us

216.73.216.229

Back
Blogs

Secondary Sanctions: What They Are and Why Non US Companies Face Real Exposure

Secondary Sanctions: What They Are and Why Non US Companies Face Real Exposure
Amir RizwanAmir Rizwan JUNE 1, 2026 15 minutes read

Secondary sanctions are not enforced with penalties, so OFAC enforcement data hides your exposure. Where the risk is actually recorded, and what puts a non-US firm there.

“Do non-U.S. companies risk exposure to sanctions for providing ammunition or other military goods to Russia or for supporting Russia’s military-industrial complex?”. This particular question was asked in the published guidance of the US Office of Foreign Assets Control (OFAC), and its answer to put it simply was, yes.

No US office is needed for that answer to reach you, and neither is a US customer, a US bank account, or an American on the payroll. Most compliance teams outside the United States go hunting for their exposure in OFAC’s enforcement record, where the penalties are published and the figures are large. That record will not show it, because secondary sanctions are not enforced with penalties at all.

What are Secondary Sanctions?

Secondary sanctions are measures one country imposes on foreign companies for doing business with parties that country has sanctioned, even when the transaction never touches its territory. The United States; government actively applies them at scale.

Primary sanctions work in a way most people expect laws to work. The US prohibits US persons, meaning US citizens, US-incorporated companies, and anyone physically in the United States, from dealing with a sanctioned party. If this rule is broken then it is synonymous to having broken a US law.

Secondary sanctions, however, work differently. A bank in Dubai, a trading house in Singapore, or a shipping agent in Istanbul is not bound by US sanctions law in the first place. But, there is instead a consequence attached to this relationship. If a deal goes through with the wrong counterpart or a rival then there is a risk of losing one’s entire access to the American market, the correspondent banking relationships and one’s ability to clear payments in American dollars.

Difference Between Primary and Secondary Sanctions

The two regimes draw on the same watchlists, so the names look identical. What differs is who is bound, what happens to you, and where the warning appears.

# Primary sanctions Secondary sanctions
Who is bound US persons and US-incorporated entities Non-US persons and companies, anywhere
US nexus required Yes, a US person, US territory, or US-origin goods No
What it does Prohibits the transaction outright Attaches a consequence to the transaction
If you proceed You have violated US law You have not violated US law, you have become sanctionable
Typical consequence Civil penalty, criminal referral SDN designation, loss of correspondent accounts, market exclusion
Where it surfaces OFAC civil penalty list SDN List and CAPTA List
Advance warning Regulatory prohibition, published in advance A notation on the counterparty’s list entry

Difference between Primary and Secondary Sanctions

Where the Distinction Holds, and Where it Fails

The distinction sounds academic until you try to brief a board on it. The Congressional Research Service puts the mechanism plainly. In its analysis of the North Korea programme, it notes that such restrictions:

“Do not prevent foreign persons from engaging in prohibited transactions with North Korea, but carry the risk that if they do so, they may be subject to U.S. sanctions”.

The same structure runs through every secondary sanctions authority, and OFAC’s own drafting follows it, because its guidance describes non-US persons as risking “exposure” to sanctions rather than committing violations.

There is an important establishment, though. Non-US firms can still break US sanctions law directly. OFAC states that non-US persons are prohibited from causing or conspiring to cause a US person to violate sanctions, from engaging in conduct that evades US sanctions, and in some programmes from re-exporting US-origin goods or technology in breach of the rules. A foreign firm that routes a payment through a New York bank while concealing the sanctioned party has not incurred designation risk, it has caused a violation, and that is prosecutable.

Which OFAC programmes carry secondary sanctions provisions?

Not every OFAC programme includes secondary sanctions authority. The ones that generate most of the exposure for non-US firms sit in a handful of country programmes, with Iran and Russia carrying the widest reach.

Iran, the oldest and widest authority

Iran-related authorities have carried secondary sanctions provisions the longest, and they remain the most detailed. Non-US persons, including foreign banks, can be sanctioned for knowingly engaging in significant transactions with Iranian parties on the SDN List, or with persons designated in connection with terrorism support or weapons proliferation.

