Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · EU

Name and entity screening under EU: compliance counsel

A European distribution group is finalising a long-term supply agreement with a trading company whose ultimate beneficial owner holds shares through three intermediate holding vehicles. The compliance team's off-the-shelf screening tool returns no direct hits. The deal team wants to sign. Should it?

Name and entity screening under the EU sanctions regime requires more than checking a counterparty's name against the EU Consolidated List. The legal obligation extends to entities that designated persons own or control, regardless of whether those entities appear on the list themselves. A clean database hit on a counterparty's legal name does not discharge the duty. The ownership-and-control analysis does.

This page explains the governing regime, the ownership and control test as it operates under EU law, where the EU approach diverges from OFAC and OFSI, the practical risk flags that generate exposure, and how Calder & Vance assists businesses in building and testing screening programmes that satisfy the EU standard.

What governs name and entity screening under EU sanctions?

EU sanctions are administered by the Council of the European Union, which issues regulations and decisions that are directly applicable in all EU member states. The EU Consolidated List, maintained by the European External Action Service, is the primary reference for designated persons and entities. Screening obligations arise from the relevant thematic Council regulations – covering asset freezes, prohibitions on making funds or economic resources available, and related obligations on financial institutions, corporate actors, and others within EU jurisdiction.

Every party subject to EU law – including EU-incorporated entities, EU-based branches of foreign firms, and transactions touching EU persons or territory – must screen counterparties against the list before funds or economic resources change hands. The obligation is continuous, not transactional. A counterparty who was clean at onboarding may become listed tomorrow. Periodic rescreening is not optional; it is part of the compliance duty as regulators in member states have made clear.

The EU regime is enforced at national level. Each member state designates a competent authority – the Bundesbank in Germany, the Banque de France in France, HM Treasury's equivalent office in the UK before Brexit, the relevant financial regulator in the Netherlands – and that authority may impose civil penalties, refer criminal matters to prosecutors, and require disgorgement of funds. Enforcement posture and penalty ranges differ across member states, but the underlying legal obligation is uniform across the EU.

The position above covers the standard case. Your facts – the counterparty structure, the goods or services, the jurisdiction of the parties, the volume of transactions – change the analysis.

To discuss how the EU screening obligation applies to your business model, contact Calder & Vance at info@caldervance.com.

How does the EU ownership and control test work?

Under EU sanctions regulations, the asset-freeze prohibition extends to funds and economic resources belonging to, owned, held, or controlled by a listed person. The word "controlled" is the load-bearing element. Where a listed person controls an entity – even without owning a majority stake – that entity's assets may be frozen and transactions with it may be prohibited.

The EU approach differs materially from OFAC's. OFAC applies a mechanical 50 percent rule (the rule that treats any entity owned 50 percent or more in the aggregate by blocked persons as itself blocked). EU law does not set a single bright-line ownership threshold. Instead, it requires an assessment of whether the listed person exercises control through ownership, through voting rights, through the ability to appoint the governing body, or through other means of dominance over the entity's decisions.

In practice this means that a 45-percent stake held by a listed person, combined with contractual veto rights over key decisions, may constitute control for EU purposes even though it would fall below the OFAC 50 percent threshold. Conversely, a 55-percent stake held through a nominee structure may engage both the OFAC rule and the EU control test simultaneously. The analysis must cover both, and neither screens out the other.

OFSI – the Office of Financial Sanctions Implementation in the United Kingdom – operates a similar ownership and control test (the UK test for whether a non-listed entity is caught through a listed person's ownership or control over it). OFSI guidance confirms that control is assessed broadly, including indirect and informal means. Businesses operating across the EU and the UK must apply both tests in parallel, because a conclusion that an entity is not controlled for EU purposes does not necessarily lead to the same conclusion under OFSI's guidance, and vice versa.

We regularly advise businesses where the same counterparty group requires a three-way analysis: the EU control test, the OFAC 50 percent rule, and the OFSI ownership and control test. These are not interchangeable, and defaulting to the most familiar produces gaps.

What does a compliant EU screening programme look like?

Effective screening under the EU regime has five components: the list sources, the matching logic, the ownership and control analysis, the escalation procedure, and the record-keeping discipline. Miss any one of them and the programme has a structural gap.

List sources. The EU Consolidated List is the primary reference, but it is not the only one. Thematic regulations add specific sectoral prohibitions – restrictions on certain goods, financial instruments, or services connected with a particular regime – that are not always captured in a single list export. A programme that pulls only from the consolidated list may miss sector-specific restrictions on, for example, certain capital-market transactions or certain categories of technology transfer. Screening logic must be calibrated to the sectors the business operates in.

