Calder & Vance International Sanctions & Compliance Counsel

Cross-Border Transactions & Diligence · BIS / EAR

Sanctions due diligence in M&A under BIS / EAR: a practical guide

A mid-market technology acquirer is three weeks from closing. Its counsel flags that a target subsidiary exports dual-use components to a distributor network spanning several continents. Nobody has run a BIS classification review. Nobody has checked the Entity List (the Bureau of Industry and Security's list of parties subject to enhanced export-licensing requirements) against the target's customer base. The deal pauses. Penalty exposure crystallises. As of January 2026, buyers that inherit undisclosed export-control violations under the Export Administration Regulations ("EAR") face successor-liability risk that no indemnity clause fully covers.

Sanctions due diligence in M&A under BIS / EAR requires a structured review of the target's export classification, its restricted-party screening records, its licence history, and the ownership chain of its key counterparties – all conducted before signing and, where findings warrant, before closing. The EAR applies to US-origin goods, software, and technology regardless of where the transaction closes. A buyer that fails to identify a violation before close may inherit it.

This guide walks through each phase of a BIS / EAR M&A diligence engagement, identifies the cross-regime issues that most frequently surface, and explains when specialist export-control counsel should be instructed.

Step 1: Scope the BIS / EAR exposure before the data room opens

The first task in any BIS / EAR diligence engagement is to determine whether the target's products, technology, or software are subject to the EAR at all – and if so, to what degree. This scoping work happens before the data room opens, ideally during preliminary due diligence or immediately after a letter of intent is signed.

The EAR covers US-origin items and items that incorporate a controlled US-content threshold above the applicable de minimis rule. It also reaches foreign-made items produced using certain US technology or software, through what practitioners call the foreign direct product rule ("FDPR"). For an acquirer of a non-US company, the FDPR question is frequently the biggest surprise in the room. A European or Asian target that has never applied for a US export licence may still be selling items that require one.

At the scoping stage, the diligence team should confirm: the target's country of incorporation and the countries where it manufactures; the categories of goods, software, and technology it produces or re-exports; whether any US-origin inputs or US technology licences are embedded in those products; and whether the FDPR could extend US jurisdiction to any part of the portfolio. This exercise takes days, not weeks – but skipping it means the rest of the diligence programme may be aimed at the wrong targets.

In our experience, acquirers underestimate how far the EAR reaches. The de minimis calculation and the FDPR analysis require input from both legal and technical teams. Where the target is a technology business with embedded US-licensed components, this scoping phase regularly reshapes the entire deal timeline.

Step 2: Classify the target's items against the Commerce Control List

Once EAR jurisdiction is established, the next step is to verify the target's ECCN (Export Control Classification Number under the US Commerce Control List) for each product, software package, and technology transfer in scope. Classification errors are among the most common findings in M&A export-control diligence.

The Commerce Control List assigns ECCNs based on technical parameters: the item's function, performance thresholds, and controlled characteristics. An ECCN determines which licence exceptions apply, which countries require a licence, and which end-use and end-user controls are triggered. A target that has been classifying items as EAR99 (items subject to the EAR but not listed on the CCL and not requiring a licence for most destinations) when they should carry a specific ECCN has been exporting without the licences those shipments required.

The diligence team should obtain the target's existing classification records and work product, assess the methodology used, test a sample of classifications against current CCL parameters, and flag items where the classification appears unsupported or outdated. Where the target has relied on customer-provided classifications or informal self-classifications without technical backup, that is a red flag. Reclassification may be needed, and prior shipments may warrant a voluntary self-disclosure assessment.

What happens when reclassification reveals that significant shipment volume was under-controlled for years? The answer is not always to walk away. It is to assess the actual destinations and end-users against BIS licensing policy, quantify the apparent violation period, and decide whether a VSD (voluntary self-disclosure to BIS) before or after closing produces the best outcome for the combined entity. We regularly advise buyers on exactly this sequencing question.

Step 3: Screen the target's counterparties against restricted-party lists

Restricted-party screening in a BIS / EAR diligence engagement covers more than the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). BIS maintains its own lists – the Entity List, the Denied Persons List, and the Unverified List – each carrying different legal consequences.

A shipment to a party on the Entity List typically requires a licence where none would otherwise be needed. A transaction with a Denied Person is prohibited. A party on the Unverified List triggers enhanced end-use check requirements before shipment. The target's screening programme may have addressed OFAC lists comprehensively while treating BIS lists as secondary or optional. That gap creates undetected exposure.

