Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · BIS / EAR

How to strengthen mitigation factors under BIS / EAR

An export-compliance officer at a precision-instruments firm receives a letter from the Bureau of Industry and Security. A shipment has reached an end-user whose name appeared on the Entity List. The officer knows the firm will need to respond – but the enforcement outcome, civil or criminal, will depend heavily on factors that were set long before the letter arrived. How strong is the firm's record? Did it self-disclose? Was the violation isolated or systemic? Those answers, assembled into a coherent mitigation package, are what shift a matter from a significant penalty to a cautionary letter.

Mitigation factors in enforcement under the Export Administration Regulations ("EAR"), administered by BIS (the Bureau of Industry and Security within the US Department of Commerce), are the documented conditions that a respondent presents to reduce a civil penalty or avoid a referral to criminal prosecution. BIS weighs these factors against aggravating ones under published enforcement guidelines. The sooner a business starts building this record, the stronger its position.

This guide walks through each mitigation lever in sequence – from the decision whether to file a voluntary self-disclosure ("VSD", a proactive report to BIS of a potential violation before the agency independently discovers it) through to the compliance-programme evidence that sustains the argument in a penalty negotiation. Where the BIS / EAR approach diverges from comparable regimes – OFAC, OFSI, and the EU – the guide flags the difference, because cross-border businesses typically face more than one enforcement exposure at once.

Step 1: Understand what BIS weighs – the mitigation framework

BIS evaluates every enforcement matter against a dual-column scorecard of mitigating and aggravating factors, set out in the published BIS enforcement guidelines under the Export Control Reform Act and IEEPA. Knowing what BIS looks for is the starting point for building a record that actually moves the dial.

The mitigating factors BIS formally recognises include: the existence of a meaningful compliance programme at the time of the violation; a timely VSD; voluntary remedial steps taken after discovery; cooperation with the investigation; the violation being an isolated incident rather than a pattern; the absence of prior violations; and the absence of harm to US national-security interests. Each factor is assessed on the weight of evidence the respondent presents. A bare assertion that the firm "has a compliance programme" carries almost no weight. Documented policies, training records, screening logs, and an honest root-cause analysis carry real weight.

Aggravating factors – deliberate concealment, knowledge of a prohibited end-use, a controlled-country destination, prior violations, and obstruction – sit on the other side of the ledger. Aggravating factors can neutralise strong mitigation. They can also trigger a referral to the Department of Justice for criminal prosecution under the Export Control Reform Act, at which point the civil-penalty process becomes secondary. Understanding which side of the ledger a given set of facts falls on is the first analytical step in every enforcement matter we handle.

Step 2: Decide on voluntary self-disclosure – before discovery

A timely VSD to BIS is the single most powerful mitigation tool available, but it must be filed before BIS independently discovers the violation for the disclosure to carry full mitigating weight. Once BIS has opened an investigation through its own intelligence or a third-party tip, the window for a "prior-to-discovery" VSD has closed.

The VSD process under the EAR has two stages. The initial notification – a brief letter identifying the apparent violation and committing to a full report – is submitted promptly after internal discovery. The full VSD follows after the internal investigation is complete. BIS's published guidelines indicate that a full VSD, submitted in proper form, is treated as a major mitigating factor and can reduce the applicable penalty base substantially. In our cross-border practice, we have seen export matters where a well-constructed VSD was the decisive factor between a no-action letter and a significant civil settlement.

Compare that with the OFAC VSD mechanism: structurally similar, but administered by a different agency with its own guidelines and timelines. A business with both an EAR exposure and a potential OFAC nexus – for example, an export to a country where both export-control and financial-sanctions rules bite – must manage two concurrent VSD processes. Missing the timing requirement in either regime has independent consequences. We regularly advise on coordinating these filings so that the initial disclosures to BIS and OFAC are consistent and neither pre-empts the other.

The position before OFSI in the United Kingdom is broadly analogous: early self-reporting is formally recognised as a mitigating factor in OFSI's enforcement guidance. The EU position is similar in substance, though administered at member-state level rather than by a central enforcement body. The cross-border point is that a cross-jurisdictional matter calls for a coordinated strategy rather than sequential filings managed in isolation.

The position above covers the mechanics. Your facts – the goods, the end-user, the jurisdictions involved, and what your records show – change the analysis materially. For a confidential review of a potential breach, contact Calder & Vance at info@caldervance.com.

Step 3: Conduct a structured internal investigation

The quality of the internal investigation drives the quality of the VSD and determines how credibly the firm can assert the remaining mitigation factors. A credible investigation is documented, scoped by legal privilege where appropriate, and led by people with the authority to reach uncomfortable conclusions.

