A trading firm's compliance team flags an unusual payment pattern. A counterparty in a transaction processed six months ago shares a name and date of birth with an individual on the UK Consolidated List. The firm's senior management wants answers – and wants them before the Office of Financial Sanctions Implementation hears about it first. What do you do in the next 48 hours?
Running an internal sanctions investigation under OFSI (the Office of Financial Sanctions Implementation, the UK body that administers and enforces financial sanctions) is a structured legal process with reporting obligations, privilege considerations, and enforcement consequences that differ meaningfully from the equivalent exercise under OFAC or EU sanctions. Done well, a thorough internal investigation supports a voluntary disclosure that can materially affect OFSI's enforcement response. Done poorly, it destroys privilege, omits key documents, and limits the options that remain.
This guide walks through the procedure step by step, identifies the points where investigations most commonly go wrong, and explains how the OFSI regime compares with the US and EU approaches that cross-border businesses must manage in parallel.
Step 1: Scope the apparent violation before you investigate anything else
The first task is to define precisely what you are investigating – before any documents are pulled, any witnesses interviewed, or any external parties notified. As of March 2026, OFSI administers financial sanctions under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic regulations, and its enforcement guidance sets clear expectations about the depth of a firm's own inquiry. Starting without a defined scope is the single most reliable way to generate a sprawling, uncontrolled record that creates problems it was meant to solve.
Scope definition has three components. First, identify the transaction or series of transactions in question: the dates, the counterparties, the value, the currency, and the processing chain. Second, confirm which list or designation is potentially engaged – the UK Consolidated List, a UN Security Council list, or a thematic designation under a specific set of regulations. Third, map the individuals and entities whose conduct is relevant: the relationship manager, the payments team, the compliance officer who cleared the transaction, and any third-party correspondent or intermediary. This map shapes the document custodian list and determines who should not be interviewed first.
In our experience, businesses that skip this step and move straight to document collection frequently find that the scope expands mid-investigation, undermining the credibility of their eventual disclosure and forcing them to update OFSI more than once.
Step 2: Protect privilege from the outset – and understand its limits under OFSI
Legal professional privilege is available in an OFSI investigation, but its scope and robustness depend on decisions made in the first hours, not the final report. The key decision is whether external counsel is instructed at the start and whether that instruction is documented in a way that makes the dominant purpose of the investigation a legal one. A hybrid investigation – begun by compliance staff, later handed to lawyers – creates a mixed record that OFSI may treat as partially disclosable.
OFSI has powers to require information and documents from persons it believes hold information relevant to a suspected breach. This is different from OFAC's subpoena-equivalent mechanisms and the EU regime, where disclosure powers sit with national competent authorities and their procedures vary by member state. Under OFSI's regime, the obligation to provide information exists in parallel with the firm's internal investigation – they are not alternatives. That point surprises some clients who have dealt primarily with OFAC, where the voluntary self-disclosure process has a different procedural logic.
Establish the instruction letter to external counsel before any investigative interviews are conducted. Where in-house lawyers direct the investigation, document the legal-advisory purpose of each communication explicitly. These steps will not create privilege automatically – the substance must genuinely be legal advice, not factual reporting – but without them, privilege arguments become very difficult to sustain.
Does your firm have a protocol that distinguishes privileged investigation communications from compliance-team operational records? If not, the time to build one is before the next flag arrives.
Step 3: Document preservation and collection – the data map matters
Once scope is set and privilege is protected, the next stage is document preservation. Issue a legal hold immediately. Sanctions investigations involve payment records, screening logs, sanctions-list versions, approval-chain records, and communications across multiple systems – email, messaging platforms, trade-finance portals, and often third-party correspondent records held offshore.
The data map – a record of where relevant documents sit, in what format, and under whose custody – is the architecture of the investigation. OFSI's published enforcement guidance makes clear that a firm's ability to cooperate fully, including by producing a comprehensive record of what happened and when, is a factor in the enforcement outcome. An incomplete data map produces an incomplete record, and OFSI can draw adverse inferences from gaps that appear avoidable.
Several practical points deserve attention here. Screening logs – the system output at the time of the transaction – are frequently not preserved automatically and are overwritten by system updates. Recover and preserve the version of the sanctions list that was in use at the moment of screening, not the current version. Where counterparty information was sourced from a third party, obtain and preserve that third party's communication. And where data is held in a jurisdiction outside the UK, take early advice on data-transfer constraints; some jurisdictions impose blocking statutes or privacy rules that require a specific collection protocol.
For businesses operating across multiple regimes, the collection exercise almost always intersects with BIS or OFAC reporting requirements. We regularly advise on situations where the same transaction triggers a UK reporting question under OFSI's regime and a US voluntary self-disclosure question under the EAR. The document sets overlap but are not identical, and privilege over each is governed by different rules.
