Sanctions Jurisdiction, Nexus and Extraterritorial Exposure
Every sanctions question begins with applicability: which legal regimes govern this person, entity, transaction, service or activity, and why? The answer comes from jurisdiction and nexus, meaning the legally relevant connections between the facts and a sanctioning authority's rules. A bank that starts with a sanctions list before establishing applicability can reach the wrong conclusion even when the screening technology works perfectly.
The practical objective is not to find the largest number of regimes that can be mentioned. It is to build a defensible footprint, identify the regimes that may apply, test the legal connection for each regime, then analyse the relevant prohibition, authorisation, exception, reporting duty or secondary exposure. The same customer can be lawful for one bank entity and restricted for another because the entities, staff, processing chain, payment route or service differ.
A useful discipline is to keep three ideas separate. Direct applicability asks whether the activity is subject to a regime's legal prohibitions. Participant obligations ask whether a bank, correspondent, employee, branch or other person participating in the activity has its own sanctions obligations. Extraterritorial or secondary exposure asks whether a person outside direct jurisdiction could nevertheless face designation, correspondent restrictions, market-access consequences or other sanctions risk under a specific authority. These are related questions, but they are not interchangeable.
The companion chapters divide related territory. Sanctions Regimes and Bank Obligations surveys programme architecture. Ownership and Control examines designated-person attribution. Secondary Sanctions, Facilitation and Evasion Risk covers sanctionable conduct outside ordinary primary jurisdiction in more depth. This chapter provides the analytical foundation shared by them all: identifying the relevant legal connections and turning that analysis into bank-operational decisions.
The map is deliberately a fact inventory, not a legal conclusion. A currency, server, customer nationality or goods origin may be relevant without by itself creating the same legal result in every regime. The control task is to gather the facts first and then apply the correct regime-specific test.
Persons jurisdiction: whose obligations follow whom
Persons-based jurisdiction is one of the clearest starting points, but the definitions differ by authority and programme. Under OFAC-administered sanctions, all U.S. persons must comply. OFAC describes U.S. persons as including U.S. citizens and permanent residents wherever located, persons in the United States, U.S.-incorporated entities and their foreign branches. OFAC also notes that certain programmes extend particular prohibitions to foreign subsidiaries owned or controlled by U.S. persons, so a bank cannot assume one group-wide rule from the corporate parent alone.
EU restrictive measures use their own jurisdiction clauses. A typical EU sanctions regulation applies within Union territory, on certain Member-State aircraft and vessels, to Member-State nationals inside or outside the Union, to legal persons incorporated or constituted under Member-State law, and to legal persons in respect of business done in whole or in part within the Union. That is more precise than saying simply that "EU persons" are always subject everywhere. The exact regulation governing the activity remains the legal source of truth.
UK financial sanctions similarly apply to persons within UK territory and territorial sea and to UK persons wherever they are in the world. OFSI states that UK nationals and legal entities established under UK law, including their branches, must comply irrespective of where their activities take place. Non-UK businesses can also create a UK nexus through activities in the UK or other fact-specific UK connections, which means a multinational bank needs entity and activity mapping rather than nationality labels alone.
For banks, persons analysis operates at several levels. Entity analysis determines the obligations of the booking bank, branch, subsidiary, service company and processing entity. Employee analysis identifies staff whose own nationality or location creates obligations relevant to approval, financing, facilitation or other involvement. Board and committee analysis matters where individuals vote on or approve transactions. Outsourcing analysis matters where a service provider in another jurisdiction performs part of the restricted activity.
The key design principle is do not collapse entity, branch and employee scope into one global group flag. A multinational group can adopt a global risk standard, but the legal basis for a particular decision still needs to identify which entity or person is subject to which rule.
Territory and activity location
Territorial jurisdiction is independent of corporate nationality. Activity conducted within a sanctioning jurisdiction can bring local rules into scope even when the customer and parent group are foreign. A third-country bank branch operating in London must consider UK sanctions for activities within UK scope. Activity carried on in the Union can engage the jurisdiction clause of the relevant EU regulation. Activity in the United States involves persons and services subject to U.S. jurisdiction.
The difficult cases are distributed services. A transaction may be booked in Singapore, screened by an operations team in Dublin, approved by a U.S.-person specialist in Dubai, processed by a service company in London and settled through a correspondent in New York. Those facts do not automatically mean that every connected regime governs every aspect of the transaction. They do mean that the bank must identify which persons performed which acts, where those acts occurred, and whether those acts fall within each regime's scope.
Digital delivery needs the same discipline. A customer logging in from a country, an API hosted in a jurisdiction or a cloud region used by the bank can be relevant evidence, but infrastructure location should not be converted mechanically into legal applicability. Legal advice should define which facts matter for the service and regime in question, and the system should preserve those facts so the analysis can be reconstructed.
Currency and clearing: follow the participating institutions, not the currency label
Currency is an important operational clue because it often predicts which clearing institutions and payment systems will participate. It is not, by itself, a universal jurisdiction rule.
For U.S.-dollar payments, the critical question is often whether the transaction enters the U.S. financial system or otherwise involves a U.S. person. A non-U.S. bank sending a dollar payment through a U.S. correspondent creates a real U.S. touch because the U.S. financial institution must comply with OFAC rules. OFAC also states that non-U.S. persons can be liable for causing or conspiring to cause U.S. persons to violate U.S. sanctions, and for evasion conduct. This is why payment analysis reconstructs the actual correspondent and clearing path rather than treating "USD" as a magic legal switch.
The same caution is essential for euro payments. Euro denomination alone is not an EU-jurisdiction rule equivalent to a shorthand "euro nexus". EU sanctions applicability comes from the jurisdiction clause in the relevant regulation: territory, Member-State nationals, EU-incorporated entities, business done in whole or in part within the Union and other defined connections. A euro payment processed by an EU-incorporated bank will of course involve an EU operator with its own obligations, but the legal connection is the operator and activity, not the three-letter currency code by itself.
Other currencies require the same fact pattern. A bank should identify the settlement bank, correspondent chain, local clearing operator, booking entity, processing entity and relevant staff. When the route is not known at initiation, the uncertainty is itself a control fact. A bank should not record "no nexus" merely because a payment message lacks an intermediary field that will only be populated downstream.
This distinction matters for architecture. A payment data model should store currency, clearingRoute, correspondents, bookingEntity, processingEntities and serviceLocations as different attributes. Combining them into one jurisdiction field destroys the evidence needed for precise sanctions analysis.
Goods, software, technology and services
Transactions involving goods and technology may create separate export-control and sanctions questions. These frameworks overlap but should not be conflated. Export-control jurisdiction can follow item origin, classification, destination, end user, end use or the participation of particular persons. Sanctions can separately prohibit specified goods, technology, services, financing or dealings with particular jurisdictions, sectors or parties.
For U.S.-origin items, re-export and transfer controls under the Export Administration Regulations can continue to matter outside the United States depending on the item's classification, destination, end user, end use, de minimis rules, foreign-direct-product rules and other programme-specific conditions. It is therefore inaccurate to say that every U.S.-origin item is globally prohibited or that every such issue is an OFAC sanctions issue. Banks should know enough to recognise the question and escalate classification or export-control analysis to the appropriate specialists.
EU and UK trade restrictions have their own scope, goods lists, service restrictions, exceptions, licensing routes and effective dates. A payment bank may not possess customs-grade product data, while a trade-finance bank may hold invoices, transport documents and detailed goods descriptions. Control expectations must reflect what the product can genuinely observe and where specialist evidence can be obtained.
Intangible transfers create additional complexity. Software access, technical assistance, cloud services, remote maintenance and advisory services can be restricted even when no physical shipment occurs. The bank's task is not to classify every technology product itself. It is to identify when customer purpose, counterparty, destination, service description or available trade data creates a question that cannot be safely answered from payment screening alone.
Direct applicability, participant obligations and secondary exposure
A strong nexus framework labels the type of exposure before deciding what to do.
Direct applicability exists when the relevant law applies to the person or activity and the prohibition, requirement or authorisation test must be followed. If an EU bank is within the scope of an EU regulation, the bank applies that regulation to the covered activity. If a U.S. correspondent is processing a transaction, that U.S. institution applies its OFAC obligations to its participation. If a UK entity is performing an activity within UK sanctions scope, UK rules govern that entity's conduct.
Participant obligations matter when another institution or employee in the chain has an independent duty. A non-U.S. originator may believe its own local law permits a payment, yet a U.S. correspondent cannot process it if OFAC prohibits the U.S. bank's participation. This can cause the payment to be rejected or blocked downstream even where the originator itself is not directly prohibited from all aspects of the underlying commercial activity.
Secondary or extraterritorial exposure is different again. Some U.S. authorities permit sanctions to be imposed on non-U.S. persons for specified conduct even where the conduct is not a primary OFAC violation by that foreign person. The correct analysis is programme-specific: identify the relevant authority, the sanctionable activity, materiality or significance tests where applicable, available exceptions or waivers, and the possible consequence. Do not rewrite secondary-sanctions exposure as if it were a direct transactional prohibition unless the law actually says so.
This distinction is important for customer communication and governance. "We are legally prohibited" is different from "our correspondent cannot process this," which is different again from "the activity creates secondary-sanctions exposure outside our risk appetite." Decision records should preserve that difference.
