An OFAC Civil Investigative Demand lands in a company's legal inbox on a Tuesday morning. By the following week, the compliance team has three competing demands: preserve all relevant records, respond promptly to avoid a finding of non-cooperation, and avoid producing material that prejudices a parallel criminal inquiry. Each of these objectives can conflict with the others. Getting the sequencing wrong is costly – not just in penalty terms, but in terms of how OFAC characterises the company's compliance culture in any subsequent enforcement action.
Responding to regulator information requests under OFAC rules requires a business to engage promptly and completely with the Office of Foreign Assets Control, the US Treasury bureau responsible for administering and enforcing economic sanctions. OFAC has broad authority under IEEPA and related statutes to demand documents, records, and information relevant to any apparent violation or compliance review. The manner and quality of a response – whether voluntary, timely, and complete – is a named aggravating or mitigating factor in OFAC's penalty framework. Businesses that delay, produce partial records, or fail to seek counsel at the outset consistently face worse outcomes than those that engage early.
This briefing explains who administers this process, what OFAC can demand and why, how the response procedure works in practice, where the major risk points arise, and how the position compares with the equivalent regimes under OFSI in the United Kingdom and the EU sanctions enforcement structure. Read it before the request arrives.
Who administers OFAC's information-request authority, and on what legal basis?
OFAC – the Office of Foreign Assets Control, a bureau of the US Department of the Treasury – administers the United States' economic sanctions programmes. Its authority to demand information rests on IEEPA, the International Emergency Economic Powers Act, and on TWEA, the Trading with the Enemy Act, together with the programme-specific implementing regulations issued under those statutes. OFAC does not need a court order to demand records. The demand issues directly from the agency.
The scope of OFAC's investigative authority is wide. It covers any person subject to US jurisdiction and, through the extraterritorial reach of secondary sanctions, certain non-US persons whose conduct touches a US-sanctioned activity. A non-US subsidiary of a US parent, a foreign bank processing US-dollar transactions, and a trading company using US-origin goods can each fall within OFAC's practical reach. The question of jurisdiction is often the first legal issue to address when a request arrives.
As of April 2026, OFAC's enforcement workload spans multiple programme areas simultaneously. Its Enforcement Division, rather than any single specialist branch, issues information requests. The Enforcement Division also evaluates responses in light of OFAC's published enforcement guidelines, which set out the factors OFAC weighs when deciding whether a violation is egregious and how to calibrate a penalty.
What forms does an OFAC information request take?
OFAC uses several distinct mechanisms to gather information, and the obligations that attach to each differ in important practical respects. Understanding which type of request has arrived is the first step in calibrating an appropriate response.
The most formal mechanism is a Civil Investigative Demand (a written demand that legally compels a target to produce specified documents, data, and testimony). A CID is issued where OFAC has reason to believe that a violation may have occurred. It carries legal compulsion: failure to comply, or obstruction of the investigation, can itself constitute a separate violation and will be treated as an aggravating factor. In our experience, CIDs arrive with a production deadline measured in weeks rather than months, and extensions require early, reasoned engagement with the Enforcement Division.
OFAC also issues less formal written information requests, sometimes called letters of inquiry or pre-penalty investigation letters. These are not CIDs but they carry real practical weight. A failure to respond fully and promptly to a letter of inquiry can cause OFAC to escalate to a formal CID, to draw adverse inferences about the completeness of a compliance programme, or to treat non-cooperation as an aggravating factor when it later issues a penalty notice.
A third category is the request embedded in a licensing review or a voluntary self-disclosure follow-up. Here OFAC is testing the accuracy and completeness of what the submitting party has already said. Incomplete or inconsistent answers in this context are particularly damaging, because they cast doubt on the underlying voluntary self-disclosure. Have you verified that your submission and your follow-up answers tell a consistent story?
How does the response procedure work in practice?
The moment an OFAC information request is received, the response clock starts – but equally important, the preservation obligation starts. Any document-destruction routine that runs after the request arrives is, in the normal course, an obstruction risk. The first instruction from counsel is always to suspend scheduled deletion and to map the relevant data repositories.
From that point, the procedure runs in broadly five phases. First, assess jurisdiction: confirm whether the entity receiving the request is, in fact, subject to OFAC's authority, and whether the request covers only that entity or extends to affiliates. Second, analyse the scope: read the request precisely, identify what categories of documents are sought, and flag any privilege, confidentiality, or data-protection conflicts before beginning production. Third, engage early on timing: if the production deadline is unworkable, OFAC's Enforcement Division will often grant a short extension where the request is reasoned and made promptly. Silence is not a strategy. Fourth, assemble and review the production: every document that goes to OFAC should be reviewed before it is produced, not only for relevance but for privilege and for anything that might require separate counsel advice before disclosure. Fifth, prepare a covering letter that contextualises the production, identifies any gaps and explains them, and – where relevant – lays the foundation for a voluntary self-disclosure (a proactive report of an apparent violation to OFAC, which the agency names as a significant mitigating factor in its penalty calculation).
