Scope
This guide outlines the compliance requirements introduced in the EU's eighth sanctions package against Russia (6 October 2022). It focuses on the full crypto-asset ban, SWIFT disconnections, and trust service restrictions. If your institution processes transactions involving Russian or Belarusian counterparties, maintains crypto custody services, or provides correspondent banking for EU entities, these measures are relevant to you.
This is not a comprehensive guide to the entire EU Russia sanctions regime. It specifically addresses the eighth package provisions affecting transaction screening, crypto compliance, and service restrictions.
Key Concepts and Definitions
Full Crypto-Asset Ban: The EU has removed the previous €10,000 threshold for crypto payments to European wallets. All crypto-asset wallets, accounts, or custody services are now prohibited regardless of value when connected to Russia.
SWIFT Disconnection: Designated Russian and Belarusian banks have been removed from the Society for Worldwide Interbank Financial Telecommunication messaging system, preventing them from sending or receiving standardized payment instructions through this network.
Trust Services: Registered office and management services provided to trusts. The eighth package extended deadlines and added specific exceptions for wind-down activities.
Designated Persons and Entities: As of the eighth package, the EU sanctions list includes 1,158 individuals and 98 entities (cumulative total including 2014 Crimea annexation measures).
Requirements Breakdown
Crypto-Asset Prohibition
What's banned: All wallet, account, or custody services for crypto-assets where the beneficial owner is Russian or the wallet is held in Russia. The previous €10,000 threshold no longer applies.
Why the change: The EU found that small-scale transactions under the threshold were facilitating sanctions evasion. The goal is to make crypto payment services completely unavailable.
Your obligation: Screen all crypto custody relationships and beneficiaries. If you identify a Russian nexus, freeze the account and report to your national competent authority. There's no de minimis exception.
SWIFT Disconnection
Banks removed from SWIFT:
- Sberbank (Russia's largest bank)
- Credit Bank of Moscow
- Russian Agricultural Bank
- Bank for Development and Reconstruction (Belarus)
Compliance impact: You can't receive or send SWIFT messages to these institutions. If your transaction monitoring relies on SWIFT MT messages to identify counterparties, find alternate data sources for transactions involving these banks through non-SWIFT channels.
Correspondent banking risk: If you maintain correspondent relationships with EU banks, confirm they've removed these institutions from their SWIFT directories. A payment instruction that routes through a now-disconnected bank will fail, but the attempt itself may trigger reporting obligations.
Service Restrictions
Prohibited services to Russian entities:
- Accounting
- Lobbying
- Public relations
- Consultancy
Application: EU companies and major consultancy firms operating in the EU cannot provide these services to legal persons established in Russia or Russian entities.
Sanctions screening implication: If your institution processes payments for professional service firms, flag transactions where the beneficiary is a Russian legal entity and the remittance information suggests these service types.
Trust Service Exceptions
Extended deadline: Provision of registered office and management services to targeted trusts was extended to 5 July 2022 (this date has passed, but it's relevant for historical compliance reviews).
Wind-down authorization: National competent authorities may authorize trust services beyond that date for operations "strictly necessary for the termination of contracts" initiated before 11 May 2022.
Carved-out purposes:
- Humanitarian purposes
- Civil society activities
- Administration of occupational pension schemes
- Insurance policies
- Employee share schemes
- Charities
Your action: If you're reviewing historical transactions involving trust services and Russian counterparties between May and July 2022, check whether your jurisdiction's competent authority issued wind-down authorizations.
Implementation Guidance
Update Your Screening Lists
The eighth package added new individuals and entities. Your name screening system must include:
- The consolidated EU sanctions list (Official Journal of the European Union)
- Updates published after 6 October 2022
Set up alerts for Official Journal publications. The EU doesn't always announce updates through press releases.
Adjust Crypto Monitoring Rules
If you custody crypto-assets:
- Identify Russian beneficial owners: Run your existing customer base against the Russia nexus criteria (citizenship, residency, entity registration).
