A European trading company finalises a sale of precision optical components to a buyer in a third country. The end-use certificate reads "civil telecommunications." Six months later, the company's compliance officer learns that identical components appear in a defence procurement catalogue. Was the original export lawful? Could it happen again? These questions sit at the heart of the EU's end-use and end-user control regime – and getting them wrong carries penalties that can reach the criminal threshold.
End-use and end-user controls under the EU regime are the set of obligations that govern not just what is exported, but who receives it and for what purpose. They operate within the EU's dual-use rules, which are administered by each Member State's competent authority under the overarching EU framework. As of April 2026, the EU rules impose mandatory due-diligence checks on exporters, require specific licences where a prohibited end-use is suspected, and create catch-all obligations that can bite even on items not otherwise controlled.
This guide sets out the governing authority, the practical steps for applying the controls, the cross-regime comparison with OFAC and BIS, the principal risk flags, and when to involve specialist counsel.
What is the governing authority and legal basis for EU end-use controls?
The EU's dual-use rules provide the legal basis for end-use and end-user controls, and those rules are administered jointly by the European Commission and the competent authorities of each Member State. The regime is a directly applicable instrument across all EU Member States, which means a single consolidated text sets the obligations – but each Member State enforces them through its own authority, with its own penalty scale and its own licensing queue.
The core mechanism is a licensing system that distinguishes between general export authorisations, which permit a defined category of transactions without a separate application, and specific licences (a case-by-case authorisation for a particular export where general authorisations do not cover the destination, the item, or the end-user). For end-use-sensitive goods, exporters cannot simply assume a general authorisation covers them. The destination, the end-user profile, and the stated use each feed into the determination.
The EU regime also contains a catch-all clause – an obligation that applies even to items not listed in the dual-use annex when the exporter has been informed or has grounds to suspect that the items are or may be intended for use in connection with weapons of mass destruction, certain military end-uses, or re-export to prohibited destinations. The catch-all is activated by the competent authority notifying the exporter, or by the exporter's own state of knowledge. Ignoring a red flag, in our experience, has been one of the most frequent triggers for enforcement review.
The position above describes the standard architecture. Your specific items, destination, and buyer profile may change the analysis materially.
For a first review of how the EU end-use regime applies to your goods and markets, contact Calder & Vance at info@caldervance.com.
Step 1: Classify the item and identify the relevant control parameter
The first practical step under the EU dual-use rules is to determine whether the item falls within the controlled annex – and if so, under which entry and for which reasons (national-security, nuclear, chemical, or other grounds). This is not a formality. A component that is uncontrolled in isolation may be controlled when it is specifically designed or prepared for a controlled system, or when it is bundled with software that takes it across the control threshold.
Classification feeds directly into the end-use analysis. An item controlled for national-security reasons carries different end-use restrictions to one controlled purely on nuclear non-proliferation grounds. The classification also determines which general export authorisations are available and which destinations they cover.
Exporters should produce a written classification record at this step. That record – setting out the item description, the control entry, the classification rationale, and the date of determination – forms the backbone of the compliance audit trail. Under the EU regime, exporters are expected to maintain records for a specified period; verify the current minimum retention period with the competent authority of your Member State, as enforcement guidance indicates it is substantial and cannot be treated as a brief window.
Dual-use classification is also where the EU diverges from the US Export Control Classification Number or ECCN (the identifier assigned under the US Export Administration Regulations administered by BIS). The EU annex and the US Commerce Control List share structural roots in the Wassenaar Arrangement and other multilateral regimes, but they are not identical. An item that is EAR99 under the US system – meaning it does not appear on the Commerce Control List – may still be controlled under the EU dual-use annex. A business that classifies only against the US list and then exports from an EU Member State is operating with an incomplete picture.
Step 2: Screen the end-user and assess the intended end-use
End-user screening is the procedural heart of the EU controls. The exporter must assess whether the stated end-user and the stated end-use are consistent with a legitimate civilian or commercial purpose, and must document that assessment before the shipment departs.
The EU regime expects exporters to apply a risk-based assessment that considers: the nature of the end-user (government, military, private commercial, research institution); the end-user's jurisdiction and its record under multilateral non-proliferation regimes; the plausibility of the stated end-use given the technical specification of the goods; and any red flags in the transaction structure (unusual payment terms, requests to omit items from the packing list, a buyer who appears as a front for another entity).
