Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · EU

Apparent-violation assessment under EU: the essentials

A multinational trading group completes a payment to a counterparty. Three weeks later, an internal screening review flags that the counterparty's ultimate beneficial owner appeared on an EU consolidated list at the point of settlement. The payment went out. The funds are gone. The question is no longer whether to proceed – it is what the exposure means, what the relevant Member State authority will expect, and how quickly the business must act.

Under EU sanctions law, an apparent-violation assessment (the structured internal and external review a business conducts once a potential breach of a Council regulation is identified) is the first and most consequential step after a possible sanctions breach comes to light. The governing instruments are the relevant Council regulations enacted under the EU's Common Foreign and Security Policy, and enforcement sits with the competent authorities of each Member State. As of April 2026, EU Directive 2024/1226 – harmonising criminal-law definitions and penalties across Member States – is being transposed, materially changing the enforcement environment for businesses with EU operations.

This briefing explains who administers enforcement, what the assessment process involves, how it compares with OFAC and OFSI practice, the risk flags that matter most, and when to involve sanctions counsel.

Who administers EU sanctions enforcement, and on what legal basis?

EU sanctions enforcement is decentralised: the Council adopts the relevant regulation, but investigation, assessment of apparent violations, and penalty decisions rest with the competent authority designated by each Member State. There is no single EU-level enforcement body equivalent to OFAC or OFSI. For a business operating across multiple Member States, that means the enforcement environment can differ materially depending on where the violation is deemed to have occurred.

The legal basis for EU restrictive measures is the TFEU, giving the Council authority to adopt regulations that are directly applicable across the EU without national implementing legislation. The substantive prohibitions – asset freezes, dealing bans, provision-of-funds restrictions – are set out in the relevant thematic Council regulation. Member States are required to establish the penalties for breach in their national law, subject to the minimum standards being introduced by Directive 2024/1226.

Directive 2024/1226 is the most significant structural shift in EU enforcement in years. It requires Member States to criminalise intentional violations and to align their civil penalty regimes. Transposition is underway; the practical effect is that businesses which assumed low-penalty environments in certain Member States should not rely on that assumption remaining valid. We regularly advise clients who discover, when mapping their EU exposure, that the enforcement authority with jurisdiction over their conduct is not the one they expected.

Where do the substantive rules come from? The relevant Council regulation for each programme defines the prohibitions with precision. A breach is typically the provision, directly or indirectly, of funds or economic resources to, or for the benefit of, a designated person or entity. "Benefit" is broadly interpreted. A payment that routes through an intermediary holding company controlled by a listed person can engage the prohibition even where the payment instruction named only the intermediary.

What does the apparent-violation assessment process involve?

An apparent-violation assessment is the structured sequence a business follows to determine whether a transaction, payment, or business relationship constitutes a breach of a Council regulation, what the governing authority will expect to receive, and what remediation steps preserve the best outcome.

The assessment has five core elements. First, the business must identify and preserve all records relating to the suspected transaction – instructions, wire transfer data, contractual documentation, counterparty identification, and any screening records at the point of execution. Record destruction or loss at this stage is treated by enforcement authorities as an aggravating factor. Second, the business must map the counterparty's ownership and control structure against the consolidated list as it stood at the date of the transaction, not as it stands today. Lists change; the question is whether the prohibition applied then.

Third, the business applies the ownership and control test (the EU standard for whether a non-listed entity is caught because a listed person owns or controls it) as set out in the relevant regulation and accompanying guidance from the relevant competent authority. The EU test encompasses both formal ownership of more than 50 percent of shares or voting rights and effective control exercised through other means – board composition, veto rights, contractual arrangements. This is wider than OFAC's purely mechanical 50 percent ownership rule, and that difference matters in practice.

Fourth, the business assesses whether any authorisation – a specific licence granted by the competent authority, or a general derogation in the regulation – applied to the transaction. If an authorisation existed and was properly relied upon, the exposure is significantly different from a case where no authorisation was sought. Fifth, the business determines whether a report to the competent authority is required by the applicable regulation or national law, and on what timeline.

In our experience, the single most common gap at this stage is inadequate documentation of the screening decision at the time of the transaction. An authority reviewing a potential violation will ask what the business knew, when it knew it, and what steps it took. Screening logs that are incomplete, or that cannot be recovered, leave those questions unanswered in the worst possible way.

