Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFAC

How to set up escalation and reporting under OFAC

A compliance officer at a mid-sized trading firm receives a screening alert at 4 p.m. on a Friday. A payment to a regular supplier has triggered a potential match against an entry on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). No one has written down who decides what happens next. The payment processing window closes in hours. Without a tested escalation path, the firm faces two equally poor outcomes: processing a potentially blocked transaction, or freezing a clean payment and damaging a commercial relationship.

Setting up escalation and reporting procedures under OFAC means establishing a documented, tested chain from the first screening alert through to a senior decision-maker, with clear timelines, defined roles, and a written record at each stage. OFAC's compliance guidance identifies escalation and reporting as core elements of an adequate sanctions compliance programme. Firms that lack this structure face heightened enforcement risk, and a poorly documented response to a potential match can convert a minor screening issue into a significant compliance failure.

This guide walks through the architecture of an effective OFAC escalation and reporting programme, explains where cross-border differences with OFSI and the EU create additional obligations, and identifies the points at which external sanctions counsel adds the most value.

Step 1 – Understand the Governing Regime and the Authority Behind It

OFAC – the Office of Foreign Assets Control within the US Department of the Treasury – administers and enforces US economic sanctions under the authority of statutes including IEEPA. Its remit extends extraterritorially: non-US entities that process US-dollar transactions through US correspondent banks, or that deal in US-origin goods or technology, are within scope. That extraterritorial reach is the first thing a cross-border business must absorb before designing any escalation procedure.

OFAC publishes its Framework for OFAC Compliance Commitments, which identifies five essential components of an adequate programme: management commitment, risk assessment, internal controls, testing and auditing, and training. Escalation and reporting sit within the internal-controls component, but they draw on all five. A firm cannot escalate effectively if management has not committed to acting on escalated issues, and it cannot report accurately if its risk assessment has not identified which transaction types are highest priority.

The OFAC compliance framework does not require any single prescribed escalation structure. It identifies the outcome – prompt, accurate identification of potential matches and timely action – not the org-chart route. That flexibility is useful, but it also means that a firm which does nothing can always argue it lacked prescriptive guidance. OFAC's enforcement record consistently treats the absence of a documented procedure as an aggravating factor. In our experience, regulators read a missing procedure as a management decision not to have one.

Step 2 – Map the Trigger Points That Require Escalation

Escalation begins when a screening system, a business-line team member, or an automated filter generates an alert that a counterparty, transaction, or asset may be subject to an OFAC prohibition. Not every alert requires the same response. The first design task is mapping the categories of trigger that warrant different levels of escalation urgency.

Three broad categories cover most situations a cross-border business encounters. First, a potential exact or near-exact match against the SDN List or another OFAC-administered list – this is the highest-urgency tier and requires immediate escalation to the designated sanctions officer. Second, an indicator of indirect exposure – for example, a counterparty in which a listed person may hold an interest – requiring the ownership and control (the test for whether a non-listed entity is caught through a listed person) analysis before a decision is taken. Third, a transaction that falls within a programme that requires a licence and where no licence is yet confirmed – this is a process alert rather than a match alert, but it still requires escalation before the transaction proceeds.

Have you documented which of these three categories your screening tools actually detect? In our practice, firms often configure their tools for SDN matches and then assume the tool handles indirect exposure. It does not, without specific ownership-chain logic built in.

Alongside transaction-screening alerts, escalation maps must address the receipt of a subpoena, a voluntary self-disclosure (VSD – a proactive report to OFAC of an apparent violation) decision point, a request from a correspondent bank for information about a specific payment, and the discovery of a blocked asset that has not been reported. Each of these has a different procedural response and a different urgency timeline.

Step 3 – Design the Escalation Chain and Assign Named Roles

An escalation chain that works in practice has named individuals, not job titles in the abstract, assigned to each decision point. The chain should run from the front-line reviewer who first sees the alert, through a designated sanctions officer (or compliance officer with sanctions authority), to senior management for any decision involving a potential match that cannot be resolved within a defined short window.

The key design questions are straightforward but frequently unanswered in the documentation. Who has the authority to place a hold on a payment? Who can release a hold after a false-positive determination? Who decides whether to make a VSD to OFAC? Who approves a decision to submit a specific-licence application? Each of these is a distinct authority, and conflating them in a single role creates bottlenecks – and, in enforcement contexts, accountability problems.

Cover for absences is a practical issue that organisations often discover only when it matters. If the designated sanctions officer is unavailable and a same-day decision is needed, the escalation chain needs a named deputy and the deputy needs documented authority to act. OFAC's enforcement posture treats the absence of a functioning escalation structure at the time of an incident as evidence of systemic inadequacy, not bad luck.

