A technology exporter ships components from the United States to a European distributor, who re-exports to a third-country buyer. Both legs of the transaction carry legal risk – but the rules governing each leg differ substantially. Under the Bureau of Industry and Security's Export Administration Regulations (EAR – the US export-control regime administered by BIS), the focus falls on the item, its classification, and every party in the transaction chain. Under EU dual-use export-control rules, the assessment turns on similar but divergently structured tests, often producing different conclusions on the same set of facts. For compliance counsel and in-house teams, understanding where these regimes align and where they part company is not an academic exercise. It decides whether a transaction proceeds, requires a licence, or must be stopped entirely.
Trade-transaction screening under BIS / EAR requires a business to assess the item's export classification, the end-user, the end-use, and every intermediary in the chain against US-controlled lists including the Entity List and Denied Persons List. The EU applies a parallel but distinct structure, combining product classification under EU dual-use rules with sanctions-list screening under Council regulations. As of January 2026, the two regimes share a common policy goal – preventing controlled items from reaching restricted destinations and end-users – but they apply different classification systems, different list architectures, and different extraterritorial reach, meaning a transaction that is lawful under one regime may still require a licence, or be outright prohibited, under the other.
This analysis sets out how trade-transaction screening operates under BIS / EAR, where the EU diverges, the practical implications for cross-border transactions, and when to involve sanctions and export-control counsel.
How does BIS / EAR structure trade-transaction screening?
Under the EAR, every export, re-export, or in-country transfer of a US-origin item or a foreign-made item containing US-controlled technology above a defined threshold must be assessed against a layered screening framework before the transaction proceeds. The foundational tool is the Export Control Classification Number (ECCN – the alphanumeric code on the Commerce Control List that describes what controls apply to an item and why). Items without an ECCN fall under the catch-all designation EAR99, which carries fewer restrictions but does not remove screening obligations entirely.
BIS maintains several restricted-party lists that exporters must consult. The most consequential for trade-transaction screening is the Entity List – a register of foreign entities subject to licence requirements that BIS has determined pose an unacceptable risk of diversion. The Denied Persons List covers parties whose export privileges have been revoked. The Unverified List signals parties where BIS has been unable to verify end-use. A transaction with any listed party requires careful analysis, and many will require a specific licence or will face a policy of denial.
Beyond list screening, the EAR requires exporters to assess end-use and end-user. The catch-all controls mean that even an EAR99 item cannot be exported if the exporter knows or has reason to know it will be used for a prohibited end-use – weapons of mass destruction programmes are the paradigm case – or re-exported without authorisation. In our cross-border practice, we regularly advise exporters who under-invest in end-use screening relative to list screening, which leaves a material gap.
The de minimis rule (the threshold above which foreign-produced items incorporating US-controlled content require US re-export authorisation) extends BIS jurisdiction extraterritorially. This is the lever through which BIS reaches transactions that are entirely outside the United States. A European distributor re-exporting goods that contain US-origin technology above the applicable threshold must comply with the EAR on that re-export, regardless of whether EU rules would themselves require a licence.
Where does the EU dual-use regime apply a different test?
The EU's export-control regime for dual-use items operates through a Council Regulation that lists controlled items in a structure broadly parallel to, but not identical with, the US Commerce Control List. EU classification is based on agreed multilateral control lists – the Wassenaar Arrangement, the Australia Group, the Missile Technology Control Regime, and the Nuclear Suppliers Group – as is the US CCL, but the two jurisdictions implement those agreed parameters with different technical parameters and different catch-all provisions.
Where BIS administers a single federal regime applied uniformly across the United States, the EU dual-use regime is administered by the competent authority of each member state. Licence applications are filed nationally. Enforcement is national. This creates practical variation across the EU: the risk appetite, processing times, and interpretive practice of a licensing authority in one member state may differ meaningfully from that of another. For a cross-border business structuring a multi-leg transaction, the identity of the exporting member state is not irrelevant.
The EU regime also imposes a general catch-all obligation: exporters must obtain a licence when they know or have been informed by their member state's authority that items not on the control list are or may be intended for certain prohibited end-uses. This catch-all is structurally similar to the BIS provision but applied under national authority and with national enforcement. In our experience, businesses familiar with the BIS catch-all often assume the EU catch-all operates identically – it does not, and the differences in trigger and notification mechanism matter.
The EU regime includes general export authorisations that permit lower-risk exports to specified destinations without a case-by-case licence. BIS uses a different mechanism – licence exceptions, which are defined in the EAR and self-assessed by the exporter. Both mechanisms reduce licensing burden for routine transactions, but the scope of each is defined differently, and an exception available under BIS may not have an EU equivalent, and vice versa.
