Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · Australia

How to assess criminal export-control exposure under Australia

A trading company with operations across Asia-Pacific ships a consignment of technical equipment to a regional distributor. Weeks later, it receives correspondence from an Australian government authority. The question is not whether a customs formality was missed. The question is whether a member of the export team faces criminal liability – and whether the company itself does too. That distinction, and what drives it, is the subject of this guide.

Criminal exposure in export-control cases under Australia arises under the Autonomous Sanctions regime and the Defence Export Controls regime, both administered by the Department of Foreign Affairs and Trade (DFAT – the primary authority for autonomous sanctions and strategic goods controls). A breach can attract serious criminal penalties, including custodial sentences, where it is established that the exporter knew – or was reckless as to whether – a controlled item was being transferred without the requisite authorisation. As of March 2026, Australian enforcement posture has tightened, and cross-border exposure increasingly intersects with obligations under the US EAR, the UK export-control rules, and EU dual-use controls.

This guide walks through the assessment in sequential stages: governing authority and legal basis, the classification question, the criminal-intent test, cross-regime exposure, the voluntary disclosure decision, and when to involve counsel.

Step 1: Identify the governing authority and the legal basis

Australian export-control criminal exposure is anchored in two distinct legal instruments administered by DFAT – and confusing them is the first error practitioners encounter. The first instrument governs strategic goods and defence-related items; the second governs measures against designated persons and entities under Australia's Autonomous Sanctions regime. Each carries its own prohibition structure and its own criminal threshold.

Under the strategic-goods instrument, DFAT administers controls on the export, supply, and brokering of items on the Defence and Strategic Goods List (DSGL – the Australian control list of items requiring a permit before export). The DSGL is structured in two parts: Part 1 covers munitions and controlled military articles; Part 2 covers dual-use goods, software, and technology. A supply, export, or brokering of a DSGL item without a permit issued by DFAT constitutes a contravention. Whether that contravention is criminal depends on the fault element established – a point addressed in Step 3.

Under the Autonomous Sanctions regime, DFAT designates persons and entities and imposes asset freezes and dealing prohibitions. Supplying sanctioned parties with controlled goods – or indeed any goods caught by a relevant sanctions instrument – engages a separate stream of criminal liability. The two streams can apply simultaneously to the same transaction.

A critical first task is therefore to identify which stream – or both – applies to the facts. In our experience, businesses sometimes treat their export compliance and their sanctions compliance as entirely separate workstreams. For criminal exposure purposes they cannot be.

Step 2: Determine whether the item or activity is controlled

An item must be controlled before criminal liability can attach. Establishing whether a good, software, or technology falls within the DSGL is the classification exercise, and it drives every subsequent step in the analysis. Classification errors are the most common source of undetected exposure in the cross-border B2B context.

The DSGL is aligned with the multilateral export-control arrangements – the Wassenaar Arrangement, the Australia Group, the Missile Technology Control Regime, and the Nuclear Suppliers Group. A business familiar with US ECCN (Export Control Classification Number under the US Commerce Control List) classifications will find the DSGL parameters broadly comparable, but they are not identical. A good classified EAR99 in the United States is not automatically uncontrolled under the DSGL, and the reverse applies equally. Have you verified classification independently against the DSGL rather than assuming parity with a foreign classification?

Several controls extend to technology and software, not only to physical goods. This is important for businesses that deliver technical assistance, training, or software updates to overseas counterparties. The supply of controlled technology by email, cloud access, or a briefing delivered on foreign soil can constitute a controlled export under Australian rules. The same principle applies under the EAR's deemed-export concept and under EU dual-use rules, though the precise scope differs across regimes.

Where classification is uncertain, DFAT operates a pre-assessment mechanism. Obtaining a formal determination before export is a risk-management step of material value: it substantially narrows the fault element available to a prosecutor, even if it does not guarantee a particular outcome.

