OFAC SDN vs EU vs UN vs UK vs DFAT: Sanctions Lists Compared

OFAC SDN, EU, UN, UK, and DFAT sanctions lists compared: who each binds, ownership tests, and update cadence, current as of August 2026.

Updated On August 08, 2026
OFAC SDN vs EU vs UN vs UK vs DFAT: Sanctions Lists Compared

There is no single global sanctions list. The lists that matter are issued by different bodies under different law, bind different people, and change on different clocks. Screening against the wrong set is the most common structural gap in a compliance programme, and the fastest to fix.

This comparison is current as of 5 August 2026. Two recent changes catch teams out: the UK closed one of its two lists in January 2026, and the EU moved its ownership threshold in 2024. Both are covered below.


Which sanctions lists actually matter, and what does each one do?

Seven sources cover most legitimate screening obligations: the OFAC SDN List and OFAC Consolidated (non-SDN) List (US), the EU Consolidated Financial Sanctions List, the UN Security Council Consolidated List, the UK Sanctions List, the Australian DFAT Consolidated List, and the US Consolidated Screening List for export controls. They overlap heavily but none is a superset of another.

The first table covers legal identity: who issues each list and who is bound by it.

ListIssuing bodyLegal basisScopeWho is legally bound
OFAC SDN ListOffice of Foreign Assets Control, US TreasuryIEEPA, TWEA and regime-specific statutes and Executive OrdersBlocking sanctions: assets frozen, dealings prohibitedUS persons: citizens and permanent residents wherever located, entities organised under US law including foreign branches, and anyone physically in the US
OFAC Consolidated (non-SDN)SameSame statutory base, narrower programmesNon-blocking restrictions: sectoral, menu-based, securities-investment prohibitionsSame, but the prohibition is specific to the programme, not a full freeze
EU Consolidated Financial Sanctions ListEuropean Commission, on Council designationsCouncil Regulations under Article 215 TFEUAsset freezes and prohibition on making funds or economic resources availableEU nationals wherever located, entities incorporated in an EU member state, and any person within EU territory
UN Security Council Consolidated ListUN Security Council sanctions committeesUN Charter Chapter VII resolutionsAsset freezes, travel bans, arms embargoesUN member states, which must implement domestically; the list binds private parties only through national law
UK Sanctions ListForeign, Commonwealth & Development OfficeSanctions and Anti-Money Laundering Act 2018 and regime regulationsAll UK sanctions types: financial, trade, immigration, shippingUK persons wherever located, and anyone within UK territory
Australian DFAT Consolidated ListAustralian Sanctions Office, DFATCharter of the United Nations Act 1945 and Autonomous Sanctions Act 2011Targeted financial sanctions and travel bansAnyone in Australia, and Australian citizens and bodies corporate wherever located
US Consolidated Screening List (CSL)Aggregated by Commerce, State and TreasuryExport Administration Regulations, ITAR, and othersExport and trade restrictions: licensing requirements, denial ordersExporters and re-exporters of US-origin items, and parties to controlled transactions

The second table covers the operational half: reach, format, cadence, and source.

ListExtraterritorial reachPublication formatsTypical update cadenceWhere to get it
OFAC SDN ListHigh: secondary sanctions exposure for non-US parties, plus USD-clearing and US-origin-goods nexusXML, CSV, fixed-field and delimited text; Sanctions List Service APINo set schedule; changes can land any business day, sometimes several times a weeksanctionslistservice.ofac.treas.gov
OFAC Consolidated (non-SDN)Moderate, programme-dependentSame as SDNSame as SDNSame as SDN
EU ConsolidatedLimited to EU nexus; applies to business conducted in whole or in part within the EUXML (token-based download); also republished via EU open-data portalsOn adoption or amendment of the underlying RegulationEuropean Commission Financial Sanctions Files service
UN ConsolidatedNone directly: reach comes from national implementationXML, HTML, PDFOn Security Council committee decisionscsanctions.un.org
UK Sanctions ListApplies to UK persons globallyOnline search tool, XML, CSV, ODS, ODT, HTML, text, PDFOn designation or amendmentsanctionslist.fcdo.gov.uk
Australian DFAT ConsolidatedApplies to Australian citizens and bodies corporate globallyXLSXUpdated file published dailyDFAT Consolidated List page
US CSLApplies to US-origin items and controlled technology anywhereJSON and CSV via APIHourlydata.trade.gov

Take one operational point from the second table: there is no common cadence. A single global polling interval either wastes requests against a list that publishes daily, or leaves a gap against one that can change intraday.


