Export control in Europe: exporter's guide

Export control in Europe: Practical Guide for Manufacturers and Exporters Legal and Compliance Strategy for International Business
Mainstream
Export control in the European Union is not a customs formality in shipment. It is a regulatory risk management system where the price of error is a business stoppage.
The main threat to the manufacturer or exporter is not the denial of a license. The company continues to ship products without realizing that it is already violating the export control regime. The consequences come suddenly: blocking of bank payments, seizure of goods at the border, inclusion in the sanctions list or criminal investigation against management.
Effective compliance begins with three checkpoints:
- Is the product subject to control (classification)?
- Who is the end user and what is the end goal of the service?
- Is a license required and on what basis can it be issued?
If these issues are not resolved before the first delivery, the company is not just risking the deal - it is risking the market.
When it is necessary to apply export controls
The EU export control regime is activated not only in the physical export of goods. Situations requiring immediate verification include:
- export of dual-use goods to third countries;
- transfer of technology or software to a foreign person (including via email or cloud);
- re-export of components previously imported into the EU;
- Intra-corporate supply between plants in different jurisdictions;
- brokerage and transit of sensitive goods;
- export of equipment not embargoed but capable of being used for military purposes;
- interaction with sanctioned persons in the supply chain;
- acquisition or acquisition of companies with sensitive export contracts.
The mistake that most of the participants make
Many companies start with the question, “Can I ship this product?”
That's the wrong first question.
The right question is: “What permits and compliance procedures should be completed so that this delivery does not lead to a legal, financial and reputational disaster?”
Sometimes the best outcome is to obtain a global license for intra-corporate supply. Sometimes, it was a rejection of a deal that, at first glance, seemed commercially attractive. Sometimes, a de-control change to get the product out of control. Export control does not require finding loopholes, but rather building a risk management system.
Step 1. Classification of the product
The first and decisive step is not to analyze the contract, but to classify the nomenclature.
Key questions:
- Does the product fall under Annex I of EU Regulation 2021/821 (dual-use goods)?
- Is it covered by national military lists?
- Is it an “out-of-the-list” (not subject to the restrictions of Regulation 2021/821) product but can be used to make weapons of mass destruction (catch-all clause)?
- What is the technical specification: parameters, power, accuracy, encryption capabilities?
- Does the product contain components made in the United States (the de minimis rule or the direct product rule) that automatically impose U.S. export controls?
If the classification is incorrect, the entire chain of compliance will be incorrect. You can not rely on the codes of the HS - you need technical expertise of the product and comparison with checklists.
Step 2. Identify the counterparty and the purpose of use
The most perfect product without violations can turn into a risky supply because of the counterparty.
We need to check.
- the end user and the end user;
- whether the counterparty is connected with military structures;
- Whether the company or its beneficiaries are under EU sanctions;
- whether there are “red flags” in the supply chain (shell company, lack of expertise, non-standard route, refusal to provide information about end-use);
- whether the delivery address is the same as the legal address of the business;
- Whether the destination country is subject to a full or partial EU embargo.
Information about the end-use is especially valuable when the customer explicitly or indirectly points to the military scope.
Step 3. Identify the applicable licensing regime
License requirements are determined at the intersection of the product classification, destination country and purpose of use.
This has an impact on:
- type of license (individual, global, national general, general export license of the Union);
- Terms of use of the license (delivery only to certain persons, reporting, post-shipment obligations);
- the possibility of intra-corporate technology transfer;
- Requirements for disclosure of the beneficiaries of the transaction;
- the need to obtain an import certificate from the end user (End-Use Statement);
- The possibility of using exceptions (for example, for repairs or exhibitions).
If a product falls under catch-all, a license is often requested not on the basis of a list but on the basis of “informing” the competent authority of the buyer’s intentions.
An error at this stage leads to an illegal delivery that will not become legal backdate.
Step 4. Check for jurisdictional conflicts
EU export controls do not exist in a vacuum. The manufacturer is often bound by US regulations (EAR, ITAR), even if the product has never crossed the US border.
The transaction can operate in parallel:
- Regulation (EU) 2021/821;
- American ITAR/EAR;
- national laws of a Member State (e.g. on the control of torture);
- United Nations sanctions programs;
- Restrictions on the country of origin of components.
A conflict of jurisdictions could lead to a situation where the supply is allowed in the EU but banned by OFAC, posing the risk of blocking the dollar payment and secondary sanctions for the European exporter.
Step 5. Develop an Internal Compliance Program (ICP) Strategy
The best defense against infringement charges is not a one-time request to lawyers, but a functioning and documented system of export controls within a company.
