A European bank receives a documentary credit request for goods destined for a third-market buyer. The commodity is common. The counterparty is not on any list. Yet three layers up the ownership chain, a blocked entity holds a controlling interest. The letter of credit clears routine screening. The transaction should not proceed.
Trade-finance sanctions controls under EU explained means this: every instrument that facilitates a cross-border trade – letters of credit, guarantees, documentary collections, supply-chain finance – carries a sanctions exposure that standard AML screening does not fully address. The governing authority is the EU Council, acting under its autonomous sanctions regulations and implementing the relevant UN Security Council measures. As of July 2026, EU prohibitions bite on the provision of financing, brokering, and ancillary services, not only on the direct sale or transfer of goods.
This analysis walks through the EU legal basis, the ownership and control test that catches non-listed counterparties, the specific gaps that trade-finance teams consistently miss, the divergence between the EU, OFAC, and OFSI positions, and the risk flags that should trigger a call to counsel.
What is the EU legal basis for trade-finance sanctions controls?
The EU trade-finance prohibitions sit in the relevant Council Regulations, which implement both UN Security Council measures and the EU's autonomous designations. Each regulation covers not only direct transfers but also the making available of funds and economic resources – a phrase broad enough to capture letters of credit, standby guarantees, performance bonds, supply-chain finance arrangements, and commodity-backed lending.
The Council acts through a dual instrument: a Common Position or Decision sets the political objective; the Regulation gives it direct legal effect across all member states. That structure means the prohibition is uniform in text but not always uniform in enforcement. National competent authorities – financial intelligence units, central banks, and sector regulators – apply the rules with varying levels of scrutiny and very different enforcement histories.
A trade-finance desk in Frankfurt and one in Warsaw are operating under identical legal text. But their competent authorities may have different expectations about what a "reasonable steps" defence looks like, how quickly a transaction freeze must be reported, and what documentation constitutes adequate due diligence. In our cross-border practice, that divergence in national implementation is where firms get caught.
The prohibitions extend to any person within the EU, any EU-incorporated or EU-registered legal person wherever they operate, and any transaction conducted in whole or in part through the EU financial system. That last limb is the extraterritorial hook. A non-EU bank clearing a euro-denominated trade through an EU correspondent is caught. So is an EU-parent treasury that books a guarantee on behalf of a non-EU subsidiary.
How does the ownership and control test apply to trade counterparties?
The EU ownership and control test treats a non-listed entity as subject to the same prohibitions as a listed person when it is owned or controlled by a listed person, either directly or indirectly. The test is not purely mechanical: control can arise through shareholding, contractual arrangements, management rights, or the practical ability to direct the entity's conduct.
This is the first major divergence from OFAC's approach. OFAC applies the 50 percent rule (the rule under which any entity owned 50 percent or more in aggregate by one or more blocked persons is itself treated as blocked, regardless of whether it is listed). The threshold is arithmetic and binary. Under the EU regime, a non-listed entity can be caught at below fifty percent ownership if a listed person exercises control through other means – a shareholder agreement, board appointment rights, or veto provisions in a joint-venture contract.
For a trade-finance team, this means ownership screening is necessary but not sufficient. Has the business reviewed the counterparty's governance documents? Has it considered whether a listed person holds a blocking minority, a casting vote, or a right of first refusal that gives practical control? These questions sit outside a standard sanctions-screening tool's logic.
The practical consequence in trade finance is acute. A commodity trader may screen its immediate buyer, confirm no list matches, and proceed. If the buyer is effectively controlled by a listed entity through a management contract – a common structure in certain commodity supply chains – every payment under the resulting documentary credit is a prohibited transaction. The letter of credit issuing bank, the confirming bank, and the advising bank are all potentially liable.
In our experience, the control analysis is the element most consistently deferred until after a transaction is already partially executed. At that point, unwinding the exposure is considerably more complicated than preventing it.
Which specific trade-finance instruments carry the highest EU sanctions exposure?
Letters of credit carry the most structured exposure because every bank in the chain – issuing, confirming, advising, and reimbursing – touches the transaction. A prohibition on financing a sanctioned counterparty applies at each link. An EU bank that advises a letter of credit issued by a non-EU bank in favour of a non-listed buyer may still be providing a financial service that facilitates a prohibited transaction if the underlying goods are subject to a sectoral embargo.
Standby letters of credit and demand guarantees present a subtler risk. The instrument is contingent – it may never be called. EU prohibitions, however, apply to the making available of financial resources, not only their actual transfer. Issuing a standby guarantee in favour of a counterparty associated with a designated entity is itself a prohibited act, even if the guarantee is never drawn.
