A freight forwarder's quarterly review flags a discrepancy: an item classified under a general-purpose heading has been shipped to a destination requiring a licence that was never obtained. The shipment was six months ago. The compliance programme said it had controls in place. Clearly, something failed – but where, and how badly?
A compliance audit and testing programme under the BIS / EAR (the US Export Administration Regulations, administered by the Bureau of Industry and Security) is the structured process by which an organisation verifies that its export-control procedures are functioning as designed, identifies gaps, and corrects them before an enforcement action intervenes. As of July 2026, BIS expects exporters to maintain documented, tested compliance programmes; a well-evidenced audit trail is a significant mitigating factor in any enforcement assessment.
This guide walks through the audit cycle step by step – from scoping and classification review through transactional testing, cross-border comparison with aligned regimes, and the decision about when external counsel should be involved.
Step 1: Scope the audit and establish the legal baseline
An effective BIS / EAR compliance audit begins with a written scope document that defines which product lines, business units, destinations, and transaction types will be reviewed, and which legal instruments govern each of them.
The EAR covers the export, re-export, and in-country transfer of items on the Commerce Control List (CCL – the BIS schedule that assigns an Export Control Classification Number to each controlled item) as well as EAR99 items (goods not specifically listed on the CCL but still subject to the EAR's general prohibitions). The scope document should record which categories of the CCL are relevant to the business, which destinations are in play, and which end-use and end-user controls may apply independently of classification.
At this stage, the audit team must also map the applicable embargo and sanctions layer administered by OFAC. BIS and OFAC operate distinct regimes with overlapping territorial reach. A shipment might clear EAR licensing requirements but still be prohibited under an OFAC country-programme measure. Scoping both simultaneously is standard practice for any cross-border business.
The scope document should be approved by a senior officer before fieldwork begins. In our experience, audits that skip this step tend to drift – they become reactive surveys of whatever the compliance team already monitors, rather than structured risk-proportionate reviews.
Step 2: Review export control classifications across the product portfolio
Classification accuracy is the load-bearing pillar of EAR compliance; every other control downstream depends on knowing what an item is and what licence requirement, if any, it attracts.
The audit team should pull the full product register and verify that each item either holds a documented ECCN (Export Control Classification Number under the CCL) or has been reviewed and recorded as EAR99. Classification should be based on technical specifications, not commercial descriptions. Where classifications were inherited from a predecessor business or from a supplier's paperwork, they should be independently verified.
A common failure mode is de facto reliance on an ECCN assigned years earlier, without checking whether subsequent regulatory amendments moved the item to a different category or altered its licence requirements. The CCL is revised regularly. An annual classification review is the minimum standard; more frequent checks are appropriate for dual-use technology lines where controls evolve quickly.
Where classification is genuinely uncertain, the correct route is a Commodity Jurisdiction request to the State Department (for defence articles potentially governed by the ITAR rather than the EAR) or a Classification Request to BIS. Neither of those processes constitutes an admission. In our cross-border practice, we regularly advise on classification posture for product lines that sit at the EAR/ITAR boundary – a position that attracts heightened scrutiny.
Step 3: Test transactional controls – the screening and authorisation cycle
Transactional testing examines whether the controls documented in the compliance programme are actually operating on live and historical transactions, not merely on paper.
The testing sample should be risk-stratified. Higher-risk transactions – controlled-item exports to destinations with elevated screening complexity, transactions involving parties that have appeared on watchlists, or shipments where the stated end-use is imprecise – should be over-represented. A purely random sample will miss the pattern of failures that matters to BIS.
For each transaction in the sample, the audit team should verify the following sequence:
- Was the ECCN (or EAR99 determination) recorded at the time of the transaction, not retrospectively?
- Was the destination, end-user, and end-use assessed against the applicable country chart and general prohibitions?
