Publicité
ERP IMPLEMENTATION
🇫🇷 Lire en français

ERP Export Controls: Dual-Use Goods, OFAC Sanctions and EU Blacklists

How to automate export controls in your ERP: dual-use goods (EU Regulation 2021/821), OFAC sanctions, denied party screening. A practical guide for IT and compliance teams.

ERP Export Controls: Dual-Use Goods, OFAC Sanctions and EU Blacklists

A British industrial manufacturer had been supplying a Malaysian customer for four years — steady orders, on-time payments, no red flags. Then an internal audit revealed that the customer was a subsidiary of an entity on the Bureau of Industry and Security (BIS) Entity List. The result: multiple open orders frozen, a mandatory disclosure to the relevant authorities, contractual penalties, and potential US fines for violating the Export Administration Regulations — even for a company with no US operations, because its products contained American-origin components above the de minimis threshold.

This scenario is no longer exceptional. It has become increasingly common since 2022, as sanctions against Russia, Belarus, and certain Chinese entities accumulated rapidly. The question is no longer whether export controls apply to your business, but whether your ERP is configured to automate compliance — before a customs alert or regulatory audit forces the issue.

Key points at a glance

  • Any EU company exporting goods listed in Annex I of EU Regulation 2021/821 is subject to dual-use export controls, regardless of sector.
  • The OFAC SDN list and EU restrictive measures target specific entities — not entire countries. Your ERP must screen each counterparty individually, not apply blanket country blocks.
  • European subsidiaries of US groups are subject to OFAC regulations and the EAR, even without direct US customers — extraterritoriality is real and enforced.
  • SAP GTS is the benchmark for large enterprises; for mid-market companies, SaaS solutions such as Descartes Denied Party Screening integrate via API with any ERP.
  • Over 99% of screening alerts are false positives: a human validation workflow is essential.

1. Why export controls have become an ERP problem

The sanctions explosion since 2022

Before Russia’s invasion of Ukraine in February 2022, international sanctions lists mainly covered a handful of embargoed countries (Iran, North Korea, Cuba) and terrorist entities. The landscape has changed fundamentally. The European Union adopted successive sanctions packages against Russia and Belarus, adding thousands of entities, individuals, and restricted products. The US Treasury’s Office of Foreign Assets Control (OFAC) and the Bureau of Industry and Security (BIS) simultaneously expanded their own lists significantly.

For any mid-market industrial exporter, this means that the universe of counterparties requiring screening has grown dramatically. A compliance check that could once be handled manually for a few dozen orders per month can no longer be done reliably without ERP automation.

From manual checking to automation: an operational necessity

Manual screening relies on fragile processes: an Excel spreadsheet maintained by the export manager, checks applied to large orders but overlooked on smaller ones, a compliance officer on leave with no trained backup. In the event of a customs inspection or regulatory audit, the company must demonstrate that it operates a formalised, systematic export compliance programme — not an ad-hoc procedure.

The ERP is the natural place to automate these checks, because that is where orders, shipments, and invoices are created. A block triggered in the ERP at the point of order entry is infinitely less costly than a hold at the border or a retroactive investigation.


2. The three-tier regulatory framework

Tier 1 — Dual-use goods: EU Regulation 2021/821

EU Regulation 2021/821 of 20 May 2021, published in the Official Journal of the EU on 11 June 2021, is the reference framework for dual-use items in Europe. It establishes a common regime for controlling exports, brokering, technical assistance, transit, and transfers of goods that have both civilian and military applications.

Annex I of the regulation contains the common control list: materials, electronic components, telecommunications equipment, lasers, sensors, certain software, and navigation technologies. If a product you manufacture or distribute appears on this list, you have licensing or notification obligations depending on the destination.

Each dual-use item is classified by a European Export Control Number (ECN), aligned with international control arrangements (Wassenaar Agreement, NSG, MTCR). In your ERP, this translates into an attribute field to be populated on the product master record.

