Calder & Vance International Sanctions & Compliance Counsel

Cross-Border Transactions & Diligence · EU

An EU matter: sanctions due diligence in M&A in practice

A European private equity firm is three weeks from signing on a mid-market acquisition. Its target – a manufacturing group with operations across multiple EU member states – has passed preliminary screening. Then a revised ownership analysis surfaces a minority stake held by a trust whose ultimate beneficial owner appears on the EU Consolidated List. The signing timetable collapses. Counsel is instructed on a Thursday. The regulatory position needs to be confirmed before Monday.

Sanctions due diligence in M&A under the EU regime requires a systematic review of ownership and control at every level of the target's structure, measured against the EU Consolidated List and the relevant thematic Council regulations. Where a listed person holds an interest – however structured – the transaction may be wholly prohibited or may require a specific authorisation before it can proceed. As of January 2026, the EU's ownership and control test (the principle that a non-listed entity may still be caught where a listed person owns or controls it) sits at the centre of every cross-border acquisition touching an EU party.

This case comment walks through an anonymised matter handled by our practice: the situation that arose, the legal questions the matter raised, the analysis we applied across the EU regime and its interaction with OFSI, the options we identified, and the lesson for businesses running M&A processes under time pressure.

The situation: a trust structure and a buried beneficial owner

The target group had a clean first-layer shareholder register. Three holding companies sat above the operating subsidiaries, all incorporated in EU member states. Standard automated screening of those entities returned no hits. The acquirer's compliance team had concluded the process was complete.

The problem was in the second and third layers. One of the three holding companies was partly owned by a discretionary trust established outside the EU. The trust deed named a corporate trustee. Beneficial ownership disclosures filed at national level identified individuals as beneficiaries – but the documentation was incomplete. A manual review of the trust's underlying assets, cross-referenced against the EU Consolidated List, revealed that a named beneficiary held a significant beneficial interest and was subject to an EU designation under the relevant thematic sanctions regulations.

The immediate question was stark: did that designation mean the target group itself was caught? And if so, what were the consequences for an acquirer that had already exchanged heads of terms?

In our cross-border practice, incomplete beneficial ownership disclosure is the most common trigger for exactly this kind of late-stage crisis. Automated screening against first-layer shareholders is not due diligence. It is a starting point.

What is the EU ownership and control test – and why does it matter here?

The EU ownership and control test treats a non-listed entity as caught by the prohibition applicable to a listed person where that person owns or controls it, applying a threshold and a qualitative control assessment that can extend liability beyond any fixed percentage. The governing instruments are the relevant Council regulations applicable to the specific designation regime. Unlike OFAC's 50 percent rule (a mechanical aggregate-ownership trigger), the EU test is layered: it looks first at ownership percentage, then at whether the listed person exercises control through other means – voting rights, governance arrangements, the power to appoint directors.

In this matter, the beneficial owner's interest in the trust sat below the level that would mechanically trigger the prohibition on a percentage basis alone. That might sound reassuring. It was not. The trust deed contained a provision giving that beneficiary a power of direction over distributions and, in defined circumstances, over the trustee's exercise of its voting rights in the holding company. That governance mechanism was enough to bring the holding company within the scope of the control limb. The holding company in turn held a direct stake in the target group's principal operating entity.

The practical effect was that the target's principal operating entity was potentially subject to the asset-freeze prohibitions under the relevant Council regulation. Completing the acquisition – transferring ownership of an entity in that position – would have required a specific authorisation or would have amounted to a prohibited dealing in frozen assets.

How does this compare to the UK position? Under the UK sanctions regime administered by OFSI, the test is materially similar in structure – ownership or control – but OFSI's published guidance applies a distinct analytical methodology. OFSI has indicated that the control question is assessed holistically, and that the same trust-based governance mechanism might be characterised differently depending on the specific facts. We identified a divergence in the conclusions that might be reached under each regime – relevant here because the target had a UK subsidiary and the acquirer had UK entities in its structure. The more restrictive conclusion governs where both regimes are engaged.

How was the legal risk characterised?

Once the ownership and control analysis was complete, we set out three positions to the client.

