A US-headquartered group acquires a European technology business and assumes, reasonably, that the new subsidiary's export-compliance programme meets group standard. Eighteen months later, a routine internal audit surfaces shipments of dual-use items to consignees that were on the BIS Entity List at the time of delivery. The items had never been classified. The end-use certificates were incomplete. Nobody had tested the screening logic since implementation. The exposure is real, and the window for voluntary self-disclosure (a VSD – a formal, proactive disclosure to the regulator before it discovers the violation independently) is closing.
Compliance audit and testing under BIS / EAR is the structured, documented process by which an organisation verifies that its export-control programme works in practice, not just on paper. The governing authority is the Bureau of Industry and Security (BIS), operating under the Export Administration Regulations (the EAR). A programme that has not been independently tested cannot reliably detect the classifications, screening failures, and end-use gaps that BIS enforcement actions consistently expose.
This analysis covers what the BIS / EAR compliance audit and testing standard requires, where businesses systematically fall short, how the comparable EU dual-use and UK export-control regimes diverge, and what a cross-border operation should do before the auditor – or the regulator – arrives.
What does the BIS / EAR compliance-programme standard actually require?
BIS has articulated its expectations through published enforcement guidance and its stated approach to evaluating mitigating factors in penalty determinations. A compliant programme under the EAR is not defined by a single mandatory checklist; it is assessed holistically against a set of recognised elements that BIS weighs when deciding whether a voluntary self-disclosure or a penalty negotiation reflects genuine systemic controls or a paper compliance exercise.
The five elements BIS consistently considers are: committed senior management support; risk-based product and country screening; export classification procedures covering the Commerce Control List; a training programme that reaches operational staff, not only compliance personnel; and ongoing auditing and testing. That final element is the one most frequently absent or deficient when enforcement contact occurs. An organisation can have the first four elements documented to a high standard and still face significant exposure if it has never tested whether the procedures actually produce compliant decisions.
What does "testing" mean in practice? It means more than reviewing written procedures. It means running transaction samples through the classification process and checking outputs against the ECCN (Export Control Classification Number – the alphanumeric code under the Commerce Control List that determines whether an item requires a licence, qualifies for an exception, or is classified as EAR99). It means querying whether screeners are checking the Entity List, the Denied Persons List, the Unverified List, and the Military End-User List, not merely the SDN List (OFAC's Specially Designated Nationals and blocked persons list, which is distinct from the BIS derogatory lists). Confusing OFAC screening with BIS screening is among the most common errors we see in practice.
In our practice, the audit function that impresses BIS in a VSD context is one that can demonstrate a recurring, documented testing cycle with defined sample sizes, clear pass/fail criteria, root-cause analysis for failures, and a remediation log showing that identified gaps were closed.
Where do businesses miss: the six recurrent failure modes
The gap between what a compliance programme describes and what it produces is almost always located in one of six places. Identifying which applies requires testing, not self-certification.
The first failure mode is classification by assumption. A business assumes that an item it has sold for years is EAR99 – that is, subject to the EAR but not listed on the Commerce Control List and therefore requiring no licence for most destinations – without having performed a documented analysis. The product is then redesigned, or the technology it embodies advances past a performance parameter, and the item quietly crosses into a controlled ECCN without anyone noticing. Classification cannot be a one-time exercise; it must be revisited when specifications change and when the Commerce Control List is amended.
The second failure mode is screening against the wrong list. Some organisations screen only against OFAC's SDN List when BIS requires separate screening of its own derogatory lists, each of which imposes different obligations. An entity that is not on the SDN List may be on the Entity List, requiring a licence that is generally presumed to be denied. Testing the screening configuration is essential.
The third failure mode is the untested licence exception. The EAR permits certain exports without a licence if specific conditions are met. Those conditions are transaction-specific and fact-dependent. A compliance programme that permits staff to self-select an exception without documented verification of eligibility creates exposure every time the exception is misapplied. Testing should sample exception use and verify the conditions were checked and recorded at the time of the shipment.
