Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · OFSI

Escalation and reporting procedures under OFSI: a compliance guide

A multinational treasury team receives a payment-screening alert. A counterparty's beneficial owner shares a name with an entry on the UK Consolidated List. The compliance officer escalates to legal. Legal escalates to the board. Three weeks later, no report has reached OFSI, and the firm cannot locate the original transaction records. That sequence – well-intentioned but poorly designed – is where penalties begin.

Escalation and reporting procedures under OFSI are the internal and external steps a UK-regulated business must follow when it identifies a potential sanctions breach, holds funds belonging to a designated person, or suspects a transaction is prohibited. The governing instrument is the Sanctions and Anti-Money Laundering Act ("SAMLA") and the thematic regulations made under it. OFSI can impose significant civil monetary penalties for failures to report, and the reporting obligation operates independently of whether a licence is in place.

This guide sets out each step in sequence: from the screening alert through internal escalation, the obligation to report to OFSI, record-keeping, and the parallel considerations that arise when other regimes – OFAC, the EU, and SECO – apply to the same transaction.

Step 1 – What triggers the escalation duty under OFSI?

The escalation duty is triggered the moment a person knows or has reasonable cause to suspect that they hold funds or economic resources owned, held, or controlled by a designated person, or that a counterparty is such a person. That is the statutory formulation under the relevant thematic regulations made under SAMLA. It does not require certainty. Reasonable suspicion is enough to start the clock.

In practice, escalation triggers fall into three categories. The first is a direct screening hit: the name of a counterparty, beneficial owner, or vessel matches a designated person on the UK Consolidated List. The second is an indirect ownership match: a non-listed entity is owned or controlled by a designated person, which brings it within the prohibition even though its own name does not appear on the list. The third is a transaction-pattern alert: a payment route, intermediary bank, or goods description matches a known typology for sanctions evasion – and the obligation here is to escalate even if no specific name is matched.

What constitutes "reasonable cause to suspect"? OFSI's published enforcement guidance frames it as an objective test. A compliance officer reading the facts at the time of the alert is judged against what a reasonably competent professional in that role would have suspected. In our experience, firms underestimate the second and third trigger categories significantly. They invest in name-matching but leave ownership and typology screening to ad-hoc judgment.

One practical point that matters before Step 2: document the trigger. Write down the time, the alert type, the data that produced it, and the name of the person who received it. That record is your starting evidence for any OFSI engagement.

Step 2 – How should internal escalation be structured?

Internal escalation under an OFSI-compliant programme moves through a defined chain, not an informal conversation, and it should reach a named decision-maker within a short, pre-set window. Many organisations run a tiered structure: a first-level compliance analyst, a sanctions officer, a head of compliance or MLRO, and then senior legal counsel or the board – with each tier holding defined authority and a defined response time.

The escalation path must be written down in a procedure document that staff can locate without assistance. It should specify: who reviews the alert at each stage; what evidence they must gather before passing it upward; and at what point the matter becomes a board notification rather than a compliance matter. OFSI's enforcement approach weighs whether a firm had a documented escalation path when assessing whether a breach was "most serious" or less so. Absence of a documented path is an aggravating factor.

We regularly advise firms that the most common structural gap is not the absence of a procedure on paper but the absence of a procedure that has ever been tested. A procedure that exists in a policy document but has never been walked through – in a tabletop exercise, a fire drill, or a simulated alert – will fail when a real alert arrives at volume or at speed. Has your escalation chain been tested in the last twelve months?

A second structural point: the sanctions escalation path must be separate from, though connected to, the anti-money-laundering suspicious-activity reporting path. They are different legal obligations with different regulators. Mixing them risks delayed action on the OFSI reporting deadline and may compromise the integrity of a suspicious-activity report.

Step 3 – What is the OFSI reporting obligation, and when does it apply?

