Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFSI

OFSI vs Australia: End-use and end-user controls: the key divergences

A British exporter signs a contract to supply precision components to a distributor in Sydney. The items fall under the UK's export-control regime. The transaction also touches Australia's autonomous-sanctions framework. The compliance team asks: which end-use and end-user obligations apply, how do they interact, and where do the two regimes pull in different directions? These are not abstract questions. A wrong answer can mean a refused shipment, a licence revoked, or a referral to enforcement.

End-use and end-user controls under OFSI and the UK export-control regime differ materially from their Australian equivalents in scope, legal basis, and the conditions that trigger a licence requirement. As of April 2026, both regimes are active and evolving; neither is a straightforward proxy for the other. A business operating across both jurisdictions must understand each regime on its own terms and manage the points where they diverge.

This analysis sets out the governing legal authority in each jurisdiction, maps the key divergences across six dimensions, identifies the risk flags that most frequently catch cross-border businesses, and explains when specialist counsel is necessary.

What legal authority governs end-use controls in each regime?

The UK's end-use and end-user controls operate through two interlocking bodies of law: the financial-sanctions rules administered by OFSI (the Office of Financial Sanctions Implementation, the HM Treasury authority responsible for UK financial-sanctions enforcement and licensing) and the export-licensing rules administered by the ECJU (Export Control Joint Unit, within the Department for Business and Trade). The primary statutory authority is the Sanctions and Anti-Money Laundering Act, commonly called SAMLA, supplemented by the relevant thematic sanctions regulations for each programme. The Export Control Order provides the framework for licensing physical goods and technology.

Australia's regime operates under DFAT, the Department of Foreign Affairs and Trade, which administers the Autonomous Sanctions regime (Australia's independent country-specific and thematic controls, enacted by the Australian government without a UN mandate). Separate from those autonomous measures, Australia implements UN Security Council-mandated controls through its Charter of the United Nations Act framework. The Customs Act and subordinate instruments impose physical export-licensing requirements on controlled goods and technologies.

What this means in practice is that neither regime is purely "financial" or purely "physical." Both interweave asset-freezing obligations, transaction prohibitions, and export-licensing requirements. However, the administrative architecture differs. In the UK, OFSI handles the financial-sanctions side and ECJU handles export licensing – two regulators, two licensing queues, two enforcement cultures. In Australia, DFAT spans both sanctions and strategic-goods functions, though different internal divisions handle each. That structural difference has procedural consequences examined below.

The UN Security Council Consolidated List underpins both regimes where UN-mandated programmes are in play. Where a listed person appears on the UN list, both the UK and Australia have obligations to give effect to the designation. The divergences explored here principally concern the autonomous programmes and the national licensing architecture, where each state has made independent choices.

How do the two regimes define "end-use" and "end-user" for licensing purposes?

Both regimes centre on preventing controlled goods and technology from reaching destinations, uses, or users that would undermine the policy objectives of the relevant programme – but they define the triggers for that concern differently.

Under the UK regime, an end-use concern arises in two main ways. First, a specific good or technology may require a standard export licence regardless of the stated end-use, because it is classified as controlled on the UK Strategic Export Control Lists. Second, a separate "end-use" or "catch-all" control can apply even to goods that are not controlled by classification, when the exporter has reason to know or suspect that the goods may be used in programmes related to weapons of mass destruction or in other prohibited end-uses specified in the Export Control Order. The ECJU's guidance distinguishes between the classification-triggered requirement and the awareness-triggered catch-all. A business that is told, or otherwise forms a reasonable belief, that uncontrolled goods will feed into a prohibited programme must apply for a licence before proceeding.

Australia's regime applies a comparable but not identical structure. The Defence Export Controls framework classifies goods and technology using lists derived from the international export-control arrangements in which Australia participates. A separate end-use certification process applies to certain categories of controlled-goods exports. Where goods are not themselves controlled, the autonomous-sanctions prohibitions can still bite if the transaction involves a designated person or entity, or if the supply supports an activity subject to a sectoral restriction.

The practical divergence is this. In the UK, the catch-all is anchored to specific statutory grounds; the exporter's state of knowledge is a central element of whether the control bites. In Australia, the equivalent concern is addressed more through the licensing classification itself and through conditions attached to specific permits. The UK regime is, in that respect, more explicitly sensitive to the exporter's subjective awareness – which creates a different compliance obligation, and a different enforcement exposure, for a business with mixed-jurisdiction operations.

