A multinational treasury team processes hundreds of cross-border payments each week. One morning, a routine transfer is flagged: the beneficiary's parent company appears on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The payment is held. The treasury head asks: can this proceed under a licence? How long will it take? And does it matter that the receiving bank is in the EU, where a separate regime governs the same transaction?
Payment authorisations under OFAC and the EU sanctions regime share a common purpose – permitting otherwise prohibited transfers in defined circumstances – but they differ materially on procedure, timing, evidentiary standards, and the role of general versus specific licences. As of May 2026, both regimes require a licence before a blocked payment may lawfully proceed, but the paths to that authorisation, and the risks of getting it wrong, diverge at almost every stage.
This analysis maps those divergences across the full lifecycle of a payment authorisation, identifies the risk flags that compliance teams most frequently miss, and sets out when specialist counsel should be brought in on each side of the Atlantic.
What does a payment authorisation actually authorise?
A payment authorisation permits a transfer of funds that would otherwise be prohibited because a party to the payment – the originator, the beneficiary, or an intermediary – is a blocked person, a designated entity, or a person owned or controlled by one. The authorisation does not alter the underlying designation; it carves out a specific transaction, or a defined category of transactions, from the general prohibition.
Under OFAC, the governing authority is the relevant programme regulations issued under IEEPA or TWEA. A payment involving a blocked person requires either a general licence (a standing authorisation permitting a defined category of transactions without a separate application) or a specific licence (a case-by-case authorisation issued on application). The distinction is critical. General licences cover a significant volume of routine transactions – humanitarian transfers, certain professional fees, overflight payments – and a practitioner's first task is always to determine whether one already covers the facts before filing anything.
Under the EU regime, the equivalent authority is the relevant Council Regulation and its implementing measures. The EU uses the term "authorisation" or, in some programme texts, "derogation". Member State competent authorities – not a single EU-level body – grant individual authorisations, which creates a layer of national variance that has no equivalent in the OFAC structure. The practical consequence: a French entity and a Dutch entity dealing with the same counterparty may face different procedural timelines and documentary standards, even though the underlying Council Regulation is uniform across the bloc.
How does each regime structure the licensing procedure?
Under OFAC, the specific-licence application process follows a well-documented sequence: the applicant submits a written request to OFAC's licensing division, supported by factual background, identification of the blocked party, the proposed transaction, and a statement of the legal basis for relief. OFAC reviews the application against the applicable programme policy, its foreign-policy mandate, and any published licensing policies for that regime. Processing times are not fixed by statute and vary by programme complexity and application volume; in our experience, straightforward payment authorisations in lower-risk programmes can resolve in a matter of weeks, while complex or novel applications under heavily contested programmes take considerably longer.
The EU procedure differs structurally. An applicant submits to the competent authority of the Member State where it is established – or, for certain cross-border matters, to the authority of the Member State with the relevant nexus to the transaction. That authority applies the criteria set out in the relevant Council Regulation: typically, that the funds or resources are necessary for basic needs, legal fees, extraordinary expenses, or a purpose specifically permitted under the programme. The competent authority may consult other Member States or the Commission, particularly for high-value or precedent-setting requests. There is no single EU licensing gateway equivalent to OFAC's licensing portal.
What does this mean operationally? It means that a business with entities in multiple EU Member States should map, at the outset, which authority will handle each application and whether there are national-level procedural rules – filing forms, fee requirements, notarisation standards – that sit alongside the EU-level criteria. We regularly advise clients who have filed in the wrong Member State or under a superseded national template, and the resulting delay can be significant.
Where do the regimes diverge on payment authorisations?
The divergences are structural, not merely procedural, and they affect the probability of success as much as the timeline. Four divergences stand out in cross-border payment work.
First: the single-authority advantage. OFAC operates as a single licensing authority for all US-programme payment authorisations. Whatever the counterparty's location, the application goes to one body applying one set of criteria. The EU's decentralised model means that a payment from a German bank to a blocked party may be handled by the German competent authority under national procedures, while a parallel payment from a Spanish subsidiary goes to the Spanish authority. The substantive test is the same; the process and timeline may not be.
