A Canadian trading company receives a call from its bank: a payment has been flagged against the Consolidated Canadian Autonomous Sanctions List (the master list of individuals and entities subject to Canadian restrictive measures). The compliance officer pulls the records. The counterparty had been listed for two months before the transaction settled. No one noticed. Now what?
Enforcement risk after a breach under Canada is governed primarily by the Special Economic Measures Act ("SEMA"), administered by Global Affairs Canada ("GAC"). A breach of a SEMA prohibition can result in significant criminal penalties, and the window to take corrective action – through voluntary disclosure and internal remediation – is short. As of March 2026, Canadian enforcement activity has been increasing in frequency and scope, making early, structured response critical.
This guide walks through the discovery-to-resolution sequence, the cross-border dimensions that compound Canadian exposure, and the practical steps a business should take before the regulator makes first contact.
Step 1: Understand the governing regime and who enforces it
Canada's autonomous sanctions regime is built on SEMA, with additional measures flowing from the United Nations Act for UN-mandated programmes. GAC is the lead policy authority; it maintains the Consolidated Canadian Autonomous Sanctions List and issues permits. The Royal Canadian Mounted Police ("RCMP") and the Canada Border Services Agency ("CBSA") have investigative authority for criminal breaches. Prosecutions run through the Department of Justice.
For export-control matters that intersect with sanctions – for example, a controlled good shipped to a listed destination or end-user – the Export and Import Permits Act and GAC's export-controls bureau create a parallel enforcement exposure. In our practice, breaches that seem confined to sanctions frequently involve an unreported export-control dimension. Identifying both at the outset shapes the disclosure strategy.
The key prohibitions under SEMA cover dealings in property, provision of financial services, facilitation, and making goods and technology available to or for the benefit of designated persons. "Facilitation" is broadly construed: arranging a third-party's transaction can engage liability even without direct benefit to the designated person.
Step 2: Scope the apparent violation before doing anything else
The most consequential decision in the first 48 hours is to scope the apparent violation accurately rather than to act on incomplete information. Acting – whether by making a disclosure, freezing assets, or alerting counterparties – before the facts are clear can prejudice the firm's position.
A structured scoping exercise covers four questions:
- Is the counterparty, or the beneficial owner, on the Consolidated Canadian Autonomous Sanctions List? Run the full ownership chain, not just the entity name. Canada's ownership and control test (the principle that dealings with entities controlled by designated persons may themselves be prohibited) means a clean entity name does not clear the transaction.
- What is the prohibited dealing? Identify the specific prohibition engaged – financial services, property, facilitation – because each carries different elements and defences.
- When did the listing take effect relative to the transaction date? A transaction that settled before the listing date is not retrospectively prohibited, though ongoing contractual obligations post-listing require separate analysis.
- Is there a cross-border dimension? If payments routed through a US correspondent bank, or if the goods touched EU territory, OFAC and EU Council-regulation exposure may layer on top of Canadian liability.
Document the scoping exercise contemporaneously. If the matter later proceeds to a criminal investigation or a voluntary disclosure, the regulator or prosecutor will want to see that the firm identified the issue promptly and responded methodically.
The position above covers the standard discovery scenario. Your specific facts – the nature of the dealing, the goods, the payment route, and the counterparties – will change the analysis materially. To discuss the scope of an apparent breach under Canadian sanctions, contact Calder & Vance at info@caldervance.com.
Step 3: Assess voluntary disclosure – and why timing is decisive
Voluntary disclosure to GAC and, where relevant, to the RCMP is the primary mitigation tool available after a breach under the Canadian regime. There is no formal "VSD" programme under SEMA equivalent to OFAC's structured voluntary self-disclosure pathway, but GAC's published guidance recognises voluntary reporting and cooperation as factors that weigh in the firm's favour. Canadian prosecutors and courts similarly treat early, candid disclosure as a relevant consideration in charging decisions and sentencing.
The timing question is not simply about acting fast. A premature disclosure that understates the breach, or that conflicts with facts the regulator already holds, can be more damaging than a measured disclosure made once the facts are clear. The practical discipline is to move as quickly as the facts allow – which typically means completing the scoping exercise in parallel with preparing the disclosure, not sequentially.
