A freight forwarder in Singapore books a consignment for an end-user in a third market. The customer passes the initial name check. Weeks later, the forwarder discovers the buyer's parent appears on the BIS Entity List. The shipment has already cleared. That sequence – compliant on its face, non-compliant in substance – is the pattern BIS enforcement actions turn on.
Name and entity screening under the Export Administration Regulations (the EAR) requires checking every transaction party – buyers, consignees, end-users, and freight intermediaries – against the BIS Consolidated Screening List and related restricted-party lists before a shipment proceeds. A single unscreened hop in the supply chain can expose an exporter to a significant civil penalty, a denial order, or criminal referral to the Department of Justice. The obligation is continuous and does not pause between transactions.
As of July 2026, BIS enforcement activity has extended well beyond US-origin goods to catch foreign-produced items with a sufficient US-content nexus. This guide sets out how to build and run a screening programme that addresses that reach, identifies where the EAR diverges from OFAC, OFSI, and EU obligations, and marks the points at which in-house teams should bring in external counsel.
Step 1: Understand which lists govern EAR screening
BIS administers several restricted-party lists and compliance counsel working under the EAR must address each one, because the consequences of a hit differ between them.
The Entity List is the primary BIS instrument. Parties added to it are subject to a licence requirement for all items subject to the EAR, and licence applications face a presumption of denial in most cases. The Denied Persons List carries a harder prohibition: a denied person is barred from receiving any item subject to the EAR, and US persons are barred from participating in any transaction with them. The Unverified List flags entities whose bona fides BIS has been unable to verify; it triggers heightened due-diligence obligations but does not itself impose a licence requirement. The Military End-User List (MEU List) operates under a licence requirement for specified items destined for listed military end-users in identified countries; the de minimis and foreign-direct-product rules can extend the reach of MEU controls to non-US products.
Alongside these BIS lists, OFAC's Specially Designated Nationals and Blocked Persons List (the SDN List) and the Sectoral Sanctions Identifications List are legally distinct but practically inseparable for any exporter. A party cleared on the Entity List may still be blocked under an OFAC programme. In our experience, exporters who treat BIS and OFAC screening as separate workflows routinely generate false clearances at the BIS stage.
The BIS Consolidated Screening List (CSL) aggregates the Entity List, Denied Persons List, and Unverified List alongside several other government lists. It is the recommended starting point for any compliance programme, but it does not include OFAC lists; those require a separate API feed or subscription service. Running both is not optional.
Step 2: Map every transaction party before the export proceeds
Effective EAR screening covers every party to the transaction, not only the named buyer on the commercial invoice. Exporters routinely under-screen the freight forwarder, the bank financing the shipment, intermediate consignees, and ultimate end-users identified in the order documentation.
BIS applies a know-your-customer standard that requires exporters to look behind a transaction when red flags appear. A buyer unwilling to identify the end-user, a routing pattern inconsistent with the stated destination, or payment instructions running through a jurisdiction with no apparent commercial connection to the goods – each is a red flag that triggers an obligation to investigate before proceeding. Proceeding in the face of an unresolved red flag does not shield the exporter; it can aggravate the enforcement outcome.
The party-mapping exercise should produce a documented list of roles: principal party in interest, consignee, end-user, freight forwarder, and any intermediate agent. Each role maps to the applicable screening list or combination of lists. This mapping should be retained as a transaction record.
For a business operating across both the US and the EU, an important divergence arises at this stage. EU dual-use controls under the relevant Council regulation extend catch-all obligations to exporters who know or suspect that re-export is intended to a restricted destination or end-user. The obligation to investigate the downstream transaction is structurally similar to the BIS red-flag standard. But the lists differ, the thresholds differ, and a party cleared under EU controls may remain restricted under BIS, or vice versa. Running parallel screens is not duplication – it is the minimum required to operate safely across both regimes.
Step 3: Manage name-matching logic and avoid false clearances
Name-matching is where technically compliant screening programmes produce the most operationally dangerous errors. The Entity List and associated BIS lists use transliterated names, aliases, and variant spellings. An automated tool calibrated for exact-match performance will produce false clearances at a rate that creates genuine enforcement exposure.
