Sanctions Under Strain: Navigating a World Without a Common Rulebook

Sanctions Under Strain: Navigating a World Without a Common Rulebook

02 Jun 2026

Sanctions Under Strain: Navigating a World Without a Common Rulebook

Sanctions Under Strain: Navigating a World Without a Common Rulebook

Sanctions compliance used to be about list management. You maintained an up-to-date consolidated list of designated persons, screened your customer base against it, acted on positive hits, and documented your process. The job was not simple, but it was bounded. The parameters were clear.

That world no longer exists.

In the space of a few years, the sanctions landscape has fractured into a configuration of competing, sometimes contradictory, regime requirements that no single institution - however well-resourced its compliance function - can navigate with full confidence. The session on sanctions evasion at Transform Finance's Amsterdam summit made no attempt to soften this assessment. The problems it surfaced were structural, geopolitical and, in several cases, without obvious resolution.

The Multi-Regime Problem

The starting point is the multiplicity of regimes themselves. Most institutions operating in European markets must manage multiple sanctions regimes at once: EU consolidated sanctions, UK designations, UN Security Council lists and, because the dollar remains central to global trade finance, OFAC itself. Each regime operates according to different designation timelines, different licensing frameworks, different definitions of ownership and control, and different interpretations of what constitutes prohibited activity.

The timing problem alone generates significant operational burden. When the same individual is to be designated by multiple authorities, as frequently occurs, the designations do not happen simultaneously. An institution that has already segregated assets and restructured monitoring for a US designation may need to begin the process again when EU designation follows, sometimes weeks or months later. The compliance cost is duplicated; the legal analysis must be repeated.

Licensing compounds the complexity. Some regimes provide general licences covering specified categories of activity from the date of designation. Others require individual licensing applications. Within the EU, licensing operates at member state level - meaning a transaction touching three European jurisdictions may require three separate licences from three separate authorities, entirely aside from any US dollar exposure that would additionally require OFAC clearance.

The divergence on ownership and control is perhaps the most technically demanding. A further complication lies in the concept of effective control: the principle by which sanctions obligations can extend from a listed individual to the entities they direct. In practice, that principle is not applied consistently, with the UK taking a broader view, the EU applying a narrower framework, and OFAC following a different approach again. An institution trying to apply a consistent, conservative standard across all regimes will frequently arrive at conclusions that differ from those a peer institution has reached applying the same underlying facts to regime-specific guidance.

The OFAC Question

Under the protection of Chatham House rules, no aspect of the sanctions discussion generated more candid comment than the relationship between EU-based institutions and US sanctions requirements.

EU institutions are not, as a matter of law, required to apply OFAC sanctions unless they qualify as US persons or their transactions have US nexus. In practice, however, many do so voluntarily, as a matter of policy. The reason is not regulatory obligation but risk calculus: the secondary sanctions programme, under which OFAC can restrict access to the US payment system for any institution that conducts significant business with OFAC-designated parties, creates a de facto compliance obligation regardless of legal status.

"We apply OFAC sanctions as if we are a US bank," one compliance officer said plainly, "because the secondary sanctions programme means one mistake of sufficient size can cut us off from US dollar settlement. The consequence of getting it wrong is not a fine - it's being excluded from the payment system."

The EU blocking statute, notionally designed to protect European companies from extraterritorial US sanctions reach, was assessed as providing limited practical protection. Several speakers noted that it has never been effectively invoked and that in any case it can be circumvented by the simple expedient of declining business on commercial rather than compliance grounds.

The result is that many European institutions operate under a de facto US-equivalent sanctions standard despite having no US legal obligation to do so - and in doing so, sometimes find themselves in tension with EU policy objectives. The recent geopolitical divergence between the US and EU on Iran policy provides a live example: the EU has moved more slowly, and the US more aggressively, producing a gap in which European institutions face contradictory signals about what constitutes acceptable exposure.

