Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · EU

Internal sanctions investigations under EU: the essentials

A European trading company discovers – mid-transaction – that one of its counterparties routed payments through an entity that may carry a nexus to a listed person. The legal team needs to know: is this a technical breach, a full prohibition violation, or something that can still be unwound? Who must be told, and when? That is the moment an internal sanctions investigation begins. Getting the structure right in the first hours can decide whether the matter is resolved by disclosure or escalated to enforcement.

Internal sanctions investigations under EU rules are governed by the relevant Council Regulation applicable to the programme in question, administered by the competent authorities of each EU Member State. As of April 2026, there is no single EU-level enforcement body; national authorities hold the investigative and sanctioning power. The speed, scope, and rigour of the internal review a business conducts before approaching those authorities will shape every outcome that follows.

This briefing sets out how the EU regime operates in practice, what a well-run internal investigation must cover, how EU obligations compare with those under OFAC and OFSI, and when external counsel should be instructed.

Who administers EU sanctions and what legal basis governs?

EU sanctions are adopted by the Council of the European Union as binding regulations, directly applicable in every Member State without national implementing legislation. The Council Decision sets the political basis; the Council Regulation creates the legal obligations that bind persons and entities within EU jurisdiction. Each programme – whether targeting proliferation, destabilisation, or terrorism financing – has its own Council Regulation and its own defined scope of prohibitions.

Enforcement is devolved. Each Member State designates one or more competent authorities to investigate suspected violations and impose penalties. In Germany that function sits with the relevant federal ministry and the competent customs authority; in France, the DGSI and the Trésor play different roles depending on whether the exposure is financial or trade-related; in the Netherlands, the relevant financial-sector supervisor and the prosecutor operate in parallel. The consequence for a business with EU-wide operations is significant: a single transaction can trigger scrutiny from more than one national authority simultaneously.

The EU General Court and, on further appeal, the Court of Justice of the European Union are the bodies with jurisdiction to review the legality of designations. They are not, however, the route for enforcement of violations. Enforcement is strictly national. In our cross-border practice, clients are regularly surprised to discover that an apparent violation touching France and the Netherlands may involve two separate national investigations running concurrently, each with its own procedure and its own penalty calculus.

What do EU sanctions actually prohibit, and what triggers an investigation?

The core prohibitions in EU sanctions regulations are, in substance: making funds or economic resources available directly or indirectly to designated persons or entities; dealing in assets of designated persons; providing financial services that facilitate a prohibited transaction; and circumventing these prohibitions through third parties. The prohibition on indirect provision – which catches transactions routed through intermediaries without actual knowledge of the designation nexus – is the source of most internal investigations in our experience.

An investigation is typically triggered by one of four events. First, a screening hit – whether during onboarding, transaction processing, or periodic review – that cannot immediately be cleared. Second, a regulatory enquiry or information request from a Member State competent authority. Third, a counterparty disclosure or press report that causes the compliance team to re-examine prior transactions. Fourth, an internal audit or M&A due diligence review that surfaces a historical payment pattern.

What distinguishes an EU investigation trigger from its OFAC counterpart? Under the OFAC regime, the concept of apparent violation (a transaction that appears on its face to breach a prohibition, regardless of intent) drives the disclosure analysis. EU frameworks are more fragmented: the question of whether a breach has occurred, and what knowledge element is required, varies by the relevant Council Regulation. Some regulations impose strict liability for dealing in designated assets; others require knowledge or reasonable cause to know. Mapping which standard applies is the first legal question in any EU internal investigation.

Have you reviewed which specific Council Regulation governs each sanctions programme your business is exposed to? The answer determines both the prohibition standard and the enforcement authority.

Related practices

The position above covers the standard trigger analysis. Your facts – the counterparty structure, the payment flow, the jurisdictions of the entities involved, and the specific programme in play – change the analysis materially. To discuss a potential exposure, contact Calder & Vance at info@caldervance.com.

How should a business structure an internal investigation under EU rules?

A well-run EU internal investigation follows a defined sequence, beginning with containment and moving through factual development, legal analysis, and disclosure assessment. The sequence is not optional: a disorganised review that destroys document integrity or delays a mandatory report will worsen the firm's position with the competent authority.

The first phase is containment. Any ongoing transaction that is the subject of the investigation should be paused pending legal review. Funds or assets that may be blocked should not be released, returned, or transferred until the prohibition position is confirmed. This is not a commercial decision – it is a legal obligation under the relevant Council Regulation. Releasing potentially blocked assets during an investigation can itself constitute a separate violation.

