A trading company based in Singapore discovers, mid-shipment, that a consignment destined for a partner entity may involve a person listed under Australia's Autonomous Sanctions regime. The goods have left port. The bank is asking questions. The compliance officer has forty-eight hours before the next payment is due. What does Australian law require, and where does the investigation begin?
Under Australia's Autonomous Sanctions regime, administered by the Department of Foreign Affairs and Trade (DFAT – the principal regulator for Australia's targeted financial sanctions and trade measures), a business that suspects a potential breach must act promptly: preserve evidence, assess exposure under the Autonomous Sanctions Act and its associated regulations, and consider whether disclosure to DFAT is warranted. There is no fixed statutory deadline for voluntary disclosure in Australian sanctions law as there is under some other regimes, but delay in identifying and addressing a breach is treated as an aggravating factor in any subsequent enforcement assessment.
This guide walks through each stage of an internal sanctions investigation under Australia's regime – from the initial trigger and scope-setting through to disclosure decisions, remediation, and the cross-border questions that arise when OFAC, OFSI, or another regime runs alongside DFAT.
Step 1 – Identifying the trigger and preserving the record
The investigation clock starts when a credible indicator of a potential sanctions breach first reaches a responsible person within the business – whether that is a screening alert, a counterparty inquiry, a bank query, or an internal tip. At that moment, the single most important action is evidence preservation.
Australia's Autonomous Sanctions regime imposes obligations on persons and entities subject to Australian law, including companies incorporated in Australia and persons ordinarily resident there, as well as entities conducting business in Australia. The Autonomous Sanctions Act establishes the primary offence framework; the sanctions regulations made under it implement designations against particular countries, individuals, and entities. DFAT maintains the Consolidated List (Australia's primary screening list, which incorporates both autonomous designations and UN Security Council listings).
Practical preservation steps at the trigger stage are straightforward but often overlooked under time pressure. Freeze communications: issue a document-hold notice to all custodians who touched the relevant transaction or counterparty. Capture system data: export screening logs, payment records, and contract files before routine purge cycles run. Note timestamps: the exact time a potential issue was first identified is material to any subsequent disclosure or enforcement assessment. In our experience, businesses that fail to act within the first twenty-four hours routinely lose electronic records that would have supported their case.
Have you confirmed which version of the Consolidated List was live at the time of the transaction? DFAT updates the list without a fixed notice period. Matching against the current list without verifying the historical position at the transaction date is a common and consequential error.
Step 2 – Scoping the investigation: what authority and what legal basis?
Scoping defines the legal questions the investigation must answer, the evidence it must gather, and the people who must be involved. Getting the scope wrong at the outset is one of the most reliable ways to extend the duration and cost of an investigation.
Under the Autonomous Sanctions regime, the core legal questions are threefold. First: was the counterparty, or any person in the ownership or control chain, a designated person or entity (an individual or body subject to a targeted financial sanction or travel ban under Australian regulations) at the time of the relevant act? Second: did the conduct involve a sanctioned supply (the provision, import, export, or brokering of goods or services that are the subject of an applicable trade sanction)? Third: was the entity subject to Australian jurisdiction at the time?
The ownership and control test under Australian law draws on the concept of a controlled entity – an entity owned or controlled by a designated person. The test is not purely mechanical in the way OFAC's 50 percent ownership rule operates; Australian law also asks whether effective control exists through other means, including directorship arrangements and contractual rights. In our cross-border practice, this distinction regularly produces different answers under Australian law and under OFAC, meaning a counterparty that is not blocked under OFAC may still be a controlled entity under the Australian regime, or vice versa.
The scope document should specify: the transaction or transactions in question, the relevant time window, the jurisdictions implicated, the designated-list universe to be searched, and the legal standard to be applied. Where a matter touches both DFAT and another regime – OFAC, OFSI, the EU Council regulations – the scoping document must record each regime separately, because their standards, defences, and disclosure routes diverge materially.
Step 3 – Gathering and reviewing the evidence
Evidence gathering in a sanctions investigation is not the same as general contract-dispute disclosure. The investigator is building a chronology of acts and knowledge, not simply collecting documents responsive to a list of categories.
Key evidence sources in an Australian sanctions investigation typically include: corporate registry records for counterparties (including beneficial-ownership filings where available in the relevant jurisdiction); screening logs and the version of the Consolidated List used at the time of the transaction; payment-instruction records showing the flow of funds and the identity of all parties; shipping documentation and export-control filings; internal communications showing what compliance staff knew and when; and any due-diligence reports prepared before the transaction was approved.
