Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · OFSI

Understanding responding to regulator information requests under OFSI

A UK-based trading company receives an unexpected letter from the Office of Financial Sanctions Implementation. OFSI is requesting information about a transaction completed several months earlier. The compliance team has never faced this before. What must they produce? How quickly? What happens if the response is incomplete?

Responding to regulator information requests under OFSI rules is a statutory obligation, not an optional exercise in co-operation. Under the Sanctions and Anti-Money Laundering Act (SAMLA) and the relevant thematic sanctions regulations, OFSI holds broad powers to require persons to provide information or produce documents. Failure to comply – or providing false or misleading information – can itself constitute a criminal offence, separate from any underlying sanctions breach. As of April 2026, this power sits at the centre of OFSI's active enforcement posture.

This briefing explains the authority behind these requests, what they typically cover, how a recipient should manage the response process, where cross-border complications arise, and when to involve specialist counsel.

What legal authority underpins an OFSI information request?

OFSI derives its information-gathering power from SAMLA and from the individual thematic regulations made under it. The power is broad: OFSI may require any person to provide information or to produce documents that OFSI reasonably considers relevant to its functions. "Functions" here covers enforcement, monitoring compliance, and administering the licensing regime. The request can be addressed to a direct party to a transaction, to a financial institution that processed a payment, or to a professional adviser who facilitated a deal.

Importantly, the power is not limited to businesses that are themselves suspected of a breach. OFSI regularly exercises it against third parties – banks, lawyers, accountants, freight forwarders – when those parties hold information relevant to another entity's conduct. If your business was one step removed from a suspect transaction, you can still receive a formal information request.

The request is typically delivered in writing. It will identify the statutory basis, describe the subject matter, and set a deadline for response. That deadline is formal. Unlike a voluntary inquiry, a statutory information request carries legal consequences for non-compliance. The obligation to respond is not discretionary.

The position above covers the standard case. Your facts – the nature of the transaction, your role in it, the goods or funds involved, and which regime is in play – change the analysis considerably.

For a preliminary assessment of your obligations on receipt of an OFSI information request, contact Calder & Vance at info@caldervance.com.

What does OFSI typically request – and in what form?

An OFSI information request typically covers three broad categories: records of transactions, identity and ownership information, and communications. Understanding which category applies to your situation shapes the scope of your response effort.

Transaction records are the most common target. OFSI will ask for payment instructions, SWIFT messages, account statements, invoices, contracts, and shipping documents. The request will often specify a date range. It is a mistake to treat that range as a ceiling: if documents outside the stated period are directly relevant to understanding the transaction, omitting them risks an incomplete response.

Identity and ownership information is increasingly prominent, particularly where OFSI suspects that a listed person's interest has been obscured through intermediate holding structures. Here the request may ask for corporate-registry extracts, shareholder registers, beneficial-ownership declarations, and any internal due-diligence records the recipient holds. In our experience, businesses that conduct thorough know-your-customer (KYC) screening at onboarding find this category easier to satisfy; those that relied on informal checks find it more challenging.

Communications – emails, instant messages, board minutes, internal memoranda – are also within scope. OFSI can and does ask for internal communications. Recipients should not assume that internal deliberations are protected from production. Legal professional privilege may protect certain categories of lawyer-client communications, but that privilege must be properly invoked and substantiated; it is not automatic.

Documents are usually required in English. Where original records exist in another language, OFSI may require a certified translation. The cost and time for translation should factor into your response timeline assessment from day one.

How does the response process work in practice?

The response process has four practical stages: receipt and triage, legal-privilege assessment, document collection and review, and submission. Each stage carries its own risk of error.

At receipt and triage, the first task is to read the request carefully and identify exactly what is being asked for. Requests sometimes use broad language. Before collecting anything, confirm the scope with your legal adviser. Misreading the scope – producing too little or too much – both create problems. A narrow response to a broad request leaves OFSI unsatisfied; an over-inclusive response can inadvertently disclose material that is privileged or that relates to unconnected matters.

The legal-privilege assessment must happen early. Communications between your business and its external legal advisers may attract legal professional privilege. Communications between employees, or between your business and third parties, generally do not. Privilege must be asserted document by document; a blanket claim over a folder of emails will not hold. Have your legal adviser conduct this review before the collection is assembled.

