29 January 2013
Ruling [CJEU] ¦ Bank Mellat and the Limits of Financial Sanctions Evidence
Why corporate links alone cannot justify financial sanctions
The General Court’s judgment in Bank Mellat v Council provides an important lesson for financial crime professionals: restrictive measures must be supported by specific, verifiable evidence, and a bank’s provision of financial services to a sanctioned customer does not automatically establish support for the underlying predicate offense.
The case concerned European Union measures freezing Bank Mellat’s funds because of alleged links to Iran’s nuclear and ballistic missile programmes. The Court annulled each contested listing, finding serious defects in the Council’s reasoning, evidence disclosure, assessment of the facts and respect for procedural rights.
Although the case concerned nuclear proliferation rather than money laundering, its reasoning is highly relevant to sanctions compliance, financial crime controls and the treatment of predicate offenses.
Sanctions exposure is not the same as proof of criminal conduct
Financial crime regimes often depend on a predicate offense. Money laundering, for example, requires proceeds connected to an underlying criminal activity. Terrorist financing and proliferation financing operate differently in legal terms, but they raise a comparable evidential issue: authorities and regulated institutions must distinguish between a genuine connection to prohibited conduct and a broad, unsupported inference based on association.
Bank Mellat was described as engaging in a pattern of conduct supporting and facilitating Iran’s nuclear and ballistic missile programmes. It was also accused of providing services to United Nations and EU-listed entities and of being the parent bank of First East Export Bank, which had itself been designated under a United Nations Security Council resolution.
The Court held that several of these statements were too vague to meet the obligation to state reasons. General assertions about a “pattern of conduct” did not identify the transactions, customers, services or circumstances said to establish the prohibited support. Similarly, references to services provided to listed entities were insufficient where the relevant conduct was not described with adequate precision.
For financial institutions, the principle is clear. A risk assessment may begin with a customer’s ownership, counterparties, geography or sector. It cannot end there. A serious conclusion that a bank has facilitated a predicate offense requires a factual bridge between the red flags and the alleged unlawful activity.
A listed customer does not automatically make every service unlawful
A central issue was Bank Mellat’s relationship with Novin Energy Company, an entity subject to United Nations restrictive measures on grounds connected with nuclear proliferation.
Bank Mellat accepted that it had provided account-operation services to Novin. It argued that it had not known, and could not reasonably have suspected, Novin’s involvement in proliferation before the United Nations designation. After the designation, the bank issued an internal instruction ending the relationship. It stopped providing new services and processed only payments arising from pre-existing instructions, cheques and promissory notes.
The Council did not establish that the payments were connected with proliferation. The Court therefore concluded that the earlier services and the steps taken to terminate the relationship did not constitute support for nuclear proliferation.
This distinction matters in sanctions and anti-money laundering work. Servicing an account belonging to a designated or high-risk customer may create substantial exposure, but the legal and compliance analysis must still identify the relevant conduct.
Institutions should assess at least four separate questions:
- What services were provided?
- When were they provided?
- What did the institution know or reasonably suspect at the time?
- What steps did it take after the risk became apparent?
The same structure is useful when reviewing potential money laundering. A bank’s relationship with a customer later linked to fraud, corruption, trafficking or other predicate conduct does not, without more, prove that the bank knowingly handled criminal proceeds. Timing, knowledge, transaction purpose and subsequent remedial action remain critical.
The predicate offense must be identified with precision
The judgment reinforces the importance of separating three distinct propositions.
The first is that a customer is associated with a jurisdiction, sector or government. The second is that the customer has dealt with a person or entity subject to restrictive measures. The third is that the customer itself has participated in, facilitated or benefited from a specified prohibited activity.
Those propositions may overlap, but they are not interchangeable.
In a money laundering investigation, the predicate offense might be bribery, tax fraud, sanctions evasion, embezzlement, narcotics trafficking or cybercrime. A finding that funds passed through a bank account connected with a risky customer does not identify the predicate offense, establish the illicit origin of the funds or demonstrate the institution’s knowledge.
Similarly, in proliferation financing, the existence of a relationship with a listed entity does not automatically prove that every transaction financed proliferation-related activity. The transaction must be examined in context, including the goods or services involved, the parties, payment instructions, account history, ownership structure and available information at the relevant time.
The Council could not rely on an unsupported subsidiary connection
One of the reasons given for listing Bank Mellat was that it was the parent bank of First East Export Bank. The latter had been designated under a Security Council resolution.