Because the authority is old and heavily used, it is also the programme where OFAC’s list annotations are most developed, which matters for the practical question of how you spot the risk.

Russia, under E.O. 14024 as amended by E.O. 14114

Russia is where the reach expanded most recently. Executive Order 14114, issued on 22 December 2023, amended Executive Order 14024 to let OFAC sanction foreign financial institutions that handle transactions involving Russia’s military-industrial base.

The order gives OFAC two tools. It can block the institution outright, or it can prohibit or impose strict conditions on that institution’s correspondent accounts and payable-through accounts in the United States. A correspondent account is the account a foreign bank holds with a US bank so it can move dollars, so losing one removes a bank’s ability to serve dollar-paying customers.

The covered sectors are named in the order and include technology, defence and related material, construction, aerospace, and manufacturing.

The Three Mechanisms OFAC Actually Uses

Most explanations treat secondary sanctions as one thing. In practice OFAC reaches for three separate instruments, and they produce very different outcomes.

Mechanism What OFAC does Effect on the foreign firm Where it appears
SDN designation Adds the foreign person to the Specially Designated Nationals List Assets blocked, US persons must stop dealing with you, effective global exclusion SDN List
Menu-based sanctions Selects from a statutory menu, for example five or more measures under CAATSA section 235 Varies by selection, from export licence denial to banking restrictions Programme-specific announcements
Correspondent account restriction Prohibits or conditions US correspondent and payable-through accounts Dollar clearing restricted or cut, without full blocking CAPTA List

The CAPTA List is worth knowing about specifically, because it is not part of the SDN List. It sits with OFAC’s other non-SDN lists in the consolidated list, which means a screening configuration pointed only at the SDN List will not see it.

Three OFAC secondary sanctions mechanisms

What Triggers Secondary Sanctions Exposure for a Non US Firm?

Exposure rarely arrives through a decision anyone made deliberately. It arrives through a payment route, a counterparty’s counterparty, or an ownership structure nobody traced to the end.

Dollar clearing and correspondent banking

Most global trade is still priced and settled in dollars. When a dollar payment clears, it typically passes through a correspondent bank in the United States, and at that moment the transaction becomes visible to US authorities.

That visibility is what gives secondary sanctions their practical force. A firm can have no US entity, no US staff, and no US customers, and still route almost every payment it makes through US infrastructure. What the US holds is not legal reach over your business but a chokepoint in the payment plumbing that carries your money.

Counterparties, Vessels, and the 50% Rule

Your own customer is the easy part to screen. Secondary sanctions exposure usually sits one step further out, in the counterparty your customer pays, the vessel that carries the cargo, or the parent company behind the trading entity on the invoice.

Ownership is where this gets technical. Under OFAC’s 50 Percent Rule, an entity is treated as blocked if it is owned 50 percent or more, directly or indirectly, by one or more blocked persons, and OFAC aggregates those holdings. Two designated individuals holding 25 percent each is enough to block the company they jointly own, even though neither crosses the threshold alone. The company itself never appears on any list, so a name-matching check will clear it.

One nuance is easy to miss. The 50 Percent Rule addresses ownership and not control, so an entity controlled by a blocked person without the ownership stake is not automatically blocked, which means it needs a judgement call rather than a rule lookup.

The Jurisdictional Gap

Sanctions evasion tends to exploit the seams between regulators rather than any single institution’s controls. Andrei Sribny, who leads the AML Certification Center, framed the pattern this way in a Shufti panel discussion.

“In most cases criminals don’t need to challenge the technology. They exploit inconsistencies between jurisdictions. The strength of a verification process is determined by the weakest point in the chain, and that weak point is very often a country, not a tool.”

For secondary sanctions the observation is exact. A structure is assembled where corporate transparency is thin, then used in a market where controls are assumed to have already happened upstream. Your screening engine performs correctly at every step and still misses the exposure, because the gap is in registry quality rather than in match logic.

