A US dollar payment clears a correspondent bank. Hours later, the compliance team identifies a sanctions hit in the transaction record. The counterparty, or one of its beneficial owners, appears on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The funds have moved. The question is no longer whether a problem exists – it is how bad the problem is, and what the business does next.
Enforcement risk after a breach under OFAC is shaped by two variables above all others: whether the business makes a voluntary self-disclosure (a VSD – a proactive report to OFAC before the agency identifies the violation independently) and the quality of its compliance programme at the time of the apparent violation. OFAC's enforcement guidelines treat a timely, complete VSD as a significant mitigating factor, capable of reducing a civil penalty base substantially. The clock starts the moment the apparent violation is identified.
As of April 2026, OFAC remains one of the most active civil enforcement authorities in the international sanctions environment. This page explains the enforcement process, the factors OFAC weighs, how the position compares with the approaches taken by OFSI in the UK and the EU, and the practical steps a business should take from the moment a potential breach surfaces.
What governs OFAC enforcement, and who is at risk?
OFAC derives its enforcement authority primarily from the International Emergency Economic Powers Act (IEEPA) and the Trading with the Enemy Act (TWEA), supplemented by the programme-specific regulations that implement each sanctions regime. The authority extends to US persons wherever located, to entities organised under US law and their non-US branches, and – critically – to any transaction that touches the US financial system or involves US-origin goods, technology, or software.
That last point is where enforcement risk after a breach under OFAC reaches businesses that consider themselves non-US. A European trading house, an Asian bank with a US dollar clearing relationship, or a logistics firm moving US-origin goods can each face civil liability without a US employee or office being involved in the transaction. We regularly advise businesses that discover their US dollar processing alone is sufficient to bring them within OFAC's civil jurisdiction.
The practical reach is wide. Any entity – including a non-US parent of a US subsidiary – that causes a US person to violate OFAC rules can itself be found liable. This facilitation exposure is often underestimated by compliance teams that focus only on their own entities' direct dealings.
The position above covers the standard jurisdictional question. Your facts – the counterparty, the currency, the goods, the ownership chain, the nationality of the financial intermediary – change the analysis in each direction. For a rapid assessment of your exposure, contact Calder & Vance at info@caldervance.com.
How does OFAC classify an apparent violation, and what does that mean for penalty exposure?
OFAC does not treat all violations the same. Its enforcement guidelines establish an analytical matrix that determines whether a violation is classified as egregious or non-egregious, and whether disclosure was voluntary or not. Those two axes together set the penalty range within which OFAC operates.
The guidelines identify the following categories of factors. Aggravating factors include: wilful or reckless conduct; actual awareness of a sanctions nexus at the time of the transaction; harm to the objectives of the sanctions programme; senior-management involvement; the company's prior history with OFAC; and failure to take remedial action after the violation became known. Mitigating factors include: a timely and complete VSD; a well-designed and genuinely implemented compliance programme that existed before the violation; prompt cooperation with OFAC's investigation; and the absence of prior violations.
The statutory maximum civil penalty under IEEPA is set by the relevant programme regulations, and OFAC has the power to impose a penalty per transaction. In practice the penalty figure for a non-egregious violation where a VSD has been filed is materially lower than the statutory maximum – in our cross-border practice, clients who file a complete and timely VSD with a strong remediation package consistently achieve a better outcome than those who wait for OFAC to act first. The gap between those two outcomes can be large.
For egregious violations without a VSD, OFAC calculates the penalty at or near the statutory maximum per-transaction figure. That figure is updated periodically for inflation – verify the current amount before relying on any stated sum.
What is the voluntary self-disclosure process, and when should a business file?
A VSD is a proactive, written disclosure to OFAC describing an apparent violation before the agency has independently identified it. Filing a complete VSD is the single most consequential decision a business makes after an apparent OFAC violation surfaces.