Step 3: Apply the criminal-intent test

Australian export-control criminal liability is fault-based. A strict-liability civil contravention can arise from a breach without fault. Criminal liability requires a fault element: the prosecution must establish that the person acted knowingly, recklessly, or – in some constructions – with wilful blindness. Understanding precisely which fault element the applicable instrument uses, and how courts in Australia have characterised recklessness in export-control contexts, is the crux of the criminal analysis.

Recklessness is the fault element most frequently in issue. Under Australian criminal law, a person is reckless with respect to a circumstance if they are aware of a substantial risk that the circumstance exists and, having regard to the known risk, it is unjustifiable to take that risk. In an export-control context, this means that a business which proceeds with a shipment after identifying warning signs – a destination flagged in internal screening, a stated end-use that is implausible for the stated end-user, a counterparty that declines to answer standard due-diligence questions – faces a materially higher prospect of a criminal characterisation than one that failed to notice the issue at all.

This fault analysis has a direct compliance implication. A programme that documents a thorough classification review and a considered end-use assessment – even where the conclusion ultimately turns out to be wrong – provides evidence against recklessness. A programme that conducts no review, or that records no reasoning, does not. In our practice, we advise clients to treat the record of the compliance decision as evidence in a hypothetical prosecution – because that is precisely what it may become.

Corporate liability can arise alongside individual liability. Directors and officers may face personal criminal exposure where they authorised, permitted, or acquiesced in the prohibited conduct. The compliance team and the export-licensing officer are not the only individuals at risk.

Step 4: Map cross-regime exposure – where Australia intersects with other regimes

Australia's export-control criminal exposure rarely sits in isolation for a cross-border business. A transaction that gives rise to Australian criminal risk very often generates parallel exposure under at least one other regime, and the assessment must account for all of them.

The most significant overlap is with the US EAR, administered by BIS. Where goods or technology of US origin – or goods containing more than a de minimis amount of US-controlled content – are re-exported from Australia or routed through an Australian entity, BIS has extraterritorial reach over that transaction. A breach of the EAR by an Australian exporter can result in BIS enforcement action independent of what DFAT does. The Entity List (BIS's list of parties subject to enhanced licence requirements under the EAR) may capture counterparties that do not appear on DFAT's sanctions designations, and vice versa.

UK export-control rules administered by ECJU present a secondary layer. Where UK-origin goods or technology are involved, or where a UK entity in the supply chain is taking a step that constitutes an export under UK law, the ECJU regime applies concurrently. The UK's Strategic Export Licensing rules and the penalty exposure they carry can run in parallel with DFAT's action.

The EU dual-use regulation creates a third layer for transactions touching EU-origin goods or EU-resident parties. EU rules on catch-all controls – which can require a licence even for non-listed items where the exporter has knowledge of a military or WMD-related end-use – impose obligations that can coincide with Australian DSGL controls on the same shipment.

OFAC financial-sanctions exposure is a fourth consideration. Where the transaction involves USD-denominated payments or US counterparties, OFAC's jurisdiction applies regardless of the goods' origin. A transaction that is export-compliant under the DSGL can simultaneously violate an OFAC country or thematic programme. In our cross-border practice, we treat each layer as a separate but related analysis, because the regime that poses the highest criminal risk on any given set of facts is not always the most obvious one.

The position above covers the standard cross-regime picture. Your facts – the goods, the route, the counterparties, the payment chain, the involvement of US-origin technology – change the analysis materially.

For an assessment of your exposure across multiple regimes, contact Calder & Vance at info@caldervance.com.

Step 5: Evaluate the voluntary disclosure decision

A voluntary self-disclosure (VSD – a proactive report to the relevant authority of a suspected breach, before enforcement action is commenced) is the pivotal decision in managing criminal export-control exposure under any regime, and Australia is no exception. The decision to disclose – or not to disclose – shapes nearly every subsequent outcome.

