Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · BIS / EAR

How to assess criminal export-control exposure under BIS / EAR

A logistics manager at a mid-size industrial group receives a request from procurement: ship a batch of precision sensors to a distributor in a third market. The distributor looks clean on screening. The deal closes. Six months later, federal investigators contact the group's US subsidiary. The sensors, it emerges, had an Export Control Classification Number (ECCN – a code under the US Commerce Control List that determines whether an item needs an export licence) requiring a licence. No licence was obtained. The question is no longer whether a compliance failure occurred. The question is how serious the criminal exposure is, and what to do about it now.

Criminal exposure under the Export Administration Regulations (the EAR – the US export-control rules administered by the Bureau of Industry and Security, BIS) arises when a person knowingly exports, re-exports, or transfers a controlled item without the required authorisation, or violates the terms of a licence. The governing statute is the Export Control Reform Act and the implementing authority is BIS, with the Department of Justice handling criminal prosecution. The exposure can be severe: the EAR provides for significant per-violation criminal penalties and custodial sentences, and BIS and DOJ have demonstrated sustained enforcement appetite. As of early 2026, the enforcement posture remains active across both the Entity List and end-use controls.

This guide walks through the assessment process step by step – from initial classification review to voluntary self-disclosure and parallel-regime exposure – so that a compliance officer, general counsel, or exporter facing a potential violation can orient quickly and act before options narrow.

Step 1: Establish what was exported and whether it is controlled

The first question in any criminal exposure assessment is whether the item, software, or technology at issue is subject to the EAR at all, and if so, what controls apply. Most items are classified under an ECCN on the Commerce Control List; items not specifically listed fall under a catch-all designation – EAR99 – which carries fewer restrictions but is not restriction-free.

Classification is not optional, and it is not permanent. An item's ECCN can change when BIS updates the list, when technology evolves, or when the item is bundled with controlled software. In our experience, exporters that classified their product line once at product launch and never revisited it carry the highest classification risk. The first remedial step in any exposure assessment is to pull the current classification record – internal, self-classification, or a BIS commodity-classification determination – and verify it against the current Commerce Control List.

Where classification is genuinely uncertain, a formal commodity-classification request to BIS is available. Submitting one before export is a strong indicator of good faith. Submitting one after a problem is identified still has value as a scope-narrowing tool, though it does not itself extinguish liability.

The assessment must also cover software and technology, not just hardware. Source code, technical drawings, and manufacturing know-how can all be EAR-controlled. Deemed exports – transfers of controlled technology to foreign nationals on US soil – are caught on the same basis as physical shipments. A detailed item-and-data inventory is essential before the full scope of exposure can be known.

Step 2: Identify the applicable licence requirement or licence exception

Once the ECCN is confirmed, the analysis turns to whether a licence was required for the destination country, end-user, and end-use, and whether an applicable licence exception (a standing authorisation in the EAR permitting a defined category of exports without a case-by-case application) was available and properly used.

Licence requirements vary by reason for control – national security, nuclear, chemical and biological, missile, crime control, anti-terrorism, regional stability, and others – and by country classification. Not all destinations carry the same control burden. This is where mapping each shipment to the correct destination group, end-user type, and end-use category becomes critical. A shipment that was licence-free for a civilian buyer in one country may have required a licence for the same item shipped to a different end-user in the same country if that end-user appeared on the Entity List (BIS's list of parties subject to specific licence requirements as a result of activities contrary to US national security or foreign policy interests) or the Denied Persons List.

Licence exceptions have conditions. Using an exception that did not apply – because the destination, end-use, or value was outside the exception's terms – does not constitute an authorisation. It constitutes a violation. In our cross-border practice, we regularly advise on exactly this scenario: a shipment made under an exception that was technically available for the item but not for the specific end-user or quantity. The exposure that follows is treated by BIS as a knowing violation where the internal record shows the relevant conditions were examined and a wrong conclusion was drawn.

The position above covers the standard case. Your facts – the item, the destination, the end-user, the route taken, and the documentation held – change the analysis materially. If you are uncertain whether the licence requirement applied, an early classification-and-authorisation review can clarify the exposure perimeter.

Apparent Violation Assessment (EU) – for cross-regime exposure where EU dual-use controls may also be engaged.

Step 3: Map the knowledge and intent elements

Criminal liability under the EAR requires knowledge. This is the element that most distinguishes criminal exposure from administrative liability, and it is where the internal record becomes decisive.

The EAR's knowledge standard is demanding: it covers actual knowledge that a violation is occurring or will occur, but it also covers conscious avoidance – a deliberate effort to remain ignorant of facts that would otherwise create awareness of a likely violation. BIS and DOJ regularly rely on conscious-avoidance findings to establish criminal intent without a confession or an explicit instruction to evade controls.

What does the internal record show? Did sales or compliance staff receive red flags – an unusual routing, an implausible end-use, a customer who declined to answer end-use questions – and proceed anyway? Were internal queries escalated and then overridden? Were licence exceptions applied without checking the underlying conditions? Each of these patterns is exactly the kind of evidence that prosecutors assemble in export-control criminal cases. The mapping exercise at this step is not about determining guilt; it is about understanding the evidentiary landscape before investigators have the opportunity to map it first.

In a recent matter, a manufacturer of dual-use electronic components faced an inquiry after controlled items reached an end-user whose stated use differed from the contract documentation. We reviewed the internal communication record and identified a series of escalation decisions that, viewed in sequence, created a plausible conscious-avoidance inference. Reframing those decisions in the context of the firm's documented compliance programme – and demonstrating the steps taken when the discrepancy was eventually identified – was central to the voluntary self-disclosure strategy. The matter resolved through the administrative channel rather than criminal referral, though no outcome can be guaranteed.

What is the cross-border exposure picture, and how does it differ from UK and EU controls?

BIS / EAR criminal exposure does not stop at the US border. The extraterritorial reach of the EAR is significant, and any assessment must address it.

Re-exports of US-origin items – and in some cases items containing a defined percentage of US-controlled content, or produced using US technology – are subject to the EAR even when the re-exporting party is a non-US entity. This is the de minimis and foreign-direct-product framework: a European or Asian distributor that re-exports a US-origin controlled item to a restricted destination can face BIS enforcement action, as can the US supplier that enabled the re-export through inadequate end-use controls.

UK controls under the Export Control Order, administered by the ECJU (Export Control Joint Unit), and EU dual-use controls under the applicable EU regulation operate on similar item-classification logic but are not identical to the EAR. Control lists differ. Licence exceptions differ. Enforcement channels differ. A shipment that required a licence under the EAR may or may not require one under the UK or EU regime, and vice versa. The critical point is that compliance with one regime does not mean compliance with another. Any cross-border assessment must map each applicable regime independently.

Canada's export-control regime under the relevant federal statute operates on a comparable licensing model for strategic goods. The risk profile for a Canadian subsidiary re-exporting US-origin items is therefore double-layered: it may face both US EAR exposure and Canadian criminal liability. See the companion guide at Criminal Export Exposure: Canada Guide for an analysis of the Canadian position.

For a wider multi-regime view, the cross-border exposure guide at Criminal Export Exposure: Cross-Border Guide maps the interaction of several regimes simultaneously.

The stricter prohibition governs in practice: where a non-US exporter must comply with both the EAR and its home-regime controls, whichever imposes the higher standard sets the effective compliance floor. This is not a theoretical point. We regularly advise multinational groups on exactly this scenario – where the EAR requires a licence and the home regime does not, or where the home regime's list covers an item the EAR classifies as EAR99.

Step 4: Assess the voluntary self-disclosure option

A voluntary self-disclosure (VSD – a proactive disclosure to BIS of an apparent violation, made before the regulator initiates its own investigation) is one of the most consequential decisions in an export-control matter. Done well, it is a powerful mitigating factor. Done badly, it can narrow the firm's options and confirm facts that BIS would otherwise have had to establish independently.

BIS's enforcement posture treats timely, accurate, and complete VSDs as a significant mitigating factor in penalty calculations. The operative guidance makes clear that incomplete or misleading VSDs can aggravate, rather than mitigate, the penalty. The internal investigation that precedes a VSD must therefore be thorough. Have all the transactions been identified? Has the classification been verified for each? Has the knowledge and intent record been fully examined?

