Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · OFSI

Managing a compliance monitorship under OFSI: a compliance guide

A payment firm discovers that one of its corporate clients processed transactions to a counterparty that later appeared on an OFSI asset-freeze list. The firm's compliance team has already filed a report under the applicable regulations. OFSI now signals that it will require independent oversight of the firm's remediation programme. What happens next – and what does managing that process well actually require?

A compliance monitorship under OFSI is a structured oversight mechanism in which an independent monitor, appointed following an enforcement settlement or as a condition of a civil penalty decision, reviews and tests a firm's sanctions compliance controls over an agreed period. As of March 2026, OFSI has the power under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic regulations to impose monitorship conditions as part of a monetary penalty settlement or, in some cases, as a stand-alone remediation requirement. The monitorship period, the monitor's scope of work, and the reporting obligations are defined in the settlement or appointment terms.

This guide walks through each stage of the OFSI monitorship lifecycle – from initial appointment through to monitor sign-off – and explains where the process diverges from comparable mechanisms under OFAC, EU competent authorities, and SECO. It also identifies the risk flags that most commonly extend a monitorship beyond its original term.

What is an OFSI compliance monitorship and when is one imposed?

An OFSI compliance monitorship is an independent, time-limited review of a firm's sanctions compliance programme, imposed as a condition of resolving an enforcement matter under the UK financial-sanctions regime. OFSI's enforcement powers derive from SAMLA and the relevant thematic regulations; the monitorship is one of several outcomes available to it following a finding of a breach or a voluntary disclosure.

OFSI imposes a monitorship in one of three scenarios. First, where a monetary penalty is agreed and OFSI determines that the firm's remediation steps have not yet been independently verified. Second, where a settlement is reached without a formal penalty but the firm's compliance controls are assessed as materially deficient. Third – and less commonly – where a firm proactively proposes independent oversight as part of a voluntary self-disclosure (VSD; a report made to OFSI before any formal investigation has begun) to demonstrate good faith and strengthen its mitigation case.

The scope of the monitorship is not fixed by statute. It is negotiated – or, where OFSI imposes it unilaterally, contested – before appointment. That negotiation matters considerably. A broadly drafted scope can expose operational areas that were not implicated in the original breach, generating fresh findings and extending the monitorship's duration. In our experience, firms that enter the scoping process without legal support frequently agree to terms that are far wider than the underlying facts require.

One immediate question for any board or general counsel is whether the monitorship is a purely domestic UK matter. It rarely is. A firm subject to OFSI oversight is, in most cases, also operating within the reach of OFAC, EU competent authorities, or both. Parallel disclosure obligations, the risk of US secondary-sanctions exposure, and the interaction between the OFSI monitorship and any EU or OFAC programme review must be addressed from day one.

Step 1 – Prepare the foundation before the monitor arrives

The period between confirmation of the monitorship and the monitor's first formal engagement is the most operationally valuable window a firm has. Use it.

The first priority is a legal-privilege review. Identify which internal investigation materials, board minutes, and external advice documents are protected by legal professional privilege. A monitor has access to materials within the agreed scope; privilege protects others. Confusing the two – or failing to mark privileged materials clearly – can inadvertently waive protection over documents that OFSI, and potentially other regulators, might otherwise never see.

The second priority is a programme baseline. Before the monitor forms their first impression, the firm should conduct its own honest gap analysis: which controls failed, why they failed, and what remediation steps have already been taken. This baseline serves two purposes. It gives the firm a starting position to defend, and it provides the monitor with a structured entry point that frames the scope of their work. Presenting a reactive, disorganised compliance function to an incoming monitor from the outset is a significant risk.

Third, designate a monitorship management team. This team should include a senior compliance officer with clear authority, legal counsel (internal or external) with sanctions expertise, and an operations lead who can respond quickly to the monitor's document requests. A single point of contact for the monitor reduces the risk of inconsistent representations and speeds up the information flow the monitor needs.