For multi-jurisdictional businesses, the escalation chain also needs to specify which jurisdiction's rules govern when regimes conflict. A UK-based entity subject to both OFSI and OFAC obligations may receive alerts that engage both regimes simultaneously. The chain must specify which compliance officer has primary responsibility and how cross-regime coordination works. This is not theoretical: the US and UK ownership tests differ in material ways, and a decision that resolves an OFSI question may not resolve the OFAC question.

Step 4 – Establish Timelines and Decision Windows

Timelines under an OFAC programme are not all statutory, but they are real. Several are embedded in OFAC's own guidance or in related US law; others are operational realities imposed by correspondent-bank requirements and payment-system cutoff times.

Once a firm identifies that it is holding blocked property or funds, OFAC requires reporting within a short statutory window – the specific period is set by the applicable OFAC programme regulations and varies; verify the current requirement before relying on it. What does not vary is the principle: the clock starts from knowledge, not from a convenient administrative moment. In our experience, firms that treat the reporting obligation as starting from the date of a formal internal review rather than from the date of awareness expose themselves to an avoidable aggravating factor in any subsequent enforcement analysis.

For specific licences (case-by-case authorisations to conduct an otherwise prohibited transaction), OFAC processing times vary by programme and by the complexity of the application. Escalation procedures should build in lead time before a commercial deadline, rather than treating the licence application as an emergency measure after a deal has already been signed. A decision matrix in the procedure – if the transaction is of type X and requires a licence, begin the licence process at least N weeks before closing – prevents the compressed timeline from becoming a risk factor.

The VSD timeline is particularly important. OFAC's enforcement guidelines treat a prompt VSD as a significant mitigating factor. "Prompt" is not defined with a precise day count in published guidance, but the practical standard is clear: a firm that takes months to disclose after discovering an apparent violation is unlikely to receive the same credit as one that discloses within weeks. The escalation procedure should specify the maximum internal review period before a VSD decision is escalated to senior management and, where appropriate, external counsel.

Step 5 – Document Every Stage and Maintain Records

Documentation is not a formality. It is the evidence base against which OFAC – and, in a criminal matter, the Department of Justice – will assess the firm's response if an apparent violation is ever reviewed. An escalation procedure that operates but is not documented is almost indistinguishable, from a regulator's perspective, from one that did not operate at all.

Each escalation event should generate a written record capturing: the date and time the alert was raised; who raised it; what screening hit or trigger event was identified; what decision was made; who made it; and the basis for the decision. Where a false-positive determination is made, the reasoning should be recorded explicitly. Where a hold is released after review, the record should state why. Where a VSD decision is made, the file should document the chain of authority approvals.

Record-keeping obligations under OFAC require firms to maintain records relating to any transaction or activity that touches a sanctions programme. The required retention period under current OFAC guidance is five years. That five-year window means that an escalation decision made today will potentially be reviewed in a future investigation against records that must still be retrievable. Storing records in systems that are scheduled for decommissioning before the retention period ends is a risk that compliance teams sometimes identify only when an investigation is already under way.

A related point concerns the format of records. Escalation decisions made over messaging applications – including encrypted platforms – may not satisfy OFAC's record-keeping requirements if the messages are not archived. In our practice, we regularly advise firms to route escalation communications through systems that are already configured for regulatory record-keeping, rather than retrofitting archiving onto informal channels.

Step 6 – Cross-Regime Reporting: How OFAC Differs from OFSI and the EU

OFAC's escalation and reporting requirements do not operate in isolation for any business with non-US operations. Understanding where the UK and EU regimes diverge – and where they reinforce OFAC obligations – is essential to building a procedure that holds across the full scope of a cross-border business.

Under OFSI (the Office of Financial Sanctions Implementation, the UK equivalent of OFAC), there is a statutory obligation to report knowledge or reasonable cause to suspect that a person is a designated person, or has committed an offence under the relevant financial-sanctions legislation. This is a positive reporting obligation; it is not contingent on a specific transaction being in progress. The OFAC reporting obligation is structurally different: it attaches primarily to the holding of blocked property and to the filing requirements that accompany specific licence applications and VSDs. A firm that designs its escalation procedure around only one of these models will have gaps when it encounters the other.

The EU regime, administered through Council regulations, imposes both asset-freezing obligations and reporting requirements on competent national authorities. The ownership and control test under EU law requires an assessment of effective control, not only a mathematical ownership calculation. That means a counterparty in which a listed person holds less than 50 percent of the shares may still be caught if there is evidence of effective control. An escalation procedure designed for OFAC's mechanical threshold test will not catch this category of EU exposure without an additional analytical step.

For a business operating across all three regimes, the practical answer is a tiered escalation protocol. Tier one applies the OFAC 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) as a threshold test to every counterparty. Tier two applies the EU and OFSI control analysis to any counterparty that passes the OFAC threshold test but where there are indicators of listed-person involvement. Tier three addresses regime-specific reporting obligations – OFSI's positive reporting duty, OFAC's blocked-property report, and the relevant EU competent-authority notification requirement – as distinct procedural steps, not as a single "report to regulator" action.

