Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · OFAC

Responding to regulator information requests under OFAC: legal support

Your legal team receives a letter from OFAC. It requests documents, records, and explanations relating to a transaction or a counterparty. The clock starts immediately. How your organisation responds – what it discloses, in what order, and with what framing – can determine whether the matter closes quietly or escalates into a formal enforcement action.

Responding to regulator information requests under OFAC is a high-stakes process governed by OFAC's enforcement authorities under IEEPA and related statutes. The agency uses information requests to assess whether an apparent violation occurred, to evaluate the degree of culpability, and to decide between no-action, a cautionary letter, a civil penalty, or a criminal referral. How a business handles this initial stage shapes every subsequent outcome.

This page sets out the governing authority, the procedural sequence, the cross-regime dimensions, the risk flags that matter most, and how Calder & Vance assists businesses at each stage of the process.

What is an OFAC information request and who has authority to issue one?

An OFAC information request is a formal written demand from the Office of Foreign Assets Control requiring a person or entity to produce records, provide explanations, and identify relevant personnel in connection with a transaction or relationship under review. OFAC derives this authority from IEEPA and the statutes underpinning each sanctions programme it administers.

The request may arrive as a subpoena-equivalent demand, as a voluntary request for information, or as a follow-on query appended to an apparent-violation notice. The label matters less than the substance: any written communication from OFAC that asks for records or explanations demands immediate legal attention. Ignoring or mis-handling it is itself a basis for aggravated treatment in any later penalty determination.

OFAC's enforcement authority is broader than many recipients appreciate. The agency can direct its information requests at US persons, at non-US entities with a US nexus – a US-dollar transaction, a US financial institution in the correspondent chain, or US-origin goods – and at entities that have dealings with US-listed persons. A European or Asian business that assumes OFAC has no reach over it, simply because it is incorporated outside the United States, takes a significant legal risk. In our experience, that assumption is among the costliest errors a cross-border compliance team can make.

What is the procedure for responding to regulator information requests from OFAC?

The procedural sequence for responding to regulator information requests from OFAC has four distinct phases: receipt and scope assessment, document preservation and collection, legal analysis and privilege review, and submission. Each phase carries its own timeline pressures and decision points.

Receipt and scope assessment must happen within the first two to three business days. The recipient should identify the legal authority cited, the time limit stated in the request, the categories of documents sought, and the individuals named. If the request does not state a deadline, that does not mean there is none: OFAC's practice is to treat non-response as an aggravating factor. Legal counsel should be engaged at this stage, before any documents are gathered or any response is drafted internally.

Document preservation follows immediately. A litigation-hold equivalent should go out across all relevant custodians – email, messaging platforms, trade-finance systems, screening logs, and compliance records. Destruction of relevant records after receipt of an OFAC inquiry carries separate legal consequence. The scope of the hold should be defined by counsel, not by the compliance team working in isolation.

Collection and privilege review is where the substance of the response is built. Responsive documents are gathered, duplicates removed, and legal privilege assessed over each category. Attorney-client and work-product protections apply in the US context, but their scope is not absolute and their application to foreign subsidiaries requires careful analysis. What a business chooses to produce – and what it designates as privileged – is a legal decision, not an administrative one.

Submission should be accompanied by a covering letter that contextualises the documents, sets out the entity's legal position concisely, and identifies any claims of mitigation. OFAC's enforcement guidelines treat the quality and completeness of cooperation as a significant mitigating factor. A well-structured submission does more than answer the question asked: it signals that the business has a functioning compliance programme and that the matter does not represent wilful or reckless conduct.

How does the cross-regime picture affect an OFAC information-request response?

A business that has received an OFAC information request almost invariably has exposure in other jurisdictions, and a response strategy developed in isolation from those regimes can create serious problems. This is the cross-regime dimension that compliance counsel must address at the outset.

Under UK rules, OFSI administers financial-sanctions enforcement separately. If the same transaction is under review by both OFAC and OFSI – which occurs in matters involving sterling payments, UK-incorporated intermediaries, or UK-licensed firms – a disclosure to OFAC that admits a technical breach may need to be assessed against the separate voluntary self-disclosure (a formal notification to OFSI of a possible breach, made proactively) regime in the United Kingdom. The two agencies do not coordinate submissions automatically, and a disclosure that reduces OFAC exposure can, if drafted carelessly, increase OFSI exposure or vice versa.

The EU position adds further complexity. Where a French, German, or Dutch entity is involved in the same transaction chain, the relevant Council regulation and the supervisory authority of the member state in question apply in parallel. EU sanctions do not follow the OFAC 50 percent rule (the rule treating entities owned 50 percent or more by blocked persons as themselves blocked) in the same mechanical way; the EU test incorporates a control analysis. A response that assumes OFAC's ownership-and-control logic will apply equally under EU law may misstate the legal position in the European portion of the transaction.

