Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · BIS / EAR

BIS / EAR vs EU: Name and entity screening: the key divergences

A trading house in Singapore routes a shipment of industrial components through a European distributor to a buyer in South-East Asia. The US exporter has screened the end-user against OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and found nothing. The European distributor has run the same buyer against EU consolidated lists. Both screens return clean. Three weeks later, BIS queries the shipment: the buyer appears on the Entity List (BIS's list of parties subject to enhanced export-licensing requirements or outright denial), a list neither team had incorporated into its screening workflow.

Name and entity screening under the US BIS / EAR regime and the EU export-control and sanctions regime cover overlapping but materially different lists, apply divergent ownership-and-control tests, and impose distinct licensing consequences when a match is found. A screen that satisfies one regime may fail the other entirely. As of mid-2026, the gap between the two regimes creates measurable compliance risk for any business that transacts across both jurisdictions.

This analysis maps the key divergences across the six dimensions that matter most in practice: the lists themselves, the ownership test, the legal consequence of a hit, the licensing route, the record-keeping obligation, and the interplay with secondary-sanctions risk.

What does each regime actually screen?

The BIS / EAR regime requires exporters to screen against multiple separate lists that do not map neatly onto any EU equivalent. The Entity List names parties for whom a licence is required regardless of the item's Export Control Classification Number (ECCN – the classification under the US Commerce Control List that determines whether a licence is required and for what destinations and end uses). The Denied Persons List prohibits transactions outright with named individuals and companies. The Unverified List flags parties whose bona fides BIS has been unable to confirm. Each list carries a different legal consequence, and a party may appear on more than one simultaneously.

The EU approach combines two layers. The EU Consolidated List of persons, groups, and entities subject to financial sanctions is a distinct instrument from the EU Dual-Use Regulation list of controlled goods and technologies. When a party is subject to EU financial sanctions, financial transactions are prohibited. When a party is flagged under the dual-use rules, the obligation is to apply for an export authorisation before shipment. A business that conflates the two mechanisms will misread both the prohibition and the remedy.

In our cross-border practice, the most common screening gap is the failure to run the Entity List as a separate check. Many compliance teams treat OFAC and BIS screening as interchangeable. They are not. A party can be clean on every OFAC list yet appear on the Entity List with a presumption of denial attached.

How do the ownership and control tests diverge?

The ownership test under US sanctions administered by OFAC follows a mechanical threshold: a non-listed entity is treated as blocked when listed persons own it 50 percent or more in the aggregate, directly or indirectly. Intention and management arrangements are irrelevant. The BIS / EAR regime does not apply the same threshold rule to the Entity List; instead, BIS designates parties by name, and the listed party's ownership of another company does not automatically extend the designation to that company by rule. The practical effect is that an entity controlled by an Entity List party may not itself be on the list – but exporting to it with knowledge of the diversion risk triggers separate liability.

The EU position is more nuanced. Under EU financial-sanctions regulations, the ownership-and-control test extends the prohibition to entities owned or controlled by designated persons, where "control" encompasses legal control, indirect ownership, and influence over management decisions. This is broader in one sense – it captures control without ownership – yet narrower in another, because it applies only to EU financial-sanctions lists, not to dual-use export controls. The EU dual-use rules impose end-use and end-user checks as a separate obligation, not an extension of the financial-sanctions ownership test.

What does this mean for a business screening a joint venture? Under OFAC rules, the arithmetic of the listed partner's shareholding decides. Under EU financial-sanctions rules, a minority stake with board control may still catch the entity. Under BIS / EAR, neither automatic test applies; the exporter must instead ask whether the transaction will benefit a listed party or divert to a prohibited end use.

What are the legal consequences when a match is found?

A hit against the BIS Entity List does not automatically prohibit the transaction: it triggers a licence requirement, typically with a presumption of denial for controlled items. The presumption of denial means that BIS will refuse the application in the ordinary case unless the exporter can demonstrate a compelling policy reason to grant. For Denied Persons List hits, the prohibition is absolute – no licence can cure the bar. The distinction between "licence required with presumption of denial" and "prohibited outright" is critical and frequently misunderstood by compliance teams outside the US.

An EU financial-sanctions match, by contrast, freezes assets and prohibits the making available of funds or economic resources. The consequence is a direct prohibition, not a licence trigger. There is a licensing route – EU competent authorities can grant specific authorisations – but the starting position is prohibition, not elevated scrutiny. For EU dual-use controls, the consequence of a match on a controlled good is a licence requirement, structurally closer to the BIS Entity List mechanism, though the list of controlled goods and the classification methodology differ.

