A UK university research team collaborates with a visiting academic whose national ties trigger a screening alert. A London-based defence contractor transfers design drawings to an overseas subsidiary. A fintech company gives a foreign national remote access to software with encryption functionality. In each case, the same question arises: has technology been exported in a way that engages UK financial-sanctions or export-control obligations – and if so, what must happen next?
Deemed exports and technology transfer under OFSI concerns the transmission of controlled technical knowledge, software, or design data to a person subject to UK financial-sanctions or export-control restrictions – regardless of whether any physical goods cross a border. As of April 2026, OFSI administers financial-sanctions obligations under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic regulations, while the Export Control Joint Unit ("ECJU") governs licence requirements for physical and intangible exports under the Export Control Order. The two regimes operate in parallel, and both can bite on the same technology-transfer transaction.
This guide explains the governing tests, the procedural steps a compliance team should follow, how the UK position compares with the US and EU approaches, and when to involve specialist counsel.
What is a deemed export, and why does it matter under UK law?
A deemed export occurs when controlled technology, software, or technical data is made available to a foreign national inside the UK – or transferred electronically, verbally, or visually to a person outside it – without any physical shipment of goods. The technology has been "exported" in substance, and the legal obligations attach accordingly.
Under the Export Control Order, a licence may be required for the intangible transfer of controlled technology to specified destinations or persons, irrespective of the physical location of the item. The controls apply to software, source code, technical drawings, manufacturing know-how, and training that reveals controlled parameters. The question of whether a licence is required turns on the Export Control Classification Number (ECCN – the US term; the UK equivalent is the goods category under the relevant control list entry), the destination, the end-use, and the end-user.
OFSI adds a separate and concurrent layer. Where the recipient of the technology is a designated person under a UK sanctions regime, or is an entity owned or controlled (the UK test for whether a non-listed company is caught through a listed person) by a designated person, making technology available – even within the UK, even digitally – may constitute providing financial services or dealing with frozen assets, depending on how the transaction is characterised. These two bodies of law do not map neatly onto each other. Exporters who treat OFSI compliance and export-licensing compliance as distinct workstreams risk gaps in coverage.
In our practice, the most frequent gap we encounter is a company that has obtained an ECJU licence for a technology transfer but has not run an OFSI screen on the end-user, or vice versa. Both checks are required, and both must be completed before the transfer.
How does the UK deemed-export test compare with the US and EU positions?
The UK and US approaches share the concept of intangible technology transfer, but differ in structure, scope, and the threshold that triggers a licence requirement. Understanding both is essential for any business operating across the Atlantic.
Under the Export Administration Regulations (the EAR), the US Bureau of Industry and Security ("BIS") applies a formal deemed-export rule: the release of technology or source code to a foreign national in the United States is treated as an export to that person's home country. The rule is expressly tied to the Export Control Classification Number of the technology and to the nationality of the recipient. Licence requirements flow from country-destination controls on the CCL. OFAC operates separately: a transfer to a person on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) triggers asset-freeze prohibitions regardless of export-control classification.
The UK position under the Export Control Order follows a similar logic for intangible transfers, but the licensing architecture differs, and OFSI's financial-sanctions prohibitions are applied under SAMLA-based thematic regulations rather than a single omnibus statute. One practical divergence: the US deemed-export rule explicitly addresses the nationality of the recipient as the jurisdictional trigger. The UK rules focus more on destination and end-use, though the OFSI overlay addresses the person directly. This distinction matters when a business employs nationals of a sanctioned country in the UK: a US-origin technology may require a BIS licence for internal access by that employee, while the UK position turns more directly on whether that person is themselves designated or is controlled by a designated person.
The EU dual-use regulation applies to intangible transfers originating from EU member states. It similarly covers software and technology transferred by electronic means, by fax, or by telephone. Post-Brexit, the UK operates its own export-control regime and the EU rules do not apply to UK-origin transfers – though a UK exporter transferring through an EU intermediary may trigger EU controls in addition to UK ones. The stricter prohibition governs in any multi-regime transaction: if one regime requires a licence and another does not, the licence is needed.