Secondary-sanctions risk is a further layer. Even where a non-US business is not technically subject to OFAC's primary jurisdiction, it may be exposed to secondary sanctions (measures that target non-US persons for dealings with designated parties, even absent a US nexus) risk depending on the parties and the programme. An information request from OFAC is sometimes the first signal that the agency is considering whether secondary measures are appropriate. Counsel advising on the response must assess that dimension explicitly.

In our cross-border practice, we regularly advise clients who face simultaneous or sequential information requests from OFAC, OFSI, and one or more EU member-state authorities. The sequencing and framing of each response requires a coordinated strategy, not four separate submissions developed independently.

The position above covers the standard multi-regime case. Your facts – the counterparty, the goods or services involved, the payment route, the individuals named – change the analysis materially. For an assessment of your exposure under OFAC and any parallel regimes, contact Calder & Vance at info@caldervance.com.

What are the risk flags that increase exposure in an OFAC information-request process?

Several categories of risk consistently increase a business's exposure when responding to regulator information requests from OFAC. Identifying them early allows counsel to address them directly rather than allow them to surface as aggravating factors in a penalty determination.

Delay in response or non-response is the most consequential risk flag. OFAC's enforcement guidelines treat failure to cooperate as an aggravating factor. A business that misses a response deadline – or that provides an incomplete initial submission and then goes silent – signals a level of disregard that can convert a civil matter into a referral for criminal review. If more time is genuinely needed to compile records, counsel should request an extension in writing, with reasons, before the stated deadline passes.

Incomplete document collection follows. A submission that omits a material category of documents – whether because a custodian was not included in the preservation hold, because a messaging platform was overlooked, or because a foreign subsidiary's records were not requested – will be discovered. OFAC has access to financial-intelligence data and to information shared by other agencies. Gaps in a production that should be complete are read as suppression.

Inconsistency between the submission and third-party records is another significant risk. Banks produce records independently. Shipping companies hold cargo documentation. Payment systems have audit trails. If the entity's submission states that a payment was for a legitimate commercial purpose but the underlying records – produced by a third-party bank – show a different picture, the inconsistency is an aggravating factor of the first order. The submission must be reconciled against all third-party records counsel can identify before it is submitted.

Prior history of OFAC contact is also relevant. If the business has received a prior cautionary letter, or was previously the subject of an apparent-violation notice, OFAC will note that history. The response should address – rather than ignore – the prior contact and explain what remedial steps have been taken.

Inadequate compliance-programme evidence is a further risk. OFAC's penalty calculation takes account of whether the business has a sanctions-compliance programme. A programme that exists on paper but cannot be evidenced through training records, screening logs, escalation decisions, and remediation documentation will not attract the mitigation it would otherwise justify. If the programme is weak, it is better to acknowledge remediation in progress than to assert a programme that the record cannot support.

When should a business involve specialist sanctions counsel for an OFAC information request?

Specialist sanctions counsel should be engaged as soon as the information request is received – or, ideally, before the organisation does anything else. This is not a precaution for complex matters only. Even a request that appears routine on its face can, on examination, disclose a latent issue that the initial response will determine.

There is a persistent belief among compliance teams that an information request can be handled internally, with outside counsel engaged only if the matter escalates. In our experience, this approach routinely increases, rather than reduces, the organisation's ultimate exposure. The submission itself is an enforcement document. Statements made in it are binding representations. Documents produced in it define the scope of what OFAC can and cannot ask for next. These are legal decisions.

Counsel is particularly important where the request discloses a potential apparent violation (a transaction or relationship that may have breached a sanctions prohibition, whether or not OFAC has yet characterised it as such). In that situation, the response strategy must address the question of whether a voluntary self-disclosure to OFAC is appropriate. A VSD – made proactively and in good faith before OFAC has independently identified the matter – is treated as a significant mitigating factor under the enforcement guidelines. The decision whether to make a VSD, and how to sequence it relative to the information-request response, requires experienced legal judgment.

A micro-scenario illustrates the point. In a recent matter, a financial institution in the payments sector received an OFAC information request relating to a series of transactions processed through a correspondent bank. The initial instinct of the compliance team was to produce the payment records with a brief covering letter and treat the matter as a standard inquiry. Counsel's review revealed that two of the transactions involved an entity caught by OFAC's ownership rules through a layered holding structure. A VSD was filed alongside a carefully framed response. The matter closed without a penalty. Had the submission gone in without that analysis, the outcome would have been materially different.

