Sanctions Compliance in France: Complete Business Guide

This guide explains how French businesses can manage sanctions risk through screening, beneficial ownership checks, export controls, payment reviews, due diligence, licensing, training and continuous monitoring of EU restrictions. 

**Alt text:** EU sanctions France compliance guide showing a Paris office, Eiffel Tower, compliance checklist, legal books, and laptop with regulatory symbols.

A transaction that appeared lawful yesterday may become restricted after a new designation, ownership change, or amendment to an EU sanctions regulation. A French company may suddenly find that it cannot deliver goods, receive payment, provide software access, or continue supporting a long-standing customer.

EU sanctions France compliance is the process through which a business identifies, prevents, and manages transactions prohibited or restricted under EU and French sanctions rules.

It is what protects a company from supplying funds, products, technology, or services to sanctioned parties. It is why businesses must examine beneficial ownership, end users, payment routes, and delivery destinations rather than checking customer names alone. It is also why sanctions compliance affects manufacturers, exporters, technology companies, consultancies, financial institutions, logistics providers, and SMEs, not only banks.

In this guide, you will learn how sanctions apply to businesses in France, which authorities and sanctions lists matter, how to build a complete compliance programme, how export controls interact with sanctions, and when OFAC restrictions may become relevant to a French company.

What Is Sanctions Compliance?

EU sanctions France review framework showing four key questions: who, what, where and why, covering counterparties, products, destinations and intended use.

Sanctions compliance is the system of governance, due diligence, screening, controls and documented decisions used to prevent prohibited dealings with designated individuals, organisations, governments, sectors, regions, vessels and other restricted parties.

Sanctions can freeze assets, prohibit funds from being made available, restrict imports or exports, prevent investments and limit access to particular financial, professional or technical services. The restrictions differ between regimes, so businesses must examine the legal measure applying to the particular transaction.

A company may face a sanctions problem even when its direct customer does not appear on a sanctions list. The customer may be owned or controlled by a designated person. The goods may be restricted because of their technical characteristics. The service may be prohibited because of the recipient’s location or sector. The payment may also involve a sanctioned bank or another restricted intermediary.

A proper sanctions review must therefore answer four fundamental questions:

  • Who are the parties and their owners?

  • What products, technology, funds or services are involved?

  • Where will the transaction, delivery, payment or performance take place?

  • Why is the customer purchasing the product or service, and what is its intended end use?

The EU Sanctions Helpdesk uses a similar practical approach to help European SMEs understand the parties, products, locations and purposes involved in a transaction. It also offers compliance resources and personalised support for businesses conducting sanctions due diligence.

Why Sanctions Compliance Matters for French Businesses

A sanctions violation can occur before a product reaches its final destination. Accepting an order, receiving an advance payment, providing technical information or granting access to a digital platform may already involve restricted activity.

Banks and customs authorities provide important safeguards, but they do not replace the company’s own responsibilities. A bank may process a payment without knowing the end use of the goods. Customs may review an export declaration without having access to all beneficial ownership information. The business itself usually has the fullest understanding of the commercial relationship.

Sanctions compliance also protects the organisation from major operational disruption. A weak programme can lead to payments being frozen, goods being detained, licences being delayed, customer relationships being terminated and senior managers being unable to explain why a transaction was approved.

The consequences extend beyond formal penalties. A business may lose access to banks, insurers, investors, public contracts and international partners if it cannot demonstrate effective controls.

For French SMEs, the objective is not to create a compliance department comparable to that of a global bank. It is to establish controls that are proportionate to the company’s actual countries, customers, products, services and transaction methods.

The Legal Framework for EU Sanctions in France

European Union sanctions are commonly adopted through Common Foreign and Security Policy decisions and implemented through EU regulations. The regulations create legally binding obligations within their scope and apply directly across EU Member States, including France.

Some regimes implement resolutions adopted by the United Nations Security Council. Others are autonomous EU measures responding to issues such as human rights abuses, cyberattacks, terrorism, weapons proliferation or threats to the sovereignty of another state.

Sanctions may be country-based, thematic or targeted. A country appearing on an EU sanctions page does not necessarily mean that every form of trade with that country is prohibited. One regime may target a limited group of officials, while another may contain extensive financial, trade, transport and service restrictions.

