A European crypto exchange onboards a new institutional client. The compliance team screens the wallet address and the legal entity name. Both return clean results. Six weeks later, internal monitoring flags a transfer to a counterparty that an EU Member State authority has notified as linked to a designated person. The question is no longer whether the controls worked. It is whether the gap between them was lawful.
Crypto and VASP sanctions compliance under EU rules is governed by the relevant EU Council regulations imposing asset-freezing obligations on all persons and entities within the EU's jurisdiction – including virtual-asset service providers (VASPs, firms that exchange, transfer, or custody crypto-assets on behalf of clients). As of mid-2026, EU obligations apply to the digital-asset sector with the same force as to traditional finance, and the transfer of funds regulations extend screening requirements directly to crypto transfers. The obligations are strict-liability in character: intent does not determine whether a breach has occurred.
This briefing sets out who administers the regime, what the key prohibitions require, how the ownership-and-control test applies to crypto counterparties, where EU obligations diverge from OFAC and OFSI, and what enforcement exposure looks like in practice.
Who administers EU crypto and VASP sanctions compliance?
EU financial sanctions are a matter of Member State competence at the enforcement level, with the Council of the EU as the legislative authority. Each of the 27 Member States designates its own national competent authority (NCA) – the body responsible for receiving notifications of frozen assets, granting licences (called authorisations under EU instruments), and enforcing sanctions breaches within its territory.
This distributed structure creates a practical complexity that VASPs rarely anticipate. A VASP authorised in one Member State but serving clients in several others may face scrutiny from multiple NCAs. The NCA of the Member State where the VASP holds its Markets in Crypto-Assets (MiCA) authorisation typically leads, but it does not hold exclusive enforcement jurisdiction. In our experience, VASPs that structure themselves to carry a single regulatory passport without mapping which NCAs can reach their client book face material exposure.
Alongside the NCAs, the European Banking Authority (EBA) and the European Securities and Markets Authority (ESMA) hold supervisory roles relevant to the crypto sector under their mandates. The incoming EU Anti-Money Laundering Authority (AMLA), which is expected to assume direct supervisory responsibility for certain high-risk obliged entities, will extend its reach to at least some VASPs operating across the single market. The timeline and scope of AMLA's direct supervision remain subject to phased implementation; verify the current position before relying on any assumed start date.
At the level of legal authority, the sanctions obligations themselves flow from Council regulations – instruments that are directly applicable in all Member States without transposition. There is no equivalent of the UK's need to transpose SAMLA-enabling regulations into each new designation instrument; a Council regulation creates the obligation the moment it enters force and is published in the Official Journal.
What does the EU prohibit, and how do the obligations bite on VASPs?
The core EU sanctions prohibitions applicable to VASPs are asset-freezing and the ban on making funds or economic resources available to designated persons. These prohibitions extend to any person or entity who is a designated person under the relevant thematic Council regulation, and – through the ownership-and-control test – to entities that are owned or controlled by those persons.
For a VASP, the asset-freeze obligation means that a wallet, a custody account, or any crypto-asset holding attributable to a designated person must be frozen on identification. The obligation is immediate. There is no grace period comparable to the wind-down licences that OFAC may issue in certain programmes. Making funds available covers not only direct transfers but the provision of any service – trading access, custody, conversion – that results in a designated person having use of an economic resource.
The transfer-of-funds regulation imposes a parallel set of requirements. From the point at which that regulation's provisions applied to crypto-asset transfers, VASPs acting as originators or beneficiaries of transfers must collect and transmit payer and payee information – a requirement that has become known in the sector as the travel rule. Compliance with the travel rule does not satisfy the sanctions obligation; it runs alongside it. A transfer that is travel-rule compliant but executed for a designated person remains a sanctions breach.
What the prohibitions do not contain is an automatic exemption for unhosted wallets or for transactions below a value threshold. Some compliance programmes treat low-value transfers or peer-to-peer transactions as lower priority. Under EU sanctions rules, the designation of a person is the trigger, not the transaction size. Is your screening logic calibrated to the EU's threshold-free framework, or has it inherited assumptions from a different regime?
How does the EU ownership-and-control test apply to crypto counterparties?
The EU sanctions ownership-and-control test is wider than the OFAC 50 percent rule, and that difference is operationally significant for VASPs screening corporate and institutional clients. Under the EU approach, an entity that is owned or controlled by a designated person is caught by the sanctions prohibitions even if the direct ownership stake falls below any simple threshold.
