top of page

AML: EBA Sanctions Guidelines

Key Guidelines from the European Banking Authority on Sanctions Compliance


 On 14 November 2024, the European Banking Authority (EBA) released two comprehensive sets of guidelines designed to establish unified EU standards for governance arrangements and compliance measures. These guidelines, effective on 30 December 2025, provide financial institutions ample time to align their systems and policies with the new requirements.

This landmark initiative demonstrates the EBA's commitment to strengthening the EU's sanctions compliance framework while assisting financial institutions in navigating the complexities of restrictive measures.


The First Set of Guidelines: Governance and Risk Management


Guidelines EBA/GL/2024/14 apply to all financial institutions under the EBA's supervision. They establish a structured framework for governance, internal controls, and risk management to address threats associated with breaches or circumvention of sanctions.


Key features include:

  • Governance: Institutions must implement governance structures capable of addressing sanctions-related risks effectively.

  • Risk Assessment: Financial institutions are encouraged to perform regular evaluations of their exposure to restrictive measures.

  • Tailored Compliance: Compliance processes should be adapted to match the size, nature, and complexity of the institution.


The Second Set of Guidelines: Payment Service Providers and Crypto-Assets

Guidelines EBA/GL/2024/15 target Payment Service Providers (PSPs) and Crypto-Asset Service Providers (CASPs), addressing the unique risks these entities face in sanctions compliance.


Key Requirements for CASPs:


Reliable Screening Systems: CASPs must implement adequate systems to screen transactions and customer data effectively, ensuring compliance with EU and national restrictive measures.

Accurate Data: Screening datasets must be detailed, accurate, and updated promptly to reflect changes in restrictive measures.

Screening Frequency: CASPs should regularly screen their customer databases, with triggers and schedules based on risk assessments.


Screening Process Includes:

·         Verifying whether a party is designated.

·         Managing risks of sanctions violations and circumventions.

·         Screening all crypto-asset transfers before processing.

 

Freezing Assets:

CASPs must establish policies to freeze transactions when an alert confirms a match with designated individuals or entities.


Outsourcing Screening:

While outsourcing screening is permissible, CASPs remain ultimately responsible for compliance with restrictive measures.


Unified Implementation and Risk Mitigation

The EBA’s guidelines aim to harmonise the implementation of restrictive measures across the EU, addressing governance and risk management challenges. Non-compliance with sanctions can lead to severe legal, financial, and reputational consequences, potentially destabilising the financial system.


Comments


Terms of Website Use

Cookie policy

Privacy policy

© 2025 by Customs Manager Ltd.

bottom of page