Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · BIS / EAR

Name and entity screening under BIS / EAR: the key divergences

A payments firm with correspondent relationships across three continents runs a routine screening refresh. The buyer's ultimate beneficial owner surfaces as a match on the Entity List (BIS's list of parties subject to enhanced licence requirements or outright restrictions under the Export Administration Regulations). The compliance team freezes the relationship. But is the Entity List hit actually a prohibition? And how does that hit interact with the OFAC SDN List (OFAC's list of Specially Designated Nationals and blocked persons) check the firm ran in the same pass? Two regulators, two different legal standards, and two different consequences – all triggered by the same name.

Name and entity screening under BIS and the EAR (Export Administration Regulations) is legally distinct from OFAC financial-sanctions screening and from the EU and UK ownership-and-control tests. The BIS regime targets export transactions – shipments, re-exports, transfers in country – and runs against the Entity List, the Denied Persons List, and the Unverified List, each carrying different legal consequences. A match does not automatically block the transaction; it triggers a licence-requirement or due-diligence obligation that depends on the list and the item. As of July 2026, firms operating across US, EU, and UK regimes routinely run parallel screening passes against divergent list architectures, and a single consolidated result can obscure which legal obligation actually applies.

This analysis maps the BIS screening architecture, compares it with the OFAC, EU, and OFSI frameworks, identifies the points of sharpest divergence, and sets out the practical steps a cross-border compliance team should take when a BIS list hit appears alongside an OFAC or EU hit in the same screening run.

What does the BIS screening architecture actually cover?

The BIS screening architecture covers three principal lists, each with a distinct legal consequence, and no single rule treats a match the same way across them. That structural difference is the first point most cross-border teams misread.

The Entity List is the most commercially significant. A party placed on it is subject to a licence requirement for any export, re-export, or in-country transfer of items subject to the EAR. The licence review policy for most Entity List entries is a presumption of denial. That presumption means that in practice a licence application is rarely worth pursuing; the real question is whether the item is subject to the EAR at all and whether any licence exception applies.

The Denied Persons List (DPL) is different in kind. A DPL entry represents an active denial order – an administrative sanction against a specific individual or company. Any export transaction that involves a denied person, in any capacity, is prohibited without a specific licence. There is no de minimis carve-out. We regularly advise clients who have discovered that a freight forwarder or logistics agent on a multi-hop shipment carries a DPL entry; the exposure extends to every party in the transaction chain that had, or should have had, knowledge of that involvement.

The Unverified List (UVL) operates at a lower level of restriction but is not a clean bill of health. A UVL entry signals that BIS has been unable to verify the party's legitimacy through an end-use check. Shipping to a UVL party without first completing a BIS undertaking (a written confirmation of end-use and end-user from the party) is a red flag that can itself constitute a violation under the "reason to know" standard. In our experience, many compliance programmes treat the UVL as a watch list rather than an active restriction trigger – that is an error.

There is also the Military End-User (MEU) list, a subset of the Entity List specifically addressing parties assessed as military end users in designated countries. The MEU designation removes access to a range of licence exceptions that would otherwise be available, materially narrowing the permissible transaction scope even for low-controlled items.

How does BIS screening diverge from OFAC financial-sanctions screening?

The fundamental divergence between BIS and OFAC screening is the legal consequence of a match: an OFAC SDN match blocks the transaction and freezes the property; a BIS Entity List match triggers a licence requirement that may, on analysis, have an applicable exception.

OFAC screening applies to persons and entities across all transaction types – financial, commercial, and operational. The SDN List is a property-blocking instrument. When a person appears on it, all their property and interests in property subject to US jurisdiction are frozen, and US persons are prohibited from dealing with them in any capacity. The 50 percent rule extends that prohibition to any entity owned 50 percent or more in the aggregate by one or more blocked persons, whether or not the entity itself appears on any list. That rule operates automatically and without any licensing carve-out at the transaction level.