DFAT operates a disclosure mechanism for export-control breaches. A timely, accurate, and complete VSD is typically treated as a significant mitigating factor. It can influence whether the authority characterises the conduct as a contravention warranting a criminal referral or as a matter to be resolved administratively. It can also affect the quantum of any civil penalty and the terms under which the business continues to hold an export permit. What it does not do is guarantee a particular outcome, and that is a point we are careful to make clearly to any client considering this route.

The VSD decision is complicated where multi-regime exposure exists. A disclosure to DFAT may not satisfy BIS or OFAC disclosure expectations, and the content of a DFAT disclosure could be discoverable in a US enforcement proceeding. In our experience, coordinating a disclosure strategy across DFAT, BIS, and OFAC simultaneously – where all three regimes are engaged – is a task requiring careful sequencing and a clear understanding of what each authority regards as a complete disclosure.

Key factors that inform the VSD decision include: the nature and duration of the breach; the number of transactions affected; whether the apparent violation involved a restricted party; the quality of the company's compliance programme at the time; and whether any internal reporting mechanism was triggered and recorded. A business that surfaces the issue through its own programme, reports promptly, and cooperates fully is positioned differently from one whose breach is identified by a third party or an authority.

If a transaction has already been flagged, or if an inquiry has been received, an early legal review can preserve options that narrow quickly. Contact Calder & Vance at info@caldervance.com for a confidential assessment.

Step 6: Identify the risk flags that raise the criminal threshold

Certain fact patterns consistently elevate criminal exposure under the Australian regime – and under its comparators. Recognising them early determines whether the matter is a compliance remediation or a criminal-defence preparation.

The first flag is a destination concern: a country or territory where Australian autonomous sanctions apply, or where controlled goods are subject to heightened DSGL restrictions, appearing in the shipping documents, the stated end-use, or the payment routing. Destination and end-use are the two most common factors that prosecutors rely upon to establish knowledge or recklessness.

The second flag is end-use implausibility. Where the stated end-use for a dual-use item is commercially implausible given the end-user's apparent business, or where the end-user's identity cannot be confirmed through reasonable due diligence, the risk of a recklessness finding is substantially elevated. This is the pattern that catch-all controls – which allow DFAT to require a permit even for non-listed items in defined circumstances – are designed to reach.

The third flag is an unusual payment structure: payments routed through third-country intermediaries, requests for invoice amendments, or requests to describe goods differently from their technical specification. These patterns do not automatically establish criminal intent, but they appear with regularity in enforcement cases as circumstantial evidence of knowledge.

The fourth flag is a compliance-programme gap. Where the business cannot produce evidence of a classification review, an end-use check, or a screening against the relevant lists, the absence of that record is itself a risk indicator in any enforcement investigation. The fault-element analysis turns partly on what steps the business took – and demonstrably took. A gap in the record is an argument for the prosecution.

The fifth flag is a prior warning. A previous DFAT correspondence, a compliance notice, or an internal escalation that identified the same counterparty, good, or destination – and was not resolved – strongly colours the fault-element analysis. Prior notice is powerful evidence of knowledge.

Step 7: Decide when to involve counsel

The threshold for involving external counsel in a criminal export-control matter is lower than most in-house teams assume. By the time a formal inquiry is received, the window for the most effective protective steps has often already narrowed.

Legal advice should be sought at the point a business identifies a potential breach – not at the point it receives correspondence from DFAT or another authority. The reasons are practical. Privilege attaches to communications made for the purpose of obtaining legal advice, and early legal involvement preserves that protection over the internal investigation. A self-conducted review that is not attorney-client privileged can be compelled in later proceedings. Early counsel involvement also ensures that any decision about voluntary disclosure is taken with a complete understanding of the multi-regime picture, not only the Australian dimension.

