Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · Australia

Penalty defence and settlement under Australia: step by step

A freight forwarder based in Sydney receives a written notice from the Department of Foreign Affairs and Trade. A shipment it handled six months ago appears to have reached a destination or end-user contrary to Australia's autonomous sanctions rules. The question is immediate: what does the company do next, and in what order?

Penalty defence under Australia's autonomous sanctions regime is a structured process governed by the Autonomous Sanctions Act and administered by DFAT, with criminal enforcement referred to the Australian Federal Police and, ultimately, the Commonwealth Director of Public Prosecutions. The regime carries significant criminal and civil exposure. Acting early – scoping the apparent violation, preserving records, and engaging counsel before a formal investigation gains momentum – materially affects the options available.

This guide sets out each step in the defence and settlement process, explains where the Australian approach diverges from comparable regimes, and identifies the risk flags that most commonly complicate matters for cross-border businesses.

Step 1: Understand the governing regime and DFAT's authority

Australia's autonomous sanctions regime is established by the Autonomous Sanctions Act and the regulations made under it, together with any applicable United Nations-derived obligations implemented through the Charter of the United Nations Act. DFAT administers the sanctions programme, maintains the Consolidated List of designated persons and entities, and is the primary regulator for licensing and compliance. Enforcement of criminal sanctions breaches is, however, a law-enforcement function: DFAT refers suspected offences to the Australian Federal Police, and prosecutions proceed through the Commonwealth criminal justice system.

That division of authority matters immediately. A business that discovers a potential breach is dealing, at minimum, with two possible trajectories: an administrative or civil matter managed through DFAT, or a criminal referral. The distinction turns on the nature and seriousness of the conduct, the apparent intention of those involved, and the quality of the company's compliance posture at the time. Understanding which trajectory is more likely – and acting to influence that assessment – is the first practical task for counsel.

Australia's sanctions programme covers designated persons and entities, country-based restrictions (applied through regulations specifying the applicable country regime), and thematic measures aligned with UN Security Council resolutions. As of early 2026, the regime continues to expand its designated-person list and to add new thematic measures. Practitioners should verify the current list position before advising on any specific counterparty.

Step 2: Scope the apparent violation before anything else

Before any submission is made to DFAT or any other authority, a business must understand exactly what occurred. Scoping the apparent violation means identifying the transaction or conduct, the legal provision that may have been breached, the persons involved, and the documentary record – in full, and before positions are taken externally.

In our experience, the most consequential decisions in a sanctions enforcement matter are made in the first seventy-two hours. Statements made informally to a regulator, records that are altered or not preserved, or a compliance response assembled without legal input can close off routes that would otherwise remain open. The discipline here is simple: secure the records, restrict internal communications about the matter to those who need to know, and obtain legal advice before responding to any regulator.

Scoping has a defined structure. Counsel will typically need to establish:

  • The identity of the counterparty or end-user and whether they appear on the DFAT Consolidated List or a UN-derived list at the relevant time.
  • Whether the goods, services, or funds involved fall within a prohibited category under the applicable regulations.
  • Whether any exemption or permit applied – or whether one could have applied if sought.
  • The role of each business unit and individual in the transaction, and their state of knowledge.
  • The internal compliance controls in place and whether they were followed.

This scoping exercise produces two outputs: a factual record of what happened, and a preliminary legal assessment of whether a violation occurred and, if so, of what kind. Both are privileged work product when conducted under legal professional privilege and should be treated accordingly from the outset.

Step 3: Assess disclosure – when and how to approach DFAT

Australia does not operate a formal voluntary self-disclosure programme equivalent to the structured VSD (voluntary self-disclosure to a regulator) process that OFAC administers in the United States or that BIS maintains for export-control matters. That does not mean proactive disclosure is irrelevant. DFAT has published guidance indicating that cooperation, self-reporting, and remediation are factors it considers when assessing the appropriate regulatory response to an apparent breach. A business that comes forward, explains the matter clearly, and demonstrates that it has addressed the root cause is in a materially different position from one that is discovered.

The practical question for counsel and client is therefore: given what the scoping exercise has revealed, is proactive disclosure appropriate here, and if so, on what terms? There is no single answer. Relevant considerations include the seriousness of the conduct, whether DFAT is likely to become aware through other channels, the involvement of third-country regulators (a point addressed below), and the company's wider compliance record. A disclosure made without adequate preparation – incomplete facts, no remediation plan, no legal framing – can do more harm than good.

