A trading company ships precision components from a European facility to a distributor in a third market. Weeks later, its compliance team discovers that the goods fall under US export-control jurisdiction – and that the distributor appears on a restricted-party list. Two regulators now have a potential interest: the US Department of Justice and, because the company has a UK subsidiary, His Majesty's Treasury through OFSI. The question is not merely civil. It is whether directors face criminal prosecution.
Criminal exposure in export-control cases under OFAC and OFSI is real, concurrent, and structurally different. OFAC can pursue criminal penalties for wilful violations of US sanctions rules, with significant custodial sentences available under the governing statute. OFSI's criminal route is narrower in practice but has been materially strengthened by legislation enacted in recent years. As of early 2026, both regimes operate independently, meaning a single transaction can generate parallel criminal jeopardy across two jurisdictions.
This analysis maps the criminal exposure framework under each regime, compares the tests for wilfulness and knowledge, examines how extraterritorial reach extends US criminal exposure to non-US persons, and identifies the practical risk flags that should trigger immediate legal review.
What is the legal basis for criminal exposure under OFAC?
OFAC's criminal authority flows from statutes including IEEPA and TWEA, which authorise the US government to impose both civil and criminal penalties for sanctions violations. Under IEEPA, wilful violations carry significant custodial exposure and substantial financial penalties. Prosecutions are brought by the Department of Justice; OFAC itself handles the civil track in parallel.
The distinction between civil and criminal exposure under the US regime turns on the element of wilfulness. A civil penalty can follow a strict-liability finding – the violation occurred and the party did not take all reasonable steps to avoid it. Criminal prosecution requires the government to establish that the defendant acted wilfully: that they knew their conduct was unlawful and proceeded anyway. In our experience, this distinction is frequently misunderstood by compliance teams who assume that civil findings cannot escalate. They can and do.
The Export Control Reform Act ("ECRA") governs the export-control criminal track under BIS jurisdiction. Wilful violations of the Export Administration Regulations (the "EAR") carry their own criminal penalties, separate from OFAC sanctions exposure. A single shipment can attract liability under both regimes simultaneously – sanctions exposure for the restricted-party dimension and export-control criminal liability for the classification or licence failure.
The position above covers the standard case. Your facts – the counterparty, the goods, the classification, the routing, the regime in play – change the analysis materially. For a confidential assessment of your exposure, contact Calder & Vance at info@caldervance.com.
How does OFSI approach criminal liability – and where does it differ?
OFSI's criminal enforcement rests on a different statutory foundation. Under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the thematic UK sanctions regulations made under it, criminal offences arise where a person deals with the funds or economic resources of a designated person, or makes those assets available, knowing or having reasonable cause to suspect that they are dealing with a designated person's property. The "reasonable cause to suspect" limb is notably broader than OFAC's wilfulness standard: it catches deliberate ignorance as well as actual knowledge.
In practice, OFSI prosecutions for breaches related to export-control transactions have been less common than the equivalent US criminal track. Two structural differences explain this. First, the UK enforcement architecture separates financial-sanctions enforcement (OFSI) from export-control enforcement (ECJU under the Export Control Order). A transaction that raises both dimensions generates two separate regulatory relationships in the UK, compared with the integrated US approach where OFAC and the DOJ operate on a coordinated basis. Second, OFSI's civil monetary-penalty power – enhanced by the Economic Crime (Transparency and Enforcement) Act – has given the regulator a powerful non-criminal tool that it has used with increasing frequency.
That said, the criminal route remains available and should not be discounted. OFSI can refer cases to law-enforcement authorities where it identifies evidence of deliberate or systematic breach. For individuals – directors, compliance officers, and decision-makers – this is the exposure that matters most.
Does US criminal exposure reach non-US businesses?
US criminal jurisdiction extends well beyond US persons and US-incorporated entities. The EAR applies to re-exports from third countries of items that contain more than a defined threshold of US-controlled content. IEEPA sanctions prohibit US-dollar transactions and dealings that involve the US financial system, irrespective of where the transacting parties are located. Both extend potential criminal liability to non-US companies and individuals who wilfully violate the rules.
The mechanisms are worth understanding precisely. A non-US company that routes a payment through a US correspondent bank is potentially subject to OFAC jurisdiction for that transaction. A European manufacturer that re-exports goods with US-origin controlled components without the required BIS authorisation faces EAR criminal liability. These are not theoretical positions. The DOJ has prosecuted non-US nationals on exactly these bases, and extradition requests have followed in cases where the US authorities considered prosecution necessary.
