Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · BIS / EAR

BIS / EAR vs EU: End-use and end-user controls: what businesses miss

A semiconductor company based in Germany receives an order from a distributor in a third market. The goods carry an ECCN (Export Control Classification Number under the US Commerce Control List) that triggers controls under the Export Administration Regulations. The distributor looks clean. Its named directors are not listed anywhere. The transaction appears routine.

Then the compliance team asks a harder question: what will the distributor do with the components, and who will it sell them to? That question – simple in form, complex in law – sits at the heart of end-use and end-user controls under BIS / EAR and the parallel EU dual-use regime. The two regimes approach it differently, and the gap between them decides whether a shipment is lawful, requires a licence, or must be refused entirely.

End-use and end-user controls under BIS / EAR and the EU dual-use rules each prohibit exports where the exporter knows or has reason to know that goods or technology will be used in prohibited programmes or by prohibited parties. The BIS / EAR regime is broader in extraterritorial reach and imposes specific red-flag duties on US-origin items wherever they travel. The EU regime is anchored in the exporter's location and applies a catch-all that is narrower in geographic trigger but increasingly significant in practice. Neither regime is uniformly stricter across all dimensions, and a business operating under both simultaneously faces the possibility that one regime permits what the other prohibits.

This analysis maps the two regimes criterion by criterion – the legal basis, the end-use test, the end-user assessment, the red-flag standard, the catch-all provisions, and the practical consequences of a breach – and sets out what cross-border businesses most often overlook.

What legal authority underpins each regime?

The BIS / EAR regime derives its authority from the Export Control Reform Act and is administered by the Bureau of Industry and Security within the US Department of Commerce. It applies to items that are subject to the EAR by virtue of their US origin, their US content above a defined de minimis threshold, or their manufacture using controlled US technology. The territorial reach extends far beyond US borders. A German re-exporter, a Singaporean distributor, and a Japanese manufacturer incorporating a controlled US component all remain subject to EAR requirements when they move that item onward.

The EU dual-use regime rests on a Council Regulation that establishes a common list of controlled items and a common licensing structure across EU member states. Day-to-day administration falls to national competent authorities – in practice, the export-control agencies of each member state. There is no single EU-level enforcement body equivalent to BIS. The regulation covers items exported from EU customs territory, re-exports by EU operators, and, under the catch-all, certain items not on the control list where the exporter has been informed or has grounds to suspect prohibited end-use.

The structural difference matters immediately. BIS exercises extraterritorial jurisdiction by following the item. The EU regime, by contrast, follows the exporter. A non-EU exporter handling non-EU goods with no EU content is generally outside the EU regime's scope. That distinction shapes the entire comparative analysis.

How does each regime define the end-use test?

Under BIS / EAR, the end-use test operates on two levels. First, certain items carry specific end-use restrictions on the face of their Commerce Control List entry. Those restrictions apply regardless of who the buyer is: if the intended use falls within a prohibited category – missile development, chemical or biological weapons programmes, nuclear proliferation, or military end-use in certain destinations – the export requires a licence or is prohibited outright. Second, a general prohibition applies to any export, re-export, or in-country transfer where the exporter knows that the item will be used in a prohibited end-use, even if the item itself carries no specific end-use control and would otherwise be licensable or eligible for a licence exception.

The EU catch-all operates on similar logic but is triggered differently. An exporter must apply for a licence – even for a non-listed item – where it has been informed by the competent authority that the item is or may be intended for use in connection with weapons of mass destruction programmes, certain military applications, or maritime or aviation applications subject to embargo. Beyond formal notification, the exporter must also apply where it is aware that the item is intended for a prohibited end-use. The practical consequence is that an EU exporter who receives a direct red flag from its authority is automatically caught; one who has constructive knowledge but no formal notification is in a greyer position than a comparable US exporter would be under the EAR's "reason to know" standard.

In our cross-border practice, this asymmetry creates genuine risk for businesses that apply one regime's threshold to both. The EAR's "reason to know" standard is operationally demanding. It requires the exporter to look beyond the stated transaction and consider all available information about likely use. The EU standard, as applied by most member-state authorities, is closer to actual knowledge combined with the duty to investigate where circumstances are suspicious. Neither formulation is a free pass.

