Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · BIS / EAR

Sanctions risk assessment under BIS / EAR: step by step

A trading house exports precision measurement instruments to a distributor in a third market. Months later, an internal audit reveals that one of the end-users listed in the distributor's sub-sale records appears on the Entity List (a list maintained by the Bureau of Industry and Security — BIS — of parties subject to specific licence requirements under the Export Administration Regulations). The shipment has already left. What exposure does the company carry, and what should it have done before the goods moved?

A sanctions risk assessment under the BIS / EAR (the Export Administration Regulations administered by the US Bureau of Industry and Security) is the structured process by which an exporter, re-exporter, or in-country transferor identifies whether a transaction triggers a US licence requirement, a restricted-party bar, or an end-use prohibition. As of mid-2026, the EAR reaches items by virtue of US-origin content, US technology, and items produced abroad using US-controlled equipment or software — making the regime relevant to non-US businesses as well. Completing this assessment before each transaction is the minimum standard BIS expects.

This guide sets out the assessment in sequential steps, explains where BIS / EAR obligations diverge from the OFAC, OFSI, and EU approaches, and identifies the risk flags that most commonly surface in cross-border practice.

Step 1: Establish whether the EAR applies to your item and transaction

The first question is jurisdictional: does the EAR reach this item? The EAR covers items on the Commerce Control List (CCL) and — critically — also covers many items not specifically listed there, through the EAR99 catch-all category. EAR99 items are generally low-risk, but they are still subject to the EAR's end-use and end-user controls, and a licence may be required if the destination, end-user, or end-use raises a flag.

The jurisdictional test under the de minimis rule and the foreign direct product rule (FDPR) is the point most non-US businesses miss. An item manufactured entirely outside the United States can still be subject to the EAR if it incorporates more than a defined threshold of controlled US-origin content by value, or if it is the direct product of certain US-controlled technology or software. In our cross-border practice, we regularly advise European and Asian manufacturers who discover — often during an internal review — that their product line is partially subject to the EAR without any US export having occurred in the conventional sense.

The practical starting point is an item-level analysis: what is the item, where was it designed, where was it manufactured, does it incorporate any US-origin components or software, and was it produced on equipment that is itself EAR-controlled? These questions must be answered before classification begins.

Step 2: Classify the item under the Commerce Control List

Once you have confirmed EAR applicability, the item must be assigned an ECCN (Export Control Classification Number — the alphanumeric code under the CCL that identifies the item's control parameters and the reasons for control). The ECCN determines which destinations require a licence, which exceptions may apply, and which end-uses trigger heightened scrutiny.

Classification is a technical exercise. It requires an accurate description of the item's parameters — performance thresholds, frequencies, materials, software functions — cross-referenced against the CCL's entries and the associated technical notes. Misclassification in either direction creates risk: over-classification burdens legitimate trade; under-classification exposes the exporter to enforcement.

Where an item spans multiple categories — a dual-use component embedded in a commercial product, for instance — each sub-component may need its own analysis. In our experience, classification errors cluster around software and technology transfers, where the item is not a physical good and the CCL's software-related entries require careful reading. A manufacturer that has not reviewed its classifications in two or more years should treat those classifications as provisional until re-confirmed against the current CCL.

Step 3: Screen all parties against the restricted-party lists

Restricted-party screening is not a single-list check. Under the EAR, the relevant lists include the Entity List, the Denied Persons List, and the Unverified List — each carrying different consequences and each maintained by BIS — alongside OFAC's SDN List (the list of Specially Designated Nationals and blocked persons) and the OFAC sectoral lists. A transaction may be clean under one list and prohibited under another.

The screening obligation extends beyond the direct buyer. The EAR's red flag doctrine requires exporters to investigate and resolve indicators of diversion or prohibited end-use before proceeding, even where no list hit is returned. A payment route through an unusual intermediary, a shipping address inconsistent with the stated end-user, or a buyer whose stated business bears no relationship to the item ordered are all red flags that suspend the right to proceed without further inquiry.

Cross-regime divergence is significant here. OFAC's SDN screening logic is mechanical: the blocked-person test and the 50 percent or more ownership rule either apply or they do not, regardless of knowledge. BIS red-flag doctrine, by contrast, involves a knowledge element — but "knowledge" under the EAR is defined broadly to include wilful blindness. A business that declines to investigate a visible flag cannot claim ignorance. We regularly advise clients that the EAR's red-flag standard is, in practice, stricter than it appears because it obliges the exporter to act on information it has, not merely on list hits it receives.

The position under OFSI and the EU adds a further dimension. Both regimes apply an ownership and control test — meaning that an unlisted entity can be caught if a designated person controls it, even without reaching the ownership threshold. A business that has mapped OFAC exposure but not considered OFSI or EU control exposure may have an incomplete picture of the counterparty's risk.

The position above covers the standard screening case. Your facts — the counterparty's ownership chain, the goods involved, the payment route, and the regimes in play — change the analysis materially.

For a structured screening review of a counterparty or supply-chain relationship, contact Calder & Vance at info@caldervance.com.

Step 4: Assess the end-use and end-user

Even where the item clears list screening and carries a low-control ECCN, the EAR's end-use controls can require a licence or prohibit the transaction outright. The three principal end-use controls cover nuclear, chemical and biological, and missile-related applications, and there is a general prohibition on exports to parties engaged in sanctioned activities as defined by the applicable country regime.

End-use controls are particularly relevant in sectors where dual-use potential is high: precision manufacturing equipment, advanced materials, high-performance computing components, and telecommunications infrastructure. A business selling to a distributor — rather than a known end-user — must assess whether it has adequate visibility into sub-sales and whether its contractual protections (end-use certifications, right-of-inspection clauses, re-export restrictions) are enforceable and monitored.

The end-user statement or certificate is a standard tool, but it is not self-executing. In our practice, we have seen end-user certificates treated as compliance events rather than compliance tools — collected, filed, and forgotten. The certificate's value lies in the follow-up: does the stated use align with the buyer's business? Does the destination correspond to the certified location? Has the buyer taken prior delivery of items that might suggest diversion? These are the questions a BIS examiner will ask, and they should be asked internally first.

What happens when a red flag cannot be resolved?

When a red flag is identified and cannot be resolved through reasonable inquiry, the exporter must not proceed until the flag is cleared or a licence has been obtained. This is not a compliance recommendation. It is a legal obligation under the EAR. The exporter who proceeds over an unresolved red flag does so with knowledge — and the enforcement consequences of a knowing violation are substantially more serious than those arising from a negligent one.

The options when a flag cannot be resolved are, in sequence: pause the transaction and conduct further due diligence; request a Commodity Jurisdiction determination or classification ruling where the item's status is genuinely unclear; apply for a specific licence from BIS where a licence exception is unavailable; or decline the transaction.

If a transaction has already proceeded and a potential violation is identified, the calculus changes. A VSD (voluntary self-disclosure to BIS) is available and, under current BIS enforcement guidance, is treated as a mitigating factor. The decision to submit a VSD, the timing, the scope, and the framing of the disclosure are legal judgments that should not be made without counsel. A poorly framed VSD can expand the scope of an inquiry rather than limit it.

If a filing has been refused, or a transaction has already been flagged by BIS or a freight partner, an early review can preserve options that narrow quickly with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.

How does the BIS / EAR approach differ from OFAC, OFSI, and EU obligations?

The BIS / EAR regime and the OFAC sanctions regime are distinct in authority, scope, and enforcement logic — and understanding the difference is essential for any exporter with US-connected trade. OFAC administers economic and trade sanctions targeting specific countries, persons, and entities. BIS administers export controls targeting items by their technical characteristics, destination, and end-use. The two regimes overlap but are not substitutes: a transaction that requires no OFAC licence may still require a BIS licence, and vice versa.

The OFAC ownership test — the 50 percent rule — is bright-line. The BIS analysis is multi-factor: it weighs the ECCN, the destination, the end-user, the end-use, and the available exceptions. BIS licence exceptions can authorise transactions that OFAC would block absent a specific licence, and the reverse is equally true. A business that clears only one of the two US regimes has completed half the analysis.

The cross-border dimension extends further. The UK's OFSI administers financial sanctions independently of the US, applying an ownership and control test that can capture entities not caught by OFAC's ownership rule. The EU applies a similar control test under the relevant Council regulations. Switzerland's SECO, Canada's Global Affairs Canada, and Australia's DFAT each administer autonomous sanctions programmes that may diverge in their list coverage and in their licensing processes. A shipment cleared under the EAR may still be blocked at the point of financing, insurance, or transit by a non-US regime operating independently.

In our cross-border practice, we advise exporters to treat the EAR analysis as the first step, not the last. Multi-regime screening — covering OFAC, OFSI, the EU lists, and the relevant transit-jurisdiction regimes — should run in parallel, not sequentially. Where the regimes diverge, the stricter prohibition governs the transaction.

Common risk flags and how to address them

The most frequent risk flags in BIS / EAR assessments cluster around four patterns. First, stale classification: ECCNs assigned at product launch that have not been reviewed against CCL amendments or product modifications. Second, incomplete ownership mapping: screening that reaches the direct buyer but not the ownership chain behind it, missing a blocked or restricted shareholder. Third, distributor opacity: a commercial relationship where the exporter has no visibility into the distributor's sub-sales and no contractual mechanism to obtain it. Fourth, technology and software transfers treated as non-exports: code transmitted electronically, training delivered remotely, or technical data shared in a web portal — all of which are "exports" under the EAR.

A common myth in this area is that the EAR applies only to physical shipments. It does not. Technology and software — whether transmitted, emailed, downloaded, or provided through a cloud service — are subject to the EAR to the same extent as a physical item. A company that has invested in screening physical goods but has not reviewed its software licensing, its cloud-access controls, or its technical-training programme has a gap in its compliance programme that a BIS examiner will locate.

The procedural response to each of these flags is the same: document the analysis, resolve the flag before proceeding, and record both the flag and its resolution in the transaction file. Record-keeping under the EAR must be maintained for a defined period; verify the current requirement before relying on your programme's retention settings.

Related practices

Frequently asked questions

What are the steps to carry out a sanctions risk assessment under BIS / EAR?
A BIS / EAR sanctions risk assessment follows five sequential steps: (1) confirm EAR jurisdictional reach over the item, including the de minimis and foreign direct product rule analyses; (2) classify the item under the Commerce Control List to determine its ECCN; (3) screen all parties — exporter, buyer, intermediaries, and known end-users — against BIS and OFAC restricted-party lists; (4) assess the end-use and end-user for the applicable end-use controls; and (5) identify any available licence exceptions, or apply for a specific licence where none applies. Each step should be documented in the transaction file.
What is the most common mistake in sanctions risk assessment?
The most common mistake is treating restricted-party screening as the whole of the assessment. Screening for list hits is necessary but not sufficient. The EAR also requires an end-use and end-user analysis, a red-flag review, and — for non-US exporters — a de minimis and FDPR determination. Businesses that invest in automated screening but do not address classification accuracy, distributor sub-sale visibility, or technology-transfer controls will have a compliance programme that passes surface review but fails under examination. In our experience, these gaps are most common in software and advanced-manufacturing sectors.
How does BIS / EAR differ from other regimes here?
BIS / EAR is an item-and-destination control regime. Its core logic asks: what is the item, where is it going, who is the end-user, and what will it be used for? OFAC is a person-and-entity control regime: its core question is whether a blocked or sanctioned person is involved in the transaction. The two regimes run in parallel and are not interchangeable. OFSI and EU sanctions add a control test that can capture unlisted entities through designation of the persons who control them — a dimension that OFAC's 50 percent ownership rule does not fully replicate. A complete assessment must address each applicable regime separately.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.