A virtual-asset service provider operating across EU member states discovers that a wallet address linked to one of its customers appears on the EU Consolidated List. The compliance team freezes the assets. But questions multiply fast: does the freeze obligation extend to the customer's other wallets held on the same platform? What must be reported, to whom, and within what window? Is the position different under OFAC or OFSI? These are not hypothetical concerns. As of mid-2026, EU crypto and VASP sanctions compliance sits at the intersection of financial-sanctions rules that were written for banks and a technology that did not exist when those rules were drafted.
Crypto and VASP sanctions compliance under EU (the obligations imposed on virtual-asset service providers by EU Council regulations and the EU Transfer of Funds Regulation) requires VASPs to screen wallets and customers against the EU Consolidated List, freeze assets of listed persons, report to competent national authorities, and apply travel-rule data requirements to crypto transfers. The EU regime operates alongside – and sometimes in tension with – the OFAC rules that govern US-nexus transactions and the OFSI regime that covers UK-incorporated or UK-presence businesses. Where the rules conflict, the stricter prohibition generally governs.
This analysis maps the EU obligations in detail, compares the divergences with OFAC and OFSI, identifies the risk flags specific to virtual-asset businesses, and sets out when cross-border VASPs should involve counsel.
How does the EU sanctions regime apply to virtual-asset businesses?
The EU regime treats VASPs as obliged entities under both its financial-sanctions rules and its anti-money-laundering framework, creating a layered compliance obligation. Under the relevant EU Council regulations, VASPs must freeze funds and economic resources belonging to, owned, held, or controlled by any person or entity on the EU Consolidated List. The freeze obligation applies regardless of whether the assets take the form of fiat currency, crypto-assets, or tokenised instruments.
The legal basis sits in the individual thematic sanctions regulations adopted by the Council of the EU, which apply directly across all member states without transposition. Each regulation defines "funds" and "economic resources" broadly. Regulators in several member states have confirmed that crypto-assets fall within those definitions. There is no formal carve-out for decentralised protocols, and a VASP that routes a transaction involving a listed person through a smart contract does not escape the prohibition on that basis alone.
For VASPs, the practical consequence is threefold. First, customer screening must cover not only the registered account holder but also the beneficial owner of the wallet, applying the ownership and control test (the EU and UK test for whether a non-listed entity is caught through a listed person). Second, transaction monitoring must be capable of flagging wallet addresses associated with listed persons, not only legal-name hits. Third, where a freeze is triggered, the VASP must notify its competent national authority without delay – the reporting window is short and varies by member state under implementing measures.
In our cross-border practice, we regularly see VASPs that have invested in name-screening tools but have not addressed on-chain analytics. That gap is where enforcement risk accumulates.
What is the EU travel-rule standard for crypto transfers, and how does it compare with OFAC?
The EU travel-rule standard, derived from the Transfer of Funds Regulation as extended to crypto-asset transfers, requires VASPs to transmit originator and beneficiary information with every crypto transfer and to verify that information above a defined threshold. The obligation applies to all crypto-asset transfers from or to a VASP established in the EU, covering both the sending and receiving sides of the transaction.
The information that must accompany a transfer includes the originator's name, the wallet address or transaction identifier, and – above the relevant threshold – the originator's account number and address or national identity number. The receiving VASP must check this data against the EU Consolidated List before making funds available to the beneficiary. This is the point at which the travel rule and the sanctions-screening obligation intersect directly.
Under OFAC, the travel-rule equivalent derives from the Bank Secrecy Act and FinCEN rules that apply to money-services businesses, including those handling convertible virtual currency. The OFAC overlay is separate: any US-nexus transaction – involving a US person, US-dollar settlement, or software or infrastructure with a US footprint – triggers OFAC compliance obligations independently of where the VASP is registered. A European VASP using US-hosted node infrastructure or accepting US-person customers may sit within OFAC's reach even if it has no US establishment.
The divergence matters operationally. Under the EU regime, the travel rule is a data-transmission and verification obligation. Under the OFAC rules, the focus is on the prohibition: if the originator or beneficiary is an SDN (a person on OFAC's Specially Designated Nationals and Blocked Persons List), the transaction must not proceed regardless of whether the data was transmitted correctly. Both regimes bite simultaneously on a cross-border transfer. In our experience, compliance teams that treat the travel rule as a data exercise and OFAC compliance as a separate workstream miss the overlap.
The position above covers the standard cross-border case. Your specific facts – the wallet infrastructure, the customer base, the settlement currency, the hosting jurisdiction – change the analysis. For an assessment of your EU and OFAC exposure, contact Calder & Vance at info@caldervance.com.
How does the EU ownership and control test apply to crypto-asset holdings?
The EU ownership and control test asks whether a non-listed entity is owned or controlled by a listed person; if it is, the entity's assets are frozen in the same way as the listed person's own assets. Applying that test to crypto is technically demanding. Unlike shareholdings in a company, ownership of a crypto-asset can be established by mere possession of a private key, and control can be exercised indirectly through a smart contract, a custodian arrangement, or a multi-signature wallet structure.
