A trading company buys precision components in one jurisdiction, ships them to a subsidiary in a second, and re-exports them to a customer in a third. Every leg of that journey may trigger a fresh set of authorisation requirements – not just in the country of origin, but in each jurisdiction whose rules follow the goods. For a business managing a multi-country supply chain, that is not a theoretical risk. It is an operational reality that materialises at the border, in the bank, and in the compliance audit.
Re-export controls and extraterritorial reach are the mechanism by which a country extends its export-control rules beyond its own borders. The primary regime is the US Export Administration Regulations ("the EAR"), administered by the Bureau of Industry and Security ("BIS"), which applies US-origin content, technology, and software – and items produced with US equipment – wherever in the world they travel. The EU, the UK, and other regimes carry comparable, if narrower, extraterritorial provisions. Non-compliance can result in denial orders, debarment from US markets, and significant civil and criminal exposure.
This guide walks through the re-export and extraterritoriality analysis step by step, covering the US EAR, the EU dual-use rules, the UK Export Control Order, and the interaction between them – so that compliance teams and supply-chain managers can map their obligations before the next shipment moves.
Step 1: Identify whether US-origin content or technology is in the item
The first question in any re-export analysis is whether the item, software, or technology in question has US-origin content, was produced using US technology, or was manufactured on US-controlled equipment – because, if so, the EAR follows it regardless of where the re-export originates. BIS administers this through the de minimis rule and the foreign-direct product rule ("FDPR"), both of which extend US jurisdiction over non-US goods.
Under the de minimis rule, a foreign-made item that incorporates controlled US-origin content above a defined value threshold remains subject to the EAR when re-exported. The FDPR goes further: it can subject a foreign-produced item to the EAR when that item is the direct product of US-origin technology or software, or when it is produced by a plant that is itself a direct product of such technology. As of mid-2026, BIS has expanded FDPR coverage in specific country contexts; verify the current scope before relying on historical assumptions.
In our practice, the most common oversight at this stage is treating a product as "not US" because the manufacturing facility is located outside the United States. That assumption is incorrect wherever US-origin machinery or know-how is embedded in the production process. The classification analysis must go to the inputs, not only to the geography of manufacture.
Practical action at Step 1:
- Request a bill of materials or technology origin declaration from the upstream supplier.
- Identify whether any US-origin software or technology was used in the design or production process.
- Confirm whether any equipment used in production is itself controlled US technology.
- Document the outcome so that each subsequent re-export leg has a traceable basis.
Step 2: Classify the item under the applicable control list
Once origin is confirmed, the item must be classified against the relevant control list in each jurisdiction whose rules apply. Under the EAR, an item's Export Control Classification Number ("ECCN") determines which countries, end-uses, and end-users require a licence. An ECCN is a five-character alphanumeric code on the Commerce Control List; items that fall outside a specific ECCN are designated "EAR99" and generally carry the lowest re-export burden, though they remain subject to restrictions when the destination, end-user, or end-use is sanctioned or controlled.
The EU dual-use regime, operating under the relevant Council Regulation on dual-use items, maintains a control list that largely mirrors the Wassenaar Arrangement and other multilateral export-control regimes. The UK, following the Trade Control and Export of Goods framework administered by the Export Control Joint Unit ("ECJU"), maintains its own list, which was derived from the EU list at the point of the UK's departure from the EU but has since been updated independently. Japan's export controls, administered under the Foreign Exchange and Foreign Trade Act, the Singapore Strategic Goods Control Act, and the UAE's dual-use controls each run comparable lists aligned to international arrangements.
Where the same item is controlled under two or more regimes simultaneously, the stricter prohibition governs each leg. A component may be EAR99 but controlled under the EU list, or vice versa. Classification must be run against every list whose jurisdiction is engaged, not only the most familiar one.
Practical action at Step 2:
- Obtain or validate the ECCN for each controlled item in the supply chain.
- Check the item against the EU, UK, and any other applicable national control list.
- Record the classification in the trade compliance file for each product line.
- Update classifications when the item's specification or software version changes.
Step 3: Determine the destination, end-user, and end-use risk
Classification alone does not determine the licensing outcome. The EAR's Country Chart and the Commerce Country Groups assign different licence requirements to the same ECCN depending on destination and the stated reason for control – national security, nuclear non-proliferation, missile technology, chemical and biological weapons, crime control, and others. A re-export to a close ally may require no licence; the same item to a different destination may require a specific licence or be subject to a policy of denial.
