Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · EU

Criminal exposure in export-control cases under EU: the essentials

A logistics director at a mid-sized European technology group receives a routine port-authority query. A consignment of dual-use components, cleared internally as low-risk, has been detained pending licence verification. The items were shipped without authorisation. Within days, the query becomes a criminal investigation referral. How did a compliance gap become a matter for prosecutors?

Criminal exposure in export-control cases under EU rules arises when a natural or legal person exports, transfers, or brokers controlled goods without the required authorisation, or provides false information to obtain one. The governing instruments are the EU dual-use regulation and the relevant Council regulations on sanctions, with criminal enforcement delegated to member-state prosecutors under their national implementing legislation. Penalties range from substantial fines to custodial sentences for individuals, and the exposure reaches corporate officers personally.

This briefing sets out the legal basis for criminal liability, how enforcement is structured across the EU, where the exposure diverges from the UK and US positions, and what a business or individual facing an investigation should do first.

What is the legal basis for criminal liability in EU export-control cases?

Criminal liability in EU export-control cases rests on two overlapping pillars: the EU dual-use regulation, which requires authorisation for exports of goods with both civilian and military potential, and the relevant Council regulations that impose autonomous trade restrictions and asset-freeze measures. Each pillar delegates criminal enforcement to member states, which means the offence definition, sentencing range, and prosecutorial approach vary across the EU's twenty-seven jurisdictions – but the trigger for liability is set at Union level.

The core prohibition is exporting a controlled item without the authorisation the EU dual-use regulation requires, or in breach of a restriction imposed by a Council regulation. Brokering and transit controls extend the reach: a broker facilitating a controlled transfer from a third country to another third country may be caught even if no EU-origin goods cross an EU border. This extraterritorial dimension is often underestimated.

Intent and knowledge are central to criminal liability. Prosecutors must generally show that the accused knew, or ought to have known, that the goods required authorisation and that no authorisation had been obtained. Wilful blindness – structuring due diligence to avoid finding a problem – is treated in most member-state systems as equivalent to actual knowledge. In our experience, this is precisely where corporate officers face the greatest personal exposure: the question is not only what they knew but what their position required them to know.

Who administers and prosecutes these cases at member-state level?

No single EU agency prosecutes export-control violations as criminal matters. Enforcement is divided between two layers: the administrative layer, which sits with national licensing and customs authorities and the European Commission (in its role overseeing the dual-use regulation), and the criminal layer, which sits entirely with member-state prosecutors, police, and customs intelligence units. The split creates real complexity for businesses operating across multiple EU member states.

At the administrative level, customs authorities are the first line of detection. They screen export declarations against the EU's Common Customs Tariff codes and the control lists, identify goods that may require a licence, and can detain consignments pending verification. Where they find a violation, they may refer the file to prosecutors or pursue administrative penalties directly, depending on national law.

Criminal referrals typically follow one of three routes: a customs authority identifies a shipment and refers; a licensing authority discovers that a trader misrepresented goods on an application; or an intelligence-led investigation, sometimes involving coordination through Europol, identifies a pattern of systematic violations. The involvement of Europol in serious cases introduces a pan-EU intelligence dimension that a company facing a single-member-state inquiry may not anticipate.

For businesses with operations in several member states, the risk of parallel proceedings is real. A shipment originating in one member state, transiting through a second, and involving a broker established in a third can produce three separate criminal referrals under three different national codes. We regularly advise on how to manage that multi-jurisdiction exposure from a single point of oversight.

What conduct creates the sharpest criminal risk?

Four categories of conduct consistently produce the most serious criminal exposure under EU export-control rules. Understanding them is the starting point for any risk assessment.

The first is unlicensed export of dual-use goods (items that have legitimate civilian applications but can also be used for military, surveillance, or weapons-of-mass-destruction purposes). The EU dual-use regulation sets a control list; items on that list require an authorisation unless a specific exemption applies. Shipping without checking classification status is the most common single source of criminal exposure across the EU.

The second is misrepresentation on a licence application. Providing false or misleading information about the end-user, end-use, or destination – or omitting a material fact – is a standalone criminal offence in every member state that has implemented the directive on criminal sanctions for breaches of Union restrictive measures. It can attract a more serious charge than the underlying export offence itself.

The third is breach of sanctions-related trade restrictions. The relevant Council regulations prohibit not just financial dealings but also the sale, supply, and transfer of certain goods and technology to designated persons or territories. Where a person does so knowing the restriction applies, the conduct is both a sanctions violation and, in an increasing number of member states, a criminal export offence.

The fourth – and most rapidly developing – is circumvention-adjacent conduct: assisting a third party to export controlled items through a jurisdiction with weaker controls, or structuring a transaction to pass through an intermediate country that is not subject to the same restriction. This conduct is now addressed directly in the relevant Council regulations, and several member states have legislated criminal offences for it specifically. The firm does not advise on such conduct; we set it out here so that compliance teams can identify and report it.

