A multinational bank settles an OFAC enforcement matter. The settlement includes a compliance monitorship – an external examiner embedded in the institution for two or three years, reporting on remediation progress. Eighteen months later, the same institution faces an EU Council investigation into payments touching a designated entity. Brussels also wants a monitorship. Same bank. Two monitors. Two regimes. And, in our experience, two almost irreconcilable expectations of what a monitor is actually there to do.
Managing a compliance monitorship under OFAC and under the EU sanctions regime differ in legal basis, scope, monitor independence, and reporting obligations. OFAC monitorships arise under settlement agreements governed by IEEPA and are supervised by OFAC directly. EU monitorships are rarer, arise under Council regulations or Member State enforcement, and their form varies by jurisdiction. The divergence is material: a business that treats the two processes as interchangeable risks non-compliance under both.
This analysis maps the key points of divergence criterion by criterion, identifies the practical risk flags for a business subject to both regimes, and sets out when cross-border counsel is essential.
How does a compliance monitorship arise under OFAC?
An OFAC compliance monitorship arises as a condition of a settlement agreement resolving an apparent violation (OFAC's term for a potential breach that has been disclosed, investigated, and agreed for civil resolution). The legal basis is OFAC's authority under IEEPA and the relevant programme regulations. OFAC has published a framework document setting out what it considers the five essential elements of an effective compliance programme – management commitment, risk assessment, internal controls, testing and auditing, and training – and a monitorship is designed to verify that the settling party is building those elements into its operations.
The settlement agreement itself defines the monitor's mandate. Typically it identifies the monitor's term, the reporting cadence, the subject-matter scope (which business lines, which sanctions programmes, which geographies are in scope), and the standard against which the institution will be measured. OFAC retains the right to review monitor reports and to take further enforcement action if the remediation falls short.
In our cross-border practice, businesses frequently underestimate the administrative burden at this stage. The monitor is not an adviser to management. The monitor reports to OFAC, not to the institution. That structural distinction – whose agent the monitor is – shapes everything that follows.
How does an EU sanctions monitorship differ in legal basis and structure?
The EU sanctions regime does not maintain a single, codified monitorship process comparable to OFAC's. Enforcement of EU Council regulations is primarily a matter for individual Member States, and the form of remedial oversight therefore varies by national competent authority. Some Member States impose monitorship-style conditions through administrative settlement or criminal law cooperation procedures; others rely on enhanced supervisory engagement with the relevant financial regulator. The EU General Court and the Court of Justice play a role in designation challenges, but not in monitorship design.
Where an EU monitorship does exist, it is most commonly found in the context of cross-border institutions that are simultaneously subject to prudential supervision. The monitor's mandate may overlap with that of the prudential supervisor, creating a governance question about which authority takes precedence when reports conflict. That question has no settled answer at EU level.
A further structural difference: the EU relies heavily on national financial intelligence units and competent authorities to identify breaches and impose conditions. The absence of a single EU-level enforcement body with OFAC's degree of direct settlement authority means that a business managing EU exposure across multiple Member States may find itself dealing with several parallel oversight structures simultaneously. The position above covers the standard case. Your facts – the counterparties involved, the Member States with jurisdiction, the goods or financial flows in question – change the analysis considerably.
For an assessment of your EU enforcement exposure, contact Calder & Vance at info@caldervance.com or review our EU apparent violation assessment service.
What does the monitor's role actually require in each regime?
Under OFAC, the monitor's principal obligation is to assess and report on the institution's progress against the remediation commitments made in the settlement agreement. The monitor reviews policies, tests controls, interviews staff, and samples transactions. Reports go to OFAC, with copies to the institution. The institution has a right to respond to draft findings, but the monitor's conclusions are the conclusions that reach the regulator.
The monitor's scope under OFAC is typically sanctions-specific. It does not ordinarily extend to anti-money-laundering controls or trade compliance unless those topics are expressly included. Businesses sometimes assume that a strong AML programme satisfies a sanctions monitor. It does not. The two programmes address different legal requirements, and an OFAC monitor is not assessing AML compliance unless the settlement agreement says otherwise.
