Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · EU

Counterparty due diligence under EU: what businesses must know

A trading business in the Netherlands signs a distribution agreement with a company headquartered outside the EU. The counterparty looks clean on initial screening. A compliance officer then traces the ownership chain one layer deeper and finds a listed individual holding a controlling stake in an intermediate holding vehicle. The deal is already signed. Does EU law treat the distributor as a restricted party? Can payments flow? These are not hypothetical questions. They arise weekly in cross-border commercial practice.

Under the EU sanctions regime, a non-listed entity may be caught by the relevant Council Regulation if a designated person owns or controls it – either through an ownership threshold or through other means of control that give a listed person effective authority over the entity's decisions. The test is broader than a simple percentage trigger, and as of July 2026 the EU has issued clarifying guidance that tightens how firms are expected to document their analysis. Failure to identify the exposure leaves the business open to enforcement action across every EU Member State.

This guide walks through the EU counterparty due diligence process step by step, identifies the points where businesses most often make errors, and explains when the analysis diverges from the OFAC and OFSI approaches. It draws on our cross-border practice advising importers, exporters, and financial institutions on EU sanctions risk.

What governs counterparty due diligence under EU sanctions?

EU counterparty due diligence is governed by the relevant Council Regulation applicable to the sanctions programme in question, supplemented by the corresponding Council Decision and, where relevant, European Commission implementing guidance. There is no single codified EU due diligence statute. Instead, obligations flow from the asset-freeze and dealing-prohibition provisions contained in each thematic regulation – covering sectors, designated individuals, and listed entities alike.

The administering authority at the EU level is the Council of the EU, which adopts and amends the designation lists. Enforcement, however, falls to each Member State. This creates a material practical point: the same transaction, involving the same counterparty, may be investigated by different national authorities in different Member States simultaneously. A business operating in Germany, France, and the Netherlands faces three enforcement authorities, not one, and each applies the same Council Regulation but through its own national procedural rules.

The Consolidated List of Persons, Groups and Entities Subject to EU Financial Sanctions (the EU Consolidated List) is maintained by the European Commission and updated on the day that a new Council Regulation enters into force. Screening against this list is the baseline. It is not, however, the end of the analysis – because the ownership and control test means that unlisted entities may also be caught.

In our cross-border practice, we regularly advise businesses that have screened against the EU Consolidated List, found no match, and concluded that their counterparty is clear. That conclusion is premature unless the ownership structure has also been examined.

Step 1: Identify who you are dealing with and what the trigger is

The first step in EU counterparty due diligence is to define the legal entity or individual you are proposing to deal with and to establish whether any EU sanctions programme is capable of applying to that relationship at all. Not every counterparty triggers an EU sanctions analysis of equal depth. The applicable programme depends on the counterparty's nationality, domicile, sector, and the nature of the transaction.

Start with four questions. First, is this counterparty a natural person, a legal entity, or an unincorporated arrangement? Each carries a different documentation requirement. Second, in which jurisdiction is the entity incorporated or registered, and where does it actually operate? Third, what goods, services, or funds are being transferred? Fourth, is the transaction itself within the territorial or personal scope of the applicable Council Regulation?

EU sanctions have a broad jurisdictional reach. They apply to EU persons and entities wherever they are located. They apply to transactions conducted in whole or in part within EU territory. They also apply to any action taken by a person on board an EU-flagged vessel or aircraft. Where a non-EU parent company processes a transaction through a European subsidiary, the EU regime applies to the subsidiary's conduct regardless of where the parent sits.

Once the trigger is confirmed, the compliance officer should document the applicable regulation by name and confirm the current version of the relevant sanctions list. Lists are amended frequently. A snapshot taken three weeks ago may not reflect a designation added last week.

Step 2: Screen the counterparty against the EU Consolidated List and sector restrictions

Screening against the EU Consolidated List is the first substantive check, but it must be paired with a review of any sector-specific prohibitions in the applicable programme. Two distinct categories of restriction operate simultaneously: named-person designations and category-based prohibitions that apply regardless of whether a specific entity is listed.

For named-person screening, the search must cover the legal entity name, any known trading names or former names, registration numbers, and the names of key individuals – directors, ultimate beneficial owners, and authorised signatories. A transliteration issue or a spelling variant is enough to produce a missed match in an automated screen. Human review of near-matches is therefore part of the process, not an optional extra.

Sector restrictions present a different challenge. Some EU programmes prohibit the provision of specified services – financial, legal, technical – to broad categories of counterparty defined by nationality or sector affiliation, not by designation status. A counterparty that does not appear on the EU Consolidated List may still be subject to a service prohibition. The compliance officer must check both tracks independently.

Where any match or potential match is returned, the correct response is to halt the transaction and seek legal advice before proceeding. Continuing while a potential match is under review creates enforcement risk. Have you confirmed that your screening tool covers both name matches and sector prohibitions – or only the list?

