An exporter ships a batch of industrial components. The products were classified years ago. The end-use certificates are on file. The compliance team believes the programme is sound. Then a BIS audit inquiry arrives – and the review that follows reveals that the classification was wrong, the end-user screening had a logic gap, and three shipments went to a party now on the Entity List. The question is no longer whether there is a violation. It is how serious it is, and whether a voluntary self-disclosure can contain the damage.
A compliance audit and testing programme under the Export Administration Regulations (EAR – the principal US export-control rulebook administered by the Bureau of Industry and Security, BIS) is the structured process by which an organisation tests whether its export controls actually work, not merely whether policies exist on paper. As of mid-2026, BIS enforcement posture has sharpened considerably; a well-documented audit and testing record is the single most effective mitigant available to a business facing a potential violation.
This guide walks through the audit and testing process in six steps, covering the governing authority, the classification and screening tests, cross-border regime interactions, the most common failure points, and when to involve external counsel.
Step 1: Understand the governing authority and legal basis
BIS administers the EAR under authority granted by the Export Control Reform Act and, ultimately, IEEPA. The EAR controls the export, re-export, and in-country transfer of commercial and dual-use goods, software, and technology originating in the United States or containing US-controlled content above the applicable de minimis threshold. Every person in the supply chain who re-exports US-origin goods or technology – not just the original US exporter – is potentially subject to BIS jurisdiction.
The audit and testing obligation is not codified as a single requirement. It flows from BIS's published guidance on export-compliance programmes, which identifies five core elements: management commitment, risk assessment, export controls, training, and auditing and corrective action. The fifth element is the focus of this guide. BIS's guidance treats the absence of an audit function as an aggravating factor in enforcement proceedings. In our experience, businesses that treat the audit element as a tick-box – rather than an active testing regime – are the ones that face the sharpest penalty exposure when a violation emerges.
What does "testing" mean in practice, as distinct from "auditing"? Auditing reviews whether controls were applied; testing verifies whether the underlying logic is correct. An audit might confirm that an item was screened before export. A test asks whether the screening tool would correctly catch a controlled item if the classification had been entered incorrectly. Both are necessary.
Step 2: Classify your items before you audit anything else
Classification is the foundation of every EAR compliance obligation, and errors at this stage corrupt every downstream control. Before an audit can assess whether screening, licensing, or record-keeping is working, the business must confirm that each product, software package, or technology type has been assigned the correct Export Control Classification Number (ECCN – the alphanumeric code under the US Commerce Control List that determines what controls apply) or has been affirmatively determined to be EAR99 (goods subject to the EAR but not listed on the Commerce Control List, which generally require no licence unless destined for a controlled party or end-use).
Classification errors are the most frequent root cause of substantive EAR violations we see. Products that were classified when first launched often remain under their original ECCN long after the technology has changed, the product line has expanded, or the control list itself has been updated. A meaningful audit tests the classification itself – not merely whether a classification exists in the system.
Practically, this means pulling a sample from across the product range and asking: who classified this item, on what basis, and when was it last reviewed? For items at the boundary between a controlled ECCN and EAR99, or between two ECCNs with different licence requirements, the audit should document the technical rationale explicitly. Where uncertainty remains, a commodity-classification request to BIS is a recognised route to certainty – and a completed request demonstrates good-faith compliance.
Related practices
- Compliance audit and testing – Australia regime – how the Australian autonomous sanctions and export-control obligations compare to BIS/EAR.
- Compliance audit and testing under BIS / EAR: guide 3 – continuing this series with deeper focus on enforcement risk and voluntary self-disclosure.
Step 3: Test the screening logic and denied-party controls
Screening for denied and restricted parties is a separate control layer from classification, and it must be tested independently. BIS maintains several restricted-party lists – the Entity List, the Denied Persons List, the Unverified List, and others – and an export to a party on any of these lists can trigger a violation regardless of whether the underlying item requires a licence on its own merits. The rule is sometimes described as "know your customer is not on the list," but the legal standard is stricter: a party who knew or had reason to know of a violation is caught, even if no actual list match was confirmed.
