The Licence Exists and the Payment Still Fails: Humanitarian Carve-Outs, General Licences and the Control Nobody Built


Sanctions policy has spent the better part of a decade constructing carve-outs. The Security Council adopted a standing humanitarian exception across its asset freeze regimes. The European Union, the United Kingdom and the United States have each issued authorisations for humanitarian activity, medical supply, food and the work of non governmental organisations in jurisdictions that are otherwise comprehensively restricted. Read as a body of law, the position is now reasonably generous. Read as an operational outcome, the payment still fails.
The reason is a category mismatch that almost nobody in the policy debate names. A humanitarian exemption is a legal instrument addressed to the party conducting the activity. The thing that actually stops the payment is a screening engine addressed to names, jurisdictions and message strings, operated by an analyst working a queue against a service level. Nothing in the drafting of the exemption reaches into that queue. The carve-out changes what is lawful; it does not change what the system does, and it gives the analyst no mechanism for recording why an alert that matched correctly should nonetheless be released.
This post takes the exemptions as given and asks a narrower question: what has to exist inside a bank for a published carve-out to result in a payment reaching a hospital, and why, in most institutions we see, none of it does. Licences are unstructured text, expiry is untracked, and the exemption decision is a free text note in a case file that no report can count.
Regulatory and Market Context
The legal architecture has three layers and institutions routinely collapse them. At the top sits the United Nations humanitarian exception introduced by Security Council Resolution 2664 in December 2022, which carved out from the asset freeze measures of the Council's regimes the funds and services necessary to ensure the timely delivery of humanitarian assistance by the United Nations, its agencies and implementing partners, with the ISIL and Al-Qaida regime handled on a differently framed and time limited basis the Council has since revisited. Beneath it sit national and bloc implementations, because a Council exception does not self-execute: the European Union, the United Kingdom and the United States each gave effect to it through their own instruments, the United States largely through general licences issued by the Office of Foreign Assets Control. Beneath that again sit autonomous measures, which the Council exception does not govern at all, and which are most often the binding constraint on any given transaction.
The second distinction that matters operationally is between general and specific licences. A general licence is published, standing and self-executing for anyone within its scope, and almost always carries conditions: a defined permitted activity, described categories of counterparty, a start date, an expiry date, recordkeeping obligations and frequently a reporting condition requiring usage data to be returned to the issuing authority within a stated period. The Office of Financial Sanctions Implementation publishes numbered general licences on this model and grants specific licences on application to a named applicant for a narrowly described purpose; OFAC operates a comparable split. The critical point, which sanctions policies frequently misstate, is that a licence permits an act and obliges nobody to perform it. No regime compels a bank to process a payment merely because a licence exists, and that single fact is the space in which de-risking happens. FATF has examined the unintended consequences of its own standards, including financial exclusion and the treatment of the non profit sector, and both FATF and the Wolfsberg Group have been clear that wholesale withdrawal from humanitarian relationships is not a proportionate response. But a licence an institution cannot operationalise is, in its effect on an aid consignment, indistinguishable from one never granted.
What the Data Is Showing
The first finding from TrustSphere's sanctions engagement work is that the licence inventory does not exist. Asked to produce a current list of the general licences it relies upon, with issuer, reference, scope, permitted activity, conditions, expiry and a named owner, most sanctions functions cannot do it inside a week. The licences are known to individuals and sit as downloaded documents in a shared drive, referenced in the narrative text of an annually refreshed policy. There is no single artefact saying what the institution believes it is permitted to do.
The second finding concerns the release record, and it has the widest consequences. Where a payment that alerted correctly is nonetheless released under an exemption, the disposition is recorded as a free text note naming the licence in whatever form the analyst happened to write it. There is no coded field for the licence, none for the condition relied upon, and no linkage between the released message and the authority for the release. The institution therefore cannot say how many payments it released under a given licence, for what value, to which counterparties and in which period, which is the precise question a supervisor and the licence itself will eventually ask.
The third finding concerns expiry, amendment and the reporting conditions that depend on both. General licences are time limited and are amended, replaced and superseded, and almost no institution we have reviewed keeps a calendar for them with a named owner, a review date set before expiry and a defined action on lapse. The failure boards expect is continuing to release after expiry. The failure we see more often is the opposite: a licence is widened or replaced by a successor with broader scope, nobody notices, and the firm goes on refusing payments it has been expressly permitted to make, invisibly, because a refusal generates no alert and no exception report. Where a periodic usage return is required, the work begins when somebody remembers the obligation, and consists of querying case notes for text strings and assembling a figure that cannot be reproduced. Data never captured at the moment of decision cannot be reported reliably afterwards.