BIS does not operate a 50 percent aggregation rule equivalent. An entity owned by an Entity List party is not automatically subject to the same restrictions as the listed party, unless it has itself been added to the list. This is a significant structural difference. A compliance team running a consolidated screen that returns a BIS Entity List hit on a parent company needs to apply the EAR's own "acting on behalf of" and "knowledge" standards to determine whether a downstream subsidiary transaction is caught – and those standards do not map cleanly onto the OFAC aggregation analysis.

A further divergence concerns jurisdiction. OFAC sanctions apply to US persons and to transactions touching US jurisdiction, but certain programmes also carry extraterritorial secondary-sanctions exposure. BIS jurisdiction is anchored to the EAR's own jurisdictional reach: items subject to the EAR (by virtue of US origin, technology content, or the de minimis rule) remain subject to it regardless of where the transaction occurs. A non-US company re-exporting a product containing more than a defined proportion of US-controlled content remains subject to the EAR even if no US person is involved in the transaction. That extraterritorial effect – the de minimis rule and the foreign-direct product rule – is the mechanism through which BIS list exposure reaches non-US screening programmes.

Does your compliance programme classify BIS list hits and OFAC hits under the same escalation protocol? In our experience, firms that use a unified escalation path for both miss the threshold question: for a BIS hit, the first query is whether the item is subject to the EAR at all; for an OFAC hit, that question is largely irrelevant.

Where does the EU and UK screening architecture diverge from the BIS model?

The EU and UK screening regimes diverge from BIS at the level of legal test, list architecture, and the governing concept of control. Understanding those divergences prevents a cross-border team from incorrectly concluding that a BIS clean result satisfies EU or UK obligations, or vice versa.

EU financial sanctions operate through Council regulations implementing asset-freezing and dealing prohibitions. The lists are administered by the EU Council and maintained in the EU Consolidated Sanctions List. Unlike the BIS Entity List, an EU designation triggers a comprehensive asset freeze and dealing prohibition that does not require the transaction to involve a controlled item. The test is whether the person is designated, and whether any dealing falls within the prohibition.

The EU ownership-and-control standard extends those prohibitions to entities owned or controlled by designated persons. Ownership and control under EU law is assessed not only by the mechanical percentage threshold but also by qualitative control – the ability to exercise a dominant influence. This is materially broader than the BIS approach. An entity not on any list can still be caught if a designated person controls it through means other than majority shareholding.

OFSI in the UK applies a similar ownership-and-control standard under SAMLA (the Sanctions and Anti-Money Laundering Act). OFSI guidance addresses both direct and indirect ownership, and control through other means. The UK's approach post-Brexit has largely mirrored the EU position on ownership thresholds but has developed its own enforcement posture and its own licensing practice. Notably, OFSI has issued monetary penalties without requiring a finding of intent for civil violations – a stricter enforcement position than some other regimes maintain.

What this means for a screening programme is that a clean BIS result for a counterparty does not constitute an EU or UK screen. The lists are different. The legal tests are different. And the consequences of a match are different. A compliance programme that conflates them – or that sequences a BIS screen as a proxy for an EU or UK check – carries structural risk that becomes visible only when an enforcement inquiry arrives.

The position in Singapore, Japan, and the UAE adds further dimension. Each of those jurisdictions has its own list-based screening obligations derived from UN Security Council measures and, in some cases, autonomous national designations. A counterparty clean on BIS, OFAC, OFSI, and EU lists may still appear on a UN Consolidated List designation or a national-authority list in a relevant transit or end-user country. Where supply chains run through multiple jurisdictions, screening must be run against each applicable list – not only the US and EU lists that most global compliance tools prioritise.

What are the practical risk flags in a cross-border BIS screening run?

The most common practical risk flags in a BIS screening run are not false positives on the lists themselves; they are false negatives – cases where the relevant restriction applies but the screening tool does not capture it.

The first flag is the "reason to know" standard. BIS enforcement does not require proof of actual knowledge that a party is a restricted entity. It is sufficient that the exporter had reason to know. A cluster of red flags – unusual routing requests, payments from third parties, requests to omit ECCN classifications from shipping documents, end-user addresses that do not correspond to the stated use – can constitute constructive knowledge even without a list hit. A screening tool that checks names against lists and returns no match does not clear a transaction that is otherwise surrounded by red flags.

