A trading company in the Netherlands wins a framework agreement with a distributor whose parent group has complex ownership. The compliance team screens the parent. No match. Then a second-tier shareholder surfaces – and that name sits on the EU Consolidated List (the master list of persons, entities, and bodies subject to restrictive measures under EU Council regulations). The contract is already countersigned. What now?
As of August 2026, EU sanctions risk assessment requires a structured, regime-specific process: map the transaction and counterparty, apply the EU ownership-and-control test, check all applicable Council regulations and the EU Consolidated List, identify the prohibitions and exceptions that govern, and document the outcome. The EU test looks at both ownership and control – a wider net than OFAC's mechanical 50 percent ownership rule – and that distinction changes the analysis on a significant proportion of cross-border deals.
This guide walks through the assessment step by step, flags where EU rules diverge from OFAC and OFSI, and explains when the matter moves beyond in-house resource.
Step 1: Define the scope of the assessment
A sanctions risk assessment under EU law begins by identifying every element of the transaction that could attract the prohibitions in the relevant Council regulation: the parties, the goods or services, the payment route, and the jurisdictions touched. EU sanctions have extraterritorial reach (the principle that EU-law prohibitions bind EU persons and entities wherever they operate, and non-EU persons for certain conduct connected to the EU) that is often underestimated. An EU-incorporated entity that conducts business outside the EU still carries full exposure to EU Council regulations.
The starting questions are practical. Who are the direct counterparties? Who controls or owns them? What goods or services are being transferred, and do they appear on any EU control list for dual-use items or sector-specific restrictions? Which payment institutions are involved, and are they EU-based? Do any transit or transshipment routes pass through EU territory or involve EU financial institutions?
Defining scope first prevents the common error of running a superficial name-check and treating it as a complete assessment. Name-screening is one element. It is not the whole exercise.
Step 2: Apply the EU ownership-and-control test
Under EU Council regulations, funds and economic resources must be frozen not only for listed persons themselves but for entities owned or controlled by a listed person – and control is assessed in substance, not just on share registers. This is the most operationally significant difference between the EU approach and the OFAC 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked, regardless of control factors).
Under OFAC, the test is principally arithmetic: aggregate the ownership percentages held directly or indirectly by blocked persons; if they reach or exceed 50 percent, the entity is blocked. The question of who runs the entity is secondary. Under EU rules, a listed person may hold less than 50 percent equity and still control an entity through board appointments, veto rights, contractual arrangements, or economic dependence. If that control is established in substance, the entity's assets are caught.
In our cross-border practice, transactions involving closely held businesses in opaque jurisdictions are routinely cleared by automated name-screening without any ownership-and-control mapping. That gap is where EU enforcement finds its cases. Have you obtained a corporate structure chart, reviewed the shareholder agreement, and considered whether any listed person can direct the entity's decisions?
The UK position under OFSI uses a similar ownership-or-control standard, so an assessment that is adequate for EU purposes will largely serve OFSI requirements too – though the two regimes sometimes list different persons, so both lists must be run separately.
Step 3: Identify the applicable Council regulations and prohibitions
EU sanctions are not a single code. They are a collection of regime-specific Council regulations, each built on a Council Decision, each targeting a different set of persons, sectors, or activities. The prohibitions in each regulation differ in scope, and the exceptions and derogations (standing or case-by-case authorisations permitting otherwise prohibited transactions) that apply under one regulation may not apply under another.
The assessment must identify which regulations are potentially engaged. That means checking the EU Consolidated List for each counterparty and beneficial owner, then reading the applicable regulation to understand the precise scope of the prohibition. A financial-services prohibition in one regulation may catch correspondent banking. A separate goods prohibition in another may catch the underlying commodity. Both may apply to the same transaction.
Sector-specific restrictions add a further layer. Several EU regimes impose prohibitions not on specific listed persons but on entire categories of transaction – certain financial instruments, access to capital markets, or specific goods categories – regardless of whether the direct counterparty appears on any list. These sectoral restrictions require a separate review of the goods, services, and financial products involved.
This is the step where in-house teams most commonly under-resource the assessment. We regularly advise clients who have screened counterparties correctly against the Consolidated List but have not identified that the transaction falls within a sectoral restriction in the same regulation.
How does the EU approach differ from OFAC and OFSI?
EU, OFAC, and OFSI sanctions share a common objective but differ materially in legal structure, list scope, and the mechanics of the ownership test – and those differences determine both the assessment methodology and the compliance risk a business carries.
OFAC administers US sanctions under statutory authority including IEEPA. Its primary tool is the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The SDN List is supplemented by sector-specific sanctions programmes that impose narrower restrictions on certain activities rather than a full asset-freeze. OFAC's ownership rule is principally a 50 percent aggregate ownership test; control factors are relevant but the ownership arithmetic is decisive in most cases. OFAC also administers secondary sanctions (US measures that can penalise non-US persons for certain conduct with a sanctioned counterparty, even without a US nexus), which extend US reach far beyond the US person perimeter.
OFSI administers UK financial sanctions under the Sanctions and Anti-Money Laundering Act. OFSI's list is the UK Sanctions List, which diverged from the EU list following the UK's departure from the EU. OFSI's ownership-or-control test mirrors the EU standard more closely than OFAC's – both look at substance rather than arithmetic alone. OFSI's enforcement posture has become markedly more active, and its reporting obligation – requiring a relevant firm to report knowledge or reasonable cause to suspect that a person is a designated person, or that a sanctions breach has occurred – is a live compliance obligation with a short reporting window under current OFSI guidance.
