European Regulations

EU Sanctions Against Ukraine: Corrections in Lists Affecting Spanish Companies and Banks

E
Equipo Editorial CambiosLegales
Sep 25, 2026 6 min 70 views

Key data

RegulationRectification to Council Decision (CFSP) 2023/432 of 25 February 2023, amending Decision 2014/145/CFSP on restrictive measures against those threatening the sovereignty and territorial integrity of Ukraine
Publication25 September 2026
Entry into force25 February 2023 (retroactive to the original corrected decision)
Affected partiesFinancial entities, companies with international operations and persons included in EU sanctions lists
CategoryEuropean Regulation
Type of measureCorrection of identifying data and/or reasons for inclusion in sanctions lists
Applicable sanctionsAsset freezing and prohibition of entry into EU territory
Impact analysis reserved for subscribers
The detailed impact analysis of this regulation is available with the PRO and Business plans. Access the full content and receive personalized alerts.
From €9.99/month · Cancel anytime

If your company works with international counterparties or your financial entity manages accounts for non-resident clients, this rectification requires you to take action. Council Decision (CFSP) 2023/432, which amended the EU's restrictive measures in force since 2014 against those threatening Ukraine's sovereignty and territorial integrity, has been formally corrected. The corrections may affect names, identifying data or reasons for inclusion in the sanctions lists, which partially invalidates the records that your compliance system had until now.

The original sanctions framework begins with the Council Decision 2014/145/CFSP, adopted following the Crimea events in 2014, and has been expanded and amended on multiple occasions. This rectification does not add new persons to the list nor removes any: its function is to correct material errors in the data already published, but those errors, if not corrected in your systems, can generate false negatives or false positives in compliance controls.

What does this regulation establish?

This rectification corrects Council Decision (CFSP) 2023/432 of 25 February 2023. That decision amended the restrictive measures adopted since 2014 against persons and entities that compromise or threaten the territorial integrity, sovereignty and independence of Ukraine.

The published corrections may include one of the following types of changes:

  • Correction of names or spellings of natural or legal persons included in the lists
  • Update of identifying data (dates of birth, nationalities, passport numbers or other identifiers)
  • Correction of the reasons for inclusion in the sanctions list

The restrictive measures applied to persons and entities included in these lists are:

  • Asset freezing: all funds and economic resources belonging to listed persons or entities must be immobilized
  • Prohibition of entry: natural persons included in the list cannot enter or transit through the territory of the European Union

The rectification does not modify the scope of sanctions nor add new categories of restrictive measures. Its purpose is exclusively to correct material errors in previously published information.

Economic and operational impact

The direct impact of this rectification is not economic in terms of new fees or regulatory costs, but rather operational and legal risk. Companies and financial entities that do not update their screening lists assume two types of risk:

  • False negative risk: if the correction updates a name or identifying data and your system continues to use the incorrect version, you could operate with a sanctioned counterparty without detecting it. This exposes the company to administrative and criminal sanctions in Spain.
  • False positive risk: if the correction removes an error that generated undue matches, maintaining the incorrect data can block legitimate operations, with the resulting operational and reputational cost.

In Spain, non-compliance with EU restrictive measures can result in serious administrative sanctions and, in the most serious cases, criminal liability. The applicable Spanish regulations include the Law 10/2010 on the prevention of money laundering and financing of terrorism, which requires entities subject to it to keep their counterparty control systems updated.

Who does it affect?

  • Financial entities: banks, savings banks, credit cooperatives, payment entities and any institution that manages customer funds or assets with international exposure
  • Companies with international operations: exporters, importers, companies with subsidiaries or partners in countries in the Russian environment or with counterparties in emerging markets where sanctioned persons may be present
  • Law firms and advisors: that provide services to clients with links in risk areas or that manage assets of non-resident natural or legal persons
  • Fund managers and family offices: with investments or stakes in structures that may include listed persons or entities
  • Natural and legal persons included in the lists: who may see their identifying data or the reasons for their inclusion corrected

Practical example

Imagine that a Spanish bank has in its screening system the name of a Russian businessman with a certain spelling, as it appeared in the original version of Decision (CFSP) 2023/432. This rectification corrects the spelling of that name (for example, a transliteration from Cyrillic to the Latin alphabet that was incorrectly transcribed). If the bank does not update its database, its control system will not detect matches with the corrected name, and could process transfers or maintain active accounts for that person without triggering any alert.

In a subsequent inspection by the Bank of Spain or Sepblac, the entity would not be able to demonstrate that its controls were up to date with the current version of the sanctions lists. This can result in a sanctioning file for non-compliance with due diligence obligations in international sanctions matters.

Do you need to track this and other regulations?

Consult the full details on CambiosLegales

What should companies do now?

  1. Download the updated version of the sanctions lists: access the EU Sanctions Map or the EU consolidated list and download the most recent version that incorporates this rectification.
  2. Update internal screening systems: if your company uses compliance software (AML, KYC or counterparty screening systems), verify that the provider has incorporated the corrections published in this rectification.
  3. Review active counterparties: perform a cross-search between your current counterparties and the corrected data to detect possible matches that the previous system would not have identified.
  4. Document the update: keep written record that you have reviewed and updated your compliance lists following the publication of this rectification. This documentation is key in case of inspection.
  5. Inform the compliance officer: the compliance officer or the person responsible for money laundering prevention must be notified of this change and validate that internal procedures have been updated.

Frequently asked questions

What exactly does this rectification of Decision (CFSP) 2023/432 correct?

The rectification corrects material errors in Council Decision (CFSP) 2023/432 of 25 February 2023. The corrections may affect names, identifying data (such as dates of birth, nationalities or document numbers) or the reasons for inclusion of persons and entities in the lists of those sanctioned for threatening Ukraine's sovereignty and territorial integrity. It does not add new persons nor removes any from the list.

What sanctions are applied to persons and entities included in these lists?

The restrictive measures include two types of sanctions: asset freezing (all funds and economic resources must be immobilized) and prohibition of entry or transit through the territory of the European Union for natural persons listed.

What happens if my company does not update its compliance lists with these corrections?

Non-compliance with EU restrictive measures can result in administrative and criminal sanctions in Spain. If your screening system does not reflect the corrected data, you could operate with a sanctioned counterparty without detecting it, which exposes you to a sanctioning file by Spanish supervisory authorities, including the Bank of Spain and Sepblac in the case of financial entities.

Where can I consult the updated list of persons and entities sanctioned by the EU?

The consolidated list of EU sanctions is available on the official European Union portal through the EU Sanctions Map. You can also consult the full text of this rectification in the Official Journal of the EU.

From what date are the corrections published in this rectification effective?

The corrections are effective from the date of entry into force of the original decision being corrected: 25 February 2023. A rectification has retroactive effect on the text it amends, so the corrected data must be considered effective from that original date.

Official source

Consult complete regulation in official source

Notice: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://eur-lex.europa.eu/./legal-content/AUTO/?uri=OJ:L_202690803



Share:
E
Equipo Editorial CambiosLegales

El equipo editorial de CambiosLegales analiza diariamente los cambios normativos que afectan a empresas y autónomos en España, ofreciendo análisis pro...

Comments

No comments yet. Be the first to comment!

Leave a comment
Activate alerts