Second: general licences and their EU counterpart. OFAC's general-licence architecture is extensive. Many routine payment categories – maintenance of blocked accounts, transactions ordinarily incident to a personal communication, specific categories of emergency humanitarian payments – are covered without any application. The EU builds equivalent relief into the Council Regulation itself, as a carved-out permitted category, but the scope and drafting vary by programme. A payment that falls within an OFAC general licence may still require an individual authorisation under the EU programme if the EU text does not contain a matching permission. Practitioners must map each regime's relief provisions independently; assuming symmetry is a common and costly error.
Third: the ownership and control test. OFAC's 50 percent rule (treating entities owned 50 percent or more by blocked persons as themselves blocked) applies mechanically, without any control analysis. A payment to an entity that crosses the ownership threshold is blocked regardless of whether the designated person exercises management influence. The EU applies an ownership and control test (the test for whether a non-listed entity is caught through a listed person) that reads more broadly in theory – it can catch entities that are controlled without majority ownership – but its application in practice depends on the specific Council Regulation and the competent authority's approach. In our cross-border practice, we find that the control limb of the EU test is underweighted by financial institutions that have been trained primarily on the OFAC 50 percent standard. A payment that appears clean under OFAC may still be caught under the EU if a designated person exercises decisive influence over the beneficiary without holding a majority stake.
Fourth: blocking versus freezing. OFAC "blocks" property of SDNs, which means assets must be placed in a segregated, interest-bearing account and reported to OFAC. The EU "freezes" funds, which means they cannot be moved but need not be physically segregated in the same way. The practical difference matters for banks holding the payment: US correspondent banks have specific blocking and reporting obligations that do not map one-for-one onto EU freezing requirements. A cross-border payment that is simultaneously blocked under OFAC and frozen under an EU programme creates a dual obligation for any financial institution in the chain.
Which regime is stricter on payment authorisations?
Strictness is the wrong frame; the more useful question is which regime creates more exposure for a given transaction, and the answer depends on the programme, the counterparty, the payment route, and the governing regime for the institution processing the transfer.
OFAC's reach is extraterritorial in a way that the EU's is not. Under secondary-sanctions mechanisms – applicable to the most heavily designated programmes – a non-US financial institution that processes a payment involving a blocked person may find itself exposed to the risk of designation or correspondent-banking restrictions, even if the transaction has no US nexus beyond a dollar-denominated clearing leg. The EU does not operate a secondary-sanctions mechanism in the same structural sense, though the EU Blocking Regulation creates a parallel compliance obligation for EU persons subject to certain listed third-country extraterritorial measures. The result is that for US-dollar payments specifically, OFAC's reach is wider and the risk of inadvertent exposure is higher for institutions outside the US.
The EU regime is, however, stricter in one respect that practitioners sometimes underweight: the prohibition on making funds available. The EU standard prohibits not only the direct transfer of funds to a designated person but also making funds available, directly or indirectly, to or for the benefit of a designated person. The "for the benefit of" limb has been construed broadly by some competent authorities and has caught payment transactions where the ultimate economic benefit – not the nominal beneficiary – accrued to a designated person. In our experience, the beneficial-ownership analysis required to satisfy this standard in an EU context is more granular than what OFAC's SDN-matching alone requires.
The position above covers the standard analytical structure. Your specific facts – the payment currency, the routing banks, the jurisdiction of the payee, and the applicable programme – change the analysis materially.
For a structured review of where your payment flows sit across the OFAC and EU regimes, contact Calder & Vance at info@caldervance.com.
What are the key risk flags in a cross-border payment authorisation?
Risk flags in payment authorisation work tend to cluster around three failure modes: classification errors, process errors, and assumption errors. Each produces a different type of exposure.
