A mid-sized technology distributor operating across North America and Europe receives a routine query from its bank: a payment made several months earlier has been flagged against the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The transaction was not large. The counterparty was not obviously connected to a designated person. Yet the exposure is real, and the question of what happens next turns almost entirely on one variable: what mitigation factors in enforcement an OFAC case can produce, and how persuasively they can be assembled.
Under OFAC's enforcement guidelines, the outcome of an apparent violation depends on a structured assessment of aggravating and mitigating factors applied against the base penalty range. Mitigation is not a discretionary favour; it is a documented analytical step that OFAC must apply. The difference between a finding of no action, a cautionary letter, and a substantial civil penalty is, in most cases, the quality of the mitigation record.
This case comment examines a representative OFAC enforcement matter, the factors that shaped the outcome, and the practical lessons that apply to any cross-border business facing a comparable situation. It also sets out how the OFAC approach to mitigation compares with OFSI in the United Kingdom and the EU regime, where similar but not identical principles apply.
The situation: how the apparent violation arose
The business distributed licensed software to clients in several jurisdictions. Its screening programme was operational but had a documented gap: it screened counterparties at onboarding but did not re-screen against updated lists at the point of each transaction. A counterparty that had been clean at onboarding was subsequently designated. Two payments processed after the designation date reached that counterparty before the gap was identified.
The bank's query triggered an internal review. The review confirmed that both payments had settled after the designation. The business was therefore looking at two apparent violations under the applicable OFAC regime. Neither payment was large. Both were commercial in character, with no evidence of any attempt to circumvent the rules. The business's legal team contacted Calder & Vance at that point.
The first question we address in any such instruction is scope: how many transactions are actually implicated? In our experience, the initial count is almost always incomplete. A thorough look-back across payment records, licence files, and counterparty data frequently surfaces additional items – and it is far better to identify them now than to have OFAC identify them later.
What is the OFAC enforcement framework for mitigation factors?
OFAC's enforcement process moves through a defined sequence: an apparent violation is identified; OFAC issues a request for information; the business responds with its account of the facts and any mitigation evidence; OFAC makes a penalty determination. The civil penalty base is set under the applicable IEEPA authority and can reach a significant level per violation. Mitigation can reduce the final figure materially – and in the right cases, it can produce a cautionary letter instead of any penalty at all.
OFAC's published guidelines identify two categories of factors that affect the outcome. General factors apply to every case: the apparent violator's awareness of the conduct, the harm caused, the individual characteristics of the subject, and whether it has a voluntary self-disclosure (VSD) (a report made to OFAC before or at the time the agency discovers the violation independently). Specific aggravating and mitigating factors then adjust the analysis within the range set by the general factors.
The mitigation factors that carry the most weight in our practice are these. First, a VSD filed promptly and completely. OFAC's guidelines treat a complete VSD as a significant mitigant and reduce the base penalty range substantially. The filing must be accurate; an incomplete VSD that OFAC must later correct creates a credibility problem that is hard to recover from. Second, the existence of a sanctions compliance programme (SCP) that was in place at the time of the violation and that met the five-element standard OFAC describes: management commitment, risk assessment, internal controls, testing and auditing, and training. A programme that exists only on paper carries little weight. Third, the remedial action taken after discovery: how quickly was the gap identified, what was done to close it, and has OFAC been given clear evidence of those steps? Fourth, the absence of prior violations: a business encountering this for the first time, with a documented compliance history, is assessed differently from a repeat subject.
Aggravating factors work in the other direction. Senior management involvement or wilful blindness, a pattern of violations, deliberate concealment, and harm to US foreign policy objectives all push the determination toward the higher end of the range – or toward a referral to the Department of Justice for potential criminal exposure.
How did mitigation apply in this matter?
In this particular engagement, several mitigating factors were available. Others required careful handling to preserve their value. A complete VSD was filed within a short period of the initial identification. The filing covered both payments, the full factual record, and the business's account of the screening gap. It did not minimise, and it did not over-explain. OFAC's guidelines give maximum mitigation value to a VSD that is complete, timely, and candid.
The business had a functioning compliance programme. It was not perfect – the re-screening gap was the proof – but it was genuine. Management commitment was documented. Training records existed. The programme had been tested. In our experience, OFAC's examiners read programme documentation carefully; they will identify quickly whether a programme is operational or merely archival. We advised the client to produce the programme evidence systematically and to be explicit about what the gap was, rather than allowing OFAC to discover it independently during the review.
Remedial action was a strong point. Within weeks of the discovery, the business had implemented transaction-level re-screening, updated its counterparty data feed, and rerun the complete customer base against the current list. Those steps were documented and included in the response. The speed and thoroughness of the remedial action directly addressed one of OFAC's central concerns: whether this business poses a continuing risk.
The harm involved in the payments was limited. The amounts were small. There was no evidence that the designated counterparty used the funds in a way that harmed any US foreign policy objective. That factual record mattered. OFAC's assessment of harm is not confined to the payment amount; it extends to the geopolitical consequence of the specific transaction. In this case, the harm analysis supported mitigation rather than aggravation.
The business had no prior OFAC violations. A clean enforcement history is a straightforward mitigant, but only if it is demonstrated rather than asserted. We obtained and presented the relevant internal records confirming the absence of prior findings.
The cross-border angle: how OFSI and the EU handle mitigation differently
Any business with cross-border operations faces the possibility that a single compliance failure generates exposure in more than one regime. The technology distributor here had EU operations. That meant the EU sanctions regime was also relevant to the analysis, even though the payments in question ran through a US-correspondent bank and the primary exposure was under OFAC.
