Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · cross-border

End-use and end-user controls across regimes: procedure and pitfalls

A trading house ships temperature-control units to a distributor in a third market. The end certificate names a civilian integrator. Six months later, those units appear in a system with a clear military application. Customs investigators call. The exporter had a clean screening record, no listed counterparties, and a filed end-use certificate. What went wrong?

End-use and end-user controls impose obligations that reach beyond the moment of export. Under the US Export Administration Regulations, the UK Export Control Order, and the EU dual-use rules, an exporter must verify not only who receives the goods but what they will do with them – and must maintain evidence of that verification for a defined period. A failed end-use check can constitute a strict-liability violation even where the exporter had no knowledge of the diversion.

This guide sets out the procedure for applying end-use and end-user controls across the principal regimes, maps where those regimes diverge, and identifies the pitfalls that most frequently produce enforcement exposure.

Step 1: Classify the item and identify which regime governs

Before any end-use or end-user check begins, the exporter must know which regulatory regime bites – because the applicable regime determines which list applies, which certificate is required, and which authority will investigate a breach.

In the United States, the Export Administration Regulations (the EAR) govern dual-use and certain commercial items exported from US territory and, importantly, items of US origin or incorporating US-origin content above a defined threshold wherever they sit in the world. The classification turns on the Export Control Classification Number (ECCN – a code on the US Commerce Control List that identifies what controls apply to an item). Items not on the Commerce Control List carry the designation EAR99 and are subject to a lighter but non-zero control regime.

In the United Kingdom, the Export Control Order covers dual-use and military items. The ECJU administers licensing. Classification follows the UK dual-use list, which mirrors the international Wassenaar, Australia Group, MTCR, and NSG control lists. For UK exporters, Brexit means the EU regime no longer governs UK-origin goods; a separate UK licence is required.

The EU dual-use rules – set by the relevant Council Regulation on controls for the export, brokering, technical assistance, transit, and transfer of dual-use items – apply to exports from EU member-state territory. National competent authorities in each member state administer them, with the European Commission coordinating the catch-all mechanism. As of April 2026, the EU regime expressly includes human-rights end-use considerations alongside the more traditional WMD and military end-uses.

Where an item has both US-origin components and an EU-based exporter, both regimes can apply simultaneously. Compliance counsel must assess both. That overlap is where cross-border exposure concentrates.

Step 2: Screen the end-user against all relevant lists

End-user screening is a discrete step that sits after classification and before order acceptance. It is not a one-time event: the screen must be repeated at shipment, and ideally at any material change in the transaction structure.

Under the EAR, the primary lists are the Entity List (BIS's list of persons subject to licence requirements), the Denied Persons List, and the Unverified List. A hit on the Entity List typically triggers a licence requirement that would otherwise not apply, or an outright prohibition depending on the listed party's entry. The SDN List (OFAC's list of Specially Designated Nationals and blocked persons) is a parallel and separate obligation – a party can be clear of BIS lists but blocked under OFAC, or vice versa. In our practice, exporters who run only one of the two checks regularly miss the other.

In the UK, the ECJU administers export-licensing requirements, but the OFSI consolidated list and the UK sanctions regulations introduce a separate financial-sanctions overlay. An end-user who is not on a BIS list may nonetheless be a designated person under UK sanctions, converting what appeared to be a licensing question into an outright prohibition.

The EU operates its own consolidated list of persons subject to restrictive measures, administered through the Council regulation framework. Competent authorities in each member state also maintain national registers. At the UN level, the Security Council Consolidated List applies across all member states and sits beneath all national regimes as a floor obligation.

A practical screen must therefore cover, at minimum: the BIS Entity List and Denied Persons List; the OFAC SDN List and relevant programme-specific lists; the OFSI consolidated list; the EU consolidated list; the UN Security Council Consolidated List; and any programme-specific lists relevant to the destination. That is not a sequential process. It is a simultaneous parallel check.

The position above covers the standard case. Your facts – the counterparty's jurisdiction, the item's classification, the end-use certification chain, and the regimes in play – change the analysis materially.

For a focused review of your screening and classification processes, contact Calder & Vance at info@caldervance.com.

Step 3: Obtain and verify end-use documentation

End-use documentation is the exporter's primary defence in any subsequent investigation. The required form and the degree of verification expected differ across regimes.

Under the EAR, an end-use certificate or statement of end-use is the standard instrument. BIS's guidance on end-use checks expects exporters of sensitive or controlled items to obtain a government-issued import certificate or an end-user statement, depending on the destination country and item classification. For items on the Commerce Control List, a more detailed statement is expected. For EAR99 items to non-embargoed destinations, a lighter documentary standard typically applies – but red flags override that default.

The UK regime requires exporters to have reasonable grounds to believe an end-use certificate is accurate. The ECJU's guidance makes clear that a certificate obtained without reasonable inquiry does not discharge the obligation. Where the end-user is a distributor rather than the ultimate consumer, the exporter must look through the distribution chain to the final application.