The fourth failure mode is the inherited subsidiary. When a business is acquired, the acquirer's export-compliance obligations extend to the acquired entity from closing. In our experience, integration audits are routinely deferred, and the subsidiary continues operating under its pre-acquisition procedures – procedures that may not have reflected the EAR at all, particularly for non-US businesses that had not previously considered themselves subject to US controls. The de minimis rule and the foreign direct product rule are the two EAR extraterritoriality mechanisms most commonly overlooked in post-acquisition reviews.
The fifth failure mode is training that does not reach the decision-makers. Compliance training delivered only to the compliance team, and not to sales, logistics, engineering, and finance, leaves the people who make classification and shipping decisions without the knowledge to flag problems. Audit should test not just whether training occurred but whether it was effective: did staff who completed the training make fewer errors in the subsequent period?
The sixth failure mode is a testing programme that tests only what the programme describes, not what actually happens. A procedure that calls for dual classification review is tested by checking whether two reviewers signed the form, not by checking whether the classification itself was correct. Substantive testing – checking the accuracy of outputs – is distinct from procedural testing, which checks only whether the steps were followed. Both are necessary.
How does the BIS / EAR audit standard compare with EU and UK controls?
The cross-border dimension matters because most businesses subject to the EAR also operate under the EU dual-use regime or the UK Export Control Order, and the compliance expectations of each regime differ in structure even where they converge in intent.
Under the EU dual-use rules, the obligation to maintain an internal compliance programme – what the EU framework calls an Internal Compliance Programme (ICP) – is explicitly linked to access to certain simplified licensing procedures and global licences. An ICP is not mandated for all exporters, but its absence disqualifies an organisation from the most flexible licensing routes. EU authorities assess ICPs against published criteria covering commitment, structure, process, records, and auditing. The audit and testing limb of an EU ICP therefore has a licensing-access function that is structurally different from the BIS context, where compliance-programme quality is relevant primarily to penalty mitigation.
The UK position, administered by ECJU under the Export Control Order, is broadly analogous to the EU structure in its ICP requirements, though the two regimes have diverged since the UK's departure from the EU regulatory framework. A UK exporter holding an Open General Export Licence is expected to maintain internal controls commensurate with the scope of that licence. ECJU's compliance and outreach programme conducts periodic assessments of licence holders, and a failure to maintain adequate records or testing can result in revocation of the licence and referral to law enforcement.
The practical divergence that matters most for cross-border operations is the trigger for an audit obligation. Under the EAR, BIS does not impose a statutory audit frequency; the expectation is that a compliant programme will include periodic, risk-based testing. EU and UK regimes tie audit expectations more explicitly to the licence or authorisation held. For a business managing all three regimes, the most demanding standard in each area should govern the programme design. Where the regimes diverge, the stricter prohibition or obligation applies; a cross-border programme that meets only the least demanding of three applicable regimes is, by definition, non-compliant under the other two.
Our compliance counsel regularly advises on reconciling these three regimes into a single, coherent audit and testing programme. The reconciliation exercise is less technically complex than it first appears; the regimes share common architecture. The difficulty is operational: ensuring that the testing protocols are genuinely integrated rather than three parallel processes that generate inconsistent outputs.
The position above covers the standard cross-border case. Your facts – the goods, the destinations, the licence types held, the ownership of the group – change the analysis considerably.
For an assessment of your BIS / EAR compliance-audit exposure and how it interacts with your EU or UK obligations, contact Calder & Vance at info@caldervance.com.
The extraterritorial dimension: why non-US businesses cannot ignore BIS / EAR audit obligations
A European or Asian manufacturer may believe that BIS / EAR compliance audit is a US-business question. That belief is incorrect, and it is one of the most consequential misapprehensions in cross-border export-control practice.
The EAR applies extraterritorially through two primary mechanisms. The first is the de minimis rule: goods that incorporate more than a defined threshold of controlled US-origin content are subject to the EAR when re-exported from a third country, regardless of whether the exporter has any US connection beyond that content. The second is the foreign direct product rule, which extends EAR jurisdiction to certain foreign-made items produced using US technology or software, or using equipment that itself is a direct product of certain US-origin technology. Both mechanisms mean that a non-US business may be exporting EAR-controlled items without ever having assessed whether the EAR applies to its products.
