AWS · AWS Customer Agreement · View original document ↗

Export Controls and Sanctions Compliance

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time AWS changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for AWS Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The agreement requires both parties to comply with applicable export control laws and sanctions programs, including EAR, ITAR, and OFAC. Customers bear sole responsibility for export compliance related to how they use AWS services, including content transfer, processing, and region selection. Customers also represent and warrant that they and their financial institutions are not on any prohibited party lists maintained by the UN, U.S. government, EU, or member states.

This analysis describes what AWS's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The provision places sole responsibility for export control compliance on the customer for their specific use of AWS services, including content and workload characteristics, and requires affirmative representation that the customer and its financial institutions are not subject to sanctions. Violation of export control representations could constitute a material breach triggering immediate termination under Section 5.2(b)(ii).

Consumer impact (what this means for users)

Under Section 11.6, customers affirmatively represent that they and their financial institutions are not subject to sanctions or listed on prohibited party lists, and assume sole responsibility for ensuring their use of AWS services complies with applicable export control and sanctions regulations. Breach of these representations may constitute grounds for immediate suspension or termination under Sections 4.1 and 5.2(b)(ii).

Cross-platform context

See how other platforms handle Export Controls and Sanctions Compliance and similar clauses.

Compare across platforms →

Monitoring

AWS has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
In connection with this Agreement, each party will comply with all applicable import, re-import, sanctions, anti-boycott, export, and re-export control laws and regulations, including all such laws and regulations that apply to a U.S. company, such as the Export Administration Regulations, the International Traffic in Arms Regulations, and economic sanctions programs implemented by the Office of Foreign Assets Control. For clarity, you are solely responsible for compliance related to the manner in which you choose to use the Services or AWS Content, including your transfer and processing of Your Content, the provision of Your Content to End Users, and the AWS region in which any of the foregoing occur.

Excerpt from AWS's Customer Agreement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly implicates the Export Administration Regulations administered by the Bureau of Industry and Security, ITAR administered by the Directorate of Defense Trade Controls, and OFAC sanctions programs administered by the U.S. Department of the Treasury. For international customers, EU dual-use export control regulations and member state implementing legislation may also apply. The UN Security Council consolidated sanctions list is specifically referenced. Criminal and civil penalties under these frameworks are substantial and separate from contractual consequences. 2. GOVERNANCE EXPOSURE: High. The requirement that customers represent their financial institutions are not subject to sanctions is notable, as customers may not have direct control over or continuous visibility into the sanctions status of their banking relationships. Changes in ownership, financial institution relationships, or operational geographies may require re-evaluation of this representation. 3. JURISDICTION FLAGS: Customers operating in or serving users in sanctioned jurisdictions face elevated exposure. International customers subject to conflicting export control regimes (such as EU anti-boycott regulations that may conflict with U.S. sanctions requirements) should seek legal counsel on compliance obligations. Customers in the defense and aerospace sectors using AWS for workloads that may be subject to ITAR should confirm appropriate AWS GovCloud or ITAR-compliant service configurations. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should include export control screening as part of AWS account setup and ongoing compliance monitoring, including screening of any third parties accessing the account. The representation regarding financial institution sanctions status should be validated and documented at contract inception and reviewed periodically. Organizations using AWS for international data transfers should confirm that their AWS region selections do not inadvertently route traffic through sanctioned jurisdictions. 5. COMPLIANCE CONSIDERATIONS: Export control compliance programs should be reviewed to ensure they address cloud service use, including content classification for EAR and ITAR applicability, end user and destination screening, and AWS region selection for applicable workloads. Legal teams should assess whether any dual-use technology, encryption, or controlled data processed through AWS services requires export licenses or is subject to license exceptions.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Provision details

Document information
Document
AWS Customer Agreement
Entity
AWS
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014475
Document ID
CA-D-00674
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
9df8e129bfd7d38f49d5f527b5c87cb344da507e62f98112482fffa7af8bd0f0
Analysis generated
July 9, 2026 05:40 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: AWS
Document: AWS Customer Agreement
Record ID: CA-P-014475
Captured: 2026-07-09 05:40:32 UTC
SHA-256: 9df8e129bfd7d38f…
URL: https://conductatlas.com/platform/aws/aws-customer-agreement/provision/CA-P-014475/export-controls-and-sanctions-compliance/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does AWS's Export Controls and Sanctions Compliance clause do?

The provision places sole responsibility for export control compliance on the customer for their specific use of AWS services, including content and workload characteristics, and requires affirmative representation that the customer and its financial institutions are not subject to sanctions. Violation of export control representations could constitute a material breach triggering immediate termination under Section 5.2(b)(ii).

How does this clause affect you?

Under Section 11.6, customers affirmatively represent that they and their financial institutions are not subject to sanctions or listed on prohibited party lists, and assume sole responsibility for ensuring their use of AWS services complies with applicable export control and sanctions regulations. Breach of these representations may constitute grounds for immediate suspension or termination under Sections 4.1 and 5.2(b)(ii).

Is ConductAtlas affiliated with AWS?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by AWS.