A technology distributor headquartered in the Netherlands ships a component to a reseller in Singapore. The reseller re-exports that component to an end-user whose beneficial owner appears on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The Dutch distributor never touched the second shipment. Does OFAC care? The answer is almost certainly yes – and the EU has its own extraterritorial claims that point in a different direction. Understanding which regime reaches further, and where they diverge, is the analytical task that determines whether a cross-border supply chain is compliant.
As of April 2026, OFAC's extraterritorial reach under IEEPA extends to any transaction that involves US-origin goods, US-dollar clearing, or the involvement of a US person anywhere in the chain – regardless of where that transaction physically occurs. The EU's equivalent reach is narrower in scope but distinct in its legal mechanism, targeting designated persons and EU-nexus transactions rather than asserting jurisdiction over non-EU parties conducting non-EU business. Where both regimes apply simultaneously, the stricter prohibition governs each element of the transaction.
This analysis maps the divergences across five dimensions: the legal basis for extraterritorial reach, the re-export trigger, the ownership-and-control test, the licensing route, and the practical risk flags that in our experience businesses most commonly miss.
What is the legal basis for OFAC's extraterritorial reach?
OFAC's authority to regulate conduct outside US territory flows primarily from IEEPA and, for older programmes, from TWEA. These instruments empower the President to block transactions that constitute an unusual and extraordinary threat to national security, foreign policy, or the economy. That authority is not geographically confined: OFAC's regulations extend to US persons wherever they are located, to transactions that pass through the US financial system, and to goods and services of US origin regardless of where they currently sit in the supply chain.
The practical consequence for a non-US business is threefold. First, if the goods contain US-origin content above a de minimis threshold – a threshold defined under the Export Administration Regulations administered by BIS – re-exporting them to a sanctioned destination or a blocked person triggers both OFAC and BIS exposure simultaneously. Second, if the payment for those goods is denominated in US dollars, it will clear through a US correspondent bank. At that clearing moment, a US person processes the transaction, and OFAC jurisdiction attaches. Third, if any US national, resident, or US-incorporated entity participates in the deal – as a broker, freight forwarder, insurer, or consultant – that participation is a US person's conduct and is subject to OFAC's rules wherever it occurs.
In our cross-border practice, the dollar-clearing point is the most frequently overlooked nexus. A business based in a third country may confidently believe it has no US connection, yet route payment in USD as a matter of commercial convenience. That single choice pulls the transaction inside OFAC's jurisdiction.
How does the EU's extraterritorial reach compare?
The EU's sanctions reach flows from Council regulations adopted under the Common Foreign and Security Policy. Those regulations bind EU persons – natural persons who are EU nationals or resident in the EU, and legal entities incorporated or operating in the EU. They also apply to conduct occurring within EU territory. Beyond those anchors, the EU does not assert a general claim to regulate conduct by non-EU parties transacting entirely outside the EU.
That structural difference matters. An EU-incorporated subsidiary of a non-EU group is fully caught by EU sanctions. Its non-EU parent conducting a separate transaction outside EU territory in a non-EU currency is, in principle, outside the EU's direct reach – though secondary-sanctions risk from OFAC may still apply to that parent through a US-dollar or US-person nexus.
There is a further complication that the EU adds and OFAC does not: the EU Blocking Regulation (the instrument designed to protect EU persons from the extraterritorial effects of third-country sanctions). Where OFAC imposes secondary sanctions that purport to penalise EU persons for lawful EU conduct, the Blocking Regulation prohibits EU persons from complying with those OFAC requirements without prior EU authorisation. This creates a genuine legal conflict for an EU-incorporated entity operating under both regimes. The Blocking Regulation does not nullify OFAC's reach from OFAC's perspective; it simply makes compliance with OFAC potentially unlawful under EU law. Resolving that conflict requires a jurisdiction-by-jurisdiction analysis of which prohibition governs the specific conduct in question.
The position above covers the standard structural case. Your facts – the counterparty's incorporation, the payment currency, the goods' origin, the identity of the end-user – determine where the conflict bites for your business specifically. For a tailored assessment, contact Calder & Vance at info@caldervance.com.
Where do OFAC and the EU diverge on the re-export trigger?
Under the EAR, a re-export is the shipment or transmission of an item subject to the EAR from one foreign country to another. The EAR's re-export controls operate alongside OFAC's sanctions: the EAR addresses the item's classification and destination; OFAC addresses the sanctioned-country or blocked-person nexus. A re-export to a sanctioned destination requires both a BIS licence exception or licence and OFAC authorisation where a US-sanctions programme applies.
OFAC's re-export analysis asks two questions. Is the item US-origin or does it contain US-origin content that takes it above the de minimis threshold? Does the re-export involve a US person, US-dollar clearing, or a destination or end-user covered by a US sanctions programme? If the answer to either question is yes, OFAC's rules are engaged even though the original US exporter is not a party to the second transaction.
