A manufacturer based in the United Kingdom receives an export licence approval from ECJU for a controlled item. Its EU-based distributor then ships a variant of the same product to a third country. Both parties assumed the classifications were equivalent. They were not. The EU list had been updated; the UK list had not yet followed. The shipment proceeded without a required licence. That gap – assumed equivalence between two post-Brexit regimes that were once identical – is the single most common error we see in cross-border export-control matters.
As of April 2026, the UK and EU operate separate dual-use export-control regimes. The EU applies its own dual-use regulation directly, administered at member-state level with Commission oversight. The UK applies its own statutory regime, administered by ECJU, with OFSI holding a parallel role on financial-sanctions aspects of controlled transactions. The two lists diverged the moment the UK left the EU's regulatory orbit. A classification that clears one regime does not automatically clear the other. For cross-border transactions, both must be assessed independently.
This analysis sets out where the UK and EU regimes diverge on dual-use classification, how OFSI's financial-sanctions authority intersects with ECJU's export-licence function, and where businesses – particularly those operating supply chains that cross the Channel – are most exposed.
What is EU dual-use classification, and who administers it?
EU dual-use classification is the process of determining whether goods, software, or technology fall within the EU's controlled list, triggering a requirement for an authorisation before export. The EU's dual-use regulation is directly applicable across all EU member states. Classification decisions are made by exporters, with competent authorities in each member state providing guidance and enforcement. The classification list is the annexe to the EU regulation, which the EU periodically updates to reflect the Wassenaar Arrangement, the Nuclear Suppliers Group, and other multilateral export-control regimes.
The EU regulation covers a wide scope: physical goods, intangible technology transfers, software, and brokering services. Each item on the controlled list carries a technical specification. The specification is precise. A product is controlled if it meets the stated technical parameters; it is not controlled if it does not. In practice, the boundary is often contested. Manufacturers optimise their products near control thresholds, and small technical changes can push an item in or out of scope. That is why classification is a legal and technical exercise, not a box-tick.
Enforcement authority in the EU sits with national competent authorities. There is no single EU enforcement body. The European Commission coordinates and issues guidance, but penalties for unlicensed exports are set and imposed at the national level. Exporters trading across multiple EU member states therefore face a degree of national variation in enforcement posture, even though the underlying classification list is uniform.
How does the UK regime differ after Brexit?
The UK's export-control regime is now fully distinct from the EU's. ECJU administers export licensing under the statutory regime set by the Export Control Order and the Sanctions and Anti-Money Laundering Act ("SAMLA") architecture. The UK dual-use list was initially identical to the EU list at the point of Brexit, but the two lists have since diverged as each jurisdiction has implemented Wassenaar updates and made independent classification decisions.
This divergence has practical consequences. An item that is not controlled under the EU list may be controlled under the UK list, or vice versa. A business that classifies its product solely against the EU list and then exports from or through the UK is working with an incomplete picture. The reverse is equally true for businesses that classify against the UK list and then route a shipment through an EU member state.
The divergence is not radical – the two lists remain substantially similar, rooted in the same multilateral agreements – but the margin of difference is real and growing as each regime independently implements updates. In our practice, the most common divergence points involve specific technical parameters in the electronics, telecommunications, and materials categories. These are areas where the Wassenaar technical working groups have produced updated specifications that each jurisdiction has implemented at a slightly different pace.
One further distinction matters. The UK regime applies extraterritorially in a number of respects. UK nationals and companies incorporated in the UK may be subject to UK export-control requirements regardless of where the physical export originates. A UK-owned subsidiary in an EU member state exporting a controlled item may face UK obligations in addition to EU ones. The two regimes stack rather than substitute for each other.
Where does OFSI's authority intersect with export-licence decisions?
OFSI's role is financial sanctions, not export licensing – but the two regimes intersect in ways that compliance teams frequently overlook. OFSI administers the UK's financial-sanctions regime under SAMLA and the relevant thematic regulations. Its prohibitions cover making funds or economic resources available to designated persons. Where an export transaction involves a counterparty that is, or may be, designated under a UK sanctions regime, both the ECJU licensing question and the OFSI financial-sanctions question arise simultaneously.
Consider the practical scenario. A UK exporter secures an ECJU export licence for a dual-use item. It then contracts with a buyer whose beneficial owner appears on the UK Consolidated List. The ECJU licence does not resolve the OFSI prohibition. The export-licence approval and the financial-sanctions clearance are separate legal questions answered by separate authorities under separate instruments. A business that treats an ECJU licence as a green light for the whole transaction is exposed on the OFSI dimension.
The interaction runs in the other direction too. An OFSI licence to transact with a designated person does not authorise the export of a controlled item. The exporter still needs an ECJU authorisation for the goods. This two-track structure – financial sanctions on one track, export controls on the other – is not replicated identically in the EU, where the financial-sanctions regime and the dual-use regulation interact differently, with member-state competent authorities sometimes holding responsibility for both aspects.
We regularly advise clients who have obtained one approval and assumed the other is covered. It is not. The position is clear in the legislation, but operationally it is easy to miss, particularly where compliance responsibilities are split between a trade-finance team managing the ECJU side and a financial-crime team managing OFSI exposure.
The position above covers the standard case. Your facts – the counterparty, the goods, the route, the UK and EU regimes in play – change the analysis. For a review of how OFSI and EU dual-use obligations interact on a specific transaction, contact Calder & Vance at info@caldervance.com.
How do the EU and UK ownership-and-control tests differ in this context?
