A technology exporter finalises a distribution agreement with a regional reseller. The reseller has cleared an OFAC screen. It does not appear on any EU or UN list. The compliance team marks the file closed. Six months later, BIS issues a notice: the reseller's subsidiary is on the Entity List, and several of the shipments involved items with a Commerce Control List classification requiring a licence the exporter never sought. The OFAC screen was, by itself, correct. The BIS analysis was never done.
Counterparty due diligence under BIS and the EAR (the Export Administration Regulations, the primary US export-control instrument administered by the Bureau of Industry and Security) differs structurally from sanctions screening under OFAC, OFSI, or the EU regime. BIS due diligence is item-led and end-use-led, not list-led alone. The Entity List (BIS's list of parties subject to licence requirements imposed for national-security or foreign-policy reasons) is only one of several BIS-administered restriction lists, and list status is only one variable in the analysis. A counterparty may pass every list screen and still require a licence – or be prohibited – depending on what is being shipped, to where, and for what stated purpose.
This analysis sets out the key divergences between BIS / EAR counterparty due diligence and the parallel obligations under OFAC, OFSI, and the EU regime, identifies the risk flags practitioners see most frequently, and explains when the analysis requires qualified export-control counsel.
The governing regime: BIS, the EAR, and the structure of US export controls
BIS administers the EAR under authority delegated through the Export Control Reform Act and, ultimately, IEEPA. The EAR controls the export, re-export, and in-country transfer of items on the Commerce Control List (CCL) – a tiered inventory of dual-use goods, software, and technology, each assigned an ECCN (Export Control Classification Number) that maps to a set of control reasons and corresponding licence requirements by destination.
The counterparty analysis under the EAR runs in two parallel tracks. The first is list screening: BIS maintains several restriction lists, the most significant being the Entity List, the Denied Persons List (persons whose export privileges have been revoked), and the Unverified List (parties for whom BIS has been unable to verify end-use). The second track is the transaction analysis: even where no list hit exists, an exporter must determine whether the item's ECCN, the destination, and the end-use together require a licence or trigger a licence exception. These two tracks operate independently, and both must be completed.
This architecture distinguishes BIS due diligence from OFAC screening. OFAC's SDN List (the list of Specially Designated Nationals and blocked persons) operates as a near-absolute prohibition tied to the identity of a party. Under BIS, the identity of the party is one variable among several. Two shipments to the same counterparty may attract entirely different treatment depending on the item's CCL classification.
How the Entity List and the Denied Persons List work in practice
An Entity List designation imposes a licence requirement – typically a presumption of denial – for any export, re-export, or transfer to the named party of any item subject to the EAR, not only of items that would otherwise require a licence. This means that a low-classification item that would qualify for a licence exception in the ordinary course becomes licence-required when the recipient is on the Entity List, and the presumption of denial means the licence is likely to be refused.
The Denied Persons List is stricter still. A denial order suspends the party's export privileges outright; US persons and entities are prohibited from participating in any transaction involving a denied party, even as an intermediary or freight forwarder. In our experience, compliance programmes that focus exclusively on the Entity List and the SDN List routinely miss Denied Persons List hits – particularly where the denied party operates through an affiliated distributor not separately named.
The Unverified List carries a different and often underappreciated consequence. BIS adds parties to the list where it has been unable to conduct a pre-licence or post-shipment verification, typically because access was denied or the party was uncontactable. A counterparty on the Unverified List is not prohibited, but several licence exceptions (standing authorisations that permit defined exports without a separate application) become unavailable for shipments to that party. An exporter relying on an exception for an otherwise EAR99 or low-ECCN item must verify the Unverified List, not only the Entity List.
Where does BIS / EAR counterparty due diligence diverge from OFAC screening?
The most significant structural divergence is that OFAC screening is primarily identity-based, while BIS due diligence is primarily transaction-based. Under OFAC, a counterparty either is or is not a blocked person or a person subject to a specific programme prohibition, and that status applies uniformly across all transactions with that party. Under the EAR, list status, item classification, destination, and end-use each independently influence the result, and the analysis must be run for each transaction.
