Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · BIS / EAR

Compliance audit and testing under BIS / EAR: what businesses must know

A mid-sized precision-parts manufacturer receives an enquiry from a new distributor in a third market. The export compliance team runs a check, approves the shipment, and the goods leave the facility. Six months later, an internal review reveals that the distributor's ultimate parent had appeared on the Entity List (BIS's list of parties subject to heightened licensing requirements under the Export Administration Regulations) for over a year before the first order. No licence was sought. No voluntary disclosure was made. The business now faces a potentially significant civil penalty exposure under the EAR (the Export Administration Regulations, the principal US export-control regime administered by the Bureau of Industry and Security).

A compliance audit and testing programme under BIS / EAR systematically tests whether an organisation's export-control procedures match the obligations imposed by the EAR, identifies gaps before an enforcement inquiry does, and provides the documented evidence that regulators treat as a mitigating factor. As of July 2026, BIS continues to treat the presence – or absence – of a well-tested internal compliance programme as a material factor in civil penalty determinations. This guide sets out the steps, the risk flags, and the points at which outside counsel adds the most value.

The sections that follow move from the legal foundation through a practical audit sequence, a cross-regime comparison, and the risk flags that practitioners most commonly encounter.

Step 1: Understand the legal foundation before you audit anything

The EAR does not mandate a specific compliance programme structure; what it does is impose strict-liability obligations – civil penalties can apply whether or not the exporter knew that a violation occurred – and calibrate enforcement outcomes to the strength of the compliance programme the business had in place at the time of the apparent violation.

BIS publishes guidance describing the elements it considers indicative of a well-designed export-compliance programme. Those elements are not a safe harbour, but they form the template every audit should test against. The five core elements, as practitioners have mapped them from BIS guidance, are: management commitment, a risk assessment, written policies and procedures, training, and ongoing testing and auditing. The fifth element – testing – is what most businesses underinvest in. Policies that have never been stress-tested against real transaction flows are exactly what an enforcement inquiry will expose.

Understanding that foundation matters because a compliance audit is not a paperwork exercise. It is a legal risk-management step that produces evidence. That evidence either supports a voluntary self-disclosure or counters the argument that a violation was wilful. The distinction drives penalty outcomes at a practical level.

Step 2: Map your transaction flows and classify your items correctly

Before any audit can proceed, the business needs a clear picture of what it exports, where it exports it, and to whom. Classification is the analytical baseline: every item, software, or technology subject to the EAR carries an ECCN (Export Control Classification Number under the US Commerce Control List), and the ECCN determines which licence requirements and licence exceptions apply to a given destination, end-use, and end-user combination.

In our experience, ECCN classification errors are the single most common source of unreported violations discovered during audit. The two failure modes are opposite but equally costly. Some businesses over-classify, restricting legitimate trade unnecessarily and adding licence application costs. Others under-classify – or rely on a "no ECCN required, EAR99" determination that was never properly documented – and ship controlled items without a licence. Both indicate that the classification process is not functioning as a genuine control.

The audit should test whether the classification methodology is documented, who owns it, when it was last updated, and whether it covers all product lines including software, encryption functionality, and technology transferred to foreign nationals in the course of employment. That last category – deemed exports and deemed re-exports, the EAR's treatment of technology transfers to foreign nationals as if they were physical exports to the person's home country – is frequently absent from classification registers even in mature compliance programmes.

A practical audit step here is to take a sample of five to ten high-value or technically complex items, re-classify them independently, and compare the result against the company's live register. Discrepancies in that sample predict the error rate across the full catalogue.

Step 3: Screen counterparties, end-users, and end-uses – and test the screening logic

Counterparty screening under the EAR covers three overlapping lists: the Entity List, the Denied Persons List (a list of individuals and entities whose export privileges have been revoked), and the Unverified List (a list of parties BIS has been unable to verify as legitimate end-users through pre-licence checks or post-shipment verification). A party on any of these lists triggers distinct obligations: denial of export privileges, licence requirements beyond the standard matrix, or an obligation to submit an "is-informed" letter before proceeding.

The audit must test not just whether screening is performed but whether the screening logic is current, calibrated, and documented. Three specific questions should be in scope. First, is the screening database updated in real time or on a periodic cycle – and if periodic, how long is the gap? Lists change frequently. Second, does the screening cover the full ownership and intermediary chain, not just the immediate buyer? The Entity List captures named parties; it does not automatically capture their subsidiaries or affiliates by name, but the EAR's "knowledge" standard reaches situations where a business had reason to know a controlled item would reach a listed party. Third, are red-flag indicators being checked alongside the formal lists – unusual payment terms, atypical routing through third countries, purchaser requests to remove markings, end-use representations that are vague or inconsistent? Red-flag procedures are explicitly part of BIS guidance, and their absence is noted during enforcement reviews.

Testing the screening logic means running test cases: known-listed parties, known-clean parties, and edge cases (name variations, transliteration differences, partial matches). The test results should be documented. If the screening tool fails on a known-listed party, that is a material finding requiring immediate remediation, not a note for the next quarterly review.

