A trading group with operations in three jurisdictions receives notice that its parent company has reached a settlement with a US enforcement authority. Within days, the group's EU and UK subsidiaries are asking the same question: does the monitorship imposed on the parent extend to us, and if so, who is in charge? The answer is rarely simple, and the cost of getting it wrong can reset the monitorship clock entirely.
Managing a compliance monitorship across borders requires a business to satisfy potentially simultaneous obligations imposed by OFAC, OFSI, the EU Council, and other national enforcement authorities – each of which may appoint or approve a different monitor, set different reporting windows, and apply different programme standards. There is no single international monitorship template. The governing authority and the applicable regime determine every procedural step.
This guide walks through the phases of a cross-border monitorship: from the appointment of the monitor, through the first assessment, to ongoing reporting and, ultimately, the conditions for discharge. As of March 2026, the divergence between OFAC, OFSI, and EU practice has sharpened, making structured planning essential before the monitorship begins.
What is a compliance monitorship and when does it apply cross-border?
A compliance monitorship (an arrangement under which an independent expert assesses and reports on a firm's sanctions or export-control programme to an enforcement authority) most commonly arises from a settlement or consent agreement following an apparent violation. Under the US regime, OFAC may impose or recommend a monitorship as a condition of a civil settlement; BIS can do the same under the Export Administration Regulations. OFSI in the United Kingdom and EU enforcement authorities have comparable powers.
A monitorship becomes cross-border when the settling entity has affiliates, branches, or significant business relationships that are subject to different national regimes. In that situation, the monitor's mandate – however it is framed in the settlement documents – may not automatically carry legal authority in a second jurisdiction. The parent-company settlement does not bind the UK subsidiary to OFSI's satisfaction, nor does it constitute an EU Council-approved compliance measure.
Cross-border monitorships therefore involve three distinct problems: jurisdictional scope (which entities are covered under which law), programme standards (what the monitor must assess and by whose benchmark), and reporting (to whom, in what form, and by when). Practitioners managing these matters must address all three simultaneously rather than sequentially.
Step 1 – Mapping the jurisdictional perimeter before the monitor is appointed
The first and most consequential step is defining which legal entities and which geographic operations fall within each enforcement authority's reach. This mapping exercise must be completed before the monitor's terms of reference are finalised, because scope errors at appointment are difficult to correct once the process is running.
Begin with the settlement document itself. OFAC settlements name the settling entity and frequently list the subsidiaries the agreement is intended to cover. BIS administrative settlements do the same. But neither instrument binds OFSI or the EU Council. If the group's UK and EU operations have potential exposure – from the same conduct that produced the US settlement, or from related activity – those authorities may open separate proceedings or require parallel assurance.
In our cross-border practice, groups that treat the US settlement as the end of their enforcement exposure routinely discover that OFSI or an EU national competent authority has been monitoring the same underlying conduct. Early engagement with non-US authorities, conducted carefully through counsel, can shape whether a second formal process is required or whether a voluntary assurance commitment is sufficient. Waiting for that second process to arrive is almost always more expensive.
The jurisdictional map should also address secondary-sanctions risk. A business that operates in sectors sensitive to OFAC's secondary-sanctions programmes may find that its non-US entities face exposure even without a direct US-nexus transaction. The monitor appointed under an OFAC settlement may need to assess global operations for secondary-sanctions risk – and that assessment will carry implications for the group's EU and UK compliance programmes regardless of whether those authorities have formally intervened.
Step 2 – Establishing the monitor's authority, standards, and reporting lines
Once the perimeter is defined, the next step is formalising what the monitor can do, whose programme standards they apply, and to whom they report. This structural question determines whether the monitorship is operationally feasible or whether it will generate friction with local management and local counsel from the outset.
Under OFAC practice, the monitor typically operates under a detailed engagement letter approved by OFAC as part of the settlement. That letter sets out the scope of review, the testing methodology, the timeframe for the first report, and the conditions under which OFAC may require additional review. BIS monitorship terms follow a similar structure. Both regimes expect the monitor to assess the entity's programme against a recognised set of elements – often described in the relevant agency guidance as a five-element framework covering management commitment, risk assessment, internal controls, testing and auditing, and training.
OFSI's approach to monitorships is less codified but no less demanding. OFSI's published enforcement guidance makes clear that it expects entities subject to enforcement action to demonstrate a credible path to compliance. In practice, that means OFSI may require periodic reporting from a qualified internal function or an external adviser, even where a formal monitorship has not been explicitly ordered. The standard applied by OFSI focuses on whether the entity has identified the root cause of the breach and whether its programme now addresses that root cause structurally.
