A technology exporter with customers across the United States, Europe, and Asia runs a routine compliance check before shipping a batch of dual-use components. Its screening tool flags a distributor. The entity does not appear on OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons). But does it appear on the BIS Entity List? Is it captured by an EU restrictive measure? These are separate questions with separate consequences – and confusing them is a common, costly mistake.
Entity list and denied-party screening under BIS / EAR and EU compared is the process of checking counterparties against two structurally different control regimes before executing an export or re-export. Under the Export Administration Regulations (EAR), the Bureau of Industry and Security (BIS) maintains a set of restricted-party lists – most prominently the Entity List – that trigger licence requirements regardless of the item's classification. The EU operates a parallel but legally distinct system of restrictive measures and, in parallel, an export-control regime under its dual-use rules that cross-references designated persons. A business exporting goods or technology to the same end-user may face obligations under both regimes simultaneously, and the stricter prohibition governs.
This analysis maps the two regimes side by side, identifies the points of divergence that create the most practical difficulty, and sets out what a cross-border compliance programme needs to address. It covers the governing authority, the structure of each list, the tests that apply to ownership and control, the consequences of a hit, and the risk flags that should prompt early counsel involvement.
What are the governing authorities and legal bases for each regime?
The BIS Entity List and the broader EAR denied-party screening architecture derive their legal authority from the Export Control Reform Act and IEEPA, administered by the US Department of Commerce through BIS. The Entity List is a positive-law licensing requirement: a listing imposes a licence requirement for all items subject to the EAR destined for the listed entity, regardless of whether a licence would otherwise be needed. Separately, BIS maintains the Denied Persons List (a list of individuals and entities whose export privileges have been revoked) and the Unverified List (entities for which BIS has been unable to verify end-use). These three lists serve different legal functions and impose different obligations.
The EU's equivalent architecture is divided across two legislative instruments. First, the EU dual-use regulation establishes a licensing requirement for controlled goods and technology; it cross-references persons subject to EU arms embargoes and restrictive measures. Second, the Council's restrictive-measures regulations – adopted under the Treaty on the Functioning of the European Union – list designated persons and entities directly, imposing asset freezes and, depending on the measure, transaction prohibitions. The lists are published in the Official Journal and implemented by competent authorities in each member state. In our cross-border practice, clients frequently conflate these two pillars, treating them as a single "EU sanctions list" when they are legally and procedurally distinct.
A business subject to both regimes must screen against all relevant BIS lists and all applicable EU restrictive-measures lists. An entity that appears on one but not the other still triggers obligations under the regime on which it appears. That asymmetry defines the cross-border compliance problem.
How does the BIS Entity List work in practice?
A listing on the BIS Entity List means that the exporter must obtain a specific licence from BIS before exporting, re-exporting, or transferring any item subject to the EAR to that entity, regardless of the item's Export Control Classification Number (ECCN – the alphanumeric code under the Commerce Control List that determines baseline licence requirements). The licence review policy for most Entity List entries is "presumption of denial", which means BIS will decline the application in almost all circumstances. In effect, a listing is a near-total bar on EAR-subject transactions.
The threshold question for any exporter is whether its item is "subject to the EAR". Items produced outside the United States can still be subject to the EAR if they incorporate more than a de minimis percentage of US-origin controlled content, or if they are direct products of certain US-origin technology. This extraterritorial reach – the de minimis and Foreign Direct Product (FDP) rules – means that a European manufacturer shipping European-made goods may nonetheless be caught by Entity List obligations if its production process used controlled US technology. The FDP rules were substantially expanded in recent years and now cover certain categories of semiconductor and advanced-computing items with particular breadth.
Practically, a confirmed hit against the Entity List means the exporter must stop the transaction unless a licence is in place. There is no general licence equivalent that permits routine Entity List transactions to proceed. We regularly advise exporters who discover, mid-transaction, that a customer's affiliate has been listed; the question of whether the affiliate's involvement in the transaction triggers the listing is a fact-specific analysis that turns on who is the "ultimate consignee" and the degree of the affiliate's participation.
How does EU denied-party screening differ in structure and effect?
EU denied-party screening operates through a different architecture. The EU does not have a single "EU Entity List" equivalent to the BIS construct. Instead, the relevant checks are threefold: screening against the EU Consolidated List of persons subject to EU financial sanctions; screening against the arms-embargo lists embedded in specific Council Decisions; and, for export-control purposes, checking whether the end-user is subject to any restriction under the applicable dual-use regulation that requires enhanced scrutiny or a specific authorisation.
