Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFSI

OFSI vs EU: End-use and end-user controls compared

A UK-based exporter ships specialist software to a distributor in a third market. The distributor's end-customer is a research institute. The institute, it later emerges, has connections to a programme that appears on both UK and EU control lists. The exporter assumed the sale was clean because the distributor was unrelated to any sanctioned entity. But the question of who ultimately uses the goods – and for what – is precisely where OFSI and the EU diverge in ways that can leave an exporter exposed even when the immediate counterparty screens clear.

End-use and end-user controls are legal obligations that restrict the transfer of controlled goods, software, and technology based on the declared final application and the identity of the ultimate recipient. In the United Kingdom, these rules sit across two overlapping regimes: OFSI administers financial sanctions that reach trade transactions, and the Export Control Joint Unit enforces export licensing and end-user undertakings under the Export Control Order. The EU operates a structurally comparable system under the EU dual-use rules and relevant Council regulations, but the two regimes differ materially on the threshold for triggering controls, the documentary standard required, and the enforcement posture regulators have adopted.

This analysis maps each point of divergence across the UK and EU regimes, identifies the practical risks for cross-border exporters, and explains when the gap between the two regimes requires targeted legal advice.

What are end-use and end-user controls, and why do they matter?

End-use and end-user controls govern the onward destination and application of goods, software, and technology after the first transfer – not simply who receives the initial shipment. An exporter may lawfully transact with its direct counterparty and still violate a control if it knew, or had reason to suspect, that the goods would be redirected to a prohibited application or an entity subject to designation.

Under the UK regime, the Export Control Order gives the Secretary of State authority to impose end-use controls on items that would not otherwise be controlled. This mechanism – sometimes called a catch-all – activates when the exporter is informed, or has grounds to suspect, that the goods are or may be intended for use in connection with weapons programmes or designated actors. OFSI sits alongside this: a UK-nexus transaction that involves a person or entity subject to an OFSI financial-sanctions designation triggers its own prohibition, regardless of whether the export licence has been granted.

In the EU, the dual-use regulation contains a structurally similar catch-all. An exporter must apply for a licence if it has been informed by the competent authority, or if it is aware, that items not listed on the EU control list are intended for use in connection with specified sensitive end-uses. The EU also operates a general obligation to exercise due diligence across the supply chain – a concept that has been reinforced and expanded through successive revisions to the dual-use rules.

Why does this matter for cross-border businesses? Because a business that exports under a valid UK Open General Export Licence may not automatically satisfy EU re-export requirements if the goods will subsequently move from an EU member state onward. The licences are not mutually recognised. Each jurisdiction evaluates the transaction independently, against its own threshold.

How do the UK and EU catch-all thresholds differ?

The trigger for the UK and EU catch-all controls is expressed in similar terms but interpreted differently in practice. Both require the exporter to act when it "knows" or has reason to believe the controlled use is intended. The divergence is in how regulators and enforcement bodies have developed the standard of awareness that is sufficient to activate that obligation.

Under UK rules, the ECJU has issued guidance indicating that exporters should apply heightened scrutiny when dealing in sectors, destinations, or transaction structures that are associated with diversion risk. The standard is objective: the question is whether a reasonable exporter in the same circumstances would have recognised the risk. A subjective belief that the end-use was benign provides no shelter if the warning signs were present.

The EU's approach in recent years has moved towards a more demanding diligence standard. The revised dual-use regulation introduced an explicit expectation that exporters assess not just the direct customer but the transaction's wider supply-chain context. Competent authorities in several member states have applied this to require enhanced end-user statements in circumstances where the UK's ECJU might have accepted a standard undertaking.

The practical consequence is asymmetric. An exporter that satisfies the UK's objective-knowledge threshold may still face an EU competent authority's demand for additional documentation on the same transaction. We regularly advise exporters who discover this gap only after a shipment has cleared UK customs but is then queried at an EU transit point.

Is the EU catch-all therefore stricter? Not always. The UK's OFSI dimension adds a layer that has no precise parallel in the EU dual-use rules. A UK-nexus transaction involving a counterparty that is subject to an OFSI designation is prohibited regardless of the end-use question. The EU financial-sanctions regime imposes an equivalent prohibition, but the interaction between EU trade controls and EU financial sanctions does not carry the same single-regulator integration that OFSI and ECJU maintain in UK practice.