How do the two regimes screen restricted parties differently?
BIS restricted-party screening is a discrete, formally maintained process. The Entity List, Denied Persons List, and Unverified List are published by BIS and updated regularly. US sanctions list screening – principally the OFAC SDN List (OFAC's register of Specially Designated Nationals and blocked persons) – runs in parallel and is administered by a different authority. A well-designed US compliance programme runs both checks simultaneously, because an entity may appear on one list but not the other, and the legal consequences differ.
The EU does not maintain a single equivalent of the BIS Entity List as an export-control instrument. Restricted-party screening under EU rules combines: (a) EU sanctions lists under the relevant Council regulations, which operate as asset-freeze and dealing prohibitions; and (b) national-authority determinations under the catch-all mechanism, which can restrict exports to specific parties on a case-by-case basis. For a cross-border business, this means the EU list architecture and the BIS list architecture are not interchangeable. Screening against one does not satisfy the other.
Aggregation and ownership rules add a further layer. OFAC's 50 percent rule (treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked) applies in the OFAC sanctions context, not in the BIS export-control context. The EU applies an ownership and control test (the test for whether a non-listed entity is subject to restrictions through a listed person's ownership or control) under its sanctions regulations. Neither the BIS Entity List nor the EU dual-use control list uses the same ownership-aggregation logic as the respective sanctions list. A compliance team must therefore apply the correct ownership test to the correct instrument. Running the wrong test against the wrong list is a persistent source of error in cross-border transaction screening.
What does this mean in practice? A counterparty that passes BIS Entity List screening may still be subject to OFAC sanctions. An entity that clears EU sanctions screening may still be a restricted party under a member state's catch-all determination. The two-regime structure – export controls and financial sanctions – must run in parallel, not in sequence, and neither replaces the other.
What is the extraterritorial reach of each regime, and why does it matter?
The extraterritorial reach of BIS / EAR is one of the regime's most commercially significant features. The de minimis rule and the foreign direct product rule (the rule that subjects certain foreign-made products that are the direct product of US-controlled technology or software to EAR requirements) mean that a transaction with no US party and no US-origin item may still require BIS authorisation if the product was made using US technology above the applicable threshold. As of January 2026, BIS has expanded the foreign direct product rule to cover a wider range of semiconductor and advanced technology transactions.
The EU dual-use regime does not contain a comparable extraterritorial mechanism. An EU-origin item exported by a non-EU party from outside the EU does not generally engage EU dual-use controls. A US-origin item re-exported by a non-EU party from outside the United States does engage BIS controls. This asymmetry is consequential. A European company re-exporting US-origin goods from a third country needs to satisfy BIS requirements even if EU law does not apply to that leg of the transaction. We regularly advise European trading houses who discover this obligation mid-transaction.
The EU has strengthened its "no re-export to Russia" provisions and introduced export restrictions that apply to EU operators regardless of the origin of the goods – this is a different kind of extraterritorial-adjacent reach, achieved through transaction-party jurisdiction rather than product jurisdiction. The practical effect is that an EU-incorporated entity must comply with relevant EU trade restrictions on its transactions even when operating from a non-EU location. Both regimes therefore assert a form of reach beyond their territorial borders, but the mechanism differs.
For a cross-border business, the critical question is: which regime's rules apply to this transaction, and do both apply simultaneously? The answer is often that both apply, with different trigger conditions and different licensing requirements. Where both apply and their requirements conflict, the stricter prohibition governs. There is no carve-out for the fact that one regime permits what the other prohibits.
The position above covers the standard analytical case. Your facts – the item's classification under each regime, the parties in the chain, the destination, and the intended end-use – will determine which controls bite and whether a licence is needed. For a transaction-specific assessment, contact Calder & Vance at info@caldervance.com.
What are the common risk flags in cross-border transaction screening?
In our experience advising cross-border businesses on trade-transaction screening, a consistent set of risk flags recurs across sectors and regimes. Identifying them early shapes whether a transaction can proceed, and under what conditions.
Re-export through third-country intermediaries. The most frequent gap we see is a failure to screen the full transaction chain. A company that screens its direct counterparty but not the final consignee, or does not ask where the goods will ultimately go, leaves itself exposed. Under both BIS / EAR and EU dual-use rules, knowledge of – or reason to know – a prohibited end-use or re-export route engages the catch-all controls. The intermediary's identity and jurisdiction are not neutral data points.
