A Canadian trading company closes a payment to a supplier. Weeks later, an internal audit flags that the counterparty matches a name on the Consolidated Canadian Autonomous Sanctions List (the list of persons and entities designated under Canada's autonomous sanctions programmes). The transaction has settled. The proceeds are gone. What happens next decides whether a compliance failure remains a contained incident or becomes a formal enforcement matter.
Remediation after a sanctions breach under Canada's sanctions regime requires a structured response: scope the potential violation, preserve evidence, assess reporting obligations under the Special Economic Measures Act ("SEMA") and related instruments, consider voluntary disclosure to Global Affairs Canada ("GAC"), and implement programme fixes before any regulator makes contact. Speed and completeness both matter. As of March 2026, GAC has strengthened its enforcement posture, and the window to act voluntarily is narrow.
This guide walks through each stage of that process, identifies the points where the Canadian position diverges from those of OFAC, OFSI, and the EU, and flags when specialist counsel should be instructed.
Step 1: Recognise the scope of Canada's sanctions authority and legal basis
Canada's autonomous financial and trade sanctions operate primarily under SEMA, supplemented by the United Nations Act (which implements UN Security Council resolutions) and the Justice for Victims of Corrupt Foreign Officials Act ("Magnitsky Act"). GAC administers all three instruments and maintains the Consolidated Canadian Autonomous Sanctions List. Understanding which instrument governs the apparent breach shapes every subsequent step.
SEMA sanctions prohibit a broad range of dealings: transfers of property, provision of financial services, and making property available to designated persons. The prohibitions extend to any person in Canada and any Canadian wherever located. That extraterritorial reach is a recurring surprise for multinationals: a Canadian subsidiary's transaction, a Canadian national approving a payment abroad, or a Canadian-flagged vessel can each bring SEMA into play even when the contracting entity is incorporated elsewhere.
The United Nations Act carries separate prohibitions aligned with Security Council measures. Where both SEMA and the United Nations Act apply to the same set of facts, the stricter prohibition governs. In practice, that often means the UN-derived obligation controls the analysis. Counsel advising at this stage must identify the governing instrument before any disclosure strategy is formed.
Cross-border angle: if the transaction also touched a US or UK counterparty, OFAC and OFSI obligations run in parallel. OFAC's 50 percent rule (the rule treating entities owned 50 percent or more by blocked persons as themselves blocked) may have been triggered independently, and OFSI's ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person) may have a different scope. A breach under SEMA does not automatically constitute a breach under the other regimes – nor does clearance under one regime provide a defence under another.
Step 2: Secure the evidence and contain the incident
Before any disclosure assessment, the facts must be preserved precisely as they existed at the time of the transaction. Do not alter records, do not brief counterparties informally, and do not rely on verbal reconstructions of the approval sequence.
In our experience, the most damaging errors at this stage are inadvertent: an employee updates a spreadsheet to "clarify" a field, a relationship manager contacts the counterparty to ask about ownership, or a compliance officer sends an informal email that later reads as an admission. None of these actions are intentional obstruction, but all of them complicate the position before a regulator.
The practical evidence-preservation steps are straightforward:
- Freeze and image all transaction records, screening logs, approval workflows, and correspondence at the time the issue is identified.
- Identify every individual who touched the transaction and preserve their communications.
- Document the screening tool version, list vintage, and exact match or false-positive logic that was used at the time of approval.
- Record the date and method by which the potential breach was identified.
That last point matters because GAC, like other regulators, gives weight to whether the issue was self-identified or whether it was discovered by the authority. Self-identification before external scrutiny is a material factor in how enforcement discretion is exercised.
Step 3: Assess the apparent violation – does a reportable breach exist?
Not every screening hit and not every payment that touches a listed name constitutes a sanctions violation. The analysis turns on whether the relevant SEMA prohibition, UN Act obligation, or Magnitsky-Act measure was actually contravened on the facts.
The assessment should address four questions. First: was the counterparty, at the time of the transaction, a designated person under the applicable instrument? List vintage is critical. A counterparty designated after the payment settled is a different situation from one designated before. Second: did the transaction fall within the scope of the prohibition – was it a transfer of property, a financial service, or some other act caught by the specific instrument? Third: does any exception, permit, or authorisation apply? SEMA and related instruments carry carve-outs for certain humanitarian transactions, certain pre-existing contractual obligations, and certain legally required payments; these must be assessed on their specific terms. Fourth: was there knowledge, intention, or recklessness? Canada's sanctions offences carry both strict-liability elements and intent-based elements depending on the instrument; the mental-element question affects both the severity of the exposure and the weight given to voluntary disclosure.
