Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · OFAC

Mitigation factors in enforcement under OFAC: scope and obligations

A compliance officer at a multinational trading company receives an OFAC subpoena. The transaction in question cleared eighteen months ago. Screening was in place, but the ownership chain was not fully mapped. A related-party shipment may have reached a blocked destination. The question is no longer whether a violation occurred – it is how serious the consequences will be.

OFAC's civil enforcement regime distinguishes sharply between egregious and non-egregious apparent violations. Mitigation factors in enforcement (qualitative and procedural circumstances that reduce the penalty OFAC imposes) can lower a civil monetary penalty to a fraction of the statutory maximum – or result in no penalty at all. The outcome depends on how the apparent violation is characterised, what the business did before and after discovery, and how counsel presents the full picture to OFAC.

This briefing explains how OFAC's mitigation and aggravation framework operates, how it compares with analogous regimes in the United Kingdom and the European Union, and what a business should do from the moment it identifies an apparent violation.

Who administers OFAC's enforcement regime, and on what legal authority?

OFAC – the Office of Foreign Assets Control, a bureau of the US Treasury – administers civil economic sanctions enforcement under authority delegated principally through the International Emergency Economic Powers Act (IEEPA) and, for older programmes, the Trading with the Enemy Act (TWEA). OFAC issues regulations for each sanctions programme and publishes separate enforcement guidance that governs how it evaluates apparent violations and calculates civil monetary penalties.

Jurisdiction is broad. OFAC asserts authority over US persons anywhere in the world, all persons and entities physically within the United States, US-incorporated entities and their foreign branches, and – under secondary-sanctions doctrine – non-US persons who engage in conduct that triggers a secondary-sanctions designation risk. That extraterritorial reach means a European or Asian company that routes a payment through a US correspondent bank, or that uses US-origin software, can fall within OFAC's enforcement perimeter without any US nexus beyond that single touchpoint.

OFAC's enforcement guidance sets out a two-track approach. An apparent violation is assessed first as egregious or non-egregious. It is then paired with a voluntary self-disclosure (VSD) – a proactive, self-initiated disclosure to OFAC before the agency independently learns of the violation – or the absence of one. The combination of egregiousness and VSD status drives the penalty base before any individual mitigation or aggravation factors are applied.

What are the core mitigation and aggravation factors OFAC applies?

OFAC's enforcement guidance identifies a defined set of general factors – some mitigating, some aggravating – that it weighs when assessing the appropriate penalty or other response. Understanding these factors before a potential violation surfaces is what separates a prepared business from one reacting under pressure.

Key mitigating factors include the following:

  • Voluntary self-disclosure. A timely, complete, and accurate VSD is the single most powerful mitigation lever. OFAC treats a qualifying VSD as a substantial mitigating factor. Where a non-egregious violation is paired with a VSD, the base penalty is typically set at half the transaction value, subject to the applicable floor.
  • Compliance programme in place at the time of the violation. A pre-existing, well-tested sanctions compliance programme – one that screens counterparties, maps ownership chains, and trains relevant staff – signals that the violation was an isolated failure rather than a systemic one. In our experience, businesses with documented programmes almost always receive more favourable treatment than those without any formal structure.
  • Prompt remediation. Steps taken immediately after discovery – halting the activity, freezing payments, correcting the process failure – demonstrate that the business has controlled the harm and reduced the risk of recurrence.
  • Cooperation with OFAC's investigation. Timely and complete responses to OFAC information requests, voluntary production of records beyond what is formally required, and proactive communication with the agency are each treated as mitigating.
  • Minimal harm to sanctions programme objectives. Where the underlying transaction had limited nexus to the targets the programme is designed to address – for example, a de minimis value, or goods with no strategic significance – OFAC will note that the harm was limited.
  • Isolated and unsophisticated violation. A single transaction, with no pattern of conduct, and no deliberate structuring, is treated more favourably than a series of transactions suggesting awareness of the risk.
  • Licences sought in good faith. Where the business or its counterparty sought a licence or legal opinion before the transaction, even if the analysis was ultimately flawed, that effort is credited.

Aggravating factors run in the opposite direction. They include wilful or reckless conduct, management awareness of the violation, harm to the targets of the sanctions programme, concealment or obstruction, a history of prior sanctions violations, and the involvement of a sophisticated financial institution or large corporate with dedicated compliance resources. Where OFAC concludes that senior management knew of the violation and allowed it to continue, the case moves quickly toward the egregious track.

The position above covers the standard analysis. Your facts – the counterparty's identity, the goods, the payment route, the regime in play – change the weighting of every factor. To discuss an apparent violation, contact Calder & Vance at info@caldervance.com.

How does the egregious / non-egregious classification affect the penalty base?

OFAC's penalty matrix uses the egregious / non-egregious distinction as its primary variable, with VSD status as the secondary variable. The resulting four-cell grid drives the base calculation before individual mitigation or aggravation factors are applied.

