A payments business settles a cross-border transaction. Three days later, its compliance team identifies a match: the counterparty's ultimate beneficial owner appears on OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The deal has already settled. Funds have moved. What happens now, and how quickly must the business act?
Enforcement risk after a breach under OFAC is governed by IEEPA and the relevant programme regulations administered by the Office of Foreign Assets Control. As of April 2026, OFAC operates a graduated enforcement system in which a voluntary self-disclosure (a VSD – a proactive report to OFAC of an apparent violation before the agency opens its own inquiry) can reduce the base civil penalty by a significant proportion. The difference between a timely VSD and a reactive response to an agency-initiated investigation is not procedural; it is financial, reputational, and in aggravated cases, criminal.
This page sets out how OFAC's enforcement process works after an apparent violation is discovered, where the cross-border dimensions – secondary sanctions, OFSI, and EU divergences – change the picture, and what a business must do to preserve every available option. We address the VSD mechanics, the penalty calculus, the investigation timeline, and the role of specialist sanctions counsel at each stage.
What is OFAC's legal basis for civil enforcement?
OFAC's civil enforcement authority derives from IEEPA – the International Emergency Economic Powers Act – and from the Trading with the Enemy Act for older programme regulations, supplemented by the applicable country-programme regulations issued under each executive order. These instruments authorise OFAC to impose civil monetary penalties on any US person, and on non-US persons transacting in US dollars or otherwise within US jurisdiction, who commit an apparent violation of a sanctions programme.
The enforcement regime is strictly liability-based for civil purposes. OFAC does not need to prove that the business intended to violate sanctions. A payment routed through a US correspondent bank to an SDN-owned counterparty is an apparent violation regardless of whether the payer knew of the ownership link. That is the practical consequence of the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked): ignorance of the indirect ownership structure provides no automatic defence, though it is a significant mitigating factor in OFAC's penalty calculation.
The civil penalty framework distinguishes between non-egregious and egregious violations. Non-egregious cases attract lower base penalties; egregious cases – where wilfulness, concealment, or senior management involvement is found – attract the statutory maximum per transaction. The statutory maximum changes as the relevant penalty statutes are updated; verify the current figure before relying on it. In our practice, the most consequential factor affecting where a matter sits on that spectrum is whether the business disclosed proactively or waited.
The position above covers the standard civil track. Your facts – the counterparty structure, the goods or funds involved, the transaction route, and the programme in play – change the analysis substantially.
For an assessment of your exposure under OFAC, contact Calder & Vance at info@caldervance.com.
How does a voluntary self-disclosure affect the enforcement outcome?
A VSD is the single most consequential decision a business makes after identifying an apparent OFAC violation. OFAC's enforcement guidelines treat a timely, complete, and accurate VSD as a significant mitigating factor that can reduce the base civil penalty applicable to a non-egregious violation by a substantial margin – in practice, the reduction for a qualifying non-egregious VSD is substantial and well-documented in OFAC's published enforcement guidance, though the precise figure should be verified against the current guidance before reliance.
The decision to file a VSD is not simply a tick-box. A VSD must be comprehensive: it must describe the facts of the apparent violation, identify the transactions involved, explain how the violation occurred, and set out the remedial measures taken or planned. An incomplete or misleading VSD can be treated as an aggravating factor rather than a mitigating one. We regularly advise businesses at exactly this point – the initial assessment of whether the facts support a clean VSD, a partial disclosure, or a no-action conclusion.
Timing matters acutely. OFAC distinguishes between disclosures made before the agency becomes aware of the violation and those made after an investigation has begun. Once OFAC opens an inquiry – typically prompted by a suspicious activity report, a bank's blocking notice, or a third-party referral – the benefit of proactive disclosure narrows sharply. In our experience, businesses that delay the internal investigation pending a full audit risk losing the VSD window entirely.
There is a parallel criminal track. The Department of Justice has independent authority to prosecute wilful violations of US sanctions laws. A VSD to OFAC does not constitute a parallel disclosure to DOJ, and it does not prevent criminal referral where the facts support it. For any matter involving apparent wilfulness, board-level decisions, or deliberate routing through third parties, criminal-defence considerations must be assessed alongside the civil VSD decision from the outset.
