A technology distributor operating between North America and Asia-Pacific closes what looks like a clean deal. The buyer passes OFAC screening. The goods are commercially available. The internal legal team clears it. Six weeks later, a customs hold reveals that the item's Export Control Classification Number (ECCN – the identifier assigned to goods and technology under the US Commerce Control List) triggered a licence requirement that the distribution team had never assessed. The transaction was not an OFAC problem. It was a BIS problem. And the difference between those two regimes – in scope, in methodology, and in the tests they apply – is where risk assessments most often fail.
Sanctions risk assessment under the BIS / EAR regime is materially different from an OFAC-centric assessment. The Export Administration Regulations (EAR – the rules administered by the US Bureau of Industry and Security governing the export, re-export, and in-country transfer of controlled items, technology, and software) require a classification-first, end-use-second analysis that OFAC screening does not replicate. A business that applies only OFAC methodology to a BIS-regulated transaction will miss a significant category of exposure.
As of July 2026, enforcement activity under the EAR continues to reach non-US businesses through the extraterritorial reach of the de minimis rule and the foreign-direct-product rule. This analysis sets out where the regimes diverge, how the BIS risk-assessment methodology works in practice, and what a cross-border compliance team must do differently when goods, technology, or software touch the US supply chain.
What makes BIS / EAR risk assessment structurally different from OFAC analysis?
BIS / EAR risk assessment begins with the item, not the counterparty. That distinction drives the entire methodology and sets it apart from the OFAC model.
Under OFAC, the primary question is identity: is the counterparty a Specially Designated National, a blocked entity, or a jurisdiction-wide target? The SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and the relevant programme regulations define who or what is prohibited. Screening tools, ownership-chain analysis, and the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) govern the answer.
BIS works differently. The first question is classification: what is the item, does it have an ECCN, and what controls attach to that classification? Only once classification is established does the analyst ask about the destination, the end-user, and the end-use. The sequence is not interchangeable. Running counterparty screening before classification gives a false sense of completion.
In our cross-border practice, we regularly see compliance programmes that maintain strong OFAC screening processes but carry almost no systematic classification review. The two gaps are not equivalent. A missed SDN hit is an OFAC violation. A mis-classified export is an EAR violation. Both are civil and potentially criminal matters, but they arise from entirely different analytical steps and require different remediation.
The second structural difference is extraterritorial reach. OFAC's programme-based jurisdiction has well-understood extraterritorial dimensions, particularly through secondary-sanctions risk. BIS extraterritoriality operates through two specific mechanisms – the de minimis rule and the foreign-direct-product rule – that can pull non-US-origin items into EAR jurisdiction based on their content or their production method. A risk assessment that does not test for those triggers will miss jurisdictional exposure even where no US person is involved in the transaction.
How does the BIS classification-first methodology work in practice?
Classification under the EAR determines whether an item is subject to the rules at all and, if so, what controls apply. The process has a defined sequence that every risk assessment must follow.
The first step is to determine whether the item is on the Commerce Control List (CCL – BIS's enumerated list of controlled items, technology, and software, each assigned an ECCN). If the item has an ECCN, the controls column of the CCL entry specifies the reasons for control (national security, anti-terrorism, nuclear non-proliferation, regional stability, and others). Those reasons determine which country-destination combinations require a licence.
If the item does not appear on the CCL, it is classified as EAR99. That designation does not mean it is uncontrolled. EAR99 items can still require a licence when the destination, end-user, or end-use triggers a separate restriction – the Entity List, the denied-persons list, or an end-use control that catches nuclear, chemical, biological, or missile programmes regardless of classification.
This is one of the most consequential errors we encounter in practice. Compliance teams see EAR99 and stop the analysis there. The end-use and end-user checks are then not run. The result is a transaction that cleared classification review but remained exposed on a different ground entirely.
Step two is destination analysis. Once the ECCN and control reasons are known, the analyst maps them against the relevant country chart, which the EAR maintains as a matrix of destinations and control reasons. A licence exception may apply, but the availability of an exception must itself be confirmed against the specific control reasons – not assumed from the item's general commercial character.
Step three is the end-use and end-user check. This applies independently of the CCL determination. The Entity List (BIS's list of parties for whom specific export licence requirements apply, separate from the SDN screening process) must be screened against all parties: exporter, consignee, purchaser, end-user, and freight forwarder. The Denied Persons List and the Unverified List add further layers. Each list carries different consequences, and the compliance action for a party on the Unverified List differs from the action for an Entity List party.
Where does the BIS / EAR regime diverge from the OFAC ownership test?
The ownership test under OFAC is mechanical: 50 percent or more ownership by a blocked person, directly or in aggregate, makes the owned entity itself blocked, regardless of its operational independence or its own listing status. The test is binary and does not require a case-by-case assessment of control.
BIS does not apply the same bright-line test. The EAR's person-based controls – particularly the Entity List – operate through a designation mechanism. A party is subject to enhanced licence requirements when BIS has specifically designated it. The analysis is not automatic aggregation from ownership; it is a case-by-case determination made by BIS itself. Aggregated ownership of an Entity List party by a blocked person does not automatically make the unlisted parent an Entity List party under BIS rules.