A second divergence concerns the 50 percent rule. Under OFAC, any entity owned 50 percent or more in the aggregate by one or more blocked persons is itself treated as blocked, regardless of whether it appears on a list. The rule is mechanical: share of ownership is the trigger, not control or managerial influence. The EU and UK regimes (OFSI) apply a broader ownership-and-control test, which can catch entities where listed persons exercise decisive influence even below the 50 percent threshold.
BIS has no equivalent 50 percent rule. An entity wholly owned by an Entity List party is not automatically subject to Entity List restrictions unless it is itself named. However, BIS's knowledge standard is critical here: an exporter who has reason to know that an item will be re-exported to or through an Entity List party, or diverted to a prohibited end-use, must treat the transaction as if the prohibition applied directly. In our practice, this knowledge standard functions as the BIS analogue to the OFAC ownership test – it requires exporters to look beyond the immediate counterparty to the full transaction chain.
Consider the divergence in practical terms. A distributor incorporated in a third country that is majority-owned by an OFAC SDN is itself blocked under OFAC; no transaction with it is permissible without a licence. The same distributor, if not itself listed by BIS, may receive EAR-controlled items under certain conditions – but only if the exporter has no knowledge, actual or constructive, that the ultimate recipient or end-use triggers a restriction. Where the ownership chain is known, that knowledge standard is almost certainly engaged. A compliance programme that treats the OFAC screen as dispositive for the BIS analysis will miss this category of risk entirely.
The end-use and end-user certificate: a tool with no OFAC equivalent
One instrument that is central to BIS due diligence but absent from OFAC or EU sanctions compliance is the end-use certificate or end-user statement: a document in which the buyer represents the identity of the ultimate consignee, the intended end-use, and, where relevant, a commitment not to re-export without authorisation. For certain CCL classifications and destinations, the EAR requires such a statement as a condition of the licence exception or as supporting documentation for a licence application.
The end-use certificate serves a due-diligence function beyond its documentary purpose. The process of obtaining and reviewing it forces the exporter to surface the end-use and ultimate consignee information that the transaction-based analysis requires. A distributor unwilling to provide an end-user statement, or one that provides a statement containing implausible or internally inconsistent information, is a material red flag under the EAR's knowledge standard. Under OFAC, the parallel test is the reasonably practicable ownership and control inquiry; under EU and OFSI regimes, it is the ownership-and-control analysis. The BIS tool is different, but the risk-signal it produces is structurally similar.
In a recent matter, a manufacturing business had shipped components through a distributor for several years without incident. A review of renewal documentation for the annual end-user statement revealed that the stated end-user had changed – the new entity was in a country subject to heightened BIS scrutiny – and the stated application had shifted from the commercial product described in prior years to an application consistent with a military end-use. We advised the client to suspend shipments, conduct an enhanced end-use review, and engage directly with BIS. The disruption to the commercial relationship was significant, but the alternative – continued supply against an end-use statement the client now had reason to doubt – would have engaged the knowledge standard directly.
Red flags and the knowledge standard: what triggers enhanced due diligence?
The EAR's knowledge standard is broader than simple actual knowledge: it includes what a party in similar circumstances would know, meaning that wilful blindness to obvious red flags does not provide a defence. BIS has published non-exhaustive guidance on indicators that should prompt enhanced inquiry; these indicators are sometimes called "red flags" in practitioner shorthand.
The most common red flags in cross-border B2B transactions include the following. A counterparty declines to identify the end-user or ultimate consignee. The stated end-use is inconsistent with the counterparty's business profile or the volume of goods ordered. Payment terms or routing are unusual for the industry or jurisdiction. The counterparty requests removal of the manufacturer's name, country of origin, or ECCN from documentation. The destination country is on a BIS heightened-scrutiny list. The goods have a high strategic value relative to the commercial purpose stated.
How does the OFAC standard compare? OFAC's equivalent concept is the reason to know standard, applied in assessing whether a transaction violates a programme prohibition and whether a voluntary self-disclosure (VSD – a disclosure to OFAC of a potential violation before enforcement action is commenced) would be appropriate. The functional operation is similar: actual knowledge is not required, and ignoring obvious indicators is not a defence. The difference is that under the EAR the inquiry is anchored to the transaction – the item, the end-use, the route – while under OFAC it more often centres on the counterparty's identity and ownership structure.
