Europe · Sanctions and compliance

Building an International Compliance Program

Erich Rath10 min read

Building an International Compliance Program Practical Guide for Businesses Working with the European Union

Mainstream

The International Compliance Program is not a package of policies downloaded from the Internet. It is a living risk management system that protects the assets, reputation and top officials of the company.

The question is not whether you have politicians. The main question is whether your system will work at 4 a.m. when the operations manager decides to ship the goods to the troubled counterparty, bypassing the ban.

Therefore, effective construction of a Compliance program begins with three checks:

  1. What are the real risks of your business (geography, product, customers)?
  2. The requirements of which regulators are critical for you (EU sanctions, export controls, secondary US sanctions).
  3. How to enforce rules on the operational level, not just on paper.

If the program is not integrated into business processes, the company is doomed to fines, asset locks in the EU, criminal prosecution of management and termination of contracts.

When it is necessary to build an international Compliance program

The need for a system program arises if:

  • your company exports or imports goods across EU borders;
  • You use European banks to settle in euros or dollars.
  • The supply chain affects dual-use products.
  • Contractors are located in high-risk jurisdictions;
  • Investors or partners request ESG/Compliance due diligence.
  • You have received requests from banks to suspend payments;
  • previous audit found violations;
  • Top management faces personal responsibility.
  • You are planning to trade M&A in Europe or with European assets.
  • You have a complex ownership structure that affects offshore companies;
  • You are working on EPC contracts, trading or logistics where the sanctions risk is maximum.

The mistake most companies make

Many companies start with the question:

Where to download a sample of Compliance-policy?

That's the wrong first question.

The right question is:

What specific transactions could result in the blocking of our account with a German bank or the personal liability of the beneficiary?

Sometimes the best result is the introduction of automated sanctions scoring. Sometimes, a point-based training of the sales department. Sometimes, a change in the structure of the contract. Sometimes it is a complete stoppage of business.

Compliance-program does not require copying someone else’s rules, but fine-tuning to your risk profile.

Step 1. Identify applicable jurisdictions and regimes

The first thing to look at is the legal landscape.

It is not enough to say, “We are complying with the sanctions.” You need to determine which regimes have extraterritorial effect and apply to you:

  • EU sanctions (Council Regulations): Sectoral, personal freezing of assets, bans on transactions with certain territories (for example, Crimea/Sevastopol, DPR/LPR, as well as sanctioned persons).
  • Export controls (Regulation 2021/821): Dual-use products, catch-all clauses, end-use control.
  • Secondary Sanctions of the United States (OFAC): The dollar is relevant even if you do not use the dollar directly, but you are referring to U.S. goods, technology, or residents.
  • National laws: Some restrictions in Germany, the Netherlands or the Baltic States, which may be more stringent than the European ones.

Step 2. Conduct a Risk Assessment (Risk Assessment)

The risk map is not a checkmark table, but the basis of a proportional program.

We need to analyze:

  • products/services (special attention to codes of HS and dual-use goods);
  • geography of end users and consignees;
  • The payment chain (through which banks and in which currencies money goes)
  • Beneficial ownership of counterparties (final owners);
  • intermediaries, agents and traders (false transit, circumvention of sanctions);
  • channels of intangible technology transfer (remote access, email, cloud).

A simple check on the UN and EU lists is the minimum. This Risk Assessment identifies atypical red flags: For example, ordering goods not according to the customer profile or requesting a change in the delivery route.

Step 3. Develop policies and procedures

Politicians are the skeleton of the program. But they should be working papers, not academic essays.

Key documents:

  • Sanctions and Export Control Policy: A clear ban on circumvention of sanctions, the “know your counterparty” (KYC) rule and “know your product” (KYP) rule.
  • Due Diligence Procedure: Checklists, risk levels, escalation of complex cases to compliance officers or outside lawyers.
  • Gifts and Hospitality Policy: Limits to eliminate corruption risks.
  • Third-Party Code of Conduct: Distributors and agents in compliance.
  • Whistleblowing Policy: a hotline or channel for anonymous reporting of violations (requirement of EU directives).

Step 4. Implementing Due Diligence Sanctions Procedures

It's the heart of the program. Without him, politicians are useless.

Level 1. Primary Screening (Screening): Automatic or manual verification of the company name, owners and directors by sanctions lists of the EU, UN, OFAC, UK. It is important to configure the algorithm to avoid false positives, but not miss the real match.

