Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · UN

Voluntary self-disclosure under UN: a practical guide

A trading company completes a series of shipments before its compliance team identifies that a named consignee appeared on the UN Consolidated List (the list maintained by the United Nations Security Council committees of all designated individuals and entities under active UN sanctions programmes). The transaction is closed. The goods have moved. What now? The question of whether and how to disclose to the relevant authorities is one of the most consequential decisions a business will face in the aftermath of a potential sanctions breach.

Voluntary self-disclosure under UN-derived sanctions regimes means proactively reporting a potential or actual breach to the competent national authority before that authority discovers it independently. The UN Security Council establishes the designations; enforcement is carried out by member states through their domestic implementing legislation. As of April 2026, a voluntary self-disclosure (VSD – a proactive report by a subject person to a regulator before enforcement contact) can produce meaningful mitigation in penalty proceedings, but the process, timing requirements, and risk profile differ significantly across the US, UK, and EU regimes that give domestic legal force to UN obligations.

This guide walks through the governing authority, the disclosure decision, the process in each major regime, cross-border considerations, risk flags, and when to instruct counsel. It follows the G-steps structure: each phase is self-contained, and each builds on the last.

Step 1: Understand the governing authority – the UN Consolidated List and national implementing regimes

The UN Consolidated List is maintained by the Security Council and its sanctions committees under Chapter VII of the UN Charter; it has no direct private-law enforcement mechanism of its own. Enforcement falls entirely to member states through their national implementing legislation, and those national regimes are the authorities to which a VSD is directed.

In practice, the three regimes a cross-border business is most likely to face are OFAC in the United States, OFSI in the United Kingdom, and the relevant Council mechanism in the European Union. Each transposes UN designations into domestic law through its own instruments – IEEPA-derived regulations for OFAC, the Sanctions and Anti-Money Laundering Act (SAMLA) and the thematic regulations for OFSI, and the relevant Council Regulation for the EU. A business subject to multiple jurisdictions faces multiple disclosure obligations, which may not run in parallel.

Why does this matter for disclosure? Because the entity to receive the VSD is a national regulator, not the UN itself. There is no mechanism to self-disclose to the Security Council. The question is always: to which national authority, under which regime, and by when?

One further point: UN designations are frequently mirrored, but not always. A person on the UN Consolidated List is not necessarily listed under OFAC's SDN List (the list of Specially Designated Nationals and Blocked Persons) or on the OFSI or EU lists. Conversely, the national regimes maintain autonomous listings that extend beyond UN obligations. A transaction may involve a UN-listed party that is listed under only some of the national regimes relevant to your group. Mapping that overlap is the first task in any post-transaction analysis.

Step 2: Conduct an immediate internal scoping exercise before deciding whether to disclose

Before drafting a VSD, a business must understand precisely what it is disclosing. A poorly scoped VSD that under-describes the conduct, or that is later contradicted by documents in a regulatory review, can eliminate the mitigation benefit and create additional liability.

The scoping exercise should address four questions. First, which legal entity or entities within the group are within the territorial or jurisdictional reach of each regime? OFAC's reach extends to US persons, entities organised under US law, and any transaction that clears in US dollars or touches the US financial system – a considerably wider class than pure US-domiciled businesses. OFSI's reach covers UK persons, UK-incorporated entities, and conduct occurring in the United Kingdom. The EU regime applies to EU-established persons and to conduct within EU territory. A group with US parent financing and EU operating subsidiaries may face VSD obligations in two or three jurisdictions simultaneously.

Second, does the apparent violation involve a UN-listed party, an autonomously listed party, or both? The answer shapes which authority the VSD goes to and what legal basis the breach arises under.

Third, what is the nature of the potential violation – a payment, a shipment, a service, a debt that should have been frozen? Each regime's enforcement guidance weights the severity of different conduct types differently.