In a recent matter, a financial-services group based outside the United States received an OFAC letter of inquiry relating to payment transactions that had passed through its US correspondent bank. We mapped the group's transaction records, engaged with the Enforcement Division on scope and timing, and prepared a structured production accompanied by a voluntary self-disclosure covering the subset of transactions that presented exposure. The voluntary self-disclosure was one of the factors OFAC took into account when declining to pursue a penalty notice. No outcome can be promised, but early and structured engagement consistently outperforms delay.
Where do the major risk points arise when responding?
Five risk points recur across OFAC information-request matters, and each is avoidable with early counsel involvement.
Scope creep. Producing more than the request covers can disclose matters OFAC was not investigating. A carefully scoped production protects the entity from self-inflicted exposure on unrelated issues. Equally, producing less than the request covers without explaining the gap is treated as non-cooperation.
Privilege waiver. US attorney-client privilege and work-product protection apply, in principle, to communications between company and counsel. But the rules on privilege waiver in the context of regulatory productions are technical. A cover letter that characterises privileged communications without expressly reserving privilege can waive the protection. This is one of the most common and expensive errors we see.
Data-protection conflicts. A company with employees or customers in the European Union or the United Kingdom faces a genuine tension between OFAC's demand for records and the data-protection obligations imposed by EU and UK law. There is no automatic EU or UK exemption for US regulatory demands. Producing personal data to a non-EU / non-UK regulator without a lawful transfer basis can itself constitute a separate regulatory breach. This is a live cross-border issue that requires coordinated advice.
Parallel criminal exposure. Where the facts underlying an OFAC investigation could also support a criminal prosecution by the US Department of Justice, a civil response to OFAC that concedes certain facts may create risk in the criminal track. The Fifth Amendment does not protect a company (as opposed to an individual) from compelled production, but the structure and content of the production can still be managed to reduce collateral risk. When a matter has dual-track potential, individual employees who may face personal exposure need separate counsel.
Inconsistency with prior disclosures. If the entity has previously filed a voluntary self-disclosure with OFAC, or has made representations in a licence application, the response to an information request must be consistent with those earlier submissions. OFAC cross-references these documents. Inconsistency is a serious aggravating factor.
How does the OFAC position compare with OFSI and the EU?
Responding to regulator information requests under OFAC rules differs from the equivalent obligations under OFSI in the United Kingdom and the EU sanctions enforcement structure in ways that matter operationally.
Under OFSI – the UK Office of Financial Sanctions Implementation – financial sanctions enforcement operates under SAMLA, the Sanctions and Anti-Money Laundering Act. OFSI has statutory powers to request information from any person it believes has, or has had, possession or control of funds belonging to a designated person, or who can give information relevant to an investigation. The reporting obligation for known or suspected breaches is mandatory and runs to OFSI as soon as practicable. The penalty regime is civil, with maximum penalties set by statute, but OFSI also has a disclosure route to the Crown Prosecution Service where criminal conduct is suspected.
The EU sanctions enforcement structure is more diffuse. Enforcement is largely delegated to EU member states under the relevant Council Regulations, with each state designating competent authorities. The result is that a business with operations across multiple EU member states may face information requests from several national authorities simultaneously, each applying the same EU-level prohibitions but through different procedural rules. There is no single EU equivalent of OFAC's centralised Enforcement Division. In our cross-border practice, this fragmentation is one of the most persistent practical challenges for multinationals: the same underlying transaction can trigger separate investigations in multiple member states, with inconsistent deadlines and disclosure standards.
A cross-cutting point applies to all three regimes: where a business faces concurrent requests from OFAC, OFSI, and one or more EU national authorities, the sequencing of disclosures must be managed carefully. A voluntary self-disclosure to OFAC that admits certain facts may, if it reaches OFSI or EU authorities, pre-empt the narrative in those parallel processes. Coordination of the multi-jurisdictional response is not optional; it is the central strategic question.
The position in other regimes – including those administered by SECO in Switzerland, Global Affairs Canada, DFAT in Australia, and the relevant national authorities in Singapore, the UAE, and Japan – varies by statute and by the maturity of enforcement practice in each jurisdiction. Where a business has operations or counterparties in those jurisdictions, local counsel in the relevant jurisdiction should be engaged to assess the parallel information-request obligations.