Step 3: Trace ownership and apply the control test

The ownership and control test under EU sanctions determines whether a non-listed entity is nonetheless subject to the asset-freeze provisions because a designated person owns or controls it. This is the step where most due diligence failures occur.

The EU test has two limbs. The ownership limb asks whether a designated person, directly or indirectly, holds a sufficient ownership interest in the entity. The applicable regulations do not always specify a precise percentage for all programmes in identical terms; the question is whether the designated person holds an ownership interest that gives effective participation in or control over the entity. In practice, EU guidance and Member State enforcement experience treat a 50 percent or more threshold as a clear indicator, but lower stakes combined with other control factors can also engage the provision. The second limb asks whether a designated person controls the entity through any other means – board seats, veto rights, contractual arrangements, or other mechanisms of effective authority – even without majority ownership.

This dual-limb structure means the EU test is analytically wider than OFAC's mechanical 50 percent rule, and it requires judgment rather than arithmetic. A counterparty where a designated person holds, say, 35 percent but also has the contractual right to appoint the majority of the board may well be caught under the control limb, even though it would not be automatically blocked under the OFAC ownership rule.

In our experience, the documents required to complete this step include: the entity's current articles of association or equivalent constitutional document; a current shareholder register; a disclosure of any shareholders' or voting agreements; the register of ultimate beneficial owners in the relevant jurisdiction; and any known contractual arrangements that confer governance rights. Where the counterparty is in a jurisdiction with limited corporate transparency, enhanced source-of-funds and beneficial-ownership enquiries are necessary.

The analysis must go up the ownership chain until it reaches natural persons. Intermediate holding companies and trust structures do not interrupt the analysis. If a listed individual holds 60 percent of a Cayman Islands holding vehicle that in turn holds 55 percent of the EU counterparty, the counterparty is caught under the ownership limb, regardless of the intermediate layer.

Step 4: Assess sector prohibitions, goods classifications, and dual-use considerations

Beyond the named-party and ownership analysis, EU counterparty due diligence must address whether the proposed transaction involves goods, technology, or services that are independently restricted under EU law. This step is often treated as belonging to export-control compliance rather than sanctions due diligence, but the two overlap significantly in current EU programmes.

EU dual-use export controls, governed by the applicable EU regulation on dual-use items, require exporters to determine whether the goods or technology fall within a listed category and whether an export authorisation is required for the destination. A counterparty that is not itself sanctioned may still be subject to a licensing requirement because of the nature of the goods or the end use.

The EU has also introduced sector-specific restrictions – in energy, transport, technology, and financial services – within certain sanctions programmes. These restrictions may prohibit the provision of specified services to broad classes of counterparty in the relevant sector, regardless of whether any individual on the counterparty's side appears on the EU Consolidated List. The due diligence process must therefore map the proposed transaction against the service prohibitions in the applicable programme, not only against the designation list.

Where there is genuine uncertainty about whether a restriction applies, the correct step is to obtain a legal opinion before committing. Proceeding on the basis that the restriction "probably" does not apply is not a defence under the applicable Council Regulation.

The position above covers the standard analytical path. Your transaction – the specific goods involved, the counterparty's sector, the route of the payment, and the programme in play – may require a different or deeper analysis. To discuss the specifics of a cross-border transaction, contact Calder & Vance at info@caldervance.com.

Step 5: Document the analysis and maintain records

Documentation is not a procedural formality. It is the primary evidence that a business exercised due diligence and, if a question later arises, that the conclusion it reached was reasonable on the information available. EU enforcement authorities examine documentation when assessing whether a breach was inadvertent and whether cooperation warrants a reduction in any penalty.

A complete due diligence file for a single counterparty relationship should contain: the date and scope of each screening run; the version of the EU Consolidated List consulted; the name-variation search terms used; the ownership and control analysis with source documents; a record of any legal advice obtained; and the sign-off by the responsible compliance officer or legal counsel. Where a transaction recurs over time – a standing supply agreement, for example – the file should record periodic rescreening dates, not just the initial check.

Five years is the record-keeping period that prudent compliance programmes apply for EU sanctions documentation, reflecting the general limitation periods applicable in most Member State enforcement systems and aligning with the record-keeping standards imposed by anti-money laundering rules to which many EU-regulated entities are also subject. Verify the current period required by the applicable national regime before relying on this figure.

The documentation standard also matters for internal purposes. When a compliance officer changes roles, when a deal is revisited months later, or when a regulator issues an information request, a well-maintained file means the organisation can demonstrate what it did and why. A scattered email thread does not serve the same purpose.

How does the EU approach differ from OFAC and OFSI?

The EU ownership and control test is structurally broader than the OFAC rule and operationally closer to the OFSI test, but with important differences that matter in practice. Understanding those differences is essential for any business operating across multiple regimes simultaneously.

