A US-headquartered technology company agrees to supply software tools to a distributor in a third market. The distributor is not listed. The goods are not classified as weapons. Yet the transaction still carries meaningful legal risk – because the end use to which those tools will be put, and the identity of the ultimate end-user, engage overlapping control regimes on both sides of the Atlantic. Get the analysis wrong and the firm faces enforcement action in Washington and potentially in London as well.
As of April 2026, end-use and end-user controls (the legal mechanisms that restrict transfers of goods, technology, or services based on their intended use or the identity of the ultimate recipient) operate under materially different frameworks in the United States and the United Kingdom. OFAC administers the US sanctions component under IEEPA and related statutes; the UK's OFSI (Office of Financial Sanctions Implementation) administers financial-sanctions controls under SAMLA; and the US Bureau of Industry and Security administers the parallel export-control layer through the EAR. These regimes share a common purpose but diverge sharply on trigger tests, the degree of constructive-knowledge liability, reporting obligations, and the treatment of licensed intermediaries.
This analysis maps the key divergences, criterion by criterion, and identifies the practical pressure points for cross-border businesses managing dual compliance obligations.
What is the governing authority for end-use and end-user controls under each regime?
The US controls sit across two separate but interacting authorities: OFAC administers asset-freezing and dealing-prohibition measures under IEEPA and related statutes, while BIS administers the EAR (the Export Administration Regulations) for export-control purposes under the Export Control Reform Act. OFSI, by contrast, administers a unified financial-sanctions regime under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic sanctions regulations; UK export licensing sits with the ECJU (Export Control Joint Unit), not OFSI.
This structural difference matters for end-use analysis. A US exporter supplying dual-use technology must satisfy OFAC's sanctions screening and BIS's export-control requirements simultaneously. A UK exporter faces OFSI on the financial-sanctions side and ECJU on the export-licensing side – two separate competent authorities with separate licensing tracks, separate enforcement mandates, and separate reporting requirements. In our cross-border practice, the failure to recognise this four-authority picture (OFAC, BIS, OFSI, ECJU) is the single most common source of compliance gaps at the structuring stage.
Where does the EU sit in this picture? The EU dual-use regime under the relevant Council Regulation imposes its own end-use catch-all controls. The EU's controls extend to intangible transfers of technology, and the test for whether a catch-all applies turns on the exporter having grounds to suspect that the goods or technology could contribute to a proscribed end use. That is a constructive-knowledge standard that runs closer to the US approach than to the UK's narrower OFSI financial-sanctions trigger – a distinction we return to below.
How do OFAC and OFSI define the end-user test differently?
OFAC's end-user analysis is primarily a sanctions-screening question: is the ultimate recipient a Specially Designated National (SDN – a person on OFAC's list of blocked persons), or an entity that blocked persons own 50 percent or more in the aggregate? If the answer is yes, the transaction is prohibited regardless of the supply chain's length or the number of intermediaries between the US exporter and the end-user.
OFSI applies a different test. The UK financial-sanctions prohibition attaches to dealing with a designated person's funds or economic resources. The relevant question is whether the transaction, at any stage, makes funds or economic resources available – directly or indirectly – to a designated person. The trigger word "indirectly" does a great deal of work here. But OFSI's control test for associated entities is broader than a mechanical ownership threshold: control through other means – board representation, contractual power, or de facto direction – can bring a non-listed entity within the prohibition even where the 50 percent ownership line is not crossed.
The practical divergence is significant. A company with a listed person holding a 40 percent stake would not, on OFAC's ownership test alone, be treated as a blocked entity. Under OFSI's ownership-and-control analysis, that same company could be caught if the listed person exercises control through the mechanisms described above. Have you tested the counterparty against both standards, or only run it through an SDN-list check?
The BIS layer adds a third test. Under the EAR, a Red Flag analysis applies: exporters are expected to know their customer and to inquire further when there are indicators – or "red flags" – that goods may be diverted to an unlicensed end-use or end-user. The EAR does not require proof of knowledge; it requires that the exporter have no reason to believe the transaction is improper, and that reasonable enquiries are made when red flags are present. This is a due-diligence standard that sits between OFAC's mechanical ownership test and the EU's catch-all constructive-knowledge standard.
Where does constructive knowledge create different liability profiles?
Constructive-knowledge liability is the area where OFAC and OFSI diverge most sharply – and where cross-border businesses face the greatest exposure to unexpected enforcement.
OFAC applies a strict-liability standard to sanctions violations. That means a US person can be liable even if it did not know that a transaction involved a sanctioned party, provided OFAC determines that "reason to know" was present. OFAC's enforcement guidelines set out a range of aggravating and mitigating factors, but the baseline is strict. A voluntary self-disclosure (VSD – a proactive report to OFAC before the agency opens an investigation) is among the most significant mitigating factors available under OFAC's framework.