In a recent matter, a technology manufacturer shipping controlled components identified a buyer who appeared on neither the SDN List nor any EU financial-sanctions list, but who was listed on the Entity List with a presumption-of-denial policy. The exporter had to determine whether a licence application was worth pursuing or whether a redesigned sales channel was the more proportionate response. We assessed eligibility, scoped the application, and managed the regulator's queries. The matter underlined that a clean financial-sanctions screen is not a clean export-control screen.

Where do the licensing routes diverge?

Under the EAR, a specific licence application to BIS is the formal route when an item requires a licence and the entity-level designation does not bar the application outright. BIS typically processes applications within a statutory period; in practice, processing time depends on the complexity of the transaction and any interagency referral. Licence exceptions – standing authorisations for defined categories of transactions – may also apply and, where available, avoid the need for a case-by-case application. The availability of a licence exception must be checked against the specific ECCN, the destination, and the end use before reliance.

The EU licensing architecture is national: each member state's competent authority issues export authorisations under the EU Dual-Use Regulation. The EU Global Export Authorisation and EU General Export Authorisations function as standing permissions for defined goods, destinations, and quantities, broadly analogous to EAR licence exceptions. However, because licensing decisions are made at the member-state level, outcomes can differ across the EU for the same transaction. A French exporter and a German exporter shipping identical goods to the same buyer may face different processing timelines and, in marginal cases, different outcomes.

For financial sanctions, both the EU and the UK regime (OFSI) offer specific licences for defined categories of activity such as humanitarian transactions, legal fees, or the satisfaction of prior obligations. The EU mechanism requires application to the relevant member-state authority; OFSI decides applications in the UK. These are separate from export-authorisation processes and address different prohibitions.

The position above covers the standard case. Your facts – the counterparty, the goods, the route, the regimes in play – change the analysis. For an assessment of your exposure and whether a licence exception, a specific licence application, or a structural redesign is the right response, contact Calder & Vance at info@caldervance.com.

How do record-keeping and reporting obligations compare?

The EAR imposes a record-keeping obligation of five years from the date of the transaction, covering all export-control records including screening documentation, licence copies, and end-use certificates. This is a minimum; some transactions involving sensitive items or end uses may attract longer retention under other applicable regimes. The five-year rule applies regardless of whether a licence was required or an exception was used.

EU member states apply their own record-keeping requirements under the EU Dual-Use Regulation's national implementation. Periods vary by jurisdiction but are commonly set at five years or a figure close to it, though practitioners should verify the current requirement in each relevant member state before relying on any general statement. For EU financial sanctions, reporting obligations differ: firms subject to anti-money-laundering rules must report knowledge or reasonable grounds to suspect a sanctions breach to the relevant financial intelligence unit, with a reporting window that varies by jurisdiction.

Under OFSI in the UK, there is a specific statutory obligation to report knowledge or reasonable suspicion of a breach. We regularly advise financial institutions on the interaction between OFSI's reporting obligation and the concurrent OFAC reporting expectation that arises when US persons or US-dollar transactions are involved. Both can be triggered by the same event; the timelines and the recipients differ. Managing both simultaneously requires coordination that a single-regime screen will not surface.

What is the secondary-sanctions risk and how does it differ?

Secondary-sanctions risk is a distinctly US concept. OFAC may designate non-US persons who engage in significant transactions with certain sanctioned parties, even where those persons have no US nexus. The BIS / EAR regime does not carry an equivalent secondary-sanctions mechanism; its controls operate through jurisdiction over the item (US-origin goods, US-origin technology, the de minimis rule, and the foreign direct product rule) rather than through designating third-country actors for their trading relationships.

The EU does not operate a secondary-sanctions regime. EU sanctions apply to EU persons, EU-incorporated entities, conduct within EU territory, and transactions in EU currency where that criterion is a legal basis. A non-EU company trading with a party designated only by OFAC has no EU-law obligation arising from that fact alone. The EU Blocking Regulation, however, complicates the picture for EU operators: it prohibits EU persons from complying with certain designated US sanctions measures and creates a legal tension where an EU business is simultaneously subject to US secondary-sanctions risk and prohibited from complying with those US measures as a matter of EU law.

This tension – real, legally live, and not resolved by any agreement between the jurisdictions as of mid-2026 – is one of the most complex risk-management questions we handle. It arises most acutely for EU-incorporated subsidiaries of US multinationals and for EU banks with US correspondent relationships. There is no clean answer. The practical management approach requires advice that covers both regimes and maps the specific US measure against the specific EU blocking prohibition.

