A multinational's compliance team receives a letter from the US Treasury's Office of Foreign Assets Control. The tone is formal. The deadline is short. The request asks for transaction records, counterparty details, and internal communications stretching back several years. No one on the team has handled this before. What happens next – and how it is handled in the first seventy-two hours – can determine whether the matter closes as a cautionary lesson or escalates into a formal enforcement proceeding.
An OFAC information request is a formal demand by the regulator for documents, records, or written explanations relating to a potential sanctions violation or a pending licence review. The governing authority is OFAC under its powers derived from IEEPA and related statutes. The response window is typically short, the scope of required disclosure is broad, and the manner of response – including whether a voluntary self-disclosure (VSD) (a proactive, pre-enforcement report of an apparent violation) is warranted – has direct consequences for any eventual penalty assessment.
This guide walks through each phase of the response process, from the moment the letter arrives to the point at which the matter is resolved or referred for further proceedings. It also sets out where OFAC's approach diverges from comparable regimes – OFSI in the United Kingdom, and the EU enforcement structure – so that businesses with multi-jurisdictional exposure understand where the procedural differences bite.
Step 1: Understand what you have received and who it is from
The first task is to identify the precise nature of the communication, because OFAC issues several distinct categories and each requires a different initial response. An administrative subpoena or formal information demand differs from a courtesy inquiry or a licensing follow-up, and conflating them is a common early error that wastes time and can signal institutional confusion to the regulator.
OFAC's enforcement correspondence typically falls into one of three types. First, a request for additional information in connection with an existing licence application or a pending transaction query – these are administrative and relatively routine. Second, a pre-penalty or penalty-related inquiry, where OFAC is gathering facts relevant to a potential or formal Notice of Apparent Violation. Third, a more targeted investigative demand arising from a referral, a voluntary self-disclosure by a counterparty, or the regulator's own monitoring of the financial system. The nature of the demand governs the urgency, the scope of the document-preservation obligation, and whether outside counsel should be instructed before a single line of response is drafted.
As of the first quarter of 2026, OFAC enforcement correspondence typically identifies the programme under which the inquiry arises – the applicable country or thematic sanctions programme – and the class of conduct under examination. Read that identification carefully. It sets the boundary of the request and, just as importantly, signals the scope of your own internal review.
Preserve everything. Before the team takes any other step, a written litigation-hold or document-preservation notice must go to every custodian whose records could be relevant. Destruction or alteration of responsive documents after a demand has been received is an independent and serious violation. In our experience, businesses that delay this step – even by a single business day while they debate whether the request is "really serious" – create an additional legal exposure that is entirely avoidable.
Step 2: Assemble the response team and define the privilege structure
Responding to an OFAC information request is not a compliance-team task alone; it is a cross-functional legal matter that requires a clearly designated lead and a defined privilege perimeter from the outset. The composition of the response team and the channels through which information flows within it determine whether attorney-client privilege and work-product protection are available if the matter becomes adversarial.
The core team should include outside sanctions counsel, in-house legal, the compliance officer responsible for the relevant programme, and – depending on scope – representation from the business lines and the technology team that holds the relevant records. Communications about the substance of the inquiry should flow through legal counsel wherever possible, and internal emails should clearly be directed to counsel for the purpose of obtaining legal advice. This is not a formality. If the matter escalates and the regulator requests internal communications, a well-constructed privilege log protects analysis from disclosure; an unprotected internal email trail does not.
The position above covers the standard case. Your facts – the counterparty, the volume of transactions under scrutiny, the number of jurisdictions involved, and whether parallel inquiries are running at OFSI or within the EU – change the analysis substantially.
For cross-border businesses, this step also requires an early assessment of whether the OFAC request has a mirror in another jurisdiction. In our cross-border practice, we regularly advise clients who receive concurrent inquiries under two or more regimes. OFSI's enforcement correspondence, for example, operates under a different statutory timetable than OFAC's, and the two agencies do not coordinate their timelines with each other. Managing a dual response carelessly – providing a document to one regulator that contradicts what was said to the other – is a risk that demands active management from day one.
