Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · EU

Voluntary self-disclosure under EU: a practical guide

A European trading company completes a series of transactions and, during a routine internal review, discovers that one counterparty had an indirect connection to a listed entity under an EU Council regulation. The payments cleared months ago. The goods have been delivered. No authority has yet made contact. What happens next – and whether the company is penalised heavily or treated as a cooperative actor – may turn entirely on a single decision taken in the next few days: whether to make a voluntary self-disclosure (a proactive notification to a competent authority disclosing an apparent sanctions violation before that authority becomes aware of it independently).

As of April 2026, the EU does not operate a single centralised sanctions enforcement authority. Disclosures are made to the competent authority of the relevant Member State under the applicable Council regulation and national implementing legislation. Despite the absence of a single EU-wide VSD programme, timely and well-prepared disclosure consistently produces more favourable outcomes than waiting for an authority-led investigation to open.

This guide walks through the EU voluntary self-disclosure process step by step – from identifying the apparent violation, through the decision to disclose, to managing the authority's response – and compares key aspects of the EU approach with the positions taken by OFAC and OFSI.

Step 1: Identify and scope the apparent violation before you disclose anything

The first step is to scope what actually happened – because an incomplete or inaccurate disclosure can be more damaging than a well-prepared one submitted a few days later. Begin by identifying the relevant Council regulation and the specific prohibition that may have been breached: asset freezes, the making available of funds, the provision of services. Then trace the transaction chain: counterparty identity, ownership structure, dates, values, and the goods or services involved.

EU sanctions prohibitions apply to persons and entities within EU territory, to EU nationals and companies operating anywhere, and to activities conducted partly within the EU. That extraterritorial reach means a transaction touching an EU-incorporated subsidiary, or routed through an EU correspondent bank, can fall within scope even if its principal parties are outside the EU. In our experience, companies underestimate this reach when mapping which transactions need to be examined.

Ownership and control analysis is critical at this stage. Under EU Council regulations, the ownership and control test (the EU rule treating non-listed entities as captured where a listed person owns or controls them) extends the prohibition beyond direct SDN-equivalent designations. An entity not named on the EU Consolidated List may still be caught if a listed person exercises effective control, even below a formal ownership threshold. Document your analysis carefully – it will form part of the disclosure package.

Step 2: Decide whether to disclose – and to which authority

Unlike OFAC's consolidated VSD mechanism, which channels disclosures to a single US agency, EU disclosure goes to the competent authority of the Member State whose jurisdiction is engaged. That is typically the authority of the country where the disclosing entity is incorporated or where the transaction was executed. Some Member States have designated financial intelligence units; others use trade or finance ministries; the United Kingdom, now outside the EU, uses OFSI. Identifying the correct authority is not always straightforward, particularly for a transaction involving multiple EU jurisdictions.

Should you always disclose? The honest answer is that it depends on the facts. Disclosure is not legally mandatory in every EU Member State for every apparent violation – though some national regimes impose reporting obligations on financial institutions and regulated persons that can effectively require it. Where it is not strictly compulsory, the decision turns on a careful weighing of factors. Is the violation clear-cut or arguable? Is there a record of good-faith compliance effort? What is the likelihood of independent detection? These are not questions to answer alone.

In our cross-border practice, we advise clients to treat disclosure as the default position in all but the most borderline cases. The reputational and relationship-with-authority benefits of proactive disclosure almost always outweigh the downside of self-reporting a matter that might never have surfaced independently. The key condition is that the disclosure is made before the competent authority has become aware of the apparent violation through its own investigation or through a tip from a third party.

Related practices

The position above covers the standard case. Your facts – the counterparty, the goods involved, the route of the transaction, and the Member State whose authority is competent – change the analysis materially. For a pre-disclosure assessment of your exposure, contact Calder & Vance at info@caldervance.com.

Step 3: Build the disclosure package – what competent authorities expect

A well-structured disclosure package is the single most important factor in how a competent authority responds. Authorities across EU Member States consistently distinguish between disclosures that demonstrate genuine engagement and those that appear reactive or defensive. The package should address, at minimum: a factual account of the apparent violation; the relevant Council regulation and the prohibition engaged; the counterparty and ownership-chain analysis; the value and nature of the goods or services; the dates; and the remedial action already taken or planned.

