Verifex

Understanding EBA/GL/2024/14: internal controls for implementing EU and national sanctions

A high-level overview of expectations around policies, controls, and operational measures for European financial institutions.

Legal Disclaimer: This guide is for informational purposes only and does not constitute legal or regulatory advice. Financial institutions should consult qualified legal counsel to determine their specific compliance obligations under European and national laws.

What EBA/GL/2024/14 covers

The European Banking Authority (EBA) issues guidelines to foster consistent supervisory practices across the EU. EBA/GL/2024/14 sets common standards for the internal policies, procedures and controls that credit and financial institutions need in order to implement — and not breach or circumvent — Union and national restrictive measures (sanctions). It is a sanctions / restrictive-measures instrument, distinct from the EBA's separate AML/CFT guidelines. Published 14 November 2024, it applies from 30 December 2025.

For compliance officers, understanding these guidelines is critical because they detail what regulators expect regarding the design, implementation, and oversight of screening systems. It's no longer just about checking names; it's about proving you have robust, governed processes in place.

Key areas of operational control

Screening governance & policies

Institutions must establish clear internal policies governing how, when, and against which lists screening occurs, overseen by management.

Evidence & audit trail expectations

Regulators expect demonstrable proof of screening operations, including timestamped records of decisions and the exact data used at the time.

False positive handling procedures

Clear procedures must be in place for reviewing, escalating, and resolving alerts, ensuring that true matches are not inadvertently cleared.

Operational controls & monitoring

Systems must be robust, with controls to ensure lists are updated promptly and the technology performs reliably under volume.

Risk-based approach

Screening measures should be proportionate to the risk profile of the customer, product, and geographic exposure.

Reporting & escalation

Defined workflows for reporting confirmed matches to the relevant competent authorities in a timely manner.

How screening infrastructure supports governance

While software is designed to support compliance review—which relies heavily on internal policies and human oversight—modern screening infrastructure provides the technical foundation needed to meet regulatory expectations.

  • Evidence Capsules: Verifex generates append-only, hashed records for every screen, demonstrating exactly what data was used and why a match decision was made, supporting audit requirements.
  • Audit Trails: Comprehensive logs of system configurations, list updates, and analyst review actions provide transparency into the operational controls in place.
  • Structured Matching: Consistent, rule-based fuzzy matching algorithms ensure that screening is applied uniformly, aligning with risk-based policy frameworks.

Frequently Asked Questions

What is EBA/GL/2024/14?

EBA/GL/2024/14 is the EBA's Guidelines on internal policies, procedures and controls to ensure the implementation of Union and national restrictive measures (sanctions). They set out how credit and financial institutions should govern and run the systems that keep them from breaching or circumventing EU and national sanctions. They were published on 14 November 2024 and apply from 30 December 2025. A paired set, EBA/GL/2024/15, applies specifically to payment service providers and crypto-asset service providers for transfers of funds and crypto-assets. These are restrictive-measures (sanctions) guidelines, distinct from the EBA's separate AML/CFT guidance.

Does this guideline apply to my institution?

These guidelines generally apply to credit and financial institutions operating within the EU. You should consult with your legal counsel to determine your specific regulatory obligations.

How does screening software help with EBA compliance?

Modern screening software provides the operational infrastructure needed to enforce policies. It automatically updates lists, applies consistent matching logic, and generates the append-only audit trails that regulators expect to see.

Is compliance with EBA guidelines mandatory?

National competent authorities typically integrate EBA guidelines into their supervisory expectations, making them effectively binding for institutions under their purview.

Technical foundations for compliance.

Provide your compliance team with the tools and evidence they need to oversee robust operations.