EuropeGlobal EconomyThought

Export control: compliance enforcement trends in the UK and EU

There is a growing trend for export control authorities across Europe to increase focus on what happens after an export licence is issued. The UK provides a clear example, with a marked increase in post-licensing compliance activity. In particular, the UK’s Export Control Joint Unit (ECJU) conducted 383 post-export compliance checks in 2025, up from 270 in 2024 and 244 in 2023.

Of first-time checks, 24% were found to be non-compliant and a further 21% not fully compliant. The ECJU issued 66 warning letters, and two exporters each had a licence suspended for repeat infractions, according to the UK Government’s Strategic Export Controls Annual Report.

While national statistics are not directly comparable, the same trend is noted across the EU. The European Commission reported that member states conducted 1,353 compliance audits in 2024. In Ireland, the Department of Enterprise, Tourism and Employment (DETE) completed 50 audits in 2025, comprising 28 on-site and 22 desk-based audits, compared with 34 on-site inspections in 2023, according to its 2025 Annual Report. Similarly, Sweden’s Inspectorate of Strategic Products conducted 50 targeted supervision visits in 2025, up from 22 in 2023, according to its yearly report.

Licensing authorities are increasingly focusing on ensuring that licence conditions are complied with in practice, against a backdrop of sanctions evasion, diversion concerns and increasingly sensitive technologies. The scale of dual-use trade reinforces that focus: authorised EU dual-use trade totalled approximately €77.6 billion in 2024, up from €71 billion in 2023.

Intangible transfers are an emerging area of audit focus. Under EU and UK rules, controlled software and technology may be exported when transmitted or made available abroad electronically, including by email, download, screen sharing, cloud or remote access and, in some cases, telephone or video calls. Such transfers may leave a less obvious audit trail than physical shipments.

Companies should expect increasing scrutiny of where controlled technology is stored, who can access it and from where, how access is approved, and whether system logs demonstrate that transfers were made under the appropriate authorisation.

Recent UK enforcement illustrates the risk. In July 2026, HMRC issued a record £6.4 million compound penalty after a UK exporter was considered to have failed to keep accurate records of controlled-technology transfers under various licences, despite issues being voluntarily disclosed.

Given the growing compliance focus, effective preparation for audits is critical, and there are several key steps businesses can take

Effective preparation begins with understanding who is conducting the audit, its purpose and legal basis, and what triggered it. Those questions determine both the likely scope of the review and the exporter’s obligations.

In the UK, an ECJU compliance inspection is different from an HMRC enforcement or Customs check. The ECJU performs a licensing-assurance function, examining whether licenses have been used correctly and whether records and procedures satisfy their conditions. ECJU inspectors may inspect and copy required records, and non-compliance may lead to warning letters, suspension or revocation. They are not criminal investigators or prosecutors; instances of non-compliance are reported to HMRC.

HMRC has broader statutory enforcement powers. It may require information, examine customs and commercial records, detain or seize goods and investigate suspected offences. Its review may also extend into wider customs compliance. Information provided during such a review may have enforcement consequences, so responses should be accurate, carefully verified and distinguish established facts from matters requiring confirmation.

The trigger for the audit also shapes preparation. The visit may be a first inspection, a routine review of an open licence, an intelligence-led audit, a response to a voluntary disclosure or a revisit following an adverse result. For example, ECJU normally aims to revisit within six to eight months of a non-compliant inspection. In that situation, the business should be ready to demonstrate clearly how previous findings have been remediated.

The authority and trigger of the audit will also shape what is examined. The ECJU typically requests an export log covering the licenses and period identified in its pre-visit questionnaire. A representative sample is then typically selected for review. Businesses should therefore be able to retrieve the complete supporting file, including licences, invoices, customs declarations, transport documents, end-user undertakings, screening evidence, approvals and records of usage against quantity or value limits.

A HMRC review may extend beyond individual transactions to examine the company’s broader customs and compliance framework, including declaration processes, broker oversight, classification and licence usage, and the consistency of customs, commercial and licensing records.

The approach of EU regulators can differ again. For example, DETE generally selects exports for review in advance of the audit, while examining specialist knowledge, company-wide awareness, the internal compliance programme and documentary compliance. Its 2025 report identified missing documentation, poor preparation, knowledge gaps and inconsistencies between authorisation applications and customs declarations as common issues.

Given the growing compliance focus, effective preparation for audits is critical, and there are several key steps businesses can take.

The starting point should be a focused internal review tailored to the likely scope of the audit. Businesses should test classification, licence coverage and conditions, declarations, undertakings, screening and usage against quantity or value limits. Supporting records should be assembled and reconciled against licence, customs, shipping and broker data. For intangible transfers, the review should go beyond written policies to test actual access rights, system controls and audit logs.

Issues identified during that exercise should be addressed before the visit where possible. Remediation should preserve a clear audit trail, records should never be backdated, and the company should consider, with legal advice where appropriate, whether a voluntary disclosure is required or advisable.

Companies should also maintain an issues register recording each issue, affected transactions, root cause, corrective action and longer-term improvements. This allows the business to explain clearly what went wrong, what has been done about it and how recurrence will be prevented.

Finally, preparation should address who will engage with the authority. The team will usually require input from trade compliance, logistics or customs, legal and, where relevant, technical personnel. Someone from senior management should attend at least at the beginning or end of the visit to demonstrate ownership of compliance. As export control audits become a more prominent part of the regulatory landscape, companies that understand the nature and scope of the review, identify and address weaknesses in advance, and can demonstrate effective controls will be better placed to manage the audit and any issues that emerge.