Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · OFSI

OFSI vs EU: Internal sanctions investigations: what businesses miss

A payments business operating across the UK and the EU discovers, mid-transaction review, that a counterparty's controlling shareholder may appear on both the OFSI Consolidated List and the EU's asset-freeze register. The compliance officer knows a problem exists. What she does not know is which regime governs the investigation, what she must report, by when, and whether disclosing to one authority automatically exposes the firm before the other. These questions do not resolve themselves.

Internal sanctions investigations under OFSI and the EU sanctions regime share a common purpose – identifying whether a prohibition has been breached – but they differ materially on reporting triggers, disclosure mechanics, voluntary self-disclosure ("VSD") credit, legal-privilege protection, and the standard of evidence required to satisfy the regulator. A business that treats the two regimes as interchangeable risks mishandling the investigation, losing mitigation credit, and triggering enforcement in the jurisdiction it forgot to manage. As of March 2026, both regimes are active enforcement environments; neither rewards delay.

This analysis sets out the divergences that matter in practice, maps the stages of an internal investigation from trigger through disclosure, and identifies the points where OFSI and the EU part company most sharply. It is structured as a regime-by-regime analysis across five decision points, closing with the cross-border risk flags that practitioners most commonly see.

What triggers the obligation to investigate – and do the two regimes agree?

The investigation obligation arises differently under each regime, and that difference shapes the entire downstream process. Under OFSI, the obligation to report knowledge or suspicion of a sanctions breach falls on a defined set of persons – broadly, those in the regulated financial sector – under SAMLA and the relevant thematic regulations. The duty is suspicion-based: it attaches when a person knows or has reasonable cause to suspect that a person with whom they deal is subject to a financial-sanctions prohibition or has committed an offence. That is a lower threshold than certainty, and it activates before the internal investigation is complete.

Under the EU regime, the applicable Council regulations impose an obligation to provide information and to cooperate with competent authorities, but the precise trigger for proactive disclosure varies across member states because sanctions enforcement is administered nationally. There is no single EU-wide reporting hotline. A firm with entities in Paris, Amsterdam, and Frankfurt is, in effect, managing three parallel reporting regimes under a common regulatory instrument – the Council regulation – but with three different national enforcement bodies, each with its own procedural expectations and response timelines.

In our cross-border practice, this divergence is the first thing that trips businesses up. A firm that designs its investigation solely around OFSI's suspicion-based trigger may meet the UK deadline comfortably while inadvertently exceeding the shorter informal expectation of a particular EU member-state authority. Have you mapped which national authority in each relevant member state is the competent body for the specific sanction type you are investigating?

How do the legal-privilege rules differ, and why does it matter for investigation design?

Legal professional privilege over investigation documents is not uniform across the two regimes, and the divergence affects how a business should structure the investigative work product from day one. In the UK, advice privilege attaches to confidential communications between a lawyer and a client for the purpose of giving or receiving legal advice. Litigation privilege applies to documents created for the dominant purpose of actual or reasonably contemplated litigation. OFSI does not have the power to compel disclosure of genuinely privileged documents, and privilege is a meaningful shield in an enforcement context – provided the documents were created in the right way.

Across EU member states, the position is more variable. Privilege generally protects communications with external legal counsel under EU competition-law principles established by the Court of Justice, but those principles do not map perfectly onto sanctions investigations conducted at national level. Some member-state authorities take a narrower view of what qualifies as privileged, particularly where in-house counsel are the primary investigators or authors of memoranda. In Germany, the Netherlands, and Belgium, for example, communications by in-house lawyers may attract more limited protection than equivalent UK documents.

The practical consequence is structural. A business running a joint OFSI/EU investigation should, from the outset, segregate documents by jurisdiction, ensure that investigation memoranda are prepared at the direction of external counsel under a clearly stated legal-advice mandate, and avoid mingling factual investigation notes with compliance-commentary documents. We regularly advise clients to establish two parallel document streams at the investigation's start – one governed by UK privilege principles, one by the law of the relevant member state – rather than trying to retrofit privilege claims after the fact.

