Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFAC

OFAC vs EU: Entity List and denied-party screening: the key divergences

A trading company in Singapore is midway through onboarding a new technology buyer in Europe. Its compliance team screens the buyer against the US Entity List (the Bureau of Industry and Security's list of foreign parties subject to licence requirements under the Export Administration Regulations) and finds a clean result. The same team then runs the buyer through the EU's Common Foreign and Security Policy restrictive measures (the Council's asset-freeze and sectoral lists under the relevant EU regulations). Again, clean. The deal proceeds. Three months later, the exporter's US supplier flags that a co-investor in the buyer appears on OFAC's SDN List (the list of Specially Designated Nationals and blocked persons maintained by the Office of Foreign Assets Control) and that the buyer's parent sits on the BIS Entity List. The shipment is held.

The OFAC SDN List, the BIS Entity List, and the EU's various restrictive-measures lists are legally distinct instruments administered by different authorities under different statutory regimes. They do not mirror each other. A counterparty that clears one list may still be captured by another – and the legal consequences of transacting with a listed party differ sharply depending on which list is in play and which jurisdiction's law governs the transaction.

As of April 2026, the divergence between these regimes has widened rather than narrowed, as each authority has added parties under its own criteria at its own pace. This analysis sets out the key differences across the US and EU regimes, explains what each list actually prohibits, and identifies where a cross-border business is most likely to be caught out.

What Is the Legal Architecture Behind Each Screening Regime?

The BIS Entity List is an export-control instrument. It is not a sanctions list. Placement on the Entity List means that a US exporter – or a non-US exporter shipping items that contain US-origin content above the applicable de minimis threshold (the proportion of US-controlled content that triggers the EAR's extraterritorial reach) – must obtain a specific licence before exporting, re-exporting, or transferring certain items to that party. The legal authority is the Export Control Reform Act and the Export Administration Regulations administered by the Department of Commerce's Bureau of Industry and Security.

The OFAC SDN List operates on entirely different ground. It is an economic-sanctions instrument. A party on the SDN List is "blocked": US persons are prohibited from virtually all transactions with that party, and any property or interests in property of that party within US jurisdiction are frozen. The authority derives from the International Emergency Economic Powers Act or the Trading with the Enemy Act, depending on the programme. Critically, the 50 percent rule (OFAC's rule that any entity owned 50 percent or more in the aggregate by blocked persons is itself treated as blocked, whether or not it appears on the SDN List) extends the prohibition far beyond the listed names.

The EU regime is a further distinct layer. The EU's restrictive measures are imposed by Council regulations, giving them direct effect across all EU member states. They typically include asset freezes and prohibitions on making funds or economic resources available to listed persons. The EU does not maintain a single list equivalent to the SDN List. Instead, there are regime-specific lists within each Council regulation, consolidated on a rolling basis into the EU Consolidated List published by the European External Action Service. The EU also maintains a separate common military list and controls on dual-use goods under the EU dual-use regulation, which imposes its own catch-all and end-user controls alongside the specific entity lists.

The practical consequence: a business operating across jurisdictions must run parallel screening processes against instruments that share no common update cadence, no common listing criteria, and no common legal effect. Missing one of these layers is among the most common compliance failures we see in cross-border export transactions.

How Do the Listing Criteria Differ – and Why Does That Matter?

The criteria for BIS Entity List designation and OFAC SDN designation are substantively different, and a party can appear on one without appearing on the other. BIS places parties on the Entity List when it determines that they pose an unacceptable risk of diversion to prohibited end uses or end users, or when they have acted contrary to US national security or foreign-policy interests. No criminal conviction is required. The standard is administrative and subject to internal BIS review. Delisting requires a petition to the End-User Review Committee.

OFAC designations under IEEPA-based programmes typically require a finding that the target meets specific programme criteria – connection to a designated person, engagement in sanctioned activity, or a status determination. The legal basis and the evidentiary threshold vary by programme. The SDN entry may include identifying information, aliases, and addresses, but the entry itself is not a judicial finding.

The EU listing process under Council regulations requires a reasoned decision of the Council, typically adopted by unanimity, subject to periodic review. An EU-listed person has the right to challenge the designation before the EU General Court in an annulment action under the relevant EU treaty provisions. In our cross-border practice, we have acted on matters where an EU annulment application was viable precisely because the evidentiary basis in the Council's statement of reasons was thin – an argument that would not have the same traction before BIS or in an OFAC administrative review, where the procedural standards differ materially.

