Calder & Vance International Sanctions & Compliance Counsel

Licensing & Authorizations · EU

Payment authorisations under EU: a practical guide

A European trading firm processes a routine invoice payment to a long-standing supplier. The compliance team runs the SWIFT details through the firm's screening tool. The counterparty is not on any list. But the payment passes through an account held by a financial institution subject to EU asset-freeze measures – and the transaction is blocked. The firm has no clear idea whether it needs a specific authorisation, how to apply for one, or which competent authority has jurisdiction. As of June 2026, this scenario is one of the most common compliance breakpoints we see across the EU sanctions regime.

Payment authorisations under EU sanctions are case-by-case permissions granted by the competent national authority of a Member State, allowing a payment or fund transfer that would otherwise be prohibited under the relevant Council Regulation. The governing authority is the designated national competent authority – typically a finance ministry, central bank, or treasury unit – acting within the legal basis set by EU Council regulations. No single EU-level body grants these authorisations; the process is national, though the legal standard is set at the EU level.

This guide walks through each stage: identifying whether an authorisation is required, selecting the correct competent authority, building the application, managing the review, and understanding how the EU position compares with the approaches taken by OFAC, OFSI, and other major regimes.

Step 1: Confirm whether a payment authorisation is actually required

Not every payment touching a sanctioned counterparty requires a specific authorisation – and applying for one when an exemption or general derogation already covers the transaction wastes time and creates a compliance paper trail that may raise questions you do not need. The first analytical step is to determine whether the payment falls within a prohibition at all, and then whether a standing derogation applies.

EU Council regulations typically prohibit making funds or economic resources available to, or for the benefit of, listed persons and entities. A payment may trigger that prohibition in several ways: the payee is designated, the ultimate beneficiary is designated, or the account at the correspondent or beneficiary bank is subject to an asset freeze. Understanding which limb applies matters, because the available derogations differ.

Standing derogations commonly available under EU regulations include releases for basic needs (food, rent, utilities, medical expenses), for legal fees up to defined limits, for diplomatic or consular activities, and for extraordinary expenses with prior competent-authority approval. These are not licences that must be individually applied for; they are self-executing if the conditions are met. However, the conditions are strict, and the relevant Council Regulation sets them precisely. Whether a given payment falls inside a derogation is a legal assessment, not a screening exercise.

In our experience, a significant proportion of enquiries we receive about payment authorisations resolve at this stage. The payment is either not prohibited, or it is already covered by a standing derogation. The competent authority application process is reserved for cases that genuinely do not fit those categories.

Step 2: Identify the correct competent national authority

The competent national authority is the body in the relevant Member State designated to grant authorisations under the applicable EU sanctions regime. Because the EU has 27 Member States, each with its own designated authority, selecting the right one is not a formality – a misdirected application will simply be declined as inadmissible, and time will have been lost.

The general rule is that the competent authority is determined by the location of the funds or economic resources subject to the freeze. If the frozen account or asset is held with a financial institution in Germany, the German competent authority applies. If the payment is being processed by a French bank, the French authority is likely competent. In cross-border transactions where funds move through multiple jurisdictions, more than one authority may have a role – though in practice a lead authority is usually identified by the location of the funds to be released.

A secondary consideration is the location of the applicant. Some competent authorities require that the applicant be established in their jurisdiction, or that the direct connection to the frozen asset runs through their territory. When a non-EU business is the applicant, it will typically need to route the application through its EU-established correspondent or the EU financial institution that is directly affected by the prohibition.

Do not underestimate the procedural differences between national competent authorities. Some operate dedicated online portals with standardised forms. Others require a letter-based application addressed to a named unit. Response times, information requirements, and the standard of supporting documentation each authority expects vary considerably. We regularly advise clients on which authority to approach and how to calibrate the application for that authority's known practices.

Step 3: Build the application – what competent authorities require

A well-structured application for a payment authorisation under the EU regime sets out five things: the legal basis for the authorisation (the relevant derogation provision in the Council Regulation), the factual background (who is paying, to whom, for what, and why), the connection to the prohibition (why the payment would be prohibited without the authorisation), the purpose the payment serves (which must match a permitted category), and the supporting evidence for each of those points.