Have you mapped your goods against both classification lists? An item that sits below the UK control threshold may nonetheless be controlled for Australian export purposes, or vice versa. Classification parity is rarely automatic.

Where do the regimes diverge on licensing structure and timelines?

The licensing architecture is where practitioners and compliance teams encounter the sharpest day-to-day differences between the UK and Australian regimes.

UK export licences come in two main types: open general licences (standing authorisations covering defined categories of transactions without a separate application) and specific licences (case-by-case authorisations for transactions that fall outside an open general licence). The ECJU publishes a suite of open general licences that, where applicable, significantly reduce the administrative burden for routine export flows. A business that qualifies for an open general licence must register, keep records in accordance with its conditions, and comply with end-user provisions embedded in the licence terms – but it does not require case-by-case approval. Where a specific licence is needed, the ECJU processes applications and may request additional information or undertakings from the applicant. OFSI handles any parallel licensing requirement arising from the financial-sanctions dimension of a transaction – for example, where a payment to a counterparty would otherwise be prohibited.

Australia does not operate an equivalent to the UK's open general-licence system in the same form. Australian export permits for controlled goods are generally transaction-specific, though some provisions allow for longer-term arrangements in certain circumstances. This means that businesses supplying controlled goods into or through Australia face a higher per-transaction administrative burden than equivalent flows managed under a UK open general licence. The absence of a like-for-like open-licence facility is a persistent structural difference that affects supply-chain planning for dual-jurisdiction exporters.

Timelines also diverge in practice. UK ECJU processing times for specific-licence applications vary by programme complexity and current queue. Australian DFAT processing is similarly variable. Neither regime publishes legally binding turnaround commitments that can be quoted as fixed deadlines here; both advise applicants to plan for meaningful lead times and to submit well in advance of contractual delivery dates. In our experience, underestimating the licensing queue in either jurisdiction is among the most common reasons a transaction slips or fails commercially.

How does the end-user undertaking process compare?

End-user undertakings – written commitments from the buyer or recipient about how goods will be used and whether they may be re-transferred – are a feature of both regimes, but the mechanics and weight attached to them differ.

Under the UK regime, the ECJU requires an end-user undertaking or end-user certificate in specific licence applications involving sensitive goods or destinations. The undertaking must come from the ultimate end-user, not merely the importer or broker. Where a supply chain has multiple links, the ECJU may require undertakings at each stage. The quality of the end-user undertaking forms part of the ECJU's assessment of the application; a weak or unverifiable undertaking is a reason for refusal or for attaching conditions. OFSI-licensed transactions involving counterparties in designated countries or those touching designated persons also require the licensed party to maintain records that demonstrate the transaction stayed within the licence terms.

Australia's system likewise requires end-user documentation for many controlled-goods exports. The specific form, content requirements, and the parties from whom undertakings must be obtained can differ from the UK's requirements. Australian requirements may also reflect the supplier-nation conditions imposed by the originating country of the technology – a relevant consideration for goods that are of US origin or contain US-origin components, since BIS and the EAR (Export Administration Regulations, the US rules governing dual-use exports) impose their own re-export and end-user conditions that travel with the goods regardless of where the immediate exporter is located.

That third-layer risk – US extraterritorial reach through BIS controls – is one that practitioners advising on OFSI-versus-Australia comparisons must address, even though it technically belongs to a third regime. A UK exporter of goods containing US-origin technology is simultaneously subject to ECJU rules, potentially OFSI rules, and BIS re-export conditions. The Australian buyer may face its own DFAT obligations. None of these regimes yield to the others; the stricter prohibition governs. For related analysis of how BIS's deemed-export rules compound this exposure, see our work on deemed exports under the BIS EAR.

In our cross-border practice, we find that multi-layered end-user documentation is the element most frequently incomplete when a transaction comes under regulatory scrutiny. A chain of undertakings that has a gap – typically at the level of a sub-distributor or an intermediate warehouse – is treated by regulators as an absence of documentation for that segment, regardless of good faith.

What are the record-keeping and reporting obligations in each regime?

Record-keeping is where compliance teams are most often caught out. Both the UK and Australian regimes impose obligations that extend beyond the transaction itself; they require ongoing maintenance of documentation that demonstrates continuous compliance with licence conditions and the relevant prohibitions.

