A freight forwarder receives a purchase order from a trading company in a third country. The buyer has no obvious connection to a denied party. The goods are commercial electronics with a dual-use classification. The transaction clears a basic name-screen and moves toward shipment. Three months later, BIS issues a temporary denial order naming the trading company as a front for a restricted end-user. The forwarder is now a party to an apparent violation of the Export Administration Regulations.
Counterparty due diligence under the BIS / EAR requires exporters, re-exporters, and in-country transferors to screen against multiple US government lists, examine red flags in the transaction record, and assess the end-use and end-user against the Commerce Control List. The obligation is not satisfied by a single name-screen. As of July 2026, BIS expects an affirmative programme of enquiry proportionate to the risk profile of the item, the destination, and the party.
This guide walks through the procedure step by step, identifies the pitfalls that generate enforcement exposure, and maps the key differences between the BIS / EAR approach and the parallel obligations that arise under OFAC, OFSI, and the EU dual-use rules.
Step 1: Understand what the BIS / EAR due-diligence obligation actually requires
The EAR imposes a positive obligation to avoid facilitating transactions that a party knows, or has reason to know, will violate the regulations. This is not merely a prohibition on transacting with listed parties. It extends to situations where the facts of a transaction – the routing, the payment method, the buyer's profile, the end-use representation – give rise to a reason-to-know standard that BIS and, in criminal matters, the Department of Justice will hold the exporter to.
Three distinct legal pillars frame the obligation. First, the denied-persons and entity-list screening duty: parties on the Entity List (a BIS-maintained list of foreign persons subject to licence requirements), the Denied Persons List (persons whose export privileges have been revoked), or the Unverified List (parties whose bona fides BIS has been unable to verify) require specific attention. Second, the red-flag inquiry duty: where the facts raise a concern, the exporter must seek and verify a satisfactory explanation before proceeding. Third, the end-use and end-user certification requirement: for controlled items, BIS may require documentary assurance about the ultimate recipient and use.
In our cross-border practice, the most dangerous misconception is that clearing the Entity List is sufficient. It is the floor, not the ceiling.
Step 2: Map the item classification before screening the counterparty
Screening a counterparty in isolation – without first understanding what you are exporting – produces systematically incomplete results. The Export Control Classification Number (ECCN, the alphanumeric code on the Commerce Control List that determines the licence requirements for a given item) drives every subsequent step: which licences are required, which licence exceptions are available, and which end-users or end-uses are categorically prohibited regardless of screening results.
An item classified EAR99 (no ECCN: outside the CCL's specific control entries, though still subject to the EAR's general prohibitions) carries a lower compliance burden for most destinations and end-users than a controlled dual-use item. But even EAR99 goods may not be exported to a Tier 1 or Tier 2 embargoed destination, to a party on the Entity List, or for a prohibited end-use such as weapons of mass destruction programmes. Classification therefore sets the risk-tiering for the counterparty review that follows.
Where classification is uncertain, a commodity jurisdiction request (to confirm whether the item falls under EAR or ITAR) or a classification request to BIS may be necessary before the counterparty analysis is meaningful. Skipping this step generates exposure that no amount of counterparty screening can cure.
Step 3: Screen against the required US government lists
The core screening obligation covers at minimum the BIS Entity List, the BIS Denied Persons List, the BIS Unverified List, the OFAC SDN List (OFAC's list of Specially Designated Nationals and blocked persons), the OFAC Non-SDN lists, and the State Department's Debarred List under ITAR. These are distinct databases maintained by distinct agencies; a single consolidated-search tool that covers all of them is the practical minimum for a compliant programme.
Name-matching is the first failure point. Transliteration variants, corporate-name changes, known aliases, and the use of freight forwarders or intermediary companies are all standard methods by which restricted parties insert themselves into a supply chain. Screening must be run on the full ownership chain where practicable, not only the immediate buyer. Where an entity is 50 percent or more owned – directly or through layers – by an SDN, OFAC treats that entity as itself blocked even if it does not appear by name on any list. The same aggregate-ownership logic applies to Entity List restrictions.
Re-screening at the point of shipment, not only at order intake, is material. List positions change. BIS has added parties to the Entity List on short notice in response to specific proliferation or diversion concerns. A counterparty that passed screening at order acceptance may be listed by the time goods reach the port. Shipment without re-screening at that stage is a documented enforcement risk.
Step 4: Assess and respond to red flags
The red-flag doctrine is the part of BIS / EAR counterparty due diligence most frequently under-addressed in standard compliance programmes. BIS has published guidance setting out categories of conduct that should trigger an inquiry. The list is illustrative, not exhaustive, but the recurring indicators in enforcement actions include: a buyer unwilling to provide end-use information or end-user certifications; a purchase order that specifies quantities inconsistent with the buyer's stated business; a routing through a third country with no obvious commercial rationale; payment in cash or through an unusual financial intermediary; a request to omit controlled-goods markings from shipping documentation; and a buyer whose stated business is inconsistent with the technical specifications of the goods ordered.
What does the obligation require once a red flag is identified? The exporter must conduct a reasonable inquiry. That means asking specific questions, documenting the questions, documenting the responses, and making a documented assessment of whether the responses resolve the concern. Where the concern is not resolved to the exporter's satisfaction, the transaction should not proceed. BIS does not require certainty; it requires a documented, proportionate enquiry. In our experience, the absence of documentation is often more damaging in an enforcement context than the underlying fact pattern.
Have you built a red-flag escalation procedure that produces a documented record, or does your programme rely on individual judgment without a paper trail? The difference is significant when BIS or DOJ examines your files.
Step 5: Obtain and verify end-use documentation
For controlled items, the EAR's end-use controls require exporters to secure representations from the importer and, in some cases, the ultimate end-user about the intended use of the goods. The Destination Control Statement is a mandatory export document notation for many controlled items; it places the buyer on notice of US export restrictions and creates a record of the representation. For higher-risk transactions, BIS may require or recommend a Statement of Ultimate Consignee and Purchaser or similar instrument.
Verification is a separate step. A signed certificate is only as valuable as the due diligence behind it. Where the item is high-value, technically sensitive, or destined for a market with elevated diversion risk, exporters should consider whether site visits, third-party verification, or enhanced background checks on the ultimate end-user are warranted. BIS's pre-licence check and post-shipment verification programmes exist precisely because the agency recognises that paper documentation alone is insufficient for the highest-risk transactions.
A party placed on the Unverified List has failed a BIS pre-licence check or post-shipment verification. Transacting with an Unverified List party for controlled items without specific licence authority is itself a red flag that requires resolution before the transaction proceeds. The fact of Unverified List placement means BIS has, on at least one prior occasion, been unable to confirm that the party received a controlled item for the stated purpose.
How does BIS / EAR counterparty due diligence differ from OFAC, OFSI, and EU requirements?
The BIS / EAR due-diligence standard is distinct from the parallel obligations under OFAC, OFSI, and the EU dual-use rules in three material respects: the legal basis for the obligation, the test for constructive knowledge, and the ownership-and-control analysis.
Under OFAC, the primary prohibition is transacting with or for the benefit of a designated person. The ownership test – the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked, regardless of whether the entity is named on any list) – is mechanical. OFAC does not apply a reason-to-know standard to the ownership analysis: if the aggregate direct and indirect ownership by blocked persons meets the threshold, the entity is blocked, whether the exporter knew it or not. This creates strict-liability exposure for otherwise compliant exporters who screen for list matches but do not examine ownership structures.
Under OFSI and the relevant EU regulations, the test incorporates both ownership and control – the ability to direct or influence the entity's decisions. An entity owned below the relevant threshold but controlled by a designated person may still be caught. The practical implication for cross-border exporters is significant: a transaction that passes an OFAC ownership screen may still be prohibited under the UK or EU regime applicable to the same goods or finance.
The EU dual-use regime, operating under EU rules on the control of exports of dual-use items, imposes an obligation on the exporter to exercise due diligence and to decline a transaction where there are reasonable grounds to suspect a prohibited end-use. The standard is comparable to BIS's reason-to-know test in structure, though the specific indicators and the enforcement posture differ. Canada's Export and Import Permits Act and Australia's autonomous sanctions and export-control rules each impose their own end-user and end-use verification requirements, which may apply concurrently where a multinational exporter is incorporated or operating in those jurisdictions.
The practical consequence: a BIS / EAR-compliant due-diligence programme is necessary but not sufficient. For cross-border exporters, the applicable country regime for each jurisdiction of operation must be mapped and the most restrictive standard applied to each transaction.
What are the common pitfalls that generate BIS / EAR enforcement exposure?
Enforcement patterns before BIS and DOJ identify several recurring failure modes. The first is reliance on a single list-screening tool that does not cover all applicable US government lists. A programme that screens only the SDN List – or only the Entity List – will miss parties who appear only on the other list, or who are blocked through the OFAC ownership rule without appearing by name on any list.
The second is the absence of a documented red-flag procedure. BIS enforcement guidance consistently identifies the failure to investigate known red flags as an aggravating factor in penalty determinations. The absence of a written escalation procedure, and of contemporaneous records of the inquiry conducted, removes the mitigating evidence that a well-documented compliance programme would otherwise provide.
The third is the treatment of licence exceptions as self-executing. Many BIS licence exceptions carry conditions – restrictions on the end-user, the end-use, the destination, or the ultimate disposition of the goods. Exporters who satisfy the stated eligibility conditions at the time of export but fail to track post-export requirements (re-export controls, reporting obligations, return requirements) create exposure that begins after the goods have left the country.
The fourth – and in our experience the most underappreciated – is the assumption that due diligence conducted at the intermediary (freight forwarder, distributor, reseller) level is sufficient to discharge the exporter's own obligations. The EAR does not permit an exporter to rely entirely on a third party's due diligence. Where the exporter has reason to know of the ultimate transaction, the obligation runs to the exporter directly.
A myth worth addressing directly: "We are not the manufacturer, so export-control rules are not our concern." The EAR applies to re-exporters and in-country transferors, not only to original exporters. A European distributor re-exporting US-origin goods, or a manufacturer incorporating US-origin components above the applicable de minimis threshold (the percentage of controlled US-origin content above which the EAR follows a foreign-made item), is subject to the same due-diligence obligations as the original US exporter. The origin of the goods, not the nationality of the exporter, is the trigger.
When should you involve export-control counsel in a counterparty review?
The threshold for involving counsel is lower than most compliance teams assume. The cases where specialist input adds the most value are not limited to obvious red flags or enforcement notices – they arise in the pre-transaction structuring phase, where the choice of entity, supply chain design, and documentation approach determine the risk profile of every transaction that follows.
Specific triggers for early counsel involvement include: a counterparty appearing on the Unverified List; a new market entry into a jurisdiction with elevated BIS diversion-risk designation; a corporate acquisition where the target's export history is unknown; a transaction where the end-use representation is implausible given the buyer's stated business; and any situation where the supply chain involves an intermediary whose role in the transaction is commercially unexplained.
In a recent matter, a technology exporter identified a distributor whose purchase history was inconsistent with its stated customer base. We assessed the red-flag indicators against the BIS published guidance, advised on the scope of the enquiry required, and assisted in preparing the documented record of the inquiry. The transaction was restructured to obtain enhanced end-user documentation. No enforcement action followed, and the distributor relationship continued on a more transparent contractual basis.
The position above covers the standard analysis. Your facts – the classification of the goods, the countries in the supply chain, the structure of the counterparty's ownership, and the regimes applicable to each entity in the chain – change the analysis materially.
For an assessment of your counterparty due-diligence programme under BIS / EAR, contact Calder & Vance at info@caldervance.com.
Related practices
- Sanctions compliance audit and testing – structured testing of screening and due-diligence controls against current regime requirements.
- Counterparty due diligence under EU sanctions – step-by-step guide to the EU ownership and control test and the dual-use verification obligation.
- Counterparty due diligence under EU rules: advanced issues – deeper analysis of EU due-diligence obligations for complex supply chains.