The investigation needs to answer four questions cleanly. First: what was exported, and what was its ECCN (Export Control Classification Number under the US Commerce Control List)? Second: where did the goods go, and who was the end-user? Third: what licences or licence exceptions were applied, and were they correctly applied? Fourth: how did the failure occur – was it a process breakdown, a training gap, a data error, or a deliberate decision?

The root-cause analysis is not incidental. BIS specifically recognises remediation of root causes as a mitigation factor. A firm that identifies a process gap and closes it before the enforcement process concludes is in a materially better position than one that simply reports the facts and waits. Document every remedial step: updated screening procedures, revised end-use certificate requirements, additional training records, and any disciplinary or structural changes made in response to the violation.

Scope the investigation carefully. Over-scoping – reviewing five years of global exports when the apparent violation is a single shipment – creates discovery risk. Under-scoping – failing to follow the trail where it leads – undermines the credibility of the "isolated incident" argument. In a recent matter, a manufacturing business initially scoped its investigation to the flagged transaction. When we mapped the export-classification history for the product line, two further shipments with the same mis-classification emerged. Bringing those to BIS proactively in the VSD, rather than waiting for BIS to find them, preserved the full VSD credit and positioned the matter as a compliance failure rather than a pattern of knowing violations.

How does a strong compliance programme affect the penalty assessment?

A demonstrably effective compliance programme at the time of the violation is a named mitigating factor in BIS's enforcement guidelines, and it can do more than reduce a penalty: it supports the "isolated incident" narrative and distinguishes a firm that made a genuine error from one that operated without controls.

What does BIS expect a meaningful EAR compliance programme to look like? The agency's own guidance points to five core elements: management commitment and dedicated resources; regular risk assessment across the export portfolio; written policies and procedures calibrated to the firm's specific risk profile; training that is documented and tested; and an audit and monitoring function that catches errors before they become violations. Each element needs evidence, not assertions.

The compliance record that matters most is the one that existed before the violation. A programme retrofitted after discovery carries far less weight, though even post-violation remediation is recognised as a mitigation factor. Firms that invest in periodic export-compliance reviews – mapping their Commerce Control List classifications, reviewing licence exceptions, and testing screening logic – build the record that supports the mitigation argument before they ever need it.

BIS takes a qualitative view: a small exporter with proportionate, well-documented controls can fare better than a large firm with an elaborate but poorly implemented programme. We have acted for businesses of both types. The common denominator in successful mitigation arguments is specificity – not "we have a compliance programme" but "here is the written procedure, here are the training records, here is the audit log that should have caught this and did not, and here is how we have fixed that gap."

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Write to Calder & Vance at info@caldervance.com to discuss the position.

What risk flags can undermine an otherwise strong mitigation package?

Several patterns reliably damage mitigation arguments regardless of how well the rest of the package is assembled. Identifying them early – ideally before the VSD is filed – allows a respondent to address them honestly rather than have BIS surface them during the investigation.

The first risk flag is evidence of prior knowledge or red-flag awareness. If internal communications show that someone in the organisation flagged a concern about the end-user, the destination, or the classification, and the concern was overridden without documented analysis, BIS will treat that as knowledge of a violation rather than a good-faith error. Red flags that were raised and dismissed are more damaging than red flags that were never raised at all, because they show the control environment identified the risk and the organisation chose not to act.

The second risk flag is inconsistency between the VSD narrative and the contemporaneous documents. If the VSD describes a process breakdown but the shipping files show that the applicable licence-exception condition was deliberately noted and then applied to ineligible goods, the inconsistency will be identified. Every factual claim in the VSD must be traceable to a document or a witness statement that can withstand scrutiny.

The third risk flag is scope creep during the BIS investigation. Once BIS opens a formal investigation, it may request records beyond the initially disclosed transactions. Firms that have not conducted a thorough internal review before the VSD sometimes find that the investigation surfaces additional violations. A second wave of apparent violations, discovered by BIS rather than disclosed by the firm, converts a mitigation credit into an aggravating factor. This is precisely why the internal investigation must be scoped and conducted rigorously before the VSD is finalised.

A fourth pattern we observe repeatedly: over-reliance on automated screening without human review of ambiguous results. Screening systems generate hits and misses. A system that was set to pass a counterparty through because it matched only at a low confidence threshold is not a defence if the end-user was in fact listed. BIS expects a firm to have screening procedures that are periodically tested and calibrated. An unreviewed screening log with known anomalies is a liability, not an asset.

Cross-regime comparisons: where BIS / EAR diverges from OFAC, OFSI, and the EU

Businesses facing an EAR enforcement matter rarely face only an EAR matter. The same underlying transaction – an export of controlled goods to a restricted destination – can trigger OFAC sanctions prohibitions, UK OFSI obligations, and EU Council-regulation requirements simultaneously. The mitigation frameworks across these regimes are broadly aligned in principle but diverge in significant procedural respects.

