Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · OFAC

Remediation after a sanctions breach under OFAC: step by step

A payments firm processes a wire transfer. Post-execution screening flags the beneficiary as a match against the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The transaction has already settled. The compliance officer asks three questions at once: what do we report, to whom, and by when? The clock is already running.

Remediation after a sanctions breach under OFAC follows a defined sequence: contain the apparent violation, preserve evidence, conduct a structured internal investigation, assess voluntary self-disclosure, submit to OFAC, and rebuild the control that failed. As of March 2026, OFAC treats a voluntary self-disclosure (a proactive, timely report to the regulator before it becomes aware through other means) as a significant mitigating factor in the penalty calculus. Acting before OFAC contacts you is categorically different from responding after.

This guide walks each stage of that sequence, identifies the points where decisions harden, and flags where the OFAC analysis intersects with the UK, EU, and other regimes that may run concurrently.

Step 1 – Contain the apparent violation and preserve the record

The first obligation after identifying a potential sanctions breach is to stop ongoing exposure and lock the evidence before anything changes. Do not delete transaction records, alter system logs, or instruct counterparties informally while the assessment is open.

Practical containment means four things in sequence. First, freeze any further execution of the transaction or the relationship that generated the hit. Second, block assets where that obligation is live under OFAC rules – failing to block is itself a separate potential violation. Third, preserve all relevant records: transaction data, counterparty files, screening logs, and internal communications from the period of the suspected violation. Fourth, brief only those who need to know; premature wide disclosure can complicate a later voluntary self-disclosure and create waiver risks over legal advice.

Record-keeping is not optional. OFAC expects businesses to retain records relevant to a potential violation, and document retention obligations run for a significant period under the applicable regime. Build a document-hold notice immediately, directed at any custodian – IT systems included – that holds relevant data.

One more thing often overlooked at this stage: check whether a mandatory blocking report is already required. Where the transaction involved blocked property, a report to OFAC is typically due within a short statutory window. Missing that deadline compounds the original exposure.

Step 2 – Conduct the internal investigation and scope the apparent violation

A structured internal investigation establishes the scope of what happened before any decision is taken on reporting – and the quality of that investigation directly shapes OFAC's assessment of the response.

The investigation should answer six questions. Who was the counterparty, and why did screening not catch them at onboarding or at transaction time? When did the first touch-point with the prohibited person or entity occur? How many transactions are implicated, and over what period? What was the root cause – a data gap in the screening list, a name-matching failure, a compliance override, a process breakdown? Did any individual know or have reason to know that a prohibition applied? And are there parallel exposures under other regimes?

That last question matters more than firms typically expect. A transaction that touches OFAC may simultaneously implicate OFSI in the United Kingdom or the EU Council regulations if UK or EU persons, financial institutions, or correspondent banks were involved. In our cross-border practice, we regularly see situations where a firm has scoped the OFAC piece carefully but has not mapped whether the same transaction carried UK or EU nexus. The consequences of that gap are serious: OFSI and EU competent authorities operate independent enforcement tracks, and the mitigating value of early engagement with one regulator does not automatically transfer to the others.

The investigation output should be a written memorandum – prepared under legal-professional privilege where possible – that sets out the facts, the apparent violation, and an initial assessment of aggravating and mitigating factors under OFAC's penalty guidelines. That memorandum becomes the foundation for the voluntary self-disclosure decision.

Should you make a voluntary self-disclosure to OFAC?

A voluntary self-disclosure (a proactive, timely report submitted before OFAC independently learns of the violation) is the single most consequential decision in the remediation sequence, and it must be taken deliberately rather than reflexively.

OFAC's enforcement guidelines treat a VSD as a significant mitigating factor. In practice, a VSD can reduce the base civil monetary penalty by a material proportion compared with a non-disclosed violation of the same seriousness. That reduction is not guaranteed, and OFAC retains discretion – but the trend across enforcement actions is consistent. What counts as "timely" is not defined by a fixed calendar deadline; OFAC expects disclosure as soon as practicable after the business has sufficient facts. Delay to investigate is permissible; delay to manage the outcome is not.

Not every apparent violation warrants a VSD. OFAC distinguishes between egregious cases – those involving wilful conduct, concealment, harm to sanctions programme objectives, or senior-management knowledge – and non-egregious cases. For a non-egregious matter where the business has strong mitigating factors and a clean prior record, some circumstances support a written cautionary letter or no-action outcome rather than a penalty. Counsel can model the risk either way before a filing decision is taken.

A caution, though: the analysis is not purely domestic. If your business has a UK or EU affiliate that was involved in the same transaction chain, a VSD to OFAC does not satisfy OFSI's separate mandatory reporting obligation where one applies, nor does it address EU reporting requirements. These parallel tracks require coordinated handling, and a filing strategy that optimises one jurisdiction can inadvertently prejudice another if not managed in concert.

