Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · BIS / EAR

BIS / EAR vs EU: Escalation and reporting procedures compared

A dual-use exporter ships components from the United States and the European Union to a distributor in a third market. Midway through the shipment cycle, the internal compliance team discovers that a consignment may have been routed through an undisclosed intermediate party. Two questions arise immediately: who must be told, by when, and in what form? Under the US Export Administration Regulations ("EAR", administered by the Bureau of Industry and Security, "BIS") and the EU's dual-use regulation (the applicable Council regulation governing the export of dual-use items), the answers diverge in ways that matter enormously to the cross-border business managing both exposure points at once.

As of July 2026, the BIS / EAR and EU dual-use regimes govern escalation and reporting procedures through structurally different mechanisms. BIS operates a voluntary self-disclosure ("VSD") programme under the Export Control Reform Act and the EAR, under which disclosing parties may receive a significant mitigation of any civil penalty. The EU regime delegates enforcement primarily to member-state competent authorities, creating a patchwork of reporting obligations and escalation timelines that varies across the single market. For a cross-border business, the interaction between these two regimes – and the risk that action under one triggers scrutiny under the other – defines the practical compliance task.

This analysis maps the escalation and reporting procedures under each regime in turn, identifies the key points of divergence, and closes with a practical decision sequence for businesses that face a potential violation spanning both jurisdictions.

How does the BIS / EAR voluntary self-disclosure regime work?

The BIS / EAR VSD mechanism is the primary escalation and reporting procedure available to a company that has identified a potential violation of US export controls. A VSD is a voluntary, written narrative disclosure to BIS's Office of Export Enforcement ("OEE") that describes the apparent violation, the goods or technology involved, the parties to the transaction, and the remedial steps taken or planned. It is not a confession; it is a structured opportunity to shape the enforcement outcome before BIS discovers the issue independently.

The VSD procedure requires a company to submit an initial notification and, within a defined period, a complete narrative report. In our cross-border practice, the quality of the complete narrative – its factual precision, its analysis of the applicable Export Control Classification Numbers under the Commerce Control List ("CCL"), and the robustness of the remediation section – drives the credit BIS gives to the disclosure. A rushed or incomplete narrative can undercut the mitigation benefit.

BIS assesses apparent violations under a matrix that weighs aggravating and mitigating factors. Voluntary disclosure is listed explicitly as a mitigating factor, and in our experience it is one of the most consequential ones available. Where a company has identified an apparent violation of the EAR, delayed escalation increases the risk that BIS or US Customs and Border Protection identifies the issue first, removing the VSD option entirely.

The critical internal escalation question under the EAR is therefore one of timing: when does a compliance team's suspicion become a legal obligation to investigate and, if investigation confirms the issue, an obligation to report? The EAR does not impose a hard statutory deadline running from the moment of discovery in the way that some financial-crime regimes do. That flexibility cuts both ways. It permits a measured internal investigation before disclosure, but it also means that a company that delays indefinitely cannot later claim the VSD mitigation in good faith. Counsel who advises regularly before BIS will tell you that OEE scrutinises the gap between the date of discovery and the date of disclosure.

One further point bears emphasis. The EAR's VSD programme applies specifically to export-control violations. It sits alongside, but is distinct from, any OFAC voluntary self-disclosure for sanctions violations. A cross-border incident that touches both export controls and financial sanctions may require concurrent disclosures to two separate US agencies, each with its own format and evidentiary standards. The position above covers the standard EAR case. Your facts – the goods, the parties, the route, and the regime in play – change the analysis.

For a confidential review of a potential EAR breach, contact Calder & Vance at info@caldervance.com.

What are the escalation obligations under the EU dual-use regime?

Under the EU dual-use regime, escalation and reporting obligations are routed primarily through the competent authorities of individual member states rather than through a single EU-level enforcement body. The applicable Council regulation establishes the substantive controls – which items require a licence, which end-uses trigger heightened scrutiny, which destinations raise concerns – but the enforcement architecture is national. This structural feature produces one of the most consequential divergences from the BIS / EAR model.

