A payment firm operating a virtual-asset exchange platform discovers, mid-onboarding, that a wallet address links to a counterparty whose ultimate beneficial owner appears on the EU Consolidated List. The transaction is paused. The compliance team asks: does the EU ownership-and-control test capture this entity? Is the wallet itself a "fund or economic resource"? Does a reporting obligation now run? These questions land fast, and the answers are not always intuitive.
As of July 2026, virtual-asset service providers (VASPs – firms that exchange, transfer, or custody crypto-assets on behalf of clients) are subject to EU financial sanctions in the same way as traditional financial institutions. The applicable Council regulations prohibit making funds or economic resources available to, or for the benefit of, designated persons. Crypto-assets are treated as funds or economic resources for this purpose. The ownership-and-control test (the EU rule that catches entities owned or controlled by a listed person, even if the entity itself is not designated) applies to wallet structures, corporate vehicles, and decentralised arrangements alike.
This guide walks through the compliance obligations step by step, compares the EU position with OFAC and OFSI, flags the points where VASPs most frequently mis-step, and explains when specialist counsel adds the most value.
Step 1: Understand who the EU rules bind – and what "funds" means for crypto
EU financial-sanctions regulations bind any person or entity within EU territory, any EU-incorporated or EU-registered entity operating abroad, and any person conducting business in euros – regardless of where they are physically located. For VASPs, the territorial reach is broad. A non-EU VASP routing a euro-denominated transaction, or using EU correspondent banking, can fall within scope.
The term "funds" in the applicable Council regulations is defined widely. It covers financial assets and benefits of every kind, including electronic money. Practitioners advising on EU matters confirm that the definition has consistently been read to include crypto-assets. "Economic resources" – a separate category – covers assets that may be used to obtain funds, goods, or services. An illiquid token can therefore qualify as an economic resource even if it has no readily realisable market value.
What does this mean operationally? A VASP that credits a wallet, processes a transfer, or releases a staked position involving a designated person's assets is potentially making funds or economic resources available. The prohibition runs even where the VASP has no commercial motive and acts purely as an intermediary. In our experience, the "intermediary defence" is one of the most persistent misconceptions we encounter among crypto compliance teams encountering EU rules for the first time.
One further point worth noting at this step: the prohibition covers acting "for the benefit of" a designated person. A transaction that does not directly touch the designated person's wallet can still infringe the rules if its economic benefit flows to them. Benefit analysis requires more than a name-screening check against the transaction parties.
Step 2: Apply the EU ownership-and-control test to wallet and corporate structures
The EU ownership-and-control test treats an entity as caught by financial-sanctions restrictions if a designated person owns it or controls it, even if the entity is not itself listed. Unlike OFAC's 50 percent rule (a mechanical ownership threshold), the EU test has two limbs: ownership and control. Control is assessed qualitatively and can be established without majority ownership.
For VASPs, this creates a screening challenge that pure list-matching does not resolve. Consider a wallet held by a special-purpose company. The company is not listed. The beneficial owner, holding forty-five percent, is listed. Under OFAC's mechanical rule the company would not be captured by the threshold alone. Under the EU test, the question is whether the listed person controls the entity – through contractual arrangements, veto rights, delegated authority, or simply through the practical power to direct its decisions. The answer may well be yes.
Applying this test to decentralised or anonymised wallet structures is genuinely difficult. In our cross-border practice, we advise VASPs to approach the control analysis in three stages. First, identify the legal owner of the wallet or the account. Second, map the beneficial ownership chain to the level of natural persons, using the same threshold applied under the applicable anti-money-laundering rules as a practical floor. Third, ask whether any person identified in the chain is designated, and if so whether they could – by any mechanism – exercise control over the assets or direct their use. If the answer to the third question is uncertain, the conservative position is to treat the asset as caught pending a legal review.
The EU test also applies to subsidiaries and affiliated entities. A VASP that custodies assets on behalf of a corporate group must review the group structure, not just the contracting entity. The control test is not satisfied merely by showing that the listed person does not hold a majority stake.
Step 3: Build a sanctions-screening programme calibrated to EU crypto exposures
A functioning EU sanctions-screening programme for a VASP must screen against the EU Consolidated List – the single list of all persons, entities, and bodies subject to restrictive measures under EU Council regulations. The list is updated frequently. Static, infrequent screening creates a gap: a counterparty designated after onboarding will not be caught until the next screening cycle.