The EU's re-export exposure works differently. EU sanctions regulations typically contain provisions that prohibit EU persons from knowingly and intentionally participating in activities whose object or effect is to circumvent the prohibitions. Those participation provisions are targeted: they catch an EU person who structures or facilitates a re-export designed to reach a designated person or a sanctioned destination. They do not impose a blanket licence requirement on all re-exports of EU-origin goods to all destinations in the same way that the EAR's destination-control statement regime does.
The practical divergence is significant. A non-EU, non-US distributor re-exporting goods that originated in an EU member state to a non-designated third-country buyer faces no EU re-export prohibition in principle, provided no EU person participates in the re-export and the transaction is not designed to circumvent EU sanctions. The same distributor re-exporting goods with US-origin content above the applicable de minimis threshold to the same buyer – even one who is not on the SDN List – may still require a BIS licence if the destination is controlled. And if that buyer's beneficial owner is on the SDN List, OFAC's blocked-property prohibitions attach the moment a US-person or US-dollar nexus appears anywhere in the chain.
How do the ownership-and-control tests differ?
OFAC applies the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by one or more blocked persons as themselves blocked, regardless of whether the entity itself appears on the SDN List). The test is ownership-based and mechanical: if the aggregate ownership by blocked persons reaches or exceeds that threshold through direct or indirect holdings, the entity is treated as blocked. Control, in the corporate-governance sense, is not independently sufficient under OFAC's test, though OFAC may designate a controlled entity separately.
The EU applies an ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person). Under EU Council regulations, the prohibitions extend to entities owned or controlled by designated persons. Control under the EU test is broader than OFAC's threshold: an entity can be caught even where a designated person holds less than 50 percent of its shares, if that person exercises decisive influence over the entity's decisions. This makes the EU test harder to apply with certainty. A shareholding of 40 percent combined with board representation, veto rights, or funding dominance may be enough to bring an entity within the EU prohibition even though OFAC's mechanical 50 percent test would not capture it.
For a re-export analysis, this divergence matters at the end-user identification stage. Screening the buyer against the SDN List and finding no direct hit is not enough. Under OFAC, you must trace the ownership chain to 50 percent or more held by any blocked person. Under the EU, you must also ask whether any designated person exercises control short of that ownership line. In our experience, businesses that run both analyses sequentially – OFAC ownership first, then EU control – are better positioned than those that apply a single consolidated screening pass.
What are the risk flags that businesses most commonly miss?
Five patterns appear repeatedly in matters we review. Each is addressable before a transaction closes; each becomes significantly harder to manage after a shipment has departed or a payment has cleared.
The first is the dollar-denominated payment in a non-US supply chain, discussed above. It is worth restating because it appears so reliably in matters that have escalated. A non-US party with no US-person involvement and no US-origin goods may still face OFAC exposure solely because its commercial team defaulted to USD invoicing.
The second is layered ownership at the end-user. Distributors and resellers are frequently interposed between the original exporter and the ultimate buyer. Each layer of intermediary potentially obscures a blocked-person holding. The deeper the ownership chain, the more likely that a 50-percent ownership interest, or a control position under the EU test, sits undisclosed. Contractual end-user statements are useful but not sufficient; independent ownership verification is required for high-risk supply chains.
The third is the interaction between the EAR and OFAC in a single shipment. A re-exporter who obtains a BIS licence exception may wrongly assume that OFAC exposure is thereby managed. The two regimes are parallel, not hierarchical: a BIS licence does not constitute OFAC authorisation. Separate OFAC analysis – and, where required, a separate OFAC licence – is always necessary.
The fourth is the deemed export risk embedded in technology transfers. Where technical data or source code of US origin is released to a foreign national in a third country, that release is deemed an export to the person's country of nationality under the EAR. A re-export of the same data to a national of a sanctioned country triggers OFAC exposure as well. Our colleagues' analysis of the deemed-export classification process is set out in detail at Deemed Export Technology – BIS/EAR Service.
The fifth – and the one that generates the sharpest divergence between OFAC and the EU – is the Blocking Regulation conflict for EU-incorporated entities. An EU subsidiary of a non-EU group that receives an OFAC subpoena or an instruction from a US parent to terminate a relationship with an EU counterparty may find that compliance with the US demand is prohibited under EU law unless prior authorisation is obtained. Failing to identify this conflict early can leave the EU entity in breach of one regime whichever choice it makes.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential initial assessment.
Which regime is stricter, and when does the stricter prohibition govern?
Neither regime is categorically stricter than the other across all dimensions. OFAC's extraterritorial reach is broader in jurisdictional scope: it follows the goods, the currency, and the person rather than being anchored to EU territory or EU persons. The EU's control test is broader in entity-scope: it captures influenced entities that OFAC's mechanical ownership test would not. The two regimes impose different sets of obligations on different actors, and the stricter prohibition governs each element of the transaction to which both regimes apply.