The practical sequence is as follows. First, the business must scope the apparent violation: identify every transaction potentially affected, map the sanctions nexus, preserve all relevant records, and instruct counsel before any further action. Second, counsel conducts a privilege-protected internal investigation to establish the facts, assess whether a violation has occurred, and gather the mitigating evidence. Third, a decision is made on whether to file a VSD, a voluntary disclosure to a parallel agency (such as the Department of Justice in a criminal context), or neither. Fourth, if a VSD is filed, it must be complete – a partial or materially inaccurate VSD can itself become an aggravating factor.
Timing matters acutely. OFAC does not publish a rigid deadline for a VSD, but the mitigating credit is lost if OFAC identifies the violation first. In our experience, the window between an apparent violation surfacing internally and OFAC becoming aware of it can close without warning – through a suspicious activity report filed by a correspondent bank, a counterparty's own disclosure, or a routine examination.
Should the business also notify its primary regulator? Where the business is a bank or payment firm, a parallel report to a prudential supervisor will often be required under the applicable supervisory rules. Coordinating those disclosures is an early task for counsel. A misfiled or mistimed report to one authority can complicate the position with another.
If a transaction has already been flagged, or a filing has already been refused, an early review can preserve options that narrow with time. Contact us at info@caldervance.com to discuss the immediate steps.
How does OFAC's approach compare with OFSI and the EU?
Enforcement risk after a breach does not exist in a single-regime vacuum. Most businesses facing an OFAC breach also hold relationships or assets in jurisdictions where OFSI in the UK or the EU Council regulations apply. The approaches diverge in ways that matter operationally.
OFSI – the Office of Financial Sanctions Implementation in the UK – operates under the Sanctions and Anti-Money Laundering Act (SAMLA) and the relevant thematic UK sanctions regulations. Like OFAC, OFSI has a civil monetary penalty power and considers voluntary reporting as a mitigating factor. However, OFSI's enforcement posture differs in one critical respect: the UK regime imposes a reporting obligation on certain persons who know or have reasonable cause to suspect that a person is a designated person or that a sanctions breach has occurred. That obligation is not merely a mitigating option – it is a legal requirement for those within scope. A business managing an OFAC apparent violation and a simultaneous UK nexus must understand that the OFSI reporting clock may be mandatory, not discretionary.
Under the EU Council regulations, member states are responsible for enforcement, meaning that the competent authority, the penalty regime, and the procedural rules differ across the EU. Some member states operate strict liability regimes; others require proof of knowledge or negligence. Where a breach has an EU dimension – a euro clearing leg, a subsidiary in an EU member state, or goods transiting through EU territory – the applicable national regime governs, and its rules may be materially stricter or more lenient than OFAC's matrix. Parallel EU proceedings are not automatically coordinated with an OFAC VSD.
The practical consequence is that a business filing a VSD with OFAC must simultaneously assess its obligations in every other jurisdiction with a sanctions nexus. Treating the OFAC filing as a global resolution is a common and costly error. Our practice routinely coordinates the multi-regime response – assessing the OFAC, OFSI, and EU positions in parallel so that no disclosure in one jurisdiction inadvertently prejudices the position in another.
What are the principal risk flags after an apparent OFAC breach?
Several patterns consistently amplify enforcement risk. Recognising them early shapes the response strategy.
- Delayed internal escalation. Compliance teams that investigate for weeks before escalating to legal counsel lose the window for a timely VSD and allow the factual record to become less clear. Escalation to counsel should happen on the day of identification.
- Incomplete transaction mapping. A business that discloses one transaction and later discovers three more is in a far worse position than a business that identifies all affected transactions before the VSD is filed. Scope the full population first.
- Gaps in the compliance programme. OFAC treats an inadequate compliance programme as an aggravating factor. If the apparent violation reflects a systemic gap – a screening tool that did not cover the relevant list, an ownership analysis that stopped at the first layer – that gap should be remediated and documented before the VSD is filed, or the remediation plan should be included in the submission.