Remediation is not optional colour. Authorities want to see that the disclosing entity has already begun – or has a credible plan to begin – correcting the compliance gap that allowed the violation to occur. That may mean a revised screening programme, updated ownership-and-control checks, changes to the approval process for high-risk transactions, or enhanced due diligence procedures. A disclosure that presents the violation in isolation, without remediation, is a weaker submission.

Record-keeping is also essential. Across EU Member States, as well as under OFAC and OFSI rules, retaining documentation of the transaction, the compliance review, and the disclosure process itself is required for a defined period under the applicable regime. Verify the precise retention period applicable to your circumstances before relying on any general figure.

One practical note on legal privilege: internal investigation materials, legal advice on the disclosure decision, and draft packages should be handled by – or under the direction of – qualified counsel to preserve legal professional privilege where applicable. Privilege rules differ between EU Member States and between EU proceedings and any parallel US or UK matter.

How does the EU approach compare with OFAC and OFSI?

The most important structural difference between EU disclosure and its US counterpart is the absence of a published, regime-wide mitigation framework at EU level. OFAC operates a documented enforcement and voluntary self-disclosure policy under which a timely, thorough, and non-egregious VSD can reduce a base penalty significantly. OFSI has published guidance that acknowledges disclosure as a mitigating factor in its penalty calculations. At EU level, the treatment of disclosure varies by Member State, and not all national authorities publish detailed enforcement guidance that quantifies the mitigation benefit.

That said, the practical outcome across the major EU enforcement jurisdictions broadly tracks the approach of OFAC and OFSI: early, accurate, and cooperative disclosure produces better outcomes than non-disclosure. The divergence lies in predictability. A company disclosing to OFAC can read the published framework and form a reasonable view of the likely penalty range. A company disclosing to a national EU competent authority may have less published guidance to work with – which makes experienced counsel familiar with that authority's practice even more valuable.

A second difference concerns simultaneous obligations. A transaction involving an EU entity may also trigger reporting obligations under OFAC (if a US-nexus exists) and OFSI (for any UK element). Where all three regimes are engaged, the disclosures must be managed in parallel. The timing of each disclosure, and the consistency of the factual account across all three, requires careful co-ordination. Inconsistency between submissions to different regulators creates a significant risk of its own.

For a comparative view of the OFAC process, see our guide at voluntary self-disclosure under OFAC.

If a transaction has already been flagged by an authority, or a compliance review has identified an apparent violation that is likely to surface, an early review can preserve options that narrow with time. Contact us at info@caldervance.com to discuss the position before the disclosure window closes.

Risk flags: when a disclosure becomes more complicated

Several features of an apparent violation raise the complexity and the stakes of the disclosure decision. Being alert to these risk flags at the outset allows counsel and the internal team to structure the disclosure appropriately, rather than revising mid-course.

The first flag is multiple transactions. A single inadvertent payment to an indirectly connected counterparty is one thing. A pattern of transactions over several months, involving the same counterparty, suggests a systemic compliance failure rather than an isolated incident. Authorities treat systemic failures more seriously. The disclosure package must address the root cause, not just the individual transactions.

The second flag is wilfulness or awareness. If internal communications show that someone in the organisation was aware of the connection to a listed entity and the transaction proceeded anyway, the analysis shifts substantially. A disclosure in those circumstances requires especially careful preparation and legal advice before anything is submitted.

The third flag is a parallel criminal exposure. In some EU Member States, intentional breach of sanctions regulations is a criminal offence. Where that risk exists, the disclosure strategy and the identity of who submits the notification matter. Counsel with criminal-law experience in the relevant jurisdiction should be involved from the outset.

The fourth flag is a third-country dimension. If the transaction also involved US-controlled goods, US persons, or a US correspondent bank, a separate OFAC analysis is required. BIS and the EAR (the Export Administration Regulations, the US Commerce Department's export-control rules administered by BIS) may also be engaged if the goods had a US origin or incorporated US-origin content. Treating the matter as EU-only when a US obligation also exists is one of the most common errors we see in cross-border matters.