Fourth, is the conduct continuing? An ongoing transaction involving a blocked or listed party creates a separate obligation to cease immediately; that obligation is independent of and prior to any VSD decision. We regularly advise clients that the disclosure decision and the remediation decision are distinct, and that conflating them leads to delay in remediation that can itself aggravate the enforcement position.

Step 3: Assess the disclosure threshold and timing across each applicable regime

Each major regime sets its own standard for when disclosure is appropriate, and the timing of that disclosure materially affects the mitigation it produces.

Under the OFAC regime, OFAC's enforcement guidelines treat a VSD as an aggravating or mitigating factor depending in part on when it is made. A disclosure made promptly after the business becomes aware of the apparent violation – and before OFAC has initiated an investigation – carries full mitigation weight. A disclosure made after OFAC has contacted the company or opened an investigation is treated differently and may not produce the same reduction. OFAC's published guidance (generic: the enforcement guidelines, not a specific document number) sets out a base penalty framework in which a VSD may reduce the penalty base by a significant proportion. In our experience, the window between internal discovery and regulatory contact can be short; acting decisively in the first days is critical.

OFSI in the United Kingdom operates under a monetary penalty regime established by SAMLA and the relevant thematic sanctions regulations. OFSI's published enforcement guidance confirms that voluntary disclosure is a mitigating factor in its penalty calculation. OFSI does not publish a fixed percentage reduction, but the guidance makes clear that an early, complete, and proactive disclosure is treated more favourably than a disclosure made after OFSI has already commenced enquiries. The reporting obligation under the UK regime is separate from and wider than a VSD: regulated sector entities have a mandatory reporting obligation to OFSI when they know or have reasonable cause to suspect a breach. For those entities, disclosure is not discretionary – it is a legal requirement. For non-regulated-sector businesses, the decision is discretionary but strategically significant.

The EU regime adds a further layer. Member states implement and enforce EU sanctions at national level, meaning that a VSD in the EU is directed to the relevant national competent authority – which may be a financial regulator, a trade authority, or a specialised sanctions body, depending on the member state. There is no single EU-wide VSD mechanism. The evidential and procedural requirements vary, and in our practice we have seen cases where the approach taken by one member state's authority differed substantially from that of another, even on materially similar facts.

For Switzerland (SECO), Canada (GAC), and Australia (DFAT), the same principle applies: VSD goes to the domestic authority, and the timing and process rules are set by national implementing instruments. Businesses with exposure in those jurisdictions should assess each regime independently.

Step 4: Prepare and submit the voluntary self-disclosure

A well-constructed VSD is a structured, factual narrative. It is not a confession drafted in loose terms, and it is not a summary dismissal of the apparent breach as a minor technical matter. Regulators read these documents carefully, and the quality of the submission signals the seriousness with which the business treats its compliance obligations.

The core components of an effective VSD submission are as follows.

  • A clear statement of the apparent violation: the nature of the transaction or conduct, the date or period, the parties involved, and the list on which the relevant person or entity appears.
  • The jurisdictional analysis: why the relevant regime applies to this entity and this transaction.
  • The facts as known: a chronological account of the business's knowledge and actions, including when the apparent breach was identified and by whom.
  • Root-cause analysis: an honest assessment of the compliance failure that allowed the transaction to proceed – whether a screening gap, an ownership analysis error, or a process failure.
  • Remediation steps already taken: ceasing ongoing transactions, blocking or freezing assets as required, suspending the relationship with the relevant counterparty.
  • Proposed remediation programme: the steps the business proposes to take to prevent recurrence, in sufficient detail to demonstrate they are genuine and proportionate to the root cause.

Privilege considerations are significant here. Communications between counsel and client prepared in anticipation of the VSD may attract legal professional privilege, but the VSD document itself, once submitted, is in the regulatory record. The distinction between legal advice sought from counsel and the final submission is one that should be managed carefully from the outset of the exercise.

