A trading company in Hamburg has just agreed terms on a humanitarian shipment. Its legal team identifies that the transaction falls under a Council regulation that includes broad prohibitions. A colleague recalls that a general authorisation exists. But does the company actually qualify? And what internal steps must it complete before relying on it? These questions are not academic. Getting the answer wrong can mean the authorisation is invalid, the transaction is unlawful, and the firm faces enforcement.
Under the EU sanctions regime, a general licence (a standing authorisation that permits a defined category of transactions without a separate application to a competent authority) is available only when the transaction falls precisely within the criteria set by the relevant Council regulation or the competent authority's published conditions. Eligibility is not self-declaring. A business must test each criterion, document its assessment, and retain that record. Where uncertainty remains, a specific licence (a case-by-case authorisation) is the correct route.
This guide walks through each stage of the eligibility analysis, maps the key divergences between the EU regime and OFAC and OFSI, and identifies the risk flags that most often cause businesses to lose the protection they thought they had.
Step 1: Identify the applicable Council regulation and the authorisation provision
The first step is to identify the correct Council regulation and to locate within it the specific authorisation that might apply to your transaction.
EU sanctions are not a single instrument. Each thematic programme has its own Council regulation and Council Decision. The authorisations differ in scope, in the categories of permitted activity, and in the conditions attached to them. A general licence valid under one programme may have no counterpart under another. Assuming that an authorisation which covers one type of activity or one programme extends to a different set of facts is one of the most common errors our practice sees.
The regulation will either grant the authorisation directly – sometimes expressed as a derogation from the prohibition – or will empower the competent authority of each Member State to grant authorisations within defined parameters. In the second case, the competent authority may publish a general licence of its own, or may require an individual application. You must check both levels: the Council regulation and any instrument the relevant competent authority has issued under it.
Who is the competent authority? For financial sanctions, it is typically the national authority designated by each Member State – in Germany, this is managed at Federal level; in France, at the Treasury; in Ireland, at the Department of Finance. For dual-use export controls, the national export-licensing authority is the relevant body. You must identify the authority in the jurisdiction where you are established, because the territorial scope of the authorisation follows the place of establishment, not the location of the goods or the counterparty. As of June 2026, the interaction between Member State competent authorities and the Council's own instruments remains an area where businesses frequently mis-identify which body they need to satisfy.
Step 2: Map your transaction to the conditions of the authorisation
Once the provision is identified, the business must test each condition of the authorisation against the facts of its transaction. This is not a checklist exercise; it is a legal analysis.
A typical EU general authorisation for humanitarian activity, for example, will specify the type of goods or funds that may be transferred, the category of recipient (an international organisation, a UN agency, or an NGO satisfying defined criteria), the purpose of the transfer, and often the geographic reach. Each limb must be satisfied. A transfer that meets the purpose test but is made to a recipient that does not meet the category test is not covered.
Three questions structure the analysis. First: is the transaction type within scope – does the authorisation cover asset releases, financial transfers, goods exports, or services, and does your transaction fit? Second: is the counterparty or beneficiary within the permitted class – is it a listed person, an entity owned or controlled by a listed person, or does it hold a separate status that the authorisation specifically accommodates? Third: are there additional conditions – reporting obligations, end-use declarations, or value caps – that constrain the authorisation?
In our experience, the second question is where most eligibility failures occur. A business identifies that a humanitarian authorisation exists and proceeds without confirming that the specific beneficiary satisfies the category condition. The authorisation covers certain classes of recipient. If the beneficiary falls outside that class – even marginally – the authorisation does not apply.
The position above covers the standard case. Your facts – the goods, the counterparty structure, the Member State of establishment, and the specific Council regulation in play – change the analysis. For an eligibility assessment before a transaction, contact Calder & Vance at info@caldervance.com.
Step 3: Apply the EU ownership-and-control analysis where a counterparty is involved
Where the transaction involves a counterparty that is not itself listed, the business must determine whether that party is nonetheless caught by the prohibitions through the EU ownership and control test (the test under which a non-listed entity may be subject to the same obligations as a listed person if a listed person owns or controls it).
