Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · EU

How to assess criminal export-control exposure under EU

A mid-sized European manufacturer ships a consignment of precision optics to a distributor in a third country. The documentation looks clean. The end-user certificate is signed. Six months later, a national prosecutor contacts the compliance team. The goods, it emerges, had an Export Control Classification that required an individual licence – and no licence was obtained. The question is no longer whether a regulatory fine is coming. The question is whether directors face criminal charges.

Criminal exposure in export-control cases under EU rules arises primarily through Member State criminal law, applied to violations of EU dual-use regulations and, where applicable, the arms embargo and sanctions regulations administered by the Council. The EU regime does not itself create a uniform criminal offence: each Member State defines penalties, but the underlying prohibition is set at the EU level and the factual trigger – an unlicensed export, a false end-use statement, a breach of a denial condition – is the same across the bloc. As of March 2026, prosecutors in several jurisdictions have significantly increased enforcement activity in this area.

This guide walks through the assessment in six steps: identifying the legal basis of exposure, mapping the classification question, reviewing end-use and end-user conditions, testing the knowledge and intent elements that determine criminal versus administrative liability, comparing the EU position with those of OFAC and OFSI, and deciding when to involve counsel.

Step 1: Identify the legal basis – EU rules and Member State criminal law

The starting point in any criminal export-control assessment is identifying which instrument created the obligation that was allegedly breached. EU dual-use controls operate through a directly applicable Council Regulation: it sets the lists, the licence requirements, and the prohibition conditions that bind all Member States uniformly. What it does not do is define the criminal sanction. That task is left to each Member State's own legislation, which must give effect to the requirement that penalties be effective, proportionate, and dissuasive.

In practice, this means the same export violation can produce very different criminal outcomes depending on where the exporter is established. A manufacturer based in Germany, France, or the Netherlands will face the criminal law of that state, even though the underlying prohibition is identical across all three. Jurisdiction typically attaches where the goods departed, where the entity is incorporated, or where the decision to export was made.

Two additional EU instruments are relevant. The EU Blocking Regulation affects how certain third-country export-control decisions interact with EU obligations. More directly, the sanctions regulations adopted by the Council – covering asset freezes, arms embargoes, and sector-specific export prohibitions – add a second layer of controls that can engage both administrative and criminal liability simultaneously. An unlicensed export of a controlled good to an entity subject to an EU sector-specific restriction may therefore breach both the dual-use regulation and the relevant thematic sanctions regulation.

The cross-border angle matters immediately. Where an exporter operates across multiple Member States – through subsidiaries, warehouses, or transit arrangements – the same shipment may fall within the jurisdiction of more than one national prosecutor. We regularly advise clients who discover that a single transaction has attracted parallel inquiries in two jurisdictions.

Step 2: Map the classification – did the item require a licence?

The classification question is the factual foundation of every criminal exposure assessment. An item requires an individual licence if it appears on the EU Common Military List or on the dual-use list appended to the applicable Council Regulation, and if no general authorisation or Union General Export Authorisation covers the proposed transaction.

Classification errors are common. They arise from reliance on supplier descriptions rather than technical specifications, from outdated product assessments that predate list amendments, and from a failure to apply the catch-all provisions. The catch-all is particularly significant in criminal proceedings: a prosecutor does not need to prove that the item was on the list if it can be shown that the exporter had reason to believe – or was actually informed by the competent authority – that the item might be intended for a use that would trigger control.

In our experience, the classification file is the first document a criminal defence team needs. If an exporter cannot produce a contemporaneous, technically grounded classification analysis, the criminal inference is straightforward: the exporter either did not check or chose to proceed without certainty. Both positions are difficult to defend.

What does a defensible classification record look like? It should identify the technical parameters of the item, map those parameters to the list entries considered and rejected, record who conducted the analysis and when, and note any competent-authority confirmation. This is distinct from a commercial item description.

Step 3: Review end-use and end-user conditions – where criminal exposure concentrates

Criminal exposure in export-control cases under EU rules is most acute where the alleged violation involves a false or misleading end-use statement. Regulators and prosecutors treat end-use fraud as the most serious category of export-control breach because it is intentional by nature and undermines the entire licensing architecture.

The end-user certificate and the post-shipment assurance are not administrative formalities. They are the factual basis on which a licence was granted or a general authorisation was relied upon. Where those documents contained a misstatement – even one the exporter did not originate but passed on without verification – the question for criminal liability is what the exporter knew or should have known.

