Home Blog Treasury Management EBA Sanctions Compliance Guidelines 2026: What Financial Institutions Need to Implement Now

EBA Sanctions Compliance Guidelines 2026: What Financial Institutions Need to Implement Now

Treasury Management

·

What Financial Institutions Need to Implement Now

Summarise the article with your AI

At the end of 2025, the EBA sanctions compliance guidelines came into force, establishing the first harmonised EU standards for sanctions compliance. Financial institutions must implement robust governance frameworks, appoint senior compliance officers, conduct annual exposure assessments, and deploy screening systems with appropriate calibration to balance compliance with operational efficiency. Corporate payments service providers face additional requirements for real-time transaction screening and alert handling under the EBA Sanctions Compliance Guidelines in 2026.

Just before lunchbreak, a critical cross-border supplier payment to Germany triggered a sanctions alert at a French PSP. The compliance team scrambles to investigate, while the CFO rings, demanding answers. Meanwhile, other payments sit in limbo, waiting for verification on whether the screening system was accurate or produced a false positive.

Treasury teams across Europe deal with this daily. The EBA sanctions compliance guidelines apply from 30 December 2025, establishing the first common EU standards on governance arrangements and policies that financial institutions should have in place to comply with Union and national restrictive measures. For the first time in EU history, we have harmonised standards on how to handle sanctions.

What are the EBA sanctions compliance guidelines?

The European Banking Authority (EBA) published two distinct sets of guidelines on how financial institutions must handle restrictive measures that establish common requirements across all member states. The first set applies to every regulated financial institution within the EBA's supervisory remit, covering governance, policies, procedures and internal controls. The second set targets payment service providers and crypto-asset service providers specifically, with detailed requirements on screening systems and alert handling.

Under the EBA's "comply or explain" framework, both authorities and financial institutions must make every effort to comply. If you're operating as covered, regulated entity in the European banking system, this affects you:

Who do the guidelines apply to?

The guidelines cover:

  • All credit institutions (banks) within the EBA's supervisory remit
  • Investment firms providing regulated investment services
  • Payment institutions and electronic money institutions (EMIs)
  • Payment Service Providers (PSPs) conducting transfers of funds
  • Crypto-Asset Service Providers (CASPs) conducting transfers of crypto-assets

Relevant member state authorities supervising these institutions must also comply.

Key governance requirements for all financial institutions (the first set of guidelines)

Senior management responsibility isn't negotiable

Under the EBA sanctions compliance guidelines, management bodies bear ultimate responsibility for sanctions compliance. They must approve the compliance strategy, ensure all members understand the institution's exposure to restrictive measures, and adopt an appropriate risk management framework that's sufficiently independent from the business it controls.

Financial institutions must also appoint a senior staff member in charge of restrictive measures compliance, someone with direct access to the management body who can coordinate effectively with internal control functions. This role may be combined with anti-money laundering duties if justified by the institution's size and complexity, but it cannot create conflicts of interest.

The governance requirements go deeper. Each bank must conduct a comprehensive exposure assessment identifying which sanctions regimes apply to its operations, evaluating the likelihood of breaches and circumvention, and assessing potential impacts. This assessment must consider geographic risk, customer risk, product risk and delivery channel risk. And it must be reviewed at least annually.

Screening, calibration and alert handling for PSPs and CASPs (the second set of guidelines)

The screening challenge: balancing precision with operational reality

Payment service providers must implement screening systems adapted to the size, nature and complexity of their business. The system must be reviewed at least annually, with documented capabilities and limitations available to regulators on request.

What must a PSP actually screen? Everything that matters: customer first names and surnames, dates of birth, legal entity names, aliases, beneficial owners, wallet addresses for crypto-assets, payer and payee information, transfer purposes, and details of all PSPs involved including BIC and SWIFT codes.

The calibration requirements present a genuine challenge. A firm must maximise alert quality whilst ensuring compliance, walking a tightrope between too many false positives and insufficient sensitivity. The guidelines mandate fuzzy matching techniques that can identify names where spelling, pattern or sound represents a close match.

When alerts fire, procedures must enable investigation without delay. Every decision must be documented. Higher-exposure situations require at least two-person review. If a firm cannot conclusively determine whether a match is genuine, it must refrain from providing services until a conclusive decision has been reached. 

Why IBAN validation and screening matter more than ever

Back to that payment freeze at the French PSP. What happened wasn't the result of a system running on controls that were too tight. All systems, processes and governance frameworks simply demand attention to regulatory requirements. Firms often accept false positives to remain on the safe side rather than risk compliance breaches.