What are the critical risk flags for cross-border screening programmes?

Six risk flags recur across the cross-border screening engagements we handle. Each reflects a structural feature of the BIS / EAR versus EU divergence rather than a random compliance failure.

  • Single-list screening: running only the SDN List misses the Entity List, the Denied Persons List, and the Unverified List. Each list triggers different obligations. A complete US export-control screen requires all relevant BIS lists in addition to all OFAC lists.
  • Conflating financial sanctions and export controls: an EU financial-sanctions screen does not substitute for a dual-use export-control classification and end-user check. The lists, the tests, and the consequences are different instruments.
  • Static screening only: lists change without notice. An entity that was clean at the time of contract may be added to a list before shipment. Screening should occur at the point of contract, at the point of shipment, and – for ongoing relationships – at regular intervals.
  • Ignoring the foreign direct product rule: US-origin technology used to produce a foreign item can bring that item within EAR jurisdiction even where neither the exporter nor the buyer is a US person. EU-based exporters frequently underestimate this.
  • Misreading the EU Blocking Regulation: EU operators who simply defer to US guidance on transactions touched by designated US extraterritorial measures expose themselves to EU legal liability. The blocking regulation requires active legal management, not passive deference.
  • Inadequate ownership mapping: under the EU financial-sanctions control test, a minority stake with operational control can extend the designation to an unlisted entity. Under OFAC's 50 percent rule, the arithmetic of aggregate ownership decides. Neither test is satisfied by screening only the named counterparty.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.

A common misconception: "clean on OFAC" means "compliant"

The prevalent belief among non-specialist compliance teams is that a clean OFAC screen is a clean sanctions screen. This conflates two distinct regulatory regimes and ignores the BIS / EAR architecture entirely. OFAC administers economic sanctions; BIS administers export controls. Both are arms of the US Government, but they operate under different statutory authorities, maintain different lists, apply different tests, and impose different obligations and remedies.

A company that appears clean across every OFAC list may nonetheless require a BIS export licence, may trigger the foreign direct product rule, may engage with a party on the Entity List, or may be the subject of a BIS end-use check triggered by a pattern of transactions with third countries of concern. The failure to understand this distinction is not merely a conceptual error. It is a common pathway to regulatory exposure.

The EU dimension adds a further layer. EU compliance teams that rely on US-focused screening tools without incorporating EU dual-use classification and EU competent-authority list checks are operating with a materially incomplete programme. In our experience, this gap is particularly acute in technology and industrial-goods sectors where items frequently sit at or near control thresholds under both regimes.

Related practices

Frequently asked questions

Where do the regimes diverge on name and entity screening?
The regimes diverge across four principal dimensions. First, the lists: BIS / EAR maintains the Entity List, Denied Persons List, and Unverified List as distinct instruments, while the EU combines financial-sanctions lists with dual-use end-user considerations. Second, the ownership test: OFAC applies a mechanical 50 percent aggregate-ownership threshold; EU financial sanctions apply an ownership-and-control test that can capture minority-stake control. Third, the legal consequence of a match: Entity List hits trigger a licence requirement with a presumption of denial; EU financial-sanctions matches create a direct prohibition. Fourth, secondary sanctions: OFAC may designate non-US actors for certain trading relationships; the EU has no equivalent mechanism and operates a blocking regulation that conflicts with certain designated US secondary-sanctions measures.
Which regime is stricter on name and entity screening?
Neither regime is uniformly stricter. The BIS / EAR regime is broader in jurisdictional reach through the foreign direct product rule, which can catch non-US items produced with US technology. The EU financial-sanctions regime is broader in its control test, which captures minority-stake influence that OFAC's 50 percent rule would not reach. For most cross-border exporters, the practical answer is that both regimes must be satisfied simultaneously, and the stricter prohibition governs each specific element of the transaction. Where the two create conflicting obligations – as the EU Blocking Regulation does for certain US-designated extraterritorial measures – the position requires specific legal analysis rather than a general answer.
What should a cross-border business do about name and entity screening?
A cross-border business should operate screening that covers all relevant lists in all applicable regimes: for US transactions, that means OFAC lists and BIS lists as separate checks; for EU transactions, the EU Consolidated List and dual-use end-user assessment; for UK transactions, OFSI's consolidated list. Screening should occur at contract stage, at shipment, and periodically for ongoing relationships. Ownership chains should be mapped to at least the level required by the most demanding applicable test – which under the EU control test may require mapping management influence, not just shareholding arithmetic. Where a match is found, the legal consequence and the available remedy differ by list and by regime; specialist advice should be sought before a decision is made.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.