A payments firm with clearing operations in London and Sydney discovers, during a routine internal review, that a series of transactions were processed for a counterparty later identified as connected to a designated person. Two enforcement regimes are now potentially engaged: OFSI (the UK's Office of Financial Sanctions Implementation, the authority responsible for financial-sanctions enforcement in Great Britain and Northern Ireland) and DFAT (the Australian Department of Foreign Affairs and Trade, which administers Australia's Autonomous Sanctions regime). The firm's General Counsel wants to know: does a settlement framework exist in each jurisdiction, how does penalty mitigation work, and does a voluntary disclosure in one jurisdiction trigger or influence the other?
Penalty defence and settlement under OFSI vs Australia diverge materially on disclosure obligations, the structure of civil penalties, the settlement mechanism, and the degree to which cooperation and remediation reduce liability. As of early 2026, OFSI operates an explicit monetary-penalty regime with a published mitigation framework, while Australia's autonomous-sanctions enforcement architecture gives DFAT and the Commonwealth Director of Public Prosecutions a different toolkit – one with fewer published civil-penalty pathways and a greater reliance on criminal referral for serious breaches. The regime you face first, and the facts you disclose, shape the outcome in both.
This analysis sets out how the two regimes approach enforcement, where mitigation and settlement operate, what the key procedural divergences are, and how a cross-border business with exposure in both jurisdictions should sequence its response.
What legal authority underpins enforcement in each regime?
OFSI's enforcement authority derives from SAMLA – the Sanctions and Anti-Money Laundering Act – and the thematic financial-sanctions regulations made under it. Those regulations authorise OFSI to impose monetary penalties on a civil standard where it is satisfied, on the balance of probabilities, that a person has breached a financial-sanctions prohibition and knew, or had reasonable cause to suspect, that they were doing so. The civil enforcement route is the primary tool for compliance failures that do not reach the threshold for criminal referral to HMRC or the National Crime Agency.
Australia's enforcement basis is the Autonomous Sanctions Act and its associated regulations. Criminal penalties attach to breaches of the prohibition on dealing with a designated person's assets or making assets available to a designated person. There is no comprehensive civil monetary-penalty regime for autonomous-sanctions breaches that mirrors OFSI's published civil-enforcement pathway. Enforcement is therefore more binary: administrative engagement with DFAT, or criminal prosecution by the Commonwealth DPP. In our cross-border practice, this structural difference is the first thing counsel must explain to a client that has experience of the OFSI model and assumes a comparable settlement pathway exists in Canberra.
The UN Security Council Consolidated List underpins both regimes for listings that originate at Security Council level, but each jurisdiction implements and enforces those obligations independently. Where a listed person appears on both the UK sanctions list and Australia's consolidated list, a single breach of dealing with that person engages both enforcement authorities.
How does OFSI's monetary-penalty and settlement process work?
OFSI's civil monetary-penalty process moves through defined stages: an assessment of the apparent breach, a preliminary case notice, an opportunity for representations, and then a final penalty notice if OFSI remains satisfied. The firm subject to enforcement can make written representations in response to the preliminary notice; that submission is the primary mechanism for presenting mitigation. OFSI publishes enforcement guidance that identifies the aggravating and mitigating factors it weighs.
Mitigation under the OFSI model turns on several factors. Voluntary self-disclosure (a VSD – the proactive report of an apparent breach before OFSI opens a formal inquiry) is a significant mitigating factor and can materially reduce the penalty level. The quality of the pre-existing compliance programme matters; a well-designed programme that detected the breach and generated the disclosure is treated more favourably than an absence of controls. Speed of remediation – blocking the account, reversing the transaction where possible, enhancing controls – is also relevant. In our experience advising OFSI matters, the representations stage is not a formality: a structured, evidence-based submission that addresses each mitigation factor in OFSI's framework has a real effect on outcome.
There is no formal "settlement agreement" mechanism in the US-OFAC sense, where a settlement is reached pre-notice and published as a Settlement Agreement. OFSI reaches its decision through the penalty-notice process, and any reduction is reflected in the final notice figure rather than in a separately named settlement document. The firm can request an internal review of the penalty decision and can appeal to the Upper Tribunal. That appellate pathway – internal review, then specialist tribunal – is a material option that is sometimes overlooked in the heat of the initial enforcement response.
The position above covers the standard enforcement case. Your facts – the transaction value, the counterparty structure, the quality of your compliance records, the timeline between the apparent breach and any report – change the analysis significantly.
For a preliminary assessment of your OFSI exposure, contact Calder & Vance at info@caldervance.com.