Does your compliance programme capture both tracks? In our experience, most export compliance programmes run list screening well. Fewer integrate the transaction-based, end-use-focused inquiry that BIS requires as a separate and independent step.
The position above covers the structural analysis. Your specific facts – the item's CCL classification, the destination, the counterparty's position in the supply chain, and any indicators already known to your team – change the risk assessment materially. For an assessment of your exposure under the EAR, contact Calder & Vance at info@caldervance.com.
Re-export controls and extraterritorial reach: the BIS dimension OFAC and EU screens miss
One of the most operationally consequential features of the EAR is its extraterritorial reach through re-export controls. Items subject to the EAR remain subject to BIS jurisdiction after they leave the United States, wherever they travel and whoever holds them. A non-US distributor that receives US-origin goods and then transfers them to a third-country buyer must comply with EAR re-export requirements, even if that transfer is entirely outside the United States and involves no US person.
The de minimis rule and the foreign-direct product rule (FDPR) extend BIS jurisdiction further. Under the de minimis rule, foreign-made items that incorporate US-origin controlled content above a defined threshold level remain subject to EAR when exported or re-exported. Under the FDPR, certain foreign-produced items that are the direct product of US-origin technology or software subject to the EAR are themselves subject to EAR jurisdiction, even if they contain no US-origin components. As of mid-2026, the FDPR has been significantly expanded in recent years, meaning that non-US manufacturers using US semiconductor design software or US-origin manufacturing equipment face EAR jurisdiction over a wider range of their output than they did five years ago.
This extraterritorial reach has a direct bearing on counterparty due diligence. A non-US business purchasing from a non-US supplier may be acquiring items that carry EAR re-export obligations without realising it. A due-diligence programme limited to OFAC and EU list screening will not surface this exposure. Where a supply chain involves US-origin goods, US-origin technology, or items produced using US equipment or software, the counterparty due diligence must include a determination of whether the EAR applies to any link in the chain.
OFSI and the EU regime do not operate an equivalent re-export-control mechanism. EU dual-use rules impose export controls on EU-origin goods and on certain transfers of technology within the EU, but they do not assert jurisdiction over goods after they have left EU territory in the way the EAR does. The UK Export Control Order operates similarly. For a business managing a supply chain that spans US, EU, and UK origins, the BIS re-export analysis must run in parallel with, and independently of, the EU and UK export-control assessment.
When does the stricter prohibition govern? Interaction with OFAC, EU, and UK sanctions
A cross-border business subject to both OFAC and BIS jurisdiction, and potentially to EU or UK sanctions obligations, must apply the strictest prohibition that applies to any given transaction. This is the governing principle where the regimes overlap: compliance with the less restrictive regime does not excuse a violation of the more restrictive one.
In practice, this creates several interaction patterns that counterparty due diligence must anticipate. First, a counterparty who passes an Entity List screen may nonetheless be blocked under OFAC's SDN List or under an EU or UK programme, in which case the OFAC or EU/UK prohibition governs and no BIS licence exception analysis is relevant. Second, a counterparty who passes all list screens may still be prohibited under the EAR on end-use grounds – the transaction-based track of BIS analysis that has no direct OFAC equivalent. Third, an item may require a BIS licence for export to a given destination even where the counterparty is clean under all sanction programmes, because the CCL classification and destination controls impose that requirement independently of any party-based restriction.
Secondary-sanctions risk adds a further layer. US secondary sanctions, applied through OFAC under IEEPA and programme-specific executive orders, can affect non-US parties who conduct significant transactions with targets of certain US programmes. A non-US distributor engaged in significant business with parties in a programme-covered jurisdiction may face OFAC secondary-sanctions exposure even if it is not itself designated, and even if the goods involved are not subject to the EAR. A counterparty due diligence programme that addresses BIS compliance without considering OFAC secondary-sanctions risk is structurally incomplete for non-US counterparties with exposure to covered jurisdictions.
If a transaction has been flagged by a compliance filter, or if a filing has been refused, an early legal review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss the position.
