A trading company incorporated in Germany enters a supply agreement with a distributor based in a third country. Weeks into the relationship, a routine screening sweep flags a beneficial owner of the distributor against the EU Consolidated Sanctions List. The question arrives immediately: is the distributor itself prohibited? Can existing invoices be paid? Does the prior shipment trigger a reporting obligation? These questions are not theoretical. They arise in cross-border commercial relationships daily, and the consequences of answering them incorrectly are substantial.
Counterparty due diligence under EU sanctions law requires a systematic assessment of ownership, control, and exposure against the EU Consolidated Sanctions List and the relevant thematic Council regulations. The governing authority is the Council of the European Union, with enforcement distributed across the competent authorities of EU Member States. Where a counterparty, or a person who owns or controls it, appears on the EU list, all funds and economic resources must be frozen, and making funds or resources available to them is prohibited.
This page explains the legal basis and scope of EU counterparty due diligence, the ownership-and-control test that determines when a non-listed entity is caught, the procedure for conducting a defensible review, the points at which EU exposure intersects with OFAC and OFSI obligations, and the risk flags that signal a need for specialist counterparty due diligence EU legal support.
What is the legal basis for EU counterparty due diligence?
EU sanctions obligations derive from Council regulations adopted under the relevant Council Decisions. These instruments create directly applicable law across all EU Member States without the need for transposition. Any person or entity established in the EU, any EU national wherever located, and any person or entity conducting business within the EU must comply. The geographic reach extends beyond corporate headquarters: an EU-incorporated subsidiary of a non-EU parent is within scope, and a transaction routed through an EU correspondent bank can create EU obligations for the non-EU principal.
The EU Consolidated Sanctions List, maintained by the European Commission, is the reference list for asset-freezing designations. Separate from it, thematic Council regulations define the prohibited conduct for each country or subject-matter regime. The list does not operate in isolation from those regulations. A counterparty may not appear by name on the list but may nonetheless be caught through the ownership and control test (the EU rule that a non-listed entity is caught when a listed person owns or controls it).
Compliance counsel advising on EU counterparty screening must therefore review both the list and the underlying regulations simultaneously. Reviewing only one without the other is a recurring source of exposure. In our practice, we regularly advise clients who believed their screening programme was adequate because it matched against the list, only to find that the control leg of the test had been ignored entirely.
How does the EU ownership and control test work in practice?
The EU ownership and control test determines whether a non-listed entity falls within the asset-freeze and dealing prohibitions because a listed person owns or controls it. Ownership and control are assessed separately, and either leg can be sufficient.
On ownership, EU regulations generally apply a 50 percent or more ownership threshold, treating entities in which a listed person holds directly or indirectly 50 percent or more of the proprietary rights as caught. This mirrors the OFAC position in one respect: the aggregation of holdings across multiple listed persons counts toward the threshold. Two listed persons each holding 30 percent of the same target can together satisfy the ownership test, even if neither does individually.
Control is the more demanding element. EU regulations extend the prohibition to entities controlled by a listed person, and control is not defined by a single numerical threshold. A listed person sitting on a management board, exercising veto rights over material decisions, or directing strategy through contractual arrangements can satisfy the control test without holding a majority ownership stake. This is the point at which EU analysis diverges most clearly from the US position under OFAC, where the 50 percent rule is mechanical and does not include a standalone control test. Practitioners advising on EU counterparty risk must map control structures, not merely share registers. Have you confirmed that your counterparty's governance documents – its articles of association, shareholder agreements, and board composition – do not give a listed person control rights below the ownership threshold?
We regularly see the control question overlooked in due diligence reviews that focus exclusively on share registers. A listed person who is a minority shareholder but holds a contractual right of approval over material contracts can satisfy the EU control test, creating a dealing prohibition that renders the entire commercial arrangement unlawful.
The position above covers the standard case. Your facts – the counterparty's jurisdiction of incorporation, the structure of its shareholder agreement, the nationality of its ultimate beneficial owners, and the specific EU regime engaged by your goods or services – change the analysis materially. For an initial assessment of your counterparty's EU sanctions exposure, contact Calder & Vance at info@caldervance.com.
What does a defensible EU counterparty due diligence review cover?