The VSD process runs in parallel with, not instead of, DOJ's criminal enforcement authority. A VSD to BIS does not preclude a DOJ criminal referral. Where the facts disclose significant criminal exposure – repeated violations, conscious avoidance, involvement of senior personnel, connection to a sensitive destination – the VSD strategy must be coordinated with advice on the criminal side simultaneously. This is not a moment to address administrative and criminal exposure sequentially.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. The window between identifying a potential violation and an enforcement action initiating is the period of maximum strategic flexibility.

Step 5: Review the Entity List and denied-party exposure

Criminal exposure under the EAR extends beyond item controls to party-based restrictions. The Entity List imposes specific licence requirements on named parties. The Denied Persons List prohibits all export transactions involving listed individuals and entities. Engaging in any transaction with a denied person – regardless of the item's classification – is a strict-liability violation at the administrative level and a criminal offence where knowledge is present.

The challenge in party-based screening is not the lists themselves but the ownership and beneficial-interest layers behind the named party. A counterparty that does not itself appear on any list may be owned or controlled by a party that does. BIS does not apply an equivalent to OFAC's mechanical 50 percent ownership threshold in exactly the same form, but the EAR's knowledge standard means that a wilful failure to look behind the listed entity creates conscious-avoidance exposure.

Screening programmes that run only the named counterparty against the consolidated denied-party lists, without checking the ownership chain, miss the most sophisticated exposure pattern. In our experience, this is the area where technology platforms and manual processes most frequently diverge: the system flags the first-level entity, but the human review of the ownership register never happens.

Common risk flags and the myth that "it was only one shipment"

A widely held belief among exporters who have identified a single apparent violation is that isolated incidents attract minimal enforcement attention. That belief is not well-founded.

BIS enforcement priorities are not simply a function of volume. A single shipment of a high-control item to a sensitive destination – or a single transaction with a denied party – can attract criminal referral regardless of whether it stands alone in the company's export history. Aggravating factors that BIS's enforcement guidance identifies include the sensitivity of the item, the destination, the end-user, the degree of harm to US national security or foreign-policy interests, and whether the exporter was previously put on notice through a BIS advisory or warning letter. A single violation carrying several of these aggravating factors will be treated far more seriously than multiple minor clerical errors on low-control items.

The common risk flags that, in our practice, distinguish manageable administrative exposure from serious criminal risk are:

  • Controlled items shipped to end-users on or connected to the Entity List or Denied Persons List
  • Transactions routed through third-country intermediaries without end-use verification
  • Classification records that are absent, outdated, or internally contradicted
  • Internal communications showing awareness of a compliance concern followed by a decision to proceed
  • Repeated use of a licence exception whose conditions were not checked on each transaction
  • Deemed exports to foreign nationals working on sensitive programmes without classification review

Any single one of these flags warrants immediate legal review. Two or more together indicate that the exposure assessment cannot wait.

Related practices

Frequently asked questions

What are the steps to assess criminal export-control exposure under BIS / EAR?
The assessment moves through five sequential steps: confirm the item's classification under the Commerce Control List; identify whether a licence was required and whether any exception applied and was properly used; map the internal knowledge and intent record against the EAR's conscious-avoidance standard; evaluate the voluntary self-disclosure option and its interaction with DOJ's criminal authority; and screen the full transaction chain for Entity List and denied-party exposure, including the ownership layers behind named counterparties. Each step can alter the exposure picture materially. Compress or skip any one of them and the assessment is incomplete.
What is the most common mistake in criminal exposure in export-control cases?
The most common mistake is treating the issue as an administrative compliance matter and engaging only administrative counsel, while leaving the criminal exposure unaddressed. Where the internal record shows conscious avoidance, or where the item or destination is sensitive, DOJ involvement is a live possibility. A second common error is submitting a voluntary self-disclosure that is incomplete – because the internal investigation was not thorough enough – which can convert a mitigating factor into an aggravating one. Both errors are avoidable with proper scoping at the outset.
How does BIS / EAR differ from other regimes here?
The EAR's extraterritorial reach – through de minimis, foreign-direct-product, and re-export rules – is broader than most comparable national export-control regimes. UK and EU controls are territorially anchored to the exporting entity's jurisdiction and do not follow US-origin items in the same way. Canada's regime applies its own criminal standards to Canadian exporters, including those re-exporting US-origin goods. The practical consequence for a multinational group is that a single export event can engage two or more criminal regimes simultaneously, each with its own classification logic, knowledge standard, and enforcement authority. Compliance with one regime does not satisfy the others.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.