Till Otto

Benjamin Arens

Benjamin Arens

Preventing the circumvention of targeted financial sanctions under the AMLR

Under the AMLR, the prevention of the circumvention of targeted financial sanctions will complement the fight against money laundering and terrorism financing. This article outlines the changes.

Several uniformed police officers or security personnel standing in a narrow alley

With the start of application of the AMLR on 10 July 2027, not only will an expanded group of obliged entities have to comply with anti-money laundering requirements, but the objective of these regulations will also be extended to include an additional element. Alongside the fight against money laundering and terrorist financing, the AMLR introduces the prevention of the evasion of "targeted financial sanctions" as the third element that these compliance requirements aim to prevent.

What are "targeted financial sanctions"?

Sanctions – also known as "embargoes" or "restrictive measures" – are an instrument used by the international community to security-respond to breaches of international law, human rights violations, or threats to peace. They are designed to bring about a change in behaviour on the part of the individuals or entities against whom they are imposed, so that they cease the conduct disapproved of by the international community. As part of foreign trade law, they restrict international economic and financial transactions. As a result, the export sector and the financial market in particular play a central role in the successful enforcement of sanctions.

Only "targeted financial sanctions" fall within the scope of the AMLR. These are EU measures that freeze assets, or prohibitions that directly or indirectly ban the provision of funds or other economic resources to or for the benefit of the designated individuals or organisations. The measures covered must be designated in corresponding decisions of the Council of the EU (pursuant to Art. 29 TEU) or in Council regulations (pursuant to Art. 215 TFEU). This includes, in particular, the prohibitions on disposal and provision under the relevant EU sanctions regulations as essential EU measures in the area of financial sanctions.

In addition to EU sanctions, international financial sanctions imposed by the United Nations, as well as United Nations sanctions related to proliferation financing, are also to be subsumed under the term "targeted financial sanctions". Although not explicitly mentioned, they are included for reasons of legislative systematicity due to their mention under the definitions of the AMLR (Art. 2(1) No. 50, 51 AMLR).

Both the EU and the United Nations provide a systematic overview of the sanctions in place (European Union Sanctions Map / UN Sanctions Map). Furthermore, the EU provides a dashboard via the "EU sanctions tracker", which can be used to identify individual sanctions regimes, nationalities, and sanctioned individuals or entities using a search mask.

What measures must obliged entities take?

With the entry into force of the AMLR on 10 July 2027, obliged entities will have to establish a comprehensive risk management system in their businesses and institutions to prevent the circumvention of targeted financial sanctions. In principle, the requirements for preventing the circumvention of sanctions are in no way inferior to the established requirements for preventing money laundering and terrorist financing, and comprise the same components that have emerged in anti-money laundering risk management in recent years.

The offence of targeted circumvention of financial sanctions

The starting point for establishing appropriate and effective risk management in the area of sanctions is also a deeper understanding of the offence and its methods of commission. Unlike money laundering, where it has to be determined from an ex post perspective whether the money is incriminated, the perspective for the offence of sanctions circumvention is similar to that of terrorist financing. In both cases, an ex ante perspective must be adopted to assess whether funds or other financial resources are likely to flow to sanctioned persons or entities or terrorist organisations. In the case of sanctions circumvention, as in the case of terrorist financing, it is helpful to be able to refer to lists (sanctions lists/terrorist lists) containing the sanctioned persons and actors. However, forecasting or determining this in individual cases is more complicated, as complex circumvention structures are increasingly being used to disguise the ultimate beneficiary of a transaction. In this case, the risk-based approach must also be applied in the area of sanctions circumvention: in case of doubt, a (suspected) sanctions circumvention must be assumed and appropriate measures taken.

