A multinational exporter ships advanced electronic components from a European facility to a Canadian distributor. The goods sit on the EU dual-use list. They may also fall under the US Export Administration Regulations. And the Canadian buyer sources financing from a US correspondent bank. Suddenly, three separate regimes are in play simultaneously – and each applies a different classification logic.
EU dual-use classification, OFAC sanctions exposure, and Canadian export-control obligations follow distinct legal frameworks, administered by different authorities, applying different thresholds and list structures. As of April 2026, a business moving controlled goods across the Atlantic must satisfy all three regimes concurrently; satisfying one does not discharge the others. The strictest applicable prohibition governs at every step.
This analysis maps the key divergences between the EU dual-use classification regime and the US OFAC and Canadian regimes, identifies where the conflicts create practical risk, and sets out the decision sequence a cross-border business should follow before committing to a transaction.
What legal authority governs each regime – and why does the gap matter?
The EU dual-use regime, the US controls administered by OFAC and BIS, and the Canadian export-control regime each draw on separate statutory authority, administered by separate agencies, and enforced with separate penalty structures. Understanding who is in the room is the first step in any classification analysis.
In the European Union, the legal basis is the relevant Council Regulation on the control of exports, brokering, technical assistance, transit, and transfer of dual-use items. Licensing decisions are made at member-state level by national competent authorities, but the substantive list – the EU Dual-Use List – is set at Union level and mirrors the multilateral export-control regimes. The European Commission coordinates and the Council legislates; enforcement is a member-state function. This matters because a French exporter and a German exporter operating under the same EU regulation may face different national administrative practices.
In the United States, export-control authority over dual-use goods sits primarily with the Department of Commerce, Bureau of Industry and Security, under the Export Administration Regulations. OFAC, by contrast, administers economic sanctions under IEEPA and related statutes. The two instruments operate in parallel: BIS controls the movement of goods, software, and technology based on the item's characteristics and destination; OFAC controls transactions with designated persons and embargoed destinations regardless of what is being moved. A shipment can clear BIS licensing requirements and still be prohibited under OFAC if a sanctioned person touches the transaction. The distinction between a BIS export-licence question and an OFAC sanctions question is not always obvious to a compliance team that handles both.
Canada administers export controls under its domestic export-control legislation, with the relevant permit and list framework maintained by Global Affairs Canada. Canada participates in the same multilateral control regimes as the EU and the United States, so the underlying control lists share common ancestry. However, Canada's permit structures, enforcement posture, and interaction with US secondary-sanctions risk follow their own logic. In our cross-border practice, businesses often assume that because Canada is a close ally of the United States, the two regimes are functionally equivalent. They are not.
Related practices
- Deemed export and technology controls under the EAR – US BIS classification, deemed-export analysis, and licence applications for technology transfers
- EU dual-use classification: OFAC vs EU divergences – detailed comparison of EU and US classification tests and licensing routes
The position above covers the structural baseline. Your facts – the specific item, the end-user, the financing chain, and the route – change the analysis materially. For an assessment of your exposure across these regimes, contact Calder & Vance at info@caldervance.com.
How does EU dual-use classification work, and where does the US EAR diverge?
EU dual-use classification is a two-stage inquiry: first, does the item appear on the EU Dual-Use List by reference to its technical parameters; second, does any catch-all control apply to require authorisation even for unlisted items destined for certain end-uses or end-users. The item-based list is organised by category and by control parameter – technology, software, or goods – and the parameters are drawn from the Wassenaar Arrangement, the Nuclear Suppliers Group, the Australia Group, and the Missile Technology Control Regime.
The US Export Administration Regulations use a parallel structure. Each item on the Commerce Control List carries an ECCN (Export Control Classification Number under the US Commerce Control List), which maps reasons for control – national security, nuclear non-proliferation, missile technology, anti-terrorism, and others – to licence requirements and licence exceptions by destination, end-user, and end-use. An item that sits in a given EU classification category will often, but not always, map to a US ECCN in the same multilateral-regime category. The divergences arise at the edges of each list, in the technical parameters, and in the exceptions available.