End-user and end-use checks are equally critical. BIS maintains the Entity List, the Denied Persons List, and the Unverified List, among others. An item destined for a listed entity – or where there are red flags that the stated end-use is a pretext – requires heightened scrutiny. The EAR's "know" and "reason to know" standards impose positive obligations to investigate when circumstances suggest diversion. Red flags include unusual payment terms, requests to omit technical data from documentation, destinations that are inconsistent with the buyer's business, and requests for items that exceed the buyer's apparent technical capacity.
Under the EU regime, end-use controls operate through an additional layer: the catch-all control. Where an exporter knows or has been informed by an authority that an item, even if not listed, is or may be intended for use in connection with weapons of mass destruction or certain military programmes, a licence may still be required. The UK's export-control regime contains analogous catch-all provisions, administered through ECJU licensing decisions.
We regularly advise clients on end-use audit programmes and escalation procedures. A single unresolved red flag, if it is later shown to have been known to the exporter and ignored, can transform a civil exposure into a criminal referral.
Practical action at Step 3:
- Screen every end-user against the BIS lists, the OFAC Specially Designated Nationals list, the EU Consolidated List, the UN Consolidated List, and any other applicable list.
- Evaluate the end-use against the catch-all thresholds in all engaged regimes.
- Document all red flags identified and the steps taken to resolve or escalate them.
- Implement a defined escalation path for unresolved concerns before release of goods.
The position above covers the standard case. Your facts – the item's origin, the supply-chain structure, the destination country, and the end-user profile – will change the analysis at each step. For a rapid preliminary assessment of re-export exposure in your supply chain, contact Calder & Vance at info@caldervance.com.
Step 4: Assess whether a licence exception or authorisation applies
If classification and destination analysis establish that a licence is required, the next step is to determine whether an exception or authorisation covers the re-export. Under the EAR, BIS publishes a set of named licence exceptions – such as those for technology and software under restriction, for items temporarily exported for repair, or for certain government end-uses – that may permit the re-export without a formal application. Each exception carries its own eligibility conditions, record-keeping requirements, and geographic or end-user limitations.
The EU regime operates through a system of Union General Export Authorisations ("EU GEAs"), which authorise exports to specified destinations without a case-by-case licence, and national general authorisations issued by individual member states. Outside these authorisations, an individual licence from the relevant national authority is required. Under the UK regime, ECJU issues Open Individual Export Licences, Open General Export Licences ("OGELs"), and Standard Individual Export Licences. An OGEL may cover the re-export where the destination, item, and end-use satisfy the OGEL conditions – but the exporter must register to use the OGEL and maintain records of each shipment made under it.
A common error at this stage is treating a licence exception or general authorisation as a blanket permission. Each has conditions. Shipping to a destination covered by an OGEL but to an entity on a denial list does not make the shipment permissible. And using a licence exception under the EAR while the re-export also triggers a requirement under the EU or UK regime means two sets of conditions must be satisfied simultaneously.
Practical action at Step 4:
- Check all applicable EAR licence exceptions against the specific facts of the re-export.
- Review available EU GEAs and UK OGELs for coverage of the destination and item.
- Confirm that the end-user and end-use do not disqualify the exception or authorisation.
- If no exception applies, begin the specific-licence application process early – processing times vary and can be a matter of weeks to months depending on the regime and the nature of the item.
Step 5: Apply the multi-regime matrix and identify divergences
Where a re-export chain crosses multiple jurisdictions, the compliance obligation is not a single licence requirement but a matrix of requirements that must be satisfied concurrently. This is where cross-border re-export analysis becomes genuinely difficult, and where the risk of unintentional breach is highest.
Consider a common fact pattern: a US-origin component, classified at a specific ECCN, is incorporated into a finished product in Germany, shipped to a distribution hub in Singapore, and re-exported to a buyer in the Gulf. That chain engages the EAR (US-origin content throughout), the EU dual-use regime (point of incorporation and first export from the EU), the Singapore Strategic Goods Control Act (point of re-export), and potentially the UAE controls and OFAC sanctions (destination). Each regime has its own licence-trigger test, its own authorisation architecture, and its own enforcement posture. Satisfying one does not satisfy the others.
The divergences between the US and EU regimes in particular create practical tension. The EAR is extraterritorial by design: it follows the goods wherever they go. The EU regime applies at the point of export from the EU; it does not follow the goods after they leave EU territory in the same way – though catch-all and end-use provisions may still bite. The UK regime, post-departure from the EU, is broadly aligned to the EU list but administered independently, and ECJU decision practice has diverged in some areas from EU member-state practice. Japan, Singapore, and the UAE each operate their own classification and licensing mechanisms, which may require a domestic filing in the transit or destination country quite separately from the origin-country authorisation.