The fourth finding is that de-risking is measured at the wrong level, when it is measured at all. Exit decisions for humanitarian and non profit customers are taken at relationship level, on the basis of accumulated operational friction nobody has quantified: rejected payments, repeated information requests, investigation hours, correspondent queries. The committee sees a narrative about difficulty and an unfavourable revenue line, not the fact that the friction is generated by the absence of an internal control rather than by the customer's risk.
Implications for Financial Institutions
The first implication is that a licence must be represented as a structured object in the control estate rather than as a document. That object needs a stable internal identifier, the issuing authority and its own reference, the permitted activity in terms the operation can apply, the counterparty and jurisdiction scope, effective and expiry dates, the conditions attached, the reporting obligations with their due dates, the internal owner, and a version history recording every amendment and successor. It is a small data structure, and without it every other control here is impossible.
The second implication is that the release decision must be coded rather than written, and designed backwards from the return. When an analyst releases an alert under an exemption, the case must capture the licence identifier from the structured inventory, the specific limb or condition relied upon, the evidence supporting the conclusion that the transaction falls within scope, and the approver. Read the reporting condition first, determine which fields it requires, and build those into the release decision so that the return becomes a query rather than a project. A free text note is not an audit trail, because it cannot be aggregated, queried, reported, sampled or reproduced two years later. Institutions making this one change typically discover within a month that their actual licensed population differs materially from what they had assumed.
The third implication concerns the correspondent chain, and it is the hardest. A licence held by the originating institution does not travel with the payment. Intermediaries apply their own screening, under their own regimes, with their own appetite, and their analysts see a message that matched a list and no visible authority for release. The richer field set available under ISO 20022 makes it possible to carry a licence reference and a purpose code in a form a downstream system can read, which helps at the margin but does not resolve the problem, because a reference asserted by a sender is not evidence to a receiver. Institutions serious about humanitarian corridors should agree the treatment bilaterally with their correspondents in advance and in writing, rather than discovering the position payment by payment.
The fourth implication is that de-risking must become a priced and governed decision rather than a default. Before any humanitarian or non profit relationship is exited on financial crime grounds, the committee should see the operational cost quantified, the proportion of that cost attributable to missing internal capability rather than to customer risk, the licences that would have covered the activity, and the remediation option with its price. Exiting a sector because the institution never built a licence register is a decision, and it should be recorded as one.
Conclusion
The gap between a carve-out and a cleared payment is not a legal gap. It is a data and control gap, and it is small enough to be embarrassing. A licence register with expiry dates, a coded release reason, a reporting field captured at the point of decision and a named owner would resolve most of it, without a vendor, a programme or a regulatory change. It requires somebody to accept that a legal instrument sitting in a shared drive is not a control.
The wider point is about what the sanctions function measures. Screening metrics describe prohibition: alerts raised, alerts cleared, service levels met, payments stopped. Nothing in that reporting set describes permission, which is the other half of the regime and the half on which humanitarian access depends. Until an institution can report how many payments it released under licence, how many it refused despite a licence being available, and how many licences it allowed to lapse unnoticed, it does not know whether its sanctions programme is calibrated or merely restrictive. The carve-outs have been built. The control that would make them real, in most institutions, has not.
Suggested Next Steps
Build a structured licence register covering every general and specific licence the institution relies upon, carrying issuer reference, permitted activity, counterparty and jurisdiction scope, effective and expiry dates, attached conditions, reporting obligations with due dates, named internal owner and full version history.
Replace free text exemption notes with a coded release decision capturing the licence identifier, the condition relied upon, the supporting evidence and the approver, so that the licensed population can be counted, sampled and reported rather than reconstructed.
Read every reporting condition before it falls due, build the fields it requires into the release decision, and keep a calendar of licence expiry and review dates owned by a named individual with a defined action on lapse, amendment or replacement.
Require any proposed exit of a humanitarian or non profit relationship to come to committee with the operational cost quantified, the share of that cost attributable to missing internal capability, the licences that would have covered the activity, and a priced remediation option as the alternative to exit.
Sources: United Nations Security Council, Office of Financial Sanctions Implementation, Office of Foreign Assets Control, HM Treasury, EU Council and European Commission, Financial Conduct Authority, Prudential Regulation Authority, European Banking Authority, FATF, Wolfsberg Group, TrustSphere Risk Index, April 2026.
Companion vendor assessment: today's TrustSphere Risk Index post assesses Sigma360 against this problem. Read it at www.trustsphere.ai
TrustSphere helps financial institutions design and deploy intelligent fraud and financial crime detection solutions. Visit www.trustsphere.ai



Comments