Calder & Vance International Sanctions & Compliance Counsel

Licensing & Authorizations · EU

Payment authorisations under EU: scope and obligations

A European payments platform routes a settlement through a correspondent bank. The counterparty is not itself listed. But one of its owners is a designated person. The correspondent freezes the transfer and flags the transaction. Now the platform faces a question its compliance manual did not fully answer: does an authorisation exist that permits the payment to proceed, and who must grant it?

Under EU sanctions regulations, payments involving designated persons or their assets are prohibited unless a competent authority in a Member State grants a specific authorisation – or the transaction falls within a standing derogation. The EU Council regulations define the categories of permitted purpose; national authorities decide individual cases. As of June 2026, the regime applies with direct effect across all Member States, though the authority that handles the application, and the procedural rules, differ by jurisdiction.

This briefing sets out who administers the EU payment-authorisation regime, what the core prohibitions and derogations cover, how a firm applies, where the procedural gaps sit, and how the EU position compares with OFAC and OFSI – the two regimes most likely to run in parallel for a cross-border business.

Who administers payment authorisations under EU sanctions, and what is the legal basis?

EU sanctions regulations are adopted by the Council of the European Union and apply directly as law in every Member State. No domestic implementing act is needed for the prohibition itself. The regulations designate competent authorities – typically finance ministries or national sanctions offices – as the bodies that receive and decide individual authorisation requests.

This creates a structurally fragmented system. The prohibition is uniform. The procedure for seeking relief is not. A firm based in France applies to the Direction générale du Trésor. A firm in Germany applies to the Deutsche Bundesbank or the Bundesamt für Wirtschaft und Ausfuhrkontrolle, depending on the asset type. A firm operating across multiple Member States may need concurrent applications in more than one jurisdiction. In our experience, this fragmentation is the single most common source of delay and inconsistency in EU payment-authorisation matters.

The Council Decisions that accompany each regulation set the political framework. The regulations themselves carry the operative obligations and the derogation catalogue. Neither instrument names a pan-EU licensing office comparable to OFAC in the United States. The European Commission monitors compliance and can issue guidance, but it does not grant authorisations.

The legal basis for the payment-freeze obligation sits in the EU's autonomousSanctions regime, distinct from UN Security Council obligations, though the two often overlap in practice. Where a UN Consolidated List designation is also mirrored in the EU regulation, the obligation runs from both sources and the stricter prohibition governs.

What does the EU prohibit in relation to payments, and what derogations exist?

The core prohibition under EU sanctions regulations is the freeze of all funds and economic resources belonging to, owned, held, or controlled by a designated person, and the prohibition on making funds or economic resources available to that person, directly or indirectly. A payment routed through a chain that terminates in a designated person's hands is caught even if the immediate counterparty is not listed.

The ownership and control test – the mechanism by which a non-listed entity can still fall within the freeze – is broader under the EU than the mechanical OFAC threshold. EU regulations capture entities owned or controlled by a designated person. Control does not require majority ownership. It can arise through voting rights, the ability to appoint board members, or contractual or structural influence over key decisions. This means that a firm doing ownership analysis using only a percentage-ownership threshold may miss EU-caught entities that fall below a numerical cut-off.

Against that prohibition, the regulations set out standing derogations and a mechanism for competent-authority authorisations. The main standing derogations typically cover:

  • Payments for basic human-needs purposes, including food, medicine, rent, and utility costs, up to defined thresholds where the regulated person is a natural person
  • Extraordinary expenses, subject to competent-authority notification or prior authorisation
  • Payments under contracts concluded before the designation date, where the payment serves no sanctioned purpose
  • Legal fees and costs for representation, within limits set by the regulation
  • Diplomatic or consular purposes

These derogations are self-executing where the conditions are met, but the burden of demonstrating that the conditions are satisfied rests on the person relying on the derogation. Firms should not treat a derogation as automatic permission. They must assess and document the factual basis at the time of the transaction. If doubt exists, a competent-authority notification or prior-authorisation application is the safe route.

For transactions that fall outside the standing derogations, the firm must obtain a specific authorisation from the relevant competent authority. The application must identify the designated person, the purpose of the payment, the amount, the legal basis for the request, and evidence that the purpose satisfies a recognised category. There is no single EU-wide form. Each Member State authority uses its own format.

How does a firm actually apply for a payment authorisation under the EU regime?

The application process begins with identifying which Member State competent authority has jurisdiction. Jurisdiction generally follows the location of the funds, the account, or the entity making or receiving the payment. Where funds are frozen at a bank in one Member State and the applicant is established in another, the authority of the Member State holding the funds typically takes the application.

