Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · BIS / EAR

Name and entity screening under BIS / EAR: a practical guide

A trading company finalises a purchase order for precision optical components. The goods are dual-use. The buyer has passed an initial name check. But has anyone screened the buyer's freight forwarder, the end-user listed in the application, or the intermediate distributor named in the shipping instructions? Under the Export Administration Regulations (EAR – the US Commerce Department's export-control rules administered by the Bureau of Industry and Security, or BIS), each of those parties is a potential restricted-party risk. A single unscreened link in the chain can convert a lawful shipment into a violation.

Name and entity screening under BIS / EAR requires exporters to check all parties to a transaction – not only the buyer – against BIS's own restricted-party lists and against the consolidated US Government screening lists before any controlled item ships, is re-exported, or is transferred in-country. As of July 2026, the primary lists are the Entity List, the Denied Persons List, the Unverified List, and the Military End-User List. A hit on any of them changes, restricts, or may prohibit the transaction entirely.

This guide sets out who must be screened and why, which lists govern, how to structure the screening process, where the analysis diverges from OFAC and other regimes, and the risk flags that should trigger a call to sanctions counsel.

Step 1: Understand who administers BIS / EAR screening – and why it differs from sanctions screening

BIS administers the EAR under authority derived from the Export Control Reform Act, while OFAC administers its separate economic-sanctions programmes under IEEPA and related statutes. The two systems coexist but are not the same. An item that clears an OFAC screen can still be blocked under the EAR, and an OFAC-listed party may not appear on any BIS list – meaning an exporter who runs only an OFAC check is operating with an incomplete picture.

The EAR applies to all items that are subject to US jurisdiction by virtue of their origin, content, or technology. Jurisdiction is item-based, not solely person-based. That is the structural difference that shapes every screening decision: even where a counterparty is clean on every list, the item itself may carry a licence requirement that makes the transaction conditional. In our cross-border practice, exporters frequently conflate OFAC screening with EAR screening, treating a clear OFAC result as a green light for shipment. It is not.

BIS maintains its own restricted-party infrastructure, separate from and in addition to the OFAC SDN List. Each BIS list has a different legal trigger and a different compliance consequence. Understanding that architecture is the starting point for any effective programme.

Step 2: Know which lists apply and what each one means for the transaction

The Entity List identifies foreign persons – companies, research institutions, government bodies, and individuals – against whom BIS has imposed a licence requirement for all items subject to the EAR. A hit on the Entity List means you need a licence, and the policy is generally a presumption of denial. This is not a discretionary flag; it is a hard legal obligation. Exporters who ship without a licence to an Entity List party face civil and, in serious cases, criminal exposure.

The Denied Persons List is narrower and more severe. Persons on this list have had their export privileges revoked by order of BIS. No US exporter, and no party acting on a US exporter's behalf, may participate in any transaction with a denied person. There is no licence route. Involvement in such a transaction is itself a violation, regardless of intent.

The Unverified List is different in character. It identifies parties in respect of whom BIS has been unable to complete an end-use check. Appearance on this list does not impose a licence requirement automatically, but it is a significant red flag. Best practice – and, for many controlled items, a practical requirement – is to obtain a statement from an Unverified List party before proceeding. Absent that statement, shipping to an Unverified List party carries a risk of a deemed knowledge finding.

The Military End-User List captures entities in designated countries that BIS has determined are military end-users for purposes of the military end-user rule. For items controlled by that rule, a licence is required even if the item would otherwise be eligible for a licence exception.

The practical implication is that a compliant programme screens against all four lists – and against the broader consolidated US Government list, which aggregates BIS, OFAC, and other agency lists – before any transaction proceeds.

Step 3: Identify every party who must be screened

The EAR imposes obligations not only in respect of the named buyer but in respect of every party whom the exporter knows, or has reason to know, is involved in the transaction. That language – "knows or has reason to know" – is the operative standard for the knowledge-based controls embedded in the EAR, and it has been interpreted broadly in enforcement practice.

At a minimum, screening should cover: the consignee, the end-user as stated in any end-user statement or application, the freight forwarder, the intermediate consignee, and any financial institution named in the payment instructions. Where a transaction involves a re-export, the chain extends to the foreign intermediate party.

In our experience, the parties most often missed are the freight forwarder and the intermediate consignee. Both appear in the logistics documentation rather than the commercial contract, so they are sometimes outside the scope of the initial commercial-team screen. That gap has produced enforcement referrals. Does your screening process pull from the shipping file, or only from the contract file?

An additional, frequently overlooked category is the beneficial owner of the nominal buyer. The EAR does not have a bright-line ownership test equivalent to OFAC's 50 percent rule (the rule treating entities owned 50 percent or more by blocked persons as themselves blocked). However, the "reason to know" standard means that a buyer majority-owned by a Denied Person or an Entity List party can draw the exporter into liability even if only the nominee entity was screened. Ownership diligence is therefore a component of a complete EAR screening programme, not a separate activity.

Step 4: Design a screening process that catches the patterns screening tools miss

A well-designed EAR screening process has five operational components: list coverage, name-matching logic, periodic re-screening, escalation protocol, and documentation. Each component addresses a distinct failure mode seen in enforcement cases.

List coverage means the screening database queries all relevant BIS lists in their current form. Lists are updated without fixed notice cycles. A programme that subscribes to a consolidated list feed and validates that the feed includes BIS-specific entries is materially stronger than one that relies on a single-source database.

Name-matching logic must account for transliteration variants, aliases, alternate spellings, and name-order differences. The Entity List and Denied Persons List often carry aliases, but a screening tool set to exact-match only will miss them. Fuzzy-match thresholds that are set too low produce alert fatigue; thresholds set too high produce missed matches. Calibrating that setting is one of the more technical and firm-specific elements of programme design.

Periodic re-screening applies to ongoing relationships. A party who was clean at onboarding can be added to the Entity List or Denied Persons List mid-relationship. Many exporters screen at onboarding and not again until the next order arrives. The gap between those two points is where violations occur in long-standing distribution arrangements. We regularly advise clients to introduce automated triggers that re-screen counterparties when list updates are published.

Escalation protocol means that a positive match – or a potential match above the threshold – goes to a named decision-maker with export-control authority, not back to the commercial team that generated the order. Mixing the commercial and compliance functions at the escalation stage is a recognised structural weakness that BIS has noted in enforcement contexts.

Documentation means recording the screen date, the lists queried, the result, the decision taken, and the person who took it. Record-keeping is both a compliance requirement under the EAR and a practical defence in any subsequent enforcement inquiry.

How does BIS / EAR screening differ from OFAC, OFSI, and the EU?

The primary divergence is jurisdictional reach. OFAC sanctions follow the person: a US-nexus transaction with an SDN is prohibited regardless of where the goods originate. The EAR follows the item: a foreign-origin item with no US content or technology is generally not subject to the EAR at all, even if the buyer is an Entity List party. These are distinct legal questions, and conflating them produces errors in both directions.

OFSI and the EU apply an ownership and control test (the UK and EU standard under which an entity may be caught by sanctions if a designated person owns or controls it, without the mechanical 50 percent threshold of OFAC's rule). The EAR has no equivalent ownership threshold, but the "reason to know" standard can reach ownership structures where the beneficial owner is a restricted party. The practical consequence is that a transaction cleared under the EU's ownership-and-control analysis may still require a BIS licence if the end-user is on the Entity List, and vice versa.

Canada's export-control regime and the Australian Autonomous Sanctions scheme each have their own screening lists and licence structures. Where a transaction routes through a Canadian or Australian affiliate, those affiliate entities carry their own screening obligations under their domestic rules. A parent-company screen in New York does not discharge a subsidiary's obligations in Sydney. In our cross-border practice, this is one of the most consistent gaps we identify in group-level compliance programmes.

The UN Consolidated List intersects with BIS screening because OFAC designations frequently implement UN Security Council listings. However, the UN list and the Entity List are maintained on different criteria and by different processes. An entity may appear on one without the other. A programme that assumes alignment between them will have blind spots.

The position above covers the standard multi-regime structure. Your specific goods, routes, and counterparties will alter the analysis – sometimes significantly. If your business spans more than one jurisdiction, the interaction between regimes deserves a dedicated review.

For an assessment of your exposure under BIS / EAR and the applicable parallel regimes, contact Calder & Vance at info@caldervance.com.

What are the risk flags that should trigger escalation to counsel?

Several patterns in transaction or due-diligence data signal a materially elevated risk level. These are not automatic proof of violation, but each one, left unaddressed, has been a feature of enforcement referrals and civil penalty proceedings.

The first is an address, phone number, or email domain shared between the buyer and a known Entity List party. Corporate groups operating across multiple affiliates sometimes share administrative infrastructure. Where a screen returns a close-but-not-exact match and the contact details overlap, the "reason to know" standard becomes engaged.

The second is a stated end-use that is implausible given the buyer's size, location, or sector. BIS's end-use controls target scenarios where the stated civilian end-use masks a military or proliferation application. A small distributor in a market with no identified civil aviation industry ordering avionics components is a scenario that warrants additional verification, not clearance.

The third is reluctance to provide an end-user certificate or a statement of end-use. Legitimate buyers of controlled goods are accustomed to providing such statements. Resistance, delay, or a request to omit the end-user's name from documentation are red flags that the "reason to know" standard is designed to capture.

The fourth is a payment routing that passes through a jurisdiction or financial institution that has no apparent connection to the buyer or the goods. Unusual payment structures in export transactions are among the patterns BIS and DOJ have highlighted in enforcement contexts. Have you mapped the full payment chain against the parties in the shipping documentation?

The fifth is a re-export instruction received after the initial sale. A buyer who requests that goods be forwarded to a third party – particularly one in a country with heightened EAR controls – may be attempting to use the exporter as an unwitting conduit. The EAR's re-export rules mean the original exporter can retain liability even after the goods leave the first buyer's possession.

If a transaction has already been flagged – by a screening hit, a bank query, a compliance-team concern, or a DOJ/BIS inquiry – an early review can preserve options that narrow with time. Contact us at info@caldervance.com to discuss a confidential review.

Common myths about BIS / EAR screening – and the corrected position

The most persistent misconception we encounter is that a clean OFAC screen is sufficient for US export-control compliance. It is not. OFAC and BIS are separate regulatory regimes with separate lists, separate legal bases, and separate enforcement arms. Running one without the other leaves the transaction half-checked at best.

A second widespread belief is that small-value transactions fall below BIS scrutiny. The EAR does not contain a general de minimis transaction-value threshold for the principal licence requirements. Low-value shipments of high-controlled items remain fully subject to the EAR. The de minimis concept in the EAR relates to US-content thresholds in foreign-made items, not to the commercial value of the transaction.

A third myth is that a distributor who buys for resale bears no responsibility for the ultimate end-use or end-user. The EAR's knowledge standard applies to parties in the distribution chain. A distributor who has reason to know that a buyer intends to re-export the goods to a restricted end-user – or who wilfully closes its eyes to that possibility – can face the same liability as the original exporter. Due-diligence provisions in distribution agreements do not transfer the legal obligation; they may reduce, but do not eliminate, exposure.

We have acted for businesses that operated under each of these assumptions and found themselves facing an enforcement inquiry as a result. Early programme design is substantially less costly than a penalty defence.

How Calder & Vance assists with BIS / EAR screening and compliance

Our team works with exporters, distributors, and multinationals at each stage of the EAR screening lifecycle – from initial programme design to response to BIS inquiry.

For businesses establishing or reviewing a screening programme, we assess eligibility for consolidated-list tools, review the name-matching configuration, map the ownership and control chain for key counterparties, and benchmark the programme against the five-element standard used by BIS in enforcement mitigation assessments.

For businesses handling a positive or potential match, we scope the transaction, advise on the applicable licence requirements or exceptions, and assist with the licence application if one is required. Where a transaction has already occurred and a potential violation is suspected, we advise on voluntary self-disclosure (VSD – the process by which a company proactively reports an apparent violation to BIS in exchange for mitigated treatment) and prepare the submission.

For compliance officers designing group-wide programmes, we have particular experience in the interaction between BIS screening obligations and the parallel requirements of OFAC, OFSI, and the EU – ensuring that a group screen covers all regimes without creating duplicative or conflicting procedures.

In a recent matter, a manufacturing business in the electronics sector identified, during an internal audit, that a freight forwarder used across several years of shipments had been added to the Unverified List midway through the relationship. The business had screened at onboarding but had no re-screening trigger. We scoped the apparent violations, advised on the VSD process, and prepared the submission. The matter was resolved without the maximum civil penalty that would otherwise have applied.

Related practices

Frequently asked questions

What are the steps to set up effective screening under BIS / EAR?
Effective BIS / EAR screening has five steps: ensure list coverage across all BIS restricted-party lists and the consolidated US Government list; configure name-matching logic to capture aliases and transliteration variants; establish periodic re-screening for existing counterparties when lists are updated; build an escalation protocol that routes positive matches to an export-control authority rather than the commercial team; and document every screen, result, and decision. All five steps must be in place before a controlled item ships.
What is the most common mistake in name and entity screening?
The most common mistake is screening only the named buyer and not all parties to the transaction. The EAR's "knows or has reason to know" standard reaches the freight forwarder, the intermediate consignee, and the ultimate end-user. A second near-universal error is treating a clean OFAC result as a complete US government screen, without checking the BIS Entity List, Denied Persons List, Unverified List, and Military End-User List separately. Each list has different legal consequences and is maintained independently.
How does BIS / EAR differ from other regimes here?
BIS / EAR screening is item-centric: the legal obligation flows from the nature and classification of the goods, not solely from the identity of the counterparty. OFAC, OFSI, and the EU sanctions regimes are primarily person-centric: the prohibition attaches to who you deal with. The EAR also has no direct equivalent to the EU and UK ownership-and-control test, but applies instead a "reason to know" standard that can reach ownership structures where the beneficial owner is a restricted party. These differences mean that parallel screening across all applicable regimes is the only complete approach.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.