Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · OFSI

Apparent-violation assessment under OFSI: compliance counsel

A UK-licensed bank processes a payment for a corporate customer. Post-execution screening returns a potential match: one beneficial owner of the counterparty appears on the Office of Financial Sanctions Implementation (OFSI – the UK Treasury body responsible for licensing, enforcement, and civil penalty decisions under the Sanctions and Anti-Money Laundering Act, known as "SAMLA") consolidated list. Is the transaction a breach? Does it need to be reported? Can the firm continue to service the account? The answers to all three questions turn on whether the facts amount to an apparent violation (a transaction or arrangement that, on the available evidence, may have contravened UK financial sanctions).

An apparent-violation assessment under OFSI is the structured legal review a firm must conduct when it identifies a potential sanctions breach – examining the applicable prohibition, the ownership-and-control facts, any available licence or exception, and the reporting obligation that runs in parallel. Getting this assessment right, fast, matters: OFSI operates a mandatory reporting window, and how you frame the voluntary disclosure that may follow affects the penalty outcome materially. Specialist apparent-violation assessment OFSI legal support is not a luxury at this stage; it is the mechanism that distinguishes a managed outcome from an uncontrolled one.

As of April 2026, OFSI's enforcement posture has hardened. This page explains the legal basis, the step-by-step assessment process, how the UK position diverges from OFAC and EU tests, the risk flags that practitioners most frequently encounter, and how Calder & Vance assists clients from the moment a potential breach surfaces.

What is the legal basis for OFSI's enforcement authority?

OFSI's power to investigate, penalise, and publicise apparent violations derives from SAMLA and the relevant thematic sanctions regulations made under it. The regime is civil, not criminal, in the first instance – OFSI imposes monetary penalties on a civil-standard finding that a person knew or had reasonable cause to suspect that they were dealing with a designated person. A parallel criminal track exists for deliberate breaches, but the civil route is the one most firms encounter first.

The governing test has two limbs. First, a prohibition must have been contravened – dealing, making available, or facilitating a financial benefit for a designated person or an entity they own or control. Second, the respondent must have known, or had reasonable cause to suspect, the contravention at the time it occurred. OFSI's published enforcement guidance makes clear that the "reasonable cause to suspect" limb catches firms that failed to run adequate screening, not only those who had actual knowledge of a designation.

Penalty levels are significant. OFSI can impose a civil penalty of up to the greater of a fixed statutory ceiling or a multiple of the value of the breach, whichever is higher. Where a firm holds a licence or had a genuine belief in the lawfulness of the transaction, that bears on mitigation – but it does not automatically bar a finding of liability. One critical point: the value-based uplift means that a single high-value payment can produce a very large penalty even where the underlying compliance failure was procedural rather than deliberate.

The position above covers the standard enforcement path. Your specific facts – the nature of the transaction, the counterparty structure, the screening process you had in place – change the analysis significantly.

For tailored advice on how OFSI's enforcement guidance applies to your situation, contact Calder & Vance at info@caldervance.com.

How does the ownership-and-control test work under OFSI?

Under the UK regime, a non-listed entity falls within the prohibition if a designated person owns or controls it – and the test is broader than many compliance teams expect. Ownership and control (the UK and EU test for whether a non-listed entity is caught through a listed person) captures both direct and indirect holdings, but it extends further: a designated person may "control" an entity through board composition, veto rights, or other means of directing activity, even where their ownership stake alone falls below a threshold.

This diverges from OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked), which is purely mathematical and aggregates across all blocked holders. Under OFSI and the EU, a factual assessment of actual control is required in addition to the ownership calculation. In practice this means that a counterparty with a 35 percent stake held by a designated person may still be caught if that person directs its day-to-day affairs – a question that ownership-only screening systems do not answer.

When conducting an apparent-violation assessment, counsel must therefore go beyond the screening result. The steps are: verify the identity of the person flagged, check the current designation status and the list version used at the time of the transaction, map the full ownership and control chain to the counterparty, and then determine whether the transaction involved "dealing with" that counterparty's funds or economic resources within the meaning of the applicable regulations.

