A trading company in Hamburg ships electro-optical components to a distributor in a third market. The end customer turns out to be a military research institute. The exporter held an EU general export authorisation and believed it covered the transaction. It did not. The reason: a catch-all control that activates the moment an exporter has knowledge – or grounds to suspect – that goods will reach a prohibited end-use or a controlled end-user. That knowledge test is where most export-control problems in the EU regime begin.
End-use and end-user controls under the EU dual-use regime work through two interlocking mechanisms: the classification-based licence requirement that attaches to listed goods, and the catch-all clause (the obligation to seek a licence even for unlisted goods when an exporter is aware or has been informed that the goods are or may be intended for a controlled end-use). Both mechanisms are governed by the EU Dual-Use Regulation, administered by member-state competent authorities, and interpreted through Commission guidance and national practice.
As of April 2026, the EU Dual-Use Regulation applies across all member states and is the primary instrument for controlling the export of dual-use items from EU territory. This guide takes compliance officers, export managers, and legal counsel through the full procedure – from classification and end-user screening to documentation, red-flag assessment, licence applications, and the points at which a cross-regime comparison changes the analysis.
Step 1: Establish whether your goods are listed or unlisted – and why it matters for the catch-all
The first step in any end-use analysis under the EU regime is to determine whether the goods, software, or technology appear on the EU Common Military List or the dual-use annexe to the Regulation. Listed items require a licence for export to most non-EU destinations; the end-use question then becomes one of licence type and conditions. For unlisted items, the catch-all clause is the operative control, and its trigger is knowledge or reasonable grounds for suspicion rather than the inherent nature of the goods.
Why does this distinction matter so much in practice? Because an exporter who correctly concludes that goods are unlisted may still be prohibited from shipping if it has received information – from a customer, a freight forwarder, or even a government advisory – indicating a weapons-of-mass-destruction, military, or other controlled end-use. The exporter's state of knowledge is the control, not the classification. In our experience, exporters of commercially ordinary goods are often unaware that a red-flag situation has triggered a de facto licence requirement.
The EU Dual-Use Regulation distinguishes three controlled end-use categories for the catch-all: use in connection with weapons of mass destruction, use as parts of military items already subject to an arms embargo, and – under certain conditions – use by embargoed destinations. Each category has a different trigger for the knowledge test, and the practical consequences of mis-classifying the situation are significant. Verify the current position of any specific goods against the EU Common Customs Tariff and the dual-use annexe before proceeding, as classifications are periodically updated.
Step 2: Screen the end-user – who is the actual recipient?
End-user screening requires identifying the ultimate consignee, not merely the declared buyer. Under the EU regime, an exporter must not rely solely on the invoice counterparty; it must look through the transaction chain to determine who will receive and use the goods. The competent authority in each member state will scrutinise end-user documentation at the point of licence assessment or post-shipment control.
The screening obligation extends beyond formal sanctions lists. An exporter must check the consolidated EU sanctions list, UN Consolidated List, and – critically for transactions with a US-origin technology component or for goods that may re-enter the US supply chain – the BIS Entity List and the Specially Designated Nationals list (OFAC's list of blocked persons). This is the point at which a purely EU-law compliance exercise intersects with extraterritorial US controls.
What does effective end-user screening look like operationally? At minimum it should cover: verification of the legal entity against the relevant lists, ownership mapping to 50 percent or more beneficial ownership levels (to catch entities owned or controlled by listed parties), review of the end-user's stated business against the goods' specifications, and a geographic risk assessment based on the destination country's control status. Where the end-user is a distributor or intermediary, the screening must extend to the declared final customer.
We regularly advise clients who discover mid-transaction that their due-diligence process captured the first-tier buyer but not the disclosed sub-buyer. That gap in the screening chain is the single most common source of catch-all exposure in cross-border EU export-control matters. A practical fix is to require a contractual end-user undertaking from every intermediary in the chain, stipulating the ultimate destination and use, and to treat any refusal to provide it as a red flag in its own right.