Classification errors occur when the paying institution or the applicant misidentifies the legal basis for the payment or the nature of the block. The most common variant is treating a matched name as a conclusive SDN hit without completing the ownership analysis. A payment to a company whose name matches an SDN List entry may in fact be to a different legal entity with no connection to the listed person. Equally, a payment to a company with a clean name may be prohibited because that company is owned 50 percent or more by a blocked person who does not appear on the institution's screening alert. Screening logic that stops at name-matching and does not extend to beneficial-ownership analysis is not adequate for either the OFAC or the EU regime.
Process errors in the licensing phase include filing with the wrong authority (particularly common in EU matters), submitting an incomplete evidentiary package, or failing to address the specific legal criteria the authority is required to apply. OFAC's licensing criteria are set by programme policy and published licensing guidance; the EU criteria are in the Council Regulation itself. An application that reads as a general commercial justification rather than a tailored response to the applicable legal test is likely to be returned for supplement, extending the timeline.
Assumption errors are the most operationally damaging. The most frequent: assuming that an OFAC general licence covers the EU position, or vice versa. It does not. A payment authorised under an OFAC general licence still requires EU authorisation if an EU programme applies. Equally, an EU competent authority's grant of an individual authorisation does not create any OFAC relief. Each regime must be addressed independently, and the relief obtained under one does not satisfy the other.
One further assumption error deserves specific mention: the belief that a correspondent bank's independent compliance check substitutes for the originator's own analysis. A correspondent bank that clears a payment has made its own compliance determination, but that determination does not protect the originator or the beneficiary. The originator's obligations under the applicable regime exist independently of the correspondent's decision to process or block the transfer.
If a transaction has already been flagged, a payment held, or a filing returned incomplete, an early review of the facts and the applicable relief provisions can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss next steps.
How does the UN Consolidated List interact with OFAC and EU payment prohibitions?
The UN Consolidated List (the list maintained by the Security Council committees of persons and entities subject to UN measures) sits beneath both the OFAC and EU regimes as the baseline multilateral layer. Security Council measures adopted under Chapter VII of the UN Charter bind all UN member states; OFAC and EU designations frequently – though not always – mirror UN listings.
For payment authorisation purposes, the UN layer matters in two ways. First, where a person is listed solely on the UN Consolidated List but not on the SDN List or the EU list, the payment prohibition derives from the implementing national legislation of the receiving state, not from OFAC or EU authority directly. Second, the UN regime has its own limited relief mechanism – the Ombudsperson process for the ISIL/Al-Qaida sanctions regime and the Focal Point for de-listing for other UN programmes – and payments to or from persons using those mechanisms may attract specific exemptions under national implementing law. Neither the OFAC nor the EU licensing route addresses UN-level measures independently; the interaction between the layers must be mapped in each case.
Practitioners advising on multi-regime payment authorisations note that the UN layer is frequently treated as subsumed within the OFAC or EU analysis and therefore not separately addressed. Where the UN listing is the source of the prohibition, however – particularly for transactions involving parties in jurisdictions where OFAC and EU measures have no direct extraterritorial effect – the UN-level analysis must be conducted on its own terms.
How should a compliance programme handle simultaneous OFAC and EU payment obligations?
A compliance programme designed to handle payment screening under one regime only will produce gaps when a transaction triggers both. The design requirement for cross-border payment compliance is a dual-track analysis: each payment assessed against the applicable OFAC prohibitions and general licences, and independently assessed against the applicable EU prohibitions and programme-specific relief.
In practice, this requires four structural elements. First, a screening layer that checks against both the SDN List and the EU consolidated list, with separate alert-management workflows for each. Second, a beneficial-ownership workflow that applies the OFAC 50 percent rule and the EU ownership and control test independently, because the same counterparty may fall on one side of the line under OFAC and the other under the EU. Third, a general-licence library that maps, programme by programme, which OFAC general licences and which EU programme-level permissions apply to the firm's typical payment types, updated each time either regime publishes amendments. Fourth, a specific-licence and authorisation request process that documents, for each application, which authority received the application, the legal basis cited, the documents submitted, and the outcome – with five years of record-keeping applied to both sides, consistent with the minimum retention standard applicable under both regimes (verify the current position before relying on this).
