A payment firm processes thousands of transactions each day across multiple EU member states. Its screening engine flags a counterparty in a third market. The match is fuzzy – a transliterated surname, a variant spelling, an alias from a decade ago. Is this a true hit? Does the EU regime treat the counterparty as blocked? And how does that analysis compare with what OFAC or OFSI would require? The answers are not identical. They may not even be close.
Name and entity screening under EU sanctions law requires financial institutions, corporates, and service providers to check counterparties against the EU Consolidated List maintained by the Council, applying the ownership-and-control test set out in the relevant Council regulations. The EU approach diverges from OFAC's mechanical 50 percent ownership rule and from OFSI's enforcement posture in ways that create genuine compliance risk for cross-border businesses. As of July 2026, those divergences are widening rather than narrowing.
This analysis maps where the EU regime sits on name and entity screening, how it compares with OFAC, OFSI, and selected other regimes, where the risk concentrates, and what a compliance function should have in place before the next transaction cycle.
What does EU name and entity screening actually require?
EU name and entity screening requires persons and entities within the EU's jurisdiction to check that they do not make funds or economic resources available, directly or indirectly, to any person or entity on the EU Consolidated List – and to freeze any assets that are held. The obligation bites on all EU-established entities, their EU branches, and transactions conducted in EU currency or cleared through EU-based infrastructure, regardless of where the counterparty sits. That jurisdictional perimeter is broader than many clients initially assume.
The legal basis is the relevant thematic Council Regulation for each programme – whether that covers financial sanctions targeting a particular sector, a geographic programme, or a cross-cutting thematic list. The Council publishes and updates the Consolidated List centrally. Member states' competent authorities – the national sanctions authorities, working alongside the Council – administer enforcement within their territories. In practice this creates a layered enforcement environment: the obligation is uniform across the EU, but enforcement action can originate from any one of the member-state competent authorities, and their posture and resources differ.
What triggers a screening obligation? The obligation is continuous. It is not satisfied by a one-time check at onboarding. EU practice guidance – consistent with the position of the major member-state competent authorities – requires ongoing monitoring. A counterparty that clears screening today may appear on an updated list within days. In our experience, firms that treat screening as a one-off step at relationship inception carry a materially different risk profile from those that screen against every update cycle.
How does the EU ownership-and-control test differ from OFAC's 50 percent rule?
The EU applies an ownership-and-control test that is deliberately broader than OFAC's purely mechanical threshold. Under OFAC, the rule is straightforward: if blocked persons own, individually or in the aggregate, 50 percent or more of an entity, that entity is itself treated as blocked – full stop. Ownership is the test; control is not a separate limb under OFAC's standard framework.
The EU approach is different in a structurally important way. EU Council regulations extend the freeze obligation to entities owned or controlled by a listed person. Control is an independent ground. An entity in which a listed person holds a minority interest may still be caught if that person exercises control through board appointments, veto rights, contractual arrangements, or de facto economic dominance. The test requires a facts-and-circumstances assessment, not a simple mathematical calculation.
This creates a class of entities – those below the 50 percent ownership threshold but subject to listed-person control – that OFAC would not automatically treat as blocked but that EU law does capture. For a compliance team running the same counterparty through both regimes, the EU result can be more restrictive. The reverse is also possible: OFAC's aggregation mechanic can capture an entity where two listed persons each hold less than 50 percent but together cross the line, even where neither exercises control. Neither regime is uniformly stricter; they diverge by fact pattern.
OFSI in the UK follows a model closer to the EU than to OFAC on this point. UK sanctions law also provides for the control limb alongside ownership. But OFSI's enforcement guidance adds its own interpretive layer – including on the question of what constitutes "making available" – and that guidance is not identical to EU practice. Where a transaction touches all three regimes simultaneously, the compliance answer for each must be reasoned independently. Assuming that a clean OFAC analysis settles the EU question is one of the most persistent mistakes we see in cross-border practice.
Where do EU screening divergences create the most acute risk?
The sharpest divergence risks for EU name and entity screening cluster around four practical areas: transliteration and alias coverage, the legal-entity boundary question, the treatment of non-EU nationals and entities, and the update-cycle lag.
Transliteration and alias coverage. The EU Consolidated List includes aliases and transliteration variants, but coverage is not exhaustive. Cyrillic, Arabic, Chinese, and other script variants may appear in different forms depending on the transliteration standard used at the time of listing or by the submitting member state. A screening engine tuned to exact or near-exact matching against Western-script primary names will miss a listed person operating under a transliterated variant that sits in the alias field. How does your screening logic handle scripts that were not the primary language of listing?
Date-of-birth and nationality matching introduce a further layer of ambiguity. Two individuals sharing a common name from the same region, with similar birth years, generate a high volume of false positives. Over-tuning to reduce false positives risks suppressing a genuine hit. Under-tuning creates alert fatigue and the same practical outcome. In our experience, calibration of fuzzy-match thresholds is where the most compliance resource is consumed and where the most errors occur.