Where disclosure is the right route, counsel will prepare a written submission to DFAT that sets out the facts, the legal analysis, the corrective steps already taken, and the proposed resolution. The submission is drafted to reduce the risk of criminal referral and to frame the matter as one suited to administrative resolution.

The position above covers the standard case. Your facts – the counterparty, the goods, the route, the regime in play – change the analysis significantly.

For an assessment of your exposure under Australia's autonomous sanctions regime, contact Calder & Vance at info@caldervance.com.

Step 4: Manage the cross-border dimension – OFAC, OFSI, and third-country exposure

A sanctions enforcement matter in Australia rarely stays within Australia's borders. Cross-border businesses face the real possibility that the same transaction, the same counterparty, or the same goods attract scrutiny from more than one regulator simultaneously. Managing that multi-regime exposure is a core part of the defence strategy.

Consider the typical scenario for an Australian exporter with US-origin goods or US-dollar payment flows. The transaction may engage both Australia's autonomous sanctions regime and the US Export Administration Regulations administered by BIS, or OFAC's economic sanctions. Where US-origin goods are involved, US export-control rules can apply extraterritorially regardless of the nationality of the exporter. A shipment that constitutes an apparent violation in Australia may also constitute an apparent violation under the EAR – and the two regulatory processes will not wait for each other.

The UK regime administered by OFSI operates similarly. A business with UK operations, UK-incorporated entities in its group, or transactions cleared through UK financial institutions may face parallel OFSI scrutiny for conduct that originates in an Australian-nexus transaction. OFSI and OFAC apply different ownership-and-control tests: OFAC's 50 percent rule (treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked) is mechanical; OFSI and the EU apply a broader ownership and control test that can catch entities where a designated person exercises effective control even without a majority ownership stake. A counterparty that passes the OFAC threshold analysis may still be caught under OFSI's control test – and vice versa.

The EU presents a further dimension for Australian businesses with European operations or European counterparties. EU Council regulations are directly applicable in member states and can capture a transaction that has any EU-nexus, including goods transiting through EU ports, payments cleared through EU financial institutions, or services provided by EU-established entities.

In our cross-border practice, we regularly advise clients to map every regulatory jurisdiction that could conceivably reach the transaction before committing to a disclosure or defence strategy in any single one. A voluntary submission to DFAT that contains concessions inconsistent with the US or EU legal position can create difficulties in parallel proceedings that are far harder to resolve than the original Australian matter.

Step 5: Engage with the investigation – procedural steps and risk flags

If DFAT initiates a formal inquiry or the matter is referred to the Australian Federal Police, the procedural posture changes. A business under investigation has rights – and obligations – that differ from those of a business that has voluntarily come forward. The investigation phase typically involves requests for documents, requests for written responses to specific questions, and potentially interviews with relevant individuals.

Key procedural risk flags at this stage include:

  • Document preservation: A failure to preserve relevant records once an inquiry is foreseeable can itself become an issue. Implementing a legal-hold protocol early is a basic precaution that is often overlooked.
  • Inconsistent internal accounts: Where different employees have given different versions of events in internal communications – written before legal advice was sought – those inconsistencies will be visible to investigators. Counsel needs to understand the full picture before investigators do.
  • Third-party involvement: Intermediaries, freight forwarders, logistics agents, and financial institutions involved in the transaction may themselves receive regulatory requests. Their responses may not align with the company's position, particularly if they have their own interests to protect.
  • Ongoing business: A business that continues to deal with the same counterparty or conduct similar transactions after discovering an apparent violation faces a significantly more serious position. One of the first practical steps counsel takes is confirming that the activity in question has stopped.

If a transaction has already been flagged, or a regulatory inquiry has begun, an early review can preserve options that narrow with time. Reach Calder & Vance at info@caldervance.com for a confidential assessment.

Step 6: Build the penalty defence and mitigation case

Whether the matter proceeds toward criminal prosecution, civil penalty proceedings, or a regulatory resolution with DFAT, the substantive defence and mitigation case must be assembled with care. Australia's sanctions regime does not publish a structured penalty matrix of the kind that OFAC uses to calculate a base civil monetary penalty, but the factors that influence the outcome are consistent with those applied across comparable regimes.

