A trading company based in Europe identifies a potential technology buyer in a third market. The goods are dual-use. Before the contract is signed, the compliance team searches the buyer's name against a US denied-party list – but only one list. The shipment is approved. Weeks later, an affiliate of the buyer appears on the Bureau of Industry and Security's Entity List (a list maintained under the Export Administration Regulations, or EAR, of parties subject to specific licence requirements and other restrictions because of conduct deemed contrary to US national security or foreign policy interests). The exporter now faces an apparent violation and a potential enforcement inquiry. The question every compliance officer should have asked first: which lists need to be checked, and how?
Effective entity list and denied-party screening under BIS / EAR requires checking multiple US Government lists – not just the Entity List – against every party to the transaction: the buyer, the end-user, the freight forwarder, the financial intermediary, and any identified beneficial owner. The process is governed by the Export Administration Regulations administered by the Bureau of Industry and Security. As of May 2026, failure to screen completely – or to act on a positive match – can result in the loss of export privileges, significant civil penalties, and, in aggravated cases, criminal referral.
This guide walks through each step of the screening process, identifies where the analysis diverges from other major regimes, and sets out the risk flags that warrant immediate legal review.
Step 1: Understand which US lists govern export-related screening
The BIS / EAR regime is not a single list. It is a set of overlapping restricted-party databases, each with different legal effects, administered by different US agencies, and requiring different responses when a match is found.
The core lists a compliance team must check before any shipment of EAR-controlled goods or technology are:
- The Entity List – maintained by BIS. Parties on this list are subject to a licence requirement for specified or all items subject to the EAR. Licence applications for Entity List parties are typically reviewed under a presumption of denial, though the applicable policy varies by entry. The list identifies the party's name, address, and country – and entries increasingly include aliases and related parties.
- The Denied Persons List – also maintained by BIS. Parties on this list are prohibited from participating in any transaction subject to the EAR. There is no licence route. A hit here stops the transaction entirely.
- The Unverified List – maintained by BIS. Parties whose bona fides BIS has been unable to verify in a prior end-use check. Shipping to an Unverified List party without additional due diligence creates a red flag (a warning sign that, under the EAR's "know your customer" guidance, must be resolved before proceeding).
- The Military End-User List – maintained by BIS. Parties identified as military end-users in specified countries, triggering licence requirements for items that would otherwise be eligible for export without a licence.
- The SDN List – maintained by OFAC, not BIS. But it sits within any defensible denied-party screening programme. Items subject to the EAR may also be controlled under OFAC sanctions. A party blocked under OFAC may be lawfully unreachable under the EAR on independent grounds.
- The Consolidated Screening List – a US Government aggregator that combines BIS, OFAC, and State Department lists into a single searchable database. It is a useful starting point but is not a substitute for direct checks against each source list.
In our experience, compliance teams at exporters unfamiliar with the EAR often focus solely on the Entity List or on OFAC's SDN List, treating either as the whole of the US screening obligation. Neither is correct. Each list has a distinct legal basis and a distinct consequence for a match.
Step 2: Identify every party that must be screened
EAR-based screening obligations extend beyond the direct purchaser of the goods. The EAR's "know your customer" guidance requires exporters to screen – and, where red flags arise, to resolve them – for every party whose participation in the transaction is known or reasonably ascertainable.
At minimum, screen the following:
- The buyer and any named purchasing agent.
- The consignee and any ultimate consignee identified in shipping documents.
- The end-user, if different from the consignee.
- The freight forwarder and any named logistics intermediary.
- The financial institution processing the transaction, where it is identified.
- Beneficial owners of the buyer or consignee, to the extent ownership information is available.
That last category is the hardest. The EAR does not impose the same mechanical ownership threshold that OFAC applies in its 50 percent rule (OFAC's rule treating any entity owned 50 percent or more by one or more blocked persons as itself blocked, regardless of whether it appears by name on the SDN List). BIS does not have an equivalent automatic-aggregation rule. However, where a beneficial owner of the buyer appears on the Entity List or another BIS list, and the exporter proceeds without investigation, that knowledge can be treated as constructive notice of a red flag. Proceeding without resolving it is precisely the conduct the EAR's red-flag guidance is designed to deter.
How well does your current screening programme capture the beneficial ownership layer? This is the question that distinguishes a baseline compliance exercise from one that would withstand a BIS end-use check.
Step 3: Run the search – and document every decision
The mechanics of running a search are straightforward. The outcome of that search – and the record that the search was run – are what determine how a firm fares in any subsequent enforcement inquiry.
Operationally, a defensible screening process includes the following elements:
- Use a current source. Lists are updated without notice. A search run against an outdated local copy of the Entity List may miss a recently added party. Screening tools should pull from the live Consolidated Screening List or directly from BIS's own database, with update frequency documented in your compliance policy.
- Run name variations. Entity List entries can include aliases, but not always every known alias. Transliterations of non-Latin script names are inconsistent. A robust search runs the party's name in its original script and in any common romanisation, plus its legal name, trading name, and any acronym used in commercial documents.
- Screen the address, not just the name. Some Entity List entries share a name with legitimate parties but are distinguished by address or country. Address-level screening reduces both false positives and missed matches.
- Assess partial matches. A screening tool that returns only exact matches is a compliance risk. The standard is whether a reasonable compliance officer, on seeing the potential match, would have investigated further. Document the basis for clearing any near-match.
- Record the date and version of the list consulted. In any enforcement context, BIS will want to know what list was consulted, when, and by whom. A log entry that captures the list version, the search terms used, and the reviewer's name and date is the minimum defensible record.
- Re-screen on material change. A counterparty cleared at onboarding may be listed between contract signature and shipment. Screening should be re-run at each transaction stage where goods or technology are physically or constructively transferred: on order receipt, on licence application (if required), and immediately before shipment.
In a recent matter, a manufacturing exporter had a well-designed screening tool but ran searches only at the point of initial customer onboarding. A distributor added to the Entity List six months into a multi-shipment contract received three further shipments before the listing was detected. The resulting apparent violation required a voluntary self-disclosure process. The documentation gap – no re-screening between shipments – made the disclosure more complex to manage. Timely re-screening would have stopped the third shipment at the point the listing took effect.
Step 4: Assess red flags before clearing a transaction
A clean search result does not end the screening obligation. Under the EAR's red-flag guidance, an exporter cannot proceed where it has knowledge of a fact that suggests the transaction may violate the EAR – regardless of whether the relevant party appears on any list by name.
BIS has published illustrative red flags. They include circumstances such as:
- A buyer who is unfamiliar with the product's specific technical parameters yet has no apparent legitimate use for it.
- A request to ship without standard documentation, or to use unusual routing through a third country.
- Payment terms or routing inconsistent with the commercial relationship.
- A freight forwarder or intermediary in a country not obviously linked to the transaction.
- A request to omit the end-user from the shipping documentation.
The obligation is not to refuse every transaction where a flag arises. It is to pause, investigate, and document the resolution. If the flag cannot be resolved to the exporter's satisfaction, proceeding is legally hazardous – and the EAR's "know your customer" guidance specifically cautions against accepting implausible explanations at face value.
We regularly advise clients on how to build red-flag escalation procedures that are proportionate to the company's export volume and the sensitivity of the items being shipped. A company exporting a single category of low-sensitivity consumer goods to a handful of recurring customers has different operational needs than an advanced-technology manufacturer selling into multiple high-risk markets.
How does BIS / EAR screening differ from OFSI, the EU regime, and other regimes?
The BIS / EAR regime has several characteristics that set it apart from the financial-sanctions screening most compliance teams are already running under OFSI, the EU Council regulations, or OFAC's own IEEPA-based sanctions programmes.
Extraterritorial reach. The EAR controls not only US-origin goods and technology but also certain foreign-made items that incorporate a specified percentage of US-controlled content (the de minimis threshold) and foreign-produced items that are the direct product of US-origin technology or software. A non-US company exporting goods from outside the United States may still need to screen under the EAR if the items trigger these rules. OFSI and the EU Council regulations do not operate through an equivalent product-content test: their reach is primarily jurisdictional and counterparty-based.
List logic. OFSI applies an ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person's ownership or control). The EU regime applies a similar approach. The EAR's Entity List does not work this way: the listed entity is the entry on the list, not its owners. However, the red-flag obligation can effectively require investigation of an unlisted parent or affiliate where the relationship is commercially material.
No equivalent 50 percent rule. As noted above, the EAR lacks the automatic aggregation rule that governs OFAC SDN-related screening. This can create a compliance gap for teams that design their screening programme around the OFAC model and assume it covers BIS exposure.
Licence policy divergence. Under OFSI, a specific licence application is assessed against a set of licensing criteria set out in the applicable regulations. Under the EU dual-use rules, Member State authorities assess applications against a published set of criteria. BIS reviews Entity List licence applications – where licence applications are accepted at all – under a policy that varies by the specific entry. Some entries carry a presumption of denial for all items. Others permit applications for specific categories of items. Knowing which policy applies to a given entry is essential before investing in a licence application.
Canada and Australia. For exporters also operating under Canadian export controls (administered through Global Affairs Canada) or the Australian Defence Export Controls regime, the screening obligation covers different list structures. Canadian controls reference an Area Control List and a Prohibited End-User List. The Australian regime applies export permit requirements by reference to the Defence and Strategic Goods List. Neither operates an equivalent to the BIS Entity List, though both impose red-flag-style obligations. A compliance programme designed for one regime is not automatically adequate for another: the lists, the triggers, and the documentation requirements differ.
The position above covers the standard structure. Your facts – the item's classification, the destination country, the identity of the end-user, and the regimes in play across your supply chain – change the analysis. For a review of your screening programme's cross-regime gaps, contact Calder & Vance at info@caldervance.com.
Step 5: Handle a match – what to do when a party appears on a list
A confirmed match is not automatically the end of a transaction. The required response depends on which list the match appears on, and whether a licence or other authorisation might apply.
For a Denied Persons List match, the response is simple and non-negotiable: the transaction cannot proceed. There is no licence route. Any participation in a transaction by a denied person – as buyer, consignee, freight forwarder, or intermediary – is prohibited. The compliance record should show that the match was identified, the transaction was declined, and the counterparty was notified only to the extent required under the applicable law.
For an Entity List match, the analysis is more nuanced. First, determine whether the item being exported requires a licence by reference to the specific Entity List entry. Some entries impose a licence requirement for all items subject to the EAR. Others cover only items with specified Export Control Classification Numbers. If no licence is required for the item in question – and no other licence-triggering provision applies – the transaction may proceed. If a licence is required, assess whether BIS is likely to grant one under the policy applicable to that entry. Where the entry carries a presumption of denial, a licence application is unlikely to succeed; advising the client to divert the transaction rather than incur the cost and delay of an application may be the more proportionate course.
For an Unverified List match, the options are limited but not closed. The exporter may seek to obtain from the Unverified List party the documentation required to support an end-use certificate and request that BIS conduct a verification. Where that is impractical, the item and destination country should be assessed to determine whether proceeding without verification is legally acceptable. In many cases it is not.
In all match scenarios, document the decision. The record of how the match was assessed, what investigation was conducted, what was found, and what action was taken is the firm's primary protection in the event of a subsequent BIS inquiry or enforcement proceeding.
Step 6: Voluntary self-disclosure and enforcement risk
If a screening failure has already occurred – a shipment has been made to a party that should have been identified as restricted – the question is not whether to act but how quickly.
BIS operates a voluntary self-disclosure programme (a mechanism under the EAR by which a party reports an apparent violation to BIS in exchange for consideration of that disclosure as a mitigating factor in any subsequent penalty determination). The decision to submit a VSD is fact-specific and consequential. A well-prepared VSD can significantly affect the penalty outcome. A poorly prepared one – one that omits relevant transactions, misstates the scope of the apparent violation, or reveals a pattern of systemic non-compliance without proposing remediation – can produce a worse outcome than a BIS-initiated inquiry.
The mitigating and aggravating factors that BIS applies in penalty determinations are published in its enforcement guidelines. Among the factors BIS considers: whether the violation was wilful or reckless, whether the exporter had an effective compliance programme in place, whether the disclosure was prompt and complete, and whether the apparent violation resulted in actual harm to US national security or foreign policy interests.
We have acted for exporters at every stage of this process – from the internal scoping exercise, through the preparation and submission of the VSD, to the negotiation of the penalty outcome. Early legal involvement, before the disclosure is filed, consistently produces better-structured submissions and better outcomes. What a team learns in the first week of an internal investigation often changes the scope and framing of the VSD materially.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.
Common myths about Entity List screening – and why they matter
A persistent myth in export-control compliance is that the Entity List and the SDN List are functionally equivalent – that a firm running OFAC screening has, in substance, covered its BIS obligations. This is incorrect in several respects.
The SDN List is a financial-sanctions instrument. Its primary purpose is to block the assets of listed persons and prohibit US persons from transacting with them. The Entity List is an export-control instrument. It governs the supply of physical goods and technology. The lists are maintained by different agencies, draw on different legal authority, operate different match thresholds, and impose different licence requirements on a hit. An OFAC SDN match and an Entity List match require entirely different response protocols.
A second common misconception is that screening once per counterparty – typically at onboarding – is sufficient. As the example in Step 3 illustrates, lists are updated continuously. A counterparty added to the Entity List after onboarding is a live compliance risk from the date of that addition. Screening at onboarding without periodic re-screening is, in practice, no screening at all for the period after the first check.
A third misconception is that the Consolidated Screening List is a complete and current substitute for direct list checks. The Consolidated Screening List is a valuable resource and a defensible starting point. But its update cadence may lag the authoritative source lists. For high-risk transactions or high-volume exporters, reliance solely on the aggregator – without direct verification – introduces a gap that BIS does not excuse on the basis of a third-party tool's latency.
Related practices
- Deemed Export and Technology Controls under BIS / EAR – advisory on technology transfer, deemed-export licensing, and end-use controls for US-controlled items.
- Entity List Screening under BIS / EAR: Advanced Topics – deeper analysis of red-flag resolution, licence applications, and multi-jurisdiction conflicts.
- Entity List Screening under Canadian Export Controls – guide to the Area Control List and Prohibited End-User List obligations under the Canadian regime.