Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · EU

Compliance audit and testing under EU: what businesses must know

A mid-size trading company completes its annual internal review and concludes that its sanctions compliance programme is working well. Six months later, the European Commission opens an inquiry. The company's screening tool had not been updated to reflect a Council regulation amendment issued three months prior, and a counterparty active in a restricted sector had slipped through. The audit said "pass." The regulator said otherwise.

Under EU sanctions law, a compliance audit is not a box-ticking exercise. It is a structured, evidence-based review of whether a business's controls – screening, ownership-and-control analysis, transaction monitoring, and reporting – match the obligations imposed by the relevant Council regulations as currently in force. As of July 2026, those obligations are enforced at Member State level, but the legal framework is uniform across the EU; a gap in one Member State's enforcement posture does not reduce the underlying legal risk for a cross-border business.

This guide walks through the audit and testing process step by step: the governing authority, the structure of an EU compliance audit, how to test individual controls, the cross-border dimensions that most internal audits overlook, and the risk flags that should trigger external counsel.

Step 1 – Understand the governing regime and who enforces it

EU sanctions compliance obligations derive from Council regulations that apply directly and uniformly across all Member States, without transposition. The European Council adopts the measures; Member State competent authorities enforce them at the national level. Audit readiness therefore means satisfying not one regulator but the competent authority of every Member State in which the business operates, holds assets, or routes transactions.

This structure matters for audit design. A business headquartered in one Member State but with subsidiaries in two others faces the enforcement postures of three national authorities. In our experience, businesses that treat EU sanctions as a single, monolithic obligation often under-prepare for the subsidiary-level review that follows a group-wide audit finding. The relevant Council regulation is the legal anchor; the competent authority of each Member State is the enforcement counterpart.

The EU General Court and the Court of Justice of the European Union provide the appellate layer for designation challenges. For the compliance audit, however, the practical counterpart is the national authority. Businesses should identify their primary competent authority before the audit begins and understand that authority's published guidance and enforcement priorities.

A cross-border business should also note that EU obligations interact with those of OFSI in the United Kingdom and OFAC in the United States. Where a group entity is subject to all three regimes, the audit scope must reflect each. The stricter prohibition governs. That principle is not just a legal truism – it is a practical audit instruction: always test against the most restrictive applicable standard.

Step 2 – Map the obligations before you measure compliance with them

An EU compliance audit cannot proceed until the team has produced a current and accurate obligations map: every prohibition, asset-freeze requirement, reporting duty, and licensing condition that applies to the business as of the audit date. This is not a one-time task. Council regulations are amended frequently, and designation lists are updated without predictable schedules.

The obligations map should address four categories. First, asset-freeze prohibitions: which listed persons and entities are relevant to the business's counterparty universe, and does the business hold or control any funds or economic resources belonging to them? Second, the ownership and control test (the EU rule that a non-listed entity is captured where a listed person owns or controls it, even below a mechanical ownership threshold): has the business mapped the ownership chains of material counterparties beyond the first layer? Third, sector-specific restrictions: do any of the applicable Council regulations prohibit services, goods, or transactions in sectors relevant to the business, regardless of whether a specific listed person is involved? Fourth, reporting and record-keeping obligations: does the business know what it must report to its competent authority, within what timeframe, and how?

The obligation-mapping exercise is also where the cross-regime comparison must be built in. EU sanctions law does not apply a mechanical 50 percent or more ownership threshold in the same way OFAC does. The EU ownership and control test is broader: control can be established through contractual means, governance rights, or economic dependence, even where the listed person holds less than a majority equity interest. In our cross-border practice, this divergence is the single most common source of audit gaps when a business has relied on an OFAC-calibrated screening tool to satisfy its EU obligations.

Step 3 – Test your screening controls against the EU standard

Screening control testing is the operational core of a compliance audit. The test objective is straightforward: can the business's screening tool reliably detect listed persons and entities, including those captured by the EU ownership and control test, against the current EU Consolidated List and the lists maintained under each relevant Council regulation?

