A trading company sources components from a third-country supplier. Export-control screening flags one of the supplier's shareholders as appearing on a restricted-party list maintained by the US Department of Commerce. The question arrives on a compliance officer's desk: is the supplier itself a restricted party? Can the shipment proceed? And what happens if the answer is wrong?
Under the Export Administration Regulations (the EAR, administered by the Bureau of Industry and Security, BIS), there is no single codified "50 percent rule" equivalent to OFAC's ownership test. BIS uses a family of lists – principally the Entity List and the Denied Persons List – and the prohibition runs to the named party itself. Ownership analysis enters the picture when a business must determine whether a transaction involves, directly or indirectly, a listed entity or whether an unlisted entity is effectively the same as a listed one. As of mid-2026, that analysis draws on a combination of BIS list-entry terms, end-use and end-user controls, and, for transactions that also carry sanctions exposure, the separate OFAC ownership test. The two regimes do not map onto each other cleanly.
This guide sets out how ownership and control analysis works in the BIS/EAR environment, where it intersects with OFAC's 50 percent rule, and what steps a compliance team should take before it approves a transaction.
Step 1 – Understand what BIS lists control and why ownership matters
BIS list restrictions attach to the named party and, through the terms of a list entry, to certain transactions with that party. The restriction is not automatically inherited by affiliated entities in the mechanical way that OFAC's ownership rule operates. An entity that owns, or is owned by, a listed party is not automatically restricted simply by virtue of that relationship.
Why does ownership analysis matter, then? Several reasons. First, BIS entry terms frequently prohibit exports, re-exports, or transfers "for use by" or "for the benefit of" the named entity. A transaction routed through an unlisted affiliate can still violate those terms if the beneficial end-user is the listed party. Second, the licencing conditions in end-use certificates and end-user statements require accurate identification of the true recipient. Third, where a target or counterparty is subject to both BIS restrictions and OFAC designations – which is common in overlapping enforcement environments – the OFAC 50 percent rule (the rule treating entities owned 50 percent or more in the aggregate by blocked persons as themselves blocked) will apply to the sanctions dimension of the transaction, independently of BIS list analysis.
In our experience, the most frequent compliance error is treating BIS and OFAC as a single unified system. They are parallel regimes with different triggers, different lists, and different ownership logic. Conflating them produces both false positives that stall legitimate trade and false negatives that expose a business to enforcement.
Step 2 – Run a structured restricted-party check against BIS lists
The first operational step is a methodical screen of all parties to the transaction against the BIS lists that carry legal effect under the EAR. The principal instruments are the Entity List, the Denied Persons List, and the Unverified List. Each has different consequences. A match on the Entity List generally requires a licence for any item subject to the EAR destined for that party. A match on the Denied Persons List prohibits participation in any export transaction. The Unverified List indicates that BIS has been unable to verify the end-user; it triggers enhanced due diligence rather than a flat prohibition.
Screen every party in the transaction chain: the buyer, the freight forwarder, the intermediary, the end-user named in the order documentation, and any financial institution routing payment. Ownership is relevant here in two ways. If the end-user is an unlisted subsidiary of a listed parent, the licence requirement may still apply depending on the terms of the parent's entry. And if a party is not yet listed, an awareness that the transaction may violate the EAR – sometimes framed as "red flags" in BIS guidance – can trigger liability regardless of list status.
Is your screening tool pulling from a current version of each list, or from a vendor database with a refresh lag? The currency of the screen matters. BIS updates its lists without a fixed publication schedule.
Step 3 – Map the ownership and control chain of any flagged party
Once a screen produces a potential match or a red flag, map the ownership and control structure of the flagged entity before making a clearance decision. This is where the analysis becomes closest to what practitioners call "ownership analysis" in the OFAC sense, though the legal standard differs.
For BIS purposes, the question is not whether the flagged entity owns 50 percent of the counterparty or vice versa. The question is whether the transaction involves the listed entity, directly or indirectly, having regard to the entry terms and the end-use and end-user conditions. That requires tracing the corporate chain to establish who controls the goods once delivered, who benefits from the transaction, and whether the listed entity sits anywhere in that chain as a meaningful economic participant.
Collect the following for each entity in the chain:
- Ultimate beneficial ownership registers and corporate filings from the jurisdiction of incorporation
- The ownership percentage of each intermediate holding company, with source documents
- Any contractual control rights that could make a nominally independent entity a conduit for the listed party
- Indicators of operational control: shared management, shared premises, intercompany loans, common customers
Where the OFAC dimension is also in play – because the listed BIS entity is also an OFAC-designated party, or because the counterparty has shareholders on the SDN List – apply the OFAC 50 percent rule separately and in parallel. Under OFAC, the test is mechanical: if blocked persons own 50 percent or more in the aggregate, directly or indirectly, the entity is treated as blocked regardless of whether it appears on any list. That threshold and that aggregation logic are specific to OFAC and do not translate to BIS list analysis.
How does BIS / EAR differ from OFAC, OFSI, and EU ownership tests?
The BIS/EAR regime and OFAC are both US instruments, but they apply materially different ownership logic. OFAC's rule is a bright-line numerical test: 50 percent or more aggregate ownership by blocked persons equals a blocked entity, full stop. BIS does not apply that same automatic extension. The prohibition follows the list entry and its specific terms, not a universal ownership formula.
The divergence becomes practically significant in M&A and supply-chain due diligence. A target company may have a corporate parent that is an OFAC-blocked entity but is not itself on any BIS list. Under OFAC, the subsidiary is blocked. Under BIS, the subsidiary may not be independently subject to licence requirements unless the end-use terms of the parent's entry, or a separate red-flag analysis, draw it in. Equally, an entity on the BIS Entity List is not automatically an OFAC-blocked party; it does not follow that dealings with it are frozen-assets violations.
The UK regime administered by OFSI applies an ownership and control test (the combined test that catches entities owned or controlled by designated persons). The EU Council regulations apply a comparable standard. Both are broader than OFAC's purely numerical threshold in one respect – control, not just ownership percentage, can suffice. Both are also separate from BIS/EAR, which has no extraterritorial ownership extension of that type.
For a business with operations or counterparties that intersect with EU or UK sanctions as well as US export controls, the practical consequence is that a transaction may be clear under BIS/EAR while simultaneously blocked under OFSI or the relevant EU regulation. The stricter prohibition governs. We regularly advise clients who have cleared a transaction under one regime without checking the others – and discovered the problem only when payment is blocked or a shipment is refused.
The position above covers the standard cross-regime question. Your specific facts – the goods, the classification, the counterparty structure, the route – change the analysis materially.
For an initial assessment of your exposure under BIS/EAR and the intersecting sanctions regimes, contact Calder & Vance at info@caldervance.com.
Step 4 – Assess end-use controls and red-flag obligations
Even where ownership mapping does not reveal a listed entity in the chain, BIS imposes end-use and end-user controls that operate independently of list status. The EAR prohibits exports, re-exports, and transfers where the exporter knows – or has reason to know – that the transaction is destined for a prohibited end-use or end-user. "Reason to know" is an objective standard.
BIS publishes guidance on red flags: indicators that a transaction may not be what it appears. Ownership and control red flags include:
- A purchasing entity that appears to have no legitimate commercial use for the goods
- A request to route payment or delivery through an entity unconnected to the stated end-user
- A buyer who is reluctant to provide end-user documentation or who names an end-user in a jurisdiction that is a known transshipment risk
- A corporate structure that places the ultimate beneficial owner outside the stated jurisdiction without a credible business reason
Where red flags are present, the compliance obligation is to inquire further and to decline or pause the transaction until the red flag is resolved. Proceeding with unresolved red flags – even where no BIS list match exists – can constitute a violation. Ownership analysis is therefore not only a list-matching exercise; it is also an input into the reasonable-inquiry standard that BIS applies in enforcement.