How does Australia's enforcement pathway differ?
Australia does not publish an OFSI-equivalent graduated civil-penalty schedule for autonomous-sanctions breaches, and there is no standing DFAT enforcement guidance that maps out mitigating factors in the structured way OFSI does. That absence is operationally significant. A business responding to a potential Australian autonomous-sanctions breach cannot open DFAT's published framework and identify the precise factors that will govern mitigation; instead, it must engage the authority directly and understand the pathway through dialogue and legal advice.
The criminal character of Australian autonomous-sanctions enforcement is the dominant practical reality. Breaches of the core dealing prohibition are criminal offences carrying significant penalties for both individuals and bodies corporate. The Commonwealth DPP makes prosecution decisions on the standard public-interest criteria. Cooperation with DFAT, proactive disclosure, and prompt remediation are all factors the authority will consider, but they operate within a prosecutorial discretion model rather than a civil-penalty mitigation matrix.
Australia does operate an asset-freeze reporting obligation. Holders of frozen assets are required to report to DFAT under the relevant regulations. That obligation exists independently of any breach and creates an early touchpoint with the regulator. Prompt, accurate reporting of a frozen-asset holding – even where the holding arose inadvertently – establishes a cooperative relationship that is relevant if enforcement follows. The distinction between the reporting obligation (mandatory on holding) and voluntary self-disclosure of a dealing breach (a strategic choice with mitigating effect) is one that cross-border businesses often conflate. They are different acts with different legal consequences.
What do these structural differences mean in practice? They mean that the response strategy for an Australian autonomous-sanctions issue cannot be copied from the OFSI playbook. The sequencing of disclosure, the framing of engagement with DFAT, the involvement of criminal-defence capacity alongside sanctions counsel – these all need to be calibrated to a different institutional environment.
Where do the regimes diverge most sharply on penalty defence?
The most operationally significant divergence is in the transparency of the penalty framework. OFSI publishes detailed enforcement guidance that sets out its decision-making factors; a respondent can read the framework and build a representations strategy directly against it. Australia does not have a comparable public document for autonomous-sanctions civil enforcement. That asymmetry of information is the single largest practical challenge for a cross-border business managing a dual-jurisdiction breach.
A second divergence lies in the nature of the decision-maker. OFSI is an administrative authority within HM Treasury; its penalty decisions are taken on a civil standard and can be reviewed by the Upper Tribunal. The Australian enforcement pathway, for serious breaches, routes through the criminal courts. These are fundamentally different legal environments: rules of evidence, standards of proof, and the consequences of conviction or a finding against the respondent are not comparable. A penalty under OFSI sits on the public record as an administrative finding; a criminal conviction in Australia carries different reputational, licensing, and personal consequences.
The third divergence is disclosure sequencing in a dual-jurisdiction matter. If a business discloses to OFSI first and that disclosure becomes part of the public record – OFSI publishes enforcement notices – the narrative and the facts articulated in the UK may shape the Australian authority's understanding of the breach. In our practice, we advise clients facing potential dual-jurisdiction exposure to plan both disclosures together, with carefully consistent factual framing, rather than treating them as sequential independent acts. The timing of each disclosure relative to the other, and the precision of the facts disclosed in each, are decisions that require coordinated legal advice.
There is a further divergence on the treatment of subsidiary entities and group-level liability. OFSI's enforcement generally targets the entity that effected the prohibited transaction. Australian enforcement considers the individual actors within the entity as well as the corporate. Personal criminal liability for directors and compliance officers is a live consideration in the Australian regime that does not have a direct equivalent in OFSI's civil-penalty enforcement, though criminal referral under UK sanctions law is also possible for wilful breaches.
If a transaction has already been flagged, or a filing has been refused, early legal review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com.
What is the role of voluntary self-disclosure in each regime?
VSD is a structurally embedded mitigation tool in the OFSI regime. OFSI's published enforcement guidance treats proactive voluntary disclosure – made promptly, accurately, and before the authority has opened its own inquiry – as a significant factor reducing both the likelihood of the highest-penalty outcomes and the quantum of any penalty imposed. The benefit of a VSD diminishes if OFSI discovers the breach independently before the disclosure arrives. Speed and completeness therefore matter: a partial, delayed, or reactive disclosure carries less weight than a full, early, proactive one.
In Australia, disclosure to DFAT ahead of any formal inquiry is similarly a factor in prosecutorial discretion and in the authority's overall assessment of culpability and cooperation. There is no published scoring matrix. But experienced counsel advising on Australian autonomous-sanctions enforcement would note that cooperation and transparency with DFAT are standard mitigation arguments in any engagement with the Commonwealth DPP. The absence of a formal framework does not mean the action is without value; it means the value must be established through the engagement itself rather than read off a published document.
