A trading company ships industrial equipment to a buyer in a third market. The buyer's name is clean. The ultimate end-user, however, turns out to be a defence entity sitting on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The shipment is now a sanctions violation – even though the direct counterparty was never designated. This is the defining problem of end-use and end-user controls under OFAC: the identity of the direct buyer is only part of the analysis.
As of April 2026, OFAC requires businesses to look beyond the contractual counterparty and assess who will ultimately receive, use, or benefit from the goods, technology, or services being transferred. The obligation is not purely formal. A transaction with a clean buyer can still violate OFAC's rules if the end-user is a blocked person or the end-use serves a prohibited purpose. OFAC's standard for this analysis is rooted in its "reason to know" doctrine under IEEPA and the relevant programme regulations.
This guide sets out the governing authority, the practical test businesses must apply, how the OFAC analysis compares with BIS controls and allied regimes, the most common failures, and when to engage specialist counsel.
Step 1: Understand the governing authority and what it requires
OFAC administers end-use and end-user controls through programme-specific regulations issued under IEEPA, TWEA, and related statutory authorities; the precise scope of any prohibition turns on the relevant programme, but the analytical architecture is consistent across regimes.
The foundational obligation is this: a US person, or any person conducting a transaction with a US nexus, must not facilitate a transfer of goods, technology, funds, or services if that transfer would benefit a blocked person – regardless of whether the direct counterparty is itself designated. OFAC treats facilitation broadly. Arranging, approving, financing, or insuring a transaction can all engage the prohibition if a blocked end-user is the downstream beneficiary.
The "reason to know" standard is the operative test. A business need not have actual, confirmed knowledge of an illegal end-use or a blocked end-user to be liable. If the circumstances surrounding a transaction should have prompted further enquiry – and that enquiry was not conducted – OFAC may find a violation. Red-flag awareness, not wilful blindness, is the minimum floor. In our experience, the firms most exposed are those that treat the "reason to know" standard as equivalent to a formal notification requirement; it is not.
The practical consequence is that a transaction-level review of the direct buyer is necessary but never sufficient. Businesses must examine the ownership chain, the proposed application of the goods, the route to delivery, and the identity of any intermediate parties. A multi-tiered analysis – not a single-point screen – is required.
Step 2: Identify the correct end-user and map the delivery chain
Correctly identifying the end-user means tracing who will take physical or functional control of the goods or technology and in what capacity – not who has signed the purchase order. This is the step most frequently omitted in practice.
Start by mapping every party in the delivery chain: the buyer, any freight forwarder, the importer of record in the destination country, any disclosed sub-buyer, and the entity that will ultimately operate or consume the goods. Each node in the chain requires screening against OFAC's SDN List, the Non-SDN designations relevant to the programme, and the UN Consolidated List. The Consolidated List is a useful cross-reference; a name appearing there often presages an OFAC designation even where the US-programme designation has not yet been made.
Ownership matters here as much as it does in a standard counterparty screen. OFAC's 50 percent rule (the rule treating entities owned 50 percent or more in aggregate by blocked persons as themselves blocked) applies to end-users as it does to any other counterparty. An entity owned 50 percent or more by a designated person is blocked as a matter of law, whether or not it appears by name on any list. If a downstream buyer is an unlisted subsidiary of a designated parent, the transaction is prohibited nonetheless.
Consider the route as an independent risk vector. Goods transiting through a third country, handled by a logistics agent with links to a designated entity, can generate its own violation. Mapping the route is not a formality; in our practice we have seen transactions structured with a clean buyer and a clean end-user become non-compliant solely because of the freight corridor chosen.
Step 3: Assess the end-use and evaluate red flags
After confirming the identity of each party, the next analytical step is to assess the proposed end-use and weigh any red flags that might indicate the stated purpose is not the actual one.