Red flags are not codified in a single list under the EU regime. The competent authorities issue guidance, and the EU framework references internationally recognised red-flag indicators. In our practice we advise clients to maintain a standing red-flag checklist calibrated to the sectors and destinations in which they operate, and to update it at least annually. A static checklist applied to a changing transaction portfolio misses precisely the patterns that enforcement actions later identify.
The end-user certificate – a written declaration from the buyer confirming the stated end-use and undertaking not to re-export without prior authorisation – is a standard control tool under the EU regime. It does not, on its own, discharge the exporter's due-diligence obligation. It is one element of a broader assessment. Competent authorities have found exporters in breach even where an end-user certificate was on file, when other due-diligence steps were absent or inadequate.
Screening must also cover the EU Consolidated List of persons and entities subject to EU restrictive measures, as well as relevant UN Security Council consolidated list entries. An end-user who appears on either list – or who is owned or controlled by a listed person – cannot receive a controlled export absent a specific licence or derogation. The ownership-and-control test under the EU regime turns on both ownership and actual control, which is broader than the purely mathematical OFAC 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked). In our cross-border practice, this divergence catches clients who have cleared a counterparty under the US threshold but remain at risk under the EU test.
Step 3: Determine the applicable licence type and apply for it where required
Once the item is classified and the end-user assessed, the exporter must determine whether a general export authorisation (a standing authorisation that permits a defined category of transactions without a separate application) covers the transaction, or whether a specific licence is required.
The EU operates several layers of general authorisations: a Union General Export Authorisation that covers the lowest-risk items to the lowest-risk destinations; national general authorisations issued by individual Member States for additional categories; and global licences that cover repeat transactions to a defined set of end-users. Exporters who rely on a general authorisation are still required to register, maintain records, and – in some Member States – report use of the authorisation. "Available" does not mean "unconditional."
Where a general authorisation does not apply – because the destination is excluded, the item is too sensitive, or the end-use presents a concern – the exporter must apply for a specific licence from the competent authority of the Member State from which the goods will be exported. This application must set out the item details, the end-user, the stated end-use, the value, and the supporting documentation. Competent authorities may request additional information, may impose conditions on the licence if granted, and may deny the application if the end-use risk assessment is not satisfied.
Processing times for specific licences vary by Member State and by item sensitivity. In our experience, applications that arrive with a complete documentation package and a credible end-user analysis move materially faster than those that require supplementary requests. Incomplete applications are a systemic source of delay that can cost exporters time-sensitive contracts.
If a transaction has already been flagged by a competent authority, or a shipment has been detained, an early review by counsel can preserve options that narrow quickly. Contact Calder & Vance at info@caldervance.com for a confidential assessment.
Step 4: Establish post-shipment controls and record-keeping
The EU exporter's obligation does not end at the point of shipment. Post-shipment controls are a formal expectation under the regime. These include maintaining the full audit trail of the transaction – the classification record, the end-user screening documentation, the end-user certificate, the licence or authorisation relied upon, the shipping documents, and any post-export reports or undertakings made to the competent authority.
Record-keeping under the EU dual-use rules must cover the duration specified by the competent authority and by the relevant national implementing rules. Exporters should treat this as a multi-year obligation. A competent authority conducting a compliance review will request documentation going back several years. Gaps in the record are treated as a compliance failure independent of whether the underlying transactions were substantively lawful.
Where a licence was granted with conditions – for example, a requirement to conduct a post-shipment verification or to obtain confirmation of delivery to the stated end-user – those conditions are legally binding. Failure to honour them is a breach of the licence, not merely an administrative omission.
We regularly advise clients on building record-keeping systems that are scalable across product lines and geographies. A system designed only for the current transaction volume tends to fracture at the point when enforcement attention arrives – which is, invariably, when transaction volumes were highest.
How does the EU end-use regime compare with the US and UK approaches?
The EU, US, and UK approaches to end-use and end-user controls share a common purpose but differ in structure, catch-all scope, and licensing mechanics – and those differences decide the compliance programme design for any exporter operating across all three jurisdictions.
Under the US Export Administration Regulations (the EAR, administered by BIS), end-use controls operate principally through the Entity List (a list of foreign parties subject to specific licence requirements under the EAR), the Military End-User Rule, and a series of specific end-use conditions embedded in the ECCNs themselves. The US regime also operates with extraterritorial reach: items produced outside the United States may still fall under EAR controls if they contain a sufficient proportion of US-origin content or US technology (the de minimis and foreign-direct product rules). An EU exporter of components that incorporate US-origin technology must run both sets of controls in parallel. The deemed export and technology transfer service under BIS and the EAR addresses this intersection in detail.