What a common myth gets wrong about EU voluntary self-disclosure

A persistent assumption among compliance teams is that disclosure is only worth making if the violation is certain. If there is any arguable basis on which the transaction was lawful – perhaps the ownership analysis is inconclusive, or a general authorisation may have applied – the logic runs: wait and see whether the authority raises it.

That reasoning is understandable, but it misreads how competent authorities approach cooperative actors. The relevant question is not whether the violation is definitively proven at the time of disclosure; it is whether the disclosing entity acted in good faith, promptly, and transparently once it had grounds to believe a breach may have occurred. An entity that waits for legal certainty before disclosing often waits too long. By the time the ownership chain is fully traced and the legal question settled, the authority may already have the transaction in view through a bank's own suspicious-transaction report or a trade data query.

A related myth is that disclosure guarantees a fine, whereas silence may mean no penalty at all. In our experience, the reverse is more often true: proactive disclosure is more likely to result in no monetary penalty, or a substantially reduced one, than a contested investigation that the authority pursues independently. The comparison is not disclosure versus no consequences; it is disclosure-with-mitigation versus investigation-without-it.

When to involve external sanctions counsel

Internal compliance teams handle routine screening and transaction monitoring effectively. But a voluntary self-disclosure – particularly one involving multiple transactions, a systemic root cause, or a parallel OFAC or OFSI obligation – benefits from external counsel for specific reasons. Counsel can provide legally privileged advice on the disclosure decision and the package content. Counsel familiar with the relevant national authority's practice can pitch the disclosure at the right level of detail and in the right tone. And where the matter has a criminal dimension, the involvement of specialist legal advisers is not optional.

Timing matters enormously. In a recent matter, a financial-services business identified an apparent breach under an EU Council regulation following an internal audit. The ownership-chain analysis was complex, and the initial instinct was to complete a full legal opinion before disclosing. We were instructed, completed a rapid apparent-violation assessment, and advised on an expedited disclosure to the relevant national authority. The authority treated the matter as cooperative and the outcome reflected that. A delay of several more weeks would have materially changed the risk profile as the authority's own supervisory review of the sector was underway.

The moment to involve counsel is not when the disclosure package is ready. It is when the apparent violation is first identified – or even earlier, as part of a standing arrangement for rapid incident response.

Frequently asked questions

What are the steps to make a voluntary self-disclosure under EU?
The process begins with scoping the apparent violation and identifying the competent authority of the relevant Member State. You then build a disclosure package that covers the factual account, the applicable Council regulation and prohibition, the counterparty and ownership-chain analysis, the value and dates of the transactions, and your remediation plan. The package is submitted to the competent authority. You then manage any follow-up queries, co-operate with any investigation, and implement the remediation measures you committed to. Where a parallel OFAC or OFSI obligation exists, those disclosures must be managed in parallel and kept factually consistent.
What is the most common mistake in voluntary self-disclosure?
The most common mistake is submitting a disclosure that describes the apparent violation accurately but fails to address the root cause and the remediation plan. Competent authorities distinguish between an entity that discloses a problem and an entity that discloses a problem and demonstrates it has been fixed. A disclosure without remediation is a weaker submission and can attract greater scrutiny rather than credit for co-operation. The second most common mistake is treating a multi-regime matter as a single-regime one and failing to make the parallel disclosure to OFAC or OFSI where a US or UK nexus exists.
How does EU differ from other regimes here?
The principal difference is structural: the EU has no single, centralised enforcement authority and no published, regime-wide VSD mitigation framework equivalent to OFAC's published enforcement policy. Disclosures go to the competent authority of the relevant Member State, and the published guidance on how disclosure will be treated varies between jurisdictions. OFSI, by contrast, has published enforcement guidance acknowledging disclosure as a mitigating factor. OFAC operates a detailed, publicly documented framework. The practical implication for a cross-border business is that EU disclosure benefits more from familiarity with the specific authority's practice and less from reading a published schedule of mitigations.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.