Testing the screening function means more than verifying that a screening tool subscription is active. It means asking: does the system screen all relevant transaction parties (not just the consignee, but the end-user, the freight forwarder, and the ultimate beneficial owner where known)? Does it flag name variants, transliterations, and aliases? Does it screen against the current version of the lists, updated at a frequency appropriate to the business's transaction volume? And does a positive hit actually stop the transaction, or does it merely generate a notification that staff can override without documented escalation?
In a recent matter, a mid-sized technology distributor believed its screening programme was functioning correctly. A testing exercise revealed that override decisions were being recorded but never reviewed by anyone with authority to escalate. A shipment to a party that had been added to the Entity List was processed after an override, without the required licence. The audit and testing work surfaced the gap before it reached BIS; the business was able to restructure the escalation process and document corrective action. That documentary record proved material when the issue was subsequently self-disclosed.
The position above covers the standard case. Your facts – the counterparty structure, the goods involved, the route, and whether US-person involvement triggers additional obligations – change the analysis materially. For an assessment of your screening controls and BIS / EAR exposure, contact Calder & Vance at info@caldervance.com.
Step 4: Cross-border considerations – where BIS / EAR intersects with other regimes
One of the most important – and most frequently underestimated – aspects of an EAR compliance audit is the extraterritorial dimension. The EAR's reach extends beyond the United States to cover re-exports by non-US persons where US-origin content exceeds the applicable de minimis threshold, and to cover foreign-produced items that incorporate certain US-origin technology or software (the foreign-direct product rule). A compliance programme that only addresses US-origin shipments from a US facility leaves the business exposed on re-exports made by its overseas subsidiaries or distributors.
The audit must therefore ask: where does the US-content threshold apply across the supply chain? Has the business assessed whether its non-US operations are re-exporting EAR-controlled items without the required authorisation? Does the compliance programme in those jurisdictions address BIS requirements, or only local export-control obligations?
The interaction with other regimes adds further layers. Under the UK's Export Control Order, administered by ECJU, and under EU dual-use rules based on EU Regulation 2021/821, the control lists and licence requirements are similar in structure to the EAR but differ in their specific entries and jurisdiction triggers. A good classified under an EU dual-use category may not match its EAR ECCN precisely. Conversely, an item that is EAR99 may still require a UK or EU licence depending on the destination and end-use. An audit that covers only one regime leaves gaps in the others.
For businesses operating across multiple jurisdictions, we regularly advise on how to design a single integrated audit programme that covers BIS/EAR obligations alongside UK and EU controls, rather than running three separate and potentially inconsistent processes. The efficiency gain is real; more importantly, the risk of one regime's gap being invisible to the other regime's audit team disappears.
The OFAC sanctions dimension also intersects with export-control audits. Certain destinations and end-users trigger both an EAR licence requirement and an OFAC prohibitions analysis. A compliance audit that covers only one of these exposures is incomplete. Both the item-based controls (EAR) and the party-and-destination-based controls (OFAC) must be addressed in a unified testing process. We have acted for clients where the export-control audit surfaced the OFAC dimension for the first time – and where addressing both simultaneously produced a stronger corrective-action package than two separate exercises would have done.
Step 5: Audit record-keeping and documentation controls
Record-keeping is a standalone compliance obligation under the EAR, not merely a support function for other controls. The EAR requires that records related to export transactions be retained for a defined period from the date of export or the date of the relevant licence application. Gaps in the record-keeping system are independently enforceable and routinely cited in BIS enforcement actions as a distinct element of the violation package.
A record-keeping audit asks four questions. First: are all required records actually being retained – shipping documents, export declarations, end-user statements, classification records, and screening records? Second: are they retained in a form that is accessible and legible for the full required period? Third: are they associated with the correct transaction and retrievable if BIS issues a production request? Fourth: does the retention policy distinguish between EAR record-keeping requirements and other retention frameworks (data protection, tax, commercial) so that records are not purged under one policy before they expire under the EAR?
