A treasury team at a European trading house identifies an urgent payment to a supplier. The supplier is not itself listed. But the funds must pass through a correspondent account linked to a party that appears on an EU sanctions list. The payment is blocked. Can it be authorised? If so, by whom, and within what timeframe?
EU payment authorisations (case-by-case permissions granted by a competent national authority to release or process a payment that would otherwise be prohibited under EU sanctions) are available for a defined set of purposes, including the satisfaction of prior contractual obligations and humanitarian needs. The governing instruments are the relevant Council regulations, which establish the prohibition, and the delegated competence of Member State authorities, which issue the authorisation. A poorly structured application – or a misreading of which authority has jurisdiction – can result in a refusal that is difficult to reverse.
This guide walks through the procedure step by step: who applies, to which authority, on what grounds, with what documentation, and where applications most commonly fail. It also sets out how the EU position compares with the approach taken by OFAC and OFSI, since many cross-border payments engage more than one regime simultaneously.
What is an EU payment authorisation and when is one required?
An EU payment authorisation is a competent-authority permission that allows a specific payment, transfer of funds, or release of frozen assets that would otherwise be prohibited under a directly applicable EU sanctions regulation. The prohibition typically attaches the moment a counterparty, beneficiary, or intermediary is listed on the EU Consolidated Sanctions List, or where a payment would make funds or economic resources available to such a person.
The trigger for an authorisation requirement is not always a listed counterparty at the end of the chain. It arises equally where a correspondent bank in the payment route is subject to an asset-freeze, or where an entity is caught by the EU ownership and control test – under which a non-listed entity can itself be subject to the asset-freeze prohibition if it is owned or controlled by a listed person. The EU test here turns on both ownership (typically a majority holding) and broader control, meaning that an entity majority-owned or demonstrably controlled by a listed person is treated as subject to the same prohibitions. That extends the class of potential blocking events well beyond the list itself.
Not all prohibited payments qualify for authorisation. The relevant Council regulation for each sanctions programme identifies which derogations are available and on what grounds. Common grounds include: prior contractual obligations entered into before the listing of the relevant person; humanitarian purposes; satisfaction of a judicial, administrative, or arbitral decision; and diplomatic or consular activities. Where none of those grounds apply, the analysis stops and no authorisation is available.
In our experience, businesses frequently conflate the question of whether a payment is prohibited with the separate question of whether an authorisation is available. The two analyses must be conducted in sequence.
Step 1 – Identify the competent authority and confirm jurisdiction
The first step is determining which Member State's competent authority has jurisdiction to receive and decide the application. Under EU sanctions regulations, the authorisation function is delegated to the national competent authority of the Member State in which the relevant funds, accounts, or economic resources are held, or in which the applicant is established. This is not always obvious, and getting it wrong wastes significant time.
Where the frozen funds are held in an account at a bank established in Germany, the German competent authority is the relevant body. Where the applicant is a French company but the funds are held in a Luxembourg account, the Luxembourg authority has jurisdiction over the release, while the French authority may have jurisdiction over aspects of the transaction involving the French entity. Multi-bank, multi-jurisdiction payment chains create concurrent jurisdiction questions that require early legal analysis.
The European Commission maintains a list of Member State competent authorities, but the list captures the authority's identity, not its procedural requirements. Each authority sets its own application form, supporting-document requirements, and processing practice. There is no single EU-wide authorisation form. This divergence between Member States is one of the most consistently underestimated sources of delay.
Where multiple Member State authorities are involved, applicants should map the jurisdictional split at the outset and consider whether to submit simultaneous applications or to sequence them. Coordination between counsel in different Member States is often required at this stage.
Step 2 – Establish the legal ground and assemble the evidence package
Once jurisdiction is confirmed, the applicant must identify which derogation ground applies and build the documentary evidence to sustain it. A bare assertion that the payment is permitted is not sufficient. Competent authorities require evidence that the ground is satisfied in the specific facts of the case.
For the prior-contractual-obligations ground, this means demonstrating that the contract under which the payment obligation arises was entered into before the relevant listing date, that the payment obligation itself flows from that pre-existing contract, and that the funds will be received by or for the benefit of a non-listed person. Where the listed person is the ultimate beneficiary – even partially – the ground may not be available, or the authorisation may be conditional on the listed person's share being segregated and frozen on receipt.
Documentation that competent authorities typically expect includes: a copy of the relevant contract with dates clearly visible; evidence of the payment obligation (invoice, demand, arbitral award); a corporate chart showing the ownership and control structure of all parties; screening evidence confirming the listing status of each entity in the chain; and a concise legal memorandum explaining why the derogation applies. Some authorities also require a declaration that the funds will not ultimately accrue to the benefit of a listed person.
What competent authorities do not respond well to is ambiguity in the ownership chain. If the application does not clearly resolve who owns and controls the payee – and whether any listed person sits in that chain – expect a request for further information. Each round of information requests extends the timeline, often by weeks.
Step 3 – Submit the application and manage the authority's review
Submission requirements differ by authority. Some Member States operate an online portal; others require submission by post or secure email. Confirm the correct channel before submission; an application sent by the wrong route may not be treated as received.
Processing timelines vary considerably between Member States and depend on the complexity of the application and the current workload of the authority. There is no single statutory decision period that applies across all Member States under EU sanctions regulations. Applicants should treat any timeline given by the authority at the outset as indicative, not guaranteed. In our experience, straightforward applications on well-established grounds in Member States with efficient competent authorities can be resolved in a matter of weeks. Complex applications – particularly those involving multi-layered ownership structures or contested factual issues – can take several months.