Effective testing goes beyond running a sample of counterparty names against the list. A well-structured screening test covers at least four dimensions. Name-matching quality: does the tool detect common transliterations, name variations, and aliases? List currency: is the tool updated promptly when the relevant lists are amended, and how long does that update take? Ownership-chain depth: does the tool flag entities owned or controlled by listed persons through intermediate holding structures, or does it stop at the first corporate layer? False-negative rate: when a known-listed person is run through the tool under a variant name, does the tool catch it?

The position above covers the standard case. Your facts – the counterparty universe, the sectors in which the business operates, the jurisdictions of incorporation of the relevant counterparties – change the analysis materially. Where a business operates in sectors subject to broad sector-specific restrictions under a Council regulation, name-matching alone is insufficient. The audit must also test whether the business has controls to identify restricted transactions that do not involve a specifically listed person.

For businesses that have not recently tested their screening controls against the EU standard specifically, this is worth doing before a competent authority does it for you. Contact Calder & Vance at info@caldervance.com for a structured screening-control review.

Step 4 – Audit the ownership-and-control analysis process

The EU ownership and control test is the area where most compliance audit findings surface, in our experience. The test requires a business to look beyond the named counterparty to the persons who own or control it. A listed person with a forty percent stake, combined with contractual veto rights over material business decisions, may satisfy the control limb of the test even without a majority ownership interest.

Auditing the ownership-and-control process means asking two questions at each stage. First, what information does the business actually collect about the ownership and control of its counterparties? Second, what does the business do with that information once it is collected? The audit should trace a sample of counterparties from the initial onboarding data through to the compliance conclusion, checking whether the analysis reached the right answer and whether it was documented adequately.

Documentation is not a bureaucratic nicety. A business that correctly identifies no listing risk but cannot demonstrate how it reached that conclusion is vulnerable in an enforcement context. The EU framework does not prescribe the exact format of the analysis, but a competent authority reviewing a transaction will expect to see a reasoned, contemporaneous record. The audit should test whether such records exist and whether they are retrievable.

Ownership structures change after onboarding. The audit must also assess whether the business has a trigger mechanism for re-reviewing counterparties when a material ownership change occurs, or when a new designation is issued that might affect a previously cleared counterparty. Periodic re-screening against an updated list is necessary but not sufficient: it must be paired with a process for re-assessing control where the ownership picture has changed.

Step 5 – Review transaction monitoring and reporting obligations

EU Council regulations impose reporting obligations on persons who hold or identify blocked funds or economic resources. The obligation is not merely to freeze; it is also to notify the competent authority. The audit must assess whether the business's transaction-monitoring process is capable of identifying a potential blocking obligation promptly, and whether the reporting pathway to the competent authority is clear and tested.

The timeframe for reporting is set by the applicable Council regulation and the guidance of the relevant competent authority. It varies across Member States and across programmes. The audit should confirm the specific obligation that applies in each Member State where the business operates and verify that the business's internal escalation process is calibrated to meet the shortest applicable window.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. For a confidential assessment of your reporting position, contact us at info@caldervance.com.

Transaction monitoring under the EU regime also has a cross-border dimension that audit teams frequently overlook. An EU-established business that provides services to a non-EU entity may still be subject to EU restrictions if those services relate to a listed person or a restricted sector. The territorial scope of each Council regulation is a distinct audit question, and it should be addressed explicitly in the obligations map produced in Step 2.

How does the EU compliance audit differ from the OFAC and OFSI approaches?

EU compliance auditing differs from the OFAC five-element standard and the OFSI approach in three material respects: the ownership-and-control test, the enforcement architecture, and the licensing route.

On the ownership and control test, the EU applies a broader, qualitative standard than OFAC's mechanical 50 percent or more ownership rule. Under the EU test, a business must assess control through multiple lenses – equity ownership, voting rights, contractual mechanisms, and economic dependence. OFSI's test is similarly broad. A compliance audit designed around the OFAC threshold will not satisfy the EU or OFSI standard. This is the most common structural gap we identify when a business presents us with an audit report that was designed for OFAC and asks us to confirm it covers EU obligations.

On enforcement architecture, OFAC is a single federal regulator. In the EU, each Member State has its own competent authority. A group audit must therefore assess the adequacy of controls in each Member State jurisdiction, not merely at group level. The adequacy of the group-level control may not translate to adequacy at the subsidiary level if the subsidiary faces sector-specific obligations or operates in a jurisdiction with a more active enforcement posture.

