A technology company based in Europe sells components to a trading intermediary in a third market. Months later, a US law-enforcement referral identifies the goods as controlled items under the Export Administration Regulations (the EAR), shipped without the required authorisation. The company's counsel receives a preservation notice. Does criminal exposure extend to the non-US exporter? Which regulators have jurisdiction? And what, precisely, triggers the criminal – rather than civil – threshold?
Criminal exposure in export-control cases arises under multiple regimes simultaneously for any business with a cross-border footprint. The governing authorities – the US Bureau of Industry and Security (BIS), the UK's Export Control Joint Unit (ECJU), EU member-state prosecutors, and their counterparts in Japan and Singapore – each apply distinct knowledge and intent standards. A finding of wilful conduct under the EAR can produce both criminal prosecution and civil administrative action; other regimes focus primarily on strict-liability administrative penalties but may escalate to criminal referral where intent is clear.
This guide walks through a structured, step-by-step assessment of criminal export-control exposure for businesses operating across the major regimes: from item classification through jurisdiction mapping, intent analysis, voluntary disclosure, and the decision of when to instruct specialist counsel.
Step 1 – Classify the item and identify every applicable control list
The first step in any criminal exposure assessment is establishing whether the item, technology, or software is controlled under each relevant regime's list, because an uncontrolled item under one regime may carry significant restrictions under another.
Under the EAR, every physical good and associated technology is assessed against the Commerce Control List (CCL). An item is assigned an Export Control Classification Number (ECCN – a five-character alphanumeric code that identifies the specific controls, licence requirements, and licence exceptions that apply). If no ECCN applies, the item is designated EAR99 – generally exportable to most destinations without a licence, but still subject to end-use and end-user controls. The classification determines whether a licence was required; a required licence that was not obtained is the predicate act for criminal exposure under the Export Control Reform Act.
The UK uses the UK Strategic Export Control Lists, administered by ECJU. The EU maintains its own dual-use list under the applicable Council regulation on dual-use items; member states enforce it through their own criminal-law systems. Japan applies controls under its Foreign Exchange and Foreign Trade Act and the Export Trade Control Order. Singapore operates under the Strategic Goods (Control) Act. Each list carries different threshold criteria, even for broadly similar technologies.
In our experience, the most common originating error in criminal export-control matters is a classification made at the product-development stage that was never revisited when the item's specification changed. Reclassification – or a formal commodity-jurisdiction determination – is the first remediation step. Without it, the entire exposure assessment rests on a potentially false premise.
Practical check: does your organisation hold written classification records? Are those records tied to the specific product version that was exported, not a predecessor model? If the answer to either question is no, classification should be reperformed before any regulator contact.
Step 2 – Map jurisdiction: which authorities can prosecute?
Jurisdiction in criminal export-control cases extends well beyond the country where the exporter is incorporated, and failing to map every potentially asserting authority is one of the most consequential errors a business can make at the outset of an internal investigation.
BIS and the US Department of Justice (DOJ) exercise extraterritorial reach over non-US persons and entities under several well-established theories. Where the item is of US origin, incorporates US-origin content above the applicable de minimis threshold, or was produced using US-origin technology, the EAR's re-export controls apply regardless of where the exporter sits. A German company re-exporting US-origin goods without authorisation is within BIS's enforcement perimeter. The DOJ has criminally prosecuted non-US nationals in this context.
UK jurisdiction attaches where the goods depart from the United Kingdom, or where the person arranging the transfer is a UK person or company. ECJU refers serious cases to the Border Force and, ultimately, to Crown Prosecution Service for criminal charge. The relevant thematic export-control regulations carry custodial penalties for wilful violations.
EU member states each have their own criminal codes, but the dual-use regulation creates a harmonised licensing obligation. A French exporter, a Dutch intermediary, and a German parent can each face prosecution in their respective jurisdictions for the same shipment. Coordination between member-state prosecutors is possible but not guaranteed; in practice, the most affected jurisdiction tends to lead.
