Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · Singapore

How to manage deemed-export risk under Singapore

A regional headquarters in Singapore engages a foreign national – an engineer, a business-development manager, a contracted researcher. The individual is granted access to product specifications, manufacturing tolerances, or source code. No goods leave the building. Yet, under the applicable Singapore export-control rules, a transfer of controlled technology may just have occurred. Has your compliance programme accounted for that?

A deemed export (the regulatory concept under which access to controlled technology by a foreign national is treated as an export to that person's country of origin) is a live compliance obligation under the Singapore strategic goods regime. The Strategic Goods (Control) Act and the regulations made under it govern the transfer of controlled goods, software, and technology – including intangible transfers. Singapore Customs administers the regime. As of April 2026, firms operating in Singapore's technology and manufacturing sectors that employ foreign nationals or share controlled technical data with offshore parties face material deemed-export exposure that a standard trade-compliance screen will not catch.

This guide walks through the governing framework, how to classify controlled technology, the deemed-export trigger and its cross-regime comparators, the practical steps for managing ongoing risk, common programme failures, and when to bring in specialist counsel.

Step 1: Understand the governing regime and who administers it

The Singapore strategic goods regime is administered by Singapore Customs under the Strategic Goods (Control) Act – referred to here as the SGCA – and its subsidiary regulations, which implement Singapore's obligations as a participant in the major multilateral export-control arrangements including the Wassenaar Arrangement, the Nuclear Suppliers Group, the Australia Group, and the Missile Technology Control Regime.

Singapore Customs holds authority over the full lifecycle of a controlled-goods or technology transaction: classification, permit issuance, compliance audits, and enforcement. The regime covers goods, software, and technology on the Singapore Strategic Goods Control List. Critically, that list captures not only physical commodities but also the technical data and know-how that describes how controlled goods work, are produced, repaired, or operated.

The SGCA expressly extends to intangible transfers of technology. That extension is the foundation of the deemed-export concept in Singapore. If a person shares controlled technical data with a foreign national – whether orally in a meeting room, electronically by file transfer, or passively by granting system access – that sharing is potentially a regulated transfer requiring either a permit or an applicable exception. Singapore Customs publishes guidance on the scope of this obligation, and practitioners advising on Singapore matters note that the intangible-transfer provisions are applied actively, not treated as a residual backstop.

One operational point that compliance teams sometimes overlook: the nationality of the recipient, not the recipient's physical location at the point of access, is the reference for assessing which country a deemed export is directed to. A French national seconded to Singapore who accesses controlled technical data from a Singapore server has, in principle, received a transfer deemed directed to France. This matters for permit eligibility and for any cross-regime analysis.

Step 2: Classify the technology before you assess the transfer

Classification is the gatekeeping step. Until you know whether the technology in question is controlled under the Singapore Strategic Goods Control List, you cannot assess your permit obligations, your exception eligibility, or your cross-border exposure.

The Singapore Strategic Goods Control List is aligned with the multilateral control lists. For technology, the relevant parameters are the technical specifications of the controlled item to which the technology relates (the goods, software, or system it describes or enables), and the categories and technical parameters set out in the applicable multilateral arrangement. Technology is generally controlled when it is "required for" the development, production, or use of a controlled item – a formulation that tracks the Wassenaar Arrangement's technology notes.

In our experience, classification errors concentrate in two areas. First, firms apply goods-classification logic to technology and miss technical-data items that have no direct hardware equivalent. Second, firms treat general-purpose know-how as uncontrolled when it in fact provides a direct capability path to a controlled item's performance envelope. A dual-use engineering business needs a structured classification process that distinguishes public-domain information (which falls outside control) from controlled technical data, and that documents the analysis at the item level.

Firms that are also subject to US Export Administration Regulations (EAR – the US Commerce Department's export-control rules under the Bureau of Industry and Security) will already hold Export Control Classification Numbers (ECCNs) for their controlled items. Singapore's list broadly tracks Wassenaar, so a US ECCN classification is a useful starting point for Singapore purposes – but it is not determinative. There are coverage differences at the margin, and an EAR99 item (an item not on the US Commerce Control List) is not automatically uncontrolled under the SGCA. Each regime must be assessed on its own list.

Step 3: Apply the deemed-export trigger to your workforce and data flows

The deemed-export trigger fires when a foreign national gains access to controlled technology and that access constitutes a regulated transfer under the SGCA. Mapping this trigger across a real workforce and data environment requires three questions answered in sequence.

First: who is accessing what? This requires an inventory of foreign nationals – employees, contractors, interns, secondees, visitors – and a mapping of which controlled technical data each of them can access in the ordinary course of their role. "Access" includes network access to controlled information, not only documents physically handed over. If your HR system and your access-control architecture are not integrated into your export-compliance programme, this inventory is probably incomplete.

Second: is the technology they can access controlled under the SGCA? This question links back to Step 2. The classification work done at the item level must be mapped to the data environment so that access rights can be calibrated to control status.

