Cross-Border Regulatory Review Process: What Counsel Must Do
A cross-border regulatory review process is the coordinated set of legal, procedural, and compliance steps that counsel and compliance teams must complete to obtain clearance from multiple national or supranational authorities before closing a transaction or operating across jurisdictions. Three actions should happen before anything else: (1) map your ownership structure and identify every jurisdiction where a filing trigger plausibly exists — covering merger control, FDI/national security screening, and sanctions; (2) centralize core diligence documents in a single, access-controlled repository so they are ready for parallel regulator requests; and (3) designate a single internal filing owner with a master timeline that accounts for the longest-running review clock.
The scope is wider than most deal teams initially assume. A single transaction can simultaneously trigger:
- CFIUS (Committee on Foreign Investment in the United States) review for national security implications of foreign ownership
- European Commission merger control and the EU FDI cooperation mechanism for transactions with EU-wide effects
- OFAC (U.S. Office of Foreign Assets Control) sanctions screening for counterparty and ownership chain exposure
- FATF (Financial Action Task Force) AML/CFT standards compliance, particularly for financial services and payment intermediaries
- FSB (Financial Stability Board) data-framework and supervisory expectations for cross-border payment service providers
Missing even one of these can delay closing, expose the transaction to post-closing unwinding, or generate enforcement liability. The rest of this guide explains exactly how to manage each one.
Table of Contents
- What does the cross-border regulatory review process actually cover?
- Which regulatory authorities should you be tracking?
- How do you coordinate filings across multiple jurisdictions?
- What compliance issues most often complicate cross-border reviews?
- A step-by-step checklist for before, during, and after a cross-border review
- Who should be involved, and how should governance be structured?
- What do you do when jurisdictions reach different conclusions?
- What recent policy changes should US companies be tracking?
- Key Takeaways
- The part of cross-border reviews most counsel underestimate
- Jarel gives legal teams a single workspace for the entire review
- Useful sources
- FAQ
What does the cross-border regulatory review process actually cover?
The phrase “cross-border regulatory review” covers several distinct review types that can run in parallel. Knowing which category applies to your transaction is the first classification step.
Merger control and antitrust reviews assess whether a transaction substantially lessens competition in a relevant market. Thresholds are jurisdictional and turn on turnover, market share, or deal value. A transaction can clear in one jurisdiction and face a Phase II investigation in another.
FDI and national security screening focuses on who owns the acquirer, not just market structure. CFIUS in the US and equivalent bodies in EU member states examine whether a foreign government, state-owned enterprise, or entity with ties to a foreign adversary would gain control over critical infrastructure, technology, or data.
Foreign subsidies screening is a newer EU-specific category. The EU Foreign Subsidies Regulation allows the European Commission to investigate whether a non-EU government subsidy distorts competition in the EU market, including in M&A contexts.
Sectoral regulatory reviews apply in regulated industries: banking and payments (central banks, the Federal Reserve, OCC, ECB), telecoms, energy, and healthcare. These reviews often run on separate tracks with different decision-makers and timelines.
Export controls and sanctions are not filing-based in the traditional sense, but they function as a parallel review stream. OFAC, the Bureau of Industry and Security (BIS), and equivalent foreign authorities can block or condition a transaction based on counterparty identity or the technology being transferred.
Data transfer and privacy reviews arise when a transaction involves personal data flows across borders, triggering GDPR adequacy requirements in the EU, state-level privacy laws in the US, or data-localization requirements in other markets.
When multiple review types overlap, sequencing matters. Merger control and FDI reviews often run simultaneously, but a sanctions issue that surfaces mid-review can freeze everything else. Identify overlaps early and build contingency time into the master timeline.
Which regulatory authorities should you be tracking?
The authorities below represent the core directory for US-centered cross-border transactions. Each has a distinct remit, and knowing who makes the final call versus who merely comments shapes your engagement strategy.
-
CFIUS — reviews foreign investments in US businesses for national security risk. It has authority to block, condition, or unwind transactions. Non-US government links, investments in critical infrastructure or technology, and access to sensitive personal data are the most common triggers. CFIUS makes final decisions subject to presidential review.