Japan's Foreign Exchange and Foreign Trade Act applies to Japanese residents and entities, including subsidiaries of foreign parents. Singapore's regime reaches persons who export from Singapore or who knowingly facilitate such export. The UAE applies controls through its own strategic-goods legislation; the practical enforcement posture there focuses on end-use and end-user undertakings rather than extraterritorial prosecution, but export violations can result in licence revocation and reputational consequences before the Emirates Authority.
The jurisdiction-mapping step produces a list of live exposure vectors – not a single answer. Each vector requires its own intent analysis, considered next.
Step 3 – Analyse the intent standard in each applicable regime
The intent threshold is the single most important variable in determining whether a violation is likely to be treated as a criminal matter or resolved through civil administrative channels, and it differs materially across the regimes in scope.
Under the EAR, criminal liability requires that the conduct was wilful. Wilfulness, in US federal criminal law, generally means the defendant knew the conduct was unlawful and acted deliberately. This is a demanding standard that DOJ must prove beyond reasonable doubt. However, deliberate avoidance of knowledge – constructive knowledge acquired by deliberately looking away from red flags – has been treated as equivalent to actual knowledge in export-control prosecutions. This is the principle often called the "wilful blindness" doctrine. In our cross-border practice, we see this standard misunderstood: businesses sometimes believe that the absence of a formal internal approval for a transaction insulates them from criminal exposure. It does not, if the red flags were present and ignored.
UK criminal export-control offences are generally strict liability for the act of exporting without a licence, with intent becoming relevant primarily at sentencing and for the aggravated offence of knowingly or recklessly making a false statement in a licence application. The practical effect is that the prosecution does not need to prove the defendant knew the item was controlled; it needs to prove the export occurred without the required authorisation. This makes the UK criminal threshold lower in some respects than the US threshold for a comparable act, even though headline penalties may differ.
EU member-state criminal laws vary, but most require at minimum knowledge that the goods were controlled. Intent is typically relevant to both liability and sentencing; some jurisdictions require dolus eventualis (indirect intent or recklessness). The divergence between member-state intent standards is a meaningful practical consideration in multi-country internal investigations.
Japan applies administrative penalties by default; criminal referral arises where violations are serious or repeated, and where intentional conduct is established. Singapore similarly escalates to criminal prosecution for knowing or reckless violations. The applicable country regime for each jurisdiction should be verified as currently in force before placing reliance on it.
What does this mean in practice? A business conducting a cross-border exposure assessment must run the intent analysis separately for each jurisdiction – not assume that a finding of no criminal intent under the EAR resolves the UK or EU position.
Step 4 – Identify red flags and assess whether the violation was self-generated or third-party-induced
Criminal export-control exposure rarely materialises without prior warning signs. Identifying those signs – and determining whether the business had constructive or actual knowledge of them – is essential to both the exposure assessment and any subsequent voluntary self-disclosure strategy.
The standard set of export-control red flags – codified in BIS guidance and broadly mirrored in UK and EU guidance – includes: a buyer who declines to state the end use; payment terms that are unusual for the goods involved; a shipping route that adds no logical commercial value but passes through a third country; a buyer whose profile does not match the technical complexity of the item; and resistance to providing standard end-use certifications. Where one or more of these indicators was present and the transaction proceeded without enhanced due diligence, the exposure assessment must account for the elevated probability of a wilful-blindness finding.
The distinction between self-generated and third-party-induced violations also matters for the regulators. A violation arising from a counterparty's misrepresentation, where the exporter conducted reasonable due diligence, occupies a different position in the enforcement calculus than a violation arising from the exporter's own classification error or deliberate choice to ship without a licence. Neither fully eliminates exposure, but the former is generally treated more leniently in both the US and UK voluntary self-disclosure processes.