Secondary-sanctions risk adds a further dimension. Persons who materially assist a designated entity in completing a transaction can themselves become subject to designation. A criminal investigation and a designation are not mutually exclusive; they have occurred concurrently in recent enforcement cycles.
For a business operating across the US and UK regimes – or with supply chains that touch US-origin goods – this extraterritorial dimension is the factor most likely to be underestimated. Our practice regularly advises European companies who discover, after the fact, that a transaction they considered entirely domestic had a US-nexus that OFAC or the DOJ regards as sufficient for jurisdiction.
How do the two regimes compare on the wilfulness and knowledge tests?
The difference in the mental-element tests between OFAC and OFSI is analytically significant and has direct implications for how a business should structure its defence or its voluntary self-disclosure. The comparison is not merely academic: it determines the risk that directors and senior managers carry personally.
Under the US criminal track, wilfulness is the standard for custodial liability. Prosecutors must show that the defendant knew the conduct violated US law and acted with that knowledge. The courts have construed this to include deliberate avoidance of the truth – the so-called "ostrich instruction" – meaning that a director who deliberately declines to investigate a red flag cannot claim the protection of ignorance. Wilfulness does not require proof that the defendant knew the specific regulation they were violating; knowledge that their conduct was broadly unlawful is sufficient.
Under OFSI's criminal provisions, the test for the standard offence is knowing or having reasonable cause to suspect. This is a lower bar in one respect: "reasonable cause to suspect" is an objective test, assessed against what a reasonable person in the defendant's position would have known or concluded. A compliance officer who ignores repeated screening alerts may satisfy this test even if they genuinely believed the transaction was clean. The practical consequence is that OFSI's criminal route can reach a broader population of individuals than the US wilfulness standard – though in practice, prosecutorial discretion has meant that OFSI criminal referrals have been reserved for the more egregious cases.
Where the regimes converge is in their treatment of senior management accountability. Both DOJ and OFSI guidance emphasises the role of individual accountability in enforcement decisions. A business that can demonstrate that its board-level oversight was robust, its training was current, and its escalation procedures functioned as designed will receive more favourable treatment in both jurisdictions than one that cannot.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss the position.
What is the role of voluntary self-disclosure in managing criminal risk?
Voluntary self-disclosure (a VSD) – a proactive report to the relevant regulator or enforcement authority before that authority becomes aware of the potential violation through other means – is the most significant risk-management tool available to a business facing potential criminal exposure. Under both the OFAC and BIS frameworks in the US, a timely and complete VSD is a significant mitigating factor in enforcement decisions. Under OFSI guidance, voluntary disclosure is similarly treated as a factor that can reduce civil monetary penalties and influence whether a matter is referred for criminal investigation.
The timing constraint is critical. A VSD must be made before the regulator or law-enforcement body learns of the matter independently. Once an investigation is open, or a subpoena has been issued, the window for a VSD-based mitigation argument has in large part closed. For export-control cases under the EAR, BIS operates its own VSD process through the Office of Export Enforcement. OFAC maintains a separate submission procedure. OFSI has its own reporting mechanism under SAMLA.
Coordination between the two tracks – US and UK – requires careful management. A VSD filed with OFAC that contains detailed admissions may be available to OFSI through information-sharing arrangements, and vice versa. In a cross-border matter, the sequencing and content of disclosures needs to be managed by counsel with a view across both regimes. Uncoordinated disclosures made through separate national counsel, with no common strategy, are one of the more avoidable ways in which businesses convert a manageable civil exposure into a more serious problem.
In a recent matter, a manufacturing business with operations in both the US and the UK identified an apparent export-control violation following an internal audit. We scoped the apparent violation across both regimes, assessed the VSD window in each jurisdiction, and prepared coordinated disclosures that addressed the US criminal risk while preserving the available mitigation arguments before OFSI. The matter was resolved on the civil track in both jurisdictions.
Risk flags that indicate criminal – not merely civil – exposure
Not every export-control failure carries criminal risk. The assessment turns on the specific facts, the mental element that can be established, and the enforcement posture of the relevant authority. Certain patterns, however, consistently appear in cases where regulators and prosecutors have pursued the criminal route.