Document collection and review is the most resource-intensive stage. Establish a clear custodian list – the individuals whose files, inboxes, and messaging platforms are in scope – and collect systematically. A gap later discovered by OFSI is far more damaging than one you identify and explain proactively. Where documents have been deleted in the ordinary course of business before the request arrived, document that fact clearly and be prepared to explain your retention practices.

Submission should be accompanied by a covering letter that maps the documents to each numbered item in OFSI's request. Do not simply send an undifferentiated bundle. A clear map demonstrates good faith and makes it easier for OFSI to confirm that the request is fully satisfied.

What are the consequences of a deficient response?

The consequences of failing to comply with an OFSI information request are serious. Failing to comply, or knowingly providing false or misleading information, can constitute a criminal offence under the relevant thematic regulations. A criminal prosecution for a response failure is a distinct legal jeopardy from any penalty for the underlying transaction.

Beyond criminal liability, a deficient response will almost certainly escalate OFSI's attention. A business that responds promptly, completely, and accurately signals that it has functioning compliance controls. One that provides incomplete responses, misses deadlines, or appears to withhold documents signals the opposite – and that inference will inform OFSI's enforcement decision on the underlying matter.

OFSI's enforcement guidance makes clear that the quality of a firm's co-operation is a factor in penalty calculations. Proactive, substantive co-operation can reduce the civil monetary penalty applicable to an underlying breach. Obstruction or non-disclosure can increase it. The information-request response and the substantive enforcement investigation are not separate matters; they are part of the same file.

There is a widespread assumption that a thorough internal investigation, completed before responding to OFSI, is always the right approach. That is not always the case. An extended internal review that delays the OFSI response can itself constitute non-compliance. The two processes – internal fact-gathering and formal OFSI response – must run in parallel, not in sequence. If a transaction has already been flagged, or a request has arrived, an early review can preserve options that narrow with time.

For a confidential review of an information request or a potential breach, contact Calder & Vance at info@caldervance.com.

How does this differ from comparable requests under OFAC and the EU regime?

Cross-border businesses frequently ask how OFSI's information-gathering powers compare with those of OFAC (the US Office of Foreign Assets Control) and the EU member-state competent authorities. The differences are material and affect how a multi-jurisdiction business structures its response.

OFAC's equivalent mechanism is an administrative subpoena or a civil investigative demand. The power is similarly broad, and the legal consequences of non-compliance are also severe. However, the procedural context differs. Under OFAC, a recipient has additional avenues to negotiate the scope or timing of production, particularly through its legal advisers engaging the agency's enforcement division directly. OFSI's process tends to be more letter-based and less iterative. In our cross-border practice, we regularly advise businesses that have received simultaneous OFSI and OFAC requests arising from the same transaction. Handling both calls for careful co-ordination: what is disclosed to one authority may not be appropriate to disclose to the other, depending on privilege rules and confidentiality obligations in each jurisdiction.

Under the EU regime, information-gathering powers sit with national competent authorities in each member state. If a business has operations in France, Germany, or the Netherlands, it may receive requests from those national authorities rather than from a single EU-level body. The procedural rules – deadlines, response formats, privilege protections – vary between member states. Switzerland, which maintains its own autonomous sanctions regime administered by SECO, follows a similar decentralised model.

A critical point for UK businesses with EU subsidiaries or EU-based counterparties: the information you hold in London may be subject to an information request from an EU national authority. Sharing that information across borders raises both data-protection and legal-privilege questions that must be addressed before production. The EU Blocking Regulation adds a further layer in specific circumstances, restricting compliance with certain foreign requests. Counsel covering both regimes simultaneously is not a luxury in this scenario; it is a necessity.

The harder practical question is this: if two requests from different authorities produce conflicting obligations, which governs? The answer depends on the hierarchy of norms applicable to your business, the governing law of your contracts, and any applicable blocking or privacy statutes. There is no universal rule. In our experience, the answer must be worked out on the specific facts of each case.

What are the common risk flags that escalate a simple information request?

Not all OFSI information requests are equal. Some are exploratory, aimed at building a fuller picture of an industry or a transaction type. Others are targeted: OFSI has already identified a potential breach and is gathering evidence. Recognising which kind of request you face shapes how you prepare.

The first risk flag is specificity. A request that names specific transactions, specific dates, and specific counterparties signals that OFSI has already identified a potential issue. A broad sectoral request – asking about all transactions involving a particular category of counterparty over a twelve-month period – may be investigative but is less specifically targeted at your business. Specificity means OFSI is closer to a formal investigation.