The practical consequence for a business operating across all three regimes is that a transaction may be permissible under EU rules (because a relevant derogation applies), prohibited under OFAC (because a secondary-sanctions restriction bites), and in a grey zone under OFSI pending specific guidance. The stricter prohibition governs in each case. A multi-regime risk assessment must map this table before a decision is taken.
Step 4: Document the assessment and escalation triggers
Documentation is not a bureaucratic afterthought. Under EU rules, a well-documented assessment is the primary evidence that an entity exercised due diligence and did not deliberately or negligently breach a prohibition. It is also the foundation for any subsequent voluntary self-disclosure or VSD (a proactive disclosure to a competent authority of a potential breach, typically treated as a mitigating factor in enforcement) if a breach is later identified.
The assessment record should capture: the date of the assessment, the lists and sources consulted, the ownership-and-control analysis with the underlying evidence (corporate documents, shareholder registers, beneficial ownership disclosures), the regulations reviewed and the specific prohibitions and derogations considered, the conclusion reached, and the name of the person who approved it. Where a conclusion depends on a judgment call – for example, whether a contractual arrangement amounts to control – the reasoning should be set out in full.
Escalation triggers should be defined in advance. A potential match on the Consolidated List, an ambiguous ownership chain, a sectoral restriction in the applicable regulation, or a transaction with a non-EU counterparty that creates secondary-sanctions exposure under OFAC – each of these should have a defined escalation route to senior compliance resource or external counsel.
Record-keeping obligations under EU law require that relevant documentation be retained for a defined period. While the specific retention period varies across Member State implementing law and the applicable regulation, practitioners consistently recommend retaining transaction-related sanctions documentation for at least five years – and in some circumstances longer, to align with the most conservative position across applicable regimes. Verify the current requirement for your specific situation before relying on any particular figure.
Step 5: Apply derogations and consider licensing where the assessment flags a prohibition
If the assessment identifies that a transaction is, or may be, caught by a prohibition in a Council regulation, the next step is to determine whether a derogation or authorisation route is available. EU Council regulations typically contain both standing derogations (which permit defined categories of transaction without a case-by-case application) and specific authorisation mechanisms (which require a competent authority, usually a national authority in the relevant Member State, to grant a licence for the transaction).
Standing derogations in EU regulations may cover, for example, the release of funds to satisfy a pre-existing court or arbitration judgment, payments due under contracts concluded before the designation of the relevant party, or certain humanitarian transactions. The precise scope of each derogation varies by regulation, and the conditions attached to them are strictly construed. An assessment that concludes a derogation applies without checking the conditions in detail carries residual risk.
Where no standing derogation applies and a specific authorisation is needed, the application is made to the competent authority of the Member State through which the EU person is operating. Timelines for authorisation decisions vary by Member State and by the complexity of the application. In our experience, under-resourced applications – those that do not set out the precise legal basis for the authorisation, the factual basis, and the conditions the applicant will observe – are the applications that face delay or refusal.
The position under the EU differs from OFAC here. OFAC issues both general licences (standing authorisations that permit a defined category of transactions without a separate application) and specific licences (case-by-case authorisations). OFAC administers both centrally. EU authorisations are decentralised to Member States, creating variance in process and speed across the 27 jurisdictions. A business with operations in multiple Member States may need to co-ordinate applications across more than one competent authority for the same transaction.
Risk flags: when does the assessment require external counsel?
Most sanctions risk assessments under EU rules can be managed in-house when the transaction is straightforward, the counterparties are in low-risk jurisdictions, and no listing or sectoral restriction flags on the relevant check. The assessment tips into specialist territory when any of the following appears.
First, a potential or confirmed match on the EU Consolidated List, or on the SDN List or UK Sanctions List for a transaction that also has US or UK dimensions. Name matches require legal analysis of the listing, the applicable prohibitions, and whether any derogation or authorisation route is open. A false positive from a screening tool requires documented clearance. A true match requires immediate legal advice.
Second, an ambiguous ownership or control structure. Where a counterparty has layered ownership through multiple jurisdictions, uses nominee arrangements, or where a shareholder agreement confers veto or board-appointment rights on a person of concern, the ownership-and-control analysis cannot be done by reading a corporate extract alone. It requires legal judgment about substance.
Third, a transaction involving goods or services that may engage EU dual-use export controls under the EU dual-use regulation as well as financial sanctions. The interaction between the two regimes requires a combined assessment.
Fourth, any transaction where secondary-sanctions risk under OFAC may arise. EU persons are not the primary targets of OFAC secondary sanctions, but the risk is real for businesses with US dollar payment flows, US-person counterparties, or US-incorporated affiliates. If secondary-sanctions exposure appears, the assessment must be conducted with US-qualified advice alongside the EU analysis.
A common myth in in-house compliance teams is that EU sanctions are less strictly enforced than OFAC – and that a robust compliance effort is therefore less urgent. That position is no longer reliable. Enforcement competence in the EU sits with Member State authorities, and several of those authorities have significantly increased both the frequency and the scale of enforcement actions in recent years. The trend is toward higher penalties and, in serious cases, criminal referral. Treating EU sanctions as a secondary compliance priority is a risk posture that the enforcement record no longer supports.
The position above covers the standard assessment workflow. Your facts – the counterparty structure, the goods involved, the payment route, and the regimes in play – change the analysis at every step. For an assessment of your exposure under EU sanctions, contact Calder & Vance at info@caldervance.com.
Related practices
- Compliance audit and testing – structured testing of screening logic and programme design across regimes
- Sanctions risk assessment under OFAC – step-by-step guide to the US regime and its extraterritorial reach
- OFAC sanctions risk assessment: ownership and control – deeper analysis of the 50 percent rule and aggregation issues