A multinational procurement team is reviewing a new distribution partner in Central Asia. The entity does not appear on any list. But two of its directors sit on the boards of companies that do. The compliance officer asks: is this relationship permissible under EU sanctions, and what else do we not know? That question defines the whole problem of sanctions risk assessment under an EU regime.
A sanctions risk assessment under the EU regime requires a structured review of counterparty identity, ownership and control chains, the applicable Council regulations, and the business's exposure to designated persons or restricted activities. As of mid-2026, the EU maintains a substantial number of distinct sanctions regimes, each administered through directly applicable Council regulations and enforced by national competent authorities. The assessment is not a one-time screen; it is an ongoing analytical process.
This guide walks through each stage of that process: identifying the governing authority, mapping exposure, applying the ownership and control test, addressing cross-border divergence, spotting the risk flags that practitioners most frequently encounter, and knowing when external counsel is warranted.
Step 1 – Identify the governing authority and applicable Council regulation
The starting point of any EU sanctions risk assessment is establishing which Council regulation governs the counterparty, the goods, or the transaction in question. EU sanctions are adopted as Council Decisions – which set the political framework – and as directly applicable Council regulations that impose the binding legal obligations on natural and legal persons within EU jurisdiction.
Each thematic or geographic programme is a distinct instrument. A business may face simultaneous exposure under more than one. Relevant national competent authorities – the body responsible for licensing, enforcement, and interpretation in each member state – are named in the relevant regulation and on the EU's official sanctions map. In our experience, firms that treat "EU sanctions" as a single, uniform body of rules routinely misidentify which prohibitions apply and which licences are available.
The EU also maintains a consolidated list of designated persons and entities. Screening against that list is necessary but not sufficient. The regulation's prohibitions extend beyond the listed names themselves; they cover funds, economic resources, and specific activities. Identifying the regulation is the threshold step before any further assessment is meaningful.
Step 2 – Map ownership and control chains
Under EU sanctions, a non-listed entity can be caught through the ownership and control provisions of the relevant Council regulation, which extend the prohibitions to entities owned or controlled by a designated person. This is where the EU regime diverges most sharply from the US position – and where the highest-risk gaps in a standard screening programme appear.
OFAC applies a bright-line mechanical test: any entity that blocked persons own 50 percent or more in the aggregate is itself treated as blocked, with no further analysis of how control is exercised. The EU ownership threshold is set in the relevant Council regulations; the EU also extends the prohibition to entities controlled by a designated person, regardless of the precise ownership percentage. Control is assessed by reference to factors including board composition, voting rights, contractual rights to direct business decisions, and the ability to appoint management. That is a materially wider test.
What does this mean in practice? An entity in which a designated person holds a minority stake may still be caught under EU rules if that person exercises de facto control. A detailed ownership and control mapping exercise – going beyond the first ownership layer and examining governance documents, shareholder agreements, and board structures – is therefore an essential component of any EU sanctions risk assessment. We regularly advise clients whose automated screening tools fire only on direct ownership, missing intermediate holding structures entirely.
The UK regime under OFSI takes a comparably broad approach to control. Where a business is subject to both EU and UK obligations, the stricter prohibition governs in each jurisdiction. Any assessment must therefore run the ownership and control analysis against both frameworks simultaneously.
Step 3 – Assess sectoral and activity-based prohibitions
EU sanctions are not limited to asset freezes and travel bans against named persons. Many programmes include prohibitions on specific sectors, activities, goods, or services. A counterparty that is not itself designated may still sit within a prohibited sector, or a proposed transaction may involve goods or services whose supply is restricted by the relevant regulation.
Sectoral prohibitions can cover financial services, capital markets access, the provision of certain professional and technical services, specific categories of goods defined by reference to controlled-goods lists, and maritime transport. The analysis of whether a given transaction engages a sectoral prohibition is separate from – and additional to – the counterparty screening exercise.
