Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFAC

How to screen against the Entity List under OFAC

A freight forwarder in Rotterdam receives a purchase order from a distributor it has worked with for three years. The goods are commercial electronics with a civil and military application. A junior compliance analyst runs the name through the firm's screening tool. The tool returns no match. Two weeks later, a US-headquartered supplier flags the same distributor as appearing on the Entity List (the US Commerce Control List of parties subject to licence requirements under the Export Administration Regulations). The Rotterdam firm had a clean screen – but it had screened only against OFAC's sanctions lists, not against the BIS lists that govern export controls. These are distinct regimes, administered by distinct agencies, and confusing them is one of the costliest mistakes in cross-border compliance.

Effective entity list and denied-party screening under OFAC and BIS requires checking multiple lists – the SDN List (OFAC's list of Specially Designated Nationals and blocked persons), the Entity List, the Denied Persons List, and the Unverified List – against the full ownership chain of every counterparty, not just the trade name. As of May 2026, these lists are maintained by two separate US agencies under distinct legal authorities. A screen that covers only one agency's lists is incomplete as a matter of law.

This guide sets out the screening procedure step by step, explains where OFAC and BIS diverge, and identifies the risk flags that most commonly produce enforcement exposure for cross-border businesses.

Step 1: Understand which lists govern and why the distinction matters

The first step is mapping the lists that apply to your transaction – because OFAC and BIS operate under different legal authorities and impose different obligations when a counterparty appears on their respective lists.

OFAC administers economic sanctions under IEEPA, TWEA, and related statutes. Its primary tools are the SDN List and the Sectoral Sanctions Identifications List (the SSI List, which restricts specific categories of transactions with certain entities rather than blocking all dealings). A match on the SDN List means the transaction is prohibited absent a licence. OFAC's rules apply to US persons and, through secondary-sanctions provisions, can reach non-US businesses that transact in US-origin goods, US dollars, or with US counterparties.

BIS, by contrast, administers the Export Administration Regulations under the Export Control Reform Act. It maintains the Entity List (foreign parties against whom BIS has determined there is a reasonable risk of diversion to prohibited end uses), the Denied Persons List (parties denied export privileges), and the Unverified List (parties whose bona fides BIS has been unable to verify). An appearance on the Entity List triggers a licence requirement for virtually all items subject to the EAR – including many items that would otherwise be exportable without a licence.

The two regimes are not redundant. A party can appear on the Entity List without appearing on the SDN List, and vice versa. In our experience, businesses that grew up screening for OFAC sanctions routinely underweight the BIS lists. That gap is where enforcement exposure accumulates.

A third layer also applies. The UN Consolidated List, maintained by the Security Council, identifies individuals and entities subject to UN asset-freeze and travel-ban measures. UN designations are implemented through each jurisdiction's domestic legislation. OFAC generally reflects UN designations on the SDN List, but not always simultaneously. Checking only OFAC without also verifying the UN list creates a short window of exposure between international designation and US domestic implementation.

Step 2: Identify every party to the transaction and map the ownership chain

The second step is identifying who you are actually transacting with – which is rarely just the counterparty named on the contract.

Every party to the transaction must be screened: the buyer, the seller, the freight forwarder, the financial institution facilitating payment, the end user, and the intermediate consignees. For goods subject to the EAR, BIS guidance on red-flag indicators makes clear that the end user and the end use are as important as the buyer. A transaction can be clean on its face but problematic if the goods are destined for a prohibited end use or a restricted end user.

Ownership screening is equally critical. Under the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked, even if not separately listed), a counterparty that is majority-owned by an SDN is itself treated as blocked without needing to appear on the SDN List. This rule applies even if the ownership is indirect – layered through two, three, or more intermediate companies. Have you traced the ownership chain to ultimate beneficial owners, or stopped at the first registered shareholder?

The UK and EU regimes apply a similar principle but extend it through an ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person), which can capture entities where effective control exists even below the 50 percent ownership threshold. If your counterparty operates in the EU or UK as well as the US, the control dimension adds a further screening layer that a purely OFAC-focused screen will miss.

At this stage, document your source of information for each party's ownership structure. Record-keeping is a mitigation factor in any subsequent enforcement review – and in our experience the quality of contemporaneous documentation is what separates a resolved matter from a prolonged investigation.

Step 3: Run the screen – and understand what a "hit" actually means

Running the screen correctly means querying each list against each identified party using name variants, transliterations, aliases, and known associated addresses or vessel IMO numbers for maritime transactions.

Automated screening tools are not error-free. False positives – matches that do not correspond to a prohibited party – are common for common names, particularly in Arabic, Chinese, Persian, and Russian transliterations. A false positive that is dismissed without documentation is an analytical gap. Every potential match must be recorded and the disposition reasoned: explain why you concluded the hit did not correspond to the counterparty.

False negatives are the greater risk. A tool that does not query all relevant lists, does not apply fuzzy-matching at an appropriate threshold, or does not check against the current version of each list (rather than a cached version) will produce clean results for parties that are, in fact, restricted. List updates occur frequently. BIS and OFAC both publish list changes in the US Federal Register, but the publication lag means that a real-time API connection to the official lists is the minimum standard for a business with meaningful trade volume.

The position above covers the standard case. Your facts – the counterparty, the goods, the route, the payment currency, and the regime in play – change the analysis. For a preliminary review of your screening architecture, contact Calder & Vance at info@caldervance.com.

Step 4: Evaluate the nature of any confirmed match

A confirmed match does not automatically mean a prohibited transaction. The response depends on which list the match appears on and what the relevant programme permits.

An SDN match in most circumstances means the transaction is prohibited. All property of an SDN must be blocked and reported to OFAC. A specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) is available in defined circumstances, but an SDN match in a commercial transaction rarely results in a licence being granted quickly enough to save a deal. Businesses should treat an SDN match as a stop-transaction event pending legal advice.

An Entity List match is different in structure. The Entity List imposes a licence requirement; it does not automatically prohibit the transaction. For most items subject to the EAR, a licence is required before proceeding. BIS publishes, alongside each Entity List entry, a note on whether any licence exceptions are available. In many cases, the licence review policy is "presumption of denial", which has the practical effect of a prohibition. But the legal mechanism is a licence requirement – not a per se block – and the distinction matters for how you document your response.

A match on the Unverified List triggers a red-flag obligation. The exporter cannot proceed without first taking steps to resolve the unverified status, including seeking additional information about the end user. Proceeding without that resolution creates potential EAR liability.

In our cross-border practice, we regularly advise clients who have received a screening hit and are uncertain whether it is an OFAC matter, a BIS matter, or both. That initial classification determines everything that follows – the legal authority, the potential licence route, and the disclosure obligations.

Step 5: Document, escalate, and decide

A compliant screening programme is only as strong as its escalation and documentation procedure. Every confirmed or potential hit must be escalated to a designated compliance officer or external counsel before the transaction proceeds.

The escalation record should capture: the date and time of the screen, the list and version queried, the exact search terms used, the result returned, the analysis of whether the hit corresponds to the counterparty, and the decision made. If the decision is to proceed, the rationale must be documented and retained. If the decision is to halt, the reason must be recorded and the transaction must not proceed without a licence or a clear legal basis for proceeding.

Record-keeping requirements under the EAR require exporters to retain transaction records, including screening records, for a defined period. OFAC's rules impose separate record-keeping obligations for blocked property reports and related filings. Both sets of requirements run from the date of the relevant action or transaction. In our experience, incomplete records are the single most common gap identified in an enforcement review – not because the transaction was wrongly executed, but because the documentation needed to defend it was not maintained.

If a transaction has already been flagged or a filing has been refused, an early review can preserve options that narrow with time. For a confidential review of a potential screening issue or a compliance gap, contact Calder & Vance at info@caldervance.com.

How does the US screening regime compare with OFSI, the EU, and other jurisdictions?

US denied-party screening sits within a broader international system, and businesses trading across borders must manage the divergences between regimes rather than assuming that a US-compliant screen satisfies parallel obligations elsewhere.

The UK's OFSI administers financial sanctions under SAMLA and the relevant thematic regulations. The UK Consolidated List is distinct from the SDN List; the two lists overlap substantially but do not mirror each other exactly. Post-2021 UK autonomous sanctions have produced a growing number of UK-only designations that do not appear on OFAC's list, and vice versa. A business relying solely on the SDN List is not screening against UK financial sanctions obligations.

The EU maintains its own Consolidated List under the relevant Council Regulations. EU designations are published in the Official Journal and must be screened against by EU-nexus businesses and, in many cases, their non-EU subsidiaries and branches. The EU has adopted a number of autonomous designations that have no US equivalent, particularly in response to recent geopolitical developments across several programmes. A business with an EU subsidiary must screen against EU lists for its EU operations, regardless of whether the US list produces a match.

Singapore (MAS), Japan (METI/MOFA), and the UAE (the relevant national lists) each maintain distinct lists. For a cross-border B2B firm with customers or suppliers in those markets, a multi-list, multi-jurisdiction screening programme is not optional – it is the minimum standard expected by regulators and by counterparty banks conducting their own due diligence. Where a party appears on more than one list, the stricter prohibition governs.

Canada (Global Affairs Canada under SEMA), Switzerland (SECO under its applicable country regime ordinances), and Australia (DFAT's Autonomous Sanctions regime) round out the picture for businesses with operations or counterparties in those jurisdictions. We regularly advise exporters who discover, after establishing their US screening programme, that their EU or UK operations have been running without equivalent controls. Aligning those programmes – and addressing the gaps for the period before alignment – is a recurring matter in our practice.

For a practical comparison of the OFSI screening obligation alongside the OFAC standard, see our related guide: Entity List and Denied-Party Screening Under OFSI.

Common risk flags and when to involve counsel

Certain patterns in a transaction's structure consistently signal elevated screening risk and should trigger an escalation to external counsel before the transaction proceeds.

The first is a counterparty that is newly incorporated or registered in a jurisdiction with a high density of designated parties in the relevant programme. Newly incorporated shell companies with no apparent commercial history are a documented red flag under BIS guidance and OFAC practice guidance alike.

The second is a request to alter the shipping route, use an unusual intermediate port, or change the named end user after the contract is signed. Route changes that move goods through jurisdictions where diversion risk is elevated are a recognised pattern in enforcement matters. This is a detection topic, not an evasion one: identifying these patterns before shipment is the point.

The third is payment in a currency or through a channel that does not align with the commercial relationship. A request to pay through a third-country financial intermediary, or to receive payment in a currency unrelated to either party's home market, is worth examining.

Fourth: discrepancies between the stated end use and the technical specifications of the goods. If a civilian buyer is purchasing goods whose performance characteristics have a clear military utility, the EAR's end-use controls require a closer look, regardless of whether the buyer appears on any list.

Fifth: an ownership structure that is opaque, uses bearer instruments, or involves a trust arrangement where the beneficial owner is not identified. The 50 percent rule applies to indirect ownership; if the ownership chain cannot be traced, the screen cannot be completed.

A common myth among businesses new to this area is that screening a trade name against a single list – typically the SDN List or a commercially licensed database – constitutes a compliant programme. It does not. A compliant programme covers all applicable lists, applies to the full ownership chain of every counterparty, is run against current list data, and is documented at each stage. The consequences of an incomplete programme are not merely administrative: enforcement by OFAC and BIS can produce civil penalties calculated on a per-transaction basis, and in serious cases, criminal referral.

For businesses exporting items subject to the EAR, a related concern is the classification of the item itself. Whether an item requires a licence – and what exceptions may apply – depends on its ECCN (Export Control Classification Number under the US Commerce Control List) and the destination and end-use combination. Screening the counterparty is one half of the export-control compliance obligation; classifying the item correctly is the other half. Our related service covers exactly this point: Deemed Export and Technology Classification Under BIS and the EAR.

For a further look at how these issues play out in a full screening programme, see also: Extended Guide: Entity List and Denied-Party Screening.

Related practices

Frequently asked questions: entity list and denied-party screening under OFAC

What are the steps to screen against the Entity List under OFAC?

Effective screening requires five steps: identify every party to the transaction including intermediate parties and ultimate beneficial owners; check each party against all applicable US lists (SDN List, Entity List, Denied Persons List, Unverified List); apply fuzzy-matching and name-variant logic using current list data; evaluate any confirmed match to determine the legal consequence and whether a licence route exists; and document the entire process and the decision reached. A screen against the SDN List alone is insufficient as a matter of law for transactions subject to the EAR.

What is the most common mistake in Entity List and denied-party screening?

The single most common mistake is screening only against the SDN List while omitting the BIS lists – the Entity List, Denied Persons List, and Unverified List. OFAC and BIS are separate agencies administering separate legal regimes. A clean OFAC screen does not satisfy the EAR's end-user verification requirements. The second most common error is stopping the ownership trace at the first-level registered owner rather than mapping the full chain to ultimate beneficial owners, which is where the 50 percent rule most often produces an undisclosed match.

How does OFAC differ from other regimes here?

OFAC's primary mechanism is a property-blocking obligation triggered by an SDN match: all property and interests in property must be blocked and reported. BIS uses a licence-requirement mechanism: an Entity List match triggers a licence requirement rather than an automatic block. The UK (OFSI) and EU regimes apply similar blocking logic to OFAC but extend liability through a control test that can capture entities below the 50 percent ownership threshold. Non-US businesses should treat their OFAC, BIS, OFSI, and EU screening obligations as parallel and non-substitutable – a match on one list does not predict the position under another.

About the author

Renata Costa advises banks, payment firms, and virtual-asset businesses on sanctions screening, compliance-programme design, and financial-crime controls. Calder & Vance – International Sanctions & Export Control Counsel.

About Calder & Vance

Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.

Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.