In our experience, firms that maintain only entity-level screening – without mapping indirect ownership – face the greatest exposure during OFSI reviews. Have you tested your screening logic against a multi-layered structure recently?

What is the apparent-violation assessment process step by step?

The apparent-violation assessment process begins the moment a potential match is identified, and the steps must be sequenced carefully to protect both the firm's legal position and its reporting obligations. There is no single statutory timetable for the internal assessment itself, but the mandatory reporting obligation under SAMLA runs from the moment a person in the regulated sector knows or suspects that a customer or transaction is subject to a prohibition – making speed essential.

The assessment typically moves through the following phases:

  1. Triage: establish whether the screening alert is a true positive or a false positive. Confirm the identity of the flagged person against OFSI's consolidated list and the counterparty's actual beneficial-ownership data. Many alerts resolve at this stage.
  2. Prohibition mapping: if the alert survives triage, identify which specific prohibition may have been contravened. Is the issue a frozen-assets restriction, a prohibition on making funds available, or a restriction on ancillary services? The answer determines the applicable penalty ceiling and the reporting route.
  3. Licence and exception review: check whether a general licence, a specific licence, or a statutory exception covers the transaction. OFSI issues both general licences (standing authorisations for defined transaction categories) and specific licences (case-by-case authorisations for otherwise prohibited activity). If a valid licence was in place, a prohibition may not have been contravened at all.
  4. Knowledge and suspicion analysis: assess what the firm knew or had reasonable cause to suspect at the time of the transaction. This is the limb that OFSI focuses on most closely in penalty proceedings, and it is where contemporaneous documentation of the screening decision becomes decisive.
  5. Reporting assessment: determine whether the facts trigger the mandatory report to OFSI and, if so, draft and submit the report. For regulated-sector firms, this obligation is separate from any subsequent voluntary self-disclosure (VSD – a proactive submission to a regulator of an apparent violation, typically accompanied by a root-cause analysis and a remediation plan) on penalty mitigation, though the two processes interact.
  6. VSD and mitigation strategy: if a civil penalty process appears likely, prepare the VSD, the root-cause analysis, and the remediation evidence. OFSI's enforcement guidance treats a well-structured VSD as a significant mitigating factor – but only when it is prompt, complete, and candid.

In a recent matter, a financial institution in the payments sector identified a potential breach after a transaction had already settled. We mapped the ownership chain, confirmed the prohibition, and structured the mandatory report and VSD in a single coordinated submission. The matter was resolved through the administrative penalty track, and the mitigation package reduced the assessed penalty materially. We state no guaranteed outcome – but the sequencing and the quality of the submission made a measurable difference to the process.

How does the OFSI process compare with OFAC and EU enforcement?

Any business operating across borders cannot treat an apparent-violation assessment as a single-regime exercise. The same transaction can trigger parallel obligations under OFAC, EU Council regulations, and OFSI – and the tests, timelines, and disclosure mechanics differ in ways that matter operationally.

Under OFAC, the central framework is the Economic Sanctions Enforcement Guidelines, which set out an aggravating-and-mitigating-factor analysis. OFAC's VSD mechanism is well-established and can produce a significant discount on the base penalty amount. The ownership test – the 50 percent rule – is mechanical and applies regardless of control. OFAC operates on a strict-liability basis for civil penalties: knowledge or intent affects penalty level, but the prohibition itself does not require either. That differs from OFSI's requirement to show that the respondent "knew or had reasonable cause to suspect".

Under the relevant EU Council regulations, the enforcement function rests with competent authorities in each member state. The ownership-and-control test mirrors OFSI's in its control limb, and the EU does not have a single pan-EU penalty ceiling. Disclosure obligations, timelines, and the treatment of voluntary disclosure vary across member states, which creates genuine complexity for a business that may face simultaneous proceedings in multiple jurisdictions. The EU Blocking Regulation adds a further layer: where a business faces conflicting US and EU legal obligations, the EU rules may restrict compliance with OFAC demands.