The risk of getting this wrong is not theoretical. If privilege is lost over investigation documents, those documents may become disclosable to the regulator and, in a criminal context, to prosecuting authorities. A well-structured investigation protects its work product from the moment of first instruction.

Where do the regimes diverge on internal sanctions investigations at the disclosure stage?

Disclosure to OFSI is governed by a specific statutory mechanism: a "relevant firm" that knows or has reasonable cause to suspect a sanctions breach must report it to OFSI using the prescribed channel, and the report must come promptly after the knowledge or suspicion arises. OFSI publishes guidance on what the report should contain, and the firm retains an obligation to provide further information if requested. Critically, making a report does not by itself discharge liability for the underlying breach, but it is a significant mitigating factor in OFSI's penalty assessment.

Under the EU regime, there is no single instrument setting out a uniform voluntary-disclosure procedure. Disclosure must be made to the relevant national competent authority – which may be the financial intelligence unit, the central bank, the treasury ministry, or a dedicated sanctions enforcement body, depending on the member state. The absence of a standardised procedure means that the quality and timeliness of disclosure is assessed differently across jurisdictions. A disclosure that a French authority regards as timely may not satisfy the informal expectations of a Dutch counterpart reviewing the same set of facts from a different angle.

One point of genuine convergence is this: both OFSI and most EU member-state authorities treat proactive, early disclosure as a material mitigant. Under OFSI's enforcement guidance, a voluntary disclosure made promptly, with a full account of the breach, the amounts involved, and the steps taken to remedy it, can substantially reduce a civil monetary penalty. EU national authorities apply a broadly comparable logic, though the degree of credit varies by jurisdiction. The earlier the disclosure, the greater the mitigation available – a principle that holds across both regimes and drives the case for acting quickly once a potential breach is identified.

What businesses most commonly miss at this stage is the requirement to continue the investigation in parallel with, not after, the disclosure process. OFSI expects to receive updated information as the investigation develops. An initial report that is later found to have omitted material facts – even through inadvertence – will weaken rather than strengthen the mitigation case.

How does the VSD calculus differ between OFSI and EU enforcement?

A voluntary self-disclosure (a proactive report by a regulated firm of an apparent breach, made before the regulator has independently identified it) carries different weight under OFSI and EU enforcement regimes, and understanding those differences is central to any cross-border investigation strategy. Under OFSI, the enforcement guidance sets out a tiered approach to penalty mitigation: prompt disclosure, full cooperation, and demonstrated remediation are each given specific weight in the penalty calculation. OFSI has the power to impose a civil monetary penalty of up to the greater of a prescribed statutory maximum or a percentage of the value of the breach, and the mitigation available from a strong VSD package can be significant. No guarantee of outcome is ever appropriate, but the structural incentive toward disclosure is clear.

Under EU member-state enforcement, the VSD calculus is more varied. Member states with mature enforcement programmes – notably the Netherlands, Germany, and France – treat voluntary disclosure as a meaningful mitigant and have published guidance to that effect in various forms. Others have less developed frameworks, and the credit available for disclosure may depend more on the disposition of the individual case handler than on a published policy. This introduces an element of unpredictability that OFSI, with its published guidance, does not present to the same degree.

There is a further asymmetry worth noting. OFSI operates a "monetary penalty: serious" versus "monetary penalty: standard" distinction, and the classification of the breach affects both the maximum available penalty and the mitigation pathway. EU national authorities apply their own severity classifications, and the two systems do not map onto each other. A breach that OFSI would classify as standard – perhaps because the value was low or the breach was a reporting failure rather than a substantive transaction – might attract a more serious categorisation under a member state with a different policy emphasis on reporting obligations.

In our experience, the most effective approach in a cross-border matter is to assess the relative incentives under each regime simultaneously and to sequence the disclosures in a way that does not prejudice the mitigation position in either jurisdiction. That is a judgment that turns on the specific facts and cannot be made generically.