How does EU criminal exposure compare with the UK and US positions?

The EU position is structurally distinct from both the UK and US approaches, and those differences affect how a cross-border group should structure its defence and its compliance response.

Under the UK regime, OFSI (the Office of Financial Sanctions Implementation) handles financial-sanctions enforcement administratively; criminal export-control cases are handled by the King's Bench Division via the Export Control Joint Unit (ECJU) and, for serious cases, the Crown Prosecution Service. The UK operates a single national enforcement authority for each function. That means a business with a UK nexus is dealing with a known counterpart on a predictable procedural footing. The EU offers no equivalent single counterpart – which is why early coordination across relevant member-state authorities matters so much in a multi-country matter.

The United States position, administered by BIS for export controls and OFAC for sanctions, allows for substantial deference to voluntary self-disclosure (VSD – a proactive report to the regulator before the violation is detected externally). OFAC's published enforcement guidelines treat a VSD as a significant mitigating factor. BIS operates a parallel VSD programme. By contrast, EU member states vary considerably in how they treat a voluntary report: some afford meaningful mitigation, others treat it primarily as a source of evidence for prosecution. Before a business decides to self-report to an EU customs or licensing authority, it needs advice on the specific member state's enforcement approach.

There is also an important divergence in extraterritorial reach. US secondary-sanctions risk can attach to non-US persons for conduct that has no US nexus, through the breadth of IEEPA-based programmes. EU extraterritorial reach is narrower, operating primarily through Union-citizenship and Union-territorial connections, and through the brokering controls that catch EU-established brokers regardless of where the transaction occurs. A business with simultaneous US and EU exposure must assess both simultaneously – the regimes do not run on a single timeline.

For detailed analysis of the UK criminal exposure position, see our Criminal exposure in export-control cases under the UK regime briefing. The Swiss position is addressed in our Criminal exposure in export-control cases under the Swiss SECO regime analysis.

What are the personal liability risks for officers and compliance staff?

Personal liability for corporate officers is one of the most underappreciated aspects of EU export-control enforcement. The relevant directive on criminal sanctions for breaches of restrictive measures, adopted by the Union and implemented by member states, specifically provides for criminal liability not only of legal persons but of the natural persons directing or managing them.

A director, compliance officer, or trade-finance manager who authorises, approves, or fails to prevent an export-control violation can face individual prosecution. The standard applied in most member-state systems is whether the person, given their position and authority, ought to have ensured compliance. This is not a negligence test in the civil sense; in several jurisdictions it is a statutory strict-liability standard modified only by a demonstrable, documented compliance effort.

What does a documented compliance effort look like? In our cross-border practice, the elements that most consistently provide a credible personal-liability defence are: a written export-compliance policy that the officer signed and disseminated; screening records showing that the specific goods were classified and the licence requirement assessed; evidence of escalation when a red flag arose; and training records for the relevant staff. These are the same elements audited in any regulatory review, but their evidentiary function in a criminal matter is distinct. They demonstrate that the officer discharged a professional duty, not merely that the company had a policy on paper.

Corporate criminal liability is also live. Several EU member states – including those with the largest export economies – impose criminal fines on legal persons found to have committed export-control violations through their organs or employees. The fine calculation varies; in some jurisdictions it is a multiple of the transaction value, in others a statutory range. The prospect of a criminal conviction on a company's public record, quite apart from the financial penalty, carries obvious implications for future export-licence applications and counterparty relationships.

What are the key risk flags and when should counsel be instructed?

Several patterns consistently precede criminal referrals in EU export-control matters. Identifying them early determines whether a business manages the situation or finds itself responding to prosecutors.

The first risk flag is a customs hold or a request for licence documentation that a company cannot immediately satisfy. A customs authority retaining a shipment is not necessarily the beginning of a criminal investigation – but it can become one if the response is delayed, incomplete, or inconsistent. The window between a customs query and a formal referral can be short.

The second is discovery during an internal audit or diligence exercise of past shipments that may have required authorisation and did not carry one. The question of whether to report proactively – and to which authority – is one where legal advice is critical before any approach is made. The answer turns on the member state, the nature of the goods, the destination, and the likely prosecutorial posture.

The third is a business-partner notification: a supplier, freight forwarder, or bank flags a concern about a transaction. Third-party alerts increasingly precede enforcement action because supply-chain participants face their own compliance obligations and have incentives to distance themselves from potential violations.

Counsel should be instructed at the earliest possible point – ideally before any response is made to an authority, and certainly before any written submission or interview. Statements made by corporate representatives in the administrative phase of an investigation can be used in subsequent criminal proceedings. In our experience, the instinct to cooperate quickly and fully, without first understanding the procedural landscape, is one of the costliest mistakes a company can make in this context.

