OFAC's 50 Percent Rule, articulated in the agency's revised guidance of August 13, 2014, provides that any entity owned fifty percent or more in the aggregate by one or more blocked persons is itself blocked property — even if the entity appears on no sanctions list — so a payment to a perfectly clean-looking LLC can be a prohibited dealing when two sanctioned individuals hold thirty percent and twenty-five percent of it respectively. For payments and correspondent programs, the rule converts list-based screening into an ownership-inference problem, and the difference between the two disciplines is where violations hide.
3G Times publishes information, not legal advice. Sanctions compliance is enforcement-exposed and fact-specific; ownership analysis belongs with sanctions counsel.
How does the rule work mechanically?
List screening asks whether a name matches; the rule asks who profits. Blocked persons — those on OFAC's list — include individuals and entities. When blocked persons' ownership stakes in another entity sum to fifty percent or more, that entity is blocked by operation of the rule: its property and interests must be blocked, and US persons cannot deal with it. The aggregation across multiple blocked persons is the step screening engines historically missed, because each individual stakeholder may sit below matching attention while the sum crosses the line. Two boundary readings matter: ownership, not control — a blocked person who directs but does not own an entity does not trigger the rule (though other theories may reach the conduct) — and the fifty-percent threshold itself, with the guidance drawing the line at fifty percent or more.
| Structure | Blocked status | Screening consequence |
|---|---|---|
| 51% owned by one SDN | Blocked by rule | Treat as SDN-equivalent |
| 30% + 25% held by two SDNs | Blocked by aggregation | Ownership graph required |
| 49% owned by one SDN | Not blocked by rule | Risk-note; watch for changes |
| SDN controls, does not own | Not blocked by rule | Other exposure theories |
| Rule-blocked entity's subsidiary | Blocked by inheritance | Graph traversal continues |
Why is the rule hard for payment systems?
Because the data architecture differs. Payments programs excel at name-and-identifier matching against lists updated daily; ownership data is slower, costlier, and structurally awkward — registry filings lag reality, beneficial-ownership reporting regimes have their own timelines, and nested chains (a rule-blocked entity owning another owning another) require traversal rather than lookup. The correspondent context compounds it: a downstream institution's customer may transact with a rule-blocked entity that only the correspondent's visibility could connect. OFAC's enforcement history prices the gap: settlements repeatedly cite dealings with entities blocked by the rule — unlisted, aggregated-owned — where the institution's program screened lists competently and inferred ownership not at all.
What does an ownership-aware program add?
Three layers beyond the list. Ownership data acquisition: corporate-registry sources, beneficial-ownership filings where available, and commercial ownership databases, fused into a graph with timestamps — ownership changes over time are themselves risk events. Aggregate computation: for each counterparty, sum blocked-person stakes on a rolling basis, recompute on list updates and ownership refreshes, and flag crossings of the threshold in either direction. Traversal: propagate blocked status through chains — a fifty-one-percent-owned subsidiary of a rule-blocked entity is blocked property in turn — and through the payment path itself, so the customer's counterparty two hops away inherits the analysis. The alert outputs are actionable precisely because they name the ownership chain, which is what investigators and counsel need to clear or confirm.
How does this interact with the travel-rule and KYC stack?
Synergistically, when designed to be. The beneficial-ownership data KYC programs already collect for the corporate transparency regime is the same data the rule's computation consumes — different threshold, different purpose, one source of truth. The travel rule's counterparty packets and ISO 20022's structured party fields give payment screening richer identifiers to join against the ownership graph. And the examinable artifact converges: a screening program that documents list matching, ownership aggregation, and traversal with data-refresh timestamps answers the supervisory question — "how do you reach what lists do not show" — in one architecture instead of three disconnected ones.
What does this mean in practice?
- Fuse ownership data into the screening pipeline — registry and beneficial-ownership sources with refresh cadences, not one-off diligence snapshots.
- Compute aggregates on list updates. A designation changes the math for every partially-owned counterparty; recompute on the SDN delta, automatically.
- Traverse the chains. Blocked status inherits; the graph that stops at one level misses the subsidiary that carries the exposure.
- Document the methodology. The exam question is the inference process — data sources, refresh logic, aggregation rules — because the rule itself is invisible in any list.
The 50 Percent Rule is OFAC's quietest instruction and its most structural: the sanctions perimeter is an ownership lattice, not a name list. Programs that learned to compute the lattice treat an unlisted counterparty as a question with an answer; programs that never did treat the same counterparty as clean by default, which is precisely the assumption the rule exists to punish.
The program-maturity signal examiners read is refresh cadence: ownership graphs re-computed on every SDN delta and every registry refresh, with the computation log retained. The institution that can show today's aggregate for any counterparty from yesterday's designation is operating the rule as designed; the one that batches recomputation monthly is holding exposures the list already priced.
The synthesis returns to the rule's elegance: OFAC wrote one sentence in 2014 that converted every unlisted counterparty into an arithmetic question. The institutions that operationalized the arithmetic — data fused, aggregates computed on designation deltas, chains traversed — answer the question reliably in milliseconds; the rest of the market answers it, occasionally and expensively, in enforcement settlements.
How does crypto ownership complicate the rule?
On-chain and protocol-based ownership resists the registry logic the rule assumes — control surfaces without stake registries, treasury multisigs without filings — so the analysis leans on the control-and-facts theories accompanying ownership under each program. The graph discipline survives: whatever the source of ownership truth, aggregation and traversal still decide whether an entity is blocked property.
Frequently asked questions
Does 49.9 percent ownership ever matter?
Not under the rule itself — below the threshold, the entity is not blocked by ownership. But stakes move, and the same structure at fifty-one percent tomorrow blocks the entity; monitoring near-threshold holdings is cheap insurance against arithmetic drift.
Are foreign persons covered?
The rule binds US persons, including foreign branches and, per specific programs, entities owned by US persons. Non-US banks feel it through correspondent relationships and US-dollar clearing — the reason rule-aware screening is a global standard rather than an American one.
The ownership data quality caveat completes the honest limits: registries lag, filings occasionally lie, and layered jurisdictions hide stakes behind nominees. The rule-aware program documents sources and their vintage precisely because perfect ownership truth does not exist — the standard is reasonable diligence with recorded methodology, an examinable artifact rather than an epistemological one.
What about EU or UK equivalents?
The UK and EU maintain similar ownership-or-control concepts with their own formulations — the EU's listed-covers and the UK's ownership-and-control tests — and the graph-based program satisfies all of them with per-regime computation layers on one data foundation.
For more context, read Who the FTC Safeguards Rule Covers, and When Its Incident-Notification Requirement Triggers.
For more context, read ecoa adverse action notices ai.
For more context, read off-channel communications sec settlements.