- Failure to consider parallel criminal exposure. OFAC civil proceedings and DOJ criminal enforcement are separate tracks that can run concurrently. A VSD to OFAC does not resolve criminal exposure; it may in some circumstances inform it. Counsel must assess both tracks before any disclosure is made.
- Secondary-sanctions exposure. Where the apparent violation involves a counterparty or transaction caught by secondary-sanctions provisions – which extend US sanctions reach beyond the primary US-nexus test – the business's non-US relationships and operations require separate analysis.
- Record-keeping deficiencies. OFAC expects businesses to retain records of all transactions for a prescribed period. An inability to reconstruct the transaction record compounds every other risk factor.
A myth we encounter frequently is that a business with a small exposure – a low-value transaction, a brief relationship with a designated person – can simply note the issue internally and move on without disclosure. The enforcement guidelines do consider transaction value as a factor; a genuinely de minimis position can support a no-action outcome. But the decision to rely on that requires a documented legal assessment, not an unrecorded internal judgment. OFAC's published enforcement actions include cases involving modest transaction values where the egregious-conduct finding overrode the size of the transaction entirely.
What does the Calder & Vance enforcement response process look like?
Our enforcement response to an apparent OFAC breach follows a structured sequence designed to preserve privilege, protect the client's interests across regimes, and give the business the clearest possible picture of its options before any irrevocable step is taken.
In a recent matter, a financial services business identified a series of payment transactions with a sanctions nexus during a routine retrospective screening exercise. We were instructed within 24 hours. We scoped the full transaction population, assessed the OFAC and OFSI dimensions in parallel, established the compliance programme's state at the relevant time, prepared a VSD to OFAC, and coordinated a parallel OFSI notification. The matter proceeded through OFAC's administrative process without escalating to a penalty proceeding. No outcome of that kind is guaranteed; each matter turns on its own facts.
Our enforcement response covers the following actions:
- Scope the apparent violation and map every affected transaction under legal privilege.
- Assess the OFAC, OFSI, and EU enforcement positions simultaneously – and identify any criminal track that requires parallel counsel.
- Advise on whether to file a VSD, and if so draft, review, and submit the disclosure package to OFAC.
- Prepare and deliver remediation evidence to accompany the VSD – programme gap analysis, screening-logic improvements, and management-level attestations.
- Manage OFAC's investigative queries and respond to any requests for additional information.
- Coordinate with local counsel in any non-US jurisdiction where a parallel enforcement position arises.
- Prepare a penalty defence submission if OFAC issues a pre-penalty notice.
We operate at fixed-fee entry points for initial scope assessments, which gives the business a defined cost before committing to a full response engagement. Subsequent work is scoped on the facts.
When should a business involve sanctions enforcement counsel?
Immediately. That is the direct answer, and the enforcement guidelines support it. The mitigating factors that OFAC weighs most heavily – a timely, complete VSD; a well-implemented compliance programme; prompt cooperation – are all shaped by decisions made in the first hours and days after an apparent violation surfaces. Counsel instructed early can preserve those options. Counsel instructed after an internal investigation has been conducted without privilege, or after informal conversations with a regulator, faces a narrower set of choices.
There is also a structural reason to involve counsel before any disclosure is drafted. A VSD or a report to OFSI is not merely a notification – it is a legal submission that will be scrutinised, compared with the underlying transaction record, and used to assess the business's credibility for the remainder of the proceeding. A submission that is internally inconsistent, that omits material facts, or that over-characterises the compliance programme invites a less favourable outcome than no disclosure at all.
Is the business's compliance team capable of drafting a complete, accurate, and strategically sound VSD under time pressure, across multiple regimes, while also managing the operational disruption of a suspected breach? That is the question a General Counsel should ask before deciding whether to handle the response in-house.
Related practices
- Apparent violation assessment – EU sanctions – assess exposure, procedure, and disclosure obligations under EU Council regulations
- Enforcement risk after a breach – OFSI – UK financial sanctions enforcement, mandatory reporting, and OFSI penalty process