For a non-egregious case with a VSD, the base penalty is set at half the transaction value, subject to a statutory minimum floor. For a non-egregious case without a VSD, the base is the greater of the transaction value or a regulatory minimum. Egregious cases attract significantly higher base penalties: with a VSD, the base rises to half the statutory maximum per transaction; without a VSD, the base is the full statutory maximum per count. The statutory maximum per transaction is set by statute and adjusted periodically for inflation – verify the current figure before relying on it.

What does this mean in practice? A business that identifies an apparent violation, conducts an honest internal review, and submits a complete VSD before OFAC opens an independent investigation can reduce its penalty exposure by a substantial multiple relative to a business that waits for the agency to come to it. That arithmetic shapes the first decision a business should make when it identifies a potential violation: how quickly can a thorough internal investigation be completed, and can a VSD be submitted while the facts are still within the firm's control?

We regularly advise clients at exactly this decision point. The answer is not always to file a VSD – there are situations where the facts do not yet support a reliable disclosure, or where parallel criminal risk requires a more cautious approach. But the window in which a VSD can still operate as a strong mitigation lever is shorter than most businesses assume.

What is a voluntary self-disclosure, and when should one be considered?

A voluntary self-disclosure (VSD) to OFAC is a written, proactive notice that a business has identified an apparent violation of sanctions regulations. To qualify as a VSD, the disclosure must be initiated by the business before OFAC independently discovers the violation – either through its own investigation, a third-party referral, or a report by another regulator. A disclosure made after OFAC has already opened an inquiry does not qualify as a VSD and loses the associated mitigation credit.

The VSD submission should contain a factual description of the apparent violation, the value and number of transactions, the counterparties involved, the cause of the violation, and the remediation steps already taken or planned. A partial or inaccurate VSD can itself become an aggravating factor if OFAC concludes the business was not fully candid. Accuracy matters more than speed – but speed also matters, because the window before an independent OFAC discovery can close without warning.

In parallel, consider the interaction with other regulators. A US bank or broker-dealer filing a Suspicious Activity Report (SAR) on the same transaction may prompt a FinCEN or DOJ referral to OFAC. A UK business subject to OFSI's mandatory reporting obligation – which requires reporting knowledge or reasonable cause to suspect a breach to OFSI within a defined window – may need to coordinate the timing of a VSD to OFAC with its obligations under the UK regime. We have acted for clients managing simultaneous disclosure obligations across both regimes, and the sequencing of those disclosures requires careful planning.

How do OFSI and EU enforcement compare with OFAC's mitigation approach?

The mitigation principles that apply under OFAC have direct analogues in the UK and EU regimes, but the procedural mechanics differ in important ways – and for any business operating across these jurisdictions, those differences are operationally significant.

Under the UK regime, OFSI – His Majesty's Treasury's Office of Financial Sanctions Implementation – has the power to impose civil monetary penalties for breaches of UK financial sanctions. OFSI's enforcement guidance identifies a list of factors it considers when deciding whether to impose a penalty and at what level. These include cooperation with OFSI's investigation, proactive disclosure, the existence of a compliance programme, and the degree to which the business profited from the breach. The mandatory reporting obligation under the UK sanctions regime requires certain persons who know or have reasonable cause to suspect that a person is a designated person, or has committed a breach, to report to OFSI promptly. Failure to comply with the mandatory reporting obligation is itself an offence. In our cross-border practice, businesses sometimes treat OFSI as the quieter counterpart to OFAC – a mistake that has become increasingly costly as OFSI's enforcement capacity has grown.

At the EU level, enforcement of Council Regulation obligations is decentralised: each member state's competent authority imposes penalties under its national implementing legislation. There is no single EU analogue to OFAC's VSD process. However, cooperation with national authorities and self-reporting are consistently credited in national enforcement decisions across the major jurisdictions. The EU General Court has addressed the standards for designations in annulment proceedings, though the enforcement-penalty function sits with national authorities rather than the Court. For a business facing an apparent EU sanctions breach, the practical question is which member state's competent authority has jurisdiction – and that analysis turns on where the transaction was executed, where the entity is incorporated, and where the relevant financial institution is regulated.

The cross-border divergence matters most when a single transaction engages both OFAC and an EU or UK regime simultaneously. Where that occurs, the strictest prohibition governs, and a business that obtains an OFAC licence does not thereby obtain permission under EU law, or vice versa. We advise clients to map all applicable regimes before any disclosure strategy is finalised.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact us at info@caldervance.com for a confidential assessment.

What risk flags should a business monitor before an enforcement action arises?

The most effective mitigation strategy is one that prevents the violation from occurring in the first place – or, where a violation does occur, ensures the business discovers it internally rather than through an OFAC inquiry. Several recurring risk patterns generate OFAC enforcement actions, and each carries a corresponding compliance control.