Control, for EU purposes, encompasses factual dominance over the decisions of an entity. It can arise from a minority shareholding combined with board rights, from a contractual arrangement, or from a pattern of economic dependence. An entity owned at thirty-five percent by a designated person may be EU-caught where that person exercises de facto control through governance rights or economic leverage. Under OFAC's rule, the same entity would not be blocked by that holding alone unless aggregated ownership of blocked persons reached 50 percent or more.
For VASPs, this creates a due-diligence challenge that static list-screening does not resolve. A wallet address maps to a legal person or an individual. That legal person's ownership chain may contain a controlling minority holder who appears on the EU Consolidated List without appearing on the SDN List. Screening against OFAC's list alone will not surface the exposure.
In our cross-border practice, we regularly advise VASPs that operate under MiCA and serve clients across the EU, the US, and the UK simultaneously. Mapping the ownership chain of a corporate client against all three ownership-and-control tests – OFAC's aggregated-50-percent rule, OFSI's similar but separately administered rule, and the EU's broader control standard – is now a baseline expectation for regulated entities in the sector.
The practical implication is that a VASP relying solely on name and wallet screening against a single list is likely to have gaps in its coverage of the EU ownership-and-control dimension. Enhanced due diligence for institutional clients should include a documented review of beneficial ownership, governance rights, and funding sources against the EU Consolidated List.
Where does EU differ from OFAC and OFSI – and why does it matter for VASPs?
EU, OFAC, and OFSI sanctions obligations differ in structure in ways that directly affect how a cross-border VASP must design its compliance programme. The divergences are not merely procedural; they reflect genuinely different legal architectures.
On ownership and control, as noted above, the EU test reaches further than OFAC's mechanical 50 percent rule. OFSI's UK approach is closer to the EU standard – it includes a control limb – but the UK and EU lists are no longer identical following the UK's departure from the EU framework. A person listed under an EU Council regulation may not appear on the UK Consolidated List, and vice versa. A VASP serving both EU and UK clients must run both lists.
On licensing (referred to as authorisation under EU instruments), the EU route requires an application to the relevant NCA in the Member State with jurisdiction. There is no central EU licensing authority equivalent to OFAC's Office of Licensing or OFSI's Licensing team. The result is that multi-Member-State VASPs assessing whether a prohibited transaction might be authorised must identify the correct NCA, apply the substantive tests set by the relevant Council regulation, and manage any divergence in how different NCAs apply those tests in practice.
On reporting, the EU requires that persons freezing assets notify their NCA. The exact timing window varies by Member State implementation and by the relevant regulation. Compare this to OFSI's requirement under UK law, which mandates reporting within a defined statutory period. The absence of a single harmonised EU reporting deadline is a compliance design issue that VASPs setting up their incident-response procedures must account for.
Secondary sanctions are another dimension of divergence. The United States maintains a secondary-sanctions architecture – under which non-US persons risk designation for transactions that would not themselves violate US primary sanctions – that has no direct EU equivalent. However, certain EU regulations extend their prohibitions to conduct that facilitates a designated person's activity, even by intermediaries. This is not a replica of the US secondary-sanctions architecture, but it has comparable reach in specific thematic programmes. VASPs processing transfers that pass through multiple jurisdictions should map both the primary prohibition and any facilitation prohibition before executing.
The EU Blocking Regulation adds a further complication for VASPs with US operations. Where a VASP is subject to certain listed US extraterritorial sanctions measures, EU law may impose a positive obligation not to comply with those measures. Managing the conflict between a US compliance obligation and an EU blocking obligation is a specialist exercise that should not be resolved through an internal compliance memorandum alone.
What are the main risk flags for VASPs under the EU regime?
Risk in the EU crypto-sanctions space concentrates in several patterns that we encounter repeatedly in practice.
The first is unhosted-wallet exposure. A VASP that processes transfers to or from unhosted wallets – those not associated with a regulated entity – has reduced ability to verify the beneficial owner. EU sanctions obligations do not relax for unhosted wallets. Where the ultimate holder of an unhosted wallet is a designated person, the prohibition applies. Blockchain analytics tools can surface red flags – transaction patterns, cluster associations, mixer exposure – but they do not substitute for a sanctions determination. A tool that shows a high-risk score is not a legal assessment of whether a designated person is involved.