Where Should you Look to Find Secondary Sanctions Risk?

Here is the part almost no explainer covers. OFAC does not leave secondary sanctions exposure for you to infer, because it writes the warning directly into the list entry.

When a person is designated under an authority that carries secondary sanctions consequences, OFAC adds a notation reading “Additional Sanctions Information – Subject to Secondary Sanctions” to that person’s SDN List entry, alongside the tag for whichever programme designated them. The tag tells you why they were listed. The notation tells you what dealing with them would do to you.

That single field changes the compliance question from a research project into a screening configuration. A team that ingests the SDN List but discards the additional-information field has thrown away the only machine-readable indicator of its own secondary sanctions exposure.

Three sources carry the picture between them:

  1. The SDN List: This is for designations and the secondary sanctions notation attached to them.
  2. The CAPTA List: This is for foreign financial institutions whose US correspondent accounts have been restricted rather than blocked.
  3. The civil penalty list, This for telling about primary sanctions enforcement and almost nothing about your position as a non-US firm.

The 2025 penalty figures make the last point concrete. OFAC published 14 civil penalties totalling $265,746,819 that year, and the roster is American. The largest, a $215,988,868 penalty against GVA Capital Ltd., went to a firm in San Francisco. That is not evidence that non-US firms escaped scrutiny during 2025, it is evidence that the instrument used against them leaves no trace on that particular page.

Are secondary sanctions legal under international law?

The honest answer is that the question has never been settled.

What the critics argue

The United Nations Special Rapporteur on unilateral coercive measures examined secondary sanctions in a 2022 report and basically reached a conclusion that

“The extraterritorial jurisdiction claimed by sanctioning States when imposing secondary sanctions is not recognized as legal under international law, but the use of secondary sanctions is expanding as States impose more primary sanctions”.

The report grounds that view in sovereignty and non-intervention, and in the observation that targets are generally designated without charge or trial.

The European Union reached a similar conclusion much earlier. The recital to Council Regulation (EC) No 2271/96 states that by their extraterritorial application, such laws violate international law.

Against that, no court has agreed or disagreed. No international court or tribunal has ruled on the legality of US secondary sanctions. The International Court of Justice case most often cited in this context, Certain Iranian Assets, concerned the attachment of Iranian state assets under US terrorism judgments rather than secondary sanctions, and the separate Iranian challenge to the 2018 sanctions snapback has never reached a merits judgment.

Secondary sanctions vs extraterritorial jurisdiction

The two terms get used interchangeably, and they are not the same thing.

Extraterritorial jurisdiction means a state applying its own law to conduct outside its borders, so that the foreign conduct becomes lawful or unlawful under that state’s rules. Secondary sanctions, in their classic form, do something narrower. They leave the foreign conduct legally untouched and instead condition a benefit, namely access to the US market and financial system, on whether you engage in it.

That framing is the strongest defence of the practice, and it is worth being precise about its provenance. The argument is made mainly by legal scholars rather than by the US government, and where Washington has set out a jurisdictional theory in statute, as in the 1996 Helms-Burton Act, it asserted the effects doctrine outright rather than the market access argument.

The distinction also has limits. Once a penalty rather than an exclusion is imposed, the “we are only withholding a privilege” reasoning becomes much harder to sustain.

The EU Blocking Statute problem

For EU-based firms the tension is not theoretical. The Blocking Statute prohibits EU operators from complying with the listed US measures, which are the Cuba and Iran regimes. In 2021 the Court of Justice of the European Union held in Bank Melli Iran v Telekom Deutschland that the prohibition applies even where a company complies voluntarily and was never ordered to by a US authority.

An EU company caught between the two regimes therefore faces a genuine conflict of laws rather than a compliance preference, which is a matter for external counsel and not for a screening policy.

How can a non-US firm manage secondary sanctions risk?

Effective practice here goes beyond a name check against the SDN List, because the exposure sits in fields, lists, and structures a basic screening pass never reads.