A compliance audit for a non-US business with US-origin content in its supply chain therefore includes a de minimis calculation as a foundational step. If the calculation has never been performed, the business does not know whether it is subject to the EAR. And if it is subject to the EAR without knowing it, its programme – however well-designed for the EU or UK regime – is not addressing the actual risk.
The BIS Entity List further complicates the picture. The Entity List includes non-US entities. A non-US business exporting to another non-US business that is on the Entity List requires a BIS licence for items subject to the EAR, regardless of the exporter's nationality. Screening programmes that do not check the Entity List – often because the business assumed the EAR did not apply – will miss this obligation entirely.
In a recent matter, a European technology supplier with long-standing US component relationships had never assessed whether its products crossed the de minimis threshold. An internal audit, conducted following a change of ownership, identified two product lines that were subject to the EAR. One of those product lines had been shipped to a consignee listed on the Entity List. The compliance counsel's role was to scope the apparent violation, advise on voluntary self-disclosure, and prepare the supporting documentation. The matter required careful, structured engagement with BIS; early action preserved options that would have narrowed materially had the issue surfaced through enforcement rather than self-identification.
What does a rigorous BIS / EAR compliance audit look like in practice?
A compliance audit under the EAR that would withstand BIS scrutiny – whether as part of a VSD package or a penalty mitigation submission – has several identifiable characteristics. A business can use this as a benchmark for assessing its own programme.
First, the audit has a defined scope document that identifies the population of transactions to be reviewed, the period covered, the legal standard being tested, and the methodology for sampling. Sample selection should be risk-weighted: higher risk destinations, larger transaction values, items in controlled ECCNs, and transactions involving any party that appeared on a derogatory list at any point in the period.
Second, the audit uses independent reviewers. Self-assessment by the same team that conducted the transactions being reviewed has limited evidentiary value. Independence does not require an external engagement for every audit cycle; it means the reviewers did not make the decisions being reviewed. For the highest-risk product lines or destinations, an external review adds credibility that is particularly valuable in a VSD or enforcement context.
Third, the audit tests classification accuracy, not just classification process. This means taking a sample of items that were shipped as EAR99 or under a specific ECCN and verifying, from the technical specifications, whether the classification was correct. In our experience, classification errors are most frequently found in categories involving performance parameters – telecommunications equipment, electronics, sensors – where the threshold between EAR99 and a controlled ECCN is defined by a technical specification that changes as the product evolves.
Fourth, the audit produces a written report with findings graded by severity, a root-cause analysis for each failure mode identified, and a corrective-action plan with assigned ownership and deadlines. A report that catalogues findings without identifying root causes does not produce programme improvement; it produces a list of symptoms.
Fifth, the audit cycle is documented and recurring. A one-time audit, conducted in response to a specific concern, is not a compliance programme. BIS weighs the existence of a prior, systematic audit history when evaluating whether a disclosed violation was the product of a weak programme or an isolated failure in an otherwise sound one. That distinction can be significant in the penalty calculation.
Risk flags: when the compliance audit reveals a potential violation
What happens when the audit finds something? This is the question that senior management is often unprepared to answer when they commission an audit. The answer determines whether the business controls the narrative or loses it.
An audit finding that suggests an apparent violation of the EAR – a shipment to a denied party, an unlicensed export of a controlled item, a licence exception that was not applicable – requires an immediate legal privilege assessment. The audit report and its underlying workpapers may be subject to attorney-client privilege if the audit was conducted under legal direction with the purpose of obtaining legal advice. If it was not structured that way, the documentation may be discoverable in subsequent enforcement proceedings.
The decision on whether to submit a VSD is one of the most consequential in export-control law. A timely, well-prepared VSD submitted before BIS has opened its own investigation is a significant mitigating factor. A VSD submitted after BIS has made contact, or one that is incomplete or inaccurate, is not treated with the same weight. The decision should not be made on the basis of internal risk tolerance alone; it requires legal analysis of the apparent violation, the likely BIS enforcement posture, the secondary-sanctions exposure in other regimes, and the disclosure obligations that may apply under other applicable rules.