Extraterritorial exposure beyond direct applicability
A bank can face material sanctions risk even where direct primary jurisdiction does not prohibit the transaction. Secondary-sanctions authorities can threaten designation, correspondent restrictions or other consequences for specified conduct. Correspondent banks can restrict relationships with institutions whose activity creates sanctions risk. Market infrastructures, insurers, custodians and clearing partners can impose their own lawful risk standards. Group risk appetite can also be more conservative than the minimum legal position.
These effects must be governed deliberately. The bank should record whether a restriction is based on direct law, a partner's legal obligation, secondary-sanctions exposure, contractual conditions or internal risk appetite. Mixing these bases creates poor customer explanations and weak audit evidence.
Secondary-sanctions assessments should be tied to the actual authority. Some measures use concepts such as significant transactions, material assistance, sector participation or specified services. The bank should not invent a generic global threshold. Where the question is whether a foreign person could itself be designated or subjected to correspondent restrictions, sanctions legal counsel should own the interpretation and senior risk governance should own the resulting appetite decision.
Nexus-aware routing versus evasion
Banks and customers can legitimately consider cost, speed, currency, correspondent availability and legal complexity when choosing a transaction route. Reducing unnecessary operational exposure is not automatically sanctions evasion.
The risk changes where routing or structuring is used to evade or avoid an applicable prohibition, conceal a sanctions-relevant fact, cause a regulated person to process something it could not lawfully process with full information, or neutralise the effect of a sanctions rule. OFAC expressly warns that non-U.S. persons may not cause U.S. persons to violate U.S. sanctions or engage in evasion. EU sanctions regulations also contain anti-circumvention provisions in defined terms. The bank therefore examines purpose, transparency, timing, commercial rationale and the underlying activity rather than treating any non-dollar or alternative-correspondent route as suspicious by definition.
A good investigation asks: Was the route normal before the sanctions event? Did costs increase without commercial explanation? Were counterparties or instructions changed immediately after a designation? Did the customer conceal the destination or end user? Were payment legs fragmented so no institution could see the complete activity? Does the new structure preserve the same prohibited economic outcome? Those facts are stronger than the mere choice of a different currency.
Blocking statutes and conflicts of law
Multi-regime analysis becomes most difficult when one legal framework restricts compliance with another country's extraterritorial measures.
The EU Blocking Statute, Council Regulation (EC) No 2271/96, protects defined EU operators against the effects of specified extraterritorial third-country legislation listed in its Annex. It is not a general rule that permits ignoring all U.S. sanctions, nor does it convert every U.S. sanctions decision into an EU-law conflict. The organisation must identify whether the person is protected, whether the foreign measure is one of the listed instruments, whether the proposed conduct amounts to prohibited compliance, and whether an authorisation route is available.
The United Kingdom has its own post-Brexit Protection of Trading Interests framework. UK government guidance explains that the PTI legislation protects specified UK persons from the extraterritorial effect of defined U.S. sanctions relating to Iran and Cuba, prohibits certain direct and indirect compliance with those proscribed sanctions, creates notification requirements and allows authorisation in specified circumstances. This is a separate UK framework and should not be described simply as the EU Blocking Statute.
This is where the common phrase "apply the strictest regime" can fail. If regime A prohibits a transaction and regime B prohibits complying with specified extraterritorial measures of regime A, choosing the most restrictive answer does not solve the conflict. The bank needs a conflict-of-laws analysis, legal escalation, any available authorisation process, and a documented operating position. Group policy should make this an explicit exception to ordinary multi-regime combination logic.
The applicability sequence in practice
A defensible sanctions nexus assessment follows a repeatable sequence.
First, reconstruct the facts: customer and connected parties, ownership and control, booking entity, branch, employees and approvers, processing entities, service locations, payment currency, actual or expected clearing route, correspondents, goods or service content, origin, destination, end user and purpose. Distinguish known facts from assumptions and missing data.
Second, create the candidate regime set. A regime belongs in the candidate set because a legally relevant connection may exist, not because the country is politically important or the currency is commonly associated with that authority.
Third, test direct applicability separately for each candidate regime. Record the precise connection: person, entity, territory, business done in the jurisdiction, U.S. financial-system participation, goods or technology rule, or other programme-specific basis. If the question is novel or contested, obtain legal advice rather than turning policy shorthand into law.
Fourth, test the substantive measure under each applicable regime: asset freeze, prohibition on making funds available, sectoral restriction, service ban, investment restriction, goods restriction, reporting requirement, licensing condition or other rule. An identified nexus does not itself tell the bank which prohibition applies.
Fifth, assess permissions: exceptions, general licences, specific licences, derogations, wind-down provisions and transitional clauses. Permission analysis follows identification of the relevant restriction so that teams do not search for a licence before knowing what needs authorisation.
Sixth, examine secondary-sanctions exposure and partner constraints that remain outside direct applicability. Label them accurately rather than merging them into primary prohibition logic.
Seventh, check for conflict-of-laws or blocking-statute issues. In an ordinary multi-regime case with no conflict, the transaction can proceed only if it is permissible under every directly applicable legal requirement relevant to the bank's participation. Where laws conflict, legal escalation replaces simplistic "strictest rule" logic.
Finally, convert the legal position into the correct operational action: release, repair, hold for information, refuse or reject, freeze or block where an asset-freeze rule requires it, seek a licence, restrict a service, escalate the relationship, make required reports, or apply a documented risk-appetite decision. The action must match the legal basis. A transaction rejected because a service is prohibited should not be recorded as an asset freeze unless an applicable freeze obligation actually exists.
Data and systems: what a nexus engine really needs
Nexus analysis is often treated as a legal memo problem, but production quality depends on data design. The bank needs effective-dated entity data showing incorporation, branches and service roles; staff data where nationality or location is legitimately required for sanctions staffing controls; payment data showing currency and actual correspondents; customer and ownership data; product and service metadata; goods and trade information where the bank receives it; and decision evidence showing which rule version was applied.
The system should store a reason for applicability, not only a boolean result. Useful fields include candidateRegime, directApplicability, applicabilityBasis, relevantEntity, relevantPerson, territorialFact, clearingParticipant, secondaryExposure, conflictFlag, legalAdviceReference, authorisationReference, decision, decisionBasis and effective dates. This supports testing, audit and future re-performance when a regulator asks why a transaction was stopped two years earlier.
Rules must also distinguish hard legal gates from risk signals. A confirmed participating U.S. financial institution is a concrete fact. An expected dollar-clearing route can be a prediction needing confirmation. A customer changing from USD to another currency after a designation is a risk indicator, not automatic proof of evasion. Architecture that stores all three as one nexus=true field prevents analysts from seeing the difference.
Change management matters because jurisdiction rules and programme measures evolve. Legal interpretations, sanctions regulations, general licences, competent-authority guidance and partner requirements need effective dates and controlled deployment. Regression tests should include previously permitted and previously restricted scenarios so that a policy update does not silently widen or narrow applicability beyond the approved interpretation.
Facilitation self-assessment: is the bank's own conduct restricted?
The final lens turns the analysis onto the bank's service. Even if the customer is not itself prohibited from every aspect of the underlying activity, can the bank lawfully finance, approve, guarantee, process or otherwise support it under the rules applicable to the bank and its staff?
OFAC guidance makes this concrete for U.S. persons: U.S. persons may not approve, finance, facilitate or guarantee a foreign person's transaction where that transaction would be prohibited if performed by a U.S. person or within the United States, subject to programme-specific rules and authorisations. The bank therefore tests its own conduct, not only the customer's status.
The same analytical principle applies more broadly: identify the exact service the bank provides and test the relevant regime's service prohibition, facilitation rule, anti-circumvention rule or other restriction. Do not import the U.S. word "facilitation" into every jurisdiction as if it had identical legal meaning. Use the terminology and legal test of the applicable regime.
Knowledge and intent standards also differ. Some rules require knowing and intentional participation in circumvention; other prohibitions can operate without a comparable intent element. Controls must preserve the facts supporting the correct standard rather than applying one global "knew or should have known" threshold to every programme.
The practical conclusion is simple but demanding: build the complete footprint, identify the legal connection, test each regime on its own terms, separate direct law from secondary exposure, and make the operational disposition match the actual legal basis. That is the difference between a screening-centric sanctions process and a defensible bank-wide sanctions jurisdiction framework.
Operational deep dive: nexus-analysis methodology by transaction type
The base chapter established the nexus dimensions. This deep dive provides the assessment methodology for each major transaction type, with the evidence each analysis requires and the documentation standard supporting dispositions under multi-authority scrutiny.
Payment-nexus assessment method
Payment applicability analysis reconstructs the full transaction footprint before testing regimes: originator and beneficiary identity with ownership and control where thresholds indicate, intermediary and correspondent chain with clearing-path identification, currency and clearing-system routing, goods or purpose content from remittance and reference data, and booking entities at each processing stage. Each footprint element maps to nexus dimensions systematically: parties to persons and designation analysis, clearing path to currency-nexus assessment, goods content to goods-nexus evaluation, booking entities to territorial and persons applicability. The method prevents the characteristic payment error of screening parties while ignoring the clearing path that independently engages regimes.
Evidence standards require the footprint to be evidenced rather than assumed: clearing-path confirmation from payment-system data rather than currency-based assumption, intermediary identification from message records rather than correspondent-relationship guesswork, and goods-content assessment from actual remittance data rather than customer-profile inference. Where footprint elements are unavailable, the analysis records the gap with its implication: unknown clearing paths for USD-denominated flows cannot be assumed nexus-free, and the disposition must reflect the uncertainty through enhanced inquiry or protective treatment rather than hopeful processing.