Where do the regimes diverge on end-use and end-user controls?

The most significant divergences between the BIS / EAR and EU regimes fall across five dimensions. Understanding each dimension is necessary before a business can decide which controls apply to a given transaction – and what it must do if both apply simultaneously.

First, scope of the end-user list. BIS maintains the Entity List, the Denied Persons List, and the Unverified List as specific end-user controls. An export, re-export, or transfer to a party on the Entity List requires a licence, and in many cases the review policy is a presumption of denial. The Unverified List imposes its own obligations: before shipping to an unverified party, the exporter must take prescribed steps, and shipping without those steps can itself constitute a violation. The EU has no equivalent consolidated end-user list at the supranational level. Member states maintain national lists and there is a centralised database of denials that exporters in all member states are expected to consult. But the structure is decentralised, and coverage varies. A party that has been denied a licence by one member state may not appear on a list that another member state's exporters routinely consult.

Second, the red-flag standard. BIS publishes guidance identifying specific red flags that trigger the duty to inquire further before proceeding. These include a buyer's unwillingness to provide end-use information, a request for packaging inconsistent with the stated application, a routing through a jurisdiction with no plausible connection to the stated end-user, and payment terms that are unusual for the transaction type. Under BIS guidance, encountering a red flag does not automatically prohibit the transaction. It does impose a positive duty to investigate and, if the concern cannot be resolved, to refrain from proceeding. EU member-state guidance on red flags varies. The Netherlands, Germany, and France have published detailed guidance; smaller member states rely more heavily on the EU Commission's advisory notes. The practical consequence is that a business operating across multiple EU jurisdictions must know which national authority's guidance applies to each shipment, not just the EU regulation itself.

Third, the military end-use rule. BIS has broadened its military end-use and military end-user controls to cover items not on any control list when the exporter knows that those items are destined for military end-use in certain specified destinations. The rule is not triggered merely by the fact that the buyer is a military entity: it requires a connection between the item and a covered military function. The EU addressed military end-use through a series of Council measures and tightened controls, but the structure is different. Items that serve a military purpose are more likely to be classified under the EU Munitions List than to be caught through a catch-all. The EAR's broader extension of catch-all logic to non-listed items destined for military use is a distinctly US approach.

Fourth, deemed export and deemed re-export. Under BIS / EAR, a deemed export occurs when controlled technology is released to a foreign national within the United States. That release is treated as an export to the person's country of nationality and may require a licence. The EU regime has no equivalent deemed-export concept. The EU regulation covers physical export from EU customs territory and, in limited respects, the transmission of software and technology; but the deemed-export logic – that handing a controlled document or source code to a foreign colleague inside the EU is itself a controlled act – is not replicated. Businesses that operate US-EU joint laboratories or employ multinational engineering teams frequently discover this gap only when a BIS classification review is underway.

Fifth, re-export controls. BIS's jurisdiction follows US-origin items as they move from country to country. A European company that receives US-origin components and then sells them onward must comply with EAR re-export requirements. The EU regime does not follow items in this way after they have left EU customs territory. A Finnish company that ships EU-controlled items to a distributor in the UAE has no EU-law obligation regarding the distributor's onward shipment – though the situation would be entirely different if those items also contained US content above de minimis.

Which regime is stricter on end-use and end-user controls?

Neither regime is uniformly stricter. The honest practitioner's answer is that it depends on the item, the destination, the buyer, and the transaction structure. That said, certain patterns are consistent across our experience advising on cross-border export-control matters.

BIS / EAR is generally more demanding in three respects: extraterritorial reach (the EAR follows US-origin content across borders); the breadth and currency of end-user lists (the Entity List is comprehensive and updated frequently); and the specificity of the red-flag duty (BIS guidance makes the "reason to know" obligation operationally concrete). An exporter shipping items with any US content to a sensitive destination or end-user faces EAR obligations that the EU regime may not independently generate.

