A cross-border trading business receives a written request from a UN Security Council Sanctions Committee – or from a national authority acting on the Committee's behalf – seeking information about a transaction, a counterparty, or a movement of funds. The request names no specific penalty, sets no obvious deadline in the covering letter, and the compliance team has never handled one before. What happens next determines whether the business is treated as a cooperative witness or a subject of concern.
Responding to regulator information requests under the UN sanctions regime requires early legal review, a disciplined document-preservation step, and a structured response that addresses the Committee's mandate without volunteering material that widens scope. The governing authority is the relevant Security Council Sanctions Committee, operating under the UN Charter and the relevant Committee's guidelines. Unlike OFAC or OFSI enforcement letters, a UN information request carries no domestic-law penalty in itself – but the national authority transmitting it does carry enforcement powers, and those powers apply from the moment the request arrives.
This guide walks through the process step by step: from identifying who is really asking and why, through document review and legal-privilege considerations, to drafting the response and managing the cross-regime implications that almost always accompany a UN-level inquiry.
Step 1 – Identify the requesting authority and its actual legal basis
Before a single document is pulled, confirm exactly who issued the request and under what authority they are acting. A UN Sanctions Committee does not communicate directly with private entities in most cases. The request arrives through a UN Member State – typically the state in which your business operates or is incorporated – acting under its own national implementing legislation.
That distinction matters immediately. The UN Consolidated List establishes the designations. The Sanctions Committee's guidelines set the procedural rules for the Committee itself. But the coercive power to compel a response, and the consequences of non-compliance, flows from the national regime: in the United States from IEEPA and OFAC's regulations, in the United Kingdom from SAMLA and the relevant thematic sanctions regulations with OFSI as the enforcement body, and in the EU from the relevant Council regulation enforced by the competent national authority of the Member State.
Ask three questions immediately. First: is this a direct Committee request transmitted through diplomatic channels, or is it a national authority's own investigation triggered by conduct that also implicates UN designations? Second: is there a stated response deadline in the national covering document? Third: is the request addressed to the legal entity, a specific individual within it, or both? The answer to each changes your response strategy.
In our experience, businesses that treat a UN-adjacent inquiry as purely a UN matter – and ignore the domestic-law dimension – miss the enforcement risk that is actually live. The national authority is the one that can impose a financial penalty, open a criminal referral, or issue a direction. The Committee is the policy principal. Manage both.
Step 2 – Preserve documents and impose a litigation hold
The moment a request is received, issue an internal litigation hold. This instruction goes to every team that touched the transaction or counterparty in question: trade finance, treasury, compliance, operations, and any external logistics or freight partners whose communications you hold.
A litigation hold does three things. It stops the routine deletion of emails, chat logs, and transaction records that would otherwise proceed automatically. It creates a documented record that the business acted in good faith on receipt of the request. And it provides the legal team with a defensible starting point if the inquiry escalates to a formal investigation.
Record-keeping obligations under most national regimes that implement UN sanctions run for a defined period from the date of the transaction. In our cross-border practice, we regularly advise clients to treat the hold as covering all records generated from the date of first contact with the counterparty, not merely the transaction at the centre of the request. Gaps in the record are harder to explain than a complete set of documents showing a decision you wish you had made differently.
One practical point: if the request was transmitted through a national authority, check whether that authority's own guidance specifies a record-preservation requirement triggered by the request itself. OFSI's enforcement guidance, for example, addresses record-keeping obligations in the context of a financial-sanctions investigation. Assume the equivalent exists in each jurisdiction and preserve accordingly.
Step 3 – Conduct a privileged internal review before drafting any response
The review of the underlying facts must be conducted under legal-professional privilege before a word of the external response is drafted. Once a document is created for the purpose of responding to a regulator, its status becomes contentious if the inquiry escalates. Structure the review so that the factual analysis and the legal advice remain privileged.