For businesses with Singapore, UAE, or Japanese counterparties, the local regime obligations are increasingly active. Singapore's Monetary Authority maintains its own sanctions list and reporting requirements. UAE financial institutions are subject to Cabinet resolution obligations and Central Bank expectations. Japan's METI and Ministry of Foreign Affairs administer parallel export and financial-sanctions controls. A cross-border apparent-violation assessment must identify which regimes are engaged and sequence the disclosure and remediation steps accordingly – particularly because a disclosure in one jurisdiction can generate information that another authority uses.

If a transaction has already been flagged, or a disclosure has been submitted in one regime but not another, an early cross-regime review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss the position.

What are the most common risk flags in an OFSI apparent-violation assessment?

The risk flags that most frequently complicate an OFSI apparent-violation assessment fall into four categories: screening-system gaps, documentation failures, licence assumption errors, and disclosure sequencing mistakes. Understanding them before they arise is the difference between a well-managed review and a prolonged enforcement process.

Screening-system gaps are the most common root cause. Systems that screen only against OFSI's own list miss designations under EU regulations that continued to apply during a transitional period, or UN Consolidated List entries that OFSI has not yet mirrored. In our cross-border practice, we regularly advise clients who discover post-transaction that their system applied an outdated list version or failed to aggregate indirect ownership holdings.

Documentation failures undermine the "reasonable cause to suspect" defence. If the firm ran a screening check and found no match, but has no record of the list version used, the date of the check, or the identity of the person who cleared it, OFSI has no basis on which to find that the firm acted reasonably. Every cleared screening decision should carry a timestamp, a list version, and an approver. That record must be retained for the applicable statutory period – verify the current record-keeping requirement before relying on any assumed timeframe.

Licence assumption errors arise when a business assumes that a general licence covers its transaction without reading the conditions carefully. General licences contain geographic, counterparty, and value conditions. A transaction that looks covered may fall outside the conditions on close reading, and OFSI does not accept reliance on an inapplicable general licence as a full defence.

Disclosure sequencing mistakes occur when a firm files a mandatory report to OFSI before it has completed its internal assessment of the facts. A mandatory report submitted with incomplete or later-revised facts can complicate the subsequent VSD process and may reduce OFSI's confidence in the firm's candour. The internal assessment and the external disclosure must be sequenced deliberately.

Is a voluntary self-disclosure always the right course of action?

The decision to submit a VSD to OFSI is a legal strategy decision, not an automatic compliance step. A well-prepared VSD can significantly reduce the civil penalty that OFSI would otherwise impose, and OFSI's published enforcement guidance identifies early, complete, and accurate disclosure as a substantial mitigating factor. But the decision must be made on the specific facts.

A VSD that is submitted before the facts are fully understood can acknowledge a broader violation than the evidence supports. It can also lock a firm into a factual account that is difficult to revisit later. In our experience, firms that instruct counsel before submitting a VSD – rather than after – produce more focused, accurate submissions that better serve both the reporting obligation and the penalty mitigation objective.

The VSD itself should address: the nature and value of the transaction, the identity of the designated person involved, the screening process in place at the time, the root cause of the failure, the steps taken to prevent recurrence, and the evidence of remediation already completed. OFSI is more likely to treat a submission favourably when the firm demonstrates that it identified the issue through its own compliance processes rather than through external discovery.

One persistent myth in this area is that submitting a VSD guarantees immunity from a civil penalty. It does not. OFSI retains full discretion to impose a penalty even after receiving a complete and candid disclosure. What a well-structured VSD does is shift the penalty calculation materially toward the lower end of the applicable range – and, in some cases, result in a settlement that avoids formal penalty proceedings entirely. The outcome depends on the facts, the quality of the submission, and the strength of the remediation evidence.

