Your legal team has just received a formal letter from a competent authority in an EU member state. The authority demands documents, transaction data, and written explanations in connection with a suspected breach of an EU sanctions regulation. The clock is already running. How you respond – and how quickly you do it – can determine whether this ends as a routine inquiry or as an enforcement action with significant consequences.
Responding to regulator information requests under EU sanctions law requires a structured, legally privileged response process managed from day one by qualified counsel. The governing authority is the competent authority of the relevant member state, acting under the applicable Council regulation and national implementing legislation. As of April 2026, EU member-state enforcement postures have become markedly more assertive, with competent authorities issuing wider document requests, shorter response windows, and greater cross-border coordination with the European Commission and partner regulators.
This page explains the legal basis for EU information requests, the response procedure and its cross-regime parallels, the risk flags that change the analysis, and how Calder & Vance supports businesses through each stage of the process.
What is the legal basis for an EU information request in sanctions enforcement?
An EU information request in the sanctions context is a formal demand issued by a national competent authority under the powers conferred on it by the applicable Council regulation and the national laws that implement EU sanctions obligations. Each EU member state designates one or more competent authorities – typically a financial intelligence unit, a central bank supervisory arm, a customs authority, or a trade ministry – and those bodies hold the power to require production of records, accounts, transaction data, ownership information, and written explanations. The request is not a criminal summons. It is an administrative demand. That distinction matters for privilege, for timing, and for the tone of any response.
The legal basis matters practically because it determines what the authority can lawfully compel, what the recipient must produce, and what can legitimately be withheld. Competent authorities in larger member states have in recent years significantly expanded the scope of their requests, and in our experience many recipients underestimate the breadth of what can be demanded before they have taken advice. The authority's powers typically extend to requiring access to electronic systems, production of communications, and disclosure of the identities of beneficial owners throughout an ownership chain.
For businesses with cross-border operations, the EU position is only one layer. A request from an EU competent authority can sit alongside – or trigger – a parallel inquiry from OFSI in the United Kingdom or from OFAC in the United States. Where the transaction in question involves a US-person, a US-nexus, or US-origin goods, OFAC's extraterritorial reach means that material disclosed to an EU authority could also be relevant to a US investigation. Managing these parallel processes requires coordinated strategy from the outset.
The position above covers the standard case. Your facts – the member state, the authority, the goods or transactions in question, the ownership of the counterparty, and any US or UK nexus – change the analysis materially. For an initial assessment of your exposure and your obligations, contact Calder & Vance at info@caldervance.com.
What does the response procedure involve, and how long does it take?
An EU information-request response procedure typically runs through four sequential phases: intake and triage, privilege review and document collection, substantive response drafting, and submission and follow-up management. The governing deadline is set by the authority in the request letter itself. Response windows vary between member states and between authority types, but they are almost always shorter than businesses expect and rarely accommodate the full internal process of a complex organisation without careful programme management.
Phase one – intake and triage – must happen within hours of receipt, not days. The first questions are: who within the organisation received the request, is it addressed to the entity or to an individual, what is the stated legal basis, and what precisely is being demanded? A request that is ambiguous in scope should be clarified with the authority early, because failing to address every element of the request can itself be treated as non-compliance. In our experience, the triage stage is where the most consequential decisions are made, and it is where having experienced counsel on the phone within the first 24 hours is most valuable.
Phase two – privilege review and document collection – is frequently the most time-consuming element. EU law recognises legal professional privilege for communications with external qualified lawyers, but the rules on in-house counsel privilege differ from those in common-law jurisdictions. Material protected by lawyer-client privilege in the UK or the United States may not be afforded the same protection in an EU proceeding. Communications with an in-house lawyer are generally not privileged under EU competition and enforcement practice; the position for sanctions proceedings follows national rules, which vary. This is a cross-border risk that should be mapped before any document is reviewed or produced.
Phase three – drafting the substantive response – requires precision. Errors of fact, ambiguous language, or omissions can be treated as misleading the authority, with consequences that are separate from, and additional to, any underlying sanctions question. The response should be drafted with the assumption that it will be read alongside the original transaction records, the organisation's compliance policies, and any prior communications with the authority. Every statement should be capable of being stood behind in any subsequent proceeding.
