A multinational with operations across both the United Kingdom and the European Union discovers, mid-transaction, that a payment has been processed to a counterparty whose ultimate beneficial owner may be subject to financial sanctions. The compliance team freezes the next payment. The legal team asks the question that decides the next six months: should we open a formal internal investigation, and if so, under which regime's rules do we run it? The answer is not the same in London as it is in Brussels. As of March 2026, the divergence between the OFSI and EU approaches to internal sanctions investigations is wide enough to shape every decision in that process – from how you document, to when you report, to how you engage the regulator.
Internal sanctions investigations (structured internal reviews of whether a potential sanctions breach has occurred, what was processed, by whom, and under which regime) are governed in the UK by OFSI under the Sanctions and Anti-Money Laundering Act (SAMLA) and by OFSI's enforcement guidance, and in the EU by the relevant Council Regulations administered through Member State competent authorities. The two regimes share the same ultimate goal – identify the violation, report where required, and remediate – but they differ materially on reporting timelines, voluntary disclosure mechanics, penalty mitigation, and the role of legal privilege in the investigation file.
This analysis sets out the two regimes criterion by criterion, maps the points of divergence that matter most to a cross-border compliance officer, and explains when to involve external sanctions counsel. We address the UK position first, the EU comparators second, and close with the practical decisions a business faces when both regimes are simultaneously engaged.
What triggers an internal sanctions investigation under OFSI and the EU?
An internal sanctions investigation is triggered when a business has reason to believe that it holds, controls, or has dealt with funds or economic resources belonging to a designated person – and needs to determine whether that belief is well-founded, and whether a reportable event has occurred. Under OFSI, the trigger is defined by SAMLA and the relevant thematic regulations: any person who knows or suspects that they hold or control funds or economic resources owned or controlled by a designated person must report to HM Treasury. The suspicion threshold is deliberately low.
Under the EU position, the equivalent obligation sits in the relevant Council Regulation for each programme. Member State competent authorities – in France, Germany, the Netherlands, and elsewhere – each apply the Council Regulation through national implementing legislation. The practical result is that the trigger point is broadly aligned with the UK, but the authority to whom you report, the format of reporting, and the consequence of late or incomplete reporting varies by Member State. A business with entities in Frankfurt, Amsterdam, and London faces three separate reporting chains, even for a single incident.
The first practical decision in any cross-border investigation is therefore to map every entity touched by the potential violation and every regime potentially engaged. Have you identified every payment leg, every entity, and every jurisdiction of incorporation? That mapping exercise is the foundation of everything that follows.
How do OFSI and EU enforcement authorities run an investigation from the outside in?
Once a regulator is engaged – whether through voluntary disclosure, a suspicious activity report, or its own intelligence – the investigation mechanics differ significantly between OFSI and the EU competent authorities.
OFSI operates as the UK's financial sanctions implementation and enforcement authority under HM Treasury. It has powers to request information, to require the production of documents, and to impose civil monetary penalties without a criminal prosecution. OFSI's enforcement guidance sets out a tiered approach to penalty outcomes: a business that has voluntarily self-disclosed, cooperated fully, and put remediation measures in place can expect substantially lower penalties than a business that did not. The guidance also distinguishes between cases OFSI handles as regulatory matters and those referred to law enforcement for criminal investigation. In our experience, the path chosen at the investigation stage – how quickly the firm reports, how completely it cooperates, and how clearly it evidences its remediation – determines which of those two tracks the matter follows.
At the EU level, enforcement is fragmented by design. The Council Regulation creates the prohibition; enforcement is the Member States' responsibility. This means that a business under investigation in Germany faces the Bundesbank or the competent federal authority, not a centralised EU enforcement body. The European Commission has powers of its own under the EU anti-circumvention regime, but day-to-day enforcement against an individual breach sits at national level. The practical implication for an internal investigation is significant: there is no single EU counterpart to engage, and the disclosure made in one Member State does not automatically cover entities in others.
Where do the regimes diverge on voluntary self-disclosure?
Voluntary self-disclosure (a VSD – proactive notification to the regulator of a potential violation before the regulator becomes aware through other means) is a recognised mitigating factor under both OFSI and the relevant EU national enforcement regimes, but the mechanics and the benefit differ. This is arguably the sharpest point of divergence for any cross-border business running a parallel investigation.
Under OFSI's enforcement guidance, a VSD made promptly and in good faith, supported by a clear account of how the potential violation occurred, what funds were involved, and what remediation steps have been taken, can materially reduce the civil monetary penalty. OFSI has published guidance on the factors it weighs when assessing penalty outcomes, and voluntary disclosure features prominently as a mitigant. The guidance does not specify a fixed deadline for disclosure after internal discovery – the key is that disclosure occurs before OFSI becomes aware from an external source, and that it is genuinely voluntary. Waiting until the regulator calls is not a VSD.