Both the UK and EU apply ownership-and-control tests to determine whether a non-listed entity is caught by financial-sanctions prohibitions through its relationship with a listed person. Under OFSI, the test looks at ownership of more than 50 percent of shares or voting rights, or the right to appoint or remove a majority of the board, or the exercise of dominant influence. Under the EU regime, the test is broadly comparable but applied by member-state competent authorities, who may take slightly different positions on what constitutes dominant influence in practice.
For dual-use export transactions, this matters because the financial-sanctions prohibition on making economic resources available can be triggered by an export even where the buyer is not itself listed, if the buyer is owned or controlled by a listed person. A business that screens only the named buyer and not the ownership chain is working with an incomplete screen. The controlled-item classification is irrelevant if the financial-sanctions prohibition is already engaged at the counterparty level.
The divergence between OFSI and EU tests on the control element – specifically, what counts as dominant influence – can produce different answers on the same fact pattern. A buyer that a UK-based compliance team clears under the OFSI test might still be caught under the EU test applied by a competent authority in the relevant member state. For businesses with supply chains that touch both jurisdictions, a conservative approach is to apply both tests and take the stricter result.
What are the most common classification mistakes in cross-border supply chains?
The most common mistake is treating a classification as jurisdiction-universal. A manufacturer classifies a product once, against a single list, and then applies that classification to all markets without re-running the analysis for each relevant jurisdiction. Where the product moves from the EU to the UK, or from the UK to an EU member state for onward export, the classification must be assessed against both regimes. A single classification memo is not sufficient.
The second common mistake is failing to re-classify after a product modification. Dual-use classifications attach to technical specifications. When a product is upgraded – a higher processor speed, a different encryption standard, a new software module – the classification must be revisited. In practice, engineering teams make these changes without flagging them to the compliance function. The result is an export proceeding under a stale classification. Where the technical threshold is crossed, the export becomes unlicensed.
A third area of risk is the treatment of technology transfers and software. Both the UK and EU control the transfer of technology and software that is designed for, or can be used for, controlled applications. Sending technical data by email to a counterparty in a third country is an export. Giving access to a cloud-hosted platform to a user in a controlled destination is an export. Many businesses have well-developed physical-goods compliance processes but inadequate controls over intangible transfers. This gap is increasingly an enforcement focus for both ECJU and EU member-state authorities.
In a recent matter, a technology business in the advanced materials sector had applied a consistent classification to its hardware exports but had not assessed its associated software and technology packages. The software contained algorithms that, when assessed against the current UK and EU dual-use lists, fell within controlled parameters. We were instructed to map the full product portfolio, assess the applicable classifications under both regimes, and identify which transfers required licensing. The review identified a category of software transfers that had been proceeding without required authorisations, and we advised on the appropriate steps to remediate the position.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.
How does the US regime complicate a UK–EU dual-use analysis?
Cross-border supply chains frequently involve US-origin goods, software, or technology, which brings the Export Administration Regulations administered by BIS into scope. The EAR applies to items of US origin regardless of where the export occurs. A UK company re-exporting US-origin controlled goods requires authorisation under the EAR in addition to any required UK ECJU licence. An EU manufacturer that incorporates US-origin components above the applicable de minimis threshold faces the same obligation.
The ECCN (Export Control Classification Number under the US Commerce Control List) assigned to an item under the EAR is not directly equivalent to the EU or UK classification, even where the underlying technical specification is similar. The control reasons differ. An item controlled under the EAR for national-security reasons may also be controlled under the EU list for anti-terrorism reasons, but the licensing requirements, available exceptions, and competent authorities are entirely separate. Businesses that assume a BIS classification supersedes or encompasses an EU or UK classification are wrong in both directions.
The US also applies what practitioners refer to as a deemed export rule: the transfer of controlled technology to a foreign national on US soil is treated as an export to that person's country of nationality. Neither the UK nor the EU has an identical concept, though both regimes control intangible technology transfers. This difference in scope means that a multinational with US operations and UK or EU supply chains may be managing three different compliance obligations simultaneously, each with its own classification list, licensing authority, and enforcement regime.
Secondary-sanctions risk adds a further layer. Where a transaction involves a counterparty or destination that is subject to US secondary sanctions, a non-US business – including a UK or EU company – may face OFAC risk even where no US goods, software, or technology are involved. The export-control classification question and the sanctions-screening question must both be answered, and the answers may come from different parts of the applicable regulatory regimes. Neither clears the other.
A common misconception: one classification covers all regimes
A persistent assumption in cross-border trade is that a product classification obtained from one competent authority provides cover across all major export-control regimes. It does not. This misconception is particularly common where a business has received a formal classification determination or an export licence from one authority and treats that approval as a universal position paper.
The reason it does not work that way is structural. The UK, EU, and US maintain separate classification lists, updated at different times through different processes, even where those lists share a common source in the Wassenaar Arrangement or other multilateral agreements. Each authority is responsible for applying its own list to the specific facts of the transaction in question. A classification determination from ECJU tells you the UK position. It tells you nothing about the EU position under the EU dual-use regulation, and nothing about the BIS position under the EAR.
In our experience, this misconception is most dangerous in two situations. First, where a compliance team inherits a product portfolio from a predecessor or from an acquired business and accepts the prior classification work without re-running it. Second, where an exporter has a long-established classification for a product that has since been technically modified, but the modification was not flagged for compliance review. Both situations share a common feature: the classification is confident but not current. Confidence without currency is a compliance gap.
Related practices
- Deemed Export and Technology Controls under BIS/EAR – US deemed-export obligations and technology-transfer licensing under the EAR
- EU vs SECO Export Licence Determination – comparative analysis of EU and Swiss export-licence requirements and divergence points
- OFAC vs BIS/EAR Export Licence Determination – how OFAC sanctions licences and BIS export licences interact on the same transaction