Step 4: Conducting interviews – sequence, records, and the privilege trap
Witness interviews are the most legally sensitive phase of an internal investigation, and they require a defined protocol. The sequence matters: begin with documentary review before interviewing individuals whose testimony may be shaped by what they believe the documents show. Interview witnesses in ascending order of exposure – administrative staff before relationship managers before senior approvers – so that the most significant witnesses are interviewed with the fullest picture of the factual record.
Each interview should be conducted by external counsel, with a note-taker present and a clear Upjohn-style warning (adapted for the UK context): the interviewer represents the firm, not the individual; anything said may be shared with regulators; the individual should seek personal legal advice if their own position may be affected. This warning is not a formality – it establishes the character of the interview, protects the firm's privilege, and is fair to the individual.
The interview record should be a contemporaneous note prepared by counsel, not a verbatim transcript or a witness statement signed by the interviewee. A signed statement creates a document whose status under OFSI information-gathering powers is ambiguous and which may be more easily required in any subsequent court or tribunal process. A counsel-prepared note, clearly marked as privileged legal advice, is more defensible.
In our cross-border practice, we see a recurring problem with investigations that are conducted partly in the UK and partly in another jurisdiction. The interview standards, privilege rules, and witness rights differ. An interview conducted in the United States by US counsel under an expectation of US work-product protection may not carry the same protection when OFSI reviews the UK entity's cooperation. Take separate advice in each relevant jurisdiction before the interview programme begins.
Step 5: Should you make a voluntary disclosure to OFSI – and when?
Whether to make a voluntary self-disclosure ("VSD") – a proactive report to OFSI of a potential breach before OFSI identifies it independently – is one of the most consequential decisions in a sanctions enforcement matter. OFSI's published enforcement guidance expressly recognises voluntary disclosure as a mitigating factor in its penalty assessment. Regulators generally look more favourably on firms that identify and report their own breaches than on those that wait for a regulatory inquiry.
The timing of a VSD is critical. A disclosure made before OFSI has any indication of the issue carries greater mitigation weight than one made after a tip-off or a suspicious-activity report has already reached the authority. This means the internal investigation must reach a view on the facts quickly enough to allow a timely disclosure. An investigation that runs for many months before a VSD is filed loses much of the mitigation benefit that speed would have secured.
Under OFSI's regime, a monetary penalty can be issued for a breach of a prohibition in the applicable financial-sanctions regulations. OFSI has a tiered enforcement approach – ranging from a warning letter or a case for civil monetary penalty, through to a referral to law-enforcement authorities for the most serious cases. The level of cooperation, including whether a VSD was made, the quality and speed of the firm's response to information requests, and whether remedial action was taken, all bear on the outcome. OFSI can also publish details of an enforcement case, which has reputational implications distinct from the financial penalty.
Compare this with OFAC's VSD process, where the agency has published guidance indicating that a timely, accurate, and complete VSD is treated as a significant mitigating factor and can lead to a substantial reduction in the base penalty amount. The EU regime is more fragmented: each member state's national competent authority applies its own enforcement norms, and VSD practices are not harmonised. For a business with operations across multiple regimes, this means that a disclosure strategy must be designed for each regime separately, and the sequencing of disclosures matters.
The position above covers the standard case. Your facts – the transaction, the counterparty, the goods or services involved, and which regimes are engaged – change the analysis significantly.
For an early assessment of your exposure under OFSI or a parallel regime, contact Calder & Vance at info@caldervance.com.
Step 6: Remediation and the investigation report
OFSI expects a firm that has identified a breach to take remedial action – not merely to describe what went wrong, but to fix it. The investigation report serves two audiences: the firm's own board and senior management, who need to understand the root cause and the remediation plan; and OFSI, if the report or a summary of it is shared as part of a VSD or in response to an information request.
A well-structured investigation report covers the factual record (what happened, when, and who was involved), the root cause analysis (why the screening or control failed), the legal analysis (what prohibition was potentially breached and under which instrument), and the remediation plan (what the firm has done and will do). The remediation plan should be specific and timed. Generic commitments to "improve controls" carry little weight. OFSI looks for evidence that the root cause has been addressed, not just acknowledged.
Remediation commonly includes recalibrating screening tools, retraining staff, revising the sanctions escalation protocol, and reviewing adjacent transactions that may have passed through the same control gap. In our practice, the review of adjacent transactions frequently surfaces additional potential issues – which then need to be evaluated for separate disclosure. Build that review into the plan from the start, rather than discovering it after the initial VSD has been filed.
If a transaction has already been flagged, or a filing has been refused, an early legal review can preserve options that narrow with time. Contact us at info@caldervance.com.