End-user undertakings: what each regime requires

An end-user undertaking is a written commitment, typically from the consignee or ultimate end-user, that the goods will be used as declared and will not be re-exported without authorisation. Both the UK and the EU require these undertakings in a range of controlled-goods transfers, but the form, scope, and enforceability of those documents differ materially.

Under UK practice, the ECJU prescribes standard-form end-user undertakings for specific licence applications. The document must identify the goods, the declared end-use, and the ultimate consignee. It must be signed by an authorised representative of the end-user and returned to the exporter for retention. Record-keeping obligations apply to the exporter: both the undertaking and the related export documentation must be retained for a period that, as a general rule under the Export Control Order, extends to a minimum of four years from the date of export, though the exact period should be verified against the current rules before reliance.

In the EU, end-user statements are required under the dual-use regulation for a range of individual licence applications and in certain open-licence conditions. The EU's model end-user statement includes additional fields compared with the standard UK form: a declaration of no re-export to a third country without prior authorisation, a statement as to the intended use by application category, and in some member states a certificate from the competent authority of the destination country. Germany, France, and the Netherlands – all significant exporters of controlled technology – apply additional national requirements on top of the EU baseline.

This divergence creates a real operational problem for UK exporters selling into or through EU territory. A UK-issued end-user undertaking, even where it is comprehensive under UK standards, may not satisfy the EU competent authority's requirements for an equivalent transaction. In our experience, businesses that rely on a single template across both jurisdictions encounter delays and, in some cases, refusals at the EU licensing stage.

The position above covers the standard case. Your specific transaction – the goods, the classification, the destination, and the end-user – changes the analysis. For an assessment of your documentary requirements under both regimes, contact Calder & Vance at info@caldervance.com.

Where does OFSI's role begin in a dual-use export transaction?

OFSI's role in a dual-use export transaction begins the moment any party in the transaction chain is subject to, or is directly or indirectly owned or controlled by a party subject to, a UK financial-sanctions designation. At that point, the export is not simply a licensing question – it becomes a prohibited transaction under the relevant UK financial-sanctions regime, irrespective of whether an export licence has been granted.

This intersection is a persistent source of confusion. Export counsel focus on the classification of the goods and the licensing position; sanctions counsel focus on the counterparty and the ownership chain. When OFSI sanctions and ECJU licensing obligations converge on the same transaction, neither analysis is sufficient on its own. We have acted for businesses that held a valid export licence and proceeded with a shipment, only to face an OFSI inquiry when it emerged that the end-user's parent company was subject to a designation imposed after the licence was issued.

The EU equivalent is the Council regulations implementing financial sanctions, which sit alongside the dual-use regulation. A transfer that would require an EU export licence may independently be prohibited under EU financial sanctions if the end-user is designated. However, the EU does not have a single authority equivalent to OFSI that administers both financial sanctions and export controls under one institutional roof. The two tracks are enforced by different bodies, which means an EU exporter faces a multi-authority compliance check that in the UK is concentrated in two closely related government departments.

The practical lesson is straightforward. Any export-control review that reaches a positive licensing conclusion must be followed, or accompanied, by a sanctions screen of every party in the transaction chain: the buyer, the end-user, the freight forwarder, and any intermediate distributor. A counterparty screen at deal inception is not sufficient; the screen must be refreshed at the point of shipment, because designations are imposed without notice and at any time.

Risk flags: the scenarios where the regimes diverge most sharply

The divergences between the UK and EU regimes are not evenly distributed across transaction types. Certain scenarios concentrate the risk and produce materially different compliance obligations depending on which regime applies – or, for cross-border exporters, both.

Re-export through an EU distributor. A UK exporter may ship under an Open General Export Licence to an EU distributor, with the expectation that the distributor will sell on to end-customers. If those end-customers are in a third country, the re-export leg falls under EU jurisdiction. The EU's rules on re-export authorisation in the end-user statement may require the distributor to obtain a separate national licence or a Commission-level authorisation. The UK OGLE provides no cover for that leg. The exporter has completed its UK compliance obligation; the distributor faces an EU one that the transaction structure may not have anticipated.