One practical difference: OFSI's voluntary-report pathway is documented and the submission can be structured to address the published mitigation factors point by point. The submission itself becomes part of the case record and the representations. In Australia, the initial contact with DFAT is often more exploratory – establishing the facts, identifying the applicable prohibitions, and understanding the authority's current assessment – before a formal position is adopted. These are different conversations requiring different preparation.
Can a single VSD-equivalent submission satisfy both regimes? The answer is almost always no. Each authority requires engagement in its own format, on its own obligations, assessed against its own legal standards. A submission prepared for OFSI will address SAMLA, the relevant UK thematic regulations, and OFSI's published mitigation criteria. A communication to DFAT must address the Autonomous Sanctions Act and the specific asset-dealing prohibition engaged. The underlying facts may be the same; the legal framing must differ.
Risk flags for cross-border businesses managing dual-jurisdiction exposure
In a dual-jurisdiction matter, several risk factors elevate the legal exposure beyond what either regime alone would produce. The following are the patterns we encounter most frequently in cross-border enforcement matters.
Parallel inquiry risk. Where OFSI and DFAT both have reason to open inquiries, the risk is that each authority develops its own factual record independently. Inconsistencies between the UK and Australian disclosure records – arising from incomplete information at the time of the first disclosure, different legal definitions of the breach, or simply the pressure of dealing with two authorities simultaneously – can be used to question the bona fides of the cooperation. Coordinated legal advice across both jurisdictions is the direct mitigation.
Compliance-programme evidence. Both OFSI and Australian enforcement attach significance to the quality of the compliance programme in place at the time of the breach. A business with a well-documented screening process, clear escalation procedures, and training records is in a materially stronger position than one that cannot demonstrate its pre-breach controls. In our experience, the quality of that documentary record, assembled before enforcement begins, has a significant effect on the mitigation available.
Individual exposure in Australia. As noted above, Australian autonomous-sanctions enforcement extends to individuals within a corporate entity. Directors, compliance officers, and senior managers who approved or failed to prevent the prohibited transaction may face personal liability. Any engagement with DFAT in a serious-breach scenario should be conducted with that individual exposure explicitly in mind. Counsel acting for the corporate may not be acting for the individual; separate representation may be necessary.
Export-control interaction. Many of the transactions that trigger a sanctions enforcement issue also engage export-control questions. A cross-border transfer of goods or technology to a counterparty connected to a designated person may simultaneously raise questions under the UK Export Control Order and the relevant Australian export-controls framework. Separating the sanctions-enforcement response from the export-control review and handling them as independent matters is a common error. The factual overlap means they need to be assessed together.
Related practices at Calder & Vance that frequently arise in dual-jurisdiction enforcement matters:
- Apparent violation assessment (EU) – identifying and scoping apparent breaches before engagement with enforcement authorities
- Post-breach enforcement risk: BIS/EAR vs EU – comparative analysis of US and EU enforcement exposure for export-control violations
- Post-breach enforcement risk: BIS/EAR vs EU (part 2) – extended analysis of voluntary disclosure, settlement, and penalty mitigation across regimes
How to sequence a response when both regimes are engaged
When a business identifies a potential breach that engages both OFSI and Australia's autonomous-sanctions regime, the response sequence matters more than most compliance officers initially appreciate. Acting in one jurisdiction without considering the implications for the other creates avoidable exposure. The following sequence reflects the approach we take in cross-jurisdiction matters.
The first step is a rapid internal scope: identify the transaction or transactions, the counterparty, the designated person or entity linked to the counterparty, and the legal basis of the prohibition in each jurisdiction. That analysis must be done before any external disclosure. A disclosure that mis-characterises the breach – for example, by describing it in terms drawn from the OFSI prohibition when the Australian prohibition is differently framed – can create confusion in the authority's file that is difficult to correct later.
The second step is to assess the disclosure obligation independently in each regime. There is no single cross-jurisdictional disclosure mechanism. OFSI's voluntary-report pathway operates under UK law; DFAT's engagement process operates under Australian law. Each has its own timing considerations. In a matter where OFSI might discover the breach independently – for example, because a counterparty appears on a published enforcement notice – the time window for a proactive VSD with maximum mitigation value may be shorter than the business assumes. Have you identified when OFSI is likely to become aware, and built your disclosure timeline around that point?