OFAC does not publish a single codified list of prohibited end-uses in the way that BIS maintains a list of controlled end-uses under the EAR. Instead, the prohibition derives from the underlying programme: supplying goods for use in a sanctioned activity, or for the benefit of a blocked person or blocked programme, is prohibited. The question is therefore whether the goods or technology, when deployed for their stated purpose by the stated end-user, would generate a benefit to a blocked person or a prohibited programme.
Red flags do not create an automatic finding of violation, but they trigger a heightened duty to enquire. OFAC and BIS maintain overlapping lists of the circumstances that constitute red flags; both agencies treat failure to respond to red flags as aggravating in an enforcement context. Common red flags include:
- A buyer or end-user unwilling to state the intended end-use in writing.
- A requested product or specification inconsistent with the buyer's stated business.
- A delivery destination that is inconsistent with the buyer's location or business profile.
- Payment through an unrelated third-party, or in a currency inconsistent with the transaction.
- A last-minute change in the shipping route, the receiving entity, or the payment method.
- An intermediary who declines to identify the ultimate consignee.
The presence of one or more of these indicators does not mean the transaction is prohibited. It means the business cannot proceed without resolving the flag to a reasonable standard of comfort. What does "resolving" look like? Written confirmation of end-use, enhanced due diligence on the end-user's ownership chain, an independent reference check, or, where doubt remains, a specific-licence application to OFAC.
How does OFAC compare with BIS end-use controls?
OFAC and BIS both regulate end-use and end-user, but through distinct legal mechanisms; understanding the overlap – and the gap – is essential for any business exporting goods with a US nexus.
BIS controls under the EAR (the Export Administration Regulations) are item-specific and tied to the ECCN (Export Control Classification Number under the US Commerce Control List). A given item with a particular ECCN may require a licence for export to a specified destination or end-user category, and BIS maintains specific prohibitions on stated end-uses – most notably controls on items destined for weapons programmes. BIS's Entity List identifies parties for whom a licence is required regardless of item classification.
OFAC's end-use analysis is not item-specific in the same way. It is programme-specific and person-specific: the prohibition derives from who benefits, not from what the item is. A common misunderstanding – the most important to correct – is that an OFAC clean does not give BIS clearance, and vice versa. A transaction can be BIS-clean (no ECCN-triggered licence required) and OFAC-prohibited (because the end-user is a blocked person). Both analyses must run in parallel, not sequentially.
The United Kingdom's regime under OFSI and the Export Control Order administered by ECJU adds a third layer for businesses with UK operations or UK-manufactured goods. OFSI's end-user analysis is broadly analogous to OFAC's: it asks whether making funds or economic resources available, directly or indirectly, would benefit a designated person. The ownership and control test under UK sanctions (the test for whether a non-listed entity is caught through a listed person) uses both a 50 percent ownership prong and a separate control assessment. A company not owned 50 percent by a designated person may nonetheless be caught if that person exercises effective control. This is a material divergence from OFAC's purely mechanical ownership test.
The EU regime similarly combines an ownership threshold with a control assessment under the relevant Council Regulations. Practitioners advising on cross-border transactions must assess all three simultaneously; an analysis limited to a single regime will routinely miss exposure.
What are the most significant risk flags and compliance failures?
In our cross-border practice, a small number of recurring failures account for the majority of end-use and end-user violations that reach the enforcement stage.
The first is treating list-screening as the whole of the analysis. A fully automated screen against the SDN List answers one question: is this named entity designated? It does not answer whether a non-listed subsidiary is caught by the 50 percent rule, whether an intermediate freight forwarder has SDN links, or whether the end-use itself generates a prohibited benefit. Screening is the start, not the end.
The second failure is inadequate contractual documentation. A purchase order that specifies an end-use is not, by itself, an end-use undertaking that satisfies the "reason to know" standard. Businesses that rely on representations in sales documents without independent verification are poorly positioned in an enforcement context. Effective end-use undertakings are enforceable, specific, and verifiable against the actual delivery evidence.
