The EBA guidelines aim to establish common standards for the internal policies, procedures, and controls of financial institutions to ensure compliance with EU and national restrictive measures. They address the divergent expectations of competent authorities and the legal and reputational risks that financial institutions face. Two sets of guidelines are proposed: one for all financial institutions and another…
This document is a guide published by the European Banking Authority (EBA) in November 2024. It includes two sets of guidelines (EBA/GL/2024/14 and EBA/GL/2024/15) aimed at framing the internal policies, procedures, and controls of financial institutions to ensure the implementation of European Union and national restrictive measures. The scope covers financial institutions supervised by the EBA, payment service providers (PSPs), and crypto-asset service providers (CASPs), in connection with restrictive measures applicable to transfers of funds and crypto-assets. These guidelines apply from 30 December 2025 and concern compliance with targeted sanctions regimes and sectoral measures adopted within the EU and Member States (p. 1-12).
The subject concerns the harmonization of internal policies, procedures, and controls of financial institutions to ensure the effective implementation of European Union and national restrictive measures. This topic is crucial because the non-uniformity of expectations from competent authorities in Member States complicates institutional compliance, increasing legal, reputational, and financial risks, and potentially undermining the effectiveness of sanctions regimes. Key findings reveal significant divergences in supervision and expectations, as well as weaknesses in institutions' internal arrangements, notably in governance, filtering systems, and risk management. These shortcomings expose institutions to high risks of non-compliance and may cause harm to consumers, including unjustified fund blockages or excessive de-risking practices. In response, the EBA has issued two sets of guidelines: EBA/GL/2024/14, addressed to all institutions under its supervision, which sets common standards on governance and internal arrangements to manage risks related to restrictive measures; and EBA/GL/2024/15, specific to PSPs and CASPs, detailing compliance requirements for transfers of funds or crypto-assets. These guidelines notably provide for conducting an assessment of exposure to restrictive measures, appointing a senior officer responsible for compliance, implementing appropriate filtering systems, rigorous alert management, freezing and reporting of affected funds, as well as regular staff training. They apply proportionately to the size, nature, and exposure of institutions. Supervisory authorities must rely on these guidelines to assess institutions' internal arrangements. The implementation of these standards aims to strengthen consistency and effectiveness of compliance with restrictive measures in the EU, contributing to the protection of European values, international security, and financial system stability (p. 3-7).
The document addresses the issue of heterogeneous implementation of restrictive measures in the EU, identified by the European Commission and confirmed by the EBA, which noted differences in supervision, expectations, and quality of internal arrangements of financial institutions. These divergences complicate compliance, expose to legal and reputational risks, and may undermine the effectiveness of sanctions regimes. The recent regulatory framework, notably Regulation (EU) 2023/1113 on transfers of funds and crypto-assets, requires the EBA to issue specific guidelines for PSPs and CASPs. However, this mandate is considered insufficient to cover all issues related to internal systems and legal risk management linked to restrictive measures. The objective is therefore to provide a common European framework, via two sets of guidelines, to harmonize practices of financial institutions and relevant providers, strengthen governance, policies, procedures, and controls, and improve supervision. The guidelines target competent authorities and financial institutions supervised by the EBA, as well as PSPs and CASPs, covering targeted and sectoral restrictive measures. They aim to ensure effective compliance, proportionate to risk exposure, and to reduce risks of violation or circumvention of measures (p. 4-7).
1. Governance and Responsibility (p. 13-17):
- Institutions must establish a robust governance framework to ensure compliance with restrictive measures.
- Responsibility lies with the management body which must approve the strategy, oversee implementation, and be regularly informed of exposures and incidents.
- A senior officer dedicated to compliance with restrictive measures must be appointed, with necessary skills, who may combine this role with other responsibilities under strict conditions to avoid conflicts of interest.
- In groups, coordination of assessments and policies between entities is mandatory.
2. Assessment of Exposure to Restrictive Measures (p. 17-20):
- Institutions must identify areas of vulnerability and exposure to restrictive measures.
- The assessment must cover applicable regimes, risks of non-application and circumvention, impact of breaches, and incorporate geographic, client, product/service, and distribution channel factors.