The second flag is the de minimis and foreign direct product rule exposure. A UK or EU entity shipping a product that contains more than a controlled threshold of US-origin controlled content is shipping an item subject to the EAR. If the consignee appears on the Entity List, the UK or EU entity may be in breach of the EAR even though it has no US presence and no US persons are involved in the transaction. This is the extraterritorial mechanism that converts a BIS screening obligation into a global compliance question for any business in the supply chain of US-origin or US-technology products.

Third: the MEU list is under-screened. Many commercial screening tools do not maintain a current and complete MEU list feed, or do not flag MEU entries separately from the main Entity List entries. The consequence is that transactions involving parties whose licence exception access has been narrowed by MEU status may proceed on the erroneous assumption that a standard licence exception is available.

Fourth: name-matching logic is rarely adequate for BIS list screening when applied across transliterated names, aliases, and entity variants. BIS list entries include aliases, but the quality of alias coverage varies. A screening programme calibrated to a high-confidence match threshold for OFAC SDN matching may miss a lower-confidence partial match that is the correct BIS entity. The sensitivity settings used for OFAC and BIS screening should not be identical; the risk profiles of the two lists are different.

In a recent matter, a technology manufacturer discovered that its logistics provider had been added to the Unverified List following a failed end-use check by BIS. The manufacturer's screening tool had not been updated to reflect that addition. The goods – which carried an ECCN classification requiring a licence for certain end uses – had moved on a licence exception that the UVL status made unavailable without a prior undertaking. Early engagement with counsel to scope the apparent violation and advise on voluntary self-disclosure preserved options that narrowed as time passed.

How should a compliance programme be designed to handle BIS and OFAC hits in the same screen?

A compliance programme that handles BIS and OFAC hits in the same screen needs separate analytical pathways for each hit type, not a unified escalation queue that treats all matches as equivalent prohibitions.

When an OFAC SDN match appears, the immediate question is: is this a true match? If it is, the transaction is presumptively prohibited, property may need to be frozen, and a report to OFAC may be required. The compliance officer does not need to assess the item classification or the licence exception before escalating. The prohibition operates at the level of the person.

When a BIS Entity List match appears, the immediate question is different: is the item subject to the EAR? If the item is EAR99 (the catch-all category for items not listed on the Commerce Control List), the Entity List restriction still applies. That is a point many teams miss. Entity List restrictions apply to all EAR-subject items, including EAR99 items, for the listed party. The next question is whether the proposed transaction falls within a licence exception. For most Entity List entries, the available exceptions are narrow or foreclosed by the listing's licence review policy.

When both a BIS hit and an OFAC hit appear on the same counterparty, the more restrictive prohibition governs. The OFAC prohibition operates as a property-blocking measure and applies to all dealings, not only to export transactions. The BIS restriction applies to EAR-subject exports. The compliance response must address both, and the record should document the analysis under each regime separately.

We regularly advise clients on building tiered screening architectures that separate the list-type logic, the jurisdiction trigger, and the consequence analysis into distinct decision paths. A single escalation ticket that says "match – hold" without specifying which list, which regime, and which legal consequence applies is not a compliance record; it is a risk log entry that tells a regulator the firm knew about a hit but did not analyse it.

The position above covers the standard case. Your facts – the item classification, the counterparty's role, the jurisdiction of the transaction, and the specific list involved – change the analysis. For a review of your screening architecture or an assessment of a specific match, contact Calder & Vance at info@caldervance.com.

When does a BIS screening result require counsel involvement?

A BIS screening result requires counsel involvement when the match is on the Denied Persons List, when the item is subject to a licence requirement for the specific end use or end user, when the red-flag analysis is inconclusive, or when a prior shipment to the flagged party is under review.

DPL matches are the clearest case. A denial order is an active administrative sanction. Any continuation of a transaction – even a shipment in transit – that involves a denied party in any role can constitute a violation. The first call after a confirmed DPL match is to counsel, not to the licensing team.

