Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · UN

Remediation after a sanctions breach under UN: step by step

A trading company's compliance team runs a routine ownership check three days before a scheduled payment. The beneficial owner of the counterparty appears on the UN Consolidated List (the list of individuals and entities subject to measures imposed by United Nations Security Council resolutions). The payment is on hold. The question that lands on the General Counsel's desk within the hour is not merely whether the transaction is blocked – it is what the business must do next, and in what order, to manage its exposure across every jurisdiction where it operates.

Remediation after a sanctions breach under the UN regime is a multi-layered process. The UN Security Council sets the underlying prohibitions through binding Chapter VII resolutions, but enforcement and reporting obligations are implemented at the national level by each UN Member State. That means a single apparent breach can trigger parallel obligations under OFAC, OFSI, the EU Council regulations, and the applicable country regime wherever the business has a presence – all running simultaneously and with different deadlines.

This guide walks through the remediation process step by step: from the moment a potential breach is identified through internal escalation, regulatory reporting, voluntary self-disclosure, programme repair, and the long-term record-keeping that protects the business if the matter is ever revisited.

Step 1 – Immediate containment: what to do in the first hours

The first action after identifying a potential breach is to stop any further prohibited activity and preserve the evidence. This is not about making a final legal determination. It is about ensuring that the business does not compound an apparent violation while the facts are still being gathered.

Practical containment means three things at once. First, freeze any pending transactions that touch the same counterparty, beneficial owner, or affiliated entity. Second, ensure that the individuals who identified the issue are documented as having done so – the date, the time, the method of discovery. Third, place a litigation hold on all relevant records: correspondence, payment instructions, screening logs, ownership documentation, and any prior due-diligence reports on the counterparty.

In our experience, the greatest damage done in the first 24 hours is not to the regulatory position – it is to the evidentiary record. Employees overwrite screening results, email chains are deleted in routine archiving, and ownership documents are returned to counterparties who then become uncooperative. A containment checklist issued immediately by legal or compliance, before anyone contacts the counterparty, avoids these problems.

One question that arises immediately: should the counterparty be told? In most cases the answer is no – at least not until counsel has reviewed the position. Notifying a counterparty whose beneficial owner is listed may itself raise concerns under the applicable country regime's tipping-off or obstruction rules. Wait for legal advice before making contact.

Step 2 – Internal fact-gathering: mapping the breach against the UN regime

The second step is a structured internal investigation to determine exactly what happened, under which authority it is prohibited, and which jurisdictions are engaged. The UN Consolidated List is the starting point, but it is rarely the only relevant instrument.

The UN Security Council imposes asset freezes, travel bans, and arms embargoes through binding resolutions. Each thematic committee – covering, for example, proliferation-related matters or specific country programmes – maintains its own sub-list and its own set of exceptions and humanitarian carve-outs. When mapping the breach, the analyst must identify which committee's measures apply, what the exact prohibition covers, and whether any standing exemption could apply in the circumstances.

The cross-regime dimension is unavoidable here. A payment that breaches a UN Security Council asset freeze will almost certainly also breach the parallel implementing measures adopted by the business's home jurisdiction. OFAC implements UN measures through its own programme regulations. OFSI implements them through the UK's relevant thematic sanctions regulations made under SAMLA. The EU Council adopts a separate implementing regulation. Switzerland's SECO issues a corresponding ordinance. These are not identical instruments. The definition of the prohibited counterparty, the available exemptions, and the reporting obligations can all differ in ways that matter for remediation strategy.

The fact-gathering exercise should produce a written internal record covering: the nature of the transaction or activity; the listed party or entity captured by the UN Consolidated List; the date the activity occurred and the date it was discovered; the jurisdictions engaged; and a preliminary assessment of whether any exception or authorisation might apply. That document is privileged if prepared under legal direction and forms the foundation of everything that follows.

Step 3 – Regulatory reporting obligations and how they differ by regime

Reporting a potential breach to the relevant national authority is, in most UN-implementing jurisdictions, a legal obligation – not a voluntary choice. The practical challenge is that the reporting deadline, the reporting format, and the authority to whom the report must be made all differ between regimes, and several deadlines can run concurrently.

Under the UK regime, OFSI's reporting guidance requires that a person who knows or suspects that they are in possession of frozen funds or are dealing with a designated person must report to OFSI as soon as practicable. The window is short. OFSI also expects firms to report any suspected breach even where the firm itself is not the principal actor – for example, where a correspondent bank route was used. Missing this window does not merely create a reporting-compliance problem; it is itself a potential criminal offence under the relevant thematic sanctions regulations.