The second phase is factual reconstruction. The investigation team – which should include qualified external counsel from the outset in any matter of significance – maps the transaction chain. Who are the counterparties? What entities were interposed? What beneficial ownership structure sits behind each? Ownership and control (the EU test for whether a non-listed entity is caught because a listed person owns or controls it) must be assessed for every entity in the chain. EU regulations apply both an ownership limb and a control limb, and the control test is deliberately broad: it looks at whether a listed person can exercise decisive influence over the entity, not just whether they hold a formal shareholding.

The third phase is legal analysis: does the reconstructed transaction chain engage a prohibition? If so, on which legal basis, and in which Member State? This phase must also assess whether any derogation or authorisation might apply. Some Council Regulations provide for competent-authority authorisations for specific categories of transaction – the equivalent of the specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) available under OFAC and OFSI. Where an authorisation route is available, the internal review must assess whether it was obtained, whether it covers the transaction in question, and whether its conditions were met.

The fourth phase is disclosure assessment. EU regulations do not provide a single, uniform voluntary disclosure mechanism equivalent to OFAC's VSD (voluntary self-disclosure to a regulator) pathway. Some Member States have developed national guidance on disclosure and its effect on penalty calculation; others have not. The decision to disclose, to whom, in what form, and at what point in the investigation, is one of the most consequential choices in an EU enforcement matter. It should not be made without legal advice, and the analysis must account for the multi-authority risk described above.

How does the EU investigation regime compare with OFAC and OFSI?

Businesses with transatlantic or UK-EU operations regularly face the same underlying transaction reviewed under three regimes at once. The differences in how each regime runs an internal investigation are substantial, and advisers who treat them as equivalent will cause significant problems.

Under OFAC, the voluntary self-disclosure process is well-documented in published guidance. OFAC has historically treated a timely, thorough VSD as a significant mitigating factor in penalty calculation. The process is centralised: one filing to one agency. Timelines and the factors OFAC weighs in penalty assessment are publicly available, which allows experienced counsel to give a reasonably precise assessment of the range of outcomes.

Under OFSI – the Office of Financial Sanctions Implementation in the United Kingdom – the position shifted materially when the civil penalty regime was strengthened. OFSI (the UK's financial-sanctions enforcement body) operates a monetary penalty regime, and its published enforcement guidance sets out the factors it considers, including the quality of the subject's compliance programme at the time of the breach and the extent of cooperation during any review. OFSI can also publish details of a penalty even where no monetary penalty is imposed, which creates reputational consequences that the subject firm may not have anticipated.

The EU position differs on both counts. Penalties are set by national law and can vary dramatically between Member States. There is no EU-wide published guidance on voluntary disclosure equivalent to the OFAC or OFSI frameworks. In some jurisdictions, proactive disclosure has a demonstrable mitigating effect; in others, the legal basis for that mitigation is less clearly established. The multi-authority risk means that a disclosure to one competent authority does not necessarily resolve the investigation in another Member State. And where criminal liability exists alongside civil liability – which is the position in most EU jurisdictions for intentional violations – the disclosure decision becomes yet more complex.

In our cross-border practice, the hardest cases are those where a business has already disclosed to OFAC on the assumption that an EU matter would be resolved by extension. That assumption is wrong. EU investigations run independently, on national law, and a disclosure strategy must be designed for each regime separately.

If a transaction has already been flagged or a competent authority has issued an information request, an early legal review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.

What are the principal risk flags in an EU internal investigation?

Several patterns consistently indicate that an EU internal investigation has a higher risk profile and requires more intensive legal management.

The first is counterparty complexity. Transactions involving entities with layered or opaque ownership structures – trusts, foundations, multi-tier corporate chains crossing multiple jurisdictions – carry elevated risk precisely because the ownership and control analysis is difficult. A designation of a beneficial owner two levels up in the chain can catch the direct counterparty without any entry on the list. The absence of a screening hit is not clearance.

The second is multi-Member State exposure. A transaction that has connection points in several EU jurisdictions – origination in one, processing in another, delivery in a third – may engage the competent authorities of each. National enforcement postures are not uniform. Some Member States have invested significantly in sanctions-enforcement capacity; others are in earlier stages of building it. The firm's exposure in any given enforcement environment depends heavily on which authority takes the lead.

The third is the interaction between financial sanctions and trade sanctions. A transaction may simultaneously engage a financial prohibition (the payment) and an export-control or trade-sanctions prohibition (the goods). In the EU, trade measures are administered separately from financial-sanctions measures, and the investigative and enforcement track differs. A business that treats the matter as purely a financial-sanctions question and fails to assess the dual-use or trade-measures dimension may find a second enforcement track it had not anticipated.

The fourth is the extraterritorial dimension. EU sanctions, while not extraterritorial in the same formal sense as OFAC measures, have significant reach wherever EU-nexus factors are present: EU-incorporated entities, EU-incorporated subsidiaries of non-EU groups, transactions processed through EU financial institutions, and goods or services originating in the EU. A non-EU business that clears the OFAC analysis and overlooks the EU nexus in its transaction is exposed.