Under EU national enforcement procedures, the monitor – where one is imposed – may have a broader remit. Some Member State competent authorities treat financial-crime controls holistically, meaning that the monitor examines both sanctions screening and the broader financial-crime architecture. That broader scope can be an advantage (a single oversight process) or a disadvantage (a higher bar to satisfy). In our experience, institutions that negotiate the monitorship terms at the outset consistently achieve better outcomes than those that accept the default scope.
Rhetorical question: if your monitor's mandate was drafted by OFAC's settlement team and is silent on EU obligations, does it cover the EU competent authority's requirements at all? Almost certainly not.
Where do the regimes diverge on managing a compliance monitorship?
The most significant divergences between OFAC and EU monitorships fall into four categories: reporting destination, independence standards, scope of review, and interaction with criminal proceedings.
On reporting destination, OFAC monitorships report directly to the agency. EU monitorships typically report to a national competent authority, a financial regulator, or a criminal court, depending on the procedural vehicle. Where the institution operates in multiple EU Member States, the question of which authority receives the primary report – and which authorities receive copies – requires careful coordination.
On independence standards, OFAC guidance indicates that the monitor must be independent of the settling institution and approved by OFAC. The EU does not maintain a single published standard, although most Member State competent authorities require that the monitor have no prior relationship with the institution and no financial interest in the outcome. In practice, the pool of qualified monitors is not large, and conflicts-of-interest checks at appointment are more rigorous than they were previously.
On scope of review, OFAC monitorships are programme-specific; EU monitorships may be institution-wide. That difference in scope drives a material difference in cost and management burden. A major institution subject to both simultaneously should plan for two separate governance tracks – one feeding the OFAC monitor, one feeding the EU oversight – with a small coordination function to prevent inconsistent representations to each.
On interaction with criminal proceedings, the US Department of Justice may run a parallel criminal investigation where OFAC has reached a civil settlement. A monitor report that goes to OFAC can, in certain circumstances, be accessible in those proceedings. EU criminal investigations similarly present document-privilege questions that differ from those in US discovery. Counsel should advise on privilege architecture at the outset of any monitorship, not after the first report has been filed.
What are the main risk flags for a business managing both regimes simultaneously?
A business managing an OFAC monitorship while simultaneously subject to EU sanctions oversight faces a specific set of risk flags that are distinct from the risks of each monitorship in isolation. Identifying them early is the most cost-effective risk-management step available.
The first risk flag is inconsistent remediation narratives. The OFAC monitor report and the EU competent authority report are not privileged from each other in most circumstances. If the institution's account of its historical controls or the cause of a violation differs between the two reports, that inconsistency becomes an enforcement liability in both jurisdictions. In our practice, we regularly advise institutions to establish a single factual record before either monitorship begins, and to maintain that record consistently.
The second risk flag is scope creep. OFAC monitorships can be extended if OFAC believes the institution's remediation is inadequate. EU national authorities similarly have discretion to expand the period of oversight. An institution that is simultaneously experiencing scope creep in both monitorships faces a compounding cost and management-attention problem that can itself impair compliance.
The third risk flag is monitor coordination. If the OFAC monitor and the EU monitor are different firms (which is frequently the case), they may reach different conclusions about the adequacy of a control. The institution then faces a gap it must remediate twice – once to satisfy each monitor's standard. Establishing a clear internal governance structure that manages monitor communications, document production, and management responses is not optional; it is the foundation of a successful parallel-monitorship strategy.
The fourth risk flag is secondary-sanctions exposure during the monitorship period. If the institution is under OFAC oversight and processes a transaction that touches an EU-designated entity, OFAC will treat that as a potential new violation, likely aggravated by the fact that the institution was on notice through the monitorship. The UK's OFSI similarly takes the position that a business under sanctions scrutiny is held to a higher standard of care. Have you mapped your ongoing transaction flows against all three designation lists – OFAC, EU, and OFSI – since the monitorship began?
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss a confidential review.
How does the UK OFSI position interact with OFAC and EU monitorships?
The UK's OFSI (Office of Financial Sanctions Implementation) operates a sanctions enforcement regime that is legally distinct from both OFAC and the EU Council. Following the United Kingdom's departure from the EU, OFSI has developed its own enforcement guidance under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic sanctions regulations.