A defensible EU counterparty due diligence review is not a single database search. It is a structured process that begins with the counterparty as a legal entity and works outward through its ownership chain, its management, its affiliates, and its business activities, matching each layer against the EU Consolidated Sanctions List and the relevant thematic regulations.
The core steps are these. First, identify the legal entity precisely: full legal name, jurisdiction of incorporation, registration number, and any trading names or former names. Second, identify all persons who hold an ownership interest and all persons who exercise control. This requires reviewing corporate registry extracts, beneficial ownership disclosures, and – where available – shareholder agreements. Third, screen all identified persons against the EU list using a disciplined name-matching methodology that accounts for transliteration variants, common misspellings, and date-of-birth confirmation. Fourth, assess the ownership and control test: do any listed persons reach the thresholds or satisfy the control criteria?
Fifth, identify the specific EU regulations applicable to the transaction or relationship. The prohibition on providing funds or economic resources differs in its details across the major EU regimes, and some regimes include sector-specific restrictions that go beyond the list-based asset-freeze prohibitions. A counterparty that passes the list check entirely may still be engaged in a restricted sector under the applicable Council regulation. Sixth, document the analysis contemporaneously. The record of the review – its methodology, its sources, and its conclusions – is the primary defence if a competent authority later questions the transaction.
Record-keeping is not optional. EU instruments and Member State implementing legislation impose documentation obligations, and a well-maintained review record can demonstrate good faith and procedural rigour in any subsequent enforcement dialogue.
How does EU counterparty due diligence compare with OFAC and OFSI requirements?
For businesses operating across jurisdictions, EU counterparty due diligence sits alongside OFAC and OFSI obligations rather than replacing them. The regimes are concurrent and, in some respects, divergent. Where they diverge, the stricter prohibition governs the actor subject to both.
Under OFAC, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked) is the primary test. There is no freestanding control test independent of the ownership analysis. An entity owned 49 percent by a Specially Designated National is not automatically blocked by that fact alone under OFAC, though OFAC may designate it separately. Under the EU and under OFSI, a listed person exercising control without reaching the ownership threshold can still bring the entity within the prohibition.
OFSI's approach under the UK sanctions regime has moved closer to the EU position on control. The UK ownership-and-control test, applicable under SAMLA-derived regulations, evaluates both direct and indirect ownership and a broader conception of control. For a business that is simultaneously subject to EU and UK obligations – common for EU-incorporated subsidiaries of UK parents or for financial institutions with regulated entities in both jurisdictions – the analysis requires parallel tracks. The more restrictive conclusion on ownership or control governs the overall position.
The secondary-sanctions dimension is also relevant here. OFAC's secondary-sanctions authorities allow it to take action against non-US persons who engage in significant transactions with certain designated persons, even where no US nexus to the transaction exists. A European business conducting counterparty due diligence under EU rules may satisfy EU requirements entirely and still face secondary-sanctions exposure under OFAC if the counterparty is also subject to a US programme. In our cross-border practice, we advise clients to assess the OFAC exposure in parallel with the EU analysis, because a clean EU screen does not foreclose US consequences.
For a detailed treatment of the OFAC counterparty review process, see our service page at Counterparty due diligence under OFAC. For the UK position, see Counterparty due diligence under OFSI.
If a transaction has already been flagged, or a payment has been refused by a correspondent bank, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.
What are the principal risk flags in EU counterparty due diligence?
Several patterns in counterparty structure or in transaction documentation consistently signal elevated EU sanctions risk. Recognising them early in a commercial relationship is materially less costly than identifying them after a transaction has closed.
Opacity in beneficial ownership is the most common indicator. A counterparty that provides only its immediate corporate parent, declines to disclose its ultimate beneficial owners, or structures its ownership through bearer shares or nominee arrangements creates a gap in the review that the EU prohibition can fill. The obligation under EU instruments is to look through to the natural persons who ultimately own or control the entity. Refusal to support that inquiry is itself a red flag.
Unusual payment routing is a second indicator. Requests to pay an invoice to a third-party account, to a jurisdiction unrelated to the counterparty's operations, or to an account that changes between transactions merit scrutiny. The EU prohibition covers making funds and economic resources available indirectly, meaning a payment to an unrelated third party on the counterparty's instruction can be a violation if the third party is linked to a listed person.
