Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFAC

End-use and end-user controls under OFAC: a compliance guide

A technology distributor in the Gulf region receives a purchase order for software with industrial applications. The buyer looks clean. First-tier screening passes. But three links down the distribution chain sits an entity on OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons) – and the technology will reach it. The distributor did not look that far. The transaction is now an apparent violation of US sanctions.

End-use and end-user controls under OFAC require any US person – and any person whose transaction touches the US financial system or US-origin goods – to verify not only who is buying, but where the item goes and who ultimately uses it. As of April 2026, OFAC administers these obligations across its programme regulations under IEEPA and related statutory authority, and enforcement actions confirm that destination and end-use are treated as independent grounds for a violation, separate from the identity of the direct counterparty.

This guide walks through the governing authority, the step-by-step compliance procedure, the cross-regime comparison with OFSI and the EU, the risk flags that matter most in practice, and when to involve sanctions counsel.

What authority governs end-use and end-user controls under OFAC?

OFAC administers end-use and end-user obligations through its programme regulations, which implement executive orders issued under IEEPA and, in certain programmes, the Trading with the Enemy Act. The prohibition on facilitating a transaction with a blocked person extends to transactions where the sanctioned party is the final recipient of goods, services, or technology – even when it is not named in the contract. OFAC's guidance makes clear that the "facilitation" prohibition can be engaged by a party anywhere in the distribution chain.

The reach of OFAC's authority here is deliberately broad. US persons are covered by definition. Non-US persons are covered when their transaction involves US-origin items, US-dollar clearing, or US financial institutions. In our cross-border practice, the practical consequence is that a European or Asian distributor of US-origin goods bears a real compliance obligation, not merely a contractual one imposed by its US supplier.

The governing instruments do not require proof of intent for a strict-liability civil violation. Knowledge matters to the severity of a penalty. But a business that failed to ask about end-use cannot escape liability simply by pointing to its ignorance.

Two companion regimes operate alongside OFAC. BIS administers end-use controls under the Export Administration Regulations, with its own end-user list (the Entity List) and its own prohibited end-use categories. These two systems are separate but overlapping: a transaction that clears OFAC may still require a BIS export licence, and vice versa. Our practice covers both, and we regularly advise clients where the two regimes impose concurrent obligations on the same shipment.

The position above covers the standard case. Your facts – the item, the buyer, the route, the ultimate recipient – change the analysis materially.

For an assessment of your exposure under OFAC and BIS, contact Calder & Vance at info@caldervance.com.

Step 1 – Identify the transaction's full distribution chain

The first step in end-use and end-user compliance under OFAC is to map the complete path from seller to ultimate recipient, not just the immediate buyer. This means identifying the consignee, the freight forwarder, the sub-distributor, and the end-user as separately screened parties.

A distribution chain of four or five parties is common in technology and industrial-equipment transactions. OFAC does not limit its interest to the first-tier buyer. The question it asks – and that enforcement staff will ask in a review – is who receives the benefit of the good or service at the end of the chain.

Practical steps at this stage:

  • Obtain from the buyer a written end-user declaration identifying the intended recipient and use-case.
  • Request intermediate consignee information, particularly where goods transit through a third country.
  • Map any intermediary entities against the SDN List, the Consolidated Sanctions List, and the relevant country-programme lists.
  • Identify re-export risk: will the buyer sell on? If so, to whom?

In our experience, technology distributors operating across the Middle East and Southeast Asia consistently underestimate the length of their distribution chains. A product sold to a reseller in one jurisdiction can reach an SDN-listed end-user in another jurisdiction within weeks. That is not a theoretical risk. It is a pattern we see in practice.

Step 2 – Screen the end-user, not just the counterparty

Screening the immediate buyer and stopping there is the single most common compliance gap in end-use and end-user controls under OFAC; every subsequent step depends on having screened the correct party, which is the ultimate recipient. The SDN List, the Consolidated Sanctions List, the Non-SDN lists (including the Non-SDN Menu-Based Sanctions List), and the relevant country-specific lists must all be checked for the end-user.

Screening for end-users raises specific challenges that counterparty screening does not.

First, the end-user may not be disclosed. A buyer that knows its downstream customer is sanctioned has an incentive to conceal it. A business that proceeds without disclosure – even if it did not know – may face an enforcement inquiry. OFAC's guidance on voluntary self-disclosure indicates that failure to identify a sanctioned end-user is treated as an aggravating factor in penalty assessment.