Red-flag indicators are well established across EU guidance and the export-control practice of Member State authorities. They include: a buyer that operates in a sector inconsistent with the goods; a request to omit technical specifications from shipping documents; unusual payment routing; a third-country re-export to a destination that would itself require a licence; and reluctance by the buyer to confirm the ultimate end-use in writing.

A business that identified one or more of these indicators and proceeded without escalating has a materially weaker position in any criminal proceedings than one that can show documented escalation, legal review, and a reasoned decision to proceed. The difference between an administrative penalty and a criminal prosecution often turns on exactly this paper trail.

Step 4: Test the knowledge and intent elements

Criminal liability under Member State law implementing EU export controls generally requires proof of knowledge or intent, though the precise standard varies. Some Member State systems impose criminal liability on negligent conduct; others require at least recklessness or deliberate disregard of a known risk. Understanding the applicable mental element is essential before advising on exposure.

Three scenarios arise in practice. First, the exporter knew the item was controlled, knew no licence had been obtained, and proceeded. This is the clearest criminal exposure and the one most likely to attract prosecution rather than a civil or administrative response. Second, the exporter had reason to know – red flags were present, a legal review was available but not sought, or a prior refusal was on record – but chose not to investigate. Many Member State prosecutors treat this as sufficient for criminal liability. Third, the exporter acted on a genuinely held, objectively reasonable classification analysis, disclosed fully to the competent authority, and had no reason to doubt the end-use statement. This is the strongest position in a criminal defence.

The distinction between categories two and three is often the question in a criminal investigation. In our cross-border practice, the quality of the contemporaneous documentation is what separates these categories in proceedings. A post-incident reconstruction of the classification analysis, however accurate, carries less weight than a record made at the time.

The position above covers the standard case. Your facts – the item, the jurisdiction, the end-user, the documentation, and what the exporter's internal records show – change the analysis sharply. For an assessment of your exposure under the EU regime, contact Calder & Vance at info@caldervance.com.

How does the EU criminal exposure test compare with OFAC and OFSI?

The EU's fragmented, Member State-implemented criminal enforcement model differs significantly from the approaches taken by OFAC in the United States and OFSI in the United Kingdom, and that difference affects both strategy and risk calibration for businesses operating across regimes.

OFAC's enforcement is primarily civil and administrative. Criminal prosecution for US export-control violations is led by the Department of Justice working alongside BIS, and the standards for criminal liability under the EAR turn on wilfulness in most serious cases. OFAC itself does not prosecute; it imposes civil penalties, and the voluntary self-disclosure (VSD) mechanism – a formal self-report to OFAC, which can reduce a civil penalty by a significant proportion – is a well-developed part of the US regime. For a detailed comparison of the OFAC criminal exposure question, see our guide to criminal export-control exposure under OFAC.

OFSI in the United Kingdom administers financial sanctions rather than export controls directly, but the enforcement posture is relevant: OFSI's monetary penalty regime has a civil standard of proof for the higher tier of penalties, and criminal prosecution for UK trade sanctions violations runs through HM Revenue and Customs and the Crown Prosecution Service. The UK has been increasing enforcement resources in this area, and the interplay between OFSI financial sanctions and ECJU export licence conditions creates a layered exposure for UK-established exporters.

The EU's reliance on Member State criminal law means there is no single prosecutorial authority to negotiate with, no VSD mechanism at the EU level equivalent to the US model, and no consolidated enforcement statistics that allow a firm to calibrate the probability of criminal referral versus administrative settlement. What is consistent across the EU is the underlying prohibition: if the goods required a licence and no licence was obtained, the factual violation is established. Whether it becomes a criminal matter depends on the Member State and the evidence of knowledge or intent.

For businesses with operations in Japan – a jurisdiction that has significantly strengthened its export-control criminal enforcement in recent years – our guide to criminal export-control exposure under Japan's regime sets out the applicable tests and risk indicators.

If a transaction has already been flagged, or an internal review has surfaced a potential violation, an early legal assessment can preserve options that narrow with time. Contact us at info@caldervance.com.

Step 5: Identify risk flags that elevate criminal exposure

Not every export-control violation attracts criminal investigation. Prosecutors and competent authorities assess a set of aggravating factors that distinguish cases warranting criminal referral from those handled administratively. Mapping these factors against your facts is a core part of any exposure assessment.