The divergence in listing criteria means that the lists will regularly diverge in content. A party may be on the EU list but not on the SDN List, on the Entity List but not on either sanctions list, or on the SDN List but absent from the EU Consolidated List. Any screening programme that relies on only one of these instruments is structurally incomplete.

Where Do the Regimes Diverge on Entity List and Denied-Party Screening?

The principal divergences in screening between the US and EU regimes fall across four dimensions: legal effect, geographical reach, ownership and control analysis, and update frequency.

Legal effect. A BIS Entity List hit triggers a licence requirement – it does not automatically prohibit the transaction. An OFAC SDN hit prohibits the transaction and freezes the property. An EU Consolidated List hit triggers the asset freeze and the prohibition on making resources available under the applicable Council regulation. These are categorically different consequences, and conflating them in a compliance programme creates both under-reaction to SDN hits and over-reaction to Entity List hits.

Geographical reach. The EAR applies to items – goods, software, and technology – that are subject to the EAR, wherever they are located. The foreign direct product rule (the EAR provision extending US jurisdiction to foreign-made products that are the direct product of US-origin technology or software above specified control thresholds) can capture a non-US manufacturer's product if it was produced using certain US technology. OFAC's rules apply to US persons and to transactions that involve US-origin goods or funds, but the secondary-sanctions architecture under certain IEEPA programmes imposes risks on non-US persons who transact with SDN-listed parties, even without a US nexus in the transaction itself. The EU's asset-freeze prohibitions apply to any person – EU or non-EU – who is subject to EU jurisdiction, which includes non-EU entities operating within EU territory and EU-established entities operating globally.

Ownership and control analysis. This is where the regimes diverge most sharply in practice. OFAC's 50 percent rule is mechanical: 50 percent or more aggregate ownership by blocked persons, direct or indirect, makes the entity blocked. Control is separately addressed in OFAC guidance but ownership is the primary test. The EU and UK regimes apply an ownership and control test (the test for whether a non-listed entity is caught through a listed person's ownership or control of it). Under the EU approach, a party can be treated as falling within the prohibitions even where the listed person holds less than 50 percent of the shares, if the listed person exercises decisive influence or control. The BIS Entity List has no equivalent aggregation or deemed-entity rule: the listed party is the listed party, and downstream entities are not automatically caught unless they are separately listed.

Update frequency and format. The SDN List and the Entity List are updated at different times by different agencies. The EU Consolidated List is updated separately again. There is no co-ordinated publication schedule. A screening programme that pulls list data at weekly intervals will have a structural gap in the periods between updates. Real-time or near-real-time screening against all three instruments is the minimum standard for a business handling significant transaction volumes.

Which Regime Is Stricter on Entity List and Denied-Party Screening?

Strictness depends on the dimension being assessed, and in our experience no single regime is uniformly stricter across all of them. The question is more productively framed as: where is each regime strictest, and for which categories of actor?

For a US exporter, BIS's Entity List is in many respects more operationally disruptive than the SDN List, because the Entity List is larger, broader in scope, and the licence requirement attaches to items rather than only to funds or blocked property. The SDN List's scope is legally more severe – a prohibited transaction is a prohibited transaction, and no licence is available as of right – but the volume of relevant counterparties in a given sector may be smaller.

For a non-US exporter shipping items that contain US-origin content, the EAR's de minimis rules and the foreign direct product rule mean that BIS's Entity List can reach the exporter even without a direct US connection. OFAC's secondary-sanctions exposure is real but programme-dependent: it applies where the applicable programme imposes non-US-person risk, which not all programmes do.

For an EU-based business operating entirely outside the US, the EU Consolidated List is the primary operative constraint. However, EU law does not currently contain a general deemed-entity rule equivalent to OFAC's 50 percent rule. An EU-based business that transacts with a non-listed entity in which an EU-listed person holds a minority stake is in a materially different legal position from a US person facing the same fact pattern under OFAC.

The practical implication for a cross-border business is this: the strictest prohibition in any applicable jurisdiction governs that transaction. A transaction lawful under EU law may be prohibited under OFAC. A transaction cleared under the EAR may still be blocked under OFAC's SDN rules. Compliance programmes that silo US and EU screening miss this interaction. We regularly advise businesses that have run a transaction through one layer and assumed the analysis was complete.

In a recent matter, a European technology distributor had implemented screening against the EU Consolidated List and the BIS Entity List, but had not integrated OFAC SDN screening because its business was perceived as "EU-only." A US-origin software component in the distributor's product stack brought the EAR into play, and the customer's parent company was an SDN. We assessed the exposure, advised on voluntary self-disclosure timing and scope, and helped the business restructure its screening programme to cover all three instruments in real time. The matter illustrated a pattern we see repeatedly: the assumption that EU-based operations do not attract US sanctions exposure is wrong where US-origin items or US-dollar clearing are in the chain.

