A financial institution holds a specific licence permitting a defined category of payments to a frozen account. Midway through the licence term, the account holder requests a change to the permitted transaction type. Separately, the licence is approaching its expiry date. Two questions arise simultaneously: can the licence be amended, and what does renewal require? For a business operating across UK and EU sanctions regimes, the answers are not the same – and the divergence carries real compliance risk.
Licence amendments and renewals under OFSI and the comparable EU licensing regime follow distinct procedural and substantive paths. OFSI administers licences under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic regulations; the EU licensing function sits with competent authorities in each Member State, operating under the applicable Council Regulation. As of May 2026, the two regimes diverge meaningfully on amendment triggers, the information required to support a renewal, and the consequences of operating on an expired licence while an application is pending.
This analysis sets out the procedural architecture of each regime, maps the principal points of divergence criterion by criterion, identifies the risk flags that practitioners encounter most often, and explains when specialist counsel should be engaged.
How the two regimes authorise licensed activity
Under OFSI, a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) is issued on defined terms: the parties, the transaction type, the permitted amount, and the duration. OFSI issues licences under SAMLA and the relevant thematic sanctions regulations, applying the licensing grounds set out in those instruments. The licence is a permission, not an exemption; activity outside its precise terms remains prohibited.
The EU position mirrors this architecture in principle but fragments in practice. Each Member State's competent authority issues licences under the applicable Council Regulation. The substantive licensing grounds are uniform across the bloc – they derive from the Regulation itself – but procedural requirements, application forms, response timelines, and amendment practices vary by jurisdiction. A licence issued in one Member State does not automatically authorise activity in another, even under the same Regulation.
This structural difference matters immediately for any cross-border business. A group with entities in the UK and two EU Member States may hold three separate licences for what is commercially a single transaction stream. Each licence has its own expiry date, its own amendment procedure, and its own competent authority. Keeping those three permissions aligned is a compliance task in its own right.
In our experience, businesses frequently underestimate the fragmentation of the EU licensing regime at the Member State level. They obtain a licence from one competent authority and assume it covers EU-wide activity. It does not. The risk of operating without a valid licence in a second Member State is real and, under some Council Regulations, carries significant civil and criminal exposure.
What triggers a licence amendment – and how the two regimes handle it
An amendment is required whenever the licensed activity changes in a way that falls outside the existing licence terms. The threshold question – what counts as a material change requiring an amendment as opposed to a change within existing terms – is answered differently by OFSI and the EU competent authorities.
OFSI takes the position that the licence terms are read precisely. A change in the counterparty, the transaction type, the permitted amount, or the payment route each constitutes a change that requires either an amendment or a new application. OFSI's published guidance makes clear that operating outside licence terms, even where the variation appears minor, is a breach of the underlying prohibition. The burden is on the licence holder to identify any divergence from the original terms and to seek amendment before the divergence occurs.
EU competent authorities apply the same principle, but the margin for interpretation is applied differently across Member States. Some authorities have indicated, through correspondence and published Q&A, that changes to the operational mechanics of a permitted transaction – the bank account through which payment is routed, for example – do not require a formal amendment where the commercial substance remains unchanged. Others require a fresh application for any change to the named accounts. Practitioners advising on EU matters note that obtaining a clear view of the competent authority's position in writing before making the change is essential.
The practical implication is this: a business that has negotiated a single amendment process with OFSI cannot assume an equivalent approach will work with its EU competent authority. Where a change is operationally urgent – a correspondent bank has withdrawn, for example, and a new payment route must be used immediately – the divergence between OFSI and EU practice can create a short window in which one leg of a transaction is authorised and another is not.
The position above covers the standard case. Your facts – the counterparty, the goods, the route, the regime in play – change the analysis. For an assessment of your specific amendment position, contact Calder & Vance at info@caldervance.com.