The review should address five things in sequence. First, map the transaction: identify each party, each payment leg, each goods movement, and each jurisdiction through which the transaction passed. Second, check each party against the UN Consolidated List as it stood at the time of the transaction – not only as it stands today. A party listed after your transaction closed is a different risk profile from a party that was listed throughout. Third, identify whether any applicable general licence or national authorisation was in effect at the relevant time. Fourth, assess whether the transaction involved any item with an Export Control Classification Number (ECCN – the US Commerce Control List identifier used to determine licensing requirements under the Export Administration Regulations) that might engage parallel BIS or ECJU obligations. Fifth, identify whether any national authority has already been notified – whether by the business itself or by a counterparty.
That fifth point is often overlooked. If a bank in the transaction chain has already made a suspicious-transaction report to its domestic financial intelligence unit, the national authority may already hold information about the transaction. Responding without knowing what the authority already knows is a significant risk. Have you checked with all financial intermediaries in the chain before you frame your response?
Step 4 – Assess whether a voluntary self-disclosure should accompany the response
An information request does not automatically mean the business has committed a violation. But the review conducted at Step 3 may reveal conduct that amounts to an apparent violation – a transaction that should have been blocked, a payment that moved through a listed person's account, or a shipment that engaged a licence requirement that was not satisfied.
If the review identifies an apparent violation, the question of voluntary self-disclosure (VSD – the practice of proactively reporting a potential violation to the relevant authority before it is independently discovered) becomes live. VSD is a recognised mitigating factor under OFAC's enforcement guidelines, under OFSI's published enforcement guidance, and under the BIS administrative enforcement regime for export-control violations. The weight given to a VSD varies by regime and by the severity of the conduct, but in every major regime it is treated more favourably than a violation uncovered through an investigation.
The timing of a VSD is critical. Filing after the authority has already identified the conduct through its own inquiry typically reduces – or eliminates – the credit available. That is the narrow window within which counsel's involvement adds the most value. For a detailed treatment of the BIS process, see our guide to voluntary self-disclosure under the BIS and the EAR. The equivalent process in Australian practice is covered in our voluntary self-disclosure guide for Australia.
The decision to disclose is never mechanical. It requires weighing the strength of the apparent violation, the likely consequence of the authority discovering it independently, the scope of any applicable mitigation, and the cross-regime implications – because a disclosure to one authority may need to be replicated, or at minimum considered, in each jurisdiction with a parallel enforcement interest.
Step 5 – Draft the response: scope, structure, and what not to include
The response to an information request should answer the question asked. It should not answer questions the authority has not asked. That rule sounds obvious. In practice, compliance teams under pressure to demonstrate cooperation routinely produce responses that volunteer facts, characterise intentions, or offer legal arguments that widen the inquiry rather than closing it.
A well-structured response does the following. It identifies the legal entity responding and confirms its understanding of the request. It sets out the documents and information being provided, clearly described and indexed. It states what is being withheld – typically privileged legal advice – and provides a brief basis for each claim of privilege. It responds factually to each specific question without embellishment. And it closes with a point of contact for any follow-up.
What it does not do: it does not offer a legal conclusion about whether a violation occurred. It does not characterise the intent or state of mind of any individual within the business. It does not volunteer information about other transactions, counterparties, or jurisdictions not addressed in the request. And it does not make representations about future conduct – those belong in a remediation plan, if one is required, and they should be drafted separately under counsel's supervision.
Translated to the cross-regime context: if the UN-adjacent request comes from a US authority and also implicates EU or UK nexus, the US response should address the US questions. A separate assessment of whether parallel disclosures are required under OFSI's reporting obligations or under the relevant EU national authority's regime is a distinct exercise. Conflating them in a single response creates evidentiary risk in each jurisdiction.
Step 6 – Manage the cross-regime implications
A UN Security Council designation has effect across all UN Member States. But the national implementation of that designation – the specific prohibitions, the ownership and control tests, the licensing routes, and the enforcement powers – differs materially between regimes. That divergence is not academic: it shapes what the business must do and in what order.