Goods-based restrictions interact with EU dual-use export-control rules. Where a transaction involves the transfer of controlled items, the business must assess both the sanctions prohibition and the export authorisation requirement under the EU dual-use rules. These are distinct legal instruments administered by different national authorities, but the compliance analysis must address both. For more on that intersection, see our related practice on sanctions risk assessment and export-control classification.
In our experience, sectoral restrictions are the category most frequently overlooked by businesses whose compliance programmes were designed around counterparty screening rather than transaction and product analysis.
Step 4 – Apply the cross-regime comparison and identify extraterritorial exposure
An EU-only assessment is rarely sufficient for a cross-border business. Three additional dimensions of exposure arise routinely.
First, secondary-sanctions risk under US law. OFAC administers secondary-sanctions programmes that can reach non-US persons transacting with certain designated persons or in certain sectors, even where the transaction has no US nexus in the form of a US person, US goods, or a US dollar clearing leg. A European business that concludes its EU compliance is satisfied may still face significant reputational and correspondent-banking risk if its counterparty is subject to a US secondary-sanctions designation. The assessment must at minimum flag this risk and advise whether a parallel US check is required.
Second, UK sanctions divergence. Since the UK's departure from the EU single market, the UK has maintained and developed its own sanctions regime under the Sanctions and Anti-Money Laundering Act. The UK list and the EU list are not identical. Designations have been made by one authority but not the other. A business that is subject to both regimes – because it has UK operations, UK persons in management, or transactions involving UK financial institutions – must screen against both and apply the analysis that produces the stricter result.
Third, UN Security Council obligations. The EU gives effect to UN Security Council-mandated sanctions through its Council regulations. Where a designation is UN-mandated, it binds all UN member states, including those whose own autonomous sanctions regimes are less developed. This matters for businesses with supply chains or distribution networks in jurisdictions outside the major Western regimes.
The position above covers the standard case. Your facts – the counterparty jurisdiction, the nature of the goods, the financial flows, the regime in play – change the analysis in ways that a generic guide cannot anticipate. For a cross-border assessment that addresses your specific exposure, contact Calder & Vance at info@caldervance.com.
Step 5 – Identify risk flags and document the assessment
A well-constructed EU sanctions risk assessment is both an analytical exercise and a documented record. Competent authorities reviewing a firm's compliance expect to see evidence that the assessment was conducted, that its scope was appropriate to the risk, and that any adverse findings were escalated and resolved. Documentation is not optional.
The risk flags that most frequently arise in practice include the following.
- Opaque ownership chains. Beneficial ownership structures that pass through multiple layers of holding companies, particularly in jurisdictions with limited public-registry disclosure, are a primary indicator of potential exposure that standard screening misses.
- Director and board overlap. The scenario in the opening of this guide – directors serving on the boards of designated entities – is a genuine red flag. Designation of an individual extends to economic resources under their control.
- Unusual payment routing. Transactions routed through third-country intermediaries without a clear commercial rationale merit enhanced scrutiny, particularly where the routing passes through a jurisdiction in which there is a designated entity with common ownership.
- Goods with dual-use characteristics. Any shipment of items that appear on the EU dual-use list triggers a parallel export-control assessment, regardless of the sanctions position.
- Last-minute counterparty substitution. A change of contracting party close to the point of performance, particularly where the substitute entity's ownership is difficult to verify, is a structural risk indicator that warrants enhanced due diligence.
Record keeping is a formal obligation under most EU member-state implementations of EU sanctions. The retention period applicable in a given member state should be verified, but periods of five years are common across the regimes. The assessment record should include the screening methodology, the date of the search, the results, any escalation decision, and the rationale for proceeding or declining.
Step 6 – Manage ongoing monitoring and trigger-based reassessment
EU Council regulations are amended with regularity. New designations are published in the Official Journal. General authorisations are granted, modified, and withdrawn. A sanctions risk assessment conducted at contract inception may be superseded before performance is complete.
