Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · EU

Compliance audit and testing under EU: what businesses miss

A mid-sized European trading group acquires a logistics subsidiary and, within weeks, its compliance team discovers that the new entity's screening tool covers only direct counterparties. Beneficial-ownership chains are not tested. Dual-use classifications have not been reviewed. Existing licences have never been audited against actual shipment data. A single enforcement inquiry from a national competent authority could expose the group to significant civil penalties across multiple EU member states simultaneously. As of July 2026, enforcement activity under the EU sanctions regime is intensifying, with national authorities under growing pressure to demonstrate active supervision. The question is not whether your compliance audit covers the basics. The question is whether it covers what the EU actually requires – and most programmes do not.

Compliance audit and testing under the EU regime means the systematic, documented review of a business's sanctions and export-control controls against the Council regulations and implementing measures in force at the time of the audit. The governing authority is the European Council (for designations) and the national competent authorities of EU member states (for enforcement and licensing). The single most common gap we identify is the failure to test ownership-and-control logic against the EU's dual-pronged test – both ownership 50 percent or more and broader control – which is more demanding than the OFAC mechanical threshold.

This analysis sets out the legal basis for the EU audit obligation, the procedure and tests that matter most, the points where the EU regime diverges from OFAC and OFSI, the risk flags that experienced counsel look for first, and the practical steps a business should take before the regulator asks the questions.

What is the legal basis for compliance audit obligations under the EU sanctions regime?

The duty to maintain effective controls flows directly from the relevant Council regulations, which impose prohibitions on EU persons and entities and create a positive obligation to act on knowledge of a breach. National competent authorities – the designated enforcement bodies in each member state – hold the power to investigate, penalise, and publicise non-compliance. The regime does not publish a single consolidated compliance standard equivalent to OFAC's five-part framework, but the enforcement posture of national authorities has made the underlying expectations functionally equivalent.

The EU's structure creates a layered obligation. The Council regulation sets the prohibition. The implementing regulation adds designated names and entities. Subsequent amending regulations add or remove designations, often on short notice. A business that audited its controls in January 2026 may already be operating against a list that has changed materially. In our practice, we see this sequence cause real problems for businesses that rely on periodic rather than continuous monitoring.

Two additional instruments shape the audit agenda. First, the EU Blocking Regulation (the instrument that prohibits EU persons from complying with certain extraterritorial measures by third-country authorities) creates a compliance tension: the same transaction may require action under one regime and prohibit compliance with another. Testing how your programme resolves that tension is a core element of any serious EU sanctions audit. Second, EU dual-use export control rules (the controls governing goods and technology that have both civil and military applications) sit alongside the sanctions regime and must be covered in any integrated audit of cross-border trade flows.

The position above covers the standard case. Your specific corporate structure, the sectors in which you operate, and the nationalities of your counterparties and shareholders change the analysis materially.

For a confidential review of your EU compliance programme, contact Calder & Vance at info@caldervance.com.

How does the EU ownership-and-control test differ from the OFAC and OFSI approaches?

The EU ownership-and-control test is the most consequential point of divergence between the major regimes, and the one most likely to produce a gap in a programme designed primarily around OFAC. Under the EU regime, an entity falls within the scope of a designation if a listed person owns or controls it – with control assessed not only by shareholding but by the capacity to determine strategic commercial decisions, appoint management, or otherwise direct the entity's conduct. Ownership at 50 percent or more creates a presumption, but the test does not stop there.

OFAC's position is more mechanical. The 50 percent rule (OFAC's test treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked) is the operative threshold for determining whether an unlisted entity is itself blocked. Aggregation of interests by multiple blocked persons applies, but the test is fundamentally ownership-focused. Control in the management sense is not independently decisive under the OFAC framework in the same way it is under the EU regime.

OFSI, the UK's Office of Financial Sanctions Implementation, applies a test that is closer to the EU approach. Ownership and control under OFSI encompasses both a direct ownership limb and a control limb. The control limb asks whether a designated person is able to determine or influence the activities of an entity. That is a qualitative question, and it can catch entities in which a designated person holds a minority stake but exercises strategic influence through board representation or contractual rights.

What does this mean for audit design? A programme calibrated to OFAC's binary threshold will miss cases where EU or OFSI control analysis would catch the same entity. We regularly advise businesses operating across these three regimes to run a three-track ownership analysis: the OFAC aggregation check, the OFSI control review, and the EU ownership-or-control assessment. Running only one track is not a multi-regime compliance programme. It is a single-regime programme with an illusion of coverage.

One practical consequence: a joint-venture partner who holds 30 percent of a target entity and sits on its supervisory board may not trigger the OFAC 50 percent rule but may well be assessed as exercising control under EU and OFSI analysis, particularly where board approval is required for material commercial decisions. Have you tested your JV structures and minority holdings against that standard?

What does a well-structured EU compliance audit actually cover?

A well-structured EU compliance audit covers five functional areas: list coverage and update frequency, ownership-and-control logic, transaction monitoring and payment screening, licensing and authorisation management, and record-keeping against the applicable retention standard. Each area has both a design element (does the programme say the right thing?) and an operational element (does the programme do the right thing in practice?).