A company operating across multiple EU member states may face meaningfully different escalation procedures depending on where it is established and where the export takes place. Some member-state competent authorities have published detailed guidance on how exporters should report a potential breach; others have not. In the absence of a single harmonised VSD mechanism equivalent to BIS's OEE programme, a company must identify the applicable national procedure in each relevant jurisdiction.

What is consistent across the EU is the obligation to maintain records and to make them available to the competent authority on request. The applicable Council regulation requires exporters to retain records relating to export transactions for a defined period. Crucially, that record-keeping obligation is a compliance baseline, not an escalation procedure in itself. The escalation step – deciding when and how to approach the competent authority about a potential violation – turns on national law and national enforcement practice.

There is, however, a supra-national dimension that practitioners must not overlook. Where a breach implicates the EU's dual-use regulation and also involves items or technology that fall under US export-control jurisdiction – for instance, items with a US-origin component that triggers re-export licence requirements under the EAR – the EU-level incident simultaneously creates BIS exposure. The two enforcement tracks run in parallel and do not coordinate. A company that manages only one of them runs a significant residual risk on the other.

Beyond the member-state patchwork, the EU General Court and the Court of Justice have addressed export-control licensing decisions in annulment proceedings. These are not, strictly speaking, escalation or reporting procedures; they are judicial-review routes available after an adverse licensing or enforcement decision. But they are part of the escalation architecture in the broader sense: a company that disputes a competent authority's finding has a route to challenge it, and that route requires early engagement of specialist counsel.

Where do the regimes diverge on escalation and reporting procedures?

The sharpest divergence between the BIS / EAR and EU dual-use regimes on escalation and reporting lies in institutional architecture. BIS operates a single, federal, well-documented VSD programme with published guidance on aggravating and mitigating factors. The EU operates through twenty-seven national enforcement channels, each with its own procedural norms.

A second divergence concerns the incentive structure. BIS has codified mitigation credit for voluntary disclosure. The EU member states vary: some have formal mitigation schemes, some operate informally, and some publish little guidance at all. A company disclosing under the EAR knows, broadly, what it is gaining by going first. A company reporting to a member-state competent authority in the EU has less predictability about what that disclosure will produce.

Third, the evidential standards differ. A BIS VSD requires a detailed factual narrative, a self-classification of the items involved against the CCL, and a remediation plan. EU national competent authorities may have different expectations of what a voluntary report should contain. Submitting a BIS-format disclosure to an EU competent authority without adjustment may provide too much information in some respects and too little in others.

Fourth, the timeline dynamics diverge. Under the EAR, the gap between discovery and disclosure is scrutinised, but there is no single hard statutory clock for the VSD itself. Under some EU member-state regimes, procedural timelines for responding to a competent authority investigation are set by national administrative law, which may impose stricter deadlines once a formal inquiry is opened.

Fifth, and critically for businesses with US-origin goods in their supply chains, the EAR has extraterritorial reach through the de minimis rule and the foreign direct product rule ("FDPR"). An EU exporter who ships a product containing controlled US-origin content, or a product that is the direct product of US-origin technology or software, may be subject to EAR licence requirements even if the company has no US presence. A breach of those requirements creates BIS exposure for that EU company – and that exposure is governed by the BIS VSD procedure, not by the EU national competent authority.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com.

How does the 50 percent rule interact with export-control escalation?

Export-control compliance and financial-sanctions compliance are legally distinct but operationally intertwined. When a company escalates an export-control concern, the same facts that constitute a potential EAR violation may also reveal a financial-sanctions breach – for instance, because the end user is linked to a blocked person under OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons), or because the intermediate party is an entity that falls within the 50 percent rule (OFAC's rule treating entities owned 50 percent or more, in the aggregate, by blocked persons as themselves blocked).

This intersection matters for escalation sequencing. A company that identifies an export-control issue should instruct its compliance team to run a parallel sanctions screen before it finalises the scope of any VSD or national report. Disclosing an EAR violation while simultaneously transacting with a blocked person would compound the exposure materially. In our practice, we have seen compliance teams treat export-control and sanctions escalation as separate workflows that rarely communicate. That separation creates risk.