Under OFAC, the 50 percent rule (the rule treating any entity owned 50 percent or more by one or more blocked persons as itself blocked, regardless of whether it appears on the SDN List) operates mechanically based on ownership percentage. Under OFSI and the EU equivalent, the test extends to control – meaning that a minority-ownership stake, combined with board rights or contractual powers, can still bring an entity within the prohibition. That divergence means a counterparty cleared under one jurisdiction's ownership test may remain caught under another's. In our experience, businesses that screen only against the UN Consolidated List and their domestic list miss the secondary list exposure.
The extraterritorial reach of the US regime adds a further dimension. Even a transaction with no US person, no US goods, and no dollar clearing can attract OFAC attention if it involves a UN-listed party and the business has any US-person dimension – a US parent, US investors, or US employees in the decision chain. Compliance counsel acting in a UK or EU investigation should always consider whether OFAC notification is also required or prudent.
For businesses that discover, during the Step 3 review, that an EU jurisdiction is also engaged, our colleagues who advise on apparent violation assessment under the EU regime can assist with that parallel strand. Cross-regime management from a single instructed team is consistently more efficient than running separate national-counsel tracks that do not share a common legal strategy.
Step 7 – After the response: remediation, monitoring, and records
Submitting the response is not the end of the matter. It is the beginning of a monitored period during which the authority digests the response, may issue follow-up questions, and decides whether to close the inquiry or escalate it to a formal investigation.
During that period, three things should happen in parallel. First, the business should implement any remediation steps that the Step 3 review identified as necessary – enhanced screening, a revised counterparty approval process, or updated sanctions-clause language in contracts. Doing so before the authority asks for a remediation plan demonstrates good faith and reduces the weight of any penalty if one follows. Second, the business should maintain the litigation hold until the authority formally closes the inquiry or until counsel advises that the hold can safely be lifted. Third, the business should document every step taken from receipt of the request to final resolution – not in a form that waives privilege, but in a form that demonstrates a competent and timely response.
A final practical point: if the authority's follow-up questions suggest the inquiry has expanded beyond the original scope – for example, to additional transactions, additional time periods, or additional counterparties – treat that expansion as a new trigger. Reassess whether a VSD is now appropriate. Consider whether local counsel in any newly implicated jurisdiction needs to be instructed. And brief the board or audit committee if the scope is material. Sanctions inquiries that start narrow can widen quickly, and the governance record matters.
Common mistakes and risk flags in UN information-request responses
Experience in this area produces a consistent set of errors. They are worth naming directly, because each one has resulted in an inquiry that could have closed early instead running for an extended period.
The first and most common mistake is treating the UN information request as a routine compliance query rather than a legal proceeding. The request is not a questionnaire. It is the opening of a formal regulatory exchange with enforcement potential in multiple jurisdictions. It should be handled accordingly, from the first hour.
The second mistake is producing an over-broad response. Businesses trying to demonstrate cooperation sometimes produce every document that could possibly be relevant. An over-broad production creates a larger factual record for the authority to examine and may surface issues beyond the original scope. Respond to what was asked; do not produce what was not requested.
The third mistake is ignoring the cross-regime dimension. A response crafted for a UK national authority may create an inconsistency with a position being taken simultaneously in a US OFAC context. Coordinate across jurisdictions before any response is filed.
The fourth mistake is failing to involve counsel early enough. The decision about what to include, what to withhold as privileged, whether to make a VSD, and how to frame factual representations is a legal question. It should not be answered by the compliance team alone, however experienced. A significant enforcement action that began as a routine information request is almost always one where early counsel involvement would have changed the outcome.
Is your compliance programme designed to detect a UN-linked inquiry from a national authority – not only a direct OFAC or OFSI letter? If it is not, that is a gap worth closing before the next request arrives.
Related practices
- Apparent Violation Assessment – EU – assessing EU-regime exposure when a UN-linked inquiry has an EU dimension
- Voluntary Self-Disclosure – Australia – the VSD process and credit available under Australian sanctions practice