Risk assessment

The foundation of risk management to prevent the circumvention of targeted financial sanctions is the risk assessment (Art. 10(1) AMLR). As part of the risk assessment, entities must evaluate the specific entry points for the circumvention of targeted financial sanctions presented by the business model, the product portfolio, the geographic scope of activity, and the customer base. This includes taking into account measures already taken to prevent sanctions circumvention and determining what further measures need to be implemented. Obliged entities can use already published guidelines as a reference. For instance, both the Deutsche Bundesbank and the Federal Office for Economic Affairs and Export Control (BAFA) have published information sheets on compliance with (financial) sanctions. In addition, the EU has published a guidance note specifically for Russia-related sanctions on implementing a risk management system to prevent the circumvention of Russia-related sanctions. These documents provide reference points for identifying and analysing risks of sanctions circumvention, but are not intended to be exhaustive and, above all, cannot replace a company-specific analysis.

Internal policies, procedures and controls

Derived from the results of the risk assessment, appropriate internal safeguards (the AMLR uses the term "internal policies, procedures and controls", Art. 9(1) AMLR) must be established. The scope of an appropriate design of internal safeguards is derived from the risk assessment and must reflect the business activity and size of the obliged entity, in particular the specific risks associated with these factors as well as the complexity of the business model, and must be suitable for covering all areas of activity of the obliged entity (Art. 9(1) subpara. 2 AMLR). The AMLR specifies a minimum standard of measures that must be established in detail (catalogue of internal policies, procedures and controls in Art. 9(2) AMLR). The most significant measures in the catalogue are explained in more detail below. This catalogue must be adapted and expanded in a business model-specific and risk-proportionate manner.

In particular, when designing internal safeguards, it must be noted that the risk-based approach – known from previous anti-money laundering requirements and now also applicable to the offence of sanctions circumvention within the framework described here – must not affect the obliged entity's sanctions compliance in such a way that it departs from the established rule-based system of sanctions compliance. With regard to targeted financial sanctions, there remains an absolute obligation to freeze corresponding sanctioned funds or other assets and not to make them available, directly or indirectly, to designated persons or entities (Recital 33 AMLR).

Customer Due Diligence

The inclusion of the offence of "circumvention of targeted financial sanctions" also affects the execution of customer due diligence. When boarding customers, obliged entities must check whether the customer or the customer's beneficial owners are subject to targeted financial sanctions (Art. 20(1)(d) AMLR), i.e., screening against sanctions lists must be carried out. This obligation also applies to ongoing monitoring, which requires obliged entities to review their customers at (risk-based) intervals. This review must now also include whether customers have been added to any relevant sanctions list during the course of the business relationship.

Money Laundering Reporting Officer

With the extension of anti-money laundering requirements, the scope of responsibility of the Money Laundering Reporting Officer (MLRO) within the company is also expanded. The MLRO is now also responsible for ensuring compliance with and implementation of targeted financial sanctions within the company's scope of activity, and serves as the point of contact for employees as well as the competent supervisory authorities. They are responsible for submitting suspicious transaction reports regarding sanctions circumvention to the Financial Intelligence Unit (FIU). Since the issue of sanctions circumvention involves questions that generally cannot be answered using the established expertise of an MLRO, relevant staff must be trained in good time to establish and maintain an effective risk management system within the company.

Conclusion and Outlook

The expansion of the anti-money laundering framework to include sanctions circumvention represents a significant update for obliged entities, which they must comply with by the time the AMLR becomes applicable on 10 July 2027 at the latest. Obliged entities should therefore plan the adaptation of their internal safeguards at an early stage and train their employees accordingly. Key information on implementing the requirements will be provided in the AMLA guidelines on the business-wide risk assessment on the basis of Art. 10(4) AMLR. The AMLA published an initial consultation draft for feedback on 16 April 2026, with the consultation phase running until 15 July 2026. On 28 May 2026, the AMLA held a public hearing for stakeholders to discuss the consultation draft.

Contact

Prefer skipping forms? Reach us directly by phone or email and we’ll take it from there

Contact

Prefer skipping forms? Reach us directly by phone or email and we’ll take it from there