OFSI's civil enforcement does not depend on knowledge: a person can be penalised for breaching financial-sanctions regulations without knowing or having reasonable cause to suspect a breach was occurring. However, the penalty that OFSI may impose is subject to a higher ceiling where the breach was deliberate or there was reasonable cause to suspect one. In practice this means the knowledge element in the UK regime affects the severity of the penalty rather than the threshold for liability. That is a meaningful nuance: a firm that acted in good faith on a flawed screening result is still liable, but its exposure is materially different from that of a firm that ignored known risks.
Under BIS and the EAR, knowledge-based controls are more explicit. The EAR prohibits exports when the exporter "knows" the goods will be used in a proscribed manner. "Knows" is defined to include not only actual knowledge but also belief that such an end-use is substantially probable. This creates a middle position between OFAC's strict standard and the EU catch-all. For a cross-border business running BIS and OFAC compliance in parallel, the risk of inconsistent standards applying to the same transaction is real and regularly underappreciated.
The position above covers the standard analysis. Your facts – the technology, the counterparty, the jurisdiction, and the distribution chain – change the liability calculus materially. For an assessment of your exposure across OFAC, BIS, and OFSI, contact Calder & Vance at info@caldervance.com.
How do the regimes treat licensed intermediaries and distributor chains?
One of the least-discussed divergences between OFAC and OFSI is how each regime treats the role of an authorised intermediary in a multi-tier distribution chain.
Under OFAC, a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) is issued to the named applicant and covers the transaction as described. A general licence (a standing authorisation permitting a defined category of transactions without a separate application) may extend to third parties who rely on it. However, a US exporter relying on a general licence must confirm that the specific transaction actually falls within the licence's terms – the existence of a general licence does not by itself authorise a transaction that falls outside its scope. Relying on a general licence without analysis of scope is a common cause of apparent violations.
OFSI's specific licences are similarly transaction-specific. A UK exporter whose distributor holds an OFSI licence cannot automatically rely on that licence: the question is whether the UK exporter's own conduct in facilitating the transfer falls within a licensed exception, or whether the exporter itself requires authorisation. In our experience, distribution chains involving a UK parent, an offshore subsidiary, and a non-UK end-customer frequently require separate analysis at each tier.
The EAR adds a fourth consideration: deemed export controls. A deemed export occurs when controlled technology is released to a foreign national within the US – this is treated as an export to the foreign national's country of origin. OFSI has no equivalent concept; UK export controls under ECJU licensing apply to physical export rather than to intangible transfer to a person within the UK. This means a US company employing a non-US national in a technical role may trigger BIS requirements that have no UK equivalent. For further analysis of deemed export obligations under the EAR, see our dedicated service guide: Deemed Export and Technology Controls – BIS / EAR.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. To discuss a specific situation, contact us at info@caldervance.com.
What risk flags should compliance teams monitor in a dual OFAC/OFSI environment?
Certain patterns consistently signal elevated risk in transactions subject to both OFAC and OFSI oversight. Recognising them early reduces the likelihood of a compliance failure reaching an enforcement stage.
The first risk flag is ownership opacity. Where a distributor or agent's ownership chain is not fully documented beyond the first tier, neither the OFAC 50-percent-rule analysis nor OFSI's control test can be completed. A chain that resolves after two levels but is silent on ultimate beneficial ownership leaves the exporter exposed. Beneficial-ownership registers, where available, should always be verified against the latest list positions.
The second flag is geography and routing. Goods routed through a third country – particularly one that is itself subject to a sanctions programme – carry a presumptive risk of diversion. Both OFAC and OFSI have acted against parties who relied on the absence of a direct nexus to a sanctioned destination while ignoring transit risk. BIS's red-flag indicators specifically address unusual routing and abnormal shipping patterns.
The third flag is end-use inconsistency. Where the stated end-use is inconsistent with the buyer's known business, or where the specification of the goods is more capable than the stated application requires, the EAR red-flag analysis is engaged. OFSI's enforcement guidance references the importance of knowing the business purpose of a transaction when assessing whether a dealing prohibition applies.
A fourth flag, which our practice sees regularly, is misaligned due-diligence depth. Firms often apply a thorough SDN-list check but a superficial ownership-chain analysis, or vice versa. The result is a compliance record that demonstrates effort without having discharged the legal standard under either regime. Documentation of the analysis – what was checked, when, and against which list version – is a critical element of the defence in any enforcement enquiry.
How do reporting and record-keeping obligations compare?
