CIS · Sanctions and compliance

Export controls: Key legal risks

Erich Rath10 min read

Mainstream

Export control is not a customs clearance. It is a system of legal norms that determines what, to whom, where and under what conditions can be transferred.

The key legal risk here is not the delay of cargo at the border. The main risk is a complete blocking of a business operation due to violation of export control rules, entailing multimillion-dollar fines, criminal liability for management or placing the company on sanctions lists.

Effective export control risk management begins with three audits:

Who is the end user and whether there are no red flags?Whether the deal is a covert circumvention of sanctions or whether it will lead to military end use.

If these three issues are not resolved before shipment, the company risks not the finances of the moment, but the strategic right to exist in international markets.

When Export Control Risks arise

Export control risks are relevant if:

  • The company exports high-tech equipment or dual-use goods
  • Cross-border transfer of software or technology (including email and cloud services)
  • The foreign partner requires re-export to a third country
  • Supply Chain Companies From High Risk Countries
  • The contractor belongs to the military-industrial complex
  • Payment is made through a bank that is subject to restrictions.
  • There are signs of circumvention of sanctions: transit through third countries, non-standard payment terms, last-minute change of recipients
  • Business is related to investments in strategic industries

The mistake most companies make

Many exporters start with the question:

Do we need a license?

That's the wrong first question.

The right question is:

What part of our transaction or technology would qualify as a breach even in the absence of an outright ban?

Sometimes the biggest risk is not the lack of a license, but the application of the end-use/end-user restrictions. And sometimes, it’s an intra-corporate transfer of technology that management simply doesn’t consider “export.” Sometimes, it is necessary to continue working on a long-term contract after the tightening of sanctions.

Export control risk management does not require formal checks of lists, but rather a legal audit of the entire value chain.

Step 1. Check the product and technology

The first thing to learn is not the destination country or the name of the buyer, but the product itself.

Key aspects of classification:

  • checklists of dual-use goods
  • military list
  • national lists (for example, USA, EU, UK, Switzerland, etc.)
  • De minimis (minimum share of controlled components in foreign goods)
  • Foreign Direct Product Rule for technologies created using U.S. software or hardware
  • Intangible technology transfers (access to drawings, transfer of know-how through online meetings)
  • Restrictions on the provision of services (engineering, consulting, technical support)

If a product is not classified correctly, all subsequent compliance procedures will be based on a false basis.

Step 2. Checking the participants in the transaction

The main legal risk is not concentrated in the product, but in the end user.

It is necessary to check:

  • Is the counterparty under blocking sanctions (SDN List, EU Consolidated List, UK Sanctions List, etc.)
  • Who is the real beneficial owner
  • The final recipient of the goods (End-User)
  • Is the buyer not a company-layer?
  • Whether the transaction involves a military end user (MEU List)
  • Are there any signs of a counterparty belonging to sectoral sanctions (SSI List)

The critical issue here is not formal compliance, but multi-level due diligence, including analysis of corporate structure and reputational risks.

Step 3. Assessing country risks and re-exports

Even if direct exports are allowed, the risk may arise on re-export.

Analyzed:

  • Existence of an embargo against the country of end-use
  • military end-use by the importing country
  • re-export rules from the jurisdiction of original export
  • transit risks (congestion in ports of high-risk countries)
  • risks associated with Crimea, new regions of the Russian Federation or unrecognized territories, if they are expressly excluded from the permitted geography of supplies

Particular risk: provision of warranties and maintenance of previously supplied equipment in the country, which was subsequently embargoed.

Step 4. Analyze the reservation on the inadmissibility of circumvention of sanctions

Any transaction is checked for violation of sanctions clauses (Sanctions Clause) in contracts with banks, insurers and major counterparties.

You need to make sure that the company’s actions:

  • will not violate its own contractual assurances
  • will not result in cross-default on other contracts
  • do not violate the export control rules of the country of the producer of the goods or the country of registration of the parent company
  • There will be no risk of secondary sanctions.

Step 5. Assessing the Risks of Management Responsibility

In most jurisdictions, violation of export control rules entails not only corporate fines, but also personal liability.

Risk scenarios:

  • Criminal liability of directors and persons responsible for compliance
  • the risk of extradition when crossing the borders of the jurisdictions that imposed sanctions (for example, the United States)
  • Prohibition or Disqualification of Managers
  • Seizure of management assets abroad

Ignoring personal risks for beneficiaries and top management is one of the main strategic mistakes.

