Calder & Vance International Sanctions & Compliance Counsel

Licensing & Authorizations · OFAC

OFAC vs EU: Choosing between specific and general licences compared

A trading company structured across the United States and the European Union signs a term sheet with a distributor whose ultimate parent sits close to a restricted counterparty network. Legal and compliance want to proceed but recognise that the transaction may be prohibited without prior authorisation. The question becomes urgent: is a general licence (a standing authorisation that permits a defined category of transactions without a separate application) already available, or must the business apply for a specific licence (a case-by-case authorisation issued after review of the particular facts)? Getting that choice wrong wastes months and exposes the firm to liability regardless of intent.

Choosing between specific and general licences under OFAC and the EU regime involves a structured two-stage analysis: first, whether an existing general licence covers the proposed activity; second, if it does not, whether the facts support a specific-licence application under the applicable standard. The two regimes share the general architecture but diverge sharply on scope, conditionality, and the burden placed on the applicant. As of June 2026, cross-border businesses operating between US and EU jurisdictions face a meaningfully different compliance posture under each system, and a choice that satisfies OFAC may still leave EU obligations unmet.

This analysis sets out how each regime handles the distinction between general and specific licences, where the regimes converge and where they pull apart, the practical decision sequence for a cross-border business, the risk flags that counsel most often sees in practice, and when to involve specialist advice before a transaction proceeds.

How do OFAC and the EU structure the general-licence mechanism?

Under OFAC, general licences are issued by the Office of Foreign Assets Control under IEEPA or the relevant statutory authority, and they authorise a defined class of transactions that would otherwise be prohibited without requiring individual prior approval from the agency. The general licence is self-executing: the party relying on it need only confirm that its facts fit within the stated conditions. OFAC publishes general licences as part of its programme regulations, and they are subject to amendment or revocation. Conditions are frequently specific: they may limit the counterparty category, the goods or services covered, the dollar threshold, or the purpose of the transaction.

The EU operates through Council regulations that may include direct authorisations or that empower competent authorities in each member state to issue authorisations. What the EU regime calls a "derogation" or a standing authorisation is structurally similar to an OFAC general licence, but the EU layer of national competent authority implementation adds a layer of interpretive variation. A derogation that one competent authority reads broadly may be read narrowly in another jurisdiction. In our cross-border practice, we regularly encounter businesses that have cleared reliance on the EU authorisation with counsel in one member state, only to discover that a second member state's authority takes a different position on the same instrument. That divergence has direct consequences for groups with operations spread across the single market.

Both regimes share the principle that where a general licence or standing authorisation applies, it should be used: a specific-licence application for activity already covered by a general licence will typically be redirected or refused. The threshold question – does a general licence exist, and do the facts fit squarely within its conditions – is therefore the first analytical step every time.

What conditions must be satisfied before relying on a general licence?

Reliance on a general licence under OFAC is not passive. The party using the general licence must independently verify that each condition is met, must maintain records sufficient to demonstrate ongoing eligibility throughout the duration of the activity, and must be prepared to produce those records on request. OFAC expects businesses to conduct their own legal analysis; the agency does not pre-approve reliance. OFAC does operate a specific-inquiry process through which a business may request a formal statement of the agency's view, but this process is distinct from a licence application and does not itself authorise a transaction.

The conditions that most often create compliance risk include: the counterparty category (does the person receiving the benefit of the transaction qualify?), the purpose restriction (is the stated end-use the only permitted purpose, or does the general licence extend to incidental benefits?), and the geographic or programme-specific carve-out (does the general licence apply across the entire OFAC programme, or only to certain designations within it?). In our experience, errors in the third category – assuming programme-wide coverage when the general licence is designation-specific – account for a disproportionate share of voluntary self-disclosure cases that our practice handles.

Under the EU regime, the conditions precedent to relying on a standing derogation differ in two important respects. First, certain EU measures require prior notification to the relevant competent authority before the authorised activity can begin. This is not a licensing step, but it creates a procedural burden that OFAC's self-executing model does not impose. Second, the EU framework sometimes layers reporting obligations on top of the initial authorisation: a business that proceeds under a standing derogation may be required to report the transaction after the fact, within a defined window. Where OFAC would require record retention, the EU equivalent may require active reporting to the supervising authority.