Third: is a permit required, or does an exception apply? Singapore Customs provides for permits (both individual and strategic trade authorisations for qualifying entities) and for specific exceptions. The key exceptions to analyse for deemed exports are the knowledge exception (for information in the public domain) and exclusions for technology that is not required for the controlled use. Counsel's review of exception eligibility is important here: exception conditions are drafted narrowly, and applying them incorrectly is itself a compliance failure.

A practical observation from our cross-border practice: firms that rely on "the foreign national works for us" as an implied licence are exposed. Employment does not create an export-control authorisation. Nationality, role, data-access level, and the classification status of the information accessed are the operative facts, not the employment relationship.

How does Singapore's deemed-export approach compare with the US and EU positions?

A comparison across regimes is essential for any business operating internationally, because the US regime is the most operationally demanding point of reference and the EU position has historically diverged in notable ways.

Under the EAR, the US deemed export rule applies when a foreign national in the United States is given access to controlled technology or source code. The nationality test (citizenship or permanent residency) and the licence requirements under the EAR are well-established and require active screening of foreign-national employees against the relevant control lists and destination restrictions. BIS has a history of enforcement in this area. For a business that is already running a US deemed-export programme under the EAR, the Singapore programme will have structural similarities – classification, access mapping, permit or exception determination – but the underlying lists and the specific exception conditions are different, and conflating them is a known error.

The EU position is different in character. Historically, EU dual-use rules focused on tangible exports and, to a varying extent, cross-border intangible transfers to third countries. The revised EU dual-use regulation that has applied since 2021 expanded controls on intangible transfers, including to third countries via electronic means. However, the EU position on deemed exports in the domestic context (i.e., access by a third-country national within the EU) has remained less prescriptive than the US model. Member State implementation also varies. For a business with a Singapore hub and EU affiliates sharing technology, the Singapore intangible-transfer obligation and the EU's cross-border intangible-transfer controls may both be engaged simultaneously, requiring a joined-up analysis. We regularly advise clients who discover mid-transaction that their Singapore and EU positions have developed independently and are inconsistent.

Under the UK regime, the Export Control Order and ECJU guidance address intangible transfers, including technology provided by electronic means to persons outside the UK. For UK-headquartered businesses with Singapore subsidiaries, the question of who controls the technology and who has authorised access may require both a Singapore permit analysis and a UK export-control review for the same data set. These are separate obligations under separate authority; the Singapore permit does not satisfy the UK requirement.

The practical implication of these divergences is that a multinational cannot run a single deemed-export programme and tick all boxes. Each regime requires its own classification, permit, and exception determination. The cross-regime point – whether a US EAR licence exception, a Singapore SGCA permit, and a UK export-control authorisation are all in place for a given technology-access scenario – is a transaction-specific question that benefits from coordinated counsel.

What are the practical steps for an ongoing deemed-export compliance programme?

An ongoing deemed-export compliance programme under the Singapore regime has five operational pillars that must work in combination. Missing any one of them creates gaps that accumulate into material violations.

Pillar 1 – Technology inventory and classification register. Maintain a live register of all controlled technology assets: which items are controlled, at what classification level, and which data repositories or systems hold them. The register must be updated when new products, software versions, or technical datasets are created or acquired.

Pillar 2 – Foreign-national tracking. Integrate HR onboarding, contractor engagement, and visitor management into the compliance programme. For each foreign national, record nationality, role, and the controlled technical data to which their role requires access. This tracking must extend to remote access and to secondees or joint-venture partners who may access data via shared platforms.

Pillar 3 – Access-control architecture aligned to classification. Information-technology and information-security controls must reflect the export-classification status of the data they protect. Controlled technology should be ring-fenced behind access controls that are calibrated to permit status and that generate an audit trail. An access-control system that restricts data by business sensitivity but not by export-control classification is not a compliant system for these purposes.

Pillar 4 – Permit and exception management. Maintain a current schedule of permits and authorisations. Where exceptions apply, document the exception analysis at the item and recipient level. Permits issued by Singapore Customs may carry conditions and validity periods; a lapsed permit is a gap in authorisation. If a strategic trade authorisation applies, the conditions attached to that scheme must be maintained and audited.

Pillar 5 – Training, testing, and record-keeping. Personnel who have access to controlled technology – not only the compliance team – must be trained on the deemed-export obligation and on what to do when access changes or when a new foreign national joins the team. Records of training, classification decisions, permit applications, and access logs should be retained for the period required by applicable Singapore Customs record-keeping obligations. In our practice, audit readiness – the ability to produce records promptly to Singapore Customs on request – is a direct indicator of programme quality.

What are the most common risk flags and compliance failures?

The most common compliance failure in Singapore deemed-export management is treating the obligation as a one-time set-up task rather than an ongoing programme. Organisations that classified their technology correctly at programme launch but did not build a process to re-classify when products evolved, or to update access mapping when the workforce changed, are routinely non-compliant within twelve to eighteen months of their initial effort.