The sequence for a standard specific-authorisation application runs broadly as follows:

  1. Confirm the designation and the prohibition. Check the EU Consolidated List and the specific regulation applicable to the designated person's programme. Verify whether the transaction falls within the scope of the prohibition as a matter of law before proceeding to an application.
  2. Identify the competent authority. Locate the authority in the Member State where the payment is frozen or where the applicant is established. Check current procedural guidance on that authority's website, as requirements vary.
  3. Prepare the application file. Assemble evidence of the identity of all parties, the legal basis for the derogation or authorisation category, supporting documentation for the stated purpose (invoices, contracts, medical evidence as applicable), ownership and control analysis for any corporate counterparty, and a declaration of no sanctioned benefit.
  4. Submit and manage correspondence. Submit the file in the language required by the authority. Many authorities will request supplementary information. Responding promptly is important: delays extend the period during which funds remain frozen and the counterparty cannot be paid.
  5. Await the decision. Timelines vary. Some authorities issue decisions in a matter of weeks; others take several months. There is no EU-wide statutory processing deadline comparable to OFAC's published licence-processing statistics.
  6. Execute the payment only after authorisation is confirmed. Proceeding before the authorisation is granted – on the assumption that approval will follow – constitutes a breach of the prohibition.

In our practice, applications that arrive with incomplete ownership analysis or an underdeveloped statement of purpose are the most commonly delayed. The competent authority cannot approve a purpose it cannot verify. Investing time in the evidential package before submission shortens the overall process.

The position above covers the standard case. Your facts – the counterparty, the payment route, the Member State in play, and the programme in question – change the analysis materially.

For a preliminary assessment of your application and which authority to approach, contact Calder & Vance at info@caldervance.com.

How does the EU payment-authorisation regime compare with OFAC and OFSI?

Cross-border businesses almost always face more than one regime simultaneously. A payment that is frozen under EU rules may also be caught by OFAC or OFSI – and the three systems handle authorisations differently in ways that matter operationally.

Under OFAC, specific licences are issued centrally by the Office of Foreign Assets Control in Washington. The process is standardised: a single application, a single authority, a published set of licensing policies, and guidance notes on common categories. OFAC also issues general licences – standing authorisations for defined transaction categories – which a firm can self-execute without a separate application, provided the conditions are met. OFAC publishes the text of general licences in the relevant programme pages. The 50 percent rule (OFAC's rule that treats entities owned 50 percent or more by a blocked person as themselves blocked) applies mechanically; the control test does not extend beyond that threshold under OFAC's framework.

Under OFSI in the United Kingdom, specific licences are granted by the Office of Financial Sanctions Implementation. OFSI publishes licensing grounds under the Sanctions and Anti-Money Laundering Act and the relevant thematic regulations. Firms apply to OFSI directly, and the ownership test under UK sanctions law captures both ownership and control – aligning more closely with the EU position than with OFAC's purely mechanical test. OFSI also maintains an monetary penalty regime under which it can impose significant civil penalties for breaches, including for transactions that a firm believed were authorised but were not.

The practical implication of running under all three regimes simultaneously is that a transaction may be permissible under EU authorisation but still prohibited under OFAC – or vice versa. Where that conflict arises, the stricter prohibition governs. A business that obtains EU authorisation for a payment cannot proceed with the dollar leg of that payment if OFAC's position prohibits it.

For a detailed comparison of the OFAC payment-authorisation process, see our briefing at Payment authorisations under OFAC: scope and obligations.

What are the key risk flags and common mistakes in EU payment-authorisation practice?

Several patterns recur in EU payment-authorisation matters that reach us after a problem has crystallised. Understanding them before a transaction is executed is more valuable than understanding them after a breach has occurred.

Relying on a self-assessed derogation without documentation. Firms that treat a derogation as automatically available – because the payment looks like a food or medicine purchase, for example – but do not document the factual basis at the time of the payment are exposed if the authority later reviews the transaction. The derogation is only as strong as the file supporting it.

Underestimating the control test. Because the EU ownership and control test extends beyond majority shareholding, firms whose screening processes look only for percentage-ownership hits will miss controlled entities. In our experience, this is especially acute in joint-venture structures and in businesses with complex governance arrangements, where a designated person holds influence without a majority stake.

Failing to consider the counterparty's own exposure. A payment from an EU-established firm to a non-listed intermediary that then remits funds to a designated person violates the prohibition on making funds available indirectly. Due diligence on the full payment chain – not just the immediate counterparty – is required.

Proceeding in parallel across regimes without checking for conflicts. As noted above, EU authorisation does not cure an OFAC or OFSI prohibition. Firms that obtain EU clearance and then route the payment through a US correspondent bank without checking the OFAC position expose themselves to a separate enforcement action.

Missing the notification requirement where prior authorisation is not needed. Some EU derogations require the competent authority to be notified rather than asked for prior approval. The notification window is set by the regulation. Missing it does not make the transaction retrospectively unlawful in every case, but it is a compliance breach in its own right and can attract regulatory attention.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss the position.

