Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · BIS / EAR

Sanctions compliance programmes under BIS / EAR: a practical guide

A mid-sized electronics manufacturer signs a distribution agreement with an overseas partner. The compliance team runs a counterparty screen. Nothing flags. Six months later, a BIS inquiry arrives: the partner has been re-exporting controlled items without authorisation. The exporter's own licences, end-user statements, and internal controls are now under review. Was the original screening enough? Almost certainly not.

A sanctions compliance programme under the Export Administration Regulations ("EAR") – the principal US export-control regime administered by the Bureau of Industry and Security ("BIS") – must do more than screen names. As of mid-2026, BIS expects exporters, re-exporters, and transferors to maintain a structured, risk-based programme that covers classification, licensing, end-use verification, and ongoing monitoring. A programme that addresses only the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) while ignoring the BIS Entity List and Denied Persons List is a programme with a significant gap.

This guide walks through the design of a BIS / EAR compliance programme in practical steps, with cross-regime comparisons at each stage. It identifies the risk flags practitioners see most often and sets out when the analysis warrants external counsel.

Step 1 – Understand who and what the EAR covers

The EAR applies to items "subject to the EAR" – broadly, goods, software, and technology that originate in the United States, are manufactured outside the United States using US-origin technology above a specified threshold (the de minimis rule), or are produced on US equipment under certain conditions (the foreign direct product rule). The regime reaches far beyond US borders. A European subsidiary transferring US-origin software to a third-country customer can trigger EAR obligations even if no US person is involved in the transaction.

This extraterritorial reach is the starting point for programme design. Many businesses assume the EAR applies only to exports from US soil. In our experience, that assumption is the single most common gap we find when reviewing existing programmes. The correct question is not "are we exporting from the United States?" but "does this item carry US-origin content or technology above the applicable threshold?"

BIS administers the Commerce Control List ("CCL"), which assigns an Export Control Classification Number ("ECCN") – a five-character alphanumeric code identifying the reason and scope of control – to each controlled item. Items not on the CCL fall under EAR99. EAR99 items generally require no licence for most destinations, but they can still be prohibited when the end-user or end-use is restricted. A programme that treats EAR99 classification as the end of the analysis is under-built.

Step 2 – Map and classify your items before you screen your parties

Item classification is the foundation of a BIS-compliant programme; party screening without it is structurally incomplete. The classification process begins with a technical review of the item against the CCL. If the item is not clearly EAR99, a formal classification request may be submitted to BIS for a binding commodity classification ruling – a step worth considering for product lines where the technical parameters sit close to a control threshold.

Classification determines which licences or licence exceptions are available, which destinations require individual authorisation, and which end-uses are categorically prohibited. The Export Control Reform Act and its implementing rules under the EAR set out the licensing and exception framework. Practitioners should note that the CCL is amended regularly; a classification valid at launch may not remain valid after a regulatory update. Your programme should include a periodic reclassification trigger – typically tied to product change cycles or a defined calendar interval.

How does this compare with other regimes? The EU dual-use rules operate a similar list-based approach through the EU dual-use regulation, with an annex that maps controlled goods to categories. The UK Export Control Order uses comparable list technology. However, the CCL is more granular, and the foreign direct product rule has no direct equivalent in the EU or UK regimes. That difference matters for manufacturers who supply components to third-country assemblers: BIS jurisdiction may reach those downstream products even when EU or UK jurisdiction does not.

Step 3 – Build a multi-list party screening architecture

Effective party screening under the EAR requires checking multiple BIS-administered lists simultaneously, not just OFAC's SDN List. The three primary BIS lists are the Entity List (parties requiring a licence for specified reasons, generally denied), the Denied Persons List (parties whose export privileges have been revoked), and the Unverified List (parties for whom BIS has been unable to conduct end-user verification). Transacting with an entity on the Entity List without the relevant authorisation is a violation, regardless of whether that entity appears on any OFAC list.