Second, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) applies to end-users as it does to direct counterparties. A named end-user that passes a name-search screen may still be blocked because a listed person holds a controlling stake. Ownership analysis cannot be skipped.

Third, the relevant ownership threshold under OFAC is 50 percent or more in the aggregate. Two listed persons each holding 26 percent of an end-user entity together exceed that threshold. Standard automated screening tools rarely aggregate across multiple listed holders unless specifically configured to do so.

For an assessment of your screening programme's coverage of end-user ownership chains, write to info@caldervance.com.

Step 3 – Obtain and verify end-use certificates and representations

An end-use certificate – a written declaration by the buyer or end-user identifying the specific intended application of the goods or services – is a central tool in end-user compliance under OFAC, and it provides a meaningful defence if it is genuine and followed up.

The key word is "genuine." A certificate signed by the buyer but never verified provides limited protection if the end-use turns out to be different. OFAC's enforcement approach looks at whether a business took reasonable steps to ensure accuracy. That means, at a minimum:

  1. Requiring a certificate that specifies the end-user's name, address, and intended use at the time of sale.
  2. Cross-referencing the stated use-case against the technical characteristics of the item: does a purely civilian end-use make sense for a product with obvious defence applications?
  3. Retaining the certificate in the transaction file for at least five years from the date of the transaction, consistent with OFAC's record-keeping expectations under its programme regulations.
  4. Following up by contractual means where re-export risk is identified: a re-export clause obliging the buyer to seek permission before onward transfer is a standard risk-mitigation tool.

A certificate that raises more questions than it answers – a generic stated use, a buyer that operates in an unrelated sector, a named end-user that cannot be independently verified – is a red flag, not a comfort. In such cases, we regularly advise clients to pause, seek clarification, and where necessary decline the transaction.

Step 4 – Assess red flags and apply enhanced due diligence

Once initial screening and documentation are complete, end-use compliance under OFAC requires an active red-flag analysis: are there indicators that suggest the stated end-use or end-user is not genuine? Red flags do not automatically block a transaction, but they require a documented response.

OFAC and BIS have both issued guidance on red-flag indicators. The following appear repeatedly in enforcement actions and compliance advisories:

  • A buyer who is reluctant to identify the end-user or to provide an end-use certificate.
  • A transaction route that passes through a jurisdiction unrelated to the stated business purpose.
  • Payment terms or payment routing inconsistent with the stated commercial relationship.
  • A buyer whose stated line of business is inconsistent with the goods ordered.
  • Unusually large orders of items with obvious dual-use potential, without a plausible commercial explanation.
  • Prior communications indicating that the goods will be re-sold or transferred to a third party without further disclosure.

Where one or more red flags are present, enhanced due diligence is required. That may mean requesting additional documentation, seeking independent verification of the end-user's identity and operations, escalating the transaction to senior compliance review, or – where the doubt cannot be resolved – declining the transaction entirely.

What it does not mean is proceeding and hoping for the best. OFAC treats wilful blindness as the equivalent of knowledge for the purpose of assessing a violation's severity and for criminal referral to the Department of Justice.

How does the OFAC approach compare with OFSI, the EU, and BIS?

OFAC's end-use and end-user controls sit within a wider international architecture that includes the UK's OFSI, the EU's Council regulations, and BIS's export-control regime under the EAR – and the differences between these regimes are operationally significant for any cross-border business.

OFAC vs BIS. Within the US system, OFAC and BIS operate in parallel. OFAC's prohibitions are status-based: a transaction is prohibited because the end-user is a blocked person or the destination is a comprehensively sanctioned territory. BIS controls are item-based: a transaction is controlled because the export-control classification of the item triggers a licence requirement for the destination or end-use. A business must clear both. Passing OFAC does not imply BIS clearance, and vice versa. Our practice handles both concurrently; see our service on deemed-export and technology controls under BIS and the EAR for detail on the BIS layer.

OFAC vs OFSI. Under OFSI, the UK's ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person) applies to end-users as it does to direct counterparties. The critical difference from OFAC is that OFSI's test extends beyond a mechanical ownership percentage to encompass control: an entity through which a designated person can direct activity may be caught even if the percentage holding is below 50. For businesses with UK nexus selling into markets where OFAC and OFSI designations diverge, the control limb of OFSI's test can capture entities that OFAC's 50 percent rule does not. Our guide on end-use and end-user controls under OFSI addresses this in detail.

