Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · BIS / EAR

Name and entity screening under BIS / EAR: procedure and pitfalls

An exporter in the electronics sector prepares to ship a consignment of items classified under the Export Administration Regulations (EAR – the US Commerce Department's principal export-control instrument, administered by the Bureau of Industry and Security (BIS)). The freight forwarder flags a name match on the buyer's agent. Is the agent on the BIS Entity List? Is it a denied person? Does the match reach the level of a true hit, or is it a false positive generated by transliteration? These questions must be answered before the shipment leaves the dock – and the window to answer them correctly is short.

Name and entity screening under the BIS / EAR is a mandatory pre-transaction step for any US-origin goods, technology, or software subject to the EAR. It requires checking prospective parties against the BIS Entity List, the Denied Persons List, the Unverified List, and the consolidated screening lists published by the US government. A confirmed hit prohibits the transaction unless a licence is obtained or an exception applies; an unresolved false positive can delay or kill the deal just as effectively. As of July 2026, BIS has continued to expand its controlled-party lists, making systematic, documented screening a baseline compliance obligation, not an optional refinement.

This guide walks through the screening procedure step by step, identifies the lists that matter and why, explains how BIS / EAR screening diverges from OFAC, UK OFSI, and EU approaches, and flags the pitfalls that repeatedly produce enforcement exposure.

Step 1 – Identify which parties require screening and which lists apply

Effective BIS / EAR screening begins before a transaction is structured, not after it is signed. Every party in the transaction chain who will receive, re-export, or use the item is in scope – the end-user, the purchaser, the intermediary, the freight forwarder, and any named consignee.

The BIS-administered lists that must be checked are distinct in scope and consequence. The Entity List (EL) identifies foreign entities for which BIS has determined there is a reasonable risk of diversion to prohibited end-uses; exporting to a listed entity typically requires a licence with a presumption of denial. The Denied Persons List (DPL) names individuals and companies whose export privileges have been revoked; no transaction involving a denied person, in any capacity, is permitted. The Unverified List (UVL) identifies entities whose bona fides BIS has been unable to verify through end-use checks; shipments to UVL parties require the exporter to obtain a UVL statement and, if that is refused, the party must be treated as a red flag requiring licence review. Beyond BIS's own lists, the Office of Foreign Assets Control (OFAC) SDN List (Specially Designated Nationals and Blocked Persons) must also be checked, because OFAC and BIS prohibitions operate in parallel and independently. A party can be on one list but not the other – or on both.

The US government's consolidated Consolidated Screening List (CSL) aggregates several of these lists and the OFAC SDN List into a single API-accessible resource. Many exporters use the CSL as a first pass. That is a reasonable starting point, but it is not a substitute for understanding which individual list generated a match and what the legal consequence of that match is. In our experience, compliance teams that screen only against the CSL without understanding the list-by-list logic are poorly placed to handle a hit correctly.

Step 2 – Match logic and the false-positive problem

A name match generated by a screening tool is not a confirmed hit; it is the beginning of an analysis. The match-logic question – how similar does a name need to be to require further review? – is one of the most practically difficult in export-control compliance.

BIS and OFAC do not publish a single prescribed algorithm for name-matching. Exporters must therefore adopt a documented, risk-calibrated approach to their matching thresholds. Set the threshold too tight (requiring an exact character-by-character match) and the screen will miss transliterations, aliases, and spelling variants. Set it too loose and the volume of false positives becomes operationally unmanageable, training staff to dismiss alerts rather than investigate them. That habituation is itself an enforcement risk.

Aliases matter. Entities on the Entity List and the SDN List are identified by known aliases, dates, addresses, and in some cases identifiers. A screening tool that checks only the primary name and misses the alias field produces structurally deficient results. Does your current screening configuration check every alias field on each list? If the answer is uncertain, the programme needs testing.

The treatment of transliterations is a particular pressure point for exporters dealing with counterparties whose names originate in Arabic, Chinese, Cyrillic, or other non-Latin scripts. Transliteration variants across romanisation standards can produce names that look different but identify the same person. Robust screening programmes hold a table of known variants and apply fuzzy matching calibrated to the script family involved. They also document that calibration so that, in an enforcement review, the exporter can demonstrate the logic of the match decision.

Our practice regularly advises clients that a voluntary self-disclosure (VSD – a report submitted by the exporter to BIS to disclose an apparent violation) is complicated when the underlying match decision is undocumented. BIS's enforcement guidance treats the quality of a compliance programme as a mitigating factor in penalty decisions. A match process that cannot be explained in writing is not a mitigating factor – it is a gap.

Step 3 – Investigate the hit and apply the party-type analysis

Once a plausible match is identified, the next step is not to stop the shipment immediately – it is to investigate whether the match is a true positive and, if it is, to determine which list the party appears on and what consequence follows.

For Entity List hits, the consequence depends on the item's Export Control Classification Number. A licence requirement generated by an Entity List designation applies to all items destined to that party that are subject to the EAR and require a licence to that destination, but it also applies to any item – including items otherwise licensable under a licence exception – when the exception is not available to EL parties. The entity-level licence requirement overrides standard exception availability. This is a common source of error: exporters assume that because an item qualifies for a No Licence Required designation to a given country, it can move freely to an EL entity in that country. It cannot, where the EL entry specifies otherwise.

For Denied Persons List hits, the analysis is simpler but the consequence is absolute. No US person, and no person abroad acting with the knowledge that a denied person is a party, may participate in the transaction. There is no licence pathway for a denied person. The transaction must stop.

For Unverified List hits, the exporter must obtain a written statement from the party confirming certain end-use assurances. If the party refuses or fails to respond within a reasonable period, BIS's guidance treats that refusal as a red flag requiring licence review before the export may proceed.

In a recent matter, a trading company in the industrial equipment sector discovered mid-transaction that its agent's parent company appeared on the Entity List. The item in question was subject to a licence exception that the EL entry had specifically removed as available to that entity. We reviewed the classification, confirmed the licence requirement, assessed eligibility for a specific licence, and prepared the application. The transaction was restructured around a compliant route. No shipment moved until authorisation was confirmed.

How does BIS / EAR screening differ from OFAC, OFSI, and EU screening?

BIS / EAR screening and OFAC sanctions screening are legally distinct processes administered by separate agencies under separate legal authorities, but they interact in practice and must be run simultaneously for any export transaction involving US-origin content.

The critical structural difference is this: OFAC's asset-freeze rules apply to the property of designated persons regardless of the type of goods involved. BIS controls apply to specific items – goods, software, technology classified under the Commerce Control List (CCL) – regardless of whether the recipient is on a list. An item that is EAR99 (the lowest-control tier, not listed on the CCL) may still require an OFAC licence if the end-user is an OFAC-designated person. An item that is classified on the CCL at a level requiring a licence to a given country may be controlled even when the counterparty is not on any list at all. Running only one of these screens produces a compliance programme that is, at best, half-complete.

The UK regime (OFSI for financial sanctions; ECJU for export licensing) applies a broadly parallel structure, but the list architecture is different. The UK Sanctions List administered under the Sanctions and Anti-Money Laundering Act ("SAMLA") and the relevant thematic regulations does not automatically mirror the BIS Entity List. A counterparty removed from a BIS list may remain on the UK Sanctions List, or vice versa. Post-Brexit divergence has produced a meaningful gap between UK and EU lists that compliance teams managing cross-border supply chains must track separately.

The EU operates the Common Foreign and Security Policy asset-freeze list and the EU dual-use controls under the relevant Council Regulation. EU dual-use screening checks a different set of restricted parties than BIS does. A company that clears a BIS screen may appear on the EU's catch-all controls or be subject to end-user restrictions under the applicable EU thematic sanctions regulations. For businesses shipping from both a US and a European manufacturing base – which is the position of many multinationals – both screens must run and the more restrictive control governs.

Singapore, Japan, and the UAE have each developed controlled-party lists under their respective national instruments that do not replicate the US or EU lists in their entirety. An exporter shipping through a hub in one of these jurisdictions should ensure that local counsel has reviewed the applicable country regime, because a transit or re-export through a third country can trigger additional screening obligations under that country's rules.

Related practices

What are the key risk flags that screening alone will not catch?

Screening against published lists is necessary but not sufficient. The BIS / EAR red-flag doctrine requires exporters to identify and act on warning signs that a transaction may involve a prohibited end-use or end-user, even when no party appears on any controlled list. Screening a clean name against a list and getting no hit does not discharge the obligation to investigate red flags.

The categories of red flags that recur in enforcement matters include: a buyer who declines to state the end-use or provides a vague answer; payment terms or routing that are inconsistent with the declared commercial purpose; a request to omit the item from shipping documents; a destination that is inconsistent with the buyer's stated business; and an intermediary whose involvement cannot be commercially explained. None of these triggers a list hit. All of them require the exporter to pause and investigate before shipping.

The know your customer (KYC) analysis that financial institutions apply to their clients has a direct analogue in export-control compliance. Exporters are expected to understand their buyers, to verify the stated end-use, and to document that verification. Where an end-user certificate is obtained, BIS expects it to be reviewed and retained – not filed unread.

A related risk flag is the deemed export rule. The EAR treats the release of controlled technology to a foreign national in the United States as an export to that person's home country. A company that licenses technology to a foreign employee or contractor without checking whether that person or their home country creates a licence requirement under the CCL is exposed to a violation that no physical-shipment screen will ever catch. Deemed export compliance requires a separate analytical layer – classification of the technology, identification of the nationals who will receive access, and verification that no licence is required or that an applicable licence or exception covers the disclosure.

Does your compliance programme include a deemed export review for technology transferred internally, through licensing arrangements, or at trade exhibitions? In our experience, this is the area most frequently absent from otherwise competent export-control programmes.

Common myths and objections in BIS / EAR screening

A persistent myth in this area is that BIS / EAR controls apply only to items that are physically exported from the United States. This is incorrect. The EAR's extraterritorial reach – through the de minimis rule for US-origin content and the foreign direct product rule (FDPR) for items produced abroad using US technology or equipment – extends controls to non-US items that meet defined thresholds. A manufacturer in a third country who uses US-origin production equipment or US technology may be producing items subject to the EAR, and may therefore need to screen its buyers against BIS lists and conduct the same red-flag analysis that a US exporter would perform. The FDPR has been expanded significantly in recent regulatory cycles, and its reach is a live question for non-US companies that have not assessed their supply chains against the current rules.

A second myth is that a clean list screen produces a safe harbour. It does not. BIS's enforcement posture is clear: an exporter who ships to a clean-listed party on the strength of a screen alone, without reviewing red flags, is not protected from enforcement action if the goods reach a prohibited end-use. The red-flag obligation is independent of the list-screening obligation. Both must be satisfied.

A third misconception concerns the relationship between OFAC sanctions compliance and BIS / EAR compliance. Some compliance teams treat them as interchangeable – running one screen and assuming the other is covered. They are separate legal regimes with separate lists, separate legal bases (IEEPA for both, but administered by different agencies under different regulations), separate penalty structures, and separate disclosure channels. A VSD to OFAC does not serve as a VSD to BIS. If an apparent violation involves both regimes, separate disclosures to each agency may be required.

When to involve external sanctions and export-control counsel

Counsel involvement is warranted at several distinct points in the BIS / EAR screening process. Recognising those points in advance – rather than after a problem has crystallised – is the most effective risk-management step available to a compliance function.

The first point is programme design. A screening programme designed without reference to the specific items a company exports, the jurisdictions it ships to, and the types of counterparties it engages is unlikely to be calibrated correctly. We regularly assist exporters in mapping their product classification against their customer base and designing a screening logic that is proportionate to their risk profile.

The second point is a confirmed or probable hit. When a screen produces a match that survives initial review, the company needs to determine quickly: which list, which legal consequence, which options are available (licence application, transaction restructuring, or refusal), and whether a voluntary self-disclosure obligation has been triggered. That analysis is time-sensitive. Decisions made in the first hours after a hit can preserve or foreclose options.

The third point is a request for information from BIS – whether in connection with an end-use check, a post-shipment verification, or an enforcement inquiry. BIS's end-use check process (the pre-licence check and post-shipment verification process) is administrative in form but consequential in substance. A company that handles a BIS inquiry without understanding what information it is required to provide, and what it should preserve, risks aggravating a manageable situation.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. For a confidential review of a potential breach or a compliance programme gap, contact Calder & Vance at info@caldervance.com.

Frequently asked questions

What are the steps to set up effective screening under BIS / EAR?
Effective BIS / EAR screening requires five linked steps: classify every item in your product range under the Commerce Control List; identify every party in the transaction chain (exporter, buyer, intermediary, end-user, consignee); run each party against the Entity List, Denied Persons List, Unverified List, and OFAC SDN List simultaneously; apply a documented match-logic that captures transliterations and aliases; and review all red flags for prohibited end-uses regardless of whether a list hit occurs. Each step must be documented and reviewed at least annually, and whenever a new product line or market is added.
What is the most common mistake in name and entity screening?
The most common mistake is running a name screen against only one list – typically the OFAC SDN List or the aggregated Consolidated Screening List – and treating a clean result as full clearance. BIS / EAR compliance requires separate checks against the Entity List, Denied Persons List, and Unverified List, each of which carries a different legal consequence. A second frequent error is failing to screen aliases: parties on the Entity List are often listed under multiple transliterations or trading names, and a screen that checks only the primary name will miss them. A third error is ignoring the red-flag doctrine after a clean screen.
How does BIS / EAR differ from other regimes here?
BIS / EAR controls are item-based: they attach to goods, software, and technology classified under the Commerce Control List, and they apply extraterritorially through the de minimis and foreign direct product rules to non-US items that meet defined thresholds. OFAC's controls are person-based: they freeze the property of designated parties regardless of what goods are involved. The UK and EU regimes combine both approaches but under different list architectures and thresholds that do not replicate the US lists. For cross-border transactions, all applicable regimes must be screened independently, and the most restrictive control governs.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.