Step 5 – Determine whether a licence or exception applies
Where ownership or end-use analysis indicates that a licence is required, the next step is to establish whether a licence exception under the EAR applies or whether a specific licence application to BIS is necessary. Licence exceptions are categorical permissions that eliminate the need for a case-by-case application when defined conditions are met. Their availability depends on the item's Export Control Classification Number (ECCN – the alphanumeric code that places an item on the Commerce Control List and determines which controls apply) and on the destination, end-user, and end-use.
An entity on the Entity List is typically subject to a licence requirement with a case-by-case review policy or a policy of denial. Licence exceptions are generally unavailable for Entity List parties unless the entry specifically indicates otherwise. A specific licence application is therefore usually the only formal route. BIS processes applications under a case-by-case standard; timelines vary and are not fixed by regulation in a way that the current registry confirms with precision, so treat any vendor's quoted timeline as an indication only and verify the current position before relying on it.
Where the OFAC dimension is also live, a BIS licence does not substitute for OFAC authorisation. The two authorisations are separate requirements. Obtaining one without the other leaves the transaction exposed on the uncovered side.
Step 6 – Document the analysis and establish ongoing monitoring
BIS requires exporters to retain export-control records. The applicable record-keeping period under the EAR is five years from the date of the export, re-export, or transfer. That requirement covers the classification records, the end-user statements, the screening results, the ownership analysis, and any licence or licence-exception determination. Documentation that cannot be produced in an enforcement review is not documentation that protects the business.
Ownership and control structures change. A shareholder may be designated after a transaction closes. A corporate reorganisation may move an entity under the control of a listed party. Ongoing monitoring of counterparties is not a compliance luxury; it is a baseline expectation in BIS enforcement guidance and, under OFAC's rules, it is a precondition for catching a situation where a non-listed party becomes blocked mid-contract.
Establish a monitoring cadence suited to the risk level of each counterparty. High-risk counterparties – those in sectors of concern or jurisdictions of concern – warrant more frequent re-screening than established customers in low-risk sectors. Where a counterparty's ownership structure is opaque or changes materially, repeat the full ownership-mapping exercise rather than relying on the original clearance.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.
Common risk flags and the objection we hear most often
A persistent misconception in cross-border compliance is that the BIS 50 percent rule and the OFAC 50 percent rule are the same thing with the same consequences. They are not. BIS does not apply a mechanical aggregate-ownership threshold that extends list treatment automatically to affiliates. Compliance teams trained on OFAC sometimes apply OFAC logic to BIS screening – and either over-block transactions that BIS does not prohibit or, conversely, miss the OFAC analysis entirely because they have satisfied themselves on the BIS side.
A related risk: assuming that a clean restricted-party screen is a complete clearance. It is the starting point. An entity can be clean on all published lists and still be a prohibited end-user because of red flags, because of the beneficial-use terms of a related entity's entry, or because the goods are destined for a prohibited end-use. Ownership analysis must sit alongside, not inside, the list check.
A third risk flag is incomplete aggregation. Even where BIS does not apply OFAC's 50 percent aggregation rule, the OFAC dimension of the same transaction does. Where two OFAC-blocked persons each hold minority stakes in the counterparty, they aggregate for the OFAC test. A screen that checks each shareholder individually without aggregating them will miss the threshold. In our practice, this is one of the most common gaps we find in financial-institution screening programmes and in trade-finance compliance reviews.
What does your ownership-tracing process look like past the first layer? If the answer is "we rely on the counterparty's self-certification," that is a gap that BIS enforcement and OFAC enforcement have both identified as inadequate.
Related practices
- Sanctions compliance audit and testing – stress-testing your programme against current BIS and OFAC standards
- 50 percent rule ownership analysis – further BIS/EAR guidance – extended practitioner notes on classification and end-use controls
- Cross-border ownership analysis across sanctions regimes – comparing OFAC, OFSI, and EU ownership and control tests in one transaction