After the UN snapback, what is the Iran sanctions response?
- Authority
- UN Security Council; EU Council; OFSI; OFAC
- Rule type
- regulation
- Jurisdiction scope
- UN; EU; UK; US federal
- Effective date
- Sep 28, 2025
- Source text
- Read primary rule text ↗
Re-baseline screening and controls across UN, EU, UK, and US layers; check ownership, banking routes, and wind-down deadlines.
Non-advice notice: This record is a legal-analysis record and compliance-operations overview, not legal advice. It does not decide whether a particular transaction, counterparty, affiliate, payment route, or wind-down step is lawful.
Legal-background review: Mara, sanctions-law and legal-operations reviewer. Last verified: 2026-08-25 00:00 UTC. Primary-source scope: UN snapback materials as described in cited legal analyses, EU sanctions materials including Council Regulation (EU) 2025/1975 as described in cited sources and the Consilium Iran sanctions policy page, UK OFSI and designation mechanics as described in cited sources, and OFAC’s Iran sanctions program page. Consilium material available to this record was snippet-level, and Congress materials were not relied on.
The practical legal response to Iran financial sanctions in 2025 starts with one correction: after the UN snapback, a US-only refresh is the wrong baseline. The working file now has to reconcile four layers — UN, EU, UK, and US — before anyone can say the sanctions-screening result, the ownership chain, the payment route, and the license memo still line up.
That does not mean every multinational is suddenly unwinding a live Iran business. Many Western firms had already exited or heavily restricted Iran exposure after 2018, so the live task for many legal and compliance teams is less theatrical and more time-consuming: rescreen counterparties, remap beneficial ownership and control, check banks and transfer routes, identify any residual contractual rights or receivables, and preserve the decision record while the legal ground is still moving.

What changed: the baseline is multilateral again
The snapback sequence matters because it changed the control environment before many internal tools would have reflected it. The E3 states notified the UN Security Council on August 28, 2025 that Iran was in significant non-performance; a Security Council resolution to extend sanctions relief failed on September 19, 2025; and the pre-2016 UN Iran sanctions resolutions — identified in the cited analyses as Resolutions 1696 through 1929 — were revived through the snapback process.[1][2][3]
Sources differ by one day on the effective date. Gibson Dunn and Debevoise describe reimposition as occurring on September 28, 2025; Crowell and LBKM describe the operative deadline or snapback date as September 27, 2025.[1][2][3][4] For controls work, that discrepancy should be handled conservatively: preserve the date source used in the file, avoid treating the one-day difference as a permission gap, and test any transaction in that window against counsel’s jurisdiction-specific conclusion.
The revived UN baseline is not just a diplomatic marker. It is the reason EU and UK controls had to be reassembled around designations, sectoral restrictions, banking controls, transport and insurance exposure, and wind-down mechanics. The company that says it has “no Iran business” still needs to prove what that means across customers, vendors, minority-owned affiliates, agents, insurers, banks, freight forwarders, receivables, and legacy contracts.
| Layer | Control question after snapback | Immediate compliance consequence |
|---|---|---|
| UN | Which pre-2016 UN restrictions and listings are revived? | Refresh screening and legal baselines against the revived resolutions, not only against national lists. |
| EU | Which Regulation 2025/1975 prohibitions, asset freezes, banking limits, and wind-down rules apply? | Check EU persons, EU-incorporated entities, EU territory, EU-origin funds and transfer touchpoints, and January 1, 2026 wind-down endpoints. |
| UK | Which UN and autonomous designations were reimposed, and which OFSI general licenses were time-limited? | Rescreen UK nexus files, preserve OFSI license reliance records, and check short 2025 wind-down deadlines. |
| US | How do OFAC’s Iran program, the 50% rule, secondary sanctions, and 2025 maximum-pressure designations affect the same fact pattern? | Keep US-person, US-dollar, US goods/services, ownership, correspondent-banking, shadow-fleet, and gatekeeper risks in the same review file. |
UN layer: revive the legal map before retesting the names
A screening run is only as good as the legal universe it is screening against. After snapback, the first step is not to ask whether OFAC added a name. It is to confirm whether the internal sanctions matrix recognizes the revived UN resolutions and whether the screening vendor, ERP restricted-party rules, contract playbooks, and escalation memos were updated to match.