The position above covers the standard case. Your facts – the counterparty, the goods, the route, the regime in play, and the number of transactions implicated – change the analysis. For an assessment of your specific exposure, contact Calder & Vance at info@caldervance.com.

Step 3 – Prepare and submit the voluntary self-disclosure package

A well-constructed VSD submission to OFAC is a legal document, not a narrative apology. Its content and structure directly affect how OFAC categorises the matter and what it does next.

The submission should set out: the identity of the reporting party; the facts of each apparent violation (counterparty, transaction type, date, amount, and the specific OFAC programme implicated); a description of how the violation was discovered and when; the actions taken to contain and remediate; the root-cause analysis; any prior compliance history; and the corrective measures already implemented or committed to. Omissions that OFAC later discovers – particularly about additional transactions in the same series – are treated as aggravating factors. The investigation phase therefore has to be substantially complete before the VSD is filed.

Supporting documentation accompanies the narrative: transaction records, screening logs, organisational charts where ownership questions arise, and evidence of the corrective action programme. If the matter involves a blocked-property situation (property in which a blocked person has an interest), the blocking report and any interim actions should be referenced and annexed.

Timing interacts with completeness. OFAC's guidance contemplates a preliminary notification followed by a more detailed submission where the full investigation is ongoing – this can preserve the timing benefit while allowing the business to complete its review. Counsel experienced in OFAC submissions can advise on whether a phased approach is appropriate and how to structure the preliminary notice to avoid inadvertent admissions.

Step 4 – Manage the OFAC review process

Once a VSD or a response to an OFAC administrative subpoena is submitted, the matter enters the regulator's review queue. The timeline is not fixed and varies with the volume of OFAC's docket, the seriousness of the matter, and whether OFAC has follow-up questions.

During this period, three disciplines matter. First, maintain the document hold and ensure that no destruction schedule operates over relevant records. Second, respond promptly and completely to any follow-up requests from OFAC. A pattern of delayed or incomplete responses to information requests – even after an otherwise strong VSD – signals poor cooperation and can reverse mitigating credit already earned. Third, do not unilaterally close the matter or treat the absence of contact from OFAC as a resolution. OFAC may be reviewing multiple submissions simultaneously; silence is not clearance.

In our practice, we advise clients to maintain a dedicated matter file throughout the OFAC review period, updated with every communication, every document produced, and every internal decision taken. Should the matter escalate to a settlement negotiation or a civil penalty proceeding, that file becomes the evidentiary basis for the defence.

Where the matter also carries UK or EU dimensions, the parallel OFSI or competent-authority review tracks require separate management. OFSI's enforcement process and the EU Member State routes each have their own information-request procedures and timelines. Coordinating responses across these tracks – so that positions are consistent and no filing in one jurisdiction contradicts a position taken in another – is a distinct workstream that should be planned from the outset.

Step 5 – Rebuild the compliance programme that failed

Remediation under OFAC does not end with the VSD submission or even with the penalty resolution. The correction of the underlying compliance failure is itself an assessed factor, and OFAC's guidelines place substantial weight on the adequacy and sincerity of the corrective-action programme.

A corrective-action programme that satisfies OFAC's expectations typically addresses five elements: the specific root cause identified in the investigation; the screening or procedural gap that permitted the violation; management oversight and accountability for the corrected process; training directed at the staff involved and at the compliance function; and testing of the remediated control against the original failure scenario. Each element should be documented and, where possible, time-stamped against the date of the VSD commitment.

The five-element structure mirrors what OFAC identifies in its published framework for evaluating compliance commitments. A programme that addresses root cause without testing the fix, or that trains staff without adjusting the screening configuration, will not read as genuine remediation to an examiner. We regularly advise clients on designing corrective-action programmes that are specific to the failure mode rather than generic policy updates.

One practical point on screening: many violations trace to a gap between the screening list version in use and the current OFAC list state. List update frequency, the SDN List matching logic, and the handling of aliases and transliterations are all technical parameters that require dedicated review. A corrective-action programme that treats list-matching as a binary pass/fail – without addressing fuzzy matching, name variants, and beneficial-ownership aggregation – leaves the same exposure in place under a different description.

If a transaction has already been flagged, or a filing has been refused, an early review of your corrective-action programme can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss a structured review.

Cross-regime considerations: where OFAC, OFSI, and EU obligations diverge

A business managing post-breach remediation in one regime must assess whether the same facts trigger obligations in others – and the answer is more often yes than firms expect.