Does your business have a protocol that routes customs queries and licence-documentation requests to legal counsel before an operational response is sent? If the answer is no, that gap should be addressed before the next shipment is detained.

Related practices

How Calder & Vance advises on EU criminal export-control exposure

We advise corporate clients, officers, and individuals at every stage of EU export-control enforcement: from the first customs query through to criminal proceedings. Our work covers the full response cycle.

Where a potential violation has been identified internally, we scope the apparent violation, assess the facts against the dual-use control lists and the relevant Council regulations, identify which member-state authorities are in play, and advise on whether and how to approach those authorities. We do not assist with concealing or minimising legitimate violations; our role is to ensure the client understands its legal position accurately and acts on it lawfully.

Where an authority has already made contact – through a customs hold, a written inquiry, a dawn raid, or a formal investigation notice – we manage the response. We advise on interview strategy for individuals, prepare documentary responses that accurately address the authority's questions without creating additional exposure, and co-ordinate with local counsel in the relevant member-state jurisdiction where trial-level criminal representation is required.

In a recent matter, a manufacturing group discovered during an acquisition due-diligence process that the target company had shipped dual-use components without the required authorisation over a period of several years. We assessed the apparent violations across the relevant member-state jurisdictions, identified the two jurisdictions with the most significant criminal exposure, and advised on a structured remediation and disclosure approach. The matter concluded administratively, without criminal referral, through early engagement with the competent authority.

We also assist with the forward-facing programme work that reduces the probability of criminal exposure arising. We test screening logic, map classification across the client's product range, and design export-compliance procedures to the standard that member-state authorities recognise as evidence of good faith. A well-constructed programme does not guarantee immunity – no compliance adviser can promise that – but it materially affects both the probability of a violation occurring and the outcome if one does.

The position above covers the standard case. Your facts – the goods, the destination, the route, the jurisdictions in play, the knowledge of the individuals involved – determine the specific legal exposure and the response options. For an initial assessment of your position under the EU criminal export-control rules, contact Calder & Vance at info@caldervance.com.

A common misconception: "Our goods are commercial, not military – we have no criminal exposure"

The most persistent myth we encounter in this area is that criminal export-control exposure is a concern only for businesses dealing in military equipment or weapons-related technology. It is not.

The EU dual-use regulation controls a broad range of commercially standard goods: industrial chemicals, telecommunications equipment, navigation systems, certain machine tools, electronic components, and software. Many of these appear on the control lists precisely because they have civilian applications and can also serve military or surveillance purposes. A business selling entirely within what it understands as a commercial market may be exporting items that require a licence to specific destinations or end-users, without ever having performed a classification exercise.

The criminal exposure does not depend on the goods having been designed for a military purpose. It depends on whether they appear on the control list, whether the export required authorisation, and whether authorisation was obtained. Businesses in sectors that do not self-identify as defence or dual-use – advanced materials, chemicals, electronics, software, precision manufacturing – are those most likely to have unaddressed classification gaps, and therefore the most likely to face criminal exposure from conduct that seemed entirely routine.

We regularly advise clients in these sectors who have never dealt with a licensing authority and did not know they were required to. An early classification review is far less costly than a criminal investigation, and it is the starting point for any credible export-compliance programme.

Frequently asked questions

Who administers criminal exposure in export-control cases under EU?
Criminal exposure in EU export-control cases is administered at two levels. At Union level, the European Commission oversees the dual-use regulation and the Council adopts the restrictive-measures regulations that frame the prohibited conduct. Criminal enforcement is then delegated entirely to member states: national customs authorities, licensing bodies, and prosecutors apply their own implementing legislation, guided by the Union framework but with significant procedural and sentencing variation across the twenty-seven jurisdictions.
What does EU prohibit in relation to criminal exposure in export-control cases?
The EU dual-use regulation prohibits the export, transfer, transit, and brokering of controlled dual-use goods without the required authorisation. The relevant Council regulations additionally prohibit the sale, supply, and transfer of certain goods and technology to designated persons or restricted destinations. Providing false or misleading information to obtain a licence is a standalone prohibited act. Circumvention-related conduct – facilitating a third party's violation through structuring or routing – is addressed directly in the current Council regulation framework.
How is criminal exposure in export-control cases enforced under EU?
Enforcement follows a path from administrative detection to criminal referral. Customs authorities identify potential violations at the point of export; licensing authorities identify misrepresentation when reviewing applications or post-export documentation. Either authority may refer a case to national prosecutors. Serious or systematic cases may involve Europol co-ordination. Prosecution, trial, and sentencing then proceed under national criminal procedure. Penalties include custodial sentences for individuals and criminal fines for legal persons; the specific ranges are set by member-state law.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.