Common deficiencies in cross-border counterparty due diligence programmes
In our cross-border practice, the same structural deficiencies appear repeatedly in export compliance programmes that were designed for OFAC or EU sanctions screening and then extended, without redesign, to cover BIS obligations.
The most common deficiency is the conflation of list screening with transaction-based analysis. A programme that screens counterparties against the Entity List, SDN List, and EU and UN consolidated lists, and then closes the file on a clean result, has not completed the BIS due diligence. The CCL classification, licence-exception eligibility, and end-use analysis remain to be done.
The second common deficiency is inconsistent screening of all BIS restriction lists. The Entity List receives the most attention, but the Denied Persons List and the Unverified List carry consequences that a single-list screen will miss, as described above. In our experience, screening tools and internal procedures that reference the Entity List by name but sweep in the other lists only by implication frequently fail to update when BIS adds or removes parties from the secondary lists.
A third deficiency involves supply-chain mapping. The EAR's knowledge standard requires the exporter to look beyond the immediate buyer to the ultimate consignee and the end-use. Programmes that rely on contractual representations from the immediate counterparty, without any process for verifying or monitoring those representations, are exposed when the counterparty re-routes goods or changes end-use without notifying the exporter.
A related myth in this space is worth addressing directly: that EAR compliance is a concern only for manufacturers and exporters of high-technology items, not for distributors, resellers, or service providers. This is incorrect. The EAR applies to any party that facilitates an export or re-export of items subject to its jurisdiction – including freight forwarders, financial intermediaries arranging payment for controlled-goods transactions, and software resellers. The anti-boycott provisions of the EAR apply still more broadly, extending to any US person who receives a boycott-related request in the course of inter-state or foreign commerce, regardless of the goods involved.
What a cross-border counterparty due diligence programme should cover
A BIS-compliant counterparty due diligence programme for a cross-border business operating in both the US-controlled and non-US controlled environments requires at least the following elements.
First, item classification. Every item in the product or service portfolio must be classified against the CCL. Items not on the CCL are designated EAR99 and generally do not require a licence for most destinations and end-uses, but they are not exempt from all EAR obligations – in particular, EAR99 items may not be shipped to parties on the Entity List without a licence, and they remain subject to the knowledge standard on end-use.
Second, a multi-list screening protocol. Screening must cover at minimum the Entity List, the Denied Persons List, the Unverified List, the OFAC SDN List, the OFAC Consolidated Sanctions List, the EU Consolidated List, the UN Consolidated List, and any applicable UK OFSI financial-sanctions list. Where the business has operations in or counterparties from Singapore, Japan, UAE, Australia, Canada, or Switzerland, the applicable national restriction lists must also be included.
Third, a transaction-based analysis triggered by the item's CCL classification. For any item with an ECCN, the analysis must determine whether a licence is required for the specific destination and end-use, whether a licence exception is available, and whether the counterparty's position on any restriction list affects exception eligibility.
Fourth, end-use documentation and red-flag monitoring. The programme must include a process for obtaining, reviewing, and retaining end-user statements, and a protocol for identifying and escalating the red flags identified above. Record-keeping must be maintained for the applicable statutory period; under the EAR, records of export transactions must generally be kept for five years from the date of the transaction or the latest action related to it.
Fifth, a re-export analysis for any non-US links in the supply chain. Non-US subsidiaries, distributors, and logistics partners handling US-origin goods or FDPR-covered items must be included in the due-diligence scope, with written guidance on their re-export obligations.
Sixth, a voluntary self-disclosure protocol. Where a review identifies a potential EAR violation – an unlicensed export, an unreported end-use diversion, or a transaction with an Entity List party – the programme must provide a clear internal escalation and decision-making process for assessing whether a VSD is appropriate. A timely and well-documented VSD is a recognised mitigating factor in BIS enforcement; the absence of a programme for identifying and managing potential violations is an aggravating one.
Related practices
- Compliance audit and testing – assessing the effectiveness of sanctions screening and export-control procedures against current regime requirements.
- Counterparty due diligence: EU vs SECO – how the EU Council regulation and Swiss SECO controls diverge in counterparty analysis and cross-border supply-chain screening.
- Counterparty due diligence under OFAC – the identity-based analysis, the 50 percent rule, and the OFAC screening obligation for US and non-US persons.