Phase four – submission and follow-up – does not end the matter. Authorities frequently issue follow-up questions, request meetings, or seek supplementary data. The substantive response is the beginning of a dialogue, not a closing statement. Managing that dialogue consistently and without inadvertent inconsistency requires a coordinated approach with the same team throughout.
How does the EU information-request regime compare to OFAC and OFSI processes?
The EU information-request process, the OFAC subpoena and administrative process, and the OFSI information-gathering powers share the same underlying logic – compelling disclosure to support enforcement – but they diverge in meaningful ways that affect how a cross-border business should respond. Understanding those divergences is essential where a single transaction has generated inquiries from more than one authority.
Under the EU regime, the competent authority is a national body whose powers derive from EU regulations transposed into member-state law. There are 27 potential competent authorities across the EU, and the enforcement standards, response timelines, and procedural norms are not fully harmonised. A request from a Dutch authority and a request from an Italian authority can differ significantly in scope, tone, and implied expectations. Businesses with operations in multiple member states may receive coordinated requests that are designed to capture documents held in different jurisdictions simultaneously.
Under OFAC, the information-gathering process typically operates through an administrative subpoena or a voluntary information request, and the target is engaging directly with a single federal authority. OFAC's process is often longer in its initial phases but can escalate faster into a formal investigation. OFAC's extraterritorial jurisdiction means that a non-US company responding to an EU competent authority may simultaneously owe obligations to OFAC if the transaction involved a US nexus – even if OFAC has not yet made a direct approach. That risk requires a parallel analysis.
Under OFSI in the UK, information-gathering powers under the Sanctions and Anti-Money Laundering Act ("SAMLA") allow OFSI to require persons to provide information, produce documents, and attend for interview. OFSI's enforcement posture has developed a clear disclosure-cooperation correlation: early and complete cooperation is a recognised mitigating factor in enforcement. That factor is present in the EU framework as well, but it operates differently between member states. In some jurisdictions, voluntary early disclosure before a formal request significantly reduces the enforcement risk; in others, the procedural rules give less latitude to the competent authority to factor cooperation into an outcome.
The practical cross-border lesson is this: where a transaction is under scrutiny by more than one authority, the decision about what to produce, in what order, and to whom must be made strategically and with full visibility of each regime's rules. A disclosure that satisfies the EU competent authority could, in the absence of coordinated advice, create an admission that complicates the OFAC or OFSI analysis.
If a transaction has already been flagged, or if a request has arrived from more than one authority, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss a coordinated response strategy.
What are the key risk flags in an EU information-request situation?
Not every EU information request carries the same risk profile. Several indicators raise the stakes and should trigger immediate engagement with specialist counsel rather than an in-house response managed alone.
The first risk flag is the subject matter of the request. A request that focuses on a specific counterparty, transaction, or date range – rather than a general compliance inquiry – signals that the authority has already identified a potential violation. It may be acting on information provided by another authority, a transaction monitoring alert, or a voluntary disclosure by another party to the transaction. The more targeted the request, the more likely it is that the authority has a working hypothesis about the conduct in question.
The second risk flag is the identity of the counterparty named or implied in the request. If the authority is asking about a counterparty that appears on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons), or on the EU Consolidated List, or on the UK financial-sanctions list, the underlying question is whether a dealing with a designated person has taken place. That question carries a strict-liability dimension in most EU member-state regimes: the question of whether the business knew it was dealing with a designated person is relevant to penalty, but not necessarily to liability. Strict liability with knowledge-relevant penalty is a materially different position from a fault-based standard, and it shapes how the response should be framed.
The third risk flag is the ownership and control (the EU test for whether a non-listed entity is captured through a listed person's ownership or controlling influence) of the counterparty in question. If the authority's inquiry touches on entities that may be owned or controlled by a designated person, the organisation needs to map the ownership chain completely before making any statement about the nature of its relationship with the counterparty. Gaps in that analysis can lead to a response that is technically accurate but incomplete – which the authority may treat as misleading.
