Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · EU

Payment-processing controls under EU: the essentials

A payment-services firm processing euro transfers on behalf of a European corporate client discovers, mid-batch, that one of the beneficiaries shares a name with an entity on the EU Consolidated List. The batch is worth several million euros. Does the firm freeze the payment? Block the account? Notify the authorities? Make the wrong call and it faces enforcement proceedings; make no call at all and it faces the same. As of August 2026, this scenario plays out daily across the EU's payment infrastructure – and the legal obligations are more granular than many compliance teams assume.

EU payment-processing controls prohibit the making available of funds and economic resources to designated persons and entities, require the freezing of assets belonging to or controlled by those parties, and impose reporting and record-keeping obligations on all persons subject to EU jurisdiction. The obligations arise under successive Council regulations and are directly applicable across all EU Member States without the need for implementing legislation. The key test – whether a non-listed entity is caught – turns on ownership 50 percent or more by a designated person or, separately, on control.

This briefing sets out who administers the regime, what the core prohibitions require, how the ownership and control test operates in practice, where EU rules diverge from OFAC and OFSI, the main enforcement mechanisms, and when payment processors and their counsel need to act.

Who administers EU payment-processing controls?

EU sanctions are imposed by the Council of the European Union, acting under the EU's Common Foreign and Security Policy, and give rise to directly applicable Council Regulations that bind all EU Member States and their residents. There is no single EU-level enforcement authority analogous to OFAC or OFSI. Enforcement falls to national competent authorities in each Member State – typically a financial intelligence unit, a central bank, a finance ministry, or a designated supervisory body, depending on the Member State.

This structure has a direct operational implication for payment processors. A firm with operations in multiple EU Member States may face different national regulators, different reporting templates, and different penalty ranges, even though the underlying prohibition comes from the same Council Regulation. In our experience, businesses that treat EU sanctions as a single, uniform system quickly find that the procedural requirements – for freezing notifications, for asset reports, for licensing applications – vary considerably from Berlin to Amsterdam to Dublin.

The European Banking Authority has issued convergence guidelines on sanctions compliance for credit institutions and payment-service providers, and the European Commission publishes consolidated versions of the EU Consolidated List and maintains a sanctions map. These tools assist compliance teams but do not displace the obligation to check the specific national procedural rules in each jurisdiction of operation.

For payment processors specifically, the principal operational interface with the regime is through their payment-message flows. Every credit transfer, direct debit, card transaction, and e-money instruction that passes through an EU-regulated firm is subject to the prohibition on making funds available to a designated person. That obligation is real-time; there is no grace period once a designation is in force.

What are the core prohibitions in EU payment-processing controls?

The core prohibition is the making available of funds or economic resources, directly or indirectly, to or for the benefit of a designated person. A second, related obligation is the freezing of all funds and economic resources belonging to, owned by, held by, or controlled by a designated person. Both obligations bite on any natural or legal person subject to EU jurisdiction.

For payment-service providers, "making available" is broad. It includes initiating a payment, executing a payment instruction, releasing a hold, and approving a credit facility. Where a payment processor acts as an intermediary – processing a transfer from an EU bank to a non-EU correspondent – the obligation extends to payments that pass through the firm's systems, not only those where the firm's direct customer is the designated party.

The "for the benefit of" limb is particularly significant. A payment made to an undesignated entity can still violate the prohibition if the economic benefit flows through to a designated person. This captures dividend payments, management fees routed through intermediaries, and loan repayments where the ultimate creditor is designated. In our cross-border practice, we regularly advise payment firms on exactly this question: the payee is clean, the purpose is commercial, but the beneficial-flow analysis exposes the transaction.

The prohibition on making funds available is distinct from the asset-freezing obligation. Freezing means immobilising assets that are already within the firm's custody or control – a bank balance, a pending payment instruction, a pledged security. Once a firm identifies that it holds assets belonging to a designated person, it must freeze immediately and report to the relevant national competent authority. The asset does not leave the firm; it is suspended pending authorisation or other lawful disposal.

A point that compliance teams sometimes miss: the prohibition applies not only to funds but also to economic resources – broadly, assets that can be used to obtain funds, goods, or services. For a payment processor this is rarely the operative concept; but for a platform that holds crypto-assets, tokenised instruments, or other non-cash balances on behalf of customers, the economic-resources limb may bite independently of any traditional payment flow.

How does the EU ownership and control test work?

Under EU Council regulations, an entity that is owned or controlled by a designated person is itself subject to the prohibitions, even if it does not appear on any list. The test has two branches: an ownership branch and a control branch.

The ownership branch catches entities owned 50 percent or more by a designated person, whether directly or through a chain of intermediaries. The EU position on ownership aggregation mirrors OFAC's: two designated persons each holding 30 percent of the same entity together reach the threshold, and the entity is caught. The calculation is done on an aggregate, not a per-designated-person, basis.

