A payments firm operating across three EU member states completes its annual counterparty refresh. Thousands of records. Automated screening flags run overnight. The morning report shows no matches. Then a compliance officer, reviewing a high-value correspondent relationship by hand, notices a transliteration variant that the system passed without comment. The entity on the EU Consolidated List carries a name romanised differently from the version in the firm's customer-relationship data. The transaction had settled. The firm now faced a potential breach of the relevant EU Council regulation.
Name and entity screening under EU sanctions is governed by the relevant Council regulations and enforced at member-state level through competent national authorities. The EU's ownership and control test (the rule treating non-listed entities as caught when a listed person owns or controls them) adds a layer of complexity that purely name-based screening tools routinely miss. In this matter, a combination of transliteration gaps, an inadequate ownership-chain review, and an over-reliance on a single data source produced a false-negative result on a restricted-party relationship.
This case comment sets out the situation that arose, the legal issues it engaged, the analysis we conducted, and the lessons that apply to any business running EU-regime screening across a multi-entity counterparty base.
The situation: a false negative and its causes
The firm's screening programme compared customer names directly against list data pulled from a single commercial provider. No fuzzy-matching threshold had been set for non-Latin characters. No periodic manual review of high-risk segments was formalised in policy.
When the problematic correspondent was onboarded, the name in the customer record used one romanisation standard. The EU Consolidated List entry used a different one – both legitimate representations of the same source-language name. The gap was wide enough that the automated comparison produced no hit. The entity remained active in the firm's systems for a period measured in months.
A secondary failure compounded the first. The correspondent's principal shareholder was itself a listed person. The firm's due-diligence workflow did not include an ownership-chain review for existing counterparties at the point of the annual refresh. New customers received a beneficial-ownership check; existing customers did not, unless a manual trigger was raised. No trigger was raised. The ownership and control issue – the question of whether the correspondent was caught indirectly through its listed shareholder – was therefore never put to the analysis.
We regularly advise businesses that these two failures appear together precisely because they are structural: one sits in data quality and system configuration, the other in policy design. Fixing one without the other leaves a residual exposure.
What legal issues did the situation engage?
The relevant EU Council regulation imposing the applicable sanctions programme prohibits the making available of funds or economic resources, directly or indirectly, to or for the benefit of listed persons and entities caught by the ownership and control test. The prohibition is not qualified by knowledge or intent in the same way as some other regimes: the act of making funds available is the violation, subject to the defences available in the specific regulation.
The ownership and control test under EU law asks two questions. First, does a listed person own the entity – meaning hold, directly or indirectly, more than fifty percent of the proprietary rights or shares? Second, even without majority ownership, does a listed person control the entity through other means, such as voting rights, the power to appoint senior management, or contractual influence over strategic decisions? This is a broader test than OFAC's purely mechanical 50 percent threshold, and it requires a qualitative judgement that no automated list-matching tool can supply.
In this matter, the listed shareholder held a minority stake on paper. But an examination of the correspondent's constitutional documents, a shareholder agreement, and board composition data showed that the listed person held effective control through a combination of veto rights and management appointment powers. The entity was caught under the control limb, not the ownership limb. Screening against the EU Consolidated List alone would never have surfaced this; it required a substantive ownership-and-control analysis of the counterparty's governance structure.
Enforcement of EU sanctions operates at member-state level. Each competent national authority has its own enforcement posture, penalty range, and approach to mitigation. The firm's operations spanned three member states, meaning three potential enforcement tracks, each with its own procedural requirements for voluntary disclosure and cooperation. That jurisdictional layering is a recurring feature of EU-regime matters that a single-country compliance model does not handle well.
How does the EU position compare with OFAC and OFSI?
The EU control test is materially broader than the OFAC ownership threshold, and practitioners advising on cross-border matters must hold both in mind simultaneously. Under OFAC, the 50 percent rule (OFAC's rule blocking entities owned in aggregate fifty percent or more by blocked persons) is arithmetic: if the number is reached, the entity is blocked, regardless of whether the owner exercises any influence in practice. If the number is not reached, ownership alone does not block the entity – though OFAC may designate it separately.
OFSI in the United Kingdom applies a test closer to the EU's, examining both ownership above fifty percent and control, including through indirect means or a combination of interests. The practical implication is that a business screened clean under OFAC's mechanical threshold may still be caught under OFSI or EU analysis if a listed person exercises control through rights other than formal share ownership.
For the firm in this matter, which had US-dollar-denominated correspondent relationships alongside its EU operations, that divergence was operationally significant. A single analysis using OFAC standards would have produced a false all-clear on the EU and UK control question. In our cross-border practice, we see this gap most often in financial institutions whose compliance architecture was designed around the OFAC model and then extended to cover EU and UK obligations without recalibrating the control-analysis step.
For further context on how a related screening matter played out under OFSI, see our commentary at Name and Entity Screening: an OFSI matter, and for a Swiss-regime perspective, see Name and Entity Screening: a SECO matter.
What options were considered, and what route was taken?
Once the issue was identified, the firm faced three immediate decisions: whether to suspend the relationship pending analysis, whether to make a voluntary self-disclosure (VSD – a proactive report to the competent authority ahead of any formal inquiry), and which member-state authority to approach first given the multi-jurisdictional exposure.
