RiskPulseRequest Demo

Insight

When a US Sanctions Listing Isn't Enough

The CJEU ruled banks can't deny basic accounts solely on OFAC listings. This forces European FIs to revamp sanction screening, requiring nuanced, AI-driven assessments to balance EU legal duties with US sanctions risk.

When a US Sanctions Listing Isn't Enough

When a US Sanctions Listing Isn't Enough: The CJEU's Landmark Ruling on Basic Account Access and What It Means for European AML Programmes

On 11 June 2026, the Court of Justice of the European Union delivered a judgment that European compliance teams will be discussing for some time. In Case C-81/24 (LH v OTP banka d.d.), the Court ruled that a bank cannot refuse to open a payment account with basic features for a consumer solely because that person appears on a sanctions list maintained by the US Office of Foreign Assets Control (OFAC).

The case in brief

The dispute originated in Slovenia in 2022, when a bank — then Nova Kreditna Banka Maribor, since acquired by OTP Group — declined to open a basic payment account for a consumer identified only as LH. The sole basis for the refusal was the applicant's inclusion on an OFAC list. Notably, the individual had never been convicted of the offence that led to the US designation and was not subject to any restrictive measures imposed by the United Nations, the European Union, or Slovenia itself.

The Slovenian court referred the matter to Luxembourg, asking whether the Payment Accounts Directive (2014/92/EU), read alongside the EU's anti-money laundering framework, permits refusal on these grounds. The Court's answer was clear: every consumer legally resident in the EU has the right to a basic payment account, and while that right is conditional on compliance with anti-money laundering and counter-terrorist financing rules, a third-country sanctions designation — standing alone — does not satisfy the threshold for refusal.

The judgment broadly follows the September 2025 Opinion of Advocate General Richard de la Tour, who reasoned that an OFAC listing may legitimately inform a bank's risk assessment and justify enhanced due diligence, but cannot function as an automatic disqualifier where EU and national law impose no equivalent sanction.

Why this creates real tension for European financial institutions

On paper, the ruling simply restates a principle of financial inclusion. In practice, it strikes at the heart of how many European institutions have operationalised sanctions and AML risk.

Screening logic must become more discriminating. Most institutions screen prospective customers against consolidated watchlists that blend UN, EU, national, and US designations. Many onboarding workflows treat any list hit as a hard stop. The Court has now made clear that, at least for basic payment accounts, the legal weight of a hit depends on whose list it is and what underpins it. Screening systems built around binary match/no-match outcomes will need to differentiate by list origin, legal applicability, and the substantive grounds for designation.

De-risking comes under fresh scrutiny. Blanket de-risking — declining whole categories of customers to avoid compliance cost and exposure — has long been criticised by the EBA and FATF. This judgment converts that supervisory disapproval into enforceable consumer rights. An institution that refuses a basic account must now be able to evidence an individualised assessment showing genuine ML/TF risk under the EU framework, not merely point to a foreign designation.

The documentation burden rises. Refusal decisions become contestable in court. That means every adverse onboarding decision needs a defensible, well-reasoned audit trail: what risk factors were identified, what enhanced due diligence was performed, what the customer's explanations were, and why the residual risk was deemed unacceptable under EU law specifically.

The transatlantic squeeze remains. None of this makes US secondary sanctions exposure disappear. Institutions with US dollar clearing, US operations, or correspondent relationships still face real commercial and legal consequences for servicing OFAC-designated parties. European banks are now navigating between an EU legal duty to serve and a US-driven commercial imperative to avoid — a tension reminiscent of the EU Blocking Statute debates, and one that demands far more granular, case-by-case judgment than most compliance operating models were built for.

Where generative AI fits: from binary screening to reasoned assessment

The common thread in all of the above is that compliance teams must replace crude, rule-based decisions with nuanced, well-documented, individualised assessments — at scale, without ballooning headcount. This is precisely the gap that generative AI solutions such as RiskPulse are designed to close.

Contextualising screening hits. Rather than surfacing a raw name match, generative AI can synthesise the full context around a designation: which authority issued it, the stated legal basis, whether parallel EU or UN measures exist, related adverse media, and any litigation or delisting history. An analyst receives a structured narrative instead of a fragment, enabling exactly the differentiated treatment the Court now requires.

Supporting proportionate enhanced due diligence. Where an OFAC listing justifies enhanced due diligence rather than refusal, tools like RiskPulse can assemble and summarise source-of-funds information, transaction expectations, and beneficial ownership data, and flag the specific residual risks an institution must weigh — turning EDD from a checklist exercise into a genuine risk evaluation.

Generating defensible decision records. Because refusals are now justiciable, the quality of written rationale matters as much as the decision itself. Generative AI can draft consistent, regulation-referenced decision memoranda that articulate why an account was opened with monitoring conditions, or why it was lawfully refused on EU-recognised grounds — giving institutions an audit trail that stands up to both supervisors and courts.

Keeping pace with a moving legal landscape. This judgment will not be the last word; national transpositions, EBA guidance, and the incoming EU AML Regulation and AMLA supervision will all reshape expectations. AI-driven horizon scanning can translate these developments into updated policies, screening logic, and analyst guidance far faster than traditional change management cycles.

The bottom line

The CJEU has told European banks that compliance cannot be outsourced to someone else's sanctions list. Financial inclusion and financial crime prevention must be reconciled customer by customer, with reasoning that holds up under legal challenge. Institutions that continue to rely on blunt, binary screening will face rising legal, regulatory, and reputational exposure from both directions. Those that invest in intelligent, explainable, AI-augmented compliance — pairing the analytical depth of solutions like RiskPulse with experienced human judgment — will be far better placed to operate confidently in a world where the right answer is rarely a simple yes or no.

See it in action

Bring a real case.
We’ll show you the workflow.

Share a real workflow, a sample file, or a current challenge and we’ll show you how RiskPulse works in practice.

Request Demo