Singapore, the UAE, and Japan have each developed their own escalation and reporting requirements under their respective national sanctions instruments. The standards are not uniform. Singapore's MAS financial-sanctions requirements include notification obligations that operate on shorter timelines than OFAC's. Businesses with significant operations in these jurisdictions should verify the applicable country regime's reporting windows and integrate them into the escalation chain explicitly, rather than treating OFAC as a proxy for all regimes.

Step 7 – Test the Procedure and Identify When to Involve External Counsel

A written escalation and reporting procedure that has never been tested is an aspiration, not a control. OFAC's compliance guidance explicitly identifies testing and auditing as one of the five essential components of an adequate programme. The escalation procedure should be tested at least annually through scenario exercises that simulate a real match, a potential indirect-exposure situation, and a VSD decision point.

Testing reveals bottlenecks that are invisible in the org-chart version of the procedure. In a recent exercise we facilitated for a financial-services client, the escalation chain worked well for straightforward SDN matches but broke down at the point where a decision required both the sanctions officer and a senior business-line approval. The two individuals had different interpretations of their respective authorities. That ambiguity, if discovered during a real event rather than a test, would have cost the firm significant time and created a documentary gap.

External sanctions counsel is most valuable at four points in the escalation cycle. First, at the design stage – ensuring the procedure maps to current OFAC guidance and to the cross-regime requirements that apply to the firm's specific activities. Second, at the point of a potential match that cannot be resolved by the standard false-positive analysis – where the counterparty's ownership chain is complex or where programme-specific restrictions raise questions that general compliance training does not answer. Third, when a VSD decision is being considered – the VSD process involves legal judgments about the scope of the disclosure, the characterisation of the violation, and the penalty-mitigation strategy, all of which benefit from specialist input. Fourth, in the design and execution of the annual test, where an outside assessment of the procedure's weaknesses carries more weight with OFAC than a purely internal review.

The position above covers the standard design. Your facts – the jurisdictions you operate in, the sectors you serve, the payment channels you use, and the specific OFAC programmes most relevant to your business – change the analysis significantly.

If you are designing or reviewing your escalation and reporting procedures, contact Calder & Vance at info@caldervance.com for an assessment.

Common myths in escalation design

A persistent misconception in this area is that an escalation procedure can be satisfied by routing every alert to the same senior officer for sign-off. This seems conservative; it is actually a control weakness. When every alert goes to one person, that person is overwhelmed, decisions become cursory, and the documentary record collapses into a series of brief approvals with no reasoning. OFAC's compliance framework calls for proportionate escalation – the level of authority matched to the seriousness of the issue – precisely because a flat structure produces both over-escalation of trivial matters and under-examination of genuinely complex ones.

A second myth is that a VSD is always the right answer when an apparent violation is identified. VSD is a significant mitigation tool, but it is not unconditional. The decision to disclose turns on an analysis of the apparent violation's scope, the likely enforcement interest, and the quality of the evidence available to support the firm's account of events. In our experience, firms that make a VSD without completing that analysis first sometimes disclose in terms that are broader than the facts require, creating enforcement exposure for activity that would not independently have come to OFAC's attention.

Related practices

Frequently asked questions

What are the steps to set up escalation and reporting under OFAC?
The core steps are: (1) map the trigger points that require escalation – SDN matches, indirect exposure, missing licences, blocked-property discovery; (2) design the escalation chain with named individuals and defined authorities; (3) establish decision timelines, including the blocked-property reporting window and the VSD review period; (4) document every escalation event and maintain records for at least five years; (5) test the procedure annually through scenario exercises; and (6) define the points at which external counsel is brought in. Each step should be written into a policy document that management has formally approved, so that it forms part of the firm's evidence of an adequate sanctions compliance programme.
What is the most common mistake in escalation and reporting procedures?
The most common mistake is building a procedure that routes every alert to a single decision-maker without differentiating by urgency or complexity. This creates a bottleneck that generates cursory decisions and thin documentation. A close second is treating the blocked-property reporting clock as starting from the date of the internal review rather than from the date of awareness – a distinction that OFAC's enforcement posture consistently treats as material. Both errors are avoidable with a clearly written tiered escalation protocol and an explicit statement in the procedure of when the reporting obligation begins.
How does OFAC differ from other regimes here?
OFAC's escalation and reporting obligations are primarily triggered by the holding of blocked property and by the VSD process; the ownership test is mechanical at the 50 percent threshold. OFSI imposes a positive reporting duty based on knowledge or reasonable suspicion, regardless of whether a transaction is in progress – a materially broader trigger. The EU regime adds an effective-control analysis that can catch counterparties below the OFAC ownership threshold. Businesses subject to all three regimes need a tiered protocol that addresses each regime's specific reporting trigger, rather than a single "report to regulator" step that conflates structurally different obligations.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.