A European trading company receives a formal letter from a national competent authority. The letter requests documents, records, and written explanations concerning a series of transactions that may have touched a designated party. The deadline is short. The scope is broad. And the wrong response – whether too narrow, too expansive, or too slow – can transform a routine enquiry into a full enforcement investigation.
Responding to regulator information requests (formal demands from EU Member State authorities or EU-level bodies for documents and explanations relating to potential sanctions breaches) requires a structured, legally advised approach. Under the EU sanctions regime, national competent authorities derive their investigative powers from the relevant Council Regulation and from implementing national legislation. The response window is typically short, and each document produced can become evidence in a subsequent penalty or criminal proceeding.
This page sets out how the EU information-request process works, how it compares with parallel regimes, what risks arise, and how Calder & Vance advises businesses through each stage.
What is an EU regulator information request and who sends it?
An EU regulator information request is a formal, legally binding demand issued by a national competent authority – the designated enforcement body in a given EU Member State – requiring a person or entity to produce records, answer written questions, or appear for interview in connection with a suspected breach of EU sanctions.
The EU sanctions architecture is distinctive. The Council adopts measures through Council Regulations and accompanying Council Decisions. Those instruments are directly applicable across all Member States. Enforcement, however, is decentralised: each Member State designates its own competent authority, and enforcement posture varies significantly between jurisdictions. In France that authority differs from the one in Germany or the Netherlands. The request you receive will carry the branding and procedural rules of the issuing authority, not a single EU-wide office.
Why does this matter in practice? Because the procedural rights available to the recipient, the applicable deadlines, and the sanctions for non-compliance are all shaped by national procedural law layered over the EU substantive regime. We regularly advise businesses that assume a uniform EU process, only to discover that their specific competent authority operates under rules materially different from those they encountered in a prior jurisdiction.
What legal basis governs the information request?
The legal basis for an EU sanctions information request sits in the relevant Council Regulation, which typically requires Member States to establish competent authorities and empower them to obtain information necessary for enforcement. National implementing legislation then specifies the procedural rules: how requests are framed, what time limits apply, what privileges are preserved, and what consequences follow non-compliance.
Two features of the EU legal basis shape the response strategy. First, the relevant Council Regulation usually includes a prohibition on providing information that would facilitate circumvention or evasion – meaning that the response must be accurate and complete, but must not inadvertently disclose information in a way that assists a designated party. Second, the EU instrument co-exists with any applicable UN Security Council measure. Where the relevant sanctions programme traces back to a binding UN Security Council resolution, the obligations are reinforced at the multilateral level, and national competent authorities are entitled to rely on both layers.
The position above covers the standard EU case. Your facts – the issuing authority, the specific Council Regulation in play, the goods or funds at issue, and any concurrent OFAC or OFSI exposure – change the analysis materially. For an assessment of your exposure under the EU regime, contact Calder & Vance at info@caldervance.com.
How does the EU procedure compare with OFAC and OFSI information requests?
The EU decentralised model contrasts sharply with the centralised US and UK approaches, and those differences directly affect how a cross-border business should position its response.
Under the US regime, OFAC (the Office of Foreign Assets Control, the primary US sanctions enforcement authority) conducts its own investigations and issues its own subpoenas and information requests directly to the target. The investigative and penalty-setting function sit in the same agency. Response strategy must account for the risk that a voluntary self-disclosure – a VSD (a voluntary submission of an apparent violation to the regulator before it initiates an investigation) – can materially reduce the penalty base. OFAC's published enforcement guidelines describe how a timely VSD is treated as a mitigating factor, and our cross-border practice regularly addresses the sequencing question when a client faces concurrent EU and OFAC exposure.
Under the UK regime, OFSI (the Office of Financial Sanctions Implementation, the UK financial-sanctions authority) holds both licensing and enforcement functions. OFSI's enforcement guidance describes a statutory reporting obligation: persons who know or have reasonable cause to suspect that they hold funds or economic resources belonging to a designated person must report to OFSI. That obligation is distinct from any information request OFSI may subsequently issue. The ownership-and-control test under UK sanctions differs from the EU position and from OFAC's mechanical 50 percent or more threshold: both OFSI and the EU apply a control element, but the analysis under each regime can reach different conclusions on the same facts.
The practical implication for a cross-border business is sequencing. A response filed with a national EU competent authority may be visible to OFAC or OFSI through information-sharing arrangements, or the same underlying conduct may be under review by more than one authority simultaneously. Disclosures made to satisfy one authority can affect the posture before another. We advise on this sequencing question as a core element of the response strategy.
What is the correct procedure for responding to an EU information request?
A structured response to an EU regulator information request moves through identifiable phases, each of which carries its own risk if handled incorrectly.
Phase 1 – Receipt and triage. Identify the issuing authority, the legal basis cited, the scope of the request, and the response deadline. Preserve all documents potentially within scope immediately. Do not destroy, alter, or remove documents once a request has been received. Assess whether the request is formal or preliminary: some authorities issue informal enquiries before a binding demand, and the appropriate response strategy differs.
Phase 2 – Scope and privilege review. Map what falls within the request. Legal professional privilege may protect communications with external legal counsel in some EU Member State jurisdictions, but the scope of that protection varies. In-house legal advice enjoys privilege in some systems and not others. Identifying the applicable privilege rules in the specific Member State is a threshold task. Documents that are privileged must be logged, not produced – but the basis for withholding them must be defensible.
