
On 23 July 2026, the EU adopted its 21st package of sanctions against Russia: 218 new individual listings, the most in four years. For the maritime sector, its significance lies less in the numbers than in reach. For the first time, the listing criteria capture the vessels and companies that service the shadow fleet (bunkering, crewing and management) alongside refineries, oil traders, ports and the banks behind freight and energy flows. Compliance now depends on the network around a vessel, counterparty or payment, not the contracting party alone.
Energy & Maritime Trade
The oil price cap's automatic adjustment is paused until 15 July 2027. Transaction bans now cover two Russian ports, four airports and, for the first time, refineries processing Russian crude. Georgia's Kulevi refinery is the first listed. Eighteen oil-sector entities, three Russian refineries, a major Belarusian refinery and five oil traders were designated, with new LNG notification obligations added.
Shadow Fleet & Service Providers
41 more tankers listed, bringing the total to 673. Listing criteria now extend to vessels that service the shadow fleet. Five bunkering vessels, eight companies and a crewing agency were named. Providing fuel, crew, management or support to a sanctioned vessel now carries direct exposure. Bunker stems, STS transfers and last-minute vessel substitutions are red-flag triggers.
Banking & Payments
More than 100 Russian banks now face transaction bans: 94 with asset freezes, 33 newly added, plus a prohibition on financial-messaging services. Correspondent and beneficiary banks handling freight, hire, demurrage and fuel payments must be screened. Non-Russian banks, including a Kyrgyz bank tied to Russia's SPFS system, were listed for circumvention. Crypto-asset services used for evasion are also now restricted.
Trade & Circumvention
56 listings target the military-industrial complex, with wider export bans and new import bans on metal ores. A further 51 entities joined the dual-use control list (27 based outside Russia, in China, Türkiye, Kyrgyzstan, India, Kazakhstan and the UAE) underlining the focus on circumvention networks. The EU also strengthened protection for EU operators against retaliatory Russian litigation.
What Regulators Expect — and What Organisations Must Check
Enforcement increasingly turns on indirect exposure. A counterparty may appear on no list yet still be owned or controlled by a designated party, act on its behalf, or service a sanctioned vessel or trade. Regulators expect firms to look through the contracting party to ownership and control, associated companies and vessels, managers, charterers, beneficial owners, banks and intermediaries, and to watch for changes in flag, management, routing or ownership. Name screening confirms only that a name is not designated today; on its own, it is no longer sufficient.
Before Approving Any Transaction
Screen vessels by IMO number (not name alone), counterparties, directors, beneficial owners and banks against current EU, OFAC, UK and UN lists
Review ownership and control beyond the contracting party, applying thresholds such as the OFAC 50% rule
Check for links to sanctioned vessels, shadow-fleet networks, designated ports, refineries, oil traders or banks
Examine vessel history: prior names, flag changes, AIS gaps, dark activity and STS transfers in high-risk areas
Assess the source, routing, documentation and parties behind each cargo, energy or payment flow
Record results, evidence, timestamps and decisions, and keep monitoring after onboarding
Key Compliance Takeaways
Name screening is a starting point, not a conclusion
Indirect ownership and control now drive exposure.
Service providers are in scope
Bunkering, crewing, management and logistics to a sanctioned vessel carry direct risk.
Third-country intermediaries and banks
A primary circumvention channel: screen the whole chain.
Monitor continuously
A clean counterparty can become exposed through a new listing, ownership change or associated vessel.
Keep a defensible, timestamped record
Document what was checked, when and why.
Moving Forward: Continuous Due Diligence and How Marcura Compliance Can Help
Due diligence can no longer be a one-off gate at onboarding. Firms should widen their checks, review existing customers and suppliers as well as new ones, and connect counterparty, vessel, ownership, financial and operational data so a risk signal (a flag change, a new bank, an associated vessel) surfaces before a deal proceeds. Regulatory change is constant: a party that looked acceptable at onboarding can become exposed overnight through a new listing, ownership change or service relationship.
Networked Risk Intelligence
Marcura Compliance is built for networked risk. Powered by a maritime data ecosystem spanning millions of counterparties and vessels, it brings counterparty, vessel and ownership information into a single workflow: digital onboarding and KYB, real-time sanctions and risk screening, and beneficial-ownership analysis aligned to the OFAC 50% rule.
Vessel Evasion Detection
For vessels, Marcura Compliance screens ownership, associated parties and historical routes, surfacing evasion indicators such as AIS manipulation, undisclosed ship-to-ship transfers and flag-hopping, the precise signals that regulators now expect firms to detect and document.
Continuous Monitoring & Audit Trail
The platform provides continuous monitoring and alerts, document collection and verification, configurable escalation and approval workflows, and a full timestamped audit trail, replacing fragmented, manual processes with a clearer, shared view of the parties and assets behind every transaction.
The 21st package makes one thing plain: static list screening is no longer enough. Exposure now flows through the wider network around a counterparty, including its owners, vessels, banks, service providers and payment routes, and that network shifts constantly. Speak with the Marcura Compliance team to review or strengthen your sanctions and counterparty-risk processes.
This article is provided for general information and thought-leadership purposes only. It does not constitute legal or compliance advice. Organisations should verify designations against the official consolidated sanctions lists and take professional advice on their specific circumstances. Sources: Council of the European Union, press release, 23 July 2026; European Commission, press release IP/261680, 23 July 2026; Marcura Compliance.

Read more
recent news

New guide
Take control of Procure-to-Pay
Why invoice control breaks down between PO and payment — and how leading ship managers close the gap. Free guide, plus two diagnostic tools.