Several factors determine whether voluntary disclosure is the right path:
- Whether the regulator is likely to discover the breach independently (through financial-intelligence reporting, trade data, or a counterparty disclosure)
- Whether the breach was systemic or isolated
- Whether there is a genuine compliance failure or a screening-tool gap that can be demonstrated and corrected
- Whether related breaches in other jurisdictions need to be managed concurrently
In our experience, the firms that manage enforcement risk most effectively treat disclosure as a strategic decision requiring legal analysis, not an automatic first step. Have you assessed what GAC is likely to know before you decide whether and when to approach them?
Step 4: Understand the cross-border multiplication of risk
A breach under the Canadian regime rarely exists in isolation. For most cross-border B2B transactions, the same dealing that violates SEMA may simultaneously trigger obligations or expose the firm to enforcement under OFAC, the EU Council regulations, or OFSI in the United Kingdom.
The US dimension is frequently the most significant. OFAC's secondary sanctions authority (measures that can restrict access to the US financial system for non-US persons engaged in targeted activities) does not require a US nexus to apply to some programmes. More commonly, a Canadian transaction with a designated person will have touched US-dollar clearing, a US correspondent bank, or US-origin goods – creating a direct OFAC nexus. OFAC penalties are assessed per transaction and can be substantial; the regimes operate independently, meaning a disclosure to GAC does not protect against a parallel OFAC investigation.
The EU and UK positions on the same counterparty may differ. Designation lists are not perfectly aligned: a person listed under Canadian measures may not be listed under EU Council regulations, or may be listed but subject to a different prohibition scope. This divergence cuts both ways. A transaction permissible under EU rules may still violate SEMA, and vice versa. For businesses with European operations, a Canadian enforcement matter can expose the parent entity to EU and UK regulatory scrutiny of their own handling of the transaction.
Switzerland, through SECO's autonomous sanctions ordinances, and Australia's DFAT regime follow comparable autonomous-sanctions models. Each requires separate analysis of listing status and prohibition scope. The safest working assumption for any cross-border breach is that the apparent violation touches at least two regimes and that counsel in each relevant jurisdiction should be involved at the outset.
If a transaction has already been flagged under another regime, or if a filing has been refused, an early cross-regime review can preserve options that narrow significantly with time. Contact Calder & Vance at info@caldervance.com to discuss a multi-regime enforcement response.
Step 5: Apply the correct ownership and control test
The ownership and control analysis under Canadian sanctions law determines whether a non-listed entity is caught through a listed person's interest in it. GAC's position tracks the prohibition: dealings with an entity that is owned or controlled by a designated person may themselves be prohibited dealings for the benefit of that designated person.
Canada does not publish a mechanical percentage threshold equivalent to OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) in the same explicit statutory form, but the practical analysis requires reviewing all ownership interests, direct and indirect, and assessing control through governance rights, board composition, and economic dependency. An entity owned at 45 percent by a designated person, with the designated person also holding effective control over board decisions, presents a high-risk profile that a purely mechanical test would miss.
This is where Canadian practice diverges materially from the OFAC model. Under OFAC, the 50 percent aggregation rule provides a clear mechanical trigger. Under the Canadian and EU approaches, control is a facts-and-circumstances analysis. The implications for screening are significant: automated tools calibrated to OFAC thresholds will under-screen for Canadian and EU purposes. In our practice, we regularly advise clients to run a separate, judgement-based ownership review after automated screening returns a clean result on percentage-ownership grounds alone.
A related risk is aggregation across multiple listed persons. If two designated persons each hold a minority stake in the same target entity, their combined holding may engage a prohibition even if neither individually crosses any threshold that would prompt an automated alert.
Step 6: Identify the common risk flags that escalate enforcement exposure
Several patterns, in our experience, consistently escalate enforcement exposure under the Canadian regime and attract regulatory scrutiny:
- Delayed internal escalation. A compliance officer who identifies a potential breach but delays escalation to legal counsel and senior management – whether from uncertainty about the severity or from a desire to verify before alarming the board – creates a documented gap between discovery and response. Regulators and prosecutors treat that gap as material.
- Incomplete screening at onboarding. Most post-breach reviews reveal that the listed counterparty was screenable at the point of onboarding but was not screened, was screened against an incomplete list, or was screened and the alert was dismissed without adequate review. Systemic screening failures attract the most serious enforcement responses.
- Failure to rescreen on amendment. A transaction that was clean at inception may become prohibited if a counterparty is listed after signing. Ongoing obligations – drawn-down credit facilities, long-term supply agreements, joint ventures – require periodic rescreening, not a one-time check.
