Calder & Vance International Sanctions & Compliance Counsel

Licensing & Authorizations · OFAC

Choosing between specific and general licences: OFAC and EU compared

A trading company operating between New York and Amsterdam receives a payment instruction from a longstanding counterparty. A routine compliance screen flags the underlying transaction as touching a sanctioned programme. The question lands on the General Counsel's desk within hours: is there a general licence that already permits this, or must the business stop, apply, and wait? The answer is not the same under OFAC and under the EU Council regulations – and the wrong call in either direction carries serious consequences.

Choosing between specific and general licences under OFAC versus the EU turns on fundamentally different legal architectures. Under OFAC, general licences (standing authorisations permitting defined transaction categories without a separate application) are published as part of the programme regulations, and a business may rely on them directly if it meets the stated conditions. Specific licences (case-by-case authorisations issued on application) are required where no general licence applies. The EU operates a parallel structure – Council-regulation derogations function as the equivalent of general licences, while competent-authority authorisations mirror the specific-licence route – but the drafting style, eligibility criteria, and procedural timelines differ in ways that regularly catch cross-border businesses out. As of June 2026, the divergence between the two regimes has grown rather than narrowed, making the choice of route consequential for any business with US and EU exposure simultaneously.

This analysis sets out how each regime structures the choice, where the divergences bite hardest, what the procedural steps look like in practice, and when a business should stop self-assessing and involve sanctions counsel.

How OFAC structures the choice between general and specific licences

OFAC's starting position is that any transaction involving a blocked person or a sanctioned programme is prohibited unless a licence or other authorisation applies. General licences are the primary relief mechanism for categories of activity that OFAC has pre-assessed as low risk or as serving a defined policy purpose – humanitarian trade, certain personal remittances, wind-down periods, or the maintenance of certain accounts. A business that falls squarely within a general licence's scope may proceed without further contact with OFAC.

The critical discipline is reading the general licence precisely. Each one contains scope conditions, exclusions, and often a reporting requirement. In our experience, businesses that mis-read a general licence – typically by treating an exclusion as a carve-out rather than a prohibition – can find themselves in a worse position than if they had applied for a specific licence in the first place, because the apparent reliance on an invalid authorisation can affect how OFAC characterises the subsequent violation.

Where no general licence applies, or where the facts are close to but not clearly inside one, the specific-licence route is the correct path. OFAC receives applications through its secure portal. The process requires the applicant to describe the transaction, the counterparties, the basis for the requested authorisation, and the policy rationale. OFAC's review timelines vary materially by programme and by application volume; the system prompt prohibits invented timelines, so the current position should be verified directly with OFAC or with US sanctions counsel before relying on any published estimate.

What distinguishes the OFAC model is the absence of a statutory right to a licence. OFAC exercises broad discretion. It may deny without explanation, grant with conditions, or request further information. That discretionary character shapes the entire strategy around a specific-licence application: the quality of the policy argument, not merely the legal eligibility, often decides the outcome. This is where experienced licensing counsel adds the most value.

How the EU structures the equivalent choice

The EU's licensing architecture is embedded in the Council regulations that establish each sanctions programme. The regulations contain derogations – provisions permitting otherwise prohibited transactions where specified conditions are met and, in most cases, where the relevant Member State competent authority has granted prior authorisation. These derogations are the functional equivalent of OFAC general licences in the sense that they define the universe of permissible exceptions, but they operate differently.

First, EU derogations are not self-executing in the way OFAC general licences can be. Many require an explicit authorisation from the national competent authority even where the applicant clearly meets the eligibility criteria. The competent authority in each Member State administers the derogation process, which means that a German company and a Dutch company in identical factual positions may face different procedural requirements, different documentation standards, and different timelines. For a business with entities across multiple Member States, this fragmentation is a practical challenge that does not arise under OFAC.