That divergence creates a real operational problem for businesses that use a single unified screening tool. An entity that OFAC treats as blocked (because a designated person owns more than half of it) may be unrestricted under BIS entity controls, and vice versa. The converse is equally possible: an entity on the Entity List that no designated person owns is flagged by BIS screening but cleared by OFAC screening.
From a practical compliance standpoint, this means that BIS screening and OFAC screening must be run in parallel but assessed on different legal bases. A unified "cleared" or "blocked" output from a single tool is not adequate for dual-jurisdiction transactions. In our experience, the businesses that manage this most effectively maintain separate analytical tracks for OFAC status and EAR entity-control status, with a clear escalation path when the two tracks give different answers.
The EU and UK regimes add a third analytical track. Both apply an ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person's ownership or direction), which is broader than OFAC's 50 percent rule because control can be decisive even where ownership sits below that threshold. A business operating across the Atlantic must run OFAC, EU, and UK tests simultaneously on the same counterparty, accepting that they may yield different results.
What does extraterritorial reach mean for a non-US business conducting a BIS risk assessment?
For a non-US business, the EAR's extraterritorial reach is the most operationally consequential feature of BIS risk assessment. Two rules determine when non-US-origin goods, software, or technology become subject to the EAR.
The de minimis rule captures foreign-made items that incorporate US-controlled content above a defined value threshold. When a non-US product contains US-origin controlled components or software, the entire product can become subject to EAR jurisdiction for purposes of export or re-export to specified destinations. The threshold varies by destination and by control reason; there is no single universal figure, and the applicable threshold must be confirmed against the relevant country and the relevant ECCN. Using a figure without that confirmation is a classification error, not a compliance step.
The foreign-direct-product rule is structurally different. It captures non-US products that are the direct product of certain US-controlled technology or software. It operates even where the US-origin content has no physical presence in the finished product. As of mid-2026, BIS has extended the foreign-direct-product rule in the context of specific country-programme designations; whether a particular production process triggers the rule requires item-specific legal analysis, not a general assumption.
For the compliance practitioner advising a European or Asian manufacturer, this means that the EAR risk assessment cannot be limited to US-origin components. The production process itself must be reviewed. Has the manufacturing line used any US-origin semiconductor equipment, US-controlled software tools, or US-origin process technology? If yes, the foreign-direct-product analysis must be run before the product leaves the factory.
We regularly advise manufacturers who discover this exposure only at the export stage, when the re-export analysis flags a jurisdiction that triggers the rule. At that point, the product may already be in the supply chain, and the remediation options are narrower. An upstream classification review – before production commitments are made – is far more cost-effective than a downstream compliance response.
How does a BIS / EAR risk assessment interact with the UK and EU export-control regimes?
A cross-border business rarely faces the EAR in isolation. The UK regime, administered by the Export Control Joint Unit (ECJU), and the EU dual-use framework, governed by the relevant Council regulation, each have their own control lists, licensing requirements, and end-use controls. The overlap and divergence between those regimes and the EAR shape the risk-assessment methodology for any multi-leg transaction.
Items controlled under the EAR are often, but not always, controlled under the UK Military List, the UK dual-use list, or the EU dual-use regulation. The control reasons, the licence exceptions, and the destination-based triggers differ. An item that qualifies for a licence exception under the EAR may nonetheless require an individual licence from ECJU for re-export from the United Kingdom. A compliance programme that maps only the first jurisdiction in the chain is incomplete.
There is a working principle that experienced practitioners apply consistently: where the controls of two regimes diverge, the stricter prohibition governs the transaction. This is not a legal rule in the sense of a single instrument stating it – it is a practical compliance standard that reflects the reality that both regimes apply simultaneously and that a transaction authorised by one but not the other is still a violation.
The UN Consolidated List adds a further layer. Security Council resolutions impose arms embargoes and broader trade restrictions that are implemented independently by each of the major regime jurisdictions. Those implementation obligations can make a transaction unlawful under one regime even where the bilateral export-control analysis gives a clear result. End-use controls under the EAR that target weapons of mass destruction programmes parallel, but do not replace, the UN-level prohibitions.
Australia's autonomous sanctions regime, administered by DFAT, Canada's SEMA-based controls, and the regimes of Singapore, the UAE, and Japan each have their own classification and end-user check requirements. For goods moving through multiple transshipment points, each leg must be assessed under the regime of the jurisdiction from which the export or re-export departs. A risk assessment that covers only the originating jurisdiction is incomplete for a multi-leg supply chain.
What are the most common risk flags in a BIS / EAR sanctions risk assessment?
Six patterns account for the majority of EAR violations that we see in cross-border supply chains. Identifying them early transforms a risk assessment from a screening exercise into an actionable compliance review.
First is the EAR99 stop error. Classification as EAR99 ends the CCL analysis but does not end the risk assessment. End-use checks must continue. A product sold into a programme that serves a nuclear end-use is a potential violation regardless of CCL status.
