A payments team at a European bank receives a transfer instruction from a corporate client. The originator traces back to a counterparty with a shareholding held by a person on the EU Consolidated List. The transaction is caught. No funds may move without authorisation. The compliance officer has hours, not days, to frame the right question to the competent authority. Getting that question wrong delays the release and can expose the institution to an enforcement review.
Payment authorisations under EU sanctions rules are case-by-case permissions granted by the designated national competent authority in each Member State, allowing a payment or fund transfer that would otherwise be prohibited under the applicable Council Regulation. As of June 2026, authorisations are available under most thematic EU sanctions regimes, but each regime sets its own conditions, and the competent authority in the Member State where the funds are held or the transaction is being executed is the correct first port of call.
This briefing sets out who administers EU payment authorisations, what is prohibited and what can be authorised, the procedure a business should follow, how the EU position compares with OFAC and OFSI, the key risk flags practitioners see in practice, and when to involve sanctions counsel.
Who administers payment authorisations under the EU regime?
EU payment authorisations are not administered by a single central authority. Each Member State designates one or more national competent authorities – typically the finance ministry, the central bank, or a dedicated sanctions unit – that receive and assess authorisation requests under the relevant Council Regulation. The Council sets the legal basis and the categories of permissible authorisation; the national authority applies them to the specific transaction.
This decentralised structure has a direct consequence for any cross-border payment. If the funds are frozen at a French institution and the beneficiary is in Germany, the applicable competent authority is the French authority, because that is where the funds sit and where the prohibition bites. The German nexus does not confer jurisdiction on the German authority for that request. In our cross-border practice, we see clients incorrectly file requests in the jurisdiction of the payee rather than the jurisdiction of the frozen asset or account, causing avoidable delays.
The European Commission publishes a list of Member State competent authorities under each sanctions regime. That list is the starting point. However, the procedural rules, the documentary requirements, and the review timelines vary between Member States even when the substantive legal test is drawn from the same Council Regulation. Practitioners advising on EU matters note that two Member States applying the same regulation can have meaningfully different expectations at the application stage.
For businesses with exposures across several Member States – a trade-finance bank clearing payments through correspondent accounts in multiple jurisdictions, for instance – the practical answer is to map where each frozen asset or blocked account sits and file separately in each jurisdiction. Coordination between counsel in each Member State then becomes a project-management question, not merely a legal one.
What does the EU regime prohibit in relation to payments?
The core EU financial-sanctions prohibition freezes all funds and economic resources owned or controlled by a listed person and prevents any person from making funds or economic resources available, directly or indirectly, to or for the benefit of a listed person. A payment instruction that routes value to a designated person, or releases frozen funds without authorisation, falls squarely within the prohibition.
The EU applies an ownership and control (the combined test under which a non-listed entity can be caught if a listed person owns it or exercises control over it) test that is broader than the mechanical OFAC 50 percent threshold. Under EU rules, an entity can be caught by control even where the listed person's ownership stake falls below any numerical threshold, if the facts demonstrate that the listed person can direct the entity's conduct. This means that a payment to an entity with minority-but-controlling listed-person involvement is prohibited, regardless of ownership percentage. That is a critical distinction from the US position and one that compliance teams used to screening against OFAC thresholds sometimes miss.
What is caught therefore includes: payments to a listed person's bank account; payments to an entity that a listed person owns or controls; transfers that would release frozen funds held for the account of a listed person; and any arrangement that allows a listed person to derive an economic benefit from a transaction, even if the counterparty is not itself designated. The phrase "directly or indirectly" in the Council Regulations is read broadly by Member State authorities.
Are all payments to entities with a listed-person nexus automatically blocked? Not necessarily. Where the connection is through a minority, non-controlling shareholding and the payment is to the entity rather than to the individual, careful analysis of the ownership and control test may demonstrate that the prohibition does not apply. That analysis should be documented before any payment proceeds.
How does the authorisation procedure work in practice?
An authorisation request is a formal written application to the relevant national competent authority, setting out the factual basis for the transaction, the legal ground relied upon within the applicable Council Regulation, and the supporting evidence. The authority then assesses whether the statutory conditions for the authorisation are met.
The Council Regulations provide for several categories of authorisation, varying by regime. Commonly available grounds include: authorisations to satisfy basic needs of a designated natural person (food, rent, medical costs); authorisations to meet pre-existing contractual obligations entered into before the designation; authorisations to pay professional fees and reimburse expenses of legal representatives; and authorisations serving extraordinary expenses where the competent authority is satisfied that specific conditions are met. The ground relied upon shapes both the evidence required and the conditions the authority will attach to any permission granted.