The control branch goes further. It can capture entities where a designated person holds less than 50 percent but exercises effective control through other means – a dominant board position, a right of veto over significant decisions, contractual control over operating revenues, or an economic relationship that makes the entity dependent on the designated person. This is a qualitative assessment, not a mechanical arithmetic one, and it requires legal judgment rather than a simple screening match.

This is where EU and UK rules diverge significantly from the US position. Under OFAC, the test is purely ownership-based at the 50 percent threshold; control as an independent trigger does not feature in the same way. Under OFSI and the EU, control can catch an entity at, say, 35 percent ownership if the designated person exercises effective management control. That divergence creates a genuine compliance asymmetry for cross-border payment processors. An entity that passes an OFAC screen – because no single blocked person owns 50 percent – may still be prohibited under EU rules if the practical control analysis is unfavourable.

In our experience, the control question is the most frequently underweighted element of EU payment-screening programmes. Firms invest heavily in list-matching technology but conduct little or no substantive control analysis for entities where ownership is below the 50 percent threshold. That gap is an enforcement liability.

The position above covers the standard case. Your facts – the ownership chain, the contractual arrangements, the route of the payment, the Member States involved – change the analysis. For an assessment of your specific exposure under the EU regime, contact Calder & Vance at info@caldervance.com.

What are the licensing and derogation routes for payment transactions?

Council regulations provide for specific authorisations – licences or derogations – that permit otherwise prohibited transactions in defined circumstances. The categories are set by the Council Regulation itself, and national competent authorities grant them on a case-by-case basis. No central EU authority issues payment-specific licences; the application goes to the competent authority of the Member State where the firm is established or where the funds are located.

The most commonly used derogations for payment processors cover: satisfaction of prior contractual obligations entered into before the designation date; payments for basic human needs (food, rent, medical care) on behalf of a designated natural person; legal costs; and extraordinary expenses. Each category has conditions, and not all categories appear in every sanctions regime – the Council tailors the derogation structure to the specific programme.

Timing matters. A prior-contract derogation must, in most programmes, be applied for within a defined window and cannot be used retroactively to authorise a payment already made. A payment processor that executes a payment and then applies for a derogation is in a different legal position from one that identifies the issue, freezes the payment, and applies for authorisation before proceeding.

The licensing process under EU regulations is not fast by default. National competent authorities vary significantly in their processing times, resourcing, and the detail they require in an application. We have acted for firms in Member States where a straightforward prior-contract derogation application took several months to process, while the funds remained frozen and the commercial relationship strained. Early legal advice, and a well-prepared application file, materially shortens that timeline in practice.

One cross-regime point that is practically important: an EU derogation does not authorise the corresponding USD leg of a transaction if that leg routes through the US financial system. If the euro payment is licensed by an EU competent authority but the USD correspondent transfer is processed by a US institution, OFAC rules apply independently. Dual-licensing – applying concurrently to OFAC and the relevant EU authority – is the appropriate approach for cross-currency payment flows.

What are the principal risk flags for payment processors?

Ownership and control gaps are the primary systemic risk for payment processors operating under EU rules, as set out above. Beyond that, five further risk patterns arise regularly in practice.

First, nested-payment structures. Where a payment processor sits in a chain between an originating institution and a beneficiary institution, it may not receive the full transaction data needed to screen effectively. EU rules, reinforced by the relevant Wire Transfer Regulation, require that information about the payer and payee accompanies the payment message throughout the chain. Gaps in that data are a red flag and a compliance obligation independently of the sanctions screen.

Second, customer-wallet structures. Where a payment platform holds pooled or omnibus accounts on behalf of retail or SME customers, individual customer-level screening must happen at onboarding and on an ongoing basis. A platform that screens only at the account level – and does not screen sub-account holders – creates a structural gap.

Third, crypto and tokenised asset flows. Virtual asset service providers (VASPs – entities offering exchange, custody, or transfer services for crypto-assets) are subject to EU sanctions in the same way as traditional payment-service providers. The absence of a bank-intermediary does not remove the obligation; the VASP must screen counterparty wallet addresses and conduct the same beneficial-ownership analysis as a credit institution.

Fourth, non-EU correspondent relationships. A payment instructed by an EU-based payer but routed through a non-EU correspondent does not leave EU jurisdiction for sanctions purposes. The EU-regulated originating firm remains responsible for the payment's compliance. The non-EU correspondent may have its own screening obligations under OFAC or OFSI, but those do not substitute for the EU firm's obligations.

Fifth, designation updates. Sanctions lists change, sometimes several times a week. A customer or counterparty that passed screening at onboarding may be added to the EU Consolidated List at any point thereafter. Ongoing monitoring – not just point-in-time screening – is an obligation, and frequency of rescreening is a direct function of the firm's risk rating of the relationship.

If a transaction has already been flagged, a payment blocked, or a regulator query received, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential initial assessment.

How is EU payment-processing controls enforced?

Enforcement of EU sanctions is a matter for national competent authorities, and penalty structures differ materially across Member States. Some Member States impose strict-liability administrative penalties for breaches, with no requirement to show intent; others require at minimum negligence. Criminal penalties for wilful violations are available in most Member States and may include custodial sentences for natural persons. The firm-level financial penalty bases vary: some national regimes cap sanctions at a fixed amount, others apply a turnover-based multiplier, and a small number allow penalties that track the value of the breach.

