A compliance officer at a logistics group discovers, mid-audit, that a freight forwarder in its network has been routing shipments through an intermediary with apparent links to a designated party. The transaction touched three jurisdictions. Which regimes apply? Who investigates? What must the business report, and to whom, and by when? These are not hypothetical questions. They are the opening moves of a real internal sanctions investigation.
An internal sanctions investigation (a structured, privilege-protected inquiry conducted within a business to assess whether a potential sanctions violation has occurred and to quantify exposure) must, in a cross-border business, be run concurrently against every regime with a plausible jurisdictional hook. The United States, United Kingdom, and European Union each apply different legal tests, different reporting obligations, and different enforcement postures. A procedure designed for one regime alone will miss exposure under the others.
This guide walks through the procedure step by step, identifies where the regimes diverge materially, and flags the pitfalls that most commonly undermine an investigation before it can protect the business.
Step 1 – Triage: which regimes have a jurisdictional hook?
Before a single document is collected, the investigation team must establish which sanctions regimes are capable of applying to the facts in hand. The answer determines scope, privilege strategy, and – critically – whether any voluntary reporting obligation is engaged before the investigation concludes.
OFAC's jurisdiction extends to US persons, to persons located in the United States, and to transactions that touch the US financial system or US-origin goods or technology. That last limb is wide. A payment cleared in US dollars through a US correspondent bank can engage OFAC even if neither the buyer nor the seller is American. OFSI covers UK persons, UK-incorporated entities, and conduct in the United Kingdom. The EU regulations bind EU-established entities and transactions that transit the EU financial system.
In our experience, the most common triage failure is limiting the scope to the entity where the red flag appeared, rather than mapping every group entity, every correspondent-bank leg, and every goods origin. A shipment of goods manufactured in the United States carries BIS jurisdiction regardless of the shipper's nationality. Have you mapped the goods origin as well as the parties?
The jurisdictional map should be committed to a written scope document before the evidence phase begins. Scope creep mid-investigation is costly; scope restriction that later proves wrong is worse.
Step 2 – Preserving privilege: structuring the investigation correctly from day one
The question of legal professional privilege is not administrative housekeeping. It is, in a cross-border sanctions investigation, the decision that most often determines whether documents can be produced voluntarily to one regulator without triggering compelled disclosure to another.
Under English law and the laws of most EU member states, privilege attaches to communications made for the dominant purpose of obtaining legal advice. Under US law, the attorney–client privilege covers confidential communications between counsel and client; the work-product doctrine protects materials prepared in anticipation of litigation. The two regimes overlap but do not coincide, and documents created without appropriate structuring can fall into a gap between them.
Practical structuring points follow from this. Investigation reports should be commissioned by qualified lawyers in the relevant jurisdictions, addressed to counsel, and marked accordingly. Factual summaries prepared by compliance staff – without a directing legal instruction – may not attract privilege in all regimes. Witness memoranda are particularly at risk. In our cross-border practice, we regularly advise on structuring the investigative team so that the privilege wrapper is coherent across all relevant jurisdictions from the outset, rather than retrofitted after disclosure becomes an issue.
A further cross-border complication arises with EU in-house lawyers. Legal professional privilege under EU competition-related proceedings historically did not extend to in-house counsel. Sanctions enforcement by national authorities in EU member states follows domestic privilege rules, which vary. The investigation team must map privilege jurisdiction by jurisdiction.
Step 3 – Evidence collection across jurisdictions: what can you gather, and how?
Evidence collection in a cross-border sanctions investigation involves four distinct challenges: data-protection constraints, cross-border data-transfer rules, the risk of tipping off, and the integrity standards required by enforcement agencies if the investigation is later disclosed.
EU data-protection rules constrain the transfer of personal data – including employee communications – from EU entities to US counsel conducting the investigation. The regime governing such transfers has changed and continues to evolve; verify the current position before proceeding. UK rules operate on a parallel track post-Brexit. Transfer restrictions do not make evidence collection impossible, but they require a lawful transfer mechanism to be identified before data leaves the jurisdiction.
Tipping off is a distinct risk. Where a potential sanctions violation also engages an anti-money-laundering regime, a premature disclosure – even internally – can constitute a tipping-off offence under the applicable AML rules. The investigation team should include AML counsel if the facts engage financial flows, and information sharing inside the group should be managed carefully.
Evidence-integrity standards matter because enforcement agencies – OFAC, OFSI, and EU member-state authorities – assess the quality of an internal investigation when deciding how to treat a voluntary self-disclosure. An investigation that cannot demonstrate consistent chain-of-custody for documents, or that failed to interview key witnesses on a structured basis, carries less weight with regulators. That means a less favourable outcome on penalty, even where the underlying facts are disclosed fully.
Step 4 – The ownership and control analysis: where OFAC, OFSI, and EU diverge
One of the most consequential analytical steps in any internal sanctions investigation is determining whether a non-listed counterparty is nonetheless sanctioned because of its ownership by, or control by, a listed person. The three major regimes reach different answers from the same facts.
Under OFAC, the 50 percent rule (the rule that treats any entity owned 50 percent or more in the aggregate by one or more blocked persons as itself blocked) is the primary test. It is mechanical. A company owned 49 percent by a designated person is not itself blocked by that route alone, though other programme-specific rules may still apply. The rule aggregates holdings across multiple blocked persons.
Under OFSI and the EU, the test extends beyond ownership to ownership and control (the UK and EU test for whether a non-listed entity is caught through a listed person's ability to direct its affairs). Control can be established at ownership levels below 50 percent if a listed person can direct the entity's activities through contractual rights, board appointment rights, or other means. That is a materially wider test. An investigation that applies only the OFAC ownership threshold will miss UK and EU control exposure.