The EU regime can, however, be more restrictive in the catch-all context in certain respects. The EU Blocking Regulation – which prohibits EU operators from complying with extraterritorial US measures in certain circumstances – creates a genuine legal tension for EU companies subject to both regimes. An EU company that declines a transaction solely because of a US-imposed restriction on a non-US item may face exposure under EU law. Managing that tension requires careful advice on both regimes simultaneously; it is not something that can be resolved by deferring to whichever authority issues the first instruction.

The operative principle is this: where two regimes both apply, the stricter prohibition governs the exporter's actual conduct. Compliance with one regime does not discharge obligations under the other. A business that meets the EU threshold but fails the EAR red-flag test is still in breach. That straightforward point is, in our experience, the one most frequently missed in cross-border compliance programmes.

What are the most common gaps in cross-border compliance programmes?

Compliance programmes designed around one regime regularly fail when applied to both. The gaps tend to cluster around three areas: classification, screening, and documentation.

On classification: a business may correctly classify an item under the EU control list and conclude it is not controlled – only to find that the same item, because it incorporates US technology, has an ECCN that places it on the Commerce Control List and triggers EAR controls. Classification under each regime must be done independently. One analysis does not substitute for the other.

On screening: a counterparty that does not appear on the EU's centralised denial database may nonetheless be on BIS's Entity List. More subtly, a counterparty that appears on neither list may have a beneficial owner who is on OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons) or whose ownership of the counterparty triggers OFAC's 50 percent rule (the rule treating entities owned 50 percent or more by blocked persons as themselves blocked). Screening that covers only the EU denial database and the UN Consolidated List misses both of these risks. We regularly advise businesses whose screening architecture was designed for EU shipments and has never been extended to cover US-origin content moving through the same supply chain.

On documentation: BIS requires exporters and re-exporters to obtain, in many circumstances, a written end-use undertaking from the buyer. The EU regime has its own documentation requirements, which differ in form and content. A business that obtains a single multi-purpose certificate from its buyer may satisfy neither regime's documentation standard. Counsel reviewing a potential enforcement matter will look immediately at whether the documentation obtained was the right document for the right regime.

In a recent matter, a technology distributor operating across the EU had established a detailed classification procedure anchored in the EU common list. When a US-origin software update was incorporated into its product, the distributor's existing procedure did not flag the change. The item's ECCN had not been assessed, and the distributor continued shipping to several destinations without the EAR licences that would have been required. The compliance gap was identified during a routine internal audit. Early engagement allowed a voluntary self-disclosure to be structured before any regulatory inquiry arose. The outcome of that disclosure process was not guaranteed and is not represented here as a precedent – but the disclosure option itself was available only because the audit had been conducted before any authority contact.

Have you verified that your export-control programme covers both the EU regime and the EAR independently, and that US-origin content in your product triggers a separate classification analysis?

Risk flags that demand immediate counsel involvement

Certain transaction features carry heightened risk under both regimes simultaneously. When these arise, the appropriate step is to pause the transaction and seek qualified export-control counsel before proceeding.

  • The buyer or a beneficial owner appears on any end-user or sanctions list, regardless of which list or which regime's authority maintains it.
  • The buyer declines to provide an end-use certificate or gives implausible end-use information.
  • The transaction routes through a jurisdiction with no plausible commercial connection to the stated end-user.
  • The item incorporates US-origin technology, and no ECCN assessment has been conducted.
  • The buyer is located in a destination where one or more regimes applies an embargo, arms embargo, or comprehensive set of restrictions.
  • The buyer has previously been placed on BIS's Unverified List, even if it was later removed.
  • A prior export-licence application for a similar item to a similar destination was denied by any competent authority.
  • The buyer requests export-control documentation in a form inconsistent with any known legitimate end-use.

These are not merely items to note and move on from. Under both regimes, proceeding in the face of an unresolved red flag can constitute the violation itself. The "reason to know" standard under the EAR does not require proof of actual knowledge: constructive awareness of a red flag that was not investigated is sufficient.

A common myth in cross-border businesses is that end-use controls apply only to items on a control list. That is incorrect. Both the EAR and the EU catch-all provisions extend controls to items that would otherwise be outside the list, where the exporter has sufficient knowledge or indication of a prohibited end-use. A business that ships non-controlled goods to a distributor with a known connection to a prohibited programme cannot rely on the absence of an ECCN or an EU control-list classification to defeat a violation charge.