- This assessment must rely on diverse sources: client data, authority information, reliable open sources, commercial reports, and internal alert analyses.
- It must be reviewed at least annually and upon significant events (regulatory changes, new products, incidents).
3. Policies, Procedures, and Controls (p. 20-22):
- Arrangements must ensure continuous updating of information on restrictive measures and their effective application.
- They must include processes to detect, analyze, and handle alerts, with immediate actions in case of positive matches (freezing, suspension, reporting).
- Internal documentation must clearly define responsibilities, including in case of outsourcing.
4. Training (p. 21):
- Regular training, adapted to employee roles, is required to maintain awareness of restrictive measures, exposures, and internal procedures.
- The training plan must be documented and available for review.
5. Specifics for PSPs and CASPs (p. 31-42):
- These providers must implement reliable filtering systems, adapted to their exposure, with at least annual review.
- They must effectively manage sanction lists, precisely define data to filter (including beneficial owners, crypto wallet addresses).
- Filtering must cover clients, transfers of funds, and crypto-assets, with attention to circumvention risks (e.g., information alteration, transaction structuring).
- Systems must be calibrated to optimize detection while limiting false positives, notably using fuzzy matching techniques.
- PSPs and CASPs must rigorously manage alerts, with investigation procedures, fund freezing, and reporting to competent authorities.
- Outsourcing of functions must respect strict principles of responsibility and control.
6. Impact and Justification (p. 22-25, 43):
- The assessment of exposure to restrictive measures is a key tool to adapt controls and reduce risks.
- Appointment of a dedicated senior officer improves visibility and quality of compliance.
- Induced costs are considered acceptable given expected benefits in compliance, risk reduction, and support of EU values and objectives.
- The guidelines complement other EBA guides related to anti-money laundering, internal governance, ICT risk management, and operational resilience.
7. Timeline and Application (p. 7, 12, 30):
- Entry into force of the guidelines is set for 30 December 2025.
- From 10 July 2027, regulation on targeted financial sanctions will be strengthened by Regulation (EU) 2024/1624.
- Supervisory authorities must integrate these guidelines into their practices and notify their compliance to the EBA.
Findings:
- There is significant heterogeneity in supervision and implementation of restrictive measures within the EU, with differences in authorities' expectations and quality of internal arrangements (p. 4-5).
- Financial institutions show weaknesses in governance, filtering systems, and risk management, exposing to legal and reputational risks (p. 5).
- Non-compliance may lead to criminal sanctions, fines, and consumer harm (p. 3-4).
Hypotheses:
- Harmonization of expectations and practices via common guidelines will improve compliance and reduce risks (p. 6-7).
- Appointment of a dedicated senior officer will enhance effectiveness of internal arrangements (p. 24).
Interpretations:
- Assessment of exposure to restrictive measures is an essential tool to adapt controls and resources proportionately (p. 23).
- Costs related to guideline implementation are offset by benefits in compliance, risk reduction, and support of European values (p. 24-25).
Uncertainties:
- The actual effectiveness of the guidelines will depend on their adoption by competent authorities and institutions, as well as concrete implementation (p. 7).
- Evolution of restrictive measures regimes and technologies (notably in crypto-assets) may require future adaptations (p. 35-36).
The EBA concludes that adoption of these two sets of guidelines is necessary to harmonize and strengthen the implementation of restrictive measures in the European financial sector. It recommends:
- Financial institutions to implement policies, procedures, and controls proportionate to their exposure to restrictive measures, including regular assessment of this exposure.
- Appointment of a senior officer responsible for compliance with restrictive measures, with adequate human and technical resources.
- Implementation of adapted, reliable, and regularly tested filtering systems, notably for PSPs and CASPs, covering clients, transfers of funds, and crypto-assets.
- Establishment of clear procedures for alert analysis, fund freezing, transfer suspension, and reporting to competent authorities.
- Regular and appropriate staff training.
- Competent authorities to integrate these guidelines into their supervisory practices and notify their compliance to the EBA.
The guidelines will enter into force on 30 December 2025, with a regulatory transition planned in 2027 for certain targeted financial sanctions. These measures aim to improve consistency, security, and integrity of the European financial system, while supporting the EU’s political and security objectives (p. 6-7, 25, 43).
Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.