In practice, this means the investigation must produce a layered ownership-and-control map: first, the mechanical OFAC ownership analysis across the full chain; second, a UK/EU control analysis that looks at governance documents, shareholder agreements, board composition, and management agreements. We have acted for businesses that cleared the OFAC threshold comfortably but found OFSI exposure through a contractual right of direction that had never appeared in any screening database.
Step 5 – Voluntary self-disclosure: timing, content, and cross-regime interaction
Voluntary self-disclosure (VSD) – the act of proactively reporting an apparent violation to the relevant authority before that authority identifies it independently – is one of the most significant mitigation tools available to a business under investigation. It is also one of the most complex to deploy across multiple regimes simultaneously.
OFAC treats a timely, thorough VSD as a significant mitigating factor when calculating civil penalties. The size of that benefit depends on the quality of the disclosure: a comprehensive submission that identifies the root cause, quantifies the transactions, and demonstrates remediation measures receives substantially more credit than a bare notification. OFSI operates on a similar principle; its enforcement guidance treats co-operation and self-disclosure as factors that reduce the penalty calculation. EU member-state authorities follow domestic administrative-penalty frameworks, which differ across the bloc, but co-operation is consistently treated as a mitigant.
The cross-regime complication is sequencing. A VSD to OFAC that includes details of EU-leg transactions may trigger parallel enquiries from EU national authorities to whom OFAC's disclosure is visible or shared. A VSD to OFSI does not automatically notify OFAC. The decision about which authority to approach first – and in what terms – requires a regime-by-regime assessment of jurisdictional exposure, followed by a sequencing strategy. Acting without that strategy can preserve exposure in one regime while attempting to close it in another.
Timing matters acutely. OFSI's reporting obligation for a licence or general licence (a standing authorisation that permits a defined category of transactions without a separate application) breach can be short; verify the current statutory window under the applicable regulations before relying on any general statement. OFAC has no equivalent mandatory reporting deadline for civil matters, but its guidance on the weight given to a VSD is sensitive to whether the disclosure preceded the agency's own awareness. The investigation team must assess both at the outset.
The position above covers the standard case. Your facts – the counterparty, the goods, the route, the number of regimes engaged – change the analysis. For a confidential assessment of your exposure before you decide on disclosure, contact Calder & Vance at info@caldervance.com.
Step 6 – Remediation: what regulators expect, and how to demonstrate it
Remediation is not a post-investigation afterthought. Enforcement agencies treat the credibility and completeness of remediation as a central factor in their penalty assessment and in their decision whether to bring formal enforcement action at all.
OFAC's enforcement guidelines identify a number of remediation indicators that weigh in a company's favour: disciplinary action against responsible personnel, improvement of screening systems, enhanced due-diligence procedures for higher-risk counterparties, and mandatory training. OFSI's enforcement guidance reflects a similar set of expectations. The EU member-state authorities follow their own national frameworks but broadly align on the expectation that the business has addressed the root cause, not merely the symptoms.
Root-cause analysis is therefore the analytical centre of the remediation phase. If the violation occurred because a screening tool did not query against the UN Consolidated List, fixing only the OFAC query is insufficient. If the violation occurred because ownership data was not obtained for a key counterparty, the fix must address the due-diligence process for that category of counterparty across all jurisdictions.
Remediation documentation should be prepared as part of the investigation record and cross-referenced to the findings. Where a VSD has been made, the submitting party should be in a position to update the relevant authority on remediation steps completed and planned. A business that can demonstrate, at the time of VSD, that it has already implemented interim controls is materially better placed than one that remediation is still pending.
If a transaction has already been flagged, or a regulator has made a first contact, early review of the investigation and remediation record can preserve options that narrow with time. Write to info@caldervance.com for a confidential review.
Cross-regime divergence: where the pitfalls concentrate
The most significant procedural pitfalls in a cross-border internal sanctions investigation are not found in any single regime. They arise at the intersections between regimes – where an action that is appropriate under one set of rules creates risk under another.
The first pitfall is single-regime scoping. An investigation scoped only to the jurisdiction where the compliance team sits will routinely miss OFAC extraterritorial exposure if US-origin goods or a USD clearing leg is present, and will miss UK exposure if any group entity is UK-incorporated. We regularly advise businesses that have conducted a thorough internal review under one regime and then received an OFSI or OFAC inquiry covering the same facts.
The second pitfall is privilege misconstruction. Documents created during the investigation that do not attract privilege in all relevant jurisdictions become available to enforcement agencies in those jurisdictions. The business that produces documents voluntarily to OFAC may then face those same documents in an OFSI enforcement enquiry if they were not structured correctly from the outset.
The third pitfall is disclosure sequencing. A VSD to one authority without a sequencing plan for others can generate parallel investigations that were avoidable. Equally, delay in VSD while seeking to perfect the investigation record can move the disclosure from the beneficial "pre-awareness" window to a less favourable post-awareness position.
The fourth pitfall is the control-threshold gap between regimes. Businesses that apply only the OFAC 50 percent ownership test as their standard will systematically under-identify UK and EU exposure, particularly in markets where listed persons hold minority stakes with contractual control rights.
A common myth among businesses facing this situation is that a clean OFAC result means no enforcement exposure. It does not. OFSI and EU member-state authorities have independent enforcement remits, and conduct that falls below the OFAC mechanical threshold can still constitute a UK or EU violation if a control test is satisfied. The stricter prohibition governs the conduct in the jurisdiction that applies it.
Related practices
- EU Apparent Violation Assessment – assess EU-leg exposure and identify the applicable Council regulation obligations
- Internal Sanctions Investigation – EU Guide – step-by-step procedure under EU Council regulations and member-state enforcement
- Internal Sanctions Investigation – Japan Guide – the applicable country regime in Japan and how it interacts with the major Western regimes