A European trading company closes a supply agreement with a distributor whose ultimate beneficial owner has just appeared on a newly published EU Council designation list. The compliance team's screening tool flagged the owner but not the distributor. Does the prohibition bite? How quickly must the firm act? These questions are not academic – they determine whether the business is exposed to asset-freezing obligations, criminal liability in certain member states, and a cross-border knock-on under OFSI or OFAC.
A sanctions risk assessment (a structured review that maps a business's exposure across counterparties, sectors, geographies, and products against the applicable legal prohibitions) is the foundation of any defensible EU sanctions compliance programme. Under the relevant Council regulations, the obligation to freeze assets and refrain from making funds available arises automatically upon designation, with no grace period. An assessment conducted before a transaction or relationship is entered into – rather than after a problem surfaces – is the single most effective way to keep the business on the right side of the prohibition.
This page explains what an EU sanctions risk assessment involves, how the procedure compares with OFAC and OFSI approaches, where businesses typically go wrong, and how Calder & Vance supports clients in carrying out this work rigorously and efficiently.
What does EU sanctions risk assessment cover, and who needs it?
An EU sanctions risk assessment covers every channel through which a designated person or entity – or a non-listed entity controlled or owned by one – could touch a business's operations, and it rates those channels by likelihood and consequence. The governing legal instrument is the relevant Council Regulation, which imposes directly applicable obligations across all EU member states without requiring domestic transposition. Any natural or legal person, entity, or body that transacts in euros, uses EU-incorporated entities, operates within the EU, or provides services from within the EU can be within scope.
The assessment is not limited to counterparties. It must extend to the supply chain, to financial intermediaries, to cargo routes, and – where the business has exposure to US dollar clearing or UK-nexus transactions – to secondary-sanctions vectors that could trigger OFAC or OFSI scrutiny in parallel. In our cross-border practice, businesses that focus their assessment narrowly on direct counterparties routinely miss indirect exposure that a regulator would regard as obvious.
Who specifically needs this work? The practical answer spans a wide range of operators: multinational manufacturers with EU legal entities, financial institutions processing euro-denominated payments, commodity traders, shipping and freight businesses, technology exporters, and any private equity or M&A team acquiring a target with counterparties or operations in or touching sanctioned sectors. The question is not whether a business has EU nexus; the question is whether it has mapped all the ways that EU nexus creates a legal obligation.
What is the legal basis and who administers EU sanctions?
EU restrictive measures are adopted by the Council of the EU by unanimity. Each sanctions programme has a twin instrument: a Council Decision (providing the political basis) and a Council Regulation (imposing the directly effective legal obligations). It is the Regulation that carries enforceable prohibitions on asset-freezing, the making available of funds and economic resources, and in many programmes trade and sectoral restrictions. The EU General Court and the Court of Justice of the EU provide judicial oversight; the former hears annulment actions brought by designated persons challenging the legal basis or procedural adequacy of their listing.
Enforcement is decentralised. Member states' competent authorities – the relevant financial intelligence units, central banks, customs agencies, and trade ministries depending on the programme – supervise compliance and can impose penalties. Civil and in some member states criminal consequences differ across jurisdictions, which itself creates a risk that multi-entity EU groups tend to underestimate. A business with operations in more than one member state faces multiple enforcement bodies, not one.
The European Commission coordinates guidance and publishes the EU Consolidated List of designated persons. That list is the primary screening reference, but it does not displace the obligation to analyse ownership and control: a non-listed entity controlled by a designated person is subject to the prohibition even if it does not appear on the Consolidated List itself.
The position above covers the standard case. Your facts – the counterparty's ownership structure, the goods or services in question, the member states involved, and any US or UK nexus – change the analysis considerably. For an early assessment of your exposure under the EU regime, contact Calder & Vance at info@caldervance.com.
How does the EU ownership and control test work – and how does it differ from OFAC and OFSI?
Under the EU regime, an entity is caught by the asset-freeze where it is owned or controlled by a designated person, and both the ownership leg and the control leg are assessed. The ownership limb examines whether a designated person holds 50 percent or more of the proprietary rights in, or a majority interest in, the entity. The control limb is broader: it asks whether a designated person has the ability to exercise a dominant influence over the entity's decisions – through board composition, veto rights, contractual arrangements, or de facto management.
This two-limb structure creates a material divergence from the OFAC standard. OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) is purely quantitative and aggregates interests across all blocked persons. It does not independently assess control. OFAC's approach is therefore more mechanically predictable – but it can miss scenarios where a designated person exercises effective dominance through a smaller equity stake, which the EU control test would catch.
OFSI in the United Kingdom applies an ownership-and-control test that is conceptually closer to the EU approach, but the practical guidance and the evidentiary standards differ. In our experience, transactions involving entities in EU jurisdictions that also have UK-regulated counterparties require both tests to be run separately – a finding of "not caught" under one regime is not portable to the other.
