A mid-sized European trading group had operated across four EU member states for over a decade. Its compliance programme had grown organically – built in layers, never stress-tested as a whole. When a corporate restructuring brought two additional subsidiaries into scope, the group's general counsel commissioned an internal review. What that review uncovered reshaped the entire programme.
A compliance audit and testing EU case of this kind typically reveals that programmes which function adequately in isolation fail at the seams: gaps in ownership-and-control mapping, inconsistent screening logic, and undocumented escalation paths are the common failure modes. The governing authority is the relevant EU Council regulation, enforced at member-state level, with liability that can attach to the entity and to responsible individuals. As of July 2026, EU sanctions law imposes strict asset-freeze and dealing prohibitions that leave no margin for procedural error.
This case comment sets out how the matter arose, what the audit revealed, how the legal and compliance questions were resolved, and what the outcome means for similar cross-border businesses operating under the EU regime.
Background: how a structural gap became a compliance problem
The group's core business involved sourcing and distributing industrial components across EU and non-EU markets. Each operating entity maintained its own screening subscription and ran its counterparty lists independently. There was no group-level consolidation of screening outputs and no shared ownership-and-control methodology.
The restructuring introduced two subsidiaries incorporated in different member states. One had existing commercial relationships with counterparties in jurisdictions subject to EU thematic sanctions regulations. The other held a minority stake in a joint venture whose ultimate beneficial ownership had not been reviewed since the joint venture was formed.
The general counsel's initial concern was narrow: did the new subsidiaries need to be added to the group's screening platform? In our experience, that question almost always opens a wider one. Here, it opened several.
The internal review flagged that one counterparty in the joint-venture structure had a shareholder whose name appeared on the EU Consolidated Sanctions List. The match had not been caught because the subsidiary's screening tool was configured to search only direct contractual counterparties, not shareholders of those counterparties. The gap was procedural, not intentional – but under the relevant Council regulation, that distinction affects penalty mitigation, not the question of whether a prohibition applies.
What is the EU ownership and control test, and why did it matter here?
Ownership and control under EU sanctions law is the test that determines whether a non-listed entity is caught by the asset-freeze prohibitions because a designated person owns or controls it. The EU test is broader than a mechanical percentage threshold: it looks at both ownership stakes and the ability to exercise decisive influence over the entity's decisions.
In this matter, the joint-venture shareholder held less than half of the voting rights. That meant the entity was not automatically caught by the ownership limb. But the shareholder's rights under the joint-venture agreement – including veto rights over material commercial decisions – raised a genuine question under the control limb. Whether those rights constituted "decisive influence" was a legal question that required analysis of the agreement against the EU guidance on ownership and control test criteria.
This is precisely where the EU and OFAC approaches diverge. Under OFAC's 50 percent rule (the rule that treats any entity owned 50 percent or more in the aggregate by blocked persons as itself blocked), the analysis is predominantly mechanical. A sub-50-percent stake, absent aggregation that crosses the threshold, generally does not trigger OFAC's rule. The EU control test adds a qualitative layer that can capture minority stakes accompanied by structural rights. That divergence is material for any group operating across both regimes.
In the UK, OFSI applies a similarly broad ownership-and-control approach under the relevant thematic regulations made under the Sanctions and Anti-Money Laundering Act ("SAMLA"). A business that screens only against the OFAC threshold may therefore satisfy US requirements while remaining exposed under EU and UK rules. We regularly advise on this three-way divergence, and it consistently surprises compliance teams who have mapped only one regime.
What the compliance audit revealed: five structural findings
Once instructed, we conducted a structured audit of the group's compliance programme across all six entities. The audit was organised around a five-element standard: governance and accountability, risk assessment, policies and procedures, testing and monitoring, and training. That standard reflects the approach applied by EU member-state enforcement authorities when assessing whether a compliance programme is adequate to support a mitigation argument in enforcement proceedings.
The five findings were as follows.
- Screening scope: three of the six entities screened only direct contractual counterparties. Shareholders and beneficial owners of counterparties were not systematically checked. The joint-venture gap traced directly to this deficiency.