In our cross-border practice, we advise clients to map this matrix at the transaction-design stage, not at the point of shipment. By the time goods are at the port, the options narrow significantly. Have you identified which regimes each leg of your supply chain engages?
A related complexity is the interaction between export controls and financial sanctions. A shipment that clears the EAR licensing requirements may still be blocked because the buyer appears on the OFAC SDN List (OFAC's list of Specially Designated Nationals and blocked persons) or the EU Consolidated List. The two control systems operate independently and must both be cleared.
For cross-border matters engaging both US and non-US regimes, see our related guidance on deemed exports and technology controls: Deemed export and technology controls under BIS and the EAR. For EU-specific extraterritoriality analysis, see Re-export and extraterritoriality under EU dual-use rules and EU re-export controls: a further guide.
Step 6: Establish record-keeping, monitoring, and escalation protocols
A well-functioning re-export compliance programme does not end at the point of authorisation. Each shipment must be documented, the authorisation or exception basis must be on file, and the programme must be reviewed when the regulatory position changes – which, in the export-controls space, can happen quickly and without extended notice.
Under the EAR, exporters and re-exporters are required to maintain records of all export-related transactions for a defined period; the current requirement runs to five years from the date of the export, re-export, or transfer. Records must include the licence, the exception used, the shipping documentation, and any supporting end-use or end-user certificates. OFSI's enforcement guidance imposes comparable record-keeping obligations in the financial-sanctions context, and EU dual-use regulations carry their own retention requirements. Verify the specific retention period for each applicable regime, as requirements can differ.
Monitoring obligations do not stop at the point of sale. Post-shipment verification – confirming that the goods reached the stated end-user and were used for the stated purpose – is a recognised best practice and, in some circumstances, a regulatory requirement. BIS's End-User Review Committee and national authorities in the EU and UK may require or request post-shipment verification for sensitive items.
Escalation protocols are the operational mechanism that converts a red flag into a documented compliance decision. Every export compliance programme should have a defined path from the front-line logistics or sales team to the compliance officer and, where the question is genuinely uncertain, to external counsel. A voluntary self-disclosure ("VSD") to the relevant authority – in the US, to BIS or OFAC depending on the nature of the apparent violation – can be a significant mitigating factor in penalty determination, but only when it is made promptly, completely, and in accordance with the applicable procedure.
Practical action at Step 6:
- Implement a document-retention system covering all export-related records for the required period across each applicable regime.
- Establish post-shipment verification procedures for sensitive or controlled items.
- Maintain a written escalation policy that specifies the steps from front-line identification to compliance review to external advice.
- Review the programme at least annually, or when a material change occurs in the regulatory position of any engaged regime.
Common risk flags and when to involve external counsel
Certain patterns in a re-export transaction should prompt an immediate compliance review, not a post-shipment audit. The following are the flags that, in our experience, most consistently precede a compliance failure or enforcement inquiry.
A request to divert or re-route a shipment after the original documentation has been completed is one of the strongest indicators of diversion risk. The EAR and the EU and UK regimes all contemplate post-export controls, and an exporter who re-routes a shipment to an unlicensed destination on a buyer's instruction – without re-clearing the authorisation – has likely violated both the origin-country controls and any applicable re-export rules at the new destination.
Inconsistency between the buyer's stated business and the technical specification of the goods requested is a classic red flag. An agricultural company requesting precision navigation components, or a retail distributor seeking items rated for extreme-temperature industrial use, should prompt a know-your-customer review before the order is processed.
The involvement of a third-country intermediary whose role in the transaction is not commercially logical – a broker who neither adds value nor has obvious logistics capacity – is a recognised diversion indicator. BIS and the EU authorities both publish guidance on red flags, and compliance teams should screen against these before approving new intermediary relationships.
A common objection from businesses at this stage is that export-controls compliance is only relevant for military or dual-use technology companies. That is not correct. Any business that moves goods with US-origin content, technology, or software through its supply chain is potentially within the EAR's reach, regardless of sector. The automotive, life-sciences, telecommunications, and energy sectors all routinely engage re-export obligations without always recognising it.
If a transaction has already been flagged, or a filing has been refused or queried by an authority, an early review of the position can preserve options that narrow as time passes. For a confidential review of a potential breach or a re-export compliance gap, contact Calder & Vance at info@caldervance.com.
Related practices