If a transaction has already been flagged, or an internal review has surfaced a potential breach, an early engagement with counsel preserves options that narrow quickly with time. Contact Calder & Vance at info@caldervance.com for a confidential review of your situation.

A common misconception: "Our compliance programme protects us."

A frequently encountered belief is that the existence of a sanctions-compliance programme – a written policy, a screening tool, a designated compliance officer – is sufficient to mitigate or even avoid liability in an OFAC enforcement matter. This is incorrect, and acting on it during an information-request response can be costly.

OFAC's enforcement guidelines do treat the presence and quality of a sanctions-compliance programme as a mitigating factor. But the guidelines also specify what "quality" means: the programme must be implemented in practice, tested against the firm's actual risk profile, and evidenced through records of training, screening decisions, escalation, and remediation. A programme that describes a process the organisation does not actually follow is not a mitigating factor. In some cases, it is an aggravating one – because it shows the organisation knew what was required and failed to do it.

The second part of the misconception is that a strong compliance programme makes an apparent violation less likely to attract scrutiny. OFAC's information requests often arise from patterns identified through financial-intelligence data, not from voluntary disclosure. A business with a functioning programme that produced an isolated technical breach is in a better position than one with no programme at all. But the programme does not prevent the inquiry; it shapes the outcome of it.

Counsel advising on the response should be in a position to evidence the programme comprehensively: written procedures, training logs, screening-tool configuration records, escalation decisions, and remediation steps taken. That evidence is the substance of the compliance-programme mitigation argument, and it must be built into the submission from the outset.

How Calder & Vance assists with OFAC information-request responses

Calder & Vance acts as lead counsel for businesses at every stage of an OFAC information-request process, from the moment a request is received through to the resolution of the underlying enforcement inquiry.

At the receipt stage, we assess the legal authority cited, the scope of the request, and the applicable time limits. We advise immediately on whether a preservation hold is needed, which custodians should be included, and whether any parallel UK or EU reporting obligations are triggered.

During document collection and review, we manage the privilege analysis across the responsive population, identify gaps in the record that need to be addressed, and reconcile the entity's position against third-party records we can identify. Where the collection spans multiple jurisdictions, we coordinate with local counsel in the relevant jurisdiction to ensure that data-protection constraints – which affect what can be transferred from EU and UK entities to a US counsel team – are managed correctly.

On the submission, we draft the covering letter, structure the privilege log, and frame the entity's legal position in a way that addresses all relevant mitigating factors. Where a VSD is appropriate, we advise on the timing, the scope, and the framing, and we manage the interaction between the VSD and the information-request response to ensure consistency.

For clients with parallel exposures – OFSI, an EU member-state authority, or a foreign financial regulator – we develop a coordinated strategy that sequences and frames each disclosure to maximise mitigation across all regimes. We have acted for financial institutions, exporters, and multinational trading companies across this range of situations.

Our work includes: scoping the apparent violation, advising on voluntary self-disclosure, preparing the penalty defence, and managing the regulator's follow-on queries through to resolution. Where the inquiry proceeds to a penalty stage, we advise on the enforcement-guidelines factors that apply and prepare the penalty response.

Related practices

Frequently asked questions

How long does it take to respond to an information request under OFAC?
The timeline depends on the scope of the request, the volume of documents, and whether a VSD is being prepared in parallel. OFAC typically states a response deadline in the request itself; if it does not, a short response window should be assumed. Complex matters involving multiple custodians, foreign subsidiaries, or privilege review across large document sets may require an extension request, which counsel should submit in writing before the stated deadline. An extension does not guarantee approval, and the substantive response must be genuinely complete when submitted.
What are the main risks in responding to regulator information requests under OFAC?
The main risks are delay or non-response, incomplete document production, inconsistency between the submission and third-party records, and failure to assess whether a voluntary self-disclosure is appropriate. Any of these can convert what might otherwise be a cautionary letter into a civil penalty, or escalate a civil matter to a criminal referral. The quality of legal counsel engaged at the outset is the single most important variable in managing these risks. Acting without experienced sanctions counsel during this process is itself a significant risk.
Do we need specialist counsel for responding to regulator information requests?
Yes. An OFAC information-request response is an enforcement document, not an administrative filing. Statements made in it are binding; documents produced in it define the scope of further inquiry; and the decision whether to make a voluntary self-disclosure carries material legal consequence. General legal teams without specific OFAC and sanctions-enforcement experience routinely underestimate these dimensions. Specialist sanctions counsel should be instructed as soon as the request is received, before any internal response is drafted or any documents are gathered.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.