In practice, the application should identify: the parties to the transaction; the amount and currency; the account or asset involved; the legal basis for the authorisation within the regime; a clear explanation of why the conditions for that basis are met; and supporting documents (contracts, invoices, fee schedules, proof of the designated person's identity and ownership chain). Incomplete applications are the most common cause of delay. A well-structured submission anticipates the questions the authority will ask.
Timelines differ by Member State. Some authorities acknowledge receipt promptly and issue decisions within a matter of weeks; others work to longer internal cycles. The Council Regulation itself does not prescribe a mandatory decision period in the same way that OFAC's specific-licence procedure operates. In our experience, an application that clearly maps the facts to the relevant legal ground, supported by a complete documentary file, proceeds materially faster than one that requires the authority to seek clarification repeatedly.
Where an authorisation is granted, it will be subject to conditions – typically specifying the payment amount, the account to which funds are to be released, the timeframe within which the transaction must occur, and a reporting requirement on completion. These conditions are not formalities. Breach of an authorisation condition can itself constitute a sanctions violation under the applicable Council Regulation.
How does the EU position compare with OFAC and OFSI?
The EU, OFAC, and OFSI each operate a licensing or authorisation regime for otherwise-prohibited transactions, but the three regimes diverge on the ownership and control test, the procedural mechanics, and the penalty structure for breach – and those differences matter for any cross-border payment that touches more than one jurisdiction.
On the ownership test: OFAC applies the 50 percent rule (OFAC's rule treating entities owned 50 percent or more in the aggregate by one or more blocked persons as themselves blocked, regardless of control). OFSI and the EU apply an ownership or control test, meaning that control below the 50 percent threshold can still trigger the prohibition. A payment that passes an OFAC screen may still be prohibited under EU rules if the counterparty is controlled by a listed person through contractual arrangements, voting rights, or board representation rather than majority equity.
On procedure: OFAC issues specific licences (case-by-case authorisations) and general licences (standing authorisations permitting defined categories of transaction without individual application). The EU equivalent is the competent-authority authorisation described above, together with the general derogations built into each Council Regulation. OFSI in the UK has a comparable licensing regime under the relevant thematic sanctions regulations made under the Sanctions and Anti-Money Laundering Act. The key practical difference is that EU authorisations are issued at Member State level, so a multi-jurisdictional payment may require parallel applications in several countries simultaneously.
On penalties: each regime carries its own enforcement posture. Civil and criminal penalties are available under national legislation implementing EU sanctions obligations across all Member States, while OFAC's maximum civil penalty per violation can be substantial and is set by the applicable enabling statute. OFSI similarly has the power to impose significant financial penalties. The critical cross-border point is this: a business that secures an EU authorisation for a payment but fails to consider whether the same payment requires an OFAC licence – because a US-dollar clearing leg touches a US correspondent bank – faces potential US enforcement liability even though it acted lawfully under EU rules. The stricter prohibition governs each leg of the transaction independently.
For a business operating between the EU and the United Kingdom, the post-2021 divergence between EU and UK designation lists adds a further layer. A person listed under one regime may not be listed under the other. The authorisation requirements therefore need to be assessed separately for each applicable regime, not assumed to be coextensive.
What are the key risk flags practitioners see?
Five patterns recur in the matters we advise on. Each is avoidable with the right process before a payment instruction is issued.
First, the control question is resolved too quickly. Screening shows ownership below any threshold, the payment proceeds, and the control analysis is never done. EU rules require that control be assessed even where ownership is low. A listed person who nominates board members, holds veto rights under a shareholders' agreement, or is otherwise in a position to direct the entity's conduct can bring that entity within the prohibition without holding a single share.
Second, the wrong competent authority is approached. As noted above, jurisdiction follows the location of the asset or account, not the location of the counterparty or the instructing bank. Filing in the wrong jurisdiction adds weeks and can complicate the relationship with the authority that does have jurisdiction.
Third, the legal ground is mis-identified. Invoking "basic needs" for a commercial payment, or "pre-existing contractual obligations" for a transaction entered into after the designation date, will result in rejection and may prompt the authority to scrutinise the applicant's overall compliance programme.