A second persistent risk flag is the assumption that a US EAR licence or a US general licence satisfies the Singapore obligation. It does not. A US authorisation governs US-origin technology under the EAR. Singapore's controls are an independent set of obligations. Holding a US authorisation may reduce the US-law exposure for the same technology transfer, but it creates no authorisation under the SGCA. We have acted for businesses where the US compliance team believed the position was covered and the Singapore entity was entirely without a permit structure.

Third: verbal or informal technology transfers. Presentations at technical conferences, demo sessions with potential customers, and technical briefings to joint-venture partners all carry deemed-export risk if controlled technology is disclosed. A compliance programme that controls document access but does not reach informal knowledge-transfer events – trade shows, academic collaborations, factory visits – is incomplete.

Fourth: the contractor and supply-chain gap. Independent contractors, outsourced engineers, and embedded personnel from partner firms access the same systems as direct employees. If these categories of worker are not within scope of the deemed-export access-mapping programme, they represent an uncontrolled transfer channel.

A common misconception worth addressing directly: some businesses believe that because Singapore is a free-trade hub and an open economy, its strategic goods controls are lightly enforced. That inference is wrong as a matter of law and, increasingly, as a matter of practice. Singapore Customs has a well-resourced compliance function and conducts audits. Singapore is also a participant in international export-control co-operation arrangements, which means information on potential violations can flow across jurisdictions. The openness of Singapore's economy is a reason its strategic goods regime is taken seriously, not a reason to take it lightly.

When should you involve specialist export-control counsel?

Specialist counsel adds most value at four defined points in the programme lifecycle: initial programme design, when a classification question is genuinely borderline, when a permit application must be submitted to Singapore Customs, and when an apparent violation has come to light.

At programme design stage, counsel can map the full technology inventory against the Singapore Strategic Goods Control List, design the access-control architecture to comply with both the SGCA and any parallel US or EU obligations, and identify permit requirements before any transfers occur. Acting before transfers take place is categorically easier than remedying non-compliant transfers after the fact.

Borderline classification questions arise when the technology straddles the line between a controlled application and general-purpose use, or when the "required for" formulation of the technology note does not map cleanly onto the item being assessed. A controlled-technology classification that is wrong in either direction – over-restrictive or under-restrictive – creates operational or compliance cost. Counsel with experience across the Singapore and US regimes can provide a comparative classification opinion that gives the business a defensible position.

When a permit application is required, the quality of the submission matters. Singapore Customs will review the application on its merits, and a poorly structured submission that fails to address the authority's assessment criteria delays or jeopardises the permit. We assess eligibility, prepare and submit the permit application, and manage Singapore Customs' queries through to a decision.

If an apparent deemed-export violation has already occurred – because a foreign national accessed controlled technology without an applicable permit or exception – the priority is to scope the exposure, assess whether a voluntary disclosure is appropriate, and preserve the options that remain available. Early involvement of counsel at this stage limits the risk of compounding the position through further unauthorised transfers or through disclosure decisions made without a complete legal analysis.

The bridge between this section and the next step is simple: if you are unsure whether your programme covers the deemed-export obligation fully, or if a transaction or workforce change has raised a question you cannot resolve internally, the time to seek a review is before the transfer, not after. If an issue has already arisen, contact us early.

Related practices

Frequently asked questions

What are the steps to manage deemed-export risk under Singapore?
Managing deemed-export risk under Singapore's strategic goods regime requires five sequential steps: (1) confirm whether the technology in question is on the Singapore Strategic Goods Control List; (2) identify all foreign nationals with access to that technology and map their nationality; (3) determine whether a Singapore Customs permit is required or an exception applies; (4) implement access controls aligned to the classification status of the technology; and (5) maintain records and audit readiness for Singapore Customs inspection. Cross-regime alignment with any applicable US, UK, or EU obligations should run in parallel.
What is the most common mistake in deemed exports and technology transfer?
The most common mistake is treating a US EAR authorisation or a one-time classification exercise as a substitute for an ongoing Singapore-specific programme. A US licence does not satisfy the SGCA obligation. Equally, a classification exercise that is not refreshed as products and personnel change becomes unreliable quickly. Compliance teams that conflate the two regimes, or that treat deemed-export compliance as a set-and-forget task, carry unrecognised ongoing exposure. A second common error is failing to include contractors and secondees within the access-mapping programme.
How does Singapore differ from other regimes here?
Singapore's strategic goods regime aligns closely with the multilateral export-control arrangements and expressly covers intangible technology transfers, including access by foreign nationals within Singapore. Compared with the US EAR deemed-export rule, Singapore's provisions have a similar conceptual structure but rest on a different list, different permit pathways, and different exception conditions – making them a separate compliance obligation, not a parallel one. Compared with EU dual-use rules, Singapore's intangible-transfer controls are more explicitly operationalised. A business subject to more than one of these regimes must run separate analyses for each.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.