Dual-use classification gaps. Businesses that classify items for EU export purposes and assume the same classification applies under the EAR, or vice versa, make a structural error. The control lists are aligned at the multilateral level but differ in implementation. An item that does not appear on the EU list may appear on the CCL, and an ECCN that triggers BIS licence requirements may map to an EU classification that permits a general authorisation. Classification must be conducted separately under each applicable regime.
Screening against the wrong lists. As noted above, EU sanctions lists, EU dual-use controls, BIS restricted-party lists, and OFAC sanctions lists are four distinct legal instruments administered by different authorities. Screening against one does not satisfy the others. A compliance system that routes a single screening check through a consolidated database must be tested to confirm it captures all four layers and that the database itself is current.
Outdated screening data. Both regimes update their restricted-party lists and designations continuously and without fixed notice periods. A transaction screened at the point of initial enquiry must be re-screened at the point of shipment. In the period between contract signing and goods crossing the border, a counterparty may have been added to a restricted list. The interval matters.
Voluntary self-disclosure obligations. Under BIS / EAR, a VSD (voluntary self-disclosure to BIS) is a factor in enforcement penalty calculations. Under EU rules, reporting obligations and voluntary disclosure mechanisms differ by member state. If a transaction has already proceeded and a potential violation is identified, acting quickly to assess VSD options – under whichever regime applies – can affect the penalty outcome materially. If a transaction has been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com.
How should a compliance programme handle BIS / EAR and EU screening in parallel?
A compliance programme designed for one regime and stretched to cover another is, in our experience, the architecture that produces enforcement exposure. The correct approach builds the two screening layers deliberately, with separate classification workflows, separate list-screening processes, and a clear policy on which authority's requirements govern each leg of each transaction.
For classification, the programme should maintain product classification records under both the CCL (with the applicable ECCN) and the EU dual-use list. Where the two classifications differ in their control triggers – for example, where an item requires a BIS licence to one destination but qualifies for an EU general authorisation for the same destination – the compliance file should document both analyses. Do not assume they produce the same answer.
For list screening, the programme should consult, at minimum: the OFAC SDN List; the BIS Entity List, Denied Persons List, and Unverified List; and the relevant EU sanctions lists under the applicable Council regulations. Where the transaction involves parties in other jurisdictions – for example, Singapore, the UAE, or Japan – the relevant national lists should be added to the screening run. Screening tools that aggregate multiple lists must be configured to cover all relevant sources and tested against known data to confirm coverage.
For end-use and end-user screening, the programme should obtain and document end-use certificates or equivalent representations for high-risk transactions. Under BIS / EAR, certain transactions to certain destinations or end-users require a specific end-user statement. Under EU dual-use rules, equivalent documentation requirements apply under national licensing procedures. The documentation standard under each regime is the benchmark; internal comfort is not a substitute.
Record-keeping is a compliance obligation under both regimes. The EAR requires exporters to keep records relating to export transactions for a defined period. EU member-state rules impose parallel obligations, though the specifics vary. A compliance programme must confirm the applicable retention period under each regime and apply the longer standard where both apply simultaneously.
Is your current screening programme tested against both BIS / EAR and EU dual-use requirements separately? If the answer is unclear, that itself is a risk flag.
A myth worth correcting: EU and US dual-use controls are equivalent
The prevailing assumption among businesses that export globally is that BIS / EAR and EU dual-use controls are essentially equivalent because both implement the same multilateral control lists. The assumption is incorrect, and acting on it creates compliance exposure.
The two regimes share a common multilateral foundation, but they diverge in: the scope and definition of items on their respective control lists; the extraterritorial application of their rules; the administration of licensing (federal for the US, member-state-level for the EU); the scope and availability of general licences and exceptions; the catch-all trigger conditions; and the enforcement posture of the administering authorities. A transaction that qualifies for a BIS licence exception does not automatically qualify for an EU general authorisation. An item classified as EAR99 may still require an EU licence for certain destinations.
We regularly advise businesses that discover this asymmetry when a shipment is detained or a licence application is refused. The earlier in the transaction design phase the two regimes are assessed in parallel, the more options are available. By the time goods are at the port, the options narrow considerably.
Related practices
- Correspondent banking and de-risking – OFAC considerations for financial institutions managing correspondent relationships
- Trade-transaction screening: OFAC vs BIS / EAR – how the two US regimes interact on a single transaction
- Trade-transaction screening: OFAC vs BIS / EAR (extended analysis) – deeper treatment of licence exceptions and list interactions