In the EU, the position depends on the Member State. Some national regimes have explicit VSD or cooperation provisions with defined mitigation bands. Others treat voluntary disclosure as a general mitigating factor with less predictable outcomes. Several Member State frameworks do not publish detailed penalty-mitigation guidance comparable to OFSI's, making it harder to quantify the benefit of early disclosure before engaging the authority. In our cross-border practice, this asymmetry means that the VSD timing and content strategy for a UK entity and for its EU affiliate may need to be coordinated but cannot be identical.
The position above covers the standard case. Your facts – the counterparty, the goods, the payment route, the entity structure, and the regimes in play – will change the analysis materially. For an assessment of your exposure under OFSI or the applicable EU regime, contact Calder & Vance at info@caldervance.com.
How does legal privilege operate in each regime's investigation?
Legal privilege is one of the most practically sensitive questions in any internal sanctions investigation, and the position is not uniform between the UK and the EU.
In the UK, legal professional privilege (LPP) protects confidential communications between a lawyer and a client made for the purpose of obtaining legal advice, and materials prepared for the dominant purpose of litigation. Where an internal sanctions investigation is conducted under the supervision of external counsel, and where the investigation documents – interview notes, transaction analyses, privilege memoranda – are created for the purpose of obtaining legal advice or in contemplation of proceedings, those documents may attract LPP. This matters because OFSI, in an enforcement context, cannot compel production of privileged material.
Under EU law, legal privilege in the context of competition and regulatory investigations is recognised, but the scope and the tests differ from the common-law position. In-house counsel communications in EU proceedings have historically attracted narrower privilege protection than those of external lawyers. The EU position does not automatically map onto Member State criminal or administrative enforcement proceedings, which are governed by national procedural law. For a business with a German entity and a UK entity both under investigation, the privilege analysis must be done separately for each jurisdiction. Documents that are privileged in London may not be privileged in Frankfurt, and the investigation must be structured accordingly from the outset – not retrospectively.
The implication is structural. Decisions about who leads the investigation (in-house or external counsel), which entities are included in the instruction, and how interview notes are characterised should be made before the first document is created. Restructuring privilege protection mid-investigation is significantly harder and may not be possible. In a recent matter, a financial services business that had begun an internal investigation using its compliance team alone – without external counsel instruction – found that its interview notes were not covered by privilege when the regulator made a subsequent information request. The matter was resolved, but the early structural decision created significant difficulty.
What are the key risk flags in a cross-border internal investigation?
Running an internal sanctions investigation across OFSI and EU jurisdictions simultaneously produces a set of risk flags that a single-regime investigation does not generate. Identifying them early is the difference between a matter that is managed and one that escalates.
The first risk flag is disclosure sequencing. If a UK entity discloses to OFSI before an EU entity has assessed whether it has a parallel reporting obligation, the OFSI disclosure may contain information that is then inconsistent with, or that pre-empts, the EU disclosure. Regulators compare notes. The OFSI disclosure and the EU Member State disclosure must be aligned in their factual account, even if their legal analysis differs.
The second flag is the ownership and control analysis. The OFSI ownership and control test and the EU equivalent are similar in purpose – both ask whether a non-listed entity is owned or controlled by a designated person – but they are not identical in application. OFSI applies the test under SAMLA and the relevant thematic regulations; the EU applies the test under the relevant Council Regulation, with the same 50 percent ownership threshold that OFAC uses for its mechanical test, but with additional control indicators. An entity that falls outside the OFSI test may nonetheless fall within the EU test, or vice versa. The investigation must run both analyses in parallel.
The third flag is the interaction with anti-money laundering obligations. A sanctions hit that generates a VSD to OFSI may simultaneously generate a suspicious activity report obligation under the Proceeds of Crime Act. In the EU, the equivalent AML reporting obligation is set by the Member State's implementation of the relevant EU directive. Tipping-off restrictions apply in both regimes and constrain what can be communicated to the counterparty, to affiliates, and sometimes to group compliance functions while the suspicious activity report is live. The investigation process must be designed to manage both channels without conflating them.
If a transaction has already been flagged, or a disclosure filing has been made, an early review of the parallel EU position can preserve options that close quickly. Contact us at info@caldervance.com for a confidential review.
How does the penalty calculus compare across the two regimes?
The penalty regimes are not directly comparable, but understanding the structure of each helps a business assess what is at stake before it decides how to engage the regulator.
OFSI has powers to impose civil monetary penalties in cases of strict liability – meaning the business need not have known it was in breach. The fact of the breach, if proved to the civil standard, is sufficient for a penalty. OFSI's enforcement guidance sets out the aggravating and mitigating factors it applies, and voluntary disclosure, cooperation, and remediation all feature as mitigants. The maximum civil penalty available to OFSI is set by statute; it is a significant figure. Criminal penalties for knowing or intentional breach are more severe and are imposed by the courts, not OFSI directly.
