A freight forwarder discovers that a shipment of electronic components it handled three months ago included items requiring a licence under the Export Administration Regulations (the EAR – the primary US export-control instrument administered by the Bureau of Industry and Security, or BIS). No licence was obtained. The shipment has already arrived. What happens next, and how fast does the window for action close?
As of March 2026, a confirmed or apparent violation of the EAR exposes an exporter, freight forwarder, or other party to civil penalties, denial of export privileges, and – in the most serious cases – criminal referral to the Department of Justice. The critical variable is timing: BIS's own guidance makes clear that a voluntary self-disclosure (VSD – a proactive submission to BIS describing an apparent violation) is the most significant factor it weighs when deciding penalty level. Acting before BIS opens its own inquiry changes the risk profile materially.
This guide walks through the enforcement risk sequence after an apparent breach of the EAR: from initial discovery through scope assessment, the VSD decision, the formal enforcement process, cross-border complications, and the practical steps that reduce exposure at each stage.
Step 1: Understanding the governing authority and legal basis for EAR enforcement
BIS enforces the EAR under authority derived from the Export Control Reform Act and, historically, the International Emergency Economic Powers Act (IEEPA). Civil enforcement sits with BIS's Office of Export Enforcement (OEE). Criminal matters are referred to DOJ. The two tracks can run simultaneously, and a business responding to one must account for the other from the outset.
The EAR regulates the export, re-export, and in-country transfer of items on the Commerce Control List (CCL – BIS's itemised schedule of controlled goods, software, and technology, each assigned an Export Control Classification Number, or ECCN). Items not on the CCL may still require a licence if destined for a restricted end-user, a restricted end-use, or a restricted destination. This matters for breach analysis: the violation category determines both the enforcement track and the penalty ceiling.
Who can be an enforcement target? The exporter of record is the primary subject. But BIS's jurisdiction extends to any US person or any person acting within US jurisdiction – including freight forwarders, banks that processed the payment, and foreign re-exporters who subsequently moved US-origin items in violation of the EAR. In our practice, businesses often underestimate the breadth of that reach until BIS's first communication arrives.
Step 2: Scoping the apparent violation before anything else
Before deciding on disclosure or any other response, a business must understand precisely what it is dealing with. A scope assessment is not optional: it determines the appropriate legal track, the disclosure content, and the likelihood that BIS will treat the matter as egregious.
The scope assessment should address at least the following:
- Classification: what ECCN applies to the item, and was a licence required for the specific transaction (destination, end-user, end-use)?
- Volume: how many transactions are implicated, over what period?
- Knowledge: did any person with relevant authority know, or have reason to know, that the transaction was controlled?
- Benefit: was there commercial gain from proceeding without a licence?
- Destination and end-user: does the item or its end-user appear on the Entity List (BIS's list of parties subject to licence requirements based on national-security and foreign-policy grounds) or the Denied Persons List?
- Prior history: has BIS issued any prior warning letter or penalty to the same business?
Each of those factors maps directly onto BIS's published penalty matrix. A single shipment of a low-ECCN item to a non-restricted destination is a very different legal problem from a pattern of unlicensed exports to an Entity List party. Conflating them leads to a disproportionate or – worse – an incomplete response.
In our experience, internal investigations that stop at the first identified transaction almost always miss related transactions in adjacent business lines or under slightly different product codes. A thorough look at the shipping records for the two to three years before discovery is the minimum prudent step.
Step 3: The voluntary self-disclosure decision – how to weigh it
A VSD to BIS's OEE is the single most consequential decision in post-breach management. BIS has consistently treated a timely, complete, and accurate VSD as the strongest available mitigating factor, and its enforcement guidance reflects that position explicitly.
What does a VSD involve in practice? A preliminary notice – a brief letter identifying that the company has discovered an apparent violation and is conducting an internal review – can be submitted first to preserve the VSD timeline while the full investigation continues. The substantive submission follows and sets out the facts, the legal analysis, the number and value of transactions, the corrective measures already taken, and the company's co-operation commitment.
The timing question is critical. A VSD submitted before BIS has opened its own inquiry, issued a warning letter, or taken any investigative step is weighted much more heavily than one filed in response to BIS contact. Once BIS has already identified the issue – through a tip, a customs referral, or its own intelligence – the disclosure is no longer truly voluntary in the same sense, and BIS treats it accordingly.
Does that mean every apparent violation should be disclosed immediately? Not necessarily. There are situations where the scope is genuinely unclear, the legal classification is in good-faith dispute, or the facts do not yet support a confident determination that a violation occurred at all. In those cases, rushing a premature disclosure can create a record that is harder to defend than waiting a short period to complete a proper review. The decision requires legal judgment. It is rarely straightforward.
The position above covers the standard case. Your specific facts – the items involved, the destinations, the entities, the internal knowledge at the time – change the analysis substantially. For a confidential review of whether a VSD is appropriate to your situation, contact Calder & Vance at info@caldervance.com.
Step 4: The BIS enforcement process after a VSD or investigation opens
Once BIS has received a VSD or has opened its own investigation, the formal enforcement sequence follows a defined path. Understanding each stage allows a business to allocate resources efficiently and avoid procedural errors that damage credibility with the regulator.
BIS OEE reviews the submission or conducts its investigation and determines whether to refer the matter to the Office of Chief Counsel for an administrative proceeding, refer it to DOJ for criminal consideration, or close it without penalty. The outcome of that triage depends heavily on the factors established in the scope assessment: classification, knowledge, benefit, and prior history.
If an administrative proceeding is initiated, BIS issues a charging letter alleging the specific violations. The respondent has the right to respond, request a hearing before an administrative law judge, or negotiate a settlement. Most matters settle. Settlement terms typically involve a civil monetary penalty, a suspended penalty subject to a compliance commitment, and – for more serious cases – a temporary denial of export privileges.
A temporary denial order (TDO – an emergency measure that immediately bars a party from participating in US exports) is one of BIS's most disruptive tools. It can be issued without prior notice and does not require a finding of guilt. It is typically reserved for ongoing patterns of serious violations, but a business must understand that it is on the table once an investigation is open.
For criminal referrals, DOJ can prosecute under the Export Control Reform Act. Wilful violations carry significant exposure for both the company and responsible individuals. The interaction between the administrative and criminal tracks requires careful management: statements made in a VSD or an administrative proceeding can surface in a parallel criminal matter.
If a transaction has already been flagged, a filing refused, or a BIS letter received, an early legal review preserves options that narrow quickly. Contact us at info@caldervance.com for an assessment of where the matter stands.
Step 5: Cross-border complications – when the EAR intersects with OFAC, OFSI, and EU rules
An EAR violation rarely exists in isolation. A shipment that breaches BIS export controls commonly also implicates OFAC financial sanctions if the end-user is designated, OFSI obligations if a UK-nexus financial institution processed the transaction, or EU dual-use controls if the goods moved through a European distributor.
The extraterritorial reach of the EAR is one of its most operationally significant features. The EAR controls not only the export of items from the United States but also the re-export of US-origin items from third countries and the re-export of foreign-made items that contain more than a de minimis proportion of US-controlled content (the de minimis rule). A shipment that a European logistics company regarded as a purely intra-EU movement may have been an EAR re-export if the goods contained qualifying US content. BIS's jurisdiction does not turn on where the violating party is incorporated.
At the same time, the EU's own dual-use controls under the relevant EU regulation operate independently. A European exporter who is simultaneously subject to BIS and EU scrutiny faces overlapping – and sometimes divergent – disclosure obligations, penalty bases, and timetables. The EU regime does not have a VSD mechanism as explicitly structured as BIS's, and the absence of that formal pathway requires a different disclosure strategy.
For businesses with UK operations or UK-nexus transactions, OFSI's jurisdiction over financial sanctions adds a further layer. An apparent EAR violation that also involves a designated person's financial interest triggers a separate OFSI reporting obligation. In our cross-border practice, we consistently see businesses address the BIS dimension while missing the OFSI or EU dimension entirely – which creates a second regulatory problem precisely when the first one is being managed.
Canada's export-control regime, administered under the applicable Canadian trade-control legislation, is another frequent source of parallel exposure. Canadian re-exporters of US-origin controlled goods may face obligations to both BIS and the Canadian authority. The post-breach enforcement risk guide for Canada sets out that regime's specific mechanics.
The broader cross-border picture – including how to manage multi-regime exposure in a single matter – is addressed in the cross-border post-breach enforcement risk guide.
Step 6: Corrective action and compliance programme remediation
BIS places significant weight on whether a business took genuine corrective action after discovering a violation. That weight is not merely procedural: it reflects BIS's view that the purpose of civil enforcement is to achieve future compliance, not purely to punish. A business that acts substantively before BIS completes its review is demonstrating that deterrence is already working.
What does corrective action look like in practice? It typically involves at least four elements:
- Classification review: a systematic re-assessment of the items involved, and ideally of the full product range, to ensure all ECCNs are correctly assigned.
- Screening remediation: testing and upgrading the export-screening logic to catch the pattern that produced the violation – whether that was an Entity List miss, a de minimis miscalculation, or an end-use control gap.
- Training: documented, role-specific training for all personnel with responsibility for export decisions, with records retained to demonstrate completion.
- Process controls: written procedures that create a clear decision path for any transaction where a classification question arises, including escalation to legal or compliance before the shipment proceeds.
A compliance programme built around these elements – and documented in a way BIS can evaluate – is materially different from a business that simply updates a spreadsheet after the fact. We regularly advise businesses on how to structure and document a remediation programme that reads as credible to OEE, rather than cosmetic.
One common myth is that compliance programme improvements are only relevant at the penalty stage. In practice, BIS considers them at the triage stage too: a well-documented, genuinely functioning programme can influence whether OEE recommends an administrative proceeding at all, or whether it treats the matter as a warning-letter resolution.
Step 7: Risk flags that escalate exposure – what to watch for
Several patterns consistently drive a matter from the lower end of the penalty range toward the higher end, or from administrative resolution toward criminal referral. Recognising them early allows a business to address them directly rather than discovering them when BIS does.
The highest-risk profile is a transaction where the business had actual or constructive knowledge that a licence was required and proceeded anyway. Knowledge can be constructive: if a customer's payment terms, location, or stated end-use triggered one of BIS's published red-flag indicators and no enhanced due diligence was done, BIS will treat that as a knowledge-equivalent. Have your export compliance teams reviewed those indicators recently?
A prior history with BIS is a significant aggravating factor. A business that received a warning letter and did not revise its procedures is in a structurally weaker position than one encountering BIS for the first time. The same is true of a business that made a VSD for one violation and then committed a second one in the same product line.
Entity List and Denied Persons List involvement escalates matters sharply. If the end-user, the consignee, or any intermediate party in the transaction was on either list at the time of export, the violation is treated as categorically more serious, regardless of the item's ECCN classification. In those cases, both administrative and criminal tracks are live simultaneously, and the matter requires immediate legal attention.
Finally, obstructions or misstatements to OEE during an investigation are treated as independent violations and can convert what was an administrative matter into a criminal one. Preserving documents and ensuring that any communications with BIS are accurate and consistent with the actual record is not merely good practice – it is a legal obligation.
Related practices
- Apparent violation assessment (EU) – EU enforcement analysis for businesses facing parallel exposure under EU dual-use and sanctions regimes.
- Post-breach enforcement risk: Canada – practical guide to managing export-control breach exposure under the Canadian trade-control regime.