That means checking more than obvious Iranian counterparties. If a group had old Iran-related receivables, dormant distributor files, legacy warranties, after-sales service questions, freight records, bank rejections, or escrowed funds, those records should be retested against the revived UN designations and restrictions as implemented by the jurisdictions that touch the file.
The UN layer is also where documentation discipline starts. If the team concludes that a counterparty is outside scope, the file should show which list set was checked, which ownership facts were known, which implementation laws were considered, and which date was used for the snapback analysis. A bare “no hit” notation will not help when the issue is whether the legal baseline itself was current.
EU layer: the missed risk is often banking, not a direct sale
The EU reset deserves more attention than it often gets in US-led compliance programs. Council Regulation (EU) 2025/1975 of September 29, 2025 is described in the cited analyses as restoring the pre-JCPOA EU Iran sanctions framework, including restrictions affecting oil, gas and petrochemicals, correspondent banking and fund transfers, asset freezes involving major Iranian banks and state-linked entities, and wind-down provisions expiring January 1, 2026.[1][2][5]
The common operational error is to treat EU exposure as a subsidiary question: “Do we have an EU seller?” That is too narrow. EU rules can become relevant through an EU-incorporated entity in the group, an EU employee approving or performing work, EU territory, EU-origin goods or technology, an EU bank, an EU correspondent account, an EU insurer, or a transaction routed through an EU financial institution.
For the legal team, the EU workstream should start with a transaction map rather than a sanctions-list export. Identify any Iran-linked revenue, receivables, refunds, credits, claims, insurance recoveries, bank rejections, security interests, guarantees, service obligations, or third-country counterparties that may be acting for or owned by Iranian persons. Then test each file for EU nexus before deciding whether the EU reimposition matters.

The January 1, 2026 wind-down endpoint is the kind of date that should be carried in a matter tracker, not left inside a client alert.[1][2] For each file relying on a wind-down pathway, the tracker should identify the activity authorized, the party relying on it, the legal source, the last permissible act, the payment mechanics, the evidence retained, and the business owner responsible for stopping further performance.
Banking controls need their own review. A company may have no shipment, no invoice to Iran, and no Iranian customer, but still have exposure if a payment touches a restricted Iranian bank, a designated state-linked entity, a blocked intermediary, or a correspondent-banking channel restricted under the reimposed EU rules. Payment-screening teams should not be asked only whether a name matched; they should be asked whether the funds-flow narrative makes sense under the revived EU restrictions.
What to add to the EU file
- The EU nexus analysis: entity, personnel, territory, bank, insurer, goods, technology, or payment route.
- The sanctions-list and ownership check performed after Regulation 2025/1975 was reflected in internal controls.
- Any wind-down basis, including the activity covered and the January 1, 2026 endpoint where applicable.
- A funds-flow diagram for any payment, refund, receivable, guarantee, or insurance recovery with Iran-linked facts.
- A contemporaneous explanation for closing the file, escalating it, rejecting it, freezing it, or seeking external advice.
UK layer: short licenses and long records
The UK layer is easy to underweight if the compliance program is built around OFAC and EU controls. That is a mistake after snapback. Gibson Dunn’s analysis describes the UK as reimposing 121 UN designations and 71 autonomous designations, alongside four OFSI wind-down general licenses expiring on October 28 and November 12, 2025, with six-year recordkeeping requirements.[1]
Those dates are not administrative trivia. A UK nexus can arise through a UK parent, subsidiary, branch, employee, director, bank, insurer, broker, shipping service, legal service, or funds-flow touchpoint. If a file relied on an OFSI wind-down general license, the compliance record should show that the activity fell within the license, occurred before the relevant deadline, and was documented to the standard the license required.
Six-year recordkeeping also changes how a matter should be closed. The file should not disappear into an email folder once the payment is rejected or the contract is terminated. Keep the counterparty screen, ownership notes, license analysis, internal approvals, bank communications, rejected-payment notices, and the decision memo together. A future reviewer will need the full chain, not a calendar entry saying “OFSI GL checked.”