Level 2. In-depth examination (Enhanced Due Diligence): If a customer is from a high-risk country or has a red flag, you must request:

  • ownership structure up to the final individual;
  • confirmation of the address of registration and place of business;
  • End-Use Statement (End-Use Statement)
  • Data from the supply chain and the final customer.

Step 5. Implement export controls and classification of goods

For commercial and industrial companies, it is critical to assign the correct codes to the goods:

  • Harmonized System (HS) code;
  • Dual-Use code (Annex I of Regulation 2021/821);
  • EU Military List.

Even if your product is not on the dual-use lists, the “catch-all” rule works. If you know or should know that the goods will be used for prohibited purposes (for example, for military purposes in a sanctioned country), a license is required in any case.

Step 6. Appointing a responsible and training staff

The program doesn't work without an architect.

The company must have a Compliance Officer (or local representative in the EU) with direct access to the CEO and a budget for automation.

Training should be differentiated:

  • Sales and Logistics Department: trainings on recognition of “red flags” in applications, basics of reading sanctions lists.
  • Top management: Personal liability (criminal and financial) under EU law.
  • Accounting: rules for processing payments with sanctions tags.

It is important that training is conducted on live examples and ends with testing.

Step 7. Monitoring and Internal Audit

Compliance is not static.

Regular monitoring includes:

  • automatic monitoring of changes in the EU sanctions lists (daily update);
  • Monitoring publications of OFAC and national regulators (BAFA, BIS, etc.);
  • Program testing: by the method of “secret buyer” or imitation of a prohibited transaction;
  • Look-back review to identify accidental violations.

Step 8. Establish an incident response mechanism

Violations can happen even in the best program. The main thing is reaction.

The procedure shall describe:

  • immediate suspension of shipment or payment;
  • blocking of funds in accounts if the counterparty has been subject to blocking EU sanctions;
  • notification of the correspondent bank;
  • Legal analysis of the need for self-disclosure before a national regulator in the EU (voluntary recognition often reduces the fine);
  • gathering evidence for law enforcement agencies;
  • A strategy to get out of a relationship with a problem client.

Step 9. Ensure integration with IT infrastructure

Without digitalization, the Compliance program in international business will fail.

Minimum required:

  • integration of scoring systems into ERP (SAP, 1C, Oracle);
  • geoblocking access to services for IP addresses from prohibited regions;
  • automatic stop of invoice in the accounting system in case of coincidence with the sanctions list.

Technology does not replace the lawyer, but it reduces the human factor in hundreds of routine operations.

Step 10. Provide evidence-based protection (Record-Keeping)

When checked by an EU regulator or bank, the main argument will not be assurances, but records.

According to international standards and EU requirements, it is necessary to keep the documentation for compliance checks for at least 5-7 years, including:

  • screenshots of the results of the sanctions checks with a time stamp;
  • questionnaires of counterparties;
  • Correspondence with a request for explanation;
  • minutes of meetings of the Compliance Committee;
  • End-user certificates.

The absence of records of the inspection is often interpreted by the regulator as the absence of the inspection itself.

Formal programme vs. Real protection

CriteriaFormal programmeA real working programme
PurposePresent to the bank for opening an accountPrevent risk, protect assets and manage
Risk-assessmentCommon patternSpecific analysis of products and routes
ScreeningOne-time, before the deal.Regular, post-factual audit
Response to alarmOften ignoredClear protocol of escalation and blocking
Business linkagesHinders sales.Built into the sale process as a condition of closing the transaction

The choice does not depend on the availability of certificates, but on the real willingness of management to invest in the sustainability of the business.

How to strengthen the program before problems arise

The best protection is not built during a crisis, but when you start a business in Europe or start working with sanctioned groups of goods.

Preferably in advance:

  • Check the beneficial structure for “toxicity”
  • Replace “dangerous” jurisdictions in the chain of ownership or payments
  • to introduce mandatory sanctions clauses in contracts that allow to terminate the contract without penalties if the counterparty falls under sanctions;
  • Develop a “Shipment Stop Protocol” (Shipment Stop Protocol)
  • Get prior advice from the European Public Prosecutor’s Office (EPPO) or the EU national prosecutor’s office on the disputed transactions.

Common mistakes in building a Compliance program

1. The EU and the US lists are not identical. A program that is only designed under OFAC (50% rule) can skip the European asset freezes completely.

