An export-control compliance officer at a precision-equipment manufacturer receives an email from the Bureau of Industry and Security. The subject line reads: "Request for information – EAR-related shipments." Simultaneously, the company's European subsidiary receives a written enquiry from its national competent authority acting under the EU dual-use regulation. Two requests, two regimes, two very different procedural obligations – and a single misstep in either jurisdiction can convert a manageable inquiry into a formal enforcement action.
Responding to regulator information requests under the EAR (the Export Administration Regulations, administered by the US Bureau of Industry and Security) and under the EU dual-use regime requires understanding two distinct procedural logics. BIS exercises broad pre-enforcement investigative powers, with voluntary disclosure as a key mitigant. EU competent authorities operate under national procedural rules but within a shared regulatory standard, producing material divergence in timelines, privilege treatment, and the weight given to co-operation. As of March 2026, neither regime has converged on a common response protocol.
This analysis maps the key divergences between BIS / EAR and EU information-request practice, identifies the risk flags that escalate an inquiry to enforcement, and sets out the decision points where specialist counsel should be engaged.
What authority does BIS have to request information under the EAR?
BIS derives its investigative authority from the Export Control Reform Act and the underlying enabling legislation, including IEEPA. Within that framework, the Office of Export Enforcement can issue formal requests for documents, records, and written responses. It may also conduct unannounced visits – commonly called "end-use checks" or "pre-licence checks" – to verify that exported goods are held and used as stated in licence applications and end-use certificates.
The scope of a BIS information request is frequently broader than its subject line suggests. In our experience, a request framed around a single shipment will often test the recipient's entire record-keeping practice for a multi-year window. Exporters who treat the request as narrow and produce only responsive documents for the named transaction regularly find that BIS then raises follow-on questions about record gaps elsewhere in the same period.
Two features of the BIS regime are particularly important at this stage. First, BIS operates a voluntary self-disclosure (VSD) programme – a mechanism for proactively reporting apparent violations, which is treated as a significant mitigating factor in any subsequent penalty determination. Second, the EAR imposes a record-keeping obligation: exporters must retain certain export-related records for five years from the date of export or from the date of any other relevant transaction. A document production that reveals gaps in that five-year record can itself become an additional compliance concern.
The position above covers the standard BIS inquiry. Your facts – the goods, the end-user, the licence exception relied upon, the record-keeping practice in place – change the analysis materially.
For assessment of your apparent-violation exposure under the EU regime, our team works through the same questions on the EU side: Apparent violation assessment – EU.
How does the EU dual-use information-request process differ?
EU competent authorities – the national bodies responsible for enforcing the EU dual-use regulation in each member state – have investigative powers set by both EU law and domestic procedural legislation. The result is that an information request from a German competent authority and one from a Dutch or Swedish authority may differ significantly in form, compelled-disclosure scope, and the consequences of non-response, even though both operate under the same underlying EU regulation.
At EU level, the regulation establishes the substantive obligations: classification, licensing, end-use assurance, and record-keeping. But it does not harmonise procedural enforcement. Each member state's authority applies its own national administrative-law rules on notice periods, legal-privilege protection, and the right to decline to produce self-incriminatory materials. For a multinational group receiving parallel requests in two or more EU jurisdictions, this fragmentation creates real co-ordination risk.
In our cross-border practice, we regularly advise groups whose compliance team has responded to one national authority's request in a way that is entirely appropriate under that jurisdiction's rules, but that inadvertently waives a procedural protection available in the parallel jurisdiction. Co-ordinated response strategies – agreed across all implicated subsidiaries before any single response is sent – are not a luxury at this stage. They are necessary.
A further divergence from the BIS regime concerns audit and inspection powers. Several EU member states grant competent authorities powers to inspect premises, goods, and records on shorter notice periods than those typical in BIS end-use check practice. The practical consequence is that the window between receiving an inspection notice and the arrival of officials can be measured in days rather than weeks.
Where do the BIS / EAR and EU regimes diverge most sharply?
The sharpest divergences between BIS / EAR and EU practice in this context fall across four dimensions: the weight given to voluntary disclosure, legal-privilege treatment, record-keeping obligations, and the extraterritorial reach of the request.
