Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · OFAC

Apparent-violation assessment under OFAC: a compliance guide

A payments firm discovers a transfer that cleared six months ago. The beneficiary's name matches a party on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The transaction has settled. The funds are gone. What the compliance team does in the next seventy-two hours may define whether this becomes a self-disclosed, mitigated matter or an enforcement action with a significantly larger exposure.

An apparent-violation assessment is the structured internal review a business conducts once a potential breach of OFAC sanctions is identified, before any decision is made about voluntary disclosure or remediation. OFAC governs US sanctions enforcement under the authority of IEEPA and related legislation; its enforcement guidelines treat the quality of a firm's pre-existing compliance programme and its post-discovery conduct as the two most consequential factors in penalty determination. As of March 2026, the assessment phase is where most of the penalty-mitigation value is created or lost.

This guide walks through the assessment in six stages: identifying the trigger, scoping the transaction set, applying the aggravating and mitigating factors OFAC publishes, comparing the assessment approach across the UK and EU regimes, deciding whether a VSD (voluntary self-disclosure to OFAC) is appropriate, and structuring the remediation file.

Step 1: Identifying the trigger and preserving the record

The apparent-violation assessment starts the moment the potential breach surfaces, and the first priority is evidence preservation. Whether the trigger is a screening alert, an internal audit finding, a counterparty disclosure, or a correspondent bank query, the business must immediately secure all transaction records, communications, and screening logs related to the event before any routine data-retention cycle overwrites them.

OFAC's enforcement guidelines place significant weight on a firm's record-keeping discipline. The guidelines treat evidence of a functioning compliance programme – including documented screening decisions and escalation trails – as a mitigating factor. Conversely, gaps in documentation, even innocent ones, can be read as evidence of a weak programme. In our experience, the first forty-eight hours after discovery determine the quality of the evidentiary record for the rest of the matter.

Triggers vary by sector. A bank typically discovers the issue through its transaction-monitoring or correspondent-bank queries. A goods exporter may receive a customs hold or a carrier notification. A technology firm may find an account with suspicious identifiers in an audit. The legal analysis is the same in each case: preserve first, assess second.

One practical point deserves emphasis. Do not immediately delete or quarantine records in a way that destroys metadata. The goal is preservation in place, with access controls, not destruction. The integrity of timestamps, IP logs, and screening-system output often proves decisive.

Step 2: Scoping the transaction set – how far back does the problem go?

Once the trigger event is secured, the assessment must determine whether the apparent violation is isolated or systemic. A single blocked-party transfer is a different matter from a pattern of transfers over eighteen months. Scoping requires a methodical look-back across all accounts, counterparties, and transaction channels that share the same risk characteristic as the triggering event.

The look-back period is not fixed by a universal rule. OFAC's civil enforcement posture and the relevant statute of limitations under US law are the governing references. In practice, the look-back typically covers all transactions that could fall within the applicable limitation period. Verify the current period before relying on any figure, as it can turn on the specific programme and the nature of the violation.

Scoping questions include: Was the SDN match a name match, an ownership-chain issue, or a geography-based prohibition? Did the same counterparty or a related entity appear in other transactions? Were the transactions processed through one system or multiple channels? Did the business's screening tool cover all relevant lists at the time of each transaction?

The 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) is a frequent source of discovered violations. A counterparty that was never on the SDN List directly may nonetheless have been a blocked entity throughout the transaction history if a listed person held the required ownership stake. Have you confirmed the ownership structure of every flagged counterparty, not just the surface-level name match?

In a recent matter, a financial institution identified a single flagged payment during a routine audit review. The look-back exercise revealed that the ownership chain of the counterparty had included a listed person for a period covering numerous prior transactions. The scope of the matter expanded substantially. Early scoping work, conducted thoroughly and quickly, allowed the institution to present OFAC with a complete and accurate picture at the outset – a factor the guidelines treat as favourably mitigating.

Step 3: Applying OFAC's aggravating and mitigating factors

OFAC's enforcement guidelines set out the factors it weighs when determining whether to take action and at what level. Understanding these factors in advance shapes every decision in the assessment phase, from how the remediation file is built to whether a VSD is the right route.

The aggravating factors OFAC considers include: whether the apparent violation was wilful or reckless, whether management was aware, whether the firm is a large and sophisticated entity, whether the conduct caused significant harm, whether the firm failed to take remedial action, and whether the firm has a history of prior violations or a weak compliance programme.

The mitigating factors include: whether the conduct was not wilful or reckless, whether the firm had a sanctions compliance programme (a documented, risk-based internal programme designed to prevent violations) in place and functioning at the time of the violation, whether the firm self-initiated the discovery, whether it took prompt remedial action, whether it cooperated with OFAC's investigation, and whether it made a timely VSD.

OFAC's guidelines treat a timely VSD as a significant mitigating factor, potentially reducing the base penalty amount by a substantial proportion. Quantification is not appropriate here without verified figures; verify the current position before relying on any specific reduction percentage. What matters for the assessment is that the decision whether to disclose, and the timing of that decision, directly affects the penalty exposure. That decision must be made deliberately, with legal advice, not by default.