In a recent matter, a trading business in the logistics sector identified, through routine post-shipment screening, that a consignee had subsequently appeared on the Entity List administered by BIS. We assessed whether the original shipment – made before the listing – had involved red flags that should have prompted enhanced screening at the time. The analysis concluded that the pre-listing due diligence had been adequate, which materially affected the disclosure strategy and the assessment of criminal exposure. The matter proceeded to voluntary self-disclosure, and the outcome reflected the strength of the documented diligence.
Step 5 – Evaluate the voluntary self-disclosure route across regimes
Voluntary self-disclosure (VSD) is available under the EAR, under OFSI's reporting regime, under ECJU's approach to export-control violations, and in varying forms under several other applicable country regimes. Its value in mitigating criminal exposure differs significantly across those regimes, and the decision to disclose must be taken with full awareness of the cross-border implications.
Under the EAR, BIS's enforcement guidance treats a timely and complete VSD (voluntary self-disclosure to BIS) as a significant mitigating factor that can reduce a civil penalty substantially and, in appropriate cases, influence the DOJ's charging decision. The guidance is explicit that VSD is not a guarantee of non-prosecution; it is an input into the prosecutorial discretion calculus. In our experience, the quality of the disclosure – its completeness, speed, and the remediation programme it is accompanied by – matters as much as the fact of disclosure itself.
UK ECJU does not publish a formal VSD programme equivalent to BIS's, but proactive disclosure before a regulator inquiry is a recognised mitigating factor in the enforcement guidelines. OFSI's equivalent – the obligation to report suspected sanctions breaches – operates on a different trigger and a different timeline; verify the current reporting window before relying on any specific figure, as these obligations change.
The critical cross-border complication is that disclosing to BIS without considering the parallel UK or EU position – or vice versa – can create an evidentiary record that is then available to those other authorities. Counsel experienced in multi-regime exposure should be involved before any disclosure is made, precisely because the disclosure strategy must be designed as a whole, not regime by regime in isolation.
Should you disclose in all regimes simultaneously, or sequence the disclosures? That question does not have a universal answer. It turns on the dominant jurisdiction, the nature of the goods, the entities involved, and the evidentiary posture. It is one of the most consequential early decisions in a criminal export-control matter.
If a transaction has already been flagged, or an internal investigation has identified a potential violation, the window for a strategically effective disclosure can narrow quickly. Early specialist review preserves options. To discuss a potential VSD or an exposure assessment confidentially, contact Calder & Vance at info@caldervance.com.
Step 6 – Address document preservation and internal investigation protocol
Once a potential criminal export-control violation is identified, the legal obligations and strategic imperatives around document preservation activate immediately – often before outside counsel has been formally retained.
Under US law, the destruction or alteration of documents that are potentially relevant to a federal investigation can constitute obstruction of justice, a separate criminal offence carrying serious penalties. The obligation to preserve is triggered not only by a formal preservation notice but by the moment the business has reasonable notice that a government inquiry is likely. In cross-border criminal export-control matters, that moment can arrive early – for example, when a customs authority queries a shipment, when a counterparty receives an inquiry, or when an internal compliance review identifies a likely violation.
The internal investigation protocol in a cross-border criminal export-control matter must address several distinct requirements. First, identifying the custodians of relevant records across all jurisdictions involved – not only the primary exporter's employees but those of affiliated entities, agents, and freight forwarders. Second, issuing legally privileged litigation-hold notices in a form that preserves privilege under each applicable legal system. Third, engaging appropriately qualified IT forensic support before self-collection contaminates metadata. Fourth, managing the tension between any regulatory obligation to report swiftly and the need to have a factually accurate picture before communicating with regulators.
In our practice, the investigation protocol is also where the privilege analysis becomes most acute. The attorney-client privilege that attaches to communications under US law does not translate perfectly to EU or UK privilege doctrine. Internal investigation reports prepared in one jurisdiction may be subject to production orders in another. This is not a reason to avoid documentation – it is a reason to design the investigation structure carefully from the outset, with cross-border privilege in mind.