Competent authorities are not investigative bodies for these purposes. They assess what is put before them. An application that asserts entitlement without evidencing it will be refused or returned for supplementation. An application that evidences the purpose but omits to identify the correct legal derogation will stall. In our cross-border practice, we find that the structure and completeness of the initial submission is the single largest variable in processing time.

The supporting documentation package typically includes:

  • A certified copy of the underlying contract or invoice demonstrating the nature and amount of the payment
  • Corporate ownership documentation for the payee, including the full beneficial ownership chain
  • Evidence that the payee or an intermediate counterparty is subject to the asset-freeze measure (this is the competent authority's jurisdictional hook)
  • A clear statement of the purpose of the payment and the derogation relied upon
  • Confirmation from the financial institution that it has blocked or will block the payment pending authorisation
  • In some Member States, a declaration from the applicant confirming the funds will not be made available to the designated person beyond the permitted purpose

The position above covers the standard case. Your facts – the counterparty, the account structure, the transactional purpose, and the regime in play – change the analysis materially. For a review of a specific authorisation requirement, contact Calder & Vance at info@caldervance.com.

Step 4: Manage the competent authority review process

Once an application is filed, the competent authority will review it against the criteria set in the relevant Council Regulation. There is no single EU-mandated processing timeline that applies across all Member States; the applicable country regime sets its own procedural rules. Some authorities publish indicative timelines; others operate informally. Verify the current position of the relevant authority before relying on any stated estimate.

During the review, the competent authority may issue requests for further information. Responding promptly and completely to such requests is critical. A delayed or partial response almost always extends the overall timeline, and in some Member States an unanswered request for information will result in the application being treated as withdrawn. Maintain a dated log of every communication with the authority: what was sent, when, and to whom.

Where an authorisation is granted, it will be conditional. The conditions typically specify the payment amount, the payee, the purpose, and the time window within which the payment must be made. Paying a different amount, to a different payee, or for a different stated purpose than that authorised is a separate breach, even if the authorisation was obtained in good faith. The financial institution processing the payment must be provided with a copy of the authorisation and must retain it in its records.

If a transaction has already been flagged or a payment has already been blocked, an early assessment can preserve options that narrow with time. Contact us at info@caldervance.com for a confidential review.

How does the EU payment authorisation regime differ from OFAC and OFSI?

The EU payment authorisation regime is structurally distinct from the OFAC specific-licence regime and the OFSI licensing regime in three important ways: the granting authority, the ownership and control test that determines who is blocked, and the standard applied to the authorisation criteria.

Under OFAC, a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) is issued centrally by OFAC in Washington, DC. There is one application, one authority, and one administrative process regardless of where the US-person applicant is established. The EU model, by contrast, routes the application through the competent national authority of the relevant Member State. A business with operations in four EU Member States may, in principle, face four different processes for four different payments, each involving a different national authority.

Under OFSI – the UK sanctions authority – the licensing regime is also centralised, with a single competent authority in London. OFSI operates a defined set of licensing grounds, and its published guidance sets out the evidential standard for each. The EU derogation structure is comparable in purpose but expressed differently across the thematic regulations, meaning the specific derogation available for a given payment may vary depending on which EU regime is in play.

On ownership and control: OFAC applies the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) as a mechanical, bright-line test. The EU and UK regimes both apply an ownership-and-control test, but the control limb adds a layer of analysis that can capture entities below the 50 percent threshold if a designated person exercises effective control by other means. A payment authorisation may therefore be required under the EU regime even where a parallel OFAC analysis would not block the transaction.

For a business managing payments across both regimes, the practical implication is clear. A US-law clearance does not confer EU clearance. And an EU authorisation does not resolve a US-law question. Simultaneous cross-regime analysis is not a luxury – it is the minimum standard for a multi-jurisdiction transaction.

For a detailed comparison of the OFAC specific-licence process, see our payment authorisation OFAC guide. For the equivalent analysis under Japanese sanctions, see our payment authorisation Japan guide.

Risk flags: five situations that require immediate escalation

Most payment authorisation cases can be managed through a structured application process. But certain fact patterns alter the risk profile materially, either because they approach the ethical perimeter of what an authorisation covers, because they involve secondary-sanctions risk beyond the EU regime, or because they carry criminal exposure if handled incorrectly.