The position above covers the standard case. Your facts – the counterparty, the goods, the route, the regime in play – change the analysis. Our apparent-violation assessment service sets out how we structure this review for clients across regimes; the Canadian approach follows the same discipline.
Step 4: How does voluntary disclosure work under SEMA and GAC?
Voluntary disclosure to GAC is the mechanism by which a person or entity reports an apparent breach before a formal investigation is opened. It is not a statutory scheme with a defined procedural code in the way that OFAC's voluntary self-disclosure process is codified. GAC's approach to voluntary disclosure is guided by its published enforcement policy, which identifies proactive self-reporting as a mitigating factor when exercising enforcement discretion.
The absence of a rigid procedural framework cuts both ways. There is no prescribed form, no statutory deadline, and no automatic penalty-reduction formula. That flexibility can benefit a well-prepared disclosure. It also means that a poorly framed or incomplete disclosure can harm the position more than silence would. In our cross-border practice, we consistently advise clients not to treat voluntary disclosure as a form-filling exercise. It is a legal submission.
A well-constructed disclosure to GAC should contain:
- A factual chronology, with dates, parties, amounts (where relevant), and instruments used.
- An identification of the specific prohibition apparently engaged, by reference to the governing instrument (without invented section numbers).
- A candid analysis of the mental-element question – was there knowledge, recklessness, or a genuine systems failure?
- A description of the corrective steps already taken and the programme improvements planned or implemented.
- A clear statement of what the disclosing party requests – typically a determination that no further enforcement action will be taken.
Timing matters. Disclosure made after GAC has opened an inquiry, or after a third party has reported the matter, carries less mitigating weight. The window to act voluntarily is narrow and narrows further once the counterparty, a correspondent bank, or a regulator in another jurisdiction has identified the transaction independently.
If a transaction has already been flagged or a filing has been refused, an early review can preserve options that narrow with time. To discuss a confidential assessment of your disclosure position, contact Calder & Vance at info@caldervance.com.
Step 5: What are the risk flags that escalate a Canadian breach to multi-regime exposure?
Several factors convert a contained SEMA incident into a multi-regime enforcement problem. Identifying them early is the purpose of a thorough apparent-violation assessment.
Correspondent-bank reporting. A Canadian-dollar or US-dollar payment that transits a US correspondent bank will be visible to that bank's OFAC screening programme. If the correspondent bank files a Suspicious Activity Report or blocks the payment, OFAC may become aware of the transaction independently. At that point, the Canadian voluntary-disclosure window has effectively closed for US purposes – and OFAC's VSD (voluntary self-disclosure to a regulator) process, which is a formal codified programme, requires a separate submission.
UK and EU secondary exposure. A transaction involving a UK entity or a euro-denominated payment triggers OFSI and EU-regime analysis simultaneously. OFSI's ownership and control test can catch a counterparty that is not directly listed but is effectively controlled by a designated person. The EU's equivalent test under the relevant Council regulation applies a similar logic. Do not assume a SEMA clearance resolves those questions.
Criminal referral risk. SEMA offences can carry both civil and criminal consequences. Where the mental-element analysis reveals recklessness or a deliberate decision to proceed despite a known risk, the enforcement path may lead to a referral rather than a regulatory settlement. That distinction matters for disclosure strategy.
Goods and export controls. Where the transaction involved physical goods rather than purely financial flows, the Export and Import Permits Act and Canada's export-control regime may be independently engaged. A sanctions breach and an export-control violation arising from the same shipment are separate matters requiring separate analysis.
Repeat conduct. GAC's published enforcement guidance identifies repeat conduct as an aggravating factor. A single, isolated systems failure is treated differently from a pattern of non-compliance. If the apparent breach is the second or third involving similar counterparties or transaction types, the disclosure must address the pattern honestly.
Step 6: Build the remediation plan – what a credible programme fix looks like
A credible remediation plan is the document that transforms a voluntary disclosure from a report of past conduct into evidence of future reliability. GAC, like every major sanctions authority, gives weight to concrete programme improvements over aspirational statements.