Trade-transaction nexus method
Trade applicability compounds payment analysis with goods, document and logistics dimensions: goods classification with origin determination, destination and end-user verification, transport routing with transhipment analysis, document-party mapping across commercial, transport and financial documents, and service-channel identification for financing, insurance and logistics. Each dimension tests regime applicability independently before combining: goods origin engages export-control jurisdiction, destination engages import and activity prohibitions, routing engages transhipment-jurisdiction considerations, and service channels engage service-prohibition scope per participating jurisdiction.
Document-party divergence analysis addresses the characteristic trade complexity where commercial, transport and financial documents name different parties legitimately: applicant versus importer, beneficiary versus exporter, notified parties, carriers and insurers each occupy distinct roles with separate nexus implications. The method maps every named party to nexus assessment rather than screening only the financial counterparties, since restriction-relevant parties frequently appear in transport and commercial documents invisible to payment screening. Divergence itself carries information: document sets with inconsistent party, goods or routing information indicate error or deception requiring resolution before applicability assessment can complete reliably.
Customer-relationship nexus method
Relationship-level applicability establishes the standing regime footprint within which transactions are assessed: customer persons status across relevant frameworks, ownership and control with designated-person proximity, geographic footprint of operations and counterparties, sectoral exposure to restricted industries, and historical activity patterns indicating nexus dimensions the relationship routinely engages. The relationship assessment produces the applicability baseline that transaction analysis refines: customers with US persons status, sanctioned-corridor activity or restricted-sector operations carry standing multi-regime considerations that every significant transaction revisits rather than re-derives.
Change-driven reassessment triggers keep relationship nexus current: ownership restructuring, geographic expansion, sector pivots, new product adoption and designation events affecting connected persons each trigger defined review with scope proportionate to the change. Periodic validation confirms the baseline against observed activity with divergence investigation where transaction patterns suggest unrecorded nexus dimensions. The relationship-transaction nexus connection must flow both directions: relationship assessment informs transaction scoping, while transaction findings update relationship understanding, preventing the staleness where onboarding-time nexus analysis governs evolved relationships indefinitely.
The diagram above shows the evidence chain from footprint reconstruction through per-dimension testing to combined disposition with documentation. Its message is that applicability conclusions are only as reliable as the footprint beneath them, and investment in footprint completeness, clearing-path data, goods content, relationship mapping, outperforms investment in analytical sophistication built on partial information.
Subsidiary and branch nexus mapping
Group nexus mapping inventories every entity's persons obligations, territorial footprint, processing roles and customer base with regime applicability per entity-activity combination rather than group-level generalisation. Shared-service and processing-hub analysis determines which entities touch transactions during centralised processing and what applicability each touch creates: a payment booked in Singapore, processed on a UK platform, cleared in dollars through New York engages Singapore, UK and US analysis at different processing stages with different questions. Platform-governance must encode multi-entity applicability rather than assuming booking-entity regimes govern exclusively.
Booking-model decisions carry nexus consequences that business planning should assess explicitly: booking sanctioned-corridor business in entities with broader persons obligations expands applicable regimes without commercial benefit, while booking complexity designed for tax or regulatory optimisation may inadvertently multiply sanctions applicability. New-entity establishment, branch licensing and processing-migration decisions each warrant nexus-impact assessment with sanctions-legal input before implementation rather than post-implementation discovery of expanded exposure. Entity-rationalisation programmes should evaluate nexus simplification alongside cost benefits, since fewer entities in fewer jurisdictions with clearer processing allocation reduces applicability complexity structurally.
Documentation standards for nexus decisions
Nexus-analysis documentation must support dispositions under scrutiny from any connected authority, requiring standards beyond internal-consistency memo writing. Decision records identify every regime considered with applicability conclusion and basis, the footprint evidence supporting dimension analysis with source citations, legal input obtained for boundary questions with advice references, the combined disposition reasoning showing how multi-regime assessment produced the outcome, and review and approval per the decision's consequence level. Standard templates for recurring patterns ensure consistency while preserving analytical depth for novel questions that templates cannot contain.
Record-retention for nexus analysis follows the longest applicable obligation across connected regimes with legal-hold extension where investigation or proceedings arise. Retrieval capability must support authority inquiry years after decisions: footprint reconstruction from retained payment, trade and customer records; list-version and programme-status evidence for the decision date; and the analytical reasoning connecting evidence to disposition. Authorities examining multi-regime decisions test precisely the dimensions banks most often neglect, clearing-path analysis, goods-nexus evaluation, subsidiary-touch assessment, and documentation demonstrating dimension-complete analysis provides the examination defence that partial records cannot.
Practitioner checkpoint
A practitioner finishing this deep dive should be able to reconstruct transaction footprints evidencing every nexus dimension, apply payment, trade and relationship assessment methods with appropriate evidence standards, map subsidiary and branch nexus across group processing chains, and document multi-regime decisions to authority-scrutiny standards. Shortfalls in any method indicate capability gaps needing owned remediation rather than accepted analytical limitations.
Correspondent questionnaire design for nexus transparency
Respondent-bank questionnaires provide the primary transparency mechanism for nested-nexus assessment, and their design determines whether responses support genuine analysis or decorative assurance. Effective questionnaires probe settlement-chain disclosure beyond direct respondent activity: downstream institutions served, multi-correspondent routing structures, dollar-settlement arrangements for non-dollar flows, and the respondent's own visibility into underlying originators. Control-capability questions test screening scope across customer, payment and trade populations, list-update latency with evidence, matching-threshold governance, and investigation quality through case-example review. Change-notification commitments secure ongoing transparency: new downstream relationships, routing-structure modifications, volume-profile shifts and incident disclosures each trigger defined notification with timeframes.
Response validation distinguishes substantive transparency from formalistic completion: expansive narrative answers with supporting evidence indicate control maturity, while minimal tick-box responses with generic policy attachments indicate compliance theatre warranting enhanced verification. On-site and virtual reviews test questionnaire claims against operational reality for material respondents, examining screening configurations, sampling investigation files and interviewing control staff rather than accepting documentation at face value. Questionnaire-performance tracking measures the correlation between response quality and subsequent incident experience, refining question design toward the disclosures that actually predict control effectiveness and retiring questions that consume effort without discriminating value.
Sanctions-clause drafting in commercial contracts
Loan agreements, trade contracts, insurance policies and service agreements allocate sanctions risk between parties through representations, undertakings, mandatory-prepayment triggers, illegality clauses and force-majeure provisions whose drafting quality determines outcomes when programmes change mid-transaction. Representations establish the sanctions baseline each party asserts: non-designated status, compliance with applicable measures, and disclosure of sanction-adjacent exposures, with repetition mechanics keeping representations current rather than freezing them at signing. Undertakings impose ongoing compliance obligations with breach consequences, while information undertakings secure the transparency enabling monitoring: ownership-change notification, activity-reporting requirements and audit rights proportionate to the exposure.
Mandatory-prepayment and termination triggers convert sanctions events into contractual consequences automatically: designation of relevant parties, enactment of prohibiting measures, or loss of licensing coverage each activate defined repayment, termination or suspension mechanics with timelines. Illegality clauses address performance that sanctions render unlawful, distinguishing temporary suspension with resumption mechanics from permanent termination with settlement provisions. The bank's template documentation needs sanctions provisions reflecting current programme scope with legal maintenance as frameworks evolve, and transaction-specific negotiation should strengthen protections for sanction-adjacent business rather than accepting borrower templates that allocate all sanctions risk to the lender's forbearance.
Legitimate nexus-aware routing design
Banks and customers legitimately structure transaction routing considering jurisdictional implications alongside cost, speed and reliability: selecting clearing currencies and correspondents, booking locations and processing arrangements that minimise unnecessary sanctions complexity for lawful business. Legitimate optimisation differs fundamentally from evasion-motivated nexus avoidance in purpose, transparency and substance: optimisation pursues efficiency for lawful activity with fully disclosed routing, while evasion restructures to conceal restriction-relevant connections from control functions and authorities. The distinction turns on disclosure and commercial logic rather than routing mechanics alone, since identical routings serve either purpose depending on intent and transparency.
Control design must permit legitimate optimisation while detecting evasion structuring through purpose analysis: routing choices with clear commercial rationale documented contemporaneously, disclosed fully to compliance functions and correspondents, and consistent with the customer's established patterns indicate optimisation. Routing changes coinciding with designation events, programme expansions or enhanced scrutiny, structures adding cost and complexity without commercial benefit, and non-disclosure of routing rationale to relevant control functions indicate evasion awareness requiring investigation. Staff guidance should articulate the distinction with concrete examples preventing both the over-blocking of legitimate routing efficiency and the tolerance of evasion structuring disguised as optimisation.
Benchmarking applicability decisions against peers and authorities
Applicability analysis quality is difficult to self-assess because errors manifest as violations or over-restriction rather than measurable defects, making external benchmarking essential. Industry-forum typology exchange provides anonymised nexus-decision case studies revealing how peers assess equivalent dimension combinations, exposing systematic under- or over-assessment in the bank's own practice. Supervisory guidance and enforcement actions supply authoritative calibration: penalty decisions describe the nexus analysis failures regulators punish, examination reports identify industry-wide scoping weaknesses, and thematic-review findings benchmark the bank against sector practice. Legal-adviser benchmarking across client institutions, shared within privilege constraints, reveals interpretation divergence on boundary questions where the bank's position may be outlier-aggressive or outlier-conservative.
