The EU's 21st Russia sanctions package, adopted on July 23, 2026, introduces a third-country ban tool that allows regulators to prohibit all transactions with crypto-asset service providers based in specific jurisdictions. This isn't just a minor adjustment to sanctions screening; it's a geographic kill switch.
If you're a sanctions analyst at a bank, payment processor, or crypto exchange, you're now facing a new compliance decision: do you wait for regulators to list a jurisdiction, or do you proactively restrict crypto counterparties based on your own risk assessment?
Here's how to decide.
The Decision You're Facing
When your institution deals with crypto-asset service providers, you must choose whether to:
Path A: Maintain business relationships with crypto providers in all non-listed jurisdictions, relying on entity-level screening and transaction monitoring.
Path B: Implement geographic restrictions on crypto counterparties beyond the official EU list, based on your risk appetite and sanctions-evasion indicators.
Path C: Exit crypto-related correspondent relationships entirely until the regulatory environment stabilizes.
This choice impacts your sanctions compliance framework, counterparty due diligence protocols, and operational risk exposure.
Key Factors That Affect Your Choice
Your Institution's Crypto Exposure
If you operate crypto wallets, process fiat-to-crypto on-ramps, or maintain correspondent relationships with crypto exchanges, you're directly affected. The 21st package lists 14 crypto-asset service providers under the transaction ban and establishes the jurisdictional tool for future expansion.
Even if your exposure is indirect, such as banking a fintech that deals with crypto or clearing payments for merchants who accept crypto, you still carry sanctions risk through the chain.
Regulatory Expectations in Your Home Jurisdiction
EU member states must enforce the jurisdictional ban once the Council lists a territory. However, your national authority may expect you to demonstrate why you didn't identify the risk earlier. Financial supervisors increasingly expect firms to anticipate designation lists, not just react to them.
Your Ability to Verify Beneficial Ownership and Control
The package extends the prohibition on Russian nationals sitting on boards to "any crypto-asset services business" from August 25, 2026. If you can't verify the nationality and control structure of your crypto counterparties, you can't demonstrate compliance.
Third-Country Diversion Risk in Your Portfolio
The package adds 51 entities to Annex IV for enhanced export restrictions, including entities in China, Hong Kong, Turkey, Kyrgyzstan, India, Kazakhstan, and the UAE. If your crypto counterparties operate in or route transactions through these jurisdictions, you're managing layered circumvention risk.
Path A: Rely on Entity-Level Screening
Choose this path when:
- You have a small, stable set of crypto counterparties with transparent ownership structures.
- You can verify beneficial ownership and board composition for each counterparty.
- Your transaction monitoring can detect typologies consistent with sanctions evasion, such as rapid movement across wallets or use of mixers.
- Your competent authority has confirmed that entity-level screening suffices.
- You can demonstrate that your counterparties don't facilitate Russian sanctions circumvention.
What you must do:
Screen against the 216 new designations (48 individuals, 168 entities) and the 14 newly listed crypto providers. Update your screening logic to catch the expanded transaction ban, which now covers 33 additional Russian credit institutions and extends to financial messaging services.
Confirm no Russian or Belarusian nationals control or sit on the boards of your crypto counterparties before the August 25, 2026 deadline. This requires beneficial owner identification and governance documentation, not just a name-screening hit.
Monitor for red flags: counterparties that refuse to provide ownership details, entities registered in jurisdictions with weak AML/CFT frameworks, or transaction patterns that suggest structuring or layering.
The risk you accept:
If a regulator later lists a jurisdiction where your counterparty operates, you'll need to wind down the relationship quickly. The package includes new derogations that let competent authorities authorize EU, EEA, and Swiss nationals to withdraw funds and close accounts at newly listed entities, but the wind-down period may be short.
You also risk your counterparty facilitating circumvention without your knowledge. The 21st package targets "platforms helping Russia evade EU sanctions," but detection depends on your transaction monitoring rules and your counterparty's transparency.
Path B: Implement Geographic Restrictions
Choose this path when:
- Your crypto exposure is significant and you can't verify beneficial ownership for all counterparties.
- You've identified concentration risk in jurisdictions with weak crypto regulation or high sanctions-evasion risk.
- Your risk appetite is low and your board expects you to stay ahead of regulatory listings.
- You can absorb the operational cost of maintaining a restricted-jurisdiction list.
What you must do:
Build a risk-based geographic framework. Start with jurisdictions the EU has flagged for circumvention: the Annex IV additions point to China (including Hong Kong), Turkey, Kyrgyzstan, India, Kazakhstan, and the UAE as territories where entities support Russian military-industrial complex procurement or enable sanctions evasion.
Layer in FATF assessments. Grey List and Black List jurisdictions with weak AML/CFT controls present higher risk for crypto-based sanctions evasion because regulatory oversight is limited.
Define your restriction: will you block all transactions with crypto providers in these jurisdictions, or will you require enhanced due diligence and senior approval? The latter gives you flexibility but increases your compliance workload.
Document your methodology. If a regulator questions why you restricted a jurisdiction before it was officially listed, you need to show a rational, risk-based process tied to observable sanctions-evasion indicators.
The risk you accept:
You may restrict legitimate business relationships. Not every crypto provider in Turkey or the UAE facilitates Russian sanctions evasion, and blanket geographic restrictions can create false positives that frustrate customers and counterparties.
You also accept operational complexity. Maintaining a dynamic restricted-jurisdiction list requires ongoing monitoring of regulatory developments, sanctions typologies, and enforcement actions.
Path C: Exit Crypto Relationships
Choose this path when:
- You lack the compliance infrastructure to verify crypto counterparty ownership and monitor transaction typologies.
- Your institution's risk appetite for sanctions violations is zero.
- The revenue from crypto-related relationships doesn't justify the compliance cost.
- You operate in a highly regulated sector (banking, insurance) where even indirect crypto exposure creates reputational risk.
What you must do:
Invoke the wind-down derogations in the 21st package. The new provisions let competent authorities authorize termination of relationships with newly listed banks and crypto providers, but you'll need to demonstrate that the exit is necessary to comply with sanctions obligations.
Communicate clearly with affected counterparties and customers. If you're a bank terminating a fintech client because they process crypto payments, document the sanctions-risk rationale to defend against claims of arbitrary de-risking.
The risk you accept:
You lose revenue and may damage customer relationships. If your competitors stay in the crypto space and manage the risk successfully, you've ceded market share.
You also accept that exiting today doesn't eliminate past exposure. If your historical transactions facilitated sanctions evasion, you still face potential enforcement action.
Summary Matrix
| Factor | Path A: Entity Screening | Path B: Geographic Restrictions | Path C: Exit Crypto |
|---|---|---|---|
| Crypto exposure | Low to moderate; transparent counterparties | Material; mixed transparency | Any level; zero risk appetite |
| Ownership verification | Can verify for all counterparties | Cannot verify for all; concentration in high-risk jurisdictions | Cannot verify reliably |
| Regulatory expectation | Entity-level screening acceptable | Expect proactive risk management | Sanctions risk outweighs revenue |
| Operational capacity | Strong transaction monitoring and screening | Can maintain dynamic restricted list | Limited compliance infrastructure |
| Risk accepted | Late reaction to new listings; hidden circumvention | False positives; operational complexity | Revenue loss; potential de-risking claims |
The jurisdictional ban tool in the 21st package signals where sanctions enforcement is headed: regulators will target entire ecosystems, not just individual bad actors. Your choice isn't whether to comply with the listings (that's mandatory), but whether to anticipate them.