What Are the Risk Flags a Compliance Team Should Prioritise?

The highest-risk patterns in entity-list and denied-party screening failures share common structural features. Identifying them early allows a business to harden its programme before an enforcement event.

The first is de minimis miscalculation. A non-US exporter that has not calculated the US-content percentage of its products will not know whether the EAR applies to its exports at all. If the de minimis threshold is exceeded and the product contains US-origin technology, any export to a BIS Entity List party requires a licence regardless of where the exporter is incorporated.

The second is ownership-chain truncation. Screening only the direct counterparty leaves the upper ownership chain unexamined. The OFAC 50 percent rule can block a transaction through a chain of three or four holding companies. The EU control test adds another layer: even a minority stake combined with board control can bring an entity within the EU prohibitions. Effective screening maps the full chain.

The third is list-gap timing. Between a designation and its appearance in a firm's screening database, a window exists during which prohibited transactions may be processed. Firms with weekly batch screening face this risk structurally. The answer is not to screen less frequently but to implement a process for monitoring designation announcements directly from the relevant authority websites alongside automated list updates.

The fourth is dual-use classification gaps. The BIS Entity List and the EU's catch-all controls interact: even where a product is not controlled under the Commerce Control List or the EU dual-use list, a catch-all may require a licence if the exporter knows or has reason to believe the end user has prohibited intent. Screening for listed parties is necessary but not sufficient. End-use and end-user review is a parallel obligation.

The fifth is US-dollar clearing exposure. Even where a non-US business uses no US-origin goods, routing a payment through a US correspondent bank brings OFAC into play. An SDN-listed counterparty will have its payment blocked and the transaction reported. This exposure does not require any goods to move and is separate from the EAR.

Related practices

If a transaction has already been flagged, or a screening hit has produced uncertainty about whether the shipment can proceed, an early legal review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.

How Does the Foreign Direct Product Rule Interact With the EU Regime?

The foreign direct product rule is the point at which US export-control jurisdiction most visibly collides with the EU's self-contained regime. The rule extends BIS jurisdiction to foreign-made items that are the direct product of US-origin technology or software subject to the EAR, where those items are destined for BIS Entity List parties or produced by them. The practical effect is that a German semiconductor manufacturer, a Dutch software company, or a Singaporean distributor may be subject to US EAR licence requirements for their own products if those products were developed or manufactured using US-origin technology above the applicable threshold.

The EU does not have an equivalent extraterritorial mechanism of this kind. EU dual-use export controls apply to items located in EU territory or exported by EU-established persons. They do not follow the item wherever it was made. This creates a genuine asymmetry: a product may require a BIS licence for export to an Entity List party while simultaneously being entirely free of EU export-control requirements for the same shipment.

For a business operating under both jurisdictions, this asymmetry creates a tiered obligation. The EU-side screening may clear the transaction. The BIS-side analysis may prohibit it. The compliance programme must accommodate both assessments, not assume that clearing one means clearing the other.

The EU's response to this extraterritorial dynamic has been institutional rather than regulatory: the EU Blocking Regulation (the instrument designed to limit the effects of specified third-country laws on EU persons) provides a mechanism under which EU operators may, in defined circumstances, seek to resist compliance with designated foreign measures. In our practice, the Blocking Regulation is rarely a solution to the practical problem of a US-controlled item in the supply chain. It addresses political and legal exposure in one direction; it does not resolve the US-law obligation that attaches to the item itself.

A Common Myth: Clearing One List Means the Transaction Is Safe

The most persistent misconception we encounter from businesses entering cross-border screening for the first time is that compliance with one list, from one authority, means the transaction is cleared. It does not.

The BIS Entity List, the OFAC SDN List, the OFAC Consolidated Sanctions List (OFAC's public compilation of all its programme lists, including the SDN List, the Sectoral Sanctions Identifications list, and others), and the EU Consolidated List are legally separate instruments. A match on one and a clear on the others is an incomplete analysis, not a clean bill of health. The legal consequences of a miss on each instrument are distinct: a BIS violation may result in an administrative penalty, denial of export privileges, or criminal referral to DOJ; an OFAC violation may result in civil money penalties and, in egregious cases, criminal prosecution; an EU violation is subject to member-state enforcement and, for certain programmes, carries criminal liability in the relevant jurisdiction.