List coverage is the starting point. The EU Consolidated List is updated on short notice when new designations are adopted. A programme that refreshes its lists weekly may be operating for days against an outdated list. In our experience, businesses that are part of larger groups often discover that list-update cadence varies by subsidiary, creating inconsistent exposure across the enterprise. The audit should verify both the source of the list feed and the time lag between a Council regulation entering into force and the update reaching the screening tool.

Ownership-and-control logic is the area where most audit failures concentrate. The question is whether the programme goes beyond matching listed names to direct counterparties and actually maps the beneficial ownership chains of significant counterparties. This requires documented methodology: at what ownership threshold does the programme conduct enhanced review? How does it treat nominee arrangements and trust structures? What is the escalation path when control – rather than ownership – is the operative question?

Transaction monitoring covers the review of payments, trade flows, and service arrangements for patterns that may indicate a sanctions connection not captured by name screening alone. Jurisdictional routing, payment intermediaries, and the ultimate destination of goods are all relevant under the EU regime's asset-freezing and trade-prohibition provisions. Testing whether the monitoring logic catches these patterns – not just whether it exists – is the difference between a paper programme and a tested one.

Licensing and authorisation management is often neglected entirely. A business that holds an existing authorisation from a national competent authority must verify that its actual conduct remains within the terms of that authorisation. Licences issued under earlier versions of a Council regulation may not automatically cover transactions authorised under an amended regulation. The audit should map every live licence against current transaction flows and flag mismatches.

Record-keeping must be assessed against the applicable retention period under the relevant Council regulation. The retention obligation is a legal requirement, not an internal policy choice. Failure to produce records on request from a national competent authority is itself a ground for adverse inference in an enforcement context.

Where does EU compliance audit and testing diverge from comparable regimes?

The EU regime's multi-member-state enforcement architecture creates a divergence that has no equivalent under OFAC or OFSI. A single sanctions breach by an EU-based business may be investigated and penalised by the national competent authority of every member state in which the business has an establishment or through which the transaction passed. There is no central EU enforcement body equivalent to OFAC or OFSI. Penalties and procedures differ between member states, and an audit that is calibrated to the enforcement expectations of one member state may be inadequate in another.

Under OFAC, enforcement is centralised. A voluntary self-disclosure (VSD – a proactive report of an apparent violation to OFAC before a regulator raises the issue) goes to one agency, under one procedure, and the mitigating value of the VSD is assessed against one set of guidelines. Under the EU regime, the decision of whether and how to disclose to a national competent authority depends on the law of the relevant member state. Some member states have formal self-reporting mechanisms with explicit mitigation credit. Others have no equivalent pathway. Testing your disclosure readiness under EU conditions requires a member-state-level analysis, not a single EU-level answer.

The OFSI regime adds an additional complexity for UK-based EU groups. Post-Brexit, a transaction that was previously assessed solely under EU rules now requires a parallel OFSI analysis. The designated lists are not identical. The licensing exceptions are not identical. A compliance programme designed before Brexit that has not been updated for the UK regime's independent development is a programme with a structural gap.

Switzerland, through SECO and the applicable country regime, maintains its own list that frequently mirrors EU designations but is not identical. For businesses with Swiss operations or transit, the audit must cover the Swiss position separately. Similarly, for groups with operations in Singapore, Japan, or the UAE, the audit should map the interaction between the EU regime and each applicable country regime – particularly where the EU's asset-freezing provisions conflict with a local legal obligation to perform under an existing contract.

For a comparative analysis of EU and Swiss compliance audit requirements, see our analysis of EU versus SECO compliance audit and testing.

What risk flags should a compliance audit surface under the EU regime?

The risk flags that most commonly surface in our EU compliance audits fall into three categories: structural gaps, operational gaps, and governance gaps. Each produces different types of exposure and requires a different remediation approach.

Structural gaps are flaws in how the programme is designed. The most common is a programme that was built for a single regime and then nominally extended to cover the EU without redesigning the ownership-and-control logic. The screening tool may import the EU Consolidated List correctly, but if the matching logic and the escalation procedure were designed for OFAC's binary threshold, the EU control analysis is effectively disabled. A related structural gap is the absence of a dual-use classification procedure within the compliance programme. Businesses that manufacture or distribute goods with potential dual-use applications must integrate their export-control classification review with their sanctions screening, not run them as separate processes.

Operational gaps are failures in execution. The programme exists on paper but does not function as designed. Common examples include: screening tools that are configured correctly but whose lists have not been updated following a designation wave; enhanced due diligence procedures that are triggered correctly but whose outputs are not reviewed before transaction execution; and authorisation terms that have been accepted but not communicated to the operational teams responsible for execution.

Governance gaps concern accountability and oversight. Who owns the sanctions compliance programme in the business? Is there a documented escalation path from a screening hit to a senior decision-maker? Is the compliance function independent of the revenue-generating activity it is testing? Under EU enforcement expectations, an effective compliance programme requires genuine independence and documented oversight by senior management. A compliance programme owned and operated entirely by the same team that executes the transactions it is supposed to screen is a governance gap of the most fundamental kind.