Tier 2 — Economic sanctions: OFAC, BIS and EU lists

Economic sanctions operate differently from dual-use controls. They target specific entities — individuals, companies, governments — rather than products.

The OFAC Specially Designated Nationals and Blocked Persons (SDN) list, publicly available at ofac.treasury.gov, contains entities whose assets are frozen and with whom any US person or entity subject to US jurisdiction is prohibited from transacting. OFAC updates its list irregularly, sometimes daily during geopolitical crises. A screening database must therefore be synchronised in near-real time.

The BIS Entity List, managed by the Bureau of Industry and Security and available at bis.gov, lists organisations and individuals subject to specific export restrictions for national security or foreign policy reasons. Unlike the SDN list — which implies a total block — the BIS Entity List generally requires a licence to export to listed entities.

On the European side, the EU Council maintains its own restrictive measures lists, accessible via the EU Sanctions Map. Their format and update frequency differ from US lists.

The critical point on extraterritoriality. A British or German subsidiary of a US group is subject to OFAC lists and the Export Administration Regulations (EAR), even if it exports to no US destination. Similarly, any product in which more than 25% of its value is of US origin (the EAR’s “de minimis” rule) may be subject to US controls even if manufactured outside the United States. These extraterritoriality rules are real and actively enforced.

Tier 3 — National controls: BAFA in Germany, ECJU in the UK, SBDU in France

At the national level, each EU member state — and the UK since Brexit — maintains its own control bodies and, in some cases, supplementary lists.

In Germany, the Bundesamt für Wirtschaft und Ausfuhrkontrolle (BAFA) handles export licence applications for controlled goods, with enforcement standards that are sometimes stricter than the EU average for certain product categories.

In the United Kingdom, the Export Control Joint Unit (ECJU), part of the Department for Business and Trade, administers the post-Brexit regime. This remains broadly aligned with international lists but has introduced its own specificities since 2021 — in particular, the UK’s own sanctions regime managed by the Office of Financial Sanctions Implementation (OFSI) at HM Treasury.

In France, the Service des Biens à Double Usage (SBDU) is the competent directorate within the Direction Générale des Entreprises, handling dual-use licence applications.


3. Configuring the ERP for export controls

Enriching the product master: ECN, ECCN, TARIC and dual-use flag

The first configuration step is enriching the product repository. Every article sold or shipped must carry, in the ERP, the relevant export control attributes:

  • ECN code (Export Control Number, EU nomenclature): indicates whether the item is controlled under Annex I of Regulation 2021/821.
  • ECCN code (Export Control Classification Number, US nomenclature): relevant if the company has US customers or is subject to the EAR.
  • TARIC heading: for customs classification and identification of dual-use positions.
  • Dual-use flag: a boolean field or value list that triggers control workflows.

This classification work is routinely underestimated. It requires expertise combining knowledge of the product portfolio with a careful reading of control lists. For companies without in-house export counsel, specialist consultancies offer initial classification engagements.

Enriching counterparty records: risk countries and screening status

On the counterparty side (customers, suppliers, agents, partners), the ERP must carry the following attributes:

  • Ultimate destination country: distinct from the direct customer’s country (a Dutch customer may order for delivery to a sanctioned destination).
  • Screening status: date of last check and outcome (clear, resolved alert, blocked).
  • Embargoed country flag or enhanced sanctions regime indicator.
  • Enhanced-risk entity flag: potential military end-user, entity in a sensitive sector.

The ultimate destination is often the hardest data point to capture in the ERP. Commercial operations focus on the contractual delivery address, not the end use. Yet it is the use and ultimate destination that determine licence obligations.

Configuring automatic blocking rules

Once the master data is enriched, the ERP can be configured to automatically block an order or shipment when the product-destination-customer combination triggers an alert.

Typical rules to configure:

  • Block if the ECN code is non-null AND the destination country appears on a mandatory-licence list.
  • Block if the counterparty appears on a sanctions list (real-time connection to the screening database).
  • Block if the declared ultimate destination differs from the customer’s country and that destination is under embargo.
  • Alert (without automatic block) for enhanced-risk countries requiring manual validation.