EU national competent authorities vary considerably. Some member states have well-developed enforcement and monitorship practice; others are at earlier stages. The EU Council's sanctions programme is administered at the member-state level, which means that a group with subsidiaries in multiple EU member states may face different local expectations about what a monitorship report should contain and who should prepare it. We regularly advise groups on harmonising the EU component of a multi-regime monitorship so that a single review workstream satisfies multiple local authority expectations wherever the legal basis permits.
The reporting line question is practical but sensitive. The monitor owes their primary duty to the enforcement authority, not to the entity being monitored. In a cross-border monitorship, where multiple enforcement authorities are involved, the monitor's obligations to each must be clearly articulated – and the entity must understand that information shared with the monitor may reach each authority to which the monitor reports.
How does a cross-border monitorship differ from a single-regime monitorship?
The core difference is that a single-regime monitorship has one benchmark, one reporting line, and one clock; a cross-border monitorship has several of each, and they do not always synchronise. This multiplicity is the source of most operational difficulty in cross-border monitorships.
Programme standards diverge in ways that matter operationally. OFAC's guidance on what constitutes an effective compliance programme is detailed and publicly available. OFSI's guidance is less prescriptive but places significant weight on senior management accountability and on the adequacy of the root-cause analysis. EU practice, through the relevant national competent authorities, is patchy: some authorities assess programmes against international benchmark standards; others focus primarily on whether the specific conduct that triggered enforcement has been remediated.
Timelines diverge too. An OFAC settlement may impose a monitorship of a defined duration – often one to three years, with the possibility of extension if the monitor's findings are unsatisfactory. OFSI does not publish standard monitorship durations; the length is determined by the facts of each case and by the pace at which the entity demonstrates credible remediation. EU timelines similarly vary by member state and by the severity of the underlying breach.
The practical consequence is that a group may be simultaneously in the final phase of its OFAC monitorship – with the monitor preparing a close-out report – while still in the first phase of an OFSI assurance process. The group's internal compliance team must manage both simultaneously. Resourcing that workstream, maintaining management attention, and preventing monitor-fatigue within the organisation are genuine operational challenges. In our experience, firms that assign a single senior internal owner to the entire cross-border process perform substantially better in monitor assessments than those that fragment ownership by jurisdiction.
Step 3 – Running the programme assessment: what the monitor examines
The monitor's substantive assessment, regardless of regime, will examine whether the entity's compliance programme is adequate to prevent a recurrence of the conduct that led to enforcement. The specific elements vary, but the core questions are consistent across OFAC, OFSI, and EU practice.
Ownership and control mapping is central. A monitor will expect the entity to demonstrate that it can identify counterparties who are directly listed and counterparties who are captured through the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) or the equivalent EU and UK ownership-and-control tests. Screening tools that flag only directly listed names are not, in most monitors' assessment, adequate for a business with significant exposure. This is a recurring finding in monitorship reports across all major regimes.
Transaction monitoring and screening architecture will be tested against the nature and volume of the entity's business. A financial institution faces different expectations than a goods exporter. The monitor will look at whether the screening lists used are current, whether false-positive workflows are documented and defensible, and whether escalation pathways are clear and are actually followed when a potential match arises.
Training is examined both for content and for reach. A programme that trains the compliance function thoroughly but leaves front-line business teams untouched is unlikely to satisfy any major regime's monitor. Evidence that training has been updated to reflect the conduct that led to enforcement – not just refreshed generically – is particularly important.
Record-keeping requirements apply across all major regimes. Under the EAR, exporters are required to maintain records for a defined period. Under OFSI and EU requirements, similar obligations apply. The monitor will verify that the entity's record-keeping practice meets the applicable standard and will typically request a sample of transaction documentation to test it in practice.
The cross-border dimension adds a layer: the monitor will assess whether the group's various entities are operating to a consistent standard or whether there are significant programme gaps in particular jurisdictions. Subsidiaries that have been excluded from the group's primary training and screening infrastructure are a red flag in any cross-border monitorship. The monitor's report will note them, and the enforcement authorities that receive the report will act on that notation.
Common risk flags and the mistakes firms make mid-monitorship
Mid-monitorship failures are more common than initial non-compliance. A business that has invested heavily in its programme in the immediate aftermath of a settlement can lose momentum in year two, when the urgency has faded and the resource demands of the monitorship compete with ordinary business priorities. Enforcement authorities are attentive to this pattern.
The most common structural mistake is treating the monitorship as a discrete project rather than as a live component of the firm's compliance architecture. When the monitorship ends, the programme must continue to function without the monitor's scrutiny – but programmes built primarily to satisfy a monitor, rather than to prevent violations, often do not survive the transition intact.