In a recent matter, a financial services business active across several EU jurisdictions had a screening programme that was technically current on list coverage but had not been tested against the actual flow of transactions for over eighteen months. When we ran a retrospective test against a sample of historical payments, we identified a pattern of jurisdictional routing through intermediary institutions whose own ownership structures had not been verified. The matter did not result in a confirmed breach, but the review identified the gap before a regulatory inquiry did. Early identification preserves options.

If a transaction has already been flagged, or a regulatory enquiry has arrived, an early review can preserve options that narrow significantly with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.

A common misconception: EU compliance audit is not just a list-matching exercise

The most persistent myth in EU sanctions compliance is that a programme is adequate if it screens counterparty names against the EU Consolidated List. This is wrong in three distinct ways, and the misconception is genuinely dangerous in an enforcement context.

First, as explained above, the EU test extends beyond listed names to entities owned or controlled by listed persons. A programme that screens names but does not map ownership and control is testing for perhaps forty percent of the actual exposure. The remaining exposure sits in the corporate structures of counterparties that do not appear on any list as a named entity.

Second, the EU prohibitions extend beyond asset-freezing to a range of sector-specific trade restrictions, service prohibitions, and financial-market restrictions that have no direct list-matching equivalent. Whether a particular service can be provided to a counterparty in a specified sector may depend not on any designation but on the terms of the relevant Council regulation's sectoral measures. Screening for names does not catch this exposure at all.

Third, the EU Blocking Regulation creates obligations that run in the opposite direction: EU persons are in certain circumstances prohibited from complying with instructions from third-country authorities. A compliance programme that has no mechanism for identifying when the Blocking Regulation is engaged – and for escalating to counsel when it is – is not a complete EU compliance programme.

We regularly advise clients who have been operating on the assumption that a name-screening tool, properly maintained, is a complete EU sanctions programme. It is not. Correcting this misunderstanding before an enforcement inquiry arrives is significantly less costly than explaining it to a national competent authority during one.

When should a cross-border business involve external compliance counsel?

External compliance counsel should be involved when the audit is the first formal assessment of a programme, when the programme has not been independently tested within the previous twelve months, and when the business has undergone a material change – an acquisition, a new jurisdiction, a new counterparty category, or a change in the sanctions programmes applicable to a significant trading relationship.

The standard for what constitutes an adequate compliance programme is not static. As the EU regime has developed, and as national competent authorities have increased enforcement activity, the baseline expectation has moved. A programme that was adequate two years ago may not meet the current enforcement standard. Testing against the current standard requires familiarity with current national enforcement practice, not only with the text of the Council regulation.

External counsel also serves a function that internal teams cannot: independence. A compliance team that tests its own programme is subject to the same organisational pressures that produced the programme in the first place. An independent audit, conducted by counsel who advises on enforcement and delisting as well as compliance design, is more likely to surface the gaps that an internal review rationalises away. In our cross-border practice, we find that the most consequential findings in an EU compliance audit – the ones that would have mattered most to a national competent authority – are precisely the ones that internal teams had identified but deprioritised.

For analysis of the OFAC compliance audit standard and its differences from the EU approach, see our analysis of compliance audit and testing under OFAC. For businesses with Australian operations, our Australian compliance audit and testing service page addresses the DFAT regime specifically.

Related practices

Frequently asked questions

Where do the regimes diverge on compliance audit and testing?
The principal divergences are enforcement architecture, the ownership-and-control test, and disclosure mechanics. The EU has no central enforcement body; national competent authorities in each member state enforce independently, with differing penalty scales and disclosure procedures. The EU and OFSI apply a dual ownership-and-control test; OFAC's test is primarily ownership-based at the 50 percent or more threshold. VSD procedures under OFAC are centralised and well-defined; EU member-state procedures vary. A cross-border programme must be designed to satisfy the most demanding standard applicable, not a single-regime average.
Which regime is stricter on compliance audit and testing?
Strictness depends on the dimension being assessed. The EU regime is broader in its control test and covers a wider range of sector-specific service and trade prohibitions that do not reduce to list-matching. OFAC's penalty regime can produce very large civil penalties for systemic violations, and its enforcement guidance is more prescriptive on programme elements. OFSI's recent shift to a more active enforcement posture has narrowed the practical gap between UK and EU expectations. For a multi-regime business, the operative standard is the strictest applicable requirement across all relevant regimes – where they diverge, the stricter prohibition governs the decision.
What should a cross-border business do about compliance audit and testing?
A cross-border business should first identify every regime under which it has obligations – by reference to the nationality and location of its legal entities, its counterparties, and the goods or services it provides. It should then commission an independent audit of its compliance programme against the specific tests and expectations of each applicable regime. Priority areas are ownership-and-control logic, list-update cadence, transaction-monitoring coverage, and licensing management. Findings should be documented, remediated in order of enforcement risk, and the audit cycle should be set to match the pace of regulatory change – which, under the EU regime, is currently high.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.