A regulated business that knows or has reasonable cause to suspect it is holding funds or economic resources belonging to a designated person must report that to OFSI as soon as practicable. The obligation arises under the relevant financial-sanctions regulations made under SAMLA. "As soon as practicable" is not a fixed calendar deadline in the way some other regimes specify one, but OFSI's enforcement guidance makes clear that delay without good reason is an aggravating factor in penalty calculations.

The report to OFSI must contain: the identity of the designated person or the grounds for suspicion; a description of the funds or economic resources believed to be held; the estimated value; and any known transactional history. OFSI provides a reporting portal and a secure email route. In urgent cases – where there is a risk of dissipation or immediate harm – a telephone notification followed by a written report is advisable.

There is a separate information-gathering power that OFSI holds independently. Under the relevant regime, OFSI may require a firm to produce documents and information, and non-compliance with that request is itself a civil offence. Responding to an OFSI information request is therefore not discretionary, and the response must be accurate and complete. Partial responses, even where unintentional, have been treated seriously in OFSI's enforcement record.

The reporting obligation applies whether or not a licence has been granted. A general licence does not extinguish the reporting duty. Neither does the firm's good-faith belief that the transaction was permissible. If the legal basis for that belief was a general licence, say so in the report; but file the report.

If a transaction has already been flagged or a filing has been refused, an early review can preserve options that narrow with time. To discuss your position, write to Calder & Vance at info@caldervance.com.

Step 4 – How does the OFSI position compare with OFAC and EU requirements?

OFSI, OFAC, and the EU each impose reporting and blocking obligations, but the mechanics and timelines differ in ways that matter for cross-border businesses. Understanding the divergence is not an academic exercise. A firm operating between the United Kingdom, the United States, and the European Union faces three parallel sets of obligations that may activate simultaneously on the same transaction.

Under OFAC, the blocking obligation applies when funds or property are within US jurisdiction or in the possession of a US person anywhere in the world. OFAC requires that blocked property be reported – under the relevant programme regulations – within a short statutory window following the date on which property becomes blocked or the blocking person obtains knowledge of the block. That window is significantly shorter than the "as soon as practicable" standard under OFSI. In our practice, firms that miss the OFAC deadline because they were managing the OFSI process first face compounded exposure. The programmes are concurrent, not sequential.

The EU position is set by the relevant Council Regulation. Member states implement the reporting obligation through national competent authorities, which means the deadline and the reporting format can vary between EU jurisdictions. The prohibition is EU-wide; the enforcement is national. For a business with subsidiaries in Paris, Frankfurt, and Warsaw, that produces three parallel reporting chains, each running to a different authority.

SECO, Switzerland's sanctions authority, operates under SECO ordinances and applies its own reporting mechanics. Switzerland is not an EU member state, and its sanctions regime, while closely aligned with the EU in many programme areas, is administered separately. The timing and format of a SECO report differ from both OFSI and OFAC.

One cross-cutting rule applies in all of these regimes: where two or more sets of obligations conflict, the stricter prohibition governs the conduct. A general licence under OFSI does not authorise conduct that OFAC prohibits without a corresponding licence. Firms with US-dollar transactions, US-person counterparties, or US-origin goods must map both OFAC and OFSI exposure before concluding that a general licence settles the matter.

For a deeper look at how Swiss escalation and reporting procedures operate alongside the OFSI regime, see our guide at Escalation and reporting procedures under SECO. For the related SECO compliance considerations, the companion guide is available at Escalation and reporting under SECO – further considerations.

Step 5 – Record-keeping: what must you retain, and for how long?

Record-keeping under the OFSI regime is a standalone obligation, not a by-product of reporting. The relevant thematic regulations require that persons who are required to comply with financial-sanctions obligations keep records of the information and documents that demonstrate their compliance. The retention period under OFSI rules is five years from the date on which the record is created or from the date of the relevant transaction, whichever is later.