OFSI, the UK financial-sanctions authority, applies a mitigation analysis that resembles OFAC's in broad structure but differs in important ways. OFSI's published enforcement guidance identifies the existence and quality of a compliance programme as a key factor – a point that maps closely to OFAC's treatment. However, OFSI applies a strict-liability standard: a person can be penalised for a breach even without knowledge or intent. That shifts the weight in a UK matter away from awareness-based factors and toward programme quality and remediation. OFSI also maintains a formal monetary penalty regime under the applicable SAMLA provisions, with a separate civil enforcement track and a different relationship between a voluntary disclosure and the penalty outcome.
Under the EU sanctions regime, enforcement is decentralised: each member state's competent authority applies the relevant Council regulation through its own national enforcement law. There is no single EU-wide VSD mechanism. In practice, this means that a business with operations across multiple member states may face parallel enforcement proceedings with different procedural rules, different mitigation frameworks, and different penalty scales. Coordination between national authorities does occur but is not guaranteed. If you are advising a client with a potential violation that touches both an OFAC-jurisdictional payment and EU-based operations, the starting point is to map each regime's exposure before deciding how and where to make any voluntary disclosure.
The practical consequence of this divergence is that a mitigation strategy developed solely around OFAC's framework may not serve the business in a concurrent OFSI or EU matter. We regularly advise clients on exactly this coordination question. The answer is not to apply one set of principles universally, but to assess each regime's specific requirements and to sequence any disclosures and responses so that one filing does not inadvertently prejudice the position in another.
For a related analysis of how these mitigation principles apply in an EU enforcement context, see our matter note at Apparent violation assessment: EU enforcement service.
When to involve counsel – and the common mistakes that reduce mitigation value
The most consequential decision a business makes after identifying a potential OFAC violation is how quickly it brings in specialised counsel. In our practice, the cases that resolve most favourably are those where counsel is instructed before any communication goes to OFAC. The cases that face the most difficulty are those where the business has already sent an incomplete or misleading initial response, or where a VSD was filed without a proper look-back.
Several recurring errors reduce or eliminate mitigation value. An incomplete look-back is the most common: businesses identify the payment that triggered the bank query and stop there, without examining whether the same counterparty appears elsewhere in the transaction record. OFAC will conduct its own review; if it finds items the business did not disclose, the credibility benefit of the VSD is lost.
A compliance programme presented defensively – emphasising its existence rather than its operation – is another consistent problem. OFAC is not satisfied by a policy document. The examiners ask whether the programme was actually running, whether the gap was a systematic failure or an isolated incident, and whether management knew about it. A response that reads as damage-limitation rather than candour typically produces worse outcomes than one that acknowledges the failure directly and explains what has been done about it.
Delayed remediation is also costly. A business that discovers a screening gap in January but does not close it until after OFAC's examiner visit in March has forfeited one of the strongest mitigation points available. The sequence matters: fix the problem, document the fix, then present the evidence of the fix to OFAC. Have you reviewed your screening logic for transaction-level gaps since your last programme update?
The position above covers the standard case. Your facts – the counterparty, the amounts, the programme, the timeline, the regime in play – change the analysis materially. To discuss the specifics of a potential OFAC violation, contact Calder & Vance at info@caldervance.com.
What happened: the outcome and its limits
The matter resolved without a civil monetary penalty. OFAC issued a cautionary letter acknowledging the VSD, the compliance programme evidence, and the remedial steps taken. That outcome cannot be promised in advance, and it is not the universal result of filing a VSD. OFAC's determination is case-specific and depends on the full record. The purpose of presenting this matter is not to suggest that a similar result is available in every case, but to show how the mitigation factors interact in practice.
The business emerged from the matter with a functioning and improved compliance programme, a documented clean enforcement history going forward, and a clear understanding of where its screening process had been insufficient. Those are, in their own right, valuable outcomes independent of the formal penalty determination.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact our enforcement team at info@caldervance.com to discuss next steps.
The myth: "small transactions don't attract OFAC enforcement"
A persistent misconception in cross-border compliance is that OFAC reserves its enforcement attention for large-value transactions, and that small payments to a designated counterparty can be treated as a de minimis risk. This myth is both legally wrong and operationally dangerous.
OFAC's enforcement guidelines do not set a minimum-value threshold below which a violation is automatically disregarded. Transaction value is one factor in the harm assessment, but it is not a gating criterion. OFAC has issued enforcement findings and cautionary letters in respect of transactions involving modest sums where the programme failures were significant or where the business failed to disclose promptly. The size of the payment affects the penalty calculation; it does not determine whether the violation is prosecuted.
The practical implication is clear: a screening hit involving a small payment deserves the same initial analytical rigour as one involving a large one. The VSD decision, the look-back scope, and the programme review should proceed on the merits of the legal analysis, not on a dollar-value heuristic. In our experience, the businesses that apply a threshold test to their violation triage are consistently the ones that face the largest gap between the penalty they could have avoided and the one they ultimately pay.
For an in-depth review of internal investigation procedures in OFAC matters, see our internal investigation matter note.
For a comparison of OFSI's approach to mitigation in a similar enforcement scenario, see our OFSI enforcement mitigation matter note.
Related practices
- Apparent violation assessment: EU enforcement – structuring your response to an EU apparent violation notice
- Internal investigation in an OFAC matter – scoping and conducting the look-back when a potential violation surfaces