The position above covers the standard comparative case. Your facts – the nationality of the recipient, the classification of the technology, the jurisdiction of the transferor, and the sanctions programme in play – change the analysis materially.
For a cross-regime assessment of your specific technology-transfer exposure, contact Calder & Vance at info@caldervance.com.
Step 1: Classify the technology and identify the control list entry
The first step in managing deemed-export risk is to determine the technical classification of the item, software, or knowledge to be transferred, and to map it against the UK Strategic Export Control Lists (the control list maintained by the Department for Business and Trade and administered by ECJU).
Classification requires a technical assessment. The relevant parameters depend on the category of the item: for cryptographic software, the key lengths and algorithms matter; for materials, the composition and performance thresholds are determinative; for manufacturing technology, the precision specifications are central. This is not a legal exercise alone – it requires the input of the engineer or scientist responsible for the technology, working alongside the compliance team.
Common errors at this stage include:
- Relying on a product description or commercial name rather than the technical specification;
- Assuming that because finished goods are not controlled, the underlying technology is also uncontrolled – the technology note in the control lists frequently applies to knowledge that enables production of goods, even where the goods themselves are not listed;
- Failing to check whether de minimis incorporation of US-origin content brings BIS jurisdiction into play on the same transfer.
Once a control list entry is identified, the business can assess whether any available licence exception applies, whether a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transfer) is required, or whether an Open General Export Licence (a standing authorisation for a defined category of transfers, equivalent in function to a US general licence) covers the transaction.
Step 2: Screen the recipient against OFSI designations and apply the ownership and control test
The second step is to screen the intended recipient – and, critically, the full ownership and control chain behind that recipient – against the UK Consolidated List of designated persons and any relevant thematic sanctions regulations.
OFSI's ownership and control test asks whether the recipient is owned or controlled by a designated person, even if the recipient itself does not appear on any list. "Owned" means direct or indirect ownership of more than fifty percent of the shares or voting rights. "Controlled" is broader: it covers a designated person's ability to direct the management or policies of an entity, whether through contractual rights, board composition, or other means. The control limb has no bright-line percentage threshold, which makes it more difficult to apply and more likely to be under-applied in practice.
A targeted financial-sanctions prohibition under OFSI does not require that a transfer generates proceeds or constitutes a financial service in the obvious sense. Making an asset – including intangible technical data – available to a designated person, or to an entity owned or controlled by one, can constitute dealing in frozen assets or making funds available. The analysis is fact-specific and turns on the characterisation of the transfer under the applicable thematic regulation.
In our experience, the control limb of the OFSI test is where businesses are most exposed. A counterparty that is majority-owned by a non-designated foreign state entity may still be controlled by a designated individual who holds a board seat or contractual veto. That individual's designation does not appear in any direct screening result on the counterparty. Mapping the governance structure – not only the shareholding table – is essential.
If a transaction has already been flagged, or a filing has already been refused, an early review can preserve options that narrow with time. Contact us at info@caldervance.com.
Step 3: Assess the available licensing routes under OFSI and ECJU
Where either an export-control licence or an OFSI licence is required – or both – the business must assess the available routes before proceeding.
Under the Export Control Order, ECJU grants specific licences on a case-by-case basis. The application requires a precise description of the technology, the end-user undertaking, details of the end-use, and supporting documentation from the recipient. Processing times vary with the complexity of the application and the sensitivity of the technology; applicants should plan for a process that may extend across several months for the most sensitive categories. Open General Export Licences, where applicable, are self-executing: the business registers its use and keeps records, but does not wait for regulatory approval.
OFSI's specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) is available where the applicable thematic regulation provides a licensing ground. The grounds differ between sanctions programmes: some provide for humanitarian, diplomatic, or prior-contractual grounds; others are narrower. There is no single universal licensing ground across all UK sanctions programmes. A business assessing whether a licence is available must identify the precise thematic regulation and confirm which licensing grounds it contains.
