A trading company operating across the UK and the EU finalises a supply agreement. The goods are dual-use. The compliance team assumes that a general exception it applied under the EU regime will carry over automatically to cover the UK leg of the transaction. Six weeks later, OFSI queries a payment. The transaction that felt routine turns out to be unlicensed under UK law. That assumption – that licence exceptions are interchangeable between regimes – is the most common and most costly error we see in cross-border export-control and sanctions work.
Licence-exception eligibility under OFSI and the EU diverges in three material ways: the legal instruments that define the exceptions, the conditions a business must satisfy before relying on them, and the consequences of a mistaken reliance. As of April 2026, UK financial-sanctions law operates under the Sanctions and Anti-Money Laundering Act and its thematic regulations, which have diverged from EU Council regulations at the margins since the UK's departure from the EU legal order. The exceptions are not identical, and treating them as such is a compliance failure.
This analysis sets out the governing authority in each regime, maps the key points of divergence, identifies the risk flags that practitioners see most often, and closes with a practical decision sequence for businesses operating across both jurisdictions.
What is the legal basis for licence exceptions in each regime?
Under UK law, the authority to grant licences and to define exceptions sits with His Majesty's Treasury, administered through the Office of Financial Sanctions Implementation (OFSI). The Sanctions and Anti-Money Laundering Act 2018 (SAMLA) is the primary statute; each thematic sanctions statutory instrument then sets out the prohibitions and the permitted exceptions specific to that programme. OFSI publishes licensing guidance that explains how it interprets those exceptions in practice. The guidance is not the statute, but in our experience, OFSI applies it consistently and expects businesses to know it.
Under EU law, the legal basis is the relevant Council Regulation and the accompanying Council Decision for each sanctions programme. The European Commission may issue interpretive guidance, and individual member-state competent authorities – each of which administers the EU regime within its own territory – may add their own guidance. This creates layering that the UK regime does not replicate. A business dealing with, say, a French bank and a German subsidiary faces the EU Council Regulation as the common floor, but also the guidance of the Banque de France and BaFin as administrators. OFSI operates as a single, UK-wide authority. That centralisation is an advantage for clarity, even if the substantive rules differ.
One point is often missed: since January 2021, OFSI has been free to diverge from EU exceptions. It has done so, quietly, in several thematic programmes. A business that derived its compliance position from EU Council regulations before that date and has not revisited the UK position since is operating on an outdated assumption.
How do the conditions for exception eligibility differ in practice?
Both regimes distinguish between general licences (standing authorisations that permit a defined category of transactions without a separate application) and specific licences (case-by-case authorisations). But the conditions attached to general licences – and the categories of activity they cover – are not the same.
Under OFSI, a general licence specifies its scope precisely. A business relying on one must confirm that each transaction falls squarely within the terms: the counterparty must be in the right category, the purpose must match, and any monetary threshold or time limit must be respected. OFSI's guidance is clear that a transaction falling partly outside the licence terms is not covered by it. There is no de minimis discretion.
Under the EU regime, general authorisations function similarly in principle. However, the EU's approach to certain humanitarian exceptions, for example, has at times been broader in its drafting than the UK equivalent. The result is that activity covered by an EU general authorisation may require a specific OFSI licence – or may not be covered at all under UK law for that programme.
Conditions matter at the transactional level, too. Both regimes typically require that a business relying on an exception has made reasonable enquiries as to the counterparty's status and purpose. Under OFSI, the standard of due diligence expected before relying on an exception is not explicit in SAMLA itself but is embedded in OFSI's enforcement guidance. OFSI has made clear that it will look at whether a business took reasonable steps. A business that relied on an exception without any screening, or without retaining records of its checks, will struggle to demonstrate that reliance was legitimate.
The EU regime similarly requires good faith and reasonable diligence. The divergence is in the detail: the EU's ownership-and-control test, which determines whether a non-listed entity is caught through a listed person, operates alongside the exception conditions and can disqualify an exception that would otherwise apply. That test is not identical to the OFSI ownership-and-control test, and the two can produce different results for the same corporate structure.
Where do the regimes diverge on licence-exception eligibility?
The sharpest divergences sit in four areas: humanitarian exceptions, legal-fees exceptions, maintenance-of-frozen-assets exceptions, and prior-contract exceptions.
Humanitarian exceptions are present in most major sanctions programmes under both regimes. But the scope of "humanitarian" is defined differently. The EU has in several programmes adopted broader language covering a wider range of organisations and activities. OFSI's humanitarian exceptions are drafted more tightly. A non-governmental organisation relying on EU coverage for its UK payments needs to verify the OFSI position independently.
