A logistics director at a mid-sized British manufacturer receives a call from the compliance team. A shipment of dual-use components has been held at the port. The buyer is located in a jurisdiction subject to UK trade restrictions. The export licence was not obtained. Now the question is not whether there is a problem – it is how serious that problem is, and specifically whether criminal exposure has arisen under the UK sanctions and export-control regime.
Assessing criminal exposure in export-control cases under OFSI (the Office of Financial Sanctions Implementation) and the broader UK enforcement architecture requires a structured, sequenced analysis. As of March 2026, UK law provides for both civil monetary penalties and criminal prosecution for export-control and financial-sanctions breaches. The applicable criminal threshold turns on knowledge, intent, and the specific statutory basis engaged – not simply on whether a prohibited act occurred.
This guide walks through the assessment process step by step, identifies the points where criminal risk crystallises, and explains where the UK regime diverges from its US and EU counterparts in ways that matter for cross-border businesses.
Step 1 – Identify the statutory basis engaged
The first step in any exposure assessment is to determine which UK instrument governs the conduct in question. This determines who enforces, what the criminal threshold is, and what defences or licence routes may be available.
UK export-control obligations and financial-sanctions obligations are distinct in their statutory origin, their enforcing authorities, and their criminal provisions. Financial sanctions are administered by OFSI under the Sanctions and Anti-Money Laundering Act ("SAMLA"), the primary UK sanctions legislation. Export licensing and trade controls are administered by ECJU (the Export Control Joint Unit) and engage the Export Control Order and its underlying criminal provisions.
Why does this distinction matter? Because a single shipment can engage both regimes simultaneously. A controlled item supplied to a sanctioned end-user may constitute a trade-control offence and a financial-sanctions breach at the same time. The criminal exposure for each flows from a different statutory source and may involve different prosecutors. In our experience, businesses and their advisers sometimes focus exclusively on OFSI and overlook the export-licensing dimension – or vice versa – which leaves half the criminal analysis undone.
The practical starting point is to map the act or omission against each relevant instrument. Was the item subject to an export licence requirement under the Export Control Order? Did a payment, transfer, or making available of funds involve a designated person? Could a trade restriction under the applicable country regime have been triggered independently? Each question has its own answer pathway.
Step 2 – Apply the criminal threshold test
Under UK law, the criminal threshold for both export-control and financial-sanctions offences turns principally on knowledge and intent, though the precise mental-element standard varies by provision.
For financial-sanctions purposes, SAMLA provides that a person commits a criminal offence if they knowingly or intentionally breach a prohibition. A purely accidental breach – one caused by a screening failure with no element of knowledge – is more likely to be addressed through OFSI's civil monetary penalty powers than through criminal referral. That said, OFSI's enforcement guidance makes clear that it considers the degree of culpability, the systems in place, and whether the person had reason to know of the prohibition.
For export-control offences, the criminal provisions cover conduct where there is knowledge that the item requires a licence and that licence has not been obtained. Recklessness as to whether a licence is needed has been treated as sufficient in some circumstances. This is a point of real practical significance: a business that fails to classify its goods properly and ships without a licence cannot always rely on ignorance as a shield.
The assessment must therefore establish: what did the relevant individuals know about the item, the end-user, and the licence requirement at the time of the conduct? What did the organisation's compliance systems tell them, or fail to tell them? Were there red flags that were not escalated? These questions map directly to the statutory mental elements. They also shape any eventual penalty defence or voluntary self-disclosure ("VSD") case.
Step 3 – Scope the facts and build the exposure timeline
Once the statutory basis and the criminal threshold are identified, the exposure assessment requires a disciplined reconstruction of what happened, in sequence, from first contact with the counterparty or transaction to the point at which the potential breach was identified.
The timeline should record every decision point: when the counterparty was screened, what the result was, whether the item was classified, whether a licence application was initiated, what internal approvals were obtained, and who was aware of what at each stage. This is not a paper exercise. It is the foundation for every subsequent conversation with regulators, and it is the basis on which any VSD to OFSI or ECJU would be constructed.
In a recent matter, a specialist manufacturer in the technology sector identified that several historical shipments had been made under an incorrect commodity classification, which meant that export licences had not been applied for items that required them. We assisted the client in reconstructing the full shipment history, mapping the classification error to its source in the compliance programme, and assessing the degree to which individuals with approval authority had been on notice. That analysis determined the VSD strategy and the framing of the penalty representations. The matter was resolved through the civil enforcement pathway without criminal referral.
Record-keeping is a critical parallel obligation. Businesses subject to UK export-control requirements must maintain documentation supporting each export. OFSI similarly expects that records of screening and due diligence decisions are retained. Gaps in records do not create a presumption of guilt, but they significantly complicate any defence narrative.
Step 4 – Compare the criminal risk profile across regimes
Criminal exposure in export-control cases under OFSI and ECJU cannot be assessed in isolation when a business has cross-border operations. The same transaction may engage the extraterritorial reach of US export controls (principally through the Export Administration Regulations administered by BIS) and EU dual-use regulations, each with their own criminal or quasi-criminal enforcement mechanisms.
Under the US Export Administration Regulations, BIS administers a Commerce Control List ("CCL") and enforces licence requirements with both civil and criminal penalties. Critically, the EAR applies extraterritorially in specific circumstances – including to de minimis US-origin content incorporated into foreign-made items and to items produced using certain US technology or software. A UK exporter that ships a product incorporating US-origin controlled components must satisfy itself that EAR requirements are met, in addition to UK licence requirements. Criminal exposure under the EAR is assessed by the US Department of Justice. OFSI plays no role there.
In the EU, dual-use controls sit within a directly applicable EU regulation. Post-Brexit, UK and EU controls have diverged in some product classifications and end-user provisions. A business exporting from both the UK and an EU member state faces two sets of classification obligations that are similar but not identical. Where they diverge, the stricter prohibition governs the exporter's position in each jurisdiction independently.
How does OFSI differ from OFAC on the criminal question? OFAC's enforcement is primarily civil, with criminal referrals made to DOJ for the most serious cases involving wilful conduct. OFSI similarly distinguishes between civil and criminal pathways, with criminal prosecution reserved for knowing or intentional breach. The practical difference is that OFAC operates a significantly larger civil penalty programme and has established detailed public guidance on the factors it weighs in penalty determinations. OFSI's published enforcement guidance is less granular on the criminal referral threshold, which makes early legal advice more important in a UK context when the facts suggest knowledge or intent.
For businesses with operations in Singapore, Japan, or the UAE, the picture adds further layers. Singapore's Strategic Goods (Control) Act provides criminal penalties for unlicensed exports of controlled items. Japan's Foreign Exchange and Foreign Trade Act and the UAE's export-control and sanctions regime each carry their own criminal provisions with distinct mental-element tests. A cross-border exposure assessment must address each regime on its own terms and identify which jurisdiction poses the highest criminal risk, since enforcement action in one does not preclude parallel proceedings in another.
Step 5 – Identify the key risk flags
Certain facts, when present, elevate the probability that a civil enforcement case becomes a criminal referral. Recognising these flags early allows counsel to structure the response accordingly.
The most significant risk flags in our practice are:
- Prior warnings or guidance – if the business received compliance guidance, a warning letter, or a previous civil penalty from OFSI or ECJU, and the breach occurred after that communication, the argument that the conduct was unknowing becomes very difficult to sustain.
- Documentary evidence of intent – internal emails, messaging, or records showing that individuals were aware of a restriction and chose to proceed are directly probative of the criminal mental element.
- Structured transactions – where a series of transactions appears designed to stay below a reporting threshold, or where intermediate parties are interposed between the UK exporter and a restricted end-user, this pattern raises the question of whether the structure was deliberate. Note that explaining or structuring transactions for legitimate commercial reasons is not inherently problematic, but the compliance logic must be documented contemporaneously.
- Repeated or systematic breaches – a one-off classification error presents differently from a pattern of shipments over multiple years without licence applications.
- Failure to report a known breach – OFSI expects regulated firms to report known or suspected breaches. Delay or non-reporting, once a breach is identified internally, is a separate adverse factor in enforcement.
Is every breach with one or more of these flags destined for criminal prosecution? No. But the presence of any flag should shift the internal response from a routine compliance review to an engagement involving sanctions counsel from the outset.
Step 6 – Decide on voluntary self-disclosure and the response strategy
Once the exposure has been scoped, the central decision is whether and how to approach OFSI or ECJU proactively. A VSD (voluntary self-disclosure to a regulator) is not an automatic mitigation, but it is the most powerful tool available to a business that has identified a potential breach before a regulator does.
OFSI's enforcement guidance acknowledges VSD as a factor that weighs in favour of reduced penalties. The timing and quality of disclosure both matter. A VSD that is complete, accurate, and submitted promptly – before the regulator has initiated its own inquiry – carries significantly more weight than a disclosure made after a regulator's enquiry letter has arrived.
The content of a VSD must be considered carefully. A disclosure that over-states the scope of the breach, or that includes inaccurate characterisations of the mental element, can complicate the business's position rather than improve it. We regularly advise clients that the first step before submitting any VSD is to complete the exposure analysis described in this guide, so that the disclosure is accurate, bounded, and supported by the full factual record.
The position above covers the standard case. Your facts – the item, the end-user, the route, the internal records, and the specific regime in play – change the analysis materially. For a confidential review of a potential breach, contact Calder & Vance at info@caldervance.com.
Where the exposure is primarily civil, the VSD feeds into penalty representations and the enforcement process. Where criminal indicators are present, the VSD strategy must be designed in the knowledge that anything disclosed could be used in a criminal prosecution, and privilege considerations become central to the engagement.
A common myth: civil enforcement always precedes criminal referral
One assumption we encounter frequently is that UK export-control and sanctions enforcement follows a fixed sequence: civil first, criminal only after civil resolution. That assumption is inaccurate. OFSI and ECJU are not bound to exhaust civil proceedings before making a criminal referral to prosecutors. A parallel investigation – civil and criminal simultaneously – is possible where the facts suggest a serious knowing breach.
The better assumption is that any breach with knowledge or intent indicators can attract both pathways at once. The practical implication is that a business's internal response from the moment a potential breach is identified should be designed with both tracks in mind. In our cross-border practice, we structure the initial internal review so that it is defensible in both a civil penalty defence and, if necessary, in a criminal investigation context.
If a transaction has already been flagged or an enquiry letter has arrived, early review with sanctions counsel preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss your position.
When to involve sanctions counsel
The short answer is: earlier than most businesses do. The assessment described in this guide is demanding and requires a combination of knowledge of UK financial-sanctions law, export-control law, and the enforcement practices of OFSI and ECJU. It also requires a cross-regime view when US or EU controls are simultaneously engaged.
Specific triggers that should prompt immediate instruction of sanctions counsel include:
- Identification of a shipment made without a required export licence, particularly where the item is a controlled dual-use good
- A payment or transaction involving a counterparty that appears on a sanctions list, or that is owned or controlled by a listed person
- Receipt of an enquiry letter from OFSI or ECJU
- A regulator-initiated visit, information request, or notice
- A voluntary internal audit that reveals a pattern of potential breaches across multiple transactions or time periods
- A notification from a bank or financial institution that a payment has been blocked or a screening hit has been generated
Delay in any of these circumstances is the most consistent source of avoidable harm in enforcement cases. The window for a well-framed VSD, for preserving legally privileged communications, and for securing the factual record narrows the moment a regulator begins its own inquiry.
Related practices
- Apparent Violation Assessment – EU – how EU sanctions enforcement characterises apparent violations and frames penalty decisions
- Criminal Export Exposure – SECO (Switzerland) – assessing criminal risk under Swiss export-control and sanctions law
- Criminal Export Exposure – Singapore – criminal provisions under Singapore's Strategic Goods (Control) Act and sanctions regime