Did the UK just change its sanctions list?

Yes. If your feed still points at the old file, you are screening a frozen snapshot. The OFSI Consolidated List of Asset Freeze Targets closed on 28 January 2026 and is no longer updated. The UK Sanctions List, maintained by the FCDO, is now the single source for all UK sanctions designations [GOV.UK, UK Sanctions List].

The UK previously published across two lists: the FCDO's UK Sanctions List (all sanctions types) and HM Treasury's OFSI Consolidated List (financial sanctions only). Two consequences matter operationally:

  • The old ConList.xml endpoint is stale, not empty. A pipeline pointed at it will keep returning results and passing health checks while missing every designation made since January 2026.
  • OFSI has not gone away. It remains the UK's financial-sanctions enforcement and licensing authority. Only the list publication moved.

What is the difference between the SDN List and OFAC's Consolidated list?

The SDN List means blocked: assets frozen, all dealings by US persons prohibited. The Consolidated (non-SDN) List means restricted in a specific way, not frozen. Treating a non-SDN hit as a full block over-blocks legitimate business; treating it as clear misses a real prohibition.

The Consolidated List aggregates several narrower programmes, including the Sectoral Sanctions Identifications (SSI) List covering certain new debt and equity, the Non-SDN Chinese Military-Industrial Complex Companies (NS-CMIC) List covering securities investment, the Foreign Sanctions Evaders (FSE) List, and the Non-SDN Menu-Based Sanctions List. Each carries its own prohibition. The correct response to a hit is to read the programme tag, not to apply a blanket rule.


Is the UN list already covered by OFAC, the EU, and the UK?

No. UN designations bind member states, not private parties directly. Each state implements them through its own law: the EU by Council Regulation, the UK by regulations under SAMLA 2018, Australia under the Charter of the United Nations Act 1945. Implementation is near-universal in substance but not instantaneous, and national spellings, identifiers and scope diverge.

Screening the UN list alongside your national lists is cheap insurance rather than duplication: it catches designations during the implementation lag, and it surfaces name variants that the transposing instrument dropped.


What is the 50% Rule, and do the EU and UK have equivalents?

A company can be sanctioned without appearing on any list. Under OFAC's 50% Rule, an entity owned 50% or more (directly or indirectly, in aggregate, by one or more blocked persons) is itself blocked, even though it is not named on the SDN List [OFAC guidance, 13 August 2014; OFAC FAQs 398–402]. The EU and UK have comparable but not identical tests.

United StatesEuropean UnionUnited Kingdom
Ownership threshold50% or more50% or more (lowered from "more than 50%" in July 2024)More than 50%
Aggregated across multiple designated persons?YesYesNo, not unless holdings are subject to a joint arrangement, or one designated person controls another's rights
Separate control limb?Ownership test is the published rule; control addressed programme by programmeYes: control alone can trigger the measures, independent of ownershipYes: ownership or control
Is the affected entity named on the list?Usually notUsually notUsually not

The EU aligned its ownership threshold with the US in the Council's updated EU Best Practices for the effective implementation of restrictive measures, published 3 July 2024 [Council of the EU, 3 July 2024].

The UK's control test is the least settled of the three. After the Court of Appeal's October 2023 judgment in Mints v PJSC National Bank Trust, FCDO and OFSI guidance of 17 November 2023 stated there is no presumption that a private entity is controlled by a designated public official merely because it operates in that official's jurisdiction; evidence of actual control is required [FCDO/OFSI, 17 November 2023].

The UK's non-aggregation stance may not hold. OFSI opened a call for evidence on the ownership and control test on 16 February 2026, closing 20 April 2026, which explicitly raises adopting an aggregation model in line with the US and EU [OFSI, 16 February 2026]. If that lands, the UK column above changes.

This is the most commonly missed obligation in sanctions compliance, and the one part list screening alone cannot solve. Name matching tells you nothing about who owns the customer. Ownership screening is a separate workstream.


Which lists do I actually need to screen against?

Screen the lists of every jurisdiction whose law reaches you, which usually means more than the country you are incorporated in. Currency, customers, suppliers and cloud all create nexus.

