Where an export-control and dual-use risk review stands now
An export-control and dual-use risk review. The cross-border position and what it means. The Hong Kong angle in focus. Write to info@lockhartyip.com.
The question that lands on a compliance officer's desk is rarely theoretical. A Mainland-connected group ships precision components through a Hong Kong entity to a counterparty in a third country. The goods are not weapons. The end-user agreement looks clean. Yet the transaction sits at the intersection of at least three export-control regimes – and the group has not run a formal risk review in two years. That is where the exposure begins.
An export-control and dual-use risk review assesses whether goods, technologies, software, or technical knowledge – items that have both civilian and potential military or proliferation applications – require a licence, an end-user undertaking, or a transaction restriction before they cross a border. The review spans the classification of the item, the identity of the counterparty, the end-use declared, and the payment channel used to settle the trade. For groups structured through Hong Kong, the review must address both the Hong Kong position and the export-control regimes of the jurisdictions whose goods or technology the transaction touches.
This analysis covers what is actually at stake commercially, how the cross-border interface bites in practice, the comparative read across the principal systems, and where we see the risk concentration sitting now.
What is actually at stake: the commercial pressure behind the review
Export control is, at its core, a banking and payment problem before it is a customs problem. A transaction may clear every port-of-entry check and still be blocked – or reversed – when the correspondent bank in the settlement chain runs its own screening and flags the goods description, the counterparty name, or the end-user country. That block triggers a frozen-funds position, a request for documentation, and, in the worst case, a voluntary disclosure or regulatory investigation.
For groups that use Hong Kong as a regional treasury or procurement hub, the stakes are concrete. Hong Kong-incorporated entities and Hong Kong banks settle trade in US dollars, euros, and other major currencies through correspondent networks that apply their own origin-jurisdiction compliance standards. A shipment of items classified as dual-use under a foreign regime – even one that has no direct legal force in Hong Kong – can cause a bank to decline the payment or exit the relationship entirely. Banking access is the pressure point. A review that does not address the payment channel is not a complete review.
The commercial logic is straightforward. A group that loses access to its primary settlement bank mid-transaction faces a choice between a costly restructuring of the payment route and a negotiated delay with the counterparty. Either outcome damages the commercial relationship and creates a documentary trail that will be examined if a regulator subsequently asks questions. Running the review before the transaction, rather than after the bank's compliance team has already raised a query, is the only position that preserves optionality.
In our cross-border practice, we regularly see groups that have managed export-control risk informally – relying on a general legal opinion from transaction counsel that addressed sanctions but did not separately assess dual-use classification or end-use commitments. That gap is where the exposure concentrates.
The governing instruments: how the regime is constructed
Hong Kong implements a licensing regime for strategic commodities under the Import and Export Ordinance and the Import and Export (Strategic Commodities) Regulations. The Strategic Trade Controls system administered by the Trade and Industry Department covers the export, re-export, and transit of items appearing on the Hong Kong Strategic Commodities Control Lists – lists that are harmonised, in significant part, with the Wassenaar Arrangement on Export Controls for Conventional Arms and Dual-Use Goods and Technologies (a multilateral export-control arrangement), the Nuclear Suppliers Group, the Australia Group, and the Missile Technology Control Regime.
Separately, Hong Kong implements United Nations sanctions through the United Nations Sanctions Ordinance. It does not give domestic legal effect to the unilateral trade controls or export-restriction measures of other states. That is the correct statement of the Hong Kong legal position.
However, the legal position and the practical compliance position are not the same thing. A Hong Kong entity that exports items subject to a US Export Administration Regulation (EAR) licence requirement – or that re-exports US-origin technology without the required authorisation – may face US enforcement action regardless of where the entity is incorporated. The de minimis rule (a threshold under the EAR that triggers US jurisdiction over non-US goods containing a minimum percentage of controlled US-origin content) and the foreign direct product rule (which extends US jurisdiction to certain foreign-made products that are the direct product of US technology or software) are the two mechanisms that most frequently surprise Hong Kong-based compliance teams. Neither requires the item to physically touch US soil.
The practical result is that a Hong Kong entity engaged in cross-border trade involving technology sectors – semiconductors, precision instruments, communications equipment, certain chemical precursors, aerospace components, and related software – must assess its exposure under both the Hong Kong strategic-commodities regime and the export-control regimes of the origin jurisdictions of the goods or technology in question. The review cannot stop at the Hong Kong legal perimeter.
How does the cross-border interface actually bite in practice?
The interface bites at three points: classification, the end-user chain, and the payment channel. Each creates a distinct risk layer.
Classification. The same item may sit in different control tiers under different regimes. A precision motion-control component may require a licence under one regime and be freely exportable under another. Where a group's Hong Kong procurement entity sources the item in one jurisdiction and re-exports to a third, the classification exercise must track the item through each leg. A single incorrect classification – or a classification that was correct two years ago but has since been tightened – can expose the entire shipment.
