A European trading company is reviewing a joint-venture target. Screening returns no direct hits. The target's immediate parent is clean. But two layers up, a listed individual holds a meaningful stake alongside a state-owned entity whose ownership is dispersed through a chain of nominees. Does the EU prohibition bite? The answer is not found on any list. It requires an assessment.
Under EU sanctions, the ownership and control test (the mechanism that extends prohibitions to non-listed entities when a designated person owns or controls them) goes well beyond a mechanical percentage threshold. As of July 2026, the EU regime applies a dual criterion: ownership of more than 50 percent of an entity's capital or voting rights is treated as control, but control through other means – board composition, contractual dependency, or practical decision-making power – can capture an entity even where the listed person holds a minority stake. That two-limb structure is where the analysis is hardest and where most compliance failures occur.
This guide sets out the legal basis for the EU test, the step-by-step procedure for conducting an assessment, the cross-regime comparison a cross-border business cannot ignore, the documentation standard, and the risk flags that should prompt immediate specialist review.
What is the legal basis for the EU ownership and control test?
The EU ownership and control test derives from the relevant Council Regulations that establish each thematic sanctions programme. Each regulation contains a prohibition that extends to entities that are owned or controlled by a designated person – and the prohibition is directly effective across all EU member states without requiring transposition into national law.
The administering institution is the Council of the European Union, which maintains the list of designated persons. The European Commission provides guidance on the application of the ownership and control test. National competent authorities – the sanctions authorities of each member state – are responsible for supervision and enforcement within their respective jurisdictions, and their interpretations can, in practice, diverge on the control limb.
Two points about the legal structure deserve early emphasis. First, the prohibition on transacting with a controlled entity is not a "should consider" caution. It is a hard prohibition: engaging with a controlled non-listed entity is treated as engaging with the designated person for the purposes of the regulation. Second, the burden of demonstrating that an entity is not controlled rests in practice on the party proposing to engage with it. That is not stated explicitly in most regulations, but it is the functional reality of enforcement.
The EU Consolidated List (the official register of persons and entities designated under EU sanctions) names only the listed persons and entities directly. It does not name the entities those persons own or control. That gap is the compliance challenge this guide addresses.
Step 1 – Map the ownership structure before touching the list
The first step in any EU ownership and control assessment is to build a complete ownership map before running any name against a list. Screening against the EU Consolidated List tells you only whether a specific string of characters matches a listed name. It cannot tell you whether an unlisted entity is caught through ownership or control. Those are different exercises, and conflating them is the most common cause of incomplete assessments.
Building the ownership map means: identifying all direct shareholders and their percentage holdings; tracing each shareholder to its ultimate beneficial owners; identifying any corporate or trust structures through which a natural person's interest is held; and recording the source of each piece of information – commercial registry, beneficial-ownership registry, corporate documents, or other verified sources. In a complex group, the map can extend across five or more layers and multiple jurisdictions.
Where company registries are incomplete or information is withheld, you are not in a position to certify a clean result. In our experience, the appropriate response to an information gap is to treat the position as unresolved – not to proceed on the assumption that the missing layer is clean. If the counterparty is unwilling to provide ownership information sufficient to complete the map, that reluctance is itself a risk signal.
Practical tools for this stage include corporate registry searches in each relevant jurisdiction, third-party beneficial-ownership data providers, and – for private companies in EU member states – the beneficial-ownership registers that member states are required to maintain under EU anti-money laundering legislation. Those registers are not uniformly reliable, and cross-referencing is necessary.
Step 2 – Apply the ownership limb: does the 50 percent threshold trigger?
Once the ownership map is built, the ownership limb of the EU test is applied first, because it is the simpler of the two. Under the EU test, an entity is owned by a designated person where that person holds, directly or indirectly, more than 50 percent of the entity's capital or voting rights.
Aggregation applies across multiple designated persons. If two listed individuals each hold 30 percent of a target company, their interests are aggregated to 60 percent and the entity is treated as owned by designated persons – even if each individual holding is sub-threshold. This aggregation rule is shared broadly across regimes, but the precise articulation differs, and it is a routine source of missed hits.
Indirect ownership requires following the chain through each layer. A designated person who holds 80 percent of Company A, which in turn holds 70 percent of Company B, owns 56 percent of Company B indirectly – above the threshold. The computation is a simple multiplication cascade through each layer. Where the chain branches, each branch is assessed separately, and the results are summed before applying the threshold.
What happens when the designated person's stake is exactly 50 percent? Under the EU formulation the test requires more than 50 percent for the ownership limb. An exact 50 percent holding does not automatically trigger the ownership criterion – but it very likely triggers the control limb, because parity ownership is frequently accompanied by veto rights, board appointment rights, or other structural controls. You cannot stop the analysis at the ownership limb when the result is borderline.