Under OFSI and EU sanctions regulations, the ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person) is broader than OFAC's mechanical 50 percent ownership threshold. Control, in the EU and UK sense, can be established through factors beyond formal equity ownership – voting rights, appointment rights, contractual dependence – and that broader test can catch entities that pass OFAC's screen. A company running only a US-centric ownership analysis before escalating may miss a UK or EU sanctions angle.

What does this mean in practice? Before any VSD or national report is submitted, the compliance team should confirm: whether any party to the transaction is listed on the SDN List, the EU Consolidated List, the UK Consolidated List, or the UN Consolidated List; whether any unlisted entity is caught under the relevant ownership-and-control test; and whether there are secondary-sanctions considerations under OFAC programmes that extend to non-US persons. Only once that screen is clear – or its results fully understood – should the escalation narrative be finalised.

What are the risk flags that require immediate counsel involvement?

Certain fact patterns require external sanctions and export-control counsel to be involved before any internal escalation decision is made. The risk is not only that the wrong decision is taken; it is that an internally drafted disclosure or a self-prepared report creates an evidentiary record that later proves damaging.

The first risk flag is knowledge of the end use. Where internal communications show that employees were aware, or should have been aware, that goods might be diverted or used for an unlicensed purpose, the BIS aggravating-factor analysis is materially worse than in a purely administrative error case. In that situation, the escalation decision – whether to disclose, to whom, in what form, and with what legal privilege – requires immediate counsel involvement. BIS distinguishes clearly between administrative violations and wilful conduct, and that distinction drives enforcement outcomes.

The second risk flag is concurrent criminal exposure. The EAR's export-control provisions can give rise to criminal as well as civil sanctions. Where the apparent violation involves wilful conduct, repeat conduct, or high-controlled items – particularly those with military or weapons-proliferation end uses – the Department of Justice may be involved alongside BIS. The VSD to OEE does not extinguish criminal exposure. A company in that position needs counsel who understands both the administrative VSD process and the criminal-referral dynamic.

The third risk flag is the extraterritorial dimension. If the company involved is established outside the United States but has used US-origin technology or exported items caught by the FDPR, its BIS exposure is real even though it has no US legal presence. Managing that exposure requires coordinated advice on US jurisdiction over the conduct, the applicable national procedures in the EU or other relevant jurisdiction, and the interaction between the two enforcement tracks.

The fourth risk flag is a prior disclosure or prior enforcement action. A company that has previously disclosed an EAR violation to BIS, or that has previously been the subject of enforcement, faces a higher aggravating-factor burden in any subsequent matter. Early counsel involvement is essential to frame the new matter accurately and to manage the relationship with OEE through the disclosure process.

The myth that internal compliance teams can manage a BIS VSD without external counsel is worth addressing directly. The format of the complete narrative, the classification analysis, the legal analysis of the apparent violation, and the remediation plan all affect the mitigation credit. We regularly advise companies that an internally prepared disclosure has under-stated the analysis or, conversely, over-disclosed facts that were not strictly necessary. Either error can affect the outcome.

A practical decision sequence for cross-border businesses

When a compliance team identifies a potential export-control issue that spans the BIS / EAR and EU regimes, the practical sequence should follow four stages.

Stage one: preserve and scope. Preserve all relevant communications, shipping documents, classification records, and internal approvals. Do not delete or amend records; doing so creates separate legal risk. Scope the apparent violation by reference to the item, the destination, the party, and the licence (or absence of it). Determine whether the EAR applies through the FDPR or de minimis rules, even if the exporter is EU-based. Determine whether any parallel financial-sanctions exposure exists.

Stage two: assess the concurrent jurisdiction. Determine whether the facts create BIS exposure alone, EU national competent authority exposure alone, or both. In a dual-jurisdiction case, consider whether the timing of disclosure under one regime affects the other. There is no formal coordination mechanism between BIS and EU national competent authorities; the two tracks are legally independent. However, material disclosed in one public or semi-public context can reach the other authority through information-sharing channels that exist at the governmental level.