What is OFAC's investigation process and how long does it take?
OFAC enforcement typically moves through several distinct phases: the pre-investigation review, the civil investigation, the proposed enforcement action (a finding of violation or a no-action letter), and – where the matter proceeds – a settlement negotiation or the formal penalty process. The timeline across these phases varies considerably with the complexity of the transaction history and the responsiveness of the subject.
For straightforward matters – a small number of transactions, clear facts, a cooperative subject, and an early VSD – OFAC has resolved cases within twelve to eighteen months of initial disclosure, though this is not guaranteed and current caseload affects timing materially. Complex matters involving multiple transactions, layered ownership chains, or large transaction values can extend well beyond that. Verify the current average with your counsel before setting internal planning assumptions.
At the investigation stage, OFAC typically issues a request for additional information. This is a formal demand for documents, records, and explanations covering the transactions in question, the counterparty due-diligence record, the compliance programme in place at the time, and the ownership analysis. Responses are subject to strict deadlines. Missing a response deadline or providing an incomplete answer is itself treated as an aggravating factor.
Record-keeping obligations support the investigation process on the business side. US sanctions rules require businesses to maintain records of transactions that are blocked or rejected, and of related correspondence, for a defined period. The applicable retention period under the relevant US sanctions regulations is five years; verify that this matches the current regulatory text before relying on it. Gaps in the record – missing correspondent-bank confirmations, absent ownership-analysis documentation – materially weaken the business's position at the investigation stage.
How does cross-border exposure change the enforcement risk picture?
For a non-US business, OFAC enforcement risk does not require a physical US presence. It arises whenever US-dollar clearing, US-incorporated entities, or US-origin goods or technology are in the transaction chain. That extraterritorial reach means that a German bank, a Singaporean trading house, or a Dubai-based logistics firm can all face OFAC enforcement proceedings without a US office.
The cross-border dimension creates a second, equally important layer: parallel proceedings in other jurisdictions. A transaction that triggers an OFAC apparent violation will frequently also trigger obligations under OFSI – the UK's Office of Financial Sanctions Implementation – and under the relevant EU Council regulations. OFSI and OFAC operate independent enforcement regimes with different penalty structures, different reporting obligations, and different ownership-and-control tests.
Under OFSI, a business that knows or has reasonable cause to suspect that it holds frozen funds or is dealing with a designated person must report to OFSI as soon as practicable. The UK's ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person) is not purely mechanical: it encompasses control as well as ownership, which means that a structure that falls below the OFAC 50 percent threshold may still be caught in the UK. In our experience, businesses that assess only OFAC exposure on a dollar-clearing basis routinely underestimate their OFSI and EU obligations.
The EU's position adds further divergence. EU sanctions regulations apply to EU persons and to conduct within EU territory, and the Council's designation lists do not mirror OFAC's SDN List. A counterparty cleared by OFAC may be designated under an EU programme. Conversely, a business may face OFAC exposure without any EU programme engagement. Managing the two-track analysis in parallel – OFAC civil penalty mechanics alongside EU General Court remedies for designation challenges – requires a cross-regime view that a single-jurisdiction compliance team will rarely maintain.
Secondary-sanctions risk adds a further dimension for non-US actors. OFAC secondary-sanctions programmes attach consequences to non-US persons who engage in significant transactions with designated persons or with the sectors targeted by certain programmes, even where no US nexus would otherwise exist. The threshold for "significant" is not defined by a bright line; it is assessed on the totality of the relationship, the value, the frequency, and the goods involved. If a transaction has already been executed and secondary-sanctions risk is in play, counsel should assess both the primary and secondary exposure concurrently.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.
What are the common risk flags and aggravating factors OFAC scrutinises?
OFAC's published enforcement guidance sets out the factors that move a matter toward the egregious end of the penalty spectrum. Understanding those factors is essential to assessing where a business stands before it chooses its response strategy.
The factors that consistently elevate penalty risk include: wilful or reckless conduct (where senior management knew or should have known of the violation); a pattern of violations rather than an isolated incident; harm to the integrity of the US financial system; concealment or obstruction at any stage; and a weak or absent sanctions-compliance programme at the time of the violation. Conversely, OFAC treats as mitigating: a genuine lack of awareness of the violation at the time; a strong compliance programme that detected the issue quickly; prompt remediation; and – above all – a timely, complete, and accurate VSD.