Second, the EU regulations are drafted in a register that is more detailed on eligibility but more compressed on procedure than the OFAC model. The result is that the threshold question – does this transaction fall within a derogation? – is often clearer under EU law than under OFAC, but the procedural question – what must I file, with whom, and by when? – is less standardised. We regularly advise clients that the EU competent-authority application process is operationally more demanding than OFAC's specific-licence process, even when the legal eligibility question is simpler.

Third, the EU lacks a single licensing authority comparable to OFAC. There is no pan-European equivalent of submitting a single application to a single body. For groups with a cross-border transaction touching multiple Member States, coordinating parallel competent-authority applications is a material logistical task.

Where do the two regimes diverge most sharply in practice?

The most consequential divergences cluster around four areas: the self-execution question, the policy-argument requirement, the reporting obligations attached to licences, and the treatment of wind-down and legacy positions.

On self-execution, OFAC general licences can be used directly by any person who meets their terms, without application or notice to OFAC. The EU model, as noted, almost always requires an affirmative competent-authority step even for standard derogations. A business relying on an OFAC general licence for a payment instruction can process the transaction the same day it confirms eligibility. The same business seeking a competent-authority authorisation in an EU Member State will typically wait days to weeks, depending on the authority's practice and workload.

On policy arguments, OFAC's specific-licence process expressly invites the applicant to articulate why authorisation serves US foreign policy or national security interests. The EU competent-authority process is more narrowly eligibility-focused: the question is whether the derogation conditions are met, not whether there is a broader policy case for the transaction. This means that creative or novel licensing arguments – the kind that sometimes succeed under OFAC where the facts are unusual – have less traction in the EU competent-authority process.

On reporting, both regimes attach conditions to licences and authorisations, but the form of those conditions differs. OFAC licences frequently require the licensee to keep records for a defined period and to produce them on request, with the record-keeping obligation running for five years from the date of the transaction in many programmes. EU authorisations impose reporting obligations whose scope and timing are set by the individual competent authority. A cross-border business holding licences from both OFAC and an EU competent authority must track both sets of conditions separately.

On wind-down and legacy positions, OFAC has a long-established practice of issuing wind-down general licences when new designations are announced, giving businesses a defined period – typically measured in days – to close out existing contracts, transactions, and positions. The EU also provides for wind-down through transitional provisions in Council regulations, but the drafting varies by programme and by designation wave. In our practice, the EU wind-down windows have at times been narrower in practice than the published text suggests, because the competent-authority confirmation step consumes part of the available period.

Which regime is stricter on choosing between specific and general licences?

Neither regime is categorically stricter: each is stricter in a different dimension, and the answer depends on what the business is trying to do. For transactional speed, OFAC general licences are permissive in a way the EU derogation model is not – a business can move faster under OFAC where a well-drafted general licence clearly applies. For novel or complex fact patterns where no pre-existing licence covers the situation, the EU derogation structure can be more predictable precisely because it is eligibility-focused: if the conditions are met, the authorisation should follow. OFAC's discretionary specific-licence process is faster when successful but riskier when the outcome is uncertain.

For cross-border businesses, the more important question is not which regime is stricter in the abstract but which regime's licensing position governs a particular transaction. Where a transaction involves US-origin goods, US persons, or US-dollar clearing, OFAC's rules apply regardless of where the parties are incorporated. Where the transaction involves EU-established persons or assets within EU jurisdiction, the relevant Council regulation applies. In many cross-border transactions, both sets of rules apply simultaneously – and the stricter prohibition governs. A licence from one authority does not provide cover under the other.

Have you considered whether your OFAC general-licence reliance addresses your EU exposure, or only half of it? This is one of the most common gaps we see in cross-border compliance programmes.

The procedure in practice: a cross-border decision sequence

For a business managing a transaction that implicates both regimes, the decision sequence runs as follows.