- Documentary gaps in the ownership-and-control analysis. Where a business decided a counterparty was not caught by a designation, but cannot produce the analysis that supports that decision, enforcement exposure is elevated. The absence of contemporaneous documentation suggests the analysis was never done.
- Proceeds that have already moved. Where funds from a prohibited dealing have been transferred or converted before the breach is identified, remediation becomes more complex. GAC's prohibition on dealing in the property of designated persons extends to proceeds; the firm's ability to demonstrate that it has halted and reported all dealings is undermined if funds are already dispersed.
Recognising these patterns early – before the regulator raises them – and addressing them in the voluntary disclosure is the most effective way to frame the firm's response as one of genuine compliance failure rather than deliberate risk-taking.
How Canada compares with OFAC, OFSI, and the EU on post-breach enforcement
Understanding how GAC's enforcement posture compares with the other major regimes helps a business allocate risk management resources and calibrate the urgency of its response across jurisdictions.
OFAC operates a formal, published VSD (voluntary self-disclosure to a regulator) programme with documented penalty-mitigation guidance. The process is well-worn, and the outcome ranges from a no-action letter for minor, self-remediated violations to a substantial civil penalty for egregious or wilful breaches. OFAC's enforcement actions are published; the firm's position in that precedent set is a relevant comparator. GAC has no equivalent published programme, and enforcement outcomes are less routinely published, making the precedent landscape less legible.
OFSI in the United Kingdom introduced a monetary penalty regime under SAMLA. OFSI has published its enforcement guidance and has moved toward more active enforcement, including penalties against firms that did not benefit financially from a breach. The UK regime expressly recognises the adequacy of a compliance programme as a factor in penalty assessment. Canada does not have an equivalent civil penalty track; the primary enforcement mechanism under SEMA is criminal prosecution, which creates a structurally higher threshold for escalation but also higher consequences when it is crossed.
The EU regime, enforced by member-state competent authorities under Council regulations, is fragmented by jurisdiction. A breach with a German banking connection is handled by German authorities under German procedural rules; a breach with a French component by French authorities. The aggregate exposure across member states can be significant, and coordination between national authorities is increasing. Unlike Canada, the EU regime has an administrative penalty track alongside criminal enforcement in most member states.
The practical implication of this comparison: a multi-regime breach where Canada and OFAC are both engaged requires a coordinated disclosure strategy that accounts for the different disclosure incentive structures. Disclosing to OFAC under its VSD programme may benefit the firm under OFAC's published guidance. That same disclosure may be relied upon by GAC in a Canadian investigation. Sequencing and content require cross-border counsel.
Related practices
- Apparent violation assessment – EU – assessing exposure and structuring disclosure for EU sanctions breaches
- Post-breach enforcement risk: cross-border guide – managing multi-regime enforcement exposure after a suspected breach
- Post-breach enforcement risk – EU guide – step-by-step enforcement risk management under EU Council regulations
When to involve counsel – and what to expect
The moment a potential breach is identified is the right moment to involve external sanctions counsel. This is not a precautionary recommendation; it is a structural one. The scoping, disclosure, and remediation steps set out above involve decisions – about what to disclose, to whom, in what sequence, and on what factual basis – that have direct consequences for criminal liability, civil exposure, and regulatory standing. Those decisions should not be made without qualified advice.
A common myth is that involving external counsel signals guilt or escalates the matter unnecessarily. It does neither. Regulators and prosecutors expect sophisticated firms to act through counsel; an uncoordinated response made without legal advice is more likely to create problems than to resolve them. In our experience, the firms that present the clearest, most credible voluntary disclosures are those whose counsel was involved from the first day of the internal review.
What to expect from counsel in the first phase:
- A privilege-protected scope of the apparent violation, including the ownership-and-control analysis
- An assessment of the cross-regime exposure (Canada, OFAC, OFSI, EU as applicable)
- A disclosure recommendation – whether to disclose, to whom, in what sequence, and on what timeline
- Advice on interim measures: whether to suspend the transaction, freeze assets pending clarification, or halt ongoing contractual performance
- Coordination with local counsel in other relevant jurisdictions
The engagement model at Calder & Vance begins with a fixed-fee initial assessment. We assess the apparent violation, map the cross-regime exposure, and advise on the disclosure and remediation strategy before the client commits to a full-scope engagement. This allows the business to understand its position and its options without an open-ended cost commitment at the most uncertain stage of the matter.