This matters for general-licence eligibility because some authorisations are drafted to exclude entities owned or controlled by listed persons. If the counterparty is controlled by a listed person, the general licence may not extend to it even if the transaction type is otherwise within scope.
The EU ownership and control test differs materially from the US position. Under OFAC, the test turns on 50 percent or more direct or aggregate ownership, applied mechanically. Under the EU and UK regimes, ownership is one element but control is assessed separately and is fact-specific: it can be established through governance rights, veto powers, contractual dependency, or other means that do not involve majority ownership. A company that is 40 percent owned by a listed person may nonetheless be controlled by that person if the listed person holds a casting vote or can direct the entity's commercial decisions.
This divergence has direct consequences for a business relying on an EU general licence. A screening tool calibrated to the OFAC 50 percent threshold will not catch all entities that the EU ownership-and-control analysis would treat as subject to the prohibition. The EU test requires an examination of governance documents, shareholder agreements, and the practical exercise of influence – not only the share register.
If a transaction has already been flagged by a counterparty's compliance team or by a bank, an early review can preserve options that narrow with time. Contact us at info@caldervance.com.
How does the EU regime compare with OFAC and OFSI on general licence eligibility?
Cross-regime comparison is essential for any business operating between the US, UK, and EU, because the general-licence concepts are not equivalent and the eligibility tests diverge at several points.
Under OFAC, a general licence functions as a standing authorisation issued directly by OFAC, typically in the body of programme-specific regulations or in a separately published licence document. Eligibility is assessed by the regulated party without prior approval. The conditions are set by the licence text, and OFAC publishes interpretive guidance and frequently asked questions that supplement the text. The ownership threshold is binary and ownership-based. Control, in the EU sense, does not independently trigger the blocking rule under most OFAC programmes.
Under OFSI in the UK, the position is closer to the EU model. OFSI may issue general licences (termed "General Licences" and published on OFSI's website) or require an individual licence application. The governing instrument is the Sanctions and Anti-Money Laundering Act, implemented through the relevant thematic regulations. OFSI applies both an ownership test and a control test, and the control analysis overlaps materially with the EU approach. However, OFSI's published general licences may set different category conditions from those in the Council regulation, and a business may be eligible under one regime but not the other for the same transaction.
The practical implication for a dual-listed or transatlantic business is this: a transaction may be covered by an EU general licence but require a specific licence from OFSI, or vice versa. Where both regimes apply – because the business has a UK branch or because payments clear through a UK correspondent – both eligibility analyses must be completed. The stricter prohibition governs, and the weaker authorisation does not override it.
There is also a documentation asymmetry. OFAC does not generally require a business to notify it when relying on a general licence, though specific licences require affirmative reporting. Under certain EU authorisations, the competent authority must be notified of a transaction within a defined window, and failure to notify invalidates the authorisation retroactively. That notification requirement is one of the conditions that businesses most consistently overlook.
For a practical comparison of the EU and OFAC general licence regimes, see our guide at General Licence Eligibility: OFAC. For the Japan regime, see General Licence Eligibility: Japan.
What are the record-keeping and reporting obligations attached to EU general licences?
Relying on an EU general authorisation generates record-keeping and, in many cases, reporting obligations that are as significant as the eligibility conditions themselves.
The Council regulation or competent authority instrument will typically specify what records must be kept – contracts, payment records, end-use documentation, screening evidence, and the eligibility analysis itself. The retention period is set by the applicable instrument; it is commonly set at a period of several years. Some instruments specify five years as the minimum record-keeping requirement, though businesses should verify the specific period in the relevant instrument. These records must be available for inspection on request from the competent authority.
Reporting obligations vary by programme and by the category of activity authorised. For certain financial transfers, the competent authority must be notified before the transfer is made or within a short window after it. The notification typically requires the business to identify the parties, the value, the legal basis for the authorisation, and the outcome of the eligibility assessment. A late or incomplete notification can expose the business to enforcement even where the underlying transaction was substantively lawful.
In our cross-border practice, we regularly advise businesses that have completed the eligibility analysis correctly but have not maintained records in a form that demonstrates that analysis. Where an enforcement review later occurs, the burden on the business to show that it assessed eligibility at the time of the transaction is heavy. A policy that requires contemporaneous documentation of the eligibility assessment – and a defined process for retaining that documentation – is a basic risk-management measure, not an advanced one.