Consider a transaction involving a Dutch exporter, US-origin components, USD payment, and a buyer in a jurisdiction subject to both an OFAC comprehensive programme and EU restrictive measures. The Dutch exporter is subject to EU sanctions as an EU person. It is also potentially subject to OFAC's prohibitions because the components are US-origin and the payment will clear in USD through a US correspondent. On the re-export question, OFAC's prohibition is the stricter one because it attaches to the goods' origin regardless of where the exporter is incorporated. On the ownership-and-control question, the EU's control test is potentially wider because it captures influenced entities below the 50 percent line. A compliant transaction must satisfy both regimes simultaneously.
The practical implication for compliance teams is that a single-regime analysis is structurally insufficient for any cross-border transaction involving US-origin goods, USD, or EU-incorporated parties. The analysis must be run in parallel against each applicable regime, and the most restrictive outcome on each point must be applied.
What does a compliant re-export process look like in practice?
A well-structured re-export compliance process follows a defined sequence. The first stage is item classification: establishing whether the goods, software, or technology carry an ECCN (Export Control Classification Number under the US Commerce Control List) and whether they are listed under EU dual-use rules. Classification determines which licence exceptions are available and which destinations require a licence.
The second stage is end-user and end-use screening. This involves checking the buyer and beneficial owners against the SDN List and the EU consolidated list, tracing ownership to the 50 percent threshold under OFAC's rule, and assessing control indicators under the EU test. Red-flag indicators – an unusual delivery address, a request to omit the end-user from documentation, a buyer with no apparent commercial rationale for the goods – warrant enhanced due diligence before the transaction proceeds.
The third stage is currency and payment-route analysis. If USD is the invoicing currency, US-correspondent clearing is the probable route, and OFAC jurisdiction attaches. The compliance team must confirm that no OFAC sanctions programme restricts the transaction and that no SDN-list hit, including through the 50 percent rule, is present at the payment-receiving end.
The fourth stage is licence assessment and, where required, licence application. Under OFAC, a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) is required where no general licence (a standing authorisation that permits a defined category of transactions without a separate application) is available. Under the EU, the competent authority of the member state in which the exporter is established processes export-licence applications. Under BIS, licence applications are submitted to the Office of Exporter Services. These are parallel tracks; a licence from one authority does not substitute for the other.
In a recent matter, a technology manufacturer in Northern Europe sought to supply components to a distributor in a third market for onward sale to an end-user in a jurisdiction subject to both OFAC and EU restrictions. We classified the components, confirmed that the end-user's parent fell within the EU control test despite holding below the 50 percent OFAC threshold, advised on the applicable EU export authorisation procedure, and identified that the USD payment route independently triggered OFAC jurisdiction. The manufacturer restructured both the supply chain and the payment terms to bring the transaction within an available authorisation before any shipment occurred.
For a comparison of how OFAC's re-export analysis differs from the UK's OFSI-led approach, see our companion analysis at Re-Export and Extraterritoriality: OFAC vs OFSI. The divergence between OFSI and Australia's autonomous sanctions regime is addressed at Re-Export and Extraterritoriality: OFSI vs Australia.
A common misconception: if my goods are not controlled, the EAR does not apply
The misconception most frequently encountered in compliance training is this: "our products are classified as EAR99, so we have no BIS exposure and no OFAC re-export issue." EAR99 is the residual classification for items subject to the EAR that do not require a licence for most destinations. But EAR99 does not mean uncontrolled everywhere. Exports and re-exports of EAR99 items to sanctioned destinations, to parties on the SDN List, or to parties on BIS's Entity List remain restricted regardless of the item's classification.
The OFAC dimension is distinct again. OFAC's prohibitions are not classification-dependent. A transaction involving a blocked person or a sanctioned destination is prohibited regardless of whether the goods are controlled under the EAR. An EAR99 item shipped to an SDN-listed buyer through a USD payment is a prohibited transaction under OFAC. The absence of a BIS licence requirement does not affect that analysis at all.
We regularly advise businesses that have built their entire export-compliance programme around EAR classification and have given little or no attention to the OFAC overlay. The two regimes must be applied independently: EAR classification determines which destinations and parties require a BIS licence; OFAC analysis determines whether any US sanctions programme prohibits the transaction entirely. A transaction can be BIS-clean and OFAC-blocked simultaneously.
Related practices
- Deemed Export Technology – BIS/EAR Service – classification, licence assessment, and end-use controls for technology transfers under the EAR
- Re-Export and Extraterritoriality: OFAC vs OFSI – comparing US and UK reach on re-export transactions and secondary-sanctions risk
- Re-Export and Extraterritoriality: OFSI vs Australia – divergence between OFSI and Australia's autonomous sanctions regime for cross-border supply chains