The most practically important divergence concerns the VSD mechanism. Under the EAR, the two-stage process (initial notification, then full VSD) is well-established. OFAC operates a similar process but applies its own specific guidance on what must be included in the initial notification and the full report, including transaction data, the apparent regulatory provision violated, and the corrective steps taken. The assessment of whether a VSD credit applies is made by OFAC independently of BIS. A business that submits a BIS VSD and assumes that credit flows to any parallel OFAC exposure is making a dangerous assumption.

Under OFSI in the United Kingdom, voluntary reporting is a formal mitigating factor in OFSI's published enforcement guidance. The timing and content requirements differ from both OFAC and BIS. OFSI's enforcement guidance explicitly addresses the weight given to reporting promptly, cooperating fully, and taking remedial steps. For a cross-border business with a UK nexus to the same transaction, a coordinated reporting strategy that addresses both BIS and OFSI on a consistent factual basis is essential.

The EU position is more distributed: enforcement of EU sanctions and dual-use export-control violations takes place at the member-state level, so the mitigation framework varies by jurisdiction. Some member states have developed detailed enforcement guidance comparable to BIS's; others operate with significantly less transparency about how mitigation is assessed. For EU-nexus matters, we work with local counsel in the relevant jurisdiction to map the applicable mitigation factors under national enforcement practice. Our service page on EU apparent-violation assessment sets out how we structure that analysis.

The practical lesson for cross-border businesses is this: run the mitigation analysis across all potentially applicable regimes before filing anything. Disclosures made to one agency that are inconsistent with the facts presented to another create credibility problems that are very difficult to recover from.

For comparison of how the same mitigation levers operate under Canada's export-control regime, see our guide on mitigation factors under Canada's export-control rules. For a cross-regime overview spanning multiple jurisdictions, our cross-border mitigation factors guide addresses the coordination question directly.

Common myths: what does not work as mitigation

One persistent myth in export-control enforcement is that an absence of criminal intent converts any civil violation into a minor matter. It does not. The EAR imposes strict civil liability for many provisions: a violation can result in a substantial civil penalty regardless of whether the exporter knew the goods were controlled or knew the end-user was restricted. Intent matters to the aggravating-factor analysis and to the criminal-referral decision; it does not determine whether a civil violation occurred.

A related myth is that a compliance programme, however thin, is automatically a mitigation credit. BIS assesses the quality and implementation of the programme, not its existence. A one-page export-compliance policy, unsupported by training records, screening logs, or any evidence of management engagement, will be characterised as nominal. In our experience, nominal programmes sometimes fare worse than no programme at all, because they suggest the firm was aware of its obligations but chose not to invest in meeting them.

A third myth: that cooperating with a BIS investigation requires producing everything BIS requests without legal review. Cooperation is a mitigation factor; it is not a waiver of legal rights. A business is entitled to understand the scope of any production request, to assert privilege over communications with counsel, and to engage legal representation before responding to agency inquiries. Cooperation does not mean unconditional disclosure; it means timely, complete, and accurate responses within the appropriate legal boundaries. Framing cooperation correctly – not resisting, not waiving privilege unnecessarily – is one of the practical decisions that experienced enforcement counsel earn their place in a matter.

Related practices

Frequently asked questions

What are the steps to strengthen mitigation factors under BIS / EAR?
The steps run in sequence: first, assess whether the apparent violation has been independently discovered by BIS; second, decide on a VSD and file the initial notification promptly; third, conduct a structured internal investigation covering classification, end-user identity, licence-exception eligibility, and root cause; fourth, document the compliance programme that existed at the time; fifth, implement and record remedial steps before the enforcement process closes; and sixth, coordinate any parallel OFAC, OFSI, or EU reporting on a consistent factual basis. Each step should be managed under legal privilege where possible.
What is the most common mistake in mitigation factors in enforcement?
The most common mistake is filing a VSD without first completing a thorough internal investigation. Firms that submit an initial notification and then discover additional violations during the BIS investigation lose the disclosure credit for those further matters. A second frequent error is treating a compliance programme as a check-the-box exercise: BIS assesses the quality and implementation of controls, not their nominal existence. Documented training records, tested screening logs, and root-cause remediation are what distinguish meaningful mitigation from assertion.
How does BIS / EAR differ from other regimes here?
The BIS / EAR enforcement framework is distinguished by its two-stage VSD process, its published dual-column mitigation and aggravating-factor structure under the Export Control Reform Act, and the potential for BIS to refer matters to the Department of Justice for criminal prosecution. OFAC operates a broadly analogous process but applies its own independent guidelines. OFSI in the UK recognises voluntary reporting as mitigation under separate guidance. EU enforcement runs at member-state level and varies by jurisdiction. For cross-border matters, a coordinated multi-regime strategy is essential.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.