The position above covers the standard preparation phase. Your facts – the nature of the breach, the product lines in scope, the jurisdictions in play – will change the analysis materially. If you are managing a matter that spans OFSI and a second regime, early alignment between advisers in each jurisdiction is not optional.

Contact Calder & Vance at info@caldervance.com for an early assessment of your monitorship scope and the preparation steps appropriate to your facts.

Step 2 – Negotiate and document the monitorship terms

The monitorship terms document is the governing instrument for the entire engagement, and its drafting deserves the same scrutiny as any material commercial contract. It should define the monitor's mandate precisely: which business lines, legal entities, products, and transaction flows are in scope, and which are expressly excluded.

Key provisions to address include the following. The duration: monitorships typically run for a defined period, often expressed in months, with a renewal mechanism if milestones are not met. The reporting cadence: interim progress reports, milestone reports, and a final sign-off report should each have defined timelines and addressees (OFSI, the firm's board, or both). The monitor's access rights: to staff, systems, transaction data, and correspondence. The escalation procedure: what happens if the monitor identifies a potential new breach during their work. And the milestone criteria: the measurable benchmarks the firm must achieve for the monitorship to conclude on schedule.

The escalation procedure is worth particular attention. If the monitorship terms require the monitor to report apparent new violations directly to OFSI, the firm needs a parallel internal protocol that ensures legal counsel is immediately notified of any developing issue. A new breach identified by a monitor during an active monitorship is a serious aggravating factor in any subsequent enforcement action.

Firms that have also received inquiries from OFAC or an EU competent authority face an additional consideration. The OFSI monitorship terms should be reviewed for consistency with any parallel undertakings given to those authorities. Where a monitorship scope is broader under one regime than another, the gap can create contradictory reporting obligations. We regularly advise firms on aligning the terms of parallel monitorships to reduce that risk.

Step 3 – Manage the monitor's ongoing review

Once the monitorship is active, day-to-day management is primarily an operational discipline. The monitor will request documents, conduct interviews, test screening systems, and review transaction samples. The firm's obligation is to respond accurately, completely, and on time to every request within the agreed scope.

Document requests should be processed through a single workflow. Each request should be logged, allocated to a named owner, reviewed for privilege before production, and returned within the timescale set in the monitorship terms. Missed deadlines are noted in the monitor's reports. A pattern of late or incomplete responses signals to OFSI that the firm's remediation culture has not changed since the original breach – precisely the impression the monitorship is meant to dispel.

Interview preparation is equally important. Employees and managers who will be interviewed by the monitor should understand their obligations: they must answer questions honestly and completely. They should also understand their rights, including the right to have legal counsel present or available. Coaching employees to give misleading answers is not a permissible strategy and would, if discovered, transform a compliance matter into a criminal one.

Interim progress reports are checkpoints. If the monitor's draft report identifies a control gap that the firm disputes, the firm generally has an opportunity to comment before the report is finalised. Use that opportunity carefully and in writing. Verbal representations to a monitor are often summarised, not quoted; written responses are on the record.

If a transaction has already been flagged in the monitorship, or a monitor's interim report has identified a gap that threatens the milestone timeline, an early review of your options can preserve routes that narrow with time.

For a confidential review of a developing monitorship issue, contact us at info@caldervance.com.

How does OFSI's monitorship process differ from OFAC, EU, and SECO equivalents?

OFSI's monitorship mechanism sits within a UK-specific enforcement architecture that differs in important respects from the approaches taken by OFAC, EU member-state competent authorities, and SECO in Switzerland, and those differences affect how a cross-border firm should manage a concurrent obligation.

