A freight forwarder in the Netherlands processes an export request for precision optics bound for a buyer in South-East Asia. The purchase order looks clean. The buyer's name does not appear on OFAC's SDN List. But the buyer is on the US Commerce Department's Entity List (a list of foreign parties subject to additional licensing requirements under the Export Administration Regulations). The shipment proceeds. Within months, the forwarder receives a notice from the Bureau of Industry and Security. The question was never whether the goods were controlled. The question was whether the buyer was cleared.
Entity List and denied-party screening under BIS / EAR guide 2 addresses the full procedural sequence: which lists to check, how to run the match, what a positive result requires, and where the US export-control regime diverges from the UK, EU, and Canadian equivalents. The governing authority is the Bureau of Industry and Security, acting under the Export Administration Regulations and the authority of the Export Control Reform Act. As of May 2026, the Entity List contains several thousand entries and is updated on a rolling basis with no fixed publication schedule.
This guide walks the process step by step – from list identification through match resolution to record-keeping and cross-regime comparison – so that exporters, freight forwarders, and compliance teams can build a repeatable, defensible programme.
Step 1: Identify which BIS / EAR lists require screening
Denied-party screening under the EAR is not a single-list check. It spans at least four distinct lists administered by BIS and related US agencies, each with different legal consequences on a positive result.
The Entity List is the most actively updated. Parties on it are subject to a licence requirement for all items subject to the EAR, regardless of the item's Export Control Classification Number under the Commerce Control List. A licence may be applied for, but BIS applies a policy of denial for most entries – meaning the application route is formally available but practically unlikely to succeed for the majority of listed parties. The Denied Persons List is more absolute: it prohibits any transaction involving a person on it, not merely exports. The Unverified List signals that BIS has been unable to verify the legitimacy of a party through an end-use check; this does not create an automatic licence requirement but raises a red flag that changes the due-diligence calculus. The Military End-User List identifies parties in certain countries that BIS has determined are acting as military end-users, triggering additional controls for specified product categories.
In our experience, the most common screening gap is checking only the Entity List and ignoring the Denied Persons List and Unverified List. These are separate files with different formats and different update rhythms. A programme that reads only one list is not compliant with the EAR.
Beyond BIS lists, the OFAC SDN List and the Consolidated Screening List – which aggregates multiple US government restricted-party lists into a single downloadable file – are relevant to any US-nexus export. A party clear of BIS lists but on the SDN List may still be prohibited under OFAC's distinct sanctions authority. Screening these in parallel, not sequentially, is the correct operational approach.
Step 2: Establish the jurisdictional trigger – when does the EAR apply?
The EAR applies to all items that are "subject to the EAR" – a defined term covering virtually all items of US-origin and a significant proportion of foreign-produced items containing US-origin content or technology above a de minimis threshold, or produced using US-origin technology or equipment under a foreign-direct product rule.
This extraterritorial reach is the feature that most surprises non-US exporters. A German company shipping a semiconductor to a third country may find that the chip falls under the EAR because it was manufactured with US-origin equipment or technology that triggers a foreign-direct product rule. If the buyer is on the Entity List, the German exporter requires a US BIS licence even though it is not a US company, shipping from German territory, with no US counterparty in the transaction.
Jurisdictional analysis therefore precedes list-screening in the correct sequence. Screening a party against the Entity List before confirming that the EAR applies produces a result that is incomplete. The question "is this party listed?" is only relevant if the answer to "does the EAR apply?" is yes. In our practice, we routinely see exporters perform the party check first and the jurisdictional analysis never. That inversion is where exposure starts.
A cross-border angle matters here. The UK's export control regime under the ECJU and the Export Control Order covers UK-origin goods and technology. The EU's dual-use regime under the relevant Council Regulation covers EU-origin items. Neither has a foreign-direct product rule of equivalent scope to the US. A shipment that triggers the EAR through a foreign-direct product rule will not trigger UK or EU export controls on the same basis. These regimes run in parallel, not in hierarchical sequence. Where both apply, the stricter prohibition governs.
Step 3: Conduct the match – methodology and match logic
Running the match correctly is the technical core of a compliant screening programme. An over-narrow match misses hits; an over-broad match produces so many false positives that analysts clear them without proper review – which defeats the purpose of the programme.
The recommended methodology for Entity List screening combines exact-string matching against the listed name with fuzzy-match logic at a calibrated threshold, alias and alternative-name checking (BIS lists multiple aliases per entry where known), address and country matching as a secondary discriminator, and identifier matching where a tax number, company-registration number, or passport number is available. No single field is conclusive. A name match on a common surname without corroborating data points is not a confirmed hit. A company-registration match on its own, where the name is different, warrants investigation rather than immediate clearance.
The Consolidated Screening List published by the US government and available through the International Trade Administration simplifies the aggregation problem by combining BIS, OFAC, and State Department lists in one file. Screening against it does not replace direct checks against the source lists for high-risk transactions, but it is an appropriate starting point for lower-volume programmes. Screening tools used in commercial compliance software typically draw from this file or equivalent data feeds.
What is the correct match threshold? BIS guidance does not prescribe a specific percentage score. Practitioners generally apply a threshold in the range of seventy to eighty-five percent for initial flagging, with anything above that threshold reviewed by a human analyst before clearance. Setting the threshold below seventy percent generates unmanageable false-positive volumes. Setting it above eighty-five percent risks missing variant spellings, transliterations from non-Latin scripts, and deliberate near-name obfuscation. The threshold choice should be documented in the programme's written procedures and reviewed at each programme audit.
Step 4: Resolve a positive result – escalation and the licence question
A potential match – an unresolved hit from the screening step – requires structured escalation before any transaction proceeds. This is where many programmes break down. The match is flagged, a junior analyst compares names and decides they look different enough, and the transaction is cleared without a documented resolution. That is not a defensible process.
Escalation should follow a defined decision tree. First, confirm whether the match is a true positive or a false positive using all available identifying data: full legal name, aliases, address, jurisdiction of incorporation, identification numbers, and, where available, beneficial-owner data. Second, if the match cannot be ruled out as a false positive – that is, if there is residual uncertainty – treat it as a potential true positive and escalate to senior compliance review or external counsel. Third, if the party is confirmed as listed, assess the consequence: Entity List requires a licence; Denied Persons List prohibits the transaction entirely; Unverified List requires enhanced due diligence and may require you to obtain a statement of assurance from the party before proceeding.
For Entity List matches, a licence application to BIS is the formal route. BIS reviews applications against a case-by-case standard, considering the end-use, the end-user, the item, and the destination. For parties where BIS has published a presumption of denial, the licence route remains open in principle but counsel should set realistic expectations. We regularly advise clients on whether to apply, how to present the end-use case, and when the better commercial decision is to disengage from the transaction entirely.
In a recent matter, a manufacturing business in the aerospace-adjacent sector received a purchase order from an entity that appeared – under thorough match analysis – to be associated with a party on the Entity List through a subsidiary relationship. We assessed the ownership chain, confirmed the association, and advised the client to decline the order and document the decision. The matter did not result in an enforcement referral. The early intervention preserved the client's clean enforcement record.
The position above covers the standard case. Your facts – the counterparty, the goods, the route, the regime in play – change the analysis.
For an assessment of your exposure under BIS / EAR, contact Calder & Vance at info@caldervance.com.
Step 5: Apply the ownership and control analysis – affiliated and indirect parties
Entity List screening is not complete when only the direct counterparty is checked. The EAR requires exporters to know their end-user, and BIS enforcement actions have targeted exporters who ignored red flags pointing to an unlisted front company acting for a listed entity.
Unlike OFAC's mechanical 50 percent rule (which treats entities owned at least fifty percent by blocked persons as themselves blocked, regardless of control), BIS does not publish a bright-line ownership rule equivalent. Instead, BIS expects exporters to conduct due diligence proportionate to the risk level of the transaction. For high-risk transactions – high-value items, sensitive technology categories, non-transparent corporate structures, or destinations subject to heightened scrutiny – this means looking through the direct counterparty to identify the ultimate end-user and the beneficial ownership chain.
The UK and EU regimes approach this differently. Under OFSI and the applicable EU Council regulations, an ownership and control test (the UK/EU test for whether a non-listed entity is caught through a listed person's ownership or control of it) extends the prohibition beyond the listed party to entities that a listed person controls. This is a broader and more flexible test than a mechanical percentage rule. A party with forty-five percent ownership by a listed person might escape OFAC's 50 percent rule but still be caught under OFSI's control test if additional board or operational control is present. Cross-border exporters need to apply both analyses simultaneously, not treat them as alternatives.
Canada's export-control regime under the relevant Export and Import Permits Act provisions operates on a similar item-control basis to the EAR but without the foreign-direct product rule reach. Screening against Canada's Area Control List and the relevant restricted-party lists published by Global Affairs Canada is a separate obligation for Canadian exporters. Our guide on entity list screening under the Canadian regime covers that process in detail.
