Sanctions Evasion Reference

What is end-user certificate fraud?

Supplying a false statement of who will use controlled goods and for what, so that a licence is granted or a sale proceeds on a representation the exporter cannot verify.

also known as

end-use fraud, EUC fraud, false end-user statements

seen in

Russian Federation, Islamic Republic of Iran, Democratic People's Republic of Korea

reviewed

2026-08-20

Export control depends at one crucial point on a representation rather than an observation. The exporter cannot follow the goods to their destination and cannot watch them being used. The end-user certificate stands in for that: the stated recipient certifies who will use the item, where, and for what purpose, and the exporter and the licensing authority rely on it.

Falsifying that certificate is the most direct attack on the export control system there is.

How it works

The published enforcement material describes three patterns.

The fabricated end user. The certificate names a company that does not exist, or exists only as a registration with no operations. Letterhead, stamps and signatures are produced to match. Where the licensing authority does not independently verify the entity, the fabrication holds.

The impersonated end user. The certificate names a real company, with a real address and a real business, that knows nothing about it. This is more robust than fabrication, because superficial verification succeeds: the company exists, its business is plausible, and its details check out.

The complicit end user. The certificate names a real company that signs it knowingly, intending to pass the goods on. Nothing in the document is forged. The false statement is about intention, which is the hardest thing to disprove at the time and the easiest to prove afterwards, once the goods have moved.

Why verification is the whole question

Holding a certificate and testing one are different activities, and the distinction runs through this entire subject. A file containing an end-user certificate demonstrates that the exporter asked. It demonstrates nothing about whether the answer was true.

The Export Administration Regulations set out the behaviours that should prompt an exporter to test a certificate rather than file it: a customer reluctant to offer information about the end use1 , product capabilities that do not fit the buyer’s line of business2 , routine installation, training or maintenance declined2 , and a freight forwarding firm listed as the product’s final destination3 . The regulation then tells the exporter what to do: if there are red flags, inquire4 , and do not cut off the flow of information that arrives in the normal course of business5 .

Each of those is a question about whether the certificate describes reality. None requires any special investigative capability to ask.

How it is caught

Post-shipment verification. Licensing authorities conduct end-use checks, visiting the certified end user and asking to see the item. This is the direct test, and its results are decisive: goods that are not there, or an end user who cannot explain what happened to them, close the question.

Entity verification. A certificate names a company at an address. Checking that the company exists, that it operates from that address, and that its business is what the certificate says is elementary and frequently not done.

Recovery. Where the item ends up in a restricted end use and is recovered, the certificate becomes evidence against the party that signed it.

Correspondence. In complicit-end-user cases, the intention to divert usually exists in writing somewhere between the parties, because the diversion has to be arranged. Enforcement actions in this area are commonly built on that correspondence rather than on the certificate itself.

What the sources say

Each numbered claim above, with the words of the document it rests on and — for the Panel of Experts reports — the paragraph it comes from. Quotes are checked against the source text at build time.

  1. “reluctant to offer information about the end-use”

    Red Flags, Supplement No. 3 to Part 732 of the Export Administration Regulations. U.S. Bureau of Industry and Security (via the electronic Code of Federal Regulations), 2025.

  2. “installation, training or maintenance services are declined”

    Red Flags, Supplement No. 3 to Part 732 of the Export Administration Regulations. U.S. Bureau of Industry and Security (via the electronic Code of Federal Regulations), 2025.

  3. “freight forwarding firm is listed as the product's final destination”

    Red Flags, Supplement No. 3 to Part 732 of the Export Administration Regulations. U.S. Bureau of Industry and Security (via the electronic Code of Federal Regulations), 2025.

  4. “if there are “red flags” , inquire”

    Red Flags, Supplement No. 3 to Part 732 of the Export Administration Regulations. U.S. Bureau of Industry and Security (via the electronic Code of Federal Regulations), 2025.

  5. “do not cut off the flow of information that comes to your firm in the normal course of business”

    Red Flags, Supplement No. 3 to Part 732 of the Export Administration Regulations. U.S. Bureau of Industry and Security (via the electronic Code of Federal Regulations), 2025.

Red-flag indicators

9 listed
01 The customer has little or no business background. U.S. Bureau of Industry and Security, 2025
“customer has little or no business background”

U.S. Bureau of Industry and Security, EAR Supplement No. 3 to Part 732, Red Flags (2025). Read the source document

02 The product's capabilities do not fit the buyer's line of business — the example given is a small bakery ordering several sophisticated lasers. U.S. Bureau of Industry and Security, 2025
“capabilities do not fit the buyer's line of business”

U.S. Bureau of Industry and Security, EAR Supplement No. 3 to Part 732, Red Flags (2025). Read the source document

03 The customer or purchasing agent is reluctant to offer information about the end use of a product. U.S. Bureau of Industry and Security, 2025
“reluctant to offer information about the end-use”

U.S. Bureau of Industry and Security, EAR Supplement No. 3 to Part 732, Red Flags (2025). Read the source document

04 Routine installation, training or maintenance services are declined by the customer. U.S. Bureau of Industry and Security, 2025
“installation, training or maintenance services are declined”

U.S. Bureau of Industry and Security, EAR Supplement No. 3 to Part 732, Red Flags (2025). Read the source document

05 A freight forwarding firm is listed as the product's final destination. U.S. Bureau of Industry and Security, 2025
“freight forwarding firm is listed as the product's final destination”

U.S. Bureau of Industry and Security, EAR Supplement No. 3 to Part 732, Red Flags (2025). Read the source document