The fourth risk flag is any prior correspondence with the authority, or any prior internal investigation, relating to the same transaction or counterparty. An information request that follows earlier internal findings creates a consistency obligation: the response must align with what the organisation already knows. Inconsistency between an information-request response and internal records that the authority subsequently obtains is a serious and recurring source of aggravated enforcement outcomes. We regularly advise clients to audit their prior communications and internal records before any response is drafted.
The fifth risk flag is concurrent reporting obligations. In some member states, financial institutions and other regulated entities have an obligation to report actual or suspected sanctions breaches to the competent authority independently of – and potentially before – responding to an information request. Conflating the two obligations can lead to a failure to report within the required window. The applicable obligation and its deadline should be identified at the triage stage.
What is the myth about responding directly without specialist counsel?
A persistent view among in-house teams is that an EU information request is a routine administrative exercise – something that can be managed by the compliance function alone, with a response drafted by the legal team and submitted within the deadline without external involvement. That view underestimates the dual function of the response itself.
A response to an EU competent authority is both a compliance document and a potential piece of evidence in subsequent enforcement proceedings. The same letter that satisfies the authority's administrative requirement may later be produced in a proceeding where every word is scrutinised for admissions, inconsistencies, or gaps. In our cross-border practice, we have seen responses drafted in good faith by capable in-house teams that inadvertently narrowed the organisation's defences, disclosed material beyond what was required, or made factual representations that could not be sustained when challenged. The cost of correcting those errors in a later proceeding is significantly greater than the cost of structured support at the response stage.
A further dimension is legal professional privilege. In-house counsel communications may not attract the same privilege as external lawyer communications in EU proceedings. If the response is drafted by in-house counsel without external oversight, the draft documents, research notes, and internal advice may be producible if the authority subsequently issues a wider request. Involving external qualified counsel from the outset establishes a clearer privilege perimeter around the response-preparation materials.
The myth is that external counsel slows the process. In practice, the opposite is true for any request of substance. Experienced sanctions counsel know the authority's expectations, can engage the authority on scope clarifications without prejudicing the organisation's position, and can manage the document-collection process more efficiently than an internal team working through the request for the first time.
How does Calder & Vance assist with an EU information-request response?
Calder & Vance provides end-to-end support for EU information-request responses, from the moment of receipt through submission and any follow-up engagement with the authority. Our work in this area combines EU sanctions law analysis, cross-regime coordination, and structured project management under legal professional privilege.
In a recent matter, a financial services group operating across three member states received simultaneous information requests from competent authorities in two jurisdictions, both relating to a payment that had transited a counterparty later added to the EU Consolidated List. We assessed the legal basis for each request, identified the privilege perimeter, mapped the counterparty's ownership and control structure, and prepared coordinated responses that addressed both authorities' requirements without creating inconsistency. The matter closed at the information-gathering stage without escalation to a formal enforcement proceeding. No outcome is guaranteed, but early and structured engagement consistently produces better results than reactive response alone.
Our action library for this service covers:
- Intake triage: assessing the legal basis of the request, the authority's powers, and the response deadline within 24 hours of receipt.
- Privilege perimeter: establishing and documenting the external-counsel privilege boundary over all response-preparation materials.
- Scope clarification: engaging the authority on ambiguous or overbroad demands without making admissions or prejudicing the organisation's position.
- Ownership and control mapping: tracing the counterparty's beneficial-ownership chain to identify any listed persons and assess the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) and its EU and UK equivalents.
- Document collection and review: managing the collection of responsive material, applying redaction where warranted, and reviewing for privilege and relevance.
- Response drafting: producing a response that is accurate, complete, and framed to preserve the organisation's position in any subsequent proceeding.
- Cross-regime coordination: identifying and managing parallel obligations to OFSI, OFAC, or other authorities where a US or UK nexus is present.
- Follow-up management: handling supplementary questions, meeting requests, and any escalation to a formal investigation or penalty process.
Our practice is cross-regime by design. Claire Dubois leads EU work from our core team, and where a matter involves a US or UK dimension we draw on the same firm's OFAC and OFSI capability without any external referral.
Related practices
- Apparent violation assessment (EU) – identifying and scoping a potential EU sanctions breach before an authority makes contact.
- EU information request response (extended) – deeper engagement where a request escalates to a formal investigation.
- OFAC information request response – managing a parallel or standalone OFAC inquiry with the same coordinated approach.