Under the OFAC regime, firms that discover a potential sanctions violation face separate disclosure considerations. OFAC operates a voluntary self-disclosure (VSD) mechanism under which a firm that self-reports an apparent violation, cooperates fully, and demonstrates effective remediation can achieve a significant reduction in the base civil penalty. The EO-authorised enforcement guidelines that OFAC applies identify timely VSD as an important mitigating factor. The submission must be made within a defined period of discovering the violation – verify the current deadline before relying on it, as OFAC guidance is updated periodically.

For businesses with EU operations, the applicable EU Council regulation will typically require that any breach involving frozen assets or circumvented restrictions be reported to the competent national authority of the relevant Member State. The format and timing vary by Member State. In our practice, we have seen compliance teams submit to one jurisdiction and assume that satisfies the group – it does not. Each jurisdiction must be reported to independently, and the reports must be consistent with one another.

The UN Security Council itself does not receive breach reports from private entities. It receives information from Member States through their national focal points, through the relevant committee's panel of experts, and through the Ombudsperson mechanism for the specific committee that administers the ISIL and Al-Qaida list. For most businesses, the reporting obligation is entirely at the national level.

Step 4 – Voluntary self-disclosure: when to disclose and how to structure the submission

Voluntary self-disclosure is one of the most consequential decisions in the remediation process. Done well, it can substantially reduce penalty exposure and establish the narrative that the business detected the issue through its own controls, acted responsibly, and is a credible compliance partner for the regulator. Done badly, it can expand the investigation's scope, raise questions the regulator had not yet asked, and foreclose negotiating positions.

The threshold question is whether VSD is legally mandated or genuinely voluntary in the relevant jurisdiction. As noted above, in the UK and several EU Member States, reporting is mandatory once the threshold is met. In the US, VSD to OFAC is voluntary in the technical sense – OFAC's enforcement guidelines do not require it – but the penalty mitigation it generates is substantial, and regulators do not look favourably on businesses that appear to have made a calculated decision not to disclose.

The structure of a VSD submission matters. A strong submission identifies the apparent violation with precision; explains the facts in a neutral, chronological narrative; sets out the steps already taken to contain the breach; provides a candid assessment of the root cause; and presents the remediation measures already implemented or committed to. It does not speculate about intent, assign blame to individuals by name, or make legal arguments that the violation did not occur – that territory is for the penalty defence phase, not the initial disclosure.

In a recent matter, a financial institution with operations across multiple UN-implementing jurisdictions discovered that a correspondent payment had been processed through an intermediary whose beneficial owner had been listed for several months. We prepared coordinated submissions to three separate regulators, timed to land within hours of one another, with consistent factual narratives and jurisdiction-specific remediation appendices. The approach avoided contradictory accounts reaching regulators who routinely share information with one another under mutual legal-assistance frameworks. The matter was resolved without a public enforcement action being commenced.

Step 5 – Remediation programme design: the five-element standard

Regulators in every major UN-implementing jurisdiction evaluate remediation against a broadly consistent five-element standard: governance, policies and procedures, controls and screening, training, and testing. A credible remediation submission must address all five.

Governance. The board or senior management must visibly own the compliance obligation. This means a board-level resolution acknowledging the breach, assigning accountability to a named senior officer, and establishing a formal oversight mechanism for the remediation programme. Regulators look for evidence that the compliance function has the authority and resource to implement the programme without commercial interference.

Policies and procedures. The breach analysis will have identified the policy gap or procedural failure that allowed the violation to occur. The remediation plan must address that gap with specificity. A generic policy update is not sufficient. If the gap was in the ownership-and-control analysis – for example, if the business screened only direct counterparties and not beneficial owners – the revised procedure must address that exact failure with a defined methodology and a clear ownership mapping requirement.

Controls and screening. The technical screening infrastructure must be tested against the scenario that produced the breach. If a listed person's name was not matched because of transliteration variations or a fuzzy-match threshold set too conservatively, the control must be adjusted and re-tested. The test results should be documented and retained.

Training. The individuals who handled the breached transaction, and any others with equivalent responsibilities, must receive targeted training on the specific regulatory gap identified. Generic annual sanctions training does not satisfy this element. Training records must be retained.

Testing and audit. The remediated controls must be subject to independent testing – either by a qualified internal audit function or by external counsel – before the remediation plan is certified as complete. The test protocol and results should be documented. In our experience, regulators increasingly request the testing methodology and results as part of the penalty-resolution process.

