Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · EU

Payment-processing controls under EU: what businesses miss

A payments business operating between the European Union and a third market receives a wire transfer instruction. The beneficiary's name does not appear on any list. The originating bank is clean. Screening passes. The transaction is processed. Three months later, the compliance team learns that an intermediate correspondent bank sits in a jurisdiction subject to EU restrictive measures – and that the payment routed through it constituted a prohibited transaction under the applicable Council regulation. The licence window has closed. The reporting clock has started.

Payment-processing controls under EU sanctions are wider, and technically more demanding, than most businesses assume. The prohibition reaches not just listed counterparties but the routing infrastructure, the currency of settlement, and the correspondent relationships that sit between payer and payee. Control over any part of that chain, if it touches a sanctioned person or a prohibited transaction, can constitute a violation.

This analysis sets out the EU regime in detail, maps where it diverges from OFAC and OFSI, identifies the gaps that generate enforcement exposure, and explains when to involve sanctions counsel. As of July 2026, the EU payment-sanctions perimeter has expanded materially, and compliance programmes built before the most recent round of Council regulations require re-testing.

What does the EU payment-prohibition actually cover?

The EU prohibition on payment processing is asset-freeze and dealing-ban combined: no funds or economic resources may be made available, directly or indirectly, to or for the benefit of a designated person. The phrase "directly or indirectly" is the operative word. It means that a payment which does not touch a listed person's account can still be prohibited if a listed person benefits from it.

The Council regulations define "funds" broadly. The definition covers not only bank balances and electronic transfers but financial instruments, interest, and any other instrument that can be used to obtain funds, goods, or services. A payment processed through a correspondent network, a clearing house, or a payment intermediary that involves a designated entity at any point in the chain falls within scope.

EU persons – meaning any natural person in the EU, any legal person incorporated under the law of an EU member state, and any entity doing business in the EU – are bound by the prohibition regardless of where the transaction settles. A non-EU bank that processes euro-denominated payments through an EU correspondent is equally caught, because the EU correspondent itself is an EU person conducting a prohibited act.

What does that mean operationally? It means that euro clearing alone can generate EU-sanctions exposure for a non-EU institution. In our experience, this is the point that mid-market treasury and payments teams most frequently miss: the currency of settlement, not the nationality of the parties, often determines which regime governs.

How does the EU ownership and control test apply to payment counterparties?

The EU ownership and control test (the EU principle that a non-listed entity is caught by the asset freeze if a listed person owns or controls it) applies to payment counterparties in the same way it applies to any other sanctioned-entity analysis. A company that is not listed but is owned or controlled by a listed person is treated as subject to the freeze under the relevant Council regulation.

Unlike OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked), the EU test is not purely numerical. Ownership of more than 50 percent is one route to capture, but control – the ability to appoint a majority of the board, to direct voting decisions, or to exercise a dominant influence by other means – can capture a company regardless of the ownership percentage. This distinction matters enormously in payment chains where a designated person holds a minority stake but retains effective governance control.

In our cross-border practice, we regularly advise payment firms that have screened the legal owner of an account and found it clean, without asking whether a designated person controls the entity that holds the account. The two analyses are separate. Passing one does not mean passing the other. The EU General Court has addressed control-based arguments in the context of designation challenges; practitioners advising on EU matters note that the concept of control is applied purposively, not narrowly.

The practical consequence for a payment business is a two-stage check: first, is any party to the transaction (including intermediaries) on the EU Consolidated List or any regime-specific list maintained under the applicable Council regulation? Second, is any non-listed party owned or controlled, within the meaning of that regulation, by a listed person? Both questions must be answered before the payment moves.

Where does the EU regime diverge from OFAC on payment-processing controls?

The EU and OFAC regimes share the same underlying objective but differ in scope, mechanics, and enforcement posture in ways that create real compliance traps for businesses operating across both jurisdictions.

The most significant divergence is the ownership and control test. OFAC's 50 percent rule is mechanically clear: aggregate the ownership interests of all blocked persons; if the total reaches or exceeds 50 percent, the entity is blocked, regardless of control dynamics. The EU control test is broader and less determinate. A payment firm that passes the OFAC ownership screen may still fail the EU control analysis. The reverse is rare: an entity captured by the OFAC rule will almost always also be captured by the EU.

Currency jurisdiction is a second point of divergence. OFAC's extraterritorial reach for primary sanctions is limited to US persons and US-nexus transactions; secondary sanctions extend the reach further, but through a different mechanism. The EU regime operates on the basis of person and place, not currency – but euro clearing, as noted above, creates an EU nexus for non-EU institutions that OFAC primary sanctions would not independently generate.

The third divergence concerns general authorisations. OFAC issues general licences (standing authorisations that permit a defined category of transactions without a separate application) covering a wide range of payment-related activity: personal remittances, humanitarian payments, correspondent banking in certain contexts. The EU relies primarily on humanitarian exceptions built into the Council regulations themselves and on member-state competent authority licences – which are issued at the national level. A general licence from OFAC does not authorise a payment that the EU prohibits, and vice versa.

