A multinational with operations in both the United States and Canada processes a payment. Several weeks later, a routine audit reveals that the ultimate beneficial owner of the counterparty appeared on a sanctions list at the time of the transaction. The payment has cleared. The goods have shipped. The question now is not whether a breach occurred – it almost certainly did – but what the business must do in the next days and weeks to manage its exposure across both regimes.
Remediation after a sanctions breach differs materially between OFAC and the Canadian regime administered by Global Affairs Canada (GAC). Under OFAC, a structured voluntary self-disclosure (VSD – a formal report to OFAC that the firm proactively identified and is reporting an apparent violation) can reduce a civil penalty base significantly, and OFAC's enforcement guidelines set out a well-developed mitigating-factors framework. Canada's regime is less prescriptive on procedure but carries its own mandatory reporting obligations and criminal exposure. As of March 2026, a business operating across both jurisdictions faces two parallel remediation tracks that must be managed simultaneously.
This analysis compares the two regimes across the full remediation lifecycle: the first-response obligations, the voluntary-disclosure decision, the penalty calculation logic, the cross-border complexity where both regimes apply, and the practical steps a compliance function should take before counsel is engaged.
How each regime defines the obligation to act after a breach
Both OFAC and GAC impose obligations on a person who discovers it has conducted a transaction prohibited under the applicable sanctions programme – but the source and shape of those obligations differ significantly.
Under OFAC, the obligation derives from IEEPA and the relevant programme regulations. A US person, or any person dealing in property subject to US jurisdiction, must block and report any property in which a designated party has an interest. If a payment has already cleared rather than being blocked at the point of transaction, the firm is holding unblocked property. OFAC's guidance treats the failure to block as the violation; the question then is whether to disclose it voluntarily or wait for OFAC to learn of it another way. In our experience, the choice between those two paths is the single most consequential decision in the early response phase.
Under the Canadian regime, SEMA (the Special Economic Measures Act) and its related orders create obligations for Canadian persons and businesses operating in Canada. A person who holds property connected to a listed person must report that fact to the Commissioner of the Royal Canadian Mounted Police and to the Director of the Canadian Security Intelligence Service. That reporting obligation is not discretionary. It applies whether or not the business intends to make a broader disclosure to GAC. Missing it converts a potential civil matter into something more serious.
The divergence at this stage is structural. OFAC's first-response framework is built around the voluntary-disclosure option: the firm controls whether and how it comes forward. Canada's first-response framework begins with a mandatory report. A business with exposure in both jurisdictions must therefore complete the Canadian mandatory report while simultaneously deciding whether to file a US VSD – and those two actions are not the same thing.
The voluntary self-disclosure decision under OFAC
A VSD under OFAC is a deliberate choice, not a legal requirement. OFAC's enforcement guidelines treat a timely, complete, and accurate VSD as a significant mitigating factor in penalty calculations. The practical effect is that a civil monetary penalty base can be reduced substantially when a VSD is in place, compared with a case where OFAC discovers the apparent violation through its own investigation or a third-party report.
What does OFAC actually look for in a VSD? The agency evaluates five elements: whether the disclosure was timely; whether it was proactive (the firm found the breach itself, not under regulatory pressure); whether the disclosure was complete and accurate; whether the firm took immediate remedial action; and the quality of the remediation programme put in place after the breach. Each element is assessed qualitatively, but the combined weight determines whether OFAC closes the matter with no action, issues a cautionary letter, enters a finding of violation, or pursues a civil penalty.
Timing is critical. OFAC does not define "timely" in business-day terms for the VSD itself, but the guidance makes clear that a firm that waits to see whether OFAC acts first loses the timeliness credit. In our cross-border practice, we routinely see firms delay the VSD decision while they investigate the facts internally. That internal investigation is necessary – a VSD that is inaccurate or incomplete is worse than no VSD – but it must be structured so that the submission comes in within a defensible window.
The position above covers the standard case. Your facts – the counterparty, the goods, the structure of the transaction, the programme in play – change the analysis significantly. To discuss the VSD decision for a specific matter, contact Calder & Vance at info@caldervance.com.
How Canada handles disclosure and remediation
Canada's remediation regime is built on a combination of mandatory reporting, voluntary cooperation, and prosecutorial discretion – and that combination produces a different risk profile from the OFAC model.