How does the EU assessment approach compare with OFAC and OFSI?

The EU, OFAC, and OFSI each operate a different model for assessing apparent violations, and those differences affect both the procedure and the penalty risk for a business with cross-border operations.

Under OFAC, a voluntary self-disclosure (VSD – a voluntary self-disclosure to the regulator describing an apparent violation before it is independently discovered) can reduce the base penalty by a significant proportion. OFAC publishes detailed enforcement guidelines identifying aggravating and mitigating factors, and the agency has a statutory basis for civil monetary penalties set by reference to the value of the transaction or a statutory maximum. The process is well-documented, with published penalty notices that provide a body of precedent. We regularly advise clients on parallel OFAC and EU exposure – the two regimes can apply simultaneously to the same transaction, particularly where a US-dollar payment clears through a US correspondent bank.

OFSI, the UK enforcement authority, operates a civil penalty regime that allows for monetary penalties without the need for a criminal prosecution. OFSI's enforcement guidance provides that voluntary disclosure is a mitigating factor, though the weight it carries depends on the circumstances. OFSI can also refer cases to the Crown Prosecution Service where criminal liability is in issue. Since the UK's departure from the EU, the UK consolidated list and the EU consolidated list have diverged: a person listed by the EU may not be listed by OFSI, and vice versa. A business that operates in both jurisdictions must screen against both.

The EU's decentralised model creates a complexity that neither OFAC nor OFSI presents: the same violation, committed by a business operating in multiple Member States, may be assessed by more than one national authority. The competent authority with primary jurisdiction typically follows the place of establishment of the entity that conducted the transaction, but cross-border transactions can engage more than one Member State. This is not a theoretical point. In a recent matter, a financial institution with operations in two Member States faced parallel enquiries from two national authorities in respect of the same underlying transaction. Coordinating the assessment response across two jurisdictions, with different procedural rules and different timelines, is a material undertaking.

Where the EU and OFAC regimes converge is on the importance of early, proactive engagement with the authority once a potential violation is identified. Delay is an aggravating factor in every enforcement framework we work within. Is the business that waits for a regulator's enquiry before commencing its assessment in a better position than one that acts immediately? The answer, in every regime we advise on, is no.

What are the key risk flags in an EU apparent-violation assessment?

Certain characteristics of a transaction or a business's conduct materially increase the enforcement risk once an apparent violation has been identified. Recognising these early shapes both the assessment strategy and the approach to any authority notification.

The first risk flag is a high-value transaction. The value of the transaction is a direct input into the penalty calculation under most Member State regimes and, under the harmonised criminal framework in Directive 2024/1226, is relevant to the gravity of the offence. A business should not assume that a high-value apparent violation will be treated as a technical administrative matter.

The second flag is a pattern of conduct. A single isolated transaction presents differently to an authority than a series of payments over months or years, even where each payment individually appeared low-risk at the time. Authorities examine whether the business had prior indications of risk and failed to act on them. Inconsistent screening records, or evidence that alerts were dismissed without documented rationale, suggest a systemic failure rather than an isolated lapse.

The third flag is senior-management involvement or awareness. Where the conduct involved decision-makers who had knowledge of the designation status, or where escalation routes were bypassed, the authority's assessment of wilfulness rises. The criminal limb of Directive 2024/1226 targets intentional violations; the more that internal communications show awareness of the risk, the more acute the criminal exposure becomes.

The fourth flag is the nature of the designated person's involvement. Transactions where a listed person was the ultimate beneficiary – not merely a remote upstream shareholder – attract closer scrutiny. Authorities focus on economic benefit: who received value from the transaction, in what form, and how directly.

The fifth flag is inadequate cooperation with the authority once the process begins. This means failure to respond within required timelines, production of incomplete documentation, or providing responses that later require material correction. Compliance counsel's role at this point is not only to prepare the assessment but to manage the authority relationship systematically and consistently.

When should a business involve sanctions counsel?

Sanctions counsel should be involved at the earliest point at which a potential violation is identified – before any decision is made about voluntary disclosure, before any communication is sent to a counterparty about the underlying transaction, and before any remediation steps are taken that might themselves alter the evidential record.