The diligence team should obtain the target's screening records for a meaningful lookback period, assess the lists screened, test the screening logic against current BIS list versions, and map the target's significant customers and distributors against all relevant lists. Where the target operates in distribution channels – selling through intermediaries rather than directly to end-users – the end-user verification records become a separate and important focus. Has the target obtained end-user statements or certificates for shipments to higher-risk destinations? Are those statements filed and retrievable?

Cross-regime analysis is essential here. A customer that appears clean on BIS lists may still be subject to OFAC designation, EU restrictive measures, or the UK's consolidated list administered by OFSI (the Office of Financial Sanctions Implementation). For a target with customers across multiple jurisdictions, the screening review must cover all regimes in which the combined entity will operate. A buyer already maintaining an OFAC-compliant screening programme should not assume it will capture BIS-specific restrictions – the lists are maintained separately and the obligations differ.

Step 4: Review licence history, exceptions, and compliance records

A target's licence history reveals both its level of compliance sophistication and the extent of its regulated export activity. This step is often treated as routine paperwork review. It should not be.

The review should cover all export licences applied for and obtained during the lookback period, all licence exceptions relied upon and the records supporting each, any BIS agency communications including commodity jurisdiction requests or advisory opinions, and the target's internal export-compliance programme documentation. An effective export compliance programme typically addresses: a written policy and procedures manual, a training regime, a classification and licensing decision process, a screening programme, record-keeping systems, and an audit and remediation cycle. Gaps in any of these elements are findings.

Record-keeping obligations under the EAR require retention for a specified period, and those records must be producible on demand. Where the target has incomplete or disorganised records, the diligence team cannot reliably conclude that licences were obtained when required. That uncertainty has to be reflected in the deal structure – whether through an escrow, a price adjustment, or representations and warranties that allocate the risk appropriately.

One issue that surfaces repeatedly in our practice: targets that relied on licence exceptions correctly at one point but continued to use the same exception after regulatory amendments had changed the applicable conditions. The EAR is updated regularly. A licence exception that applied without restriction several years ago may now carry conditions or destination restrictions that were not there when the target first built its compliance procedures around it. Verify currency; do not assume.

The position above covers the standard case. Your facts – the products, the destinations, the customer base, the volume of regulated activity – change the risk picture materially. For an assessment of your BIS / EAR exposure in a live transaction, contact Calder & Vance at info@caldervance.com.

Step 5: Assess the ownership chain for entity-level sanctions and control questions

Export-control diligence and sanctions diligence overlap most directly in the ownership and control analysis. Under the EAR, the question is whether a target – or its significant counterparties – are subject to BIS restrictions that flow from ownership or control by a restricted party. Under OFAC rules, the separate question is whether any entity in the chain is blocked through the application of the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked).

These analyses run in parallel but are not identical. The OFAC 50 percent rule is mechanical: aggregate ownership of 50 percent or more by blocked persons triggers automatic blocked status, regardless of whether the entity itself is listed. The EU and UK regimes add a control test alongside the ownership test. An entity that a designated person controls – through contractual rights, board influence, or operational dependence – may be caught even where the ownership percentage is below threshold. Where the target has investors or key customers in jurisdictions subject to multiple overlapping regimes, both tests must be applied.

In a cross-border M&A context, the ownership review must cover the target's own ownership structure (to ensure the target is not itself a restricted party or owned by one), the ownership structure of material customers and distributors (to assess whether the target has been supplying restricted parties without knowing it), and the ownership structure of key suppliers (particularly where US-origin technology flows the other way). This last point is frequently overlooked. If the target sources critical inputs from a supplier whose ultimate beneficial owner is a designated person, that supply chain may be compromised for the combined entity.

Step 6: Identify risk flags and structure the deal accordingly

By the end of steps one through five, the diligence team should have a clear picture of what was found and what it means for the deal. The findings now need to be translated into deal-structure decisions. This is where export-control counsel and transaction counsel work together.

Common findings and their deal implications include the following. Where the target has a pattern of classification errors on a contained product line, a pre-closing VSD to BIS may be the right step – but the timing, scope, and disclosure content require careful preparation. Where screening gaps have produced shipments to potentially restricted parties, the buyer needs to assess whether any of those shipments constitutes an apparent violation and whether the facts support a favourable outcome on a VSD or a penalty defence. Where the target has open licence applications or outstanding agency queries, closing around those open matters creates uncertainty that should be addressed contractually.

If a transaction has already been flagged, or if a filing has been refused, an early review by export-control counsel preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss a confidential review.

Structuring tools available to buyers include: representations and warranties specifically addressing EAR compliance and BIS list screening; escrow or price holdback arrangements sized to the estimated remediation and penalty exposure; pre-closing undertakings requiring the target to remediate specific findings before close; and post-closing integration plans that bring the target's compliance programme to the buyer's standard within a defined period. None of these structures eliminates the risk, but they allocate it and document the buyer's good-faith response to the findings.

A practical decision sequence: if findings are minor and isolated, proceed with enhanced representations and a post-closing integration plan. If findings are significant but remediation is feasible pre-close, negotiate a pre-closing undertaking and timeline. If findings are material and the target cannot credibly remediate before close, consider whether a VSD before close, a price adjustment, or an extended escrow adequately covers the exposure. If findings suggest knowing or systematic violations, the risk calculus changes fundamentally and specialist enforcement-defence counsel should be engaged.

Cross-regime comparison: where BIS / EAR diligence diverges from OFAC, EU, and UK

BIS / EAR diligence differs from OFAC sanctions diligence in three important ways that every compliance counsel managing a cross-border deal should understand.

First, the trigger is different. OFAC sanctions are primarily about who the counterparty is. BIS / EAR controls are primarily about what is being transferred – the goods, software, or technology – and where it is going. A transaction can be OFAC-clean and still require a BIS export licence. Conversely, a transaction that requires OFAC attention may not raise any EAR classification issue if the items are not EAR-controlled.

Second, the jurisdictional reach differs in important ways. OFAC's secondary-sanctions provisions extend to non-US persons in certain circumstances, creating exposure for businesses that never touch US soil. The EAR reaches non-US items through the FDPR, but the trigger is technical – it requires that the item was produced using US-origin technology or software above a threshold or on specific production equipment. The FDPR analysis requires technical input that most sanctions-only diligence programmes are not designed to provide.

Third, the enforcement and disclosure routes differ. OFAC's voluntary self-disclosure programme operates under a framework that is separate from BIS's VSD process. The two processes differ in how they are structured, the mitigation credit they provide, and the agencies involved. A business facing apparent violations under both OFAC and the EAR may need to manage two parallel disclosure processes, each with its own requirements. EU and UK enforcement mechanisms add further divergence: the EU General Court offers an annulment route for designation challenges, and OFSI has its own licensing and enforcement guidance with deadlines and penalty bases that differ from both OFAC and BIS. Where a cross-border deal implicates multiple regimes simultaneously, each programme must be assessed on its own terms.

Our practice regularly sits at exactly this intersection. We assess BIS / EAR exposure alongside OFAC, OFSI, and EU considerations in a single, coordinated engagement – which is often both faster and more cost-effective than separate workstreams run by different counsel.

Related practices

Frequently asked questions

What are the steps to run sanctions diligence in a deal under BIS / EAR?
A BIS / EAR M&A diligence engagement runs in sequence: scope EAR jurisdiction and FDPR exposure; classify the target's items against the Commerce Control List; screen the target's counterparties against BIS lists (Entity List, Denied Persons List, Unverified List) and OFAC lists; review the target's licence history, exceptions relied upon, and compliance programme; map the ownership chain for restricted-party connections; and translate findings into deal-structure decisions – representations, escrow, pre-closing remediation, or a voluntary self-disclosure. Each step should be completed before the next begins, because earlier findings reshape the scope of later work.
What is the most common mistake in sanctions due diligence in M&A?
The most common mistake is treating BIS / EAR diligence as an extension of OFAC screening – running the target's counterparties against the SDN List and considering the export-control review complete. BIS maintains separate lists with separate legal consequences. Classification review, licence-exception verification, and end-user documentation are distinct obligations that OFAC-only screening does not address. A second common error is limiting the restricted-party screening to direct customers, when the greater risk often sits one or two layers deeper in the distribution chain or in the target's supplier base.
How does BIS / EAR differ from other regimes here?
BIS / EAR diligence is item-led rather than counterparty-led: the primary question is whether the goods, software, or technology being transferred require a licence, not only who is receiving them. The EAR also extends through the foreign direct product rule to non-US items produced using US technology – a jurisdictional reach that OFSI and EU regimes do not replicate in the same way. The BIS voluntary self-disclosure process operates separately from OFAC's programme and has its own structure and mitigation framework. EU and UK regimes apply their own ownership-and-control tests and licensing routes, so a cross-border deal requires each regime to be assessed on its own terms.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.