A European trading company signs a distribution agreement with a third-country partner. Months later, a routine screening review flags that one of the partner's shareholders appears on the EU Consolidated List (the list of persons, entities, and bodies subject to EU restrictive measures). The question arrives on the compliance officer's desk immediately: is the partner itself captured? Can payments already processed be justified? Can the relationship continue? These are not hypothetical anxieties. They are the operational reality of counterparty due diligence under the EU sanctions regime – and the answers are neither automatic nor forgiving.
Counterparty due diligence under EU sanctions rules requires any person or entity within the EU's jurisdictional reach to verify, before and during a business relationship, whether a counterparty is subject to EU restrictive measures either as a listed person or through the ownership and control test (the EU rule that treats an entity as caught when a listed person owns or controls it). The obligation is ongoing, not transactional. Enforcement falls to competent authorities in each Member State, and penalties differ by national implementation – but the prohibitions are uniform across the single market under the relevant Council regulations.
This briefing sets out who administers the regime, what the prohibitions require, how the ownership-and-control analysis works, where EU rules diverge from OFAC and OFSI, the main risk flags, and when to involve sanctions counsel. As of August 2026, the regime continues to expand in both listed persons and thematic scope.
Who administers EU sanctions and what is their legal basis?
EU restrictive measures are enacted by the Council of the European Union, typically through a Council Decision and a directly applicable Council Regulation. The Regulation governs the prohibitions; the Decision sets the political framework. Both instruments are published in the Official Journal and take effect across all Member States simultaneously. No transposition step is required, which distinguishes the EU regime sharply from domestic legislation in third countries.
Day-to-day administration sits with national competent authorities (the body designated by each Member State to issue licences, receive reports, and enforce the prohibitions). In practice, this means that a French entity answers to its domestic authority while a Dutch entity answers to a different one, even though both apply the same Council Regulation. The European Commission coordinates implementation guidance but does not itself issue sanctions licences or enforce violations.
The EU General Court and, on appeal, the Court of Justice of the European Union are the judicial venues for challenging designations. An affected party may bring an annulment action arguing insufficient evidence, procedural error, or breach of fundamental rights. In our experience, the evidence threshold required to support a listing is lower than many businesses assume; this makes robust due diligence at the counterparty-screening stage commercially important.
The EU's jurisdictional reach is territorial and entity-based. It applies to acts done within the EU, to EU nationals and registered entities wherever they operate, and to acts involving EU currency or EU-registered vessels or aircraft. Where an EU parent company operates through a non-EU subsidiary, compliance counsel must consider both the parent's direct exposure and whether the subsidiary's activity implicates EU rules through the parent relationship.
What does the ownership and control test require, and how does it differ from OFAC?
The EU ownership and control test treats an entity as captured by EU restrictive measures when a listed person owns or controls it – even if the entity is not itself listed. This is where EU rules diverge most sharply from the OFAC framework, and where errors in counterparty due diligence most commonly occur.
Under OFAC, the 50 percent rule is mechanical: if blocked persons own, in the aggregate, 50 percent or more of an entity's shares, that entity is treated as blocked. Intention and management influence are irrelevant. The calculation aggregates holdings across all listed persons, direct and indirect. It does not turn on whether those persons exercise day-to-day control.
The EU applies a broader, two-limb test. An entity is caught where a listed person: (a) holds a majority ownership stake in it; or (b) has the ability to direct or exercise decisive influence over its management or decisions through other means – contractual rights, board composition, veto arrangements, or financial dependency. The control limb means that a counterparty can fall within EU prohibitions even where the listed person's shareholding is below the ownership threshold. Have you reviewed the governance documents of a target entity, or only its share register?
This divergence has direct operational consequences. A counterparty that clears the OFAC 50 percent screen may still be caught under EU rules because a minority listed shareholder holds blocking rights over material decisions. In our cross-border practice, we regularly advise clients who have relied on a single-jurisdiction screening result and inadvertently exposed EU operations to a second line of liability. The standard is: apply whichever prohibition is stricter to the facts in front of you.
The position under OFSI (the Office of Financial Sanctions Implementation in the United Kingdom) runs closer to the EU model than to OFAC. OFSI applies an ownership or control test, capturing entities that a designated person owns or controls. The practical consequence for a business with both EU and UK exposure is that two separate analyses are required, each under its own legal instrument, before a counterparty relationship can be assessed as compliant. For detailed guidance on the UK position, see our OFSI counterparty due diligence briefing.
The position above covers the standard ownership question. Your specific facts – the counterparty's corporate structure, the nature of the relationship, the goods or services involved, and the regimes in play – will change the analysis. If you are at the screening stage and need a rapid cross-regime review, contact Calder & Vance at info@caldervance.com.
