Calder & Vance International Sanctions & Compliance Counsel

Cross-Border Transactions & Diligence · BIS / EAR

BIS / EAR vs EU: Supply-chain sanctions mapping compared

A contract manufacturer in Southeast Asia builds components for both a US-headquartered original equipment manufacturer and a European buyer. The US relationship brings BIS authorisation requirements, end-user controls, and Entity List screening into every tier of the supply chain. The European relationship brings the EU dual-use regime, autonomous sanctions regulations, and a separate ownership-and-control test. Both regimes govern the same factory, the same goods, and often the same shipment – but they ask different questions, use different lists, and impose different consequences for failure.

Supply-chain sanctions mapping under the BIS / EAR and the EU dual-use and sanctions regimes diverge on four fundamental axes: the classification trigger, the listed-party test, the end-use and end-user controls, and the extraterritorial reach of each body of rules. Businesses that map only one regime against their supply chain carry residual exposure under the other. As of January 2026, both regimes are actively enforced and have each expanded their scope in the preceding twelve months.

This analysis works through the divergences criterion by criterion, identifies the points where the two regimes produce conflicting obligations, and sets out the practical mapping methodology a cross-border business should apply before it commits to a supply-chain structure.

What does supply-chain sanctions mapping actually require under each regime?

Supply-chain sanctions mapping is the structured process of identifying every node in a production or distribution chain – supplier, sub-supplier, freight intermediary, end customer, and beneficial owner – and testing each node against the applicable prohibitions, lists, and classification rules before goods, technology, or services move.

Under the BIS / EAR, the mapping obligation is embedded in the export-control regime rather than in a standalone sanctions programme. The EAR (Export Administration Regulations, administered by the Bureau of Industry and Security) require an exporter to classify each item against the Commerce Control List, identify the destination, identify the end user and the end use, and check that no authorisation is required – or that the applicable licence exception applies. Critically, the EAR follow the item, not just the first transaction. A US-origin item that passes through a compliant intermediary to a restricted end user is a potential violation even if the exporter received a clean order.

Under the EU regime, the mapping obligation splits across two bodies of rules. EU dual-use law requires classification against the EU Common Military List and the EU dual-use list, with licence requirements determined by the control list, the destination, the end user, and the end use. EU autonomous sanctions, by contrast, impose asset freezes, transaction prohibitions, and sectoral restrictions that do not depend on item classification at all. A counterparty can be a sanctions target for reasons entirely unrelated to the nature of the goods. In our practice, companies that have solid dual-use classification workflows frequently under-invest in the counterparty-screening side of EU mapping – and that is where enforcement actions arise.

How do the classification systems compare – and where do gaps appear?

The US Commerce Control List and the EU dual-use list are partially harmonised through the Wassenaar Arrangement, the Nuclear Suppliers Group, and other multilateral regimes, but alignment is not identity. Each list has been amended independently, and the US has introduced additional controls – including for advanced semiconductors, AI-related technologies, and certain biotechnology items – that have no direct EU equivalent, or where the EU equivalent differs in scope or in the applicable threshold.

The classification starting point under the EAR is the ECCN (Export Control Classification Number), a five-character code that determines which countries, end uses, and end users require a licence. An item that does not fall under a specific ECCN is classified EAR99 – the lowest-control category – but EAR99 items can still require authorisation for restricted end users, restricted end uses, or restricted destinations. Practitioners who treat EAR99 as meaning "no controls" make an error that BIS enforcement activity regularly exposes.

The EU classification logic begins with the same multilateral control lists but adds national controls that individual member states may apply, creating a patchwork within the EU itself. An item that a German exporter can ship freely to a given destination may require a licence from a Dutch exporter because of a national control applied by the Netherlands. Supply-chain mapping for a business with manufacturing or distribution in more than one EU member state must account for this divergence.

Where the two regimes diverge most sharply at the classification level is in emerging-technology controls. BIS has moved faster to impose controls on categories such as advanced logic chips, certain software tools, and specific production equipment. EU controls in the same areas exist but may use different item descriptions, different thresholds, or different licence exception equivalents. A supply chain mapped only to EU standards may not capture the BIS obligation triggered by the same item – particularly where the item or the underlying technology has US-origin characteristics that bring it within the EAR's reach regardless of where it is physically located.