The quality of the compliance programme at the time of the violation is particularly consequential. A programme that was documented, tested, and appropriate to the firm's risk profile – even if it failed to catch this transaction – reads very differently to OFAC than a programme that was nominal or untested. We regularly advise clients that the compliance programme review should begin in parallel with the transaction look-back, not after it.

The position above covers the standard case. Your facts – the counterparty, the goods, the transaction channel, the compliance programme in place at the time – change the analysis materially. For an initial assessment of your exposure under OFAC, contact Calder & Vance at info@caldervance.com.

How does OFAC's approach compare with OFSI and the EU?

OFAC, OFSI, and the EU sanctions enforcement authorities share the broad structure of an apparent-violation analysis, but they differ in ways that matter for a business managing multi-regime exposure. Understanding where they diverge – and where they converge – is essential for any cross-border business that may face parallel inquiries.

Under OFAC, the aggravating and mitigating factors are published in detailed enforcement guidelines that practitioners treat as a de facto roadmap. The framework is relatively transparent, and the voluntary self-disclosure mechanism is clearly defined. The US system also carries extraterritorial reach through secondary sanctions – prohibitions that can penalise non-US persons for certain conduct with sanctioned parties, even where no US nexus to the specific transaction is obvious. This reach means a non-US business may face OFAC exposure on transactions that it considers purely domestic.

OFSI, the UK's Office of Financial Sanctions Implementation, operates under SAMLA (the Sanctions and Anti-Money Laundering Act) and its thematic regulations. OFSI has a formal monetary penalty regime and publishes enforcement guidance that sets out its approach to aggravating and mitigating factors. The UK regime includes a reporting obligation: a relevant firm that knows or suspects it holds assets of a designated person, or has dealt with such a person, must report that to OFSI. That reporting window is short. The legal basis and the applicable deadline should be verified by reference to the current OFSI guidance before the business relies on any timeline. For a detailed parallel analysis of the OFSI assessment process, see our OFSI apparent-violation assessment guide.

The EU enforcement posture differs from both. Sanctions under the relevant Council regulations are implemented and enforced at Member State level. There is no single EU enforcement authority equivalent to OFAC or OFSI. This means that a violation involving assets or transactions across multiple EU jurisdictions may involve parallel investigations in more than one Member State, each applying its own procedural rules and penalty scales. The one constant across EU jurisdictions is the ownership and control test: a non-listed entity is caught where a listed person owns or controls it, and the control limb is broader than OFAC's pure ownership threshold. For detailed guidance on EU apparent-violation assessment, see our EU apparent-violation assessment service page.

Switzerland's SECO operates under its own autonomous sanctions ordinances. The assessment process shares conceptual similarities with the OFAC approach, but the procedural rules, disclosure obligations, and penalty structures differ. Cross-border businesses with Swiss operations should read the SECO regime analysis alongside this guide; our SECO apparent-violation assessment guide covers the Swiss position in detail.

The principle that applies across all regimes: where multiple jurisdictions could have an enforcement interest, the strictest prohibition governs the transaction analysis for each regime independently. A disclosure to OFAC does not satisfy OFSI reporting obligations, and vice versa. Businesses managing multi-regime exposure need a coordinated response, not sequential ones.

Step 4: Deciding whether to make a voluntary self-disclosure

The VSD decision is the highest-stakes judgment in the apparent-violation process, and it is not a default. A voluntary self-disclosure to OFAC is a formal submission that acknowledges the apparent violation, presents the facts as the business understands them, and invites OFAC to consider the matter in light of the mitigating factors. It is not a confession of liability, but it carries significant procedural and substantive consequences.

The case for a VSD is strongest when the violation is clearly within OFAC's jurisdiction, the facts are substantially clear and documentable, the compliance programme was functional at the time, the business has taken prompt remedial action, and the violation is unlikely to be discovered through an independent channel before a disclosure could be made. In our practice, the combination of early discovery, thorough documentation, and prompt remediation creates the conditions under which a VSD is most likely to produce a substantially reduced outcome.

The case against a VSD, or for delay, arises when the facts are still unclear, the scope of the look-back is unresolved, or the legal question of whether a violation occurred at all is genuinely uncertain. Filing a VSD on an incomplete factual record, or withdrawing from one after it has been filed, carries its own risks. The decision must be based on a complete internal investigation, not on the first read of the triggering event.

Timing matters. OFAC's guidelines treat the promptness of a VSD as a factor in its assessment of the disclosure's mitigating value. A disclosure made months after the firm first had reason to investigate the apparent violation reads differently from one made within weeks of discovery and a thorough internal review. There is no fixed statutory deadline for a VSD, but delay erodes its mitigation value. If a transaction has already been flagged by a correspondent bank, a regulatory inquiry, or a trade-finance counterparty, the window for a VSD that OFAC treats as voluntary may be very short.

If a transaction has already been flagged, or a notice has been received, an early legal review preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.

Step 5: What are the risk flags that escalate an apparent violation?