Internal benchmarking complements external sources: inter-entity comparison of identical transaction-type assessments reveals framework ambiguity or training gaps where booking centres diverge, decision-overturn analysis identifies the nexus dimensions most frequently misassessed, and legal-challenge outcomes test analytical positions against adversarial scrutiny. Benchmarking results feed framework revision, training priorities and standing-position updates with tracked implementation rather than accumulating as intelligence reports without operational consequence. The objective is calibrated analysis positioned deliberately within the defensible range rather than accidentally at its edges through unexamined habit.
Developing nexus analysts: competence beyond checklists
Nexus analysis demands integrative judgement across legal regimes, transaction mechanics and commercial reality that checklist procedures support but cannot replace, requiring deliberate analyst development beyond process training. Foundational development builds regime literacy sufficient to recognise applicability questions across major frameworks without practising law: programme-structure understanding, nexus-dimension awareness and escalation judgement distinguishing routine scoping from boundary questions needing legal input. Intermediate development adds transaction-mechanics fluency: payment-system routing, trade-document parties, corporate-structure reading and processing-chain analysis enabling footprint reconstruction from primary records rather than summary descriptions.
Advanced development cultivates the multi-regime reasoning this chapter teaches through supervised casework on genuine complexity: analysts draft applicability assessments reviewed by specialists with feedback addressing reasoning quality rather than merely correcting conclusions, progressing from single-regime cases through multi-regime routine patterns to novel conflicts requiring original analysis. Legal-interface skills form a distinct competency: framing precise questions for legal advisers with complete footprints and identified options, interpreting advice into operational decisions without overstepping into legal practice, and recognising when changed facts invalidate prior advice. Career pathways should retain developed nexus expertise through specialist recognition and progression rather than treating sanctions analysis as rotational generalist work, since the judgement this chapter demands compounds with experience while checklists alone never mature into wisdom.
Advanced practice: worked nexus cases
The cases below are entirely fictional with illustrative amounts. Each demonstrates nexus analysis where single-dimension assessment would mislead: the footprint, dimension-by-dimension testing, alternatives weighed, outcome with reasoning, and control lesson. Real cases turn on actual measure wording and legal advice.
The decision tree above structures every case: inventory dimensions completely, test each connected regime independently, identify an outcome that satisfies every applicable law, and document to multi-authority standards. Escalate conflicting obligations, including applicable blocking statutes, rather than assuming that the strictest restriction is automatically lawful. Refer back to it as each case proceeds.
Case 1: the dollar payment nobody's regime clearly governs
A Singapore corporate customer instructs a US-dollar payment of an illustrative 2.3 million to a Middle Eastern supplier for industrial equipment, routed through the bank's Singapore booking with USD clearing through New York. Neither party is designated, the goods are unclassified industrial equipment, and the destination is not comprehensively sanctioned. The payments team proposes routine processing; a sanctions-aware reviewer asks for nexus assessment before release.
Footprint reconstruction establishes the dimensions: Singapore persons jurisdiction for the booking entity with Singapore-implemented UN measures applicable; euro-denominated? No, dollar-denominated clearing through New York engaging US analysis for the cleared activity; goods with potential dual-use characteristics requiring classification assessment; destination with sectoral measures affecting defined industries; and a supplier ownership structure showing a minority stakeholder connected to a designated person's business network without meeting ownership thresholds. Each dimension is individually benign or borderline; combined assessment tells a different story.
Regime testing proceeds independently. Singapore-framework analysis confirms UN-implemented measures do not prohibit the transaction but requires the standard screening and reporting posture. US-nexus analysis examines whether the cleared activity constitutes facilitation of concern: goods classification review finds threshold-proximate specifications, end-user verification reveals the supplier's customer base including restricted-programme-adjacent entities, and the minority-stakeholder connection warrants control-indicator assessment. EU-nexus analysis applies through the bank's EU processing infrastructure touching the payment during centralised screening, engaging EU dual-use and sectoral provisions for the goods-destination combination. In this fictional case the combined assessment identifies licensing requirements under one framework and enhanced end-use verification needs under another, converting routine processing into conditioned handling with documented multi-regime reasoning.
The lesson is that nexus complexity concentrates precisely in transactions designed to look routine: clean parties, ordinary goods descriptions, standard corridors. Dimension-complete assessment is the only defence against confident single-dimension clearance, and the USD-clearing plus EU-processing plus threshold-proximate-goods combination demonstrates why footprint reconstruction must precede disposition rather than following alert generation.
Case 2: the subsidiary caught between regimes
A European banking group's Middle Eastern subsidiary maintains accounts for trading companies active in a jurisdiction subject to comprehensive US sanctions but more targeted EU measures. The subsidiary, organised locally with no US persons status, processes local-currency and euro-denominated business with no US clearing touch. US secondary-sanctions provisions target the trading sector concerned, while EU measures permit defined trade categories with licensing. The subsidiary's management seeks group guidance: local law permits the business, EU measures conditionally permit it, and US secondary sanctions create designation risk for sanctionable activity without directly prohibiting the subsidiary's conduct.
The analysis separates legal permissibility from risk appetite explicitly. Direct-applicability assessment confirms the subsidiary's activities fall outside US persons jurisdiction and clearing nexus, and within EU-permitted categories subject to licensing conditions. Secondary-sanctions proximity assessment examines the trading sector, transaction values and activity character against sanctionable-activity definitions, finding material proximity given the sector's explicit targeting. Facilitation assessment addresses the group's broader exposure: correspondent banks processing related flows, US-person employees in group functions supporting the business, dollar-denominated ancillary transactions, and the parent's own secondary-sanctions risk through ownership of the facilitating subsidiary.
The outcome reflects the distinction between what is lawful and what the group accepts: senior-approved risk-appetite determination restricting the subsidiary's sanctionable-sector business despite its technical permissibility, with the reasoning documented as risk-based rather than legally compelled. Implementation includes customer communication explaining service limitations without disclosing sanctions-strategy detail, staff briefing on the boundary between permitted and restricted activity within the subsidiary's portfolio, and monitoring ensuring the restriction holds in practice rather than decaying through front-office exception. The lesson is that extraterritorial exposure management is fundamentally a risk-appetite discipline operating beyond direct applicability: the analysis must be as rigorous as legal assessment while owned as business decision with senior accountability.
Case 3: the correspondent chain with hidden US touch
A respondent bank in an Asian jurisdiction sends euro-denominated payments through its European correspondent for textiles trade with Central Asian counterparties. Routine screening clears parties and goods. A correspondent-review update reveals the respondent routes underlying dollar-settlement legs for the same commercial flows through a separate US correspondent, meaning the commercial activity the European bank supports through euro clearing connects to USD settlement chains engaging US analysis. The respondent has not disclosed this structure, and its payment narratives describe the euro flows as standalone transactions.
The investigation treats the undisclosed settlement structure as the central finding rather than a technical footnote. Nexus analysis must assess commercial activity holistically rather than per-message: euro clearing supporting trade settled in dollars through US systems creates indirect US-nexus exposure for the activity the correspondent facilitates, and deliberately fragmented settlement structuring to isolate nexus dimensions indicates evasion awareness. Information requests to the respondent demand full settlement-chain disclosure with deadlines, while internal analysis reconstructs the commercial flows joining euro and dollar legs through amount, timing and counterparty correlation.
In this fictional case the respondent's disclosure reveals systematic nexus fragmentation across its correspondent network, with different legs routed to avoid any single correspondent seeing the complete sanctions picture. The correspondent's response addresses the relationship rather than individual transactions: enhanced transparency requirements with contractual force, nested-flow monitoring joining multi-correspondent activity, volume tolerances reflecting the assessed opacity, and exit preparation where transparency cannot be secured. Reporting captures the evasion-structured settlement design alongside any underlying restriction findings. The lesson is that nexus assessment must follow commercial activity across message and institution boundaries: per-message nexus analysis of deliberately fragmented flows validates the fragmentation strategy rather than controlling the underlying activity.
Case 4: the employee whose passport changes the answer
A trade-finance team structures a complex transaction involving sanctioned-corridor goods eligible for humanitarian licensing: licence applications prepared, conditions understood, processing procedures defined. Two days before execution, staffing review reveals the designated deal team includes a US-person secondee whose involvement in the transaction's structuring and approval would engage US persons-jurisdiction obligations independent of the transaction's other nexus dimensions. The humanitarian licence framework differs between the applicable regimes, with the US authorisation narrower in scope than the European permission the team obtained.
The case demonstrates persons-nexus as the dimension most easily overlooked in entity-focused analysis. Resolution requires restructuring team involvement to remove the US-person touch from restricted-activity decisions, reassessing the transaction under US requirements for any remaining US-nexus elements, and securing the narrower US authorisation alongside the European permission before proceeding. The transaction executes three weeks later than planned with both authorisations in place and restructured staffing, demonstrating that persons-nexus management costs time but prevents violations that entity analysis alone would miss.
The control lesson is systematic: staffing controls for sanctioned-corridor and restricted-activity business must identify persons-jurisdiction implications at deal inception with HR-data integration supporting the assessment, rather than discovering secondee nationalities days before execution. Deal checklists should include persons-nexus review alongside entity, currency and goods analysis as a standard dimension, with compliance authority to restructure staffing overriding commercial team preferences where obligations require. Post-incident review in this fictional case produces the persons-nexus procedure the bank should have owned before the transaction taught its necessity.