Stage three: structure the disclosure. For BIS exposure, determine whether a VSD is appropriate and, if so, instruct counsel to prepare the initial notification and complete narrative. For EU exposure, identify the relevant national competent authority and the applicable procedure in that member state. Where multiple EU member states are involved, the analysis must be conducted jurisdiction by jurisdiction. Do not assume that a single EU disclosure covers the group.

Stage four: remediate and record. Implement the remediation plan before or concurrently with disclosure. BIS gives mitigation credit for remediation that is genuine and documented. EU national competent authorities similarly regard post-incident remediation as a positive factor. Ensure that the remediation record is complete and that it addresses not only the specific transaction but also the systemic cause – whether that is a classification error, a screening gap, a supply-chain due-diligence failure, or a record-keeping deficiency.

In a recent matter, a manufacturing group with operations in both the United States and Europe discovered that components it had exported had been re-exported by a distributor to a destination that required, but did not hold, a US re-export licence. We scoped the EAR exposure under the FDPR, ran a concurrent sanctions screen against the end user, coordinated the BIS VSD process with a disclosure to the relevant EU national competent authority, and supported the remediation of the group's end-use verification procedures. The matter proceeded through the BIS administrative process with the benefit of voluntary-disclosure mitigation.

How does this analysis relate to other regimes?

The BIS / EAR and EU dual-use regime comparison does not exhaust the cross-border escalation picture. A business with operations or counterparties in the United Kingdom faces a third set of obligations under the Export Control Order and the ECJU licensing regime. UK export controls largely mirror the EU's dual-use list following the post-Brexit transition, but the enforcement architecture is different again: ECJU administers licensing, and enforcement sits with HMRC and the Crown Prosecution Service. A business that has made disclosures to BIS and to an EU competent authority must also consider whether ECJU notification is required.

Beyond the UK, Canada (Global Affairs Canada), Australia (DFAT), and other allied jurisdictions operate export-control regimes with their own escalation and reporting requirements. The US government's partner-country coordination on export controls – particularly within the multilateral export-control regimes – means that a BIS enforcement matter can have follow-on effects in allied jurisdictions. Exporters who assume that a US VSD resolves all international exposure take a significant risk.

Switzerland, through SECO, operates an autonomous export-control regime that applies independently of EU rules. Swiss-based exporters and re-exporters with US-origin goods in their supply chains face the same FDPR analysis as EU-based operators, in addition to their own national obligations.

We regularly advise clients on the interaction between the BIS / EAR, the EU dual-use regime, the UK export-control rules, and the parallel sanctions frameworks administered by OFAC, OFSI, and the EU Council. Handling these regimes as siloed workstreams is a consistent source of residual risk. The escalation and reporting procedures under each regime are technically independent but practically interconnected, and a coordinated response from the outset produces better outcomes than sequential management of each enforcement track.

Related practices

Frequently asked questions

Where do the regimes diverge on escalation and reporting procedures?
The BIS / EAR and EU dual-use regimes diverge most sharply on institutional architecture. BIS operates a single, federal VSD programme with codified mitigation credit. The EU delegates enforcement to twenty-seven member-state competent authorities, producing different procedural timelines, evidential standards, and incentive structures in each jurisdiction. A business with simultaneous BIS and EU exposure must manage two structurally different escalation tracks, which cannot be consolidated into a single disclosure.
Which regime is stricter on escalation and reporting procedures?
Strictness depends on the specific circumstances. The BIS / EAR regime offers greater predictability: a well-prepared VSD with strong remediation typically produces a documented mitigation benefit. Some EU member states have more opaque procedures and less published guidance, which can make the outcome harder to predict. Where the apparent violation involves wilful conduct or high-controlled items, US criminal exposure through the Department of Justice may make the BIS track the more demanding of the two.
What should a cross-border business do about escalation and reporting procedures?
A cross-border business should maintain separate but coordinated escalation tracks for BIS / EAR and EU national competent authority obligations. It should run a concurrent sanctions screen before finalising any disclosure narrative. It should involve external counsel before submitting any VSD or national report, particularly where knowledge of end use, prior enforcement history, or extraterritorial jurisdiction through the FDPR is in play. Escalation is a legal decision, not an administrative one, and early advice materially affects the outcome.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.