The mandatory reporting obligation under SEMA applies as soon as a Canadian person knows or believes it is in possession or control of property owned or controlled by a listed person. The report goes to the RCMP and CSIS. Failure to report is itself a criminal offence under SEMA, carrying potential imprisonment. This is a higher immediate criminal-law exposure than the OFAC framework, which treats most first-instance apparent violations as civil matters in the absence of wilful or reckless conduct.
What happens after the mandatory report? GAC exercises discretion in deciding whether to refer matters for prosecution or to handle them through an administrative route. The factors GAC weighs are broadly similar to OFAC's mitigating factors: self-identification, prompt reporting, quality of the compliance programme, and the remedial steps taken. However, GAC has historically published far less guidance on its penalty calculation methodology than OFAC has. That opacity makes the Canadian track harder to predict, and it elevates the importance of early legal advice on how to frame the disclosure and the remediation narrative.
Criminal prosecution under SEMA is reserved for serious, wilful, or reckless conduct. For inadvertent breaches by well-structured compliance programmes, the more typical outcome is an administrative resolution. But that outcome is not guaranteed, and GAC's enforcement posture has tightened in recent periods. Counsel who understands both the mandatory reporting obligation and the administrative resolution route is essential from the outset.
Where do the penalty frameworks diverge?
The penalty frameworks under OFAC and the Canadian regime reflect fundamentally different legislative philosophies, and those differences produce divergent risk exposures for the same underlying breach.
OFAC's civil penalty system uses a statutory maximum per-transaction base, set by IEEPA and periodically adjusted. The actual penalty imposed is the product of applying aggravating and mitigating factors to that base. Aggravating factors – management awareness, harm to sanctions-programme objectives, pattern of conduct, concealment – can increase the penalty toward the statutory maximum. Mitigating factors – voluntary self-disclosure, strong pre-existing compliance programme, cooperation, remediation – reduce it. The result is a calculated figure that experienced practitioners can model with reasonable accuracy once the facts are established. We regularly advise on that modelling exercise as part of the early-stage strategic assessment.
Canada's SEMA sets its own penalty regime. Criminal penalties include significant fines and imprisonment, applicable to individuals as well as corporations. The administrative track carries its own sanctions. Because GAC publishes less granular guidance on how it weights specific factors, the penalty range in a given case is harder to bracket. What is clear is that, as under OFAC, the gap between a voluntary-disclosure outcome and a contested enforcement action is large – and that gap is widest for the first-time inadvertent breach with a strong compliance programme behind it.
For a business with exposure under both regimes arising from a single breach event, the penalties are not additive in a simple sense: the same underlying transaction can produce parallel penalty proceedings in two jurisdictions. Coordinating the remediation narrative, the timing of disclosures, and the remediation programme across both tracks is the central practical challenge.
If a transaction has already been flagged, or a disclosure has been filed under one regime without addressing the other, an early review can preserve options that narrow quickly with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.
What does effective remediation look like in practice?
Effective remediation is not simply the disclosure. It is the programme of corrective action that follows, and OFAC and GAC both assess the quality of that programme when deciding how to resolve the matter.
Under OFAC's framework, effective remediation typically includes: a root-cause analysis that identifies exactly how the breach occurred; targeted enhancements to the screening programme, the transaction-approval process, or the counterparty onboarding procedures; training of the personnel involved; and a management-level certification that the corrective measures have been implemented. OFAC's guidance identifies a five-element compliance programme standard – management commitment, risk assessment, internal controls, testing and auditing, training – and assesses remediation against that standard.
Under the Canadian regime, GAC looks for equivalent corrective action. The specific expectations are less codified, but the practical requirements are similar: root cause, systemic fix, training, and evidence of implementation. Where the breach was caused by a screening gap, a credible remediation package will include a revised screening protocol, a record of the new controls, and evidence that they were tested. Where it was caused by an ownership-and-control assessment error, the remediation package should show a revised methodology for mapping ultimate beneficial ownership.
