Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFSI

An OFSI matter: encryption export controls in practice

A mid-sized UK software developer receives an order from a distributor based in the Gulf. The product is an enterprise security platform containing strong cryptographic modules. The export control classification sits on the boundary between a controlled and an uncontrolled rating. The compliance team proceeds on the assumption that the cryptographic functionality falls below the relevant threshold. Months later, OFSI writes. The letter references not only a potential financial-sanctions matter but also a referral to the Export Control Joint Unit.

Encryption export controls under UK law are administered by the Export Control Joint Unit (ECJU, the body responsible for granting export licences under the Export Control Order) and governed by the dual-use rules that implement the relevant UK controls. Where an encrypted product reaches a counterparty connected to a designated person, OFSI – the Office of Financial Sanctions Implementation, the UK's financial-sanctions authority – may also become involved. As of April 2026, both authorities are actively scrutinising technology transfers that touch sanctioned networks, and the risk of a dual-referral, combining an export-control breach with a financial-sanctions exposure, is one that many technology businesses underestimate.

This case comment works through an anonymised engagement that raised exactly that dual exposure. It sets out the situation, the legal questions, the regime analysis across UK and EU rules, the options we assessed, the route taken, and what similar businesses should do before the letter arrives.

The situation: how a product classification assumption became a compliance problem

The product at issue was an on-premises security platform whose core functionality included AES-256 encryption. The developer's compliance team had previously reviewed the classification and concluded that, because the software was commercially available and lacked certain military specifications, it sat outside the controlled categories requiring a specific export licence. That conclusion was recorded in an internal memorandum but was not supported by a formal ECJU commodity classification request.

The distributor operated across several Gulf markets. One beneficial owner of the distributor appeared on OFSI's consolidated list of designated persons. That holding was indirect – the owner sat two layers below the contracting entity – and had not surfaced during the developer's counterparty screen, which ran only against the direct contractual party.

The business had also not considered whether the transaction might engage any secondary-sanctions risk. OFAC's rules – the US Treasury's Office of Foreign Assets Control regime – carry extraterritorial reach. Because the software incorporated components produced in the United States, a US nexus existed. That nexus was not analysed before shipment.

When OFSI's letter arrived, the developer faced three simultaneous questions: was the export licence required and had it been obtained; was the financial-sanctions prohibition engaged through the beneficial ownership chain; and did the US nexus require a separate OFAC assessment?

The legal questions: encryption, dual-use controls, and financial sanctions

UK dual-use export controls apply to goods, software, and technology listed in the UK's version of the dual-use control list. Cryptographic software meeting defined parameters – including key length, algorithmic scope, and whether non-standard cryptography is involved – is controlled. The applicable test is technical and precise. A developer's reasonable belief that a product is uncontrolled does not substitute for a formal classification review, and the ECJU's commodity classification service exists precisely to resolve borderline cases.

In this matter, a review commissioned at the outset of our engagement confirmed that the product, as configured and shipped, met the parameters for a controlled classification. No export licence had been issued. That meant the shipment was, on its face, an unlicensed export of controlled technology.

The financial-sanctions question turned on whether the beneficial owner's designation engaged the prohibition on making funds or economic resources available, directly or indirectly, to a designated person. OFSI's ownership and control test – which asks whether a designated person owns or controls the counterparty, considering both formal ownership shares and practical control – is broader than a mechanical percentage calculation. The two-layer indirect holding was sufficient, on the facts, to engage the question. Whether OFSI would conclude that the payment made to the distributor had been made available to the designated owner required a careful reconstruction of the transaction flows.

The EU position was also relevant. The developer had a subsidiary incorporated in an EU member state. That subsidiary had processed supporting documentation for the transaction. EU dual-use rules, and the relevant Council regulation applicable to the designated individual, potentially applied to those acts. The EU general court's approach to indirect dealings with designated persons is well established: the prohibition is not limited to direct transfers.

What is the UK test for encryption export licence requirements?

The UK encryption export control test requires, first, that the product be correctly classified against the controlled list; second, that the destination and end use be assessed for open and specific licence eligibility; and third, that the end user and ultimate beneficial owner be screened against the consolidated list and against ECJU's restricted destinations guidance.

Correct classification is a technical exercise. It requires the developer to map the product's cryptographic functions against the precise parameters in the control list. Where the product sits on the boundary, the ECJU's commodity classification process provides a written determination that carries evidential weight in any subsequent enforcement review. In our experience, that process takes several weeks for a standard submission. Businesses operating on tight delivery schedules often skip it – which is the single most common error we encounter in encryption-related export matters.

