Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · OFSI

Remediation after a sanctions breach under OFSI: scope and obligations

A business discovers mid-month that it has made a payment to a counterparty whose ultimate beneficial owner appears on the UK Consolidated List (the official register of persons and entities subject to UK financial sanctions). The transaction has settled. The funds have moved. What must the business do next – and how quickly must it act?

Remediation after a sanctions breach under OFSI rules is a defined, obligation-bearing process governed by the UK's Office of Financial Sanctions Implementation (OFSI), the HM Treasury body responsible for administering and enforcing UK financial sanctions. The governing legislation is the Sanctions and Anti-Money Laundering Act 2018 ("SAMLA") and the relevant thematic sanctions regulations made under it. A firm that identifies a potential breach faces a short statutory window to report, a duty to preserve records, and material decisions about voluntary disclosure – each of which affects the enforcement outcome.

This briefing sets out who administers the UK post-breach process, what OFSI's core obligations require, how the enforcement calculus works, where the UK position diverges from OFAC and EU practice, and the risk flags that warrant immediate legal advice. As of April 2026, OFSI's published enforcement guidance remains the primary operational reference for any business working through a post-breach remediation.

Who administers post-breach remediation under OFSI – and what is its authority?

OFSI sits within HM Treasury and holds the primary mandate for civil enforcement of UK financial sanctions. It can investigate apparent breaches, impose civil monetary penalties, refer matters to law enforcement, and publish details of enforcement action – a power it has used with increasing regularity. Its authority derives from SAMLA and the secondary regulations enacted under it for each thematic sanctions programme.

OFSI's enforcement guidance is the practitioner's reference document. It sets out the factors OFSI weighs when deciding whether to impose a penalty, how it calculates the amount, and what weight it gives to a firm's remediation conduct. That guidance is not static: OFSI has updated it in line with the expanded civil-penalty regime that brought the UK's enforcement posture closer to, though still distinguishable from, the OFAC model.

One point that practitioners encounter regularly: OFSI's powers apply to persons operating in the UK and to conduct with a UK nexus. The territorial scope is therefore distinct from OFAC's extraterritorial reach – but a transaction with any UK-incorporated entity, UK bank, or sterling clearing step can bring OFSI into the picture even for a business headquartered outside the United Kingdom. Multi-jurisdictional businesses must map which regulator holds the clearest nexus before deciding how to sequence their notifications.

What are the core reporting and disclosure obligations after a suspected breach?

The obligation to report a suspected breach to OFSI is immediate upon knowledge. SAMLA and the relevant thematic regulations impose a duty on persons who know or have reasonable cause to suspect that they have breached a prohibition, or that they hold funds or economic resources belonging to a designated person, to disclose that knowledge or suspicion to OFSI without delay. Delay itself becomes an aggravating factor in any subsequent enforcement assessment.

The reporting duty applies broadly. It is not confined to regulated-sector firms. Any business that holds or controls funds or economic resources caught by a designation must report. Financial institutions additionally face obligations under sector-specific rules – including anti-money-laundering and counter-terrorist-financing requirements – that layer on top of the OFSI notification duty and may involve separate reports to other authorities.

What should the report contain? OFSI's published guidance indicates that a disclosure should identify the designated person, the funds or economic resources held, the estimated value, and the basis for the suspicion. An early report that is frank and complete carries more weight in mitigation than a delayed report that arrives only after an authority's own enquiries surface the issue. In our experience, businesses that act promptly and document their decision-making from the moment a screen hit is identified are materially better positioned in any enforcement dialogue that follows.

The distinction between a mandatory report and a voluntary self-disclosure (VSD – a proactive notification that goes beyond the statutory minimum, describing the breach in full, offering a root-cause analysis, and setting out remediation steps already taken) matters here. A mandatory report satisfies the legal obligation. A well-structured VSD can reframe the enforcement outcome entirely.

How does voluntary self-disclosure affect the enforcement outcome under OFSI?

A voluntary self-disclosure that meets OFSI's published criteria – prompt, complete, candid about the root cause, and accompanied by concrete remediation steps – is one of the most powerful mitigation tools available to a business facing an apparent breach. OFSI's enforcement guidance explicitly identifies VSD as a factor that can significantly reduce a civil monetary penalty, and in some cases it has led OFSI to resolve matters without a public penalty notice.

The timing and quality of a VSD are not interchangeable. A disclosure made after OFSI has already opened an investigation carries less weight than one made before any regulatory contact. A disclosure that identifies the breach but omits known related transactions, or that minimises the root cause, can harden OFSI's view rather than soften it. Completeness is not optional.