The fourth divergence is enforcement responsibility. OFAC is a single federal authority. EU sanctions enforcement is split across twenty-seven national competent authorities. The consequence for payment processing is that the standard of enforcement and the interpretation of the same Council regulation can vary between member states – though the Commission has taken steps to encourage convergence. For a payment firm with processing nodes in multiple EU jurisdictions, this is not a theoretical concern.

The position above covers the standard comparative case. Your facts – the currencies involved, the ownership chain, the routing, the specific regime in play – change the analysis materially.

For a review of your institution's payment-processing controls and their adequacy under the EU and OFAC regimes, contact Calder & Vance at info@caldervance.com.

What is the OFSI position, and why does it matter for EU-based payment firms?

OFSI – the Office of Financial Sanctions Implementation, which administers UK financial sanctions under the Sanctions and Anti-Money Laundering Act – operates a separate regime that EU-based payment firms must track. Post-exit, the UK Consolidated List and the EU lists have diverged. A person listed by the EU is not automatically listed in the UK, and the reverse is equally true.

For a payment processor with a London correspondent or a UK branch, the OFSI regime runs in parallel with the EU obligations. A payment that is authorised by an EU competent authority under an EU licence does not benefit from that authorisation under OFSI, and an OFSI licence does not authorise what the EU prohibits. Each must be obtained separately.

OFSI uses an ownership and control test. Like the EU, it looks beyond the 50 percent ownership threshold to effective control. Unlike OFAC, OFSI does not publish a consolidated list of entities that are treated as designated by virtue of ownership; the analysis must be performed by the regulated firm on each counterparty.

OFSI also requires reporting: a person who knows or suspects that a counterparty is a designated person, or that they hold funds owned or controlled by a designated person, must report to OFSI as soon as reasonably practicable. For a payment firm, that obligation can be triggered by a transaction that has already been processed – and the reporting duty runs even if no licence was required because the transaction has already settled. In our experience, this post-settlement reporting obligation is consistently underestimated by treasury and payments teams.

What are the risk flags that payment businesses consistently miss?

Five categories of risk account for the majority of the EU payment-sanctions exposure we identify in compliance reviews.

The first is correspondent banking chains. A direct transaction may be clean; the correspondent bank used to settle it may not be. EU persons that process a payment knowing – or having reasonable grounds to know – that it passes through a prohibited entity are exposed. Screening the principal parties is not enough. The routing must be understood.

The second is de-risking gap (de-risking is a financial institution's exit from a relationship to avoid sanctions exposure). When a primary bank de-risks a client, that client moves to a secondary institution. The secondary institution inherits the risk but often does not inherit the diligence file. In our practice, we have acted for payment firms that acquired clients through exactly this route and were unaware of the underlying exposure.

The third is currency-specific exposure. A transaction denominated in a non-sanctioned currency, processed entirely outside the EU, may still require EU sanctions analysis if any party to it is an EU person or if any step in the value chain touches an EU institution.

The fourth is stale ownership data. Ownership structures change. A counterparty that passed screening at onboarding may have acquired a designated shareholder since. Periodic re-screening of payment counterparties – not just at onboarding – is a requirement of an effective control programme under the EU regime.

The fifth is crypto and virtual-asset payment rails. Council regulations governing certain regimes have been extended explicitly to cover virtual assets and virtual-asset service providers. A payment routed through a VASP does not escape the EU prohibition because it is denominated in a digital asset rather than a fiat currency. Compliance counsel advising on payment-controls programmes increasingly encounter this question.

Are your screening systems interrogating correspondent chains? Is your ownership data refreshed on a defined cycle? These two gaps together account for a disproportionate share of EU payment-sanctions exposure.

What does an adequate EU payment-controls programme look like?

An adequate EU payment-controls programme has five structural elements: governance, screening, transaction monitoring, escalation, and record-keeping.

Governance means written policies approved at a senior level that assign responsibility for sanctions compliance, define the scope of the payment-controls perimeter (including currencies, correspondent relationships, and client categories), and set out the escalation path when a potential match is identified.

Screening must cover all parties to the transaction – originator, beneficiary, and intermediaries – against the EU Consolidated List and any regime-specific lists. Automated screening tools must be configured to catch name variants, transliterations, and partial matches. A tool set to exact-match only is inadequate. The EU General Court has made clear, in the context of designation appeals, that the analysis must be substantive rather than formal.

Transaction monitoring looks for patterns that screening cannot catch: unusual routing through high-risk jurisdictions, payment amounts that sit just below reporting thresholds, or counterparty behaviour inconsistent with declared business activity. These are indicators of potential evasion attempts by counterparties – and detecting them protects the payment firm from being used as a conduit.

Escalation procedures define who decides when a potential match cannot be resolved by the first-line team, and how quickly that decision must be made. For time-sensitive payments – correspondent settlements, real-time payments – the escalation clock is short.

Record-keeping is prescribed under the applicable Council regulations. A five-year retention period applies to records of transactions and due-diligence steps. That record is the primary evidence base if an enforcement authority later reviews the transaction.

