Export control and dual-use classification: what to do in the first ten days comes down to one decision: whether the item, technology or software triggers a control list before the next shipment or disclosure. Everything decided afterwards is remediation, not prevention, and the cost of a wrong call rises sharply once the goods have left Sweden.
Who this concerns
This question usually surfaces inside three types of company: manufacturers or distributors handling equipment, materials or software with a plausible military or security end-use; technology and engineering firms whose products carry encryption, sensor or navigation functions that sit close to a control list without anyone in the business having checked; and group companies that move technical data, prototypes or staff between entities in different countries as a matter of routine, not as an export event.
The trigger is rarely a shipment that was obviously wrong. It is usually a routine transaction: a sample sent to a new distributor, a software update pushed to a foreign subsidiary, a consultant travelling with a laptop, that turns out to sit inside a controlled category nobody had classified. Companies working through this within the compliance, sanctions and cyber practice tend to discover the exposure only once a counterparty, a bank or an auditor asks for the classification on file.
The foreign element changes the calculus immediately. Where the counterparty, the end-user or the parent company sits outside Sweden, the same transaction can trigger a licence requirement, a sanctions screening duty and a re-export restriction in the destination country at the same time, and the ten-day window has to cover all three, not just the Swedish classification question.
What the law says
Under Swedish law as it currently stands, export control for dual-use items sits on top of an EU-wide control list: technology, software and goods with both civilian and military applications are grouped into categories, and moving a listed item outside the EU, disclosing controlled technology to a person outside the EU, or providing technical assistance connected to a listed item, all trigger a licensing requirement rather than a paperwork formality.
The licensing authority responsible for dual-use goods decides classification questions and issues the licences that make an export lawful. It does not decide whether an item is controlled in the abstract; it decides whether the specific item, in the specific transaction, with the specific end-user, needs a licence. That is why identical products can land on different sides of the same control list depending on who is buying them and what they say they will do with them.
Sanctions add a second, independent layer. A transaction can clear export control classification entirely and still be blocked because the counterparty, the vessel, the bank or the end-user sits on a restricted list. The two checks have to run in parallel rather than in sequence, because a classification memorandum that ignores sanctions screening protects nothing.
How it works in practice
The ten-day window is not a legal deadline; it is the point at which a classification question either closes cleanly or turns into something that needs outside input. What happens inside it follows a fairly consistent order.
Day one: freeze movement, not analysis
Stop the specific shipment, disclosure or technical assistance in question without freezing the whole business. Identify exactly which transaction triggered the concern before anyone starts guessing at a category.
Day two: map every category the item could fall under
List the item's technical parameters against every plausible control category, not just the one that was flagged. Include any embedded software or technology transferred together with the physical item.
Day three: identify who classifies, and who signs off
Assign the classification decision to a named person with the authority to stop a shipment. Classification by committee, or by sales team assumption, is how the same gap gets missed twice.
Day four: screen the counterparty, not just the goods
Check the end-user statement, the actual destination, the ownership chain and whether any restricted party appears anywhere in that chain. A clean product classification means little against an unclean counterparty.
Day five: check the destination and transhipment risk
Confirm the real end destination and watch for transhipment through an intermediary country. A shipping route that does not match the stated end-use is itself a signal, independent of the product classification.
Day six: assess whether an exemption or general licence applies
Check for an available exemption before assuming a full individual licence is required. Document why an exemption does, or does not, apply; the reasoning matters as much as the conclusion.
Day seven: draft the classification memorandum
Put the decision in writing with the technical basis, the category considered and the person who signed it. This document, not the outcome, is what protects the company if the decision is tested later.
Day eight to nine: decide on voluntary disclosure
If the review uncovers a transaction that already went out without a licence, decide whether to approach the authority proactively rather than wait for an audit or a counterparty query to surface it independently.
Day ten: close the file or escalate
Either close the classification with the memorandum on file, or escalate because the item sits close to a boundary the internal team cannot resolve without outside input.