Matching logic. Transliteration variants, name aliases, date-of-birth tolerances, and address variants all affect hit quality. A programme set too tight misses hits. One set too loose generates volumes of false positives that the team cannot triage, which in our experience leads to alert fatigue and the unreviewed dismissal of real matches. The matching threshold must be calibrated against the risk profile of the customer or counterparty base.

Ownership and control analysis. This is where automated screening ends and legal analysis begins. When a potential match or a flagged shareholder appears, the programme must determine whether control is exercised over the transacting entity. That requires access to the beneficial-ownership register of the relevant jurisdiction, the shareholder agreement, and, in complex structures, filings in multiple registries.

Escalation procedure. The programme must define who makes the call on ambiguous matches, what information they receive, and what timeline they work to. A compliance team that escalates to a committee that meets monthly will not meet its obligations on time-sensitive transactions.

Record-keeping. Under EU sanctions rules, evidence of screening decisions – the list version checked, the date, the decision, the rationale – must be retained for audit. The applicable country regime specifies the retention period; in many EU member states this aligns with AML record-keeping requirements. Verify the current position before relying on it.

Where do EU screening programmes most commonly fail?

In our cross-border practice, the failure points in EU screening programmes concentrate in four areas. Knowing them in advance is significantly cheaper than discovering them in an enforcement inquiry.

Screening only the legal counterparty. The entity that signs the contract is often not the entity that matters. A trading company wholly controlled by a designated person is caught by the EU regime even if it appears nowhere on any list. Screening the contract signatory and no further is the most common structural gap we encounter.

Static onboarding checks. Lists change, sometimes with hours' notice. A customer screened cleanly at onboarding and not rescreened for twelve months represents twelve months of undetected exposure if that customer's shareholder is added to the list in the interim. The EU obligation is ongoing. Periodic rescreening frequency should be set by risk tier, not by administrative convenience.

Reliance on a single list export. Sector-specific prohibitions in thematic regulations may restrict dealings with entities or persons who do not appear on the consolidated list at all. A technology firm that screens only against the consolidated list may miss a restriction on providing certain software or technical services to a category of counterparty defined by sector rather than by name.

Treating a false-positive clearance as a clean bill of health. Clearing an alert because the name does not match precisely is not the same as concluding that no sanctioned party controls the counterparty. Alert clearance and ownership analysis are distinct steps. Many programmes run the first and skip the second.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. For a confidential review of a potential breach or a failed alert triage, contact Calder & Vance at info@caldervance.com.

How does EU screening compare with OFAC and OFSI requirements?

Businesses with operations in the EU, the United States, and the United Kingdom face three overlapping but non-identical screening obligations. The table below sets out the key divergences in conceptual terms; the practical implication is that a screening programme designed for one regime will not automatically satisfy the others.

Ownership threshold. OFAC's 50 percent rule is a bright line: aggregate ownership at or above that level triggers the prohibition, regardless of how control actually operates. The EU control test is broader in principle – a minority owner who exercises genuine control may bring an entity within the prohibition – but is less mechanically predictable. OFSI's test sits between them: it shares the EU's functional approach to control but is applied against UK-specific guidance that practitioners should read in its own terms.

Prohibition scope. OFAC prohibitions on US persons extend to prohibiting the receipt of funds from blocked persons, not only the making of funds available. The EU asset-freeze prohibition primarily targets the making available of funds and economic resources. These asymmetries matter in payment chains where funds flow in both directions.

Licensing routes. OFAC issues specific licences and general licences. The EU regime provides derogations from asset-freeze obligations, granted by the competent authority of the relevant member state, not by a single central body. This means that a multi-country EU operation may need to engage more than one authority. OFSI issues licences under the UK regime, again on a case-by-case or category basis. Where a transaction requires relief from all three regimes simultaneously, the applications run in parallel before separate authorities, on different timelines and with different evidentiary requirements.

Extraterritorial reach. The EU regime applies to transactions touching EU persons, territory, or currency. OFAC's reach extends to US persons globally and, for certain country-specific programmes, to non-US persons in defined circumstances (secondary-sanctions risk). OFSI applies to UK persons and to conduct in the United Kingdom. A non-EU firm transacting in euros through a European correspondent bank, or contracting with an EU entity, should assume that EU rules apply to at least part of the transaction chain.

We have acted for trading businesses, financial institutions, and technology companies that discovered mid-transaction that their programme satisfied one regime but was structurally silent on a second. The cost of re-engineering a programme at that stage is substantially higher than building it correctly at the outset.