EU competent authorities take the position that the test is substance-over-form. A listed person who retains economic benefit or practical control over a wallet – even if the legal title sits with a third party – means that the wallet's assets are subject to the freeze obligation. VASPs acting as custodians bear the primary obligation to assess this. The relevant question is not who holds the private key at a given moment, but who ultimately benefits from and directs the asset.
Under OFSI, the UK parallel test also extends to "control" as well as ownership, and OFSI has issued guidance confirming that control over crypto-assets can be direct or indirect. The EU and UK positions are broadly aligned on the substance of the test. Where they diverge is in the enforcement posture: OFSI has signalled a willingness to take enforcement action for inadequate control analysis, not only for direct facilitation of a prohibited transaction.
OFAC's equivalent is the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked). That test is mechanical and ownership-focused; it does not formally incorporate a control limb in the same way. A wallet that a listed person controls but does not technically own may be treated differently under the OFAC analysis than under the EU or UK tests. For a VASP operating across all three regimes, the safest approach is to apply the broadest test – EU or UK control – across the entire portfolio.
Where do the EU, OFAC, and OFSI regimes diverge most sharply for VASPs?
The sharpest divergence between the EU regime and OFAC lies in the question of extraterritorial reach and secondary-sanctions risk. OFAC regulations apply to US persons wherever located and to transactions with a US nexus; some OFAC programmes carry secondary-sanctions risk for non-US persons who engage in covered transactions with designated parties. The EU regime does not replicate secondary-sanctions architecture: it binds EU-established entities and transactions that occur within EU territory, but it does not penalise a non-EU VASP purely for transacting with a listed person outside EU jurisdiction.
That structural difference creates a difficult position for a VASP with a mixed client base. A transaction that would not trigger EU sanctions liability (because neither party is EU-established and the transaction has no EU territorial nexus) might still generate OFAC risk if there is a US-dollar leg or a US-person investor in the VASP's parent structure. The question a compliance team must answer is not simply "is this blocked under EU law?" but "does OFAC also care, and for a different reason?"
The OFSI position sits between the two. OFSI sanctions bind UK persons and UK-incorporated entities. OFSI's licensing regime is broadly similar in structure to OFAC's specific-licence mechanism, though the statutory tests and the guidance on what constitutes a licensable humanitarian or legal-expenses purpose differ in detail. A VASP that is incorporated in the UK and regulated by the FCA faces OFSI obligations in addition to any EU obligations arising from its EU operations or customer base.
A further point of divergence concerns de-risking (the practice by which a financial institution or VASP exits a relationship to avoid sanctions exposure). The EU regime does not prohibit de-risking in its direct terms, but member-state regulators have raised concerns about blanket de-risking as a substitute for proper risk-based compliance. OFAC has similarly cautioned that across-the-board rejection of whole geographic categories, without individual risk assessment, can itself create legal and regulatory issues. A well-designed programme does not de-risk blindly; it assesses.
If a transaction has already been flagged, or a wallet has been frozen and the customer is disputing the basis, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.
What are the principal risk flags for VASPs operating under the EU regime?
VASPs face a distinct set of risk flags under the EU regime that do not map directly onto the risk patterns of traditional financial institutions. Five categories recur most frequently in our advisory work.
First, unhosted wallet exposure. When a customer transfers crypto-assets from or to a wallet that has no associated VASP (a self-hosted or peer-to-peer wallet), the EU travel-rule requirements impose obligations on the VASP side of the transaction to collect and verify beneficiary or originator information. The inability to obtain that information is itself a risk indicator. EU guidance on unhosted wallets has tightened, and the inability to complete sanctions verification may require the VASP to refuse or reverse the transaction.
Second, indirect exposure through nested services. A VASP that provides services to another VASP (a nested arrangement) inherits exposure to the underlying VASP's customer base. If the nested VASP has inadequate screening, a transaction involving a listed person may reach the outer VASP's infrastructure. EU regulators treat the outer VASP as responsible for the know-your-VASP assessment, not merely for screening at the point of settlement.
Third, token classification and economic-resource questions. EU sanctions apply to "economic resources" as well as "funds." Where a VASP issues or trades tokens that represent real-world assets (real estate, commodities, equity interests), the question arises whether a listed person's token holding constitutes an economic resource subject to freeze. The answer in most cases is yes, but the mechanics of identifying and freezing a tokenised economic resource are not always clearly addressed in the VASP's operational procedures.
Fourth, sanctions-list lag in fast-moving designations. EU designations take effect on publication in the Official Journal of the EU. A VASP that screens only at onboarding and does not run ongoing periodic rescreening will miss designations made after the customer relationship opened. Automated, continuous rescreening against the EU Consolidated List is the standard expected by competent authorities.
