Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · OFSI

Remediation after a sanctions breach under OFSI: step by step

A UK-regulated financial institution processes a payment on a Monday morning. By Thursday, the compliance team realises the beneficiary's ultimate owner appeared on the OFSI Consolidated List (the UK Office of Financial Sanctions Implementation's list of designated persons and entities). The funds have moved. The breach has occurred. What happens next – and how quickly the business responds – will shape everything that follows.

Remediation after a sanctions breach under OFSI follows a defined sequence: contain the breach, preserve evidence, conduct a prompt internal review, report to OFSI within the statutory window, and build a credible corrective-action programme. As of March 2026, OFSI has the power to impose a civil monetary penalty of up to the greater of £1 million or 50 per cent of the estimated value of the breach. A voluntary self-disclosure (VSD – proactive, unsolicited notification to OFSI before the regulator becomes aware) is one of the factors OFSI weighs when setting the penalty level.

This guide walks through each stage of the remediation process under OFSI, identifies the risk flags that arise at each step, and explains where the UK position diverges from OFAC, the EU, and other major regimes.

Step 1: Contain the breach and preserve the evidence

The first action after identifying a potential breach is to stop further exposure and lock the evidentiary record. Do not process additional transactions involving the same counterparty, account, or ownership chain until the picture is clear. Equally, do not delete, overwrite, or summarise records – OFSI may request contemporaneous communications, transaction logs, screening outputs, and due-diligence files as they existed at the time.

In our experience, the most damaging early mistakes are transactional – continuing to service a relationship while the internal review is pending – and documentary. A compliance officer who consolidates records "for clarity" before the review is complete can inadvertently undermine the firm's position. Preserve everything in its original form.

Appoint a senior responsible individual at this stage. In a regulated firm, that will typically be the MLRO or the Head of Compliance, supported by legal counsel. The decision on whether to involve external sanctions counsel should be made within the first day. The sooner that decision is taken, the more options remain open.

Step 2: Conduct a rapid internal review

The internal review has two objectives: establish the factual scope of the breach, and identify the legal basis for it. These are distinct tasks and should be kept separate in the documentation.

On the factual side, the review should answer: who was involved, what was the nature of the transaction or conduct, when did it occur, what was the value, and how many instances are there. A single payment to a listed person is a different matter from a twelve-month banking relationship. OFSI's approach to both the question of whether a penalty is warranted and the level of that penalty is shaped by the gravity and scale of the conduct.

On the legal side, the review should address whether the conduct constitutes a "licence required" activity that lacked the necessary authorisation, whether any general licence (a standing authorisation permitting a defined class of transactions without a case-by-case application) might have applied, and whether the relevant designation was in force at the time. OFSI maintains the Consolidated List, but the legal trigger is the relevant thematic sanctions regulations made under the Sanctions and Anti-Money Laundering Act (SAMLA).

Instruct external counsel under legal professional privilege where the matter may result in enforcement. Communications prepared in anticipation of litigation attract privilege; post-incident reviews conducted without counsel may not. That distinction matters if OFSI later issues a formal information request.

Step 3: Report to OFSI – the voluntary self-disclosure decision

The decision to make a VSD is one of the most consequential in the remediation process. Under OFSI's enforcement guidance, a VSD is an unsolicited, prompt, and full disclosure to OFSI before it becomes aware of the potential breach by other means. A disclosure that follows a tip-off, a regulatory referral, or an OFSI enquiry is not treated as voluntary in the same way.

OFSI has published guidance confirming that a VSD is a factor it takes into account when deciding whether to impose a monetary penalty and at what level. Timing matters: a disclosure made quickly and completely is weighted more favourably than one that dribbles out over weeks. In our cross-border practice, we consistently advise clients to treat the reporting decision as a strategic one, not merely an administrative one. What you say, when you say it, and what you attach to the report shapes the regulator's first impression of the business's co-operation posture.

The report itself should include a factual narrative, the steps taken to contain the breach, initial root-cause findings, and an indication of the corrective-action programme underway. It should not speculate about intent or make admissions that go beyond established facts. OFSI may follow up with an information request under its statutory powers; the initial report sets the tone for that exchange.