The core elements of an effective programme are these. First, screening at onboarding, with a defined process for handling potential matches. Second, ongoing screening – meaning the existing client and wallet population is re-screened each time the list is updated. Third, a transaction-monitoring layer that can identify behavioural patterns consistent with sanctions risk, such as rapid layering across multiple wallets or transactions that appear designed to move assets through non-screened intermediary addresses. Fourth, a documented escalation path, so that a potential match reaches a person with authority to pause a transaction and initiate a legal review. Fifth, a record-keeping obligation: the applicable regulations require records to be maintained for a defined period, and compliance counsel should confirm the current requirement for the specific regulation in scope.
How confident are you that your screening covers indirect exposures – beneficial owners two or three levels removed from the contracting entity? That is the question supervisory authorities in several EU member states have begun to ask in routine examinations of VASPs.
The wallet-address screening dimension is specific to crypto and is not present in traditional-finance compliance programmes. EU regulations do not, as of mid-2026, prescribe a mandatory list of sanctioned wallet addresses in the way that some other jurisdictions' enforcement advisories do. However, where a supervisory authority or a government agency publishes a wallet address in connection with a designated person, treating that address as indicative of sanctions risk is the cautious and defensible position.
Step 4: Handle a screening hit – freeze, report, and manage the clock
When a VASP's screening process identifies a potential match, the immediate obligation is to freeze – to ensure that no funds or economic resources are made available to or for the benefit of the potentially designated person while the match is being assessed. The freeze must be applied without alerting the counterparty in a way that could constitute a "tipping-off" infringement under applicable anti-money-laundering rules. These two obligations – freeze and non-disclosure – can be in tension, and managing them simultaneously requires clear internal procedures.
Following the freeze, the VASP must assess the quality of the match. A "false positive" – a name or identifier that resembles a listed person but does not correspond to the same individual or entity – must be documented and resolved through a defined process. Dismissing a potential match without adequate documentation is itself a compliance failure, even if the underlying transaction is ultimately permissible.
Where the match is confirmed as a genuine hit, EU regulations impose a reporting obligation. The VASP must notify the competent national authority of the EU member state in which it operates. The timing of that notification is set by the applicable national implementing rules, and VASPs should verify the current reporting window with compliance counsel for their specific jurisdiction. Acting promptly matters: a delayed report is treated as an aggravating factor in enforcement assessments. In our experience, firms that move quickly and document the steps taken are better positioned in any subsequent supervisory interaction.
If a transaction has already been flagged or a report filed, an early legal review can preserve options that narrow with time. To discuss an active screening hit or a regulatory notification, contact Calder & Vance at info@caldervance.com.
Step 5: Understand how EU obligations interact with OFAC, OFSI, and other regimes
A VASP operating across multiple jurisdictions is subject to multiple sanctions regimes simultaneously. The EU rules do not displace OFAC or OFSI obligations, and the three regimes differ in ways that directly affect VASP compliance design.
OFAC's 50 percent rule is a bright-line ownership threshold: an entity owned 50 percent or more in the aggregate by blocked persons is itself treated as blocked, regardless of control. The EU test, as noted above, adds a control limb. A corporate structure that passes the OFAC ownership test may still be caught under EU rules by virtue of control. A compliance programme built only around OFAC standards will therefore have gaps when applied to EU obligations.
OFSI, the UK financial-sanctions authority, applies a test similar to the EU's – both ownership and control are relevant – but the UK regime is now fully autonomous from the EU following the UK's departure from the EU. Lists are not identical. A person listed by the EU may not appear on the UK Consolidated List, and vice versa. A VASP with UK and EU clients must screen against both lists independently.
Secondary-sanctions risk also enters the picture for VASPs that clear in US dollars or maintain US correspondent relationships. Even a transaction that has no primary US nexus can trigger OFAC exposure if it involves a person subject to OFAC's secondary-sanctions programmes. We regularly advise VASPs on how to structure their screening architecture to address all three primary regimes – EU, UK, and OFAC – within a single compliance workflow rather than three siloed processes.
For VASPs with clients or operations in Singapore, the UAE, or Japan, additional national regimes apply. Each has its own list, its own licensing regime, and its own enforcement posture. The principle that the stricter prohibition governs is the correct starting point: where two regimes both apply and one imposes a more restrictive requirement, that requirement sets the compliance floor.
