A European trading company receives formal notification that one of its long-standing distributors has been designated under an EU Council regulation. Contracts are mid-execution. Receivables remain outstanding. Staff in three countries need to know, immediately, whether they can lawfully complete the work already under way – or whether every subsequent action risks a sanctions violation. This is the moment wind-down authorisations exist to address.
Wind-down authorisations under EU sanctions rules are time-limited permissions granted by competent authorities in EU Member States, allowing parties to complete pre-existing contracts or obligations that would otherwise be prohibited following a new designation. They are grounded in the relevant Council regulation governing the applicable sanctions programme, and they carry strict conditions on scope, duration, and reporting. As of June 2026, the regime is actively used across multiple EU sanctions programmes, and the obligations attached to these authorisations are enforced with increasing rigour at Member State level.
This briefing explains who administers EU wind-down authorisations, what the legal basis and scope look like in practice, how the procedure works, where the regime diverges from OFAC and OFSI equivalents, what the principal risk flags are, and when to involve sanctions counsel.
Who governs EU wind-down authorisations, and what is their legal foundation?
EU wind-down authorisations are administered by the competent authority (the designated national body in each EU Member State responsible for granting derogations and licences under the applicable Council regulation) of the Member State in which the applicant is established or where the relevant activity takes place. There is no single EU-level licensing authority for sanctions derogations of this kind. The Council enacts the prohibition and the derogation mechanism; execution falls to Member States individually.
The legal foundation sits in the relevant Council regulation implementing the applicable EU sanctions programme. Each regulation typically lists categories of permitted derogation, and wind-down permissions are one such category. They are not automatically available. A party must apply, demonstrate that a pre-existing contractual obligation exists, and satisfy the competent authority that the requested activity falls within the defined perimeter of the derogation.
This decentralised structure has a material practical consequence. The competent authority in one Member State may interpret the derogation narrowly; another may apply it more broadly. Application timelines also differ. In our experience advising cross-border groups, a business with entities in multiple EU Member States may face divergent outcomes on functionally identical fact patterns – a significant source of operational risk that is frequently underestimated at the planning stage.
The Council and the European Commission publish guidance to narrow interpretation gaps, but that guidance is not legally binding on Member State authorities. The EU General Court – and in some cases the Court of Justice – provide the ultimate appellate route, but litigation is a slow remedy when a commercial wind-down window is measured in weeks.
What scope does an EU wind-down authorisation cover?
An EU wind-down authorisation permits the completion of specific, pre-existing contractual arrangements that would otherwise be prohibited by the asset-freeze and dealing prohibitions in the applicable Council regulation. The scope is narrow by design. It does not authorise new business, new extensions of credit, or the entry into successor contracts with a designated counterparty.
Typically, the permitted activities include receipt of payments due under a contract signed before designation, delivery of goods or services already contracted and partially performed, and the return of property or collateral that must pass through the designated person to be unwound. What is not permitted – and this distinction is critical – is any transaction that, on its substance, amounts to a fresh benefit flowing to the designated party.
The temporal scope is equally important. Authorisations are time-limited; the period varies by Member State and by the terms of the relevant Council regulation's derogation provision. Parties who fail to complete the permitted transactions within the authorised window cannot simply re-apply and expect an extension as a matter of course. In our practice, we have seen businesses lose the benefit of a wind-down authorisation through poor internal project management rather than any legal deficiency in the original application.
What activities are expressly excluded? Fresh credit, new contractual commitments, payment of interest accruing after the designation date (unless specifically authorised), and any transaction whose commercial purpose is to transfer value to the designated person in a manner not strictly required by the pre-existing obligation. Any ambiguity about whether a specific action falls inside or outside the authorised scope should be resolved before the action is taken, not after. Retroactive authorisation is not available in the EU regime.
How does the application procedure work in practice?
A wind-down authorisation application under an EU sanctions programme is submitted to the competent authority of the relevant Member State, typically in writing, and must identify the pre-existing contractual obligation with specificity, name the designated counterparty, describe each transaction the applicant seeks to complete, and provide a proposed time frame. Documentary evidence of the pre-existing contract is mandatory.