When must a firm involve counsel – and what does that involvement look like?

The case for external counsel is strongest at three points: before an application is submitted, when a competent authority requests further information, and after a refusal.

Before submission, counsel can assess whether the transaction structure falls within the prohibition at all, identify the correct competent authority, and draft the legal-basis section of the application in terms the authority recognises. A well-structured application moves faster and faces fewer supplementary requests. In our practice, the difference between an application prepared with care and one submitted quickly without analysis is often measured in months of additional freeze time.

When a competent authority raises questions, the response must be precise. An ambiguous answer invites a further round of questions. A response that inadvertently concedes a point the authority was not previously focused on can narrow the available grounds. Counsel familiar with the authority's practice in the relevant Member State can manage that correspondence effectively.

After a refusal, the firm has procedural options that vary by Member State. Some regulations provide for an internal review or appeal within the competent authority. Others require a challenge before the relevant administrative court. If the refusal rests on the designation itself – as distinct from the purpose of the payment – the appropriate route may be an annulment action before the EU General Court. That is a distinct proceeding with its own standing requirements, time limits, and pleading rules. It is not a substitute for reapplying with additional evidence, and the two routes are not mutually exclusive in all cases.

We also advise on the interaction between payment-authorisation questions and broader compliance-programme design. A business that has identified a gap in its ownership and control analysis through a live transaction should use the moment to redesign the screening process, not only to resolve the immediate payment. Counsel can assist with both simultaneously.

For more on frozen-asset management and related licensing services, see our service page at Frozen account management – licensing and authorisations. For the EU payment-authorisation series, see also Payment authorisations under EU: advanced issues.

A common misconception: obtaining one authorisation clears the transaction in every regime

Compliance teams sometimes proceed on the assumption that a competent-authority authorisation under the EU regime resolves the transaction in every other relevant system. It does not. An EU authorisation addresses only the EU prohibition. It has no legal effect on OFAC's position, OFSI's position, or the position of any third-country regime.

This misconception is understandable. The authorisation process is demanding, and once it is complete, the instinct is to treat the matter as closed. But a payment that requires an EU authorisation almost always has a currency leg, a banking correspondent, or a contractual counterparty that brings another regime into play. The OFAC regime, in particular, asserts jurisdiction over dollar-denominated transactions globally and over transactions that touch US persons or US financial infrastructure – regardless of whether the parties are EU-established.

In practice, this means that the EU authorisation should be the beginning of a cross-regime review, not the end of it. Before executing the payment, a firm should confirm that no US, UK, UN, or other applicable prohibition attaches to the same transaction. Where uncertainty remains, the transaction should be paused rather than executed. The cost of a pause is a delay; the cost of proceeding into a prohibition is a potential enforcement action under a regime that did not grant the authorisation.

In a recent matter, a payments business had obtained EU competent-authority authorisation for a series of transfers involving a designated entity's frozen account. The transfers were lawful under the EU regime. Before executing, the business sought our advice on the dollar leg of the same transfers. We identified that the correspondent bank route would require OFAC compliance analysis, and that one of the transfers would have triggered a prohibition under the applicable OFAC programme. The EU-authorised transfers proceeded on the non-dollar route; the problematic leg was restructured. No enforcement exposure arose.

Related practices

Frequently asked questions

Who administers payment authorisations under EU?
Payment authorisations under EU sanctions regulations are administered by the competent authority designated by each Member State, typically a national finance ministry, central bank, or dedicated sanctions office. There is no single pan-EU licensing office. An applicant must identify the authority in the Member State where the funds are held or where the applicant is established. The substantive derogation categories are set by the EU Council regulation; the procedural requirements – forms, languages, timelines – vary by national authority. Firms with cross-border operations may need to approach more than one authority for a single matter.
What does EU prohibit in relation to payment authorisations?
EU sanctions regulations prohibit the making available of funds or economic resources, directly or indirectly, to or for the benefit of a designated person, and freeze all assets belonging to, owned, held, or controlled by such persons. A payment is prohibited if it flows, through any chain, to a designated person or an entity that person owns or controls. Derogations exist for defined purposes – basic needs, legal representation, pre-designation contractual obligations, and extraordinary expenses – but reliance on them requires documented factual assessment. Transactions outside the derogations require specific competent-authority authorisation before execution.
How is payment authorisations enforced under EU?
Enforcement of EU payment prohibitions operates at the national level. Each Member State is responsible for implementing penalties for breaches of the Council regulations, and sanctions differ significantly across jurisdictions: some operate civil penalty regimes, others criminal prosecution, and several both. The European Commission monitors implementation and publishes comparative data, but does not itself prosecute breaches. A business operating in multiple Member States faces multiple enforcement regimes simultaneously. The trend across the EU has been toward stronger enforcement, higher penalties, and greater willingness by national authorities to act on institutional as well as individual conduct.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.