A European trading company enters a long-term supply agreement. Midway through contract negotiations, the counterparty's legal team inserts a standard "sanctions clause" requiring both parties to represent that they are not designated persons, to comply with applicable sanctions law, and – crucially – to suspend performance if either party triggers a restriction. Does the clause reflect EU obligations accurately? Does it allocate risk correctly across regimes? And what happens when the counterparty is subject to US secondary-sanctions rules that the EU Blocking Regulation actively prohibits a European party from following?
Sanctions clauses in contracts under EU rules are shaped by a combination of mandatory Council regulations, the EU Blocking Regulation's anti-compliance commands for certain US secondary measures, and general contract-law principles on force majeure and hardship. No single EU instrument mandates a standard clause form. Instead, the regime imposes prohibitions on particular acts and persons, and competent national authorities – one per Member State – administer licensing and enforcement. Getting the clause wrong can expose a party to liability under multiple regimes simultaneously.
This briefing sets out the governing authority, the core obligations, the ownership-and-control test that determines who the prohibitions catch, the Blocking Regulation tension, drafting risk flags, and when to instruct cross-border counsel.
Who administers EU sanctions obligations – and what is the legal basis?
EU sanctions obligations derive from Council regulations adopted under the Treaty on the Functioning of the European Union. These instruments have direct effect across all Member States: they create rights and obligations without requiring implementing legislation in each country. The Council adopts the sanctions regime; the European Commission monitors consistency; and Member States designate a competent authority (a national body, often a treasury, finance ministry, or central bank unit) to administer licensing, reporting, and enforcement within their jurisdiction.
This structure matters for contracts. A sanctions clause that refers generically to "applicable EU law" may satisfy the letter of a compliance policy without telling either party who actually processes a licence application, how to notify a suspected breach, or which authority can grant an exemption. In our experience, clauses drafted at group level frequently name the wrong competent authority – or name none at all – leaving operational teams without a clear escalation path when a transaction is flagged.
Enforcement powers vary meaningfully between Member States. Some jurisdictions impose criminal penalties alongside civil fines; others rely on administrative sanctions alone. The severity of a breach of a contractual sanctions obligation therefore depends partly on where the contracting party is established and where the relevant act occurs. That jurisdictional texture is rarely captured in a standard clause.
What EU sanctions prohibitions do contracts need to address?
EU sanctions regulations prohibit a defined set of acts involving listed persons, listed entities, or specified goods and services. The core prohibitions relevant to commercial contracts typically include: making funds or economic resources available to or for the benefit of a designated person; dealing in the assets of a designated person; and providing services – legal, financial, brokerage, or technical – that would benefit a listed party or facilitate a prohibited transaction.
For a contract drafter, the operative question is: does this agreement, if performed, result in a prohibited act? That analysis runs at several levels. First, is either contracting party itself listed, or does the ownership and control test (the EU test for determining whether a non-listed entity is caught through a listed person's interest) capture it? Second, does the subject matter of the contract – the goods, the services, the financing – fall within a category that is restricted regardless of who the counterparty is? Third, does the contract route funds or value through a restricted country or sector in a way that triggers a sectoral measure?
A clause that addresses only "SDN-style" list screening misses the second and third questions entirely. We regularly advise clients whose contracts have been flagged not because of a listed counterparty but because the goods were dual-use items subject to export-control rules that overlay the sanctions regime, or because a payment route passed through a correspondent in a restricted jurisdiction. The clause must be broad enough to capture all three levels of analysis.
How does the EU ownership-and-control test work – and how does it differ from OFAC?
The EU ownership-and-control test catches non-listed entities that are owned or controlled by a listed person, and it extends beyond a mechanical ownership-percentage trigger. Under EU regulations, "owned" generally means a direct or indirect holding of more than 50 percent of the entity's proprietary rights or capital. "Controlled" is a separate and wider concept: it captures a listed person who can exercise decisive influence over an entity through voting rights, board appointment powers, or contractual arrangements – even without a majority shareholding.
