A trading house exports specialised industrial components through a multi-tier distribution network. Tier-one buyers pass screening cleanly. By tier three, however, a critical intermediary sources from a supplier whose parent appears on the Entity List. The shipment has already moved. This scenario is not hypothetical – it is the pattern that most enforcement inquiries follow.
Supply-chain sanctions mapping under the US Export Administration Regulations (the EAR) requires exporters to trace the flow of controlled goods, software, and technology through every tier of a distribution chain and confirm that no participant is a denied party, an Entity List entrant, or an end user whose declared purpose is inconsistent with the licence exception claimed. The EU's dual-use regime imposes a functionally similar obligation, but the triggering thresholds, the ownership-and-control tests applied to counterparties, and the consequences of a missed link differ materially between the two regimes. As of January 2026, both regimes are actively enforced, and supply-chain exposure is a leading source of enforcement referrals in cross-border trade.
This analysis maps the BIS / EAR framework against the EU regime across six key dimensions: legal authority, scope of goods covered, the counterparty-screening test, end-use and end-user controls, diversion risk flags, and the multi-regime interaction that catches most businesses off guard.
What is the legal authority behind supply-chain screening in each regime?
Under the EAR, the Bureau of Industry and Security (BIS) derives its authority from the Export Control Reform Act and the administrative regulations issued under it. That authority extends to all exports, re-exports, and in-country transfers of items subject to the EAR – a category that includes commercially available goods with even modest strategic relevance, not only items purpose-built for defence.
The EU dual-use regime rests on a Council Regulation that has been substantially revised and that applies directly across all EU Member States. The regulation assigns licensing authority to each Member State's competent authority, but the list of controlled items is harmonised at EU level. That creates a paradox: the same item faces a single EU control-list entry, yet the licensing practice, enforcement posture, and due-diligence expectations can vary between Member States.
One practical implication stands out. An exporter established in an EU Member State re-exporting US-origin goods remains subject to BIS jurisdiction through the EAR's re-export rules. That exporter therefore carries two simultaneous obligations: compliance with the EU regulation and compliance with BIS. When the two regimes give different answers – for example, because the EU does not list an item at the same control level as BIS – the stricter prohibition governs the transaction. This is the first source of undetected exposure in EU-based supply chains that handle US-origin goods.
How does each regime define the scope of controlled goods?
The EAR classifies items by reference to the Commerce Control List (CCL), using an Export Control Classification Number (ECCN – a five-character alphanumeric that specifies the item category and its reason for control). Items that do not appear on the CCL are designated EAR99. EAR99 status is not a clearance; it simply means the item is not on the list. An EAR99 item exported to an Entity List party still requires a licence.
The EU control list mirrors the structure of the Wassenaar Arrangement, the Australia Group, the Missile Technology Control Regime, and the Nuclear Suppliers Group. Classification categories broadly track the CCL, but equivalence is not exact. Items are sometimes classified at a higher level under BIS, sometimes under the EU regime, and occasionally differently on both lists. Businesses that assume CCL classification automatically resolves EU classification are frequently wrong.
The EU regime also contains a "catch-all" provision: even non-listed items require a licence where the exporter knows or has grounds to suspect that the goods are intended for weapons-of-mass-destruction programmes or for military end users in countries subject to EU arms embargoes. BIS maintains an analogous catch-all through its end-use and end-user controls. Both catch-alls are exercised through regulatory guidance rather than a bright-line list – which means supply-chain mapping must go beyond list-checking to address plausible end-use scenarios. Have you reviewed the plausible downstream uses of every item in your portfolio, not only its classification?
Where do counterparty-screening tests diverge most sharply?
BIS maintains the Entity List, the Unverified List, and the Denied Persons List as the principal screening databases, alongside OFAC's SDN List and the BIS Military End User List. The Entity List imposes a licence requirement for all exports, re-exports, and transfers of EAR-controlled items to a listed party; no licence exception is available unless BIS specifies one. The Denied Persons List goes further: listed persons are prohibited from participating in any transaction subject to the EAR, including as freight forwarders, carriers, or financial intermediaries.
The EU regime's counterparty controls work differently. The EU does not publish a single equivalent to the Entity List. Instead, financial-sanctions lists issued under the relevant Council regulations designate parties whose assets are frozen and with whom transactions are prohibited. Separately, the EU has introduced targeted export-control measures applicable to specific country regimes that impose restrictions on sales to categories of end users in those jurisdictions. The gap between these two mechanisms – financial sanctions on one hand, export controls on the other – creates a mapping challenge that EU-based compliance teams often handle as two separate workflows.
In our cross-border practice, this gap is the most common structural defect we find in EU-exporter compliance programmes. A counterparty may clear the financial-sanctions screen and still be a military-affiliated entity in a jurisdiction where the EU regulation restricts sales without a licence. Integrating the two screens is not optional; it is the minimum standard that competent-authority inspections now expect.