What is the standard of evidence, and how does it affect investigation design?

The standard of evidence required to satisfy the regulator differs, and it has a direct bearing on how thoroughly – and how quickly – an internal investigation must be conducted before disclosure. OFSI operates on a civil standard: the regulator must be satisfied, on the balance of probabilities, that a breach occurred. An OFSI investigation does not require the criminal standard of proof, and OFSI does not need a conviction to impose a civil penalty. The evidentiary burden on the firm, in a disclosure context, is to provide OFSI with a factually complete account that supports an accurate assessment of the breach.

EU member states differ. Some operate purely civil enforcement regimes; others have criminal-law provisions that can be triggered where a breach involves wilful conduct or a systemic failure of controls. In France and Germany, for example, a sufficiently serious sanctions breach can result in criminal investigation and prosecution, with the higher criminal standard of proof applicable in those proceedings. A firm that has disclosed to OFSI on a civil-evidence basis may find that the same disclosures are examined in a criminal context by a member-state authority operating under a different evidentiary regime.

This cross-regime evidentiary divergence has two practical implications. First, the investigation's output – the internal investigation report – should be drafted with both the civil OFSI standard and the possibility of a criminal referral in an EU jurisdiction clearly in mind. Statements of fact that appear straightforwardly helpful in a civil context can carry different implications in a criminal one. Second, the decision about what to disclose, and in what sequence, requires criminal-law counsel in the relevant EU jurisdictions as well as sanctions counsel in both the UK and the EU. The two skill sets are not the same.

Cross-border risk flags: what businesses most commonly miss

Experience across multiple OFSI and EU enforcement matters consistently surfaces the same gaps. The first is the assumption that a single investigation report satisfies both regimes. It does not. OFSI expects a report structured around its own guidance; EU competent authorities have their own expectations, which vary. A document written for OFSI may omit information that a French or Dutch authority regards as material, or may include characterisations of intent that are helpful in a UK context but carry legal implications in a civil-law jurisdiction.

The second gap is screening continuity during the investigation. Once a potential breach is identified, the instinct is to pause the relationship while the investigation runs. What firms sometimes fail to do is continue screening the same counterparty and ownership chain on an ongoing basis during the investigation period. If additional designated persons appear in the chain while the investigation is live, that information must feed into both the internal report and the disclosure to the regulator. Stale screening is a compounding error.

The third gap is record-keeping. Both OFSI and EU national authorities expect a firm to be able to demonstrate, retrospectively, what it knew, when it knew it, and what it did. Under OFSI's enforcement guidance, a firm's record-keeping practices are themselves a component of the compliance assessment. EU member states take a comparable view. A firm that cannot produce contemporaneous records of the investigation steps, the screening results, the escalation chain, and the disclosure decision is in a structurally weaker position than one that can. The record is not created at the time of disclosure; it is created from the moment the potential breach is first identified.

The fourth, and perhaps least-discussed, gap is the interaction with anti-money-laundering reporting obligations. A sanctions breach will often involve proceeds or property that simultaneously triggers a suspicious-activity or suspicious-transaction reporting obligation under AML rules. In the UK, a firm may need to make a report to the relevant financial intelligence authority in parallel with its OFSI disclosure, and the two reports must be consistent. Inconsistency between an AML report and a subsequent OFSI disclosure is a material risk. Across EU member states, the same dual-reporting dynamic applies, and the national financial intelligence units and the competent sanctions authorities are increasingly sharing information with each other.

The fifth gap – and one we see with particular regularity in larger organisations – is the failure to escalate the investigation decision to the board or audit committee promptly. Both OFSI and EU enforcement guidance treat senior-management engagement as a marker of a well-functioning compliance culture. A breach that was managed exclusively at the compliance-officer level, without board awareness, may attract more scrutiny than one where the board received a prompt and accurate briefing and authorised the disclosure. Governance documentation of that escalation is part of the evidentiary record.