Under the UK regime, OFSI's enforcement guidance requires those who hold or deal with frozen assets, or who operate under an OFSI licence, to keep records adequate to demonstrate compliance. The ECJU similarly imposes record-keeping conditions in its specific licences and as a condition of open general licence use. The applicable period for retention is specified in each instrument's conditions. Separately, SAMLA and the thematic sanctions regulations create reporting obligations: certain persons are required to report to OFSI where they know or have reasonable cause to suspect that they hold frozen assets, or that a person with whom they deal is a designated person. Failure to report is itself a criminal offence under the UK rules.

Australia's regime imposes comparable record-keeping requirements for controlled-goods exports and for compliance with autonomous-sanctions measures. The reporting architecture differs: Australia does not have a direct equivalent to the OFSI reporting obligation as drafted in UK law, though mandatory reporting obligations arise in financial services and other regulated sectors under separate legislative frameworks. The enforcement culture at DFAT in relation to autonomous-sanctions compliance has, in practitioners' experience, developed differently from OFSI's more explicit compliance-reporting regime.

One concrete difference is the treatment of voluntary disclosure. In the UK, OFSI's enforcement guidance acknowledges VSD (voluntary self-disclosure, a proactive report to the regulator of an apparent breach) as a factor that can reduce the severity of enforcement action, including civil monetary penalties. Australia's DFAT has a comparable expectation that prompt disclosure will be considered in enforcement decisions, but the formal framework for VSD and its effect on penalty outcomes is structured differently from OFSI's published approach. A business that has identified an apparent breach must take advice specific to each regime before deciding whether, when, and how to disclose – because a disclosure that is well-structured for OFSI may not be optimally structured for DFAT, and vice versa.

Which regime is stricter on end-user controls in practice?

Framing either regime as categorically "stricter" than the other is a simplification that tends to mislead. The more useful question is: stricter on what aspect, for what goods, and in what circumstances?

The UK catch-all end-use control is, in legislative design, broadly drawn. Its reliance on the exporter's awareness means that a business with sophisticated intelligence about its supply chain – or that has received an informal tip from a government body or a credible third party – carries a higher legal exposure than one that operated without that information. Australia's classification-led approach is, by contrast, more predictable in routine supply chains: if the goods are not listed, the principal prohibition concerns designated persons and autonomous-sanctions targets, rather than a general awareness-based catch-all. For a business that knows its goods and its counterparties well, the Australian system may feel more navigable. For a business operating in higher-risk sectors or with more opaque supply chains, the UK catch-all is the more demanding regime.

On financial sanctions specifically, OFSI's regime is among the more actively enforced financial-sanctions regimes in the world outside the United States. OFSI has civil monetary-penalty powers and a published enforcement guidance that sets out aggravating and mitigating factors. The regime is strict-liability in the sense that a lack of knowledge is not, in itself, a complete defence in a civil penalty context, though it is a mitigating factor. Australia's financial-sanctions enforcement through DFAT has been less prolific in terms of published penalty outcomes; however, the Australian Criminal Code imposes criminal liability for autonomous-sanctions breaches with significant maximum penalties, and the enforcement posture has been developing steadily.

A cross-border business that asks "which regime should I prioritise?" is asking the wrong question. Both apply simultaneously to a transaction with UK and Australian dimensions. The correct approach is sequential compliance mapping: identify the controlled-goods classification under each regime, identify any designated persons in the counterparty and ownership chain, confirm the end-use documentation required by each regime, and then layer the BIS obligations where US-origin content is present. For a comparative read on how a similar divergence plays out between OFSI and the EU, our analysis of OFSI versus EU end-use controls addresses the equivalent questions for European counterparts.

Common risk flags and when to involve counsel

Several patterns consistently produce compliance failures in cross-jurisdiction end-use and end-user control work. Recognising them early is the difference between a manageable disclosure and an enforcement referral.

The first risk flag is classification divergence. A UK exporter may confirm that its goods sit below the threshold for a UK export licence. It then assumes the goods are equally uncontrolled for Australian purposes. That assumption is wrong more often than compliance teams expect. The two regimes draw on shared international arrangements – the Wassenaar Arrangement, the Australia Group, the Missile Technology Control Regime – but national implementations vary. An item that qualifies for an open general licence under the UK regime may require a specific permit in Australia, or may trigger end-use documentation requirements that do not exist for the same item under the UK rules.