In our practice, three patterns recur among businesses facing post-breach enforcement risk. First, the ownership-chain blind spot: a business screens the direct counterparty but not the ultimate beneficial owner, missing an SDN-held interest below the top entity level. The 50 percent rule aggregates holdings; two listed persons each holding a minority stake can together breach the threshold. Second, the correspondent-bank trigger: a US correspondent bank blocks a payment and issues a blocking notice, creating a formal record of the violation before the originating business has even identified the issue internally. Third, the stale compliance programme: the business's screening lists or ownership-analysis procedures have not been updated to reflect a recent designation, and the violation occurs in the gap between the designation date and the next scheduled screen refresh.
Each of these patterns has a different remediation path. The ownership-chain case requires a full beneficial-ownership audit and revised screening protocols. The correspondent-bank case requires an immediate assessment of whether a VSD remains available and coordination with the bank's own compliance team, whose reporting obligations run on their own timeline. The stale-programme case requires both a root-cause analysis and an updated compliance architecture, which OFAC will expect to see documented in any VSD submission.
A common misconception: "the breach is too small to matter"
The most frequent misunderstanding we encounter among businesses that have self-identified a low-value apparent violation is that OFAC will not pursue it. The assumption runs: the transaction was small, it was a single occurrence, and the business has since remediated. OFAC must have larger targets in view.
That assumption is mistaken in at least two respects. First, OFAC uses apparent violations – including those disclosed by VSD – to assess the health of a business's compliance programme. A small violation disclosed without a credible remediation plan may attract more scrutiny, not less, because it suggests systemic weakness. Second, civil penalty bases under OFAC are calculated per transaction, not per investigation. A seemingly minor recurring failure – for example, a systematic gap in the screening of a product line – can produce a penalty exposure that is a multiple of the apparent transaction value.
The appropriate response to a small apparent violation is not silence. It is a calibrated internal assessment: is this an isolated event or a symptom of a wider gap? Does it meet OFAC's materiality threshold for a VSD, or is it better addressed through a compliance programme update with a documented contemporaneous record? Those decisions benefit from specialist counsel input at the outset, before any submission is made or any response strategy is locked in.
How Calder & Vance assists with post-breach enforcement risk under OFAC
Our Enforcement & Investigations practice supports businesses at every stage of the post-breach process. We scope the apparent violation, advise on voluntary self-disclosure, and prepare the penalty defence. We assess the cross-regime exposure – OFAC, OFSI, EU – concurrently so that a step taken in one jurisdiction does not foreclose a remedy in another.
In a recent matter, a financial-services business discovered that a payment had been processed through a US correspondent bank to a counterparty whose ultimate parent was on the SDN List. The ownership link was indirect and had not been captured by the business's automated screening. We assessed the apparent violation, confirmed that the VSD window remained open, prepared and submitted the disclosure, managed OFAC's subsequent information requests, and advised on parallel OFSI reporting obligations. The matter resolved through the civil settlement process without criminal referral. We do not guarantee outcomes; the resolution reflected the facts, the quality of the submission, and the business's genuine remediation effort.
Our action library for post-breach enforcement matters covers: scoping the apparent violation and mapping every affected transaction; advising on the VSD decision and preparing the submission; managing OFAC's information requests within the response deadlines; conducting a root-cause analysis and designing the remediation programme; assessing parallel OFSI and EU exposure; and, where the matter escalates, preparing the civil-penalty defence or instructing local counsel in the relevant jurisdiction for parallel proceedings.
We offer a fixed-fee initial assessment for businesses that have identified a potential breach. That assessment covers the apparent violation, the VSD analysis, the cross-regime exposure map, and the immediate steps. It is completed within a defined turnaround, because time matters in enforcement matters more than in almost any other area of sanctions law.
Related practices
- Apparent violation assessment – EU – assessing and managing apparent sanctions violations under EU Council regulations
- Post-breach enforcement risk – OFSI – managing enforcement exposure and reporting obligations under UK financial sanctions
- Post-breach enforcement risk – UAE – advising on enforcement risk and disclosure under the applicable UAE sanctions regime