Where a firm operates entities in multiple EU Member States, the programme should also map which competent authority holds jurisdiction for each entity's payment activities and maintain a register of that authority's current procedural requirements. National procedural requirements change; a template that worked for a 2024 application to one authority may not satisfy a 2026 application to the same authority if guidance has been updated.
We have acted for financial institutions and multinational corporates designing or stress-testing exactly this dual-track structure. The most common finding is not that the screening logic is wrong but that the beneficial-ownership and control analysis is not operationalised at the payment level – it sits in a counterparty-onboarding process that does not refresh when designations change mid-relationship.
A common misconception about payment authorisations
A persistent misconception in this area is that a payment authorisation, once obtained, is perpetual. It is not. Both OFAC and the EU attach conditions and time limits to specific licences and individual authorisations. An OFAC specific licence is typically issued for a defined period and for a specified transaction or series of transactions; it does not authorise materially different payments without amendment or a fresh application. The EU equivalent is similarly bounded by the terms set by the competent authority.
The practical consequence: a business that obtained a payment authorisation for a particular transaction three years ago and is now processing a similar but not identical payment needs to review whether the existing licence or authorisation covers the new facts. Changes in the counterparty's ownership structure, the payment route, the currency, the amount, or the purpose can all take a new payment outside the scope of an existing authorisation. Assuming coverage without checking is one of the more avoidable causes of inadvertent breach.
A second misconception is that the payment authorisation process is faster than it is. Both OFAC and EU competent authorities operate under workloads that vary significantly with the pace of designations and regulatory change. Applications submitted without complete documentation, or without a clear and specific legal basis, extend the queue. In our experience, a well-prepared application – with the full ownership and control analysis, a mapped transaction diagram, and specific reference to the applicable programme criteria – reaches a determination materially faster than a general narrative request.
Related practices
- Frozen account management under BIS / EAR – structuring access to frozen export-control accounts and managing BIS licensing requirements.
- OFSI vs Australia: Payment authorisations compared – comparative analysis of UK OFSI and Australian DFAT licensing procedures for blocked payments.
- OFSI vs Australia: Payment authorisations compared (Part 2) – extended analysis of enforcement posture and compliance design under the UK and Australian regimes.
Frequently asked questions on OFAC and EU payment authorisations
Where do the regimes diverge on payment authorisations?
The principal divergences are authority structure, the scope of standing permissions, and the ownership test. OFAC operates through a single licensing authority with an extensive general-licence architecture; the EU operates through Member State competent authorities with programme-specific permitted categories. OFAC's ownership test is mechanical at the 50 percent threshold; the EU's test also captures control without majority ownership. A payment that is authorised under one regime may remain prohibited under the other; the two analyses must always be conducted independently.
Which regime is stricter on payment authorisations?
Neither regime is categorically stricter. OFAC's secondary-sanctions exposure makes it more dangerous for non-US financial institutions processing US-dollar payments, because extraterritorial risk can arise even without a US-person nexus. The EU's "for the benefit of" standard and its control test can, in practice, capture a wider range of payment relationships than a name-screening check alone would identify. The answer for any given payment depends on the programme, the counterparty structure, and the payment route.
What should a cross-border business do about payment authorisations?
A cross-border business should first determine which regimes apply to its payment – OFAC if there is a US nexus or a US-dollar leg; the EU programme if an EU-established entity is involved. It should then check available general licences and programme-level permissions before filing any application. If no standing permission covers the payment, it should prepare a specific-licence or individual-authorisation request tailored to the applicable legal criteria, filed with the correct authority, supported by full beneficial-ownership analysis. Specialist counsel should be involved where the ownership structure is complex, where the payment is time-sensitive, or where a prior application has been returned or refused.
About the author
Renata Costa advises banks, payment firms, and virtual-asset businesses on sanctions screening, compliance-programme design, and financial-crime controls. Calder & Vance – International Sanctions & Export Control Counsel.
About Calder & Vance
Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.
Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.