First, determine the nexus. Identify which jurisdictions are engaged by the transaction: the nationality of the parties, the location of the assets, the currency of the payment, the origin of the goods, and the routing of the transaction through clearing systems. Each nexus triggers a separate regime analysis. A transaction can have an OFAC nexus, an EU nexus, and a UK nexus simultaneously.

Second, screen against the applicable lists. Under OFAC, the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) is the primary screening target, together with the relevant programme-specific lists. Under the EU, the applicable consolidated list maintained by the Council is the reference. Under OFSI, the UK list applies. These lists overlap substantially but are not identical; a party may appear on the EU list but not the SDN List, or vice versa.

Third, assess the ownership and control position. Under OFAC, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) extends the prohibition automatically to unlisted entities. Under the EU and OFSI, an ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person) applies – and control can be relevant even where ownership is below the threshold. These tests are not the same, and a business cannot assume that an entity cleared under one regime is cleared under all of them.

Fourth, identify the applicable licence or authorisation. Under OFAC, search the programme regulations for a general licence covering the transaction. If one applies and the conditions are clearly met, document the reliance carefully. If no general licence applies, assess whether a specific-licence application is viable. Under the EU, identify the relevant derogation in the Council regulation. Determine which competent authority has jurisdiction. File the application with the required supporting documentation.

Fifth, manage the pending period. While an OFAC specific-licence application is pending, the underlying transaction remains prohibited unless a general licence or other authorisation covers it. The same position applies under the EU. A business that proceeds with a transaction on the assumption that a pending licence application will succeed is exposed.

Sixth, maintain the record. Once a licence or authorisation is granted, record the terms, comply with the conditions, and retain the documentation for the required period. Under OFAC, the five-year record-keeping expectation applies in many programmes. Under EU authorisations, follow the competent authority's specific requirements.

Risk flags and when to involve sanctions counsel

Several patterns consistently generate licensing risk in cross-border businesses. Recognising them early preserves options that narrow with delay.

The first pattern is over-reliance on a general licence without tracking conditions. A business that processes transactions under a general licence for months without reviewing whether the conditions remain satisfied – or without noticing that OFAC has amended or revoked the licence – has created a course of dealing that may be treated as a series of violations rather than as a single error. In our experience, this pattern arises most often in financial institutions processing high volumes of transactions under a general licence that was carefully reviewed at inception but not re-verified as programmes evolved.

The second pattern is treating an OFAC authorisation as adequate for EU purposes. An OFAC general licence or specific licence provides no cover under the EU Council regulations. Where both regimes apply, both licences must be obtained. Businesses that have cleared the US side of a transaction without addressing the EU side face the full range of EU sanctions consequences for the EU-nexus elements of the transaction.

The third pattern is late application. Both OFAC's specific-licence process and the EU competent-authority process take time. A business that identifies a licensing requirement after a transaction has been partially executed is in a more difficult position than one that identifies the requirement before the transaction begins. Early counsel engagement – at the due-diligence or contract-drafting stage – avoids the penalties-first conversation.

The fourth pattern is the myth that a licence application implies an admission of wrongdoing. It does not. Both OFAC and the EU competent authorities expect businesses to apply for licences when they identify that a proposed transaction falls within a prohibited category. A well-managed application is a sign of a functioning compliance programme, not of prior misconduct. Businesses that delay applications out of concern about what the filing implies frequently find themselves in a far worse position when the transaction eventually comes to a regulator's attention without a licence.

The position above covers the standard analysis. Your facts – the counterparty, the goods, the route, the regime in play, and the specific general licence at issue – change the analysis materially. For an assessment of your licensing position under OFAC or under the applicable EU programme, contact Calder & Vance at info@caldervance.com.

Interaction with export controls and adjacent regimes

The licensing question does not sit in isolation. For transactions involving goods, software, or technology, the export-control licensing regime runs in parallel with the sanctions licensing regime, and the two are legally distinct. Under the US Export Administration Regulations (EAR), administered by BIS, a licence exception (a standing permission to export without a separate BIS authorisation, subject to conditions) may apply even where the goods touch a sanctioned programme, but the licence exception does not override the OFAC prohibition. Both analyses are required. Our colleagues advise on BIS EAR licensing and authorisations including the interaction with frozen account positions that arise when a counterparty's assets are blocked.