If this is true of your businessMinimum list set
Incorporated in the US, or any USD-denominated payment flowOFAC SDN + OFAC Consolidated
Established in an EU member state, or doing business in part within the EUEU Consolidated + UN Consolidated
UK entity, UK persons on staff, or UK-facing customersUK Sanctions List + UN Consolidated
Australian entity or Australian customer baseDFAT Consolidated + UN Consolidated
Exporting goods, software or technology of US originUS CSL (Entity List, Denied Persons, Unverified List)
Correspondent banking, marketplace, or genuinely global customer baseAll of the above

The row that surprises people is the first. Clearing payments in US dollars routes them through the US financial system, which is enough to create OFAC exposure for a business with no US entity, no US staff and no US customers. OFAC civil liability is strict (no intent required), and the IEEPA maximum civil penalty is the greater of roughly $377,700 per violation or twice the transaction value (2025-adjusted; unchanged into 2026) [OFAC, 90 FR 3687, 15 January 2025].


Is every screening-list hit a sanctions designation?

No. A hit is not automatically a block. Screening feeds routinely blend three legally distinct categories, and a compliance workflow that treats them identically will either over-block or misreport.

  • Sanctions designations: asset freezes and dealing prohibitions. A match stops the transaction.
  • Export-control listings: the BIS Entity List, Unverified List and Denied Persons List. A match creates a licensing requirement or a denial-order restriction on specific items, not a frozen account.
  • Law-enforcement wanted lists: FBI Most Wanted, Interpol Red Notices, national fugitive lists. These are not designations at all. A match is intelligence that feeds a risk decision; it carries no automatic prohibition.

DeRisk Hub ingests sanctions lists, export-control lists, law-enforcement wanted lists, and PEP data as separate categories, tagged so a match against one cannot be mistaken for a match against another. The DeRisk Hub screening platform applies each category to a different decision path, and the compliance glossary defines the terms used across them.


How fast should you ingest each list?

Match the polling interval to the publishing behaviour of each source, not to a single global setting. OFAC can change intraday with no fixed schedule. The US CSL refreshes hourly. DFAT publishes daily. The EU and UK publish when an instrument is adopted.

DeRisk Hub runs two tiers on that basis. The majors are on the fast tier: OFAC SDN and Consolidated, the EU Consolidated List, the UN Consolidated List, the UK Sanctions List and the BIS lists are all polled every five minutes. Near-static sources (smaller-jurisdiction regimes, wanted lists, PEP data) are checked daily, which is both as often as they change and within what those publishers will serve.

Cadence matters because of the exposure window. If a list changes on a Tuesday and you re-screen quarterly, a newly designated customer sits undetected for an average of six weeks. Our earlier post on why continuous sanctions monitoring is non-negotiable for FinTechs works through the operational case.


Frequently asked questions

Is the UN list included in the OFAC SDN List? Not reliably. The US implements UN designations through its own process, and the two lists diverge in timing, transliteration and scope. Screen both.

Does a US company need to screen EU lists? Only if it has EU nexus: an EU subsidiary or branch, EU-located staff, EU customers, or business conducted in part within the EU. A purely domestic US business does not. Any business with EU operations does, and EU law applies to those operations independently of US law.

Is the OFSI Consolidated List still valid? No. It closed on 28 January 2026. Use the UK Sanctions List published by the FCDO.

How often do sanctions lists change? It varies by list, from potentially several times a week (OFAC) to on-adoption only (EU, UK). There is no schedule you can rely on across all sources, which is why per-list polling intervals matter.

Do I need to screen subsidiaries of designated entities? Yes, but the tests differ. Under OFAC and the EU, aggregate ownership of 50% or more by designated persons can catch an unnamed entity. Under the UK, the threshold is more than 50% held by a single designated person (absent a joint arrangement or control). Name screening alone will not find these entities. You need ownership data.


Citations


Screening the right lists, automatically

Knowing which lists apply is the easy half. Keeping them current and re-screening your book whenever one changes is what consumes compliance teams.

DeRisk Hub ingests the lists in this comparison and re-screens existing entities automatically on every source change, with every decision written to an audit trail. See the screening platform, Start your free trial, or go to DeRiskHub.com.

This article is informational and does not constitute legal advice. Regulatory positions described here were verified against the issuing bodies' published material on 5 August 2026 and change frequently; confirm against the primary source before relying on any of it.