A second consideration is the multi-regime dimension. A BIS apparent violation that involves an item with EU dual-use controls may give rise to separate reporting obligations under the applicable EU or member-state regime. A UK business with the same fact pattern faces ECJU. If a financial institution was involved in settling the transaction, OFAC may also be relevant if the counterparty had US-dollar exposure. A compliance audit that uncovers a BIS issue in a cross-border context should immediately be assessed for each of the other regimes in play.
If a transaction has already been flagged, or an audit has surfaced a potential breach, an early legal review can preserve options that narrow with time. For confidential advice on an apparent violation under BIS / EAR, write to info@caldervance.com.
Common myths and what the law actually says
The most persistent myth in BIS / EAR compliance is that a product classified as EAR99 requires no compliance monitoring. This is incorrect on two counts.
EAR99 items are still subject to the EAR. They cannot be exported to parties on BIS derogatory lists without a licence. They cannot be exported with knowledge that they will be used in a prohibited end-use. And they can change ECCN classification as the product evolves or as the Commerce Control List is amended. EAR99 means "not currently controlled under a specific ECCN" – it does not mean "outside the EAR". A compliance programme that does not test EAR99 items for end-user screening and end-use review is leaving a material gap.
The second myth is that the EAR is only a US exporters' problem. As set out above, the de minimis rule and the foreign direct product rule extend EAR jurisdiction to foreign-manufactured goods containing or derived from US-controlled technology. A European, Asian, or Middle Eastern manufacturer with US-origin components or technology in its products may be subject to the EAR for every shipment it makes, without any US nexus beyond the supply chain. We regularly advise businesses that have discovered this exposure years into their operations, often following an acquisition or a change of supply chain that first brought US-origin content into the product.
The third myth is that a compliance programme that passed an internal audit last year is adequate today. The EAR is an actively amended instrument. The Entity List is updated regularly. Product specifications change. Counterparty ownership changes. A programme that was tested against last year's legal environment and last year's product range may not be adequate today, and certainly is not adequate if the business has grown, acquired, or changed its supply chain in the intervening period.
How Calder & Vance conducts BIS / EAR compliance audits and testing
Our export-control practice covers the full audit and testing cycle for BIS / EAR compliance. We do not offer a generic checklist engagement; we structure the audit to the client's actual risk profile – its products, its markets, its ownership structure, and its prior compliance history.
Our approach begins with a scoping assessment: mapping the product range against the Commerce Control List, identifying the applicable ECCNs and the relevant licence requirements and exceptions, and establishing the counterparty universe by destination and entity type. That scoping exercise frequently reveals classification gaps before the main audit begins.
We then design and execute the testing programme: selecting the transaction sample, running the substantive classification and screening tests, and producing a graded findings report with root-cause analysis and a corrective-action plan. Where the findings suggest an apparent violation, we advise on privilege structuring, VSD eligibility, and – where relevant – the interaction with the EU dual-use regime, UK export controls, and OFAC.
For businesses operating across the US, EU, and UK regimes simultaneously, we offer an integrated audit approach that tests all three regimes against a single transaction sample, with findings mapped by regime. This avoids the inefficiency of three separate audit exercises and, more importantly, identifies cross-regime discrepancies that a single-regime audit will not surface.
In our cross-border practice, we have found that the audit function most valued by both internal stakeholders and regulators is one that produces actionable findings – not a compliance-literature review, but a tested assessment of what the programme actually produced in the period under review.
Related practices
- Compliance audit and testing – Australia – sanctions compliance auditing under Australia's autonomous-sanctions regime and DFAT controls
- Compliance audit and testing under EU dual-use controls – how the EU Internal Compliance Programme standard compares with BIS / EAR expectations
- EU vs SECO compliance audit and testing compared – cross-regime analysis of EU and Swiss export-control audit obligations