What is the practical implication? A business choosing between specific and general licences under OFAC can often move quickly if the general licence conditions are met and the internal analysis is documented. The EU counterpart may require an additional procedural step, a notification or report, that must be calendared and tracked. Failing to complete that step can convert an initially compliant transaction into a reportable breach.

When is a specific-licence application the right route?

A specific-licence application under OFAC is appropriate when no general licence covers the proposed activity, when the facts fit within OFAC's published licensing policy for the relevant programme, and when the applicant can articulate a compelling policy ground for the authorisation sought. OFAC maintains published licensing policies for its major programmes, and those policies signal the grounds on which OFAC is most likely to grant. Applications that fall outside the published policy face a higher bar and longer review.

Under the EU regime, the equivalent of a specific licence is an individual authorisation issued by the competent authority. The substantive test varies by instrument and programme, but the structural requirement is similar: the applicant must demonstrate that the activity serves a purpose that the authorisation provision is designed to permit, and that no standing derogation already covers the facts. The EU General Court has addressed the standard of review applicable to these decisions, confirming that competent authorities exercise a degree of discretion but are subject to proportionality review. Applicants who receive a refusal have judicial-review routes available, including the possibility of challenging an underlying designation if that is what blocks the authorisation.

Is the EU route faster or slower? In our experience, timelines for individual authorisations vary considerably across member states. Some competent authorities operate well-resourced licensing teams and issue decisions within weeks; others may take several months. OFAC's specific-licence process operates on timelines that the agency does not publish as binding commitments, and the complexity of the application – its policy sensitivity, the number of parties involved, and the documentation burden – drives the actual time to decision. For an urgent commercial matter, neither regime reliably offers a short-form pathway once a specific application is required. This is precisely why the general-licence analysis must be conducted thoroughly before an application is lodged.

The position above covers the standard case. Your facts – the counterparty structure, the goods or services involved, the programme in play, and the jurisdictions of the parties – change the analysis. For an assessment of your exposure under OFAC or the applicable EU Council regulation, contact Calder & Vance at info@caldervance.com.

How do OFAC and EU standards for specific licences diverge?

The OFAC specific-licence standard is built around licensing policy: published guidance, embedded in each programme's regulations, that identifies the categories of transaction for which OFAC will ordinarily consider granting a specific licence. The standard is not a right; OFAC retains full discretion. But the published policy functions as a practical roadmap. Applicants whose request falls within a stated policy category can build a case by matching their facts to the criteria. Those outside the stated categories must argue for an exception or a novel policy rationale, which is a heavier lift.

The EU standard, by contrast, is framed around the purpose of the derogation in the underlying Council regulation. The authorisation provision will typically enumerate the permitted purposes – humanitarian, personal remittance, diplomatic, judicial, etc. – and the competent authority will assess whether the applicant's proposed activity genuinely serves that purpose. The EU approach tends to be textually narrower in form: the enumerated purposes set a ceiling on what can be authorised. OFAC's licensing policy, being a policy document rather than a legislative text, can in principle evolve more quickly through agency guidance.

A further divergence arises from the treatment of secondary-sanctions risk. An EU authorisation does not resolve OFAC exposure. A business with a US nexus – dollar clearing, US-person involvement, goods of US origin – that relies on an EU individual authorisation must separately confirm OFAC authorisation or satisfy itself that no OFAC programme is triggered. The reverse is equally true: an OFAC general licence does not satisfy EU obligations. In a cross-border transaction involving both jurisdictions, both analyses must run in parallel, and the stricter prohibition governs the overall permissibility of the activity.

Can an applicant challenge a specific-licence refusal? Under OFAC, the primary options are reconsideration within the agency or, in appropriate cases, a judicial-review claim in a US federal court. Under the EU regime, a refusal of an individual authorisation can be challenged before national administrative or judicial bodies, and where the underlying designation is the root cause, an annulment action before the EU General Court may be the more effective route. The judicial routes are different, the timelines are different, and the grounds available to an applicant are different. Choosing the right review route – and preparing for it from the outset of the licensing process – is a material part of the legal strategy.

What are the record-keeping and compliance obligations after a licence is obtained?

Obtaining a general or specific licence is the beginning of the compliance obligation, not the end. Under OFAC, licence holders are required to keep records of all transactions authorised under a licence. OFAC's regulations set a five-year record-retention period, and those records must be available for production on request by the agency. Specific licences typically carry their own conditions – reporting requirements, permitted-purpose limitations, end-user controls, expiry dates – and each condition is a distinct compliance obligation that must be tracked and managed.