Incomplete ownership mapping is the most common root cause. The 50 percent rule (OFAC's rule treating entities owned 50 percent or more in the aggregate by one or more blocked persons as themselves blocked) applies regardless of whether the entity appears on any list. A business that screens only list-match data and does not analyse the beneficial ownership of counterparties will miss this category entirely. Aggregation – where two or more blocked persons each hold a minority stake that together reaches the threshold – is a particular blind spot for automated screening tools.

Correspondent banking and payment routing create exposure for financial institutions that do not control the origin and destination of funds flowing through their systems. Where a US dollar payment clears through a US correspondent, OFAC jurisdiction attaches regardless of where the originating and receiving banks are located. Non-US financial institutions with US dollar clearing relationships must apply sanctions controls at the point of payment origination, not merely at the US correspondent layer.

Re-export and transshipment risk sits at the intersection of OFAC and BIS export-control obligations. A distributor that sells US-origin goods into a third market without verifying the end-user and end-use can create joint OFAC and export-control exposure. Where goods ultimately reach a blocked destination through an intermediary, both the original exporter and the intermediary may face liability.

Cryptocurrency and virtual-asset transfers present a specific compliance challenge. Blockchain analytics tools can identify wallet addresses associated with designated persons, but the speed of transaction settlement and the pseudonymous nature of some transfers mean that violations can occur before screening has completed. De-risking (a financial institution exiting a relationship to avoid sanctions exposure) is a common but commercially costly response; a properly designed real-time screening protocol is the more defensible position.

Acquisitions and joint ventures generate inherited exposure. A buyer that completes an acquisition without screening the target's counterparty book, historical transaction flow, and ownership structure may inherit liability for the target's prior violations. OFAC has made clear that successor liability can attach to acquired entities – and that pre-acquisition due diligence, if thorough and documented, can itself be a mitigation factor if a historical violation subsequently surfaces.

Common misconceptions about OFAC's mitigation framework

One persistent myth is that only large financial institutions face serious OFAC enforcement risk. In our practice, this assumption causes significant harm: mid-market manufacturers, trading companies, and professional-services firms routinely under-invest in sanctions compliance on the basis that OFAC will not prioritise them. OFAC's enforcement record does not support that view. Enforcement actions have reached businesses across a wide range of sectors and sizes. The presence or absence of a compliance programme is a mitigation or aggravation factor in all cases, regardless of the respondent's scale.

A second misconception is that a minor or inadvertent violation does not need to be disclosed because it will never be discovered. The channels through which OFAC receives referrals are broader than most businesses appreciate: correspondent banks, foreign competent authorities, customs data, and – increasingly – signals from commercial data providers are all active sources. A violation that appears contained can surface through a route the business never anticipated. The VSD analysis should be driven by the facts and the firm's legal obligations, not by an optimistic assessment of OFAC's detection capacity.

A third misconception is that submitting a VSD is an admission of guilt that will be used against the business in subsequent proceedings. A VSD is a mitigation tool within OFAC's civil enforcement process. It does not create an automatic referral to DOJ for criminal proceedings. Where criminal risk is present – conduct that was wilful, that involved senior management, or that engaged export-control provisions with criminal penalties – that analysis requires separate assessment with counsel who covers both the civil OFAC and the criminal dimension. But the civil VSD process and the criminal exposure are distinct, and conflating them leads businesses to forgo substantial mitigation credit unnecessarily.

Related practices

Frequently asked questions

Who administers mitigation factors in enforcement under OFAC?
OFAC – the Office of Foreign Assets Control within the US Treasury – administers civil sanctions enforcement and applies the mitigation and aggravation framework under its published enforcement guidelines. OFAC's civil enforcement division reviews apparent violations, assesses each case against the egregious / non-egregious matrix, and issues a final civil penalty, a cautionary letter, or a no-action determination. For matters with a criminal dimension, DOJ exercises separate jurisdiction. The framework applies to all US persons and, under secondary-sanctions doctrine, to non-US persons exposed to US jurisdiction through correspondent banking or US-origin goods or technology.
What does OFAC prohibit in relation to mitigation factors in enforcement?
OFAC does not prohibit mitigation factors themselves – rather, its enforcement guidance defines the circumstances that reduce or increase the civil penalty imposed for an underlying sanctions violation. The underlying prohibitions vary by programme: they typically cover dealings with designated persons, transactions involving blocked property, and facilitation of prohibited transactions by third parties. What the mitigation framework governs is not the prohibition but the penalty response. A business cannot use mitigation factors to authorise a transaction that is otherwise prohibited; only a licence or a general authorisation can do that.
How is mitigation factors in enforcement enforced under OFAC?
OFAC opens an enforcement action when it identifies an apparent violation, whether through its own investigation, a VSD, or a referral. The agency issues a pre-penalty notice setting out the proposed penalty and the factual and legal basis. The respondent has an opportunity to submit a written response presenting mitigation arguments, correcting the factual record, and providing documentation of its compliance programme and remediation steps. OFAC then issues a final penalty or, in appropriate cases, a cautionary letter or a finding of violation without penalty. The entire civil process is administrative; there is no automatic court involvement unless the respondent challenges the final order.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.