What must be retained? At minimum: the screening data used at the time of the transaction; the alert record and its disposition; the internal escalation communications; any report made to OFSI and OFSI's acknowledgment; any licence application, supporting documents, and the licence itself; and the identity verification documents for the counterparty and its beneficial owners. Where a matter was investigated and closed internally without a report to OFSI – because the alert was assessed as a false positive – retain the evidence that supported that conclusion. If OFSI later takes a different view, your contemporaneous record is your primary defence.

Digital records must be stored securely and in a format that can be produced to OFSI within the timeframe of an information request. That is a practical point, not a theoretical one. Firms that hold records in archived email systems, legacy case-management tools, or paper files have found that responding to an OFSI information request within an operationally tight window is extremely difficult. Test your record retrieval before you need it.

Step 6 – Risk flags: when does the matter require external counsel?

Most escalation matters are handled internally and resolved without external involvement. Some are not. The risk flags that, in our practice, consistently indicate that external counsel should be retained early are as follows.

First: the apparent breach involves a significant sum or a systemically important counterparty. OFSI's penalty regime scales with the value of the breach, and the firm's conduct in the period immediately after discovery is assessed as either mitigating or aggravating. Advice on whether and how to engage with OFSI is most valuable before the first communication.

Second: the matter activates both OFSI and another regime – typically OFAC. When two enforcement authorities may be examining the same transaction, the sequencing of disclosures, the content of voluntary disclosures, and the relationship between the two processes all require coordination. A voluntary self-disclosure (a VSD – a report submitted to a regulator before that regulator becomes aware of the breach, generally treated as a mitigating factor) under OFAC does not automatically satisfy the OFSI reporting obligation, and vice versa.

Third: the internal escalation process itself failed. If the breach was not reported in accordance with the firm's own documented procedure – because the procedure was unclear, because a step was skipped, or because someone exercised undocumented discretion – the firm faces both the substantive breach and a process failure. OFSI weighs the adequacy of a firm's compliance programme when setting penalties. Documenting a remediation of that failure, before OFSI asks about it, changes the assessment.

Fourth: a designated individual is involved, rather than a corporate entity. The personal dimension – potential criminal exposure for the individual, reputational risk for associated directors – changes the advice significantly.

What is the common myth here? That early involvement of external counsel signals guilt or escalates a matter unnecessarily. The opposite is true. In our experience, OFSI's enforcement engagement with firms that retained counsel early, filed a prompt and complete VSD, and cooperated fully is materially different from its engagement with firms that managed the matter internally until OFSI initiated contact. Early is almost always better than late.

Related practices

Frequently asked questions

What are the steps to set up escalation and reporting under OFSI?
Start with a written escalation procedure that names each tier of decision-maker, defines the trigger criteria, and sets a response window for each level. Map the procedure to the firm's anti-money-laundering path – separately but with defined handoff points. Appoint a named sanctions officer with clear authority. Train all relevant staff. Then test the procedure in a simulated alert exercise before relying on it in a live matter. Review and update the procedure at least annually, and whenever the relevant thematic regulations change.
What is the most common mistake in escalation and reporting procedures?
The single most common mistake is conflating the escalation path with an informal chain of conversation rather than a documented decision sequence. A second, closely related failure is treating the OFSI reporting obligation as discretionary – something to do if the breach is confirmed – rather than as an obligation that activates on reasonable suspicion. Firms that wait for certainty before reporting risk filing late, which OFSI treats as an aggravating factor. A third common error is failing to retain the contemporaneous records that justify the original alert disposition, leaving the firm unable to demonstrate its reasoning at a later date.
How does OFSI differ from other regimes here?
OFSI uses an "as soon as practicable" reporting standard rather than a fixed calendar deadline; OFAC's equivalent window is shorter and statute-defined. OFSI's penalty regime is based on the greater of a fixed maximum or a percentage of the breach value, which can produce large penalties relative to the transaction amount. The EU implements a prohibition at the EU level but enforces through national competent authorities, producing variations in deadline and format across member states. SECO, while closely aligned with the EU in many programmes, is a separate authority with its own reporting mechanics. A cross-border business must map all applicable regimes independently and manage them concurrently.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.