The end-user chain. An end-user undertaking obtained from the immediate buyer does not resolve the risk if that buyer is a known intermediary or trader in a sector associated with proliferation-sensitive end-use. Counsel on our desk regularly see supply chains where the first-tier buyer is a legitimate commercial entity but the second or third tier involves a counterparty appearing on a denied-party or restricted-entity list maintained by a foreign jurisdiction. The group's Hong Kong entity is not directly subject to that list – but the bank settling the payment is, and the correspondent network through which the dollars clear certainly is.
The payment channel. This is the pressure point that turns a classification question into an operational emergency. A Hong Kong bank's compliance team will apply its own institution-level standards when processing a trade-finance or open-account payment for goods in a controlled sector. Those standards are driven by the bank's own regulatory obligations – including its exposure to US dollar correspondent banking. The result is that a Hong Kong group may face a payment block on a transaction that is fully compliant under Hong Kong strategic-trade controls but touches a sector or a geography flagged in the bank's internal screening model.
What does a group do at that point? The short answer is: produce documentation that the bank's compliance team can actually use. A risk review that is conducted before the transaction generates exactly that documentation – a classification analysis, a counterparty diligence file, and an end-use assessment that the bank can receive and act on. A review conducted after the block has been applied is reactive and incomplete; it cannot retroactively cure the concern that caused the block.
The comparative read: Hong Kong, the Mainland, and origin-jurisdiction controls
The most common multi-system scenario in our practice involves a Mainland group with a Hong Kong trading or procurement entity and a counterparty in a third country – frequently in the Middle East, Central Asia, or South-East Asia. The goods or technology in question may be of US origin, EU origin, or Mainland-Chinese origin, each of which triggers a different set of considerations.
Mainland China has its own export-control regime under the Export Control Law of the People's Republic of China, in force since 1 December 2020. That law applies to the export of controlled goods, technologies, and services from the Mainland, including – in certain circumstances – exports by foreign entities that are owned or controlled by Chinese parties. The Mainland regime uses a controlled-items catalogue that does not map directly onto either the Wassenaar lists or the Hong Kong Strategic Commodities Control Lists. A group that has assessed its Hong Kong entity's position under Hong Kong rules and the applicable foreign-origin controls has not necessarily assessed its position under the Mainland law if the transaction involves technology or know-how that originated in the Mainland.
For European-origin goods, the position is again distinct. The EU Dual-Use Regulation (the EU's principal instrument governing the export of dual-use items) applies to exports from EU member states. Where a Hong Kong entity holds an inventory of EU-origin components, the exporting entity in the EU member state will have applied for and received (or declined to apply for) an export licence. But if the Hong Kong entity then re-exports those components to a third country in a manner inconsistent with the conditions of the original EU licence, the original EU exporter may face a compliance issue. That creates a practical interdependency between the Hong Kong entity's trade compliance and its European suppliers' licence conditions.
US-origin controls, as noted above, follow the item through the supply chain via the de minimis and foreign direct product rules. The relevant US authority – the Bureau of Industry and Security within the Department of Commerce – maintains the Entity List, the Denied Persons List, and the Unverified List as key screening tools. A Hong Kong entity transacting with a party on any of these lists in a transaction involving US-origin technology faces direct US enforcement exposure.
The comparative conclusion is this: no single regime covers the full picture. A proper risk review must identify every origin-jurisdiction control that attaches to the items in question, assess the counterparty against the relevant restricted-party lists, and document the end-use commitment at each link in the chain. That is a multi-system exercise, and it requires counsel familiar with each layer.
For a structured read on how sanctions considerations interact with deal structures involving Mainland-connected entities, see our analysis of sanctions due diligence on deals touching Mainland China. Where the transaction involves a BVI holding entity, the equivalent considerations are addressed in our review of sanctions due diligence on deals touching the BVI.
The sequence above describes the standard position. Your matter turns on the specific items, the counterparties actually engaged, and the payment route chosen – which is where the risk is won or lost. To discuss how the multi-system assessment applies to your cross-border position, contact info@lockhartyip.com.
Where the risk concentration sits now: the practitioner's read
Three dynamics define where the risk is concentrating in the current environment.
First, the pace of list expansion. The restricted-party lists maintained by origin-jurisdiction authorities – in particular the US Entity List and the EU Common Foreign and Security Policy restrictive measures lists – have expanded materially over the past several years. The expansion has accelerated in technology-sensitive sectors: semiconductors, advanced computing, quantum technology, and certain aerospace and maritime components. A counterparty or an intermediate user that was not listed when the last review was conducted may be listed now. Reviews conducted more than twelve months ago carry a higher residual risk than those that are current.
