Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · cross-border

How to respond to an information request across regimes

An enforcement investigator at OFAC, OFSI, or the European Commission sends your compliance team a formal letter. It asks for documents, explanations, and data across entities in multiple jurisdictions. The window to respond is short. Which regime governs the response? What must be produced? And what happens if your answer in one jurisdiction compromises your position in another?

Responding to regulator information requests across a cross-border footprint requires a coordinated strategy. No single playbook applies: OFAC, OFSI, the EU Council enforcement mechanism, BIS, and the UN Sanctions Committee each operate distinct procedural rules, timelines, and confidentiality standards. Getting the sequencing wrong – or producing documents to one authority that another jurisdiction treats as privileged – can turn a manageable inquiry into a multi-front enforcement matter.

This responding to regulator information requests cross-border guide sets out the key steps, the regime-by-regime obligations, the practical risk flags, and the moments when engaging sanctions counsel is not optional.

Step 1: Identify the requesting authority and the legal basis for the request

The first action is to identify exactly which authority has issued the request and under what legal basis it operates – because that determines everything that follows, including your timeline, your privilege position, and whether you have grounds to narrow the scope.

Different authorities derive their powers from different instruments. OFAC issues administrative subpoenas and information requests under IEEPA and other applicable US statutes. BIS can compel production under the Export Control Reform Act. OFSI issues requests under the powers granted by SAMLA and the relevant thematic sanctions regulations. EU enforcement is typically initiated at member-state level, though the Council can request information in the context of a listing or de-listing review. The UN Security Council committees work through member states rather than directly against private parties, but a request routed through a national authority carries the same practical weight.

In our cross-border practice, the first mistake we regularly see is an assumption that all information requests are broadly equivalent. They are not. An OFAC administrative inquiry carries criminal referral risk if the response contains materially false statements. OFSI's information-gathering power is civil in character at the administrative stage but can escalate to criminal investigation. The EU general court can receive evidence produced in the context of a Council review. Knowing the legal instrument behind the letter shapes every subsequent decision.

Practical step: before drafting a single line of response, map the requesting authority, the empowering instrument, the express or implied deadline, and the sanction for non-compliance or for a late or incomplete response. Record this in a matter log from day one.

Step 2: Scope the request and identify the cross-jurisdictional exposure

Once the authority is identified, the next step is to scope the actual request – and to identify immediately which other jurisdictions are implicated by the facts, the entities, or the transactions under inquiry.

A request from OFAC about a payment routed through a US correspondent bank may simultaneously implicate the EU entities that originated the instruction, UK branches that processed it, and a Singapore subsidiary that held the underlying contract. Each of those jurisdictions has its own enforcement authority with its own powers. None of them co-ordinates automatically with OFAC. The risk is not theoretical: a voluntary disclosure to OFAC that reveals conduct also visible to OFSI can trigger a parallel UK investigation that you have not yet managed.

The scoping exercise should identify, at minimum: all legal entities involved in the transaction or conduct under review; the jurisdictions in which those entities are incorporated, licensed, or operate; the regimes that apply to the underlying activity (OFAC programme, EU Council regulation, OFSI designation, BIS entity-listing, or a combination); and any data-protection or bank-secrecy rules that restrict what can be transmitted across borders. Switzerland's bank-secrecy rules and EU data-protection obligations, for example, can constrain document production in ways that create tension with a US subpoena.

As of early 2026, the enforcement posture across OFAC, OFSI, and EU member states reflects a pattern of informal co-operation. Authorities share information about targets and transactions through bilateral and multilateral channels. A response that is factually inconsistent across jurisdictions – even inadvertently – creates a significant credibility problem.

Step 3: Assess privilege, confidentiality, and blocking-statute risks before producing documents

Before a single document is produced, the legal-privilege position must be established in each relevant jurisdiction – because privilege is not uniform and is not automatically reciprocal across the regimes in scope.

In the United States, attorney-client privilege protects confidential communications between a lawyer and client made for the purpose of obtaining or giving legal advice. Work-product protection covers materials prepared in anticipation of litigation. Both apply in an OFAC inquiry. However, in-house counsel communications may receive narrower protection under US doctrine than they would under English law or EU law. The EU General Court applies a narrower external-counsel-only privilege under what is sometimes called the AM&S principle – in-house lawyer communications are generally not privileged before EU courts and institutions. OFSI operates under English law principles, which extend privilege more broadly to in-house counsel in some circumstances, but the position requires case-by-case analysis.

