A trading house finalises a supply agreement with a counterparty in a third market. The goods are dual-use. The buyer's jurisdiction falls under an EU sanctions programme. The compliance team asks: is there a general licence that permits this? And, if so, does the company actually qualify to rely on it? Getting that analysis wrong – in either direction – stops legitimate trade or exposes the business to enforcement.
EU general licences (standing authorisations set out in the relevant Council Regulation that permit defined categories of transaction without a case-by-case licence application) are not self-executing. A business must confirm that its specific transaction, counterparty, and purpose each satisfy every condition in the authorisation text before it relies on one. As of June 2026, EU general licences vary significantly between sanctions programmes, and the conditions are more granular than many compliance teams expect.
This guide walks through the eligibility analysis in seven steps, addresses the most common errors, and explains where the EU regime diverges from its OFAC, OFSI, and other comparators.
Step 1: Identify the correct sanctions programme and the instrument that governs it
The first step is to confirm which EU Council Regulation applies to your transaction, because general licence provisions are embedded in the programme-specific instrument – not in a single cross-cutting statute. The EU does not operate a single consolidated "general licence register" of the kind that OFAC publishes on its website. Each programme's authorisations appear in the relevant Council Regulation and, sometimes, supplemented by Council Decisions or implementing regulations that amend the original text.
This matters immediately. An authorisation that exists under one programme does not carry over to another, even where the counterparty or goods overlap. A business selling goods with a humanitarian end-use must check the authorisation language in the specific programme regulation for the jurisdiction in question, not assume that an authorisation found in a different programme applies by analogy.
In our cross-border practice, the single most common starting error is mapping a transaction to the wrong instrument. A business reads an authorisation that looks applicable, relies on it, and later discovers that the counterparty's jurisdiction falls under a different regulation with no equivalent provision. That is a compliance failure even where the underlying transaction might have been authorised under a specific licence.
Practical action: before anything else, confirm the programme code or the Council Regulation number (without citing the article) under which your counterparty or goods are potentially caught, and obtain the current consolidated text of that instrument.
Step 2: Confirm that a general authorisation exists for your category of transaction
Once you have the correct instrument, the next question is whether it contains any general authorisation that covers your transaction category at all. Not all EU sanctions programmes include general authorisations. Some programmes operate on a prohibition-first basis with relief only through specific licence applications to the competent authority of the relevant EU member state.
Where general authorisations do exist, they tend to fall into recognisable functional categories. Humanitarian exceptions, diplomatic activity, energy supply continuity, personal remittances, legal services, and wind-down periods are among the types that recur across programmes – but the scope, conditions, and duration of each differ materially between programmes and between successive amendments to the same programme.
Do not assume that because a general authorisation existed last quarter it remains in force today in the same terms. The Council amends regulations by implementing regulation, often at short notice. We regularly advise clients who have been relying on an authorisation that was narrowed or removed by an amendment they had not tracked. The obligation to monitor is ongoing, not a one-time check at deal inception.
Practical action: review the current consolidated text of the programme regulation and identify the specific authorisation provision. If none exists for your category, the route is a specific licence application – covered in the related practice linked below.
Step 3: Apply the eligibility conditions – the transaction test
Every EU general authorisation carries conditions. These typically operate on three axes simultaneously: the nature of the goods or services, the identity and status of the counterparty, and the purpose or end-use of the transaction. All three axes must be satisfied. Satisfaction of two out of three is not eligibility.
The goods or services axis is usually the most technical. Some authorisations are goods-specific and reference categories by description rather than by a classification code. A compliance team must map its specific goods to those descriptions with care. Partial overlap is not sufficient; the goods must fall within the scope of the description as the regulation defines it.
The counterparty axis involves both identity screening and status assessment. A general authorisation may be unavailable where the counterparty is a designated person, an entity owned or controlled by a designated person, or where a third-party beneficiary of the transaction is sanctioned. The ownership and control test (the EU test for whether a non-listed entity is caught through a listed person's ownership or control) applies here. Under EU rules, the control limb of that test goes beyond the mechanical ownership threshold and looks at whether a listed person can exercise determining influence over the entity's decisions. That is a broader and more judgement-intensive enquiry than the OFAC 50 percent rule (OFAC's mechanical rule treating entities owned 50 percent or more by blocked persons as themselves blocked).
The purpose or end-use axis demands documentary evidence, not a declaration. Humanitarian purpose, diplomatic purpose, and legal-services purpose each carry their own evidentiary expectations. Assembling that evidence before the transaction, not after a query arrives, is the professional standard.
Step 4: Check member-state competent-authority requirements
The EU general licence system does not operate at federal level in the way that OFAC general licences do in the United States. In the US, a general licence issued by OFAC applies uniformly across all states and all US persons. In the EU, the Council Regulation sets the authorisation, but implementation and – critically – any prior notification or registration requirement is a matter for the competent authority of the relevant member state.