The EU Instant Payments Regulation requires euro payments to be processed within 10 seconds, which is forcing PSPs to rethink their entire approach to sanctions screening. Rather than screening transactions in real-time (which became impractical under the 10-second window), the regulation pushed institutions toward customer-based screening instead. PSPs now typically screen customers daily and immediately rescan when sanctions lists change.

IBAN validation helps in meeting the EBA sanctions compliance guidelines 2026. It verifies bank account authenticity, reduces transaction errors through built-in validation logic, and most importantly, enables accurate counterparty identification before sanctions screening occurs. Best practice now involves validating IBANs and Legal Entity Identifiers at entry, not at payment, as part of a centralised operating model.

Discover more about Embat

Book a call to explore how Embat combines automation and AI to eliminate manual work, reduce risk, and deliver real-time financial control.

Book a Demo

Transaction screening still matters for three reasons. First, payments outside SEPA Instant still require it. Second, the EBA sanctions compliance guidelines require PSPs to screen transfers before making funds available to the payee. Third, circumvention risks are evolving rapidly, and good screening helps detect attempts to omit, delete or alter payment message information.

All of this ultimately demands continuous list updates streaming into your systems, instead of periodic batch uploads. Also, it requires immediate suspension of operations that trigger alerts and necessitates regular assessment of how quickly the automatic suspension mechanisms actually work.

The compliance challenges financial institutions face in 2026

Intelligent calibration typically prevents frequent suspensions because of false-positives. Screening systems should balance detection accuracy with operational efficiency. It means implementing, as an example, approved list procedures for repeatedly false-flagged entities, but with documented justification and regular review.

Firms need adequate resources for alert analysis, enabling prompt reporting of genuine matches. Modern treasury platforms now frequently offer integrated sanctions screening with continuous list updates, automated IBAN validation, and intelligent alert routing that separates signal from noise. Robust treasury payment controls combine these technical capabilities with the governance frameworks necessary to deploy them effectively.

Screening systems should be tested regularly to verify calibration accuracy, list management effectiveness and response timeliness. Yet, many firms lack sufficient management information to enable effective decision-making on how to deal with the typical alert that is not a full-on hit. In some cases, the calibration of outsourced tools can be complex to verify independently.

For ongoing operations, using AI in finance (e.g. utilising TellMe for anomaly detection) can often drastically reduce manual review times and ensure payment flows remain uninterrupted. Frequently, modern treasury platforms can also support real-time monitoring capabilities and sanctions compliance capabilities that protect institutions whilst enabling smooth treasury operations.

What happens after 2026? The road to AMLA and the AML regulation

The EBA guidelines discussed here are just the beginning. From 1 January 2026, responsibility for all EU-level AML/CFT tasks have been transferred from the EBA to the new Anti-Money Laundering Authority. The EU now develops common rules via a single rulebook, while the AMLA will draft technical standards, enforce them, directly supervise selected high-risk institutions, and coordinate national Financial Intelligence Units. It is a decentralised EU agency that will coordinate national authorities to ensure the correct and consistent application of EU rules.

Key regulatory milestones

Milestone dateRegulatory eventImpact on financial institutions
30 December 2025EBA Sanctions Guidelines applyMandatory governance, fuzzy matching, and exposure assessments.
January 2026AMLA Assumes EBA MandatesShift of AML/CFT tasks to the new central EU authority.
10 July 2027AML Regulation Takes EffectA single, directly applicable rulebook replaces national directives.
January 2028AMLA Direct Supervision BeginsDirect oversight of up to 40 high-risk cross-border institutions.

The EU's Anti-Money Laundering Regulation takes effect on 10 July 2027.  This represents a fundamental shift from the current directive-based approach to a directly applicable single rulebook across all member states. Internal policies, procedures and controls for targeted financial sanctions will be regulated under this new framework.

From January 2028, AMLA will begin direct supervision of up to 40 high-risk institutions operating across at least six member states. The regulatory landscape is consolidating, standardising and intensifying simultaneously.

Building foundations that last

The EBA sanctions compliance guidelines provide a blueprint for building robust sanctions compliance infrastructure. They establish clear governance responsibilities, define screening system requirements, and set expectations for how institutions should balance compliance with operational efficiency.

Financial institutions that treat these guidelines as a compliance checkbox exercise will find themselves perpetually firefighting. Those that view them as an opportunity to fundamentally strengthen their sanctions infrastructure will emerge stronger and more competitive.

Connect your banks, predict liquidity, and manage payments from a platform that learns from your business.

Automate, centralise, and make smarter decisions in real time. Discover how Embat works.

Book a demo with our experts

Ready to flow?