How to structure an effective end-use and end-user compliance programme

A programme that is effective under both regimes shares five structural elements: classification, screening, documentation, escalation, and audit. Each must be calibrated to both regimes independently.

Classification must cover both the EU control list and, for any item with US-origin content, the Commerce Control List. The classification procedure should specify how US-origin content is identified in a product – at the component level, not only the finished-product level – and should trigger an ECCN assessment whenever US-origin content is incorporated or when a supplier's declaration indicates US origin.

Screening must cover, at minimum: the BIS Entity List, Denied Persons List, and Unverified List; the OFAC SDN List and the 50 percent rule check; the EU centralised denial database; the UN Security Council Consolidated List; and the applicable regime lists of any other jurisdiction in which the business operates or to which it ships. Manual spot-checks on automated screening results are essential. Automated tools do not consistently catch ownership chains that trigger the 50 percent rule, and they do not resolve transliteration variants of names on foreign-script lists.

Documentation must be jurisdiction-specific. For EAR-controlled items, the end-use certificate should address the specific end-use prohibitions relevant to the item's ECCN. For EU-controlled items, the form and content requirements of the applicable member-state authority govern. Obtaining both forms where both regimes apply is standard practice, not duplication.

Escalation means a written procedure that identifies who in the organisation has authority to pause or refuse a transaction, what information they need to make the decision, and what the external-counsel contact point is for cases that cannot be resolved internally within the timeframe imposed by commercial deadlines.

Audit must test each of the above elements against live transactions, not only against policy documents. A programme that looks correct on paper but is applied inconsistently in practice provides limited protection in an enforcement context. A VSD (voluntary self-disclosure to a regulator) filed after a well-structured audit that identified a gap is treated materially differently from a disclosure made after a regulatory inquiry has already opened.

The position above covers the structural case. Your facts – the item classification, the origin of technology in your product, the jurisdiction of your buyer, and the specific regime controls in play – will change the analysis at every step.

Read our companion analysis on OFAC versus BIS / EAR end-use controls for the interaction between sanctions and export-control regimes in the US context. For a practical primer on deemed-export requirements under the EAR, see our deemed export and technology controls service page.

If a transaction has already been flagged, a licence application has been refused, or an internal audit has surfaced a potential violation, an early review preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.

Related practices

Frequently asked questions

Where do the regimes diverge on end-use and end-user controls?
The principal divergences are extraterritorial reach, end-user list structure, the red-flag and "reason to know" standard, the deemed-export concept, and re-export jurisdiction. BIS / EAR follows US-origin items globally; the EU regime follows the EU exporter. BIS maintains consolidated, frequently updated end-user lists; the EU relies on decentralised national denial records. The deemed-export concept – treating technology release to a foreign national as a controlled act – is a BIS / EAR construct with no EU equivalent. Where both regimes apply to the same shipment, each set of requirements applies independently and the stricter prohibition governs.
Which regime is stricter on end-use and end-user controls?
Neither regime is uniformly stricter across all circumstances. BIS / EAR is generally more demanding in extraterritorial reach, end-user list comprehensiveness, and the specificity of its red-flag duties. The EU catch-all can be more restrictive in specific contexts, particularly where a competent authority has issued a formal notification. The EU Blocking Regulation introduces a further complication for EU operators who face conflicting US and EU obligations on the same transaction. Effective compliance counsel must assess both regimes against the specific item, destination, and buyer rather than applying a blanket hierarchy.
What should a cross-border business do about end-use and end-user controls?
The starting point is a classification exercise that covers both the EU control list and the US Commerce Control List independently, with a specific process for identifying US-origin content in finished products. Screening must cover BIS end-user lists, OFAC's SDN List including a beneficial-ownership check, and the EU denial database. Documentation must be jurisdiction-specific, not a single multi-purpose form. When a red flag arises that cannot be resolved internally, the transaction should be paused and qualified export-control counsel engaged before it proceeds. For a structured review of your programme, contact Calder & Vance at info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.