You might think you're compliant because your trust documents say the settlor has no control, your corporate structure shows no formal ties, and your beneficial ownership register lists the right names. But that's not enough anymore.
Recent rulings by the Court of Justice of the European Union (CJEU) on sanctions and anti-money laundering (AML) transparency highlight a gap between what compliance teams document and what regulators enforce. The court has made it clear: practical control takes precedence over legal formalism.
These aren't isolated issues. They're systemic blind spots that leave your organization vulnerable, even when your paperwork seems perfect.
Why These Mistakes Keep Happening
The move from document-based compliance to substance-based assessment came without a clear guide. For years, compliance frameworks relied on constitutional documents, ownership registers, and signed declarations. If the trust deed said the settlor retained no influence, that was considered sufficient.
However, Council Regulation (EU) No 269/2014 and the 4th Anti-Money Laundering Directive now require ongoing factual analysis of who actually benefits, who makes decisions, and who influences. Many teams still use tools designed for the old regime, resulting in compliance programs that look thorough but miss the essentials.
Mistake 1: Treating Trust Deeds as Conclusive Evidence
Why it happens: Your legal team drafted careful language limiting the settlor's rights. The document says the beneficiary has no control over distributions, and you assume that settles the question.
The real consequence: The CJEU held that "belonging to" and "control" under Article 2 of the sanctions regulation must be interpreted broadly, covering all forms of power or influence, even without a formal legal link. If a sanctioned individual can use, benefit from, or influence decisions over assets, those assets can be frozen regardless of what the trust instrument says.
The specific fix: Build a factual assessment process separate from document review. Map actual decision-making: Who initiates distribution requests? Who do trustees consult before major decisions? Who benefits economically from asset use even without formal distributions? Document these patterns quarterly, not just at structure inception.
Mistake 2: Running One-Time Beneficial Ownership Assessments
Why it happens: You identified beneficial owners when you established the structure or onboarded the client. The register is filed, and annual reviews confirm the same names.
The real consequence: The CJEU identified dynamic indicators of control: entity restructuring shortly before sanctions were imposed, majority shareholdings in the trustee held by the beneficiary, close personal relationships between directors and designated persons. These patterns shift. A one-time assessment can't catch a settlor who acquires influence through relationships, not documents.
The specific fix: Implement event-triggered reassessments tied to specific red flags. When a beneficiary's relative joins the trustee's board, that's a trigger. When entities are restructured within six months of new sanctions designations, that's a trigger. When decision patterns change, that's a trigger. Your beneficial ownership process should respond to facts, not just calendar dates.
Mistake 3: Ignoring Structures That Don't Transfer Legal Title
Why it happens: Your team assumes that if no formal ownership transfer occurred, AML transparency obligations don't apply. Italian fiduciary companies made this exact argument about mandati fiduciari, which don't involve title transfer.
The real consequence: The CJEU confirmed that mandati fiduciari fall within the 4th Anti-Money Laundering Directive's regime despite not involving formal ownership transfer. Member states can classify domestic arrangements as "similar to trusts" for transparency purposes if they serve similar functions. If your structure creates separation between legal and beneficial ownership, or if it allocates economic benefit through non-ownership mechanisms, it likely triggers disclosure obligations.
The specific fix: Expand your AML scoping analysis beyond ownership transfer. Ask: Does this arrangement separate decision-making from economic benefit? Does it create a fiduciary relationship where one party manages assets for another's benefit? Does it obscure who ultimately benefits? If yes to any, treat it as within scope and build disclosure protocols accordingly.
Mistake 4: Relying on Complexity as Insulation
Why it happens: Your structure involves multiple jurisdictions, layered entities, and sophisticated legal instruments. You assume regulators won't untangle it or that complexity itself provides protection.
The real consequence: The CJEU explicitly listed "needlessly complex legal structures" as an indicator of control by a designated person. Complexity isn't a shield. It's a red flag that triggers deeper scrutiny. Courts and regulators now interpret layering as evidence you're trying to obscure practical control, not as proof of legitimate separation.
The specific fix: Document the commercial rationale for every structural layer. If you can't explain why a particular holding company, trust tier, or intermediary entity serves a legitimate non-regulatory purpose, simplify the structure. When complexity is necessary (cross-border tax efficiency, genuine asset protection), maintain clear records showing the business justification predates any sanctions risk.
Mistake 5: Assuming Judicial Review Protects You
Why it happens: You know beneficial owners have rights to challenge exemption denials, so you assume procedural safeguards make aggressive disclosure safe.
The real consequence: The CJEU accepted that non-judicial administrative bodies (like Italian chambers of commerce) can make exemption decisions, as long as interim legal protection exists. But "interim protection" doesn't mean you'll win, and it doesn't prevent reputational damage or operational disruption while you litigate. Relying on appeals as your primary safeguard means you've already failed at compliance.
The specific fix: Treat disclosure decisions as risk management, not legal procedure. Before filing beneficial ownership information that could expose sensitive relationships, assess whether the structure genuinely needs the opacity you're claiming. If legitimate privacy concerns exist (personal security, competitive sensitivity), document them contemporaneously and seek exemptions proactively with supporting evidence, not reactively after disclosure.
Prevention Checklist
- Factual control assessment completed within the last 90 days for any structure with EU nexus
- Red-flag triggers documented and monitoring process assigned to specific roles
- Relationship mapping includes non-fiduciary advisors, family connections, and informal influence channels
- Commercial rationale documented for every structural layer, with evidence predating sanctions risk
- Beneficial ownership identification process covers function-similar arrangements, not just formal ownership transfers
- Event-triggered reassessment protocols established for restructurings, board changes, and sanction updates
- Decision-making patterns tracked: who initiates, who the trustee consults, who benefits economically
- Exemption requests filed proactively with contemporaneous supporting evidence, not reactively
- Training updated to emphasize substance over form and practical control over legal title
The shift from formalism to substance is the new baseline. Your compliance framework needs to match.