The UK workstream also needs a designated-owner problem solved. If trade compliance owns screening, treasury owns bank communications, legal owns license interpretation, and the business owns contract closure, nobody owns the evidence package unless it is assigned. In sanctions work, that gap usually becomes visible only when a regulator, auditor, bank, or acquirer asks why the company believed the activity was permitted.
UK checks that should not be skipped
- Rescreen counterparties, banks, vessels, insurers, brokers, and intermediaries against UK designations, not only OFAC and EU lists.
- Check whether any UK person or UK-incorporated entity participated in approval, performance, payment, insurance, shipping, or legal services.
- Map any OFSI general-license reliance to the relevant October 28 or November 12, 2025 deadline.
- Retain the evidence package for the six-year period where the cited UK wind-down license mechanics require it.
US layer: maximum pressure did not stop being relevant
The point of the snapback analysis is not that the US layer became less important. It is that the US layer is no longer enough. OFAC’s Iran sanctions program remains the standing reference point for US-person prohibitions, blocked-property controls, sectoral and secondary-sanctions risks, and list-based restrictions.[6]
The 2025 US posture was already intensifying. Paul Weiss, writing through Corporate Compliance Insights, describes NSPM-2 “maximum pressure” implementation and states that by December 2025 the administration had designated 155 Iranian persons, 460 non-Iranian persons, and more than 180 shadow-fleet vessels.[7] Those figures measure designation activity, not proof that every named category creates the same risk for every company.
For controls work, the US review still has several separate questions. Is a US person involved? Is there US-origin content, software, technology, financing, clearing, or approval? Is a blocked person involved directly or indirectly? Does the OFAC 50 Percent Rule treat an entity as blocked because of aggregate ownership by blocked persons? Does the transaction involve petroleum, petrochemicals, shipping, insurance, exchange houses, shadow-fleet vessels, or professional gatekeepers?[6]
That ownership question is where screening tools often give legal teams false comfort. A direct name hit is simple. The harder file is a third-country trader, an insurer, a logistics company, or a payment intermediary with an ownership chain that includes sanctioned Iranian interests, nominee shareholders, recently renamed entities, or vessels moving between managers. The control should require an ownership and control review before the business receives a “clear” answer.
The same logic applies to law firms, consultants, brokers, and other gatekeepers. A services engagement that looks remote from Iran can still create sanctions issues if the work facilitates a prohibited transaction, handles blocked property, receives funds through a restricted route, or assists a designated party. For a related treatment of that professional-services problem, see Iran Sanctions Legal Compliance Starts With Your Own Firm.
The right response is a re-baseline, not a memo update
A useful response file has to connect legal change to control behavior. If the only output is a board slide saying “UN sanctions snapped back,” the people approving payments, maintaining vendor masters, and clearing shipments still do not know what to do differently on Monday morning.
Start with list currency. Confirm that the screening vendor and internal restricted-party lists include the revived UN designations as implemented, the EU Regulation 2025/1975 changes, the UK reimposed UN and autonomous designations, and current OFAC Iran program data. Record the date of the list refresh and the source set used. If a vendor cannot tell you when a list changed, treat that as a control fact, not a procurement inconvenience.
Then test ownership logic. Screening a legal name without checking whether blocked or designated persons own or control the entity will miss the files most likely to become hard. The US 50 Percent Rule is the familiar reference point, but the re-baseline should ask the same practical question across regimes: who owns, controls, directs, guarantees, insures, finances, or benefits from the counterparty?