Should every apparent breach result in a VSD? Not automatically. The decision requires an assessment of whether a breach actually occurred (the legal analysis), the firm's broader exposure, whether any licence or general authorisation covers the transaction, and what the disclosure would require the firm to say. That analysis is counsel's work – and it should be completed, or at least materially advanced, before the disclosure is filed. Acting without legal review can lock a firm into a characterisation it later cannot walk back.

In a recent matter, a mid-size trading company identified a payment that had passed through an account connected to a designated person. We scoped the apparent violation, assessed whether a general licence under the applicable regime covered the transaction, and prepared a structured VSD that included a root-cause analysis and a revised screening protocol. The matter was resolved at the lower end of OFSI's enforcement range. We state that as an illustration, not a guarantee: outcomes depend on the specific facts and OFSI's own assessment.

What records must a business preserve – and for how long?

Record preservation is a distinct obligation, separate from the reporting duty, and non-compliance can itself become the subject of enforcement action. Under the relevant thematic sanctions regulations, persons who carry out transactions subject to financial sanctions requirements must keep records sufficient to establish that the transaction complied with the applicable rules. The applicable record-keeping period under OFSI's framework is five years from the date of the transaction or the end of the business relationship, whichever is later.

In a post-breach remediation, record preservation takes on additional urgency. Documents that show when a firm first received information about a potential designation, what screening processes were in operation at the time, who approved the transaction, and what enquiries were made before execution become the evidentiary foundation for any enforcement dialogue. Deleting, amending, or failing to locate those records after a breach is identified can transform a civil matter into a criminal one.

Practically, the first step after a potential breach is identified should be a document hold. That means suspending automated deletion schedules, notifying the relevant custodians, and securing communications and transaction records. The scope of the hold should be set conservatively: include adjacent transactions, the screening logic at the relevant date, and any ownership-structure analysis that was or should have been conducted at onboarding.

The five-year rule is worth comparing to the OFAC position. Under OFAC, record-keeping requirements for licensed transactions are set at a similar period, and enforcement practice places the same premium on contemporaneous documentation. The EU regime under the relevant Council regulations also imposes record-keeping obligations. Where a single transaction touches multiple regimes, the most demanding requirement governs in practice – because a document that cannot be produced to one regulator will also be unavailable to another.

How does OFSI's enforcement posture compare with OFAC and the EU?

Understanding where the UK sits relative to other regimes is essential for any cross-border business managing a multi-jurisdictional remediation. The three principal regimes – OFSI, OFAC, and the EU – share a broad architecture but differ in enforcement posture, territorial reach, and the weight given to mitigation factors.

OFAC operates under a strict-liability model for civil violations: intention is irrelevant to whether a violation occurred. Penalties can be substantial, and OFAC publishes detailed enforcement releases that name the entity and set out the aggravating and mitigating factors. Its extraterritorial reach – the ability to penalise non-US persons for dealings that touch the US financial system or that involve US-origin goods – means that a firm managing an OFSI matter may simultaneously face OFAC exposure. Secondary-sanctions risk is a distinct, additional layer.

The EU regime, administered through the Council regulations and enforced by member-state authorities, operates differently. There is no single EU enforcement body equivalent to OFSI or OFAC: enforcement is national. That means a breach with EU-member-state dimensions may produce enforcement proceedings in more than one EU jurisdiction, each with its own procedural timeline and penalty range. EU law imposes an ownership and control test (the test for whether a non-listed entity is effectively controlled by a listed person) that parallels but is not identical to OFSI's formulation. Divergences in how control is assessed can determine whether the same transaction triggers a breach in the UK, in the EU, or in both.

OFSI's enforcement posture has hardened since the civil-penalty regime was strengthened under SAMLA's amendments. OFSI can now impose penalties without needing to prove that the person knew they were breaching sanctions – a strict-liability approach for the civil track that aligns more closely with OFAC. However, OFSI retains a broader discretion to resolve matters through a monetary penalty notice, a warning letter, or no formal action, depending on the severity and the quality of the firm's response. That discretion is where remediation conduct matters most.

The position above covers the general architecture. Your facts – the goods or services involved, the counterparties, the jurisdictions of incorporation, the clearing path, and the applicable regime – can shift the analysis materially. For a cross-regime assessment of a transaction that may have touched both OFSI and OFAC, contact Calder & Vance at info@caldervance.com.

What risk flags should prompt immediate legal advice?