- Freeze accounts: Don't wait for a manual review. Automated freezing is appropriate here because there's no threshold test.
- Document your review: Record the date you identified the account, the freeze action, and your report to the competent authority.
If you process fiat-to-crypto or crypto-to-fiat transactions:
- Block Russia-connected conversions: Your transaction monitoring rules should auto-decline transactions where the originator or beneficiary has Russian nexus.
- Review wallet addresses: If your system captures destination wallet addresses, check whether you can identify wallets previously associated with Russian customers under the old €10,000 threshold.
SWIFT Disconnection Controls
Add these banks to your sanctions screening system as high-risk entities even though they're disconnected from SWIFT:
- Sberbank
- Credit Bank of Moscow
- Russian Agricultural Bank
- Bank for Development and Reconstruction
Why? Transactions may still reference them in beneficiary bank fields if routed through alternate messaging systems or correspondent networks. A match should trigger immediate escalation to your sanctions team.
Service Payment Screening
If you process B2B payments for consultancy, accounting, PR, or lobbying firms:
- Flag Russian beneficiaries: Add a rule that alerts on payments to Russian legal entities where the remittance information includes terms like "consulting fee," "advisory services," "audit," "public relations."
- Review firm client lists: If you bank large consultancy firms, ask whether they've implemented controls to block invoicing Russian clients for prohibited services.
- Don't assume good faith: The regulation applies regardless of contract date. A firm can't continue servicing a Russian client under a pre-sanctions contract without violating the package.
Common Pitfalls
Pitfall 1: Assuming the €10,000 crypto threshold still applies
Some compliance teams missed the threshold removal because earlier guidance referenced it. Re-train your crypto compliance staff. The threshold is gone.
Pitfall 2: Relying only on SWIFT for counterparty identification
SWIFT disconnection doesn't eliminate the banks. They'll use alternate channels (bilateral messaging, correspondent arrangements outside SWIFT). Your screening can't depend on SWIFT BICs alone.
Pitfall 3: Treating trust service exceptions as blanket carve-outs
The exceptions are narrow. "Humanitarian purposes" doesn't mean any trust with a Russian beneficiary that claims charitable intent. You need documented evidence that the trust falls within the specific carved-out categories, and ideally, authorization from the national competent authority.
Pitfall 4: Missing cumulative sanctions counts
The eighth package didn't create 98 entities and 1,158 individuals. That's the cumulative total since 2014. When you read "new designations," check the Official Journal for the incremental additions, not the total count.
Pitfall 5: Ignoring Belarusian entities
The Bank for Development and Reconstruction is Belarusian, not Russian. Your Russia-focused screening rules might miss it. Ensure your sanctions filters cover both jurisdictions.
Quick Reference Table
| Requirement | Scope | Threshold/Limit | Reporting Obligation | Exceptions |
|---|---|---|---|---|
| Crypto-asset ban | All wallets, accounts, custody services with Russian nexus | None (previous €10,000 limit removed) | Freeze and report to national competent authority | None |
| SWIFT disconnection | Sberbank, Credit Bank of Moscow, Russian Agricultural Bank, Bank for Development and Reconstruction | N/A (full disconnection) | Report attempted transactions | None |
| Service restrictions | Accounting, lobbying, PR, consultancy to Russian entities | All transactions | Decline and report if attempted | None for these service types |
| Trust services | Registered office and management services | All targeted trusts | Varies by jurisdiction | Humanitarian, civil society, pensions, insurance, employee shares, charities; wind-down if authorized |
| Designated persons/entities | Individuals and legal entities on consolidated list | N/A (cumulative: 1,158 individuals, 98 entities as of eighth package) | Freeze assets, report matches | Humanitarian exemptions require competent authority approval |
List source: Official Journal of the European Union - List of persons and entities under EU restrictive measures over the territorial integrity of Ukraine
Package effective date: 6 October 2022
Your next action: Verify your screening system ingested the eighth package updates. Run a test transaction with "Sberbank" as beneficiary bank. It should auto-block.



