A US-headquartered technology company exports controlled components to a distributor in a third country. Six months later, a re-export surfaces in a jurisdiction subject to comprehensive OFAC sanctions. The compliance team now faces a question that goes well beyond a civil penalty calculation: is there criminal exposure? That question – and the speed with which it is answered – can define the outcome of an enforcement engagement.
Assessing criminal exposure in export-control cases (the risk that a violation of US export controls or OFAC sanctions gives rise to criminal prosecution rather than, or in addition to, civil penalties) requires a structured analysis of four elements: wilfulness, knowledge, the applicable legal instrument, and the involvement of parallel agencies. As of March 2026, both OFAC and the Department of Justice treat criminal export-control enforcement as a priority, and cross-agency referrals between OFAC, BIS, and DOJ are a routine feature of the current enforcement environment.
This guide walks through that assessment in six steps, addresses the most common points of exposure, compares the US position with the UK and EU regimes, and explains when to involve external sanctions counsel.
Step 1 – Identify the governing instrument and the enforcement authority
Criminal export-control exposure under the US regime arises from two overlapping legal instruments: the Export Administration Regulations administered by BIS and the economic sanctions programmes administered by OFAC under IEEPA and, in limited cases, the Trading with the Enemy Act (TWEA). These are distinct regimes with distinct enforcement postures, but they frequently apply to the same transaction.
OFAC administers the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and the broader set of OFAC sanctions programmes. OFAC's civil enforcement authority is well documented. Its criminal referral authority – the capacity to refer matters to DOJ for prosecution – is the feature that transforms a compliance failing into a potential criminal matter. BIS, for its part, enforces the Export Control Reform Act and the EAR, with its own referral pathway to DOJ's National Security Division.
Practitioners advising on OFAC matters note that the single most important threshold question is whether the agency views the apparent violation as a civil matter amenable to a voluntary self-disclosure (VSD) (a voluntary self-disclosure to a regulator) – or as a potential criminal referral. That determination turns almost entirely on what the agency learns about knowledge and intent.
The position above covers the standard case. Your facts – the counterparty, the goods, the jurisdictions involved, and the documentation trail – change the analysis materially. For a preliminary assessment of your exposure, contact Calder & Vance at info@caldervance.com.
Step 2 – Apply the wilfulness and knowledge tests
Criminal liability under the US export-control regime requires proof of wilfulness: the government must show that the defendant knew their conduct was unlawful, not merely that they knew what they were doing. This is a higher standard than the strict-liability base that governs civil OFAC violations, but it is regularly met in enforcement cases involving sophisticated parties.
The knowledge test operates alongside wilfulness. Under the EAR, "knowing" a violation would occur – including where a party has reason to know through red flags that it chooses to ignore – is sufficient to support criminal prosecution. Wilful blindness, sometimes described as deliberate ignorance, is treated by US courts as equivalent to actual knowledge. That equivalence is the most dangerous gap in the assessment for compliance teams.
In practice, the assessment of knowledge turns on contemporaneous documentation. What did compliance records, internal emails, customer communications, and licensing files show at the time of the transaction? We regularly advise clients that the document review conducted in the first seventy-two hours after an apparent violation surfaces is often determinative of how the agency reads the case. A clean contemporaneous record that shows genuine diligence – even where a violation technically occurred – is the single strongest mitigant against a criminal referral.
What does the record actually show? That question, asked honestly and early, is the foundation of any credible exposure assessment.
Step 3 – Map the goods, the transaction chain, and the re-export risk
Criminal exposure is not always triggered at the point of first export. Re-export violations – where goods leave the United States lawfully and are subsequently transferred to a sanctioned destination or end-user without the required authorisation – generate a significant share of criminal referrals in the current enforcement environment. The goods classification and the transaction chain must therefore be traced fully, not just to the first foreign consignee.
The starting point is the ECCN (Export Control Classification Number under the US Commerce Control List). An item classified under a control-list entry requiring a licence for the destination in question, and exported without one, creates the foundation for both a civil and a criminal case. Items that fall outside the Commerce Control List are classified as EAR99 – but EAR99 does not mean licence-free to OFAC-sanctioned destinations; OFAC's prohibitions apply independently of export-control classification.
The transaction chain analysis must cover: the exporter of record; any freight forwarder or intermediary; the stated end-user and end-use; any known or reasonably discoverable onward transfer; and the jurisdiction of each party. In our cross-border practice, we frequently identify a structural gap at the intermediary layer – a trading company or logistics provider that sits between the US exporter and the ultimate destination and whose relationships have not been adequately diligenced.
Re-export risk is particularly acute for technology exporters supplying distributors in third countries with open re-export markets. The question is not only what the exporter knew, but what they had the means to know and what their contractual arrangements required of the counterparty.
Step 4 – Assess the parallel-agency and cross-border dimension
Criminal export-control cases in the United States rarely involve a single agency. OFAC, BIS, and DOJ's National Security Division operate as a coordinated enforcement triad, and referrals between them are a standard feature of major investigations. A company that receives a BIS administrative subpoena should assume that the information it provides may be shared with OFAC and, where criminal indicators are present, with DOJ.