The practical implication is significant. A target company whose ultimate beneficial owner appears on the EU Consolidated List but holds only forty percent of the equity may still be caught through the control test. An assessment that relies solely on ownership-percentage screening misses that exposure entirely. That gap is one of the most frequent gaps we identify when reviewing existing compliance arrangements.
What are the main risk flags that surface in an EU sanctions risk assessment?
The most significant risk flag is layered ownership: intermediate holding companies that separate a designated person from the operating entity by two or three tiers, often across multiple jurisdictions. A screening tool that checks the direct counterparty against the EU Consolidated List will not surface this without a custom ownership-chain enquiry.
A second flag is the newly designated counterparty. The EU publishes updates to the Consolidated List through Official Journal notices, and the freeze obligation takes effect at the moment of publication – not from the date a firm becomes aware of the listing. Real-time or near-real-time screening, with defined escalation protocols, is not optional.
Sectoral restrictions present a different kind of risk. Certain EU programmes impose restrictions on categories of goods, services, or financing that apply regardless of whether any specific person on the counterparty side is designated. Energy sector restrictions in certain programmes, for instance, catch transactions by reference to the sector and the role of the goods or services within it. An assessment focused only on person-screening misses this category of prohibition entirely.
Currency and clearing exposure is a fourth area. Transactions settled in euros through EU financial institutions, or involving EU-incorporated entities as correspondent or clearing institutions, create EU nexus for what a business might otherwise consider a purely non-EU transaction. We regularly advise businesses that have been surprised to discover their transaction has an EU dimension they had not recognised.
A fifth flag is the interaction between EU sanctions and the EU Blocking Regulation. The EU Blocking Regulation, which prohibits EU persons from complying with certain extraterritorial secondary-sanctions measures, can create a direct conflict where a business is simultaneously subject to US secondary-sanctions risk and EU blocking-statute obligations. Identifying this conflict early – and handling it through proper licensing or advisory channels in each jurisdiction – is a core element of a complete risk assessment.
How is an EU sanctions risk assessment conducted in practice?
A well-structured EU sanctions risk assessment follows a sequenced methodology that moves from scope-mapping through legal analysis to a remediation output. The sequence below reflects the approach we apply across our engagements, adapted to the scale and complexity of the business.
- Scope definition: identify all entities, relationships, products, services, and geographies that could engage the EU prohibition. Include both EU-regulated and non-EU operations that have EU nexus through currency, ownership, or service delivery.
- Counterparty and ownership screening: screen direct counterparties against the EU Consolidated List, then trace ownership and control chains to the ultimate beneficial owner level. Apply the two-limb EU test: ownership at 50 percent or more and effective control through any mechanism.
- Sectoral and programme mapping: identify which EU sanctions programmes are engaged by the business's sector, product, or geography. Analyse whether sectoral restrictions apply independently of person-screening results.
- Cross-regime overlay: assess the same exposure base against OFAC, OFSI, and any other applicable regime (Switzerland/SECO, Canada, Australia, or others) to identify conflicts, amplifying risks, or divergent obligations. Flag any EU Blocking Regulation tension where US secondary-sanctions exposure is present.
- Risk rating and gap analysis: rate each identified exposure by likelihood and consequence. Compare the current controls against what the assessment has surfaced to identify gaps in screening coverage, escalation protocol, record-keeping, or licensing awareness.
- Remediation and advisory output: produce a structured report setting out findings, prioritised gaps, and the specific steps the business should take to close them. Where a specific transaction or relationship requires a licensing analysis or a regulatory consent, identify that and initiate the applicable process.
The duration of this process depends materially on the complexity of the business's ownership and counterparty structures. A focused assessment for a single transaction or relationship can move quickly. A programme-level assessment for a group with multi-jurisdictional operations and a large counterparty universe takes longer, but the investment in thoroughness is what produces a defensible compliance position.
If a transaction has already been flagged, or a counterparty has appeared on the EU Consolidated List after the contract was signed, an early legal review can preserve options – including licensing routes and voluntary disclosure considerations – that become harder to access as time passes. Contact Calder & Vance at info@caldervance.com to discuss the position.
What mistakes do businesses commonly make in EU sanctions risk assessment?
The most persistent mistake is treating sanctions risk assessment as a one-time exercise rather than a continuous obligation. The EU Consolidated List changes frequently; new programmes are adopted; existing programmes are amended. A business that conducted a thorough assessment twelve months ago may be operating on an incomplete picture today. Ongoing monitoring of the list and of regulatory guidance is as important as the initial assessment.