There is a related but separate obligation for relevant firms (broadly, firms subject to the Money Laundering Regulations and other regulated-sector obligations): to report known or suspected breaches of financial-sanctions rules to OFSI as soon as practicable. A VSD and a mandatory report are not the same thing, but they overlap in practice. Counsel can help structure the disclosure to address both obligations without creating inconsistencies.

The position above covers the standard case. Your facts – the counterparty's designation basis, the nature of the goods or funds, the route the transaction took, and the regulatory regime most directly in play – can change the analysis significantly.

For an assessment of your exposure under OFSI, contact Calder & Vance at info@caldervance.com.

Step 4: How does the OFSI process compare with OFAC and the EU?

The UK, US, and EU each have their own disclosure and remediation mechanics, and businesses operating across jurisdictions face the risk that action taken to satisfy one regime creates complications under another.

Under OFAC, a voluntary self-disclosure is likewise a mitigating factor – but the US programme is more granular. OFAC's enforcement guidelines distinguish between "egregious" and "non-egregious" cases, and the penalty base under IEEPA differs from the OFSI formula. OFAC's penalties can be substantially higher in absolute terms. Where a transaction has a US nexus – a US correspondent bank, US-origin goods, or a US-person counterparty – the same conduct may constitute an apparent violation under both OFSI and OFAC. Disclosing to OFSI does not substitute for a disclosure to OFAC; both regulators must be addressed on their own terms.

Under EU Council regulations, there is no single "VSD" mechanism equivalent to OFSI's or OFAC's. Reporting obligations and the consequences of non-compliance vary by member state, because each EU jurisdiction has its own competent authority and its own penalty regime. A group with entities in multiple EU member states may face parallel obligations in each. The EU apparent violation assessment service at Calder & Vance addresses this multi-authority dimension.

Switzerland (SECO), Singapore, and other regimes that have adopted autonomous sanctions lists similarly have their own reporting expectations. There is no universal "global VSD" mechanism. For businesses with a footprint in Singapore, our post-breach remediation guide for Singapore sets out the local framework. For Swiss SECO obligations, see our SECO remediation guide.

The principle that the stricter prohibition governs applies across regimes: where a transaction is caught by both OFSI and OFAC, the more restrictive requirement determines the floor for remediation. In practice, that usually means running the OFAC analysis first, because its territorial reach and penalty exposure are typically broader.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact us at info@caldervance.com to discuss a confidential assessment.

Step 5: Build and implement the corrective-action programme

A credible corrective-action programme addresses three things: the immediate cause of the breach, the systemic weaknesses that allowed it, and the measures now in place to prevent recurrence. OFSI's enforcement guidance treats the existence and quality of a remediation plan as a relevant factor in penalty decisions.

Root-cause analysis should be honest and specific. If the breach occurred because screening was not run on the ultimate beneficial owner, the corrective action must address UBO screening – not simply state that "screening procedures have been reviewed." OFSI and other regulators are familiar with the difference between a genuine programme overhaul and a box-ticking exercise.

Typical corrective-action elements include:

  • Enhancement of screening systems and data sources to capture ownership and control chains, not just direct counterparty names
  • Revised internal procedures with clear escalation triggers
  • Training for front-line, compliance, and senior-management staff
  • Periodic testing of the revised controls, with documented results
  • Governance changes to ensure that the compliance function has sufficient authority and resources

The programme should be documented and time-bound. Where external remediation advisers are engaged, their scope and outputs should be recorded. OFSI may ask for evidence of implementation, not just a plan.

In a recent matter, a regulated financial-services business discovered that payments to a group of companies had been processed over several months without screening the group's ultimate parent. We assessed the ownership chain, scoped the apparent violations, advised on VSD structure, and supported the design of a revised UBO-screening programme. The matter progressed through the OFSI review process. No outcome is guaranteed by the steps described here, but the quality and promptness of the corrective action are factors the regulator considers.

Step 6: Manage the ongoing OFSI engagement

Once OFSI is engaged – whether through a VSD or through a formal information request – the quality of the firm's ongoing co-operation becomes a key variable. OFSI's guidance identifies co-operation with the investigation as a mitigating factor. Co-operation means timely, accurate, and complete responses to information requests; it does not mean volunteering damaging material that was not requested, nor does it mean withholding information that was.