The apparent-violation assessment is not a compliance self-audit. It is a legal assessment with enforcement consequences. Decisions made in the first 48 to 72 hours – about what to preserve, what to say to whom, and whether to approach the authority – can close off options that would otherwise be available. The business that commissions a proper legal assessment before contacting an authority is in a materially different position from one that files an incomplete or self-incriminating notification.

For businesses with cross-border operations, counsel's first task is to map the enforcement jurisdictions in play. Is there US-dollar clearing that engages OFAC? Are there UK operations or UK-incorporated entities that engage OFSI? Are there multiple EU Member States with potential jurisdiction? The answer determines the structure of the assessment and the order in which authorities are approached, if approach is indicated.

A persistent misconception in this area is that voluntary disclosure always reduces penalty. It is a factor that authorities consider; it is not a mechanical discount, and in some circumstances an ill-timed or incomplete disclosure can increase rather than reduce exposure. The decision to disclose, and the form of the disclosure, requires legal judgment informed by the specific facts and the specific authority's enforcement history and current posture.

Our practice acts for businesses at every stage of this process: from the initial triage of an apparent violation, through the formal assessment and any authority notification, to engagement with the authority's review and, where necessary, the defence of penalty proceedings. We have also acted for businesses in coordinating parallel assessments across OFAC, OFSI, and multiple EU Member State authorities.

Related practices

Common misconceptions: what the EU regime does and does not require

A number of misconceptions circulate among in-house teams encountering an EU apparent violation for the first time. Addressing them directly is part of what counsel brings to the assessment.

The first misconception is that the EU consolidated list is definitive and self-contained. In fact, businesses must screen against both the EU consolidated list and the national implementing lists of the relevant Member States, where those exist. Some Member States maintain supplementary designations. The relevant regulation governs the primary prohibition, but national implementing instruments may extend obligations further.

The second misconception is that an apparent violation is not serious unless it was intentional. Strict liability applies to most civil-penalty provisions under EU sanctions law. The absence of intent does not eliminate liability; it is a mitigating factor in the penalty assessment. Directive 2024/1226 introduces criminal liability for intentional violations, but the civil framework bites regardless of intent.

The third misconception is that reporting requirements apply only if the violation is confirmed. Many national implementing instruments require notification of a suspected breach, not a confirmed one. Waiting for the internal assessment to conclude before assessing the reporting obligation can itself become a compliance failure.

The fourth misconception, and in our experience the most commercially consequential, is that an apparent violation under the EU regime has no US implications. Where the transaction involved a US-dollar leg, a US person, a US-incorporated entity, or goods of US origin, OFAC's rules apply in addition to the EU regime. A business that conducts an EU-only assessment and ignores the US dimension risks a second enforcement process it had the opportunity to address simultaneously.

Frequently asked questions

Who administers apparent-violation assessment under EU?
There is no single EU enforcement authority. The relevant Council regulation is adopted by the Council and applies directly across all Member States, but investigation and penalty decisions rest with the competent authority designated by each Member State. For a business operating in multiple Member States, this means that the authority with jurisdiction over the apparent violation depends on where the relevant entity is established and where the conduct occurred. Directive 2024/1226 is harmonising criminal-law definitions and minimum penalty levels, but the decentralised enforcement model remains in place.
What does EU prohibit in relation to apparent-violation assessment?
The relevant Council regulation prohibits making funds or economic resources available, directly or indirectly, to or for the benefit of a designated person or entity. An apparent violation arises when a business has reason to believe that a completed or ongoing transaction may have engaged that prohibition. The regulation does not separately prohibit the assessment itself; rather, once an apparent violation is identified, obligations to report it and to freeze assets may arise under the relevant regulation and national implementing law. The key substantive question is whether the listed person received economic benefit from the transaction.
How is apparent-violation assessment enforced under EU?
Enforcement proceeds through the national competent authority of the relevant Member State. Authorities have powers to investigate, request documents, impose civil monetary penalties, and – where criminal liability is in issue – refer matters to prosecuting authorities. Directive 2024/1226 requires Member States to criminalise intentional violations and to set meaningful minimum penalties. Voluntary cooperation and early notification are recognised mitigating factors in most Member State regimes, but the weight given to them varies. A business subject to an authority enquiry should be represented by sanctions counsel from the first communication with the authority.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.