What to check before day ten
- The technical specification sheet against the applicable control categories, not the marketing description
- A signed, dated end-user statement matching the actual destination
- The ownership and group structure of the counterparty
- Whether the item has already shipped, or only been disclosed technically
- Any prior classification of the same or a similar item, and whether that decision was documented
- Contractual or insurance clauses that assume a licence already exists
Does a wrong export classification decision expose the board personally?
Yes, once the decision is treated as a governance failure rather than a technical oversight. What protects the board is not the outcome of the review but whether the decision was documented, assigned to a named person and escalated when it exceeded that person's authority. The same documentation standard that protects directors more broadly applies here: see which court or authority is competent when that protection is tested.
How does dual-use export classification differ from high-risk classification under the AI Act?
Both frameworks ask whether a product's function, not its label, puts it in a controlled category, but the logic differs. Export classification asks whether an item's military or security application requires a licence before it crosses a border; AI risk classification asks whether a system's use case inside the EU exposes people to a defined harm. A product can clear one and still fail the other, which is why the two reviews compared side by side in high-risk classification under the AI Act are worth running together.
Does checking the counterparty's beneficial owner matter for export licensing?
It matters more than the licence application form suggests. A counterparty can present a clean end-user statement while its ultimate owner, the verklig huvudman, sits on a restricted list or in a jurisdiction the licence was never meant to cover. Screening the ownership chain, not just the signatory, is part of the same ten-day review, and skipping it is one of the more common reasons a licensed transaction later attracts scrutiny.
The numbers
There is no single statutory clock that governs how long a classification review should take, and treating the ten-day window as a legal deadline rather than a working discipline is itself one of the more common mistakes. The figures that actually move the outcome are practical, not legal: how many product lines share the same technical platform and therefore the same classification question, how many jurisdictions the counterparty structure touches, and how far the transaction had already progressed before anyone raised the question.
Cost follows the same pattern. A classification reviewed before shipment costs the time of the person who does it. A classification reviewed after the goods have left, and after a bank, auditor or counterparty has already asked for the paperwork, costs the same review plus a voluntary disclosure decision, plus the time spent establishing what was actually shipped, to whom, and under what description, none of which is available once the transaction is finished and has to be reconstructed from invoices and shipping records instead of from a memorandum written at the time.
Where it usually goes wrong
A software update pushed automatically to a foreign subsidiary is not obviously an export, and treating it as routine IT maintenance rather than a technology transfer is one of the most consistent gaps a review turns up. The same applies to intra-group transfers: moving a component or a dataset between two entities of the same corporate group crosses the same control list as selling it to a stranger, and the assumption that group transactions are internal, and therefore exempt, is not supported by the classification framework itself.
Deemed export is the second recurring gap. Disclosing controlled technology to a foreign national employee, contractor or visiting engineer inside Sweden can trigger the same licensing question as physically shipping the item abroad, and businesses that classify only physical shipments miss this category entirely.
The third gap sits at the boundary between export control and sanctions. A licensed, correctly classified transaction can still be prohibited because the counterparty or an intermediary in the chain sits on a restricted list, and running the two checks separately, rather than against the same counterparty file, leaves exactly the gap a restricted party is counting on.
Where this stops being something the internal team can close alone is once the goods have already left, the technology has already been disclosed, or a licence has already been used incorrectly. At that point the question is no longer classification, it is remediation and disclosure strategy, and that decision carries consequences a ten-day internal review was never designed to absorb.
What to do next
A ten-day internal review answers the classification question for a transaction that has not yet happened. It does not answer what to do once a shipment has already gone out without a licence, once a regulator has already asked a question, or once the classification sits genuinely on a boundary between two categories with no clean answer either way. That is where an assessment starts: not a second opinion on the memorandum, but a read of the specific transaction, the counterparty file and the exposure it actually carries.
Companies running this review often carry a parallel obligation they haven't mapped yet. The entities and deadlines under the Cyber Security Act frequently overlap with the same compliance function handling export classification, and closing one without checking which entities the Cyber Security Act covers, and by when tends to produce duplicate work later rather than less of it.
Where the transaction has already moved, or the classification sits on a genuine boundary, book an assessment before deciding whether disclosure, remediation or a formal licence application is the right next step.