The EU's New Sanctions Enforcement Directive: A Guide to Personal Liability and the Criminalization of Trade Compliance Violations
As the EU's Directive 2024/1226 takes effect across member states in 2026, trade compliance violations and sanctions evasion are now harmonized criminal offenses. The new rules introduce personal liability for executives and criminalize gross negligence, fundamentally shifting the risk landscape for global businesses.
By Tiago Sousa
- Corporate Compliance Advisors
- Legal and advisory firms emphasize the urgent need for robust internal controls to mitigate personal and corporate liability.
- European Regulatory Bodies
- EU institutions view the directive as a necessary tool to end forum shopping and ensure the credibility of the bloc's foreign policy.
Perspectives this story doesn't cover
- Small and Medium-Sized Enterprises (SMEs) facing disproportionate compliance costs
The short answer
- Directive (EU) 2024/1226 harmonizes the criminalization of sanctions violations across all 27 EU Member States.
- The legislation introduces direct personal liability, with executives and compliance officers facing one to five years in prison for severe breaches.
- Intent is no longer strictly required; 'gross negligence' in handling military or dual-use goods can now trigger criminal charges.
- Corporate entities face massive financial penalties of up to €40 million or a percentage of their global turnover for compliance failures.
The European Union's regulatory landscape has entered a phase of intensified enforcement in 2026, fundamentally altering the risk calculus for global trade. The catalyst is Directive (EU) 2024/1226, a landmark piece of legislation that harmonizes criminal offenses and penalties for the violation of Union restrictive measures. By standardizing how sanctions evasion is prosecuted across the bloc, the directive empowers compliance professionals with clear, unified rules while drastically raising the stakes for organizational failures.[2]
For years, the EU faced a structural vulnerability in its sanctions regime. While restrictive measures were adopted centrally in Brussels, the prosecution of violations was left entirely to the discretion of individual Member States. This created a fractured landscape, with some countries treating severe violations as mere administrative errors while others aggressively pursued criminal charges.[2]
This disparity inevitably led to "forum shopping." Malign actors and sanctions evaders deliberately routed their illicit transactions through jurisdictions known for lenient enforcement or under-resourced investigative authorities. To close these loopholes, the European Council elevated sanctions evasion to an "EU crime" under Article 83(1) of the Treaty on the Functioning of the European Union, paving the way for the new Directive to establish a strict, bloc-wide baseline.[2]
The Directive mandates that intentional violations of EU sanctions must be criminalized across all 27 Member States. This includes making funds available to designated persons, failing to freeze assets, circumventing travel bans, or providing false information to conceal the ultimate beneficial ownership of a sanctioned entity. By defining these acts uniformly, the EU has removed the legal ambiguities that previously allowed entities to exploit cross-border loopholes.
Perhaps the most significant paradigm shift for corporate compliance teams is the introduction of direct personal liability. The Directive explicitly holds individuals accountable, meaning that trade compliance officers, managers, and corporate executives can no longer hide behind the corporate veil if they facilitate or ignore sanctions breaches.
Penalties for natural persons are severe and designed to be highly dissuasive. Depending on the gravity of the offense, individuals face maximum prison sentences ranging from one to five years. Furthermore, convicted individuals can face sweeping non-criminal penalties, including disqualification from holding senior management positions, the withdrawal of permits, and exclusion from practicing certain business activities.[2]
The legal threshold for prosecution has also been substantially lowered. Previously, authorities generally had to prove that an individual intentionally sought to evade sanctions. Under the new framework, "gross negligence" is now sufficient to trigger criminal liability in specific high-risk scenarios, fundamentally changing how companies must approach their internal controls.
This gross negligence standard applies particularly to transactions involving military equipment or dual-use goods. If a compliance officer or executive fails to implement adequate screening procedures, and those organizational deficiencies allow prohibited goods to slip through to a sanctioned destination, that failure of oversight can result in direct imprisonment. Ignorance or a lack of resources is no longer a viable legal defense.
This gross negligence standard applies particularly to transactions involving military equipment or dual-use goods.