During the review period, the authority may issue requests for further information. These requests pause the effective review clock. Responding promptly and fully is critical. A partial or delayed response is frequently the reason an otherwise well-grounded application is refused on procedural grounds or takes materially longer than it should.
The position above covers the standard case. Your facts – the counterparty, the payment route, the ground invoked, and the Member State involved – change the analysis. For guidance on your specific situation, contact Calder & Vance at info@caldervance.com.
How does the EU payment authorisation procedure compare with OFAC and OFSI?
The EU procedure differs from the OFAC and OFSI approaches in several respects that matter for businesses managing cross-border payments touching more than one regime. Recognising those differences early avoids the error of assuming that a strategy effective in one jurisdiction will translate to another.
Under OFAC, a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) is issued by OFAC centrally in Washington. There is no state-by-state split of jurisdiction. Applications are submitted to OFAC directly, on a standardised basis, and OFAC retains the right to set conditions on any licence granted. OFAC's processing times for specific licence applications are not fixed by statute and vary by programme and application complexity – from several weeks to over a year in contested or high-volume programmes. OFAC also makes available a range of general licences (standing authorisations that permit defined categories of transactions without a separate application) that can resolve a payment issue without a licence application at all.
Under OFSI in the United Kingdom, a specific licence is similarly issued by a single central authority – OFSI, sitting within HM Treasury. OFSI publishes guidance on the grounds available and its licensing process. Under OFSI's current practice, the target for licensing decisions on straightforward applications is a matter of weeks, though complex applications take longer. Notably, OFSI also applies an ownership and control test, but the UK test is set out in the relevant thematic sanctions regulations and in OFSI guidance, and its application in specific cases can differ from the EU analysis – in particular, the threshold and the control limb are defined in the UK regulations and may produce a different outcome on the same facts.
The critical cross-border implication: a payment may be authorised under EU rules but remain prohibited under OFAC secondary-sanctions risk if the payment involves US-dollar clearing or a US-nexus correspondent. Conversely, an OFAC-licensed payment may still require a separate EU authorisation. The regimes are concurrent, not mutually exclusive. Businesses should never assume that a licence from one authority resolves the position under another.
If a transaction has already been flagged by a bank's compliance system, or a payment has been returned or frozen, an early review preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss your position.
Common pitfalls and risk flags in EU payment authorisation applications
Most EU payment authorisation applications that fail do so for predictable reasons. Understanding those reasons in advance allows applicants to address them before submission rather than after a refusal.
The first and most common pitfall is filing with the wrong authority. Where there is any doubt about which Member State has jurisdiction, take legal advice before filing. A refusal by the wrong authority creates a procedural record that the correct authority may see, and it wastes the time available to resolve the underlying payment obligation.
The second pitfall is asserting a derogation ground without documentary support. Competent authorities are not required to give the applicant the benefit of the doubt. If the contract pre-dating the listing is not exhibited, or the corporate chart does not conclusively show non-listed beneficial ownership, the authority will request further material – or refuse the application.
The third pitfall is failing to address the flow of funds through the application. An authorisation to make a payment does not, by itself, authorise the recipient bank to process it. Where the payment route involves banks in other Member States, or a US-dollar correspondent bank, each institution in the chain may require its own legal analysis and potentially its own authorisation or licence.
A fourth, underappreciated risk is the de-risking response. Even where the legal analysis supports an authorisation application, banks handling the payment may decline to process it as a matter of internal risk policy. Regulatory authorisation reduces but does not eliminate that risk. Applicants may need to engage directly with the processing bank's compliance team, armed with the authorisation, to explain the legal basis and satisfy the bank's own sanctions-policy requirements.
One further risk flag: where the payment involves a party in a jurisdiction that maintains its own sanctions programme – the UAE, Singapore, or Japan – the local regime must be assessed independently. The EU authorisation has no legal effect in those jurisdictions.
The myth that EU authorisations are formalities
A persistent misunderstanding among treasury and compliance teams encountering this issue for the first time is that a payment authorisation from an EU competent authority is essentially a formality – a procedural box to tick once the commercial necessity of the payment has been established. That is incorrect, and acting on it causes significant damage to applications.
Competent authorities exercise a substantive discretion. They are required to assess whether the grounds for the derogation are genuinely met on the specific facts presented. They do refuse applications. They do impose conditions on authorisations that are granted. And they do notify other Member State authorities and, in some cases, the European Commission of authorisations issued, which creates a compliance record. In our cross-border practice, we regularly advise clients who have received a refusal and are considering whether to appeal or to restructure the application on better-evidenced grounds.
The appeal route from a refusal depends on the Member State. In most jurisdictions it will involve administrative review by a superior authority or, ultimately, challenge before the national courts. The EU General Court has jurisdiction over the legality of the underlying Council regulation and Council decisions, but it does not hear appeals from national competent authority decisions on individual applications. Those remain within national judicial systems. This is a distinction that matters for clients considering their options after a refusal.
We have acted for businesses and financial institutions where an initial application was refused, and where a reworked submission – addressing the specific reasons for refusal, supplemented with additional documentary evidence – succeeded on re-application. Getting the application right the first time is consistently more efficient than correcting a refusal.
Related practices
- Frozen account management – BIS/EAR – managing frozen accounts and licensing strategies under US export-control rules.
- Payment authorisations under EU: advanced issues – deeper analysis of complex multi-party and multi-regime payment scenarios.
- Payment authorisations under the Japan regime – procedure and practical steps for restricted payments under Japan's sanctions rules.