On licensing, the EU specific-licence route (a specific licence, being a case-by-case authorisation from the relevant competent authority to conduct an otherwise prohibited transaction) differs in procedure and timeline from OFAC's and OFSI's licensing processes. The audit should confirm that the business knows which competent authority to approach for a specific licence, what information that authority requires, and what the applicable processing timeline is. Refer to our detailed guidance on EU licensing procedures for businesses under Council regulations for the step-by-step process.

Common risk flags and when to involve external counsel

Certain findings in a compliance audit indicate that the risk has moved beyond an internal remediation task. These are the risk flags that should trigger an external counsel review.

First, a potential past breach: if the audit identifies a transaction that may have involved a listed person or blocked funds, and that transaction has already settled, the business faces a potential reporting obligation and a possible enforcement exposure. The appropriate response is not to treat it as an audit finding to be closed internally. It is to assess, with the benefit of legal privilege, whether a voluntary disclosure is required, advisable, or available.

Second, a deficient screening tool: if the audit reveals that the screening tool has not been updated to reflect a Council regulation amendment for any material period, the business needs to assess how many transactions passed through the tool during that period and whether any involved a person or entity designated during the gap. This is a data-intensive exercise that benefits from legal structuring.

Third, an ownership-and-control finding: if the audit reveals that a counterparty may be owned or controlled by a listed person, and a transaction has already occurred, the analysis of the blocking obligation and the reporting duty requires qualified legal input.

Fourth, a pending competent-authority inquiry: if a Member State competent authority has made a request for information or opened a formal inquiry, the business should involve external counsel immediately. The response to a competent authority inquiry is not an operational matter; it is a legal one, and the framing of the response can determine the trajectory of the matter.

We regularly advise businesses at each of these stages. Our work typically covers scoping the apparent issue, advising on voluntary disclosure, preparing the response to the competent authority, and designing the remediated programme.

The myth that a compliance audit is a formality deserves direct correction here. Some businesses assume that a clean internal audit effectively closes off enforcement risk. It does not. A competent authority is not bound by the conclusions of an internal audit. What a well-designed, well-documented internal audit does is demonstrate that the business took its obligations seriously, identified its own gaps, and addressed them. That demonstration has real value in an enforcement context – but only if the audit genuinely tested the controls, not merely confirmed that they exist on paper.

For a structured review of your EU compliance audit programme, we work with clients across a range of entry points. We also assist businesses operating across multiple regimes, including those subject to the Australian Autonomous Sanctions regime; our compliance audit and testing service for Australian-regime obligations covers the equivalent steps under that framework. For a broader EU-specific review, our further guidance at EU compliance audit: sector-specific considerations addresses the additional obligations that apply in particular industries.

Related practices

Frequently asked questions

What are the steps to audit and test a compliance programme under EU?
An EU compliance audit follows five structured phases: mapping current obligations under the relevant Council regulations; testing screening controls against the EU Consolidated List and relevant programme lists; auditing the ownership-and-control analysis process; reviewing transaction-monitoring and reporting procedures; and documenting findings with a remediation plan. Each phase should be completed before the next begins, because gaps in the obligations map will produce misleading results in the control-testing phase. External verification is advisable where a potential breach is identified at any stage.
What is the most common mistake in compliance audit and testing?
The most common mistake is calibrating the audit to an OFAC ownership threshold – the mechanical fifty-percent rule – rather than to the broader EU ownership and control test. The EU standard captures control through contractual, governance, and economic means, not merely equity ownership. A business that passes a fifty-percent ownership screen may still be dealing with a counterparty that is subject to EU asset-freeze obligations through a control relationship. This gap consistently appears in audit reports prepared by teams trained primarily on OFAC or OFSI requirements.
How does EU differ from other regimes here?
The EU regime differs from OFAC and OFSI in three respects that directly affect audit design. First, the ownership and control test is broader and more qualitative than OFAC's mechanical threshold. Second, enforcement is decentralised across Member State competent authorities, requiring a subsidiary-level audit review rather than a single group-wide assessment. Third, licensing applications must be directed to the national competent authority of the relevant Member State, not to a single federal body. Each difference requires a distinct audit control and a distinct testing methodology.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.