Legal-entity boundary. The control limb of the EU test means that the screening function cannot stop at the counterparty's registered name and its direct shareholders. Analysts must trace the ownership structure upward to identify any listed person with a stake, and then apply the control assessment to each intermediate vehicle. A special-purpose vehicle created by a listed person's trust structures, a nominee-held holding company, or a management-controlled fund may sit within the EU's reach even where no listed name appears in the corporate registry.
Non-EU nationals and third-country entities. The EU programme catches EU-established entities transacting anywhere in the world, and EU persons transacting anywhere. It also catches any person within EU territory. That means a transaction between two non-EU parties, if cleared in euros or processed through an EU-based correspondent, comes within scope. The implication for payment institutions and trade-finance banks is that their EU nexus – even a single clearing bank – extends the EU screening obligation globally across the transaction book.
Update-cycle lag. The EU Consolidated List is updated without a fixed notice period. A listing can take effect as soon as it is published in the Official Journal of the European Union. Firms that download the list on a daily or weekly batch basis carry an exposure window for transactions processed after a listing is made but before the firm's next refresh. Real-time or intraday API-based list connectivity materially reduces that window.
How does the EU approach compare with OFAC, OFSI, and other major regimes?
The comparison across regimes is not a simple hierarchy. It is a map of overlapping obligations that can produce different outcomes on the same counterparty.
OFAC administers its sanctions through the SDN List, the Consolidated Sanctions List, the Non-SDN Menu-Based Sanctions List, and several programme-specific lists. The lists are distinct; a counterparty may appear on one but not another, and the relevant prohibitions differ accordingly. EU screening, by contrast, draws on the single Consolidated List – though the prohibitions that attach to a given listed person depend on which programme they are listed under, so practitioners must still trace through to the programme regulation.
A meaningful structural difference: OFAC's licensing regime operates through specific and general licences, and OFAC maintains an active published library of general licences. The EU does not operate a general-licence regime in the OFAC sense. EU member-state competent authorities can issue derogations under the relevant regulation, and certain humanitarian and personal-funds exceptions are built into the regulations themselves, but there is no standing EU equivalent to OFAC's published general-licence inventory. For a business that has managed OFAC exposure through a general licence, the EU position must be assessed separately.
OFSI sits closer to the EU in structure – a single competent authority, a specific-licence model, and both ownership and control limbs – but OFSI's enforcement philosophy has its own character. OFSI has a monetary-penalty power and has demonstrated a willingness to use it. Importantly, OFSI does not require proof of intent to impose a civil monetary penalty; the test is whether the person had reasonable cause to suspect that they were dealing with a designated person. That is a different evidentiary standard from the EU's approach and from OFAC's strict-liability civil-penalty model.
For Singapore and Japan, both of which have autonomous sanctions regimes aligned broadly with the UN Consolidated List but with their own listing decisions and domestic enforcement infrastructure, the screening obligation is narrower in scope but must still be addressed by businesses with operations or correspondent relationships in those markets. A business that clears EU and OFAC screening but has a Singapore correspondent should not assume that clears the Singapore side. In our practice, multi-regime clients increasingly run parallel screening workflows rather than relying on a single engine's global coverage.
The golden rule in cross-border screening: where two regimes produce different results on the same counterparty, the stricter prohibition governs conduct within that regime's reach. There is no blended answer.
What are the most common screening programme deficiencies under EU review?
Compliance programmes are rarely wrong in their headline intent. The deficiencies tend to be operational and architectural – and they are the ones that regulators find first.
First: list coverage gaps. Some commercial screening engines do not cover all EU programme lists equally. A tool calibrated primarily for OFAC and the UN may carry thinner coverage of EU programme-specific lists, particularly for newer programmes or thematic lists added in a recent update cycle. Firms should verify their vendor's coverage map and update frequency, and not assume that a commercially licensed tool is complete for EU purposes.
Second: the scope of the screened population. The obligation extends to the counterparty, its beneficial owners above applicable thresholds, directors and key controllers, and – in the context of the EU control test – any person exercising de facto control. A screening programme that checks only the named counterparty and direct shareholders is under-inclusive. This is a particularly common gap in firms that have built their screening function around anti-money-laundering customer due diligence standards, where the beneficial-ownership threshold applies and the control question is handled differently.
Third: escalation and decision governance. When a potential match is identified, the escalation path matters. Who has authority to clear a match? What documentation must support a clearance decision? How quickly must a decision be made, and what interim steps should be taken for a transaction in flight? These are questions of governance design, not technology. We regularly advise clients whose technology infrastructure is sound but whose escalation processes are undocumented or inconsistently applied. A regulator reviewing an enforcement file looks at both.
Fourth: record-keeping. EU regulations require adequate records of the steps taken to comply. Records of screening searches, match-review decisions, escalation outcomes, and any submission to a competent authority must be retained for a period sufficient to satisfy a regulator's enquiry. Relying on system logs that are automatically purged after a short cycle is a documentary risk.
When should a cross-border business involve external sanctions counsel on screening?
The decision to involve external counsel is most valuable at three points: programme design, a potential-hit escalation, and an apparent breach.