Finally, the timing of legal privilege over investigation materials is a live issue in EU matters. Unlike in some common-law jurisdictions, the protection of in-house legal communications varies across EU Member States, and the availability of legal professional privilege over investigation documents should be assessed at the outset – before documents are generated that may later be subject to disclosure.

What does the competent authority look for in enforcement?

EU Member State competent authorities assess a potential violation against criteria that, while nationally variable, generally cluster around the same considerations. Understanding what authorities examine allows a business to structure both its investigation and its eventual engagement with the authority constructively.

Authorities look first at the nature and severity of the breach. A transaction that directly benefited a designated person in a material amount is treated differently from a technical breach arising from a failure to identify an indirect ownership link. The intentional or negligent character of the breach – and the knowledge the firm had, or should have had, at the relevant time – is central to the enforcement calculus in most EU jurisdictions.

Second, authorities examine the compliance programme in place at the time of the breach. A firm with a documented, tested, and regularly reviewed screening programme that experiences a breach despite operating it properly is in a different position from a firm that had no programme or one that it knew was inadequate. We regularly advise clients that investment in compliance architecture before a breach is the most effective form of enforcement-risk management.

Third, the conduct of the firm after it identifies the potential breach is assessed. Prompt containment, a thorough and documented internal review, early legal advice, and constructive engagement with the competent authority are all factors that enforcement authorities in EU Member States with developed enforcement guidance explicitly recognise. The opposite – delay, incomplete investigation, or failure to engage – is consistently treated as aggravating.

Fourth, in most EU jurisdictions, cooperation during the authority's investigation – production of documents, availability of personnel for interview, transparency about the scope of the matter – bears on the ultimate outcome. Obstruction, even inadvertent, can convert a civil matter into one where criminal referral is considered.

When should external sanctions counsel be instructed?

Some businesses delay instructing external counsel in the hope that the matter can be handled by the internal compliance function. That delay is itself a risk-management failure in any case of real significance. External counsel should be instructed at the point of first identification of a potential breach – before documents are gathered, before individuals are interviewed, and before any communication is sent to the counterparty or to any authority.

The reason is structural. An internal review conducted without legal direction may generate documents, emails, and interview notes that are not protected by legal professional privilege and that may later become available to the competent authority. The investigation design – what is gathered, how it is gathered, what is recorded and what is not – needs to be set by qualified counsel from the outset.

External counsel in an EU matter must understand the specific enforcement environment of each relevant Member State, not just the text of the Council Regulation. The practical operation of the competent authority, its disclosure expectations, its procedural timelines, and its penalty guidance all differ between jurisdictions. Where a matter spans multiple Member States, coordinated legal advice across those jurisdictions is essential. Calder & Vance works with local counsel in each relevant jurisdiction where needed, ensuring that the investigation strategy is coordinated rather than fragmented.

A common misconception is that the internal compliance team can manage an EU investigation to completion and bring in external counsel only if enforcement proceedings are formally opened. In our experience, the matters that reach formal enforcement disproportionately include cases where counsel were instructed late. The competent authority sees the investigation record – and that record often reflects whether the firm treated the matter seriously from the start.

See also: Internal sanctions investigations under OFSI – a companion briefing covering the UK enforcement regime and how it interacts with EU obligations for dual-jurisdiction matters.

Frequently asked questions

Who administers internal sanctions investigations under EU?
EU sanctions are adopted by the Council of the European Union as directly applicable regulations, but enforcement is administered by each Member State's designated competent authorities. There is no single EU enforcement body equivalent to OFAC or OFSI. For a business operating across multiple EU jurisdictions, this means that a single apparent violation can attract parallel investigations by authorities in more than one Member State, each applying national penalty rules and procedural standards.
What does EU prohibit in relation to internal sanctions investigations?
EU Council Regulations prohibit making funds or economic resources available to designated persons, directly or indirectly, dealing in the assets of designated persons, and providing financial services that facilitate prohibited transactions. The prohibition on indirect provision is the most significant driver of internal investigations, because it can catch a business that transacted with an unlisted entity that is in turn owned or controlled by a designated person. Some regulations impose strict liability; others require knowledge or reasonable grounds to know.
How is internal sanctions investigations enforced under EU?
Enforcement is carried out by national competent authorities under national implementing legislation. Penalties, procedures, and the availability of voluntary disclosure mechanisms vary between Member States. Criminal liability is available in most EU jurisdictions for intentional violations. The absence of a single centralised disclosure pathway – unlike OFAC's voluntary self-disclosure process – means that a disclosure strategy must be designed for each jurisdiction separately, with legal advice tailored to the enforcement environment of each relevant Member State.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.