Once a controlled classification is confirmed, the question is whether an open general export licence covers the shipment. Several open general licences exist for dual-use technology, including cryptographic products, to specified destinations and for specified end uses. Where the destination or end user falls outside an open general licence's scope, a specific licence is required. A specific licence (a case-by-case authorisation from the ECJU to export a controlled item) takes longer to obtain than many businesses anticipate. The ECJU's published processing standard is a target, not a guarantee, and complex cases take longer.

The cross-regime comparison matters here. Under EU dual-use rules, an equivalent classification exercise is conducted against the EU control list. Since the UK left the EU, the two lists have tracked broadly but not identically. A classification that is uncontrolled under EU rules may be controlled under UK rules, or vice versa. Businesses with operations in both jurisdictions cannot assume a single classification serves both regimes.

How was the OFSI matter and the export-control exposure assessed?

Our first task was to establish, with precision, what had occurred. That meant reconstructing the export documentation, the payment flows, the ownership structure of the distributor, and the technical specification of the product as shipped. We also commissioned, jointly with the client's technical team, a retrospective classification review.

The classification review confirmed the controlled status. The ownership reconstruction confirmed that the beneficial owner was designated and that the holding, while indirect, was sufficient to engage OFSI's enquiry. The payment flows showed that consideration had been transferred to the distributor before the designation was identified. Whether that constituted making funds available to the designated person was a question of fact and law that OFSI would need to resolve.

We advised the client on the voluntary self-disclosure (VSD) route – the process by which a regulated person proactively reports an apparent breach to the relevant authority before enforcement action is initiated. OFSI's enforcement guidance indicates that a timely, co-operative, and complete VSD is a significant mitigating factor in the assessment of a monetary penalty. The same principle applies in BIS enforcement practice in the US: a voluntary self-disclosure submitted promptly and with full supporting documentation is treated materially differently from a breach discovered through third-party information or agency inspection.

Separately, we engaged with the ECJU referral. The ECJU's enforcement process for unlicensed exports involves a parallel assessment to OFSI's. The two authorities share information under statutory gateways, and a matter before one is likely to reach the attention of the other. Managing both tracks simultaneously, with consistent and accurate disclosure, is essential. Inconsistent accounts across the two authorities create a secondary problem that can be harder to resolve than the original breach.

The OFAC dimension required a separate assessment. Because the software incorporated US-origin components and the beneficial owner was separately on OFAC's SDN List – the Specially Designated Nationals and Blocked Persons List, OFAC's primary list of persons whose property is blocked – a US filing was considered. The final determination on whether a voluntary self-disclosure to OFAC was warranted depended on the extent of US nexus, the nature of the re-export, and the applicable general and specific licence landscape. We co-ordinated that assessment with local counsel in the United States.

The route taken and the options considered

The client faced a genuine choice between three approaches. The first was to wait for OFSI and the ECJU to progress their enquiries and respond reactively. The second was to initiate voluntary self-disclosure to both UK authorities and, in parallel, instruct local US counsel on the OFAC position. The third was a hybrid: immediate VSD to OFSI and the ECJU, with the OFAC question parked pending a more complete US nexus analysis.

The wait-and-see approach was not recommended. OFSI's enforcement guidance is explicit that co-operation and self-reporting weigh in favour of a reduced penalty. A business that waits for a formal enforcement notice loses the benefit of the timing element. In our experience, the window between first regulatory contact and the escalation of informal enquiries into a formal enforcement track is short and unpredictable. Preserving optionality means acting early.

We recommended the second option: full and simultaneous VSD to OFSI and the ECJU, with a co-ordinated OFAC analysis running in parallel. The VSD package included the reconstruction of the ownership chain, the technical classification memorandum, the payment and documentation records, and a root-cause analysis explaining how the classification error arose and what remediation steps the business had taken.

The remediation programme – which we designed jointly with the client's compliance function – covered three areas: reclassification of the entire product range against both the UK and EU control lists; redesign of the counterparty screening process to include multi-layer beneficial ownership analysis, not only the direct contractual counterparty; and introduction of a mandatory ECJU commodity classification request for any product whose cryptographic specification places it near a control parameter boundary.

In a recent matter of this type, a technology business faced a parallel OFSI and ECJU enquiry arising from an unclassified cryptographic export to a distributor with a sanctioned beneficial owner. We prepared the voluntary self-disclosure package, managed the correspondence with both authorities, and coordinated the US nexus assessment with local counsel. The matter proceeded through the regulatory process. We do not state outcomes as guarantees, and each engagement turns on its own facts.

