2025. szeptember 20.

How should EU law reconcile the right to a bank account with anti-money laundering rules?


A case currently before the Court of Justice of the European Union (CJEU) raises a critical question for financial institutions, regulators, and human rights advocates alike.

An individual in Slovenia was refused access to a basic payment account by a bank, solely because his name appears on the U.S. OFAC sanctions list. Yet, he has:
 - never been convicted of any offence,
 - is not subject to any restrictive measures by the EU, UN, or his Member State.

Photo: Adobe stock

The Legal Background

Two key EU directives are at play:

  • Directive 2014/92/EU (Payment Accounts Directive – PAD), which guarantees consumers legally residing in the EU the right to open a basic payment account, and
  • Directive 2015/849/EU (4th Anti-Money Laundering Directive – AMLD4), which sets minimum AML and counter-terrorism financing (CTF) standards across the Union.

Under Article 16(4) of the Payment Accounts Directive, banks may only refuse to open a basic account in certain specific circumstances—most notably, if doing so would breach AML/CTF obligations.

However, the mere presence of an applicant on a foreign sanctions list (such as the U.S. Treasury’s Office of Foreign Assets Control – OFAC list) is not directly addressed by EU legislation.

OFAC Listings and the EU Legal Framework

The OFAC list is a U.S. foreign policy tool and not a component of EU sanctions law. The issue in this case was whether inclusion on such a list could be equated with an AML/CTF breach under EU law, justifying the denial of access to a basic payment account.

According to the Advocate General’s Opinion:

  • Refusal to open a basic payment account requires specific, demonstrable AML/CTF risks – such as failure to verify identity, identify a beneficial owner, or assess the purpose of the relationship (Art. 13 of AMLD4).
  • Inclusion on an OFAC list does not, by itself, trigger these conditions.

Even under Article 5 of AMLD4, which allows Member States to adopt stricter national measures, the Slovenian government had not enacted any rule explicitly tying OFAC listings to mandatory refusals.

Risk-Based Approach: A Key Principle

EU AML legislation is grounded in the risk-based approach, as reaffirmed in the Advocate General’s analysis. This means that:

  • A bank may apply enhanced due diligence where higher risks are identified.
  • Inclusion on an OFAC list may serve as an indicator of potential risk, especially if supported by adverse media, asset freezes, or other red flags.
  • However, such listing does not justify outright refusal unless the bank can demonstrate that AML/CTF compliance cannot be ensured, even with proportionate risk mitigation measures.

In fact, the European Banking Authority (EBA) guidelines explicitly state that offering only basic financial services significantly limits the scope for financial crime. The product itself, in this case, is of low inherent risk.

Proportionality and Supervision

Importantly, banks must show that any refusal is:

  1. Based on a holistic risk assessment, and
  2. Proportionate to the identified risks.

The national supervisory authority is empowered—under Article 48(8) of AMLD4—to review the adequacy of the bank’s internal controls, including its justification for refusing to onboard a customer.

Furthermore, Article 16(7) of the Payment Accounts Directive requires that the consumer be informed of:

  • The reason for refusal (unless doing so undermines security or law enforcement goals),
  • The complaint procedure, and
  • The right to contact the competent authority or dispute resolution body.

Conclusion: OFAC Listings Are Not Automatic Grounds for Refusal

The Opinion concludes clearly:

A banking institution may not refuse to open a payment account with basic features solely on the ground that the name of the applicant appears on an OFAC list, unless national law explicitly permits it.

The final assessment remains with the referring national court, but the message from the Advocate General is unambiguous: banks must apply EU law, not foreign sanctions regimes, as the basis for decisions that impact EU citizens’ rights.

Implications for Financial Institutions

This case serves as a critical reminder for EU banks:

  • Foreign sanctions lists cannot be used as a blanket filter for account denials within the EU.
  • Internal AML policies must align with the risk-based approach and provide for proportionate, individualized assessments.
  • Institutions should avoid conflating higher reputational or compliance risk with an outright ineligibility for basic banking services.

For banks, this will mean revisiting internal onboarding policies, especially where third-country designations (like OFAC or FATF grey/black lists) are used in scoring systems or client segmentation models.

Final Thoughts

Inclusion and compliance are not mutually exclusive. While banks must uphold AML standards, they also have a duty—under EU law—to support financial inclusion by providing access to basic payment services, especially where the risks can be managed, not eliminated.

If adopted by the CJEU, this Opinion will reaffirm the primacy of EU law in defining the limits of discretion available to banks when managing risk—and protect consumers from being unjustly excluded from essential financial infrastructure.

Copyright dr. Égertz Andrea
A blog tartalma nem helyettesíti a jogi tanácsadást.

A cikk szerzője

dr. Égertz Andrea
ingatlanforgalmi és európai uniós szakjogász

Közel 20 éves jogi szakmai tapasztalattal rendelkezem, a Budapesti Ügyvédi Kamara tagja vagyok. Az Eötvös Loránd Tudományegyetem Állam- és Jogtudományi karán végeztem, majd a King’s College London (University of London) egyetemen az Európai Unió jogából szereztem mesterdiplomát.

© Copyright dr. Égertz Andrea
A weboldalt készítette: Pixelhuszár
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram