An exporter ships a consignment of industrial sensors to a distributor it has screened for years. A routine classification review reveals the items carry an Export Control Classification Number (ECCN – the product-specific code under the US Commerce Control List that determines which export licence requirements apply) that was never properly mapped. The distributor then re-exports to a destination that triggers additional controls. Two regulatory programmes now apply simultaneously, and the internal compliance programme did not catch the gap before the goods moved.
A well-designed sanctions compliance programme under the Export Administration Regulations (EAR – the BIS-administered rules governing US-origin and US-content goods, technology, and software) is not a single document. It is a structured, five-element operating system: management commitment, risk assessment, internal controls, testing and auditing, and training. As of July 2026, BIS has reinforced its enforcement guidance to treat the quality of a compliance programme as a direct mitigating or aggravating factor in penalty decisions.
This guide covers how to build and maintain a BIS / EAR-compliant programme, where programmes most commonly fail, and how the US regime compares with the UK, EU, and other export-control systems your business may also be subject to.
What does BIS administer, and why does it govern your compliance programme?
The Bureau of Industry and Security (BIS), acting under the authority of the Export Control Reform Act and the EAR, administers controls on the export, re-export, and in-country transfer of dual-use goods, software, and technology. Its enforcement arm – the Office of Export Enforcement – investigates apparent violations and refers the most serious matters to the Department of Justice for criminal prosecution.
The EAR's reach is deliberately extraterritorial. US-origin items, items manufactured abroad that incorporate US-controlled content above a de minimis threshold, and items produced using certain US technology can all require a BIS licence even when the exporter is based outside the United States. That extraterritorial logic is the reason a European or Asian manufacturer needs a BIS / EAR compliance programme, not just a domestic one. We regularly advise non-US manufacturers who discover mid-transaction that their product carries US-origin content that extends US export jurisdiction over their shipment.
BIS has published detailed compliance guidance – including its "Don't Let This Happen to You" enforcement publication – confirming that a documented, tested compliance programme is treated as a meaningful mitigating factor when it calculates a civil or criminal penalty. Conversely, having no programme, or a paper programme that was never operationalised, can be cited as an aggravating factor. This creates a direct incentive to invest in programme quality.
Step 1 – Establish management commitment and governance
The foundation of any effective BIS / EAR programme is a visible, documented commitment from senior management that compliance is a business priority – not a legal formality. Without that, every subsequent element sits on unstable ground.
In practice, this means a board- or executive-level export-compliance policy statement, a named Export Compliance Officer (ECO) with direct access to leadership, and a governance structure that separates compliance accountability from revenue responsibility. The ECO must have authority to hold a shipment. If a sales team can override an export-hold without compliance sign-off, the governance layer does not exist in any meaningful sense.
What does good governance look like operationally? It means documented escalation paths, a record of compliance decisions, and a defined process for raising internal concerns without commercial pressure. BIS enforcement history – reviewed qualitatively across published summaries of settled matters – consistently shows that firms where compliance was subordinated to commercial teams experienced the most severe outcomes. Governance is not ceremony; it is the programme's immune system.
Step 2 – Conduct a risk assessment and classify your items
A risk assessment for BIS / EAR purposes has two parallel tracks: product classification and counterparty/destination risk. Both must be completed before the first controlled shipment moves.
On product classification: every item, piece of software, and technology the business exports must be mapped to the Commerce Control List. Items that do not fall under a specific ECCN classification are designated EAR99 – a category that carries its own controls for restricted destinations and end-uses, even though it is sometimes misread as "unrestricted." In our experience, EAR99 misunderstandings are among the most frequent sources of inadvertent violations, particularly for finished-goods exporters who rely on a supplier's description rather than an independent classification.
On counterparty and destination risk: the risk assessment must screen against the BIS Entity List (entities subject to licence requirements based on a risk of diversion), the Denied Persons List, and the Unverified List, as well as OFAC's Specially Designated Nationals list (SDN List – OFAC's register of blocked persons and entities, with which US-origin goods must not be supplied). Destinations carry their own licence requirements under the EAR's country-tier system. The risk map should also identify end-use red flags – the indicators of possible diversion that BIS has articulated in its published guidance, such as an intermediary with no apparent commercial purpose or an unusual payment structure.