Step 6. Identify hidden risks in M&A and investment deals

Export control is a critical factor in structuring transactions.

Risks arise if:

  • acquires a company that has previously violated export control regimes, which entails the succession of liability
  • The investor from the country without sanctions is actually controlled by a person from the sanctions list
  • purchases of assets with unresolved rights to software or technology subject to U.S. export control
  • integration into global chains of companies from the EU, where strict screening of counterparties from Russia and the CIS is required

Step 7. Build an export compliance system

The best risk protection is a preventive system that prevents a transaction from taking place.

An effective export control program (ICP) includes:

  • Written policies and procedures for classifying goods
  • Automated screening of counterparties (sanctions, industry and military lists)
  • the procedure for identifying red flags (for example, unusual delivery routes, refusal to provide data about the end user, non-standard product nomenclature for the customer)
  • mandatory export due diligence for all mergers and acquisitions
  • Regular training of employees of sales, logistics and R&D departments
  • Internal audit and escalation mechanism to the legal department

The existence of a working compliance program is considered by US regulators (OFAC, BIS) and the EU as a mitigating circumstance when imposing a fine.

Step 8. Act when a violation is detected

If a violation has already occurred, an incorrect reaction increases the risk many times over.

The correct protocol of action includes:

  • legal assessment of violation in the regime of attorney secrecy
  • making voluntary self-disclosure decisions to regulators, which often reduces the fine by half
  • Immediately stop all ongoing suspicious transactions
  • isolation of the problem within the corporate structure
  • Assessment of the risk of criminal prosecution and personal protection of management
  • communication with banks and counterparties in order to avoid a break in relations due to violation of their compliance policy

Export control of the US and the EU: Key differences in risks

CriteriaThe U.S. RegimeEU regime
ExtraterritorialityMaximum. The rules apply to products with U.S. components, technologies and individuals around the world.Limited. It is valid in the EU and in relation to EU citizens/companies.
Dual-use goodsBroad Lists (CCL), Complicated De Minimis and Foreign Direct Product Rules.It is regulated by EU Regulation 2021/821. The emphasis is on controls within the Union and on exports from the EU.
Personal responsibilityVery tall. The real threat of extradition and huge prison sentences for top management.High nationally, but the mechanisms differ from the criminal practice of the United States.
Secondary sanctionsThey are actively used outside the United States. Risk for companies from any country, even in the absence of American jurisdiction.The concept of secondary EU sanctions is practically not applied.
Risk for Russian BusinessCritical for any operations with sanctioned persons, the military-industrial complex and high-tech sectors.Critical for direct supplies of goods from the EU sanctions lists to Russia and with the participation of European subsidiaries.

The risk strategy must take into account the extraterritorial scope of U.S. law and the growing coordination between the sanctions regimes of different countries.

How to strengthen your position before the start of the transaction

Protection against export control risks begins at the stage of contract signing.

An international commercial contract should include:

  • Detailed Sanctions Clause with Right of Immediately Termination
  • assurances of the counterparty about the end user and the purposes of use
  • obligation not to re-export without written consent
  • Right to audit the end user
  • a clause on applicable law excluding the risk of enforcement bypassing sanctions
  • Protective wording about force majeure, including refusal to perform due to sanctions prohibitions
  • mechanism for returning goods or stopping payment when identifying red flags
  • obligation of the counterparty to notify of the change in ownership structure

The contract should allow the company to exit the transaction at any time without loss if its continuation creates regulatory risk.

Common Mistakes in Export Control Risk Management

  1. Ignoring the American Direct Product Rule

A foreign product made using U.S. technology may require a U.S. license to export to Russia, even if the product is physically located in Asia.

  1. Risk assessment by destination country only

Delivery to a “safe” country (for example, the UAE or Turkey) carries a huge risk if the final recipient is in Russia, and the goods go for the needs of the military-industrial complex.

  1. Consideration of the customs aspect only

Transferring technology via email or video to a foreign colleague is as much an “export” as a physical shipment.

  1. Lack of due diligence of the buyer

The contractor could be established a month before the transaction or be at the same address with the sanctioned company, which is a classic “red flag”.

  1. Relying on the local regulator’s “authorization”

The export permit from the national regulator of the exporting country does not protect against secondary sanctions of the US Treasury if the operation contradicts US law.