OFAC vs the EU. EU Council regulations impose end-use prohibitions through both list-based asset freezes and specific sector or goods restrictions. The EU's ownership-and-control approach mirrors OFSI in applying a control limb alongside an ownership threshold. Additionally, the EU's dual-use export control rules operate on a separate basis from its sanctions regulations, though both may apply to the same transaction. A transaction that passes the EU sanctions screen may still require a licence under the EU's dual-use regime. Practitioners advising on OFAC matters must account for this layer when the transaction has a European dimension.

The practical consequence of this divergence is that a business operating across US, UK, and EU nexus points must maintain a compliance programme that handles three sets of end-use obligations simultaneously. In our cross-border practice, we regularly see firms that have designed their programme for one regime and assumed it covers the others. It rarely does. For a deeper look at the OFSI-specific steps, see also our second OFSI end-use guide.

Common risk flags and when to involve sanctions counsel

Beyond the transactional red flags identified in Step 4, there are structural risk factors that increase a business's end-use exposure under OFAC and that often require counsel rather than a compliance policy adjustment alone.

The first is de-risking pressure. When a financial institution exits a relationship or declines to process a payment because of sanctions exposure concerns, it sometimes happens precisely because the bank has identified an end-user risk that the client has not. A de-risking event is a signal, not merely an inconvenience. It warrants a review of the distribution chain and the end-user population.

The second is corporate restructuring. When a business acquires a distributor or takes on a new reseller network, it inherits that entity's existing customer base and its end-user population. Sanctions due diligence in M&A contexts must therefore include a review of end-user exposure, not just a counterparty screen. We have acted for buyers who discovered post-close that their new subsidiary was supplying to sanctioned end-users through a chain neither party had mapped.

The third is technology change. Items that were not export-controlled or sanctions-sensitive at the time a distribution agreement was signed may become sensitive as dual-use classifications are updated or as new country-specific restrictions are imposed. A review triggered by a BIS classification update should include a parallel OFAC end-use review.

A common myth is that end-use controls only apply to exporters of physical goods. In fact, OFAC's "services" prohibition covers technology transfers, software licensing, and technical assistance regardless of whether any physical item crosses a border. A cloud-based software provider whose platform is accessed by a sanctioned end-user can be in violation even if no goods ever moved.

Counsel should be involved at the point of transaction structuring, not only after a problem arises. Early involvement preserves options: a specific licence application may authorise an otherwise prohibited transaction, or a transaction structure can be adjusted to remove the OFAC nexus. Once an apparent violation has occurred, the options narrow to enforcement defence and voluntary self-disclosure.

Related practices

Frequently asked questions

What are the steps to apply end-use controls under OFAC?
The process has five core steps. First, map the full distribution chain to identify every party from seller to ultimate recipient. Second, screen the end-user – not only the direct buyer – against the SDN List, Consolidated Sanctions List, and relevant programme lists, including an ownership analysis applying the 50 percent aggregate threshold. Third, obtain and retain a written end-use certificate specifying the intended recipient and application. Fourth, conduct a red-flag analysis and apply enhanced due diligence where indicators are present. Fifth, document every step and retain records for at least five years. Where doubt remains after these steps, involve sanctions counsel before proceeding.
What is the most common mistake in end-use and end-user controls?
The most common mistake is screening only the immediate counterparty and stopping there. OFAC's facilitation prohibition extends to any party in the distribution chain who benefits from the good or service, including the ultimate end-user. A business that passes its direct buyer through screening but never asks about downstream recipients has a structural gap in its compliance programme. The second most common error is treating an end-use certificate as a guarantee: a certificate provides a meaningful defence only when it is credible, specific, and followed up with proportionate verification.
How does OFAC differ from other regimes here?
OFAC's end-use test is anchored to the identity and status of the end-user: is that person blocked, or is the destination territory comprehensively sanctioned? BIS's parallel controls are item-based, turning on the export classification of the goods. OFSI and the EU apply an ownership and control test that extends beyond OFAC's mechanical 50 percent ownership threshold to include a control limb: an end-user through which a designated person can direct activity may be caught even without majority ownership. For a business with US, UK, and EU nexus points, all three sets of obligations apply concurrently and require a unified compliance approach.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.