  1. Screen the full list suite, not just the SDN List: Add the CAPTA List and OFAC’s other non-SDN lists. A configuration pointed only at the SDN List misses correspondent account restrictions entirely.
  2. Capture the secondary sanctions notation: Ingest the additional-information field, not only the name and programme tag, and route matches carrying that notation to a separate queue. It is a different risk that needs a different decision.
  3. Trace ownership to the natural persons: Apply the 50 Percent Rule with aggregation, and treat control without ownership as a judgement call requiring enhanced due diligence rather than an automatic clear.
  4. Extend screening past your direct customer: Counterparties, vessels, ports, and intermediaries carry the exposure in trade finance and shipping, so screen the transaction chain and not only the account holder.
  5. Re-screen continuously and document the reasoning: Designation happens between your periodic reviews, and a defensible file records why a decision was made rather than only what was flagged.

The fifth point is where most programmes are thinnest. Noor Ali, Partner and Head of Middle East at Bit Comply, drew the distinction sharply during a Shufti panel.

“Smart screening gives you a shorter, more precise list of alerts; contextual screening gives you a verdict with the reasoning behind it. And that’s what regulators increasingly want, not just what you flagged, but why you decided.”

How Shufti helps compliance teams see secondary sanctions exposure

The gap most teams hit is not the customer in front of them, it is everything one step behind that customer. Secondary sanctions exposure travels through counterparties, vessels, and ownership layers that a name check against a single list will never surface, and it changes between periodic reviews rather than at onboarding.

Shufti’s AML screening screens corporate entities, vessels, aircraft, and ports on the same data foundation as individuals, against 215+ sanction regimes, with continuous re-screening that refreshes every 15 minutes rather than in a daily batch. A counterparty designated on a Tuesday afternoon reaches your alert queue that afternoon, which is the difference between stopping a payment and explaining one.

See how Shufti’s screening layer reads the full OFAC list suite against your own counterparty data, then book a demo.

Frequently Asked Questions

What is the difference between primary and secondary sanctions?

Primary sanctions bind US persons and prohibit them from dealing with sanctioned parties, so breaching them violates US law. Secondary sanctions apply to non-US firms with no US nexus and do not prohibit anything, they attach a consequence, usually designation or loss of US market access.

Which OFAC programmes carry secondary sanctions provisions?

Iran carries the oldest and widest authority. Russia follows, under Executive Order 14024 as amended by Executive Order 14114 in December 2023. North Korea, Syria, and Venezuela-related authorities also generate exposure for non-US firms.

Can a non-US company be penalised under US secondary sanctions?

Not usually with a fine. The standard consequence is designation on the SDN List or a restriction on US correspondent accounts. A non-US company can face direct penalties separately, if it causes a US person to violate sanctions, evades them, or breaches re-export rules.

What triggers secondary sanctions exposure?

Conducting a significant transaction with a designated party, or with a person operating in a covered sector such as Russia's defence or aerospace industries. Dollar clearing through US correspondent banks is what typically makes the transaction visible.

How can a non-US firm manage secondary sanctions risk?

Screen the full OFAC list suite including the CAPTA List, capture the secondary sanctions notation on SDN entries, trace ownership under the 50 Percent Rule, extend screening to counterparties and vessels, and re-screen continuously with documented reasoning.

What is the difference between secondary sanctions and extraterritorial jurisdiction?

Extraterritorial jurisdiction applies a state's law to conduct abroad, making that conduct lawful or unlawful under its rules. Secondary sanctions leave foreign conduct legally untouched and instead condition access to the US market on it, which is why exposure means designation risk rather than illegality.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Join the
Shufti Sphere Newsletter

Get the latest trends, insights, and expert opinions on KYC, AML, fraud prevention, and more, straight to your inbox.

    Pitch a piece and get a verified byline in the Media room.

    Partnership Inquiries?
    Email us at [email protected]

    iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
    Copyright © 2026 Shufti. All rights reserved.