Supply-chain finance – receivables purchase, approved payables finance, dynamic discounting – is increasingly in scope. Where an EU bank or fintech purchases receivables from a supplier whose ultimate obligor is a sanctioned entity, the purchase monetises a claim against a prohibited party. The fact that the receivable was created before the designation, or that the obligor was not listed at the point of purchase, does not automatically provide a defence. The EU regulations do not generally grandfather pre-existing economic relationships once a designation occurs.
Commodity-backed lending – where the collateral is goods subject to a sectoral embargo, or where the borrower's ability to repay depends on sale proceeds from prohibited trade – is a growing enforcement focus. In a recent matter, a trading business sought our advice after its lender froze a borrowing base facility mid-drawdown. The lender had identified, through an updated ownership review, that a significant portion of the pledged receivables derived from contracts with entities linked to a designated group. We advised the trading business on the statutory freeze obligations, the timeline for making a report to the relevant competent authority, and the licensing position. The matter illustrated precisely why a static sanctions review at facility origination is not sufficient.
Documentary collections sit at the lower end of bank liability but not of commercial risk. The collecting bank does not make a payment commitment; it acts as agent. Yet if it releases documents against payment from a sanctioned account, it has processed a funds transfer in breach of the prohibition. The fact that it was acting as agent does not displace the liability.
Where does the EU position diverge from OFAC and OFSI on trade-finance controls?
Three points of substantive divergence define the multi-regime problem for a cross-border trade-finance participant.
First, the ownership threshold, as noted above. OFAC's 50 percent rule is a bright line. EU and UK OFSI rules extend to control, which has no fixed percentage. A business operating in the EU and with USD-clearing relationships must satisfy both tests – and the stricter prohibition governs. Where OFSI or the EU catches a counterparty on a control analysis that OFAC would not, the EU/UK-regulated entity cannot rely on the OFAC result.
Second, the sectoral embargo structure differs. The EU maintains detailed sectoral restrictions – on specific goods categories, technologies, financial services, and transport – that do not map directly onto OFAC's programme structures. A transaction that clears OFAC's primary-sanctions screen may still fall within an EU goods embargo because the items are listed under the EU's control list and the destination is within the embargo scope. Trade-finance teams that run only one regime check are systematically under-screening.
Third, the EU Blocking Regulation creates a structural tension for EU-based businesses with US counterparties. Where the EU has adopted a position that a particular measure is a prohibited extraterritorial application of a third country's law, an EU person is prohibited from complying with it and must notify the Commission. For a trade-finance bank caught between US secondary-sanctions pressure and the Blocking Regulation, the choice of which obligation to comply with is not straightforward. We regularly advise financial institutions on exactly this tension, and the answer is always fact-specific and regime-specific.
OFSI in the UK operates under the Sanctions and Anti-Money Laundering Act (SAMLA) and its thematic regulations. OFSI has an explicit monetary penalty power and has demonstrated a willingness to use it even where the breach was inadvertent. The UK's ownership and control test broadly parallels the EU's, but the licensing regime and the reporting obligations differ. A business structured with an EU parent, a UK subsidiary, and a US treasury function faces three simultaneous compliance obligations that do not perfectly align.
Does your current trade-finance compliance programme map those divergences, or does it apply a single regime's logic to all three? That is the question a General Counsel should be able to answer before a transaction is approved.
What are the risk flags that businesses consistently miss?
Six patterns appear repeatedly in matters we handle. Each represents a gap between a firm's stated compliance posture and its actual exposure.
The first is static counterparty files. A buyer is screened at onboarding and cleared. The file is not refreshed when designations are updated. Given the pace of EU designation activity – which accelerated significantly in recent years and continues at pace – a counterparty that was clean at contract signature may be caught by a subsequent designation before the letter of credit is presented for payment.
The second is incomplete ownership mapping. Screening tools check listed-name matches. They do not automatically trace beneficial ownership chains or assess control through non-equity mechanisms. The EU's extended prohibition on controlled entities is not operationalised by name-screening alone.
The third is goods classification gaps. Trade-finance teams approve financing for goods described in commercial invoices. They do not always verify whether those goods fall within an EU sectoral embargo or dual-use control. A misdescribed or misclassified cargo can expose the financing bank to liability for facilitating a prohibited transaction even where the counterparty is clean.
The fourth is currency and clearing assumptions. A transaction denominated in euros that clears through the EU financial system is subject to EU jurisdiction, regardless of where the counterparty or the goods are located. Many businesses operate on the assumption that non-EU parties trading non-EU goods are outside EU reach. They are not, once a euro clearing leg is involved.