One practical point deserves emphasis. Australia participates in the UN Security Council sanctions system, and the UN Consolidated List is incorporated into Australian law through the Charter of the United Nations Act. A counterparty that appears only on the UN List – not on DFAT's autonomous designations – is still subject to sanction under Australian law. Investigators who search only the autonomous list without checking the UN dimension will produce an incomplete analysis.
Interview planning matters. The investigation team should speak with the transaction approvers, the compliance officer who ran or reviewed the screening, and any relationship manager with direct knowledge of the counterparty. Interviews should be conducted in a logical sequence: documents first, then the people who created them. Notes should be taken contemporaneously and preserved. In our experience, the quality of interview notes in sanctions matters often determines the credibility of the investigation report in any subsequent DFAT review.
Where the investigation crosses borders, privilege considerations become complex. Legal professional privilege applies under Australian law, but its scope and the rules for waiver differ from the position under English law, US attorney-client privilege, or the EU legal professional privilege doctrine. If the investigation may need to feed into a parallel OFAC or OFSI process, structure legal advice carefully from the outset to preserve protection in each relevant jurisdiction.
What cross-border obligations run alongside the Australian investigation?
A business with operations or counterparties in multiple jurisdictions will almost always face obligations under more than one regime simultaneously. The Australian investigation cannot be treated in isolation.
The United States regime administered by OFAC is the most frequently encountered parallel obligation. OFAC's reach extends to any transaction that touches the US financial system, any US-incorporated entity, and any US person wherever located. If the transaction involved a US-dollar payment, cleared through a US correspondent bank, or involved a US-affiliated entity, OFAC's jurisdiction is likely engaged. OFAC's voluntary self-disclosure (VSD – a proactive disclosure to OFAC describing an apparent violation, which can reduce a civil penalty) operates under its own framework and timeline, which does not align with DFAT's. Submitting a VSD to OFAC without addressing the Australian dimension, or vice versa, can create inconsistencies that each regulator notices.
The UK's OFSI operates a separate enforcement and licensing regime under the Sanctions and Anti-Money Laundering Act (SAMLA). OFSI's reporting obligation – under which a person who knows or suspects they hold frozen funds belonging to a designated person must report to OFSI – carries its own trigger. That obligation does not wait for an internal investigation to conclude. If UK-connected assets or counterparties are in scope, the OFSI reporting question must be assessed in parallel, not after the Australian analysis is complete.
EU Council regulations apply to EU-incorporated entities and to transactions conducted within the EU, regardless of the nationality of the parties. The EU regime uses an ownership-and-control test under which a non-listed entity is caught if a designated person holds more than 50 percent of it or otherwise controls it. Where the investigated counterparty has EU operations or EU shareholders, the EU analysis is necessary.
We regularly advise businesses running internal investigations that produce exposure in three or more regimes simultaneously. The sequencing question – which regulator to approach first, and whether disclosures can be co-ordinated – is one of the most consequential judgment calls in a multi-regime investigation. There is no universally correct answer; it depends on where enforcement risk is greatest, where the reporting obligation is most prescriptive, and what the business's ongoing commercial objectives require.
Step 4 – Risk-flagging: what makes an Australian sanctions matter more serious?
Not every apparent breach carries the same enforcement risk. Australian sanctions law provides for both civil and criminal penalties, and DFAT's enforcement posture has become more active in recent years. Identifying the aggravating and mitigating factors early shapes every subsequent decision in the investigation.
Factors that increase enforcement risk under the Australian regime include: the transaction involved a listed person or entity directly rather than through a chain of ownership; the business continued to transact after an internal alert was generated and not resolved; the compliance programme had no Australian Consolidated List screening at the time; senior management was aware of a concern and did not act on it; the conduct was repeated across multiple transactions; and the business failed to report once it had identified a clear breach. Each of these factors features in DFAT's published guidance on its enforcement approach.
Factors that reduce enforcement risk, and that an investigation report should document carefully, include: a compliance programme that was appropriate for the business's risk profile; the fact that the breach was self-identified rather than identified by a third party or regulator; prompt corrective action; a history of constructive engagement with DFAT; and the absence of any nexus to a deliberate attempt to circumvent the regime. The investigation report is the primary vehicle for presenting these factors. A report that merely concludes a breach occurred, without addressing these dimensions, misses its purpose.
One specific risk flag warrants separate attention: brokering. Australian sanctions regulations on the brokering of goods can extend to persons who arrange transactions between two non-Australian parties. If the investigation involves an individual or entity that brokered a transaction without being a direct party to the underlying contract, the brokering provisions require separate analysis. They are frequently overlooked in initial scope assessments.
Step 5 – Preparing the investigation report and the disclosure decision
The investigation report is not simply a record of findings. It is the foundation of any disclosure to DFAT, any internal escalation to the board, and any subsequent enforcement defence. Its structure and content should be planned before evidence gathering begins, not assembled at the end.