Where there is a realistic prospect of criminal referral – a transaction involving a sanctions-listed party, a good in a sensitive DSGL category, or a pattern of conduct over multiple shipments – the decision to instruct external counsel immediately is, in our experience, unambiguous. The reputational and operational consequences of a criminal conviction under Australian export-control law are severe, and the margin for error in managing the disclosure and investigation phase is narrow.

Where the matter appears to be a technical breach without aggravating factors, counsel can assist in evaluating whether the case for a VSD is made, what remediation steps are appropriate, and how to document the remediation in a way that the authority can clearly see and credit. We regularly advise on these assessments as a discrete, bounded engagement before a client commits to a full enforcement-defence retainer.

Related practices

A common misconception: "We are not a US or EU company, so US and EU rules do not apply to us"

The most persistent myth in the cross-border export-control context is that an Australian exporter dealing in non-US goods is beyond the reach of US or EU enforcement. This is incorrect, and acting on this assumption is one of the most consequential errors a business can make.

The EAR's extraterritorial reach extends to items containing US-controlled content above the applicable de minimis threshold, to items produced using US technology subject to the foreign-direct-product rule, and to activities by any party – wherever located – that is on the Entity List or the Denied Persons List. An Australian manufacturer whose production process incorporates US-origin machinery or software may be producing items subject to EAR controls without realising it. BIS's enforcement practice has demonstrated clearly that it does not limit its reach to US-domiciled businesses.

Similarly, the EU catch-all and end-use controls apply to EU-origin goods and technology regardless of where the subsequent export takes place. A component sourced from a European supplier and re-exported from Australia to a third-market destination can trigger EU export-licensing obligations – and a referral to the relevant EU authority if those obligations are not met.

The practical implication is that an Australian business must maintain a compliance programme capable of identifying and managing US, UK, and EU export-control obligations in parallel with its DSGL obligations. A programme designed only for DFAT compliance is insufficient for the business operating in a cross-border supply chain. We assist clients in designing programmes that are calibrated to the full range of their exposure, not only the domestic dimension.

Frequently asked questions

What are the steps to assess criminal export-control exposure under Australia?
The assessment follows seven stages: identify whether the DSGL or the Autonomous Sanctions regime – or both – applies; classify the item against the DSGL; apply the criminal fault-element test, focusing on knowledge and recklessness; map cross-regime exposure under the EAR, UK, and EU rules; evaluate the voluntary disclosure decision and its multi-regime implications; identify the specific risk flags present in the transaction; and determine at which point counsel should be instructed. Each stage produces inputs that shape the stage that follows it. Skipping or compressing any stage creates blind spots that can prove costly once an authority is engaged.
What is the most common mistake in criminal exposure in export-control cases?
The most common mistake is treating the absence of a formal enforcement notice as confirmation that no breach has occurred. Many businesses operate with a compliance programme that detects only the most obvious prohibited transactions and assume that silence from the authority means compliance. In practice, the absence of a notice means only that an authority has not yet acted. Where a business later discloses a breach or where a third-party report triggers an investigation, the absence of contemporaneous compliance records – classification reviews, end-use assessments, screening logs – is itself evidence available to a prosecutor. Proactive record-keeping and periodic programme testing are protective measures against this pattern.
How does Australia differ from other regimes here?
Australia's export-control regime differs from comparable regimes in several respects relevant to criminal exposure. The DSGL is closely aligned with multilateral control lists but is not identical to the US Commerce Control List or EU dual-use annexes, so classification must be done independently. DFAT's enforcement capacity has grown materially in recent years, and the regime increasingly coordinates with partner-country authorities on joint investigations. Unlike the US EAR, the Australian regime does not have a formal deemed-export concept codified in the same way, though technology transfers are still controlled. The voluntary disclosure mechanism exists but does not carry the same codified penalty-mitigation structure that OFAC's enforcement guidelines provide. These differences mean that a disclosure or enforcement strategy designed for one regime requires re-calibration before it is applied in Australia.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.