Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · EU

Penalty defence and settlement under EU: scope and obligations

A compliance officer at a European trading house receives a letter from a national authority. The firm processed several payments that, on further review, appear to have had a sanctioned nexus. The authority is asking questions. A penalty decision may follow. How the firm responds in the next weeks can determine whether the matter closes with a caution or escalates into a formal enforcement action with substantial financial consequences.

Penalty defence and settlement under EU sanctions law are governed by a decentralised enforcement model: the Council of the EU sets the prohibitions through Council regulations, but each Member State designates its own competent authority and sets its own penalty scale. As of April 2026, the EU has introduced a directive requiring Member States to align their criminal-law definitions of sanctions violations, which adds a new layer to an already complex enforcement picture. There is no single EU-wide "settlement" mechanism equivalent to OFAC's administrative process; instead, firms must engage with the relevant national authority, whose procedural rules, penalty caps, and mitigating-factor criteria differ from one jurisdiction to the next.

This briefing sets out who administers enforcement across the EU, what the legal basis looks like, which obligations create the greatest exposure, how the enforcement process typically runs, where the EU position diverges from OFAC and OFSI, and when to involve external counsel.

Who administers EU sanctions enforcement, and what is the legal basis?

EU sanctions enforcement sits at the intersection of supranational law-making and national-level implementation. The Council of the EU adopts restrictive measures by Council regulation – directly applicable in all Member States – and by accompanying Council decisions. The regulations impose the prohibitions; the decisions provide the political framework. Enforcement of those regulations is, however, a matter of national law. Each Member State designates one or more competent authorities – a financial intelligence unit, a central bank, a ministry of finance, or a trade authority, depending on the Member State – and those authorities investigate and penalise apparent violations.

The result is structural fragmentation. A group with subsidiaries in four EU jurisdictions faces four different penalty regimes, four different procedural timelines, and four different standards for what constitutes a mitigating or aggravating factor. In our cross-border practice, this fragmentation is the single most significant operational challenge for multinationals responding to an EU enforcement enquiry.

A directive on criminal sanctions for violations of EU restrictive measures was agreed at the EU level and Member States were required to transpose it into national law by a specified deadline. This directive establishes minimum standards for criminal liability – including for legal persons – and for the categories of conduct that must be criminalised. It does not replace the administrative enforcement track; both tracks can run in parallel. Verify the current transposition status in each relevant Member State before relying on any description of the criminal regime.

What obligations create enforcement exposure under EU sanctions?

The primary prohibitions in EU Council regulations cover four categories: asset freezes (no funds or economic resources may be made available to a designated person or entity), dealing prohibitions (no acquisition of, or transfer of, specified securities or instruments), trade restrictions (import and export bans on listed goods, technologies, or services), and financial services restrictions (prohibitions on specific banking, insurance, or capital-market services). Violation of any of these can trigger administrative or criminal enforcement.

Two secondary exposure points deserve particular attention. First, the circumvention prohibition: EU regulations expressly prohibit any action that is designed or intended to undermine the effect of the sanctions, even where no listed counterparty is directly involved. Second, the reporting obligation: persons and entities subject to EU law must report without delay to the competent authority when they hold or control funds or economic resources belonging to a designated person, and they must provide information that would assist in tracing assets. Failure to report is itself a sanctionable omission in most Member State implementing regimes.

The ownership and control (the EU test for whether a non-listed entity is caught through a listed person's ownership or control of it) question is a recurring source of inadvertent violation. The EU test extends beyond the mechanical fifty-percent threshold used by OFAC; an entity may be caught where a designated person exercises effective control even without majority ownership. In our experience, corporate groups underestimate this extension and screen only for formal ownership, missing control structures such as board appointment rights, veto powers, or financial dependency. Have your screening procedures been updated to capture control as well as ownership?

The standard of liability varies by Member State but generally includes both intentional violations and violations attributable to negligence or a failure to maintain adequate procedures. This means that a firm with a documented, well-tested compliance programme is materially better placed to argue mitigation, even where a violation is ultimately found.

How does the EU enforcement process run in practice?

The enforcement process typically proceeds through several stages, though the precise sequence depends on the Member State involved. Understanding each stage matters because the options available to a firm narrow as the process advances.