Renewal: the divergent procedural requirements
Licence renewal under OFSI is not automatic. A licence holder that requires continued authorisation beyond the expiry date must submit a renewal application before the licence expires. OFSI does not prescribe a fixed minimum notice period for renewal applications in its published guidance, but experience before the authority indicates that applications submitted close to the expiry date carry a real risk of a gap in authorisation if OFSI requires additional information or time to process the application.
OFSI will typically require the applicant to demonstrate that the licensing ground still applies at the point of renewal. This is a substantive assessment, not a formality. Where circumstances have changed – the designated person's ownership structure, the nature of the underlying commercial relationship, or the applicable licensing ground itself – OFSI may request updated evidence, may narrow the scope of the renewed licence, or may decline to renew it. Applicants that treat renewal as a routine administrative step have been caught out by requests for fresh due diligence that they were not prepared to supply promptly.
EU Member State competent authorities operate under broadly similar principles, but the procedural timeline and documentation requirements differ. Some authorities publish standard renewal templates; others require a fresh application indistinguishable in scope from the original. A small number of Member States have indicated that where a licence was issued for a defined period and the underlying transaction has not yet completed, the authority will treat a timely renewal application as preserving authorisation during the review period. OFSI has no published equivalent of this position, and practitioners should not assume that activity during a pending renewal application is covered.
This is one of the sharper divergences between the two regimes. An EU business with a pending renewal may, depending on the Member State, have a published basis for continuing operations during the processing window. A UK business whose OFSI licence has expired has no such basis. Operating after expiry without a fresh licence is a breach of the sanctions prohibition. The consequences include OFSI's civil monetary penalty power and, in serious cases, criminal referral.
What happens if a licence lapses? Risk flags across both regimes
A lapsed licence creates immediate legal exposure. Under SAMLA and the thematic regulations, any transaction that would have required a licence is prohibited without one. There is no grace period for administrative oversight. If activity continues after expiry because a renewal application was not filed in time, or because the application was filed but OFSI has not yet responded, that activity is potentially in breach.
OFSI's enforcement posture has hardened in recent years. The authority has demonstrated a willingness to pursue civil monetary penalties where licence conditions were not followed precisely, including cases where the breach arose from administrative error rather than deliberate circumvention. A voluntary self-disclosure (VSD – a report to OFSI by the licence holder about a potential breach before OFSI initiates enforcement) can be a significant mitigating factor. The timing of a VSD matters; an early, well-prepared VSD is treated more favourably than one submitted after an external report or after OFSI has already opened an inquiry.
On the EU side, enforcement of licensing breaches sits with Member State authorities and prosecutors. The severity of the response varies. Some Member States have active enforcement programmes with meaningful financial penalties; others have not yet brought a significant licensing-breach case. Businesses operating across multiple EU jurisdictions face an uneven enforcement environment, which itself creates a compliance planning question: which jurisdiction's exposure profile drives the firm's minimum standard?
Several risk flags recur in our cross-border licensing practice:
- Treating a renewal application as equivalent to obtaining continued authorisation – it is not, under OFSI.
- Relying on a licence issued in one EU Member State for activity in another Member State without confirming that the Regulation's jurisdictional scope extends to that activity.
- Failing to amend a licence when a correspondent bank change alters the payment route named in the licence terms.
- Assuming that a licence covering a corporate entity also covers its subsidiaries – this requires a specific assessment of the ownership and control test in the applicable regime.
- Losing track of multiple expiry dates across parallel OFSI and EU licences for the same underlying transaction group.
If a transaction has already been flagged, or a licence has lapsed without a renewal application being filed, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss the position.
Cross-border divergence: secondary considerations for businesses operating under both regimes
For a business that is simultaneously a UK-nexus entity and an EU-established entity, the management of licence amendments and renewals is not two parallel tasks – it is one interconnected compliance programme. A change that triggers an OFSI amendment will typically also trigger a parallel EU review. The sequence in which those applications are filed and resolved affects the business's ability to operate continuously.
