Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFAC

End-use and end-user controls under OFAC: a practical guide

A technology distributor based in Germany routes a shipment of dual-use components through a third-country intermediary. The end-user certificate names a trading company the distributor has screened three times. What the distributor has not checked is what that trading company does with the goods – or who ultimately controls it. Under OFAC, that gap is not a procedural oversight. It can be the difference between a lawful transaction and a sanctions violation with strict-liability consequences.

End-use and end-user controls under OFAC require exporters, re-exporters, and intermediaries to verify not only that a counterparty is unlisted at the point of sale, but that the goods, technology, or services will not reach a blocked person, a sanctioned jurisdiction, or a prohibited end-use at any point in their lifecycle. OFAC administers these controls under the authority of IEEPA and related statutes. Strict liability applies: knowledge of a violation is not required for a civil penalty to arise.

This guide sets out, step by step, how end-use and end-user controls work under OFAC, where the tests diverge from OFSI and the EU, and what a cross-border business must do before it ships, re-exports, or provides services with an export-control dimension.

Step 1 – Understand the governing authority and what OFAC controls

OFAC administers US economic sanctions under IEEPA, the Trading with the Enemy Act, and a series of programme-specific statutory authorities. Its jurisdiction reaches US persons wherever located, persons and entities within the United States, and – through secondary-sanctions risk – non-US persons who facilitate transactions that implicate blocked parties or sanctioned jurisdictions.

End-use and end-user controls sit at the intersection of OFAC's sanctions programmes and the separate but often overlapping export-control regime administered by the Bureau of Industry and Security under the Export Administration Regulations. A transaction may clear BIS licensing requirements and still be prohibited by OFAC if the ultimate recipient is a blocked person or if the goods serve a prohibited end-use. Equally, a transaction may appear OFAC-clean and still require a BIS licence. The two regimes operate in parallel; neither displaces the other. When both apply, the stricter prohibition governs.

OFAC's end-user concern centres on two questions. First, is the named party blocked? Second, even if the named party is not blocked, will the goods or services ultimately reach a blocked person or a prohibited destination? The second question is where most enforcement exposure arises in practice.

Step 2 – Map the transaction chain before screening

Effective end-use and end-user controls begin with mapping the full transaction chain before any screening is run. Screening a single counterparty name against the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) captures only the most obvious exposure. It does not reveal a blocked intermediary two layers back, a sanctioned jurisdiction in the logistics route, or an end-use that is itself prohibited under a programme-specific restriction.

Transaction mapping should identify every party that will handle, receive, or control the goods or services: the buyer, the consignee, the freight forwarder, any intermediate distributor, the ultimate end-user, and any financial institution processing the payment. For technology or intangible transfers, the analysis must extend to who will have access to the technology at the destination, including nationals of sanctioned jurisdictions who may access controlled technology without a physical export taking place – a concept addressed in depth in BIS's deemed export rules.

Is your transaction chain documented before screening begins? In our experience, firms that reverse-engineer the chain after a screening hit discover dependencies they had not anticipated and face a compressed timeline for resolution.

Once the chain is mapped, each node is screened against the SDN List, the OFAC Non-SDN lists, and any programme-specific prohibited parties lists. Screening should be repeated when the transaction terms change materially, when a new party enters the chain, or when a significant interval has elapsed since the previous check.

Step 3 – Apply the ownership and control test to every entity

A counterparty that is not itself listed may nonetheless be blocked if it is owned or controlled by a blocked person. Under OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked), the test is mechanical: if one or more SDNs hold 50 percent or more in the aggregate, the entity is blocked regardless of whether OFAC has added it to the list.

Aggregation is critical. Two listed persons each holding a minority stake may reach the threshold together. Layered ownership structures – holding companies, trusts, nominee arrangements – require the analysis to be traced through each intermediate tier. OFAC's guidance confirms that the rule applies regardless of how many layers intervene between the SDN and the entity in question.

The test differs meaningfully across regimes. Under OFSI and the EU, the relevant test extends beyond ownership to ownership and control (the UK and EU test for whether a non-listed entity is caught through a listed person). An entity may be caught even where a blocked person owns less than 50 percent, if that person exercises dominant control over the entity's decisions. For a business managing multi-regime exposure, the UK and EU tests are broader, and a clean OFAC ownership analysis does not confirm a clean position under OFSI or the relevant Council regulation. See our guide to end-use and end-user controls under OFSI for a direct comparison of the two approaches.