Do not submit a VSD before the internal scoping exercise in Step 2 is complete. A partial or inaccurate VSD that requires correction creates a more complicated enforcement position than a slightly delayed but complete one – provided the delay is not so long that it appears strategic. In our experience, the right approach is usually to move quickly but not hastily.

Step 5: Manage the post-disclosure process and parallel obligations

Submitting the VSD is not the end of the matter; it is the beginning of the regulated phase. A business that has self-disclosed should expect regulatory engagement, and the quality of that engagement matters for the outcome.

Under OFAC, a VSD opens a formal review process. OFAC will typically acknowledge receipt and may request additional information, further documentation, or clarification of the root-cause analysis or the proposed remediation. Responsiveness and accuracy in those follow-up responses is as important as the initial submission. OFAC's published guidelines distinguish between egregious and non-egregious violations, and a VSD that is followed by full cooperation and a credible remediation programme is consistently treated more favourably than one where the business becomes defensive or slow in subsequent correspondence.

OFSI similarly expects full cooperation following a disclosure. The reporting obligation under the UK regime (where it applies) must be fulfilled in addition to the VSD; these are separate legal obligations. Record-keeping is important: businesses should maintain a clear documentary trail of the disclosure, all subsequent correspondence, and all remediation steps taken.

Cross-border coordination is one of the most practically challenging aspects of a multi-regime VSD. Where parallel disclosures are made to OFAC and OFSI, or to OFAC and a national EU authority, the business must ensure that the factual narrative is consistent across all submissions. Inconsistencies between submissions to different regulators are noticed – and they undermine the credibility of the compliance posture the business is trying to demonstrate. We regularly advise clients on coordinating parallel submissions to avoid exactly this problem.

The timeline from VSD submission to final resolution varies. Some OFAC matters resolve within months; others take considerably longer, particularly where the conduct is complex, the value is significant, or the review involves multiple related entities. OFSI and national EU authority timelines also vary. Building a realistic expectation of that timeline into the business's planning – including internal governance and external communication requirements – is an important part of the post-disclosure phase.

Step 6: Address the risk flags that most commonly undermine a VSD

Several patterns arise repeatedly in post-incident VSD work that either undermine the mitigation benefit or convert a manageable matter into a serious enforcement exposure.

The most common is delay. A business that identifies a potential breach and spends weeks or months in internal deliberation before disclosing loses the timing advantage that produces the strongest mitigation. The deliberation is understandable – disclosure is a significant step. But it should be conducted urgently, not at a pace that allows regulatory contact to pre-empt the VSD. Have you set a clear internal deadline for the scoping exercise to conclude?

The second is incomplete disclosure. A VSD that reveals one transaction but omits related transactions that the business is aware of, or that understates the value or duration of the conduct, is worse than no VSD. When the full picture later emerges – through regulatory data requests, document review, or whistleblower reports – the incomplete disclosure becomes an aggravating factor in its own right.

The third is poor root-cause analysis. Regulators are sceptical of VSD submissions that attribute a breach entirely to an individual error without examining the systemic failure that allowed the error to go undetected. A credible root-cause analysis identifies the control gap, the ownership or screening failure, or the process deficiency that allowed the transaction to proceed. That analysis then drives the remediation plan. A thin root-cause section signals to the regulator that the compliance programme has not genuinely been examined.

The fourth is conflating the VSD with a legal defence brief. The VSD is a factual document. Legal arguments about the weight of the evidence or the proportionality of any penalty belong in a separate legal response, if and when enforcement proceedings are formally opened. Mixing advocacy with factual disclosure muddies both.

One common misconception is worth addressing directly: that disclosing is always the right answer, and that a VSD automatically produces a reduced outcome. Neither is true. Disclosure is the right answer in most circumstances where a genuine apparent violation has occurred and the business is within the regulatory perimeter of the relevant regime. But there are fact patterns – where, for example, the jurisdictional analysis is genuinely uncertain, or where the apparent breach is based on a list-matching error that on further review resolves to a false positive – where the first step is not disclosure but rigorous due diligence to determine whether a breach has occurred at all. Disclosing a transaction that, properly analysed, did not involve a listed person is an own goal with real costs.