Suspending the relationship while analysis was underway was the correct first step. Continuing to process transactions through a counterparty under active ownership-and-control review would have compounded any existing breach and created new ones. The firm froze processing within the relevant business day once the control question was formally escalated to legal counsel.
On voluntary disclosure, the position differs across the three member states. Some competent national authorities have formal VSD frameworks under which early disclosure is treated as a significant mitigating factor in penalty calculations. Others assess voluntary disclosure less systematically, though cooperation and transparency are consistently recognised as relevant to enforcement discretion. We advised the firm to prepare a coordinated disclosure package – a single factual narrative, accompanied by the documentary record – timed to land with all three authorities on the same day, to prevent the first authority's response from pre-empting the firm's position before the other two.
The disclosure package set out the screening gap, the ownership-and-control finding, the steps taken to suspend the relationship, and the remediation programme the firm proposed to implement. It included a root-cause analysis: the data-quality gap in transliteration handling, the policy gap in the existing-customer refresh cycle, and the absence of a qualitative control-review step for non-listed entities with listed shareholders.
Enforcement outcomes vary and are not predictable. What we can say is that a well-structured early disclosure – factually complete, legally framed, and accompanied by credible remediation – consistently produces a more constructive regulatory dialogue than a disclosure that is reactive or incomplete.
Risk flags for businesses running EU screening programmes
This matter produced a clear inventory of risk flags that compliance teams should apply to their own programmes. The list is not exhaustive, but these are the failure modes we see most often in EU-regime screening engagements.
- Single data-source dependency. One commercial screening feed, however well-maintained, will not capture every name variant or transliteration across all EU list entries. A programme that relies on one source without manual validation procedures for high-risk segments is structurally incomplete.
- Inadequate fuzzy-matching configuration. Transliteration of names from Arabic, Cyrillic, Persian, or other non-Latin scripts produces legitimate multiple romanisations. A screening system without a calibrated fuzzy-match threshold tuned to the firm's counterparty base will produce false negatives at precisely these points.
- Static onboarding-only beneficial-ownership review. EU sanctions obligations apply continuously, not only at onboarding. A listed person can acquire a controlling interest in an existing counterparty after the relationship is established. Without periodic ownership-and-control reviews – triggered either by time cycle or by change-event monitoring – a firm will not detect this.
- Failure to apply the control test to non-listed entities. Matching only against listed names misses the second half of the EU test. Any counterparty with a listed person as a significant shareholder or governance participant warrants a control analysis, not merely a list match.
- No multi-member-state enforcement mapping. For a business operating across EU member states, the competent authority for financial sanctions is national. Enforcement posture, disclosure procedures, and penalty ranges are not harmonised. A single-policy response to a multi-state breach is likely to be suboptimal in at least one jurisdiction.
If a transaction has already been flagged, or if a review has surfaced a potential control relationship, an early analysis can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss the position before it escalates.
The common myth: a clean list match means a clean counterparty
Many compliance teams believe that a negative result from an automated list-matching run is a clean bill of health. This is not correct, and it is worth stating plainly.
EU sanctions prohibit transactions with entities that are caught by the ownership and control test, whether or not those entities appear on the EU Consolidated List by name. A list match is a necessary step, but it is not sufficient. The list tells you who is directly designated. It does not tell you who is indirectly caught through the control or ownership analysis. That second step requires a review of corporate structure, shareholder agreements, governance documents, and sometimes public registry filings that no automated tool will perform.
A related myth is that if a counterparty passed screening at onboarding, it remains clean indefinitely. Sanctions lists change. Ownership structures change. A counterparty that was genuinely clean at onboarding may become caught six months later if a new designation lands on one of its shareholders. A programme without a periodic refresh or a change-event monitoring process cannot detect this.
In our experience, the businesses most exposed to this failure are those that have invested significantly in automated screening technology but underinvested in the policy and analytical steps that automated technology cannot replace. The technology is necessary; it is not sufficient on its own.
What the remediation programme covered
Once the immediate disclosure and relationship-suspension steps were taken, the firm needed a remediation plan it could commit to in its regulatory submissions. We assisted in designing a programme structured around four elements.
First, a data-quality audit. Every counterparty record with a name containing non-Latin characters, or derived from a transliteration, was identified and re-screened against expanded variant lists. Secondary sources – including public registry data and the firm's own KYC documentation – were used to cross-check spelling variants.
Second, a system reconfiguration. The screening tool's fuzzy-match parameters were recalibrated in consultation with the provider. A minimum-score threshold for non-Latin name fields was set and documented in the screening policy.
Third, a policy revision for the existing-customer refresh cycle. The firm adopted an annual ownership-and-control review for all counterparties above a defined risk-tier threshold, with a change-event trigger for any registered change to a counterparty's beneficial-ownership filing in relevant public registries.
Fourth, a training module for the compliance team covering the EU ownership and control test, the distinction between it and the OFAC 50 percent rule, and the escalation path when a control concern arises. The module included worked examples using anonymised fact patterns from the firm's own counterparty base.
Our compliance audit and testing work – including programme assessments of this kind – is described in more detail at Compliance Audit and Testing.
Related practices
- Compliance Audit and Testing – structured assessment and testing of sanctions screening and compliance programmes
- Name and Entity Screening: an OFSI matter – a parallel case comment on UK-regime screening failure and remediation
- Name and Entity Screening: a SECO matter – a case comment on screening under the Swiss SECO regime