Step 6 – Record-keeping obligations and why they outlast the incident

The remediation process generates a large volume of documentation: the initial containment record, the internal investigation report, the regulatory submissions, the correspondence with the authority, the revised policies, the training records, and the testing results. Each of these documents must be retained for the period required by the applicable country regime.

Under OFSI's guidance, records relating to a potential sanctions breach should be retained for a period consistent with OFSI's enforcement and investigation powers. Under OFAC's framework, the relevant record-keeping obligation under the applicable programme regulations runs for a defined period from the date of the transaction. Under the EU Council regulations, record-keeping requirements are set in each implementing instrument. Across most regimes, the period is measured in years from the date of the activity – not the date of the remediation. Verify the current requirement for each jurisdiction before determining your retention schedule.

One record-keeping failure we see frequently: businesses retain the final submissions to regulators but not the working papers that produced them. If the regulator returns to the matter – as part of a follow-up enquiry, a successor investigation, or a request under an international information-sharing arrangement – the working papers are often more useful than the polished submission. They demonstrate the methodology, the decision points, and the good-faith reasoning that produced the final account. Retain both.

Common myths and risk flags in post-breach remediation

The most persistent myth in sanctions remediation is that a small transaction value means a small regulatory problem. It does not. The UN Security Council's asset-freeze obligations are absolute prohibitions: the quantum of the transaction is relevant to calculating a civil penalty base, but it does not determine whether a violation occurred or whether it must be reported. We regularly advise businesses that are surprised to learn that a modest payment – one that would not register as commercially significant – has triggered reporting obligations in four jurisdictions simultaneously.

A second myth: that the UN regime is less rigorously enforced than OFAC or OFSI, so remediation can proceed at a slower pace. This misreads how the enforcement chain works. The UN Consolidated List provides the designation basis; national implementing authorities carry out the enforcement. OFAC enforces UN-derived asset freezes through its own programme regulations with the same enforcement tools it applies to autonomous US designations. OFSI does the same. The pace of national enforcement is set by national authority, not by the UN committee.

Risk flags that escalate a remediation from routine to urgent:

  • Any indication that the breach was not accidental – a record of prior alerts being dismissed, a pattern of similar transactions, or evidence that the counterparty was aware of the listing.
  • A counterparty in more than one jurisdiction's implementing regime, which multiplies the reporting and penalty exposure.
  • A business operating in a sector subject to heightened regulatory scrutiny – financial services, energy, defence supply chains – where the relevant supervisor may already have concerns about the sanctions controls in place.
  • Prior enforcement contact with any of the relevant national authorities, which will aggravate the penalty assessment under the applicable guidelines.
  • A gap between the date of the breach and the date of discovery that is longer than the internal controls should have permitted, which raises questions about the adequacy of the screening programme.

When any of these flags are present, involve external counsel immediately. The remediation submission is not a form-filling exercise; it is the document that will define the firm's narrative with the regulator for the duration of the enforcement process.

Related practices

Frequently asked questions

What are the steps to build a remediation plan under UN?
A remediation plan under the UN regime begins with an internal investigation to map the breach against the Consolidated List and all applicable national implementing instruments. The five core elements are governance accountability, revised policies and procedures, updated screening controls, targeted staff training, and independent testing. Each element must be documented and capable of being produced to the relevant national authority – OFAC, OFSI, the applicable EU Member State authority, or others – on request. The plan should also include a communication strategy for regulatory submissions and a defined record-keeping schedule for all remediation documentation.
What is the most common mistake in remediation after a sanctions breach?
The most common mistake is treating the remediation as a single-jurisdiction problem. Because the UN Consolidated List is implemented by every Member State through national legislation, a business with operations or financial flows in more than one country faces parallel reporting and remediation obligations that run concurrently, with different deadlines and different procedural requirements. Submitting a disclosure to one authority and assuming it satisfies the group-wide obligation is an error we see regularly. It does not; and an inconsistent account across jurisdictions compounds the original violation.
How does UN differ from other regimes here?
The UN regime is distinctive because the Security Council sets the underlying designation standard, but all enforcement is carried out by national authorities implementing the resolutions through domestic law. There is no UN-level mechanism for private businesses to report breaches, seek licences, or negotiate penalties. That means remediation must be managed jurisdiction by jurisdiction, engaging OFAC, OFSI, the relevant EU Member State authority, SECO, or whichever national bodies are engaged by the business's footprint. The practical consequence is that multi-jurisdictional coordination – ensuring consistent submissions and avoiding contradictory accounts – is the central challenge in UN-related remediation in a way that does not arise to the same degree in a single-regime domestic breach.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.