
Top Compliance Risks Facing Global Trading Companies in 2026
Sanctions divergence, a reset CSDDD timeline and board-level customs exposure have turned trade compliance into a liquidity question, and the CFO now owns most of the controls that matter.
Global trade compliance risks in 2026 no longer arrive on a quarterly cadence. Law firms are publishing weekly sanctions updates because designations, delistings and general licences now land that often, and the three regimes that matter most to a trading house - the United States, the United Kingdom and the European Union - are pulling apart rather than converging. For a commodity or trading group, that combination turns compliance from a legal cost centre into a live constraint on cargo movement, bank lines and working capital.
Sanctions divergence is now the operating assumption
Through 2026, the practical problem is not whether a counterparty is sanctioned but by whom. Steptoe issued weekly sanctions updates dated August 10 and August 17, 2026, and Mayer Brown ran a parallel UK weekly covering the weeks of August 3 and August 10. Commentary from May through August 2026 has repeatedly flagged OFAC and OFSI announcements that do not mirror each other, and EU packages that land on their own timetable. The era in which a single consolidated screening list was a reasonable approximation of global exposure has ended.
The cost of that divergence falls on operations, not on the legal department. A cargo that is clean under EU rules may be unfinanceable if the confirming bank is US-nexus, and a payment routed through a London correspondent can stall on an OFSI designation that has no OFAC equivalent. Trading houses that built one screening rule set are now discovering that they need three, with jurisdiction-aware logic on the counterparty, the vessel, the flag, the insurer and the payment path.
The budgeting implication is straightforward. Screening technology, list ingestion and false-positive review all scale with the number of regimes maintained, not with headcount or revenue. CFOs approving 2027 compliance budgets should assume multiple, non-identical rule sets are permanent rather than a temporary feature of the current geopolitical cycle.
Omnibus I resets the CSDDD clock without removing the exposure
Directive (EU) 2026/470, the Omnibus I simplification of CSRD and CSDDD, was published in the Official Journal on February 26, 2026 and entered into force on March 18, 2026. It pushed transposition to July 26, 2028, with in-scope companies complying from a single date of July 26, 2029, and set a July 26, 2027 deadline for Commission guidelines on due diligence processes. Finance teams that had already provisioned for an earlier start now have a rephasing question rather than a cancellation.
Scope matters more than timing for most trading groups. CSDDD now captures EU companies with 5,000 or more employees and more than EUR 1.5 billion in net worldwide turnover, plus non-EU companies with more than EUR 1.5 billion of EU turnover. Turnover thresholds are unkind to trading businesses, where gross revenue can be enormous relative to margin and headcount. A group with a few hundred traders and thin percentage margins can clear the EUR 1.5 billion test comfortably.
Penalties follow the same logic. Maximum fines are capped at 3 percent of net worldwide turnover, reduced from the previous minimum maximum of 5 percent, and the EU-harmonised civil liability regime has been removed in favour of national law. Three percent of turnover in a business earning low-single-digit margins is not a fine, it is several years of profit. Modelling that number as a scenario, alongside the fragmentation risk created by national liability rules, belongs in the CFO's risk register now, not in 2028.
Customs and import enforcement has moved up the board agenda
Trade counsel have argued since February 2026 that customs and import compliance is a board-level risk rather than a logistics-desk task. Classification, valuation, origin and duty-preference claims are all judgment calls that sit inside operational systems, and they compound quietly. An incorrect tariff code applied consistently across thousands of entries becomes a multi-year retrospective assessment plus interest and potential penalties.
The defensive tool is disclosure, and it is time-sensitive. Prior-disclosure regimes generally reward companies that identify and report their own errors before an audit finds them, and the mitigation available drops sharply once an inquiry opens. That makes the decision to disclose a finance decision as much as a legal one, because it involves provisioning, timing and an assessment of what the group can prove about its own data.
Practically, this argues for a standing prior-disclosure playbook: who runs the review, what materiality triggers escalation, how the provision is booked, and who signs off. Trading groups that only build that process after receiving a customs inquiry tend to build it badly and expensively.
Third-party exposure and AML failures that scale with volume
Risk framing has shifted toward what Moody's and LexisNexis Risk Solutions describe as sanctions by extension: indirect exposure through counterparties, shadow-fleet vessels and opaque intermediaries. A trading company rarely deals directly with a designated party. It deals with a chartering agent, a ship manager, a blending facility or a payment intermediary that does. Screening the direct counterparty and stopping there leaves the largest part of the exposure unmeasured.
Enforcement continues to support the point. US sanctions and export-control activity stayed heavy through 2025, with at least one export-control resolution reported at roughly USD 140 million, and FinCEN imposed a record penalty on a broker-dealer in 2026. The lesson from the AML side is that failure now scales with transaction volume rather than with the size of the compliance team. High-volume, low-margin businesses are structurally exposed to that arithmetic.
The remedy is unglamorous data work. Counterparty master files need beneficial-ownership fields that are actually populated, vessel and voyage data need to be joined to the payment record, and refresh cycles need to be short enough to catch a designation between transactions. Most of that data sits in finance systems, which is why the control owner in practice is the CFO.
What CFOs should do before the 2027 budget cycle closes
Four actions carry most of the value. First, map group turnover against the EUR 1.5 billion CSDDD trigger and document the entity-level analysis, because scope disputes are easier to win with contemporaneous work. Second, run a scenario at 3 percent of group net worldwide turnover and show the board what that does to covenant headroom and liquidity. Third, fund divergent US, UK and EU screening logic explicitly rather than assuming one global list will hold. Fourth, stand up the prior-disclosure playbook for customs errors.
There is also a treasury dimension that often gets missed. Banks reprice or withdraw trade finance lines on compliance concerns faster than regulators impose penalties, and a withdrawn confirmation facility hits liquidity in days. Compliance quality is therefore an input into the cost and availability of working capital, which makes it a legitimate item for the CFO's own agenda rather than a delegated one.
Key takeaways
- Directive (EU) 2026/470 entered into force March 18, 2026, moving CSDDD transposition to July 26, 2028 and compliance to a single date of July 26, 2029.
- CSDDD penalties are capped at 3 percent of net worldwide turnover, down from a previous 5 percent floor on maximums, with civil liability returned to national law.
- Scope covers EU companies with 5,000+ employees and over EUR 1.5 billion turnover, plus non-EU companies with over EUR 1.5 billion of EU turnover, capturing most large trading groups.
- US, UK and EU sanctions regimes are diverging, so a single global screening list no longer approximates real exposure.
- Banks can pull trade finance lines on compliance concerns faster than regulators act, making compliance quality a liquidity variable.