A critical point: where ownership is held through nominees, trusts, or arrangements specifically designed to obscure the beneficial owner, the EU test looks through the arrangement to the economic reality. Structures that place legal title with one person while the economic benefit and direction vests in a listed person are not shielded by legal form.
Step 3 – Apply the control limb: the harder question
The control limb of the EU test captures entities that a designated person controls by other means, even where the ownership limb is not met. This is the analytically demanding part of the assessment – and it is the part that most list-screening tools and many internal compliance processes simply do not address.
Control can arise in any of several ways. Board or management appointment rights give a designated person the ability to direct the entity's business. Contractual arrangements – supply agreements, financing structures, licences of critical intellectual property – can create economic dependency such that the entity cannot operate without the designated person's ongoing consent. De facto decision-making, where the designated person instructs management despite having no formal rights to do so, can also constitute control in substance. National competent authorities and, in a small number of final judgments, the EU General Court have considered these patterns in deciding whether the prohibition extends to a non-listed entity.
How do you assess de facto control? The evidence base matters. Board minutes, management instructions, email correspondence, and patterns of commercial decision-making all bear on the question. Where a designated person routinely instructs the management of a company, issues directives that are followed without governance challenge, and has done so over a sustained period, a court or competent authority is likely to treat that company as controlled – whatever the shareholding structure says. Have you reviewed the governance record, or only the register of members?
In our cross-border practice, we find that the control limb presents the greatest divergence between regimes. Under the EU framework, the control analysis draws on corporate-law concepts of de facto directorship and practical authority. National competent authorities within the EU can give slightly different weight to different indicators. Documenting the methodology used to assess each indicator – and recording why, on the evidence available, control was or was not found – is essential to a defensible outcome.
A practical framework for the control limb involves examining four questions in sequence. First, does the designated person have formal rights to appoint or remove directors or senior management? Second, does the designated person have formal veto rights over major business decisions? Third, does the entity's commercial viability depend materially on a relationship with the designated person that cannot readily be replaced? Fourth, is there evidence that the designated person has in practice directed the entity's decisions without the governance processes that would ordinarily constrain a non-controlling party? A "yes" to any one of these warrants a conclusion of control, subject to countervailing evidence.
How does the EU test differ from OFAC and OFSI – and why does that matter for cross-border businesses?
For a business operating between the United States, the United Kingdom, and the European Union, the ownership and control tests operate in parallel – and they do not always produce the same result for the same entity. The safest general rule is that the stricter prohibition governs: if any one of the three regimes treats an entity as caught, the business must comply with that regime's prohibition, regardless of what the other two would conclude.
The OFAC position is the most mechanical. OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) requires no control analysis. An entity is blocked if the aggregate ownership of SDN List (OFAC's list of Specially Designated Nationals and blocked persons) persons reaches or exceeds 50 percent. OFAC's test does not require control, only aggregate ownership at or above that threshold. This makes it in some ways both simpler and broader than the EU test for the ownership limb alone.
OFSI's test in the United Kingdom also has both an ownership and a control limb, under the Sanctions and Anti-Money Laundering Act and the relevant thematic regulations. The ownership threshold under the UK regime is also 50 percent or more. The control analysis draws on a similar set of indicators to the EU test – appointment rights, veto rights, contractual dependency, de facto direction – but the guidance and enforcement posture of OFSI is distinct from the national competent authorities of EU member states. An entity that UK-licensed firms have assessed as not controlled may still require a separate EU assessment, because the authority applying the control test is different.
This divergence has a direct operational consequence. A multinational performing a single unified assessment and treating it as dispositive for all three regimes is taking a material risk. The analysis for each regime must be conducted by reference to that regime's legal standard. A consolidated assessment that explicitly maps findings to each regime – noting where they converge and where they differ – is the only defensible approach for a business with US, UK, and EU nexus. We regularly advise clients on exactly this three-way mapping, and the differences are more often material than not.
For businesses with exposure to the sanctions regimes of Singapore, Japan, or the UAE, a further layer of analysis is needed. Those regimes generally follow the UN Security Council Consolidated List as a baseline, but may also incorporate autonomous designations. The ownership and control tests applicable in those jurisdictions vary, and local counsel in the relevant jurisdiction should be engaged where the transaction has a material connection to those markets.
Step 4 – Document the assessment to the standard that withstands review
A sound substantive conclusion is worth little if it cannot be evidenced. Documenting an EU ownership and control assessment to the standard that will withstand scrutiny by a national competent authority, an external auditor, or a regulator in an enforcement inquiry requires more than recording the outcome. It requires recording the methodology, the evidence examined, and the reasoning applied to each step.