The EU Consolidated List covers persons and entities subject to asset freezes and other financial restrictions across all EU restrictive-measures programmes. A match on this list does not automatically impose an export-control licence requirement in the same way the BIS Entity List does – it triggers the financial-sanctions prohibition (no funds or economic resources, directly or indirectly). But where the underlying Council regulation also prohibits supplying certain goods, the export is separately caught. The overlap creates what practitioners call a "double-trigger": the transaction is prohibited under financial-sanctions rules and independently requires a licence or is refused under export-control rules.
Ownership and control is treated differently between regimes. Under BIS and the EAR, the entity must be listed by name; there is no statutory "50 percent rule" that automatically extends Entity List restrictions to subsidiaries by ownership. The exporter must assess whether the unlisted subsidiary is acting as an agent or on behalf of the listed party, but ownership alone does not automatically transmit the listing. Under EU restrictive measures, by contrast, the ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person) can bring an unlisted subsidiary within the prohibition if it is owned or controlled by a listed person. This is a material divergence.
In our experience, exporters who have mapped BIS Entity List obligations confidently – and correctly – nonetheless fail to apply the EU ownership-and-control analysis to the same counterparty. The unlisted subsidiary passes the BIS screen but may fail the EU analysis. The transaction clears one desk and is blocked by the other.
Where do the regimes diverge most sharply?
The divergences between BIS / EAR and EU denied-party screening are systemic, not marginal. Understanding them is essential to designing a screening programme that manages both regimes simultaneously.
Jurisdictional reach. The EAR's extraterritorial application through the de minimis and FDP rules extends US export-control obligations to non-US persons dealing in non-US goods, provided the relevant threshold for US-origin content or technology is met. The EU dual-use regime operates primarily on the basis of the exporter's location within the EU; extraterritorial application is narrower and turns on specific brokering and technical-assistance prohibitions rather than a general product-tracing rule. A European exporter may face BIS obligations through FDP that have no EU equivalent.
List structure and effect. The BIS Entity List imposes a specific licence requirement keyed to the listed entity as destination. The EU Consolidated List imposes a financial-sanctions prohibition keyed to the listed person as counterparty. The practical consequence differs: BIS's mechanism is an export-control gate; the EU's primary mechanism is an economic-resources prohibition. For a transaction involving both goods transfer and payment, both mechanisms can fire simultaneously, but the trigger logic and the remedial route differ.
Ownership-attribution rules. As noted, BIS does not automatically extend the Entity List to subsidiaries by ownership. The EU ownership-and-control test can. This asymmetry means that a counterparty structure that passes BIS screening may fail EU screening, or vice versa.
Licensing options. BIS entity-list licences operate under a presumption of denial for most entries. EU export-control licences – individual, global, and national general authorisations – are assessed by member-state competent authorities under a different standard and with a different process. There is no direct EU equivalent of the BIS licence-review process, and the assessment criteria are not identical.
Enforcement locus. BIS enforcement actions are taken by the Office of Export Enforcement at the federal level, with civil and criminal penalties available. EU restrictive-measures enforcement is conducted by national competent authorities in each member state; there is no single EU-level enforcement body. This means a business operating across multiple EU jurisdictions may face different enforcement postures for the same underlying transaction.
The position above covers the structural case. Your facts – the goods, the end-user, the supply chain route, and the regimes in play – change the analysis materially. For a review of your screening architecture against both regimes, contact Calder & Vance at info@caldervance.com.
What does an effective dual-regime screening programme look like?
An effective screening programme for a business subject to both BIS / EAR and EU obligations is not a single list-check. It is a structured, multi-layer process that addresses the different trigger logic of each regime.
The first layer is list coverage. The programme must screen against, at minimum: the BIS Entity List; the BIS Denied Persons List; the BIS Unverified List; the OFAC SDN List (which imposes separate obligations but is frequently implicated in the same transaction); the EU Consolidated List; and the UN Security Council Consolidated List. Depending on the goods and the destination, additional national lists – OFSI's consolidated list for UK-nexus transactions, SECO lists for Switzerland, and others – may be in scope. Screening against only one list is not a compliance programme; it is a partial check.
The second layer is ownership-chain analysis. For EU-nexus transactions, the programme must apply the ownership-and-control test to non-listed entities that are connected to listed persons. This is not satisfied by screening the immediate counterparty's name. It requires mapping the ownership structure – ideally to the ultimate beneficial owner – and assessing whether any listed person holds an ownership or control position that brings an unlisted entity within the prohibition. The depth of that analysis should be calibrated to the risk profile of the transaction and the counterparty's jurisdiction.
