A European trading company receives a written enquiry from its national competent authority. The letter asks for contracts, payment records, and counterparty documentation relating to a specific transaction. The compliance team has never dealt with a formal regulatory information request before. What exactly must they produce? How quickly? And what do they say when the records are incomplete?
Responding to regulator information requests under the EU sanctions regime is a structured legal obligation, not a discretionary courtesy. Member-state competent authorities derive their powers from the relevant EU Council regulations and from transposing national legislation. Responses must be accurate, timely, and – critically – must not prejudice any parallel investigation. Failing to respond correctly can convert a potential compliance issue into a verified breach.
This guide walks through the process step by step: the governing authority and legal basis, the immediate triage a business should run, the documentation and privilege questions, the cross-regime dimension, the most common errors, and when to bring in external sanctions counsel.
Who administers EU sanctions information requests, and what is the legal basis?
EU sanctions are administered at two levels: the Council of the European Union sets the regime through Council regulations and Council decisions, while enforcement – including information-gathering – is delegated to the competent authority in each Member State. In practice, this means that a German business receives its request from BaFin or a designated authority under German national law, while a Dutch entity deals with the Dutch central bank or a comparable body. The EU Council regulation in force for the relevant regime is the primary instrument; it obliges businesses to cooperate fully and to provide accurate information on request.
This decentralised structure creates a practical complication. The underlying prohibition and the definitions of "funds", "economic resources", and "designated person" are uniform across the EU. The enforcement procedure – timing, form, and consequence of non-response – is governed by national law. A business operating across several Member States may receive simultaneous requests from different authorities, each with its own procedural rules. We regularly advise clients that the first task is identifying which national regime applies and what the competent authority's own procedural guidance says.
One concrete point worth anchoring early: EU financial-sanctions designations appear on the EU Consolidated List, which is maintained by the European External Action Service and is updated without advance notice. When an authority asks about a specific counterparty, confirm its listing status as of the transaction date, not just today's date.
Step 1 – Triage the request before you respond
Before anything else is done, the business must read the request carefully and categorise it. Is this a routine monitoring enquiry, a request linked to a specific suspected breach, or a formal demand linked to a live investigation? The distinction matters because the risk profile – and therefore the level of caution required – is different in each case.
Triage should address four questions. First, is the request legally valid? It should identify the authority, cite its legal basis, describe the information sought, and state the deadline. A defective request should be queried – politely, promptly, and in writing – before any document is produced. Second, do the records sought touch on matters that are subject to legal-professional privilege? Documents prepared for the purpose of obtaining legal advice, or prepared in contemplation of proceedings, may be privileged under the law of the relevant Member State; this must be assessed before disclosure.
Third, is any of the information sought subject to data-protection obligations that could constrain transmission? The EU data-protection framework operates alongside the sanctions regime, and a business cannot always produce personal data simply because a regulator has asked for it without following the correct gateway. Fourth, does the request overlap with any enquiry from another authority – whether in another Member State, from OFSI in the United Kingdom, or from OFAC in the United States? We have acted for businesses where a single transaction attracted attention from more than one regime simultaneously, and the disclosure strategy must be co-ordinated from the outset.
The position above covers the standard case. Your facts – the counterparty, the goods, the route, the regime in play – change the analysis. For a confidential review of a request your team has received, contact Calder & Vance at info@caldervance.com.
Step 2 – Assemble and preserve the documentary record
Once triage is complete, the business must preserve all potentially responsive documents and then assemble the specific records the authority has asked for. Preservation comes first. Deleting, altering, or allowing routine document-destruction processes to run after a formal request has been received can, in itself, constitute a serious aggravating factor in any subsequent enforcement action.
The documents typically sought in an EU sanctions information request fall into several categories. Screening records – including the screening tool used, the list version consulted, and the result – are almost always requested. Transactional documentation including contracts, invoices, shipping records, payment instructions, and correspondent-bank records will be sought where a transaction is under scrutiny. Ownership and control documentation relating to the counterparty may be required where the authority is investigating whether a non-listed entity is captured through the EU ownership and control test.
The EU ownership and control test – which the Court of Justice and the EU General Court have developed through a body of case law on annulment actions – is not purely mechanical. Unlike the OFAC 50 percent rule (which treats entities owned 50 percent or more by blocked persons as themselves blocked), the EU test encompasses both ownership and actual control. An entity may be caught even where no listed person holds a majority stake, if a designated person exercises decisive influence. This is a material distinction. When assembling documentation, businesses should present their analysis of the ownership chain clearly, with corporate registers, beneficial-ownership filings, and any UBO disclosures that are available.
Record-keeping obligations under EU Council regulations require that relevant records be retained for a defined period after the transaction. The precise retention period can vary depending on the sector, the Member State's transposing legislation, and any concurrent AML obligations; verify the applicable period under the national rules in force. As a practical matter, sanctions-related documents should be retained for at least as long as the longest applicable obligation across all relevant regimes.
Step 3 – Draft the response with care
The written response to an EU competent authority is not a legal pleading, but it carries legal weight. Every statement made in it can be referred to in any subsequent enforcement proceedings. Accuracy is therefore non-negotiable.
