Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · BIS / EAR

Counterparty due diligence under BIS / EAR: a compliance guide

A trading company finalises a sale of precision components to a distributor in a third market. The buyer has a clean name. No SDN hit, no EU list match. The export licence paperwork looks straightforward. Three months later, BIS issues a notice: the distributor's ultimate parent appears on the Entity List (BIS's list of parties subject to enhanced licence requirements or outright denial of export privileges). The shipment has already arrived. That scenario is not hypothetical – it arises in our practice with regularity, and the cost of missing it is severe.

Counterparty due diligence under the Export Administration Regulations ("EAR") is the process of identifying whether a proposed recipient of US-origin goods, software, or technology is subject to BIS licensing requirements, restricted-party restrictions, or end-use prohibitions before the transaction completes. The governing authority is the Bureau of Industry and Security ("BIS") within the US Department of Commerce. The analysis is not limited to the named buyer: it extends through the ownership chain, the ultimate end-user, and the intended end-use – and it interacts with OFAC financial-sanctions screening, UK ECJU controls, and EU dual-use rules in ways that can trip up even experienced compliance teams.

This guide walks through the key steps, the list architecture, the cross-regime interaction, the most common failure points, and the markers that tell a compliance team it is time to call counsel.

Step 1 – Establish the regulatory baseline: who controls the rules and what do they require?

BIS administers the EAR under the authority of the Export Control Reform Act and the foundational executive instruments that give it force. The EAR governs the export, re-export, and in-country transfer of items on the Commerce Control List ("CCL") and, in certain cases, items not on the CCL at all. Every exporter of US-origin items – and every foreign re-exporter of items with US content above defined thresholds – must apply the EAR before a transaction proceeds.

The counterparty dimension of that obligation has two distinct strands. First, the item strand: what is the item's Export Control Classification Number ("ECCN"), and does that ECCN require a licence for the destination and the end-use? Second, the party strand: regardless of the item, is any party to the transaction – buyer, freight forwarder, end-user, financial intermediary – subject to a party-specific restriction? These two strands run in parallel; a clean item classification does not cure a restricted-party problem.

As of July 2026, the cross-border complexity has increased. BIS has continued to expand the Entity List and to issue Footnote 1 and Footnote 4 designations that carry more restrictive treatment than a standard entry. Any counterparty screening process that treats all Entity List entries the same is already out of date. Verify the current position before relying on prior screening results.

Step 2 – Map the full party chain before you screen

Screening only the named buyer is one of the most reliable ways to miss a BIS problem. The EAR's restrictions follow the item through its entire distribution chain. That means the compliance obligation attaches to the ultimate end-user and, in many structures, to the entity providing the financing or freight.

In practice, this means building a party map before running any database check. The map should identify at minimum: the named buyer or consignee; the ultimate consignee if different; any known or stated end-user; freight forwarders and consolidators with documentary control over the shipment; and any financial intermediary whose letter of credit or payment structure is visible to the exporter. Where the buyer is a corporate entity, the map should extend to beneficial owners at the 25 percent threshold or higher – and, for heightened-risk transactions, to lower thresholds.

Why does beneficial ownership matter under the EAR specifically? BIS applies an end-use and end-user analysis that is fact-sensitive. A clean corporate buyer owned by a listed entity does not itself become "listed" in the automatic way the OFAC 50 percent rule operates – but BIS's end-use controls and the general prohibition on proceeding when there are "red flags" of diversion can make the transaction unlicensable in practice. Ownership information is therefore essential to the red-flag analysis even where it does not trigger a bright-line prohibition.

Step 3 – Run the restricted-party screen across all five BIS lists

BIS maintains five principal restricted-party lists, and each carries different legal consequences. A sound EAR counterparty screen must check all five before a transaction is approved.

  • Entity List – parties subject to licence requirements for specified items, often with a policy of denial. This is the most frequently updated list and the one most commonly missed when a screen is run only against OFAC's SDN List.
  • Denied Persons List – individuals and entities whose export privileges have been denied. Transacting with a denied person is prohibited across the board, regardless of item or destination.
  • Unverified List – parties for whom BIS has been unable to complete an end-use check. Shipping to an unverified-listed party triggers specific due-diligence obligations and often a licence requirement in practice.
  • Military End-User List – entities identified as military end-users in specified countries, triggering licence requirements for a broad range of controlled items.
  • Debarred Persons (State Department) – while administered by the US State Department under ITAR rather than by BIS, a screen that misses debarred persons will miss a significant restriction relevant to many exporters of defence-related items.

We regularly advise exporters who have screened only against OFAC's lists – which is understandable for a financial-institution compliance programme but insufficient for an export-controls context. The party populations on the BIS lists and the SDN List are not the same. Overlap exists but is far from complete. A counterparty that is clean on the SDN List may sit squarely on the Entity List, and vice versa.

Step 4 – Apply the red-flag analysis and end-use assessment

The EAR's red-flag framework requires exporters to investigate when facts give reason to know that an item may be diverted to a prohibited use or an ineligible user. This is a judgment-based standard, not a list-check. It applies even where the counterparty is not on any restricted-party list.

The classic red flags include: a buyer that declines to provide end-use information; a transaction price that is inconsistent with commercial norms for the item; a buyer whose stated business does not match the item's typical application; routing through a jurisdiction that is itself a diversion risk; and payment structures that obscure the ultimate payor. In our experience, it is the combination of two or more soft indicators – none decisive alone – that marks a transaction as requiring escalation before approval.

Where a red flag is identified, the EAR requires the exporter to resolve it before proceeding. That means obtaining additional information, requesting end-use certifications, or declining the transaction. Proceeding without resolving a known red flag – or wilfully ignoring facts that would have surfaced one – is a significant aggravating factor in any subsequent enforcement action. The distinction between a reasonable compliance miss and a wilful violation shapes the entire penalty calculus.

A practical point on end-use certifications: a statement from the buyer that the goods will not be re-exported to a restricted destination or used in a prohibited application is a compliance record, not a guarantee of compliance. But it is also evidence of good faith, and good-faith evidence carries material weight in enforcement proceedings. Documenting the process is not bureaucratic overhead – it is legal protection.

Step 5 – Address the cross-border interaction with OFAC, OFSI, and EU controls

BIS / EAR counterparty due diligence does not exist in a vacuum. For a business with operations or financing in the United Kingdom or the European Union, the same counterparty and the same transaction must be checked against parallel regimes – and a clean BIS result does not cure an OFSI or EU restriction.

The OFAC financial-sanctions overlay is the most immediate: any transaction involving a US-dollar payment, a US correspondent bank, or US-person involvement triggers OFAC jurisdiction, and the SDN List applies to that element of the transaction independently of BIS. A buyer that passes the Entity List check may still have an OFAC-blocked owner. Run both screens; use the same party map for both.

Under UK controls, OFSI administers financial sanctions under the Sanctions and Anti-Money Laundering Act, while the ECJU administers UK strategic export controls. The UK's ownership and control test – which looks at both ownership of 50 percent or more and practical control – can capture entities that OFAC's mechanical 50 percent rule would not reach. That divergence matters when a UK-connected exporter or financier is involved.

EU dual-use rules add a further layer. The EU's controls on dual-use goods apply to EU-resident exporters and, in some circumstances, to re-exports through EU territory. The EU also operates its own restricted-party lists, which do not map cleanly onto BIS lists. An item classified under a specific ECCN for BIS purposes may have a different classification for EU purposes, or may be subject to EU controls that BIS does not apply. The general rule is that the stricter prohibition governs: where two regimes impose inconsistent requirements, the more restrictive one sets the floor for any party subject to both.

For businesses operating in Singapore, Japan, or the UAE, additional national controls layer on top. Singapore's Strategic Goods Control regime, Japan's Foreign Exchange and Foreign Trade Act controls, and the UAE's export-control framework each carry their own restricted-party concepts. In a multi-jurisdiction supply chain, counterparty due diligence is not a single workflow – it is a coordinated process across each applicable regime.

Step 6 – Document the process and retain the records

Under the EAR, exporters are required to retain export-related records for a defined period. A sound counterparty due-diligence programme therefore records not only the outcome of the screening but the process: the date of the screen, the lists checked, the version of the database used, the parties screened, the red-flag assessment, and any escalation decision. Where a compliance officer clears a transaction after reviewing a red flag, that review and its reasoning should be recorded contemporaneously.

Record-keeping has two functions. It is the operational evidence of a working compliance programme – relevant both to licensing applications and to enforcement. And it is the basis for periodic testing: without records, a compliance team cannot audit whether its programme is functioning as intended or identify where screening failures are recurring.

We have acted for exporters who had good policies and poor records. In enforcement proceedings, the absence of records makes it difficult to demonstrate the good faith that can convert a potential wilful violation into a technical one. The investment in record architecture repays itself in direct proportion to how often it is needed.

Risk flags and when to involve counsel

Some situations in an EAR counterparty review require legal analysis, not just compliance process. The following are the markers in our practice that prompt escalation to counsel.

  • A potential match against the Entity List or Denied Persons List that the compliance team cannot definitively clear or reject based on available information.
  • A transaction where the buyer or an intermediate party is unwilling to provide standard end-use information.
  • An ownership chain that includes a jurisdiction on a BIS restricted-country list or an entity with known state-entity affiliations in such a jurisdiction.
  • A transaction involving a technology or software with a dual-use classification where the stated end-use is civilian but the buyer's profile is inconsistent with that use.
  • A prior voluntary self-disclosure or enforcement inquiry that makes the firm's compliance history relevant to how a current decision will be read.
  • A proposed acquisition of or investment in a business that holds export licences or operates in controlled-technology sectors – where BIS counterparty standards apply to the diligence process itself.

The myth our clients most often hold is that BIS enforcement only reaches the largest exporters or the most dramatic diversion cases. That is not accurate. BIS enforcement actions cover a range of company sizes and transaction values, and the emphasis on strict liability in certain EAR contexts means that a technical violation does not require proof of intent. Calling counsel when a red flag surfaces – rather than after a notice arrives – is materially cheaper in every measurable dimension.

The position above covers the standard counterparty screening workflow. Your specific situation – the goods, the buyer's ownership chain, the route, the financier, the regimes in play – changes the analysis in ways that a general guide cannot address.

For a review of your compliance programme architecture, including export-controls screening logic, see our compliance audit and testing service. For counsel on a specific transaction or counterparty concern, contact us directly at info@caldervance.com.

Related practices

If a screen has returned a potential hit, or a transaction has already been flagged by a freight forwarder or bank, an early review preserves options that narrow quickly. Contact Calder & Vance at info@caldervance.com for a confidential assessment.

Frequently asked questions

What are the steps to run counterparty due diligence under BIS / EAR?
The core sequence is: (1) map all parties to the transaction, including ultimate consignee and known end-user; (2) screen each party against all five BIS restricted-party lists and separately against OFAC's SDN List; (3) apply the red-flag analysis to the transaction facts; (4) obtain end-use certifications where required; (5) document every step and retain the records. Where a match or red flag is identified, resolve it before proceeding or involve counsel. The process runs in parallel with any applicable UK ECJU or EU dual-use screening for multi-jurisdiction transactions.
What is the most common mistake in counterparty due diligence?
Screening only the named buyer against OFAC's SDN List and treating a clean result as sufficient clearance for an EAR transaction. This misses the Entity List, the Denied Persons List, the Unverified List, the Military End-User List, and the separate obligation to screen the ultimate end-user and intermediate parties. It also misses the red-flag assessment, which applies independently of any list match. In our experience, this single gap accounts for a disproportionate share of the export-compliance problems that reach counsel after the shipment has departed.
How does BIS / EAR differ from other regimes here?
OFAC applies a mechanical ownership rule: a 50 percent or greater stake by a blocked person makes the entity blocked, full stop. BIS operates differently – ownership of a listed entity does not automatically make a clean buyer restricted, but it is highly material to the red-flag and end-use analysis. OFSI and the EU add a control test on top of the ownership threshold, capturing entities that neither OFAC nor BIS would treat as automatically restricted. Each regime produces a different answer to the same ownership fact; running all three simultaneously, using a single party map, is the only way to catch the full picture.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.