A testing exercise here is straightforward in concept but often revealing in practice: pick a sample of transactions from twelve to twenty-four months ago and attempt to reconstruct the complete record for each. Classification evidence, the screening result, the export declaration, the end-user certificate, and any licence or exception notation should all be present. If they are not, the record-keeping control is failing. If a transaction cannot be fully documented, the business is in the position of being unable to demonstrate compliance it may in fact have achieved.
If a transaction has already been flagged, or a filing has been refused, an early review of the record can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review of your record-keeping posture and any apparent violations.
What are the most common failure points – and how should they be corrected?
In our cross-border practice, the failure points in EAR compliance audits cluster around five recurring patterns. Classification gaps are the most frequent: the product range has grown or changed, but the classification review has not kept pace. Party screening overrides come second: the business has a screening tool, but the override process has no meaningful friction. Re-export blind spots are third: US-origin content flows through non-US subsidiaries whose local compliance teams do not recognise the EAR obligation. Record-keeping purges are fourth: records are deleted under a data-minimisation or storage-cost policy before the EAR retention period has run. Fifth – and perhaps the most damaging – is the absence of a genuine corrective-action process: the audit finds an issue, it is noted, and then nothing changes because there is no owner for the remediation.
Is your compliance programme designed to detect problems before they become violations, or only to describe the controls that should theoretically prevent them? The distinction between a descriptive policy and a tested control is the difference between a compliance programme and a liability document.
Correction must be documented. BIS's published guidance on penalty mitigation treats a documented corrective-action process – implemented promptly after a violation is identified – as a significant mitigating factor. The corrective action must be specific: not "we will improve our screening," but "we have updated the screening configuration to include owner-level name matching, implemented a two-person escalation requirement for all overrides, and conducted retraining on [date]." A voluntary self-disclosure (VSD – a proactive report to BIS of a potential violation, which can significantly reduce penalty exposure) is most effective when accompanied by this kind of specific, evidenced corrective action.
A related myth worth correcting directly: many businesses believe that if no shipment caused actual harm – no sanctioned-regime end-use, no weapons-programme application – the violation is not serious. BIS's enforcement approach does not work that way. The absence of harmful end-use is a mitigating factor, but it does not negate the violation. The threshold question is whether the EAR was breached, not what the item was ultimately used for. The audit process should be designed on that basis.
When to involve external counsel in a BIS / EAR compliance audit
External counsel adds value at three distinct points in the audit and testing cycle. Early involvement – before the audit design is finalised – ensures that the scope covers the right risks for the business's specific product range, customer base, and supply-chain structure. Mid-audit involvement is useful where the initial testing surfaces a potential violation: an adviser can help the business assess whether it has a reportable issue, frame the corrective action, and determine whether a VSD is appropriate. Post-audit involvement is valuable where the corrective-action plan needs to be presented to BIS, or where the audit has identified a systemic gap that requires external validation before the business can represent to management or a board that the programme is now compliant.
There is a practical argument for attorney involvement in the audit design that goes beyond legal analysis. An audit conducted or supervised by counsel may generate work product that is protected from disclosure in subsequent enforcement proceedings. The precise scope of that protection depends on the facts and the structure of the engagement; this is something to address at the outset, not after the audit is complete.
We regularly advise businesses at all three stages – designing the audit framework, managing the response to a potential violation that the audit surfaces, and preparing the documentation package for a VSD or a penalty-mitigation submission. The goal in every case is the same: a compliance programme that withstands scrutiny, and a documented record of good-faith effort that protects the business if a violation is subsequently identified.
For a confidential discussion of your BIS / EAR compliance audit and testing programme, contact Calder & Vance at info@caldervance.com. We offer a fixed-fee entry-point review covering classification, screening logic, record-keeping posture, and corrective-action documentation.
See also our related guide: Compliance audit and testing across regimes – cross-border guide – for a multi-regime treatment of audit methodology covering BIS/EAR, UK ECJU, and EU dual-use obligations in a single framework.