Under the EU dual-use rules, the catch-all provision means that even an uncontrolled item requires a licence if the exporter knows or is informed by the competent authority that the item may be used in connection with WMD programmes, military end-uses in embargoed destinations, or – under the rules in force since 2021 – internal repression or surveillance. The catch-all is triggered by knowledge, constructive knowledge, or formal notification. Ignorance that results from a deliberate failure to inquire is treated as equivalent to knowledge in several member states' enforcement practice.

In our experience, the documentation failures that cause the greatest enforcement risk are: end-use certificates signed by a purchasing agent rather than the ultimate end-user; certificates that describe the application at too high a level of abstraction ("industrial use", "commercial purposes") to demonstrate genuine verification; and certificates that are filed and never reviewed against subsequent transaction data. Each of those failures has produced significant enforcement outcomes across multiple regimes.

For guidance on deemed-export obligations and technology transfers to foreign nationals, see our dedicated service page on deemed exports and technology controls under BIS and the EAR.

Step 4: Apply the red-flag standard and document the analysis

The red-flag standard is the duty to inquire further when the facts of a transaction raise plausible grounds for concern. It is a universal cross-regime obligation, even though the specific triggers and the formulation differ between the EAR, the UK regime, and the EU rules.

BIS identifies eight categories of red flag in its guidance: unusual end-user requests, payment terms inconsistent with the value of the goods, shipment routing through unexpected jurisdictions, reluctance to provide end-use information, a mismatch between the buyer's stated business and the item's capabilities, orders for quantities inconsistent with the stated application, requests to ship without standard safety or operating documentation, and last-minute changes in shipment destination. The EAR imposes a duty to stop the transaction and resolve the red flag before proceeding. Proceeding in the face of an unresolved red flag is treated as constructive knowledge of the unlicensed end-use.

The UK and EU regimes operate equivalent standards. Under EU rules, the catch-all mechanism explicitly ties the obligation to inquire to the exporter's awareness of circumstances that raise concern. Member-state enforcement practice treats an unresolved red flag as strong evidence of constructive knowledge, which in turn satisfies the mental-element test for an aggravated offence in several EU jurisdictions.

What does this mean in practice? The red-flag analysis must be documented at the time, not reconstructed after an inquiry. A contemporaneous internal memo recording the flag, the inquiry steps taken, and the resolution reached is far more valuable in an enforcement context than a post-hoc narrative. Is your organisation capturing that analysis now, or only after a problem surfaces?

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.

Step 5: Maintain records for the required retention period

Record-keeping is not a procedural formality. It is the evidentiary foundation for any voluntary self-disclosure or penalty mitigation argument, and its absence can convert a minor procedural issue into a serious enforcement matter.

Under the EAR, exporters must retain export-related records for five years from the date of export, re-export, or the transaction. That period runs from the later of the export date or the expiry of any licence. The obligation extends to end-use certificates, screening records, internal compliance notes, and correspondence with the end-user.

The UK requirement under the Export Control Order similarly runs for a defined period following the export. OFSI's enforcement guidance applies an equivalent standard to financial-sanctions records, requiring retention of documents sufficient to demonstrate compliance with the relevant prohibition and any applicable licence condition. The EU dual-use rules require records to be kept for a period set by the relevant member-state competent authority, subject to a minimum floor under the Council regulation. In practice, a five-year minimum is the standard adopted by most EU member states and is a reasonable working assumption in the absence of specific domestic guidance.

The record set should include: the classification determination and its basis; the screening result and the list versions checked; the end-use certificate and any supporting correspondence; any red-flag analysis; the licence application and authorisation (or the documented basis for proceeding without one); and any post-shipment verification steps taken. That record set serves multiple purposes: it satisfies the legal obligation, it supports a VSD (voluntary self-disclosure to a regulator) if a problem later emerges, and it demonstrates a culture of compliance that regulators across all three major regimes treat as a mitigating factor.

Where the regimes diverge: the pitfalls that produce enforcement exposure

The procedural steps above have broad parallels across regimes. The divergences are where exporters with multi-jurisdiction footprints most frequently encounter unanticipated exposure.

The most significant divergence is extraterritorial reach. The EAR applies to US-origin items and items containing US-origin content above a de minimis threshold wherever they are located, and to re-exports from any country to any other. A German exporter re-exporting a product that incorporates US-controlled components must comply with BIS re-export requirements even though the goods never return to US territory. The UK and EU regimes do not assert this form of extraterritorial reach. An exporter operating in both jurisdictions must maintain parallel compliance streams.

The second divergence is the treatment of intangible transfers. US controls on deemed exports – the release of controlled technology to a foreign national in the United States – have no direct equivalent in the UK or EU, though both jurisdictions control the electronic transfer of controlled technology to destinations or persons covered by licensing requirements. The practical gap matters most for research institutions, joint ventures, and technology licensing arrangements.

The third divergence is the catch-all mechanism's scope. The EU's updated catch-all explicitly covers surveillance technology and internal-repression end-uses. The EAR's catch-all (the EAR's own general prohibition on exports for impermissible end-uses) does not use identical framing. This means that a transaction that passes BIS scrutiny may still require an EU licence when the end-user's activities include the relevant human-rights risk factors. We regularly advise technology companies on precisely this gap.