The process commonly follows this sequence:

  1. Trigger: The competent authority becomes aware of a potential violation – through a suspicious transaction report from a financial institution, a self-report by the firm, a referral from another authority, or its own monitoring. Where the firm is the source, a voluntary self-disclosure (VSD) at this stage is generally the strongest mitigating factor available.
  2. Preliminary enquiry: The authority issues a request for information. Responses are typically required within a short statutory window. The firm must assess the legal basis of the request and balance its disclosure obligations against legal privilege. In our practice, the framing of the initial response significantly shapes the subsequent direction of the investigation.
  3. Formal investigation: If the authority identifies grounds for a finding, it opens a formal file. It may conduct interviews, request further documents, and liaise with authorities in other Member States or with OLAF (the EU's anti-fraud office) where cross-border flows are involved.
  4. Statement of objections or draft decision: The firm receives a preliminary finding and is given an opportunity to respond. This is the primary procedural moment for penalty defence: submissions on the facts, on the applicable legal standard, and on mitigating factors (compliance programme quality, self-disclosure, cooperation, remediation, absence of prior violations) are made at this stage.
  5. Decision: The authority issues a final decision. Depending on the Member State, the decision may impose a fine, a caution, a direction to cease the conduct, or a referral to prosecutorial authorities for criminal proceedings.
  6. Appeal: Most Member States provide an administrative appeal route followed by judicial review before the national courts. The EU General Court has jurisdiction over challenges to the legality of Council regulations and designations themselves, but not over Member State penalty decisions.

There is no formal EU-level settlement mechanism comparable to OFAC's settlement agreements or OFSI's published enforcement decisions with agreed penalty amounts. Some Member States have introduced administrative settlement or compromise procedures, but these are not uniform. Where they exist, a negotiated resolution can reduce the penalty and avoid public naming in enforcement registers – considerations that are commercially material for regulated firms and for entities whose reputations depend on clean enforcement records.

How does EU enforcement compare with OFAC and OFSI?

The divergence between the EU enforcement model and those of the United States and the United Kingdom creates practical difficulties for cross-border businesses, particularly where the same underlying transaction touches all three regimes.

Under OFAC, enforcement is administered by a single federal agency. OFAC publishes its enforcement guidelines, its penalty matrix, and its settlement agreements, which gives the market reasonable visibility into how the agency weighs aggravating and mitigating factors. The entire process runs through one authority for all US-sanctions matters, regardless of sector or geography. OFAC's penalty bases can be substantial; transactions with a sanctioned nexus may attract a civil monetary penalty per violation, and the published enforcement record shows that financial institutions and corporates face material consequences for systematic failures.

Under OFSI in the United Kingdom, the Office of Financial Sanctions Implementation administers civil enforcement under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic regulations. OFSI publishes enforcement guidance that describes its approach to mitigating factors, including the weight given to a VSD (voluntary self-disclosure to a regulator). The OFSI monetary penalty regime operates on a strict liability basis for the most serious cases, meaning that a firm need not have known of the violation to be liable, though knowledge is relevant to penalty quantum. OFSI can also refer cases for criminal prosecution. The UK regime is a single national authority model, contrasting sharply with the EU's decentralised structure.

The practical implication for a business facing a potential violation with EU, UK, and US dimensions is that three separate disclosure and defence strategies may be required in parallel. The decision to make a VSD to one authority – which may be required under that authority's rules or strongly incentivised by its mitigation policy – can affect the position before the others. Timing and sequencing are critical. A disclosure made to OFSI may be visible to OFAC through information-sharing arrangements; a disclosure to a Member State authority may trigger reporting obligations within the EU network. This is an area where we regularly advise clients on the sequencing and framing of multi-jurisdictional disclosures.

The EU's extraterritorial reach also requires attention. EU Council regulations apply to EU-incorporated entities, EU nationals wherever located, and any conduct occurring in whole or in part within the EU. A non-EU parent with a EU subsidiary may therefore face EU enforcement exposure even where the directing mind is outside the EU. The interaction with US secondary-sanctions risk – where OFAC may penalise non-US persons for certain dealings with sanctioned parties – means that a single transaction can attract enforcement attention from multiple regulators simultaneously. The stricter prohibition governs where two regimes apply to the same conduct and prescribe different outcomes.

What are the principal risk flags in EU penalty proceedings?

Several patterns recur in EU enforcement matters. Recognising them early is essential to managing exposure.

  • Late self-disclosure. A firm that reports a violation after the competent authority has already identified it loses the benefit of voluntary self-disclosure as a mitigating factor. In some Member States, late disclosure is treated as an aggravating factor. The practical question is always whether to report before the authority asks.
  • Inadequate compliance programme documentation. Enforcement authorities assess the quality of the firm's compliance programme at the time of the violation, not at the time of the investigation. A programme that was upgraded after the fact may demonstrate good faith but does not retroactively establish that adequate procedures were in place. Contemporaneous documentation is essential.
  • Failure to capture control structures. As noted above, the EU ownership-and-control test extends beyond formal ownership. Firms that screen only for listed names or fifty-percent-plus shareholdings may miss entities that a listed person controls through other means. This gap is a recognised pattern in enforcement referrals we have reviewed.
  • Multi-jurisdictional disclosure sequencing. Making a disclosure to one national authority without assessing the implications for other EU Member States and third-country regulators can create an inconsistent record that complicates later proceedings.
  • Legal privilege. Internal investigation documents prepared for the purpose of obtaining legal advice generally attract privilege. Communications not prepared in that context may be disclosable. Structuring internal investigations correctly from the outset protects the firm's position.
  • Corporate group liability. The directive on criminal sanctions and several Member State administrative regimes impose liability on legal persons for acts committed by persons acting on their behalf. A parent company's exposure for a subsidiary's violation depends on the Member State's implementing rules and the degree of group-level oversight. This is a live risk for holding structures with operationally autonomous subsidiaries in multiple jurisdictions.