Corporate entities face equally daunting exposure under the new rules. The Directive requires Member States to establish corporate liability when a sanctions offense is committed for the benefit of the company by any person holding a "leading position." This broad definition includes individuals with the power of representation, the authority to make decisions, or the authority to exercise control within the legal entity.[1][2]
Crucially, a company can also be held liable if a lack of supervision or control by someone in a leading position made the violation possible by a subordinate. This means that a poorly designed compliance program, inadequate employee training, or a failure to adequately audit third-party supply chains is no longer just a regulatory failing; it is a direct trigger for corporate criminal liability.[1][2]
The financial penalties for corporations have been scaled to ensure they cannot simply be absorbed as a cost of doing business. While previous national laws had wildly varying caps—ranging from €133,000 to €37.5 million in Germany, for example—the new harmonized rules push the upper limits significantly higher. Companies can now face fines up to €40 million, or a penalty calculated as a percentage of their total worldwide turnover.
To prevent the judicial system from being overwhelmed by minor infractions, the Directive does include a monetary threshold. Member States are not obliged to criminalize conduct if the value of the goods, services, or transactions involved is less than €10,000. However, this threshold is easily met if an offender carries out a series of linked, smaller transactions that cumulatively exceed the limit.
The rollout of these rules has been a multi-year process culminating in the current 2026 enforcement wave. The Directive officially entered into force in May 2024, giving Member States exactly one year—until May 20, 2025—to transpose the requirements into their national legislative frameworks.[2]
Compliance with this deadline was initially uneven. In July 2025, the European Commission took the rare and highly public step of announcing infringement procedures against 18 Member States that had missed the transposition window. This aggressive maneuver signaled to the market that Brussels views sanctions enforcement as an urgent, non-negotiable priority.
By early 2026, the legislative gap had largely closed across the continent. Germany published its Sanctions Act in February 2026, aligning its Foreign Trade Act with the Directive's strict liability standards. The Czech Republic's amendments took effect in January 2026, and Finland finalized its framework shortly after. Even countries that initially lagged, such as France, introduced comprehensive bills to the National Assembly in early 2026 to overhaul their customs and criminal codes.
For multinational corporations, the operational mandate is clear: theoretical compliance requirements have translated into immediate criminal risks. Businesses must conduct exhaustive risk assessments, evaluating their exposure across customers, suppliers, and complex global supply chains to identify potential circumvention routes.
Legal advisors emphasize that "paper programs" are no longer sufficient to protect organizations or their leadership. Companies must implement robust, automated sanctions screening tools, ensure adequate resourcing for their trade compliance departments, and establish clear, documented reporting lines directly to the board of directors.
Continuous testing and auditing of these frameworks are now essential components of corporate governance. Regular evaluations help identify vulnerabilities before they result in a breach, demonstrating to regulators that the company exercises the required level of supervision and control to mitigate the risk of gross negligence.
Ultimately, Directive 2024/1226 represents a maturation of the EU's economic statecraft. By standardizing penalties, ending forum shopping, and criminalizing negligence, the bloc has ensured that its restrictive measures carry the necessary legal weight to deter evasion, hold facilitators accountable, and protect the integrity of the international financial system.[2]
Why it matters
For corporate executives, legal teams, and compliance officers, this directive transforms sanctions compliance from a regulatory checkbox into a matter of personal criminal liability. Understanding these harmonized rules is essential to avoid severe fines, reputational damage, and potential imprisonment.
Sources
[1]SkaddenCorporate Compliance AdvisorsEU Directive on Criminal Offences and Penalties for Sanctions Violations
Read on Skadden →
[2]Sheppard MullinCorporate Compliance AdvisorsIn a bold move to tighten its sanctions enforcement, the EU rolled out Directive 2024/1226
Read on Sheppard Mullin →
Comments
More in Guides
See all →Acoustic Engineering
Active Noise Cancellation: How Phase Inversion and the Superposition Principle Silence Low-Frequency Sound
6 sources
Materials Science
Wöhler Curve and the Endurance Limit: How Stress Cycles Determine the Fatigue Life of Steel
6 sources
3D Printing Materials
PLA Creep in 3D Printing: Why Structural Parts Deform Under Continuous Load
7 sources
Emergency Prep
How to Use Power Tool Batteries as Emergency Blackout Power
4 sources
Every angle. Every day.
Get Guides stories with full source coverage and perspective breakdowns delivered to your inbox.