The competent authority will assess whether the derogation criteria in the applicable Council regulation are met. Some Member States have published standard application forms; others expect a free-form submission. Processing times are not harmonised. A well-prepared application in a jurisdiction with an experienced competent authority can be processed within a matter of weeks; poorly documented submissions, or applications to less-resourced national bodies, can take considerably longer – a critical concern when the commercial window is closing.
Once granted, the authorisation will specify the permitted transactions, the counterparties covered, the monetary ceilings (if any), and the expiry date. It will also impose reporting obligations. Most Member State authorities require the authorisation holder to report what transactions were actually completed under the authorisation, and within what time frame. Failure to report – even where the underlying transactions were entirely compliant – is itself a breach.
The position above covers the standard case. Your facts – the Member State involved, the specific Council regulation, the nature of the pre-existing obligation, and the counterparty's designation category – change the analysis materially. For a preliminary assessment of whether a wind-down authorisation is available for your transaction, contact Calder & Vance at info@caldervance.com.
How does the EU approach compare with OFAC and OFSI wind-down mechanisms?
The EU, OFAC, and OFSI each provide mechanisms for completing pre-existing activity following a designation, but the three regimes differ substantially in structure, availability, and the conditions attached. Understanding these divergences is essential for any business operating across US, UK, and EU jurisdictions simultaneously – which describes most of the clients we advise.
Under OFAC, wind-down permissions are frequently implemented through general licences (standing authorisations published by OFAC that permit defined categories of transactions without a separate application), which provide a defined window – often measured in days from the designation date – during which certain wind-down activity is automatically authorised. An OFAC specific licence (a case-by-case authorisation) may be available where no general licence applies. The OFAC model is comparatively centralised: one authority, one process, one set of published guidance. For background on the OFAC equivalent, see our wind-down authorisation guide for OFAC.
OFSI in the United Kingdom administers a licensing regime under SAMLA and the relevant thematic UK sanctions regulations. OFSI does not routinely issue general licences for wind-down purposes in the same way OFAC does. Instead, parties typically apply for a specific licence from OFSI, demonstrating that the proposed activity meets one of the licensing grounds defined in the applicable UK sanctions statutory instrument. OFSI guidance emphasises that a licence does not guarantee approval; it assesses each application on its merits. For further detail see our related OFSI licensing briefing.
The EU model sits between these two poles in some respects, but is structurally distinct from both. There is no EU-wide general licence. There is no single competent authority. The derogation must be applied for by entity, by Member State, and by reference to the specific Council regulation in play. A business with entities in France, Germany, and the Netherlands may need three separate applications to three separate competent authorities, each applying the same Council regulation but potentially with differing procedural requirements.
Where all three regimes converge is in their treatment of new business: none permits the use of a wind-down authorisation or licence as a vehicle for establishing fresh economic relationships with a designated person. The stricter prohibition governs where obligations under two or more regimes overlap. A transaction that is permitted under an EU wind-down authorisation but falls within an OFAC prohibition – because the counterparty is also on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) – remains prohibited. Secondary-sanctions exposure adds a further layer of analysis that competent authority approval at the EU level does not resolve.
What are the principal risk flags for businesses seeking EU wind-down authorisations?
The most common risk we observe in practice is the assumption that a wind-down authorisation, once granted, is self-executing. It is not. The authorisation defines the outer boundary of what is permitted; it does not approve each individual transaction that falls within that boundary. Parties must still exercise judgment, maintain records, and – critically – stop when the authorisation expires, even if the commercial wind-down is incomplete.
A second risk is jurisdictional mismatch. A wind-down authorisation granted by one Member State's competent authority does not extend to activities carried out through a group entity in another Member State. Groups that treat an authorisation held by a parent as covering subsidiary activity in another EU country are operating without legal cover in that subsidiary's jurisdiction. This is not a technical point; it is an enforcement exposure.
Third, the interaction with banking and payment infrastructure creates practical bottlenecks. A financial institution processing a payment within the scope of a valid EU wind-down authorisation must itself be satisfied that the transaction is covered. Banks conduct their own sanctions screening. In our experience, a well-drafted authorisation that clearly describes the permitted transactions significantly reduces the risk of a correspondent bank refusing the payment on the grounds that the beneficiary appears on a sanctions list. Vague or broadly worded authorisations create exactly that problem.