Mitigating factors that recur in regulatory and enforcement contexts include:

  • The existence and quality of the compliance programme at the time of the violation – was there a genuine programme, was it tested, and was it followed?
  • Proactive disclosure and cooperation with the regulator.
  • Prompt remediation – stopping the activity, addressing the root cause, and strengthening controls.
  • The absence of prior violations or a strong prior compliance record.
  • The role of the business in the transaction: was it the primary actor, or a peripheral party that relied on representations from others?

Aggravating factors typically include wilful or reckless conduct, attempts to conceal the breach, a pattern of prior violations, senior management involvement, and the involvement of particularly sensitive goods or destinations.

The defence narrative must be constructed around the facts as they actually are, not as the company would prefer them to be. A well-prepared mitigation submission presents the facts honestly, contextualises them within the compliance programme that existed, and demonstrates the steps taken since. It does not minimise conduct that will be evident from the documentary record. In our experience, regulators across all major regimes respond better to honest self-assessment than to submissions that appear to minimise or deflect.

Step 7: Resolution – from settlement to prosecution and beyond

The resolution of a sanctions enforcement matter in Australia can take several forms. At one end, DFAT may conclude that no breach occurred, or that the matter does not warrant formal action. In the middle are regulatory resolutions that involve undertakings, compliance commitments, or administrative measures. At the other end, a criminal prosecution can result in significant financial penalties and, for individuals, terms of imprisonment.

Settlement in the sense used in OFAC enforcement – a negotiated agreed penalty – is not a formal mechanism under Australia's statutory scheme in the same way. Resolution is more likely to take the form of cooperation with DFAT leading to a decision not to refer, or engagement with the Commonwealth Director of Public Prosecutions at an early stage to narrow the scope of any prosecution or agree to a resolution that reflects cooperation and remediation. The precise form of resolution available depends on the severity of the conduct, the strength of the evidence, and the quality of the cooperation offered.

For businesses concerned about the interaction between an Australian resolution and proceedings in other jurisdictions, it is important to note that a settlement or resolution in Australia does not extinguish liability under US, UK, or EU regimes. Each regime operates independently. A business that settles with DFAT must still consider whether OFAC, BIS, or OFSI has its own interest in the same conduct – and that assessment should be part of the resolution strategy from the beginning, not an afterthought.

A common objection: "Our compliance programme was reasonable – surely that is a complete defence?"

The assumption many businesses bring to this process is that a reasonable compliance programme, conscientiously operated, insulates the company from liability if a violation occurs despite it. That is not correct under any of the major sanctions regimes, and it is not correct under Australia's autonomous sanctions rules. A compliance programme is a mitigating factor, not a safe harbour. It reduces exposure; it does not eliminate it.

We regularly advise businesses that have discovered a breach and that believe their compliance programme was adequate. In most cases, the investigation reveals at least one point at which the programme could have caught the issue but did not – whether through a gap in ownership screening, a failure to check the DFAT Consolidated List at the right point in the transaction cycle, or a reliance on counterparty representations without independent verification. Identifying those gaps early, and addressing them before the regulator does, is consistently one of the most effective steps a business can take in the defence and mitigation process.

Related practices

Frequently asked questions

What are the steps to defend a penalty case under Australia?
The process begins with understanding DFAT's authority and the applicable statutory regime, then scoping the apparent violation under legal professional privilege before any external communication. The next steps are assessing whether proactive disclosure is appropriate, managing parallel exposure under other regimes such as OFAC or OFSI, and building a documented mitigation case around compliance quality, cooperation, and remediation. Resolution depends on the severity of the conduct and the quality of the engagement with regulators.
What is the most common mistake in penalty defence and settlement?
The most common mistake is making external statements – to DFAT, to counterparties, or in internal communications that are not properly privileged – before a complete factual scope of the matter has been conducted under legal advice. Premature positions, inconsistent accounts, and a failure to preserve records are the factors that most consistently convert a manageable regulatory matter into a serious enforcement problem. Acting without counsel in the first seventy-two hours is the version of this mistake we see most often.
How does Australia differ from other regimes here?
Australia's autonomous sanctions regime does not publish a formal voluntary self-disclosure programme with the same structured process or penalty-reduction guidelines as OFAC's VSD mechanism. Criminal enforcement is handled through the Australian Federal Police and the Commonwealth Director of Public Prosecutions rather than through a dedicated financial-sanctions enforcement agency. Ownership-and-control analysis under Australia's rules differs from OFAC's mechanical 50 percent rule and from the broader EU and UK control tests – a counterparty analysis must be run under the specific Australian rules rather than imported from another regime.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.