- Ownership-chain documentation: the group held no central register of ownership-and-control assessments for counterparties above a defined materiality threshold. Individual business units made their own judgments, with no review trail.
- Escalation paths: the group's policies identified who should receive a screening alert, but did not specify the timeline for escalation or the standard for a "no-action" determination. In practice, alerts were sometimes resolved by the business team that generated the transaction, with no compliance sign-off.
- Testing cadence: the programme had never been subject to independent testing. Periodic reviews had been conducted by the same compliance officer who designed the procedures – an arrangement that limits the effectiveness of the review.
- Cross-regime mapping: the group's procedures referenced EU sanctions obligations but did not address the interaction with OFSI rules or the extraterritorial reach of US secondary-sanctions measures. Given the group's non-EU operations, both were relevant.
None of these findings indicated wilful non-compliance. All of them indicated a programme that had not kept pace with the group's own growth and restructuring – a pattern we have seen repeatedly in businesses that have expanded through acquisition rather than organic growth.
How was the EU issue resolved?
The resolution turned on two parallel tracks: the legal exposure question and the programme remediation question. Both required prompt action.
On the legal exposure question, we conducted a detailed analysis of the joint-venture agreement to assess whether the designated shareholder's veto rights constituted "decisive influence" under EU sanctions standards. The analysis concluded that, on the specific wording of the agreement, the rights fell short of the control threshold – they were protective rights designed to preserve the shareholder's economic interest rather than rights that gave the shareholder authority over the entity's commercial strategy. That conclusion was reached on the facts; a differently drafted agreement would have produced a different answer.
The counterparty's own counsel confirmed that the designated shareholder had divested its interest prior to the designation date, though the corporate register had not been updated. The group obtained and retained documentary evidence of the divestment. That evidence was material: it established that no prohibited dealing had taken place, because the relationship at the relevant time was not with a designated person or entity caught by ownership and control.
On the programme remediation question, we worked with the group's compliance function to redesign the screening configuration, the ownership-and-control assessment methodology, and the escalation and testing protocols. The redesign was phased over a defined period to allow for staff training without disrupting operational activity.
The position above covers the standard path through a matter of this kind. Your facts – the structure of the relevant agreement, the date of designation, the jurisdiction of each entity – change the analysis, sometimes fundamentally. If a similar question has arisen in your business, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com.
Risk flags: when does a compliance gap become a reportable matter?
One of the questions the group's general counsel asked early in the engagement was whether the screening gap required notification to the relevant member-state competent authority. That question does not have a uniform answer across the EU.
EU sanctions regulations impose obligations on persons who hold funds or economic resources belonging to, or for the benefit of, a designated person. The obligation to notify a competent authority arises in that context. Where a screening gap has not resulted in the actual holding or dealing with blocked assets – because the underlying facts show that no designated person was involved – the notification obligation does not automatically arise. The analysis is fact-specific.
However, there is a separate and important consideration. Several EU member states have adopted regulations requiring financial institutions and other obliged entities to report information relating to their sanctions obligations proactively, including information about apparent or suspected breaches. The scope and trigger conditions of those obligations vary by member state. A group operating across multiple member states must therefore assess its notification position in each jurisdiction individually, not as a single EU-wide question. That is a point compliance teams frequently miss.
What are the risk flags that indicate a matter has moved from an internal compliance issue to one requiring external legal advice?
- A screening match that cannot be resolved as a false positive within a short period.
- Any indication that funds or assets have already moved in connection with a potentially designated counterparty.
- A member-state competent authority making contact about a transaction or relationship.
- A freeze instruction or enquiry from a bank or payment service provider citing sanctions.
- Evidence that an ownership or control question was flagged internally and not escalated.
If a transaction has already been flagged, or a filing has been refused, an early review of the facts can preserve options that narrow with time. We advise clients to treat any unresolved screening match as a legal question first and an operational question second. Contact us at info@caldervance.com for a confidential review.
The myth: a compliance programme is either compliant or non-compliant
A recurring assumption in this area is that a sanctions compliance programme either meets the standard or does not – that there is a clear line, and a business knows which side of it it stands on. In our practice, that assumption is almost always incorrect, and it is the reason many programmes go untested for too long.