At programme design, counsel can map the firm's jurisdictional exposure across regimes, define the screened-entity population, specify coverage requirements for the selected screening tool, and design governance and escalation procedures calibrated to the EU and any additional regimes in scope. This is the least expensive intervention and the most preventive. In a recent matter, a logistics business expanding into EU clearing sought our advice before go-live. We mapped the screening obligation to its new euro-clearing correspondent, identified a gap in beneficial-owner screening for its existing customer book, and re-scoped the workflow. The work was complete before the first transaction processed.
At a potential-hit escalation, counsel assists with the legal analysis of whether the match represents a genuine designation hit under the applicable EU regulation, what the ownership-and-control analysis produces for any intermediate entities, whether a derogation or exception applies, and what steps the firm should take with the transaction pending resolution. This is time-sensitive work. A transaction in flight cannot wait days for a response.
At an apparent breach – where a transaction has proceeded and there is reason to believe it involved a designated person – the analysis turns on the facts, the applicable regime's enforcement posture, and whether a voluntary disclosure to the relevant competent authority is appropriate. Early advice at this stage materially affects the options available. Options narrow with time.
The position above covers the standard case. Your facts – the counterparty structure, the currency of settlement, the EU programmes potentially in play, the jurisdictions of your group entities – change the analysis materially.
For a confidential review of your screening programme or a specific potential-hit question, contact Calder & Vance at info@caldervance.com.
A persistent myth: OFAC clearance clears the EU position
A widely held assumption in cross-border compliance teams is that if a counterparty clears OFAC screening – particularly if OFAC has issued a specific licence for the transaction – the EU screening obligation is also satisfied. This is not correct, and acting on that assumption has produced enforcement exposure for clients we have subsequently advised.
The EU Consolidated List and the OFAC SDN List are maintained independently. The listing criteria differ. A person delisted by OFAC is not automatically delisted by the EU, and vice versa. An OFAC general licence covering a category of transactions has no EU equivalent and confers no EU authorisation. Where a transaction touches both regimes, each must be assessed under its own list, its own ownership-and-control test, and its own derogation or licensing process. There is no mutual recognition between them.
The same logic applies to OFSI. A UK general licence does not authorise an EU transaction. An EU derogation does not extend to OFAC-regulated conduct. Businesses operating across all three regimes need three independent analyses for the same counterparty, not one analysis multiplied across the others.
We regularly advise multinationals whose global compliance teams have consolidated screening into a single workflow optimised for OFAC. The EU and UK tails of that workflow are underweight. Bringing them into balance is not a theoretical exercise; it is the difference between a compliant programme and one that creates exposure every time a transaction touches an EU entity or a euro clearing route.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact info@caldervance.com.
Related practices
Related practices
- Sanctions compliance audit and testing – stress-testing screening logic, ownership-mapping, and programme governance against live regime requirements
- Name and entity screening under Japanese sanctions – how Japan's autonomous regime compares with the EU and UN Consolidated List obligations
- OFAC versus EU screening: a comparative analysis – a side-by-side treatment of list architecture, ownership tests, and licensing divergences
Frequently asked questions on name and entity screening under EU
Where do the regimes diverge on name and entity screening?
The EU and OFAC diverge most sharply on the ownership-and-control test. OFAC's rule is triggered mechanically at 50 percent or more aggregate ownership by blocked persons; control is not a separate limb. The EU regime captures entities owned or controlled by a listed person, making the control assessment an independent and fact-intensive inquiry. OFSI follows a similar dual limb. On list architecture, OFAC operates multiple programme-specific lists; the EU operates a single Consolidated List but with programme-dependent prohibitions. These differences mean the same counterparty can produce different screening outcomes depending on which regime applies.
Which regime is stricter on name and entity screening?
No single regime is uniformly stricter; they diverge by fact pattern. The EU control limb can capture entities that OFAC's ownership rule misses. OFAC's aggregation mechanic can capture entities that the EU ownership test alone would not. OFSI imposes civil penalties without requiring proof of intent, which creates a different risk profile from the EU enforcement model. For a cross-border business, the operative rule is that the stricter prohibition governs conduct within each regime's reach – so the practical answer is to satisfy the most demanding applicable standard on each element of the analysis.
What should a cross-border business do about name and entity screening?
A cross-border business should first map its jurisdictional exposure: which regimes apply by virtue of its entity structure, currencies settled, clearing routes used, and the nationalities of its counterparties. It should then verify that its screening tool covers all relevant lists with an appropriate update frequency, that the screened population includes beneficial owners and controllers, and that escalation governance is documented. Where the business has significant EU exposure alongside OFAC and UK obligations, the three workflows should be tested independently. External counsel can assist with programme design, hit-escalation analysis, and breach assessment.
About the author
Renata Costa advises banks, payment firms, and virtual-asset businesses on sanctions screening, compliance-programme design, and financial-crime controls. Her work covers the architecture of cross-regime screening programmes, beneficial-ownership analysis, and the governance of escalation and hit-resolution workflows. Calder & Vance – International Sanctions & Export Control Counsel.
About Calder & Vance
Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.
Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.