-
FSB develops policy recommendations on cross-border payments, data frameworks, and supervisory consistency. Its recommendations on harmonized data frameworks and the “same activity, same risk, same rule” principle directly affect how payment service providers are supervised across jurisdictions.
OECD analysis confirms that international regulatory cooperation reduces fragmentation, but national political drivers mean divergent outcomes remain a real risk even when frameworks are nominally harmonized.
How do you coordinate filings across multiple jurisdictions?
The core principle is simple: file simultaneously where possible, and never let one jurisdiction’s clock run ahead of another’s without a deliberate reason. In practice, this requires a filing matrix built before signing.
Building your filing matrix
Map every jurisdiction where a filing trigger exists, then classify each as mandatory (hard legal obligation), voluntary but advisable (call-in risk is high), or monitor-only (low probability but worth tracking). For EU multi-member FDI filings, the best practice is to submit to all relevant national authorities on the same day. Staggered filings create information asymmetry between authorities and increase the risk of inconsistent disclosures.
Who files matters. In most merger control regimes, the acquirer files. In CFIUS, the parties file jointly or the acquirer files a unilateral notice. In EU FDI regimes, the investor typically files, but local counsel must confirm the exact rule in each member state.
Realistic timeline expectations
| Regime | Phase 1 / Initial Review | Phase 2 / Extended Review | Call-In Window |
|---|---|---|---|
| US HSR (merger control) | — | Second request extends indefinitely | N/A |
| CFIUS | — | 45-day investigation | 3 years post-closing for non-notified deals |
| EU Merger Regulation | — | — | N/A (referral mechanism applies) |
| EU FDI (revised 2026 framework) | 45 calendar days | Varies by member state | At least 15 months |
| National EU FDI (e.g., Germany) | Varies (typically 2–4 months) | Extended review possible | Up to 5 years in some cases |
The 15-month call-in window under the revised EU FDI framework is the most consequential timing risk for US acquirers. A transaction that closes without a filing can be reviewed and conditioned months later.
Filing preparation checklist
Before submitting any filing, run through these steps:
- Confirm completeness of the draft filing against each jurisdiction’s formal requirements.
- Engage local counsel in every jurisdiction at least four weeks before the target filing date.
- Align transaction documents (purchase agreement, ancillary agreements) so representations and warranties are consistent across filings.
- Prepare a parallel document request protocol so the same underlying facts are presented consistently to different authorities.
- Identify any confidentiality or data-transfer restrictions that might limit what you can share with a foreign regulator.
Pro Tip: Set a single “filing day” for all EU FDI submissions and build a shared document index that local counsel in each member state can draw from. Inconsistent filings across member states are one of the most common triggers for extended review.
What compliance issues most often complicate cross-border reviews?
Four recurring friction points account for most of the delays and enforcement risks counsel encounter.
Data transfers and privacy
Due diligence in cross-border transactions requires sharing large volumes of documents, often including personal data. EU GDPR restricts transfers of personal data to non-adequate countries without appropriate safeguards (Standard Contractual Clauses, Binding Corporate Rules). US state privacy laws add a second layer. When a regulator requests documents containing personal data, counsel must assess whether the transfer to that regulator is itself lawful. Practical guidance on preventing data leakage in regulated industries is worth reviewing before any document-sharing protocol is finalized.
AML/CFT and payments data
FATF Recommendation 16 requires payment service providers to include originator and beneficiary information in cross-border payment messages. In practice, cover payment and payment leg structures in SWIFT messaging sometimes separate this information. Interagency guidance is clear: incomplete payment-messaging information is a high-risk trigger requiring enhanced verification, not a gap to overlook. For transactions involving financial institutions or payment platforms, counsel should map every payment flow and confirm that messaging standards meet FATF requirements before closing.
Sanctions and export controls
OFAC screening is not a one-time event. It must cover the full ownership chain of every counterparty, including beneficial owners above the 50% threshold under OFAC’s aggregation rule. BIS export control analysis runs in parallel for transactions involving controlled technology or dual-use goods. Both streams can surface issues that merger control and FDI reviews do not catch, and both can independently block a transaction.