In our practice, we regularly advise businesses whose screening tools are configured primarily for OFAC purposes. They flag SDN matches reliably. They miss Entity List hits. The two lists are maintained by different agencies under different statutory authorities – IEEPA and the Export Control Reform Act respectively – and they do not map onto each other. A combined screening solution covering both is not optional; it is baseline.

Beyond list screening, the EAR's red flags doctrine imposes a duty to investigate when circumstances suggest a transaction may violate the rules. BIS publishes guidance on red flags – indicators such as unusual routing, payment in cash for high-value technical goods, or a buyer unfamiliar with the product's technical specifications. The red flags duty is distinct from the list-screening obligation. Passing a screen does not clear a transaction that carries obvious red flags.

Cross-regime note: OFSI in the United Kingdom applies an ownership and control test (the test for whether a non-listed entity is caught through a listed person) that goes beyond OFAC's mechanical 50 percent ownership rule. The EU applies a comparable ownership-and-control standard. A party that passes the OFAC test may still be caught under OFSI or EU rules. Any programme serving clients or operations across jurisdictions must reflect this divergence.

Step 4 – Design and document the licensing and transaction-authorisation process

Where classification and screening produce a positive control result, the programme must have a clear decision path: is a licence exception available, or is an individual licence required? The EAR provides a range of licence exceptions – standing authorisations that permit defined categories of transactions without a separate application – but each exception carries its own scope, conditions, and recordkeeping requirements. The programme should document which exceptions are pre-approved for internal use and which require case-by-case review by a qualified person.

For transactions requiring an individual licence, the application process is handled through the BIS Simplified Network Application Re-designed ("SNAP-R") platform. The timeline from submission to decision varies by case complexity and the level of inter-agency review required; the programme should set a realistic internal processing window upstream of any contractual delivery date, built around the fact that licences are not guaranteed and can include conditions. Deadlines in sales agreements that do not account for licence timelines are a recurring source of contractual exposure.

A voluntary self-disclosure ("VSD") – a self-initiated report to BIS of an apparent export-control violation – is a recognised mitigant in enforcement. BIS's treatment of VSDs is addressed separately, but the existence of a well-documented compliance programme, including a clear licensing process, is itself a mitigating factor in any penalty calculation. Document the decision, document the basis, and keep the record for the period specified by the EAR (verify the current retention obligation before relying on it, as retention periods are subject to regulatory amendment).

The position above covers the standard licensing decision. Your facts – the item's ECCN, the destination, the end-user, and any conditions attached to a prior licence – change the analysis materially.

For an assessment of your BIS / EAR compliance programme or a licensing question, contact Calder & Vance at info@caldervance.com.

Step 5 – Implement end-use and end-user verification controls

End-use and end-user verification is the element of a BIS compliance programme most often treated as a paper exercise. It should not be. The EAR places obligations on the exporter in relation to the actual use of items by the actual end-user, not only on the formal stated purpose at the time of export. An item exported lawfully to a legitimate buyer can become the subject of a BIS inquiry if it is subsequently diverted – and if the exporter's programme did not include reasonable steps to detect and prevent that diversion.

The core tools are: a detailed end-user statement collected before export (not after), due diligence on the end-user's business that goes beyond a list check, and a post-shipment verification process for higher-risk items. BIS itself conducts post-shipment verifications through the US embassy network. An exporter whose records cannot demonstrate what verification was done will be in a weaker position if a diversion inquiry follows.

For items at the higher end of the control spectrum – particularly items controlled for national security or proliferation reasons – the programme should consider whether additional contractual controls are appropriate, such as re-export restrictions in the sales agreement and a right to audit. These are not guarantees against diversion, but they are evidence of a programme that took the risk seriously.

In a recent matter, a trading house in a third jurisdiction had been re-exporting dual-use items sourced from a US-origin supply chain. The original exporter's programme had no post-shipment review mechanism and had not obtained re-export authorisation from the ultimate end-user. We helped the original exporter scope the apparent violation, advised on the VSD process, and worked through the corrective steps for the programme. The matter illustrated how the absence of downstream controls creates upstream exposure.