2. Traders and agents are the main source of problems of “gray” imports. Checking the end-level without checking the middleman is pointless.

3. The formal training “We sent out a presentation” doesn’t work. If an employee has not understood his or her personal responsibility before a court in the EU, the program does not work.

4. Manual check of thousands of counterparties on the EU lists once a quarter guarantees a match skip.

5. If the beneficiary shows an example of circumvention of the rules, the Compliance officer becomes the enemy of the business, not the defender.

Checklist for program construction

Before starting the program, you need to answer 15 questions:

  1. What specific EU regulations and laws of member states apply to your product?
  2. Does your product fall into the dual-use category?
  3. Are all end users verified?
  4. Are the banks excluded from the payment chain?
  5. Is the screening adjusted for Cyrillic and Latin names?
  6. Does the seller know what the “gray” transit request looks like?
  7. Who in the company has the right to cancel the sanctions stop factor?
  8. Have your distributors been checked for military connections?
  9. Is there a protocol in case of blocking SWIFT payment?
  10. Are technology transfer channels (FTP, cloud, email) secure?
  11. Is the CEO ready to be questioned by the EU's national regulator?
  12. Do you have an external legal advisor with an attorney-client privilege?
  13. Are the logs of the checks stored for at least 5 years?
  14. Is there an anonymous channel for staff complaints?
  15. What scenario will give the best commercial result: Preventing a mistake or saving a business after a fine?

What a strong Compliance strategy looks like

A strong strategy usually involves five levels of maturity:

1. Legal Assessment Analysis of applicable EU sanctions and export regimes and risks of secondary sanctions.

2. Business Process Mapping: Embedding checks into ERP systems and a business process map so that compliance does not paralyze the operating system.

3. Human Factor Learning and creating tone from the top, where compliance with restrictions is part of KPI.

4. Incident Response: Willingness to stop a transaction within an hour and start internal investigation properly.

5. Regulatory Dialogue: The ability to interact with European regulators, apply for licenses (derogations) and prove the integrity of the program.

Without a fifth level, the program risks being left unrecognized by the regulator at the time of this audit.

FAQ

Can we build a program from scratch to work with the EU? It should start with analyzing product codes and customer geography, not copying someone else’s documents.

More importantly: EU sanctions or secondary US sanctions are a priority for maintaining access to the European market and settlements in euros. But ignoring OFAC’s requirements can leave you without dollars and banking in principle.

Can you do without a Compliance Officer? Responsibility for violations in the EU is personal. If there is no employee responsible for compliance, the CEO is automatically recognized.

Immediately freeze all assets (funds, goods) and notify the national competent authority in the EU. Continuing transactions is a criminal offence.

Does the Compliance program protect against penalties? The existence of a real, risk-proportionate program is one of the main mitigating factors in the imposition of punishment by EU and US regulators.

Technically possible, but it is a serious conflict of interest and a red flag for banks. Functional separation is recommended.

How does the program for the manufacturer differ from the program for the trader?The manufacturer must control the structural elements of the product (dual purpose). The trader is the final destination and end user, and the risks of false transit are higher.

Related services

  • Sanctions, Export Controls & International Compliance
  • International Trade, Distribution & Cross-Border Transactions
  • Corporate Investigations, Regulatory Investigations & Business Integrity
  • International Regulatory Risk & Strategic Advisory

Related material

  • European Union sanctions: practical guide for business
  • Bypassing EU sanctions: pattern-detection
  • Export control of dual-use goods in the EU
  • Personal responsibility of top management for violation of sanctions
  • Sanctions Compliance for Traders and Logistics Companies
  • How to check a foreign counterparty before a transaction
  • Internal investigation of sanctions violations: step-by-step

Conclusion

Building an international Compliance program in the EU jurisdiction does not require a formal set of documents, but a deep integration of legal knowledge into business logistics.

Strong protection is based on precise identification of applicable risks, automation of sanction screening, training of personnel in specific “red flags” and readiness to respond to incidents instantly.

In the sphere of sanctions and export control, the winner is not the one who bought the most expensive system. The winner is the one who has arranged the proceedings in advance so that, at the time of a dispute with a bank or an EU regulator, he will provide irrefutable proof of his good faith, not explanations.

Have a question about the topic of this article?

Write to us and we will respond within one business day.