Under OFAC, a compliance commitment is typically embedded in a settlement agreement accompanying a civil monetary penalty. OFAC publishes detailed compliance commitment requirements and has developed a five-element model for effective sanctions compliance programmes. The OFAC model emphasises management commitment, risk assessment, internal controls, testing and auditing, and training. An independent monitor is not always required; in some matters OFAC accepts an internal attestation by senior management, though external monitoring is increasingly common in larger settlements. The five-element model is a well-established reference point that OFSI has drawn on in its own guidance, though OFSI's published enforcement materials are less prescriptive in their programme standards.

EU competent authorities – operating under the relevant Council regulations and national implementing legislation – vary considerably in their monitorship practice. Some member states operate detailed voluntary-disclosure and monitorship regimes broadly comparable to the UK position; others rely primarily on administrative penalties with less structured remediation oversight. Where a firm is subject to both OFSI and an EU authority's attention, the lack of a harmonised standard means that a monitorship milestone achieved to OFSI's satisfaction may not satisfy the EU authority's separate requirements. We have acted for clients managing exactly this gap, and it requires explicit written confirmation from each authority of the scope of their acceptance.

SECO in Switzerland operates under a distinct legal basis – the Swiss embargo ordinances and the relevant federal instruments – and its remediation approach reflects a civil-law administrative tradition rather than a common-law enforcement settlement model. Reporting timelines and milestone criteria under a SECO-adjacent process differ from OFSI's, and a firm subject to both should not assume that a single integrated monitorship will satisfy both regulators. For the SECO-specific position, see our companion guide at Managing a compliance monitorship under SECO.

Singapore's Monetary Authority and the relevant competent authorities operate under a framework centred on licensing conditions and supervisory undertakings rather than a stand-alone sanctions-monitorship regime in the OFSI sense; parallel exposure under MAS supervision requires separate management. Our guide on the Singapore position is available at Managing a compliance monitorship under Singapore's regime.

The single most practically significant divergence between OFSI and OFAC for a cross-border firm is the ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person). OFSI applies both an ownership limb and a control limb, meaning that a firm whose counterparty is controlled by – but not majority-owned by – a designated person can still be blocked. OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) is purely mechanical and does not include a freestanding control prong. A firm operating under both regimes must apply the stricter standard to each transaction: where the EU or UK control test reaches a counterparty that OFAC's rule does not, the prohibition governs for UK-nexus activity regardless of the OFAC position.

Step 4 – Address the common risk flags that extend monitorships

Most monitorships that run beyond their original term do so because of a manageable failure that was not identified early enough. Knowing the pattern is the first step to avoiding it.

The most common risk flag is a gap between the firm's documented policies and its actual operational practice. A firm may have rewritten its sanctions policy in response to the original breach. But if the screening team is still applying informal workarounds – overriding alerts without documented rationale, for example – the monitor will identify the gap quickly. Policies that exist only on paper do not satisfy the milestone criteria for any monitorship regime.

The second flag is inadequate ownership-chain mapping. OFSI's control test reaches entities managed by a designated person even where ownership sits below the relevant threshold. Screening tools that check only the names of direct counterparties do not catch this. Effective screening must reach the beneficial-ownership layer and test for control indicators, not just name matches. A monitorship milestone that requires the firm to demonstrate end-to-end ownership mapping is one of the most technically demanding, and firms without adequate data sources routinely miss the target date.

Third: training gaps. A monitor will typically test a sample of employees involved in the transaction workflows that were implicated in the original breach. If those employees cannot describe the sanctions controls that apply to their work – or give inconsistent answers about how alerts are managed – the monitor's report will reflect that. Documented, tested, role-specific training is not optional in the OFSI monitorship context.

Fourth: failure to manage the cross-regime dimension. A firm that resolves its OFSI matter but leaves a parallel OFAC or EU exposure unaddressed is not in a good position. OFSI and OFAC share information under the framework of international regulatory cooperation, and a firm that appears to have managed its UK exposure while ignoring a US or EU question will not receive credit from OFSI for its good faith in the monitorship process.

For a detailed look at how similar risk flags are assessed in the context of an EU apparent-violation matter, see our analysis at EU apparent-violation assessment service.