Fourth, authorisation conditions are treated as administrative rather than legal. An authorisation permitting a payment of a specific amount to a specific account by a specific date is a conditional permission. A payment that exceeds the amount, goes to a different account, or occurs after the authorisation has expired is not authorised. We regularly advise businesses on how to structure the transaction mechanics so that the payment is completed strictly within the authorisation's terms.
Fifth, the OFAC and OFSI dimensions are not assessed in parallel. Where a euro-denominated payment is settled through a system with US-dollar clearing, or where the institution holds a US regulatory licence, OFAC's jurisdiction is potentially engaged. Treating the EU authorisation as a complete answer to the compliance question, without checking whether a US or UK permission is also required, is a well-documented pattern in enforcement actions across multiple regimes.
When should a business involve sanctions counsel for a payment authorisation?
Counsel should be involved at the point when a payment is flagged on screening and the analysis does not yield a clear, documented conclusion that the prohibition does not apply. Waiting until the first application is rejected, or until a regulator has issued an information request, narrows the options and compresses the timeline.
There is a common misconception that competent-authority applications are purely administrative and that experienced in-house teams can handle them without external counsel. That is true for straightforward basic-needs requests, where the factual matrix is simple. It is not true where the authorisation involves a complex ownership and control question, a disputed designation, a multi-jurisdictional payment, or a commercial transaction entered into before the designation where the counterparty's circumstances have changed. In those situations, the legal ground, the evidence strategy, and the drafting of the submission all require specialist input.
If a payment has already been made and a subsequent review suggests the transaction was prohibited, the question becomes one of voluntary self-disclosure (VSD – a proactive report to the relevant competent authority or enforcement body, made before any investigation is opened, which is a mitigating factor in penalty assessments under most EU Member State implementing legislation). Early legal advice on whether to VSD, and on how to structure that disclosure, is critical. Delay in seeking advice on a potential breach does not cause the issue to resolve itself.
In a recent matter, a financial institution identified that a series of automated payment sweeps had transferred funds to an account held by an entity that, on further analysis, was controlled by a listed person. The institution had conducted ownership screening but had not applied the control test. We assessed the scope of the potential violation, advised on voluntary self-disclosure to the relevant national authority, and prepared the disclosure submission. The matter proceeded with the institution in a cooperative position from the outset, which is consistently the more effective posture in enforcement discussions.
The position above covers the standard case. Your facts – the location of the funds, the counterparty's ownership structure, the payment route, and the regimes in play – change the analysis. For an assessment of your exposure under the EU payment authorisation regime, contact Calder & Vance at info@caldervance.com.
Interaction with related EU sanctions obligations
Payment authorisations do not exist in isolation. They sit within a broader set of EU sanctions obligations that can amplify or complicate the authorisation question.
Reporting obligations run alongside the payment prohibition. Most EU sanctions regimes require entities that hold frozen funds or identify a listed person among their counterparties to report that fact to the competent authority, typically within a short statutory window. The existence of frozen funds, and the fact of the authorisation application, should be reported in accordance with whichever regime-specific reporting requirement applies. Failure to report, independently of the question of the payment itself, is a separate violation in many Member States.
Record-keeping obligations require that documentation relating to a frozen asset, an authorisation request, or a transaction conducted under an authorisation be retained for a defined period. The specific retention period varies by Member State implementing legislation and by the applicable thematic regime, but in our practice the standard expectation across major EU jurisdictions is that records are retained for a period consistent with general anti-money-laundering retention requirements. That documentation is the business's primary evidence of compliance if a regulator later reviews the transaction.
The EU Blocking Regulation is relevant for businesses that are simultaneously exposed to third-country sanctions regimes whose extraterritorial application the EU does not recognise. A business authorised under EU rules to make a payment is not thereby authorised to comply with a conflicting prohibition under a third-country regime if the EU has designated that regime as one to which the Blocking Regulation applies. In practice, this tension arises most acutely where an EU operator receives a demand under a third-country sanctions programme whose extraterritorial reach conflicts with EU law. Counsel should be involved before any decision is taken to comply with, or to refuse to comply with, the conflicting demand.
If a transaction has already been flagged, or an application has been refused, an early review can preserve options that narrow with time. For a confidential review of a potential breach or a refused authorisation, contact Calder & Vance at info@caldervance.com.
Related practices
- Frozen account management (BIS/EAR) – managing frozen accounts and BIS/EAR licensing across export-control proceedings
- Payment authorisations under OFAC – OFAC-specific licence procedure, timelines, and cross-regime comparison
- Release of blocked funds under the EU regime – procedure for releasing funds blocked under EU Council Regulations