Risk flags for technology exporters: when does an encryption deal carry a dual exposure?

Technology exporters should treat the following as immediate prompts for a classification and sanctions review, before a transaction closes.

  • The product contains cryptographic functionality above a defined key-length threshold, or uses non-standard algorithms, or is designed for network infrastructure, payment systems, or communications platforms – all of which attract closer scrutiny under the control list parameters.
  • The end customer or any intermediate distributor operates in a market associated with elevated sanctions risk, regardless of whether the immediate counterparty appears on any list.
  • The beneficial ownership of the counterparty has not been mapped beyond the first corporate layer. OFSI's ownership and control test, and the equivalent EU test, capture indirect holdings and practical control, not merely direct shareholding.
  • The product incorporates US-origin components or US-origin technology. That nexus can engage OFAC's rules independently of the UK and EU positions, and the extraterritorial reach of US controls is broader than many technology developers appreciate.
  • The compliance team's classification determination relies on a prior review rather than a live assessment. Cryptographic control parameters have been amended over recent regulatory cycles, and a product that was uncontrolled two years ago may be controlled today.
  • There is commercial pressure to ship before the compliance review is complete. That pressure, in our experience, is the proximate cause of a large proportion of the encryption export matters we handle.

Does your compliance programme require a formal ECJU commodity classification for borderline cryptographic products? And does your counterparty screen reach the beneficial owner, not just the contracting entity? If the answer to either question is no, the risk profile of your export pipeline is higher than it appears.

The lesson: classification, screening, and the dual-track risk

The core lesson from this engagement is that encryption export controls and financial sanctions are not parallel risks that can be assessed independently. They interact. A product shipped to a counterparty with a sanctioned beneficial owner is simultaneously a potential export-control breach and a potential sanctions violation. The authorities administer those regimes under different statutory powers, but they share information and they escalate in parallel.

A common assumption in technology businesses is that encryption products that are commercially available, widely used, or marketed without restriction are automatically free of export controls. That assumption is wrong. Commercial availability may be relevant to certain open general licence conditions, but it does not determine the classification. The classification is a technical exercise against the control list, and it must be done properly.

A second assumption is that financial-sanctions screening applies only to the direct contractual counterparty. That is equally wrong. OFSI's test extends to the beneficial owner. EU law applies the same principle. The 50 percent ownership threshold under OFAC's rules – the 50 percent rule, which treats any entity owned 50 percent or more in the aggregate by blocked persons as itself blocked – reaches through multiple layers of ownership. Multi-layer screening is not optional. It is the baseline.

The interaction between UK, EU, and US controls also means that a compliance programme designed around one regime will have gaps when a transaction touches the others. Where UK and EU positions diverge on classification or licensing, the stricter prohibition governs. Where a US nexus exists, a separate OFAC and BIS assessment is required, not an assumption of equivalence.

Related practices

Frequently asked questions

What went wrong in this encryption export controls matter?
The business shipped a product containing controlled cryptographic functionality without obtaining the required ECJU export licence, relying on an internal classification memorandum that had not been formally validated. Simultaneously, the counterparty's beneficial owner was a person designated by OFSI, a connection that was missed because the beneficial ownership screen stopped at the direct contractual party. The combination of an unlicensed export and a financial-sanctions nexus produced a dual-track regulatory exposure before OFSI and the ECJU.
How was the OFSI issue resolved?
The engagement focused on voluntary self-disclosure to both OFSI and the ECJU, supported by a complete reconstruction of the ownership chain, the transaction flows, and the technical classification. A parallel OFAC assessment was co-ordinated with local US counsel. A root-cause analysis and a remediation programme – covering reclassification, multi-layer screening, and mandatory ECJU classification requests for borderline cryptographic products – were prepared and presented as part of the disclosure package. We do not state the regulatory outcome as a guarantee; each matter turns on its own facts.
What is the lesson for similar businesses?
Technology businesses exporting encryption products should treat a formal ECJU commodity classification as mandatory for any product near a control parameter boundary, not as optional due diligence. Counterparty screens must reach the beneficial owner across multiple corporate layers, not only the direct contracting entity. Where a product incorporates US-origin components, a separate OFAC and BIS assessment is required. And where a compliance concern arises, early voluntary self-disclosure consistently produces better outcomes than waiting for a regulatory notice.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.