Under OFAC, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked) is mechanical. If the arithmetic reaches 50 percent, the entity is blocked. Below 50 percent, OFAC does not automatically block the entity through ownership alone, though separate control questions may arise. The rule is applied by aggregating the interests of all blocked persons who hold a stake, regardless of whether they act together.

The OFSI test under UK sanctions law uses both an ownership threshold and a control test, similar in structure to the EU. However, OFSI guidance and the relevant UK thematic regulations set out specific factors to consider in the control analysis, and the UK has its own licensing and reporting obligations that differ from those under EU law. A business that has completed EU due diligence on a counterparty cannot assume that the same analysis satisfies OFSI.

One divergence with immediate practical consequences: the EU regime's sector prohibitions are often wider in scope than the equivalent OFAC programme restrictions. A transaction that OFAC does not prohibit because the counterparty is not a blocked person may still be prohibited under the applicable EU Council Regulation because of a sector service ban. Running both analyses in parallel is the only reliable approach for businesses with EU and US exposure.

For businesses also subject to other regimes – Canada's SEMA, Australia's autonomous sanctions, or Singapore's applicable national instrument – additional checks apply. In general, where two or more regimes cover the same transaction, the stricter prohibition governs the business's conduct in the relevant jurisdiction. Our cross-border practice regularly advises clients on multi-regime alignment to avoid compliance gaps at the seams.

If a transaction has already been flagged under one regime, or if a filing has been refused or queried, an early legal review can preserve options that close quickly. Contact Calder & Vance at info@caldervance.com for a confidential assessment.

Risk flags and when to involve sanctions counsel

Certain transaction features should trigger enhanced due diligence and, in most cases, early involvement of external sanctions counsel. These are not exhaustive. They are the patterns we see most often in the matters that reach us after a compliance team has already made a decision it later questions.

The first flag is ownership complexity. Where the counterparty's ultimate beneficial owner cannot be identified through publicly available sources, or where the ownership chain passes through multiple jurisdictions with limited corporate disclosure, the standard screening process is insufficient. Enhanced beneficial-ownership enquiries and, where available, regulatory-register checks are required before the transaction proceeds.

The second flag is a near-match on screening. Where an automated screen returns a potential hit – a name match or a partial identifier match – that the compliance team assesses as a false positive, the decision to clear the match should be documented with a clear rationale and reviewed by a senior compliance officer or legal counsel. The cost of clearing a match incorrectly is significantly higher than the cost of a short delay for review.

The third flag is a counterparty in a sector that has been specifically targeted by the applicable EU programme. Where the Council Regulation in question includes service prohibitions aimed at the counterparty's industry, the due diligence cannot stop at name screening. The transactional analysis must address whether the proposed activity falls within the prohibiting language of the regulation.

The fourth flag is a change in the counterparty's ownership or control structure during a long-term contract. EU designations are applied to listed persons, and if a listed person acquires a controlling interest in a counterparty after the contract is signed, the position changes. Periodic rescreening of counterparties in long-term relationships is a necessary control, not a luxury.

The fifth flag – and the one most commonly underestimated – is a payment route that passes through a jurisdiction subject to a separate EU sectoral prohibition. Even where the counterparty itself is not restricted, a payment cleared through a restricted correspondent bank, or a service provided through an intermediary in a programme-covered sector, may engage the prohibition.

Where any of these flags is present, involving sanctions counsel before the transaction is completed is the correct step. The question is not whether the analysis is hard. The question is whether the consequences of getting it wrong – enforcement action, asset freezes, reputational damage – outweigh the cost of a proper review.

Related practices

Frequently asked questions

What are the steps to run counterparty due diligence under EU?
EU counterparty due diligence requires five sequential steps: identifying the applicable EU sanctions programme and confirming jurisdictional scope; screening the counterparty name and key individuals against the EU Consolidated List; tracing the full ownership and control chain to assess whether any designated person owns or controls the entity; checking applicable sector prohibitions and dual-use restrictions; and documenting the entire analysis with dated records. Each step requires separate documentation, and the process must be repeated when ownership changes or when the EU designation list is updated.
What is the most common mistake in counterparty due diligence?
The most common mistake is treating a clear result on the EU Consolidated List name screen as the conclusion of the due diligence process. It is the beginning. The ownership and control test means that a non-listed entity can still be caught by EU sanctions if a designated person owns it at or above the applicable threshold, or controls it through other means. Businesses that skip the ownership-chain step are exposed even when their automated screening tool returns a clean result.
How does EU differ from other regimes here?
The EU regime combines a named-person designation list with a dual-limb ownership-and-control test and sector-based service prohibitions. OFAC's rule is more mechanical – the 50 percent aggregate ownership threshold is the trigger, without a separate control limb of equivalent breadth. OFSI uses a similar dual-limb structure to the EU but differs in the specific factors cited in its guidance and in the UK's licensing and reporting obligations. Where a transaction is subject to both EU and OFAC rules, each analysis must be run independently; a clear result under one regime does not satisfy the other.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.