Regulatory arbitrage and the “same activity, same risk, same rule” principle
The FSB recommends applying the “same activity, same risk, same rule” principle to reduce regulatory arbitrage between banks and non-bank payment service providers. For deal teams, this means that structuring a transaction to route activity through a less-regulated entity type in a particular jurisdiction carries real risk: regulators are increasingly alert to this pattern, and the FSB’s push for supervisory consistency means the arbitrage window is narrowing.
A step-by-step checklist for before, during, and after a cross-border review
Who should be involved, and how should governance be structured?
The most common governance failure in cross-border reviews is diffuse ownership. When everyone is responsible, no one is. A clear RACI structure prevents this.
Core roles
Deal counsel owns the overall filing strategy and coordinates external advisors. Regulatory counsel (often specialized external counsel in each jurisdiction) handles the substance of each filing and regulator communications. Compliance owns the sanctions and AML/CFT screening tracks and monitors ongoing obligations. IT and data privacy manages data-flow mapping and cross-border data transfer compliance. Finance provides the financial data underlying filing thresholds and supports the economic analysis for merger control. Local counsel in each filing jurisdiction confirms local procedural requirements and manages relationships with national authorities.
At the board or senior executive level, a designated transaction sponsor should receive regular status updates and have authority to approve concessions or conditions. Decisions about whether to accept a regulator’s proposed condition, litigate, or redesign the transaction should not be made at the working level.
Decision gates
Build formal approval points into the timeline: one at filing submission (sign-off on completeness and consistency), one at Phase 2 entry (decision on whether to offer remedies or contest), and one at final decision (sign-off on conditions and integration plan alignment). Each gate requires documented sign-off from the designated approver.
Operational tooling
A centralized document repository with audit logs, version control, and role-based access is not optional for a multi-jurisdictional review. Regulators increasingly request document production on short timelines, and a disorganized repository creates both delay and credibility risk. Source-linked due diligence workflows reduce the time spent locating and verifying documents during regulator requests.
Playbooks, meaning rules-based review protocols that codify what to check in each document category, reduce inconsistency when multiple team members are responding to parallel information requests from different authorities. Jarel Playbooks let teams encode these rules directly into the review workflow, so every document is assessed against the same criteria regardless of who runs the review.
Practitioners emphasize embedding compliance into day-to-day operations and using risk-based processes for third-party oversight rather than static checklists. Automated monitoring tools for real-time tracking of jurisdictional rule changes are increasingly standard in well-resourced compliance programs.
What do you do when jurisdictions reach different conclusions?
Divergent outcomes are not rare. One jurisdiction clears unconditionally, another imposes conditions, and a third opens a Phase 2 investigation. The question is how to manage all three simultaneously without letting the most restrictive outcome dictate the entire transaction.
When to accept, litigate, or redesign
Accept conditions when the remedy is proportionate to the regulatory concern and the transaction’s strategic rationale survives. Litigate or appeal when the regulator’s theory of harm is factually unsupported and the cost of the condition exceeds the cost of the challenge. Redesign the transaction when a structural feature (ownership by a particular investor, a specific asset in the target portfolio) is the source of the regulatory concern and removing it preserves the core deal.
For litigation risk assessment when jurisdictions diverge, counsel should model the probability of success in each forum before committing to a challenge strategy.
Mitigation packages and parallel approvals
A mitigation package offered to CFIUS (a National Security Agreement or Letter of Assurance) can be structured to address concerns that EU FDI authorities share. Coordinating the substance of mitigation packages across jurisdictions reduces the risk of one authority’s conditions conflicting with another’s. This requires close communication between local counsel teams, which is another reason the centralized governance structure described above is not optional.
Keep counterparties, lenders, and investors informed at each decision gate. MAC clauses, regulatory condition-out provisions, and outside date extensions all depend on timely disclosure of regulatory developments. Surprises at this stage damage relationships and can trigger financing conditions.
What recent policy changes should US companies be tracking?
Two developments materially change the risk calculus for US companies with cross-border exposure: the FSB’s December 2024 recommendations on data flows and the revised EU FDI Screening Regulation.