Three structural differences generate the most frequent compliance problems. First, the EU uses a single integrated list; the US maintains the Commerce Control List alongside separate US Munitions List items under ITAR, which is administered by the State Department. An item classified as dual-use under EU rules may be munitions-listed under US rules – a far more restrictive category. Second, the EU's catch-all controls are framed around specific end-use concerns, with a particular focus on weapons of mass destruction end-use and military end-use in arms-embargoed destinations. The US EAR's catch-all logic, while conceptually similar, operates through a different set of red-flag criteria and engages OFAC's sanctions prohibitions as a separate and additional layer. Third, the EU's intra-EU transfer regime differs from the US deemed-export rule: in the EU, transfers of controlled technology within the Union are generally exempt from export authorisation; under the US EAR, a release of controlled technology to a foreign national within the United States can itself constitute a deemed export requiring authorisation.
In our experience, the deemed-export divergence is the single issue most likely to be overlooked by a European company establishing a US presence. A German company that has classified its technology under the EU regime and put an internal-transfer procedure in place may not have addressed the deemed-export exposure that arises when it employs non-US nationals in its US operations.
Where does Canada diverge from both the EU and the US classification frameworks?
Canada's export-control list is derived from the same multilateral regimes as the EU and US lists, but Canada's permit structures, general permit categories, and enforcement patterns differ in ways that matter for cross-border planning. Canada applies both an export-permit requirement and, in the context of the Canada–United States relationship, a set of bilateral arrangements that affect how US-origin goods and technology move through Canada.
The first point of divergence concerns US-origin goods re-exported through Canada. A shipment of US-origin controlled goods that moves from the United States to Canada and then on to a third country must satisfy both the US re-export controls under the EAR and Canadian export-permit requirements. The two do not simply stack: a Canadian general export permit that covers a particular destination does not discharge the US re-export licence requirement for US-origin controlled content. Businesses that treat the Canadian permit as the full answer to the compliance question take on material US enforcement exposure.
The second divergence concerns OFAC's extraterritorial reach. OFAC's prohibitions extend to US persons wherever located and to transactions with a US nexus – including US-dollar clearing, US financial institutions, and US-origin goods. A Canadian company that has no US operations but uses US correspondent banking, sources US-origin components, or employs US-person employees may have direct OFAC obligations. Those obligations sit entirely outside the Canadian export-control regime and are not discharged by compliance with Canadian law. Where does your counterparty's financing come from? If the answer involves a US bank, the OFAC analysis is mandatory regardless of where the underlying goods are classified.
The third divergence involves the classification of military end-use items. Canada has its own controls on exports to destinations where the goods may contribute to a military programme of concern. The EU has its own military end-use catch-all. The US EAR contains a military intelligence end-use and end-user control that is broader than either. A single item may require separate and independent analysis under all three frameworks before the exporter can be confident it has cleared each one.
How do OFAC's sanctions prohibitions interact with dual-use classification decisions?
OFAC's sanctions prohibitions operate independently of – and in addition to – the export-classification analysis. An item may be EAR99 (not listed on the US Commerce Control List) and still be prohibited from export if the buyer is an OFAC-designated person, an entity owned 50 percent or more by a blocked person in the aggregate, or a person located in a comprehensively sanctioned destination.
The relationship between the two bodies of US law is sequential. The first question is always the OFAC question: is this person, entity, or destination subject to sanctions that prohibit the transaction entirely? If the answer is yes, the BIS classification analysis is academic. If the answer is no, the BIS analysis proceeds. Reversing this sequence – classifying first and then running a brief sanctions screen – creates the risk that a prohibited transaction is cleared on the classification side before the sanctions prohibition is even considered.
For EU and Canadian exporters, OFAC's reach extends through the US-nexus rules. A transaction conducted in US dollars clears through US correspondent banks, which are US persons for OFAC purposes. A supplier that incorporates US-origin controlled content – above the applicable de minimis threshold under the EAR – carries US re-export obligations into the final product. And a company with US-person employees, directors, or shareholders may have US-person obligations that bite regardless of where the company is incorporated.
