Sanctions and compliance: from third-party due diligence to the decision to self-report

  • Insight Article 23 July 2026 23 July 2026
  • Global

  • Geopolitical outlook

  • Regulatory & Investigations

From diverging sanctions regimes to internal investigations, from third-party due diligence to the decision to self-report, managing compliance risk today is at once an operational, regulatory and geopolitical challenge. Where should teams draw the line on due diligence? How do you keep a compliance program credible with the business rather than merely cosmetic? When should a company self-report to a regulator, and when should it hold back?

Jeffrey Cottle shares his analysis and his experience, from both sides, in-house and as outside counsel.


Given your extensive experience in different jurisdictions (US, UK, EU) from several perspectives and positions, what is your assessment of the main regulatory approaches in these jurisdictions, and of how they have developed over the past few years?

It is fair to say that the sanctions regulatory environment is becoming increasingly complex over time. The reason is that different regulatory regimes are heading toward conflict with one another: some already conflict, and the geopolitical trend points far more in that direction than toward any kind of convergence or coherence. We’re calling this the “balkanization” of sanctions regimes.

The US, the EU and the UK used to be on the same page when it came to sanctions priorities. The days when one could count on those three regimes being close to identical are over. The US is pursuing its own set of national security priorities, and the UK and the EU theirs. The most glaring example of this is, and will be, in our view, the Russia sanctions regime. On top of that, new regimes are conflicting openly with the Western sanctions framework, foremost among them China's and, to a less impactful extent, Russia's. China's anti-sanctions regime is a particularly significant development, because it places companies squarely in the middle of a conflict-of-laws situation.

“The days of a single compliance lens are over: each regime now has to be tracked separately."

This is the underlying trend, and such situations will only multiply. The days of a single compliance lens are over: each regime now has to be tracked separately and companies will need to parse the precise jurisdictional parameters of each transaction with great care.

Third-party due diligence is a constant point of friction: too light, it misses the risk, too heavy, it stalls the business, and the hardest part is often tracing who ultimately owns and controls a counterparty. Where is it wise to draw the line, and how do you keep ongoing monitoring genuinely useful rather than a box-ticking review?

With limited resources, the starting point is the “risk-based” approach: directing scarce resources to the areas of greatest risk. There are no hard metrics, but my experience shows that, as a rule, around 20% of the counterparties in an enterprise generate most of the risk, while the remaining 80% are lower-risk. The ratio varies from one company to another, but resources should be concentrated on those highest-risk third parties.

“Too many companies understandably pour all their effort into initial onboarding of vendors, counterparties and agents, then run out of resources for the ongoing monitoring of business operations, sales volumes and revenue, which are essential to preventing diversion."

The challenge with a “risk-based” approach is that each company has to weigh how much risk it is prepared to accept, and allocate its resources accordingly. In practice, that means concentrating due diligence where the exposure genuinely lies (e.g., China, the countries bordering Russia, the Middle East, Africa) rather than spending it on counterparties in low-risk regions such as Western Europe or the Nordics, where it adds little.

Because most sanctions regimes are strict liability offenses, the depth of due diligence is not really a free choice: a company is required to follow up on whatever red flags emerge in the ordinary course of business.

For example, if a distributor in Kazahkstan has seen its sales rise by 3,000% since the invasion of Ukraine, with no plausible explanation other than possible diversion to Russia, the company must pursue the matter and get to the bottom of it. That means carrying out due diligence not just at the onboarding stage, but ongoing monitoring of indicators such as sales volumes, distributor activity, shipping activity, etc. Many of these “clues” to diversion can be detected in data a company already holds, e.g., in its CRM systems in particular: as part of a robust, risk-based compliance program, that data needs to be mined. These areas of due diligence are too often overlooked: Too many companies understandably pour all their effort into initial onboarding of vendors, counterparties and agents, then run out of resources for the ongoing monitoring of business operations, sales volumes and revenue, which are essential to preventing diversion.

You ran compliance from inside major corporations before advising on it as a lawyer. Drawing on both perspectives, in your opinion what distinguishes a compliance program that genuinely holds up (one that actually carries weight with senior management and the board) from a cosmetic one, and where do you see teams spending too much energy for too little effect?

My perspective as a former compliance officer is that it is necessary to earn credibility with the business, and the surest way to destroy that credibility is to spend resources on trivial things. There is little need, for instance, to run due diligence on certain low-risk vendors, as it usually adds nothing to prevention, but takes up valuable resources.

“Nothing erodes a compliance function's credibility faster than spending resources on trivial things."