FSB recommendations on data flows and cross-border payments
The FSB published its final report on data framework alignment in December 2024, containing 12 specific recommendations addressing data-flow frictions, supervisory consistency, and information sharing across jurisdictions for cross-border payments. The FSB also announced a Forum on Cross-Border Payments Data and invited private-sector participation, signaling a multi-year push toward harmonized data access and increased private-sector obligations for data-sharing with regulators.
For US companies operating cross-border payment services, the practical implication is straightforward: expect national regulators to progressively align their data-sharing and supervisory expectations with FSB standards. The “same activity, same risk, same rule” principle means that operating through a non-bank entity to avoid bank-level supervision is an increasingly fragile strategy.
Revised EU FDI Screening Regulation (2026)
The revised EU FDI framework, effective in 2026, introduces several changes that directly affect US investors:
- A harmonized 45-calendar-day Phase 1 review deadline across all member states, replacing the previous patchwork of national timelines
- A mandatory minimum scope for sensitive sectors, meaning more transactions will be screened than before
- Call-in windows extending post-closing review risk for transactions that close without a filing
- An optional EU-level digital filing portal and a mandatory secure EU-level database to facilitate multi-state filings
- National decision-making authority preserved: the Commission coordinates and comments, but member states retain final authority over their own screening decisions
| Policy lever | What it requires | Immediate compliance action |
|---|---|---|
| FSB Recommendation: harmonized data frameworks | Align data-sharing practices with emerging international standards | Audit data flows and messaging standards for cross-border payment operations |
| FSB “same activity, same risk, same rule” | No regulatory arbitrage between bank and non-bank PSPs | Review entity structure for any supervision gap exploitation |
| Revised EU FDI: 45-day Phase 1 | File earlier; national reviews now run on a common clock | Build EU FDI filing into deal timeline from signing |
| Revised EU FDI: 15-month call-in | Post-closing review risk for non-notified deals | Assess filing obligation before closing, not after |
| Revised EU FDI: mandatory minimum scope | More transactions screened in sensitive sectors | Expand sector-sensitivity analysis in pre-signing due diligence |
For US investors, the combined effect of these changes is earlier filings, more coordinated multi-state EU submissions, and a higher baseline for ownership and control mapping. Deals that would have closed without an EU FDI filing two years ago may now require one.
Key Takeaways
Managing a multi-jurisdictional regulatory review requires mapping every filing trigger before signing, centralizing documents from day one, and assigning a single internal owner who can coordinate across CFIUS, EU FDI, merger control, and sanctions tracks simultaneously.
| Point | Details |
|---|---|
| Map triggers before signing | Identify every jurisdiction where merger control, FDI, sanctions, or sectoral review obligations exist before the deal is announced. |
| Centralize documents immediately | A single access-controlled repository with audit logs is required for parallel regulator requests and post-closing condition monitoring. |
| Assign one filing owner | Diffuse ownership is the most common governance failure; one person must own the master timeline and coordinate all external counsel. |
| File EU FDI submissions simultaneously | The revised EU FDI framework’s 45-day Phase 1 clock and 15-month call-in window make same-day multi-state filing the only safe approach. |
| Use Jarel Playbooks for consistent reviews | Codifying pre-filing checklists and red-flag rules in Jarel Playbooks reduces inconsistency across team members and jurisdictions. |
The part of cross-border reviews most counsel underestimate
The conventional wisdom on cross-border regulatory reviews focuses on timelines and filing thresholds. Get the triggers right, file on time, and the process manages itself. That framing misses the real difficulty.
The hardest part is not identifying that a filing is required. It is maintaining factual consistency across six or eight simultaneous regulatory processes, each with its own document requests, information formats, and political sensitivities, while a deal team is also negotiating purchase price adjustments and integration plans. The moment a compliance officer in Frankfurt describes the target’s data-processing activities differently than deal counsel described them to CFIUS, you have a problem that no timeline chart fixes.
What actually works is treating the evidentiary record as a single source of truth from the moment the deal is signed. Every document produced to every regulator should trace back to the same underlying facts, and every team member answering a regulator’s question should be drawing from the same centralized workspace. This is not a technology argument. It is a basic discipline argument. Technology just makes it easier to enforce.
The second underestimated risk is the post-closing period. Conditions and undertakings imposed by regulators do not expire at closing. They run for years, require periodic reporting, and can be triggered by subsequent transactions involving the same parties. Compliance programs that treat regulatory approval as the finish line routinely fail their first post-closing compliance report.