Case 5: the blocking-statute conflict with live transaction
A European corporate customer instructs its bank to refuse Cuba-related business from a long-standing commercial partner, citing US secondary-sanctions risk to its dollar business. The bank's assessment finds the activity lawful under EU measures and covered by no EU prohibition, while the EU Blocking Statute addresses compliance with the specified foreign sanctions extraterritorial application. The customer demands the bank implement Cuba-exclusion screening across its accounts; the bank must navigate between customer instruction, blocking-statute constraints on compliance with targeted foreign measures, and its own US-nexus risk management for dollar-clearing activity.
The analysis separates the strands methodically. The customer's instruction is assessed as commercial risk management the customer may adopt for its own business within legal bounds. The bank's own implementation of Cuba-exclusion screening at the customer's direction requires blocking-statute analysis: implementing customer-directed foreign-sanctions compliance may itself engage the statute's prohibitions depending on scope and mechanism, requiring legal advice and potential authorisation procedures. The bank's dollar-clearing treatment of Cuba-connected flows follows its own US-nexus assessment independently of the customer's preferences, with transparent communication distinguishing the bank's clearing decisions from the customer's business decisions.
Resolution implements a three-part position: customer-directed screening implemented within blocking-statute-compliant boundaries defined by legal advice with authorisation sought where required; dollar-clearing treatment governed by the bank's own nexus assessment with clear customer communication about USD-service scope; and documentation separating each decision strand with its legal basis to withstand scrutiny from any direction. The lesson is that blocking-statute conflicts require strand-by-strand analysis rather than binary compliance-or-defiance framing: customer autonomy, statutory prohibition and institutional risk management each operate in their own lane, and lawful operation means respecting all three simultaneously through precise legal engineering rather than choosing sides.
Case 6: energy payments through layered European structures
A European bank's energy desk processes euro-denominated payments for natural-gas transportation services involving a supply chain touching Russian-origin molecules, Central Asian transit infrastructure, and European utility buyers. No party is designated, euros clear within European systems without US touch, and the services fall outside explicitly prohibited categories under a narrow reading. The desk head argues the business is plainly permissible; the sanctions advisory function insists on full nexus assessment before continuing a portfolio worth an illustrative 40 million annually.
Footprint reconstruction reveals dimensions the narrow reading misses. Goods-origin analysis traces the gas molecules through blended pipeline flows where Russian-origin volumes mix with Central Asian supply, raising origin-attribution questions for import-ban purposes that volumetric accounting must address rather than assume away. Service-scope analysis tests transportation, balancing, storage and financing services against sectoral energy provisions whose activity definitions capture more than headline prohibitions suggest. Counterparty analysis maps the transit operators, shippers and intermediaries with ownership tracing revealing state-connected entities below designation thresholds but within control-indicator relevance. US-nexus analysis examines dollar-denominated ancillary flows, insurance placements and the bank's own US operations' tangential involvement, while secondary-sanctions proximity assessment tests the energy-sector activity against sanctionable definitions.
Regime testing produces the differentiated outcome narrow reading would miss: EU analysis identifies authorisation requirements for defined service categories with licensing conditions the desk had never sought, operating for months on the assumption that non-prohibited meant permission-free. US analysis finds no direct prohibition on the euro-cleared core flows but identifies facilitation-adjacent exposure in dollar-denominated ancillary services requiring restructuring. Secondary-sanctions proximity sits at moderate levels warranting senior risk-appetite review rather than automatic exit. In this fictional case the outcome combines licence applications with backdated-exposure assessment and voluntary engagement with authorities on the historical gap, ancillary-service restructuring removing US-nexus touches, enhanced energy-desk procedures with service-scope screening, and senior-approved appetite positioning for the continued business with monitoring conditions.
The lesson is that sectoral-energy business with sanctioned-origin adjacency demands the full nexus machinery regardless of its routine commercial appearance: origin attribution for blended flows, service-scope analysis beyond headline prohibitions, counterparty control-indicator assessment below designation thresholds, and multi-regime licensing review. Desks generating material revenue from sanction-adjacent business need embedded nexus assessment with advisory authority to stop flows, not advisory opinions desks may discount when revenue is at stake.
Case 7: the acquisition target with a sanctioned joint venture
A corporate-finance team advises a European conglomerate acquiring a Middle Eastern industrial group with operations spanning six countries, significant government contracts, and a joint venture with a state-owned enterprise of a comprehensively sanctioned jurisdiction. The acquisition valuation assumes uninterrupted operations including the joint venture's cash flows. Financial-crime due diligence, commissioned late in the transaction timetable under deal-pressure constraints, must assess sanctions exposure sufficient to inform valuation, deal structure and completion decisions within three weeks.
Nexus assessment maps the target's regime footprint comprehensively: operating jurisdictions with programme analysis per territory, customer and supplier networks with designation and sectoral screening, the sanctioned-jurisdiction joint venture with activity-scope and value-flow analysis, dollar-clearing dependencies in the target's treasury operations, US-person employees in management, and technology inputs with origin-based control considerations. The joint-venture analysis proves decisive: the venture operates in a sector subject to comprehensive restrictions, cash repatriation flows through dollar clearing, and the venture partner's state ownership engages multiple programme dimensions simultaneously. Continued post-acquisition operation would expose the acquirer to primary violations through its ownership, while immediate divestiture faces contractual lock-in provisions and host-government approval requirements measured in months.
The advisory response structures the deal around the sanctions reality rather than the valuation assumption: purchase-price adjustment reflecting the joint venture's impaired value and exit costs, completion conditions requiring defined sanctions-remediation milestones, warranty and indemnity architecture allocating sanctions risk with survival periods matching enforcement limitation horizons, and integration planning sequencing joint-venture exit before operational combination. In this fictional case the acquirer proceeds at a reduced valuation with the sanctions workstream elevated to deal-critical status, demonstrating that late-stage diligence, while suboptimal, still prevents value destruction that undiscovered exposure would guarantee. The control lesson for banks financing acquisitions is equivalent: leveraged-finance and advisory businesses need sanctions-diligence standards with timetable protection ensuring assessment completes before commitment, since deal pressure systematically compresses exactly the analysis most needed for sanction-adjacent targets.
Case 8: virtual-asset nexus without borders
The digital-asset customer investigation concludes with relationship conditions rather than immediate exit, providing the monitored-remediation model this case contributes. Enhanced requirements include real-time blockchain monitoring with exposure thresholds triggering automatic review, counterparty-allowance frameworks restricting on-chain activity to verified-cleantexposure profiles, and monthly analytics reporting reviewed by the sanctions advisory function with trajectory assessment. These conditions test whether the customer's business model can operate within acceptable exposure: compliant adaptation validates the conditional approach while continued high-risk exposure triggers the prepared exit with documented reasoning. The remediation period also builds the bank's virtual-asset nexus methodology through live-fire calibration that policy drafting alone cannot provide.
Case 9: reinsurance retrocession with sanctioned-origin exposure
A European insurer client's reinsurance programme cedes property-catastrophe risk through a London broker to a retrocession chain spanning Bermuda, Singapore and Middle Eastern reinsurers. A sanctions review triggered by the Middle Eastern participant's ownership update reveals a minority state-connected shareholding from a comprehensively sanctioned jurisdiction, held through two intermediate holding companies with the connection emerging only at the third ownership layer. Premium flows of an illustrative 12 million annually traverse the chain, with claims-paying capacity depending on each participant's performance.
Nexus assessment maps the insurance-chain dimensions methodically: participant persons-status across underwriting jurisdictions, premium-flow clearing paths with currency analysis, the sanctioned-connection's ownership percentage with aggregation assessment under applicable regimes, and control-indicator evaluation for the state-connected minority interest. Regime testing finds the ownership below blocking thresholds on arithmetic while control indicators around board representation and strategic-direction rights require legal assessment for the control limb. Service-provision analysis examines whether premium payment and claims cooperation constitute prohibited services to the connected entity under applicable programmes, with retrocession-chain layering assessed for sanctions significance rather than treated as diluting the connection.
In this fictional case legal assessment concludes the connection falls below applicable restriction thresholds with conditions: enhanced monitoring of ownership changes with defined triggers for reassessment, claims-cooperation protocols ensuring any future claims interaction receives pre-execution review, and renewal underwriting conditional on updated ownership verification. The outcome demonstrates proportionate handling where analysis disproves prohibition while respecting the proximity: the business continues under monitored conditions rather than exiting on association alone or proceeding without safeguards. The lesson is that insurance-chain nexus demands ownership-depth analysis matching the banking standards applied to corporate customers, since reinsurance opacity otherwise shelters sanctioned connections behind layers the direct-participant screening never penetrates.
A digital-asset customer, a trading firm licensed in its home jurisdiction, processes substantial stablecoin flows through its corporate accounts: fiat deposits converted to stablecoins via regulated exchanges, on-chain transfers to counterparties globally, and reconversion to fiat for supplier payments. Blockchain analytics commissioned during periodic review reveals counterparty exposure to high-risk categories: mixing-service interaction within two hops of received funds, counterparties in comprehensively sanctioned jurisdictions, and transaction patterns consistent with over-the-counter brokerage serving undisclosed principals. The customer asserts that on-chain activity lies outside the bank's responsibility since the bank handles only fiat legs with regulated exchanges.
The nexus analysis rejects the fiat-only boundary comprehensively. Funds-transfer recordkeeping and sanctions obligations attach to the value the bank moves regardless of the customer's on-chain activity characterisation: fiat deposits funding sanctionable on-chain destinations and fiat withdrawals realising sanctionable on-chain proceeds each engage the bank's frameworks through the fiat legs it processes. Blockchain analytics provides the footprint evidence traditional payment records cannot: counterparty attribution, jurisdictional exposure and typology indicators that transform apparently clean exchange transfers into assessed sanctions risk. The customer's licensing status addresses its regulatory standing, not the sanctions character of its flows, and regulated-exchange intermediation does not cleanse sanctionable underlying activity any more than correspondent banking cleanses sanctionable trade.