The first position was that the holding company was caught, and consequently that the target's principal operating entity was subject to the asset-freeze prohibition. On this reading, the acquisition as structured could not proceed without a specific licence from the relevant competent authority. The timeline for obtaining that authorisation was uncertain and, in our experience, rarely short.

The second position was that the governance mechanism in the trust deed was insufficiently direct to amount to control for the purposes of the relevant Council regulation, and that the holding company was therefore not caught. This position was legally arguable, but it required a detailed technical submission to support it, and relying on it without that work would have exposed the acquirer to significant enforcement risk.

The third position was a structural alternative: whether the acquisition could be re-engineered to exclude the affected entity – ring-fencing the principal operating entity from the rest of the group and completing on the unaffected subsidiaries, leaving the affected entity in the vendor's structure pending resolution of the beneficial ownership position.

We advised the client that the first position could not be set aside without a formal legal analysis capable of being presented to the relevant competent authority if challenged. The third position was the most commercially viable route for preserving the timetable.

How was the EU issue resolved?

After consultation with the acquirer's board and the target's vendor, we proceeded on the third structural route. The acquisition perimeter was redrawn to exclude the entity directly linked to the tainted holding company. The transaction documentation was amended to provide for a deferred completion mechanism covering that entity, conditional on either a confirmed change in the beneficial ownership of the trust or a formal authorisation from the competent authority.

We prepared a detailed memorandum to the relevant competent authority setting out the ownership analysis, the governance mechanism identified, and the acquirer's position. The memorandum also addressed the acquirer's own compliance posture and the steps it had taken to identify the issue. Proactive engagement of this kind – presenting the analysis before a transaction completes rather than after a challenge is raised – is consistently the better-received approach in our experience of working with competent authorities across EU member states.

The competent authority acknowledged receipt of the memorandum and confirmed that the redrawn transaction as structured did not require a specific authorisation to proceed, on the basis that the entity subject to the potential prohibition was excluded from the perimeter. The main transaction completed within the revised timetable. The deferred entity remains subject to ongoing review as the beneficial ownership position is addressed.

That outcome was not guaranteed. Competent authorities have differing approaches to informal engagement, and the response time varies materially across EU member states. We do not represent that this result is replicable in every set of facts.

Where did the diligence process fail – and what should have happened?

The acquirer had run a standard compliance process. Automated screening of named entities; a review of publicly available corporate registries; a check of national beneficial ownership registers. By the standards of many M&A transactions, this was not cursory.

What it did not do was apply manual review to trust structures and to incomplete beneficial ownership disclosures. The gap is predictable. National beneficial ownership registers – even within the EU – hold incomplete data. Trust structures are frequently excluded from registry requirements or disclosed at a level of abstraction that does not surface the underlying individual. A screening tool that flags named entities does not, by design, flag an unnamed beneficiary whose position only emerges from a trust deed that sits in a data room folder labelled "governing documents."

The practical steps that would have caught this earlier are straightforward to identify in retrospect. First, a bespoke ownership and control mapping exercise, not limited to first-layer shareholders, undertaken before heads of terms are agreed. Second, a specific review of any trust, foundation, or other non-corporate structure in the ownership chain, including a request for the underlying trust deed or equivalent constitutive document. Third, an explicit beneficial ownership questionnaire addressed to the vendor, with contractual representations covering the accuracy of the disclosure.

Had those steps been taken at the outset, the matter could have been assessed before the timetable became a pressure point. The late discovery did not make the transaction impossible. It did substantially increase the complexity and cost of managing it.

Is a trust structure an unusual feature in mid-market M&A? It is not. Privately held businesses are frequently owned through structures of this kind. Any due diligence process that treats the corporate register as the endpoint of the ownership analysis will, in our experience, periodically encounter exactly this category of problem.

Related practices

Cross-regime implications: OFAC, OFSI, and the rule that the stricter prohibition governs

In a transaction that touches EU entities, a UK subsidiary, and a US-incorporated acquirer or US-nexus financing, three regimes may be engaged simultaneously. Each has its own ownership and control test. Each has its own licensing architecture. The conclusions they reach on the same set of facts do not always converge.