The granularity of rules depends on the ERP’s capabilities. SAP S/4HANA with GTS offers a highly flexible rules engine. Mid-market ERPs (Sage, Microsoft Dynamics 365 Business Central, Odoo) often require custom development or integration with a dedicated compliance tool.

Escalation workflow and decision audit trail

Automatic blocking is only the first step. When an order is blocked, a workflow must activate:

  1. Notification to the export manager with alert details.
  2. Case review: manual verification of the counterparty, cross-reference with the control list, assessment of the declared end use.
  3. Documented decision: approved with justification, or block maintained.
  4. If approved: recorded in the ERP with the reviewer’s name, date, justification, and — where applicable — the licence reference.
  5. If blocked: order refused with full traceability.

This audit trail is essential. In the event of a customs inspection or investigation, the company must be able to demonstrate that every sensitive order was subject to documented scrutiny.


4. Market solutions

SAP Global Trade Services (GTS): the enterprise standard

SAP GTS is SAP’s dedicated module for international trade management and export controls. It integrates natively with SAP S/4HANA and SAP ECC. Its capabilities cover real-time counterparty screening against OFAC SDN, EU, UN, and national lists, export licence management, quota tracking, and automated blocking.

SAP GTS makes sense for groups whose volume of international transactions justifies the investment — typically mid-to-large enterprises with significant export activity or international groups with subsidiaries across multiple countries.

Oracle Global Trade Management (GTM): the alternative for Oracle environments

Oracle GTM covers similar functionality to SAP GTS for Oracle ecosystem customers: Oracle Cloud ERP (Fusion), JD Edwards, and Oracle E-Business Suite. The solution includes denied party screening, product classification against international nomenclatures, and licence management.

Descartes Denied Party Screening: the API-first SaaS approach

Descartes Systems Group offers a SaaS denied party screening solution that stands out for its API-first architecture. The solution connects to any ERP via API and cross-references each counterparty against the world’s major lists (OFAC SDN, BIS Entity List, EU and UN lists, and dozens of national lists) in near-real time.

The advantage for mid-market companies is flexibility: no dedicated ERP module is required, integration happens at the data exchange layer. List update frequency is critical — Descartes publishes updates as soon as an official list is modified.

LSEG World-Check: the reference database for KYC screening

World-Check (formerly Thomson Reuters World-Check, now under LSEG) is a risk intelligence database covering politically exposed persons (PEPs), sanctioned entities, and individuals linked to organised crime and terrorism. It integrates via API into ERP systems or KYC/CRM tools to automatically enrich counterparty records.

World-Check is widely used in customer onboarding and third-party verification processes in regulated sectors: banking, insurance, and defence-adjacent industries.

Mid-market ERPs: current limitations

Odoo, Sage 200, Microsoft Dynamics 365 Business Central, and other SME-oriented ERPs do not offer a native export control module with real-time screening against sanctions lists. Two approaches exist for these environments:

  • External API integration: connect a SaaS screening service (Descartes, Compliance-One, or equivalent) to the ERP to screen counterparties at record creation or order entry.
  • Periodic batch verification: regularly export the active counterparty list and cross-check it against sanctions lists in a batch process. Less robust in real time, but workable for companies with low export volumes.

For businesses with few international transactions, a documented manual procedure remains acceptable — provided it is systematic and traceable. Beyond around one hundred international orders per month, automation becomes essential.


5. Implementation in four steps

Step 1 — Map your risk exposure

Before any ERP configuration, answer these questions: Which products in your catalogue could be dual-use (electronics, optics, chemicals, software, machine tools)? To which countries do you export directly or indirectly? Do you have customers in third countries where the ultimate destination is uncertain?

This mapping determines the scope of the project. A company that exports only consumer goods within the EU faces limited risk. A mid-market manufacturer selling electronic components to customers in South-East Asia or the Middle East must take the subject very seriously.