The second flag is timing. If you have previously self-reported a potential breach via a voluntary self-disclosure (VSD – a report to OFSI identifying a potential breach before the authority discovers it independently), a subsequent information request may indicate that OFSI is testing the completeness of your disclosure. An incomplete VSD that is followed by a broader information request puts you in a difficult position. It is essential that the original VSD and the information-request response are consistent and mutually reinforcing.

The third flag is parallel regulatory interest. If your business is simultaneously under inquiry from HMRC, the Financial Conduct Authority, or a foreign sanctions authority, OFSI's request may form part of a co-ordinated multi-agency investigation. In our experience, businesses that treat each inquiry in isolation, without mapping the connections between them, create unnecessary risk. A statement made to one authority can surface in another's file.

The fourth flag is the request's reference to ownership and control. Where OFSI specifically asks about beneficial owners, ultimate beneficial owners, or the ownership chain behind a counterparty, it is probing the ownership and control test (the UK test for whether a non-listed entity is caught through its relationship with a listed person). This is technically complex ground. The UK test looks at both ownership – whether a designated person holds a significant stake – and control – whether a designated person can direct or influence the entity's activities. Getting this analysis wrong in your response can make a difficult situation significantly worse.

When should you involve specialist counsel, and what will they do?

The question is not whether to involve counsel but when. The right answer, in almost every case, is at the moment the request arrives – before any documents are collected, before any internal communications are sent about the request, and before any preliminary conversations with OFSI take place.

What specialist counsel will do on your behalf falls into three practical phases. First, scope-mapping: reading the request carefully, identifying what is and is not within scope, assessing which documents attract legal professional privilege, and advising on the timeline. Second, managed collection: supervising the custodian interviews, conducting the privilege review, and ensuring that the collection is both complete and appropriately bounded. Third, submission and engagement: drafting the covering letter, mapping documents to request items, and if necessary engaging directly with OFSI to clarify scope or to seek a short extension where genuinely needed.

In a recent matter, a financial-services business received an OFSI information request arising from a correspondent-banking relationship. The request was broad and included a category of documents that attracted legal professional privilege. We scoped the collection, conducted the privilege review, prepared a detailed schedule of documents withheld on privilege grounds, and submitted the response within the required deadline. OFSI confirmed receipt and closed the information phase without further escalation. The matter was managed; it was not escalated to a formal investigation. That outcome is not guaranteed in any case, but early and properly structured engagement with the authority materially improves the position.

A common myth is that responding comprehensively and quickly without legal review demonstrates good faith to OFSI in a way that reduces scrutiny. The opposite is often true. An unguided response that inadvertently over-discloses, that fails to assert valid privilege, or that is internally inconsistent creates more difficulty than a carefully structured response that takes a day or two longer to prepare. Good faith is demonstrated by accuracy and completeness, not by speed alone.

Related practices

Frequently asked questions

Who administers responding to regulator information requests under OFSI?
OFSI – the Office of Financial Sanctions Implementation, an office of HM Treasury – administers financial-sanctions information requests in the United Kingdom. OFSI issues requests under the authority of SAMLA and the relevant thematic sanctions regulations. The ECJU administers export-control matters separately. For businesses subject to both financial sanctions and export-control inquiries, two distinct UK authorities may be relevant, and the obligations under each must be managed independently.
What does OFSI prohibit in relation to responding to regulator information requests?
OFSI's information-gathering rules prohibit knowingly providing false or misleading information in response to a statutory request. They also prohibit failing to comply within the time limit set. Both failures can constitute criminal offences under the applicable thematic regulations. Beyond criminal liability, a deficient response will be treated as evidence of poor compliance culture in any parallel enforcement proceeding and can increase the severity of a civil monetary penalty imposed for an underlying breach.
How is responding to regulator information requests enforced under OFSI?
OFSI can refer a failure to comply with an information request to the Crown Prosecution Service for criminal prosecution. In parallel, OFSI's enforcement guidance provides that the quality of co-operation – including the completeness and accuracy of information provided – is a factor in the severity of any civil monetary penalty for an underlying breach. Obstruction or incomplete disclosure is an aggravating factor. Proactive, complete, and well-documented co-operation is consistently treated as a mitigating factor in published enforcement guidance.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.