OFSI does not currently operate a formal monitorship programme of the kind used by OFAC. Its enforcement tools include monetary penalties, publication of enforcement decisions, and – for more serious cases – referral to law enforcement. However, OFSI can and does impose enhanced compliance conditions as part of a settlement, and those conditions can in practice function as an informal monitorship.
For a business that has settled with OFAC and is also subject to OFSI scrutiny, the key interaction risk is the mandatory reporting obligation. OFSI requires firms subject to financial-sanctions obligations to report knowledge or reasonable suspicion of a sanctions breach. That reporting obligation is not suspended because the institution is under OFAC monitorship. A discovery made during an OFAC monitor's review that implicates a UK sanctions programme must be assessed for OFSI reporting purposes on its own timetable – a short statutory window that does not wait for the OFAC process to conclude. Verify the current position before relying on it, and take advice on the specific reporting timeline as soon as an issue is identified.
In our experience, the OFSI dimension is the one most frequently overlooked by US-centric compliance teams managing an OFAC monitorship. That oversight creates a separate enforcement liability in a jurisdiction where OFSI's enforcement posture has become progressively more active.
A divergence scenario: one transaction, two monitors, three regulators
Consider an anonymised scenario drawn from the type of matter we handle. A financial institution headquartered in the United States, with a significant European branch, settles an OFAC matter and accepts a two-year monitorship covering its US correspondent banking operations. Twelve months in, the institution's European branch processes a payment that the EU competent authority determines may have involved a designated entity under an EU Council regulation. The EU authority opens an inquiry. The OFAC monitor, whose mandate covers the US entity, is not formally required to report on the EU matter – but the factual record the monitor has already developed is directly relevant to the EU inquiry.
The institution now faces three competing demands: the OFAC monitor's ongoing review, the EU competent authority's inquiry, and OFSI's mandatory reporting assessment. Each authority has different document-production expectations, different evidentiary standards, and different timelines. The institution's legal team had not anticipated the three-way intersection and had no pre-positioned coordination protocol.
We have acted for institutions in comparable positions. The single most important lesson is that the governance architecture for a monitorship – who owns each regulatory relationship, who controls document production, who has authority to make factual representations – must be established before the monitorship begins, not after a second jurisdiction becomes active. The cost of building that architecture after the fact is a multiple of the cost of building it at the outset.
When should a cross-border business involve counsel in a monitorship?
Counsel should be involved before the monitorship terms are finalised, not after. The settlement agreement that establishes an OFAC monitorship defines the monitor's mandate, the reporting cadence, the remediation milestones, and the consequences of failure. Each of those elements is negotiable within limits, and the terms agreed at settlement set the institution's obligations for the entire monitorship period.
The positions that matter most at the negotiation stage include: the scope of the monitor's mandate (which programmes, which geographies, which business lines); the confidentiality and privilege protections attached to monitor reports; the standard against which remediation will be assessed; and the procedure for disputing monitor findings. Agreeing inadequate terms at settlement creates a multi-year compliance burden that cannot easily be renegotiated.
A common myth is that a strong internal compliance function makes external counsel unnecessary during a monitorship. That is not the case. Internal compliance teams are responsible for running the programme; external counsel is responsible for managing the regulatory relationship, protecting privilege, advising on the legal significance of monitor findings, and identifying when a finding creates exposure under a different jurisdiction's regime. Those two roles are complementary, not substitutable.
Counsel is also essential when a monitorship overlaps with an active investigation by a different authority – DOJ, OFSI, an EU Member State – because decisions made in one proceeding (what to produce, what to acknowledge, how to characterise a control failure) can have consequences in the others. In our cross-border practice, we regularly advise institutions managing exactly this intersection, coordinating strategy across the OFAC, OFSI, and EU dimensions simultaneously.
Related practices
- EU Apparent Violation Assessment – identifying and scoping potential breaches under EU Council sanctions regulations
- OFAC vs EU: Managing a compliance monitorship – Part 2 – deeper analysis of monitor selection, reporting mechanics, and escalation procedures