Step 6 – Train staff and embed the programme in commercial operations

A compliance programme that sits in a policy document but is unknown to the sales, logistics, and finance teams who execute transactions is not a functioning programme. BIS and other regulators assess whether controls are "operationalised" – embedded in workflows, taught to staff, and tested under realistic conditions. A programme reviewed and confirmed to be well-designed on paper will receive less credit in an enforcement context if the people involved in the transaction did not know what it required.

Training should be differentiated by role. The classification specialist needs technical depth. The sales team needs to recognise red flags and know when to escalate. The finance team needs to know which payment methods and jurisdictions require additional review. Senior management needs to understand the liability regime well enough to support resource allocation decisions. Treating training as a single annual event covering all groups in one session is a common shortcoming.

Cross-regime note: UK ECJU guidance on export-control compliance similarly expects role-differentiated training and documented proof of delivery. The EU dual-use regime places comparable expectations on exporters as part of the Internal Compliance Programme framework. A programme built to the BIS standard will require only moderate adaptation to meet the EU and UK equivalents – the underlying logic of classification, screening, licensing, and verification is consistent across the three regimes, even where the specific rules differ.

Step 7 – Test, audit, and maintain the programme

Testing is not optional. A programme that has never been stress-tested against a real transaction set – where the classification, screening, and authorisation decisions are verified against the actual records – cannot claim to be functioning as designed. BIS's published compliance guidance, and the published guidance of comparable authorities such as OFSI and the EU, describes internal audit and periodic review as a baseline expectation of a credible compliance programme.

Practical testing approaches include: transaction-file audits against a sample of completed exports, tabletop exercises simulating a BIS inquiry or a diversion report, red-team exercises on the screening platform (deliberately introducing a known-hit name to confirm the system catches it), and classification reviews triggered by product changes. Each test should produce a written finding and a remediation record.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss your position.

Maintenance is the other side of testing. The CCL changes. The Entity List changes frequently, sometimes with immediate effect. BIS issues interim final rules that alter licensing requirements without a public comment period. The programme must have an owner who monitors regulatory developments, has a defined process for cascading updates to the operational teams, and can document that the programme reflected the rules in force at the time of each transaction. A compliance programme that was accurate in its first year but has not tracked regulatory changes is a programme that creates historical exposure.

Related practices

Frequently asked questions

What are the steps to design a sanctions compliance programme under BIS / EAR?
A BIS / EAR compliance programme typically follows seven linked steps: understanding the scope of the EAR's extraterritorial reach; classifying all items against the Commerce Control List; building a multi-list party-screening architecture that covers BIS lists alongside OFAC lists; establishing a documented licensing and transaction-authorisation process; implementing end-use and end-user verification controls; training staff by role; and running periodic audit and testing cycles. Each step should be documented. The programme should be owned by a named individual with standing access to regulatory updates.
What is the most common mistake in sanctions compliance programmes?
The most common mistake, in our experience, is configuring screening tools for OFAC purposes only and treating a clean SDN result as clearance for export. BIS administers separate lists – the Entity List and the Denied Persons List – under different legal authority. A party absent from the SDN List can still be the subject of a BIS licence requirement or export denial. A related mistake is treating EAR99 classification as the end of the analysis, when prohibited end-uses and end-users can still make an EAR99 transaction unlawful.
How does BIS / EAR differ from other regimes here?
The EAR's most distinctive feature for programme designers is the foreign direct product rule, which can extend US export-control jurisdiction to non-US-origin items produced using US technology or equipment. This has no close equivalent in the EU dual-use regime or the UK Export Control Order. In addition, the EAR's red flags doctrine creates an affirmative duty to investigate suspicious circumstances, beyond simple list compliance. The EU and UK regimes impose comparable due-diligence expectations, but the specific triggers and safe-harbour mechanisms differ, making it important to design for each regime in parallel rather than assuming a BIS-compliant programme is automatically sufficient for the others.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.