The position above covers the structural divergences. Your facts – the counterparty, the relevant listed person, the value of the breach, the jurisdictions of your entities, and the national competent authority – change the analysis materially. If a transaction has already been flagged, or a potential breach has been identified, early engagement with counsel can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.

A common myth corrected: parallel regimes, parallel disclosures

A widely held assumption is that disclosing to OFSI discharges the firm's obligations across the board, or that a single disclosure to a lead authority satisfies the notification requirements of every competent authority with jurisdiction. It does not. OFSI is the UK financial-sanctions authority. It has no authority to accept disclosures on behalf of EU member-state competent authorities, and an OFSI disclosure does not constitute notice to the French Treasury, the Dutch central bank, or any other EU national body. Conversely, a disclosure to an EU national authority does not reach OFSI.

The obligation to notify runs separately to each competent authority with jurisdiction over the firm's activities. A UK-regulated firm with an EU subsidiary that processed the same transaction will typically need to notify both OFSI and the relevant national authority in the member state where the subsidiary is established. If the firm has entities in multiple member states, the notification map may be more complex still. Treating OFSI as the disclosure channel for the entire group is an error that can result in enforcement action in EU jurisdictions that the firm believed were covered.

We have acted for businesses that proceeded on precisely this assumption and discovered, some months after an OFSI disclosure, that an EU national authority had independently identified the same breach and was proceeding on the basis that no disclosure had been made. The mitigation credit that a timely VSD would have generated was not available at that stage. Getting the notification map right at the outset of the investigation is not an administrative detail. It is a core component of the remediation strategy.

Related practices

Frequently asked questions on internal sanctions investigations

Where do the regimes diverge on internal sanctions investigations?

The sharpest divergences are at the reporting trigger, the disclosure mechanism, and the availability of VSD credit. OFSI operates a suspicion-based statutory reporting obligation through a defined channel, with published guidance on mitigation. EU enforcement runs through national competent authorities, each with its own procedures, severity classifications, and mitigation frameworks. A firm investigating a potential breach that spans both regimes must manage both disclosure processes separately, to different bodies, on different timelines, and under different evidentiary standards. Legal privilege also varies: UK privilege principles apply to OFSI matters; member-state law governs EU investigation documents, with less uniform protection for in-house counsel work product.

Which regime is stricter on internal sanctions investigations?

Neither regime is categorically stricter across all dimensions. OFSI has published clear enforcement guidance, a defined penalty regime with a statutory maximum, and a transparent mitigation framework. That structure gives businesses visibility on consequences and on the value of timely disclosure. EU member states vary: some, such as the Netherlands and France, have mature enforcement programmes with significant civil and criminal penalty powers; others have less developed frameworks but are investing in sanctions enforcement capacity. In our experience, the principal risk in an EU matter is the variability of outcomes across jurisdictions, not a uniformly lighter touch. Businesses with entities in multiple member states face the most complex enforcement exposure.

What should a cross-border business do about internal sanctions investigations?

Act immediately upon identifying a potential breach. The three priority steps are: (1) preserve all potentially relevant records and pause further transactions with the counterparty or property concerned; (2) instruct external sanctions counsel to scope the potential breach and map the notification obligations under each relevant regime; and (3) identify the national competent authority for each jurisdiction in which the firm has regulatory exposure and assess the disclosure timeline applicable in each. Do not file a disclosure to OFSI under the assumption that it covers EU obligations. Do not delay the investigation while waiting for certainty on the facts – the disclosure obligation under OFSI arises on reasonable suspicion, not proof. Early legal advice is the most effective mitigation available.

About the author

Henry Ashworth advises on UK financial sanctions and export controls, including OFSI licensing and enforcement, and judicial-review challenges to designations. He acts for financial institutions, multinationals, and individuals across enforcement investigations, voluntary disclosure, and penalty proceedings, with a particular focus on matters engaging both the UK and EU regimes. Calder & Vance – International Sanctions & Export Control Counsel.

About Calder & Vance

Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.

Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.