An EU authority opens an enforcement file. The notice arrives on a Friday afternoon. The compliance team has questions it cannot answer quickly: which member state has jurisdiction, what the exposure is, and whether a cooperative response will genuinely reduce the penalty. These are the moments when the difference between a well-managed enforcement response and a damaging admission is decided.
Penalty defence and settlement under the EU sanctions regime is governed primarily by national competent authorities acting within the mandatory minimum standards set by Council regulations and, increasingly, by the EU Sanctions Directive. Enforcement is decentralised: each member state designates its own authority, sets its own penalty scale within the EU-level floor, and runs its own procedure. That decentralisation makes cross-border co-ordination – and early legal assessment – essential.
This guide walks through the defence process step by step, from the moment an apparent violation is identified through to resolution, and maps the key points where the EU approach diverges from OFAC and OFSI practice.
Step 1 – Identify and preserve: what to do in the first 72 hours
The first obligation when a potential EU sanctions violation surfaces is to stop, document, and preserve. Do not delete communications, reverse transactions, or amend records before taking legal advice. The preservation of contemporaneous evidence – emails, screening outputs, payment instructions, ownership-chain analyses – shapes every subsequent stage of the defence.
In our experience, businesses lose significant ground in the first 72 hours by confusing an internal incident review with a formal enforcement response. They are different exercises. The internal review is privileged and attorney-led. Any communication that falls outside privilege and reaches a regulator – even informally – can become part of the record. Treat the two tracks separately from the outset.
At the same time, map the jurisdictional question. EU sanctions enforcement is conducted by national competent authorities, not by a single central body. The authority with jurisdiction is typically determined by where the relevant transaction was processed, where the regulated entity is established, or where the relevant asset is held. A cross-border transaction touching multiple member states can, in principle, attract the attention of more than one authority. Identify which state – or states – may claim jurisdiction before any voluntary disclosure decision is taken.
Step 2 – Assess the apparent violation: scope, severity, and the cross-regime picture
A structured apparent-violation assessment determines whether the conduct constitutes a violation at all and, if so, where it sits on the severity spectrum that drives penalty quantum. Under the EU regime, relevant factors include whether the breach was deliberate, negligent, or caused by a systemic failure; whether it was self-reported; and whether it produced a financial benefit for a designated person.
The assessment must also consider what the applicable Council regulation actually prohibits. EU sanctions prohibitions vary by regime and by thematic regulation. The scope of the asset freeze, the definition of "funds and economic resources", and the carve-outs for humanitarian transactions or contractual obligations are defined within each instrument. Analyse the specific prohibition before drawing conclusions about breach.
For businesses operating across jurisdictions, the scope of the EU analysis does not end at the EU border. The same underlying conduct may engage OFAC, OFSI, or a third-country regime simultaneously. In our cross-border practice, we regularly advise on situations where an EU entity is the primary respondent before a national authority, while its US affiliate faces a separate inquiry from OFAC for the same transaction. The two processes do not co-ordinate automatically, and an admission made in one jurisdiction can complicate the posture adopted in another. Run the multi-regime review before making any submission.
A practical assessment produces four outputs: a characterisation of the conduct (deliberate / negligent / inadvertent), a penalty-range estimate, a map of the authorities likely to have jurisdiction, and a recommendation on voluntary disclosure.
For detailed guidance on structuring the apparent-violation assessment, see our EU apparent-violation assessment service page.
Step 3 – The voluntary disclosure decision: how EU practice compares with OFAC and OFSI
Voluntary self-disclosure – VSD (proactively reporting a potential violation to the relevant authority before it becomes aware through other means) – operates differently across the major regimes, and understanding those differences shapes the disclosure strategy for a cross-border group.
Under OFAC, a VSD is a formal, structured submission that triggers a specific procedural track and is codified as a mitigating factor that can reduce the base civil monetary penalty significantly. The mechanism is well-defined. Under OFSI, the duty to report is statutory, and the timing of self-reporting is considered in the exercise of enforcement discretion, including the decision whether to publish details of a penalty.
The EU position is more variable. The EU Sanctions Directive, adopted in 2024, establishes minimum standards for criminal and administrative sanctions across member states. It requires member states to treat cooperation with authorities and voluntary disclosure as mitigating factors. But the procedural mechanics – how a disclosure is submitted, to whom, within what window, and with what evidential support – remain matters of national law. There is no single EU-level VSD form. In a state with a short notification window, failing to disclose promptly can itself constitute an aggravating circumstance.
This divergence has a practical consequence. A group-level decision to "co-operate" with EU authorities cannot be taken as a uniform instruction. The instruction must be translated into jurisdiction-specific submissions, each framed against the procedural rules of the relevant national authority. We have acted for groups where a disclosure made in one member state – correctly timed and well-framed – contrasted sharply with an equivalent disclosure in a second state that arrived too late to attract full mitigation credit.
For comparison with the US voluntary-disclosure process, our OFAC penalty defence and settlement guide sets out the OFAC-specific steps and mitigating-factor analysis.
What factors does an EU authority consider when setting the penalty?
EU national authorities setting penalties apply a mix of factors derived from the applicable Council regulation, transposed national law, and the standards now required by the EU Sanctions Directive. The core factors are broadly consistent across member states, even where the procedural rules differ.
Aggravating factors typically include: deliberate intent; prior violations by the same entity; the duration of the breach; the value or volume of the prohibited transaction; and concealment of the breach. Mitigating factors include: voluntary and timely disclosure; no prior enforcement history; prompt remediation; cooperation with the investigation; and the existence of a bona fide compliance programme at the time of the breach.