Voluntary disclosure. BIS has a well-developed VSD framework. A timely, accurate, and complete voluntary self-disclosure before BIS initiates a formal investigation is treated as a major mitigating factor. The programme is procedurally defined: a company can make a preliminary notification and then submit the full disclosure within a structured window. EU competent authorities have no equivalent harmonised VSD mechanism. Some national regimes recognise spontaneous reporting as a mitigant in penalty proceedings. Others treat it as evidence of the violation itself and adjust the penalty only marginally. The asymmetry means that a strategy calibrated to the BIS VSD pathway will not transfer cleanly to the EU side.
Legal professional privilege. Under US federal law, attorney-client privilege and attorney work-product protection apply to communications between counsel and client in the context of an export-control investigation. BIS information requests must be read against that background. In the EU, privilege is recognised but its scope varies by jurisdiction and by whether in-house counsel or external counsel produced the document. In certain member states, in-house legal advice does not attract the same protection as external counsel's advice. A document production strategy that draws an internal/external distinction in the US context may apply entirely different rules in France, Germany, or the Netherlands.
Record-keeping obligations. Under the EAR, the five-year retention period is a defined obligation. EU member-state obligations are set by the dual-use regulation and national implementing rules and differ in scope. A compliance team that has built its document-management system around a single standard may find that the EU side requires retention of categories the BIS regime does not specifically call out, and vice versa.
Extraterritorial reach. BIS exercises jurisdiction over items subject to the EAR wherever they are located. This means BIS can request information from non-US parties that have received US-origin items under a licence or exception. EU competent authorities have authority over EU-origin items and over EU-established exporters. For a non-EU, non-US intermediary holding goods of both US and EU origin, both BIS and an EU authority may simultaneously be entitled to investigate the same underlying transaction. Managing parallel requests requires co-ordination that goes beyond responding to each independently.
What are the risk flags that escalate an information request to enforcement?
An information request is not an enforcement action. But several patterns reliably convert a routine inquiry into a formal investigation – or, at its most serious, a referral to a criminal enforcement agency.
The most significant risk flag is an incomplete or inaccurate initial response. When a company provides a response that BIS or an EU authority later determines omitted material records or contained inaccurate statements, the regulator's attention shifts from the underlying export to the response itself. The underlying transaction may have been a technical violation with strong mitigating factors. An inaccurate response to a regulator can produce a far more serious exposure than the original event.
A related flag is an unexplained gap in records. Where the five-year record-keeping obligation applies and a company cannot produce records for a portion of that period, the default presumption – from the regulator's perspective – is non-compliance. The company faces the burden of explaining the gap. In our experience, companies that have experienced IT migrations, mergers, or office closures during the relevant period need to address record availability before they respond, not during the response process.
End-use and end-user discrepancies create a third category of escalation risk. A licence application states that goods will be used in a specific application by a named entity. A BIS end-use check – or an EU end-use certificate request – reveals that goods have been re-exported, retransferred, or are in the possession of a different entity. Even where this occurred through an innocent supply-chain reorganisation, the failure to seek prior approval for the change is a potential violation on its own. The regulator's response to that kind of discrepancy is more severe than to a clean administrative error.
Finally, parallel jurisdictional exposure amplifies risk across the board. A company managing a BIS information request should map whether any related transactions touch EU-origin goods or EU-established entities, and vice versa. A response that settles the BIS matter but produces admissions that trigger an EU investigation has not resolved the problem.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.
How should a cross-border business structure its response?
Structuring a response to a BIS information request – or to a parallel EU inquiry – requires a sequenced approach that runs concurrently across legal, compliance, and operational workstreams. The following decision sequence reflects how we approach this in practice.
Step one: scope the request before producing anything. Read the request carefully to identify the transactions, entities, and timeframes it covers. Do not assume the request is limited to what is named. Identify all records that fall within scope, including records held by affiliates, subsidiaries, freight forwarders, and third-party logistics providers.
Step two: assess privilege before collection begins. Communications generated in the course of the review – including internal communications about what the records show – may themselves attract privilege protection, provided they are properly structured. Once collection begins without that structure, the protection may be lost.