Step 3: Assess the red flags – knowledge, grounds to suspect, and the information test
The catch-all clause activates when the exporter has been informed by a competent authority, or is otherwise aware, that the goods are or may be intended for a controlled end-use. The EU Dual-Use Regulation also requires exporters to exercise due diligence even without formal notification: if there are grounds to suspect controlled use, the obligation to apply for a licence applies.
The Commission has published guidance on red-flag indicators to assist exporters in applying this test. The guidance is illustrative, not exhaustive. Common red flags include: an unusually high purchase price relative to the market, a buyer unwilling to provide an end-user certificate, a requested shipping route inconsistent with the declared destination, and a mismatch between the buyer's stated business and the technical specifications of the goods. The presence of one red flag does not automatically trigger the catch-all, but it obliges the exporter to investigate further before proceeding.
The information-test is deliberately subjective in one direction: it penalises wilful blindness. An exporter who does not ask the right questions when the facts before it would cause a reasonable person to ask them is treated as having constructive knowledge. The practical implication is that compliance programmes must establish written procedures for assessing and resolving red flags, and must document the outcome of each assessment. Undocumented decisions are functionally indistinguishable from decisions not made at all, when a competent authority reviews the file.
Record-keeping obligations under the EU regime require exporters to retain transaction documentation – including end-user statements, red-flag assessments, and any correspondence with the competent authority – for a defined period. Verify the current retention period with your member-state competent authority, as national implementing rules vary. As a benchmark, practitioners in our practice frequently encounter a requirement of around five years, though the applicable rule should be confirmed for the specific member-state jurisdiction.
Step 4: Determine the licence requirement and select the correct authorisation
Once classification and end-user screening are complete, the exporter must determine which licence – if any – applies. The EU regime offers several authorisation types: Union General Export Authorisations (standing authorisations covering defined categories of goods and destinations), national general authorisations (issued by individual member states), global licences (covering multiple shipments to named recipients over a period), and individual licences (case-by-case authorisations for a specific transaction). The appropriate type depends on the goods, the destination, the end-user, and the end-use.
Union General Export Authorisations do not apply automatically. The exporter must register with its member-state competent authority before first use, and the terms of the specific authorisation must be read carefully against the proposed transaction. A common error is to assume that the authorisation's geographic scope covers a destination that is in fact excluded. For catch-all situations, no general authorisation typically covers the transaction; an individual or global licence application is required.
The licence application process before the member-state competent authority typically requires: a completed application form, a detailed technical description of the goods, an end-user certificate or end-user statement signed by the final recipient, and supporting commercial documentation. Processing times vary significantly between member states – from a matter of weeks to several months for complex cases. Plan licence timelines into contractual delivery schedules; last-minute applications rarely resolve on time.
The position above covers the standard route. Your specific facts – the goods, the destination, the end-user, and any US-origin technology in the supply chain – change the analysis materially.
For early guidance on whether your transaction requires a licence and which authorisation type is appropriate, contact Calder & Vance at info@caldervance.com.
Step 5: How does the EU end-use regime compare with the US EAR catch-all and UK controls?
The EU catch-all is conceptually similar to the US EAR's knowledge standard under the Export Administration Regulations, but the two regimes diverge in important operational respects. Under the EAR, the knowledge test is broader: it covers not only WMD and military end-use but also a wider range of prohibited end-users, including those on the BIS Entity List and the BIS Military End-User list. The US regime also extends extraterritorially to foreign-produced items that meet applicable US-content or technology thresholds – a control that the EU regime does not replicate in the same form.
For any transaction involving goods or technology with a US-origin component, both regimes may apply simultaneously. An exporter who obtains an EU individual licence has not thereby cleared the transaction under US law, and vice versa. In practice, the stricter prohibition governs: if either regime prohibits the export or requires a licence, the exporter must comply with that requirement regardless of what the other regime permits.