The compliance-programme question deserves particular attention. A well-documented compliance programme does not guarantee a penalty reduction, but the absence of any programme – or a programme that visibly failed to address the relevant risk – is regularly treated as an aggravating circumstance. In our experience, the authorities most likely to take a severe view of a breach are those where the respondent cannot point to any prior screening, ownership-chain analysis, or red-flag review.
One structural difference from OFAC practice is worth noting. OFAC publishes detailed penalty guidance setting out base penalty amounts and the mitigating multipliers applied to them. EU national authorities generally have broader discretion and do not always publish the same level of quantitative detail about their penalty methodology. This means that the penalty-range estimate in an EU matter carries wider uncertainty than an equivalent estimate under OFAC. Plan accordingly.
Step 4 – Preparing the defence submission: structure and evidence
Once the voluntary-disclosure decision is taken and the jurisdictional map is settled, the formal defence submission requires careful assembly. The submission has several components: a factual narrative, a legal analysis, a remediation statement, and – where the mitigating-factors case is strong – a compliance-improvement plan.
The factual narrative must be accurate, complete, and privilege-protected in its drafting. It should describe the transaction or conduct in sufficient detail to allow the authority to assess the violation, without volunteering information that expands the scope of the inquiry beyond what the authority already knows. The line between transparent cooperation and inadvertent over-disclosure is narrow.
The legal analysis addresses whether the conduct constitutes a breach under the applicable Council regulation, whether any general derogation or licence applied, and whether the ownership and control test (the EU test for whether a non-listed entity is caught through a listed person's ownership or control) was correctly applied to counterparty relationships. Errors in the ownership-and-control analysis are among the most frequent sources of both violations and of over-reporting; getting the analysis right in the submission prevents the authority from treating a non-violation as a confirmed breach.
The remediation statement demonstrates that the business has taken concrete steps to prevent recurrence. A credible remediation statement is not a list of intentions. It describes measures already implemented: screening enhancements, ownership-chain review protocols, additional training, or revised onboarding procedures. Authorities respond to evidence of completed action, not to promises.
Step 5 – Settlement discussions and resolution
Not all EU enforcement matters proceed to a formal penalty decision. National authorities in a number of member states have the power to close a matter through a settlement or an administrative agreement – in effect, a negotiated resolution that acknowledges the breach, specifies remediation, and sets a reduced penalty in exchange for cooperation and a waiver of further challenge. The availability and mechanics of settlement vary by member state.
Where settlement is available, the decision to settle involves a careful cost-benefit analysis. Settlement avoids the cost and uncertainty of a contested procedure. It also avoids the risk that a contested decision – if lost on appeal – produces a published finding that is more damaging to the business than the original penalty. Against that, settlement involves an acknowledgment of breach, which can have consequences in related proceedings in other jurisdictions. That risk is particularly acute where OFAC or OFSI is conducting a parallel review of the same conduct.
The appeal route in EU enforcement matters runs through the national administrative or judicial review system of the relevant member state. Where the underlying listing decision itself is disputed – as distinct from the penalty for breach of the freeze – the respondent may also consider an annulment action before the EU General Court. These are different proceedings with different standards and timelines; they should not be confused in planning the response strategy.
For an illustration of how enforcement defence and settlement differ across the Asia-Pacific region, our Japan penalty defence and settlement guide provides a comparable step-by-step analysis under a different jurisdictional model.
Risk flags and when to involve counsel
Certain features of a matter signal that the enforcement risk is higher than the initial facts suggest. Recognise them early.
- Multi-jurisdictional exposure: any transaction that touches an entity in the United States, the United Kingdom, or a third country with its own sanctions regime simultaneously engages multiple enforcement authorities. A matter that looks like a contained EU issue may carry secondary-sanctions exposure or OFSI reporting obligations.
- Ownership-chain uncertainty: if the ownership or control of a counterparty was not fully mapped before the transaction, the ownership and control test may produce a different result on proper analysis. Assumptions made at the transaction stage should not be adopted uncritically in the enforcement response.
- Systemic failure: a breach that reflects a gap in the compliance programme – rather than an isolated human error – is treated more seriously by authorities and requires a more substantive remediation narrative.
- Notification deadlines: some member states impose short statutory windows for reporting potential violations. Missing a notification deadline converts an inadvertent breach into a compound problem. If a violation is suspected, identify the applicable notification rules immediately.
- Group-level co-ordination failures: where different entities in a corporate group have given inconsistent accounts to different authorities – even inadvertently – the credibility of the voluntary-disclosure narrative is undermined. Establish a single point of legal co-ordination across the group from day one.
Involve counsel as early as possible. The AUDIENCE_MYTH in EU enforcement is that a business with a strong underlying compliance programme can manage the response internally. That assumption misunderstands the process. The compliance programme is evidence; the enforcement response is advocacy. The two require different skills and, critically, the enforcement response must be coordinated with legal privilege from the outset. An internal investigation conducted without privilege protection – and then shared with an authority – can waive confidentiality over the wider investigation file.
If a transaction has already been flagged by an authority, or an internal review has uncovered a potential breach, an early legal assessment preserves options that narrow as the process continues. For a confidential review of a potential breach under the EU regime, contact Calder & Vance at info@caldervance.com.
Related practices
- EU apparent-violation assessment – structured legal review of potential breaches before making any disclosure
- OFAC penalty defence and settlement guide – step-by-step guide to the US enforcement and settlement process
- Japan penalty defence and settlement guide – comparative analysis of enforcement procedure under a different jurisdictional model