EU sanctions enforcement operates on a spectrum. Member-state competent authorities assess programmes against criteria that include the quality of governance, the depth of the risk assessment, the appropriateness of the procedures to the business's specific risk profile, and the effectiveness of testing and monitoring. A programme that ticks the formal boxes but has never been independently tested will score differently in an enforcement review than a programme that has been audited, gap-remediated, and retested.
The practical consequence is that an audit does not create exposure – it reduces it. A business that discovers and corrects a gap before a regulator does is in a substantially stronger position than one that corrects the gap after a regulator enquiry begins. The group in this matter avoided a notification issue because the facts resolved in its favour. It improved its mitigation position for the future because the programme was remediated before any enforcement contact occurred.
Compliance testing is not a sign of weakness in a programme. It is the mechanism by which a programme demonstrates its own strength.
Cross-border dimension: Australia, OFAC, and the EU in the same programme
The group's non-EU operations brought two additional regimes into scope. The subsidiary operating in the Asia-Pacific region was subject to the Australian autonomous sanctions regime, administered by the Department of Foreign Affairs and Trade ("DFAT"). Australia's sanctions programme applies to persons and entities on the Australian Autonomous Sanctions list and imposes asset-freeze and supply prohibitions that broadly parallel the EU structure but are administered under distinct national instruments. The screening and ownership-and-control methodology applicable to the Australian regime requires separate calibration.
At the same time, several of the group's components were sourced from US-origin technology. That brought BIS export-control rules and, in certain transaction scenarios, OFAC secondary-sanctions risk into play. Secondary-sanctions risk – the risk that a non-US person's conduct in a non-US transaction triggers US consequences because of the transaction's connection to a US-sanctioned regime – is not neutralised by full compliance with EU and Australian rules. The regimes are parallel; compliance with one does not discharge obligations under another.
We have acted for clients operating across all three of these regimes. The critical point is that the ownership-and-control analysis must be conducted separately for each regime, and the strictest applicable prohibition governs the transaction in each jurisdiction. A transaction permitted under EU rules may be prohibited under Australian rules, or vice versa. The programme must be designed to catch the most restrictive position, not the most permissive.
For clients managing EU and Australian compliance obligations in parallel, our work on the compliance audit and testing service for Australia describes the specific requirements of the DFAT regime and how it interacts with EU and OFAC obligations.
Lessons for similar businesses: five practical steps
The group's experience is not unusual. The five steps below reflect what we advise businesses with comparable risk profiles to prioritise.
- Map the full ownership chain of your material counterparties, not just the direct contracting party. The EU control test can reach minority shareholders with structural rights. Screening the counterparty name is the starting point, not the end point.
- Conduct an independent audit of your screening configuration. Confirm that the tool's scope, update cadence, and match-resolution procedures reflect your actual risk profile. A tool configured for one business structure may underperform after a merger or restructuring.
- Document escalation paths and maintain a review trail. Every screening match, and every no-action determination, should be recorded with a timestamp and a named decision-maker. Undocumented decisions cannot support a mitigation argument.
- Test across regimes, not just the primary one. If your business touches the EU, UK, and Australian regimes, the programme must be tested against all three. A programme that satisfies one regime may be materially deficient under another.
- Treat a restructuring or acquisition as a compliance trigger. Each change to the corporate structure, each new counterparty jurisdiction, and each new product line changes the programme's risk profile. A periodic review that follows the business calendar – rather than a fixed annual date – is more likely to catch gaps before they become problems.
For a comparison of how a similar fact pattern unfolded under an OFAC-governed engagement, see our case comment on the OFAC compliance audit and testing matter. For a broader look at how cross-border programmes are designed from the ground up, see our case comment on cross-border compliance programme design.
Related practices
- Compliance audit and testing – Australia – assessing and testing sanctions programmes under the Australian autonomous sanctions regime
- Compliance audit and testing – OFAC matter – how a comparable screening gap was identified and resolved under the US regime