How do the listed-party tests compare across the two regimes?

The listed-party analysis is the axis on which the two regimes diverge most clearly and most consequentially for supply-chain due diligence.

Under the EAR, BIS maintains the Entity List – a roster of parties for whom a licence is required for virtually all EAR-controlled items, often with a policy of denial. The Denied Persons List identifies individuals and entities whose export privileges have been revoked. The BIS Unverified List flags parties for whom BIS has been unable to complete end-use checks. Each list imposes a different consequence: Entity List placement generally means a licence requirement with a presumption of denial; Denied Persons List placement means US persons may not participate in the transaction at all; Unverified List placement is a red flag that should trigger enhanced due diligence and may affect the availability of licence exceptions.

The EU does not operate a direct equivalent of the Entity List. EU autonomous sanctions designate persons and entities under specific thematic regulations – by reference to a designated country's activities, a named individual's role, or a sectoral prohibition. These designations produce an asset freeze and a prohibition on making funds or economic resources available. There is no EU-wide general export-licence requirement triggered solely by counterparty status in the way the Entity List works. That gap is significant: a party listed by BIS on the Entity List may not be designated under EU sanctions, and an EU-designated party may not appear on the Entity List or the SDN List.

The ownership-and-control analysis also operates differently. Under OFAC's 50 percent rule (the rule treating entities owned 50 percent or more by blocked persons as themselves blocked), the test is ownership-percentage based and largely mechanical. BIS does not apply an identical aggregation rule, but the concept of ownership and control is relevant to determining whether a party on the Entity List controls the end user. The EU applies an ownership and control test – the UK and EU rule that a non-listed entity is caught through a listed person where that person owns or controls it – that turns on both formal ownership and the ability to exercise influence. In our experience, middle-tier supply-chain participants in joint-venture structures require the most careful analysis precisely because the EU and BIS tests point to different conclusions on the same facts.

The position above covers the standard case. Your counterparty, the goods, the tier of the supply chain, and the regimes in play all change the analysis. For a counterparty-screening review calibrated to your supply chain, contact Calder & Vance at info@caldervance.com.

What is the extraterritorial reach of each regime – and why does it matter for supply-chain mapping?

The extraterritorial reach of the BIS / EAR is the single most disruptive variable for non-US businesses mapping their supply chains.

The EAR applies to US-origin items, technology, and software wherever they are in the world. It also applies to foreign-produced items that incorporate more than a de minimis proportion of US-controlled content, or that are produced using US technology or production equipment in certain circumstances – the foreign direct product rule (a rule extending US export-control jurisdiction to foreign-made goods produced using certain US technology or equipment). The practical consequence is that a Taiwanese manufacturer producing a chip using US-origin semiconductor equipment may be producing an item subject to the EAR, even if no US person is involved in the transaction and the chip never touches US territory.

EU dual-use law is broadly territorial: it applies to exports from the EU, to brokering by EU-resident persons, and to transit through EU territory. It does not follow an item once it has left the EU in the way the EAR follows US-origin technology. This divergence creates a structural gap in supply-chain mapping. A non-EU, non-US intermediary sitting between a European supplier and an end customer may fall entirely outside EU export-control jurisdiction while sitting squarely within BIS / EAR jurisdiction because the item incorporates US-origin content.

For the cross-border business, this means that mapping the supply chain to EU standards alone does not discharge the BIS obligation. Where US-origin content is present at any tier, the EAR analysis must be conducted – regardless of the nationality of the exporter. We regularly advise European and Asian manufacturers that assumed their EU compliance programme covered their BIS exposure; in most cases, it does not.

The secondary-sanctions dimension adds a further layer. OFAC secondary-sanctions programmes – which are not BIS / EAR rules but interact with supply-chain decisions – can expose non-US financial institutions and trading companies to US sanctions risk for transactions with certain targets, even where no US-origin item is involved. The EU Blocking Regulation addresses this by prohibiting EU persons from complying with certain designated foreign sanctions measures. The result is a regulatory collision in which an EU company may face US penalties for proceeding and EU penalties for refusing. Supply-chain mapping for businesses in this position must surface the collision early, because the decision sequence – whether to exit, to seek a licence, or to challenge the application of the rules – has a time dimension.