Businesses operating under EU licences with an export-control dimension should also consider whether the transaction engages the EU dual-use rules or the relevant national export licensing authority, since the EU export control regime operates in parallel with the financial sanctions instruments. The account-management and licensing service for BIS/EAR matters addresses the US side of this parallel structure and illustrates how the two regimes interact for businesses with a transatlantic export profile.
What risk flags most commonly cause businesses to lose the protection of a general licence?
There are five risk patterns that, in our experience, most frequently invalidate an otherwise valid general-licence position.
The first is transaction drift. The authorisation covers the facts as they stood when the eligibility assessment was made. If the transaction structure changes – a new party is added, the goods are substituted, or the route changes – the original assessment does not carry over. A business that re-uses an earlier eligibility memorandum without revisiting it for a modified transaction is operating without protection.
The second is over-reliance on a summary. Competent authorities and trade associations sometimes publish summaries of the conditions attached to an authorisation. These summaries are useful orientation tools but they are not the authorisation. They may be out of date, may simplify conditions that are more restrictive in the original, or may omit conditions specific to certain Member States. The eligibility analysis must be conducted on the face of the instrument.
The third is failing to apply the ownership-and-control test to every party in the transaction chain, not only the direct counterparty. An intermediate logistics company that is controlled by a listed person can bring a transaction within the prohibition even if the buyer and seller are clean. This is an area where our practice has seen businesses receive enforcement notices despite having screened the principal parties.
The fourth is missing a notification deadline. As noted above, certain EU authorisations require prior or post-transaction notification to the competent authority. The window can be short. A business that completes the transaction and then notifies late – or does not notify at all – forfeits the protection of the authorisation, even though every other condition was met.
The fifth is the assumption that a general licence available in one Member State operates in the same way in another. EU financial sanctions are broadly harmonised at Council level, but the implementing instruments and the competent authority interpretations differ between Member States. A transaction that is authorised under German competent authority practice may face a different analysis in France or Italy if the transaction has a multi-jurisdictional execution structure.
A common myth is that, once a business has confirmed that the transaction type is in principle covered by an authorisation, eligibility is established. It is not. Eligibility is the product of a complete analysis of every condition – not a preliminary conclusion that the authorisation category is relevant. Confirming the category is the start of the analysis, not the end of it.
When should a business involve sanctions counsel on general-licence eligibility?
The question of when to involve external counsel is itself a risk-management decision. Counsel adds most value at specific decision points in the eligibility process.
The first is at the outset of a transaction where the counterparty, the goods, or the destination gives rise to even a preliminary screening hit. An early eligibility review is faster and less costly than an enforcement response. Where time pressure exists – a signed contract, a letter of credit with an expiry, a humanitarian emergency – the review can be structured around the operative conditions without delay.
The second is where the ownership-and-control analysis is complex. If the counterparty has a layered ownership structure, if a listed person's interest is indirect or split across nominee holders, or if governance documents are in a non-English language, the analysis is not one that a compliance function operating under normal workloads should conduct unassisted. We regularly advise on precisely this work.
The third is where the transaction straddles multiple regimes. A transaction involving both an EU entity and a US entity, where payment passes through a UK bank, engages three competent authorities and three sets of eligibility conditions simultaneously. The interaction between those conditions – particularly where the EU authorisation permits something that the OFAC regime restricts – requires a coordinated analysis.
The fourth is where a previous transaction that relied on a general licence is now under review. If a competent authority has made a request for information or if a correspondent bank has suspended payment pending verification, the window for a voluntary disclosure or a corrective submission is finite. Engaging counsel at this stage preserves the options that narrow with delay.
We have acted for businesses at each of these stages. Our work on general-licence eligibility covers the eligibility assessment, the documentation framework, the notification process, and – where a specific licence is the correct route – the application itself.
Related practices
- Frozen account management under BIS/EAR – handling blocked account obligations and export-licence conditions under the US regime
- General licence eligibility: OFAC – the US framework for standing authorisations compared with the EU approach
- General licence eligibility: Japan – how the Japanese regime handles standing authorisations for cross-border transactions