  1. Removal of the sanctions clause from the treaty template

Managers often remove it “to make it easier to sign,” depriving the company of its main defense tool.

Checklist of exporter

Before any international transaction begins, 15 questions must be answered:

What is the correct classification of the product by ECCN and EU analogues?Does the product have American components or technology that exceed the de minimis threshold?Who is the end user and what is its scope?Is the parties to the transaction included in the SDN List, SSI List or other restrictive lists?Is the destination country subject to embargo or comprehensive sanctions?What is the transportation route and is it not associated with high-risk areas?What is the payment currency and is the corresponding bank subject to restrictions?Is the risks of military end-use or end-user?Is the transaction part of a scheme of circumvention of sanctions (for example, through a third country)? Does the transaction violate the policies of our key banks and counterparties?Did logistics and sales staff be instructed about red flags?Does there be a risk of personal liability for managers signing the contract?Did you plan to immediately exit the transaction if a danger signal appears?Is there a legal department opinion covering all the above issues?

What a Strong Risk Management Strategy Looks Like

A strong strategy usually includes five levels of protection:

1. Product & Technology Control

Legal classification of products, technologies and services, taking into account all multi-jurisdictional requirements.

2. Transactional Compliance

Complete transaction review: Side screening, end-use/end-user analysis, route verification and payment logistics.

3. Structural Protection

Development of contractual mechanisms (sanctions, audit clauses, guarantee obligations) that allow to break off dangerous relations legally and quickly.

4. Strategic Advisory

Constant assessment of changes in the law of the USA, EU and Russia, forecasting the impact on the business model and building a new geography of sales and procurement without violating the regimes.

5. Crisis Management & Defense

Protection during investigations, voluntary disclosure of information, minimization of fines, protection of managers and assets.

Without a fifth tier, the top four might not save the company from catastrophic consequences.

What if our goods are supplied for civilian purposes, but the buyer is connected with the defense sector?

Even if the product is civilian, the risk of potential military end-use (catch-all control) is very high. Without a license, such a transaction would likely be found to be a violation. You should immediately obtain a legal opinion and consider Voluntary Self-Disclosure.

Can I rely on the end user certificate provided by the buyer?

The certificate itself is not a protection. Regulators expect the exporter to do due diligence: check the reliability of the certificate, independently study the beneficiaries and signs of “laying”. Absolute trust in the counterparty is not a basis for exemption from liability.

Is the transfer of technical documentation to the Russian branch of our company an export?

Yeah. The transfer of technology or software subject to export control between companies of the same group located in different countries (including Russia) is considered an export and may require a license.

Is it a liability if we are not an American company and the transaction is not going through the United States?

Yeah. The US export control rules (EAR and ITAR) have extraterritorial effect. If your product has American components or is made using certain American software/technology, you must comply with U.S. requirements wherever you are.

What are the first steps if we find a red flag in the current transaction?

Immediately suspend shipment and all transactions. To record the discovery of the flag. Conduct an internal investigation under the supervision of an external lawyer (to preserve lawyer secrecy). In no case, not trying to “agree to bypass” – this aggravates the guilt to the level of intentional crime.

Related services

  • Sanctions, export controls and international compliance
  • Corporate and Regulatory Investigations, Business Integrity
  • International Arbitration, Commercial Disputes and Cross-Border Litigation
  • International regulatory risks and strategic advice
  • International trade, distribution and cross-border transactions

Related material

  • Sanctions clauses in international contracts: How not to lose the right to protection
  • Risks of parallel imports: between the sanctions legislation and the commercial necessity
  • How to check the foreign counterparty: Blocking sanctions OFAC vs. sectoral EU sanctions: practical difference for business
  • Criminal liability of management for violation of export control
  • Developing an Export Compliance Program (ICP) in the Company
  • Voluntary Disclosures (VSDs) to Regulators: CATCH-ALL CONTROLS in M&A transactions

Conclusion

The key legal risks of export control are not limited to the lack of a shipping license. This is a complex threat stemming from the overlap of jurisdictions, the extraterritorial effect of laws and the lack of proactive compliance in the company.

A strong position is not based on responding to incidents, but on preventing them. through strict product classification, thorough due diligence of counterparties, competent contractual protection mechanisms and constant monitoring of changing regulation.

In international business, it is not the one who sells the fastest that wins, but the one who, when he makes a deal, knows for sure that it will not destroy his company tomorrow.

Have a question about the topic of this article?

Write to us and we will respond within one business day.