What are the core prohibitions in EU counterparty due diligence?
The core prohibitions under EU Council regulations are the asset freeze, the prohibition on making funds or economic resources available, and – in many regimes – a prohibition on satisfying claims by listed persons. Each has direct implications for how counterparty due diligence must be structured.
The asset freeze obligation requires that all funds and economic resources belonging to, owned, held, or controlled by a listed person are frozen without delay. A firm that receives a payment from a counterparty subsequently identified as a listed person – or a person acting on behalf of one – cannot release those funds and must report the freezing to its national competent authority within a short statutory window. The specific deadline varies by Member State implementing measure and by regime; verify the current position with your national authority before relying on it.
The prohibition on making funds or economic resources available is equally broad. It catches payments, transfers, goods deliveries, services rendered, and credit extended to or for the benefit of a listed person. The words "for the benefit of" are critical to counterparty due diligence: a transaction with a non-listed entity can breach this prohibition if the economic benefit flows ultimately to a listed person. This is why beneficial ownership mapping matters, not just screening against the EU Consolidated List.
A third category – the prohibition on satisfying claims – prevents a firm from paying out money owed to a listed person, including under pre-existing contracts or court judgments. This creates a genuine contractual-performance problem when a counterparty is listed after a contract is signed. The listing does not void the contract, but it suspends performance of any payment or delivery obligation toward the listed party. Counsel should be involved immediately when a mid-contract designation occurs.
In addition to these core financial prohibitions, EU sanctions regimes may include sectoral measures: restrictions on access to capital markets, prohibitions on specific trade flows, technical-assistance bans, and professional-services restrictions. The latter – which can restrict legal, accounting, auditing, engineering, or consulting services – are particularly relevant for professional services firms conducting due diligence as a commercial matter. Know which regime applies to your sector before you start.
How should a counterparty due diligence programme be structured under EU rules?
A well-structured EU counterparty due diligence programme runs as a sequenced process that addresses listing status, ownership and control, sectoral exposure, and ongoing monitoring. Each step builds on the last, and the output of each step informs the decision at the next.
The first step is name screening against the EU Consolidated List and the national implementing lists. This catches direct listings. It does not catch entities that are captured only through the ownership and control analysis. Name screening is necessary but not sufficient.
The second step is ownership mapping. This involves tracing the counterparty's ownership structure through any intermediate holding companies to identify whether a listed person holds a majority stake or exercises decisive control. The relevant documents are the share register, the articles of association, any shareholders' agreement, and governance documents that describe management rights. For complex structures, this will involve corporate registries in multiple jurisdictions and, in some cases, local counsel in the relevant jurisdiction.
The third step is sectoral-restriction analysis. Even where no listed person appears in the ownership chain, the counterparty may be subject to sectoral measures that restrict the type of transaction you propose. This analysis requires identification of the counterparty's sector, the goods or services in the transaction, and the specific regime applicable.
The fourth step is an ongoing monitoring programme. EU restrictive measures are updated frequently; new listings are published in the Official Journal with immediate effect. A counterparty cleared at onboarding may be listed within months. Compliance programmes that rely on point-in-time screening without a periodic refresh or a real-time alert mechanism carry material exposure. In our experience, financial institutions and professional-services firms with large counterparty pools are the clients most likely to discover a stale-list problem in an enforcement context rather than a compliance context.
The fifth step is documentation. Competent authorities, in enforcement investigations, will ask to see the due diligence record. The record should show: who screened, when, against which lists, what the results were, and what steps were taken when the result was not clear. Record-keeping obligations under EU anti-money laundering rules and sanctions rules overlap; maintaining a single, well-organised file per counterparty is both a compliance and a legal-defence measure.
If a transaction has already been flagged, or a filing has been refused, early legal review can preserve options that narrow with time. For a confidential review of your counterparty programme, contact us at info@caldervance.com.
What are the principal risk flags in EU counterparty due diligence?
Certain patterns in counterparty due diligence consistently indicate elevated EU sanctions risk. Recognising them early reduces the cost of the response. Missing them exposes both the firm and its officers to enforcement action.
The first risk flag is a corporate structure with multiple intermediate holding layers in jurisdictions with limited disclosure requirements. Layered structures are not inherently suspicious, but they expand the universe of persons whose listing status must be verified. Where a corporate registry does not disclose ultimate beneficial owners publicly, the due diligence process must go further – through registered agent records, contractual documentation, or direct inquiry to the counterparty.
The second is a counterparty in a sector subject to EU thematic restrictions: the energy sector, the financial sector, the defence and dual-use sector, and specific industrial sectors covered by regime-specific measures. Sectoral exposure means that even an unlisted, uncontrolled counterparty can be a restricted one for the specific transaction you propose.