What is the most common mistake we see? It is the assumption that EU enforcement is slower or less consequential than OFAC enforcement. Several Member State authorities have significantly increased their enforcement activity and penalty levels in recent years, and the harmonisation directive is designed to accelerate that convergence.

The myth of the passive EU enforcer

A persistent misconception in the market is that EU sanctions enforcement is primarily a paper exercise – that authorities issue cautionary letters but rarely impose material penalties, and that the true enforcement risk comes only from OFAC. This view is incorrect and increasingly so.

Member State authorities in several EU jurisdictions have imposed penalties that are significant in absolute terms and that have been accompanied by public enforcement notices damaging to the affected firm's reputation and regulatory relationships. The harmonisation directive introduces a requirement for Member States to establish minimum penalty levels for the most serious violations. Combined with the increase in cross-border information sharing among EU competent authorities and between EU authorities and OFSI and OFAC, the practical enforcement exposure for a firm operating across EU jurisdictions has materially increased.

Firms that calibrate their EU compliance investment against the historic enforcement record of the least active Member State authority in their sector are misallocating their risk budget. The correct calibration takes account of the regime's full reach across all jurisdictions where the firm operates, the direction of travel of the harmonisation directive, and the cross-border intelligence-sharing that makes it harder to contain an identified violation within a single national enforcement process.

We have acted for businesses that initially approached a Member State enquiry as a minor procedural matter, only to find that the authority shared information with a second jurisdiction whose enforcement posture was significantly more aggressive. Early, coordinated legal advice across the relevant jurisdictions is the most effective risk-management measure available.

When should a firm involve external sanctions counsel?

The decision to involve external counsel is not exclusively a function of the scale of the apparent violation. Several triggers indicate that external advice is needed regardless of initial apparent severity.

The position above covers the standard investigation sequence. The specific facts – the counterparty involved, the nature of the goods or services, the jurisdictions touched, the identity of the competent authority, and whether a criminal referral is possible – significantly change the analysis and the timeline of available options.

External counsel should be involved at the earliest opportunity in any of the following situations:

  • A request for information has been received from any competent authority, even a preliminary or informal request.
  • A transaction or series of transactions has been identified internally as having a potential sanctioned nexus, before any disclosure decision is made.
  • A correspondent bank or counterparty has raised a query or frozen a payment citing sanctions concerns.
  • A corporate acquisition or restructuring is under consideration involving an entity with EU exposure.
  • The firm's internal compliance review has identified gaps in the ownership-and-control mapping for a high-risk counterparty.

If a matter has already reached the stage of a formal investigation, a draft penalty decision, or an administrative appeal, external counsel is not optional. The procedural windows for submissions are short. The opportunity to present mitigating evidence and to challenge the authority's legal analysis closes quickly. In our experience, the quality of the written submissions at the penalty defence stage is the single most significant variable in the outcome of an EU enforcement matter.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. To discuss an apparent violation, a pending authority enquiry, or a cross-border compliance review, contact Calder & Vance at info@caldervance.com.

Related practices

Frequently asked questions

Who administers penalty defence and settlement under EU?
EU sanctions enforcement is administered nationally: each Member State designates its own competent authority under the relevant Council regulation. There is no single EU-wide enforcement agency. The result is that a firm with operations in multiple Member States may face parallel proceedings before different national authorities, each applying its own procedural rules, penalty scale, and mitigating-factor criteria. A cross-regime compliance programme must account for this structural variation.
What does EU prohibit in relation to penalty defence and settlement?
EU Council regulations prohibit making funds or economic resources available to designated persons, circumventing sanctions through indirect arrangements, and failing to report holdings or relevant information to the competent authority. Violations of these prohibitions may give rise to administrative penalties, criminal liability, or both, depending on the Member State's implementing rules. The harmonisation directive requires Member States to criminalise the most serious categories of violation and to establish penalties for legal persons.
How is penalty defence and settlement enforced under EU?
Enforcement typically runs through a sequence of information requests, formal investigation, a statement of objections, and a penalty decision, with an appeal route to the national courts. There is no uniform EU-level settlement mechanism; some Member States have administrative compromise procedures that allow negotiated resolutions. Voluntary self-disclosure before the authority has identified the violation is the most material mitigating factor available in most Member State regimes. The EU General Court handles challenges to designations and Council regulations, not national penalty decisions.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.