In this fictional case the analytics support material sanctionable exposure through jurisdictionally prohibited counterparties and mixing-obscured provenance, triggering enhanced due-diligence requirements with blockchain-monitoring conditions, restriction of fiat services connected to high-risk on-chain activity, reporting under applicable frameworks, and relationship review with exit preparation where the customer's business model depends structurally on exposure the bank cannot accept. The lesson is that virtual-asset nexus follows value across the fiat-crypto boundary in both directions: banks cannot outsource sanctions responsibility to exchanges any more than to correspondents, and blockchain analytics belongs in the standard nexus toolkit for virtual-asset-touching customers rather than specialist exotic capability invoked after incidents.
Practice close: the nexus analyst's playbook
This section serves the analyst, adviser and relationship manager confronting multi-regime questions with commercial deadlines. It compresses nexus analysis into usable sequences, then examines the exceptions and failure modes defining difficult jurisdictional judgement.
The applicability-assessment sequence
Treat every multi-regime question as a footprint problem first. The opening phase inventories dimensions completely before testing any regime: parties with ownership and control, employee and staffing involvement, booking and processing entities with platform-touch analysis, currency with clearing-path confirmation, goods with classification and origin, destination with end-user assessment, service channels with provider and location mapping, and activity territory with digital-delivery considerations. Dimension checklists per transaction type prevent the characteristic omission of clearing paths, staffing touches and processing-entity involvement that entity-and-party-focused assessment misses. Footprint gaps are recorded explicitly with implication assessment rather than silently assumed benign.
Regime testing follows footprint completion with legal input for boundary questions secured before disposition rather than after challenge. Each candidate regime is tested first for direct applicability and then for the specific restriction, permission or reporting duty relevant to the activity. In an ordinary case with no conflict of laws, processing can continue only if the bank's participation is lawful under every directly applicable requirement. Where one legal framework restricts compliance with specified foreign extraterritorial measures, the case moves to conflict-of-laws analysis and any available authorisation process rather than a simplistic "strictest rule wins" shortcut. Documentation captures dimension evidence, applicability reasoning per regime, legal advice references and the final disposition logic with approvals proportionate to consequence. Time-critical transactions follow expedited variants with pre-agreed protective treatment rather than hopeful processing while material facts remain unresolved.
Exceptions that change the playbook
Pre-existing activity predating programme changes creates grandfathering and wind-down questions distinct from new-business assessment: contracts concluded before designation, shipments in transit at effective time, payments in flight across implementation, and facilities drawn before restriction each require transitional analysis under the programme's specific provisions rather than uniform new-activity treatment. Transitional provisions vary by programme in scope, duration and conditions, demanding programme-specific assessment with legal input rather than generic grace-period assumption. Systems must distinguish pre-existing from new activity through effective-dated records, since transitional treatment depends entirely on timing evidence.
Diplomatic, official and international-organisation activity engages privileges and licensing frameworks modifying standard applicability without removing it: mission transactions proceed under applicable exemptions with verification of official character, while personal transactions of mission personnel receive standard assessment without diplomatic deference. Humanitarian activity routes through exemption and licensing channels with specialist handling preserving legitimate flows while maintaining control integrity. Each exception category needs defined identification, verification and processing procedures preventing both over-blocking of protected activity and evasion through exception claims, with staff trained to recognise exception indicators and escalate for specialist determination rather than deciding privilege and humanitarian questions at frontline level.
Customer communication on jurisdictional decisions
Multi-regime refusals and restrictions create difficult customer conversations because explanations referencing foreign regimes can confuse customers expecting domestic-law reasoning, while over-disclosure can reveal control logic or create avoidable legal risk. Communication discipline provides clear outcome statements with actionable next steps, licensing-path guidance where permissions could authorise future activity, and decision-maker contacts, without disclosing confidential intelligence or investigative methodology.
The reason for the outcome should be described accurately inside the bank even if external wording is necessarily concise. A direct legal prohibition, a correspondent's legal restriction, secondary-sanctions exposure, a conflict-of-laws issue and an internal risk-appetite decision are different bases. Conflating them makes complaints harder to resolve and weakens later audit evidence.
Front-office preparation precedes customer contact with briefing on permitted and prohibited discussion content, escalation paths for customer pressure and complaint scenarios, and documentation requirements for communication records. Disputed jurisdictional determinations need defined resolution mechanics: independent legal review with customer right to submit contrary analysis where appropriate, reasonable timeframes, and written determinations explaining conclusions sufficiently for understanding without compromising sensitive methodology.
Failure scenarios and control improvement
Review nexus analysis against six failures. Clearing-path blindness processes a payment using a currency assumption without confirming participating institutions; the remedy is route data and correspondent reconstruction. Staffing-touch blindness structures restricted activity without considering the obligations of employees, approvers or board members; the remedy is persons-jurisdiction controls with appropriate HR support. Processing-entity blindness assumes the booking entity is the only relevant bank entity; the remedy is service-chain mapping. Fragmentation blindness assesses message legs rather than the underlying commercial activity; the remedy is case-level correlation. Permission-first reasoning searches for licences before identifying the restriction that needs authorisation; the remedy is sequence-disciplined procedures. Stale standing positions apply old legal scope to evolved programmes, routes or business models; the remedy is effective-dated legal positions with change-triggered reassessment.
Each failure needs owned remediation with measurable verification rather than acknowledgment without action. The control objective is not to maximise the number of regimes attached to each payment. It is to ensure that material legal connections are neither missed nor invented.
Tester and data-analyst view
Testers validating nexus analysis need scenario packs spanning dimension combinations rather than single-regime cases: multi-currency routed transactions, subsidiary-staffed deals, fragmented settlement structures, blocking-statute conflicts and transitional-timing cases each test different analytical muscles. Expected results derive from approved legal and policy positions rather than current system behaviour, with regression execution after programme changes, platform migrations and procedure revisions.
Testing should include negative cases designed to prove that currency or infrastructure facts do not automatically become jurisdictional conclusions. A euro-denominated payment outside EU jurisdiction should not be labelled prohibited merely because the currency is EUR. A USD-denominated instruction that never enters the U.S. financial system should not be treated automatically as a U.S.-clearing event. Conversely, a non-USD commercial flow that nevertheless involves a U.S. person or U.S.-located service can still require U.S. analysis. These tests catch shorthand rules that create both false negatives and false positives.
Data analysts monitor footprint-completeness rates by dimension and channel, applicability-assessment timeliness against service standards, disposition-implementation verification across processing systems, and typology-detection performance for nexus-evasion patterns. Metrics should separate missing facts from genuinely absent nexus. A field recorded as unknown must not be silently converted to false in downstream reporting.
Pre-transaction nexus checklists by product
Front-office deal teams need product-specific nexus checklists embedding dimension review into transaction origination rather than relying on post-structuring compliance assessment. Payment checklists cover parties, ownership, clearing-path confirmation, participating institutions, purpose and booking or processing entities. Trade checklists add goods classification, origin, destination, end user, transport routing, document-party mapping and service-channel identification. Lending checklists address borrower footprint, facility purpose, drawdown-review triggers and covenant structures supporting ongoing compliance.
Each checklist carries completion evidence requirements preventing tick-box exercise without analytical substance, with compliance authority to stop transactions pending adequate assessment overriding commercial timetable pressure. Checklist maintenance keeps pace with programme evolution through change-triggered updates rather than annual reviews that lag developments: designation waves, programme amendments, new licences and enforcement actions can all alter the facts that must be captured.
Completion-quality sampling verifies checklist effectiveness through independent review of completed assessments, distinguishing genuine analytical coverage from formalistic completion. Digital workflow integration embeds checklists into deal systems with mandatory fields, evidence attachments and escalation routing, converting procedure documents into enforced process rather than optional reference material.
Framing questions for legal advisers
Nexus analysis constantly reaches questions requiring legal advice, and the quality of advice depends heavily on question quality. Effective legal referrals present complete footprints with evidenced dimensions and explicitly identified gaps rather than narrative summaries omitting the details that determine legal conclusions.
Questions should be framed precisely: which regime's applicability to which person or activity is uncertain; what interpretations are under consideration; what facts support each interpretation; what commercial context constrains the answer; and what timeframe governs the decision. Advice records should capture conclusions, scope limitations and effective dates. Changed facts trigger re-referral rather than stretching prior advice to a new transaction.
Privilege management follows the law applicable to the relevant communication. Distribution discipline prevents legal advice from becoming an uncontrolled operational document stripped of context. Standing advice arrangements for recurring nexus patterns can provide efficient coverage for routine questions while reserving bespoke referral for genuine novelty.
Incident-mode nexus assessment under time pressure
Sanctions incidents, designations affecting customers mid-transaction and programme changes with immediate effect compress nexus analysis into hours while raising its consequence. Incident procedures therefore pre-define the accelerated path: footprint triage focusing on decisive facts first, standing positions applied only within their approved scope, legal rapid-response contacts, and interim protective treatment while unresolved facts are gathered.
Protective treatment does not automatically mean an asset freeze. A bank may place an operational hold pending analysis where policy and law permit, while a legal freeze arises only when the applicable sanctions rule requires it. Incident procedures must preserve this distinction so operations does not create inaccurate regulatory records.