Step 7: When to instruct sanctions counsel and what to expect

The decision to instruct specialist counsel is not a sign of weakness; it is a recognition that VSD processes under major sanctions regimes carry material legal and reputational risk. Counsel adds the most value at two moments: early in the scoping exercise, before any regulatory contact, and at the point of drafting the submission itself.

Early instruction means the scoping exercise benefits from legal privilege protection for the advice component. It means that the jurisdictional analysis – which regimes apply, which disclosures are mandatory and which are discretionary – is conducted correctly before the business commits to a course of action. And it means that the root-cause analysis and remediation plan are calibrated to what the relevant regulator is looking for, not to what the internal compliance team hopes it wants.

What should a business expect from its counsel? First, a rapid jurisdictional triage – within days, not weeks – to identify which regimes apply and what the timing obligations are. Second, a structured scoping exercise to define the apparent violation and the documentary record. Third, a privilege-protected legal assessment of the exposure and the mitigation options. Fourth, drafting and review of the VSD submission itself, with close attention to the factual narrative, the root-cause analysis, and the remediation programme. Fifth, coordination of parallel submissions to multiple regulators where the group has multi-jurisdiction exposure. Sixth, management of the post-disclosure regulatory dialogue.

In a recent matter, a mid-sized trading business identified a series of payments that had been processed through a correspondent bank to a counterparty that had been added to the UN Consolidated List mid-contract. We scoped the apparent violations, mapped the US dollar clearing exposure under OFAC and the UK payment-firm exposure under OFSI, coordinated the drafting of parallel VSD submissions with consistent factual narratives, and managed the subsequent regulatory correspondence. The matter reached resolution without formal penalty proceedings being opened. We do not promise that outcome, but coordinated, early, and well-documented disclosure is consistently the strongest starting position.

The position above covers the standard case. Your facts – the counterparty, the transaction type, the dollar-clearing route, the corporate structure, and the regimes in play – change the analysis materially. Acting early preserves the most options.

For an assessment of your exposure and guidance on the VSD process under OFAC, OFSI, or a national EU authority, contact Calder & Vance at info@caldervance.com.

If a filing has already been refused or a regulatory notice has been received, an early review can preserve options that narrow with time. Contact us at info@caldervance.com.

Related practices

Frequently asked questions

What are the steps to make a voluntary self-disclosure under UN?
There is no direct disclosure mechanism to the UN; VSD is made to the national authority that implements UN designations domestically – OFAC in the US, OFSI in the UK, or the relevant national competent authority in the EU. The core steps are: conduct an internal scoping exercise to identify the apparent violation and confirm jurisdiction; assess timing obligations under each applicable regime; prepare a structured factual submission including the root-cause analysis and remediation plan; submit promptly; and manage the post-disclosure regulatory dialogue with full cooperation. Instructing counsel before submission is strongly advisable where multi-regime exposure exists.
What is the most common mistake in voluntary self-disclosure?
Delay is the single most common failure. A business that identifies an apparent breach but defers disclosure through prolonged internal deliberation risks losing the mitigation benefit and risks the regulator opening an independent investigation in the interim. The second most common mistake is an incomplete disclosure – covering some transactions but not related ones the business is aware of – which can convert a manageable situation into a more serious enforcement matter when the full picture later emerges through regulatory data requests or other means.
How does UN differ from other regimes here?
The UN regime differs fundamentally in that enforcement is indirect. The Security Council designates; member states enforce through domestic legislation. This means there is no single VSD process: a business may face simultaneous obligations to OFAC, OFSI, and one or more EU national authorities, each with its own timing rules, penalty framework, and cooperation expectations. The UN Consolidated List also differs in scope from the autonomous national lists: a person may be on the UN list but not on the OFAC SDN List, or vice versa, which affects which regimes are engaged and therefore which disclosures are required.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.