Structure the response to address each question or category of request in turn. Where documents exist and are not privileged, produce them. Where a document has been lost or destroyed in the ordinary course of business before the request arrived, say so clearly and explain the retention policy that governed it. Where a record shows what might look like a breach, do not attempt to minimise or explain it away in the covering letter before legal advice has been taken. In our experience, over-explanation in the initial response – volunteering conclusions before the facts are fully understood – is a significant source of avoidable difficulty.
The response should be submitted through the channel the authority has specified. If no channel is specified, written submission by recorded delivery, with a copy retained, is the safe default. Keep a full file of everything submitted: the covering letter, the exhibits, the proof of delivery, and the date. If the authority has given a deadline, meet it or seek an extension in writing before it expires.
Do not overlook the currency of the submission. If the transaction under review has already been the subject of an internal investigation, and that investigation produced conclusions, those conclusions may or may not be disclosable depending on whether they are covered by privilege. This assessment requires legal advice in each case.
Step 4 – Manage cross-regime exposure
For a business with operations in more than one jurisdiction, an EU competent authority's information request rarely sits in isolation. The same transaction may engage the UK sanctions regime administered by OFSI (the Office of Financial Sanctions Implementation), the US regime administered by OFAC, or both. Does your disclosure to the EU authority create a reporting obligation – or a risk of an adverse inference – under another regime?
Under OFSI's rules, a person who knows or suspects that they hold designated funds or economic resources has a reporting obligation. If the transaction under EU scrutiny also touches on a UK-designated person, the EU information-request process and the OFSI reporting obligation must be managed in parallel. Similarly, OFAC's voluntary self-disclosure framework has its own logic. A VSD (voluntary self-disclosure to a regulator) to OFAC can be a significant mitigant in a US enforcement outcome, but it needs to be co-ordinated with what has already been said or produced in the EU context. Inconsistency between disclosures to different authorities is a serious risk.
Secondary-sanctions exposure is a further dimension. Where the transaction involves a US-nexus – dollar clearing, a US-person counterparty, US-origin goods – OFAC may have jurisdiction over the same facts. In our cross-border practice, we structure disclosure strategies at the outset to ensure that nothing produced in one jurisdiction inadvertently prejudices the position in another. That requires a single co-ordinated view across all regimes, held from day one.
If a transaction has already been flagged or a filing has already been submitted to one authority, an early review can preserve options that narrow with time. Write to us at info@caldervance.com before the next submission is made.
Risk flags: what makes an EU regulator escalate?
Not every information request becomes an enforcement action. Competent authorities use information requests as a monitoring tool, and a well-managed response that is accurate and complete will, in most cases, allow the matter to close without further escalation. Several factors, however, reliably increase the risk of escalation.
Late or incomplete responses are the most common trigger. An authority that receives a partial response, or one that arrives after the deadline without explanation, will typically follow up with a more pointed demand. Where the follow-up also produces an incomplete response, the authority may conclude that records are being withheld. That inference – whether or not it is correct – can lead to a formal investigation.
Inconsistency between the information provided to the authority and information the authority has obtained from another source (such as a correspondent bank, a port authority, or another Member State's competent body) is a serious escalation trigger. EU competent authorities share information with each other and with OFSI under mutual-assistance arrangements. A business whose screening records state that the counterparty was clear at the time of the transaction, but whose bank records show that a payment was flagged and then released, has an apparent inconsistency that it must be ready to explain.
Screening failures where the counterparty was in fact listed at the time of the transaction are obviously the most serious risk flag. Where the EU authority's request is investigating exactly that question, the business should assume that the authority already has strong reason to believe a breach occurred. The response must be co-ordinated with legal privilege in mind from the outset.
Common misconceptions about EU information requests
One persistent myth is that an information request is a sign the authority intends to impose a penalty. It is not. The majority of EU sanctions information requests arise from routine monitoring, from financial-intelligence reports generated by correspondent banks, or from cross-border information-sharing between Member States. Many are resolved at the information-gathering stage with no further action. The risk lies in responding badly, not in having received the request.
A second misconception is that co-operating fully will necessarily worsen the outcome if a breach did occur. In our experience, the opposite is closer to the truth. EU competent authorities – and the enforcement frameworks of the relevant Council regulations – treat co-operation, voluntary disclosure, and remediation as material mitigating factors. A business that identifies a past breach, responds honestly, and takes credible remediation steps is in a materially better position than one that provides a partial or evasive response and leaves the authority to reconstruct events independently.
A third misconception is that small or low-value transactions are below the threshold of regulatory concern. There is no de minimis threshold in EU sanctions prohibitions. An economic resource of any value transferred to a designated person is prohibited. Competent authorities have pursued enforcement actions based on transactions of modest financial value. Calibrate your response to the legal obligation, not to the size of the deal.
Related practices
- EU apparent violation assessment – structured review of potential EU sanctions breaches before regulator contact
- Responding to information requests – Japan regime guide – step-by-step guide for the comparable process under the Japanese sanctions regime
- Responding to information requests – OFAC guide – the equivalent process under the US OFAC regime, including VSD considerations