In a recent matter, a European-headquartered trading company with a Canadian sales subsidiary sought to supply industrial equipment to a third-country buyer. The equipment was EU dual-use listed and held a valid EU export authorisation. The Canadian subsidiary's general export permit appeared to cover the destination. But the financing was structured through a US correspondent bank, and a minority shareholder in the buyer group appeared on OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons). We assessed the ownership chain, confirmed that the aggregate blocked-person holding did not reach the 50 percent threshold, and advised on the steps required to document that determination. The export authorisations remained valid; the US nexus required an additional OFAC analysis that had not been part of the original compliance plan.
If a transaction has already been flagged under any of these regimes, or a filing has been refused, early legal review preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.
What are the key risk flags in a cross-regime EU dual-use classification review?
Compliance failures in cross-border dual-use transactions almost always follow identifiable patterns. Identifying the pattern early is what allows a business to adjust before an enforcement notice arrives.
The first risk flag is an incomplete classification. An item is classified under one regime and the classification is assumed to transfer. EU classification does not establish US ECCN. Canadian permit coverage does not discharge US re-export controls. Each classification must be done independently, under each regime's own list and parameters.
The second risk flag is the layered-ownership problem. Screening the named buyer is not enough. The 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) operates on aggregate, indirect holdings. Two listed persons each holding a minority stake may together reach the threshold. We regularly advise on ownership-chain mapping precisely because first-layer screening misses this pattern consistently.
The third risk flag is the technology and software dimension. Physical goods are the most visible part of an export transaction, but controlled technology and software – including technical assistance, training, and cloud access to controlled software – are often caught by the same list controls and sometimes by tighter ones. An EU exporter that has obtained an authorisation for goods may not have considered whether the related installation support, maintenance training, or software update constitutes a separately controlled export.
The fourth risk flag is the re-export chain. Where goods pass through an intermediary – a distributor, a freight forwarder, a trading house – the exporter retains its own direct obligations. An end-use certificate signed by a distributor does not eliminate the exporter's exposure if the distributor on-sells to a prohibited end-user. Both the EU and the US regimes impose due-diligence obligations on the original exporter, not just on the immediate buyer.
The fifth risk flag is the financing and payment route. OFAC's secondary-sanctions exposure follows the money as well as the goods. A transaction that is fully compliant from a goods-movement perspective can generate OFAC exposure if a sanctioned-country financial institution processes any part of the payment, or if a US-dollar correspondent bank is instructed to process a payment for the account of a blocked person.
Which regime is effectively stricter – and how should a cross-border business choose its baseline?
The strictest applicable prohibition governs at every decision point. This is not a choice – it is the legal position across all three regimes. A business cannot elect to be governed by the most permissive of the three frameworks when it has obligations under all three.
In practical terms, OFAC's comprehensive-sanctions programmes tend to create the broadest absolute prohibitions, because they attach to persons and destinations regardless of the nature of the goods. A transaction with a blocked person is prohibited under OFAC even if the goods are EAR99 and unlisted under EU dual-use rules. In that sense, OFAC's person-based prohibitions are a floor beneath any export-classification analysis.
The EU's catch-all controls can, however, produce a stricter outcome for transactions involving WMD-related end-uses or military end-uses in embargoed destinations, because the catch-all can require authorisation even where the goods are not on the dual-use list at all. A transaction that generates no BIS licence requirement and no OFAC prohibition could still require an EU authorisation if the competent authority determines that a WMD-related end-use is a risk. The EU's military end-use catch-all, which applies to destinations under an EU arms embargo, is a distinct additional layer.
Canada's permit regime, while derived from the same multilateral foundations, can produce different outcomes at the level of specific destinations and specific items because Canada's autonomous sanctions and its export-permit policy may diverge from both the EU and the US at the margin. Canada also has its own blocking-statute response to certain third-country sanctions, which can create a conflict-of-laws problem for a Canadian company that is also a US person or that has US-person employees.