For related guidance on the OFAC regime, see our guide to crypto and VASP sanctions compliance under OFAC and the OFAC VASP compliance practical supplement. For compliance-programme testing across regimes, our compliance audit and testing service provides a structured assessment of screening and programme gaps.
Step 6: Identify the common risk flags specific to EU crypto compliance
Several patterns recur in EU crypto-sanctions compliance failures. VASPs that identify these early avoid the enforcement interactions that follow from them.
The first is list-matching without beneficial-ownership analysis. Screening a wallet address or a company name against the EU Consolidated List without also mapping the ownership and control chain to natural persons misses the core of the EU ownership-and-control test. The counterparty entity will often not appear on the list; the designated person sits further back in the structure.
The second is static onboarding screening only. Screening a client at onboarding and not screening again until a trigger event – such as a transaction above a certain value – creates a window during which a newly designated person continues to operate an account without restriction. The EU list is updated without notice. Ongoing screening is not optional.
The third is treating smart-contract interactions as outside scope. A VASP that interacts with a decentralised protocol does not automatically escape EU sanctions obligations because there is no human counterparty on the other side of the transaction. If the economic benefit of a transaction flows to a designated person – for example, through liquidity pool rewards or protocol-level revenue sharing – the prohibition on making funds available "for the benefit of" a designated person may be engaged.
The fourth is inadequate documentation of false-positive resolutions. Supervisory examinations of VASPs in EU member states have consistently identified the quality of false-positive documentation as a key indicator of programme maturity. A firm that cannot show how it resolved a match – who reviewed it, what information was considered, and what conclusion was reached – cannot demonstrate that it did not simply dismiss a genuine hit.
The fifth is the myth that licensing is available as a general fallback. A common misconception is that a VASP can obtain a general authorisation to continue dealing with a designated person pending a review. EU licensing for financial sanctions is transaction-specific and purpose-limited. A general authorisation to transact freely with a designated person does not exist under EU law. Where a specific licence is required, the application process is substantive and takes time. Assuming that a licence will be granted, or that it covers more than its express terms, is a significant compliance risk.
In a recent matter, a fintech operating a crypto payment corridor in multiple EU member states was flagged by its banking correspondent for transactions touching an address associated with a listed entity. The firm had screened at onboarding but not on an ongoing basis. We assisted the firm in scoping the apparent exposure, advising on its notification obligations, and redesigning its screening cycle to address the gap. The matter underscored that programme design decisions made at launch have enforcement consequences later.
Step 7: Know when to involve compliance counsel – and what they can do
A VASP's in-house compliance team can manage routine screening, false-positive resolution, and standard onboarding procedures. The moments where external sanctions counsel adds the most value are specific and predictable.
Involve counsel when a screening hit cannot be resolved as a clear false positive within your standard workflow. If the ownership or control analysis is genuinely uncertain – for example, because the corporate structure is complex, the beneficial-ownership information is incomplete, or the connection to the listed person is indirect – the analysis requires a legal opinion, not a compliance judgment.
Involve counsel before making a notification to a competent national authority. The content of the notification, the timing, and the parallel obligations it may trigger are all legal questions. A notification that is inaccurate, premature, or incomplete can create additional exposure.
Involve counsel when designing or auditing a screening programme intended to meet EU obligations. The programme elements described in Step 3 above are the minimum; the adequacy of any particular implementation depends on the VASP's business model, client base, asset types, and jurisdictional footprint. A generic programme may be inadequate for a VASP that processes high volumes of unhosted-wallet transactions, operates in multiple member states, or offers staking and liquidity services that create indirect economic-benefit exposures.
Involve counsel when a supervisory examination raises questions about the compliance programme or when an enforcement notice is received. Early engagement preserves the ability to respond constructively and, where appropriate, to make a voluntary self-disclosure that is accurate, complete, and framed to present the firm's position effectively.
The position above covers the standard case. Your facts – the counterparty structure, the asset type, the member states involved, and the specific regulations in scope – will change the analysis in ways that matter. To assess your EU crypto sanctions exposure or to instruct us on a specific matter, contact Calder & Vance at info@caldervance.com.
Related practices
- Compliance audit and testing – structured review of sanctions screening logic and programme gaps across regimes
- Crypto and VASP sanctions compliance under OFAC – step-by-step guide to the US regime for virtual-asset businesses
- OFAC VASP compliance: practical supplement – further guidance on OFAC screening, licensing, and enforcement for VASPs