What does OFAC look for when evaluating the quality of a response?
OFAC's enforcement guidelines set out the factors the agency considers when characterising a response as cooperative or non-cooperative. Cooperation is not binary. OFAC treats it as a spectrum, and where a company lands on that spectrum directly influences whether OFAC issues a No Action letter, a cautionary letter, or a penalty notice – and, if a penalty, how large.
The positive markers include: producing documents without undue delay; providing a clear and accurate narrative account of the relevant events; identifying and disclosing apparent violations proactively rather than waiting for OFAC to surface them; maintaining and producing adequate records (OFAC's guidelines address the expected standard of record-keeping for businesses subject to its jurisdiction); and engaging constructively with follow-up queries without requiring repeated demands.
The negative markers are symmetrical: delay in production, partial or cherry-picked document sets, inconsistency with earlier disclosures, failure to identify custodians of relevant records, and – most seriously – any indication that documents have been altered or destroyed after the investigation began. We regularly advise clients who have inherited a crisis partly created by their own record-management decisions in the weeks before counsel was engaged. The investigation begins before the request arrives: OFAC's preliminary inquiries, correspondent-bank reports, and third-party disclosures often pre-date the formal demand by months.
Does your organisation know today which data repositories hold the records that would be relevant to an OFAC information request? Have you tested whether your preservation protocols would activate before scheduled deletion runs? These are not hypothetical questions for large exporters, financial institutions, or businesses with cross-border exposure to OFAC-sanctioned programmes.
When should counsel be engaged, and what can counsel do?
Counsel should be engaged the moment an OFAC information request – formal or informal – arrives. Not after the production deadline has been assessed. Not after the compliance team has begun its own document review. Immediately.
The reason is structural. The decisions made in the first forty-eight hours of an OFAC investigation – what to preserve, whether to seek an extension, how to characterise the entity's prior conduct, whether to initiate a voluntary self-disclosure, whether individual executives face personal exposure – set the trajectory of the entire matter. Those decisions cannot easily be reversed. An instruction that goes to counsel four weeks into the process, after internal emails have characterised the apparent violation in unhelpful terms and after a partial production has already been sent, is structurally harder to manage than one that arrives on day one.
In terms of what counsel can do: assess eligibility for voluntary self-disclosure and prepare the submission if appropriate; scope the production, assert privilege, and manage any data-protection conflicts; engage directly with OFAC's Enforcement Division on timing and scope; and, where parallel proceedings are live, coordinate the multi-jurisdictional response. We have acted for businesses ranging from single-jurisdiction exporters to financial groups with operations across multiple OFAC-programme territories, and the one consistent finding is that early engagement materially changes the shape of the process.
If a transaction has already been flagged, or a prior production has created inconsistency with new facts, an early review can preserve options that narrow with time. For a confidential review of a potential breach, or for an assessment of your obligations under an OFAC information request, contact Calder & Vance at info@caldervance.com.
A common misconception: "We are not a US company, so OFAC cannot demand our records"
The most persistent myth in cross-border sanctions compliance is that OFAC's information-request authority stops at the US border. It does not, in practice.
OFAC's reach extends to US persons wherever they are located; to transactions that touch the US financial system; to US-dollar correspondent relationships; to US-origin goods and technology; and, through secondary sanctions, to certain categories of non-US conduct that OFAC regards as supporting a sanctioned programme. A non-US company that routes payments through a US correspondent bank, or that exports goods incorporating US-origin components, has a practical exposure to OFAC's investigative authority even if it has no US establishment.
The extraterritorial dimension is one area where the OFAC position diverges most sharply from the EU and UK regimes. OFSI and the EU authorities derive their investigative authority from the territorial and personal scope of their own instruments, which are generally narrower in extraterritorial reach than OFAC's secondary-sanctions architecture. A European business that dismisses an OFAC information request on the ground that it is not subject to US jurisdiction risks a secondary finding that the non-response itself reflects contempt for US authority – an outcome that can complicate any future US licensing or business relationship.
Non-US companies that receive OFAC correspondence should treat it seriously, obtain US-qualified sanctions counsel, and assess the jurisdictional question carefully before deciding on a response posture. The correct answer may be to contest jurisdiction – but that contest must be conducted through proper channels, not by ignoring the request.
Related practices
- Apparent Violation Assessment – EU – assessing and managing apparent violations under EU sanctions enforcement regimes
- Regulator Information Requests under OFAC – further detail – deeper procedural and strategic analysis of OFAC enforcement requests
- Regulator Information Requests under OFSI – the equivalent UK obligations and how they interact with OFAC