The practical answer for a cross-border business is to run all three analyses in parallel, to identify which is strictest for the specific transaction, and to treat that as the operative compliance standard. Attempting to identify the most permissive regime and anchor the compliance plan to it is a recognised enforcement risk – and in our experience it is the approach that generates the disclosure and penalty conversations.
What is the decision sequence a business should follow before committing to a transaction?
A disciplined pre-commitment sequence reduces the risk that a compliance problem surfaces only after a contract is signed, goods are shipped, or payment is processed. The sequence has six steps, and none of them can safely be skipped.
Step one: identify all applicable regimes. Map where the goods originate, where they will be shipped, who is involved in the transaction (exporter, buyer, end-user, financier, freight forwarder), and what US, EU, and Canadian connections exist in the chain. OFAC's reach extends through US-dollar transactions, US-origin content, and US-person involvement; EU rules follow the goods from EU territory; Canadian rules apply to exports from Canada including re-exports of foreign-origin goods.
Step two: classify the item under each applicable regime independently. EU dual-use classification is done against the EU Dual-Use List by technical parameter. US classification is done against the Commerce Control List to determine the ECCN. Canadian classification is done against the Canadian export-control list. These are three separate analyses producing three separate results. Do not assume concordance.
Step three: run the OFAC screen. Before assessing whether a licence is required, confirm that the transaction is not prohibited outright by OFAC. Screen the buyer, the end-user, the intermediaries, the financing parties, and the beneficial-ownership chain. Apply the 50 percent rule to any entity that has a blocked-person shareholder. Confirm that the destination is not subject to a comprehensive OFAC programme.
Step four: assess licence requirements and available exceptions under each applicable regime. For the EU, identify whether a Union general export authorisation, national general authorisation, or global or individual authorisation is required. For the US, identify whether an EAR licence exception applies or whether a BIS licence application is required. For Canada, confirm permit requirements and whether a general export permit covers the transaction. Verify that each authorisation or exception is valid for the specific end-user, destination, and end-use.
Step five: document the analysis. Record the classification rationale, the screening results, the ownership-chain analysis, and the licence or exception relied upon for each regime. Record-keeping obligations attach to export transactions under all three regimes, and documentation produced contemporaneously with the transaction is materially more defensible in an enforcement context than a reconstruction prepared after the fact.
Step six: build in ongoing monitoring. Designated-person lists are updated without notice. End-users can change ownership. Licence conditions can be varied. A transaction that is compliant on day one of the contract may require re-assessment before the final shipment or the final technical-support visit.
Common misconceptions about cross-regime EU dual-use classification compliance
One widely held misconception is that multilateral-regime membership creates interoperability between the EU, US, and Canadian controls. It does not. The EU, the US, and Canada are all members of Wassenaar, the NSG, the Australia Group, and MTCR. The underlying multilateral lists feed into each domestic control regime. But each jurisdiction then translates the multilateral commitments into its own domestic law, with its own terminology, its own exceptions, its own penalties, and its own administrative practice. Membership in the same club does not mean the rules are the same.
A second misconception concerns the scope of OFAC's reach over non-US companies. We regularly advise European and Canadian businesses that OFAC is a concern only for US companies. This is not accurate. OFAC's secondary-sanctions programmes create risk for non-US companies that conduct transactions in US dollars, use US financial-institution services, or deal in US-origin goods or technology. A European company that has never operated in the United States and has no US employees can still face material OFAC exposure if its correspondent bank is US-chartered or if its goods contain US-origin controlled content above the applicable threshold.
A third misconception is that a voluntary self-disclosure (VSD – a voluntary self-disclosure to a regulator) always produces a substantially reduced penalty. Under OFAC's enforcement guidelines, a timely and complete VSD is a significant mitigating factor, but it does not guarantee a specific outcome. The nature of the violation, the degree of wilfulness, the harm caused, and the compliance culture of the submitting company all affect the result. The same logic applies under the relevant Canadian and EU frameworks. VSD is a compliance tool, not a penalty waiver.
For an analysis of how these frameworks interact on your specific transaction or export programme, contact Calder & Vance at info@caldervance.com.