Which end-use and end-user controls impose the greater burden on supply-chain mapping?

End-use and end-user controls represent the area of highest practical complexity in comparative supply-chain mapping, because both regimes impose them but use different triggers, different documentation, and different red-flag standards.

Under the EAR, prohibited end uses include certain nuclear, chemical, biological, and conventional-weapons applications and certain items destined for the military of certain countries. The end-user check requires the exporter to assess not only the immediate buyer's identity but the likely end use and the identity of the end user after all anticipated re-exports. BIS guidance identifies a series of red flags – unusual payment terms, requests to omit standard information, shipping routes inconsistent with the stated destination – that should trigger enhanced due diligence or lead the exporter to decline the order. A licence exception that would otherwise authorise the transaction is unavailable if there is knowledge of a prohibited end use or a prohibited end user.

The EU approach to end-use controls operates partly through the dual-use licence regime and partly through a catch-all mechanism that can require a licence even for uncontrolled items where the exporter has been informed, or has reasonable grounds to believe, that the items will be used in connection with weapons of mass destruction or in a way that threatens international peace and security. The EU catch-all is broader in concept – it can apply to items not on the control list – but it is harder to operationalise because its trigger is knowledge-and-grounds-based rather than list-based.

In comparative terms, BIS / EAR end-user controls are more granular and more prescriptive: specific lists, specific red-flag indicators, specific licence requirements attached to specific country and end-user combinations. EU end-use controls have a broader catch-all concept but fewer pre-specified triggers. For a business mapping its supply chain, this means that BIS-side due diligence typically requires more structured document collection and red-flag screening protocols, while EU-side due diligence requires a more judgment-based assessment of end-use risk for items that fall outside the control list.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Reach our team at info@caldervance.com for a confidential assessment.

What are the common mapping failures – and how should they be corrected?

Supply-chain mapping failures cluster around five recurring patterns. Each is correctable once identified, but each also carries a consequence that is difficult to reverse.

The first failure is single-regime mapping. A business screens its supply chain against one regime's lists and classification rules, assumes the exercise is complete, and misses the exposure under the other regime. This is most common where the compliance function reports to a legal team with strong US-law or strong EU-law background but not both.

The second failure is static mapping. A supply-chain map produced at the start of a supplier relationship reflects the counterparty's status at a single point in time. Designations are added frequently and, in some programmes, with immediate effect. A counterparty that was clean at onboarding may be designated six months later. Without a programme of continuous screening against live lists – covering not only the SDN List and the EU Consolidated List but also the BIS Entity List and Unverified List – the map becomes stale and the compliance posture deteriorates without the business knowing it.

The third failure is ownership-chain truncation. Businesses that screen the direct counterparty but not the beneficial-owner chain miss the ownership-and-control analysis. Under both the EU test and the US 50 percent rule, a clean-looking counterparty can be captured through its owners. The mapping exercise must trace ownership to natural persons or to publicly listed entities that can be assessed as outside the relevant thresholds.

The fourth failure is technology-origin blindness. Manufacturers that use US-origin equipment, software, or components in their production process without considering the foreign direct product rule produce items that may be subject to the EAR regardless of the manufacturer's nationality. This is particularly acute for businesses producing electronics, advanced materials, or software tools, where US-origin inputs are pervasive.

The fifth failure is documentation failure. Even where the substantive analysis is correct, an inability to demonstrate – in an audit, an enforcement proceeding, or a due-diligence review – that the analysis was conducted, documented, and reviewed renders the compliance exercise effectively invisible. BIS and EU enforcement authorities both require contemporaneous records. Record-keeping periods differ across regimes; verify the applicable period before structuring your document-retention programme.

A common myth in cross-border supply-chain work is that a single screening pass at the start of a supplier relationship is sufficient. It is not. The obligation is ongoing, the lists change, and the classification rules are amended. A point-in-time exercise addresses neither the dynamic nature of the lists nor the re-export and re-transfer obligations that continue to apply as goods move through the chain.

How should a cross-border business structure its supply-chain mapping methodology?

A sound supply-chain mapping methodology for a business operating across both the BIS / EAR and the EU regime requires four components, applied in sequence.