Deliberate misclassification is the clearest risk flag. Where a business knowingly classifies a controlled item as if it were not subject to licensing requirements, or routes a shipment through an intermediate jurisdiction to obscure its ultimate destination, the wilfulness or knowledge element is potentially satisfied on the face of the documentation. Compliance teams should treat systematic under-classification with the same seriousness as a positive screening hit.
Repeated apparent violations following prior notice are another consistent signal. A business that has previously received a warning letter, a no-action letter, or a civil penalty – and then commits a further violation in the same product category or against the same counterparty profile – faces a materially different prosecutorial calculus than a business experiencing a first apparent violation. Both OFAC and BIS guidance expressly identifies prior violations as aggravating factors.
Senior-management involvement or awareness is a third trigger. Where emails, board minutes, or deal approval documents show that decision-makers were aware of the red flags and approved the transaction regardless, the individual criminal exposure is clear. Have those documents been reviewed? If not, they need to be – before a regulator requests them.
Transactions involving goods with a clear military, dual-use, or proliferation connection attract heightened scrutiny from the outset. End-use certificates that cannot be verified, counterparties whose stated business does not match the goods ordered, and payment structures that are inconsistent with normal commercial terms are all patterns that regulators document as evidence of wilfulness.
How do OFAC and OFSI enforcement postures compare in practice?
The US enforcement posture for export-control criminal cases is, in structural terms, more developed and more frequently used than its UK counterpart. The DOJ maintains a dedicated national security division with export-control prosecutions as an explicit priority. Joint enforcement task forces between DOJ, BIS, the FBI, and Homeland Security Investigations process criminal export-control referrals with regularity. In our cross-border practice, US criminal jeopardy is typically the first concern that a client with a US nexus needs to quantify.
OFSI's enforcement posture has evolved. The introduction of civil monetary penalties that are not capped by the value of the transaction – a development introduced by primary legislation in the economic-crime space – gave OFSI a penalty architecture comparable in scale to OFAC. Criminal referrals by OFSI remain less frequent, but the direction of travel is clear. OFSI has published guidance that specifically identifies the behaviours it views as aggravating, including deliberate breach, failure to disclose, and involvement of senior management.
One area where the regimes diverge sharply is in the availability of deferred prosecution agreements ("DPAs"). DPAs are an established feature of the US criminal enforcement environment and provide a structured route through which a company can accept responsibility, pay a financial penalty, and implement compliance improvements without a formal conviction entering. The UK has a DPA mechanism for certain offences, but its use in the export-control and sanctions space remains limited compared with the US. A cross-border business navigating parallel criminal exposure cannot assume that a resolution achieved on the US track will translate automatically into a comparable outcome before UK authorities.
The EU dimension should also be noted, even though this analysis centres on OFAC and OFSI. EU member states transpose sanctions regulations into national law, and criminal liability attaches under national criminal codes. The enforcement intensity varies by member state, but the EU's increasingly active position on sanctions enforcement – reflected in moves toward a common enforcement approach – means that a business with EU operations cannot treat criminal exposure as solely a US-UK question. For further detail on the EU criminal enforcement dimension, see our analysis at criminal exposure under OFSI and EU compared.
A cross-border myth worth correcting
One assumption that frequently complicates our clients' initial assessment of their position is the belief that criminal exposure requires a specific intent to violate sanctions – that a business which had no interest in the sanctioned sector and no knowledge of the restricted end-user is safe from criminal proceedings. That belief is inaccurate and can lead to inaction at precisely the moment when action matters most.
Under the EAR, criminal liability does not require proof that the defendant targeted a specific prohibited outcome. The wilfulness standard is met by knowledge that the conduct violated US law, not by specific intent to harm a national-security interest. Under OFSI, the "reasonable cause to suspect" standard can reach companies that maintained demonstrably poor screening procedures, even where there was no actual knowledge. In both regimes, the absence of a compliance programme – or a programme that existed on paper but was not implemented in practice – is treated as an aggravating factor, not as evidence of good faith.
A second misconception is that criminal exposure is exclusively a large-company risk. Smaller exporters and trading companies have been prosecuted for EAR violations. OFSI enforcement actions have reached sole traders and small businesses. The size of the business does not determine whether the criminal threshold is met; the facts of the transaction and the knowledge of the individuals involved do.
Related practices
- Apparent violation assessment – scoping apparent violations and advising on disclosure options across major regimes
- Criminal export exposure: further analysis – extended practitioner analysis of criminal exposure patterns in export-control enforcement