In our cross-border practice, ownership chains that satisfy the OFAC 50 percent analysis have subsequently raised control-test issues under EU rules. The safest approach is to run both tests for any counterparty where a listed person holds any stake, however small.

Step 4 – Assess end-use restrictions and obtain end-user documentation

The end-use analysis under OFAC requires the exporter to consider not only who the recipient is, but what the goods, technology, or services will be used for. Certain OFAC programmes impose transaction-type restrictions that operate independently of party-based screening: supplying services to a particular sector, providing goods for a prohibited category of use, or enabling a transaction that benefits a blocked party indirectly.

End-user documentation serves two functions. First, it records the stated intended use, creating a contemporaneous record that can support a due-diligence defence in any enforcement inquiry. Second, it shifts the factual burden: if a counterparty provides a false end-user certificate, the exporter's culpability is assessed in light of what it knew or had reason to know at the time of the transaction.

Documentation should include, at minimum: a signed end-user certificate or end-use statement from the ultimate consignee naming the specific goods, the intended application, and the location of use; any re-export or retransfer undertakings; and evidence of the due-diligence steps taken. For higher-risk transactions – those involving dual-use goods, strategic industries, or regions with elevated secondary-sanctions risk – enhanced documentation and pre-shipment verification may be required.

OFAC's enforcement guidance treats the quality of pre-transaction diligence as a significant mitigating factor. Firms that hold contemporaneous records of a thorough end-use assessment are better placed in a penalty review than those that relied on a single automated screening check.

Step 5 – Identify red flags and escalate before the transaction closes

Red flags in end-use and end-user controls are signals that the stated transaction purpose may not reflect the actual one, or that a prohibited party or destination is present in the chain. Identifying them before a transaction closes is essential. Acting after shipment substantially narrows the options available and may increase enforcement exposure.

The following patterns consistently arise in enforcement actions and in the pre-transaction reviews our practice conducts:

  • A counterparty requests that the goods be re-exported to a jurisdiction not named in the original order, without a commercial explanation.
  • The stated end-use is implausible given the technical specification of the goods or the counterparty's known business.
  • Payment routing involves a jurisdiction unrelated to the transaction parties or the delivery destination.
  • The counterparty is a newly established entity with no operating history, or an intermediary whose principal owners cannot be identified.
  • A request to omit or alter product descriptions, ECCN classifications, or party names on shipping documents.
  • An unusually high order volume for goods with known dual-use applications, inconsistent with the counterparty's stated scale of operations.

Any one of these flags does not automatically prohibit the transaction. It does require escalation, enhanced due diligence, and – in many cases – legal advice before the transaction proceeds. Proceeding in the face of unresolved red flags is treated by OFAC as an aggravating factor in penalty calculations and can elevate what might otherwise be a civil matter to a criminal referral.

The position above covers the standard case. Your facts – the counterparty, the goods, the route, the regime in play – change the analysis. For an assessment of your exposure under OFAC, contact Calder & Vance at info@caldervance.com.

Step 6 – Understand the cross-border dimension: OFAC and the EAR together

End-use and end-user controls under OFAC do not operate in isolation. For goods with an ECCN (Export Control Classification Number under the US Commerce Control List) classification, the BIS export-control regime imposes a parallel set of end-user and end-use conditions through licence requirements, licence exceptions, and the Entity List. The relationship between the two regimes is additive, not alternative.

A US-origin item that qualifies for a BIS licence exception may still be prohibited under OFAC if the end-user is an SDN or if the transaction falls within a programme-specific prohibition. Conversely, OFAC authorisation – whether through a general licence or a specific licence – does not override BIS licence requirements for controlled items. Exporters must clear both gatekeepers independently.

For businesses managing dual-use items with both OFAC and BIS dimensions, our service on deemed export and technology controls under BIS and the EAR addresses the parallel classification and end-user analysis in detail. Where a shipment involves technology that may be accessed by nationals of sanctioned jurisdictions – even within the United States – the deemed export analysis must be incorporated into the end-user controls review from the outset.

The EU dual-use regime adds a further layer for businesses with European operations. EU dual-use rules impose their own end-use and end-user conditions, and the applicable Council regulation may restrict re-export from EU member states to third countries even where the original export was licensed by BIS. A business that ships from the US, re-exports through an EU member state, and delivers to a third-country end-user may engage three regulatory authorities simultaneously: OFAC, BIS, and the relevant EU competent authority.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact us at info@caldervance.com.