OFSI and ECJU licensing are independent processes. A specific licence from one authority does not substitute for a licence from the other. Where both are required, both applications must be made, and the more restrictive outcome governs – if OFSI grants a licence but ECJU refuses, the transfer cannot proceed.
Preparation matters. Licence applications that arrive at a regulator with incomplete documentation, ambiguous end-use statements, or inconsistencies between the technical description and the control list entry take longer to process and are more likely to require supplementary information requests. We regularly advise on the preparation and submission of dual-track licensing applications where both authorities are in play.
What are the key risk flags in a deemed-export programme?
Several recurring patterns generate disproportionate risk in deemed-export programmes. Identifying them before a transfer occurs is significantly less costly than addressing them after an enforcement inquiry begins.
Remote access to controlled systems. Cloud platforms, remote-desktop tools, and shared development environments can all constitute a technology transfer if a foreign national – whether employed by the business or an external contractor – gains access to controlled software or technical data through them. Access controls that were designed for data-security purposes may not map onto the categories that define a controlled technology transfer.
Academic and research collaborations. Universities and research institutions face particular exposure. Visiting academics, jointly supervised PhD students, and grant-funded partnerships with overseas institutions all create pathways for intangible technology transfer. The "fundamental research" exemption that exists in the US EAR has a partial analogue in the UK rules, but its scope is not identical and should not be assumed to cover a collaboration simply because the research is intended for open publication.
Corporate group transfers. A parent company transferring technology to a subsidiary or affiliate in a third country is still conducting a transfer for licensing purposes. Intra-group transfers do not benefit from a general exemption. Where the subsidiary is located in a destination subject to controls, or where any entity in the group ownership chain is linked to a designated person, the transfer requires the same analysis as an arm's-length transaction.
Training and technical assistance. Providing training that reveals controlled technical parameters – whether in person, by video conference, or in written form – is itself a technology transfer. The medium does not affect the classification of the disclosure.
Have you mapped all the channels through which your technology, software, or know-how reaches foreign nationals? Most compliance audits of technology-intensive businesses reveal at least one unreviewed channel.
What is the common myth about deemed exports under OFSI, and why is it wrong?
A persistent misconception is that OFSI's remit is limited to financial transactions – wire transfers, payment instructions, trade-finance instruments – and that technology or knowledge transfers fall entirely outside its scope. This view is incorrect, and acting on it can produce a serious compliance gap.
OFSI's prohibitions are framed around making funds or economic resources available to a designated person, or dealing with the frozen assets of a designated person. "Economic resources" is a broad concept in UK financial-sanctions law. Technical data, software licences, know-how, and other intangible assets that can be used to obtain funds, goods, or services are economic resources. A technology transfer to a designated person – or to an entity owned or controlled by one – may therefore constitute making an economic resource available, which is a prohibited act under the relevant thematic regulations.
The consequences of getting this wrong can be significant. OFSI has the power to impose a civil monetary penalty without a criminal conviction; it can also refer matters for criminal prosecution. The reputational and commercial consequences of an enforcement inquiry are entirely separate from any penalty. Where a business identifies a potential breach, the question of whether and how to report it to OFSI – and whether a voluntary self-disclosure (VSD: a proactive report to the regulator identifying a potential violation) is appropriate – is a material decision that affects the enforcement outcome.
We have acted for clients who initially concluded that their technology-transfer arrangements had no OFSI dimension, only to find – on a closer analysis prompted by a transaction or an audit – that the arrangements engaged the financial-sanctions rules. Early review is consistently less costly than late remediation.
Related practices
- Deemed exports under BIS / EAR – US export-control analysis for technology transfers, classifications, and BIS licence applications
- Deemed-export risk: advanced OFSI issues – deeper analysis of OFSI licensing grounds, voluntary disclosure, and enforcement posture
- Deemed exports under Singapore law – the strategic goods control regime and technology-transfer obligations in Singapore