There is a further complication. Where OFSI and an EU competent authority have issued licences covering the same transaction on different terms – perhaps because OFSI's licensing ground is not precisely mirrored in the applicable Council Regulation – an amendment that aligns one licence's terms with changed circumstances may create a divergence with the other. The stricter prohibition governs: a transaction authorised by OFSI but not covered by the EU licence remains prohibited for EU-nexus activity. Businesses must track both permissions in parallel.
For groups that also have US-nexus operations, the OFAC licensing regime adds a third layer. OFAC's specific-licence amendment practice under IEEPA differs from both OFSI and EU procedures. OFAC is not required to respond within any published timeline; licences are typically issued for defined periods; and amendment requests are assessed substantively against the original licensing ground. A business managing OFAC, OFSI, and EU licences for a single transaction group needs a coordinated approach to amendment and renewal across all three authorities simultaneously.
We regularly advise groups on precisely this coordination challenge – mapping the expiry dates, identifying which regime's amendment trigger fires first, and sequencing applications to avoid an authorisation gap in any jurisdiction. The volume of this work has grown as licence terms have shortened and sanctions programmes have expanded in scope.
How the ownership and control test affects amendment and renewal eligibility
An amendment or renewal application is assessed against the licensing ground that justified the original licence. Where the licensing ground depends on the designated person's ownership or control of the applicant's counterparty, any change in that ownership structure is directly relevant to the continued validity of the licence.
Under OFSI and the EU, ownership and control (the test for whether a non-listed entity is caught through a listed person's interest) is assessed on a fact-specific basis. A counterparty that was not majority-owned by a designated person at the date of the original licence application may have become so through a subsequent transaction. Equally, a counterparty that was wholly owned by a designated person may have been partially divested. Neither change is self-executing on the licence: the licence holder must assess the effect, determine whether the licensing ground still applies, and if necessary apply for an amendment or a new licence.
OFSI's ownership and control test applies the principle that a person subject to a financial-sanctions prohibition includes entities owned or controlled by a designated person. The precise threshold – majority ownership, or control through other means – is set out in the relevant thematic regulations. The EU equivalent, drawn from the applicable Council Regulation, is framed similarly but applied by Member State competent authorities whose interpretive positions are not always identical.
In practice, a change in the ownership or control profile of a counterparty is one of the most common triggers for an unplanned amendment application. Businesses that conduct periodic reviews of counterparty ownership as part of ongoing due diligence are better positioned to identify the trigger before it becomes a breach. Those that rely on the original screening at the point of licence application, without any subsequent review, are exposed.
A common misconception – and what it costs
A recurring myth in cross-border licensing practice is that a licence, once issued, runs until it expires and that the licence holder's obligations are limited to staying within the original terms. This view underestimates two things: the dynamic nature of the licensing ground, and the amendment obligations that arise from operational changes.
Licences are issued on the basis of facts as presented at the time of application. If those facts change materially – the ownership structure of the counterparty, the nature of the permitted activity, the parties to the transaction – the licence may no longer cover what it appears to permit, even if it has not formally expired. Operating on a licence whose factual basis no longer holds is not necessarily protected from enforcement action simply because the licence has not been revoked.
We have acted for clients who discovered, during a compliance review or an enforcement inquiry, that a licence they had been relying on for an extended period had become misaligned with the underlying transaction. In some cases, the misalignment arose from a change in ownership of the counterparty that post-dated the original application. In others, it arose from a route change or a change in the transaction mechanics that fell outside the original licence terms. The common factor was that no one had reviewed the alignment between the licence terms and the current facts since the licence was first issued.
The corrective route – a VSD combined with a fresh or amended application – is available, but it is more procedurally demanding and more reputationally exposed than a proactive amendment process would have been. Building periodic licence reviews into the compliance calendar, tied to the expiry date and to any material change in the underlying transaction, is the more effective approach.
Related practices
- Frozen account management – BIS/EAR – managing authorisations for blocked-asset situations under US export-control rules
- Payment authorisation: BIS/EAR vs EU – comparative analysis of US and EU payment licensing requirements
- Payment authorisation: OFAC vs BIS/EAR – divergences between OFAC and BIS/EAR licensing on payment transactions