OFSI has a range of outcomes available to it. It can take no further action, issue a warning, publish a case summary (a public notice of the breach and OFSI's response, which does not itself carry a monetary penalty), or impose a civil monetary penalty. Where it proposes a penalty, the firm has the right to make representations before a final decision is issued. That representation stage is a significant procedural opportunity and should be prepared with care.

Ministerial oversight is a feature of the OFSI enforcement process that distinguishes it from the OFAC model: certain penalty decisions require Treasury ministerial sign-off. In practice, this adds a layer of process and a point at which the firm's remediation narrative must be coherent and well-evidenced.

Record-keeping obligations continue throughout. Under SAMLA and the relevant thematic regulations, firms are expected to maintain records sufficient to demonstrate compliance and to make them available to OFSI. In our practice, we advise clients to treat OFSI engagement as a managed process, with each response and each piece of correspondence reviewed before it is sent.

Common risk flags and the myth that self-reporting always makes things worse

The single most persistent objection we encounter is this: "If we report, we are admitting the breach and handing OFSI a case." That objection misunderstands how OFSI's enforcement process works.

OFSI already receives information from multiple sources – regulatory returns, suspicious-activity reports, correspondent-bank notifications, and cross-referrals from other agencies. A business that discovers a breach and stays silent is not invisible; it is simply not in control of how the breach comes to OFSI's attention. A VSD that reaches OFSI before those other sources is treated differently from one that arrives after. The difference in outcome can be material.

Other risk flags in the remediation process:

  • Delayed response: the longer the gap between discovery and internal action, the harder it is to demonstrate that the response was prompt. OFSI's enforcement guidance treats promptness as a mitigating factor; delay reads as the opposite.
  • Incomplete disclosure: a report that addresses only some of the instances, or understates the value, is worse than one that covers everything. OFSI cross-checks against transaction records and may already hold data that a partial disclosure contradicts.
  • Inadequate privilege management: internal emails written before counsel is engaged, speculating about liability or blame, can become disclosable in adversarial proceedings. Involve counsel early and conduct sensitive analysis under privilege.
  • Overlooking the US nexus: where the transaction involved a US correspondent or US-origin goods, OFAC exposure may run in parallel. Addressing only OFSI without analysing the OFAC position creates a residual risk.
  • Corrective action that does not survive scrutiny: a programme that looks good on paper but does not change actual screening outcomes will not satisfy OFSI and will not protect the firm in the event of a repeat breach.

Related practices

Frequently asked questions

What are the steps to build a remediation plan under OFSI?
A remediation plan under OFSI should address four elements in sequence: a documented root-cause analysis identifying why the breach occurred; a corrective-action programme with specific, time-bound measures; evidence of implementation (not just commitment); and governance changes to ensure the compliance function has sufficient authority. OFSI's enforcement guidance treats the quality and credibility of the remediation plan as a factor in penalty decisions. A plan that describes generic process improvements without linking them to the specific cause of the breach will carry less weight than one that is direct and evidence-based.
What is the most common mistake in remediation after a sanctions breach?
The most common mistake is delay – specifically, a gap between discovery and internal action that allows additional transactions to occur or evidence to become stale. The second most common error is an incomplete voluntary self-disclosure: a report to OFSI that covers only part of the conduct, or that understates its value or duration. Both mistakes signal to OFSI that the business did not take the matter seriously once it was identified, which works against the firm at the penalty-setting stage. Involve sanctions counsel as soon as the breach is identified; do not wait for the internal review to conclude before taking the reporting decision.
How does OFSI differ from other regimes here?
OFSI's VSD mechanism operates under a broadly discretionary enforcement framework, with ministerial oversight of certain penalty decisions – a feature absent from the OFAC model. OFAC's process is more rule-based, with published penalty matrices and a clear distinction between egregious and non-egregious cases. EU member states each have their own competent authority and penalty regime, so there is no single EU disclosure mechanism. The practical implication for a cross-border business is that a VSD to OFSI does not satisfy obligations that may run in parallel under OFAC or in one or more EU jurisdictions; each regime must be addressed on its own terms.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.