The third step is to prepare the compliance remediation. Both OFSI and DFAT will assess the business's response to the breach as part of their evaluation of cooperation and mitigation. Remediation that is documented, proportionate, and demonstrably effective – blocking the relevant accounts, enhancing screening logic, retraining relevant staff, reviewing adjacent transactions – carries more weight than a statement of intention to remediate. The remediation record should be built concurrently with the disclosure preparation, not after.
In a recent matter, a financial-services business with both UK and Australian operations discovered that a payment had been processed through a correspondent chain that included an entity connected to a designated person. We scoped the apparent violation under both regimes, identified the disclosure obligations, prepared coordinated submissions to OFSI and DFAT, and supported the compliance remediation programme. The matter progressed through the OFSI representations stage with a structured mitigation submission and resolved without the highest-tier penalty outcome.
The common misconception: Australia mirrors the OFSI model
A persistent belief among compliance teams that have experience of OFSI enforcement is that the Australian autonomous-sanctions enforcement model is broadly similar – a civil-penalty process with published mitigation factors and a pathway to a negotiated outcome. That belief is incorrect. The structural differences described in this analysis – the predominance of criminal enforcement, the absence of a published mitigation matrix, the role of the Commonwealth DPP, and the personal liability of individuals – mean that a response strategy designed for OFSI will not map adequately onto an Australian enforcement scenario.
This matters particularly for dual-jurisdiction businesses that assign primary responsibility for sanctions-enforcement response to a UK or US sanctions team. Those teams bring well-developed skills in managing OFSI or OFAC enforcement matters. But they may not have equivalent experience of the Australian regime's institutional character, its disclosure expectations, or the criminal-proceedings risk for individuals. In our practice, we regularly advise clients in exactly this position: experienced in one regime, encountering a materially different enforcement environment in another for the first time.
The practical corrective is not to treat Australian autonomous-sanctions enforcement as an afterthought once the OFSI matter is managed. It is to bring it into the analysis from the initial scope and ensure that the dual-jurisdiction matter is handled with equivalent rigour in both directions. The stakes in Australia, for the individuals involved as much as the corporate, are too significant to leave to a supplementary review.
Frequently asked questions: OFSI vs Australia penalty defence and settlement
Where do the regimes diverge on penalty defence and settlement?
The primary divergences are four. First, OFSI operates a published civil monetary-penalty regime with documented mitigation factors; Australia relies predominantly on criminal enforcement for autonomous-sanctions breaches with no comparable published civil-penalty matrix. Second, the decision-making body differs – OFSI is an administrative authority within HM Treasury, while serious Australian breaches are assessed for prosecution by the Commonwealth DPP. Third, individual liability for directors and compliance officers is a live consideration in Australia in a way that does not have a direct civil-enforcement parallel under OFSI. Fourth, the appellate routes – the Upper Tribunal in the UK versus the criminal courts in Australia – operate under entirely different legal standards and produce different consequences. Each divergence requires a distinct response strategy.
Which regime is stricter on penalty defence and settlement?
The two regimes are not directly comparable on a strictness scale because they operate through different enforcement mechanisms. OFSI's civil penalties can be significant, but they are administrative determinations on a civil standard of proof. Australian autonomous-sanctions enforcement for serious breaches can route through the criminal courts, with criminal standards of proof and the personal consequences – including potential imprisonment for individuals – that criminal conviction carries. For a corporate entity assessed on financial penalty alone, OFSI's penalties may be more immediately quantifiable. For individuals within the entity, the Australian criminal enforcement model is more severe in its potential consequences. The appropriate assessment depends on who is exposed and what the breach involves.
What should a cross-border business do about penalty defence and settlement?
A cross-border business that identifies a potential breach engaging both regimes should take three immediate steps. First, conduct a rapid internal scope of the breach under each regime's specific prohibitions before making any external disclosure. Second, obtain legal advice in both jurisdictions simultaneously – not sequentially – to ensure that disclosure timing, factual framing, and remediation actions are coordinated across both authorities. Third, document the compliance remediation immediately and thoroughly, as the quality of that record is a material factor in both OFSI's mitigation assessment and any engagement with DFAT and the Australian prosecutorial authorities. Early action in both jurisdictions consistently produces better outcomes than reactive engagement after the authority has developed its own inquiry.
About the author
Henry Ashworth advises on UK financial sanctions and export controls, including OFSI licensing and enforcement, and judicial-review challenges to designations. He has advised on OFSI enforcement matters across financial-services, commodities, and technology sectors, and regularly acts in cross-border matters where UK obligations intersect with US, EU, and third-country regimes.
Calder & Vance – International Sanctions & Export Control Counsel.
About Calder & Vance
Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.
Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.