Under the EU regime, record-keeping requirements are set at the programme level and vary between instruments. The common expectation is that a business relying on a derogation or an individual authorisation maintains documentation sufficient to demonstrate the basis on which it proceeded and the conditions it satisfied. Where prior notification or post-transaction reporting is required, the records of those communications must be preserved separately. In our experience, EU competent authorities conducting compliance reviews look first at the notification and reporting trail; a business that can produce contemporaneous records of each step stands in a markedly stronger position than one that has reconstructed the record after the fact.

Specific licences under either regime may also carry end-use or end-user monitoring obligations. Where the licence authorises the provision of goods, technology, or services, the licence holder may be required to obtain end-user certificates, conduct periodic checks on the permitted use of the licensed activity, and report anomalies. These obligations are particularly common in licences touching dual-use goods or technology – goods that have both civilian and potential other applications – where the export-control and sanctions regimes overlap. In those situations, the obligations under the EAR (BIS), the EU dual-use instrument, and the applicable sanctions programme all run concurrently, and a breach of the licence conditions in any one system can trigger parallel investigations in the others.

What risk flags arise most often in choosing between the two routes?

Six patterns generate the largest share of licensing errors that we see in practice.

First, assuming a general licence continues to apply after the conditions have changed. General licences are frequently amended, narrowed, or revoked. A business that relied on a general licence six months ago should re-verify current eligibility before conducting a new transaction, even in the same counterparty relationship.

Second, treating an OFAC general licence as authority for EU purposes (or vice versa). Each regime operates independently. Cross-reliance is not permissible and not a recognised defence in either jurisdiction.

Third, failing to document the legal analysis that supported reliance on a general licence at the time of the transaction. If a transaction later comes under scrutiny, the absence of contemporaneous analysis is read as an absence of compliance intent. OFAC and EU competent authorities both treat documented, good-faith analysis as a mitigating factor in enforcement proceedings; the absence of that documentation removes the mitigation.

Fourth, submitting a specific-licence application that duplicates activity already covered by a general licence. This does not cause a prohibition, but it signals to the agency that the applicant has not conducted a thorough pre-application analysis, which can colour the agency's view of the applicant's overall compliance posture.

Fifth, failing to identify that a counterparty relationship has changed since the licence was originally assessed. Ownership structures shift. A licence that was accurate as to the counterparty at the date of issue may no longer be accurate if the counterparty has been acquired, restructured, or if new designations have been added affecting its ownership chain. Periodic re-screening against the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and the EU Consolidated List is not a one-time exercise; it must continue throughout the licence period.

Sixth, treating the licensing question in isolation from the broader export-control position. If the transaction involves goods, technology, or software that may have dual-use classification, the licensing analysis under the sanctions programme must be run alongside the EAR export-licence analysis and, for EU-nexus transactions, the EU dual-use authorisation analysis. Failing to integrate these two regulatory streams produces authorisations that are incomplete on their face.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review of your position.

The practical decision sequence for a cross-border business

In practice, a structured decision sequence produces the cleanest outcome and the strongest documentary record. The following steps reflect how we approach a licensing question for clients operating across both the OFAC and EU systems.

Step one: Screen the counterparty, the ownership chain, and all other relevant parties against the applicable lists – the SDN List, the EU Consolidated List, and the UN Security Council Consolidated List – at the time the transaction is first proposed. Apply the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) to the full ownership chain, including indirect holdings through intermediate companies. Under the EU, apply the ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person), which extends to control relationships that fall below the ownership threshold.

Step two: Determine whether a prohibition is engaged. If no list match and no programme-specific prohibition applies, document that conclusion and proceed. If a prohibition is engaged, proceed to step three.

Step three: Identify all potentially applicable general licences or standing derogations under each regime in play. Map the conditions of each general licence against the specific facts of the transaction: counterparty category, purpose, goods or services, monetary value, and any programme-specific carve-outs. Where a general licence fits squarely, document the analysis and note any reporting or notification obligations that must be discharged.

Step four: If no general licence applies, assess whether the proposed activity falls within OFAC's published licensing policy for the programme, or within the enumerated purposes of the applicable EU derogation provision. If it does, prepare the specific-licence application. If it does not, the transaction may not be licensable and the business should consider whether to restructure the transaction or abandon it.