A related mistake is over-reliance on automated screening without human legal review. Screening tools are necessary but not sufficient. They match names against list entries – which is the starting point, not the end. The ownership-and-control analysis, the sectoral restriction mapping, and the cross-regime overlay require legal judgment that a tool cannot supply. In our experience, many enforcement-risk situations arise not because the tool failed to flag the listed person, but because no one asked whether the non-listed counterparty was controlled by that person.
Record-keeping is a third recurring gap. Under EU law and under the applicable national enforcement regimes, a business that has identified and addressed a risk must be able to demonstrate that it did so. Documentation of the assessment – the methodology, the data sources, the conclusions, and the steps taken in response – is the evidence base in any enforcement inquiry. We frequently encounter businesses that conducted a genuine assessment but retained no documentation of it.
A commonly held myth is that EU sanctions are a concern only for businesses with operations inside the EU. This misreads the legal position. The relevant Council Regulations apply to conduct within the EU, to EU nationals and entities wherever they operate, to transactions denominated in euros, and to any act performed in whole or in part within EU territory. A UK-headquartered business with an EU subsidiary, or a US business clearing in euros, is within scope. The extraterritorial dimension of EU sanctions is often underestimated by businesses that think of the rules as territorial.
When should a business involve specialist EU sanctions counsel?
Specialist counsel should be involved at the point where a legal determination – rather than a purely mechanical screening result – is needed. The triggers include: a counterparty's ownership structure that requires a control analysis, any transaction that sits within or near a sanctioned sector, a new counterparty in a jurisdiction where EU sanctions programmes are active, a screening hit that requires a licensing assessment, a voluntary disclosure consideration, and any enforcement inquiry or audit from a member-state competent authority.
Earlier involvement is almost always more cost-effective than later involvement. A business that engages counsel to scope an assessment before a transaction closes has options. A business that seeks advice after a blocked transaction has been partially executed is managing a more constrained set of possibilities.
The cross-border angle is particularly important here. Where a transaction has US or UK dimensions alongside EU exposure, the legal analysis under OFAC and OFSI runs in parallel with the EU analysis, and the three positions do not always align. A legal team that handles only one regime may give an accurate answer on that regime while missing material risk under the others.
Related practices
- Compliance audit and testing – Australia – structured programme review against the Australian autonomous sanctions regime and DFAT guidance.
- Sanctions risk assessment – OFAC – counterparty screening, 50 percent rule analysis, and SDN-list exposure mapping under the US OFAC regime.
- Sanctions risk assessment – SECO – exposure mapping and ownership analysis under the Swiss sanctions and export-control regime.
Frequently asked questions on EU sanctions risk assessment
How long does carrying out a sanctions risk assessment take under the EU regime?
The timeline depends on the scope of the assessment. A focused review of a single counterparty or transaction – tracing ownership, applying the EU two-limb test, and checking for sectoral restrictions – can be completed within a few business days where the ownership information is available. A programme-level assessment for a group with multiple EU entities, a large counterparty base, and cross-regime dimensions requires more time. In our practice, clients who have clean and accessible ownership data and a defined scope tend to move through the process substantially faster than those who need to gather and verify that data as part of the exercise. We provide a realistic timeline estimate at the outset of each engagement, based on the facts presented.
What are the main risks in sanctions risk assessment under the EU regime?
The principal risk is missing a prohibited connection that the legal rules would regard as obvious. The most frequent sources of that miss are: failure to apply the control test alongside the ownership test; over-reliance on direct-counterparty screening without tracing the ownership chain to the ultimate beneficial owner; failure to map sectoral restrictions that apply independently of listed-person status; and failure to identify EU nexus in a transaction the business considers non-EU. A secondary but serious risk is inadequate documentation – conducting a genuine assessment but retaining no record of the methodology and conclusions, leaving the business unable to demonstrate its diligence in an enforcement inquiry.
Do we need specialist counsel for sanctions risk assessment under the EU regime?
For straightforward screening of a counterparty with a transparent ownership structure and no proximity to a sanctioned sector, an experienced in-house compliance team with a well-configured screening tool may handle the initial review without external counsel. Specialist counsel becomes necessary when the ownership analysis is complex, when the transaction touches a sanctioned sector or geography, when there is a cross-regime dimension (particularly where US secondary-sanctions risk or the EU Blocking Regulation is engaged), or when a licensing question or enforcement exposure arises. In those situations – which are more common than businesses expect – the legal determination that the assessment requires is a professional judgment, not a screening-tool output.
About Claire Dubois
Claire Dubois advises on EU sanctions, including Council-regulation analysis, ownership-and-control questions under both the EU and UK regimes, and annulment actions before the EU General Court. She advises multinationals, financial institutions, and trading businesses on EU sanctions risk assessment, licensing, and the interaction between EU and US sanctions programmes. Calder & Vance – International Sanctions & Export Control Counsel.
About Calder & Vance
Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.
Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.