Incident communication runs on parallel tracks: internal stakeholders receive decision-relevant conclusions, customers receive lawful and appropriately limited notification, and authorities receive any required reports within applicable deadlines. Post-incident review examines both the substantive decision and the response process: accuracy under pressure, timeline adherence, communication quality, data gaps and framework weaknesses. Each incident should improve the standing positions and evidence model used for the next case.
Masterclass: group sanctions-policy architecture
Nexus complexity concentrates at group level, where entities with different persons obligations share platforms, policies and processing while serving customers whose activity spans regimes. This masterclass addresses the policy architecture that renders multi-entity, multi-regime operation lawful, consistent and auditable rather than fragmented across local improvisations.
Designing the group applicability framework
Group sanctions policy must resolve the tension between global consistency and local legal necessity: group-minimum standards ensuring no entity falls below defined control baselines, jurisdiction-specific overlays addressing local programme, licensing and reporting requirements, and entity-level procedures implementing both within local operating reality. The framework document specifies hierarchy explicitly: where group standards exceed local requirements, the higher standard governs; where local law prohibits group-standard implementation, blocking-statute and conflict procedures activate rather than silent non-compliance; and where local requirements exceed group standards, the local overlay governs with group visibility ensuring the enhancement propagates where relevant elsewhere.
Ownership of framework components must be unambiguous: central sanctions function owning global standards, methodology and oversight; regional functions owning jurisdictional overlays with central approval; entity compliance owning local implementation with central monitoring. RACI discipline prevents the characteristic diffusion where framework maintenance belongs to everyone and therefore no one: each standard, methodology and procedure names its owner, approver, review cycle and change authority. Framework-change governance processes programme developments, enforcement lessons, audit findings and business evolution into timely updates with impact assessment, implementation tracking and verification, ensuring the framework describes current practice rather than aspirational history.
Risk appetite across regimes and entities
Group risk appetite must address sanctions exposure with regime and entity granularity that blanket statements cannot provide: corridor-level appetite reflecting programme complexity and enforcement intensity, sector-level appetite for restricted-adjacent industries, customer-segment appetite for higher-risk profiles, and entity-level appetite variations where local law or capability constrains activity the group permits elsewhere. Each appetite position converts into business rules: onboarding criteria, transaction-acceptance parameters, monitoring intensity and escalation triggers that frontline and operations staff apply without re-deriving appetite per decision.
Appetite-breach management distinguishes temporary exception from strategic drift: defined exception-approval authorities with time limits and enhanced monitoring for justified deviations, versus pattern analysis detecting systematic appetite exceedance indicating either unrealistic appetite or undisciplined business. Secondary-sanctions and extraterritorial-exposure appetite needs explicit senior ownership given the judgement involved in operating near sanctionable boundaries: proximity thresholds, trajectory monitoring for customers approaching boundaries, and exit triggers where proximity becomes untenable. Appetite reviews follow programme developments and enforcement trends rather than calendar alone, since static appetite in dynamic sanctions environments drifts into irrelevance or over-restriction without deliberate recalibration.
The architecture diagram above shows global standards, jurisdictional overlays and entity implementation connected through defined ownership and change governance. Its message is that multi-regime operation succeeds through designed hierarchy rather than accumulated local practice, and framework maintenance deserves resourcing proportionate to the violations it prevents.
Assurance across the multi-regime control estate
Independent assurance must test nexus analysis specifically rather than assuming correct scoping behind disposition review: sampling applicability assessments for dimension completeness, challenging regime-combination reasoning, verifying footprint evidence supports conclusions, and testing standing positions against current programmes and evolved relationships. Thematic reviews across entities compare nexus-analysis quality revealing inconsistency that entity-level audits miss: identical transaction types assessed differently across booking centres indicate framework ambiguity or training gaps requiring central remediation rather than local findings.
Regulatory-examination readiness maintains applicability evidence to multi-authority standards continuously: decision records supporting dispositions under any connected authority's scrutiny, programme-change implementation evidence demonstrating responsive control, and framework documentation showing designed rather than accidental compliance. Mock examinations applying authority-style challenge to nexus decisions identify weaknesses before live examinations do, with findings tracked to remediation like any audit outcome. The assurance objective is justified confidence that every transaction the bank processes rests on dimension-complete applicability analysis, demonstrated through evidence rather than asserted through policy.
Connecting neighbouring chapters
Nexus analysis underpins every sanctions chapter while owning none of their specialties: regimes architecture provides the programme content nexus analysis applies, ownership and control supplies designated-person attribution within footprint assessment, secondary sanctions develops the extraterritorial exposure this chapter positions, screening chapters consume applicability conclusions as processing scope, and licensing implements permissions within applicable prohibitions. Each boundary carries cross-references ensuring analysts navigate from applicability determination to specialist execution without losing the multi-regime context that correct scoping provides.
Capability maturity self-assessment
Nexus-analysis maturity can be self-assessed against a staged model guiding investment prioritisation: initial maturity with ad-hoc dimension review dependent on individual expertise; developing maturity with checklists and standing positions covering routine patterns; defined maturity with dimension-complete procedures, legal-interface discipline and QA sampling operating systematically; managed maturity with metrics-driven calibration, benchmarking and continuous improvement loops; and optimising maturity with predictive exposure identification, automated footprint completeness and industry-leading analytical quality. Honest maturity placement, validated through independent assurance rather than self-rating, directs investment toward the next stage's requirements rather than advanced capabilities built on unfinished foundations. Maturity reassessment follows material programme changes, business evolution and incident experience, since capability that stood still while complexity grew has effectively regressed regardless of its historical rating.
Supervisory engagement on jurisdictional complexity
Supervisors increasingly probe nexus-analysis capability specifically, recognising that scoping failures precede most sanctions violations. Examination preparation should organise applicability evidence the way examiners test it: dimension-complete decision records for sampled transactions, standing positions with legal backing and review currency, programme-change implementation evidence with timelines, and framework documentation showing designed multi-regime operation. Mock-examination exercises applying authority-style challenge to nexus decisions identify weaknesses in reasoning, documentation and timeliness before live examinations do, with findings tracked to remediation like audit outcomes.
Ongoing supervisory dialogue on jurisdictional questions benefits from proactive transparency: briefing supervisors on material nexus positions for novel business, consulting on boundary interpretations where frameworks permit, and disclosing conflicts and their resolution where blocking statutes or multi-regime tensions affect operations. This transparency builds the supervisory confidence that earns proportionate treatment when incidents occur, contrasting with institutions whose first jurisdictional discussion with supervisors follows a violation. Enforcement-response readiness maintains the investigation, documentation and remediation playbooks that violation discovery activates, since response quality determines consequences as much as the underlying breach and prepared institutions navigate enforcement while unprepared ones improvise under pressure.
Metrics for nexus-analysis quality
Nexus-analysis effectiveness needs measurement distinct from disposition throughput, since correctly scoped decisions are the control's purpose rather than processed volume. Footprint-completeness metrics track dimension coverage by transaction type and channel: clearing-path confirmation rates, goods-content assessment rates, staffing-touch review rates and processing-entity mapping coverage, each revealing the dimensions systematically neglected. Applicability-accuracy metrics draw on QA sampling of scoping decisions, overturn analysis distinguishing scoping errors from disposition errors, and examination findings on jurisdictional coverage. Timeliness metrics measure assessment duration against service standards segmented by complexity, distinguishing efficient routine scoping from rushed complex analysis that speed targets incentivise.
Secondary-exposure metrics quantify the risk-appetite dimension: proximity-assessment coverage for sanctionable-sector customers, trajectory monitoring for approaching boundaries, and exit-trigger responsiveness where proximity becomes untenable. Legal-interface metrics track referral quality and turnaround: boundary-question identification rates, advice-implementation fidelity and re-referral discipline for changed facts. Governance reporting presents these measures as control-health evidence with trend analysis and variance explanation, connecting metric signals to resourcing, training and framework decisions. Vanity metrics, applicability assessments completed without quality context or regime counts without exposure quantification, are excluded in favour of measures demonstrating genuine scoping protection through documented management response.
Board and audit-committee reporting on jurisdictional exposure
Senior-governance reporting on sanctions jurisdiction must translate analytical complexity into decision-relevant exposure communication without oversimplifying into false assurance. Exposure reporting quantifies multi-regime touchpoints: transaction volumes by nexus dimension, customer populations with standing multi-regime considerations, secondary-sanctions proximity assessments with trajectory, and blocking-statute conflict positions with resolution status. Control reporting demonstrates applicability-analysis quality through QA results, overturn analysis, examination outcomes and incident performance rather than asserting framework existence. Change reporting tracks programme developments with assessed impact and implementation status, ensuring governance sees the evolving exposure landscape rather than static snapshots.
Decision framing presents the judgements requiring senior ownership explicitly: risk-appetite positions for extraterritorial exposure with proximity evidence, resource decisions for analytical capability with control-return justification, and strategic choices on corridors, entities and business lines where jurisdictional complexity concentrates. Reporting cadence balances currency with proportionality: quarterly substantive review with incident-driven interim updates for material developments, avoiding both the complacency of annual treatment and the noise of excessive frequency. Minutes must record the challenge and decisions evidencing active governance rather than passive receipt, since supervisory examination of sanctions governance tests precisely whether senior bodies direct the control or merely observe it.
Knowledge checks with explained answers
1. A euro payment between non-EU parties with no EU nexus is processed on the bank's EU-based platform. Does EU sanctions analysis apply?