Entity List matches require a rapid item-classification review. If the item is subject to the EAR and no licence exception applies, the transaction cannot proceed without a BIS licence. Given the typical denial presumption on Entity List entries, the question is whether the business relationship is restructurable without the listed party's involvement, or whether the transaction should simply not proceed. Counsel can assess the restructuring options and advise whether a licence application is realistic.

Red-flag situations – where no list hit appears but the surrounding circumstances suggest a restricted end user or end use – require a documented red-flag assessment. That assessment needs to apply BIS's published guidance on what constitutes a red flag and what level of diligence is expected before proceeding. A decision to proceed documented only as "no list match" is not an adequate red-flag assessment and will not constitute a defence in an enforcement inquiry.

If a transaction has already been flagged, or a prior shipment to a now-listed party is under review, an early legal assessment can preserve options that narrow with time. The difference between a VSD (voluntary self-disclosure to BIS) filed before an inquiry and one filed after a formal investigation is material to the penalty exposure. Contact Calder & Vance at info@caldervance.com for a confidential initial review.

A note on the myth that BIS screening is only a US-entity obligation

A persistent misconception among non-US businesses is that BIS and EAR obligations are a domestic US compliance matter – relevant to US exporters but not to European, Asian, or Gulf-based businesses that happen to handle goods of US origin or technology. That view is incorrect, and it is the source of a significant proportion of the EAR enforcement exposure we see in cross-border practice.

The EAR's de minimis rule and foreign direct product rule extend US export-control jurisdiction to non-US parties in two circumstances: first, when a non-US product incorporates more than a controlled percentage of controlled US-origin content by value; second, when a non-US product is itself the direct product of US-origin technology or software subject to a specific control. In either case, the non-US product is "subject to the EAR" regardless of where it was manufactured, and the person shipping it must comply with BIS list restrictions.

For non-US businesses in the supply chains of semiconductor equipment, advanced materials, telecommunications technology, and a range of other dual-use sectors, this means the BIS Entity List, the DPL, and the UVL are not academic. A non-US distributor shipping a controlled item to an Entity List party in a third country may face BIS enforcement action even if every other regulator in the chain has no jurisdiction. In our cross-border practice, we regularly advise non-US clients – European manufacturers, Asian distributors, Gulf trading houses – on mapping their EAR exposure and building BIS-aware screening into supply-chain operations that have historically screened only for OFAC and EU designations.

Related practices

Frequently asked questions

Where do the regimes diverge on name and entity screening?
The principal divergences are the legal consequence of a match, the ownership-and-control test, and the list architecture. An OFAC SDN match triggers a property block and dealing prohibition across all transaction types. A BIS Entity List match triggers a licence requirement for EAR-subject transactions only. EU and OFSI matches require an ownership-and-control analysis that extends to entities controlled through qualitative means, not only by percentage ownership. These are distinct legal tests that require separate analytical tracks in any multi-regime screening programme.
Which regime is stricter on name and entity screening?
No single regime is categorically stricter across all dimensions; the answer depends on the fact pattern. For financial and commercial dealings broadly, OFAC's property-blocking prohibitions are the most comprehensive in their scope and extraterritorial reach. For export transactions, BIS's Denied Persons List applies a complete prohibition with no transaction-type carve-out. The EU and UK regimes apply a broader qualitative control test that can catch entities not on any list. In practice, the strictest obligation is the one that applies to your specific transaction, item, and counterparty – and identifying which that is requires regime-by-regime analysis.
What should a cross-border business do about name and entity screening?
A cross-border business should first map which regimes apply to its transactions – by jurisdiction, by item type, and by the EAR's de minimis and foreign direct product rules. It should then assess whether its screening tool covers all applicable lists with sufficient alias depth and update frequency. It should operate separate escalation tracks for BIS hits and OFAC or EU hits, because the consequence analysis is different. Where a match is unclear or the red-flag analysis is inconclusive, early counsel involvement is more cost-effective than a late VSD. Contact Calder & Vance at info@caldervance.com to discuss a screening-architecture review.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.