The core design choice is the fuzzy-match threshold. Set it too high and every transaction generates a false positive queue that overwhelms reviewers. Set it too low and real hits pass as clearances. Neither outcome serves compliance. In our experience, the sustainable calibration point is one that generates a manageable escalation queue – typically achieved by combining a moderate fuzzy threshold with an alias-expansion rule and a minimum-character-match filter to suppress trivial overlaps.
Several additional matching challenges recur in cross-border export transactions:
- Romanisation variants for names originating in Arabic, Cyrillic, or Chinese scripts produce multiple spellings of the same name, each of which must be screened.
- Entity suffixes (LLC, Co., Ltd, GmbH, JSC) are frequently omitted or translated, masking a match with a listed legal entity.
- Addresses: the Entity List sometimes carries an address rather than a registered legal name. Matching on name alone can miss these entries.
- Ownership chains: a non-listed buyer whose ultimate beneficial owner appears on a list requires a secondary layer of screening logic that many automated tools do not apply unless specifically configured.
Compliance counsel reviewing a screening programme should ask: does the tool screen aliases as well as primary names? Does it flag address-based entries? Does it prompt a beneficial-owner inquiry when a transaction involves a privately held entity in a jurisdiction with limited corporate transparency? If the answer to any of these is no, the programme has a structural gap.
The position here under OFAC differs in one important respect. OFAC's 50 percent rule (treating entities 50 percent or more owned by SDN-listed persons as themselves blocked, even without a separate listing) generates an implicit screening obligation that goes beyond list-checking. Under the EAR, the Entity List and MEU List do not carry an equivalent automatic-aggregation rule, but BIS export-control restrictions can reach unlisted entities through the end-use and end-user provisions of the relevant EAR controls. The distinction matters for how a compliance programme is designed.
How does BIS / EAR screening differ from the OFAC and EU approaches?
BIS / EAR screening is item-and-use specific, whereas OFAC screening is primarily person-and-transaction specific. That structural difference shapes the compliance programme at every level.
Under OFAC, if a party is on the SDN List, the transaction is blocked regardless of what is being exported. The goods are irrelevant; the status of the person is the trigger. Under the EAR, the Entity List imposes a licence requirement that is tied to the item: the same listed entity might lawfully receive low-controlled items under an available licence exception while facing a denial presumption for controlled items. This means an EAR-compliant transaction requires not only a party screen but also an item classification check and a licence-exception eligibility assessment – and those three steps interact.
Under the EU dual-use regulation, the control structure is again different. The EU uses a list-based approach combined with catch-all provisions, but the lists themselves – the EU Common Military List, the EU dual-use annex – do not map directly to BIS lists. A party on the BIS Entity List may not appear on any EU restricted list, and vice versa. A business exporting the same product from both a US entity and an EU entity must run two fully parallel programmes and cannot use one output to satisfy the other.
The UK ECJU operates a similar parallel structure. ECJU export licences and the UK Strategic Export Control Lists diverge from both the US EAR and the EU dual-use regime in the specific classifications and end-user undertaking requirements that apply. Post-Brexit, UK controls are maintained as an autonomous instrument and have diverged in several areas from the EU position. For a business with operations in the UK, the US, and the EU, the screening and licensing obligations are additive, not interchangeable.
What does this mean practically? A screening hit under one regime cannot be resolved by clearance under another. Each regime's obligation must be satisfied independently, and a record of each assessment must be retained separately. The timeline for resolving a hit – establishing whether a licence exception applies, filing a licence application, or seeking guidance – also differs between BIS, OFAC, ECJU, and EU competent authorities. Early engagement with counsel across all applicable regimes simultaneously is considerably more efficient than sequential engagement.
What are the risk flags that should escalate to legal review?
Certain patterns in export transactions consistently precede enforcement actions and should trigger mandatory escalation to compliance counsel before a shipment proceeds.
- Last-minute changes to destination or consignee. An instruction to reroute a shipment to a different country or to change the named consignee after order placement, without a credible commercial explanation, is a textbook diversion red flag under the BIS guidelines.
- Requests to omit the item's technical specifications from shipping documentation. BIS classification depends on the accurate description of items; suppression of specifications also affects ECCN determination.
- A buyer in a low-controlled jurisdiction ordering items that appear disproportionate to their stated business activity or local market size.
- Payment routed through a third party or jurisdiction with no apparent nexus to the transaction.
- An end-user certificate that cannot be verified, or a stated end-use that is implausible for the item.
- A screening hit on the Unverified List, which requires a BIS red-flag resolution exercise before the shipment can proceed under most licence exceptions.
In a recent matter, a manufacturing client operating in the semiconductor supply chain identified a distributor on the Unverified List mid-transaction. The client's internal programme had no escalation protocol for Unverified List hits – only a binary clear/block output. We assisted in building a documented red-flag resolution file, engaging with the end-user to obtain satisfactory assurances, and structuring the transaction record to support the ultimate decision to proceed. The matter demonstrated that an Unverified List hit is not automatically a transaction-stopper; it is an obligation to investigate and document.
The position under OFSI in the UK adds a further dimension for businesses with UK operations or UK-person involvement. OFSI's approach to enforcement distinguishes between breaches involving actual knowledge and those involving inadequate due diligence, and the penalty outcome can differ substantially. Where a transaction involves both a BIS screening question and a possible UK nexus, the two enforcement risks run in parallel and should be assessed together.
Step 4: Build the record-keeping and audit trail
A screening result that cannot be produced on demand is, from an enforcement perspective, equivalent to no screening at all. BIS record-keeping requirements apply to all EAR transactions, and the obligation extends to the documentation supporting each screening decision.
The compliance file for each transaction should include: the date and scope of each list check, the version of each list queried (lists are updated frequently and the version consulted on the date of decision is the version that matters), the identity of the person who ran and reviewed the check, the outcome of any fuzzy-match escalation, the rationale for clearing a potential hit, and the licence exception or licence number relied upon. Where a transaction proceeded on the basis of a red-flag resolution, the resolution file should sit within the same transaction record.
For businesses also subject to OFAC requirements, the overlap in record-keeping obligations is useful: a single transaction file structured to meet OFAC's retention expectations will generally also satisfy the EAR's parallel requirements. The key variable is the retention period – verify the current requirement for each regime before relying on any assumption, as the applicable periods differ.
The audit function that reviews these records should be independent of the commercial teams that process the transactions. In our compliance practice, we regularly encounter programmes where the same person who cleared a transaction also signs off the audit of that clearance. That is not an audit; it is a paperwork exercise. BIS compliance reviews treat the independence of the audit function as a structural element of an effective compliance programme.
When should you involve external sanctions counsel?
The question is not whether to involve counsel, but at which stage. Waiting until an enforcement inquiry arrives reduces the options significantly.
External counsel should be engaged before the programme is built or materially upgraded, when a screening hit cannot be resolved by internal review within the available time window, when a transaction involves parties or destinations that carry elevated BIS or OFAC risk, or when the business is entering a new product line that may require fresh Export Control Classification Number (ECCN) determinations. An ECCN error – misclassifying a controlled item as EAR99, or failing to identify that a foreign-produced item is subject to the EAR through the foreign-direct-product rule – is itself an export control violation independent of any screening failure.
When BIS or another authority issues an enforcement inquiry, an information request, or a subpoena, external counsel should be instructed the same day. A voluntary self-disclosure (VSD) – a proactive report to BIS of a possible violation before the agency identifies it independently – is a significant mitigating factor in penalty assessments and is a step that counsel can help evaluate and execute. The window for an effective VSD is not indefinite; it closes when BIS initiates an investigation.
The position above covers the standard case. Your facts – the counterparty, the goods, the route, the classification, and the additional regimes in play – change the analysis. For a confidential review of your current screening programme or a specific transaction question, contact Calder & Vance at info@caldervance.com.
Related practices
- Compliance audit and testing – independent testing of screening logic and programme design across jurisdictions
- Name and entity screening under BIS / EAR: guide 4 – extended analysis of licence exceptions and end-user controls
- Name and entity screening under BIS / EAR: guide 5 – managing enforcement inquiries and voluntary self-disclosure