Phase 3 – Factual investigation. Reconstruct the transactions or relationships at issue. Who were the counterparties? What screening was run, and when? What ownership-and-control analysis was conducted before the transaction closed? The factual record must be assembled accurately, because inconsistencies between internal records and the regulator's own data can be treated as indicators of poor governance or, in the worst case, of wilful blindness.
Phase 4 – Drafting and submission. The written response must be accurate, appropriately scoped, and consistent with any prior representations to the same or any other authority. Overproduction – providing documents beyond the scope of the request – can expand the enquiry. Underproduction – failing to provide clearly responsive documents – invites follow-up demands and can be treated as obstruction. The response must also avoid inadvertently providing information to the authority that would benefit a designated person.
Phase 5 – Post-submission management. Monitor for follow-up requests, requests for interview, or escalation to a formal investigation or penalty proceeding. The response is not the end of the engagement with the authority; it is usually the beginning.
If a transaction has already been flagged or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss a confidential review.
What are the key risk flags in an EU information request response?
Several patterns consistently generate enforcement risk in our experience of advising on EU information requests. Identifying them early determines whether the matter resolves at the information-gathering stage or escalates.
Ownership and control gaps. The EU applies an ownership and control test (the test for whether a non-listed entity is effectively caught because a designated person owns or controls it). Where a business transacted with an entity that a designated person controlled but did not own at the threshold level, the transaction may still have been prohibited. If the screening programme did not capture control indicators – board composition, contractual rights, de facto influence – the regulator's view of the exposure may be broader than the business expects.
Retrospective screening. Designation lists change. A counterparty clean at the point of contracting may have been designated before performance was complete. Businesses that screen only at the onboarding stage, not at payment or delivery, carry exposure they may not have identified before the request arrived.
Third-country nexus and extraterritorial overlap. The EU regime applies to conduct within the EU, to EU persons and entities wherever located, and to transactions denominated in euros clearing through EU financial infrastructure. A transaction routed through a non-EU subsidiary may still carry EU exposure. And where the same transaction has US or UK elements, the extraterritorial reach of OFAC's secondary-sanctions rules or BIS's export-control jurisdiction may be engaged simultaneously. A response that is complete for EU purposes may nonetheless leave parallel exposure unaddressed.
Document preservation failures. The period between the underlying transaction and the information request can be lengthy. Record-keeping obligations under EU sanctions require businesses to maintain relevant documentation for a defined period – verify the applicable requirement for your specific regime and jurisdiction. Gaps in the document trail, even those that arose through routine retention policies rather than deliberate deletion, require careful explanation.
Inconsistency with prior representations. If the business has previously made any representations to the same authority, to another EU Member State authority, or to OFAC or OFSI on related transactions, the current response must be consistent. Divergence between accounts – even where the divergence results from an innocent difference in how the question was framed – will attract scrutiny.
When should a business involve specialist counsel?
The threshold for involving specialist counsel in an EU sanctions information request is lower than many businesses assume. This is the myth we most frequently encounter: that an information request is a routine administrative matter that in-house compliance can handle without external support.
In practice, the information-request stage is the moment at which the evidentiary record is being built – either in the business's favour or against it. Decisions made in the first days after receipt, including document preservation steps, privilege assessments, and the framing of initial communications with the authority, have consequences that persist through any subsequent penalty proceeding or judicial challenge. Reversing a poor early decision is always harder than making the right one at the outset.
Involve specialist counsel immediately if any of the following applies: the request covers transactions with potential US or UK sanctions dimensions; the request identifies a named counterparty or individual as a subject of the enquiry; the scope of the request suggests that the authority already holds documents or information about the matter; the business has prior dealings with the same authority; or the transactions at issue involved cross-border payment flows, dual-use goods, or financial institution intermediaries.
In a recent matter, a technology distributor operating across three EU Member States received simultaneous information requests from two national competent authorities concerning shipments to a third-country buyer. We scoped the apparent exposure, assessed the overlap between the two requests, advised on the sequencing of responses, and coordinated with the client's local counsel in each jurisdiction. The matter was resolved at the information-gathering stage without escalation to a formal penalty proceeding. No outcome is guaranteed, but early, co-ordinated advice consistently produces better results than reactive management after the position has hardened.
How does Calder & Vance assist with EU information requests?
Calder & Vance provides practitioner-led advice at each stage of an EU sanctions information request, from the moment of receipt through to post-submission management and any escalation into formal proceedings.
Our approach draws on cross-regime coverage. The EU enforcement picture rarely exists in isolation. Where OFAC or OFSI exposure is concurrent, we address the sequencing and disclosure strategy across all relevant authorities. Where the matter involves dual-use goods or export-control classifications, our export-control practice handles that dimension without the need for a separate firm.
Specifically, we: scope the apparent violation and assess the exposure under the relevant Council Regulation and any parallel regime; review all documents within scope and advise on privilege and production; prepare the written response and manage any follow-up queries from the competent authority; advise on voluntary self-disclosure where that option is available and strategically sound; and, where the matter escalates, prepare the penalty defence or the annulment action before the EU General Court.
Our entry point is a fixed-fee initial review, providing a written assessment of the scope of the request, the apparent exposure, and the recommended response strategy within a defined working period. That assessment gives the business's legal and compliance team a clear basis on which to decide next steps.
Related practices
- Apparent violation assessment under EU sanctions – structured analysis of potential breach and enforcement risk under EU Council regulations
- Responding to OFAC information requests – practitioner advice on US sanctions regulator enquiries, VSD strategy, and penalty defence
- OFAC information request response service – further guidance on managing concurrent US and cross-border enforcement enquiries