The risk assessment must be a living document. Product lines change, new distributors are onboarded, and the lists are updated frequently. A static assessment conducted at programme launch will be out of date within months.
Step 3 – Design and implement internal controls
Internal controls translate the risk assessment into operational gates. They are the point at which the programme becomes real for the teams that process orders, issue purchase orders, share technical files, or move goods across borders.
Core controls for BIS / EAR compliance include: a pre-shipment screening procedure against all applicable lists; an ECCN-review gate before any new product is offered for export; an end-use and end-user certificate process for controlled items; a technology-access control for deemed exports (the supply of controlled technology or source code to a foreign national inside the United States, which is treated as an export to that person's country of nationality); and a re-export notification and approval mechanism for distributors.
Deemed exports deserve particular attention. A company that shares controlled engineering drawings with a visiting engineer from a restricted country has made an export under the EAR, regardless of where the files sit. Controls over internal technology access – visitor management, network access controls, and lab protocols – are part of the BIS compliance programme, not solely an IT security matter.
Controls should be documented in written procedures. "We always check" is not a control. A documented, time-stamped, authorised checkpoint is. BIS examiners will ask to see evidence of the control in action, not just the written procedure that describes it.
How does the BIS / EAR programme design compare with OFSI, the EU, and other regimes?
The BIS / EAR programme model – five structured elements with explicit regulatory backing for compliance credit – has influenced programme design under other major regimes, but the specifics diverge in ways that create material compliance risk for multi-regime businesses.
Under OFSI (the UK's Office of Financial Sanctions Implementation), the compliance expectation for financial-sanctions purposes centres on screening and reporting obligations rather than a formally codified five-element structure. OFSI's licensing and enforcement guidance sets out factors it considers in monetary-penalty decisions, and the quality of the recipient firm's compliance programme is among them. However, the UK's Export Control Joint Unit (ECJU) administers export licensing separately from financial sanctions, and the two frameworks have different documentation expectations. A business that builds its programme around BIS standards and assumes ECJU alignment may miss gaps in the UK controls layer.
The EU's dual-use regulation requires Member States to ensure that exporters implement effective internal compliance programmes, but the programme requirements are described at the principles level rather than in the specific five-element terms BIS uses. Implementation varies across Member States and competent authorities. For a business that is simultaneously subject to EAR, OFSI/ECJU controls, and an EU Member State's dual-use licensing regime, a harmonised programme framework that addresses each regime's own compliance expectations is materially more defensible than three separate silos.
In Singapore and Japan, regulators have moved in recent years toward published compliance-programme guidance for strategic goods exporters, broadly reflecting the BIS model. Australia's Defence Export Controls and the DFAT autonomous-sanctions regime each carry compliance expectations that map to the BIS five-element framework at the structural level, even if the legal instruments differ. For businesses with operations across those jurisdictions, alignment to the BIS standard is a defensible baseline – but local verification is always required.
The critical cross-border point is this: where two regimes apply to the same transaction, the stricter prohibition governs. A deal that is permissible under the EAR may still be blocked by OFAC sanctions, or by an EU asset-freeze, or by a destination-country control. The programme must incorporate all applicable regimes, not just the most familiar one.
Step 4 – Training: who needs it, and how often?
Training is the mechanism by which the written programme reaches the people who make daily decisions. It is also the element most often treated as a one-time induction exercise rather than a sustained operational commitment.
BIS compliance training should be tailored to role. The ECO and compliance team need deep technical training on the CCL, licensing exceptions, and enforcement indicators. Sales, business-development, and procurement teams need practical training on the red-flag indicators, the screening process, and what to do when a transaction looks unusual. Finance and treasury teams need to understand payment controls and the OFAC dimension. Technology and engineering teams need training on deemed-export rules and technology-transfer controls. The approach is not uniform across roles, and a single annual e-learning module does not serve all of them.
Training records matter. In a BIS enforcement inquiry, a company that can demonstrate when training was given, to whom, on what content, and with what assessment result is in a materially stronger position than one that cannot. Record-keeping for training is as important as record-keeping for individual licence applications.