Certain fact patterns reliably elevate an apparent violation from a potential no-action or cautionary-letter outcome to a civil penalty or, in the most serious cases, a referral for criminal investigation. Identifying these flags early in the assessment shapes the entire response strategy.

Wilfulness is the most serious escalation factor. OFAC treats a violation as wilful where the business knew it was dealing with a sanctioned party or knew that its conduct was prohibited and proceeded regardless. Recklessness – a conscious disregard of a known risk – also elevates the matter. Internal communications that suggest awareness of a sanctions concern, followed by a decision to proceed, are the most damaging category of evidence in any OFAC enforcement matter. This is why the evidence-preservation step is so important: those communications will eventually be reviewed.

Senior management involvement or knowledge is a separate aggravating factor. A violation that a compliance officer failed to detect reads differently from one that a business-line head approved after a sanctions query was raised. The organisational level at which the violation was authorised or ignored is a key fact in the assessment.

Repeat conduct is another escalation risk. A business that received a prior cautionary letter, or that disclosed a prior matter, and then committed a further apparent violation in the same programme area, faces a significantly harder enforcement environment. OFAC's published penalty calculations treat prior violations as a substantial aggravating factor.

Sector-specific flags also arise. Financial institutions processing payments through the US correspondent banking system carry particular OFAC exposure because the US dollar clearing relationship gives OFAC jurisdiction over transactions that would otherwise have no US nexus. Similarly, exporters of items on the Commerce Control List face BIS and OFAC exposure simultaneously if the same transaction involves a sanctioned party. Do not assume that an item-classification review under BIS resolves the OFAC question; they are separate analyses.

Step 6: Building the remediation file and closing the matter

A thorough apparent-violation assessment concludes with a remediation file that can withstand scrutiny from OFAC, from a correspondent bank, or from a future acquirer conducting due diligence. The file has three components: the factual record, the compliance programme review, and the remediation evidence.

The factual record covers every transaction in the look-back scope: counterparty identity, ownership structure at the relevant date, screening data, processing records, and a clear timeline. The record must be complete and internally consistent. Gaps and inconsistencies, even innocent ones, will attract questions from OFAC reviewers.

The compliance programme review documents what the programme looked like at the time of the apparent violation, why it failed to catch the transaction, and what changes have been made since. OFAC looks for evidence that the remediation is substantive – that the firm has addressed the root cause, not merely the surface symptom. A technology firm that updated a name-matching threshold in its screening tool without addressing the underlying risk model has not remediated meaningfully.

The remediation evidence covers the steps taken after discovery: personnel actions, system changes, policy revisions, enhanced testing, and any retraining. It should be documented contemporaneously, not reconstructed after the fact. OFAC's guidelines treat the comprehensiveness and speed of remediation as a mitigating factor, and the file must show both.

Myth: a firm with a documented compliance programme cannot face a serious OFAC enforcement outcome. This is incorrect. OFAC's enforcement guidelines require that the programme be appropriate to the firm's risk profile – not merely documented. A large financial institution with a nominal paper programme and no testing or risk-calibration does not benefit from the same mitigation as an institution whose programme is genuinely fit for purpose. We regularly advise clients that programme documentation and programme effectiveness are not the same thing, and OFAC's assessors distinguish them.

Related practices

Frequently asked questions

What are the steps to assess an apparent violation under OFAC?
An apparent-violation assessment under OFAC proceeds in six stages: (1) identify the trigger and preserve the evidentiary record immediately; (2) scope the transaction set through a disciplined look-back; (3) apply OFAC's published aggravating and mitigating factors to the facts; (4) compare the exposure across any parallel regimes (OFSI, EU, SECO) where relevant; (5) decide deliberately whether and when to make a voluntary self-disclosure; and (6) build a remediation file covering the factual record, the compliance programme review, and the remediation steps taken. Legal counsel should be involved from step one, not introduced at step five.
What is the most common mistake in apparent-violation assessment?
The most common mistake is allowing business-continuity pressure to delay or compress the look-back scope. A business that discloses one apparent violation to OFAC while a related pattern remains undiscovered in the same transaction set faces a significantly worse enforcement outcome than one that presented the complete picture from the outset. OFAC's guidelines treat comprehensive self-reporting as a mitigating factor; partial reporting, if followed by a subsequent discovery, can be treated as an aggravating one. The second most common mistake is treating the compliance programme review as an afterthought to the transaction analysis rather than running them in parallel.
How does OFAC differ from other regimes here?
OFAC differs from OFSI and the EU principally in three respects. First, OFAC's aggravating and mitigating factor framework is published in substantial detail, creating a relatively transparent penalty-calibration process; EU enforcement varies by Member State. Second, OFAC's extraterritorial reach through secondary sanctions means non-US businesses can face OFAC exposure on transactions with no direct US nexus, a risk that OFSI and SECO do not replicate in the same form. Third, the OFAC voluntary self-disclosure mechanism is clearly defined and carries explicit mitigation value in the guidelines; the comparable mechanisms under OFSI and SECO differ in their procedural form and the weight given to disclosure timing.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.