The three regimes diverge at the point of mandatory reporting. OFAC operates a blocking-and-reporting obligation for property of blocked persons, with a short statutory window for the initial report. OFSI in the United Kingdom operates a mandatory reporting obligation for financial sanctions knowledge – a relevant firm (a financial institution or specified professional within OFSI's scope) that knows or suspects a breach must report within a short, defined period. The EU does not impose a single uniform mandatory-reporting window across Member States; obligations vary by jurisdiction and by the type of transaction involved.

The ownership and control tests also diverge in ways that affect scope. OFAC applies the 50 percent rule (treating entities that blocked persons own 50 percent or more in the aggregate as themselves blocked) as a mechanical, ownership-driven test. OFSI and the EU both apply an ownership and control test that reaches non-listed entities through either ownership or control, including cases where a listed person exercises dominant influence without reaching the numeric threshold. A corporate structure that sits below the OFAC 50 percent line may still fall within the UK or EU prohibition, with consequences for whether a transaction was prohibited under those regimes even if it was not prohibited under OFAC.

Extraterritorial reach adds a further layer. US secondary-sanctions programmes can affect non-US businesses that have no direct US nexus to the underlying transaction but whose institutions have US dollar exposure or US correspondent relationships. A non-US firm completing what appears to be a purely local transaction may carry secondary-sanctions risk if the counterparty or the underlying activity falls within a designated programme. Identifying that risk early – during the internal investigation rather than after a VSD has been filed – allows the response strategy to be calibrated to the full exposure picture.

Switzerland (SECO), Canada (GAC), and Australia (DFAT) each maintain their own post-breach reporting and remediation expectations under the applicable country regime. In matters involving trading routes or counterparties in those jurisdictions, parallel notifications or remediation obligations may arise independently.

Related practices

Common risk flags and the myth of self-cure

Several patterns recur in the post-breach matters we handle, and each represents a decision point where the wrong move materially worsens the outcome.

The first is the belief that a small-value transaction is not worth disclosing. OFAC's penalty assessment does not treat transaction value as a dispositive factor in every case. A low-value transaction that implicates a highly sensitive programme, or that forms part of a pattern, can attract a penalty that far exceeds the transaction amount. Low value is a mitigating factor, not a shield.

The second is delayed investigation. Firms sometimes defer the internal review while attempting to resolve the matter bilaterally with the counterparty or the correspondent bank. That deferral narrows the "voluntary" window; if OFAC learns of the violation through a third party's own disclosure before the business has filed, the VSD mitigating factor is lost entirely.

The third – and perhaps the most persistent – is the myth of self-cure: the idea that fixing the compliance programme internally, without notifying OFAC, is a complete remediation. It is not. An unreported apparent violation that recurs, or that surfaces in a subsequent audit or examination, is treated as a wilful concealment rather than a prior correction. The compliance improvement has value, but only if combined with the appropriate disclosure path.

There is also a documentary trap. Some businesses, on discovering a breach, begin informal communications with the counterparty or their own board that characterise the transaction in ways inconsistent with the later legal analysis. Those communications are discoverable and can contradict the VSD narrative. Legal privilege should be established around the review and communications process as early as possible.

Frequently asked questions

What are the steps to build a remediation plan under OFAC?
A remediation plan under OFAC should follow five sequential steps: contain the apparent violation and preserve all records; conduct a structured internal investigation to scope the facts and root cause; assess whether a voluntary self-disclosure is warranted on the specific facts; prepare and submit the VSD or other required report to OFAC with complete supporting documentation; and implement a corrective-action programme that addresses the specific compliance failure identified. Each step should be documented and, where possible, managed under legal-professional privilege. Where parallel UK, EU, or other regime obligations exist, those steps must be mirrored in each relevant jurisdiction.
What is the most common mistake in remediation after a sanctions breach?
The most common mistake is deferring the voluntary self-disclosure decision while attempting to fix the compliance programme internally, under the belief that remediation alone constitutes a complete response. OFAC does not treat internal correction as a substitute for disclosure. A business that remediates silently and later faces OFAC contact – through a third-party filing, an examination, or a follow-on transaction – loses the mitigating credit that an early VSD would have produced and may face an aggravated assessment based on the period of non-disclosure. Acting quickly and completely, under counsel, is the standard the regime rewards.
How does OFAC differ from other regimes here?
OFAC's voluntary self-disclosure path is well-established, with published guidelines that set out how a VSD reduces the base civil penalty calculation. OFSI in the United Kingdom and the EU competent authorities each operate their own post-breach procedures, with different mandatory-reporting obligations, different timelines, and different mitigation frameworks. OFSI applies a mandatory-reporting obligation on relevant firms that has no direct OFAC equivalent in its scope; the EU applies Member State-level procedures that vary across jurisdictions. The ownership and control tests also differ: OFAC uses the mechanical 50 percent rule, while OFSI and the EU extend their reach through a control test that can capture entities below that threshold. A cross-border business managing concurrent obligations across regimes requires coordinated advice in each.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.