06 Packaging is inconsistent with the stated method of shipment or the stated destination. U.S. Bureau of Industry and Security, 2025
“packaging is inconsistent with the stated method of shipment”

U.S. Bureau of Industry and Security, EAR Supplement No. 3 to Part 732, Red Flags (2025). Read the source document

07 The buyer, when questioned, is evasive or unclear about whether the product is for domestic use, export or re-export. U.S. Bureau of Industry and Security, 2025
“evasive or unclear about whether the purchased product is for domestic use”

U.S. Bureau of Industry and Security, EAR Supplement No. 3 to Part 732, Red Flags (2025). Read the source document

08 The customer is unfamiliar with the product's performance characteristics but still wants the product. U.S. Bureau of Industry and Security, 2025
“unfamiliar with the product's performance characteristics”

U.S. Bureau of Industry and Security, EAR Supplement No. 3 to Part 732, Red Flags (2025). Read the source document

09 Delivery dates are vague, or deliveries are planned for out-of-the-way destinations. U.S. Bureau of Industry and Security, 2025
“delivery dates are vague”

U.S. Bureau of Industry and Security, EAR Supplement No. 3 to Part 732, Red Flags (2025). Read the source document

Each indicator above is quoted or paraphrased from the advisory or typology report named beside it. Expand a row for the citation. These are recognition aids drawn from published guidance, not a compliance checklist.

How it is detected

The decisive test is post-shipment verification: licensing authorities visit the certified end user and ask to see the item, and goods that are not there, or an end user who cannot account for them, resolve the question outright. Short of that, elementary entity verification — does the certified company exist, does it operate from the stated address, is its business consistent with the item's capability — disposes of fabricated and impersonated certificates. Complicit end users cannot be caught this way, and those cases are typically built on correspondence between the parties arranging the onward movement, or on recovery of the item from a restricted end use.

Enforcement record

Documented outcomes on this site that turned on this technique.
Case Outcome Authority Date Penalty
Flighttime: a false end-user certificate 2022–2025 Charged, pending
Nordgas: re-exporting US pressure switches to Iran 2010–2021 Settlement OFAC 2021-03-26 $950,000
Essentra FZE: cigarette filters to North Korea through front companies 2018–2020 Settlement OFAC 2020-07-16 $665,112
ZTE: front companies and an internal plan to keep supplying Iran 2010–2017 Criminal conviction OFAC 2017-03-07 $100,871,266

Related techniques

  • What is dual-use re-export diversion? — Buying controlled civil-use goods lawfully in an open market and re-exporting them to a restricted end user, exploiting the fact that the item itself looks entirely ordinary.
  • What is third-country transshipment? — Routing restricted goods through an intermediate country so that the shipment reaching the restricted destination appears to originate somewhere the exporter would have supplied without question.
  • How are aircraft parts procured in breach of sanctions? — Buying airframe and engine components through intermediaries in unrestricted countries, so that parts for a restricted operator's Western-built fleet arrive with clean paperwork and no airworthiness trail.
  • What is a front company? — A front company is a business that trades normally but exists largely to hide another party's involvement in its transactions. The real activity is the cover; the concealed party is the point.

Where this appears

Sanctions programmes

  • Russia sanctions — Measures imposed from 2014 and greatly expanded from 2022, combining designations, sectoral restrictions, export controls and a price cap on seaborne oil.
  • Iran sanctions — A layered set of US, EU and UN measures dating from 1979 and substantially rebuilt after 2018, covering energy, finance, shipping, and proliferation-related procurement.
  • North Korea sanctions — The most comprehensive UN-mandated regime, prohibiting most trade with North Korea, backed by Panel of Experts reporting that documents evasion in unusual detail.

Jurisdictions in the published record

  • United Arab Emirates — A major re-export hub and financial centre that appears in enforcement records across almost every technique on this site, principally because of the volume of trade that passes through it.
  • Türkiye — A large manufacturing and transit economy whose trade with several restricted destinations has grown substantially, making it central to third-country routing analysis.
  • Hong Kong — A major financial and trading centre whose company formation regime, banking sector and re-export role place it in a large share of published corporate concealment cases.

Terms used on this page

  • End-user certificate — A document in which the stated recipient of a controlled item certifies who will use it, where, and for what purpose, relied on by exporters and licensing authorities.
  • Attestation — A signed statement by a party in a transaction confirming a fact that the recipient cannot itself observe, relied on as the basis for providing a service.
  • Export control — A licensing regime that restricts the export, re-export or transfer of specified goods, software and technology by reference to the item, the destination and the end use.
  • Dual-use goods — Items with legitimate civil applications that can also contribute to military or weapons programmes, and which are therefore export-controlled.
  • Wilful blindness — Deliberately avoiding knowledge of a fact that would create liability, treated in enforcement practice as equivalent to knowing it.
  • Proliferation financing — The provision of funds or financial services used for the manufacture, acquisition or transfer of weapons of mass destruction or their delivery systems, contrary to international obligations.

Further reading and sources

  1. Don't Let This Happen to You: Actual Investigations of Export Control and Antiboycott Violations. U.S. Bureau of Industry and Security, Office of Export Enforcement, 2024.
  2. Guidance on Proliferation Financing Risk Assessment and Mitigation. Financial Action Task Force, 2021.
  3. Entity List, Supplement No. 4 to Part 744 of the Export Administration Regulations. U.S. Bureau of Industry and Security, 2026.
  4. Conflict Armament Research field investigations. Conflict Armament Research, 2026.
  5. Office of Public Affairs press releases. U.S. Department of Justice, 2026.