The training calendar should be reviewed at least annually and triggered by any material change – a new product line carrying a higher ECCN, entry into a new market, or a significant change in applicable regulations. Training is not a fixed cost; it is a recurring response to a changing risk environment.
Step 5 – Testing, auditing, and the voluntary self-disclosure decision
Testing and auditing close the loop. A programme that is never tested provides management with false assurance and regulators with evidence of failure. In our experience, a programme that undergoes regular internal testing followed by periodic independent audit is one of the most effective tools for identifying gaps before they become enforcement matters.
Internal testing should examine whether controls are working as designed: are screening records being completed, are classification decisions being documented, are technology-access protocols being followed? Testing should be structured, documented, and escalated to senior management. Anomalies should produce corrective-action logs.
Independent audit adds the external dimension. An outside review – whether by external counsel, a specialist compliance firm, or both – brings a perspective unconstrained by internal assumptions about how the programme works. It also produces a documented record of good faith that has direct value in any subsequent enforcement interaction.
When testing or audit reveals an apparent violation, the company faces the voluntary self-disclosure (VSD – a proactive report to BIS or OFAC of an apparent violation, made before the regulator initiates its own inquiry) decision. BIS has published guidance on the voluntary self-disclosure process and treats a timely, well-documented VSD as a significant mitigating factor. The decision to disclose is not automatic. It involves a careful assessment of the nature and scope of the apparent violation, the likely regulatory characterisation, and the strategic implications of disclosure versus non-disclosure. This is not a decision to make without experienced export-control counsel.
Parallel to the BIS VSD process, OFAC has its own voluntary self-disclosure mechanism for sanctions violations. A single shipment can trigger both processes simultaneously. The programmes, timelines, and procedural expectations differ. A coordinated approach – treating both as a single disclosure strategy rather than two independent filings – is materially important to achieving the best available outcome.
Common pitfalls and how programmes fail in practice
What are the patterns that recur across BIS compliance failures? They are remarkably consistent across sectors and company sizes.
The most common is classification drift. An item is classified at launch, that classification is entered into the ERP system, and no one reviews it when the product is modified. Software updates, new firmware, or a revised technical specification can change the applicable ECCN. Companies that treat classification as a one-time exercise rather than an evergreen process accumulate risk with every product revision.
The second is distributor overreliance. An exporter screens its direct customer, obtains an end-user certificate, and ships. The distributor then re-exports to a destination the exporter would never have approved. Without a programme that extends controls downstream – contractual re-export clauses, audit rights, and periodic verification – the exporter remains exposed. Under the EAR, the obligation to control re-export rests, in part, on the original exporter.
Third is the deemed-export blind spot, discussed above. Many companies that are careful about physical exports have never conducted a deemed-export risk assessment. Technology shared in an engineering meeting, on a shared server, or in a development environment is an export if the recipient is a national of a restricted country. The programme must cover this.
A common misconception – and the myth worth correcting directly – is that a large BIS / EAR compliance programme is only necessary for defence contractors or major technology firms. In practice, any business that exports goods with a non-EAR99 ECCN, ships to certain destinations, or operates in sectors with dual-use relevance needs a structured programme. The scale and formality may differ by risk profile, but the elements do not disappear for mid-market companies. We advise clients across size brackets and consistently find that the mid-market exporter with no programme is more exposed, not less, because the regulator sees the absence of programme investment as an aggravating indicator.
If a transaction has already been flagged, or a classification review has uncovered a historical gap, an early review preserves options that narrow quickly. The time between identifying an apparent violation and the moment a regulator does so independently is the window in which the VSD decision, the remediation plan, and the enforcement posture can be set strategically. Contact Calder & Vance at info@caldervance.com for a confidential review.
Related practices
- Sanctions compliance audit and testing – Australia – independent audit and testing of sanctions compliance programmes against Australian regime standards.
- BIS / EAR compliance programme design: advanced topics – deemed exports, technology controls, and multi-regime alignment for complex operations.
- BIS / EAR licensing and exceptions guide – when a licence is required, which exceptions apply, and how to structure a licence application.