EU sanctions · Sanctions · Compliance · Enforcement · Sanctions screening

EU Sanctions: Framework, Enforcement and Penalties

How EU sanctions work, why member states must now treat certain breaches as crimes and what it means for compliance.

Mirko Heinbuch

By

Compliance Expert at dilisense

Published 4 min read
EU Sanctions: Framework, Enforcement and Penalties

TL;DR

EU sanctions are restrictive measures the Union adopts under its Common Foreign and Security Policy. Since Directive (EU) 2024/1226, member states must treat specified intentional breaches as crimes. Individuals face prison terms. For the most serious corporate offences, the maximum fine must reach at least 5% of worldwide turnover. For any business the front-line control is screening customers and counterparties against the EU consolidated list and keeping it current.

Introduction

For what sanctions are and how they work in general, see What are Sanctions?. This article focuses on EU enforcement and what compliance now requires.

What EU sanctions are

The European Union imposes restrictive measures under its Common Foreign and Security Policy. Most are targeted. They hit the officials, entities and individuals behind the conduct the EU objects to, not the wider population. The measures range from freezes of funds and economic resources to travel bans, sectoral controls and arms embargoes. The Council adopts each measure. Where it is economic, an EU regulation applies directly across all member states. Listed persons can challenge their designation before the General Court, with an appeal to the Court of Justice.

Breaching EU sanctions is now a crime

For years the weak point of EU sanctions was enforcement. Offences and penalties differed sharply between member states. Prosecutions were rare. That has changed.

On 24 April 2024 the EU adopted Directive (EU) 2024/1226, which sets EU-wide rules defining criminal offences and penalties for violating EU sanctions. Member states had to transpose it into national law by 20 May 2025. It requires member states to criminalise intentional breaches such as failing to freeze funds, breaching a travel ban or trading prohibited goods. Circumvention must be criminalised too. Some conduct is punishable even where committed with serious negligence.

The directive sets a floor for the maximum penalties each member state must provide. For individuals, prison terms scale with the offence, from at least one year up to at least five years where the value involved is at least €100,000 or where military or dual-use goods are concerned. For companies, member states set fines either as a share of worldwide turnover or as a fixed sum. The maximum must reach at least 5% of worldwide turnover or €40 million for the most serious offences, alongside asset confiscation. A breach is now also a predicate offence for money laundering.

These convictions were prosecuted under national law, not the directive itself. In part that is because several member states, Germany and Belgium among them, already criminalised these breaches before the directive existed. In part it is the principle of non-retroactivity. Conduct is judged under the law in force when it took place. The directive's own role is broader than harmonising what already existed. It requires member states to criminalise intentional breaches and their circumvention. It also sets minimum levels for the maximum penalties for them. Convictions built on the new implementing laws will take time to appear, given how recently the directive was adopted and how long criminal cases run.

Enforcement in practice

The convictions have started to come through. Each of the cases below was prosecuted under a national framework that predates the directive. Germany is the clearest example. Its Foreign Trade and Payments Act already made these breaches a crime. Prosecutors have used it. In March 2026 a court convicted two people for sending 111 armoured luxury cars to Russia through shell companies, some going to Russian state agencies. The main defendant received six years, a second a suspended term. Around €20 million was confiscated.

Estonia has gone furthest. It ran a string of cases through 2025, with the most serious reaching five years. Finland handed down its first prison sentence for sanctions evasion in 2026. A businessman received three years and eight months for exporting trucks and trailers to Russia. Weeks earlier a Brussels court jailed three men for running a smuggling ring that fed the Russian defence sector. It moved rare earths, an explosive detector and a defence-related machine through Hong Kong and Kazakhstan. Their terms ran from three to six years.

These are convictions, not settlements. The confiscations already run to tens of millions of euros.

What this means for compliance

For companies and financial institutions, the exposure is now personal and corporate. It runs through every customer and counterparty relationship. Meeting the duty to comply comes down to screening the people and entities you deal with against the EU consolidated list and related regimes, resolving who really owns them and re-screening as designations change.

Ownership matters, because listed parties often act through front companies. Screening a name alone is not enough. For how screening works in practice and how it operates within the EU specifically, see What is Sanctions Screening? and Sanctions Screening in Europe. dilisense delivers the EU consolidated list, alongside OFAC, UN and UK sources, through one API, updated continuously and with every match traceable to its origin.

Screen against the EU consolidated list

dilisense gives you the EU consolidated list alongside OFAC, UN and UK sources through one API, updated continuously, with every match traceable to its source.

Try the free search

Frequently asked questions

Yes. Directive (EU) 2024/1226 requires member states to criminalise intentional breaches of EU sanctions and their circumvention. States had to bring their national law into line by 20 May 2025. The directive is not directly applicable, so it takes effect through each country's own criminal law. Some member states already had such frameworks before it.

Individuals face prison terms that scale with the offence, up to at least five years for the most serious. For the most serious offences, each member state must set its maximum company fine at no less than 5% of worldwide turnover or €40 million. Member states may set it higher under national law. Asset confiscation applies on top. A breach is now also a predicate offence for money laundering.

Member states enforce them through their national authorities. The 2024 directive harmonises the offences and minimum penalties so enforcement is more consistent between member states.

By screening customers and counterparties against the EU consolidated list and related lists, checking beneficial ownership and re-screening as designations change. See What is Sanctions Screening?.

About the author

Mirko Heinbuch

Compliance Expert at dilisense

Mirko Heinbuch writes about sanctions, AML and KYC at dilisense, translating complex regulatory requirements into practical guidance for compliance teams.

  • Sanctions screening
  • Anti-money laundering (AML)
  • Know your customer (KYC)
  • Politically exposed persons (PEP)
  • Regulatory compliance

Related articles