OFAC's reporting rules require that any US person who holds blocked property must report that property to OFAC within a short statutory window after the blocking occurs, and again annually for as long as the property remains blocked. OFAC also expects prompt reporting of apparent violations. Under OFAC's enforcement framework, a VSD – filed proactively and before OFAC commences an investigation – can produce a significant reduction in penalty. The record-keeping requirement under the applicable OFAC regulations is five years from the date of the transaction.
OFSI requires that persons in the financial sector who know or reasonably suspect that a person is a designated person, or has committed an offence under the relevant financial-sanctions regulations, must disclose that knowledge or suspicion to OFSI. This reporting duty is broader in its trigger – it covers reasonable suspicion, not only actual knowledge of a block – and it applies to a wider population of regulated entities than the parallel AML reporting obligations. OFSI's record-keeping requirement under SAMLA-based obligations broadly mirrors a multi-year standard, though the precise period should be confirmed against the relevant thematic regulations in force at the time of the transaction.
The interaction between OFAC annual reporting and OFSI's suspicion-based disclosure is rarely considered together. In practice, a UK branch of a US financial institution may face both obligations simultaneously where a payment is blocked at the US-entity level while the UK branch holds related correspondence that triggers OFSI's disclosure test. We regularly advise clients on the practical sequencing of dual-regime reporting to manage both obligations without creating inconsistencies across regulators.
A common misconception: OFSI is simply a narrower OFAC
A persistent assumption among compliance teams at US-headquartered multinationals is that OFSI is essentially a smaller version of OFAC – that if a transaction clears OFAC analysis, the UK position follows automatically. This assumption is incorrect and has produced enforcement exposure in a number of cross-border matters.
The divergences are structural. OFSI's control test, described above, can catch a counterparty that clears the OFAC 50-percent-rule. OFSI's licensing categories do not always mirror OFAC's general-licence architecture. The UK-specific thematic sanctions regulations may prohibit activities that fall outside a particular OFAC programme. And, critically, the extraterritorial reach of OFAC's secondary-sanctions risk extends to non-US persons in ways that have no direct OFSI equivalent – but that can affect a UK business's US-dollar clearing relationships and correspondent-banking access.
The inverse is also true. A transaction that falls within an OFAC general licence may still require specific OFSI authorisation. A UK firm that structures its analysis around US OFAC guidance and ignores OFSI's separate licensing track may find that it has sought and obtained one authority while inadvertently operating without the other.
For analysis of how OFSI's end-use and end-user controls compare with the position in another major regime, see our parallel analysis: OFSI vs Australia: End-use and End-user Controls. For the EU-OFSI divergence analysis, see: OFSI vs EU: End-use and End-user Controls.
When should a cross-border business involve specialist counsel?
Not every transaction involving dual-use goods or a complex ownership chain requires formal legal advice at the outset. Routine screening against published lists, standard customer due-diligence checks, and documented reliance on a clearly applicable general licence are proper compliance-team functions. The question is when the facts move beyond that standard pattern.
Counsel should be involved early when any of the following applies. The counterparty's ownership chain does not resolve cleanly at the beneficial-ownership level, or there is a partial match against an SDN or UK designation. The goods are dual-use items under the EAR or the EU dual-use rules, and the stated end-use is technical or sensitive. The transaction involves a jurisdiction that is subject to a comprehensive or targeted programme under either OFAC or OFSI, or both. An OFAC or OFSI licence is required and no general licence clearly applies. A previous shipment or payment has been flagged or blocked, and the business needs to assess its reporting obligations across both regimes.
Timing matters. A VSD to OFAC, filed before an investigation opens, is treated as a significant mitigating factor. OFSI's enforcement framework similarly considers the speed and quality of self-disclosure in penalty assessments. Early involvement of counsel when a problem is suspected – rather than when it is confirmed – is consistently the position that preserves the most options.
In a recent matter, a technology distributor operating across the US and UK markets discovered that a long-standing customer had acquired a minority stake by a party who appeared on the relevant UK designation list. The distributor had cleared the customer under its SDN-list screening but had not applied OFSI's control test. We conducted a full ownership and control analysis across both regimes, identified the reporting obligations, and advised on the structured approach to notifying both OFAC and OFSI in a coordinated sequence. The matter was resolved without escalation to formal enforcement proceedings.
Related practices
- Deemed Export and Technology Controls – BIS / EAR – classifying and licensing technology transfers to foreign nationals under the EAR
- OFSI vs Australia: End-use and End-user Controls – comparative analysis of UK and Australian end-user control regimes
- OFSI vs EU: End-use and End-user Controls – mapping the divergence between OFSI and EU dual-use and sanctions controls