Step 6: Record-keeping, programme documentation, and periodic review
A screening check without contemporaneous documentation has limited value as a compliance defence. BIS expects exporters to retain records of transactions subject to the EAR, and the EAR specifies a five-year record-keeping period. Records should include the screening check itself – the date, the lists checked, the tool or methodology used, the result, and the disposition decision – together with the transactional documents: the purchase order, the export licence or licence exception claimed, the shipping documentation, and any end-use or end-user statements obtained.
Programme documentation is the second element. A screening programme is not a tool; it is a set of written policies and procedures that describe who screens, what they screen against, at what threshold, how escalation works, who authorises clearance, and how the programme is audited. BIS's enforcement guidance treats the existence and quality of a compliance programme as a mitigating factor in penalty determinations. A business with no written programme, or a programme that exists on paper but is not followed in practice, loses that mitigation.
Periodic review is the third element. The Entity List changes frequently – additions, removals, and modifications occur without a fixed schedule. A programme that pulls list data quarterly is not screening against the current list for shipments processed in the intervening period. For active export programmes, daily or at minimum weekly list-data updates are the operational standard. The Unverified List and Military End-User List follow their own update rhythms and must be pulled separately if not included in the screening tool's data feed.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.
How does the BIS / EAR regime compare with the UK, EU, and Canadian equivalents?
The BIS / EAR regime has the broadest extraterritorial reach of any major export-control system in force. Its foreign-direct product rule extends US jurisdiction to goods produced abroad using US technology, tooling, or software. No other regime matches this reach. The UK ECJU, the EU dual-use regime, and the Canadian system are each territorial in approach – they control the export of items originating in, or physically located in, the relevant jurisdiction.
On list structure, the UK maintains a consolidated list of sanctioned parties under OFSI (financial sanctions) and a separate system of export-related controls under the ECJU; there is no direct UK equivalent of the Entity List as a distinct denied-party instrument. The EU maintains a consolidated sanctions list under the relevant Council Regulations and a separate list of controlled items under EU dual-use rules, but again, there is no instrument that precisely mirrors the Entity List's function as a pre-approval requirement for all exports to named parties regardless of item classification.
On the ownership and control question, the divergence is material. OFAC's 50 percent rule is bright-line. OFSI's control test and the EU equivalent are discretionary and fact-sensitive. This creates a zone where a counterparty is blocked under OFSI/EU rules (because a listed person has de facto control below fifty percent) but not blocked under OFAC's rule. Exporters subject to all three regimes must apply each test independently and accept that the answers may differ.
On record-keeping, all major regimes impose a retention obligation, but the periods differ. The EAR mandates five years. Verify the applicable period under each regime before relying on any single retention policy across a multi-regime programme.
On voluntary self-disclosure (VSD – the process of proactively reporting a potential violation to the relevant authority before it comes to the authority's attention through other means), BIS treats a timely VSD as a significant mitigating factor. OFSI and OFAC have similar policies. In our experience, a well-prepared VSD submitted before a referral by a third party can reduce the penalty outcome significantly compared with a reactive response to an enforcement notice. The comparison across regimes is relevant to any exporter with multi-jurisdiction exposure: if a violation may engage both BIS and OFSI, the VSD strategy must be coordinated.
Related practices
- Deemed export and technology controls under BIS / EAR – advisory on technology-transfer licensing and deemed-export exposure for US-controlled items
- Entity list screening under the Canadian regime – step-by-step guide to screening against Canada's export-control and restricted-party lists
- Cross-border entity list screening guide – comparative guide to multi-regime denied-party screening across the US, UK, EU, and Canadian regimes
Common misconceptions about Entity List and denied-party screening
The most persistent myth in this area is that a party clear of the OFAC SDN List is clear for export purposes. This is wrong. OFAC and BIS administer separate regimes under separate statutory authority. A party may be absent from every OFAC list and still be on the Entity List, the Denied Persons List, or the Unverified List. These are not duplicative systems; they address different risks under different legal frameworks.
A second common error is treating screening as a one-time pre-shipment check. For transactions with extended lead times – capital equipment orders, long-term supply contracts, licensed technology transfers – the counterparty's status may change between contract signature and delivery. A party not on any list at signing may be added to the Entity List before the shipment date. A compliant programme rescreens at each material stage of a transaction, not only at the outset.
A third misconception is that the Entity List applies only to technology and defence-related goods. The Entity List imposes a licence requirement for "all items subject to the EAR" destined for a listed party – which covers a broad range of commercial and industrial goods, not only controlled-technology categories. Exporters of apparently routine products need to screen against the Entity List if any item in the shipment is subject to the EAR.
We have acted for clients who discovered, following a transaction, that their counterparty had been added to the Entity List after their initial screening but before shipment. In that situation the options narrow quickly. Early legal review of the facts, the timeline, and the VSD question is essential.