Sector exposure under thematic regulations is a third risk. The major EU Council regulations covering specific country programmes impose sector-specific restrictions that prohibit transactions in defined industries regardless of whether any individual counterparty is on the list. A counterparty operating in a restricted sector – for example, extractive industries, military goods, or certain financial services under a relevant regime – may be prohibited even if it and all its owners pass a clean list check.
Goods and technology classifications present a related exposure. EU dual-use rules restrict the export of goods and technologies with both civil and military applications, and the classification of the goods being supplied to a counterparty is part of the full counterparty due diligence review. A payment obligation can be lawful while the underlying supply remains subject to export-authorisation requirements.
Finally, changes in counterparty circumstances during a relationship require ongoing attention. A beneficial owner acquiring a listed person's interest, a management change that brings a listed individual onto the board, or a new designation of the counterparty itself during the contract period can all change the status of an ongoing arrangement. EU compliance is not satisfied by a point-in-time review conducted at the outset of the relationship.
How does Calder & Vance assist with EU counterparty due diligence?
We act for multinationals, financial institutions, exporters, and trading houses that require structured, documented counterparty due diligence under EU sanctions law. Our assistance covers the full review process: screening the counterparty and its ownership chain against the EU Consolidated Sanctions List and the relevant thematic regulations, mapping the ownership and control test to the counterparty's specific corporate structure, identifying sector-specific restrictions under the applicable Council regulation, and producing a written advice memorandum that records the methodology and the conclusions.
In a recent matter, a manufacturing business entering a distribution agreement in a third market asked us to review the proposed distributor. The distributor was not on the EU list. However, its largest minority shareholder held significant contractual veto rights over the distributor's key commercial decisions. We assessed that the shareholder's position raised a credible control question under the applicable Council regulation and advised the client to seek a restructuring of the governance rights before signing. The client negotiated the removal of the veto provisions. The relationship proceeded on terms that the client's compliance committee could approve without reservation.
We also assist clients who are in the middle of an existing relationship when an issue arises. Where a new designation has caught a counterparty or its owner during a commercial relationship, we assess the consequence for pending obligations, advise on the reporting obligation to the relevant Member State competent authority, and assist with any application for a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) where one is available under the applicable Council regulation.
A common objection is that specialist counsel is needed only when something has gone wrong. In our experience, the opposite is more accurate. The cost of a structured counterparty review before a transaction closes is a fraction of the cost of unwinding a prohibited arrangement, managing an enforcement inquiry, and demonstrating to a competent authority that the violation was inadvertent. Proactive diligence is a risk-management investment, not a compliance overhead.
For programmes that require systematic counterparty review across a portfolio of relationships – banks conducting periodic refresh reviews, trading houses screening new suppliers, or M&A teams assessing a target's counterparty base – we structure the engagement around a programme approach, with consistent methodology, documented outputs, and a defined scope that can be reported to a compliance committee. See also our practice in compliance audit and testing, which addresses how to test whether an existing programme is operating as designed.
Myths and objections: what businesses often get wrong about EU counterparty due diligence
Two misconceptions recur with enough frequency that they deserve direct treatment.
The first is that a clean result from a commercial sanctions-screening database is sufficient to conclude that a counterparty is not prohibited. It is not. Commercial databases match legal names and aliases against the EU Consolidated Sanctions List. They do not assess the ownership chain, apply the control test, or evaluate sector-specific restrictions under the applicable Council regulation. A counterparty can pass every automated screen and remain prohibited under EU law by virtue of a listed person's control position or a sector prohibition. The database is the starting point, not the conclusion.
The second is that the EU obligation applies only to entities incorporated in the EU. That position is wrong in two directions. EU regulations apply to EU nationals wherever they are located, and to any person conducting business within the EU regardless of where they are incorporated. A US subsidiary of a German parent may have EU obligations for conduct it takes in respect of EU-linked transactions. A non-EU business that routes payments through an EU financial institution creates EU obligations for that institution, which then conducts its own review – and a refusal by the bank on EU grounds is the practical consequence of non-compliance by the principal. Understanding the full jurisdictional reach of EU sanctions is the foundation of a credible counterparty due diligence review.
Related practices
- Counterparty due diligence under OFAC – structured counterparty review under US OFAC sanctions obligations
- Counterparty due diligence under OFSI – UK financial-sanctions counterparty review and ownership analysis
- Compliance audit and testing – testing whether existing sanctions screening programmes operate as designed