The second risk flag is counterparty ownership opacity. Both OFSI's financial-sanctions rules and Australia's autonomous-sanctions prohibitions capture entities that designated persons own or control. The relevant ownership threshold under both regimes, and the control test, must be applied to the full ownership chain – not merely the immediate contractual counterparty. In our experience, this is the single most common gap in compliance programmes: first-tier screening is robust, but second- and third-tier ownership analysis is absent or superficial. A distributor in Sydney whose majority shareholder is a listed person anywhere in the ownership chain is a prohibited counterparty regardless of how the business relationship is structured contractually.

The third risk flag is re-export and onward supply. Both regimes impose conditions on what happens to goods after the initial transfer. A UK-licensed export may not satisfy the conditions if the Australian recipient re-exports to a third country that is subject to a separate regime restriction. The licence conditions in each jurisdiction must be read together before the transaction is approved, not retrofitted after a downstream re-export has already occurred.

The fourth risk flag is dual-use technology transferred by non-physical means. Electronic transmission of technology – software, technical data, manufacturing know-how – is caught by both regimes, though the specific conditions differ. A UK exporter emailing a schematic to an Australian recipient has made a "transfer" for licensing purposes. Whether that transfer required a licence depends on the classification of the technology, the identity of the recipient, and the stated end-use. Businesses that have robust processes for physical shipments frequently lack equivalent controls for intangible transfers.

Is your technology-transfer process as well controlled as your physical shipments? In our experience, the answer is usually no – and that gap is increasingly the focus of regulatory attention in both jurisdictions.

When should a business involve counsel? At minimum: before a novel transaction structure involving controlled goods or technology in either jurisdiction; when a counterparty or its ownership chain raises concerns under either regime's designation lists; when an end-user undertaking is refused, qualified, or suspect; and when an apparent breach has been identified. Early involvement preserves options. A VSD that is well-timed and well-structured under both regimes' procedures is significantly more beneficial than one that arrives after the regulator has opened an inquiry.

For a micro-illustration: in a recent matter, a manufacturing business supplying specialised components discovered, mid-transaction, that an intermediate distributor had re-transferred goods to a recipient in a destination subject to UK and Australian sanctions measures. The business had clean paperwork to the level of the distributor but nothing on the downstream recipient. We assessed the apparent breach under both OFSI's and DFAT's enforcement frameworks, structured a coordinated disclosure to both regulators, and advised on the record-keeping adjustments needed to prevent recurrence. The matter progressed without a penalty proceeding. That outcome is not guaranteed in similar situations; it reflects the advantages of early, structured engagement.

The position above covers the standard case. Your facts – the goods, the counterparty, the ownership chain, the destination, and the regimes in play – change the analysis materially. If a transaction or a review has flagged a concern, an early consultation can clarify your position and identify the options available to you.

For an assessment of your exposure under both the UK and Australian regimes, contact Calder & Vance at info@caldervance.com.

Related practices

Frequently asked questions

Where do the regimes diverge on end-use and end-user controls?
The principal divergences are in the legal trigger for licensing, the availability of open general licences, the administrative structure of end-user documentation, and the reporting obligations attached to apparent breaches. The UK regime uses an awareness-based catch-all that extends licensing requirements beyond classified goods to situations where the exporter has reason to know of a prohibited end-use. Australia's equivalent protection is embedded more in the classification structure and autonomous-sanctions prohibitions. Neither regime replaces the other; both apply to a UK-Australia transaction simultaneously.
Which regime is stricter on end-use and end-user controls?
Neither regime is categorically stricter across all dimensions. The UK catch-all end-use control is more explicitly awareness-based and therefore demanding for businesses with sophisticated supply-chain intelligence. OFSI's financial-sanctions enforcement posture is among the most active outside the United States. Australia imposes strict criminal liability for autonomous-sanctions breaches and is developing its enforcement profile. The prudent approach is to map each regime independently rather than assume one subsumes the other.
What should a cross-border business do about end-use and end-user controls?
A cross-border business operating between the UK and Australia should classify its goods and technology against both regimes' control lists, screen counterparties and their full ownership chains against both designation lists, confirm end-user documentation requirements under each regime, and identify any BIS re-export conditions where US-origin content is present. Where any element of that analysis is unclear, or where a transaction raises designation or classification concerns, specialist counsel should be engaged before the transaction proceeds.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.