- Was screening conducted against the BIS Entity List, the BIS Denied Persons List, and the OFAC SDN List (Specially Designated Nationals and Blocked Persons – OFAC's primary blocking list) before shipment?
- Was a licence obtained where required, or was a licence exception validly applied and documented?
- Are the Export Control Documents (shipping records, licence copies, end-use certificates) retained and retrievable?
Record retention is a substantive obligation, not a filing courtesy. The EAR requires that export records be kept for a defined period. APPENDIX E does not supply the current figure for this page; verify the current retention requirement against the EAR's record-keeping provisions before finalising your programme.
The position above covers the standard screening cycle. Your facts – the item, the destination, the transaction structure, the identity of all parties in the chain – change the analysis materially.
For an initial assessment of your compliance programme's transactional controls, contact Calder & Vance at info@caldervance.com.
How does a BIS / EAR audit differ from other regime audits?
BIS / EAR compliance auditing shares architecture with other major export-control and sanctions audit programmes, but the divergences are operationally significant for any cross-border business.
Under the UK's Export Control Order (administered by ECJU), the classification system and end-use controls are broadly aligned with the international Wassenaar Arrangement and other multilateral regimes. However, the UK regime post-2020 has developed independently of the EU system, and there are growing divergences in controlled-goods listings and in licensing policy. A UK-based subsidiary of a US parent may need parallel ECJU and EAR licences for the same shipment, and the timing and documentation requirements of each will differ.
The EU dual-use regulation (the instrument governing export of dual-use goods from EU Member States) uses a control list that tracks the multilateral regime lists, but EU Member States administer their own licensing authorities. This produces variation in processing times and in the scope of available licence types across the single market. An EU parent exporting US-origin controlled content may simultaneously face EAR re-export controls – a source of compliance complexity that a BIS audit must address explicitly.
One structural difference deserves particular attention: BIS's extraterritorial reach. The EAR applies to items of US origin or containing US-controlled content wherever they are in the world, and to foreign-produced items that incorporate more than a defined threshold of US-controlled content or technology (the de minimis rule and the foreign direct product rule). This means a non-US company auditing its own export compliance must include US-origin content in its review scope, even where the company holds no US export licence and is not itself the US exporter of record.
The practical implication: a compliance audit designed only around the domestic regime will miss the EAR exposure entirely. We have acted for European and Asian trading companies whose audit programmes were structurally complete under their home-country rules but had no visibility into US-origin content flows at all.
What are the risk flags that demand escalation during an audit?
Certain findings during a BIS / EAR compliance audit require immediate escalation to senior management and, in most cases, to external counsel – because the window for remedial action, including voluntary self-disclosure, may be short.
The following indicators require escalation without delay:
- An unlicensed export of a controlled item to a destination, end-user, or end-use that would have required a licence. This is a potential violation. The question of whether to make a VSD (voluntary self-disclosure to BIS) needs to be assessed promptly, because BIS treats a timely, well-documented VSD as a significant mitigating factor.
- A transaction with a party on the Entity List or Denied Persons List that was not identified at the time of screening. The audit has found a potential prohibited transaction. Continuing the relationship pending assessment of the exposure is itself a risk.
- Classification errors affecting a substantial volume of transactions. Systemic mis-classification is not a paperwork issue; it is evidence of a programme failure that BIS enforcement staff will treat as an aggravating factor.
- Evidence that red flags (the indicators of diversion risk identified in BIS guidance – unusual purchase terms, reluctance to provide end-use information, atypical shipping routes) were present in a transaction but not escalated or resolved before shipment occurred.
- Any transaction that touches a destination subject to a comprehensive embargo, however the items were classified at the time.
If a transaction has already been flagged or a filing has been refused, an early review can preserve options that narrow sharply with time. Contact Calder & Vance at info@caldervance.com for a confidential initial review.