Effective ICP includes:
- a clear organizational structure with a designated export control officer;
- written procedures for classifying goods;
- Automated or semi-automatic scoring of counterparties;
- the procedure for identifying and escalating red flags;
- training of sales managers and engineers;
- registration and storage of documentation (at least 5 years, and in fact longer than the limitation period);
- procedure for obtaining and accounting of licenses;
- post-shipment monitoring;
- auditing the system.
Having a functioning ICP can be a mitigating factor in a breach and even protect management from criminal liability.
Step 6. Buyer's due diligence: recognize the red flags
This is a key step before the contract is concluded.
Before sending a commercial offer, you need to understand:
- Is the customer not a shell company?
- Whether the place of incorporation and the place of business coincide;
- Is it connected with the armed forces of the importing country?
- whether equipment for enterprises is purchased under sanctions;
- Whether there are court cases or investigations in open registers;
- whether the request is too large or technologically illogical for the buyer’s business
- Does the customer ask to turn off GPS, change the markings or disassemble the equipment?
- Does he not participate in bypass schemes through third countries?
Exporting to a harmless trading company in Yerevan or Almaty that does not have licenses and experience could effectively mean illegal shipments to Russia or Iran. Ignoring this is the responsibility of the exporter, not the buyer.
Step 7. Consideration of License Substitutes and Exclusions
Not every delivery requires a new license.
Possible legal avenues:
- use of the Union General Export Licenses (EU GEA) for certain destinations (e.g. Australia, Canada, Japan, USA);
- National general licenses for low-sensitivity goods;
- exceptions for temporary export (repair, exhibitions, testing);
- exceptions for replacement of components under the guarantee;
- Global permissions for a group of companies.
However, the terms of use of such licenses are strictly regulated. Failure to comply with reporting requirements or exceeding limits automatically turns the delivery into unlicensed.
Step 8. Apply for an Individual License
If it is impossible to do without it, the application should be prepared as an investment project.
The document should include:
- the exact classification of the goods;
- technical description;
- identification of the end user;
- End-Use Certificate (End-Use Certificate)
- contract or form;
- information about the broker or carrier;
- Non-proliferation and non-re-export obligations;
- confirmation of the absence of signs of circumvention of sanctions;
- transportation route;
- Guarantees of the exporter to implement ICP.
In sensitive supply applications, accuracy, completeness and reliability are particularly important. Withholding information or a questionable structure of a transaction almost always leads to a rejection and, in the worst case, an investigation.
Step 9. Observe post-shipment control
Obtaining a license and customs clearance is not the final step, but the transition to the next level of control.
Post-shipment control includes:
- verification of actual export with the terms of the license;
- check-up whether the funds came from a sanctioned account or were not transferred through a bank that causes suspicion;
- re-export control: Was the product resold without permission?
- End-use audit, if there are grounds for doing so;
- maintaining a dossier for each delivery;
- immediate notification to the regulator when a violation is detected.
Errors at this stage may turn the legal delivery at the time of shipment into a violation due to the subsequent actions of the buyer.
Step 10. Act in case of violation or investigation
Discovery of a breach is the moment when the fate of a company is decided.
Plan of action:
- immediate blocking of further shipments;
- Internal investigation under the supervision of lawyers (legal privilege);
- documentation of the chronology of events;
- analysis of the causes of the failure (classification, collusion of employees, circumvention of procedures);
- notifying the national competent authority of voluntary disclosure, if it is strategically justified;
- Preparation of a plan of corrective measures (remediation plan);
- Talks with the regulator about easing sanctions.
The standard “self-pass” response or destruction of documents is a guaranteed path to criminal prosecution and loss of business.
Dual-use or military goods: harder
| Criteria | Dual-use goods | Military goods |
|---|---|---|
| Regulation | EU Regulation 2021/821, but many national nuances | National lists of EU member states |
| Licensing | EU General Licenses, Global, Individual | Mostly individual, rarely general |
| Compliance complexity | High due to catch-all and U.S. components | Very tall: strict requirements for brokers, end-user certificates |
| Risk of wrongdoing | Criminal and administrative liability | Criminal liability with more severe sanctions |
| Role of ICP | Critical for General Licenses | It is often a prerequisite for obtaining a license. |
| Speed of procedures | It can be fast, depending on the country. | Almost always long checks. |
The choice of management model does not depend on the market segment, but on the specific technology and the ultimate purpose of delivery.
How to strengthen your position before starting export activities
The best protection is built in the R&D and product design phase.
It is desirable to include in the strategy:
- Analysis of export control at the design stage (design for compliance);
- classification of prototypes;
- Screening component suppliers for limitations
- introduction of a block module for subsanctions counterparties into the ERP system;
- Contract templates with end-use clauses and right to audit;
- contractual mechanisms of protection in case of new sanctions (sanctions clause, right to unilateral suspension of delivery);
- Establish a reporting system that is ready for review by the regulator.