The remediation plan should address the specific root cause identified in the apparent-violation assessment. Generic improvements – "we will improve our screening" – do not satisfy a regulator that the underlying failure has been corrected. The plan must trace the failure to its source and demonstrate that the source has been removed.
Common root causes in Canadian sanctions breaches, and the corresponding remediation steps, include:
- Stale list versions in the screening tool – remediation: automated daily refresh of all relevant lists (Consolidated Canadian Autonomous Sanctions List, OFAC SDN, UN Consolidated List) with a documented audit trail.
- Ownership-chain gaps – remediation: enhanced ownership and control checks for counterparties above a defined transaction threshold, with a documented rationale for any ownership threshold applied.
- Approval-workflow bypass – remediation: system-level controls preventing settlement until a compliance hold is resolved, with no manual override capability below a defined seniority level.
- Training gaps – remediation: mandatory sanctions training for all relevant staff, with documented completion records retained for a defined period.
- Escalation failure – remediation: a written escalation protocol specifying who is notified, within what period, and what documentation is required at each stage.
We regularly advise clients on stress-testing their screening logic, mapping ownership and control chains, and redesigning their programmes to the standard a regulator would expect to see. The test is not whether the programme looked reasonable before the breach; it is whether the programme is genuinely effective after it.
Step 7: Multi-jurisdiction remediation – how Canada differs from OFAC, OFSI, and the EU
For a business that has reported the same breach to GAC, to OFAC, and to OFSI, the procedural divergences between regimes are immediately practical. What satisfies one authority does not automatically satisfy another, and the timing requirements differ.
OFAC's voluntary self-disclosure process is highly formalised. OFAC publishes a framework for what the initial notification must contain, specifies how the full written submission should be structured, and treats the date of the initial notification as the disclosure date for limitations purposes. The OFAC process also distinguishes between an apparent violation and an egregious violation, with penalty bases that differ significantly between the two.
OFSI's approach under SAMLA and its published enforcement guidance treats voluntary disclosure as a mitigating factor, similarly to GAC, but the UK regime has developed a specific reporting obligation: a person who knows or has reasonable cause to suspect that they hold funds belonging to a designated person must report to OFSI promptly. That obligation is distinct from the penalty-mitigation disclosure.
The EU regime, under the relevant Council regulation, also imposes reporting obligations for persons who hold or control funds of designated persons, alongside a duty to cooperate with competent national authorities. EU member-state enforcement varies: some authorities have highly structured disclosure processes; others apply a more discretionary approach closer to GAC's model. Our EU post-breach remediation guide sets out those differences in detail.
The practical implication for a client facing exposure across multiple regimes is that a single remediation plan will not serve all authorities. Each submission must be tailored to the regime, must address the regime-specific procedural requirements, and must be timed carefully so that disclosure in one jurisdiction does not prejudice the position in another. Our cross-border remediation guide addresses the sequencing questions that arise when two or more authorities are involved simultaneously.
Is it possible to coordinate disclosures across OFAC, GAC, and OFSI without inadvertent admission-making in one that undermines the other? It is – but only with careful legal privilege planning from the outset. That is precisely the moment to involve cross-border counsel.
Common myths about Canadian sanctions remediation
A persistent misconception in our practice is that because GAC has historically exercised enforcement discretion in a measured way, voluntary disclosure is less important in the Canadian context than under OFAC or OFSI. That is no longer an accurate assessment of the enforcement environment. As of early 2026, GAC has substantially expanded its enforcement capacity, has published updated enforcement guidance, and has signalled clearly that proactive disclosure and credible remediation are expected – not optional.
A second myth is that a small transaction value removes the disclosure obligation. Enforcement authorities, including GAC, assess violations by reference to conduct, not solely by reference to monetary amount. A small-value breach that reveals a systemic failure in screening or in an approval process is treated more seriously than a single anomalous transaction that fell through a well-designed programme.
A third myth is that a holding company structure insulates the parent from liability for a subsidiary's breach. SEMA's prohibition on making property available to designated persons can extend to conduct by entities within a corporate group where the group relationship itself facilitates the breach. Ownership structure is a factor in the analysis, not a shield.
Related practices
- Apparent Violation Assessment – scoping and structuring your response to a potential breach across regimes
- Cross-Border Post-Breach Remediation – managing simultaneous disclosure obligations across OFAC, GAC, OFSI, and the EU