makes it easier for UK businesses to export to trusted partners without applying for individual licences for each shipment.

    Two things stand out. First, it’s a consolidation — the new OGEL merges the EU member states Dual-Use OGEL and General Export Authorisation GEA001. Second, it expands coverage. Alongside destinations already covered by existing general licences (EU member states, the US, Japan, New Zealand, Australia, Canada), it adds South Korea, Singapore, Chile, Uruguay, and British Overseas Territories. The justification is notably data-driven: the additional destinations came from a review of historic licensing decisions showing these exports are consistently approved and present low risk, and the change could save exporters from applying for more than 500 individual licences each year.

    How unusual is this? Not at all — it’s the global norm

    Using general licences for dual-use goods is standard practice, not an exception. Essentially every major export-control regime runs a tiered system: individual licences for sensitive or risky transactions, and some form of general/bulk authorization for low-risk goods going to trusted destinations. The whole point is triage. The notice says this plainly: by channelling lower-risk exports to OGELs, the UK can focus expertise on the remainder where risks are highest.

    So the concept is unremarkable. What’s mildly noteworthy here is the breadth — pushing this many destinations into a single consolidated standing licence, and doing it on an explicitly data-led “we keep approving these anyway” basis. That’s a deregulatory, efficiency-driven move, but the underlying tool is conventional.

    What the other major regulators use

    The vocabulary differs by jurisdiction but the architecture is the same everywhere. Here’s the map:

    United States (BIS / EAR). The US doesn’t call them “general licences” — it uses License Exceptions. These are codified exceptions in the Export Administration Regulations that let you export without an individual licence if the item, destination, and end-use meet specified conditions. Relevant ones for dual-use trade among allies include STA (Strategic Trade Authorization, for close partners), GBS, and ENC (for encryption items). Same idea as an OGEL: pre-defined conditions, no case-by-case application.

    European Union. The EU runs General Export Authorisations (EUGEAs) under the Dual-Use Regulation (2021/821). The most important is EU001, which covers most dual-use items going to a list of trusted destinations (US, Canada, Japan, Australia, etc.). The UK’s “GEA001” lineage you see in this notice is literally a holdover from when the UK was inside that EU framework — it’s the same instrument, now domesticated. Individual EU member states (Germany’s BAFA, France, the Netherlands, etc.) also issue their own national general authorisations on top of the EU-wide ones.

    Switzerland. Uses Ordinary General Licences (OGL) and Extraordinary General Licences (EGL) under SECO, distinguishing destinations by trust level — same trusted-partner logic.

    Canada. Uses General Export Permits (GEPs), standing permits published by Global Affairs Canada for specified goods/destinations, alongside individual permits.

    Australia. Permits and the Australian Community concept under the Defence Trade Controls regime, plus general permissions; lower-risk trade with allies (notably under the AUKUS arrangements) is increasingly handled through broad authorizations rather than individual approvals.

    Japan. METI operates bulk/general licences (including a “Special General Bulk Export Licence” and similar instruments) for trusted destinations under its catch-all and list-control system.

    The pattern: named trusted-destination lists + standing authorizations + a registration or recordkeeping obligation + reserved individual licensing for sensitive cases. The UK notice fits this template exactly.

    The one genuine catch worth flagging

    “General” doesn’t mean “no compliance burden.” With OGELs and their equivalents, the obligation shifts from getting permission to proving you were entitled to use it. You have to register, confirm the goods and destination actually fall within scope, keep records, and be ready for inspection. The notice underlines this: you must register through SPIRE before using the licence, including stating where you’ll keep export records and where ECJU may inspect them. And the UK is now adding a new wrinkle — exporters get a unique licence reference that must be entered into the Customs Declarations System, bringing OGEL exports into line with the data captured on individual licences. That last part is a quiet tightening: more visibility into who’s using these standing licences and for what, even as the licences themselves get easier to use.

    So the short version: general licensing for dual-use goods is the universal default among serious regulators, the UK is simply consolidating and broadening its version, and the trade-off is that the paperwork moves from the front end (applying) to the back end (registering, classifying correctly, and documenting).

  • The prompt:

    Why are OFAC General Licenses for the Iran program denoted by letter, where it seems all other programs’ GLs are numbered?

    The response:

    Iran GLs aren’t actually lettered as a program-wide convention—the lettering you’re seeing comes from how OFAC issues general licenses within its regulatory parts in the CFR versus as standalone numbered GLs.

    The distinction is between two issuance mechanisms:

    Codified general licenses (lettered): When a GL is written into the body of the regulations in 31 CFR, it gets a section number with a letter suffix in the §xxx.5xx range. For Iran, these live in the Iranian Transactions and Sanctions Regulations (ITSR, 31 CFR Part 560). So you see things like GL D-2 (the personal communications/internet services GL), GL I, GL J, etc. The letter is essentially the identifier OFAC assigned to that standing authorization, and revisions get numeric suffixes (D, then D-1, then D-2).

    Standalone web-published GLs (numbered): Many newer programs—Russia/Ukraine (Part 587/589), Venezuela, etc.—saw OFAC shift to issuing general licenses as separate numbered documents posted to the website (GL 1, GL 2, GL 8K, and so on) rather than codifying each one into the CFR text. These are sequentially numbered per program.

    So it’s less “Iran uses letters, everyone uses numbers” and more a function of era and method. Iran is one of the older, heavily-codified programs where the long-standing GLs were embedded in the regulations and carried letter designations. The newer expedited approach—driven partly by how fast Russia-related sanctions had to move after 2022—favored numbered standalone GLs that could be published immediately without going through rulemaking to amend the CFR.

    You’ll notice Iran also has numbered GLs in more recent actions (e.g., the post-2018 snapback wind-down GLs were numbered), and some older programs (Cuba’s CACR) similarly use lettered codified GLs. The split tracks codification method and vintage more than the program name itself.