Legal-fees exceptions illustrate the same asymmetry. Under the EU regime, legal fees and legal-representation costs can often be paid to a designated person's legal advisers under a general authorisation, subject to a monetary cap and notification. Under OFSI, the legal-fees exception in a given programme may require a specific licence rather than relying on a general one. The procedural difference is significant: a general authorisation can be applied immediately; a specific OFSI licence takes time to obtain, and the transaction is blocked until the licence issues.
Maintenance-of-frozen-assets exceptions – covering, for instance, insurance premiums, bank charges, or routine property upkeep for a designated person's frozen accounts – follow similar logic. The EU has tended to authorise more of these by general authorisation. OFSI requires specific licence applications in a number of cases where the EU does not. In our experience, advisers who have prepared a client's position under the EU regime and then assumed UK equivalence regularly find that one or more of these categories needs a UK-specific application.
Prior-contract exceptions – permitting the completion of contracts signed before a designation – are the area of most active divergence. Both regimes generally allow for some treatment of pre-designation contractual obligations, but the conditions, timelines, and notification requirements differ. The EU framework for prior contracts in several programmes has allowed a longer execution window than the comparable UK provision. That difference alone can determine whether a shipment or a payment can lawfully proceed.
Which regime is stricter on licence-exception eligibility?
Neither regime is uniformly stricter. The answer depends on the programme, the exception category, and the facts of the transaction. That is exactly why blanket assumptions in either direction are dangerous.
In the programmes where the UK has maintained full alignment with EU exceptions, the regimes are effectively equivalent for eligibility purposes. In the programmes where OFSI has diverged, the UK position is often – though not always – narrower. The EU's broader general authorisations for humanitarian, legal-fees, and prior-contract exceptions are the clearest examples. However, the EU's ownership-and-control test can capture entities that OFSI's test does not, meaning that in some corporate structures the EU regime produces the harder result at the counterparty-eligibility stage, before any exception analysis begins.
The enforcement posture of the two regimes is also asymmetric. OFSI publishes its monetary penalties policy and its enforcement guidance. It has used its civil penalty power in a range of cases across various sectors. The EU's enforcement is decentralised across member-state competent authorities, which means the practical rigour of exception monitoring varies. A French authority may approach the same exception differently from a Dutch one. That variation is itself a compliance risk for a business operating through multiple EU member states.
For a cross-border business, the answer to "which is stricter?" is less useful than the answer to "in this programme, for this exception category, do the two regimes produce the same result for our specific transaction?" That is the question that generates actionable compliance output.
Risk flags practitioners see most often
We regularly advise businesses that have built their exception analysis on one regime and not the other. The risk flags below represent the patterns we encounter most frequently.
Assumption of automatic carry-over. A business licensed or excepted under the EU regime assumes that the UK position is identical. It is not a safe assumption for any programme issued after January 2021, and it should be verified even for older programmes.
Failure to track amendment cycles. Both OFSI and EU Council exceptions are amended, sometimes at short notice. A general licence that covered a transaction in one quarter may have expired, been modified, or been superseded. Record-keeping and calendar monitoring of exception validity are not optional. OFSI expects businesses to track the current status of any general licence they rely on.
Misapplication of the ownership-and-control test at the counterparty-eligibility stage. An exception that is formally available for a transaction type may be inaccessible because the counterparty itself is treated as a designated entity through ownership or control. The EU and OFSI tests differ in their details. A counterparty that is not caught by the OFSI test may nonetheless be caught by the EU test – or vice versa. Applying only one test and assuming the other produces the same answer is a documented source of compliance failures.
Inadequate records of exception reliance. When OFSI queries a transaction, the first question is what basis the firm relied on and what records it kept. A firm that relied on a general licence but did not retain evidence of its analysis, its counterparty checks, and the relevant licence terms at the time of the transaction will find it difficult to demonstrate legitimate reliance. OFSI's enforcement guidance treats record-keeping as an indicator of the quality of the compliance programme.
Timing errors on prior-contract exceptions. Where a business is relying on a pre-designation contract exception, the window for completing the relevant transaction is defined by the applicable regulations – and it is often shorter than businesses assume. Missing that window converts an excepted transaction into an unlicensed one.
How should a cross-border business structure its exception analysis?
A systematic approach to exception eligibility under both regimes works through four sequential questions for each transaction.
First: is the counterparty itself eligible? This requires applying both the OFSI and the EU ownership-and-control tests to the counterparty's corporate structure. The tests must be run separately; they can produce different results. A counterparty that clears one test must still pass the other for the transaction to be clean across both regimes.
Second: does the transaction fall within the scope of a general licence or general authorisation under each regime? The answer must be derived from the current text of the relevant instrument, not from memory or from a prior transaction's analysis. Both regimes amend their general licences. The current position governs.