This diverges from the OFAC 50 percent rule (OFAC's rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked), which is a mechanical ownership threshold without a freestanding control limb. In practice, the EU test can catch structures that OFAC's rule would not – for instance, a minority shareholder who holds contractual veto rights over strategic decisions. Conversely, the OFAC rule aggregates holdings across multiple blocked persons, which can produce a blocked entity where no individual blocked person holds a majority stake; EU analysis applies the same aggregation logic on the ownership side.
A well-drafted EU sanctions clause should therefore refer to entities "owned or controlled" by a listed person, not simply to entities in which a listed person holds a majority interest. The distinction is more than semantic: it affects how a party conducts its counterparty due-diligence and what representations it can give with confidence. Have you verified that your screening covers the control dimension, not just direct ownership?
The EU Blocking Regulation: when a sanctions clause creates liability rather than reducing it
The EU Blocking Regulation (the EU instrument that prohibits EU persons from complying with certain extraterritorial US measures and entitles them to claw back damages arising from such measures) creates a collision point that is largely invisible to standard sanctions-clause templates. The Regulation applies to specific US measures named in its Annex – currently including measures related to Cuba and the secondary-sanctions programmes targeting designated third countries. Where the Regulation applies, an EU operator is prohibited from complying with those US measures, from giving effect to foreign court judgments based on them, and from providing information to foreign authorities in furtherance of them.
Consider what that means for a standard sanctions clause. Many US-origin templates, and many clauses drafted for dual US/EU parties, include representations that the party does not engage in transactions with named countries, sectors, or programmes – including programmes that fall squarely within the Blocking Regulation's Annex. An EU party that signs such a clause and then performs it – for instance, by refusing to supply a counterparty it would otherwise be entitled to deal with under EU law – may breach the Blocking Regulation even as it seeks to comply with a contractual obligation.
In our cross-border practice, this tension is one of the most frequently mismanaged aspects of international commercial contracts. The typical solution is not to delete sanctions representations entirely, but to carve the Blocking Regulation's perimeter precisely: the EU party's representations and obligations under the clause should be limited to compliance with "EU sanctions law as applicable to that party," without extending to obligations that would require it to act in accordance with the extraterritorial measures listed in the Annex. That carve-out needs to be explicit and drafted with both regimes in front of the drafter. For comparison, OFSI's approach in the UK means a party with UK operations may face a third set of obligations – and the OFSI position on sanctions contract clauses diverges in its own ways from both the EU and OFAC positions.
The position above covers the standard case. Your facts – the counterparty's establishment, the goods or services, the payment routes, and the specific US measures in play – change the analysis materially.
For an assessment of your EU Blocking Regulation exposure and how to structure the relevant clause, contact Calder & Vance at info@caldervance.com.
What are the risk flags in a standard EU sanctions clause?
Certain patterns in standard EU sanctions clauses consistently generate compliance risk. The first is over-reliance on list screening. A clause that requires only that neither party appear on a designated list at signing is static: it says nothing about what happens if a designation occurs mid-contract, which is the scenario that matters most operationally. EU regulations do not provide a general grace period for existing contracts when a new designation occurs; the prohibition is immediate. The clause should address ongoing obligations, not just a point-in-time representation.
The second risk flag is ambiguity in the suspension or termination trigger. Many clauses allow either party to suspend performance "if a sanctions restriction applies." That formulation is too broad: it can be invoked on the basis of any sanction in any jurisdiction, including US secondary measures that the EU Blocking Regulation prohibits the EU party from following. The trigger should be limited to a restriction that legally binds the relevant party under the regime applicable to it.
Third, clauses that require a party to obtain a licence before performing a restricted act but say nothing about what happens if the licence is refused – or how long the application process may take – leave a gap in the commercial arrangement. Licensing timelines under EU regimes are handled at Member State level and vary. The clause should allocate the risk of delay and refusal, not simply require the attempt.