Step 7 – Record-keeping, ongoing monitoring, and voluntary self-disclosure

End-use and end-user controls are not a one-time pre-transaction exercise. They require ongoing monitoring throughout the life of a transaction and, in many cases, a record-keeping obligation that outlasts the commercial relationship itself.

OFAC's guidance places significant weight on record-keeping as a component of an effective sanctions compliance programme. A well-structured programme maintains contemporaneous records of screening decisions, ownership and control analyses, end-user certifications, red-flag assessments, and any escalation steps taken. Those records are the primary basis on which a business defends its position in the event of an enforcement inquiry.

Ongoing monitoring serves a distinct purpose. A counterparty that was clean at the time of contracting may be designated during the life of a long-term supply agreement. A jurisdiction that was unrestricted at the time of shipment may become subject to new programme restrictions before delivery is complete. Compliance counsel regularly advise businesses to build designation-trigger provisions into long-term contracts, so that a new designation does not create an automatic contractual default as well as a regulatory violation.

Where a business identifies a potential violation – whether through an internal audit, a counterparty disclosure, or a screening hit on an existing relationship – the question of VSD (voluntary self-disclosure to a regulator) arises. OFAC treats VSD as a significant mitigating factor. The decision whether to disclose, and how to frame the disclosure, requires careful legal analysis of the apparent violation's nature, the applicable programme, and the likely penalty range. A disclosure that is poorly framed or incomplete can be treated as less cooperative than no disclosure at all.

Our further guide on this topic, end-use and end-user controls under OFAC – advanced issues, addresses voluntary self-disclosure, the interaction with DOJ criminal referrals, and the design of post-violation remediation programmes in detail.

Common myths about end-use and end-user controls under OFAC

A persistent misconception in our practice is that a clean SDN screening at the point of sale satisfies OFAC's end-user requirements. It does not. OFAC's standard is one of reasonable due diligence across the full transaction chain. Screening only the immediate counterparty leaves the exporter exposed to designation at any downstream point in the chain.

A second myth holds that end-use controls are primarily a concern for military or defence exporters. In practice, OFAC's programme-specific restrictions apply to a wide range of commercial goods and services, including financial services, software, energy infrastructure components, and logistics. Any business with cross-border exposure to a sanctioned programme needs to assess whether its products or services could reach a prohibited end-use, regardless of whether they appear on the Commerce Control List.

We regularly advise businesses that assumed their compliance programme was adequate until an audit or a counterparty disclosure revealed a gap. The test is not whether the programme exists; it is whether it is calibrated to the actual risk profile of the business. We have acted for exporters who implemented best-practice controls, maintained thorough records, and were nonetheless confronted with an enforcement inquiry because a downstream distributor acted outside the terms of its end-user certificate. In each case, the quality of the pre-transaction record was the decisive factor in the resolution.

Related practices

Frequently asked questions

What are the steps to apply end-use controls under OFAC?
The steps are: (1) map the full transaction chain including all intermediaries and the ultimate end-user; (2) screen every party against the SDN List and applicable non-SDN lists; (3) apply the 50 percent ownership test to every entity; (4) assess whether the intended use falls within any programme-specific prohibition; (5) obtain and retain end-user documentation; (6) identify and escalate any red flags before the transaction closes; and (7) maintain records and monitor the relationship for post-sale designation changes. Each step is a distinct requirement; omitting one does not excuse a subsequent violation.
What is the most common mistake in end-use and end-user controls?
The most common mistake is treating a single SDN screening of the immediate counterparty as sufficient. OFAC's standard requires due diligence across the full chain: the buyer, the consignee, any re-exporter, and the ultimate end-user. A business that screens only the entity it contracts with, and ignores downstream parties, is exposed to any blocked person or prohibited destination that appears further along the route. In our experience, this gap accounts for a significant proportion of voluntary self-disclosures we are instructed to prepare.
How does OFAC differ from other regimes here?
OFAC's ownership test is mechanical: 50 percent or more aggregate beneficial ownership by blocked persons triggers a block, regardless of control. OFSI and the EU extend the analysis to control, so an entity can be caught even where a blocked person holds a minority stake if that person exercises dominant control. BIS operates a parallel end-user review through the Entity List and licence conditions, which must be cleared independently of OFAC. For cross-border transactions touching multiple regimes, each authority's test must be satisfied separately; a clear position under one does not confer a clear position under another.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.