The third layer is FDP and de minimis analysis for BIS. Where goods incorporate US-origin content or were produced using US-controlled technology, the programme must assess whether the EAR applies. If it does, Entity List screening becomes mandatory regardless of the exporter's own location. This analysis requires knowing the product's content and production history – information that is often held by procurement, not compliance.
The fourth layer is the response protocol. A potential hit on any list should trigger a defined escalation path: stop the transaction; conduct enhanced due diligence; involve counsel; determine whether a licence application is feasible; and, if a breach is identified, assess whether a VSD (voluntary self-disclosure to the regulator) is appropriate. The response protocol should be tested periodically, not just documented.
We have acted for technology companies, financial institutions, and trading houses designing or overhauling this architecture. The most common gap we identify is not a missing list – it is the absence of a cross-regime ownership-and-control workstream sitting alongside the automated name-check.
What are the principal risk flags that should prompt counsel involvement?
Certain patterns in a transaction or counterparty profile materially elevate the risk of a screening failure or a prohibited transaction. Identifying them early reduces the cost of the response.
The first flag is a counterparty in or connected to a jurisdiction subject to comprehensive restrictive measures under any of the major regimes. Even where the immediate counterparty is not listed, the transactional context signals elevated due-diligence requirements under both BIS and EU rules. The EAR's end-use and end-user controls apply independently of the Entity List; a transaction may require enhanced scrutiny even without a positive list hit.
The second flag is a complex or opaque ownership structure. Where beneficial ownership is layered across multiple jurisdictions and the ultimate owner is unclear, the EU ownership-and-control analysis cannot be completed reliably without enhanced corporate registry work. In our experience, the entities most likely to generate a surprise hit during due diligence are those where the ownership chain was not mapped beyond the first tier.
The third flag is US-origin content in a non-US supply chain. If a European exporter's product incorporates controlled US technology or is produced on US-controlled equipment, FDP analysis is mandatory before any export to a high-risk destination or counterparty. Failure to conduct that analysis is not a mitigating factor in a BIS enforcement proceeding.
The fourth flag is a re-export scenario. Where goods move from a first destination to a second destination, the receiving party in the second leg must also be screened. Entity List obligations attach to the ultimate consignee and to parties that participate in the transaction, not only to the immediate buyer. A confirmed Entity List entity at any point in the chain requires a licence or a halt.
The fifth flag is a transaction involving dual-use items with high control-list ratings. Where an item carries an ECCN that places it on the Commerce Control List for national-security or nuclear-proliferation reasons, the due-diligence threshold for screening is higher across both regimes. A borderline counterparty that might be acceptable for a low-sensitivity commodity warrants much closer scrutiny in this context.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.
A common misconception: clearing one regime clears both
A persistent myth in cross-border compliance is that a counterparty cleared against the OFAC SDN List – or against a single consolidated list tool – is cleared for all export-control and sanctions purposes. It is not.
OFAC sanctions and BIS export controls are legally distinct regimes with different lists, different trigger logic, and different enforcement paths. Clearing OFAC does not clear BIS. Clearing BIS does not clear OFAC. Neither clears the EU Consolidated List. And none of them replaces the ownership-and-control analysis required under EU restrictive measures or the FDP analysis required under the EAR.
Screening tools marketed as "all-in-one" vary significantly in their list coverage and their ability to surface ownership relationships. We regularly advise firms that have invested in sophisticated screening technology but have not mapped what the tool actually checks against. A tool that screens the OFAC SDN List and the BIS Denied Persons List but does not include the BIS Entity List leaves a material gap. That gap is where enforcement actions arise.
The correct approach is to document, per transaction type and counterparty profile, which lists are checked, at what frequency, and by which process. That documentation is evidence of due diligence. It is also the basis on which a VSD, if one becomes necessary, can be presented to BIS or to a competent EU authority.
Related practices
- Deemed export and technology controls under BIS / EAR – classification, licence exceptions, and deemed-export obligations for technology transfers to foreign nationals
- EU denied-party screening compared with the SECO regime – divergences in list structure, ownership tests, and enforcement posture between EU and Swiss controls
- OFAC sanctions screening compared with BIS / EAR controls – how OFAC and BIS lists interact and where the gaps in a combined screening programme arise