Third: have all conditions attached to the exception been satisfied? Conditions include due-diligence requirements, notification obligations, monetary thresholds, and time limits. Satisfying conditions under one regime does not satisfy them under the other. Each regime's conditions must be met independently.
Fourth: are records sufficient to demonstrate legitimate reliance if queried? The answer must be yes for every transaction that relies on an exception rather than a specific licence. Records should include the counterparty screening output, the text of the exception relied on (and its version/date), the analysis of how the transaction meets the conditions, and the names of the individuals who authorised reliance.
In a recent matter, a financial-services firm had relied on an EU general authorisation for a series of fee payments related to a frozen account. The OFSI equivalent for that programme required a specific licence. The firm had not identified the divergence. When OFSI raised a query, the firm faced the dual challenge of explaining the gap and applying retrospectively for a licence that should have been obtained in advance. We assisted in scoping the apparent breach, advising on voluntary self-disclosure, and preparing the regulatory engagement. The matter reinforced a principle we return to repeatedly: exception analysis is regime-specific and fact-specific. It cannot be delegated to a general assumption.
When should a business seek external sanctions counsel?
The short answer: before the transaction closes, not after OFSI or a competent authority makes an enquiry.
External counsel adds most value at three moments. The first is when a business is entering a new market or dealing with a new counterparty in a sensitive programme for the first time. The exception analysis for an established relationship in a well-known programme may be manageable in-house. A new programme, a new counterparty structure, or a new exception category raises the probability that internal assumptions will be wrong.
The second moment is when an amendment cycle is detected. Both OFSI and the EU amend their exceptions, sometimes as part of a broader package of sanctions measures and sometimes as a standalone update. When an amendment touches an exception that a business relies on regularly, a rapid review of the current position is prudent. The cost of that review is a fraction of the cost of an enforcement inquiry.
The third moment is when a transaction has already completed and a subsequent screening hit or a regulatory query suggests that the exception relied on may not have been available. At that point, the question is whether to make a voluntary self-disclosure to OFSI and how to frame the engagement. Early advice at this stage can affect the outcome materially. OFSI's enforcement guidance indicates that it takes account of the quality of a firm's compliance programme and its conduct following a discovery. A well-managed disclosure, presenting full and accurate information, is treated differently from a disclosure made only in response to a regulatory demand.
Do you have a process for detecting when OFSI amends a general licence that your business is actively relying on? If the answer is uncertain, that gap is worth closing before the next transaction closes under that licence.
Cross-border interaction with the US export-control regime
Licence-exception eligibility is not solely a UK–EU question. For businesses trading in dual-use goods or technology, the US Export Administration Regulations (EAR), administered by the Bureau of Industry and Security (BIS), impose a parallel licence-exception regime that operates independently of both OFSI and the EU. A transaction that is excepted under OFSI and covered by an EU general authorisation may still require a specific US export licence if the goods or technology have a US-origin component or if the Export Control Classification Number (ECCN) – the US Commerce Control List classification that determines licence requirements under the EAR – triggers controls.
This interplay matters particularly for businesses that manufacture or trade in items with a dual-use profile. The EAR's extraterritorial reach means that even a UK-to-EU shipment of goods with US-origin technology may engage US licence requirements. The military end-use rules in both the BIS/EAR regime and the EU dual-use framework add a further layer of scrutiny; our analysis of those rules is available at Military End-Use Rules: BIS/EAR vs EU.
For businesses that transfer technology as well as goods – including deemed exports, where controlled technology is released to a foreign national within the exporting country – the BIS/EAR deemed-export rules interact with both OFSI financial-sanctions obligations and EU dual-use controls. A detailed treatment of that interaction is available at Deemed Export and Technology Controls: BIS/EAR.
The SECO regime in Switzerland, which applies its own autonomous sanctions and export-control rules, is a further consideration for businesses routing goods or finance through Swiss entities. The EU–Switzerland relationship on sanctions alignment has its own dynamics, and the exception structures under Swiss law are not assumed to mirror the EU position. Our analysis of the EU–SECO interaction for military end-use rules is at Military End-Use Rules: EU vs SECO.
A business that operates across UK, EU, and US export-control and sanctions regimes simultaneously must run an exception analysis in each of the three regimes for each transaction. A single compliance position does not cover all three. Practitioners who have managed multi-regime export-control matters know that the exemptions which appear to align in drafting often produce different results on specific facts.
Related practices
- Deemed Export and Technology Controls: BIS/EAR – US export licence requirements for technology transfers and deemed exports
- Military End-Use Rules: BIS/EAR vs EU – comparative analysis of US and EU military end-use controls for exporters