The European Commission’s overview of EU sanctions and related resources links businesses to current regimes, guidance and the EU Sanctions Map. The legal text of the relevant regulation should always be reviewed before the company makes a final decision.

French national measures may also impose asset freezes in specific circumstances. Businesses operating in France must therefore consider both applicable EU measures and national French freezing measures.

Directive (EU) 2024/1226 establishes EU minimum rules on criminal offences and penalties for violating Union restrictive measures. It covers conduct such as failing to freeze assets, making funds available to designated parties, prohibited trade and certain forms of circumvention. It also requires Member States to provide for liability and penalties involving legal persons.

Which French Authorities Are Involved?

Direction générale du Trésor

The Direction générale du Trésor, commonly known as the DG Trésor, is the principal French authority responsible for financial sanctions and asset-freezing measures. It publishes information on international sanctions regimes, maintains the Registre national des gels and receives reports concerning suspected violations of European or French restrictive measures.

The national register identifies individuals, entities and vessels subject to asset-freezing measures applicable in France. Businesses should consult the current register when screening customers, suppliers, beneficial owners and other transaction parties rather than depending on an old downloaded sanctions list.

Some EU sanctions regulations permit transactions only after the competent national authority has granted an authorisation. In France, businesses can use the DG Trésor sanctions portal to review applicable financial sanctions, access the national register and obtain information about authorisation procedures. A transaction requiring prior approval must not proceed until the relevant authorisation has been granted.

French Customs

The Direction générale des douanes et droits indirects plays a central role in enforcing trade restrictions, embargoes and controls affecting goods moving across borders.

French Customs provides guidance on commercial restrictions, controlled products and embargoes. Its resources cover measures such as arms embargoes, restrictions on internal repression equipment, prohibitions on dual-use goods, advanced technology and products supporting sensitive economic sectors.

Service des biens à double usage

The Service des biens à double usage, or SBDU, is the French authority responsible for examining applications and issuing licences involving controlled dual-use items. These are products, software and technologies that may have both civilian and military applications.

French exporters should determine whether an item is listed under the EU Dual-Use Regulation or subject to a catch-all control because of its intended destination or end use. The review should be completed by someone who understands the item’s technical specifications, since a commercial description or customs code may not provide enough information.

The French Customs guidance on dual-use goods and technologies explains the applicable export formalities and the relationship between customs procedures and EU dual-use controls. A dual-use authorisation does not automatically remove separate sanctions restrictions, and a sanctions authorisation does not necessarily replace an export licence.

Sector Regulators

Regulated financial and insurance businesses may also be supervised by authorities such as the ACPR. Other regulators or ministries may become relevant depending on the goods, services and industries involved.

A commercial business should not assume that its bank or freight forwarder will make the final legal decision. Each organisation remains responsible for its own conduct and should know which authority to approach when a transaction requires clarification or authorisation.

Which Businesses Need a Sanctions Compliance Programme?

Any company with international customers, suppliers, payments, technology transfers or distribution channels should assess its sanctions exposure.

Exporters and manufacturers face clear risks because products may be prohibited, licensed or diverted to restricted end users. Technology businesses must consider software access, cloud services, technical support and the electronic transfer of controlled information.

Professional service firms may face restrictions on legal, accounting, consulting, engineering, architecture, IT or business services. Logistics companies must screen cargo, routes, consignees, freight partners and vessels. Online marketplaces may need to prevent sanctioned parties from opening accounts or using their platforms.

Businesses operating only in France may still face exposure. A French supplier may be owned by a designated person, a domestic payment may benefit a restricted entity, or a customer may request delivery through a French intermediary for onward export.

The correct question is therefore not whether the business considers itself international. It is whether its funds, goods, technology or services could directly or indirectly reach a sanctioned party, destination, sector or prohibited use.

Types of Sanctions Affecting French Companies

Asset Freezes

An asset freeze prevents funds or economic resources belonging to, owned, held or controlled by a designated party from being moved, transferred, altered or used.

The rules can also prohibit making funds or economic resources available, directly or indirectly, to or for the benefit of a designated party. Economic resources may include property, goods, contractual rights, securities and other assets that could be used to obtain funds or services.

The French National Asset Freeze Register identifies persons, entities and vessels subject to freezing measures applicable in France. The DG Trésor regularly updates the register, which means companies should not rely on an old downloaded copy as their only screening source.