Some EU member states require a business to notify, register, or obtain a confirmation from the national competent authority before relying on a general authorisation. Others do not. The position is not uniform across the 27 member states, and it changes as member states update their national administrative procedures.
This is a point where the EU regime diverges sharply from OFAC practice. Under OFAC, a US general licence is self-executing: if the conditions are met, the authorisation applies without any prior filing. Under OFSI in the United Kingdom, the position is closer to the EU model: some general licences carry reporting obligations triggered by reliance. Compliance counsel advising a cross-border group with entities in multiple EU jurisdictions must map the notification requirements in each relevant member state, not only at EU instrument level.
The position above covers the standard case. Your facts – the member state of your EU entity, the goods, the counterparty's jurisdiction, and the specific programme – change the analysis. For an assessment of your exposure, contact Calder & Vance at info@caldervance.com.
Step 5: Document eligibility before the transaction proceeds
Documentation is not a formality. It is the mechanism by which a business establishes, at the moment of reliance, that it was entitled to rely on the general authorisation. After the fact, a reconstruction of the eligibility analysis carries far less weight with a competent authority investigating an apparent violation than contemporaneous records.
Best practice for EU general licence documentation includes four elements. First, a written record of the authorisation provision relied upon, with the date of the consolidated text used, confirming the provision was in force on the transaction date. Second, a record of the goods, counterparty, and purpose assessment against each eligibility condition. Third, the supporting evidence for the purpose or end-use claim. Fourth, a log of any member-state notification steps taken, with dates and confirmation numbers where applicable.
Record-keeping obligations under EU sanctions regulations apply to the underlying transaction documentation as well. Maintain records in a form that can be produced to a competent authority on request, and retain them for the duration required under the applicable programme – which varies, so verify the current position before relying on a generic retention period.
In a recent matter, a financial-services group had relied on a general authorisation across multiple transactions without maintaining contemporaneous eligibility records. When a competent authority queried one transaction, the group could not demonstrate eligibility for the others without reconstructing the analysis from emails and payment records. The remediation work – retrospective documentation, compliance-programme redesign, and engagement with the competent authority – was substantially more demanding than a properly documented eligibility file at the outset would have been.
Step 6: Assess whether a specific licence is needed instead – and how the two routes interact
A general authorisation covers what it covers, no more. Where the transaction falls outside the scope – on any of the three eligibility axes – the route is a specific licence application to the competent authority of the relevant member state, not a stretching of the general authorisation to cover a marginal case.
The specific licence route is slower, requires a formal application and supporting dossier, and is decided by the competent authority on a case-by-case basis. Competent authorities in EU member states have different processing timescales and different evidentiary expectations; there is no single EU-wide window. A business that needs certainty on a time-sensitive deal, or whose goods fall just outside a general authorisation's scope, may need to apply in the relevant member state and plan for the processing period that competent authority requires.
What a business should not do is treat a general authorisation as an approximate permission and rely on it where eligibility is genuinely uncertain. The enforcement consequence of relying on a general authorisation without meeting its conditions is, in substance, the same as transacting without any authorisation. That risk is real. Competent authorities across EU member states have taken enforcement action against entities that could not demonstrate they met the conditions of a general authorisation they claimed to rely upon.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Write to us at info@caldervance.com for a confidential initial assessment.
Step 7: Monitor for amendments and manage the ongoing compliance obligation
Eligibility at the date of first reliance does not guarantee continued eligibility. EU Council Regulations are amended by Council implementing regulations, and those amendments can narrow, suspend, or entirely remove an existing general authorisation, sometimes with immediate effect or with only a short transition period.
A standing internal process to track Official Journal publications relevant to the sanctions programmes in scope for your business is not optional for a business with material EU sanctions exposure. For a business operating under multiple EU programmes simultaneously – for example, one dealing in energy, goods, and financial services across several third-market jurisdictions – that monitoring obligation is substantial.
The cross-regime comparison is instructive here. OFAC publishes general licences on its website as standalone documents with their own effective dates, making version control more straightforward for a US practitioner. The EU embeds its authorisations in programme-specific regulations, amends them by implementing regulation, and does not always publish a clean consolidated summary. Tracking current positions requires reading across both the base regulation and subsequent amendments. We have acted for groups that maintained a 12-month-old version of a regulation as their compliance reference without realising the instrument had been amended multiple times. That gap carries direct legal risk.
A common myth is that once a general licence is confirmed at transaction inception, no further review is needed unless the transaction structure changes. That is incorrect. The authorisation must remain in force and its conditions must continue to be satisfied throughout the transaction's lifecycle. A long-term supply contract authorised by a general licence on signature may face a changed legal position by the time the fifth delivery ships.
Related practices
- Frozen account management under BIS/EAR – managing asset-freeze and export-control compliance in parallel regimes
- EU general licence eligibility: advanced scenarios – complex ownership structures, partial eligibility, and fall-back routes
- General licence eligibility under the Japan regime – how Japan's export and sanctions authorisations compare to EU practice