Step five: Regardless of the route taken, establish a monitoring schedule. Re-screen counterparties periodically. Track licence expiry and condition-compliance obligations. Maintain records in a retrievable format for the applicable retention period – five years under OFAC regulations.

Situation A: the general licence covers the transaction and conditions are met – use the general licence, document the analysis, discharge any reporting obligations, and monitor through the licence period. Risk profile: low, provided documentation is contemporaneous and complete.

Situation B: the general licence does not apply and a specific licence is required within published policy – apply to OFAC or the competent authority, anticipate a processing period that is likely to extend over multiple weeks and potentially months, prepare conditions-compliance documentation in advance. Risk profile: medium; timeline uncertainty is the primary commercial risk.

Situation C: the specific-licence application falls outside published policy – assess structural alternatives (counterparty substitution, restructuring the transaction, phased approach to reduce the prohibited element). Counsel involvement is essential at this stage. Risk profile: high if the transaction proceeds without authorisation.

For further analysis on the interaction between sanctions licensing and BIS/EAR export authorisations, see our related practice page on frozen account management and BIS/EAR service considerations. For a deeper comparative analysis of specific and general licensing across additional regimes, see our extended OFAC vs EU licensing analysis and our OFSI vs Australia licensing comparison.

A common misconception: the myth of the "safer" specific-licence route

A persistent misconception among in-house teams encountering this question for the first time is that applying for a specific licence is the conservative, lower-risk choice when a general licence exists but the fit is imperfect. The reasoning, stated explicitly, goes: "If we apply for a specific licence, we are at least on the record with the agency, and that protects us while we wait." This reasoning is wrong in two important respects.

First, submitting a specific-licence application does not authorise the transaction. The prohibitions remain fully in force while the application is pending. A business that proceeds with a transaction on the assumption that the application is "protective" is conducting a prohibited transaction and accumulating liability with each passing day. The application does not stay the prohibition. OFAC is explicit on this point, and EU competent authorities apply the same principle.

Second, an application that duplicates activity already covered by a general licence may invite agency scrutiny of the applicant's general compliance posture. If the agency review reveals that the general licence was available all along, the applicant may face follow-up questions about why it did not identify the general licence – which opens examination of the overall screening and compliance programme.

The correct conservative position is the reverse of the misconception: conduct a thorough general-licence analysis first; if a general licence applies, use it and document the analysis; if it does not, assess specific-licence eligibility and, in the meantime, halt the transaction or structure around the prohibited element. We regularly advise clients that the cost of the legal analysis up front is a fraction of the cost of a voluntary self-disclosure or an enforcement investigation later.

Related practices

Frequently asked questions

Where do the regimes diverge on choosing between specific and general licences?
OFAC and the EU diverge on three principal points. OFAC's general licences are self-executing and require only internal analysis and record-keeping; EU standing derogations often require prior notification or post-transaction reporting to the competent authority. OFAC's specific-licence standard is built around published licensing policy, which guides but does not bind the agency; the EU standard is textually constrained by the enumerated purposes in the Council regulation. Finally, the review routes after a refusal differ: OFAC reconsideration is administrative, while EU refusals may be challenged before national courts or, where the underlying designation is in issue, before the EU General Court.
Which regime is stricter on choosing between specific and general licences?
Neither regime is uniformly stricter: each is stricter in different respects. OFAC's self-executing general licences offer speed and flexibility where the conditions fit, but OFAC's secondary-sanctions reach means that a non-US party may still face OFAC exposure even when operating entirely under EU authorisation. The EU's enumerated-purpose approach creates a narrower textual ceiling on what can be authorised by derogation, and the variation in interpretation across member-state competent authorities adds operational uncertainty. In any cross-border transaction, the analysis must run under both regimes, and the stricter result governs the permissibility of the activity.
What should a cross-border business do about choosing between specific and general licences?
A cross-border business should follow a structured five-step sequence: screen fully at the outset applying the 50 percent rule and the ownership-and-control test; determine whether a prohibition is engaged; map all potentially applicable general licences against the specific transaction facts under each relevant regime; assess specific-licence eligibility only where no general licence applies; and establish ongoing monitoring, record-keeping, and reporting obligations across the full licence period. Where the transaction straddles OFAC and EU regimes, both analyses must proceed in parallel. Specialist sanctions counsel should be engaged before an application is submitted, not after a refusal is received.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.