The third is the myth that a voluntary self-disclosure – a VSD (voluntary self-disclosure to a regulator) – is always the right response to a potential violation. A VSD can be a powerful mitigating tool, and OFAC's enforcement guidance gives substantial credit for it. But VSD is not always appropriate, and filing without proper legal assessment of the apparent violation can waive protections, lock in admissions, or escalate a matter that might otherwise resolve at a lower level. Always obtain legal advice before deciding whether to file.
A fourth and underappreciated failure is the absence of end-use follow-up once goods are delivered. An end-use commitment given at the time of sale does not close the risk. If the exporter subsequently receives information that the goods have been re-exported to a prohibited destination, or that the end-user has transferred them to a third party without consent, the legal exposure continues. Programme contracts and distribution agreements should include post-delivery reporting obligations and audit rights.
When should a business seek specialist counsel on end-use controls?
Earlier than most businesses think. The questions that appear manageable at the pre-contractual stage can become enforcement-level problems with surprising speed once goods have moved.
Counsel should be engaged – not merely consulted – when: a transaction involves a party from or in a jurisdiction subject to comprehensive OFAC sanctions; when the goods or technology have a plausible dual-use application; when a screening hit is returned and its accuracy or relevance is uncertain; when a freight forwarder, sub-buyer, or agent declines to provide information about the end-user; or when post-delivery reporting suggests goods have been diverted. In each of these scenarios, the business's handling of the next step – the next communication, the next due diligence request, the next decision on whether to proceed – shapes OFAC's view of culpability if the matter later comes to enforcement.
The position above covers the standard analysis. Your specific facts – the goods, the route, the delivery chain, the applicable programme – change the assessment materially.
For an assessment of your end-use and end-user exposure under OFAC, or for advice on how to handle a red flag or a potential violation, contact Calder & Vance at info@caldervance.com.
Interaction with BIS deemed-export controls and the cross-border picture
A related dimension of end-user control that businesses often overlook is the BIS deemed-export rule. Under the EAR, a "deemed export" occurs when controlled technology is released to a foreign national within the United States; that release is treated as an export to the foreign national's country of most recent citizenship or nationality. The rule means that an end-user analysis cannot be confined to the point of physical shipment.
For businesses with foreign nationals in their research, engineering, or product teams, a deemed-export analysis is required whenever those individuals have access to technology with a sufficiently high ECCN. The analysis proceeds in two parts: classification of the technology, and then assessment of the individual's national status against the applicable country destinations. OFAC may intersect here when the individual's nationality corresponds to a comprehensively sanctioned jurisdiction.
We regularly advise exporters, manufacturers, and technology companies on how to structure internal controls that satisfy both the BIS deemed-export obligation and OFAC's end-user standard in a single, coherent compliance programme. The two analyses share data requirements but are legally distinct, and a programme designed for one will not necessarily capture the other.
For businesses exporting goods or technology with a UK origin, ECJU's end-user undertaking requirements – including in some cases government-to-government assurances – add a further procedural layer. Switzerland's SECO and Canada's GAC each maintain their own end-user-certificate requirements, which are not automatically satisfied by a BIS or OFAC-equivalent analysis. Cross-border businesses should not assume that satisfaction of one regime's end-user requirement discharges the others.
If a transaction has already been flagged by a freight partner, a bank, or an internal compliance review, an early specialist review can preserve options that narrow with time.
To discuss a potential licence application, a voluntary self-disclosure question, or a cross-regime end-user problem, write to Calder & Vance at info@caldervance.com.
Related practices
- Deemed export and technology controls under BIS and the EAR – classification, licence assessment, and compliance design for technology with foreign-national exposure.
- End-use and end-user controls: licensing and authorisation routes – when and how to apply for an OFAC specific licence for an otherwise-restricted end-use.
- End-use controls in cross-border transactions: diligence and structuring – screening, contractual protections, and post-delivery monitoring for multi-regime transactions.