How does BIS / EAR differ from OFAC, OFSI, and EU screening obligations?

The BIS export-control screening regime operates alongside – and in important respects diverges from – the sanctions screening frameworks of OFAC, OFSI, and the EU, and a business operating across those regimes cannot treat one programme as sufficient for all.

OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons) imposes a property-freeze and transactional prohibition on anyone with US jurisdiction, applying the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) automatically to non-listed entities. BIS lists do not operate by that aggregation logic. A party on the Entity List is subject to specific licence requirements on items destined to it; the obligation does not automatically cascade to entities it owns unless those entities are also listed. That difference means a business that has mapped the OFAC ownership chain has not necessarily completed its BIS screening analysis.

Under OFSI and EU financial-sanctions rules, the ownership-and-control test is a broader inquiry that goes beyond a mechanical percentage to ask whether a listed person controls decision-making. Again, that test is different in character from the BIS list-based approach. Where a business is headquartered in the UK or has EU nexus, its compliance programme must treat the BIS screening obligation as the floor, not the ceiling.

For businesses with operations in Australia, DFAT's autonomous-sanctions regime and its list of designated persons sit alongside the Australian export-control framework under the Defence Export Controls model. The interaction between BIS obligations and the Australian position is a practical concern for dual-use exporters with supply chains that pass through Australian entities. Our cross-border export-control and sanctions compliance practice covers that interaction directly; see our compliance audit and testing service for the Australian regime for more detail on where the two regimes overlap and diverge.

The cross-regime comparison matters for the audit scope decision. An audit focused only on BIS / EAR obligations will miss OFAC SDN exposure. An audit focused only on SDN screening will miss BIS list obligations and the EAR's end-use controls. In our cross-border practice, we regularly advise businesses to commission an integrated audit scope that maps all applicable list-based regimes and identifies the points of divergence before testing begins.

What are the risk flags that consistently surface during BIS / EAR audits?

Certain risk patterns appear so consistently across BIS / EAR audits that they warrant specific attention in any audit programme, regardless of the industry or transaction type.

The first is incomplete deemed-export controls. Businesses that transfer controlled technology to foreign-national employees, contractors, or visitors without running nationality-of-origin checks against the relevant country chart are routinely exposed. Deemed exports and deemed re-exports are among the most frequently cited categories in BIS enforcement guidance. An audit should check whether HR processes and visitor procedures feed into the export-compliance programme at all.

The second is unverified end-use. The EAR's end-use controls impose obligations not just at the point of export but on the exporter's knowledge of the likely end-use. Where a distributor serves a high-risk sector or a high-risk destination, an end-use certificate is not a complete answer if the business has information that contradicts it. The audit should review whether end-use representations are being collected, stored, and cross-checked against order patterns.

The third is record-keeping. The EAR requires records of export transactions to be retained for a defined period. Businesses that have not identified which records qualify, who owns the retention obligation, and what the current retention status is are exposed on multiple fronts: they cannot demonstrate compliance in an enforcement inquiry, and a voluntary self-disclosure is harder to prepare without the underlying transaction record. One practical audit test is to request the export records for a sample of five transactions from two years prior and assess whether they are complete, retrievable, and stored in a format that can be produced to BIS.

The fourth – and in our experience the most consequential – is the absence of testing as distinct from monitoring. A business that monitors transactions against written procedures but never tests whether the procedures actually work in practice may have a sophisticated-looking programme that fails in a real export scenario. Testing means running simulated or historical transactions through the process and checking outcomes against legal requirements. Monitoring checks whether the process was followed; testing checks whether the process is correct.

Step 4: Document findings and design a remediation path

An audit that produces findings without a documented remediation path is an incomplete exercise. More than that, it creates a risk: if BIS reviews the business in an enforcement context and finds that a compliance audit identified a gap that was never remediated, the audit itself becomes evidence of knowing non-compliance. That is worse than not having audited.

The documentation standard for a BIS / EAR compliance audit should therefore cover three things. The scope of the audit and the methodology used. The findings, ranked by severity and by the EAR provision implicated. And a remediation plan with assigned owners, target completion dates, and a verification step – a scheduled re-test after remediation to confirm the gap is closed, not just addressed on paper.

Where the audit uncovers a probable past violation, the documentation also needs to address the voluntary self-disclosure question. A VSD (voluntary self-disclosure to a regulator) to BIS, submitted before the agency becomes aware of the apparent violation through other means, is treated as a significant mitigating factor in penalty calculations. The timing decision on whether and when to submit a VSD is one of the most consequential choices in an export-compliance context. It should be made with legal advice, not deferred until the remediation plan is complete.

If a transaction has already been flagged by BIS, or an internal audit has surfaced a probable past violation, an early review with outside counsel preserves options that narrow with time. To discuss a potential VSD, a licensing question arising from your audit findings, or a programme-redesign following an audit, contact Calder & Vance at info@caldervance.com.

Step 5: Embed testing as a recurring programme element

A one-time audit is a snapshot. The EAR's requirements change – new entries on the Entity List, new Commerce Country Chart modifications, new controls on emerging and foundational technologies, new guidance on encryption classifications. A compliance programme that was accurate at the point of design degrades against a changing regulatory baseline unless it is actively tested and updated.