Step three: identify gaps and prepare to explain them. Where records are missing or incomplete, document the reason before the response is filed. An unexplained gap is more damaging than an explained one.
Step four: assess the VSD question. If the document review uncovers an apparent violation that the request did not specifically identify, the question of voluntary self-disclosure arises. Timing is critical: a disclosure filed before BIS formally opens an investigation is treated materially differently from one filed after. This step should not be deferred.
Step five: co-ordinate across jurisdictions. Where parallel EU requests are in play, responses should be co-ordinated so that admissions, document-production waivers, and privilege decisions in one jurisdiction do not prejudice the position in another.
Step six: draft the response to the standard of a legal submission. The response is a document of record. It will be read in the context of any subsequent enforcement action. It should be accurate, complete, clearly structured, and legally reviewed before it is sent.
For a comparison of the BIS / EAR and OFAC approaches to information-request management, see Regulator information requests: OFAC vs BIS / EAR.
Is the "we have a strong compliance programme" defence effective?
A common assumption in cross-border compliance teams is that demonstrating the existence of a written compliance programme will substantially limit enforcement exposure once a regulator asks questions. This is the myth worth correcting directly.
Neither BIS nor EU competent authorities treat the existence of a compliance programme as an automatic shield. What they assess is whether the programme is operationally effective – whether it was actually followed in the transactions under review, whether training was current, whether red flags were escalated and resolved, and whether management took compliance obligations seriously at the deal stage rather than only when answering a regulator's questions.
A company that can show it had a paper policy but cannot demonstrate that the policy governed the transactions in question is in a materially weaker position than one without a formal programme that treated every export decision carefully. In our cross-border practice, we have seen BIS treat an ineffective programme as an aggravating factor: it suggests the company knew the rules and failed to implement them.
The EU position is broadly comparable. National competent authorities assessing penalty levels consider whether the exporter had procedures proportionate to its risk profile and whether those procedures were applied. A programme designed for a different scale of operations, or one that had not been updated to reflect changes in the dual-use control list, does not attract the same mitigation credit as a genuinely operational one.
The practical implication is that the time to strengthen a compliance programme is before a request arrives, not in response to one. Retrospective programme-building during an investigation is visible to regulators and carries limited mitigation value.
See also our analysis of regulator information requests – OFAC vs BIS / EAR (further analysis) for parallel observations on programme-effectiveness as a mitigant.
When does an information request require specialist sanctions and export-control counsel?
Not every BIS information request demands immediate external legal engagement. But several features of a request – or of the facts behind it – make specialist counsel necessary rather than optional.
Counsel should be engaged at the outset where: the request covers transactions involving items that are Export Control Classification Number (ECCN)-controlled and the company is uncertain whether the correct licence exception was applied; where the request involves re-exports by a non-US distributor; where there is any possibility that the underlying transactions touched a denied party, a designated entity, or a restricted end-use; or where a parallel EU inquiry is in progress or anticipated.
Counsel should also be engaged immediately where the company discovers, during its internal review, facts that were not disclosed in the original licence application – whether or not those facts are responsive to the regulator's request. The disclosure question that arises at that point is time-sensitive and legally complex.
The BIS VSD decision is not one a compliance team should make without legal input. The timing, framing, and completeness of a voluntary self-disclosure directly affects how BIS characterises the violation and calculates the applicable penalty base. A preliminary notification made too early – before the full scope of the apparent violation is understood – can lock in a characterisation of the facts that is difficult to revise. One made too late forfeits most of the mitigation value. Counsel experienced in BIS VSD practice manages that window.
On the EU side, the decision about whether to engage with a national authority's request through legal counsel – and whether that counsel should be in-house or external, and of which nationality – affects privilege, as discussed above. These are not purely procedural questions. They have direct consequences for what the authority can compel the company to produce.
Related practices
- Apparent violation assessment – EU – assess EU dual-use and sanctions enforcement exposure before responding
- Regulator information requests: OFAC vs BIS / EAR – parallel analysis of OFAC and BIS investigative procedures