The second is the onboarding of legal entities without full beneficial-ownership mapping. MiCA-licensed VASPs are expected to hold detailed KYC information on institutional clients, but the sanctions review of that information – specifically the check against the EU ownership-and-control test – is a separate layer that not all compliance functions apply consistently.
The third is NFT and DeFi exposure. Non-fungible token platforms and decentralised-finance protocols may be VASPs for regulatory purposes depending on their operational structure. Where they are, the sanctions obligations follow. Where they are not regulated entities, the prohibition on making funds available to designated persons still applies to any legal person within EU jurisdiction who participates in the protocol. The absence of a licensing obligation does not create a sanctions exemption.
A fourth risk is stale screening. The EU Consolidated List updates frequently. A VASP that screens at onboarding but does not re-screen its active client base against updated lists will, over time, accumulate clients who have become designated subsequent to onboarding. In our experience, the interval between re-screening cycles is one of the first issues that an NCA examination examines. How frequently does your VASP re-screen its existing clients, and does your incident-response procedure activate when a newly designated person is identified in the live book?
The fifth is geographic routing. A transfer that originates outside the EU but routes through an EU-regulated VASP or through a payment processor that is itself an EU-obliged entity engages EU sanctions obligations at the point of processing. The fact that the end beneficiary is in a third country does not remove the obligation.
In a recent matter, a payment-token platform established in a Member State identified – through a blockchain analytics alert – that a corporate client's transfer had passed through a cluster of wallets associated with a person subsequently added to the EU Consolidated List. We assessed the timeline of the transaction against the effective date of designation, advised on the notification obligation to the relevant NCA, and structured the client's voluntary disclosure. The matter was resolved without further enforcement referral. The key was acting quickly and documenting the analysis fully from the moment the alert surfaced.
The enforcement posture and when to involve counsel
EU sanctions enforcement against VASPs is administered at Member State level, but the enforcement environment has tightened materially in recent years. NCAs in several Member States have expanded their supervisory capacity for the crypto sector, and the alignment of sanctions supervision with AML supervision – both increasingly directed at the same set of VASP obliged entities – means that a single examination can surface issues across both regimes simultaneously.
Penalties for sanctions breaches under EU law are determined by Member State implementing legislation. Civil penalties vary significantly between Member States. Criminal sanctions – including personal liability for directors and officers – are available in a number of jurisdictions. A VASP operating across several Member States should not assume that the penalty exposure of its home-state NCA defines the ceiling of its risk.
The common myth in the VASP sector is that decentralised operations or non-EU user bases insulate a platform from EU enforcement reach. The EU jurisdictional test looks at where the service is provided, where the platform is established, and whether EU persons are involved – not simply where the servers are hosted. A platform incorporated in a Member State is within EU jurisdiction regardless of where its clients are located. This is not a compliance corner that can be reasoned around.
Voluntary self-disclosure (VSD, the practice of proactively reporting an apparent breach to the relevant authority before it is discovered) is available under the relevant national frameworks in most Member States. Its effect on enforcement outcomes varies by NCA and by the nature of the breach. It does not guarantee a reduced penalty or a decision not to proceed, but in our experience it consistently changes the character of the enforcement dialogue and demonstrates the good faith that NCAs weight in their determinations.
Counsel should be involved at the point at which a VASP identifies a potential breach – before the notification is drafted, before the voluntary disclosure decision is made, and certainly before any response is filed with an NCA. The legal privilege that attaches to communications with counsel in preparation for a notification does not attach to internal compliance documents, which may be sought in an examination. Getting the structure right from the first moment matters.
For VASPs that have not yet experienced an enforcement event, the right moment to involve counsel is the compliance audit or programme review – before the gap is identified by a regulator. Our sanctions compliance audit and testing service for VASPs maps the programme against the EU regime's expectations and identifies where the controls need recalibration. Details of that service are available at our compliance audit and testing practice page.
For those requiring a comparative perspective, our regime briefing on crypto and VASP sanctions compliance under the Japanese regime addresses how the FSA-administered framework differs from the EU approach, and our OFAC crypto and VASP sanctions compliance briefing covers the US regime in the same depth.
Related practices
- Sanctions compliance audit and testing – structured review of screening logic, ownership mapping, and incident-response procedures against regime expectations.
- OFAC crypto and VASP sanctions compliance – parallel regime briefing covering US obligations and the OFAC licensing and enforcement architecture.