BIS guidance specifically identifies periodic auditing as a component of an effective compliance programme. The practical implementation varies by business size and export volume, but the minimum architecture includes four elements.

A scheduled full-programme review at intervals appropriate to the business's risk profile. Higher-risk businesses – those exporting controlled items to multiple destinations, those with foreign-national workforces in sensitive technology areas, those that have experienced prior violations or near-misses – should review at shorter intervals than lower-risk ones.

Transaction-level testing on a sample basis throughout each period, separate from the monitoring function. The testing function should report to a different line than the day-to-day compliance team, or use external reviewers, to avoid the self-review problem.

A trigger-based review protocol that activates a rapid audit when the business adds a new product line, enters a new market, acquires a business with its own export-compliance history, or receives any contact from BIS – whether a routine post-shipment verification request or something more serious.

A training refresh cycle linked to the test results. Where testing reveals that employees are making consistent errors in a particular area – classification, screening, end-use documentation – the training programme for that area should be updated and re-delivered. The connection between test findings and training content is the mechanism by which a testing programme produces durable compliance improvement, not just a compliance record.

We regularly advise businesses across sectors on the design and implementation of this recurring architecture. In a recent matter, a technology-sector business operating across multiple jurisdictions engaged us to review its export-compliance programme after an internal audit revealed inconsistencies in its ECCN classification methodology. We tested the classification process, mapped the gaps against the EAR's current control parameters, and redesigned the programme documentation to support a credible VSD. The matter moved to resolution without escalating to a penalty proceeding. Outcomes are never guaranteed, but early action and a well-documented programme make a material difference to the range of available options.

When should you involve outside compliance counsel?

The myth that outside counsel is relevant only when BIS has already knocked on the door is one we encounter regularly. In practice, the most effective interventions happen well before any enforcement contact.

Outside counsel adds value at several points in the audit and testing cycle that are difficult to replicate internally. The first is scope design: an outside adviser familiar with BIS enforcement priorities can calibrate the audit scope to the areas BIS has historically examined most closely, rather than applying a generic internal-audit methodology that may miss export-specific risk categories. The second is the legal-privilege question. An audit conducted under legal professional privilege produces findings that are protected from compelled disclosure in subsequent enforcement proceedings. An internal compliance audit does not carry that protection automatically. The decision about how to structure the audit – and who leads it – therefore has legal consequences.

The third, and arguably the most important, is the voluntary self-disclosure decision. If the audit surfaces a probable past violation, the analysis of whether to disclose, what to disclose, how to frame it, and when to submit is a legal judgement, not a compliance administration task. Getting that judgement wrong – disclosing too narrowly, disclosing too broadly, or disclosing before the remediation plan can be presented as a mitigating factor – can significantly affect the enforcement outcome.

The position above covers the standard case. Your facts – your products, your destinations, your counterparty structure, the specific EAR provisions in play – change the analysis materially. For an assessment of your export-compliance programme or a structured BIS / EAR audit, contact Calder & Vance at info@caldervance.com.

Related practices

Frequently asked questions on compliance audit and testing under BIS / EAR

What are the steps to audit and test a compliance programme under BIS / EAR?

A BIS / EAR compliance audit follows a structured sequence: establish the legal baseline from BIS guidance; map transaction flows and verify ECCN classifications; test counterparty screening logic against current BIS lists and red-flag procedures; review end-use controls and deemed-export procedures; check record-keeping completeness; and document all findings with a remediation plan and a scheduled re-test. Findings that indicate a probable past violation should trigger a legal assessment of whether a voluntary self-disclosure to BIS is warranted, and that decision should be made promptly.

What is the most common mistake in compliance audit and testing?

The most consistent mistake is treating monitoring as equivalent to testing. Monitoring checks whether employees followed existing procedures. Testing checks whether those procedures, if followed correctly, would actually produce a compliant outcome. A business can have complete monitoring records for a process that is legally deficient. The second most common failure is limiting the audit to formal list-screening and missing ECCN classification errors and deemed-export gaps – both of which are high-priority enforcement areas for BIS.

How does BIS / EAR differ from other regimes here?

BIS / EAR compliance operates through item classification and list-based controls rather than a property-freeze model. That means the analysis is driven by what is being exported and to whom, not solely by whether the counterparty is designated. OFAC's 50 percent rule automatically captures non-listed subsidiaries of blocked persons; BIS list-based obligations do not automatically cascade in the same way. For businesses subject to both BIS and OFAC obligations – as most US-nexus exporters are – the screening and classification programmes need to be designed to meet both standards simultaneously, because satisfying one does not satisfy the other.

About the author

Viktor Lindqvist advises exporters and trading houses on dual-use export controls, maritime and trade sanctions, and end-use compliance. He has acted on BIS classification and licensing matters, compliance-programme audits and redesigns across sectors including precision manufacturing, telecommunications, and advanced materials, and voluntary self-disclosure processes before BIS. Calder & Vance – International Sanctions & Export Control Counsel.

About Calder & Vance

Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.

Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.