The factors that consistently elevate criminal risk under the EU regime and Member State practice include: a destination subject to an EU arms embargo or sector-specific export prohibition; a consignee that is a designated person under an EU thematic sanctions regulation; evidence that the controlled good was re-exported to a destination that would have required a separate licence; a prior competent-authority warning or a prior refusal of a licence application for a similar transaction; and a systematic pattern of similar exports rather than an isolated incident.

Volume matters. A single shipment that was incorrectly classified may be treated as an administrative matter in most Member State systems. A programme of similar shipments – even if each is individually small – reads as intentional and is far more likely to attract criminal investigation. This is consistent with the enforcement approach we observe across the major EU jurisdictions.

A second category of risk flags relates to the corporate structure. Transactions structured to route goods through an intermediary in a third country, to avoid a licence requirement that would apply to a direct export, will be scrutinised for intent. The same applies to transactions where the declared value or weight in the shipping documents is inconsistent with the technical specifications of the item. These are not compliance oversights; they are indicators of intent that prosecutors are trained to identify.

Step 6: Decide when to involve counsel – and what that engagement covers

The decision to involve counsel is itself a risk-management decision. In our experience, it should be made at the earliest of the following: when an internal review identifies a potential unlicensed export; when the business receives a competent-authority enquiry, a customs query, or a request for documentation; or when a compliance officer identifies transaction-level red flags that were not escalated at the time of the shipment.

Early involvement preserves three things. First, it protects the integrity of the internal review: a lawyer-directed investigation creates a stronger basis for privilege claims over the findings, which is relevant if criminal proceedings follow. Second, it allows an assessment of whether a voluntary disclosure to the competent authority is appropriate and, if so, how to structure it. There is no EU-level VSD mechanism equivalent to the US model, but many Member State authorities treat a proactive, well-documented disclosure more favourably than a defence raised after a formal investigation opens. Third, it creates a contemporaneous record that the business took the matter seriously – which is itself relevant to the criminal standard of knowledge and intent.

What does counsel engagement cover in a criminal export-control matter? In our apparent violation assessment service for EU export-control matters, we scope the apparent violation against the applicable EU regime and the relevant Member State criminal law, advise on the privilege position for internal documents, assess the voluntary disclosure question, and prepare the legal and factual analysis needed for a penalty defence or a prosecutorial response. That work is distinct from the classification exercise; both are necessary.

A common myth is that criminal export-control proceedings in the EU are so rare that a business should manage the matter administratively and see what happens. That position was more defensible five years ago. Several Member State prosecutors have materially increased enforcement activity, and the political environment has accelerated that trend. Treating a potential criminal exposure as an administrative compliance matter carries a real risk of missing the window in which constructive engagement with the competent authority is possible.

Related practices

Frequently asked questions

What are the steps to assess criminal export-control exposure under EU?
Assess criminal export-control exposure under the EU regime in six steps: identify the EU instrument that created the obligation (the dual-use regulation or the applicable thematic sanctions regulation); confirm whether the item required an individual licence; review end-use and end-user documentation for accuracy; test the knowledge or intent elements under the applicable Member State's criminal law; map aggravating factors that elevate criminal risk; and decide whether to make a voluntary disclosure to the competent authority. Each step should be supported by contemporaneous documentation. The export classification file and the end-user record are the two most critical documents in any criminal proceedings.
What is the most common mistake in criminal exposure in export-control cases?
The most common mistake is treating a potential criminal matter as a routine compliance issue and failing to involve counsel until after a formal investigation opens. By that point, the window for voluntary disclosure has typically closed, the internal investigation record has been made without privilege protection, and key witnesses have given informal statements. A second, closely related mistake is relying on a supplier's product description as the classification analysis. Neither an item's commercial name nor the supplier's export documentation substitutes for a technically grounded classification against the EU dual-use list entries. Prosecutors treat both failures as evidence of recklessness.
How does EU differ from other regimes here?
The EU is distinctive in that it sets the export-control prohibition at the EU level through directly applicable Council Regulations, but leaves criminal enforcement entirely to Member State law and prosecutors. There is no single EU criminal authority, no EU-level voluntary self-disclosure mechanism equivalent to the OFAC or BIS models, and no consolidated enforcement record. This contrasts with the United States, where BIS and DOJ have developed a structured VSD process with defined penalty-mitigation credits, and with the United Kingdom, where enforcement runs through a national authority with published guidance. The practical consequence is that EU criminal exposure depends heavily on the Member State of establishment and the specific jurisdiction's enforcement posture.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.