A programme that has these five elements in place, tested against real transaction data, and reviewed on a defined cycle is materially better placed than one built on documentation alone. If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time.

For a confidential review of a potential breach or an assessment of your payment-controls programme, contact Calder & Vance at info@caldervance.com.

How do SECO, GAC, and DFAT payment-processing obligations interact with the EU regime?

Swiss, Canadian, and Australian sanctions obligations are increasingly relevant to payment processors with cross-border operations, and they do not automatically track the EU position.

Switzerland (SECO) maintains its own sanctions ordinances and its own designated-persons lists. The Swiss payment-processing perimeter is substantively similar to the EU in its asset-freeze and making-available prohibitions, but the Swiss lists have diverged from the EU in certain regimes. A payment firm that is EU-compliant is not automatically SECO-compliant – and for institutions with Swiss-franc clearing relationships, SECO is a primary obligation, not a footnote.

Canada (Global Affairs Canada – GAC) administers the applicable country regime under its autonomous sanctions legislation. Canadian dollar payments and transactions by Canadian persons are subject to the Canadian regime regardless of where the payment processes. Several of the entity-level designations under the Canadian regime differ from their EU equivalents in scope and in the conditions attached to any authorisation.

Australia (DFAT) operates an autonomous sanctions regime that has expanded in recent years. Australian-dollar payments and transactions by Australian entities trigger DFAT obligations independently of the EU. In our experience, businesses with operations in the Asia-Pacific region and EU headquarters frequently do not map the DFAT obligations against their EU controls – and the gap is larger than they expect.

The cross-cutting principle is that the stricter prohibition governs any given transaction. Where the EU prohibits and SECO authorises – or where DFAT restricts and the EU does not – the regulated firm must apply whichever is the more restrictive, unless the licence specifically overrides the more restrictive regime. Counsel advising on multi-regime payment matters routinely construct a waterfall analysis for exactly this reason.

What myths and misconceptions lead payment businesses into EU sanctions exposure?

The most persistent misconception is that passing a screen against the EU Consolidated List is sufficient. It is not. The EU payment prohibition reaches entities that are controlled by, or acting for the benefit of, a listed person – even if the entity itself does not appear on any list. A clean screen result is a starting point, not a conclusion.

The second misconception is that a payment denominated in a non-EU currency, routed through non-EU banks, falls outside the EU regime. As set out above, the regime applies to EU persons. An EU-incorporated payment firm processing a US-dollar transaction between two non-EU counterparties is still subject to the EU prohibition if a listed person is involved.

The third misconception is that an OFAC general licence or an OFSI licence provides cover under the EU regime. It does not. Each regime's authorisations are self-contained. A payment permitted under OFAC requires a separate EU competent-authority licence if the EU prohibition applies.

The fourth misconception is that the EU regime does not apply to virtual-asset payments. Certain Council regulations explicitly extend the prohibition to virtual assets. A VASP incorporated in an EU member state, or operating through EU infrastructure, must apply the same payment-controls analysis to crypto transactions as it does to fiat payments.

We have acted for payment businesses that built their compliance programmes around one of these misconceptions and discovered the gap only when a transaction was queried by a correspondent bank or flagged by an internal audit. In most cases, early counsel engagement – before the transaction rather than after – would have resolved the position at a fraction of the cost.

Related practices

Frequently asked questions: EU payment-processing controls

Where do the regimes diverge on payment-processing controls?

The EU regime diverges from OFAC on four points: the ownership and control test (EU adds a control limb beyond the 50 percent threshold), the currency nexus (euro clearing creates EU exposure regardless of party nationality), the licensing structure (EU licences are member-state issued, not federal), and enforcement fragmentation (twenty-seven national competent authorities apply the same Council regulations with differing intensity). The EU and OFSI regimes have diverged at list level since the UK's departure from the EU; an EU licence does not bind OFSI.

Which regime is stricter on payment-processing controls?

No single regime is consistently stricter. The EU control test captures entities that the OFAC 50 percent rule would not; OFAC's secondary-sanctions reach extends to non-US institutions that EU primary sanctions do not directly bind. The applicable rule is that the stricter prohibition governs each transaction. A payment firm operating across regimes must map each transaction against each applicable regime and apply whichever imposes the more restrictive obligation, unless a specific authorisation provides otherwise.

What should a cross-border business do about payment-processing controls?

A cross-border business should take four steps: first, map every currency and correspondent relationship against the regimes that are engaged; second, configure screening to cover intermediaries and to apply the control test, not only the ownership threshold; third, establish a documented escalation procedure and a record-keeping system with a minimum five-year retention; and fourth, review the programme against recent Council regulations and enforcement guidance on a defined cycle. Where a potential match or a past transaction is in question, involve sanctions counsel before acting further.

About the author

Renata Costa advises banks, payment firms, and virtual-asset businesses on sanctions screening, compliance-programme design, and financial-crime controls. Her practice covers EU, OFAC, and OFSI sanctions obligations, with a particular focus on payment-infrastructure risk, VASP exposure, and cross-border compliance-programme reviews. Calder & Vance – International Sanctions & Export Control Counsel.

About Calder & Vance

Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.

Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.