Step 7 – Structure the remediation programme before regulator contact
Remediation – the corrective action taken to address the root cause of the violation and prevent recurrence – is a material factor in how enforcement authorities assess the appropriate response to a disclosed violation, both criminally and in civil administrative proceedings.
BIS, in its enforcement guidance, specifically evaluates whether the disclosing party has taken prompt remedial action. The elements that attract credit include: immediate cessation of the violating conduct; classification review and reclassification where necessary; enhanced screening procedures; revised training for export compliance staff; board-level acknowledgement of the compliance failure; and the appointment, where appropriate, of an independent compliance monitor. These elements are not merely cosmetic. Where a business can demonstrate that the conditions giving rise to the violation have been structurally addressed, that demonstration supports the argument that criminal prosecution serves a lower marginal deterrence purpose than a negotiated civil resolution.
The UK and EU enforcement authorities similarly weigh post-violation remediation. ECJU's internal guidance and the relevant thematic regulations acknowledge remediation as a factor in enforcement discretion. EU member-state prosecutors, applying their national criminal codes, may also be influenced by evidence of genuine organisational change – though the weight they assign to it varies.
A remediation programme that is designed and documented before the first substantive regulator contact is strategically stronger than one assembled reactively in response to an enforcement notice. In cross-border criminal export-control matters, the remediation plan should address every regime in scope, not only the primary jurisdiction. Regulators in secondary jurisdictions who learn of a disclosure in the primary jurisdiction will ask what steps were taken to remediate the conduct that affected their own regime.
The position above covers the structured assessment in its main phases. Your specific facts – the items involved, the shipping routes, the entities implicated, the documentation that exists or does not exist – will change the analysis materially. For a confidential assessment of your exposure under the applicable regimes, contact Calder & Vance at info@caldervance.com.
Common risk flags and where cross-border businesses typically go wrong
Several recurring patterns appear in cross-border criminal export-control matters across the regimes we advise on. Understanding them is part of any effective internal assessment.
The first is jurisdiction underestimation. Businesses with no US operations routinely underestimate BIS extraterritorial reach. The de minimis rule and the foreign direct product rule extend EAR jurisdiction to items and technology produced outside the United States, and those rules have been applied with increasing frequency. If any component of your product was of US origin, or if the production technology was US-licensed, the EAR analysis is live.
The second is classification over-reliance on commercial descriptions. An item described by its manufacturer as a "commercial grade sensor" may carry an ECCN that requires a licence for the specific end-user or destination. Commercial descriptions and ECCN classifications are not the same thing, and treating them as equivalent is a classification methodology error that has produced significant criminal exposure.
The third is compliance programme atrophy. A compliance programme that was well-designed three years ago but has not been updated following changes to control lists, new regime additions to screening databases, or changes in the business's own supply chain is, in practice, no longer fit for purpose. In our experience, regulators look at whether the compliance programme was current at the time of the violation – not whether one existed at some prior point.
The fourth – specific to the cross-border setting – is the assumption that resolving the primary regime (most commonly the EAR) resolves the whole matter. It does not. The UK, EU member states, Singapore, and Japan each have their own enforcement authorities with their own statutory timelines and their own assessment of the applicable conduct. A negotiated civil resolution with BIS does not bind any of those authorities.
One myth we frequently encounter is that criminal export-control prosecution is reserved exclusively for deliberate bad actors – arms traffickers and rogue insiders. That is not accurate. Wilful blindness findings, strict-liability UK offences, and the increasingly aggressive enforcement posture of multiple regulators mean that businesses with genuine compliance intentions but inadequate programmes face real criminal exposure.
Related practices
- Apparent Violation Assessment – EU – structured assessment of export-control and sanctions violations under the EU regime, from self-identification through disclosure strategy.
- Criminal Export-Control Exposure – EU Guide – regime-specific analysis of criminal exposure under EU dual-use rules and member-state criminal codes.
- Criminal Export-Control Exposure – Japan Guide – practitioner analysis of criminal exposure under Japan's Foreign Exchange and Foreign Trade Act and strategic-goods controls.