The first component is item classification across both control lists. The same item must be classified under the Commerce Control List and under the EU dual-use list independently. Where classifications diverge, the stricter control governs for the relevant leg of the transaction. Emerging-technology items, in particular, must be re-classified whenever either list is updated.

The second component is counterparty and ownership-chain screening. Every tier of the supply chain – direct suppliers, sub-suppliers, freight intermediaries, and end customers – must be screened against the applicable lists: the SDN List, the EU Consolidated List, the BIS Entity List, the BIS Denied Persons List, and the BIS Unverified List as a minimum. Screening must extend to beneficial owners, applying the 50 percent rule for US purposes and the broader ownership-and-control test for EU purposes. This is not a one-time exercise; it must be calibrated to the frequency of list updates and the velocity of the supply chain.

The third component is end-use and end-user assessment. For each controlled item moving to a new tier, the exporter or transferor must assess the end use and the end user. BIS-side assessment follows the red-flag framework. EU-side assessment applies the catch-all test for items outside the control list and the standard licence-exception analysis for listed items. Documentation of the assessment – including the basis for any conclusion that no licence is required – must be retained for the applicable period.

The fourth component is extraterritoriality analysis. Before finalising any supply-chain structure, the business must determine whether US-origin content, US technology, or US production equipment in the chain engages the foreign direct product rule or the de minimis provisions of the EAR. This analysis often requires input from BIS counsel specifically, because it turns on technical parameters that are not always visible from commercial documentation alone. We have acted for Asian and European businesses that discovered BIS jurisdiction over their supply chains only when a US customer or investor raised the question during diligence – at which point restructuring options are more limited than at the design stage.

Situation A: the supply chain involves no US-origin content and no EU-controlled items. The BIS obligation may be limited, but the OFAC and EU-sanctions counterparty-screening obligations remain in full. Route: conduct list screening under all applicable regimes; apply the ownership-and-control test; document the absence of US-origin content.

Situation B: the supply chain involves US-origin technology or equipment at any tier. The EAR analysis is mandatory regardless of the exporter's nationality. Route: classify the item; assess the foreign direct product rule; identify the applicable ECCN or the EAR99 status; conduct end-user screening; determine licence requirements; document the analysis. The EU analysis must also be conducted in parallel for EU-regulated legs of the transaction.

Situation C: a counterparty is flagged in screening as potentially connected to a designated person. Do not proceed without counsel review. Route: suspend the transaction; conduct enhanced due diligence on the ownership chain under both the 50 percent rule and the EU control test; assess whether a specific licence is required or available; consider voluntary disclosure obligations if a potential violation has already occurred.

Related practices

Frequently asked questions

Where do the regimes diverge on supply-chain sanctions mapping?
The BIS / EAR and EU regimes diverge on four axes: item classification (partially harmonised but amended independently), listed-party tests (BIS uses the Entity List; the EU uses thematic designation regulations with no direct equivalent), extraterritorial reach (the EAR follows US-origin content globally; EU controls are primarily territorial), and end-use controls (BIS uses specific red-flag indicators; the EU uses a broader catch-all mechanism). These divergences mean that compliance with one regime does not establish compliance with the other. Both must be mapped independently for any cross-border supply chain.
Which regime is stricter on supply-chain sanctions mapping?
Neither regime is uniformly stricter. The BIS / EAR is more prescriptive on classification, more granular on end-user controls, and more far-reaching on extraterritorial jurisdiction through the foreign direct product rule. EU autonomous sanctions can be broader in counterparty designation coverage, particularly where the EU designates parties not listed by BIS. The practical rule is that where both regimes apply, the stricter prohibition governs each aspect of the transaction. A supply-chain mapping methodology should identify the controlling regime for each element rather than defaulting to one body of rules across the board.
What should a cross-border business do about supply-chain sanctions mapping?
A cross-border business should conduct parallel classification under both control lists, screen all supply-chain tiers against the applicable lists under both regimes on a continuous basis, conduct an end-use and end-user assessment calibrated to the applicable standards, and perform an extraterritoriality analysis to determine whether US-origin content engages EAR jurisdiction beyond the first transaction. Documentation of each step must be retained for the applicable record-keeping period. Where a potential conflict between regimes arises – or where a counterparty is flagged in screening – counsel with cross-regime expertise should be engaged before the transaction proceeds.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.