The UK, following its departure from the EU, operates its own export-control regime through ECJU. The UK dual-use list was initially aligned with the EU annex but has begun to diverge. An export that was a single regulated event under the EU system before January 2021 may now require separate UK and EU authorisations when goods or technology transit both jurisdictions. In our cross-border practice, we find that UK-EU dual-licensing is the most frequently overlooked dimension of end-use compliance for groups with manufacturing and distribution in both territories.
Japan's end-use control system, administered by the Ministry of Economy, Trade and Industry, shares Wassenaar Arrangement architecture with the EU and US but operates its own catch-all and applies different thresholds for when a written end-use assurance is required. For clients whose distribution networks reach Asia-Pacific, the end-use and end-user controls guide for Japan sets out the parallel obligations in detail.
The OFAC dimension is a separate but overlapping risk. A transaction that clears EU end-use controls may still involve a counterparty whose dealings in a particular territory create secondary-sanctions exposure for US-nexus participants in the same supply chain. The end-use and end-user controls guide covering OFAC considerations addresses that intersection.
The overarching principle across all three regimes is consistent: where controls are stricter in one jurisdiction, the stricter prohibition governs for any business with a presence or nexus in that jurisdiction. Exporters who calibrate only to the most permissive regime in their supply chain create a structural compliance gap.
Principal risk flags and when to involve counsel
Experience across EU end-use enforcement reviews identifies a consistent set of risk flags that should trigger a mandatory pause and assessment before a shipment proceeds. None of these flags alone confirms a violation; each one raises the probability that the competent authority, on review, will question the export.
- The buyer requests that an item be described differently in the commercial invoice than in the technical specification, or asks for documentation to be omitted.
- The stated end-use is inconsistent with the buyer's known sector – for example, a retailer purchasing precision measurement equipment, or an agricultural business ordering high-specification electronics components.
- The transaction involves an intermediary in a jurisdiction with a history of re-export concerns, where the identity of the ultimate end-user is unclear.
- The buyer is newly incorporated, has limited public presence, and is unable to provide credible end-user documentation.
- The order volume significantly exceeds what the stated end-use would plausibly require.
- The buyer or a related entity appears on a competent authority's advisory or concern list, even if not on the EU Consolidated List or the UN Consolidated List.
- A prior shipment to the same buyer triggered a competent-authority query, a licence refusal in another Member State, or a denial decision under a third-country regime.
The catch-all clause means that even for items outside the controlled annex, a red flag that goes unaddressed can transform an otherwise unrestricted transaction into a breach. "We did not know" is not a complete defence where the circumstances gave reasonable grounds for suspicion and no enquiry was made.
Counsel should be involved at the latest when: the competent authority has issued a notification that catch-all controls apply; a licence application has been refused or conditioned; a shipment has been detained or an inquiry has been opened; or the internal due-diligence review has produced an inconclusive result on a high-value or high-sensitivity transaction. Earlier involvement – at the classification or end-user assessment stage – is consistently more cost-effective than crisis intervention after the fact.
Common misconceptions about EU end-use controls
A persistent misconception in the EU market is that end-use controls apply only to items that are already listed in the dual-use annex. They do not. The catch-all obligation can apply to entirely uncontrolled items when the conditions for its activation are met. A compliance programme that runs end-use checks only on annex-listed items is structurally incomplete.
A second misconception is that obtaining an end-user certificate from the buyer completes the exporter's due-diligence obligation. Competent authorities across several Member States have made clear in enforcement guidance that the certificate is one input into a broader risk assessment, not a safe-harbour document. Where other indicators point toward a prohibited end-use, the certificate does not absolve the exporter.
A third, and closely related, myth is that EU end-use controls are lighter in practice than the US EAR system and therefore warrant less intensive compliance investment. The EU regime's catch-all, its growing enforcement profile, and the extraterritorial reach of the US EAR for dual-jurisdiction supply chains mean that treating the EU regime as the lower-intensity option carries material risk. In our experience, enforcement awareness among EU competent authorities has increased materially in recent years, and the investment in proactive compliance consistently outweighs the cost of reactive defence.
Related practices
- Deemed export and technology transfer – BIS and the EAR – US export-control obligations for technology and software transfers across borders
- End-use and end-user controls – OFAC – OFAC's approach to end-use risk and secondary-sanctions exposure in supply chains