The third is a beneficial-ownership picture that is inconsistent with the counterparty's stated commercial purpose. Where a trading company's ultimate owners have no visible connection to the trade in question, that inconsistency warrants explanation before the relationship proceeds.
The fourth is geographic exposure. Operations or counterparties in jurisdictions subject to comprehensive or near-comprehensive EU restrictive measures require enhanced procedures throughout the counterparty lifecycle – not just at onboarding.
The fifth is a mid-relationship listing event. When a counterparty, its owner, or a connected person is listed during an ongoing relationship, the business must act quickly. Funds already received may need to be frozen and reported. Future performance of any payment or delivery obligation toward the listed party is suspended. In our cross-border practice, we regularly advise on the practical steps a business must take in the first hours after discovering a mid-contract designation.
A common myth is that a non-EU entity operating exclusively outside the EU can disregard EU sanctions. In fact, EU nationals employed by that entity, EU-domiciled banks processing its payments, and EU-flagged vessels carrying its goods all create potential EU nexus points. Jurisdictional analysis must be part of the due diligence template, not an afterthought.
When should you involve sanctions counsel?
Sanctions counsel should be involved at any point where the due diligence result is not a clean negative, where the corporate structure cannot be resolved through standard registry searches, or where a mid-contract event requires an immediate legal assessment.
There are four situations where early involvement is clearly justified. First, a screening result that produces a potential match that cannot be definitively resolved by name-similarity analysis alone. The business should not proceed to clear the result as a false positive without a documented legal review, particularly where the counterparty name, jurisdiction, and sector overlap materially with a listed person's profile.
Second, where the counterparty's ownership structure includes a jurisdiction in which the beneficial owner cannot be identified through public sources. The absence of a registry result is not a clean screen; it is an information gap that the EU control test may require you to fill by other means.
Third, where the proposed transaction is subject to a general or specific licence requirement. Some EU sanctions regimes permit transactions that would otherwise be prohibited, subject to prior authorisation from the national competent authority. Identifying whether an authorisation is available, and preparing the application correctly, requires legal input.
Fourth, where an apparent violation has already occurred – a payment processed to a counterparty that should have been screened but was not, or a delivery made to a beneficiary who has since been listed with retroactive implications. Voluntary disclosure to the competent authority may be available, and the timing of that disclosure can be material to the penalty calculation. Competent authorities in several Member States have published enforcement guidance making clear that voluntary, timely disclosure is a mitigating factor in any penalty assessment.
For a detailed comparison of how OFAC structures the same counterparty analysis, see our OFAC counterparty due diligence briefing. For firms with compliance programmes that extend beyond EU and UK exposure to include Australia, our sanctions compliance audit and testing service for Australia provides a structured review against the Australian autonomous sanctions regime.
How is EU counterparty due diligence enforced?
Enforcement of EU sanctions violations is a Member State function. Each Member State is required to establish effective, proportionate, and dissuasive penalties for breaches of Council regulations, but the specific penalty structure – the maximum civil fine, the criminal threshold, and the administrative process – is set by national law and varies considerably across the single market.
Competent authorities have used a range of enforcement tools: administrative fines, criminal referrals, licence revocations, and publication of enforcement decisions. The publication of decisions – sometimes called "naming" – is a reputational measure that affects not only the entity fined but also its directors and officers where national law provides for personal liability.
Common factors that competent authorities treat as aggravating include: a systematic failure to screen, reliance on a compliance programme that had not been updated to reflect current listings, knowledge or reasonable cause to believe that a counterparty was listed, and failure to report a frozen asset within the required window. Mitigating factors typically include prompt voluntary disclosure, cooperation with the authority's investigation, and remediation steps taken before enforcement proceedings were opened.
The EU is also a participant in coordinated multilateral enforcement actions. Where a violation touches both EU and US jurisdictions – for example, where an EU entity processes a dollar-denominated payment through a US correspondent bank – the matter may attract OFAC attention in addition to the national competent authority's. Dual-regime exposure is not theoretical; it is a material risk for any EU business with US-dollar payment flows or US-based operations. In those circumstances, the legal analysis must address both regimes simultaneously, and the enforcement response must be coordinated.
Does your compliance programme capture the reporting obligations specific to each Member State in which you operate? If not, that is a gap that warrants prompt attention.
Related practices
- Sanctions compliance audit and testing – Australia – structured review of screening, ownership mapping, and programme design against the Australian regime
- Counterparty due diligence under OFAC – how the OFAC 50 percent rule and ownership analysis compare to EU practice