For an initial assessment of your position under OFAC or a parallel regime, contact Calder & Vance at info@caldervance.com.
Step 3: Map the scope of the request against your records
Once the response team is constituted, the next step is a precise mapping exercise: what does the request ask for, what records exist, where do they sit, and are any of them subject to confidentiality obligations in a third jurisdiction that could conflict with the duty to produce?
OFAC's information requests are typically organised by category – transaction records, counterparty identification, internal approval records, and communications. Each category should be matched against a custodian matrix that identifies who holds responsive records and in which system. For financial institutions and payment firms, this frequently means pulling data from multiple systems – core banking, sanctions-screening logs, SWIFT archives, and email. For multinationals with distributed operations, the mapping exercise can span multiple jurisdictions and data-protection regimes.
The jurisdictional conflict issue is real and recurrent. Where records are held in a jurisdiction with strong data-protection rules, production to a US regulator may require a careful legal analysis before documents are transmitted. This does not mean withholding documents from OFAC; it means understanding the legal basis for production in each jurisdiction and, where a genuine conflict exists, surfacing it to counsel rather than resolving it by default. Businesses that ignore this step and produce everything immediately sometimes create a data-protection breach in their home jurisdiction. Those that use it as a pretext to delay create a different problem with OFAC.
The practical output of this step is a document map: a schedule of responsive record categories, the custodians who hold them, the systems in which they sit, and any third-jurisdiction legal issue that requires resolution before production. That map becomes the backbone of the response timeline.
Step 4: Assess whether a voluntary self-disclosure is warranted
The voluntary self-disclosure question is the most consequential decision in the entire response process, and it must be addressed before any substantive communication goes to OFAC. A VSD is a proactive, pre-enforcement report of an apparent violation made to OFAC before the agency has opened a formal investigation. OFAC's published enforcement guidelines treat a VSD as a significant mitigating factor in any penalty assessment.
The decision turns on several variables. Has an apparent violation actually occurred – that is, was a transaction processed, a payment made, or property dealt with in a manner that may have violated an applicable prohibition? If so, was the conduct egregious or non-egregious? Was it the result of a systemic failure or an isolated incident? Has the regulator already identified the conduct, or is this the first point of contact? The answers determine whether a VSD is available, whether it is strategically advisable, and what form it should take.
Where an apparent violation has occurred and the regulator has not yet identified it, a well-prepared VSD can reduce a civil monetary penalty substantially. OFAC's guidelines treat timely VSD as a major mitigating factor. Conversely, a poorly prepared or incomplete VSD – one that describes the conduct inaccurately, understates the volume of transactions, or omits information that the regulator later discovers independently – can be treated as an aggravating factor. In our practice, we have seen incomplete self-disclosures create more difficulty than the underlying conduct.
Where no apparent violation has occurred and the request relates to a licensing matter or a routine query, the VSD question does not arise. The response is a factual submission, and the priority is accuracy and completeness rather than strategic positioning.
If a transaction has already been flagged internally, or if the compliance team has identified transactions that may be responsive to the regulator's inquiry, an early review by sanctions counsel can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com.
Step 5: Draft, review, and submit the response
A response to an OFAC information request should be drafted to a single standard: accurate, complete, and no broader than the request requires. Over-disclosure – providing documents, narratives, or context that go beyond what was asked – is as problematic as under-disclosure, because it may open lines of inquiry that the regulator had not identified and could not have pursued on the basis of the original request.
Each section of the response should track precisely to the corresponding category in the request. Where a record does not exist, say so explicitly and explain why. Where records have been destroyed in the ordinary course of a documented retention policy before the demand was received, explain that too. Where a record is withheld on privilege grounds, log it. Vague or evasive language – "we do not believe we have responsive documents" where the position is genuinely uncertain – creates credibility problems that are difficult to recover from later.
Factual representations in a response to OFAC are statements to a federal regulatory agency. Inaccuracies, even inadvertent ones, carry legal risk. The response should be reviewed by counsel before submission, and the review should specifically address whether every factual assertion is supported by the underlying records.