Step 5 – Achieve sign-off and maintain the programme

The monitorship concludes when the monitor certifies to OFSI – and to the firm's board – that the milestone criteria have been met. That certification is not automatic on the expiry of the monitorship period. If milestones remain outstanding, the period is extended. OFSI retains the ability to take further enforcement action if post-monitorship reviews reveal that the remediation was not sustained.

The sign-off process typically involves a final report from the monitor, a board resolution acknowledging the report's findings and committing to the ongoing programme standards, and written confirmation from OFSI that the monitorship obligations have been discharged. The firm should retain all monitorship records – including all document productions, interview notes, interim reports, and correspondence with the monitor – for the applicable record-keeping period under the relevant regulations. Verify the specific retention period with your legal adviser, as it may differ from the general five-year record-keeping standard applicable in some adjacent financial-crime regimes.

Post-monitorship, the programme should be treated as a living structure, not a completed project. The controls tested during the monitorship are now on OFSI's record. A subsequent breach in a control area that the monitor certified as effective will not receive the same credit for remediation in any future enforcement action. We advise clients to conduct a structured annual review of the programme against both the monitor's final report and any updated OFSI guidance, and to document that review at board level.

Correcting a common misconception: the monitorship ends the risk

A persistent belief among compliance teams is that successful completion of an OFSI monitorship effectively closes the chapter and resets the firm's risk profile with the regulator. This requires correction.

Successful completion of the monitorship demonstrates that the firm's programme met the agreed standards at the point of certification. It does not immunise the firm from enforcement if a new breach occurs. OFSI considers an organisation's compliance history when assessing the seriousness of a subsequent breach and in calculating any penalty. A firm that achieved monitorship sign-off but then allowed its programme to decay will face an aggravated penalty position, not a clean slate, if a further violation comes to light.

There is a second misconception: that the monitorship scope defines the outer boundary of OFSI's interest. It does not. If the monitor, during their review, identifies an apparent breach in a business line or product type that is outside the agreed scope, the monitor's reporting obligations – and OFSI's enforcement powers – are not constrained by the scoping document. The scope limits what the monitor is required to examine; it does not limit what OFSI can act on if information comes to light.

In our practice, we have seen firms treat a narrowly scoped monitorship as a green light to defer remediation in the uncovered business lines. That approach is misconceived and carries material enforcement risk.

Related practices

Frequently asked questions

What are the steps to manage a monitorship under OFSI?
Managing an OFSI monitorship involves five sequential steps: preparing the programme baseline and privilege position before the monitor arrives; negotiating the monitorship terms and scope document; managing the monitor's ongoing document requests, interviews, and system tests; addressing risk flags that could trigger a term extension; and achieving formal sign-off from the monitor and OFSI, followed by sustained programme maintenance. Each step requires documented evidence of completion, because the monitor's final report to OFSI will assess progress against each milestone in turn.
What is the most common mistake in managing a compliance monitorship?
The most common mistake is a gap between documented policy and operational practice – specifically, a firm that rewrites its sanctions policy following a breach but does not verify that the updated controls are actually being followed by its operations and screening teams. A monitor tests both: the written policy and the evidence of how alerts, exceptions, and ownership queries are handled day to day. A policy that exists only on paper will not satisfy the milestone criteria and will extend the monitorship beyond its original term.
How does OFSI differ from other regimes here?
OFSI's monitorship mechanism applies the UK-specific ownership-and-control test under SAMLA and the relevant thematic regulations, which reaches entities controlled – as well as majority-owned – by a designated person. OFAC's 50 percent rule is purely mechanical and does not include a freestanding control limb. EU competent authorities vary considerably in their monitorship practice across member states. SECO operates under a civil-law administrative tradition with different milestone and reporting criteria. For a cross-border firm, the practical consequence is that OFSI sign-off does not discharge obligations under any of these parallel regimes, each of which must be separately managed.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.