Under OFAC, the 50 percent rule is the primary test. It is aggregate and mechanical. If blocked persons together own 50 percent or more of an entity, that entity is blocked regardless of control. An interest below that line does not automatically bring the entity within scope – but OFAC's regulations separately prohibit transactions that provide material support to blocked persons, a provision that can reach transactions where the ownership test is not satisfied.

Under the EU regime, as discussed, the control limb extends the analysis beyond percentage ownership. Under OFSI, the methodology overlaps with the EU position but is applied under distinct statutory authority and with a distinct licensing process.

The cross-regime principle that matters most in practice is that where two regimes are engaged and they reach different conclusions, the stricter prohibition governs the conduct of any party subject to both. A conclusion that the EU test is not satisfied does not permit a UK-nexus party to proceed if OFSI's analysis would reach the opposite result, and vice versa. In this matter, the divergence was not dispositive because the structural route sidestepped the question. In other transactions, however, resolving that divergence is a prerequisite to any advice that the transaction can lawfully proceed.

US secondary-sanctions exposure adds a further layer for non-US businesses. A transaction that is lawful under EU and UK law may still expose an EU acquirer to secondary-sanctions risk if the target has a relationship with a person subject to OFAC designation. Secondary sanctions do not require a US nexus in the transaction itself. They operate on the conduct of non-US persons dealing with defined categories of persons or activities. In our experience, this risk is underweighted in European M&A due diligence – particularly where the target operates in markets where OFAC's secondary-sanctions programmes have broad geographic application.

The myth that automated screening is due diligence

A persistent view in M&A compliance is that running the target's name and its first-layer shareholders through a commercial screening tool satisfies the sanctions due diligence obligation. That view is incorrect, and the consequences of acting on it can be severe.

Sanctions due diligence in M&A under the EU regime requires identification and analysis of all persons who own or control the target, at every layer of the ownership and control chain. The obligation is not discharged by a screen of publicly visible corporate entities. Trusts, foundations, discretionary vehicles, and informal arrangements that give a listed person influence over an entity are all within scope. A screening tool that has no access to the underlying documents – because those documents sit in a data room, not on a public registry – cannot perform this analysis.

The competent authorities in EU member states have indicated, in their published guidance, that a due diligence defence in an enforcement context will be assessed by reference to the steps the person took, not merely the result they obtained. An acquirer that ran an automated screen but did not request underlying trust documentation has a weaker position than one that identified the issue and engaged with the competent authority transparently.

There is also a commercial dimension. A deal that completes without adequate diligence carries post-completion enforcement risk for the acquirer. That risk may materialise as a regulatory investigation, a civil penalty, or a reputational consequence that is harder to quantify but no less real. The cost of a thorough pre-completion review is measurable and finite. The cost of managing a post-completion enforcement action is neither.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. For a confidential assessment of a potential breach or an ongoing matter, contact Calder & Vance at info@caldervance.com.

Frequently asked questions

What went wrong in this sanctions due diligence in M&A matter?
The diligence process relied on automated screening of named corporate entities and did not extend to a manual review of trust structures in the ownership chain. A named beneficiary of a trust holding an indirect stake in the target was subject to an EU designation. That individual's governance rights under the trust deed were sufficient to bring a key holding company within the EU control test, creating a prohibition risk for the acquisition as originally structured. The issue was identified before completion, but only by a manual review that should have been undertaken earlier.
How was the EU issue resolved?
The acquisition perimeter was redrawn to exclude the entity linked to the affected holding company. The redrawn transaction was structured as a conditional deferred completion for that entity, pending resolution of the beneficial ownership position or a formal authorisation. A detailed memorandum was submitted to the relevant competent authority, which confirmed that the redrawn transaction as structured did not require a specific authorisation. The main transaction then completed within the revised timetable.
What is the lesson for similar businesses?
Sanctions due diligence in M&A must cover the full ownership and control chain, including trusts, foundations, and other non-corporate structures, and must be based on underlying documentation rather than registry data alone. The diligence exercise should be completed before heads of terms are agreed, not after exchange. Where a potential issue is identified, proactive engagement with the relevant competent authority – presenting the analysis rather than waiting for a challenge – is consistently the more effective approach.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.