Blocking statutes add a further layer of complexity. The EU Blocking Regulation – which applies to EU-incorporated entities – restricts compliance with US secondary-sanctions requirements and related information demands in certain circumstances. This does not mean that EU entities can simply ignore a US request, but it does mean that producing documents under a US subpoena without analysing the Blocking Regulation first creates legal exposure in the EU. We regularly advise on this precise tension, and it is one of the most consistently underestimated risks in a cross-border response.

Data-protection rules in the EU and UK impose additional constraints on the transfer of personal data to a foreign authority. A mass document production to OFAC that includes personal data of EU employees may need to be structured carefully to avoid breaching the applicable data-protection regime. Japan, Singapore, and the UAE each have their own data-transfer restrictions that compound this analysis.

The position above covers the standard case. Your facts – the requesting authority, the entities, the data involved, and the jurisdictions in play – change the analysis materially. For a case-specific assessment of your privilege and confidentiality position, contact Calder & Vance at info@caldervance.com.

Step 4: Decide whether to make a voluntary self-disclosure alongside the response

A formal information request often arrives because the authority has already identified conduct it considers potentially non-compliant. The question of whether to make a voluntary self-disclosure (VSD – a proactive report to the regulator of an apparent violation, made before the authority identifies it independently) is one of the most consequential decisions in the entire matter.

Under OFAC's civil enforcement guidelines, a timely, complete, and accurate VSD is a significant mitigating factor. OFSI operates under similar principles in its published enforcement guidance. The EU does not operate a single centralised VSD mechanism; member-state authorities vary significantly in how they treat self-reporting. BIS has its own voluntary self-disclosure procedure for export-control matters, which runs separately from OFAC even where the same transaction is at issue.

The decision is not straightforward. A VSD that discloses conduct in one jurisdiction can create evidence that another authority uses in its own proceedings. A VSD to OFAC does not bind OFSI. An admission in an EU-facing document does not operate as a formal admission before a US court, but it creates a factual record. The timing of a VSD relative to an outstanding information request also affects how the authority will characterise the disclosure: a VSD filed after an authority has formally identified an issue may receive less mitigation credit than one filed before the inquiry crystallises.

In a recent matter, a financial institution in the payments sector received an OFAC information request concerning a series of transactions processed through a US correspondent. We scoped the request, mapped the parallel OFSI exposure, assessed the VSD question in both jurisdictions, and structured a coordinated response that addressed both authorities' timelines without creating inconsistency. The matter was resolved at the administrative stage. No outcome of a similar kind is guaranteed, but early co-ordinated engagement with the multi-regime picture consistently produces better results than responding to each authority in isolation.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact us at info@caldervance.com to discuss the VSD question and the response strategy.

Step 5: Build the response – content, format, and tone across regimes

The response document itself must be accurate, complete, and carefully calibrated to the specific requests made – no more, no less. Over-production is a risk as well as under-production.

OFAC requests typically ask for transactional data in specific formats: wire-transfer records, SWIFT messaging, account information, corporate-structure charts, and certifications from officers. Completeness is assessed against the express terms of the request. Where documents are withheld on privilege grounds, a privilege log is expected. A response that asserts privilege without explaining the basis is likely to result in a follow-up request and a narrowing of any goodwill built up in the initial engagement.

OFSI requests tend to be written in broader terms and may ask for a narrative account of the events alongside supporting documents. The English-law context means that the response reads as a formal written statement, and its contents can be relied upon in subsequent proceedings. OFSI's enforcement guidance addresses the evidential weight it gives to responses, and a response that is internally inconsistent or that contradicts contemporaneous documents will be treated adversely.

EU and member-state requests vary significantly in form, but the common thread is the expectation of co-operation. A response that stonewalls or takes unnecessarily narrow positions on scope is more likely to escalate than one that engages substantively with the authority's concerns, within appropriate limits.

For BIS matters, the format of the response to an administrative inquiry follows BIS procedure, and the content must address the specific statutory elements of any alleged export-control violation. BIS and OFAC can and do run parallel inquiries on the same facts; a response to BIS that characterises the underlying transaction differently from the OFAC response creates an obvious consistency risk.

Across all regimes, the tone of the response matters. Authorities are run by human beings who exercise discretion. A response that is professionally presented, factually precise, and engages directly with the authority's concern is read differently from one that is defensive or evasive in register.

Step 6: Manage post-response engagement and monitor for parallel proceedings

The submission of a response is rarely the end of the matter. Post-response engagement – follow-up questions, requests for supplemental documents, meetings or calls with the authority, and monitoring of any parallel proceedings in other jurisdictions – requires the same disciplined approach as the initial response.

Authorities routinely issue supplemental requests after reviewing an initial response. Each supplemental request should be treated with the same mapping exercise as the original: is new material now in scope? Does the supplemental request reveal that the authority has information from another source? Has the exposure in a parallel jurisdiction changed?