Trade Restrictions and Embargoes

Trade sanctions can restrict the sale, supply, export, import, purchase, transfer, brokering or transit of particular products.

The measures may cover military equipment, dual-use items, advanced technology, luxury goods, energy products, metals, transport equipment and products capable of supporting sensitive industries.

A business must identify the regulation, relevant annex, customs classification, technical characteristics and intended destination. A general description such as “industrial component” is not enough to determine whether a product is restricted.

Financial Restrictions

Some sanctions restrict access to capital markets, lending, securities, deposits, payment services, investments or transactions involving specified financial institutions.

A lawful sale may still encounter a restricted payment route. The payer, beneficiary, banks, currency and payment intermediaries may all require review.

Businesses should not attempt to redesign a payment merely because the original transfer was rejected. Changing the bank, payer or currency without understanding the reason for the rejection can create circumvention risk.

Service Restrictions

Sanctions can restrict the provision of professional, financial, technical, engineering, software, business or consulting services.

The restriction may apply even when no physical product leaves France. Remote support, software updates, cloud access, technical documentation and online consulting can all constitute services or assistance.

Sectoral Restrictions

Sectoral measures affect defined industries, activities or transactions rather than every business connected to a country.

A customer may be absent from the sanctions list but still operate in a restricted sector. Compliance teams must therefore understand the customer’s activities, the project and the purpose of the transaction.

How to Build a Sanctions Compliance Programme

A complete business compliance guide must move beyond legal descriptions and show how controls operate in daily business. The following structure can be adapted to an SME, larger company or regulated organisation.

Step 1: Appoint a Sanctions Compliance Owner

Senior management should appoint a person with responsibility for the sanctions programme. This may be a compliance officer, legal manager, export control specialist or another appropriately trained employee.

The owner must have enough authority to pause transactions and request information. A sanctions decision should not be overridden informally by a sales manager because a customer is important.

The appointment should be documented. The organisation should also identify a backup decision-maker for urgent cases when the primary owner is unavailable.

Management should receive periodic information on high-risk transactions, confirmed matches, licence applications, overdue reviews and major regulatory developments.

Step 2: Conduct a Business-Wide Sanctions Risk Assessment

The risk assessment should describe how sanctions exposure arises across the company.

Geographic risk includes customer locations, supplier locations, shipping routes, delivery countries, payment origins and the operations of subsidiaries and distributors.

Customer risk includes ownership transparency, government connections, sector, use of intermediaries and previous reluctance to provide information. Product risk includes technical capabilities, military or dual-use potential, portability and ease of diversion.

The company should also examine how it sells. Direct sales provide more visibility than multi-level distribution. Online sales can increase volume while reducing personal contact. Agents and resellers can create indirect exposure where the final end user is unclear.

The completed assessment should classify business activities into risk levels. Low-risk domestic transactions may follow a simplified process. High-risk exports, opaque ownership structures and sensitive products should receive enhanced review and senior approval.

The assessment should be reviewed when the business enters a new market, launches a product, appoints a distributor or experiences a significant sanctions incident.

Step 3: Create a Written Sanctions Policy

The sanctions policy should convert legal obligations into clear internal rules.

It should explain which sanctions regimes the organisation considers, who must be screened and when screening occurs. It should describe ownership checks, export control classification, alert investigation, transaction holds and authority contact.

The policy should state that employees must not continue a transaction while a material sanctions concern remains unresolved. It should prohibit attempts to alter documents, routes, payment instructions or counterparties to avoid restrictions.

The policy must reflect real business operations. A copied global policy may refer to systems, departments or approval processes that do not exist within the company.

Employees should know where to find the policy, who to contact and what information to provide when escalating a concern.

Step 4: Collect Reliable Counterparty Information

Screening quality depends on the information collected before screening begins.

For companies, the organisation should normally obtain the complete legal name, trading names, registered address, company number, country of incorporation and relevant ownership details. For individuals, useful identifiers may include full name, date of birth, nationality, address and official identification information where appropriate.

The company should understand the party’s commercial role. A buyer, distributor, payment intermediary and final end user create different risks.

Information should be verified through reliable documents or sources. A self-declaration may support the review, but it should not be the only evidence in a higher-risk relationship.

If the counterparty refuses to provide basic ownership or end-use information, the organisation should not treat the absence of information as confirmation that no risk exists.