Second is single-tier ownership screening. BIS entity controls do not auto-propagate through ownership chains the way OFAC's 50 percent rule does. But a compliance programme that stops at first-tier entity screening may miss a controlled party operating as a second- or third-tier supplier or consignee. The check must go to the actual end-user.
Third is the licence exception assumption. Licence exceptions under the EAR are specific to ECCN control reasons and destination groups. Applying a licence exception that the control-reason matrix does not support is a classification error, not a compliance decision. Every exception must be confirmed against the item's actual ECCN and the specific destination.
Fourth is the transshipment blind spot. A consignment routed through an intermediary country may trigger re-export controls at the transshipment point that did not apply at the origin. Each leg of a multi-jurisdiction shipment must be assessed independently under the rules of the departing jurisdiction.
Fifth is technology transfer in the context of deemed exports. The EAR's deemed-export rule treats the disclosure of controlled technology to a foreign national within the United States as an export to that person's home country. Research collaborations, technical training, and cloud-based access to controlled software can all trigger this rule.
Sixth is the foreign-direct-product gap described above: a production process that incorporates US-controlled technology or equipment but has not been assessed for EAR jurisdiction over the resulting product.
Common misconceptions about BIS / EAR sanctions risk assessment
Several persistent misconceptions drive the risk-assessment failures we see most often.
The first is that OFAC compliance covers BIS exposure. It does not. OFAC and BIS are separate regulatory bodies with separate legal bases, separate lists, and separate enforcement programmes. Passing OFAC screening does not satisfy the EAR's classification, end-use, or entity-check requirements. The two assessments must be run independently and documented separately.
The second misconception is that BIS controls apply only to US companies. The EAR's extraterritorial provisions mean that non-US businesses re-exporting US-origin controlled items, or exporting items that incorporate US-controlled content above the applicable de minimis threshold, are subject to EAR jurisdiction. Nationality of the exporter does not determine applicability.
The third misconception is that a licence exception, once identified, remains available indefinitely. BIS can modify or withdraw licence exceptions, and their availability is condition-dependent. A licence exception used for a transaction last year may not be available for a structurally similar transaction this year if the destination, the end-user, or the regulatory position has changed. Verify the current position before relying on anything stated here.
A final, and costly, misconception is that a voluntary self-disclosure is always the right response to a discovered violation. A VSD (voluntary self-disclosure to a regulator) can significantly reduce civil-penalty exposure and demonstrates good faith. But the decision to disclose – and the timing, scope, and framing of the disclosure – requires legal assessment. An ill-prepared VSD can define the scope of an investigation more broadly than the underlying violation would have done. We advise clients to obtain legal analysis before submitting a VSD to BIS or to any other enforcement body.
The position above covers the standard pattern. Your specific facts – the item, the production process, the route, the end-users, the jurisdictions in the chain – change the analysis materially. An early review before transaction commitment is more valuable than a retrospective assessment after a compliance event.
If a filing has already been refused or a shipment held, early legal involvement can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential initial review.
Related practices
- Sanctions compliance audit and testing – structured review of screening logic and programme design
- Sanctions risk assessment under OFAC – the OFAC-centric methodology and where it diverges from BIS
- OFAC vs Canada sanctions risk assessment – comparative analysis of two regimes across the same transaction
Frequently asked questions: BIS / EAR sanctions risk assessment
Where do the regimes diverge on sanctions risk assessment?
The primary divergence is between OFAC's identity-first methodology and BIS's classification-first approach. OFAC asks who the counterparty is before anything else; BIS asks what the item is. A second divergence lies in extraterritoriality: BIS controls reach non-US-origin goods through the de minimis and foreign-direct-product rules in ways that OFAC's programme-based jurisdiction does not replicate. The EU and UK regimes add a control test that can capture entities below OFAC's 50 percent ownership threshold.
Which regime is stricter on sanctions risk assessment?
Strictness depends on the transaction. For financial transactions and broad country-programme prohibitions, OFAC often applies more extensive restrictions than BIS. For technology transfers, production-process exports, and re-exports through complex supply chains, BIS controls can bite where OFAC has no direct application. The practical standard is that where two applicable regimes diverge, the stricter prohibition governs the specific transaction – not a single regime's answer in isolation.
What should a cross-border business do about sanctions risk assessment?
A cross-border business should establish two parallel analytical tracks: an OFAC-based identity-and-ownership assessment and a BIS-based classification, end-use, and entity-check assessment. Where the transaction also involves UK or EU exports, ECJU and EU dual-use checks must run alongside those two. The methodology for each track differs, and a single unified screening tool cannot substitute for both. Businesses uncertain about their classification position should obtain a formal commodity-classification review before committing to a transaction structure.
About the author
Viktor Lindqvist advises exporters and trading houses on dual-use export controls, maritime and trade sanctions, and end-use compliance. Calder & Vance – International Sanctions & Export Control Counsel.
Published: 15 July 2026
About Calder & Vance
Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.
Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.