Cross-regime comparison: where OFSI, OFAC, and the EU diverge
Businesses with cross-border operations do not investigate a sanctions incident in a single-regime vacuum. The UK, US, and EU impose overlapping prohibitions, and a transaction that triggers an OFSI analysis will often raise questions under OFAC or an EU member state authority in the same breath. The regimes differ in ways that materially affect investigation design.
The ownership and control test (the legal test for whether a non-listed entity is caught through a listed person's ownership or control of it) illustrates the divergence. Under OFAC, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) is mechanical: aggregate the ownership of blocked persons; if it reaches 50 percent or more, the entity is blocked regardless of who manages it. Under OFSI and the corresponding EU test, the analysis extends to control – a listed person who directs, manages, or otherwise controls an entity can cause it to be caught even where ownership is below the threshold. This matters to an investigation because the factual inquiry required to establish the position differs. An OFSI investigation must map not just formal ownership but governance arrangements, voting rights, contractual control mechanisms, and management relationships.
Record-keeping obligations also differ by regime. Under OFSI's regime, firms are expected to retain records relevant to their compliance with financial-sanctions obligations. The applicable period should be confirmed against the current regulatory requirements, but in our experience the standard expectation across major regimes runs to five years or longer, and OFSI's enforcement guidance aligns with that broad standard. OFAC maintains a similar expectation. EU member state authorities vary. An investigation that needs to reconstruct events from three or four years ago may find that record-keeping practices were not uniform across the firm's jurisdictions – a common source of evidential gaps.
VSD norms also diverge. OFAC has published detailed guidance on what a voluntary self-disclosure should contain and the weight given to it. OFSI's guidance is less prescriptive on the format of a VSD but is clear that cooperation quality affects outcome. EU national authorities in some member states have well-developed VSD processes; in others, the concept is largely informal. A cross-border business making disclosures in multiple jurisdictions must manage the timing carefully: a disclosure to OFSI that refers to conduct also subject to an OFAC inquiry can affect the US investigation if the two authorities communicate, as they sometimes do.
Switzerland and Singapore operate their own financial-sanctions regimes. SECO (the State Secretariat for Economic Affairs) administers Swiss financial sanctions. The Monetary Authority of Singapore oversees Singapore's regime. Both have reporting expectations for financial institutions that suspect a breach, and both run enforcement programmes. A global investigation that ignores these regimes because the transaction was primarily UK-facing can leave the business exposed in a jurisdiction it had not considered.
Common pitfalls and risk flags
After the procedure, the failures. The pitfalls in OFSI internal investigations are mostly predictable, and most are avoidable with early legal involvement.
Starting the investigation without external counsel. In-house compliance teams are well placed to triage an issue. They are not well placed to conduct a legally privileged investigation, manage a potential VSD, and advise senior management simultaneously. The roles require different independence, and conflating them destroys the privilege that the investigation is designed to protect.
Interviewing key witnesses too early. Witnesses interviewed before the documentary record is understood frequently give accounts that the documents later contradict. That contradiction becomes a problem in any subsequent regulatory exchange. Interview sequence is not a procedural nicety – it is evidence management.
Failing to preserve the screening-list version. The sanctions list changes. The version in use at the time of the transaction is the relevant benchmark, not today's version. Many screening systems do not archive historical list versions automatically. Recover this data early; it may not be recoverable later.
Treating a breach as a single-regime event. A UK-facing transaction that involves a US-person correspondent, a US-dollar leg, or goods with an EAR classification triggers potential US jurisdiction regardless of where the primary operation sits. An investigation that looks only at OFSI misses the OFAC or BIS dimension, and that gap will be visible to any regulator who reviews the firm's response.
Disclosing too much, too quickly. Some firms, anxious to demonstrate good faith, share preliminary findings with OFSI before the investigation is complete. Preliminary findings that are later revised – as the evidence develops – create an impression of unreliability. A VSD should be made promptly, but its content should be accurate and complete, not preliminary.
Not reviewing adjacent transactions. The breach that prompted the investigation is rarely unique. A control gap that permitted one prohibited transaction usually permitted others. An investigation that closes without reviewing adjacent transactions gives regulators a reason to question the thoroughness of the firm's inquiry.
A common myth in this area is that a small or technically minor breach does not warrant a formal internal investigation or a VSD – that it is safer simply to correct the record and move on quietly. OFSI's enforcement posture does not support that view. The authority has made clear that the size of a transaction is not the primary determinant of whether enforcement action is appropriate; the adequacy of the firm's response matters independently. An undisclosed breach that later surfaces attracts the very scrutiny that the quiet approach was meant to avoid.
Related practices
- Apparent Violation Assessment – EU – evaluating potential EU sanctions breaches and structuring a disclosure strategy
- Internal Investigations under SECO – step-by-step guide for Swiss financial sanctions incidents
- Internal Investigations under Singapore's Regime – procedure and reporting obligations for MAS-supervised firms