Jarel gives legal teams a single workspace for the entire review
Cross-border regulatory reviews generate hundreds of documents, parallel information requests, and conditions that must be tracked for years. Managing that across email threads and shared drives is where evidentiary consistency breaks down.

Jarel’s source-linked workspace keeps every document, citation, and review output connected to its underlying source. Jarel Playbooks let your team encode pre-filing checklists, red-flag rules, and document standards directly into the review workflow, so every team member applies the same criteria whether they are reviewing ownership structure documents for CFIUS or sectoral filings for an EU national authority. Audit logs and role-based access controls mean every action in the workspace is traceable, which matters when a regulator asks for a record of your review process. For fintech and payments teams managing FSB and FATF compliance obligations, Jarel’s source-linked compliance workflows map regulatory requirements directly to the documents that satisfy them.
Start a free trial at jarel.se and see how your team’s next multi-jurisdictional filing runs when the evidentiary record is built in from day one.
Useful sources
The primary sources below are the authoritative starting points for any cross-border regulatory review. Bookmark them and store them in a centralized workspace where your team can access and annotate them throughout the review.
CFIUS guidance is published by the U.S. Department of the Treasury and covers mandatory and voluntary filing obligations, covered transaction definitions, and the mitigation process. The Treasury’s CFIUS resource page is the definitive reference for US FDI screening.
The revised EU FDI Screening Regulation text and practitioner analysis are available from the European Commission and from specialist competition law publications. The Baker McKenzie analysis and the Competition Law Blog summary are the most practical starting points for understanding the 2026 changes.
FSB recommendations on cross-border payments and data frameworks are available directly from the FSB website. The December 2024 final report on data framework alignment and the December 2024 announcement on the Forum on Cross-Border Payments Data are the two most relevant documents for payment service providers.
FATF standards, including Recommendation 16 on payment transparency, are published at fatf-gafi.org. The NCUA interagency guidance on cross-border funds transfers translates FATF standards into practical US compliance expectations for payment messaging.
OFAC guidance is published by the U.S. Department of the Treasury’s Office of Foreign Assets Control and covers sanctions program specifics, the 50% ownership rule, and compliance framework expectations.
OECD international regulatory cooperation resources provide the broader policy context for why harmonization efforts succeed in some areas and fail in others. The OECD IRC topic page is the best single entry point.
Foley & Lardner’s practitioner guidance on international regulatory compliance self-checks is worth reading alongside the primary sources for its operational framing of how to embed compliance into day-to-day workflows rather than treating it as a pre-closing sprint.
Store these sources in Jarel’s secure document vault so your team can annotate, cross-reference, and track updates without losing the evidentiary chain.

FAQ
What is the cross-border regulatory review process?
It is the coordinated set of legal and compliance steps required to obtain clearance from multiple national or supranational authorities before closing a transaction or operating across jurisdictions, covering merger control, FDI screening, sanctions, AML/CFT, and sectoral reviews.
What does cross-border compliance require in practice?
Cross-border compliance requires mapping filing triggers in every relevant jurisdiction, maintaining consistent factual disclosures across parallel regulatory processes, and tracking post-closing conditions and reporting obligations for the full term of any imposed undertakings.
What is the regulatory filing process for a cross-border transaction?
The filing process begins with a jurisdictional trigger analysis, followed by simultaneous or sequenced submissions to each relevant authority, coordinated document production during the review period, and negotiation of any conditions before a final decision is issued.
How does CFIUS differ from EU FDI screening?
CFIUS focuses exclusively on national security risk from foreign investment in US businesses and can recommend presidential action to block or unwind a transaction. EU FDI screening under the revised 2026 framework operates through national authorities with a harmonized 45-calendar-day Phase 1 review, but final decisions remain with each member state rather than the European Commission.
What is the biggest risk of not filing in a required jurisdiction?
Post-closing review. Under the revised EU FDI framework, call-in windows extend to at least 15 months, meaning a transaction that closes without a required filing can be reviewed, conditioned, or in extreme cases unwound well after the deal has closed.