Second, the technology-classification tightening. Export-control authorities in multiple jurisdictions have tightened the classification of items in the advanced-technology sectors. Items previously classified at a lower control tier – or not listed at all – have been reclassified. This has particular relevance for software and for technology transferred by intangible means: a licence to access software-as-a-service, a technical briefing, or a cloud-based access arrangement may now constitute a controlled export under one or more regimes. The intangible-transfer dimension is under-assessed in the compliance files we review.
Third, correspondent-bank sensitivity. The major international banks that provide US dollar and euro correspondent services to Hong Kong banks have applied progressively tighter transaction-level screening in trade-finance and open-account payment contexts. The sectors most affected include electronics, precision instruments, chemicals and precursors, and certain telecommunications equipment. A group in any of these sectors should treat the bank's anticipated compliance review as part of the transaction design, not as a post-closing administrative step.
An Asian electronics group with a Hong Kong trading entity came to us following a correspondent-bank block on a payment for precision components destined for a South-East Asian buyer (early 2027). The components were not listed under Hong Kong's Strategic Commodities Control Lists. The block had been triggered by the bank's internal screening against the US Entity List – the end-user appeared on the list under a transliteration variant that the group's own screening tool had not matched. We assisted in preparing the classification analysis and end-user diligence package, and in structuring the compliance documentation in the form the bank's compliance team required. The payment channel was restored within one clearing cycle.
A second pattern involves groups in the precision-instruments sector with Mainland-Chinese manufacturing entities and Hong Kong sales entities. The items moved through the Hong Kong entity are frequently dual-use under both the Mainland Export Control Law and the Wassenaar-derived controls. Where the group has not reconciled the two classification systems, the documentation submitted to each bank in the settlement chain is inconsistent – creating the appearance of a mismatch that flags the transaction for additional scrutiny. Reconciling the classifications before the transaction is straightforward; reconciling them after a bank has already raised a query is considerably more difficult.
What does a properly structured review actually look like?
A well-constructed export-control and dual-use risk review has five components, each of which generates a documentary record that serves a dual purpose: it is the compliance file for the group's own records, and it is the documentation package that a bank's compliance team or a regulator can receive and act on.
Item classification. Each good, technology, software, or technical service is assessed against the applicable control lists – beginning with Hong Kong's Strategic Commodities Control Lists and extending to the origin-jurisdiction lists that attach to the item by reason of its provenance. Where classification is ambiguous, a classification request to the relevant authority is considered.
Counterparty screening. The immediate buyer, the disclosed end-user, and – where the supply chain is visible – the intermediate handlers are screened against the principal denied-party and restricted-entity lists. Screening must use variant-name matching, not exact-name matching. A screening that does not catch transliteration variants is not reliable.
End-use assessment. The declared end-use is assessed against the known or plausible actual end-use, taking into account the counterparty's sector, the jurisdiction of delivery, and any intelligence available about the intermediate supply chain. Where an end-user undertaking is required or advisable, it is obtained in a form that is specific to the items and the transaction, not generic.
Payment-channel analysis. The proposed payment route – the banks involved, the currencies used, and the correspondent network through which settlement will occur – is assessed against the screening models that the relevant correspondent banks are known to apply. Where a payment route presents a material risk of a block, an alternative route is identified before the transaction closes.
Documentation package. The review concludes with a structured compliance memorandum covering each of the above components, together with the supporting documentation. The memorandum is prepared in a form that can be provided to a bank or, if necessary, to a regulator. A compliance file that exists only in the group's internal records and cannot be produced in a usable form on short notice is not effective.
If an earlier compliance review, a bank enquiry, or a transaction stall has already produced an adverse or inconclusive result, a second-look analysis can identify the gap and the steps still available. To discuss that position, contact info@lockhartyip.com.
The objection most commonly heard: "We are not subject to foreign export-control laws"
The objection is legally accurate in a narrow sense and operationally misleading in practice. A Hong Kong entity is not directly subject to the US Export Administration Regulations as a matter of Hong Kong law. It is not directly subject to the EU Dual-Use Regulation. Both statements are correct.
The operational reality is different. A Hong Kong entity that knowingly or recklessly facilitates an export of US-origin controlled technology without the required US authorisation may be added to the US Entity List – a designation that is not a criminal conviction but that has the effect of requiring a specific licence for any US-origin item (subject to a policy of denial) in future transactions. Once added, removal is a lengthy and uncertain process. The commercial consequence – loss of access to US-origin technology and to the correspondent-banking relationships that support US-dollar settlement – is severe and does not require a finding of criminal liability.