Step 4: Review the compliance programme structure against the five-element standard
BIS has articulated, in its published guidance, a five-element model for an effective export-compliance programme. A compliance audit is incomplete unless it assesses whether the programme meets this structure – not just whether individual transactions passed or failed.
The five elements are: management commitment, risk assessment, export controls implementation, training and awareness, and auditing and compliance. The audit itself falls within the fifth element, but the audit's scope must extend to all five.
Management commitment is tested not by reviewing a policy document but by examining whether senior officers have approved the programme, whether they receive regular compliance reporting, and whether they have allocated resources proportionate to the organisation's export-control risk profile. A programme that exists on paper but lacks budget, staffing, and board visibility will not meet the standard.
The risk assessment element requires the programme to be calibrated to the organisation's actual risk – the products it handles, the destinations it serves, the counterparties in its supply chain, and the commercial pressures that could create incentives for corners to be cut. A generic risk matrix imported from a trade association template is not a risk assessment for BIS purposes.
Implementation is tested by examining whether the documented procedures are followed in practice – which is the work of transactional testing described in Step 3 above. Training is tested by reviewing training logs, assessing whether staff in roles with export-control exposure have received relevant and up-to-date instruction, and verifying that training content reflects the current state of the EAR and the CCL.
A compliance programme that passes transactional testing but fails the structural review – because management has not signed off on it, or because training records are incomplete, or because the risk assessment has not been updated since a material change in the business – is still a programme with documented weaknesses that could affect the outcome of any enforcement assessment.
Step 5: Document, remediate, and design the next review cycle
The audit findings should be recorded in a written report that is clear, precise, and capable of supporting a remediation plan. The report serves two purposes: internal governance and, if a potential violation has been identified, the foundation of any VSD submission to BIS.
The remediation plan should assign a named owner to each finding, set a defined timeline for correction, and establish a verification step to confirm that the remediation has been effective. Open findings from a prior audit cycle that have not been closed are an aggravating factor in any subsequent enforcement context.
The audit cycle should be defined in advance. For most businesses operating in the mid-range of export-control complexity, an annual full audit supplemented by quarterly transactional testing is a reasonable minimum. Businesses handling items in the highest-sensitivity categories, or operating across multiple jurisdictions with parallel EAR and non-US export-control obligations, should consider a shorter cycle or continuous monitoring for high-risk transaction types.
The audit report and supporting workpapers should be retained in a form that is accessible, complete, and clearly dated. They are the evidence that a programme was operating at the time of any transaction that later comes under scrutiny. In our experience, the firms that fare best in BIS enforcement assessments are those that can produce a clear audit trail showing that the programme was tested, that findings were recorded, and that remediation was completed.
A common objection: "Our items are EAR99 – we do not need a formal audit"
This is one of the most persistent misconceptions we encounter in cross-border export-control practice. The EAR's general prohibitions – including the end-user controls, the restrictions on transactions with denied persons, and the embargo-destination prohibitions – apply to EAR99 items as well as to items listed on the CCL.
An exporter of EAR99 goods who ships to a denied party has committed a violation. An exporter who processes an order from a party on the Entity List without screening has created an exposure. The EAR99 classification relieves the exporter of a licence requirement for most ordinary transactions; it does not exempt the exporter from the regime entirely.
Beyond the EAR itself, US re-export controls mean that foreign recipients of EAR99 goods may face restrictions on what they do with those goods in certain circumstances. And OFAC country-programme measures may block transactions with counterparties in specific destinations regardless of how the goods are classified under the EAR. A compliance programme premised on "we only ship EAR99" is structurally incomplete.
Related practices
- Compliance audit and testing – Australia – Autonomous Sanctions regime audit and programme review for Australian operations.
- BIS / EAR compliance audit guide – advanced topics – In-depth treatment of re-export controls, the foreign direct product rule, and end-use certificate practice.
- BIS / EAR compliance guide – licensing and exceptions – Practical guidance on licence applications and the principal EAR licence exceptions for cross-border exporters.