In a recent matter, a manufacturing business operating across North America discovered a payments exposure involving a counterparty with a listed beneficial owner. We scoped the apparent violation, assessed the mandatory reporting obligations under both OFAC and the Canadian regime simultaneously, structured a VSD to OFAC, and designed a remediation programme that addressed the root cause in the counterparty onboarding process. The matter resolved at the administrative level under both regimes. Outcomes of that kind are not guaranteed, but the pattern is consistent: early counsel, parallel-track management, and a credible remediation package improve the resolution profile.
Risk flags and common errors in cross-border remediation
Cross-border remediation fails most often at five predictable points, and recognising them early avoids the errors that convert manageable exposures into serious enforcement matters.
The first failure point is sequencing. A business that files a VSD with OFAC before completing the Canadian mandatory report creates a documentary record that may prejudice its position in Canada. Conversely, a business that prioritises the Canadian report and delays the OFAC VSD past a defensible window loses the timeliness credit under OFAC. The two tracks must be sequenced in parallel, with each disclosure calibrated to the other.
The second failure point is scope. Firms often investigate the specific transaction that triggered the discovery without looking for related transactions. OFAC specifically weighs whether the breach was an isolated incident or part of a pattern. A narrow remediation that misses related transactions invites OFAC to expand its inquiry after the VSD is filed. A thorough look-back – across the counterparty, the beneficial owner chain, and the relevant time period – is essential before any submission is made.
The third failure point is the ownership analysis. Both OFAC and GAC look through nominal ownership to the ultimate beneficial owner. Under OFAC, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) means that a counterparty not itself listed may still be blocked. Under the Canadian regime, a similar control-and-ownership analysis applies. A remediation package that does not address the ownership analysis explicitly leaves the regulator to draw its own conclusions.
The fourth failure point is personnel. Remediation packages that list corrective actions without demonstrating individual accountability are treated sceptically. Both OFAC and GAC look for evidence that the personnel responsible for the failure were retrained, supervised, or – in serious cases – separated. The remediation narrative should address personnel directly.
The fifth failure point is documentation. A remediation programme that was implemented but not documented does not exist for regulatory purposes. Every corrective step – screening-system enhancement, training session, revised procedure, management sign-off – must be documented contemporaneously and retained. OFAC's record-keeping standard requires retention for a significant period; verify the current requirement before relying on it.
When to involve counsel and what to expect
The question of when to involve external counsel is decided by the nature of the disclosure obligations and the consequences of getting them wrong. For a mandatory-reporting jurisdiction like Canada, the answer is immediate: the reporting obligation itself is legally prescribed, and a firm that misunderstands its scope or timing commits an offence. For OFAC, the VSD is voluntary – but it is irrevocable once filed, and an inaccurate or incomplete VSD is treated as an aggravating rather than a mitigating factor. Both regimes require legal precision at the earliest stage.
What should a business expect from counsel in the first 72 hours? First, a scope assessment: which regimes apply, what the specific obligations are under each, and what the defensible disclosure window is. Second, a look-back protocol: the scope and methodology of the internal investigation, structured to be thorough without inadvertently expanding the regulatory record before the facts are established. Third, a disclosure strategy: the sequencing and framing of the mandatory and voluntary disclosures to maximise the mitigating credit available under each regime. Fourth, the outline of the remediation programme: what root-cause categories to address and what the remediation evidence package should contain.
A common misconception in cross-border remediation is that the firm needs to resolve the facts completely before it involves counsel. In our experience, the reverse is true. The structure of the internal investigation – what questions it asks, what records it preserves, how its findings are documented – has direct consequences for the quality of the eventual disclosure. External counsel should shape that investigation from the start, not review it after the fact.
Is the Canadian mandatory reporting obligation something a US-centric compliance function fully understands? In our practice, the answer is frequently no. The SEMA reporting obligation is not well-known outside specialist practitioners and Canadian compliance teams, yet it applies to any Canadian entity or person regardless of where the parent-company compliance function sits. Cross-border businesses need counsel who can operate across both tracks simultaneously.
Related practices
- Apparent violation assessment – EU – structured assessment of EU sanctions exposure before regulatory action is taken
- Remediation after a breach: OFAC vs OFSI compared – how the US and UK remediation tracks diverge and where the risks compound
- Remediation after a breach: OFSI vs EU compared – the parallel UK and EU remediation obligations and the sequencing challenge