Similarly, a Hong Kong entity that participates in a transaction that a correspondent bank's compliance team characterises as a potential circumvention of foreign export controls – even if that characterisation is incorrect – faces a de-risking response that is driven by the bank's own risk appetite, not by any Hong Kong legal determination. The bank's decision to exit the relationship, decline the payment, or request enhanced documentation does not await a regulatory finding. It precedes one.
The practical implication is that "not subject to" and "not exposed to" are different statements. A risk review addresses the exposure, not just the legal obligation. That distinction matters most for groups whose principal commercial relationships, payment channels, and technology supply chains run through jurisdictions whose export-control regimes are extraterritorial in their reach.
The decision matrix: situation, instrument, and route
The risk profile of a cross-border transaction involving potentially dual-use items maps to a set of practical choices. The following is a prose decision framework drawn from the patterns we see in practice.
Where the items are clearly listed under Hong Kong's Strategic Commodities Control Lists and a licence is required, the path is defined: apply for the licence before the shipment, obtain the end-user certificate in the required form, and ensure that the goods do not move until the licence is in hand. The risk in this situation is primarily administrative – delay, documentation, and correct classification of the licence class.
Where the items are not listed under Hong Kong controls but are of US origin or contain a meaningful percentage of US-origin content, the EAR de minimis and foreign direct product analyses must be run. The outcome determines whether a US export licence is required for the re-export from Hong Kong. If a licence is required and the transaction proceeds without one, the exposure is to the US, not Hong Kong, but the commercial consequence – Entity List designation – affects the Hong Kong entity's entire business.
Where the items are of Mainland origin, the Mainland Export Control Law classification must be reconciled with Hong Kong's own lists. Items that are controlled under the Mainland regime but not listed under Hong Kong's strategic-commodities controls remain subject to Mainland export-licence requirements if the export originates in the Mainland. A Hong Kong entity that sources from a Mainland affiliate and re-exports without confirming the Mainland export-licence position is exposed in the Mainland, not in Hong Kong – but a Mainland regulatory action against the affiliate can disrupt the group's entire supply chain.
Where the items are of EU origin, the relevant EU member-state export-licence conditions must be confirmed with the original EU exporter. If the re-export from Hong Kong to the ultimate destination is not covered by the original licence conditions, the EU exporter faces a compliance issue and may withdraw from the supply relationship rather than risk its own licence status.
In every scenario, the payment-channel analysis runs in parallel. The optimal legal position does not prevent a correspondent-bank block if the bank's own screening model flags the transaction. The review addresses both layers simultaneously.
For the full range of sanctions and AML considerations that intersect with export-control risk in cross-border transactions, our practice overview is at Sanctions & AML.
Where this is heading: the directional read
Export-control and dual-use risk is moving in one direction: broader coverage, faster list expansion, and tighter correspondent-bank screening. Several developments, each grounded in dated regulatory action, point in the same direction.
The technology-control perimeter is expanding. Advanced semiconductors, quantum computing components, and certain artificial-intelligence software are already subject to tightened controls under the US EAR, with further expansions under active consideration. Each expansion tightens the classification of items that were previously in a lower control tier and increases the number of transactions that require a licence or an end-use assessment.
The Mainland's own export-control posture is becoming more assertive. The Export Control Law of the People's Republic of China provides a basis for outbound controls on Mainland-origin technology that extends, in certain circumstances, to transactions by foreign entities with Mainland connections. The practical scope of that extra-territorial reach remains under development, but groups with Mainland-origin technology in their supply chains should monitor the position actively.
Correspondent-bank de-risking in trade-sensitive sectors is accelerating. The major settlement banks have reduced their appetite for transactions in electronics, precision instruments, and related sectors involving certain geographies. The trend is not uniform – specific institutions, specific currencies, and specific routing structures carry different risk profiles – but the direction of travel is clear. A group that has not recently reviewed its payment-channel structure for export-control-sensitive transactions should do so as a matter of course.
The practical implication for groups structured through Hong Kong is that a review conducted under the regime as it stood two years ago is not reliable today. The item classifications, the restricted-party lists, and the correspondent-bank screening models have all moved. The review is not a one-time exercise. It is a scheduled compliance function, with a review cycle tied to the pace of change in the relevant control regimes.
Related practices
- Sanctions & AML – sanctions compliance, AML risk, and counterparty due diligence for cross-border groups
- Corporate Counsel – governance, compliance frameworks, and cross-border corporate advisory
Frequently asked questions
Do I need a Hong Kong adviser for an export-control and dual-use risk review?
How long does an export-control and dual-use risk review usually take?
What documents are needed for an export-control and dual-use risk review?
Speak with Lockhart & Yip
For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →
Related
- Sanctions Aml
- Sanctions Due Diligence Deal Touching Bvi Bvi
- Sanctions Due Diligence Deal Touching Mainland China Mainland 5
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.