An effective compliance programme builds in ongoing monitoring at three levels. At the counterparty level, automated name-screening should be configured to run against updated lists on a defined frequency and to generate an alert whenever a counterparty or connected person appears on a new or amended designation. At the transaction level, the programme should define the events that trigger a fresh point-in-time assessment: material changes to ownership, a change of jurisdiction in the supply chain, an escalation in the relevant sanctions programme. At the programme level, the business's risk assessment methodology should be reviewed periodically – not only when a problem arises, but as a planned control.
Have you stress-tested your monitoring configuration against a scenario where a counterparty is designated mid-contract? Businesses that have not done so frequently discover that their processes handle initial screening well but have no clear protocol for the mid-relationship designation event.
Our compliance practice regularly advises firms on how to design monitoring controls that are proportionate to the risk profile of their counterparty base and their sector. The objective is a programme that generates actionable alerts rather than noise. For a practical review of how your current monitoring controls perform, see our service on compliance audit and testing.
How the EU assessment process compares with OFAC and OFSI
For a business running parallel US and UK assessments alongside the EU process, the most significant structural difference is the basis on which non-listed entities are caught.
Under OFAC, the rule is quantitative and ownership-focused: aggregate 50 percent or more ownership by blocked persons triggers the prohibition automatically. Control, in the sense of the ability to direct the entity's affairs, is not independently sufficient to catch a non-listed entity where ownership stays below that threshold. The analysis is more tractable but narrower.
Under the EU and UK regimes, the ownership test is supplemented by a control test that is qualitative and fact-specific. An entity may be caught even where no designated person's ownership share reaches any particular percentage, if the designated person demonstrably controls the entity's decisions. This increases the compliance burden significantly, because it requires a qualitative judgement about governance rather than a mathematical calculation from a share register.
A practical consequence of that divergence: a transaction that clears the OFAC 50 percent ownership check may still be caught under EU rules. Businesses that run only a US-standard ownership analysis and treat the EU as equivalent create a genuine compliance gap. The correct approach is to run each regime's test on its own terms and, where the tests produce different results, to treat the stricter prohibition as governing for any jurisdiction in which that regime applies.
Switzerland (SECO), Canada (Global Affairs Canada), and Australia (DFAT) each maintain autonomous sanctions regimes. In our cross-border practice, we regularly encounter businesses that have addressed OFAC, OFSI, and the EU but have not assessed whether their supply chain or counterparty base engages the Swiss, Canadian, or Australian regimes. Where any nexus exists with those jurisdictions, the assessment scope should extend accordingly.
If a transaction has already been flagged by a bank or a compliance escalation has reached your desk, the range of available options narrows over time. An early review of the position – before a commitment becomes irrevocable – is consistently more effective than a reactive response. Contact us at info@caldervance.com for a confidential assessment.
Common misconceptions in EU sanctions risk assessment
One assumption that we encounter repeatedly in practice: that an entity's absence from the EU consolidated list is sufficient to confirm that a transaction is permissible. It is not. The consolidated list identifies designated persons. It does not reflect the full scope of the prohibitions in the relevant Council regulation, which may additionally restrict the supply of goods, services, or funds to entire sectors, categories of entities, or jurisdictions, irrespective of whether the specific counterparty is named.
A second misconception is that a sanctions risk assessment is a one-person function, or that it can be delegated entirely to an automated screening tool. In our experience, the assessments that have successfully withstood regulatory scrutiny are those where a qualified person has reviewed the tool's output, applied judgement on adverse media and ownership-chain findings, and produced a documented decision. Automated screening is a necessary component; it is not a substitute for the analytical layer that determines whether a hit is a genuine match and whether the broader transaction risk has been addressed.
A third myth worth addressing: that a general authorisation automatically covers all transactions in a given category. General authorisations under EU sanctions are narrowly defined. They typically contain specific conditions – as to the purpose of the transaction, the parties, the goods, and the documentation to be maintained – that must be satisfied for the authorisation to apply. Relying on a general authorisation without verifying that all conditions are met is a significant compliance error.
Related practices
- Compliance audit and testing – systematic review of your screening controls and risk methodology
- EU sanctions risk assessment – advanced guide – deeper analysis of ownership mapping and licensing options