For businesses with UK exposure, the OFSI licensing regime operates under the Sanctions and Anti-Money Laundering Act and the relevant thematic regulations, with its own competent-authority process, its own eligibility criteria, and its own reporting obligations. The OFSI model shares some structural features with both the OFAC specific-licence process and the EU competent-authority process, but is not identical to either. A detailed comparison of the OFSI model against non-EU jurisdictions is available in our analysis of OFSI licensing compared with the Australian sanctions regime.

For businesses managing wind-down or legacy positions under both EU and Swiss (SECO) programmes, the interaction between EU derogations and SECO authorisations raises its own set of sequencing questions. Our analysis of wind-down authorisation under the EU compared with SECO addresses that specific cross-regime challenge.

If a transaction has already been flagged, or a filing has been refused or returned for further information, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.

What should a cross-border business do about choosing between specific and general licences?

The practical answer is to treat the general-licence analysis and the specific-licence application process as distinct disciplines, both requiring legal input, rather than as administrative tasks that can be delegated to screening software alone.

For the general-licence analysis, the discipline is precision reading and condition tracking. The text of the general licence or derogation sets the scope. Conditions must be documented at inception and re-verified whenever the programme or the transaction changes. Record-keeping must be organised around the applicable retention period from the outset.

For the specific-licence application, the discipline is preparation and timing. Under OFAC, the application must articulate both the legal eligibility and the policy rationale. Under the EU competent-authority process, the application must demonstrate that the derogation conditions are satisfied and must be submitted to the correct authority with the required supporting documentation. In either case, the application takes time – time that must be planned into the transaction timeline, not treated as a tail-end formality.

A business that builds licensing assessment into its transaction approval process – rather than treating it as a remediation step after the fact – is structurally better positioned than one that relies on post-execution remediation. In our cross-border practice, we assist clients at the transaction stage, not only at the enforcement stage, precisely because the options available before a transaction is executed are substantially broader than those available after it.

Related practices

Frequently asked questions

Where do the regimes diverge on choosing between specific and general licences?
The most significant divergence is the self-execution point. OFAC general licences can be used directly by any person meeting their terms, with no filing required. EU derogations almost always require a prior competent-authority authorisation even when the eligibility criteria are clearly met. Beyond that, OFAC's specific-licence process invites a policy argument; the EU process is more narrowly eligibility-focused. The two regimes also differ on which authority receives applications, on documentation requirements, and on the conditions attached to granted licences. A business with exposure in both jurisdictions must comply with both sets of requirements separately.
Which regime is stricter on choosing between specific and general licences?
Neither is categorically stricter. OFAC general licences permit faster movement where clearly applicable, but OFAC's specific-licence process is discretionary and carries outcome uncertainty. The EU derogation model is more procedurally demanding but somewhat more predictable at the eligibility-assessment stage. For novel or complex transactions, OFAC's willingness to engage on policy arguments can be an advantage; for standard transaction categories, the EU's eligibility-based framework can produce more consistent outcomes. Where both regimes apply simultaneously – which is common in cross-border transactions – the stricter prohibition governs, and a licence from one authority does not substitute for authorisation under the other.
What should a cross-border business do about choosing between specific and general licences?
Three steps matter most. First, determine which regimes are engaged by the transaction before executing, not after. Second, conduct a precise condition-by-condition review of any general licence or derogation on which you propose to rely, and document that review contemporaneously. Third, if a specific licence or competent-authority authorisation is required, build the application timeline into the transaction timeline from the outset. Late applications and post-execution remediation are materially more difficult than pre-transaction licensing. If any element is unclear, involve sanctions counsel at the due-diligence stage.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.