Common misconception: a database hit is required for a breach

A persistent myth in compliance is that sanctions exposure only materialises when a counterparty appears on a list. This is incorrect under EU law, and enforcement authorities have made the point in their guidance repeatedly.

The prohibition on making funds or economic resources available to a designated person applies whether or not the transaction is conducted through a listed entity. If funds reach a designated person indirectly – through a controlled intermediary, through a payment chain, through the settlement of a commercial debt – the prohibition may still be engaged. The EU control test exists precisely to capture this pattern. A business that relies solely on counterparty screening without tracing the beneficial-ownership and control chain above the counterparty may be transacting in breach of the asset-freeze while every automated alert shows green.

The same point applies to sectoral restrictions. Certain EU sanctions measures restrict defined categories of transaction – the acquisition of particular financial instruments, the provision of specific technical services, the transfer of listed goods – without making the restriction contingent on the other party being individually designated. A business operating in these sectors cannot discharge its obligations through name screening alone. It must also review the nature of the goods, services, or financial instruments involved.

In a recent matter: misread ownership structure

In a recent matter, a financial-services firm engaged us to review an alert generated by its screening system in connection with a payment instruction from a corporate client. The alert flagged a name variant matching a designated individual as a reported beneficial owner of the client. Initial triage by the firm's in-house team had cleared the alert on the basis that the ownership percentage fell below the threshold used in the firm's US-facing programme – a programme calibrated to the OFAC 50 percent rule rather than to EU standards.

We reviewed the client's ownership and constitutional documents. The designated individual held a minority stake but had the contractual right to appoint a majority of the board and to veto material transactions. Under the EU control test, that combination was sufficient to bring the client within the prohibition's reach. The payment was halted pending an assessment of the derogation route available under the relevant member state's competent authority.

The lesson: a programme built around one regime's ownership threshold, applied without adjustment to an EU-regulated transaction, will produce structurally wrong answers. The error here was not a technology failure. It was a legal-design failure.

Related practices

How Calder & Vance assists: EU screening support

We assist businesses at every stage of building, reviewing, and defending an EU-compliant screening programme. Our work is operational as well as analytical: we test the screening logic, map ownership and control through multi-layer structures, and redesign the programme where gaps are identified.

For businesses setting up or restructuring a programme, we assess the list sources in use, review matching-logic parameters against the risk profile of the counterparty base, and produce a gap analysis against the EU ownership-and-control standard. Where the business operates across the EU, the UK, and the United States, we conduct that assessment against all three regimes in parallel, so the programme satisfies each without creating artificial divergences between them.

For businesses that have received an alert, a regulator's query, or an enforcement notice, we scope the apparent exposure, advise on whether a voluntary self-disclosure is appropriate, and prepare the defence. For transactions where a derogation or licence is required, we assess eligibility, prepare and submit the application to the relevant competent authority, and manage the authority's queries through to conclusion.

Our practice draws on experience before OFAC, OFSI, and the relevant EU member state authorities. Where local counsel in the relevant jurisdiction is required, we co-ordinate that relationship. The client has a single point of contact for a multi-regime matter.

To stress-test your screening and compliance programme, reach our team at info@caldervance.com.

Frequently asked questions

How long does set up effective screening take under EU?
There is no fixed timeline prescribed by EU regulations, and the time required depends heavily on the complexity of the business: the number of counterparties, the sectors in play, and the IT infrastructure already in place. In our experience, a financial institution building a programme from structured specifications typically reaches operational readiness within several weeks to a few months. A corporate business with a narrower counterparty base may move faster. The ownership-and-control layer – which requires legal analysis rather than technology deployment – is usually the rate-limiting step. Attempting to compress that step is a common source of gaps.
What are the main risks in name and entity screening under EU?
The principal risks are: transacting with a counterparty controlled by a designated person without detecting the control link; relying on a single point-in-time screen rather than continuous monitoring; failing to capture sector-specific prohibitions that operate independently of the consolidated list; and applying a threshold calibrated to a different regime (such as OFAC's 50 percent rule) to an EU-governed transaction. Each of these can result in a breach of the asset-freeze without any automated alert firing. Member-state enforcement authorities treat inadequate programme design as a factor that may aggravate the penalty position.
Do we need specialist counsel for name and entity screening?
Specialist counsel is not legally required to operate a screening programme. It becomes necessary – and in practice unavoidable – in three situations: when the ownership-and-control analysis involves a layered or contested structure; when an alert has been generated and the business needs to decide whether the transaction can proceed or must be blocked; and when a competent authority is asking questions. At that point, the analysis is no longer administrative; it is legal. Attempting to manage an enforcement dialogue without qualified sanctions counsel is a significant risk to the business and, in appropriate cases, to its officers personally.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.