A well-constructed investigation report for an Australian sanctions matter should contain: an executive summary stating the principal findings and conclusions; a statement of the legal framework and the tests applied; a chronology of the relevant conduct; an analysis of whether the conduct constitutes a breach of the Autonomous Sanctions Act or the relevant regulations; an assessment of the mitigating and aggravating factors; a section addressing any parallel-regime obligations identified; and a recommendations section covering disclosure, remediation, and programme changes.
The disclosure decision turns on several factors. Where the investigation concludes that a breach has occurred, the question is whether to disclose proactively to DFAT, and in what form. Australia does not have a statutory VSD regime for sanctions breaches that is as formally developed as OFAC's equivalent, but DFAT's published guidance makes clear that voluntary disclosure is treated favourably in its enforcement process. Timing matters: disclosure made promptly after a breach is identified is more valuable than disclosure made after DFAT has received information from another source.
Where the investigation concludes that no breach occurred but that the transaction was at the margin of the regime, documenting that conclusion carefully – including the legal reasoning and the evidence relied on – is equally important. DFAT may subsequently receive information about the same counterparty from another government or financial institution. A business with a contemporaneous, well-documented analysis is in a materially better position than one that merely assumed the position was clear.
The position above covers the standard structure. Your specific facts – the counterparty structure, the goods involved, the jurisdictions of the parties, and the precise timing of the breach – change the analysis materially. For a confidential review of a potential breach, contact Calder & Vance at info@caldervance.com.
Common mistakes in internal sanctions investigations under Australia
Many investigations that begin well lose their effectiveness at predictable points. Knowing where the failure modes cluster is itself a practical risk-mitigation tool.
The most common error we encounter is a mismatch between the scope of the investigation and the actual legal question. A business will commission an investigation into a specific counterparty when the legal question is whether a class of transactions with a class of connected entities constituted a systematic breach. Solving the narrow question while the broader one remains unaddressed exposes the business to a second investigation and, potentially, to the suggestion that it chose a narrow scope deliberately.
A second recurring mistake is failing to address the UN dimension. As noted above, the UN Consolidated List is independently incorporated into Australian law. An investigation that finds no match on the DFAT autonomous list and closes on that basis, without checking the UN List position, is factually incomplete.
A third common error is allowing the investigation to run without clear terms of reference agreed at the outset. In our experience, investigations without a written scope statement routinely expand in ways that consume time and legal costs disproportionate to the risk, or conversely, are closed prematurely because no one has agreed what "completion" looks like.
A common myth is that a business domiciled outside Australia has no Australian sanctions exposure simply because it has no Australian staff or operations. That reading is too narrow. Australian sanctions law can apply to transactions processed through Australian financial institutions, to goods transshipped through Australian ports, and to companies with Australian shareholders conducting transactions with designated persons. The jurisdictional reach of the Australian regime is not limited to entities incorporated in Australia, and assuming otherwise is a significant compliance risk for businesses operating in the Asia-Pacific region.
When should you involve external sanctions counsel?
An internal investigation in a lower-risk matter – a single screening alert that can be resolved against contemporaneous records without jurisdictional complexity – may be managed by an experienced in-house compliance team. But several indicators suggest that external sanctions counsel should be involved from the outset.
The first indicator is multi-regime exposure. As discussed above, a transaction with potential DFAT, OFAC, and OFSI dimensions simultaneously requires co-ordinated legal analysis across three enforcement frameworks. An in-house team proficient in one regime is not positioned to manage that co-ordination without external support.
The second is senior-management or board involvement in the relevant conduct. Where the investigation may conclude that a decision-maker at the level of director or senior executive was aware of a concern and did not act, the investigation itself has governance implications that require independent oversight.
The third is a parallel criminal risk. Australian sanctions offences carry criminal penalties, and where the conduct may involve intentional breach or conspiracy to breach, the investigation must be structured to protect the business's legal position. That structuring requires legal advice from the first day of the investigation, not after the facts have been gathered.
The fourth is an imminent regulatory or enforcement action. If DFAT has already made contact, or if a financial institution has frozen an account pending a sanctions review, the investigation is no longer simply an internal matter. External counsel can manage the regulator relationship, assess the enforcement options, and advise on the disclosure decision under time pressure.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. To discuss an investigation or a potential disclosure to DFAT, write to Calder & Vance at info@caldervance.com.
Related practices
- Apparent Violation Assessment – EU – assessing EU sanctions breaches and structuring disclosure to EU member-state authorities
- Internal Investigation Guide – BIS / EAR – running an internal investigation under US export controls and BIS enforcement rules
- Internal Investigation Guide – Canada – managing sanctions investigations under Canadian law and GAC enforcement