How Calder & Vance assists with apparent-violation assessment under OFSI

Calder & Vance acts for financial institutions, corporates, and individuals at every stage of the apparent-violation assessment process. Our work in this area is specific and action-oriented: we do not produce general compliance audits at this stage of a matter. We focus on the legal question in front of the firm, and we move quickly.

Our action library for OFSI apparent-violation work includes:

  • Rapid triage of screening alerts to confirm true-positive status and map the applicable prohibition within 24 to 48 hours of instruction, where the facts permit.
  • Ownership-and-control analysis of the counterparty chain, including control-based routes that screening tools do not surface.
  • Licence review: confirming whether a general or specific licence covers the transaction, and advising on emergency specific-licence applications where a prohibition can be lawfully authorised.
  • Mandatory-report drafting and submission to OFSI, with a strategy for managing OFSI's queries.
  • VSD preparation: root-cause analysis, remediation evidence, and the written submission to OFSI, structured to present the mitigating factors in the strongest supportable form.
  • Cross-regime coordination: where the same transaction engages OFAC, EU, or other regime obligations, we identify the sequencing and the points of divergence that affect the disclosure strategy.
  • Penalty defence: if OFSI opens a formal enforcement process, we represent the firm through the administrative review and, where appropriate, before the First-tier Tribunal.

We advise clients who have self-identified a potential breach and need to move quickly, clients who have received an OFSI information request or supervisory inquiry, and clients who are managing a breach identified by a counterparty or regulator. Henry Ashworth leads the UK sanctions enforcement practice and has advised across the financial services, energy, and professional services sectors.

We offer a fixed-fee entry-point assessment: a defined-scope triage and legal analysis of the apparent violation, delivered within an agreed timeframe. This allows a firm to understand its position before committing to a broader engagement.

Related practices

Frequently asked questions

How long does assessing an apparent violation take under OFSI?
The internal assessment timetable is driven by the mandatory reporting obligation under SAMLA, not by a fixed statutory clock for the assessment itself. For regulated-sector firms, the reporting obligation runs from the moment knowledge or suspicion arises – so the assessment must begin immediately. In practice, a well-resourced triage can confirm whether a true positive exists within 24 to 48 hours. A complete VSD package, including root-cause analysis and remediation evidence, typically takes between two and four weeks, depending on the complexity of the counterparty structure and the volume of transaction records involved. The single most important variable is how quickly the firm assembles its screening logs and ownership data. Delays in internal fact-gathering are the most common cause of extended timelines, and they can complicate OFSI's assessment of the firm's candour.
What are the main risks in apparent-violation assessment under OFSI?
The principal risks are four-fold. First, an incomplete ownership-and-control analysis that misses a control-based route to designation. Second, a mandatory report submitted before the internal facts are fully understood, producing a later need to revise the account. Third, reliance on a general licence whose conditions do not in fact cover the transaction. Fourth, a VSD that is over-broad – acknowledging violations beyond what the evidence supports – because it was drafted under time pressure without legal review. Each of these risks is manageable with early specialist involvement. The highest-stakes moment is the first 48 hours after a potential breach is identified, when the firm's response posture is set and the reporting clock has already started.
Do we need specialist counsel for apparent-violation assessment?
For any apparent violation that involves a significant transaction value, a complex counterparty structure, or a possible cross-regime dimension, specialist counsel is not optional in any practical sense. The mandatory report and any VSD become permanent records that OFSI retains and may reference in subsequent enforcement proceedings. An inadequate or factually inaccurate submission can forfeit the mitigation credit that a candid, well-structured disclosure would have generated. In our cross-border practice, we regularly advise clients who have managed the triage stage internally but instructed counsel before submitting any external disclosure. That sequencing – internal triage first, legal review before any submission – is the model that consistently produces the best outcomes. The fixed-fee entry-point assessment at Calder & Vance is designed precisely to make early legal review accessible without an open-ended cost commitment.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.