A fourth and frequently overlooked divergence is the secondary-sanctions dimension. OFAC's secondary-sanctions programmes mean that a non-US person facilitating a transaction that would be prohibited under a primary US sanctions programme can itself become subject to US sanctions consequences. Secondary-sanctions exposure does not require a US nexus in the transaction itself. It is assessed by reference to the conduct, not the exporter's nationality. For a cross-border exporter with US dollar clearing, US banking relationships, or US-person employees, that risk is live even on transactions that never touch US territory or US-origin goods.

For a regime-by-regime comparison of end-use controls in the EU, see our guide on end-use and end-user controls under EU dual-use rules. Further detail on EU implementation practice is available at our supplementary EU end-use guide.

Common myths and the objection we hear most

The most persistent myth in cross-border end-use compliance is that a clean screening result discharges the obligation. It does not.

Screening is a necessary first step. It is not a sufficient one. The end-use obligation requires the exporter to form a view about what the goods will be used for, not merely whether the recipient is on a list. A buyer who is clear of every relevant list may still present a prohibited end-use – because the goods are intended for a WMD programme, a military end-use in an embargoed destination, or an application that triggers the EU catch-all. The screening result tells you who; the end-use analysis tells you what for.

A second myth is that small or low-value shipments do not attract enforcement attention. In our experience, enforcement agencies across jurisdictions do not apply a value threshold to end-use violations. The concern is proliferation and diversion, not transaction size. A single item of controlled technology reaching an impermissible end-user is a violation regardless of its unit value.

A third myth is that the end-use obligation ends at shipment. Post-shipment verification – checking that the goods arrived at the stated destination and are being used for the stated application – is expected for sensitive items under all three major regimes, and is increasingly a condition of licence approval. An export compliance programme that treats the licence or the customs filing as the final step is structurally incomplete.

When to involve specialist counsel

End-use and end-user controls generate legal risk that internal compliance teams alone are not always positioned to manage. Certain situations require specialist sanctions and export-control counsel.

The clearest trigger is an apparent violation: a shipment has reached an end-user whose activities or location do not match the original certification, or a transaction has been flagged by a bank, freight forwarder, or competent authority. In that situation, the decision whether to file a VSD (voluntary self-disclosure to a regulator) must be made promptly and with full knowledge of the procedural rules in each relevant jurisdiction. A VSD filed correctly and completely is treated as a significant mitigating factor under OFAC, BIS, OFSI, and the EU member-state enforcement frameworks. A VSD filed late, incompletely, or without adequate supporting documentation can make the position worse.

A second trigger is a transaction with novel features: a new destination market, a new category of end-user, a product line that straddles classification boundaries, or a corporate restructuring that changes the nationality of the exporting entity. In our experience, these transactions carry the highest end-use risk precisely because they are processed under assumptions derived from prior transactions that do not map cleanly onto the new facts.

A third trigger is a due diligence exercise in an M&A or joint-venture context. Acquiring or partnering with a business that has unresolved end-use exposure means inheriting that exposure. A pre-transaction export-control audit that maps the target's classification, licensing, and end-use documentation practices is a standard component of cross-border M&A diligence for defence, technology, and industrial goods businesses.

To discuss your end-use compliance obligations or to assess exposure on a specific transaction, reach our team at info@caldervance.com.

Related practices

Frequently asked questions

What are the steps to apply end-use controls under a cross-border guide?
The core steps are: classify the item under the applicable regime's control list; screen the end-user against all relevant lists simultaneously (BIS, OFAC, OFSI, EU, and UN); obtain and verify end-use documentation from the ultimate end-user rather than an intermediary; apply the red-flag standard and document the analysis contemporaneously; and retain all records for the required period – at least five years under the EAR and as a working minimum under most other regimes. Where the item has a US-origin component, the EAR's re-export rules apply in parallel with the national regime of the exporting country, requiring a dual-stream assessment before shipment proceeds.
What is the most common mistake in end-use and end-user controls?
The most common mistake is treating a clean screening result as equivalent to a complete end-use check. Screening confirms that the end-user is not on a relevant list; it does not confirm that the stated application is permissible. The second most common mistake is accepting an end-use certificate from a purchasing agent or distributor rather than the ultimate end-user, which means the document does not evidence what the exporter needs it to evidence. Both failures leave the exporter exposed to an apparent violation even where no diversion was intended.
How does the cross-border picture differ from a single-regime analysis?
A single-regime analysis identifies the obligations under one jurisdiction's rules. A cross-border analysis must map the extraterritorial reach of each regime and identify where they overlap or conflict. The EAR's extraterritorial application to US-origin items and re-exports is the most significant single addition: it means a non-US exporter may face BIS licensing requirements on goods it considers purely domestic. Secondary-sanctions risk under OFAC adds a further layer, applying potential US consequences to non-US persons conducting transactions that do not touch US territory but fall within a US-designated programme. Compliance counsel must address all relevant regimes simultaneously rather than sequentially.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.