Protecting the time of internal clients and business teams is essential, and so is communicating to them the risks that genuinely matter in high-risk jurisdictions. The relationship with the business needs to remain constructive at all times: As an in-house compliance counsel, much of the job, in the end, is educating internal clients about the risks they actually face, and giving them the room to operate in lower-risk jurisdictions without wasting their time.

When a serious red flag surfaces, an organization is torn between moving fast (preserving evidence, scoping the matter, deciding who to involve) and not rushing into anything that could compromise what follows (tipping off a subject, undermining a possible disclosure). What is really at stake in those first hours and days, and which early missteps do you most often see weigh on the rest of an investigation?

As a retired military officer, one of the first things I learned was the value of not panicking. All too often, a compliance incident triggers a great deal of panic, and panic leads to mistakes. In the first hour of a crisis, the single most important thing is to stay calm: to sit down and gather the facts before any announcement is made and before any investigative step is taken, so companies should approach the situation with a cool head.

"There is an almost automatic reflex in the C-suite to put out a public statement. That is the worst thing to do."

Oftentimes, in companies facing serious compliance issues, there is an almost automatic reflex in the C-suite to put out a public statement (usually denying any allegations). That is the worst thing to do, because the information released is often only partly correct: it is too early to communicate, and there is a real risk of publishing information that will be proven wrong six hours, six days or even six weeks later. In these types of situations, the advisable course of action is to gather the facts, analyze their content, but most importantly, to be very sure of them before considering issuing a public statement. It is worth noting, however, that in most situations a company will never have all the facts. That is precisely why it is best to wait and assess when it is wise to communicate. Not panicking is, in every situation, the most important posture in those first hours.

Self-reporting to a regulator is a weighty decision: it can earn a company a reduced penalty and some control over the timeline, but it also means opening a process it will no longer fully control. When should a company self-report and when should it hold back, and what ultimately tips the balance?

First and foremost, a company should not self-report potential violations of law, but rather known ones. Too often, companies are advised, usually by outside lawyers, to report something before they even know whether they have broken the law.

That is an extraordinarily expensive hypothetical to put in front of a regulator, and the regulator will run with it. There is, unfortunately, a perverse incentive for outside counsel to encourage a client to self-report. A company should therefore self-report only where there are known violations of law.

"If a regulator could find out anyway, self-reporting is no longer up for debate."

When weighing whether to report, a company should ask whether the regulator is likely to learn of the matter in any event. If there is any possibility, however remote, that it would come to light without a self-report, the company should go in and talk to the regulator. A common example is a transaction blocked by a bank for sanctions related reasons: a blocked transaction usually will be reported to a regulator (that is simply how banks operate, i.e., filing a Suspicious Activity Report, or whatever the equivalent is in the jurisdiction). Where a company was involved in such a transaction, the sensible course is to assume the regulator will know about it. In that case the matter is not even up for debate: the company should self-report, because if it stays silent and the regulator investigates of its own accord, it will receive no credit for self-reporting. That, ultimately, is the whole point of coming forward.

Where a company does self-report, the way regulators treat such disclosures is encouraging. Across the jurisdictions where I’ve made self reports (in Europe, the US, the UK and even in Africa), companies invariably receive considerable credit for coming forward. Sometimes that credit is precisely quantifiable, as in the US. In other jurisdictions it may not be, but it is real all the same. The guiding principle, in short, is to self-report only when necessary, but, when it is necessary, to do so without hesitation.

European compliance functions operate in an environment where US legislation and regulatory frameworks carry weight well beyond their own borders. If you had to single out the one issue that most deserves their attention over the next eighteen months, what would it be?

In the sanctions field, a company without a systematic approach to managing sanctions-diversion risk is already behind. A great deal of attention is now being directed at diversion – especially by US regulators - and that only makes sense: most of the primary targets of sanctions have already been designated. In the case of Russia, Iran and others, the principal targets have all been listed. What has followed, around the world, is significant growth in diversion-related activity.

"A company without a systematic approach to sanctions diversion is already behind."

Regulators understand this perfectly well: they know goods are no longer being sold into Russia directly, but indirectly. Any company that does not yet have a program geared toward sanctions diversion should put one in place quickly.


Interview conducted by Paul Caillard, coordinator of the AEGE Law Club, and Victor Chaves de Oliveira, Editor-in-Chief of the Economic Intelligence Portal for the Law Club, under the supervision of Clarisse Senaya, Editorial Director of FCS Journal.

End

Stay up to date with Clyde & Co

Sign up to receive email updates straight to your inbox!