Fourth, record-keeping requirements are non-negotiable. The applicable Council regulation and most competent authority guidance require that records of transactions carried out under a wind-down authorisation be maintained for a defined period. These records form the evidential basis of any enforcement defence. A business that cannot demonstrate, transaction by transaction, that it stayed within the authorised scope has no meaningful protection. See our related service on frozen account management and compliance infrastructure for how we structure record-keeping frameworks.
Fifth, and frequently overlooked: what happens when the wind-down period ends and transactions remain incomplete? The correct answer is to stop and seek further advice. The wrong answer – commercially understandable but legally untenable – is to continue on the assumption that the spirit of the authorisation extends beyond its terms. Competent authorities and enforcement bodies do not accept that reasoning.
How are EU wind-down authorisations enforced, and what are the consequences of breach?
Enforcement of EU sanctions, including the conditions attached to wind-down authorisations, falls to Member States under the principle that each state implements EU sanctions obligations through its own criminal and administrative law. The result is that sanctions enforcement intensity, penalty levels, and prosecution thresholds differ across the EU. There is no single EU sanctions enforcement authority equivalent to OFAC or OFSI.
What Member States share is the obligation to impose effective, proportionate, and dissuasive penalties. The EU has moved toward greater harmonisation of criminal sanctions for serious sanctions violations, and the direction of travel is toward higher penalties and expanded personal liability for directors and compliance officers. In our experience advising businesses facing enforcement inquiries, the competent authority's first question is nearly always whether the business had a functioning compliance programme in place at the time of the alleged breach.
A breach of a wind-down authorisation's conditions – acting outside the authorised scope, exceeding the monetary ceiling, failing to report, or continuing after expiry – is treated as a sanctions violation in its own right, separate from the underlying designation. This point surprises many clients. Having obtained the authorisation does not immunise a business from enforcement; it creates a set of ongoing obligations whose breach is itself sanctionable.
Voluntary self-disclosure (VSD – proactively reporting an apparent violation to the competent authority before it is discovered independently) is recognised as a mitigating factor in most Member States, though its procedural and evidential requirements vary. A timely, accurate, and well-structured VSD can materially affect the enforcement outcome; a poorly constructed one can create additional exposure. If a transaction has already been flagged, or an authorisation's conditions may have been exceeded, an early legal review preserves options that narrow significantly with time. Contact Calder & Vance at info@caldervance.com for a confidential first assessment.
A common misconception: the authorisation protects the whole group
One myth we encounter regularly in our cross-border practice is that a wind-down authorisation obtained by one entity in a group – typically the parent or the contracting entity – protects all affiliated companies that touch the wind-down activity. It does not.
An EU wind-down authorisation is granted to a named applicant, for defined transactions, in the jurisdiction of the competent authority that issued it. A subsidiary in another Member State processing a payment, a logistics affiliate moving goods, or a shared-service centre handling invoicing are all acting in their own right. Each must have independent legal cover for its specific activity. Where that cover does not exist, those entities are exposed, regardless of what the parent's authorisation says.
The same principle applies within a single Member State. An authorisation granted to Entity A does not automatically extend to Entity B, even if both are wholly owned by the same parent and operating from the same premises. Competent authorities will not accept group-level rationale as a substitute for entity-level authorisation where the regulation requires the latter.
In a recent matter, a multinational services group held a valid EU wind-down authorisation for its principal contracting entity. A shared-service centre in a different Member State continued to process invoices and payments in support of the wind-down, assuming coverage from the parent's authorisation. It had none. We assisted the group in mapping the activity, identifying the entities that required separate applications, and engaging with the relevant competent authorities. The matter was resolved, but the process reinforced that group-wide assumptions about authorisation coverage are among the most common and consequential errors in EU sanctions compliance.
Related practices
- Frozen account management and BIS/EAR compliance – structuring record-keeping and compliance controls around frozen assets and licensing obligations
- Wind-down authorisations under OFAC – how the US regime handles pre-existing contract completion after designation
- OFSI licensing and wind-down guidance – the UK specific-licence process and how it compares with the EU and US approaches