Software and technology transfers. The UK's deemed-export and technology-transfer rules apply to the communication of controlled technology to a foreign national, not only to the physical shipment of goods. The EU's dual-use regulation contains a comparable provision. Where the two regimes define the controlled technology category differently – and they do diverge at the margin, particularly following the UK's post-2021 regulatory divergence from the EU control list – a transfer that is licence-free in one jurisdiction may require a licence in the other. For a detailed treatment of deemed-export issues under the US EAR and their interaction with EU and UK rules, see our analysis at Deemed-Export and Technology Controls: BIS / EAR Service.

Dual-use items supplied to research institutions. Academic and research end-users present a particular challenge. Both the UK and EU catch-all controls have been applied in circumstances where goods were transferred to an institution with ostensibly civilian research purposes but which had undisclosed connections to a controlled programme. The EU has in recent years issued guidance specifically addressing academic and research end-users in sensitive fields. UK guidance is less detailed on this specific scenario, and the ECJU has not always given clear pre-clearance comfort where the end-user profile is ambiguous.

OFSI financial-sanctions hit mid-shipment. A designation imposed after an export licence has been granted but before the goods are delivered creates an acute problem. The export licence does not authorise the underlying financial transaction if the counterparty is now designated. In this scenario the exporter must stop the transaction, report the position to OFSI, and seek guidance on whether a specific licence or an interim freeze of assets is required. The EU's procedure in an equivalent scenario requires notification to the competent financial-sanctions authority and a freeze of any funds involved, but the administrative process differs by member state.

If a transaction has already been flagged, or a compliance question has arisen mid-shipment, an early review preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.

How do the enforcement postures of OFSI and the EU compare?

OFSI and the EU's national competent authorities adopt different enforcement approaches, and that divergence has direct implications for how exporters should calibrate their compliance investment across the two regimes.

OFSI operates as a civil-enforcement body for financial sanctions in the UK. It has the power to impose monetary penalties for breaches, and its enforcement guidance indicates that both the nature of the breach and the quality of the compliance programme at the time of the breach will be considered in determining a penalty. A strong compliance programme with documented due diligence, including end-use and end-user screening, can be a material mitigating factor. OFSI has published its methodology for calculating penalties, which takes account of the value of the breach, the degree of culpability, and co-operation with the investigation. Voluntary self-disclosure – where a business reports its own potential breach before OFSI investigates – is treated as a mitigating factor and can result in a material reduction in the penalty outcome, though no specific reduction percentage is guaranteed.

On the EU side, enforcement of dual-use controls and financial sanctions is fragmented across member state competent authorities. There is no single EU-level enforcement body for these rules equivalent to OFSI or BIS. The result is that an exporter dealing with EU-connected transactions may face investigations by two or more national authorities simultaneously, each applying its own enforcement priorities and penalty ranges. In our cross-border practice, we have seen clients face parallel investigations in two EU jurisdictions for a single transaction series, because each authority considered the EU-law breach to have occurred in its territory.

Criminal liability is also allocated differently. Under UK law, knowing or reckless breach of a financial-sanctions prohibition can give rise to criminal prosecution, separate from OFSI's civil enforcement track. The ECJU similarly has criminal-prosecution powers for export-control breaches. In the EU, criminal sanctions for export-control breaches are a matter of national law; the EU has moved to harmonise the criminal-law framework but implementation across member states remains uneven.

The enforcement divergence creates a practical recommendation: compliance documentation that would satisfy an OFSI enforcement review should be designed also to satisfy the stricter of the EU member state standards in the relevant transaction markets. Building to the higher standard once is more cost-efficient than retrofitting documentation when a multi-authority investigation begins.

Practical steps for cross-border exporters managing both regimes

Effective compliance across the UK and EU regimes requires a structured approach that integrates export-control classification with sanctions screening and treats end-use documentation as a living record rather than a box-ticking exercise.

The decision sequence for a cross-border exporter managing both regimes looks, in practice, as follows.

First: Classify the goods or technology under both the UK and EU control lists. Post-2021 divergence means the classification result may differ. Where the lists diverge, the more restrictive outcome governs the relevant jurisdiction. For a comparison of how the EU and Switzerland handle entity-list screening in this context, the analysis at Entity List Screening: EU vs SECO illustrates the multi-regime structure that exporters must manage.

Second: Screen every party in the transaction chain against the UK Consolidated List, the EU Consolidated List, and – where the goods have potential US-origin content or technology – the OFAC SDN List and BIS Entity List. Screening must cover the buyer, the consignee, the declared end-user, and any known intermediate parties. The screen should be documented and dated, and repeated at shipment.