Step 5: Screen All Relevant Parties

Screening should not stop with the name written on the contract.

Depending on risk, relevant parties may include the customer, supplier, beneficial owners, directors, authorised signatories, agents, distributors, freight forwarders, banks, consignees, vessels and end users.

Screening should occur before onboarding or contractual commitment where possible. It should also occur before sensitive transactions and when lists or ownership details change.

A company operating in France should use the French National Asset Freeze Register and relevant EU lists as primary sources. Foreign lists, including OFAC, may be relevant where the transaction creates a connection to another jurisdiction.

The system should identify spelling variations and aliases without producing an unmanageable number of alerts. Screening settings should be tested and adjusted according to the languages, countries and names present in the company’s customer base.

Step 6: Identify Beneficial Ownership and Control

A company may be affected by an asset freeze even when its own name is not listed.

The compliance team must identify individuals and entities that directly or indirectly own the counterparty. It should also examine whether a designated person can exercise control through voting rights, management appointments, contractual influence or other arrangements.

Ownership should be traced through every level of the structure. Percentages should be calculated rather than estimated, and supporting evidence should be retained.

Control requires a factual assessment. A designated person may transfer shares but continue to direct management, use assets or make important decisions. A recent restructuring should therefore be examined carefully.

Where the structure cannot be understood, the relationship should remain unapproved. Commercial urgency does not replace reliable beneficial ownership information.

Step 7: Classify Products, Software and Technology

Sanctions screening and export classification are separate but connected controls.

The product review should identify the customs code, technical specifications, origin and possible classification under the EU dual-use list or a sanctions annex.

The EU Dual-Use Regulation controls exports, brokering, technical assistance, transit and transfers involving listed dual-use items. French Customs explains that these controls support efforts against conventional weapons proliferation and weapons of mass destruction.

Classification should be conducted by someone capable of understanding technical performance. Product names and marketing descriptions rarely provide enough information.

Software, source code, technical drawings and electronic support must also be assessed. A controlled technology transfer may occur through email, remote access, shared platforms or a technical meeting.

Classification decisions should be recorded and reviewed after product changes or regulatory updates.

Step 8: Check the Destination, End User and End Use

EU sanctions France assessment framework showing product classification, destination and end-use checks for a French exporter before delivery to an end user.

The company must establish where the product or service will ultimately go, who will use it and for what purpose.

A distributor’s address is not necessarily the final destination. The business should request the ultimate consignee, installation location, end user and intended application.

An end-user certificate can support the review, but it should be compared with other facts. The declared use should make sense for the customer’s business, technical capacity and order history.

Enhanced due diligence may be necessary when a newly formed trading company orders advanced equipment, a customer cannot identify the installation site or goods are routed through an unexpected third country.

For high-risk transactions, the organisation may require proof of delivery, contractual resale restrictions and post-transaction verification.

Step 9: Review Payments and Financial Intermediaries

The finance function should confirm that the person making the payment is connected to the underlying transaction.

Payments from unrelated third parties, different jurisdictions or multiple accounts require explanation. The organisation should also review the beneficiary bank and other financial institutions involved.

A sudden request to change the currency or avoid a particular bank may have a legitimate explanation. It may also indicate an attempt to bypass financial restrictions.

Finance employees should not resubmit a rejected transfer through another channel until compliance has identified why the original payment failed.

Bank screening does not replace counterparty or product due diligence. A bank may process a transaction without knowing that the goods will be diverted to a prohibited destination.

Step 10: Review Shipping Routes and Logistics Parties

The shipping route should be consistent with the customer, destination and commercial purpose.

An indirect route may be reasonable because of cost, infrastructure or transport availability. However, unexplained routing through a high-risk transshipment country should trigger additional questions.

The business should screen relevant freight forwarders, carriers, consignees, warehouses and vessels. Maritime transactions may require vessel identification numbers because names and flags can change.

Shipping documents should be compared for consistency. The invoice, packing list, export declaration and transport document should identify compatible parties, products, quantities and destinations.

Last-minute requests to change the consignee or remove end-user information should cause the shipment to be paused.

Step 11: Investigate Sanctions Alerts

EU sanctions France screening alert workflow showing how to compare identifiers, resolve false positives, request more information, escalate matches and stop transactions when required.