Orchestrated Evasion

The panel heard detailed analysis of a category of sanctions challenge that goes beyond the familiar difficulties of list maintenance and ownership mapping: state-level, government-orchestrated evasion.

In the securities industry, Russia's response to Western asset immobilisation following its invasion of Ukraine has involved a sequence of legislative and administrative measures specifically designed to disrupt the information flows that make Western sanctions effective. Russian authorities have passed laws allowing issuers and investors to interact directly, bypassing the custodial chain normally used to verify ownership records and payment flows. The result is a framework in which sanctioned holders may continue receiving income from Western-listed securities.

The mechanism described at the summit was intricate. Sovereign debt issuances originally made in dollars or euros, whose coupons the Russian state was prohibited from paying in foreign currency following designation, were unilaterally converted to ruble payments deposited into blocked Russian accounts. Investors who could prove Russian residency were permitted to collect those payments freely - while Western investors' receivables remained in a blocked status that was effectively permanent. The result: the frozen assets were neither frozen nor accessible, the sanctioned parties received economic benefit regardless, and custodians in Western jurisdictions were left holding shortfalls they could not explain or recover.

"Sanctions compliance is no longer about list management," a compliance officer concluded. "You are dealing simultaneously with compliance risk, legal risk and operational risk. And very often the three are in conflict."

The Regulator's Perspective

A supervisor present on the panel offered a perspective that was simultaneously reassuring in its candour and clarifying in its implications.

The most common failing identified in a recent horizontal review of sanctions screening systems across multiple institutions was not deliberate evasion or negligence - it was excessive alert generation. Systems calibrated for maximum sensitivity were producing volumes of alerts that exceeded the capacity of compliance teams to assess meaningfully, creating a different kind of risk: that genuinely important hits would be buried in noise, or that the response to alert fatigue would be a systematic lowering of thresholds that no single individual had consciously authorised.

The supervisor was direct about the regulatory expectation: the goal is not compliance theatre but effective identification of genuine risk. Institutions with chronically over-alerting systems were required to develop remediation plans calibrated to producing the right balance - not the maximum number of flags, but the most useful ones. The measure of effectiveness is not alerts generated. It is sanctions risk actually identified and acted upon.

On ownership and control, the supervisor recognised both the complexity of the issue and the genuine uncertainty around interpretation. They also described a practice of holding regular joint sessions with private sector institutions to work through specific scenarios and reach shared conclusions. "We cannot always give answers even from the European Commission," the supervisor noted. "But we need consistency. We cannot wait for perfect guidance before making decisions."

A System Under Stress

The session closed with a broader observation about the systemic resilience of the international sanctions architecture - and the finding was not encouraging.

The effectiveness of global sanctions regimes has historically depended on consensus at the UN Security Council level. That consensus has broken down. With the Security Council no longer able to operate as the standard-setting body for terrorism-related designations, the cascade of consistency that should flow downward - from global to regional to national - is no longer functioning as designed. The result is a growing divergence between the groups and individuals that pose genuine global risk and those that can be acted upon through internationally recognised legal frameworks.

For financial institutions trying to apply a risk-based approach, this creates a genuine dilemma. The greatest concern lies with well-financed, structurally complex organisations operating across multiple jurisdictions. Yet, these are often the hardest entities to designate under fragmented multilateral frameworks, while those that can be most easily screened and acted upon are frequently peripheral to the primary risk.

The prescription, offered with some care, was that institutions cannot wait for the global framework to repair itself. They must invest in the strategic, intelligence-led understanding of how the terrorist and criminal organisations in their risk universe actually finance themselves - and build their own risk assessment architecture around that understanding. "The risk-based approach," one speaker argued, "is not just about what the regulations say. It is about actually understanding the risk."

That is, perhaps, where it always was.


This article is part of Transform Finance's coverage of the 4th Annual FinCrime Leaders Summit Europe, Amsterdam 2026. This article reflects a session held under Chatham House rules. To respect those conditions, comments have not been attributed to individual speakers or organisations.

Loading