Export control should be built into business, not tied to it in a crisis.
Typical mistakes of exporters
- Ignore the “catch-all” Even if the item is not on the list, knowing about the military end-use makes it controllable.
- Confusing the ECCN/Dual-Use classification codes are different universes. Mistakes here are the basis for a criminal case.
- A European product with an American chip or created by American software may fall under US re-export control.
- Check the counterparty only before the first transaction Sanctions are updated daily. The buyer could become a defendant in the list the day after the inspection.
- Long-term history of relations does not protect if the partner is unofficially supervised by the defense department.
- The regulator will not accept the argument “we had a policy template downloaded from the Internet.”
- Start negotiations with the regulator without a strategy Voluntary disclosure without a fix plan can result in a maximum penalty.
- Thinking that digital transfer is not exporting a drawing or code through Teams, Web Ex or email to a foreign colleague is a controlled export of technology.
Checklist of exporter
Before placing an order in production, answer 15 questions:
- What is the exact classification of the product according to Regulation 2021/821?
- Is there any components in the product from the USA?
- Which entity is the end user?
- Is it certified by an end-use certificate?
- Does the buyer have any connection to the military or sanctions structures?
- Is the commercial use consistent with the claimed use?
- What specific license is required?
- What are the terms of this license?
- Is the destination country under embargo or restrictions?
- Are there red flags in the logistics chain?
- Does the company have a written procedure for checking this case?
- Are all the doubts of managers documented and escalated?
- Is the company ready for post-shipment inspection?
- Is there a right to stop the shipment without penalty?
- What is the plan of action if after shipment it turns out that the buyer is included in the SDN-list?
What a strong export control strategy looks like
A strong strategy usually includes five levels:
1. Legal classification and architecture Technical product audit, analysis of applicable jurisdictions and licensing requirements.
2. Commercial protection Structuring of the transaction, distribution and agency contracts with strict compliance assurances and the right to refuse delivery.
3. Automated screening, trained personnel, regular system audits, risk escalation.
4. License management Obtaining, accounting and monitoring compliance with license conditions.
5. Crisis Response Plan for immediate action when blocking cargo, investigating or detecting a violation.
Without a fifth level, the first four can collapse overnight.
FAQ
Can I apply for a license retroactively?
Nope. Exports without a license, when required, are infringements. Voluntary recognition may mitigate liability but does not legalize shipment.
What if a competitor is driving without a license and has no problems?
That means he has problems ahead of him. Export control has a long tail (up to 5 years or more in a number of compositions). Compliance is about protecting a business, not running a race against those who take risks.
Do I have to get a license if the product is not included in the checklists?
Not unless you know or should know that it is for WMD-related purposes or for military use in a catch-all country.
Can you rely on the manufacturer’s conclusion about uncontrollability?
Nope. The responsibility for classification lies with the exporter, even if it is a distributor. It is recommended to obtain a written confirmation from the manufacturer, but to conduct your own check.
What is the “Direct Product Rule” and why is it important to me?
It is a doctrine of U.S. export control, according to which a foreign product created using U.S. technology or software may fall under U.S. jurisdiction. If your European plant uses American software for design, your exports may be regulated not only by the EU, but also by the BIS.
What if the sanctions were imposed the day after the contract was signed?
Act strictly on the sanction clause in the contract: freeze execution, notify the counterparty and request a license from the national regulator or OFAC (if applicable) to wind down transactions.
More importantly: License or ICP?
A license is a permission to make one transaction. ICP is the permission to do business in the long run. Without ICP, the company is not ready to obtain licenses.
Related services
Sanctions, Export Controls & International Compliance International Trade, Distribution & Cross-Border Transactions Corporate Investigations, Regulatory Investigations & Business Integrity International Regulatory Risk & Strategic Advisory Commercial Contracts
Related material
EU sanctions: How to build compliance in a multinational company The US Direct Product Rule for European Business How to conduct an internal investigation of an export violation of Due Diligence by a foreign counterparty: Checklist of Sanctions and Export Control Clauses in Contracts bypassing Sanctions: Legal risks for ITAR and EAR management: How to obtain a global license for intra-corporate deliveries Red flags in export transactions: case studies
Conclusion
Export controls in the European Union do not require formal questionnaires, but a deep understanding of the regulatory landscape and risk mitigation strategies.
A strong position is based on correct classification, uncompromising screening of counterparties, implemented compliance system and the ability to stop a transaction, no matter how profitable it may seem.
In international trade, the winner is not the one who gets the fastest licenses. The winner is the one who builds the business so that no supply destroys the company.
Have a question about the topic of this article?
Write to us and we will respond within one business day.