The covering letter or transmittal memorandum matters too. It should identify the entity responding, reference the OFAC correspondence that prompted the response, describe the scope of the response and any limitations on production, and – where applicable – preserve any legal objections or privilege claims without using them as grounds for non-production of non-privileged material.
How does OFAC's approach differ from OFSI and the EU?
OFAC, OFSI, and EU member-state competent authorities share the broad aim of enforcing sanctions obligations, but their procedural mechanics differ in ways that matter significantly for a business facing parallel inquiries. The key divergences are in the statutory basis for information demands, the available mitigating factors, and the post-submission process.
OFAC operates under broad administrative powers derived from IEEPA. Its enforcement programme is characterised by a published set of general and specific mitigating and aggravating factors, by the availability of VSD with defined consequences, and by a penalty framework that distinguishes between egregious and non-egregious conduct. The regulator publishes enforcement actions – without identifying case numbers or docket references in this guide – and those actions inform the practitioner community about the types of conduct and the compliance failures that attract formal proceedings.
OFSI, by contrast, operates under the Sanctions and Anti-Money Laundering Act (SAMLA) and the relevant thematic regulations. Its power to impose civil monetary penalties uses a different calculation methodology than OFAC's. OFSI also has a distinct licensing and reporting structure: there is a statutory obligation to report knowledge or reasonable cause to suspect that a person is a designated person or has committed an offence, and that obligation runs separately from any response to a formal request. A business managing an OFAC response while simultaneously holding information that triggers an OFSI reporting obligation must handle both correctly and in parallel.
The EU enforcement structure adds a further layer. Enforcement of EU sanctions regulations is a matter of national law within each member state; the competent authority, the procedural rules, and the penalty ranges differ country by country. A business that processes a transaction in breach of an EU Council regulation may face parallel proceedings in the member state where it is established, in the member state where the transaction cleared, and potentially in another jurisdiction where a counterparty is based. We regularly advise on cross-border fact patterns of exactly this type. Coordination between counsel in each jurisdiction – not piecemeal management of each authority separately – is the only approach that consistently avoids contradictory representations.
For a practical view of how an apparent-violation assessment works in the EU context, see our EU apparent violation assessment service page.
Common risk flags and when to involve counsel
Several patterns in an OFAC information request process reliably signal that the matter is more serious than it initially appears. Recognising these flags early is the practical difference between a matter that resolves at the administrative level and one that proceeds to formal penalty proceedings or a referral to the Department of Justice.
The first flag is a request that covers a longer look-back period than the regulator could have determined was relevant from public information alone. A multi-year look-back on a specific counterparty, payment channel, or product line suggests that OFAC has received information – from a counterparty's VSD, from a financial institution's suspicious-activity report, or from another agency – that focuses the inquiry on a particular course of conduct. A broad, general request is more consistent with routine information gathering; a narrow, precise one implies prior knowledge.
The second flag is a request that names individuals. OFAC enforcement actions can, in some circumstances, reach individuals within an organisation, not only the legal entity. Where the request identifies specific officers, employees, or decision-makers by name or role, those individuals may need separate legal representation, independent of the institutional response.
The third flag is timing. A very short response deadline on a complex request may indicate either administrative urgency on OFAC's part or, more rarely, coordination with another enforcement step. If the deadline appears disproportionate to the scope of the request, counsel should seek an extension before the expiry of the original window rather than after it has passed. OFAC will sometimes grant extensions for complex responses; it is considerably less receptive to requests made after the deadline.
A frequently cited misconception is that providing a prompt, cooperative response to an information request resolves the matter. Cooperation is a mitigating factor, but it does not preclude a penalty, and a poorly managed cooperative response – one that is inaccurate, incomplete, or inconsistent with records later obtained by the regulator – can convert a mitigating factor into an aggravating one. The myth that goodwill alone protects a business in enforcement is one we address early in every engagement.
Related practices
- EU apparent violation assessment – assessing apparent violations and preparing responses under EU sanctions
- OFSI information request guide – step-by-step guidance for responding to OFSI under the UK regime
- SECO information request guide – managing information requests under the Swiss sanctions regime