The following situations require escalation to qualified sanctions counsel before any further action is taken:

  • The payee's ownership structure is unclear or rapidly changing. An authorisation for a payment to a non-designated entity that is subsequently found to be owned by a designated person does not cure the underlying breach. If ownership is uncertain, the application must address it explicitly.
  • The transaction also touches US persons, US-origin goods, or the US financial system. OFAC's secondary-sanctions reach can extend to EU-established entities in certain programmes. An EU authorisation alone does not resolve OFAC exposure. Dual-regime analysis is mandatory.
  • The competent authority has already made a preliminary negative assessment. A refusal or an expression of concern early in the process is procedurally significant. Responding without legal advice risks creating a record that is difficult to manage in subsequent proceedings.
  • The purpose of the payment could be characterised as a benefit to the designated person. Derogations are purpose-specific. A payment nominally for a third party that ultimately benefits the designated person is not covered by the derogation and is not authorisable on that basis.
  • A voluntary self-disclosure (VSD) – a disclosure to a regulator of a suspected breach before a formal investigation – may be required. If a prohibited payment has already been made without authorisation, the question of whether and how to disclose to the competent authority is time-sensitive. Early advice is essential. See also our service on frozen account management for related enforcement considerations.

What businesses commonly misunderstand about EU payment authorisations

A persistent myth in this area is that obtaining a payment authorisation is primarily a banking compliance matter – that it can be handled by the financial institution processing the payment without direct involvement from the business initiating or receiving the funds. This misunderstanding has caused serious compliance failures.

The financial institution has its own obligations under the EU regime. It will block the payment. It may notify the competent authority. But it is not the applicant for the authorisation, and it is not responsible for building the application or managing the process. That obligation rests with the party seeking to make or receive the payment. A business that waits for its bank to obtain the authorisation on its behalf is likely to wait indefinitely – and may find that the payment has been reported as a suspected breach in the interim.

A second common misunderstanding is that an authorisation issued by one Member State's competent authority covers payments processed through financial institutions in another Member State. It does not. The authorisation is jurisdiction-specific. If the payment is re-routed through a different Member State's banking infrastructure after the authorisation is issued, a new assessment is required.

A third misconception is that the EU payment authorisation process is a formality for payments below a certain value. There is no de minimis threshold in EU sanctions law. A small payment to a prohibited counterparty is a prohibited payment regardless of its amount. Competent authorities have granted authorisations for low-value transactions; they have also refused them. The process applies equally.

Related practices

Frequently asked questions

What are the steps to authorise a restricted payment under EU?
The process runs in four stages. First, confirm the payment is prohibited and that no standing derogation applies. Second, identify the competent national authority in the Member State where the funds are held or the payment is being processed. Third, submit a complete application with supporting documentation evidencing the legal basis, the transactional purpose, and the parties involved. Fourth, manage the review, respond promptly to information requests, and comply strictly with any conditions in the authorisation when it is granted. Processing timelines vary by Member State; verify the current position of the relevant authority before relying on any estimate.
What is the most common mistake in payment authorisations?
The most common mistake is submitting an incomplete application to the wrong authority. An application directed to a competent authority that does not have jurisdiction over the frozen funds will be declined. An application that asserts the applicable derogation without evidencing it will be returned. Both errors cost time, and in some Member States a refusal on admissibility grounds creates a record that can complicate a subsequent submission. Structuring the application correctly at the outset – identifying the correct authority, the precise derogation, and the supporting evidence – is more efficient than resubmitting a corrected version. In our experience, working with qualified sanctions counsel on the initial submission substantially reduces the rate of supplementation requests.
How does EU differ from other regimes here?
The primary structural difference is the absence of a single EU-level licensing authority. OFAC in the United States and OFSI in the United Kingdom each centralise the licensing function; an applicant submits to one body regardless of where the transaction occurs. In the EU, the competent national authority of each Member State grants authorisations within its jurisdiction, applying the legal standard set by the relevant Council Regulation. This means that a cross-border EU transaction may engage multiple national authorities. Additionally, the EU ownership-and-control test includes a control limb that can capture entities below the 50 percent ownership threshold, creating prohibitions that would not arise under the equivalent OFAC test.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.