The Court found that this was not an independent justification. The designation of First East Export Bank was itself based on allegations concerning Bank Mellat’s involvement in proliferation. Those allegations were expressed in imprecise terms and largely duplicated another reason relied on by the Council.
This aspect of the judgment is particularly relevant to ownership and control analysis. Corporate relationships can be important indicators of risk, but they must not become a substitute for evidence of conduct. Parent companies, subsidiaries, affiliates and minority shareholders should not be treated as automatically sharing liability for one another’s activities.
For compliance teams, this means that ownership and control findings should be documented separately from transactional findings. A group relationship may justify enhanced due diligence, restrictions on services or escalation to senior management. It does not, by itself, establish that the parent participated in a predicate offense or knowingly facilitated prohibited activity.
Procedural fairness is part of effective sanctions enforcement
The Court also found that the Council had failed to give Bank Mellat adequate access to relevant evidence. One proposal relied upon by the Council was disclosed only as an annex to its rejoinder, after the initial listing, after the proceedings had begun and after the applicant had been asked to submit observations.
The Court held that the late disclosure infringed the bank’s rights of defence and its right to effective judicial protection. The Council was required to provide information in sufficient time for the bank to respond meaningfully.
This is not merely a procedural technicality. Effective challenge and review improve the quality of sanctions decisions. They can expose factual errors, clarify ownership structures, distinguish legitimate from prohibited transactions and identify whether a bank acted promptly after receiving relevant information.
The same principle has practical significance for financial institutions dealing with regulatory enforcement. A defensible decision to freeze funds, exit a relationship or file a suspicious transaction report should be based on records that identify the facts, the applicable legal rule and the reasoning connecting them. Vague references to adverse intelligence are unlikely to withstand close scrutiny if they are not supported by reliable and relevant information.
A factual error can undermine an entire listing
The original measures described Bank Mellat as a state-owned bank. The Court found that this was factually incorrect. The Council later removed that statement from the reasons used in subsequent measures.
The error was significant because it indicated that the Council had not properly checked the information submitted in support of the initial designation. The Court held that the Council had failed to assess the relevance and validity of the evidence before adopting the initial measures.
This point should resonate with any organisation operating a sanctions-screening or transaction-monitoring programme. Data quality is not an administrative concern separate from legal risk. An incorrect ownership field, outdated designation record, mistaken identity match or inaccurate country classification can affect the entire decision chain.
A robust process should therefore include source verification, independent review of material allegations, documented quality controls and a clear distinction between confirmed facts, reasonable inferences and unverified intelligence.
What this means for AML and sanctions programmes
The judgment does not require financial institutions to prove a criminal conviction before taking precautionary action. Banks may and should act on reasonable suspicion, legal prohibitions and material risk indicators. Sanctions screening is necessarily preventive, and institutions cannot wait for complete certainty before blocking a prohibited payment or escalating a relationship.
The decision does, however, show that preventive action must be proportionate and evidence-led. Institutions should avoid treating all risk indicators as conclusive proof. A customer’s nationality, state connection, business sector, dealings with a listed entity or corporate affiliation may justify scrutiny, but each factor must be assessed against the actual facts.
Where a relationship may involve proceeds of a predicate offense, the investigation should seek to establish the source and movement of funds, the underlying commercial rationale, the customer’s role, the relevant counterparties and the institution’s knowledge at the time. Where proliferation or sanctions evasion is suspected, the review should examine the goods, end users, intermediaries, payment routes and ownership or control arrangements.
The outcome should be recorded in a way that allows another reviewer, regulator or court to understand how the conclusion was reached.
Conclusion
Bank Mellat’s successful challenge illustrates a fundamental rule of financial crime enforcement: serious restrictions require serious reasoning.
A bank may be exposed to sanctions risk because of its customers, ownership links or cross-border activity. But a lawful finding that it supported a predicate offense requires more than association. Authorities must identify the relevant conduct, disclose the material evidence, address the institution’s response and verify the underlying facts.
For compliance professionals, the practical message is straightforward. Strong controls should be cautious without being speculative, responsive without being automatic and firmly grounded in evidence that can withstand independent review.
Dive deeper
- EUR-Lex ¦ Case T‑496/10, Judgment of the General Court (Fourth Chamber), 29 January 2013 ¦ Link