Potentially yes, through the processing-entity touch: activity processed within EU territory by EU systems may engage EU analysis depending on the processing character and programme scope, and the assessment cannot be completed on booking-entity regimes alone. The bank must determine through legal analysis what its platform processing engages, encode the conclusion in standing applicability positions, and apply it systematically rather than discovering platform-touch questions during incidents. Processing-entity blindness, assuming booking regimes govern exclusively, is among the characteristic nexus failures.
2. USD clearing through New York is the only US connection in an otherwise non-US transaction. Is US analysis required?
Yes. Clearing-nexus assessment examines the cleared activity under US frameworks regardless of the parties' nationalities, since US correspondents, payment systems and intermediaries constrain what they process and originator banks must assess downstream viability. The analysis tests the cleared activity, parties, goods, purpose and end-users, against applicable US prohibitions with licensing assessment where relevant. Currency-based assumption without clearing-path confirmation is inadequate in either direction: confirmed clearing engages analysis while alternative-clearing structures require evasion assessment.
3. A subsidiary's activity is lawful under local law and EU measures but proximate to US secondary-sanctions definitions. How should the bank respond?
Through senior-owned risk-appetite determination separating legal permissibility from accepted exposure: assess secondary-sanctions proximity rigorously, evaluate facilitation and group-wide consequences, and decide explicitly whether the activity continues with conditions or exits, documenting the reasoning as business judgement rather than legal compulsion. Technical permissibility never compels continuation where risk appetite excludes the exposure, and commercial desirability never overrides appetite where proximity is untenable. The decision needs senior accountability with monitoring ensuring implementation matches intent.
4. Why must footprint reconstruction precede regime testing rather than following alert generation?
Because partial footprints produce confident wrong answers: party-screening clearance means nothing where clearing paths, goods content or staffing touches independently engage regimes, and alert-driven analysis examines only the dimensions alerts illuminate. Dimension-complete footprint inventory with evidenced elements and explicitly recorded gaps provides the foundation regime testing requires; testing built on assumed benign unknowns validates hope rather than controlling activity. Investment in footprint completeness outperforms analytical sophistication built on partial information.
5. Customer-directed implementation of foreign-sanctions screening potentially engages the EU Blocking Statute. What is the correct approach?
Strand-by-strand analysis with legal advice: assess the customer's commercial autonomy to manage its own risk within legal bounds, analyse the bank's implementation actions against blocking-statute prohibitions and authorisation mechanisms, and govern the bank's own nexus-based decisions independently of customer preferences. Lawful operation respects customer autonomy, statutory prohibition and institutional risk management simultaneously through precise legal engineering rather than binary compliance-or-defiance framing, with authorisation procedures pursued through proper channels where the framework provides them.
6. A transaction was lawful when executed but a subsequent designation affects a connected party. What does nexus analysis require?
Effective-dated reassessment distinguishing the historical lawfulness from current obligations: the executed transaction stands assessed on decision-date facts with evidence preserved, while current and future activity faces the new restriction landscape with pending-item rescreening, relationship review and exposure quantification. Retrospective recharacterisation of lawful historical activity as violations misunderstands sanctions temporality; prospective blindness to designation consequences misunderstands control duty. Dated records enabling as-at reconstruction provide the foundation both positions require.
Glossary of working terms
Nexus is any connection between activity and a sanctioning authority's reach: persons, entity organisation, clearing path, goods origin, destination, service location or activity territory. Applicable regimes are the union across all dimensions.
Persons jurisdiction is the principle that persons must comply with their own authorities' sanctions globally: US persons with US measures, EU persons with EU measures, and equivalents. Staffing touches engage it independently of entity analysis.
Clearing nexus arises where currency movement through a sanctioning jurisdiction's financial system engages its frameworks for the cleared activity regardless of party nationalities.
Secondary sanctions target non-US persons for activity outside US jurisdiction, creating risk-appetite exposure without direct prohibition. Proximity assessment with senior ownership governs response.
Facilitation is the bank's own service provision supporting targeted activity, creating exposure independent of customer permissibility. It is assessed after direct applicability determination.
9. A respondent bank routes dollar-settlement legs for commercial flows through a separate US correspondent while sending euro legs through your institution with standalone narratives. How should the correspondent respond?
As a relationship-transparency issue requiring full settlement-chain disclosure, not as isolated transaction assessment. Nexus analysis must follow commercial activity across message and institution boundaries: deliberately fragmented settlement structuring to isolate nexus dimensions indicates evasion awareness regardless of each leg's standalone appearance. The response combines information demands with deadlines, nested-flow monitoring joining multi-correspondent activity, volume tolerances reflecting assessed opacity, and exit preparation where transparency cannot be secured. Per-message assessment of fragmented flows validates the fragmentation strategy.
10. What distinguishes legitimate nexus-aware routing optimisation from evasion-motivated nexus avoidance?
Purpose, transparency and substance: optimisation pursues efficiency for lawful activity with fully disclosed routing, documented commercial rationale and consistency with established patterns, while evasion restructures to conceal restriction-relevant connections from control functions and authorities. Identical routings serve either purpose depending on intent and transparency, so assessment examines disclosure completeness, commercial-logic credibility and timing correlation with designation events or scrutiny changes. Staff guidance with concrete examples prevents both over-blocking legitimate efficiency and tolerating evasion disguised as optimisation.
Blocking statutes prohibit compliance with specified foreign sanctions extraterritorial application, creating legal conflicts resolved through strand-by-strand analysis with authorisation procedures where provided.
7. A transaction's parties, goods and destination are clean under every regime the analyst checks, but USD clearing runs through New York and the bank's EU platform processes the message. Is analysis complete?
No. Clearing-path and processing-entity dimensions remain untested: USD clearing engages US analysis for the cleared activity while EU platform processing may engage EU considerations depending on processing character and programme scope. Clean parties, goods and destinations answer only their own dimensions; the transaction proceeds only after clearing-nexus and processing-touch assessment with legal input for boundary questions. Dimension checklists per transaction type exist precisely to prevent confident partial assessment masquerading as complete analysis.
8. Why does facilitation analysis follow direct-applicability determination rather than preceding it?
Because the bank's service-exposure question presupposes understanding what activity the service supports and which regimes constrain it: direct applicability establishes the activity's restriction landscape, against which the service's relationship to targeted activity is then assessed. Reversing the order produces abstract facilitation anxiety disconnected from concrete prohibitions, either over-restricting benign services or missing genuine facilitation within seemingly routine processing. Sequence discipline, footprint then regimes then facilitation, ensures each analytical layer builds on completed foundations rather than assumptions.
References and further reading
Sanctions jurisdiction and nexus analysis must be grounded in the actual measure that applies to the person and activity. The sources below support the chapter's distinctions between direct legal applicability, participant obligations, secondary exposure and conflicts of law. They do not replace transaction-specific legal advice.
United States
- U.S. Treasury, Office of Foreign Assets Control — FAQ 11, Who must comply with OFAC sanctions? Updated 21 August 2024: https://ofac.treasury.gov/faqs/11
- U.S. Treasury, Office of Foreign Assets Control — FAQ 3, What kinds of prohibitions does OFAC impose? Updated 21 August 2024: https://ofac.treasury.gov/faqs/3
- U.S. Treasury, Office of Foreign Assets Control — A Framework for OFAC Compliance Commitments: https://ofac.treasury.gov/system/files/126/framework_ofac_cc.pdf
- U.S. Treasury, Office of Foreign Assets Control — Sanctions Programs and Country Information: https://ofac.treasury.gov/sanctions-programs-and-country-information
European Union
- European Commission — Overview of sanctions and related resources, including the Commission's explanation of where EU sanctions apply: https://finance.ec.europa.eu/eu-and-world/sanctions-restrictive-measures/overview-sanctions-and-related-resources_en
- EUR-Lex — Council Regulation (EU) No 833/2014, including the jurisdiction clause in Article 13. Always use the current consolidated text for live decisions: https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:32014R0833
- European Commission — Consolidated FAQs on sanctions against Russia and Belarus, last updated 24 August 2026: https://finance.ec.europa.eu/publications/consolidated-version_en
- European Commission — Extraterritoriality (Blocking Statute), Council Regulation (EC) No 2271/96 and related guidance: https://finance.ec.europa.eu/eu-and-world/open-strategic-autonomy/extraterritoriality-blocking-statute_en
United Kingdom
- HM Treasury, Office of Financial Sanctions Implementation — UK financial sanctions general guidance, updated 12 May 2026: https://www.gov.uk/government/publications/financial-sanctions-general-guidance/uk-financial-sanctions-general-guidance
- UK Government — UK sanctions guidance for non-UK businesses, including UK-nexus principles: https://www.gov.uk/guidance/uk-sanctions-guidance-for-non-uk-businesses
- HM Treasury, Office of Financial Sanctions Implementation — UK Financial Sanctions FAQs, updated 14 September 2026: https://www.gov.uk/government/publications/uk-financial-sanctions-faqs/uk-financial-sanctions-faqs
- Department for Business and Trade — Protection of Trading Interests, covering the UK's separate retained blocking framework for specified extraterritorial U.S. measures: https://www.gov.uk/guidance/protection-of-trading-interests-retained-blocking-regulation
Accuracy note — reviewed 17 September 2026: the chapter deliberately avoids treating a currency code, server location, corporate group or foreign sanction as an automatic jurisdictional conclusion. For live activity, confirm the current regulation, programme scope, relevant persons and entities, clearing and service chain, effective date, authorisations and any blocking-statute or conflict-of-laws issue before acting.