Record-keeping across the full lifecycle of the inquiry is essential. In our experience, matters that start as routine information requests and escalate to enforcement proceedings often turn on the quality of the contemporaneous record. A matter log that captures every communication, every decision made in the response process, and the legal basis for each decision is the foundation of any enforcement defence. Under the applicable regimes, record-keeping obligations for sanctions-related matters typically extend over a period of several years; the specific period should be verified against the relevant regime's current rules.

Where parallel proceedings are running in multiple jurisdictions, a co-ordination protocol should be established early. This does not mean that the responses need to be identical: different authorities ask different questions. But it does mean that the factual narrative across the responses must be consistent, and that admissions or characterisations in one response should be reviewed before they appear in another.

Related practices

Common risk flags and the myths that create them

Two risk patterns appear in almost every cross-border information-request matter we handle. The first is the assumption that a response to one authority closes the matter. It does not. A satisfactory resolution with OFAC has no legal effect on OFSI's position, and a clean close with BIS does not extinguish EU risk on the same facts.

The second – and more costly – risk is the myth that only large-scale, intentional violations attract cross-border regulatory attention. In practice, procedural errors in the response process itself – late production, inconsistent statements, inadvertent waiver of privilege, failure to flag a parallel exposure – can transform a minor technical violation into a more serious enforcement matter. The size of the underlying transaction is not the primary driver of regulatory escalation. The quality of the response often is.

A related misconception is that a business with no US nexus is insulated from OFAC reach. Secondary-sanctions risk and the extraterritorial application of US export-control rules mean that businesses operating entirely outside the United States may still receive OFAC or BIS inquiries if their transactions involved US-origin goods, US technology, US dollars, or US-connected counterparties. The applicable US rules extend jurisdiction well beyond the territorial boundary, and ignoring an OFAC information request on the basis that the business is not US-incorporated is a serious procedural error.

Is your team aware of the parallel regime exposure before it files the first response? That question is worth asking on day one, not after the supplemental request arrives.

When to involve cross-border sanctions counsel

Counsel should be involved before the response is drafted, not after the first draft has been sent. This is the single most consistent finding from our enforcement-defence practice.

The moment a formal information request arrives from OFAC, OFSI, the EU, BIS, or any other sanctions or export-control authority, the clock starts. Response windows vary by regime and by the terms of the specific request, but they are rarely long. Early engagement with counsel allows the privilege position to be established, the cross-jurisdictional exposure to be mapped, the VSD question to be assessed, and the response to be structured with the enforcement outcome in mind.

Specific triggers for immediate engagement include: a request that references specific transactions, specific named individuals, or specific listed entities; a request that is accompanied by an asset freeze or an export-denial order; a request that arrives in more than one jurisdiction simultaneously; or any situation in which a business is unsure whether the underlying conduct constitutes an apparent violation. The last category is the most common. In our experience, the businesses that fare best in cross-border information-request matters are those that treat the inquiry as a legal proceeding from the moment it arrives – because, in a material sense, it is.

For a confidential review of a potential breach or a formal information request, contact Calder & Vance at info@caldervance.com.

Frequently asked questions

What are the steps to respond to an information request under cross-border?
The core steps are: identify the requesting authority and its legal basis; scope the request and map cross-jurisdictional exposure; assess privilege, confidentiality, and blocking-statute positions before producing anything; decide on voluntary self-disclosure where relevant; build a response that is complete, accurate, and consistent across regimes; and manage post-response engagement and any parallel proceedings. Each step should be documented in a matter log. Counsel should be engaged before the response is drafted, not after.
What is the most common mistake in responding to regulator information requests?
The most common mistake is responding to each authority in isolation, without mapping the parallel exposure in other jurisdictions. A response to OFAC that is factually inconsistent with contemporaneous documents, or that inadvertently waives privilege in a way that OFSI can later exploit, turns a manageable inquiry into a multi-front enforcement matter. The second most common mistake is treating the submission of the initial response as the end of the process. Post-response engagement and monitoring of parallel proceedings require the same rigour as the initial filing.
How does cross-border differ from other regimes here?
A purely domestic information request involves one authority, one set of procedural rules, and one privilege standard. A cross-border matter involves multiple authorities, potentially divergent privilege doctrines, blocking-statute conflicts, data-protection constraints on document production, and VSD mechanisms that do not co-ordinate with each other. The EU Blocking Regulation, US secondary-sanctions extraterritoriality, and OFSI's civil-penalty powers can each apply to the same underlying facts. Managing the interaction between those regimes – rather than responding to them sequentially – is the defining challenge of a cross-border enforcement matter.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.