Fourth, indemnity provisions that require one party to hold the other harmless for any sanctions-related loss are frequently unenforceable as drafted: they may require a party to indemnify for losses arising from its own regulatory obligations, or may conflict with public-policy limits on indemnifying for regulatory penalties. In our experience, this is the provision most likely to produce a dispute that neither party anticipated at signing.
A common misconception is that a standard "compliance with applicable laws" clause covers sanctions adequately. It does not. EU sanctions regulations are detailed, prescriptive, and subject to frequent amendment. A generic compliance representation does not put the counterparty on notice of the specific prohibitions, does not allocate the risk of a new designation, and does not resolve the Blocking Regulation tension. Dedicated sanctions language is required.
How is a potential breach of EU sanctions obligations identified and reported?
When a party to a contract identifies a potential breach of EU sanctions obligations – for instance, because a counterparty is designated after signing, or because a payment is blocked – the first obligation is to freeze the relevant funds or economic resources and not to perform further acts that would compound the breach. Under EU regulations, a person who holds or controls funds belonging to a designated person is required to freeze them and to report that fact to the competent national authority within a defined period. That obligation runs independently of any contractual arrangement: the contract cannot waive it.
Notification obligations are set out in the relevant Council regulation and in the guidance issued by the Member State's competent authority. Timelines vary by regime and by Member State, but the reporting window is typically short – and acting promptly preserves the option of a voluntary self-disclosure (VSD: a proactive report to the regulator about an apparent breach, which in most EU Member States is a mitigating factor in penalty assessment). A failure to report, or a delayed report, is itself a breach of the regulations and can attract a separate penalty.
Contractually, a sanctions clause should require each party to notify the other promptly upon becoming aware of any circumstance that may result in a sanctions restriction applying to the contract. That mutual notification obligation allows both parties to consider their position before either is in breach of a performance obligation. Timing matters: the obligation to freeze or refrain from performance arises at the moment the restriction takes effect, not at the moment either party learns of it.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review of the position.
When does EU sanctions exposure require cross-border counsel?
EU sanctions clauses rarely operate in isolation. A contract between two EU-established parties may still be subject to US secondary-sanctions risk if it involves goods, technology, or financing with a US nexus. A contract between an EU party and a non-EU party may engage the Blocking Regulation, OFSI's UK rules, and the regime of the non-EU party's home state simultaneously. The question is not which regime is "primary" but which restrictions legally bind which party – and whether those restrictions are consistent or contradictory.
In our practice, the scenarios that most reliably require cross-border analysis are: contracts involving goods that are subject to both EU dual-use controls and the US Export Administration Regulations; contracts where one party is a US-owned subsidiary of a European group; financial-services agreements where the payment leg passes through a US correspondent bank; and joint-venture documentation where one of the proposed investors operates in a jurisdiction subject to a separate thematic sanctions programme.
The myth that EU law adequately protects a European business from US sanctions exposure is persistent and dangerous. OFAC's rules apply to any transaction that has a sufficient US nexus, including transactions settled in US dollars or involving US-origin technology, regardless of where the parties are incorporated. For a business with operations or trade flows touching the United States and the EU simultaneously, the analysis requires both regimes to be run in parallel. Our cross-border practice covers that dual-track assessment. The OFAC framework for sanctions contract clauses and the EU position need to be reconciled, not treated as alternatives.
The compliance audit and testing service at Calder & Vance includes review of existing contractual language against the applicable regime, identification of gaps and conflicts, and drafting of revised or replacement provisions.
Related practices
- Compliance Audit and Testing – identify gaps in existing sanctions-clause language and screening controls
- Sanctions Clauses under OFAC – how US rules on contractual obligations diverge from the EU position
- Sanctions Clauses under OFSI – UK-specific obligations and the OFSI licensing route for restricted transactions