A manufacturer of specialised industrial components — call it a mid-size precision-engineering firm operating across three continents — receives a purchase order from a distributor it has supplied for years. The order looks routine. The goods are listed items under the Export Administration Regulations (the EAR, the US Bureau of Industry and Security's principal trade-control instrument). A junior compliance officer runs the distributor's name through a standard screening tool. Nothing flags. The order ships.
What the screen missed was a second-tier customer — a manufacturer three links down the supply chain — that appeared on the Entity List (BIS's list of foreign persons and organisations subject to specific licence requirements under the EAR). The shipment had reached a restricted end-user. Under the EAR, licence requirements attach to the controlled item and follow it to its destination and ultimate end-user, not merely to the immediate buyer. A clean first-tier screen does not discharge that obligation.
This case comment examines how supply-chain sanctions mapping under the BIS / EAR works in practice, where the specific failure arose in this matter, how the issue was resolved, and what compliance teams at exporters and trading houses should take from the experience. The cross-border dimension — where UK export controls and EU dual-use rules interact with the EAR's extraterritorial reach — adds a further layer this page addresses directly.
The situation: a routine order with a non-routine end-user
The matter arose in the industrial manufacturing sector, where end-use chains are often long and the ultimate destination of a controlled item can be genuinely difficult to trace. The exporting firm held an appropriate internal export-compliance programme. Its screening covered direct customers against the consolidated US restricted-party lists and the SDN List (OFAC's list of Specially Designated Nationals and blocked persons), the UK financial-sanctions lists, and the EU consolidated list. First-tier diligence was, by conventional standards, adequate.
The problem was structural rather than procedural. The firm's compliance architecture treated its direct customer — the distributor — as the end-user for classification and licence-determination purposes. That assumption sat unexamined in the compliance programme for some years. It was not challenged by the internal audit function and was not flagged in the firm's most recent export-compliance review. The result was that the EAR's end-user and end-use obligations — which require the exporter to exercise reasonable care to ensure the item does not reach a prohibited destination or person — were assessed only at the first tier.
When the issue surfaced — through a voluntary internal review prompted by a compliance refresh rather than by a regulator — the firm discovered that its distributor had been systematically on-selling controlled items to a restricted manufacturer. That manufacturer's listing had been in place for over a year. The exporter had, across multiple transactions during that period, supplied items that reached a person for whom a BIS licence was required and had not been obtained.
What does the EAR actually require of an exporter in the supply chain?
The EAR imposes an affirmative obligation on the US-origin exporter — and, through the EAR's reach, on any re-exporter of US-origin or US-controlled technology — to assess the end-user and the end-use of a controlled item, not merely the immediate purchaser. This is the core discipline of supply-chain sanctions mapping under the BIS / EAR framework.
Under the EAR, a controlled item is classified by its ECCN (Export Control Classification Number under the US Commerce Control List), which determines whether a licence is required for a specific destination, end-use, or end-user. Entity List restrictions operate as an overlay: once a person appears on the Entity List, any item subject to the EAR that is exported, re-exported, or transferred to that person requires a licence — regardless of the item's ECCN classification or the licence exception that might otherwise apply. The licence exception is not available where the Entity List footnote specifically removes it.
What this means for supply-chain management is precise. The exporter's compliance function must ask three questions for every transaction: first, what is the item's classification and does the destination trigger a licence requirement; second, are any of the end-users in the known or reasonably knowable distribution chain listed persons; and third, are there red flags indicating a prohibited end-use, even if no person is formally listed. Failure to ask the second question — as occurred here — is the most common structural gap we identify in export-compliance programmes.
In our practice, the gap is not usually deliberate. It reflects a compliance architecture designed for the immediate customer and not for the downstream chain. Firms that built their programmes when their customer base was domestic or limited to low-complexity export destinations often carry this architectural deficiency into an enlarged, more complex supply chain without adjusting the programme's scope.
How does BIS / EAR supply-chain mapping compare with the UK and EU approaches?
Cross-border exporters rarely operate under a single regime. The BIS / EAR sits alongside the UK export-control regime administered by the ECJU (Export Control Joint Unit) under the Export Control Order, and the EU dual-use controls under the relevant Council Regulation on dual-use items. All three regimes require end-user assessment, but they diverge in important ways.
Under the EAR, the Entity List operates as a bright-line restriction: any EAR-controlled item to a listed person requires a licence, and there is no general administrative discretion to waive that requirement absent a formal licence. The UK regime imposes a comparable structure for items listed under the UK strategic export-control lists, but the enforcement posture and guidance differ from BIS practice, and the UK operates its own restricted-party lists that do not mirror the Entity List identically. The EU dual-use controls require member-state licensing authorities to assess end-use and end-user — including potential diversion — but the EU does not maintain a direct equivalent of the Entity List; instead, it addresses similar concerns through the trade-restrictive measures that form part of the relevant Council Regulations and through catch-all controls that can apply to non-listed items where a prohibited end-use is known or suspected.
In this matter, the exporting firm also held an ECJU open export licence covering the items in question. That licence carried specific conditions on end-user documentation. When the matter was reviewed, it became clear that those conditions had not been assessed against the downstream customer identified on the Entity List. The UK exposure ran in parallel with the US exposure, arising from the same factual pattern but under different legal instruments. A compliance correction addressing only the EAR dimension would have left residual UK liability unresolved.
The cross-border interaction is where exporters most frequently underestimate their exposure. When you are licensed under one regime and compliant on paper, it is easy to assume the analysis is complete. It rarely is. The stricter prohibition governs, and two parallel regimes operating on the same transaction can create compound liability.
What are the key risk flags in supply-chain end-user mapping?
Several risk flags, had they been examined, would have identified the problem before it became a compliance event. Practitioners advising on EAR matters note that these patterns recur across sectors and company sizes.
- Distributor concentration. Where a distributor accounts for a high proportion of a controlled item's total sales into a region, and where the distributor's own customer base is opaque, the end-user chain deserves direct scrutiny rather than reliance on the distributor's representations alone.
- Absence of end-user certificates or their equivalent for items above a specified control level is itself a flag. A distributor that resists providing downstream customer information for a controlled item warrants further inquiry.
- Discrepancies between the distributor's stated business and the volume or technical specification of items ordered can indicate that goods are reaching an end-user whose needs differ from the stated application.
- The destination country's risk profile under both the EAR's country-group structure and any applicable secondary-sanctions analysis should inform the depth of diligence applied to the distributor's downstream chain.
- A distributor operating in a sector — defence, aerospace, advanced electronics, certain industrial processes — that is a frequent target of dual-use diversion schemes should trigger enhanced end-user mapping, even where the distributor itself is not listed.
In our cross-border practice, we regularly advise exporters to map the supply chain graphically, entity by entity, before applying screening tools rather than after. Screening a list of names is a different exercise from understanding the structure of a distribution network. The former is a filter; the latter is analysis. Only analysis reveals the pattern that emerged in this matter.
How was the BIS / EAR issue resolved?
Once the internal review identified the apparent violation, the firm faced a time-sensitive set of decisions. The core question was whether to make a VSD (voluntary self-disclosure to a regulator) to BIS and, in parallel, a disclosure to the ECJU on the UK side. A VSD is not a guarantee of reduced liability, but BIS guidance — and ECJU practice — recognises it as a significant mitigating factor in penalty determinations.
We were instructed at the point of the internal review's preliminary findings. The first task was to scope the apparent violation: to trace all shipments potentially affected, establish which items were subject to the EAR and at what classification level, confirm whether any applicable licence exception had been available and inadvertently foregone (it had not — the Entity List footnote in question expressly removed the relevant exception), and assess the export value and duration of the exposure.
The scoping exercise covered transactions across a period of over twelve months. It required retrieval and review of shipping documentation, export control records, and distributor correspondence. Export-control record-keeping obligations exist under both the EAR and the UK regime for a defined period; the firm had maintained its records and was able to reconstruct the transaction history in full. That record integrity materially assisted the disclosure and the subsequent regulatory engagement.
On the UK side, the parallel ECJU matter required separate analysis of the export licence conditions and a separate disclosure process. Although both disclosures arose from the same factual matrix, the legal instruments, the procedural requirements, and the agencies receiving the disclosures were distinct. A single disclosure document would not have served both purposes.
The matter proceeded through the BIS disclosure process. The firm implemented a compliance remediation plan — redesigning its supply-chain end-user mapping to extend screening to the second and third tiers of known and reasonably knowable customers, revising its distributor agreements to include contractual end-user obligations, and introducing a periodic compliance audit of its largest distributor relationships. The remediation plan was submitted as part of the disclosure package.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Reaching experienced export-control counsel promptly — before the disclosure is drafted — avoids the most common errors in scope assessment and framing that can complicate an otherwise well-intentioned disclosure. Contact Calder & Vance at info@caldervance.com for a confidential initial review.
The lesson: what should exporters take from this matter?
The lesson is not that this firm's compliance team was negligent in any culpable sense. The lesson is that a compliance programme designed for first-tier counterparty screening will fail, systematically and predictably, in a supply chain where controlled items pass through distributors into downstream customer bases that are not visible to the programme.
The EAR does not limit an exporter's obligations to its direct customer. It asks whether, in the exercise of reasonable care, the exporter knew or should have known that a controlled item was destined for a prohibited person or use. A compliance programme that structurally cannot answer that question — because it does not look beyond the first tier — falls below the standard the regime expects, even if every individual transaction appears clean at the point of shipment.
There is a myth worth addressing directly here, because we encounter it regularly in instructions from cross-border exporters: "We screened our customer; they are clean; our obligation ends there." Under the EAR, that position is incorrect. Under the UK Export Control Order and the EU dual-use controls, it is equally insufficient for items above a certain sensitivity. The distributor's clean status does not transfer to the end-user. The obligation to exercise reasonable care in end-use and end-user assessment is the exporter's own, and it is not discharged by the distributor's representations alone, absent corroborating documentation and a programme designed to evaluate it.
What a well-designed supply-chain sanctions mapping programme looks like in practice is not dramatically different from what this firm already had — it is an extension of it. The same tools, the same lists, the same classification logic. The difference is in the architecture: the programme must reach down the known and reasonably discoverable distribution chain, apply screening to second-tier customers where the goods are controlled and the sector risk is elevated, and document the analysis for each transaction. That documentation serves both as a compliance record and as the foundation of any disclosure or penalty defence that may later be required.
As of January 2026, BIS has continued to emphasise supply-chain diligence and end-user controls as a priority enforcement area. The entity-listing programme has expanded in several dual-use technology sectors. Exporters whose programmes were designed before that expansion should assess whether their architecture still reflects the current risk environment.
A common misconception: one regime's clean screen means cross-border clearance
The misconception that a clean OFAC screen or a clean EU consolidated-list screen resolves the BIS question is one of the most consequential errors in cross-border export compliance. The three regimes — OFAC, BIS, and the EU dual-use controls — each maintain separate restricted-party lists with separate legal bases and separate entry criteria. A person can appear on the Entity List without appearing on the SDN List. A person can appear on a UK financial-sanctions list without appearing on either. Cross-referencing is not optional; it is the baseline.
In this matter, the downstream customer appeared only on the Entity List. The OFAC SDN screen produced no result. A compliance programme that treated the OFAC screen as the primary or sole control produced false comfort. The BIS exposure was independent and unrelated to any OFAC designation.
We regularly advise firms on the interaction between these regimes in the context of cross-border supply chains. The starting point is a regime map: which instruments apply to the goods, to the exporter or re-exporter, and to each country in the chain. Once that map is complete, the relevant lists for each instrument can be identified, and the screening architecture built to cover all of them. A programme that applies only the most visible list — typically the OFAC SDN List, which attracts the most commercial screening tool investment — leaves significant gaps.
Related practices
- Correspondent banking and de-risking under OFAC – managing financial institution sanctions exposure across correspondent relationships
- Supply-chain sanctions mapping: an OFAC matter – a parallel case comment examining the OFAC dimension of supply-chain end-user mapping
- Trade transaction screening: a BIS / EAR matter – a companion matter examining transaction-level EAR screening failures and their resolution