Fifth, inadequate record-keeping. EU sanctions rules require VASPs to retain records of transactions, screening results, and freeze actions. Inadequate documentation both undermines a VASP's ability to demonstrate compliance in an enforcement review and makes it harder to reconstruct the facts if a transaction is challenged. Record-keeping requirements under EU law and under the VASP's own AML obligations overlap; a single well-designed system should satisfy both.
What does effective VASP sanctions compliance look like in a cross-regime environment?
Effective compliance for a cross-border VASP requires a programme that is designed for the intersection of multiple regimes, not merely for the least demanding one. A VASP that calibrates its controls to the EU minimum may still face OFAC liability for US-nexus transactions. A VASP that satisfies OFAC requirements but has not addressed the EU travel-rule obligation faces a gap on the EU-regulated side of its operations.
In our experience, the strongest programmes share five characteristics. They identify the VASP's regulatory perimeter precisely – which jurisdictions apply, which nexus tests are triggered, and which competent authority holds jurisdiction. They apply list screening to customers, beneficial owners, and counterparty wallets on a continuous basis, using both legal-name matching and blockchain-analytics tools. They have a documented procedure for wallet freezes, including the reporting chain to the competent national authority. They assess nested and institutional relationships under a distinct know-your-VASP standard. And they maintain complete records of every screening event and every decision to proceed or refuse.
Does your current programme address the ownership-and-control question for custodied wallets, or only the registered account holder? That is frequently the first gap an enforcement review identifies.
A related and often overlooked element is the interaction between sanctions obligations and data-protection rules. EU sanctions require VASPs to collect and process personal data about beneficial owners and wallet controllers. That processing must be compatible with the applicable data-protection regime. Tension between the two sets of rules is real and requires a considered approach at the programme design stage, not as an afterthought.
Situation A: a VASP onboarding a new institutional client with a complex ownership structure. The route is a structured ownership-and-control analysis, an EU-and-OFAC dual-screen, and a documented risk assessment before account opening. The indicative timeline depends on the depth of the corporate structure. The key risk is incomplete beneficial-ownership data from the client.
Situation B: a VASP that has received a notification from a competent authority that a customer account appears to involve a listed person. The route is an immediate precautionary freeze, legal review of the freeze basis, a report to the competent authority within the applicable window, and an assessment of whether other accounts held by the same customer are caught by the ownership-and-control analysis. The risk of delay is significant: late reporting is itself a potential breach.
Situation C: a VASP expanding from EU-only operations into a market where it will handle US-dollar transactions or onboard US-person customers. The route is an OFAC nexus assessment before launch, a review of secondary-sanctions exposure by programme, and a decision on whether to implement an OFAC-specific compliance layer or to segment the US-facing business operationally. The risk of proceeding without that assessment is unquantifiable until the OFAC programme analysis is done.
In a recent matter, a payments-and-crypto business operating across three EU jurisdictions identified a gap in its nested-VASP screening after a counterparty was designated. We assessed the firm's exposure under the relevant EU regulations and the applicable OFAC programmes, mapped the ownership-and-control question across the customer portfolio, and helped the firm prepare its report to the competent authority and its voluntary disclosure assessment. The matter was resolved through documented remediation and enhanced ongoing controls.
The common misconception: is blockchain transparency a substitute for sanctions screening?
A persistent misconception in the VASP sector is that the public and auditable nature of blockchain ledgers reduces the need for formal sanctions screening. The argument runs: if all transactions are visible on-chain, regulators can identify prohibited activity themselves, and a VASP is merely a conduit. This argument does not hold under any of the major regimes.
EU sanctions obligations are prospective and preventative. The obligation to screen and freeze falls on the VASP before the transaction is processed or the funds are released, not after. Blockchain transparency assists enforcement investigation after the fact; it does not discharge the VASP's real-time compliance obligation. A VASP that processes a transaction involving a listed person and then points to the public ledger as evidence that the transaction was visible has not complied with its freeze obligation.
A second version of the myth holds that only custodial VASPs have sanctions obligations, because non-custodial or partially-custodial models do not hold client funds. EU and OFAC guidance both address this. The question is not whether the VASP holds assets at a given moment, but whether it facilitates a transfer of funds or economic resources involving a listed person. Facilitation that does not involve custody can still constitute a prohibited dealing, depending on the facts and the applicable regime.
We regularly advise VASPs that have structured their services to reduce custodial exposure without undertaking the corresponding analysis of whether facilitation obligations still apply. That structural choice may reduce one risk category while leaving another unaddressed.
Related practices
- Sanctions compliance audit and testing – Australia – programme testing and gap analysis under Australia's autonomous-sanctions regime
- Crypto and VASP sanctions compliance under OFAC – practitioner analysis of OFAC obligations for virtual-asset businesses
- Crypto and VASP sanctions compliance: OFAC vs Canada – comparative analysis of US and Canadian obligations for cross-border VASPs