- Publication type
- Article
- Types of sanctions
- Export controls
- Import controls
- Individual financial measures
- Trade & investment
- Thematic area
- Sanctions compliance & due diligence
Always keep in mind the four ‘Keys to Compliance’: Who, What, Where, and Why (or ‘What for?’)
This article is the fourth and final part of the series on the four key compliance questions: Who, What, Where and Why (or ‘What for?’). It focuses on the purpose behind your transaction and the use of the goods or services you are supplying.
Sanctions focus on purpose, not just people or products
EU sanctions not only target specific people, companies or goods, they also target how goods and services are used and who ultimately benefits from them.
This means that a transaction can be prohibited even where:
- the direct customer is not listed, and
- the goods or services are not themselves restricted.
If goods, technology or services are used for a prohibited purpose, or benefit a sanctioned end‑user, the transaction may still breach EU sanctions. Sanctions compliance is therefore about preventing activities that breach or circumvent the sanctions regime, not just avoiding contact with listed names.
At the same time, EU sanctions are targeted and may include specific exceptions for certain end-users or end-uses. For example, humanitarian exceptions are designed to ensure that aid, medicines, and other essential goods can continue to be supplied.
What do ‘end‑user’ and ‘end‑use’ mean for sanctions compliance?
The end‑user is the person or organisation that will actually use the goods or services. This is not always the same as your direct customer.
The end‑use is how the goods or services will actually be used after delivery.
These concepts matter because many sanctions and export control rules apply based on use, for example, where items are used for:
- military applications,
- weapons production,
- surveillance or internal repression,
- sanctioned industries or activities.
A vague statement such as “for own use” is rarely sufficient. You should understand who will use the goods, where, and for what purpose.
What basic steps are SMEs expected to take in practice?
For small and medium-sized enterprises, or SMEs, end‑use and end‑user checks should be practical and proportionate. In most cases, this involves three basic steps.
Step 1: Ask clear questions
- Who is the final end‑user?
- Where will the goods or services be used?
- What will they be used for?
- Will they be resold, transferred or sub-licensed?
Step 2: Collect basic supporting information
This may include:
- a signed end‑user or end‑use declaration,
- company registration details of the end‑user,
- a short technical explanation of why the goods are needed.
Step 3: Assess plausibility
Ask yourself:
- Is the stated use realistic given the technical features of the goods?
- Is it consistent with the customer’s business and sector?
- Does it make sense for the country and market involved?
An end‑user declaration is a helpful tool, but it is not enough on its own. You must assess whether the information provided is credible.
Red flags linked to ‘What for?’
Common warning signs include:
- the customer cannot explain the end‑use clearly,
- the technical complexity of the goods does not match the customer’s profile,
- the stated end‑use changes during the transaction,
- the customer refuses to provide end‑user information.
One red flag does not automatically mean a transaction is prohibited. However, multiple red flags require further questions and escalation. You should not proceed until concerns are resolved and documented. If they cannot be resolved, do not proceed. Learn more about red flags here.
The role of “No Russia” and similar clauses
For certain sensitive goods, EU law requires contracts with non‑EU buyers to include “No Russia” (and in some cases “No Belarus”) clauses. These clauses are designed to prevent re‑export to sanctioned countries.
Key points for SMEs:
- where required, these clauses are mandatory;
- failing to include them is a breach of EU law, even if no re‑export occurs;
- they do not replace due diligence.
A contract clause helps manage risk, but it does not remove your responsibility to assess end‑use and end‑user risks.
What does effective compliance look like for SMEs?
Effective sanctions compliance is not about complex systems or legal language. For SMEs, it means:
- understanding who benefits from your transaction,
- understanding how goods or services will be used,
- recognising when explanations do not make sense,
- asking further questions when needed,
- keeping basic records of what you checked and why.
Sanctions compliance is judged by what you did in practice, not by whether you had perfect information.
How to get help
‘Why’ and ‘What for?’ are about purpose and outcome. They ask whether your transaction could undermine or circumvent the objectives of EU sanctions.
If end‑use or end‑user risks are unclear, or if a transaction does not make sense, pause and seek guidance before proceeding.
If you are unsure whether a certain purpose or use case presents a sanctions risk, seek guidance early. European SMEs may not always have the time or resources to conduct full sanctions due diligence independently. To support them, the EU has established and funds the EU Sanctions Helpdesk, a free service to help EU SMEs comply with EU sanctions.
The Helpdesk can:
- Answer your questions on the applicability of EU sanctions
- Offer you guidance on performing sanctions due diligence
- Undertake sanctions due diligence for you, free of charge, if you encounter red flags or you simply need support
If you have a question about a transaction, find out how to get support here.