The ownership-and-control question adds another layer. OFAC's 50 percent rule (the rule that treats entities owned 50 percent or more by blocked persons as themselves blocked) is mechanical. BIS does not replicate this rule identically for the Entity List, but affiliated entities of listed persons – subsidiaries, front companies, agents acting on behalf of listed parties – can be caught through the "knowledge" standard in the EAR: a party that knows or has reason to know that an item will be used by a denied person is prohibited from proceeding. The EU equivalent relies on a similar knowledge test, with competent authorities looking to the surrounding circumstances rather than applying a fixed ownership percentage.
What are the end-use and end-user controls that supply-chain mapping must address?
End-use controls under the EAR prohibit exports, re-exports, or transfers of controlled items to parties engaged in certain programmes regardless of whether those parties appear on a list. The knowledge standard – including "red flag" indicators that require inquiry – means that a failure to investigate a visible warning sign can be treated as constructive knowledge of a prohibited end use.
BIS has published guidance on red flags that exporters are expected to monitor. These include: a buyer who is unwilling to state the end use of the goods; a shipping route inconsistent with the stated destination; payment arrangements that obscure the beneficial recipient; and a buyer whose business profile does not match the technical sophistication of the ordered goods. Supply-chain mapping must document how each of these flags was assessed at each tier of the distribution chain.
The EU regime applies a substantively similar standard through its catch-all mechanism and through the due-diligence expectations set out in Commission guidance. However, the EU's published red-flag indicators are not structured in precisely the same way as BIS guidance, which means a compliance team that has adopted only BIS-formatted checklists may overlook a flag that EU guidance would treat as decisive.
End-user statements and delivery-verification certificates are required under the EAR for specific categories of controlled items exported under licence. The EU regime imposes analogous documentation requirements, but the form and content of required certificates differ. A business that generates end-user documentation to BIS standards and then treats the same document as satisfying EU requirements is making an assumption that competent authorities do not share.
In a recent matter, a European technology distributor had maintained end-user documentation for five years – the standard record-keeping period under the applicable regime – but had not reviewed whether the documentation met the format requirements under EU rules as well as BIS licence conditions. During a competent-authority inspection, a material portion of its certificates was found to be non-compliant with EU standards even though BIS requirements had been satisfied. Early advice on documentation architecture would have prevented that outcome.
What diversion risk flags does effective supply-chain mapping need to catch?
Diversion – the re-export or transfer of controlled items to an end user other than the declared recipient – is a central concern for both BIS and EU enforcement. Supply-chain mapping is the mechanism through which diversion risk is assessed and mitigated before a transaction is completed.
The most commonly missed flags in our experience fall into five categories. First, routing anomalies: shipments transiting jurisdictions with no apparent logistical reason for the detour, particularly where the transit jurisdiction is subject to targeted export restrictions or where local re-export norms are weak. Second, intermediary opacity: distributors who refuse to identify their downstream customers or who process high volumes of controlled goods without a credible end-user base. Third, order-pattern anomalies: repeat orders of quantities that exceed plausible operational needs for the stated use, or orders placed in a pattern consistent with stockpiling. Fourth, payment indirection: payments routed through third-party accounts or jurisdictions unrelated to the declared transaction. Fifth, classification shopping: counterparties who request lower ECCN classifications than the item's specifications justify, or who challenge a supplier's classification without a credible technical basis.
Under both the EAR and the EU regime, the discovery of a red flag does not automatically prohibit the transaction. It triggers an obligation to investigate and to document the outcome of that investigation. A business that proceeds without documenting its inquiry, even if the transaction was ultimately permissible, faces a significantly weaker position if enforcement attention follows.
What separates a defensible supply-chain programme from one that will fail an enforcement review? Documentation, paced systematically through the supply chain rather than applied only at the point of export.
How do the US and EU regimes interact – and why does the interaction matter most?
The extraterritorial reach of the EAR is the single most important cross-regime consideration for EU-based businesses. The EAR applies to the re-export of US-origin items from any country to any other country. It also applies to foreign-produced items that incorporate more than a de minimis threshold of US-controlled content (the de minimis rule) and to items produced abroad using US-origin technology or software under certain conditions (the foreign-direct-product rules).
The foreign-direct-product rules have been expanded in recent years to cover a broader range of semiconductor-related goods and to capture items produced by foreign foundries using US equipment or design software. An EU manufacturer that sources inputs from a US supplier – or that uses US-origin manufacturing equipment – may be producing items subject to BIS jurisdiction even though the finished product never touches US soil and is marketed entirely within the EU or to third countries. If that manufacturer then exports to an Entity List party, it has violated the EAR regardless of its EU authorisation.
The interaction operates in the other direction as well. The EU has adopted targeted measures – in the form of Council regulations addressing specific country-regime situations – that restrict exports of certain goods by EU operators, including subsidiaries of non-EU parent companies operating in the EU. A US parent whose EU subsidiary holds inventory of controlled items cannot authorise that subsidiary to proceed with a transaction merely because the transaction is permissible under OFAC and BIS rules; the EU regime may impose a separate prohibition.
