A technology exporter preparing a cross-border shipment runs its customer list through a standard screening tool. The tool returns no SDN hits. The compliance team clears the deal. But the buyer's end-use certificate describes a military application, the goods carry a controlled classification, and the destination falls within a heightened-scrutiny category under the Export Administration Regulations. The screening result was accurate. The risk assessment was not.
A sanctions risk assessment under BIS / EAR (the Export Administration Regulations administered by the Bureau of Industry and Security) is a structured evaluation of whether a proposed export, re-export, or in-country transfer triggers a licence requirement or an end-use prohibition under US export-control law. It covers item classification, destination controls, end-user screening, and end-use analysis. As of mid-2026, BIS administers the EAR under the authority of the Export Control Reform Act, and the scope of controlled items and restricted parties has expanded materially across successive rules.
This guide walks through each stage of a BIS / EAR sanctions risk assessment, identifies where businesses most commonly misjudge their exposure, and explains how the US regime interacts with the parallel regimes of the UK, the EU, and other key jurisdictions.
Step 1: Understand the governing regime and its authority
BIS administers the EAR under the Export Control Reform Act, using IEEPA as a principal authority base. The EAR governs exports, re-exports, and transfers of items – goods, software, and technology – that originate in or pass through the United States, or that contain more than a specified threshold of controlled US-origin content. The reach is extraterritorial: a business headquartered in Germany that re-exports US-origin goods is subject to EAR obligations regardless of where it is incorporated.
This extraterritorial reach is the starting point of any sound risk assessment. Many non-US businesses assume that BIS controls apply only to US exporters. In our practice, that assumption has repeatedly produced exposure that a threshold analysis would have caught early. The EAR's extraterritorial provisions extend to foreign-produced items that incorporate controlled US content above the applicable de minimis percentage, and separately to items produced abroad using certain US-origin technology or equipment. Both dimensions must be mapped before a conclusion is reached.
The regime sits alongside, and sometimes in tension with, other controls. OFAC administers separate economic sanctions that can prohibit a transaction entirely even when BIS would require only a licence. A sanctions risk assessment that treats BIS / EAR and OFAC as interchangeable misses the point: they are different programmes, administered by different agencies, with different legal standards. We regularly advise clients who have resolved their OFAC position and then discovered an unaddressed EAR issue – or vice versa. Addressing both from the outset avoids that sequencing problem.
Step 2: Classify the item under the Commerce Control List
Classification is the foundation of the EAR analysis. Every item subject to the EAR has an ECCN (Export Control Classification Number under the US Commerce Control List), or it qualifies as EAR99 – the residual category for items that are not specifically listed. The ECCN determines which destinations, end-users, and end-uses trigger a licence requirement, and which licence exceptions may be available.
Classification errors are among the most common sources of EAR enforcement exposure. A product that was correctly classified five years ago may now carry a different ECCN if BIS has revised the Commerce Control List entry – which happens regularly. Have you reverified the classification against the current list, or are you relying on a determination that pre-dates the last round of BIS rulemaking?
The classification exercise requires technical input. Legal counsel alone cannot correctly classify a piece of semiconductor manufacturing equipment or specialised software; the engineers who designed or modified the product must be part of the process. The classification memo should record: the technical parameters of the item, the applicable CCL category and product group, the basis for the determination, and the date of the review. That contemporaneous record matters significantly if BIS later questions the determination.
For EAR99 items, the analysis does not end at classification. EAR99 goods can still be subject to licence requirements if the transaction involves a restricted end-user, a prohibited end-use, or a destination under a heightened control regime. The classification step narrows the field; it does not close the analysis.
Step 3: Screen all parties against BIS and related lists
Party screening under the EAR covers more than the BIS Entity List. A complete screen under this step addresses the Entity List (parties for whom a BIS licence is required for any export, re-export, or transfer of EAR-subject items), the Denied Persons List (parties subject to denial orders prohibiting them from participating in any export transaction subject to the EAR), the Unverified List (parties whose end-use bona fides BIS has been unable to verify), and the Military End-User and Military Intelligence End-User lists.
Each list carries different legal consequences. A transaction with a Denied Person is prohibited regardless of the item's classification. A transaction with an Entity List party requires a licence unless a narrow exception applies. An Unverified List designation raises a red flag that requires heightened diligence before the exporter can rely on a licence exception. These distinctions drive materially different responses.
Screening must capture not only the direct buyer but also intermediaries, freight forwarders, financial institutions involved in the transaction, and – where the exporter has reason to know – the ultimate end-user. The red-flag indicators that BIS publishes provide a checklist of circumstances that should cause an exporter to pause and investigate further: evasive answers to end-use questions, cash payment requests that are inconsistent with the transaction's value, routing through jurisdictions with no apparent business connection to the deal, and similar anomalies.
It is worth pairing this screen with an OFAC check. A counterparty may not appear on any BIS list but may be on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) or be owned 50 percent or more by a blocked person under OFAC's aggregation rule. Running only one check and not the other produces a gap that BIS enforcement actions have exploited.
Step 4: Analyse the destination, end-user, and end-use
Destination, end-user, and end-use form a triad that determines the applicable licence requirements once item classification and party screening are complete. For certain destinations, BIS imposes a licence requirement on all EAR-subject items regardless of ECCN. For others, only specific ECCN categories trigger a requirement. The applicable country group classification, and any additional controls arising from multilateral arrangements to which the United States is party, must be checked in conjunction.
End-use controls are a separate and distinct layer. The EAR prohibits certain end-uses – military end-use in specified countries, weapons of mass destruction applications, and others – even for items that would otherwise be licence-free. An exporter who knows or has reason to know that its items will be used in a prohibited end-use cannot proceed, regardless of how the classification and destination analysis comes out. The "reason to know" standard is objective: a buyer's assurances do not absolve an exporter who ignored warning signs.
In our cross-border practice, end-use analysis is the step most frequently underweighted. Exporters invest heavily in classification and list screening, then treat end-use as a formality satisfied by collecting a standard certificate. That approach does not work when the transaction's red-flag indicators are inconsistent with the stated end-use, or when the ultimate destination differs from the destination identified at the point of sale. The assessment must correlate all available information before reaching a conclusion.
How does BIS / EAR differ from the EU and UK regimes in practice?
The BIS / EAR regime differs from its EU and UK counterparts in several practically significant respects, and a cross-border business cannot assume that clearing one regime clears the others.
Under EU dual-use rules, the classification nomenclature broadly tracks the multilateral control lists that the US CCL also references. However, the EU regime is administered at member-state level, and the licence-requirement triggers, available exceptions, and enforcement postures vary across member states even within the single regulatory instrument. A French exporter and a Dutch exporter shipping the same item to the same destination may face different procedural requirements at the national agency level.
Under UK export controls administered by ECJU, the control list was aligned with EU classifications at the time of the UK's departure from the EU but has since diverged in places. ECJU licensing processes and timelines differ from both the US and EU approaches. For a business operating across all three jurisdictions, a separate classification and licence determination is required in each – one determination does not carry across.
A further divergence concerns extraterritoriality. The BIS / EAR regime has the broadest extraterritorial reach of the three, applying to foreign-produced items that incorporate or are produced with US-origin controlled content or technology. EU and UK controls are primarily territorial in application. This means that a transaction that is clean under EU and UK rules may still require a BIS authorisation if US-origin content triggers the applicable threshold. We advise clients to run the US analysis first precisely because of this asymmetry.
Singapore, Japan, and the UAE each administer their own export-control regimes, and all three coordinate to varying degrees with multilateral frameworks. For re-exports transiting those jurisdictions, the applicable country regime must be reviewed in addition to the EAR. Assuming that an EAR licence exception covers a transit through Singapore without checking that jurisdiction's national rules is a risk that has materialised in enforcement actions.
What are the key risk flags in a BIS / EAR assessment?
Risk flags in a BIS / EAR assessment fall into two categories: structural and transactional. Structural flags relate to the nature of the items, the counterparty, or the destination. Transactional flags arise from the specific facts of the deal.
Structural flags include:
- Items with military, intelligence, or dual-use applications that appear in the higher-tier ECCN categories
- Counterparties in jurisdictions subject to heightened destination controls under the EAR
- Corporate structures with ownership and control (the test for whether a non-listed entity is caught through a listed person) that obscure the ultimate beneficial owner
- Industry sectors – semiconductors, advanced materials, aerospace – where BIS has issued specific guidance indicating elevated scrutiny
Transactional flags include payment terms inconsistent with the deal's commercial logic, requests to omit the item description from shipping documents, buyers who decline to answer standard end-use questions, re-routing instructions received after contract signature, and freight forwarder substitutions without explanation. BIS's published guidance on red-flag indicators lists patterns in each of these categories.
When multiple flags co-occur, the standard for what counts as "reason to know" a prohibited use shifts. A single anomaly in an otherwise routine transaction can often be resolved through enhanced diligence. Three or four concurrent anomalies in the same transaction are a different proposition and typically warrant suspending the transaction pending legal review.
When should you involve sanctions counsel, and what does the review cover?
Counsel should be involved at the point when a risk assessment reveals ambiguity that internal compliance cannot resolve with confidence. That includes: novel classification questions on new or modified products; transactions involving Entity List or Unverified List parties where a licence exception is being contemplated; end-use uncertainty where the red-flag picture is mixed; and any situation where a prior shipment may have been made without the required authorisation.
The position above covers the standard case. Your facts – the item, the buyer, the route, the regime in play – change the analysis. A technology company shipping to an established European distributor faces a different risk picture from a manufacturer shipping complex components to a new buyer in a jurisdiction with a thin verification history. Both need an assessment, but the depth and focus differ.
For a confidential review of your EAR exposure, contact Calder & Vance at info@caldervance.com.
In a recent matter, a manufacturing-sector client supplying industrial equipment to a distributor in a third market discovered – during pre-shipment compliance review – that one tier of the distribution chain corresponded to a party on the BIS Unverified List. We assessed whether any licence exception remained available, advised on the enhanced diligence steps required before reliance on that exception, and restructured the transaction documentation to reflect the concluded analysis. The shipment proceeded on a timeline that preserved the commercial relationship.
A complete BIS / EAR risk-assessment file prepared by counsel typically covers: the classification memo and CCL cross-reference, the party-screening results and list-check methodology, the destination and end-use analysis, the licence or exception determination, the red-flag review and any enhanced diligence undertaken, and the record-keeping package. That file is not only the basis for a decision; it is the primary defence if BIS later opens an inquiry.
If a transaction has already been flagged – or if a prior shipment may have occurred without required authorisation – an early review can preserve options that narrow with time. A VSD (voluntary self-disclosure to a regulator) to BIS, when appropriate and timely, is a recognised mechanism for limiting enforcement consequences. The window for that option does not stay open indefinitely.
If a transaction has already been flagged, or a filing has been refused, contact us at info@caldervance.com at the earliest opportunity.
Related practices
- Compliance audit and testing – stress-testing sanctions and export-control programmes against live operational data
- BIS / EAR sanctions risk assessment: advanced issues – deeper guidance on de minimis rules, foreign-direct product rules, and multilateral coordination
- Sanctions risk assessment under EU dual-use rules – a parallel guide covering the EU regime, member-state variation, and the EU-US divergence points