Third: Assess the end-use. Apply the UK catch-all test: is there any information that the goods are or may be intended for a sensitive end-use or a controlled programme? Apply the EU test in parallel. Where either test produces a positive answer, do not proceed without specific licence advice.

Fourth: Obtain end-user documentation to the higher of the two regimes' standards. Where the EU member state of transit or destination imposes additional requirements, build those into the standard form. Retain the signed documentation for at least the minimum record-keeping period under both regimes.

Fifth: Establish a mid-transaction monitoring trigger. Designations and list changes occur without notice. A transaction that was clean at inception can become a controlled or prohibited one before delivery. Compliance programmes that lack a pre-shipment re-screening step are routinely the ones that generate enforcement inquiries.

For a structured assessment of your export-control and end-use obligations under both the UK and EU regimes, and of the interaction with BIS and EAR requirements where US-origin technology is involved, see our service page at Entity List Screening: BIS / EAR vs EU Analysis.

A common misconception about end-use controls

A persistent belief among cross-border businesses is that obtaining an export licence from one jurisdiction's authority means the transaction is clear for all connected jurisdictions. This misreading accounts for a significant proportion of the compliance failures we see in practice.

An export licence granted by the ECJU covers the transfer of controlled goods from the United Kingdom. It provides no authority for an EU re-export leg, no assurance that an EU national competent authority will not require its own licence, and no protection against an OFSI prohibition if a party in the chain is subsequently designated. Equally, an EU individual export licence issued by a member state competent authority does not satisfy UK requirements if the goods will subsequently pass through or be exported from UK territory.

The same logic applies in reverse to end-user undertakings. A UK-standard end-user undertaking, even where it is well-drafted and properly executed, will not satisfy every EU member state's requirements for the same transaction. The EU's expectation – particularly in the context of the revised dual-use regulation – is that end-user documentation is specific to the jurisdiction in which it is deployed. A generic template will not cover the gap.

Why does this misconception persist? In part because the two regimes share terminology – "end-use control", "end-user undertaking", "catch-all" – that creates a false impression of harmonisation. The language is similar; the standards are not. Compliance counsel advising on cross-border transactions must treat each regime on its own terms, identify the divergences, and build the transaction structure to satisfy both.

Related practices

Frequently asked questions

Where do the regimes diverge on end-use and end-user controls?
The UK and EU regimes share the same catch-all structure but diverge in three material areas: the documentary standard for end-user undertakings, the degree to which the catch-all obligation is supplemented by national guidance in EU member states, and the institutional architecture – OFSI and ECJU in the UK versus a fragmented multi-authority structure in the EU. Post-2021 regulatory divergence on the control list also means that classification results do not always align, so a transaction that is licence-free under one regime may require a licence under the other. Exporters should verify the current position on control-list alignment before relying on a single-jurisdiction classification.
Which regime is stricter on end-use and end-user controls?
Neither regime is uniformly stricter. The EU's revised dual-use rules have moved towards a more demanding due-diligence expectation in certain sectors and destinations. The UK's OFSI dimension, however, adds a financial-sanctions overlay that can prohibit a transaction outright when a designated party appears anywhere in the supply chain, including after the export licence has been granted. In practice, the stricter outcome depends on the goods, the destination, and the counterparty profile. Cross-border exporters should apply the higher of the two standards at each stage of the transaction.
What should a cross-border business do about end-use and end-user controls?
A cross-border business should start by classifying the goods under both the UK and EU control lists and screening every party in the transaction chain against both regimes' lists. It should then obtain end-user documentation to the higher of the two documentary standards, implement a pre-shipment re-screening step, and retain the documentation for the full record-keeping period under each regime. Where a transaction involves US-origin technology, BIS and EAR obligations must be layered on top. Specialist counsel should be involved when a catch-all trigger is in question, when a counterparty has a complex ownership structure, or when a designation arises mid-transaction.
About the author
Henry Ashworth advises on UK financial sanctions and export controls, including OFSI licensing and enforcement, and judicial-review challenges to designations. He regularly acts for exporters, manufacturers, and financial institutions on the interaction between OFSI financial-sanctions obligations and ECJU export-licensing requirements in cross-border transactions. Calder & Vance – International Sanctions & Export Control Counsel.
About Calder & Vance
Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.