A screening alert is not automatically a true sanctions match.

The reviewer should compare all available identifiers, including legal name, aliases, date of birth, nationality, address, registration number and ownership information.

A clearly different person or company can be documented as a false positive. Where identifiers are incomplete or conflicting, the reviewer should obtain additional information before closing the alert.

Potential ownership or control cases require a separate analysis. The compliance team should document the ownership chain, control indicators and legal reasoning used.

Higher-risk alerts should receive a second review. Employees who generated the commercial relationship should not make the final sanctions decision without independent oversight.

Every outcome should be recorded so that an auditor can understand why the alert was released, escalated or confirmed.

Step 12: Manage a Confirmed Sanctions Match

When the company confirms a sanctions match, it should stop the affected transaction immediately.

Employees should not deliver goods, release services, return funds or contact the party with informal assurances. These actions may involve dealing with frozen assets or making economic resources available.

The matter should be escalated to the sanctions owner and legal function. The organisation should identify the exact legal measure and determine whether it requires an asset freeze, reporting, rejection, authorisation or another response.

Relevant documents should be preserved, including screening results, contracts, invoices, payments, shipping documents and communications.

The DG Trésor should be contacted where the applicable financial sanctions framework requires notification, guidance or authorisation. The company should obtain specific legal advice when the status of funds or goods is unclear.

Step 13: Obtain Authorisation, Keep Records and Test the Programme

Where a sanctions regulation requires prior approval, the business must not proceed until authorisation has been granted. France’s DG Trésor sanctions tele-service allows companies to submit transaction authorisation requests and supporting documents securely. The application should identify the parties, goods or services, end use, payment route and relevant legal provision. Any conditions, reporting duties or validity limits attached to the authorisation must be followed carefully.

The organisation should retain enough evidence to explain every sanctions decision. Relevant records may include screening results, beneficial ownership documents, product classifications, end-user certificates, licences, alert investigations, authority communications and internal approvals. A simple note stating “checked and approved” is not sufficient to show what was reviewed or why the transaction was accepted.

Employees should also receive training based on their roles. Sales teams need to recognise unusual customer requests, finance teams should identify suspicious payment changes, and logistics teams must understand destination and shipping-document risks. The programme should be tested through periodic audits, transaction samples and realistic alert exercises. The European Commission’s sanctions due-diligence guidance provides practical advice on risk assessment, business-partner checks, transactions, goods and circumvention warning signs.

Export Controls Compliance for French Businesses

Export controls require businesses to understand what they are transferring, not only who will receive it.

A company should begin by determining whether the product, software or technology appears on the EU dual-use list or a sanctions annex. It should also consider military classifications, catch-all controls and end-use restrictions.

French Customs is responsible for implementing EU controls affecting dual-use goods and technologies. Exporters may need prior authorisation, and particular sanctions regimes may impose additional prohibitions or derogation requirements.

The export process should include technical classification, country review, end-user due diligence, licence assessment and customs documentation.

Where both export control and sanctions authorisations are required, the company must obtain each applicable approval. One authorisation should not be assumed to replace another.

The review should cover intangible transfers. Providing controlled source code, technical drawings or remote access to a recipient outside the EU may create an export even when no physical shipment occurs.

Export control decisions should be made before production and delivery commitments. This reduces the risk of completed goods being detained while the company searches for a licence.

90-Day Implementation Roadmap

Days 1 to 30: Map the Risk

The company should identify its countries, counterparties, products, services, payment routes and distribution channels.

It should appoint a programme owner, identify urgent high-risk relationships and review whether existing customer information is sufficient for screening and ownership checks.

Days 31 to 60: Build the Programme

Management should approve the risk assessment, policy, screening workflow and escalation process.

The company should classify products, establish export licence controls, update contracts and create procedures for alerts, confirmed matches and authority applications.

Days 61 to 90: Train and Test

Employees should receive role-specific training. The company should test the programme using scenarios involving a sanctioned customer, restricted product, unusual payment and changed delivery destination.

A sample of existing relationships should be reviewed. Management should receive a report identifying implemented controls, unresolved weaknesses and future monitoring responsibilities.