A second common error is insufficient documentation of changes made in response to monitor findings. A monitor who identifies a gap in the first-year report and returns in year two to find the gap has been closed will expect a clear documentary record of what was changed, when, and by whom. An absence of that record is read as a programme that responded to findings reactively and superficially rather than systematically.
A third risk is inadequate coordination between external counsel advising the entity and the monitor. The monitor is independent; counsel does not represent the monitor and the monitor does not take instruction from counsel. But effective coordination – ensuring that counsel's advice on legal questions is factored into the monitor's assessment of the programme's adequacy – reduces the risk of the monitor taking a position that counsel and the entity would not have anticipated. Early and clear communication about respective roles is essential.
Finally, firms operating across OFAC, OFSI, and EU regimes simultaneously risk allowing the highest-profile enforcement authority to crowd out attention to the others. An OFAC monitorship, with its detailed reporting obligations and formal timelines, can absorb internal resource to the point where the UK and EU components receive inadequate attention. That imbalance will be apparent to OFSI or an EU national competent authority – and it is unlikely to be viewed favourably.
The position above covers the structural risks in a standard multi-regime monitorship. Your specific facts – the settlement terms, the regulated entities in scope, the enforcement authorities involved, and the timeline – will change the analysis materially. For an assessment of your exposure under a cross-border monitorship, contact Calder & Vance at info@caldervance.com.
Step 4 – Reporting to enforcement authorities and managing monitor findings
Reporting obligations under a cross-border monitorship are the point at which the multi-regime structure creates the most operational tension. Each enforcement authority expects timely, accurate reporting on the state of the entity's compliance programme – but the format, frequency, and content each authority expects may differ.
Under OFAC practice, the monitor submits reports directly to OFAC at intervals specified in the settlement agreement, with a copy typically provided to the entity. The entity has limited ability to amend the monitor's findings, though it may have an opportunity to submit a written response to factual errors before the report is finalised. OFAC uses the monitor's reports to determine whether the terms of the settlement have been satisfied and whether the monitorship should be extended or closed.
OFSI receives periodic reporting from entities subject to enforcement undertakings, though the exact mechanism varies by case. In matters we have advised on, OFSI has expected both structured progress reports and evidence that senior management has reviewed and signed off on the remediation steps taken. The senior management accountability element is a distinctive feature of OFSI's enforcement approach and should not be underestimated in a cross-border monitorship context.
At the EU level, reporting typically flows through the national competent authority of the relevant member state, rather than directly to the EU Council. This creates practical complexity for a group with operations in multiple member states: the group may need to submit separate reports to multiple national authorities, each of which may apply a different review standard. Coordinating those reports – ensuring consistency while addressing each authority's specific requirements – is a significant task that should be planned and resourced before the first reporting deadline arrives.
If a transaction has already been flagged, or a reporting obligation is approaching, early engagement with external counsel can preserve options that narrow with time. For a confidential review of a monitorship matter, contact us at info@caldervance.com.
When and how a monitorship ends: the discharge test across regimes
Discharge – the point at which the enforcement authority confirms that the monitorship obligations have been satisfied – is the goal of the entire process, but the conditions for discharge differ materially between regimes, and satisfying one authority does not automatically satisfy others.
Under OFAC practice, discharge follows the monitor's final report confirming that the entity's compliance programme has reached a defined standard of effectiveness and that the programme is sustainable without the monitor's ongoing oversight. OFAC reviews that report and issues a formal confirmation. If OFAC is not satisfied, it may extend the monitorship or impose further conditions.
OFSI does not publish a formal discharge process in the same way, but in practice an entity is considered to have completed its enforcement obligations when OFSI is satisfied that the root cause of the breach has been addressed, the programme is adequate, and the undertakings given at the time of settlement have been fulfilled. Senior management attestation is typically required at this stage.
EU discharge practice, again, varies by member state. Some national competent authorities issue a formal confirmation; others close the matter by administrative notice. Where the monitorship has run across multiple EU jurisdictions, each relevant authority must be satisfied independently.
The practical point is that a group that obtains OFAC discharge may remain under OFSI supervision for a further period, or may be awaiting confirmation from one or more EU national competent authorities. Managing the close-out phase requires the same structured attention as the initial phase. Do not assume that one authority's satisfaction communicates itself to the others.
Related practices
- Apparent violation assessment (EU) – early-stage analysis of EU sanctions exposure and enforcement risk before a monitorship begins.
- Compliance monitorship – EU guide – detailed guidance on managing an EU Council-supervised monitorship from appointment to discharge.
- Compliance monitorship – Japan guide – practical guide to monitorship obligations under the applicable Japanese regime.