The UK Export Control Order, administered by the ECJU, operates a parallel catch-all. Since the UK departed from the EU, the UK's controls apply separately and are no longer unified with the EU regime. UK and EU-incorporated entities in the same corporate group may therefore face independent licensing obligations for what appears to be a single transaction. We advise clients regularly on co-ordinating EU and UK licence applications to avoid a situation where goods are cleared under one regime but held at the border under the other.
Switzerland, operating through SECO and the Swiss goods-control legislation, applies its own end-use controls that track – but are not identical to – the EU regime. For exporters routing goods through Switzerland or relying on Swiss entities in the supply chain, an independent assessment of Swiss requirements is warranted.
If a transaction has already been flagged by a competent authority, or a shipment has been stopped, an early review preserves options that narrow quickly. Contact info@caldervance.com for a confidential assessment.
Step 6: Document the decision and maintain the compliance record
Every end-use and end-user decision must be documented contemporaneously. This means recording the classification outcome, the end-user screening results, the red-flag assessment, the choice of licence type, any communications with the competent authority, and the final shipping documentation. A compliance record assembled after the event is treated sceptically by enforcement authorities; a record built in real time is the primary evidence of a good-faith compliance effort.
The documentation package for a typical dual-use export should include: the export licence or the reference to the general authorisation used, the end-user certificate, the exporter's own red-flag assessment worksheet, the screenshot or log of list-screening outputs, and the bill of lading or equivalent shipping document. Where goods are shipped in multiple consignments under a global licence, each consignment should be cross-referenced to the licence and its cumulative quantities tracked against the authorised volume.
Post-shipment controls are a feature of the EU regime that exporters sometimes underestimate. A competent authority may conduct a post-export verification – checking that the goods reached the declared end-user and were used for the stated purpose. Some member states require the exporter to obtain confirmation of delivery from the end-user and to retain it as part of the compliance record. Check the specific requirements of your member-state competent authority at the time of shipment.
Risk flags and when to involve counsel
Several patterns reliably indicate heightened legal risk in end-use and end-user transactions under the EU regime. Awareness of them allows compliance teams to escalate before a transaction closes rather than after enforcement attention arrives.
- Unfamiliar or newly established counterparties in high-risk destinations, particularly those that cannot be verified through public registries or commercial databases.
- Requests to ship to a freight forwarder or logistics intermediary as the named end-user, with no disclosure of the onward customer.
- Technical goods ordered in quantities inconsistent with the buyer's declared business scale or sector.
- Payment routed through a third country unconnected to the buyer's stated location.
- A buyer who declines to sign a standard end-user certificate or who proposes unusual amendments to its terms.
- Any government advisory, trade press report, or EU Commission notice identifying the destination or end-user sector as a diversion risk.
A common misconception in this area is that end-use controls apply only to high-technology or defence-adjacent goods. That is inaccurate. The catch-all clause in the EU Dual-Use Regulation applies to any item – including commercially ordinary goods – where the exporter has knowledge or grounds to suspect a controlled end-use. A basic electronic component, a commercial chemical, or standard software can each trigger an obligation to apply for a licence if the facts support it. The classification of the goods does not immunise the exporter from the catch-all.
Counsel should be involved early in any transaction where: a catch-all situation is even arguable, an end-user certificate has been refused or qualified by the counterparty, a prior shipment to the same customer or destination has attracted competent-authority attention, or the supply chain involves US-origin technology alongside EU-origin goods. Acting after a competent authority has opened an inquiry limits the available options considerably.
Related practices
- Deemed export and technology controls under BIS/EAR – US export-control classification and licence exceptions for technology transfers
- End-use controls: advanced guide – deeper analysis of catch-all triggers, enforcement patterns, and multi-regime co-ordination
- End-use compliance programme design – building a durable end-use screening and documentation programme across EU, UK, and US regimes