Complete Business Sanctions Compliance Checklist

Use the following checklist during an internal compliance review:

  1. Senior management has approved the sanctions programme and appointed a responsible owner.

  2. The company has documented its geographic, customer, product, service, payment and delivery risks.

  3. A written sanctions policy explains screening, escalation and transaction holds.

  4. Reliable identity and ownership information is collected before approval.

  5. Customers, suppliers, owners and relevant transaction parties are screened.

  6. Ownership and control are assessed rather than relying on name screening alone.

  7. Products, software and technology are classified for export control purposes.

  8. Destination, end user and end use are verified for higher-risk transactions.

  9. Payment parties, banks and unusual payment arrangements are reviewed.

  10. Shipping routes, freight providers, vessels and consignees are checked when relevant.

  11. Alerts are investigated using complete identifiers and documented reasoning.

  12. Confirmed matches are stopped and escalated immediately.

  13. Required DG Trésor authorisations and export licences are obtained before activity begins.

  14. OFAC exposure and possible EU Blocking Statute conflicts are assessed.

  15. Contracts allow suspension, information requests and termination where necessary.

  16. Screening results, licences, decisions and authority communications are retained.

  17. Employees receive training based on their responsibilities.

  18. The programme is tested through audits, sample reviews and incident exercises.

  19. Counterparties are rescreened when lists, ownership or transaction details change.

  20. Management receives regular reporting on risks, alerts, licences and corrective actions.

Key Takeaways

EU sanctions France compliance is an operational business responsibility, not only a legal research or name-screening exercise.

French companies must understand the parties, ownership, products, services, destinations, end uses, payments and logistics involved in each higher-risk transaction.

The French National Asset Freeze Register, EU Sanctions Map, DG Trésor resources and French Customs guidance should form part of the organisation’s official source framework.

Export controls and sanctions must be assessed together. A product may require a licence without involving a listed party, while a non-controlled product may still be prohibited under a sanctions regulation.

OFAC may matter where a French transaction has a US connection, but companies must also consider the EU Blocking Statute and possible conflicts between legal regimes.

The most effective programme is proportionate to the business. It combines management accountability, reliable information, documented decisions, trained employees and regular testing.

Conclusion

Sanctions compliance is now a central requirement for French organisations participating in international business.

The greatest risks are often indirect. An unlisted customer may be controlled by a designated owner. An ordinary commercial item may be diverted to a prohibited end user. A service delivered online may fall within a sectoral restriction. A payment may involve an unexpected sanctioned intermediary.

A complete business compliance programme allows the organisation to detect these issues before signing a contract, accepting funds or delivering goods and services.

The programme should begin with a risk assessment and continue through customer onboarding, ownership checks, product classification, transaction monitoring, escalation, recordkeeping and audit.

Sanctions lists and regulations change regularly. Counterparties, owners, banks and delivery routes can also change during an existing relationship. Compliance must therefore operate continuously rather than as a one-time onboarding check.

French organisations that follow the framework in this guide will be better prepared to protect their operations, respond to regulatory questions and make defensible commercial decisions.

For structured professional development, explore the French Compliance Institute’s Certificate in Sanctions Compliance .

Frequently Asked Questions

A French business should review the French National Asset Freeze Register and relevant EU sanctions lists and regulations. Foreign lists such as OFAC may also matter where the transaction has a connection to another jurisdiction.

The exact control depends on the organisation’s risk and applicable obligations. However, a company must have an effective method for preventing prohibited dealings. Risk-based screening is an important part of demonstrating that method.

No. OFAC does not automatically apply to every French transaction. It may become relevant through US persons, US operations, US-origin products, technology or financial channels.

No. Sanctions restrict particular parties, countries, sectors or activities. Export controls regulate goods, software and technology based on classification, destination and end use. A transaction may be subject to both.

The company should pause the affected activity, collect identifying information and investigate whether the alert concerns the same person or entity. It should not release the transaction until the concern has been resolved.

The company should stop the transaction, preserve relevant records, identify the applicable legal measure and escalate the matter to compliance and legal specialists. It may also need to freeze assets or contact the DG Trésor.

No. Where prior authorisation is required, the company should wait until the competent authority has granted it and should follow all conditions attached to the decision.

Rescreening should occur when sanctions lists change, ownership changes, the transaction risk increases or another material event occurs. High-risk relationships may also require periodic scheduled reviews.

The frequency should reflect the company’s risk. Higher-risk exporters and internationally active businesses should test their controls regularly and after important regulatory or operational changes.