Step 2 — Enrich your ERP master data

This is the longest and most technical phase. It involves classifying each product reference against ECN/ECCN nomenclatures, enriching customer and supplier records with control attributes, and documenting the classification methodology for future audits.

A frequently overlooked point: subcontractors and intermediaries. In complex distribution chains, an agent or distributor may resell your products to a listed entity without your direct knowledge. Contracts with distributors must include an export compliance clause and a due-diligence obligation on their side.

Step 3 — Select and integrate your screening database

Selection criteria for a screening database:

  • List coverage: at a minimum, OFAC SDN, BIS Entity List, EU and UN lists. National lists (BAFA, HM Treasury/OFSI, SBDU) are a plus depending on your markets.
  • Update frequency: ideally real-time, or at most daily.
  • False positive management: the quality of the matching algorithm (handling of Arabic and Cyrillic transliterations, spelling variants) determines the volume of alerts requiring manual handling.
  • API SLA and availability: a screening service that goes down during an urgent order creates an operational problem.

Step 4 — Train sales administration and export teams

Technology alone is insufficient. Sales administration and operations teams must understand why an order is blocked, how to investigate an alert, and what the escalation procedure is. Training must cover three critical points: how to interpret a screening result, how to handle false positives (which represent the vast majority of alerts), and how to document a clearance decision for the audit trail.


6. What the ERP cannot do

Human judgement on near-matches

Screening algorithms generate alerts when a counterparty name resembles a name on a list. A legitimate “Mohammed Al-Rashidi” may trigger an alert because a different “Mohammed Al-Rashidi” is listed. The decision to clear or maintain a block requires human analysis that cannot be fully automated.

The reverse risk — false negatives — is equally real: a listed entity using a transliteration or alias not captured in the database may pass through without an alert. The ERP reduces risk; it does not eliminate it.

Financial transactions: a separate perimeter

Export controls in the ERP cover goods and services flows. Financial transactions fall under a different perimeter: banks have their own screening obligations via SWIFT and their anti-money-laundering systems. The commercial ERP and the banking system do not automatically communicate on this point.

An order cleared by the ERP may subsequently be blocked by the bank if the payment is directed to a financially sanctioned entity. These two control layers are complementary and distinct.

The catch-all clause: the risk of unlisted products

EU Regulation 2021/821 includes a “catch-all” provision: even if a product does not appear in Annex I of controlled dual-use goods, the exporter must refuse or submit to licence any export if they know or have reason to believe the item will be used for military purposes in an embargoed country, or for the development of weapons of mass destruction.

This clause relies on the exporter’s judgement. The ERP cannot automatically detect a suspicious end use for an unclassified product. It implies training commercial teams to recognise warning signals: unusual order quantities for a customer profile, questions about military technical specifications, prices accepted without any negotiation.


Conclusion: export compliance as a competitive advantage

Export controls were long seen as a concern only for large enterprises with well-resourced legal departments. The accumulation of sanctions since 2022 and the expanded extraterritorial reach of US regulations have changed the picture for mid-market exporters — including those with no direct link to the United States.

A mid-market company with a formalised export compliance programme — classified product records, automated counterparty screening, documented validation workflows — gains a concrete advantage on three fronts: it reduces the risk of fines and export licence suspensions; it builds confidence with key accounts that themselves face compliance audits across their supply chains; and it accelerates international customer onboarding because checks are systematic and traceable.

Implementation takes time — three to twelve months depending on catalogue size and the complexity of target markets. But it is built on durable foundations: enriched ERP master data and validation workflows remain valid regardless of how sanctions lists evolve.

To explore related topics, see our ERP and international trade guide — customs, VAT and multi-country compliance and our article on ERP and GRC — governance, risk and compliance. If your broader concern is regulatory compliance for your information systems, our NIS2 directive and ERP guide covers the cybersecurity obligations that intersect with export control programmes.