Calder & Vance International Sanctions & Compliance Counsel

Cross-Border Transactions & Diligence · BIS / EAR

Supply-chain sanctions mapping under BIS / EAR: a practical guide

A freight forwarder in Singapore receives a purchase order for precision optical components. The end customer is a trading company in a third market. Two layers up the ownership chain sits a name that appears on the BIS Entity List. Does the shipment require a licence? Is the forwarder exposed under US export-control law even though it is not a US company? These are not hypothetical concerns – they are the questions that decide whether a transaction proceeds or becomes an enforcement matter.

Supply-chain sanctions mapping under the Export Administration Regulations (the EAR, administered by the Bureau of Industry and Security, BIS) means tracing every node in a transaction – supplier, intermediary, freight agent, end customer, and ultimate end-user – against the BIS-maintained control lists, checking the goods or technology against the Commerce Control List (the CCL), and confirming whether a licence exception covers the shipment or a licence application is required. As of January 2026, the EAR applies extraterritorially to items of US-origin content and to foreign-produced items incorporating US technology above defined thresholds. A mapping exercise that stops at the direct buyer routinely misses the exposure.

This guide walks through the mapping process in practical steps, identifies the divergences that matter when the EU dual-use regime or UK export-control rules also apply, and explains when a matter moves beyond internal compliance capacity.

Step 1: Understand the governing authority and legal basis before you start

The EAR is the primary US export-control instrument for dual-use and less-sensitive defence items not covered by the International Traffic in Arms Regulations; BIS administers it under authority delegated through the Export Control Reform Act. Mapping under the EAR is not optional for non-US companies when the transaction touches items or technology subject to US jurisdiction.

The key jurisdictional triggers are three. First, items physically located in the United States. Second, items of US origin wherever they are. Third, foreign-produced items that meet the de minimis rule (incorporating US-controlled content above a defined percentage threshold) or that fall under the foreign-direct product rule (FDPR), which can reach foreign-made items produced using US technology or software.

In our cross-border practice, the FDPR is the most frequently misunderstood trigger. A manufacturer in Germany or Japan that uses US semiconductor equipment to produce a chip may find that chip is subject to the EAR. That extends US export-control jurisdiction to goods that never entered the United States. Understanding this before mapping is not a technicality – it defines the perimeter of what you need to screen.

The BIS maintains several control lists that a mapping exercise must run against: the Entity List (entities requiring a licence for exports of any item subject to the EAR), the Denied Persons List (parties barred from participating in EAR-regulated transactions), and the Unverified List (parties whose bona fides BIS has been unable to verify). Prohibited-party screening covers all three, not only the Entity List. Does your screening programme pull from all three sources on each refresh?

Step 2: Classify the items and map the technology transfer

Correct classification is the foundation. Every item or technology subject to the EAR is assigned an Export Control Classification Number (ECCN, a five-character alphanumeric code on the CCL that identifies the reason for control and the applicable licence requirements and exceptions). Items not specifically listed on the CCL fall under the catch-all classification EAR99, which generally requires no licence for exports to most destinations – but is not exempt from end-user and end-use controls.

The classification determines which countries, end-uses, and end-users require a licence. A common error is to treat EAR99 as categorically low-risk. It is not. An EAR99 item shipped to a party on the Entity List still requires a licence. An EAR99 item destined for a prohibited end-use – including weapons of mass destruction programmes – triggers a general prohibition regardless of classification. Technology transfers, including deemed exports where a foreign national in the United States receives controlled technical data, follow the same classification logic as physical goods.

When mapping a supply chain, classification needs to happen at every node where goods or technology change hands, not only at the initial export point. A component exported under a licence exception may be incorporated into a finished item at an intermediate stage. The finished item then has its own ECCN and its own licence requirements when re-exported.

Step 3: Screen every party across all three BIS lists – and map ownership chains

Prohibited-party screening under the EAR covers the direct buyer, the freight forwarder, the end-user declared on the shipping document, and any intermediate consignee. It also covers the ultimate consignee as confirmed through end-use certificates and contractual representations. Screening only the immediate counterparty is the most common shortfall we see in supply-chain diligence reviews.

Ownership mapping matters because the Entity List designates legal entities, but beneficial ownership of those entities can shift risk to unlisted affiliates. If an Entity List company holds a controlling stake in the declared end-user, a transaction to that end-user may still be problematic even if the end-user's own name does not appear on any list. BIS's end-user and end-use controls require that a US exporter or a party to a transaction not have knowledge – including "reason to know" – that an item will be diverted to a prohibited party or use.

"Reason to know" is a deliberate standard. It captures wilful blindness. Red flags that trigger the reason-to-know standard include: a customer who is unwilling to state the end-use, an order for quantities inconsistent with the buyer's stated business, a request to omit standard markings, a shipping route through a jurisdiction with a history of diversion, and payment terms or intermediary structures that serve no apparent commercial purpose. A mapping exercise must document how each red flag was assessed and resolved.

In a recent matter, an industrial-equipment manufacturer discovered during pre-shipment diligence that its declared freight forwarder was majority-owned by a company listed on the Entity List. The entity-level listing did not appear on the surface screening of the forwarder's name. Full ownership mapping surfaced the connection. We assisted the client in re-routing the logistics arrangement and confirming with BIS's licensing division whether a licence was required. The matter was resolved before shipment. Had it not been caught, the exporter would have faced liability under the applicable prohibitions.

How does BIS / EAR supply-chain mapping compare to the EU dual-use regime and UK export-control rules?

The EAR, the EU dual-use regime (governed by the applicable EU Council regulation), and the UK export-control regime (administered by the Export Control Joint Unit, ECJU, under the Export Control Order) share a common origin in the Wassenaar Arrangement and other multilateral control lists, but they diverge materially on scope, thresholds, and the treatment of extraterritoriality.

The most significant practical divergence for supply-chain mapping is extraterritorial reach. The EAR applies to re-exports of US-controlled items by any party in any country, subject to the de minimis and FDPR thresholds. The EU dual-use regime generally does not assert equivalent extraterritorial jurisdiction over re-exports from third countries; its controls attach at the point of export from an EU member state. The UK regime post-exit follows a similar principle. This means a supply chain with US-origin inputs carries US-export-control obligations even when the shipping leg is entirely outside the United States.

A second divergence is the catch-all control. Both the EU and UK regimes include catch-all provisions that can require a licence for unlisted items where the exporter has knowledge of a prohibited end-use or destination. The EAR's general prohibitions operate similarly but are triggered by the reason-to-know standard across all items, including EAR99. Practitioners need to run both analyses in parallel when a transaction involves both US-controlled content and an EU or UK export point.

A third point of divergence is licensing architecture. OFAC licences (for US financial sanctions) are separate from BIS licences (for export controls). A transaction may require both a BIS licence and an OFAC authorisation, and they are obtained from different agencies on different timelines. In our experience, clients who plan only for one frequently encounter delay when the second requirement surfaces mid-transaction.

For supply-chain mapping purposes, the practical rule is: where stricter obligations from two or more regimes apply simultaneously, the stricter prohibition governs the transaction. You cannot satisfy a less stringent home-country rule and treat that as discharge of a separately applicable US obligation.

Related practices

Step 4: Document the analysis and apply the correct licence exception or submit a licence application

Once items are classified, parties are screened, and red flags assessed, the next step is to determine whether a licence exception covers the transaction. The EAR contains a range of named exceptions – covering low-value shipments, certain technology transfers, and transactions to specified destinations or for specified uses. Each exception has precise conditions. Applying an exception requires confirming every condition is met and retaining documentation that shows the exception applies.

Where no exception covers the transaction, a licence application to BIS is required before export. The application process involves submitting a detailed description of the item, its classification, the proposed end-use, and information about the end-user. BIS may impose licence conditions – including reporting requirements, end-use verification visits, and restrictions on re-transfer. Those conditions survive the initial export and must be built into contractual arrangements with the buyer and any downstream party.

Record-keeping is a legal obligation, not merely good practice. Under the EAR, parties subject to the rules must retain export-related documents for a defined period. Gaps in documentation are themselves a compliance failure and can convert an otherwise defensible transaction into an apparent violation when BIS conducts an end-use check.

The position above covers the standard case. Your specific facts – the item's ECCN, the destination, the end-user's identity and ownership, and any red flags in the transaction structure – change the analysis significantly. For an assessment of your supply-chain exposure under BIS / EAR, contact Calder & Vance at info@caldervance.com.

Step 5: Establish ongoing controls and trigger points for re-screening

Mapping a supply chain once is not sufficient. The BIS control lists are updated frequently. An entity not listed when a long-term supply agreement is signed may be added to the Entity List before a shipment under that agreement takes place. A jurisdiction's status can change, affecting applicable licence requirements. Technology can be reclassified.

Effective ongoing controls include: a standing protocol for re-screening counterparties before each shipment under a framework agreement; an alert mechanism tied to BIS list updates; a defined review trigger when a counterparty undergoes ownership change; and a training programme for staff handling export documentation, so that red flags in shipping instructions are identified before the transaction is committed.

Periodic end-use verification is also part of the programme for higher-risk transactions. BIS conducts its own post-shipment verification visits in many jurisdictions, often in cooperation with host-country authorities. An exporter who has taken its own verification steps is better placed to respond to an enquiry than one who has relied solely on contractual representations from the buyer. What would your verification file show if BIS initiated a post-shipment check tomorrow?

If a shipment has already been flagged, or a transaction is under internal review for potential non-compliance, early legal assessment can preserve options – including the route of a voluntary self-disclosure (VSD, the process by which a party discloses an apparent violation to BIS before enforcement action begins, which the agency treats as a mitigating factor in penalty determination). That window can close. For a confidential review of a potential issue under BIS / EAR, contact us at info@caldervance.com.

Risk flags specific to supply-chain structures and when to involve counsel

Supply-chain structures introduce specific risk concentrations that differ from single-transaction export-control analysis. Distributors and trading houses operating in multiple jurisdictions create diversion risk: controlled items may move from an approved buyer to a third party in a restricted destination without the original exporter's knowledge. Long supply chains with multiple re-export legs multiply the number of points at which a prohibited party could enter the chain.

The following patterns in a supply chain are indicators that closer analysis – and, in many cases, external sanctions and export-control counsel – is warranted:

  • A distributor in a jurisdiction with a significant history of diversion that serves multiple sub-distributors whose identities are not disclosed
  • An end-user whose stated business activity is inconsistent with the technical specification of the goods ordered
  • A corporate structure where the declared buyer is a recently formed entity with limited operational history, acting as intermediary for an unstated ultimate customer
  • A transaction where the contractual party requests shipment to an address different from the address on the commercial documentation
  • A supply arrangement where the counterparty has requested removal of country-of-origin markings or technical documentation identifying the item's classification
  • A re-export from a third country where the original export authorisation did not include re-transfer provisions

We regularly advise exporters and procurement teams who have identified one or more of these patterns mid-transaction. The analysis at that stage covers: whether the transaction can proceed with additional controls, whether a licence application is required, whether the situation warrants a VSD, and what documentation should be placed on record before any further steps are taken. Early involvement typically expands the available options; late involvement typically reduces them.

A common objection at this stage is that involving external counsel signals a problem to the counterparty. In our experience, the greater risk is the reverse: proceeding without adequate analysis of a flagged transaction and finding that the omission is later characterised as wilful blindness.

Frequently asked questions

What are the steps to map sanctions risk in the supply chain under BIS / EAR?
Supply-chain sanctions mapping under the EAR follows a defined sequence: (1) confirm whether the goods or technology are subject to the EAR by checking US-origin content, the de minimis threshold, and the FDPR; (2) classify each item against the CCL to identify its ECCN; (3) screen all parties – supplier, intermediary, freight agent, end-user, and ultimate consignee – against the Entity List, Denied Persons List, and Unverified List; (4) assess red flags using the reason-to-know standard; (5) confirm whether a licence exception applies or submit a licence application; (6) document the analysis and build re-screening triggers into the ongoing relationship. The process applies to both physical goods and technology transfers, including deemed exports.
What is the most common mistake in supply-chain sanctions mapping?
The most common mistake is stopping the party screen at the immediate buyer and omitting ownership mapping for intermediate parties and end-users. A direct buyer whose name does not appear on any BIS list may still be owned or controlled by an Entity List party. Similarly, treating EAR99 classification as a signal that no further analysis is needed is a recurring error: EAR99 items exported to Entity List parties, or for prohibited end-uses, still require a licence. A third frequent gap is failing to account for the FDPR, which can bring foreign-produced items within EAR jurisdiction even when the transaction has no apparent US nexus.
How does BIS / EAR differ from other regimes here?
The most important difference is extraterritorial reach. The EAR applies to re-exports of US-controlled items by non-US parties in any country, subject to the de minimis and FDPR thresholds. The EU dual-use regime and the UK export-control regime do not assert equivalent extraterritorial jurisdiction over re-exports from third countries; their controls generally attach at the point of export from the EU or UK. For a supply chain involving US-origin inputs, this means US-export-control obligations travel with the item through every re-export leg. Where both the EAR and another regime apply, the stricter obligation governs. A BIS licence does not discharge a separately applicable EU or UK export authorisation requirement.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.