Secondary sanctions risk adds a further dimension. Although secondary sanctions are primarily an OFAC mechanism rather than a BIS tool, the practical effect for EU businesses is that certain transactions involving third-country intermediaries may attract OFAC secondary-sanctions designation risk even where the goods involved are not subject to the EAR. Supply-chain mapping that addresses BIS and EU dual-use controls without considering the OFAC dimension is therefore incomplete for any business that maintains US-dollar relationships, correspondent banking lines, or US investors.
We regularly advise EU-based trading groups that have constructed supply-chain compliance programmes siloed by regime. The BIS team checks the Entity List; the EU compliance team checks the financial-sanctions lists; and OFAC secondary-sanctions risk is treated as a banking problem rather than a supply-chain problem. None of those teams communicates systematically with the others. That architecture produces gaps that enforcement bodies have learned to look for.
What a business should do: a practical decision sequence for cross-regime supply-chain mapping
The starting point for any cross-regime supply-chain mapping exercise is item classification – not counterparty screening. Classification determines which regime applies, which licence requirements arise, and which exceptions or authorisations are available. A mis-classified item invalidates every subsequent analysis step. Classification must cover both the CCL and the EU control list independently; equivalence cannot be assumed.
Once classification is established, the mapping exercise follows a tiered sequence.
Tier one is counterparty screening: all direct transaction parties screened against the Entity List, Denied Persons List, BIS Military End User List, OFAC SDN List, EU consolidated financial-sanctions list, and any regime-specific restricted-party measures relevant to the destination. Screening must capture legal entities and the natural persons who own or control them, not only the named contracting party.
Tier two is end-use assessment: each counterparty's declared end use is evaluated against known red flags and against the control reason of the relevant ECCN or EU list entry. Where the end use is plausible but involves a sensitive sector – telecommunications infrastructure, advanced manufacturing, academic research with dual-use potential – enhanced due diligence is applied and documented.
Tier three is supply-chain tracing: the first two tiers are repeated for material second- and third-tier suppliers and distributors identified through contractual disclosure, commercial-database research, or on-site verification. The depth of tracing is calibrated to the sensitivity of the item and the risk profile of the destination.
Tier four is documentation and record-keeping: end-user statements, screening records, due-diligence memoranda, and any internal escalation decisions are retained for the applicable record-keeping period. Under both the EAR and the EU regime, a documented decision to proceed – even where that decision involves accepting a residual risk after inquiry – is significantly more defensible than an undocumented transaction.
Where the analysis produces an uncertain result – a counterparty relationship that clears the screen but raises concern, or an end-use scenario that is plausible but not confirmed – early involvement of sanctions counsel allows the business to structure its inquiry, document its analysis, and, where necessary, pursue a licensing route or an advisory opinion before the transaction completes.
Common errors and the myth that list-checking is enough
The most persistent mistake in supply-chain sanctions mapping is the belief that a clean screening result ends the analysis. It does not. List-based screening is a necessary starting condition; it is not a sufficient compliance step under either the EAR or the EU dual-use regime.
This myth is understandable. Screening tools are commercially available, automated, and fast. They produce a result that looks definitive. But both BIS and EU enforcement guidance make clear that an exporter who proceeds despite red flags is not protected by a clean screen. The knowledge standard – which covers what a reasonable person would have inquired into – is broader than the list-matching standard.
A second common error is treating US-origin-content tracing as a one-time exercise. The foreign-direct-product rules apply not only at the point of initial incorporation of US technology but throughout the product lifecycle. A component that was non-subject to the EAR when first sourced may become subject following a change in US regulatory coverage. Supply-chain mapping is not a project; it is a recurring review obligation.
A third error is failing to maintain documentation of negative screening results. Where a compliance team screens a counterparty, finds nothing, and moves on without retaining a record, the business cannot demonstrate that the screen was performed if enforcement attention arises later. Both BIS and EU competent authorities expect to see a documented screening record, not merely a signed end-user statement.
We have acted for businesses at the post-detection stage where the underlying transaction was likely permissible, but the absence of documentation made a voluntary self-disclosure and a remediation programme the only practicable path. The cost of that path, measured in management time and professional fees, substantially exceeded what a structured supply-chain mapping programme would have cost at the outset.
Related practices
- Correspondent banking and de-risking – OFAC exposure assessment and advisory support for financial institutions managing cross-border correspondent relationships.
- BIS / EAR vs EU supply-chain mapping: extended analysis – further detail on classification, foreign-direct-product rules, and multi-tier distribution mapping.
- OFAC vs BIS / EAR: supply-chain mapping compared – how OFAC financial-sanctions obligations interact with BIS export-control requirements in cross-border supply chains.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review of your supply-chain exposure.