The lack of a single EU enforcement authority means that a payment processor operating across multiple Member States faces potentially multiple enforcement proceedings for the same underlying breach, in different procedural traditions and with different penalty outcomes. That asymmetry is not theoretical; we regularly advise financial institutions that face parallel inquiries from two or more national authorities arising from the same payment flow.

Voluntary disclosure – proactively reporting a potential breach to the national competent authority before it is detected – is recognised as a mitigating factor in most Member State enforcement frameworks, although the degree of mitigation and the procedural mechanism differ. A voluntary self-disclosure (VSD – proactive notification of a regulator before detection) that is prompt, complete, and accompanied by a clear remediation plan is treated more favourably than a disclosure made after the authority has begun an inquiry. Timing is therefore critical: the decision to disclose should be made with legal advice, promptly upon identification of the issue.

Record-keeping obligations are an integral part of the enforcement picture. Council regulations require firms subject to EU sanctions to maintain adequate records of their compliance actions. The specific retention period differs by programme and by Member State procedural rules, but practitioners generally advise keeping records for a minimum period consistent with national limitation periods for administrative proceedings – which in several Member States extends to five years or more from the date of the relevant transaction or action.

Appeals against national enforcement decisions follow the administrative and judicial review routes of the relevant Member State. Challenges to the underlying designation – the listing of the person or entity on the EU Consolidated List – go to the EU General Court by way of an annulment action under the Treaty on the Functioning of the European Union. These are distinct proceedings. A payment processor challenging a penalty decision is not the same party or proceeding as a designated person challenging their own listing.

How does the EU regime compare with OFAC and OFSI?

The three regimes share the same structural objective – blocking access to the financial system for designated parties – but diverge in ways that matter operationally to cross-border payment processors.

On the ownership and control test, the OFAC position is mechanical: 50 percent or more aggregate ownership by blocked persons captures the entity, full stop. OFSI and the EU both add a control limb: a person who does not own 50 percent may still control, and the controlled entity is caught. For a payment processor that screens globally, this means that a counterparty that passes an OFAC screen is not automatically clear under EU or UK rules.

On licensing, OFAC runs a centralised specific-licence system through a single regulator. EU licensing is decentralised to national competent authorities, with the derogation categories set by the Council. OFSI operates a separate, UK-only specific-licence system. A multi-currency payment that requires authorisation may need concurrent applications to three or more authorities, each with different forms, timelines, and evidential requirements.

On extraterritoriality, OFAC's reach is broader: it extends to non-US persons for dealings in US dollars, for US-nexus transactions, and through secondary-sanctions measures that target persons doing business in designated sectors regardless of US connection. EU sanctions bind persons and entities subject to EU jurisdiction – broadly, those established in the EU, operating within the EU, or dealing in euros – but do not generally extend to purely non-EU transactions. However, a euro-denominated payment that clears through an EU correspondent bank brings the EU rules into play even if both the payer and payee are outside the EU.

On enforcement structure, OFAC acts as a single national authority with a published enforcement framework and a public record of penalty notices. OFSI does the same for the UK. The EU's multi-authority model means that enforcement outcomes are less predictable and less publicly visible, which makes it harder for practitioners to calibrate risk without detailed Member State-specific knowledge.

Does your compliance programme treat EU, OFAC, and OFSI as genuinely distinct regimes, or does it apply a single rule-set to all three? In our experience, the firms that face the most difficult enforcement conversations are those that built their programme around OFAC and assumed the EU and UK requirements were substantially the same.

Related practices

Frequently asked questions

Who administers payment-processing controls under EU?
EU payment-processing controls are administered by national competent authorities in each EU Member State, acting under directly applicable Council Regulations imposed by the Council of the European Union. There is no single EU-level enforcement body. In practice, the national authority may be a finance ministry, central bank, or designated financial supervisory authority, depending on the Member State. Firms with operations across multiple Member States must engage with each relevant authority separately.
What does EU prohibit in relation to payment-processing controls?
EU sanctions prohibit making funds or economic resources available, directly or indirectly, to or for the benefit of a designated person or entity, and require the immediate freezing of assets belonging to, owned by, or controlled by designated parties. For payment processors, this means that initiating, executing, or releasing a payment to or for the benefit of a designated party is prohibited. Entities owned 50 percent or more by designated persons, or otherwise controlled by them, are caught even if not themselves listed.
How is payment-processing controls enforced under EU?
Enforcement is carried out by national competent authorities in each Member State, using administrative and criminal mechanisms that vary in penalty structure and procedural requirements across the EU. There is no single EU enforcement body. Voluntary self-disclosure of a breach, made promptly and in full before the authority identifies it, is generally treated as a mitigating factor. Record-keeping obligations support enforcement; inadequate records independently expose a firm to adverse findings during an investigation.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.