Not every screen hit or uncomfortable transaction requires an immediate call to counsel. But certain indicators signal that the risk profile has moved beyond routine compliance management. Businesses that recognise these flags and act on them promptly preserve options that close quickly.

  • A confirmed designation match – where the counterparty, its ultimate beneficial owner, or an entity captured by the 50 percent rule (OFSI's rule treating entities owned 50 percent or more by designated persons as themselves subject to the relevant prohibition) appears on the UK Consolidated List, and a transaction has already settled.
  • A freeze obligation that has not been applied – funds or economic resources belonging to a designated person that have not been frozen pending OFSI's further instructions.
  • A payment through a UK-nexus channel – a transaction involving a UK bank, a sterling clearing step, or a UK-incorporated intermediary that touches a designated person under any regime, because the nexus may simultaneously engage OFSI and, if the payment involved US correspondent banking, OFAC.
  • Receipt of an information request from OFSI – OFSI's formal request for information is a procedural step that carries its own response obligations and timeline. Engaging without legal advice at this stage is a significant risk.
  • Aggregate exposure across multiple transactions – where a root-cause review reveals that the control failure producing one apparent breach has generated a pattern of non-compliant activity across multiple transactions, OFSI's aggravated-penalty provisions become directly relevant.
  • Concurrent exposure under another regime – where the same transaction or counterparty is also under review by OFAC, a European national authority, or another regulator, the sequencing of disclosures and the consistency of the factual narrative across jurisdictions require co-ordinated management.

If a transaction has already been flagged, or an OFSI information request has arrived, an early review can preserve options that narrow with time. To discuss your exposure under the OFSI regime, contact Calder & Vance at info@caldervance.com.

A common misconception about OFSI remediation

A persistent myth in the market is that small-value transactions attract no meaningful enforcement interest from OFSI. The reasoning runs: OFSI is a resource-constrained body; it will pursue high-value breaches and ignore everything below a certain threshold. That view is incorrect – and acting on it can prove costly.

OFSI's enforcement guidance identifies the value of a transaction as one factor in its assessment, but it is not a safe-harbour threshold. OFSI has taken enforcement action in matters involving relatively modest sums when the breach reflected a systemic control failure, a pattern of repeated non-compliance, or a deliberate disregard of a known designation. The reputational element of a published penalty notice – which names the business and sets out the facts – can cause commercial damage well beyond the face value of the penalty. Moreover, a pattern of small-value transactions with a designated person can in aggregate produce a more serious enforcement outcome than a single large transaction that was the product of a genuine control failure.

In our cross-border practice, we regularly advise businesses that have assumed a de minimis position protects them, only to find that OFSI's analysis focuses on the firmness of their controls and the credibility of their response rather than the size of the amount involved. The threshold question is not "how much?" but "how did this happen, and what have you done about it?"

Related practices

Frequently asked questions

Who administers remediation after a sanctions breach under OFSI?
OFSI – the Office of Financial Sanctions Implementation, a unit of HM Treasury – is the administering and enforcing authority for UK financial sanctions, including post-breach remediation obligations. It operates under SAMLA and the relevant thematic sanctions regulations. OFSI has the power to investigate, impose civil monetary penalties, refer matters to law enforcement, and publish enforcement details. For concurrent cross-border exposure, OFAC and EU national enforcement authorities may hold separate jurisdiction over the same facts, requiring co-ordinated engagement across regimes.
What does OFSI prohibit in relation to remediation after a sanctions breach?
OFSI does not prohibit remediation itself – it mandates it. The relevant thematic sanctions regulations require immediate reporting of known or suspected breaches and the preservation of records for five years. What OFSI's regime prohibits is making funds or economic resources available to designated persons without a licence, freezing obligations not applied, and failing to disclose known or suspected breaches. Non-compliance with post-breach obligations – delayed reporting, incomplete disclosure, or inadequate record-keeping – functions as an independent aggravating factor in any civil or criminal enforcement assessment.
How is remediation after a sanctions breach enforced under OFSI?
OFSI can impose a civil monetary penalty on a strict-liability basis for the underlying breach; intention is not required for civil liability. Enforcement outcomes range from no formal action (for minor or inadvertent breaches with strong remediation) through a warning letter to a formal monetary penalty notice that is typically published. OFSI's guidance sets out the aggravating and mitigating factors it applies, with voluntary self-disclosure, the quality of remediation, and co-operation all carrying weight. For the most serious cases, OFSI can refer the matter to the Crown Prosecution Service for criminal proceedings.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.