At the EU level, the penalty framework is a Member State matter. Maximum penalties vary considerably between jurisdictions. Some Member States have published detailed penalty-calculation methodologies; others have not. The direction of travel is towards greater harmonisation following the EU's work on the enforcement of sanctions, but as of March 2026 the practical outcome of an equivalent breach in Germany, France, or the Netherlands will produce different penalty exposure and a different process. This is not a reason to defer disclosure – it is a reason to obtain jurisdiction-specific advice before the disclosure is made.
The question compliance officers and general counsel regularly ask us is: which regime is stricter? The honest answer is that it depends on the Member State. For larger financial institutions, the combination of OFSI civil penalties and the parallel UK criminal regime produces a demanding environment. For businesses with significant EU presence, certain Member State regimes have demonstrated a willingness to impose substantial penalties for relatively technical breaches. In our cross-border practice, we treat both regimes as serious enforcement environments and advise clients accordingly.
What should a cross-border business do in the first 72 hours?
The first 72 hours of an internal sanctions investigation are disproportionately important. Decisions made quickly – or deferred – in that window shape the entire matter.
The first action is to identify and preserve. Every transaction record, every payment instruction, every screening output, every communication relating to the counterparty must be identified and placed under a document-preservation hold. Deletion of relevant records – even inadvertently, through routine retention cycles – will be treated as an aggravating factor by any serious enforcement authority.
The second action is to instruct external counsel and establish the privilege structure. As set out above, the decision about who leads the investigation and under what instruction determines whether the investigation file attracts privilege. That decision must be made before the first document is created.
The third action is to map the regimes. Which entities are involved? In which jurisdictions are they incorporated? Which sanctions regimes are potentially engaged – OFSI, the relevant EU Council Regulation, OFAC, or others? Which of those regimes has a reporting obligation, and what is the relevant deadline?
The fourth action is to assess the reporting obligation. Not every potential violation is a reportable event, and not every reportable event requires disclosure within the same window. The analysis of whether a reporting obligation has been triggered, and by which regime, requires a review of the specific facts against the specific legal test. A business that reports when it has no obligation to do so, or that reports prematurely with incomplete information, may create additional exposure. A business that does not report when it should have done so faces the full weight of non-cooperation as an aggravating factor.
The fifth action is to consider the cross-border sequencing. If OFSI and one or more EU competent authorities are all potentially engaged, the sequence and content of disclosures must be coordinated. This is a legal and strategic exercise, not just an administrative one.
A decision matrix for the most common situations:
Situation A: A single UK entity has processed a payment to a potentially designated counterparty. No EU entity is involved. Route: OFSI VSD process, privilege structure established, AML reporting assessed in parallel. Timeline: prompt disclosure, generally within a matter of days once the facts are established. Primary risk: delay that converts a VSD into a non-voluntary disclosure.
Situation B: Both a UK entity and an EU entity have processed payments. Route: parallel OFSI and EU Member State disclosure process, with coordinated factual accounts. Timeline: longer, given the coordination requirement, but urgency remains. Primary risk: inconsistent disclosures to different regulators, and privilege structures that differ between the two entities.
Situation C: The potential violation involves US-origin goods or a USD-denominated payment, triggering potential OFAC jurisdiction in addition to OFSI and the EU. Route: three-regime investigation with US counsel engaged alongside UK and EU advisers. Timeline: the most complex scenario; early identification of the OFAC nexus is critical. Primary risk: a VSD to OFSI or the EU authority that inadvertently prejudices the OFAC position.
The myth that a OFSI disclosure automatically satisfies the EU obligation
One assumption we regularly encounter in cross-border matters is that a voluntary disclosure made to OFSI covers the business's obligations under the EU regime as well. It does not. OFSI is a UK authority. Its jurisdiction is UK entities and persons within the UK regime. An EU-incorporated entity subject to the relevant Council Regulation has a separate obligation to the relevant Member State competent authority. The OFSI disclosure, however complete, does not operate as notice to Frankfurt or Amsterdam.
The practical consequences of this misunderstanding are significant. A business that believes it has discharged its disclosure obligations by filing with OFSI, and then receives an information request from an EU competent authority six months later, faces the position of having apparently failed to disclose when it should have done so. The mitigating benefit of voluntary disclosure is lost. The aggravating factor of apparent non-cooperation is engaged.
The reverse version of this myth is equally common: that because the EU regime is fragmented and Member State enforcement is variable, the EU obligation is less pressing. In our experience, this underestimates the EU enforcement environment, particularly in jurisdictions with active competent authorities and sophisticated penalty regimes. Treat both regimes as live enforcement environments from the outset of every investigation.
Related practices
- Apparent violation assessment – EU enforcement – assessing whether a potential breach meets the EU threshold for disclosure and penalty exposure
- Penalty defence and settlement: BIS/EAR vs EU compared – comparative analysis of settlement mechanics and penalty mitigation across the two regimes
- Penalty defence and settlement: OFAC vs BIS/EAR compared – how OFAC and BIS approach penalty calculation, VSD credit, and settlement