The fifth is the ancillary-services perimeter. EU prohibitions extend to insurance, re-insurance, transport, and technical assistance, where those services relate to prohibited transactions or designated counterparties. A freight forwarder providing logistics for goods that are themselves lawful may still be providing a service that facilitates a separately prohibited transaction. Trade-finance counsel should be reviewing the full service wrapper, not only the financing instrument.
The sixth is inadequate escalation protocols. When a screening tool generates an alert, what happens next? In our experience, financial institutions with well-designed compliance programmes still have escalation gaps – alerts that are cleared at desk level without legal or senior compliance review, or freezes that are not reported to the competent authority within the applicable statutory window. Both patterns create enforcement exposure.
How does the derogation and licensing regime apply to trade-finance transactions?
EU sanctions regulations typically include derogations – defined categories of transaction that are permitted despite the general prohibition. Common derogations cover humanitarian transactions, diplomatic missions, pre-existing contracts (subject to conditions and time limits), and transactions necessary for the winding down of a relationship with a designated party.
The pre-existing-contract derogation is frequently misapplied in trade finance. It does not provide a general permission to honour letters of credit or guarantees already issued at the time of a designation. It applies to a specific, narrower class of obligations and is subject to conditions – including, in most regimes, notification to or authorisation from the relevant competent authority. A bank that continues to process payments under a pre-existing instrument on the assumption that the derogation automatically applies is taking a legal risk that should be assessed on the specific text of the applicable regulation.
Specific licences are available from national competent authorities in most EU member states for transactions that fall outside the derogation categories but where there is a legitimate reason for authorisation. Licensing timelines vary materially by jurisdiction. The applications process requires a well-constructed factual and legal submission. A poorly framed application that does not address the regulator's likely concerns extends the process and may not succeed. We assist businesses in assessing eligibility for a derogation or a specific licence, preparing the submission, and managing the competent authority's queries.
It is worth noting – because it is often overlooked – that even a licensed transaction carries record-keeping obligations. EU sanctions compliance requires that businesses maintain documentation of the legal basis on which a transaction was conducted, the screening steps taken, any derogation or licence relied upon, and the relevant correspondence with the competent authority. The retention period under most EU regimes is set at five years. A firm that has a licence but no contemporaneous documentation of how it was obtained and applied is in a weaker position in any subsequent enforcement review.
What is the enforcement posture and what triggers a review?
EU sanctions enforcement is decentralised. Each member state's competent authority is responsible for enforcement within its jurisdiction. The European Commission monitors overall consistency but does not directly prosecute. This means enforcement standards, investigation timelines, and penalty levels differ substantially across member states.
In the current environment, financial-sector firms face the highest intensity of review. Correspondent banking, trade finance, and payment processing are explicitly identified in multiple member states' enforcement guidance as priority areas. Regulators are requesting information from banks about their exposure to designated counterparties, their screening systems' logic, and their escalation records. A compliance programme that cannot produce that documentation promptly creates its own enforcement risk.
The triggers for a regulatory review in the trade-finance context include: a suspicious transaction report filed by a correspondent bank; a referral from a customs authority following a goods seizure; intelligence shared by a foreign regulator (including OFAC or OFSI under information-sharing arrangements); and self-identification by the regulated entity following an internal audit. The last category – voluntary self-disclosure (VSD) – is recognised in some EU member states' enforcement guidance as a factor that may reduce penalties. But the credit given for VSD varies and is not guaranteed. Timing matters: a disclosure made promptly before the regulator is independently aware of the issue is treated differently from one made after an investigation has already commenced.
The myth that only direct exporters face trade-finance sanctions enforcement is worth correcting here. Banks, insurers, freight forwarders, and supply-chain finance providers have each faced competent-authority reviews across EU member states in recent periods. The ancillary-services prohibition means that the perimeter of enforcement is not coextensive with the perimeter of direct trade.
The position above covers the legal standard. Your specific facts – the counterparty structure, the goods, the instrument, the clearing currency, and the member state of the relevant competent authority – change the analysis in ways that a general briefing cannot anticipate.
Related practices
- Sanctions compliance audit and testing – structured review of screening logic, escalation protocols, and programme gaps across major regimes
- OFAC versus EU trade-finance controls – a side-by-side analysis of the divergent positions across the two primary regimes
- Trade-finance controls under OFSI – how the UK's financial-sanctions regime applies to documentary credits, guarantees, and supply-chain finance