The documentation package for an EU ownership and control assessment should contain, at minimum: the ownership map with sources noted at each node; the results of the list checks run against the EU Consolidated List and any other applicable lists; the analysis of the ownership limb, with the aggregation computation where relevant; the analysis of the control limb, with each indicator addressed in turn and the evidence supporting the conclusion on each; and a clear conclusion identifying whether the entity is, on the evidence and the applicable legal test, owned or controlled by a designated person.
Records should be maintained for at least the minimum period required by the applicable regime. In our practice, we recommend retaining assessment documentation for the duration of any continuing relationship with the counterparty and for a further period extending beyond the relationship's end, on the basis that regulators have broad authority to request records and enforcement time-limits are long. Verify the current retention requirements for the specific regime before setting your retention policy.
The assessment should also record who conducted it, when, and on what information. A dated and signed assessment that was accurate when conducted but whose conclusions have been overtaken by a subsequent designation or a restructuring of the counterparty does not constitute a continuing clean bill of health. Triggering events – a new designation, a corporate restructuring, a significant change in management or ownership – require a reassessment. Treating an assessment as a one-time exercise is a common and sometimes serious error.
Risk flags that require immediate specialist review
Most ownership and control assessments are resolved through careful but routine analysis. Some, however, present features that take them outside the scope of a standard in-house assessment. The presence of any of the following risk flags should prompt immediate specialist review before the transaction proceeds, any funds are transferred, or any services are provided.
First, an opaque ownership chain in which the ultimate beneficial owner cannot be verified through commercially available sources. This does not necessarily mean the entity is caught, but it means the assessment cannot be completed – and an incomplete assessment is not a safe harbour.
Second, a counterparty that is unwilling to provide information sufficient to complete the ownership map, particularly where no credible commercial explanation is offered for the refusal. Reluctance to disclose ownership is a standalone risk signal under the EU anti-money laundering framework and under the guidance issued by several national competent authorities.
Third, a designated person who holds a below-threshold stake but also holds contractual rights – over financing, over intellectual property, over supply arrangements – that give practical decision-making authority over the entity. This is a control analysis, and it is not mechanical.
Fourth, a counterparty operating in a sector that is a known enforcement priority for national competent authorities. The assessment may be substantively correct but the risk of a regulatory enquiry into the transaction is materially higher, and the documentation standard must reflect that.
Fifth, a transaction structure in which the control assessment rests on a narrow factual argument – a claim, for example, that formal veto rights held by a designated person are not exercised in practice. Arguments of that form are defensible in principle but fragile in execution, and the consequences of getting them wrong are severe. This is the circumstance that most clearly calls for external counsel before proceeding.
The position above covers the standard case. Your specific facts – the counterparty, the sector, the jurisdiction of the national competent authority most likely to supervise the transaction, the route of any funds or goods – change the analysis materially. To discuss an assessment with a sanctions lawyer who advises on the EU regime, contact Calder & Vance at info@caldervance.com.
Common misunderstanding: why "clean on the EU list" does not mean "clean under EU law"
The most persistent misconception in EU sanctions compliance – and the one that most often underlies serious enforcement failures – is that a name-check against the EU Consolidated List is a complete sanctions assessment. It is not. It is one step in a larger analysis.
The EU Consolidated List identifies designated persons by name, date of birth, identifying numbers, and aliases. It does not identify the companies, partnerships, foundations, or trusts through which those persons exercise control. The obligation to identify and assess those entities rests with the business conducting the transaction. Compliance counsel and regulators in EU member states have been consistent on this point: the obligation is on the party transacting, not on the list to flag every indirect exposure.
A second misunderstanding is that the control test requires a final, authoritative determination before the assessment is usable. In practice, the standard is one of reasonable assessment: a documented, evidence-based conclusion reached by a competent person applying the applicable legal test to the available evidence. Perfection is not the standard; reasonableness and documentation are. An assessment that acknowledges its limits – noting, for example, that a specific ownership layer could not be verified through available sources and that the assessment is conditional on that information being correct – is more defensible than an assessment that overstates its certainty.
A third misunderstanding is that the EU ownership and control test is static. It is applied as of the date of the transaction, but the assessment must be maintained and updated. A designation that occurs after an assessment is completed may immediately change the conclusion. Many businesses set periodic review cycles for high-risk counterparties; a rolling cycle tied to the publication of new designations is sound practice.
If a transaction has already proceeded on the basis of an assessment that is now in question – because a counterparty has been subsequently designated, because new information has come to light about the ownership chain, or because the assessment was less thorough than it should have been – an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential initial review.
Related practices
- Sanctions compliance audit and testing – assessing programme effectiveness across multi-regime obligations
- EU ownership and control assessments: guide 3 – advanced scenarios including trust structures and nominee arrangements
- EU ownership and control assessments: guide 4 – documentation standards and audit-readiness for complex groups