There is also a timing dimension to the myth. Businesses sometimes assume that because a counterparty was clean at onboarding, it remains clean. Designations happen continuously. A relationship that was clean at inception may be prohibited a year later without any change in the counterparty's legal structure. Periodic rescreening of the full counterparty book – at a cadence appropriate to the risk profile of the portfolio – is not a regulatory nicety. It is a baseline obligation under any serious compliance programme.

What should a compliance team actually do? Map every applicable list against the jurisdictions and items in the supply chain. Automate screening with real-time or near-real-time list updates. Map the ownership chain to at least the level required by the most demanding applicable rule – which in most cross-border contexts means applying OFAC's 50 percent aggregation methodology as the floor. Review the list of applicable regimes whenever the product range, the supply chain, or the customer base changes. And when a hit appears, do not assume it is a false positive: escalate, analyse the legal effect under each applicable regime, and document the analysis.

What Should a Cross-Border Business Do About Entity List and Denied-Party Screening?

The answer depends on the business's starting point, but the structural elements of an adequate programme are consistent across sectors. In our experience, businesses that handle both US-origin goods and EU-based transactions need to build a programme that addresses at minimum five obligations simultaneously: BIS Entity List screening, OFAC SDN and programme-list screening, EU Consolidated List screening, ownership-chain analysis under the applicable aggregation and control tests, and end-use and end-user review for dual-use items.

The decision sequence runs as follows. First, classify the items. Does the EAR apply? Does the EU dual-use regulation apply? Are there other national export-control regimes in the supply chain – UK, Swiss, Canadian, Japanese, or Australian – that impose additional controls? Item classification determines which list-screening obligations attach. Second, determine jurisdiction. Which regime's sanctions and export-control rules apply to your entity, your goods, and your customers? A non-US entity may still be within OFAC's reach through the secondary-sanctions architecture or through US-dollar clearing. Third, screen comprehensively. Run the counterparty, its known owners, and its known subsidiaries against every applicable list, at a frequency calibrated to transaction volume and risk. Fourth, document. The absence of documented analysis is treated by enforcement authorities as the absence of analysis. Record what you screened, when, against which list version, and what the result was. Fifth, escalate hits. A potential match is not a compliance failure unless a prohibited transaction proceeds. The failure is completing the transaction without legal review.

Where a business is uncertain whether the EAR applies to its products at all, a classification and de minimis analysis is the logical starting point. Calder & Vance regularly assists exporters and distributors with classification under both the EAR and the EU dual-use regulation, ensuring that the screening obligation is correctly defined before the screening programme is built.

For a cross-border business that already has a screening programme in place, the right question is not "do we screen?" but "do we screen the right lists, at the right frequency, against the right counterparty population, with the right ownership-chain depth?" If the answer to any of those sub-questions is uncertain, a programme audit is warranted before a transaction generates an enforcement inquiry.

To discuss a review of your screening programme or an assessment of your exposure under the BIS Entity List, OFAC, or the EU Consolidated List, contact Calder & Vance at info@caldervance.com.

Frequently asked questions

Where do the regimes diverge on Entity List and denied-party screening?
The BIS Entity List, the OFAC SDN List, and the EU Consolidated List are separate legal instruments with different listing criteria, different legal effects, and different geographical reach. The Entity List triggers a licence requirement; the SDN List prohibits the transaction and freezes property; the EU list imposes asset-freeze obligations under Council regulations. OFAC applies a mechanical 50 percent ownership aggregation rule to extend prohibitions to unlisted entities; the EU applies an ownership and control test that can catch minority-held entities; BIS applies no equivalent deemed-entity rule. Update cadences are independent across all three instruments.
Which regime is stricter on Entity List and denied-party screening?
No single regime is uniformly stricter. The BIS Entity List is broader in the number of parties listed and in the range of items affected. OFAC's SDN List is legally more severe in effect – blocking the transaction entirely – and extends to non-US persons through the secondary-sanctions architecture of certain programmes. The EU regime applies to all persons subject to EU jurisdiction and uses a control test that can catch parties a purely mechanical ownership test would miss. For a business operating across jurisdictions, the strictest applicable prohibition in each regime governs each element of the transaction.
What should a cross-border business do about Entity List and denied-party screening?
A cross-border business should implement screening that covers all applicable lists – BIS Entity List, OFAC SDN and programme lists, and EU Consolidated List – with ownership-chain analysis to the depth required by the most demanding applicable rule. Screening should run at a frequency matched to transaction volume and risk, and all results, including negative results, should be documented. Where the EAR's extraterritorial reach is uncertain, a de minimis and product-classification analysis should precede programme design. When a potential hit appears, legal review before any transaction proceeds is the baseline standard.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.