The cross-border dimension adds a second layer. UK and EU counterpart regulators – OFSI and the EU member-state competent authorities – have their own criminal enforcement frameworks. The UK's Sanctions and Anti-Money Laundering Act (SAMLA) creates criminal offences for breach of financial sanctions with a knowledge element broadly comparable to the OFAC standard. EU member states implement criminal sanctions enforcement at the national level, with differing thresholds and prosecutorial traditions. A transaction that runs through a UK or EU entity may therefore generate parallel criminal exposure in those jurisdictions alongside the US enforcement risk.
The divergence matters practically. Under OFSI, the ownership-and-control test for determining whether a non-listed entity is caught includes a control element – meaning that a company may be subject to OFSI prohibitions even where listed persons hold less than the threshold ownership stake, if they exercise control in other ways. OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) is mechanical and does not turn on control. That divergence can mean that a transaction assessed as compliant under one regime is a potential violation under another.
If a transaction has already been flagged, or a filing has been refused, an early multi-regime review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com.
Step 5 – Evaluate the voluntary self-disclosure decision
Once a potential violation is identified, the most consequential decision in the exposure assessment is whether and when to file a VSD with OFAC and, separately, with BIS. A timely and complete VSD to OFAC is a significant mitigating factor in the agency's penalty calculation. More importantly for criminal-exposure purposes, a well-constructed VSD that demonstrates genuine cooperation and a credible remediation plan reduces – though it does not eliminate – the risk of a criminal referral to DOJ.
The VSD decision is not straightforward. Filing a VSD that is incomplete, or that is inconsistent with evidence already held by the agency, is substantially worse than not filing at all. The document-and-facts review that precedes the VSD decision is therefore not optional. It is the condition that determines whether a VSD is a genuine mitigant or an aggravating event.
In our experience, the most common error at this stage is treating the VSD as an administrative filing rather than as an enforcement strategy document. The VSD is the first substantive communication the agency receives about the company's knowledge, intent, and remediation. Every choice in its drafting – scope, chronology, characterisation of the facts – shapes the enforcement trajectory that follows.
The VSD decision is also bilateral. If the goods were subject to BIS export-control requirements, a separate VSD to BIS may be appropriate. Coordinating those two filings to ensure consistency and to address any differences in the information already held by each agency is a practical necessity, not a courtesy.
Step 6 – Identify risk flags and determine when to involve counsel
Not every apparent export-control violation carries meaningful criminal exposure. The risk-flag analysis distinguishes the cases that warrant immediate external counsel from those that can be managed through internal compliance channels with advisory support. The following patterns consistently elevate criminal risk in cases we handle:
- Documentary evidence of actual knowledge of a sanctions restriction at the time of the transaction – including internal emails that flag the risk and are not acted upon.
- Deliberate structuring of the transaction to avoid a screening hit or a licence requirement, even where the individual steps appeared compliant in isolation.
- Repeated violations of the same type after an internal compliance finding – a pattern that agencies read as wilful disregard rather than systemic error.
- Involvement of a counterparty that was, at the time, the subject of an agency inquiry or enforcement action that the exporter could reasonably have identified.
- Transactions involving goods with recognised end-use risk – items with known weapons-relevant applications – exported to end-users whose declared use does not match the technical specification of the goods.
- Evidence that a freight forwarder or intermediary advised against the transaction on sanctions or export-control grounds and the exporter proceeded regardless.
Where any of these flags are present, the assessment should involve external sanctions counsel before any communication with the agency. That is not a counsel-preservation exercise. It is a practical reality that the first substantive agency communication – whether a response to an administrative inquiry, a VSD, or a voluntary production – sets the frame for everything that follows.
A micro-scenario illustrates the pattern. In a recent matter, a mid-sized electronics manufacturer received a BIS administrative inquiry regarding shipments to a distributor in a third country. Internal review revealed a chain of emails in which the sales team had been informed of a potential end-use concern and had proceeded without escalating to compliance. We conducted a scoped document review, coordinated a VSD strategy with both OFAC and BIS, and designed a remediation programme addressing the escalation gap. The matter resolved at the civil level. The outcome illustrates the value of early structured analysis – but outcomes are never guaranteed and depend on the specific facts of each case.
A common myth: civil resolution forecloses criminal exposure
A persistent misconception among compliance teams is that an OFAC civil settlement – a payment, a consent agreement, a no-action letter – resolves the full exposure arising from the same conduct. It does not. OFAC's civil enforcement authority and DOJ's criminal jurisdiction are legally distinct. A civil settlement with OFAC does not bar DOJ from pursuing criminal charges on the same underlying conduct where the criminal elements are independently established. That is not a theoretical risk. In our practice we have advised clients who assumed a civil settlement had closed the matter, only to face subsequent criminal inquiry from DOJ or a parallel authority.
The same principle applies in reverse: a DOJ declination does not automatically extinguish OFAC's civil enforcement authority. The regimes operate in parallel, and a structured resolution strategy must address both tracks from the outset.
Related practices
- EU apparent-violation assessment – scoped review of potential EU sanctions violations and disclosure strategy
- Criminal export-control exposure under OFSI – step-by-step guide to UK criminal sanctions risk
- Criminal export-control exposure under SECO – guide to Swiss export-control criminal exposure