Next, map residual exposure. Do not limit the inventory to open sales contracts. Include dormant accounts, receivables, credits, refunds, warranty claims, distributor terminations, bank holds, rejected payments, insurance claims, shipping disputes, arbitration proceeds, software-access issues, and any third-country counterparty whose commercial role points back to Iran.
| Control area | Question to answer | Evidence to keep |
|---|---|---|
| Screening | Were counterparties, owners, banks, vessels, insurers, and intermediaries screened against UN, EU, UK, and US lists after the snapback updates? | Screening date, source list, match disposition, escalation notes, and reviewer. |
| Ownership and control | Could a listed or blocked person own, control, direct, or benefit from the entity even without a direct name match? | Corporate registry extracts, ownership chart, beneficial-owner notes, adverse-media checks, and counsel conclusion. |
| Banking and transfers | Does any payment, refund, receivable, guarantee, escrow, correspondent route, or bank communication create EU, UK, US, or UN exposure? | Funds-flow diagram, bank messages, rejected-payment notices, license analysis, and treasury approval. |
| Wind-down | Is any activity relying on an EU or UK wind-down measure, and did it occur before the applicable deadline? | License source, activity description, deadline, proof of completion, and stop-work instruction. |
| Closure | Can a later reviewer understand why the company approved, blocked, rejected, froze, or escalated the matter? | Contemporaneous decision memo, legal sources checked, business facts, approvals, and retention location. |
Wind-down tracking should be date-specific. EU files need attention to the January 1, 2026 endpoint described in the cited analyses; UK files need attention to the October 28 and November 12, 2025 OFSI general-license expiries where those licenses are the relied-on authority.[1][2] A general reference to “available wind-down relief” is not a legal conclusion.
For firms with oil, shipping, insurance, logistics, trading, or financial-institution touchpoints, the review should connect this record with sector-specific files. The same counterparty may appear in different ways: a vessel in one screen, a manager in another, a charterer in a third, and a bank or insurer in the payment chain. For related US oil-market wind-down mechanics, see What US Iran sanctions whiplash means for oil markets; for Hormuz-related US sanctions framing, see What Changed in US-Iran Sanctions at the Strait of Hormuz?; and for a screening example involving insurers and the 50 percent analysis, see US Iran sanctions name Hormuz insurers as blocked parties.
Policy context is useful only if it does not blur the legal file
There is a policy debate about whether snapback changes Iranian conduct, strengthens bargaining leverage, or mainly hardens positions. Nephew’s June 2025 sanctions analysis and Crisis Group’s snapback Q&A are useful context for why governments treated sanctions architecture as a pressure tool rather than a paperwork exercise.[8][9] That context should not be allowed to substitute for the narrower legal work.
A board does not need a lecture on the JCPOA history to approve the control response. It needs to know whether the company can show that it refreshed screening, updated ownership logic, identified residual Iran touchpoints, checked EU and UK wind-down deadlines, preserved OFSI and EU license files where relevant, and kept OFAC’s maximum-pressure designation environment inside the same review.
Later 2026 general-license developments may matter for current transactions, but they should be treated as currency updates, not as the anchor for the 2025 response. The anchor remains the September 2025 snapback and the immediate multilateral re-baseline it required.
The operating posture
The cleanest Iran sanctions response after snapback is disciplined and unglamorous: refresh sanctions-screening lists across UN, EU, UK, and US sources; remap ownership and control rather than relying on direct-name hits; inventory residual counterparties, receivables, payment routes, banks, insurers, vessels, and service providers; check wind-down deadlines and license conditions before anyone acts; and document the conclusion while the facts and legal sources are still fresh.
For many companies, that process will end with no active Iran business to unwind. That is still a result worth documenting. The risk is not only that a prohibited transaction slips through; it is that a company cannot later show how it knew the old “no Iran business” answer still held after the legal baseline changed.
References
- Snap Decision: Renewed Global Iran Sanctions and Increased Risks for Business, Gibson Dunn
- United Nations, European Union and United Kingdom, Debevoise, November 2025
- Impending Deadline for UN Action on Iran: What the Snapback of Iran Sanctions Could Mean for Global Business, Crowell
- US Sanctions Iran Comprehensive Review, LBKM
- Sanctions against Iran, Consilium
- Iran Sanctions, Office of Foreign Assets Control
- The State of OFAC Sanctions Enforcement in 2026, Corporate Compliance Insights
- Back to Basics: Iran Sanctions After the June 2025 Conflict, Center on Global Energy Policy
- Iran Sanctions Snapback: Q&A, International Crisis Group
Operationalizing workflow
No workflow has been explicitly linked to this obligation yet. See Workflows generally.
Illustrative cases
No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.
← Back to RegulationReport a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →