Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · OFSI

How to assess criminal export-control exposure under OFSI

A logistics director at a mid-sized British manufacturer receives a call from the compliance team. A shipment of dual-use components has been held at the port. The buyer is located in a jurisdiction subject to UK trade restrictions. The export licence was not obtained. Now the question is not whether there is a problem – it is how serious that problem is, and specifically whether criminal exposure has arisen under the UK sanctions and export-control regime.

Assessing criminal exposure in export-control cases under OFSI (the Office of Financial Sanctions Implementation) and the broader UK enforcement architecture requires a structured, sequenced analysis. As of March 2026, UK law provides for both civil monetary penalties and criminal prosecution for export-control and financial-sanctions breaches. The applicable criminal threshold turns on knowledge, intent, and the specific statutory basis engaged – not simply on whether a prohibited act occurred.

This guide walks through the assessment process step by step, identifies the points where criminal risk crystallises, and explains where the UK regime diverges from its US and EU counterparts in ways that matter for cross-border businesses.

Step 1 – Identify the statutory basis engaged

The first step in any exposure assessment is to determine which UK instrument governs the conduct in question. This determines who enforces, what the criminal threshold is, and what defences or licence routes may be available.

UK export-control obligations and financial-sanctions obligations are distinct in their statutory origin, their enforcing authorities, and their criminal provisions. Financial sanctions are administered by OFSI under the Sanctions and Anti-Money Laundering Act ("SAMLA"), the primary UK sanctions legislation. Export licensing and trade controls are administered by ECJU (the Export Control Joint Unit) and engage the Export Control Order and its underlying criminal provisions.

Why does this distinction matter? Because a single shipment can engage both regimes simultaneously. A controlled item supplied to a sanctioned end-user may constitute a trade-control offence and a financial-sanctions breach at the same time. The criminal exposure for each flows from a different statutory source and may involve different prosecutors. In our experience, businesses and their advisers sometimes focus exclusively on OFSI and overlook the export-licensing dimension – or vice versa – which leaves half the criminal analysis undone.

The practical starting point is to map the act or omission against each relevant instrument. Was the item subject to an export licence requirement under the Export Control Order? Did a payment, transfer, or making available of funds involve a designated person? Could a trade restriction under the applicable country regime have been triggered independently? Each question has its own answer pathway.

Step 2 – Apply the criminal threshold test

Under UK law, the criminal threshold for both export-control and financial-sanctions offences turns principally on knowledge and intent, though the precise mental-element standard varies by provision.

For financial-sanctions purposes, SAMLA provides that a person commits a criminal offence if they knowingly or intentionally breach a prohibition. A purely accidental breach – one caused by a screening failure with no element of knowledge – is more likely to be addressed through OFSI's civil monetary penalty powers than through criminal referral. That said, OFSI's enforcement guidance makes clear that it considers the degree of culpability, the systems in place, and whether the person had reason to know of the prohibition.

For export-control offences, the criminal provisions cover conduct where there is knowledge that the item requires a licence and that licence has not been obtained. Recklessness as to whether a licence is needed has been treated as sufficient in some circumstances. This is a point of real practical significance: a business that fails to classify its goods properly and ships without a licence cannot always rely on ignorance as a shield.

The assessment must therefore establish: what did the relevant individuals know about the item, the end-user, and the licence requirement at the time of the conduct? What did the organisation's compliance systems tell them, or fail to tell them? Were there red flags that were not escalated? These questions map directly to the statutory mental elements. They also shape any eventual penalty defence or voluntary self-disclosure ("VSD") case.

Step 3 – Scope the facts and build the exposure timeline

Once the statutory basis and the criminal threshold are identified, the exposure assessment requires a disciplined reconstruction of what happened, in sequence, from first contact with the counterparty or transaction to the point at which the potential breach was identified.

The timeline should record every decision point: when the counterparty was screened, what the result was, whether the item was classified, whether a licence application was initiated, what internal approvals were obtained, and who was aware of what at each stage. This is not a paper exercise. It is the foundation for every subsequent conversation with regulators, and it is the basis on which any VSD to OFSI or ECJU would be constructed.

In a recent matter, a specialist manufacturer in the technology sector identified that several historical shipments had been made under an incorrect commodity classification, which meant that export licences had not been applied for items that required them. We assisted the client in reconstructing the full shipment history, mapping the classification error to its source in the compliance programme, and assessing the degree to which individuals with approval authority had been on notice. That analysis determined the VSD strategy and the framing of the penalty representations. The matter was resolved through the civil enforcement pathway without criminal referral.

Record-keeping is a critical parallel obligation. Businesses subject to UK export-control requirements must maintain documentation supporting each export. OFSI similarly expects that records of screening and due diligence decisions are retained. Gaps in records do not create a presumption of guilt, but they significantly complicate any defence narrative.

Step 4 – Compare the criminal risk profile across regimes

Criminal exposure in export-control cases under OFSI and ECJU cannot be assessed in isolation when a business has cross-border operations. The same transaction may engage the extraterritorial reach of US export controls (principally through the Export Administration Regulations administered by BIS) and EU dual-use regulations, each with their own criminal or quasi-criminal enforcement mechanisms.

Under the US Export Administration Regulations, BIS administers a Commerce Control List ("CCL") and enforces licence requirements with both civil and criminal penalties. Critically, the EAR applies extraterritorially in specific circumstances – including to de minimis US-origin content incorporated into foreign-made items and to items produced using certain US technology or software. A UK exporter that ships a product incorporating US-origin controlled components must satisfy itself that EAR requirements are met, in addition to UK licence requirements. Criminal exposure under the EAR is assessed by the US Department of Justice. OFSI plays no role there.

In the EU, dual-use controls sit within a directly applicable EU regulation. Post-Brexit, UK and EU controls have diverged in some product classifications and end-user provisions. A business exporting from both the UK and an EU member state faces two sets of classification obligations that are similar but not identical. Where they diverge, the stricter prohibition governs the exporter's position in each jurisdiction independently.

How does OFSI differ from OFAC on the criminal question? OFAC's enforcement is primarily civil, with criminal referrals made to DOJ for the most serious cases involving wilful conduct. OFSI similarly distinguishes between civil and criminal pathways, with criminal prosecution reserved for knowing or intentional breach. The practical difference is that OFAC operates a significantly larger civil penalty programme and has established detailed public guidance on the factors it weighs in penalty determinations. OFSI's published enforcement guidance is less granular on the criminal referral threshold, which makes early legal advice more important in a UK context when the facts suggest knowledge or intent.

For businesses with operations in Singapore, Japan, or the UAE, the picture adds further layers. Singapore's Strategic Goods (Control) Act provides criminal penalties for unlicensed exports of controlled items. Japan's Foreign Exchange and Foreign Trade Act and the UAE's export-control and sanctions regime each carry their own criminal provisions with distinct mental-element tests. A cross-border exposure assessment must address each regime on its own terms and identify which jurisdiction poses the highest criminal risk, since enforcement action in one does not preclude parallel proceedings in another.

Step 5 – Identify the key risk flags

Certain facts, when present, elevate the probability that a civil enforcement case becomes a criminal referral. Recognising these flags early allows counsel to structure the response accordingly.

The most significant risk flags in our practice are:

  • Prior warnings or guidance – if the business received compliance guidance, a warning letter, or a previous civil penalty from OFSI or ECJU, and the breach occurred after that communication, the argument that the conduct was unknowing becomes very difficult to sustain.
  • Documentary evidence of intent – internal emails, messaging, or records showing that individuals were aware of a restriction and chose to proceed are directly probative of the criminal mental element.
  • Structured transactions – where a series of transactions appears designed to stay below a reporting threshold, or where intermediate parties are interposed between the UK exporter and a restricted end-user, this pattern raises the question of whether the structure was deliberate. Note that explaining or structuring transactions for legitimate commercial reasons is not inherently problematic, but the compliance logic must be documented contemporaneously.
  • Repeated or systematic breaches – a one-off classification error presents differently from a pattern of shipments over multiple years without licence applications.
  • Failure to report a known breach – OFSI expects regulated firms to report known or suspected breaches. Delay or non-reporting, once a breach is identified internally, is a separate adverse factor in enforcement.

Is every breach with one or more of these flags destined for criminal prosecution? No. But the presence of any flag should shift the internal response from a routine compliance review to an engagement involving sanctions counsel from the outset.

Step 6 – Decide on voluntary self-disclosure and the response strategy

Once the exposure has been scoped, the central decision is whether and how to approach OFSI or ECJU proactively. A VSD (voluntary self-disclosure to a regulator) is not an automatic mitigation, but it is the most powerful tool available to a business that has identified a potential breach before a regulator does.

OFSI's enforcement guidance acknowledges VSD as a factor that weighs in favour of reduced penalties. The timing and quality of disclosure both matter. A VSD that is complete, accurate, and submitted promptly – before the regulator has initiated its own inquiry – carries significantly more weight than a disclosure made after a regulator's enquiry letter has arrived.

The content of a VSD must be considered carefully. A disclosure that over-states the scope of the breach, or that includes inaccurate characterisations of the mental element, can complicate the business's position rather than improve it. We regularly advise clients that the first step before submitting any VSD is to complete the exposure analysis described in this guide, so that the disclosure is accurate, bounded, and supported by the full factual record.

The position above covers the standard case. Your facts – the item, the end-user, the route, the internal records, and the specific regime in play – change the analysis materially. For a confidential review of a potential breach, contact Calder & Vance at info@caldervance.com.

Where the exposure is primarily civil, the VSD feeds into penalty representations and the enforcement process. Where criminal indicators are present, the VSD strategy must be designed in the knowledge that anything disclosed could be used in a criminal prosecution, and privilege considerations become central to the engagement.

A common myth: civil enforcement always precedes criminal referral

One assumption we encounter frequently is that UK export-control and sanctions enforcement follows a fixed sequence: civil first, criminal only after civil resolution. That assumption is inaccurate. OFSI and ECJU are not bound to exhaust civil proceedings before making a criminal referral to prosecutors. A parallel investigation – civil and criminal simultaneously – is possible where the facts suggest a serious knowing breach.

The better assumption is that any breach with knowledge or intent indicators can attract both pathways at once. The practical implication is that a business's internal response from the moment a potential breach is identified should be designed with both tracks in mind. In our cross-border practice, we structure the initial internal review so that it is defensible in both a civil penalty defence and, if necessary, in a criminal investigation context.

If a transaction has already been flagged or an enquiry letter has arrived, early review with sanctions counsel preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss your position.

When to involve sanctions counsel

The short answer is: earlier than most businesses do. The assessment described in this guide is demanding and requires a combination of knowledge of UK financial-sanctions law, export-control law, and the enforcement practices of OFSI and ECJU. It also requires a cross-regime view when US or EU controls are simultaneously engaged.

Specific triggers that should prompt immediate instruction of sanctions counsel include:

  • Identification of a shipment made without a required export licence, particularly where the item is a controlled dual-use good
  • A payment or transaction involving a counterparty that appears on a sanctions list, or that is owned or controlled by a listed person
  • Receipt of an enquiry letter from OFSI or ECJU
  • A regulator-initiated visit, information request, or notice
  • A voluntary internal audit that reveals a pattern of potential breaches across multiple transactions or time periods
  • A notification from a bank or financial institution that a payment has been blocked or a screening hit has been generated

Delay in any of these circumstances is the most consistent source of avoidable harm in enforcement cases. The window for a well-framed VSD, for preserving legally privileged communications, and for securing the factual record narrows the moment a regulator begins its own inquiry.

Related practices

Frequently asked questions

What are the steps to assess criminal export-control exposure under OFSI?
Assessing criminal exposure requires six sequential steps: identify the statutory basis engaged (SAMLA for financial sanctions, the Export Control Order for trade controls); apply the relevant criminal threshold test (knowledge and intent); reconstruct the facts and build an exposure timeline; compare the risk profile across any other regimes simultaneously engaged; identify the specific risk flags that elevate criminal probability; and then decide on the VSD strategy and response. Each step feeds the next. Beginning at step five without completing the earlier steps produces an incomplete and unreliable assessment.
What is the most common mistake in criminal exposure in export-control cases?
The most common mistake is treating a potential breach as a single-regime compliance issue when multiple regimes are engaged. A UK exporter that identifies a potential OFSI financial-sanctions breach but fails to assess the parallel ECJU export-licensing position, the BIS extraterritorial reach, and any EU dual-use obligations has assessed only part of the exposure. The second most common mistake is delaying the internal review and the VSD decision while waiting for more information – which often destroys the window for an effective early disclosure.
How does OFSI differ from other regimes here?
OFSI's criminal enforcement pathway under SAMLA is reserved for knowing or intentional breaches; civil monetary penalties cover the broader range of conduct. Compared with OFAC, OFSI publishes less granular guidance on the precise factors that trigger a criminal referral, making early legal review more important in a UK context. Compared with EU dual-use enforcement, which is administered by member-state authorities under EU regulation, OFSI's remit is limited to financial sanctions, while export-control criminal liability sits separately with ECJU. This division of authority across UK regulators is itself a source of risk for businesses that assume a single enforcement point.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.