Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · BIS / EAR

Sanctions compliance programmes under BIS / EAR: explained

An exporter finalises a distribution agreement. The goods are dual-use. The end-customer sits in a jurisdiction where the Export Administration Regulations (the EAR – the US export-control rules administered by the Bureau of Industry and Security, or BIS) impose licence requirements for certain items. The exporter's compliance team knows the rules exist. What it has not done is build the internal controls to catch that question before the contract is signed. That gap is precisely where BIS enforcement begins.

Sanctions compliance programmes under BIS / EAR rules are the documented, operational controls an organisation uses to identify licence requirements, screen end-users, and prevent unlicensed exports of items subject to the EAR. BIS has published a framework – the Export Management and Compliance Programme (EMCP) – setting out the elements it expects to see. As of mid-2026, BIS treats the presence or absence of a functioning programme as a material factor in penalty calculations and voluntary self-disclosure decisions.

This briefing explains who administers the regime, what the programme must contain, how it compares with UK and EU export-control compliance expectations, where programmes typically fail, and when to bring in specialist counsel.

Who administers the BIS / EAR regime and what is its legal basis?

BIS administers the EAR, which derives its authority from the Export Control Reform Act and, ultimately, from the power granted under IEEPA and related statutes. The EAR controls the export, re-export, and in-country transfer of items – goods, software, and technology – that appear on the Commerce Control List (CCL), as well as items not on the CCL but still subject to the EAR's catch-all and anti-diversion rules.

BIS operates alongside OFAC within the broader US export and sanctions apparatus. The distinction matters: OFAC administers economic sanctions that prohibit transactions with listed persons and designated countries, while BIS regulates the movement of controlled items regardless of who receives them. A transaction can pass OFAC screening and still require a BIS licence. In our practice, conflating the two is one of the most common errors we see in compliance programme design.

Within BIS, the Office of Antiboycott Compliance and the Office of Export Enforcement (OEE) share responsibility for outreach, guidance, and enforcement. OEE conducts investigations, executes administrative subpoenas, and refers serious matters to the Department of Justice for criminal action. Penalties under the EAR can reach very significant civil and criminal levels; verify the current figures before relying on them, as monetary caps are subject to periodic statutory adjustment.

What does a BIS / EAR compliance programme have to contain?

BIS's EMCP guidance sets out the structural elements it expects a serious programme to address. No single document format is mandated, but the guidance describes a recognisable architecture. Programmes that omit elements are treated as indicators of systemic non-compliance rather than isolated procedural gaps – a distinction that affects both whether BIS pursues a matter and how it resolves it.

The core elements are:

  • Management commitment – a visible, board-level or senior-management endorsement that the programme is a business priority, not a legal formality.
  • Export classification – procedures for determining the ECCN (Export Control Classification Number under the CCL) for every product, technology, and item of software. Classification drives everything downstream: if the ECCN is wrong, the licence determination is wrong.
  • Licence determination and application – a documented decision tree for applying licence exceptions (standing authorisations that permit certain transactions without a separate application) and, where no exception is available, for applying for a specific licence.
  • Screening and end-use controls – systematic screening of customers, end-users, and consignees against the BIS Entity List, the Denied Persons List, the Unverified List, and OFAC-administered lists. This is where the BIS and OFAC programmes intersect.
  • Record-keeping – the EAR requires exporters to maintain export records for five years from the date of export, re-export, or in-country transfer, or five years from the date of any applicable licence or authorisation, whichever is later.
  • Training – documented initial and refresher training for all personnel involved in export decisions, licensing, logistics, and sales.
  • Audit and self-assessment – periodic internal review of transactions, classifications, and screening outcomes to detect errors before they become violations.
  • Corrective action and voluntary self-disclosure (VSD – a formal notification to BIS that the company has identified an apparent violation) – BIS's penalty guidelines treat a timely, complete VSD as a significant mitigating factor.

The position above covers the standard case. Your facts – the product mix, the geography of your distribution network, the identity of the end-user, and the route of the shipment – change the analysis materially. For a review of how these elements apply to your specific programme, contact Calder & Vance at info@caldervance.com.

How does the BIS / EAR programme standard compare with the UK and EU approaches?

BIS's EMCP is the most codified of the three major Western export-control compliance frameworks, but it operates alongside – and is sometimes overridden by – the UK and EU regimes when goods transit through or originate in those jurisdictions. Understanding the divergences is not an academic exercise. A multinational that designs its programme solely around the EAR will have gaps where the UK Export Control Order or EU dual-use rules impose different classification standards, different end-user assurance requirements, or different reporting obligations.

Three areas of practical divergence stand out.

Classification systems. The EAR uses the CCL and ECCN system. The UK and EU use their own control lists, derived from the Wassenaar Arrangement classifications but not identical to them. An item that falls under one ECCN in the US may attract a different control entry in the UK or EU – or may sit on one list but not another. Classification must be done in parallel for a multi-origin supply chain, not transposed from one regime to the other.

Re-export and extraterritorial reach. The EAR's de minimis rule and foreign direct product rule (FDPR) extend US jurisdiction to non-US goods that incorporate controlled US content or that are produced using certain US technology or equipment. UK and EU export controls follow territorial and origination principles and do not have equivalent provisions. This asymmetry means a UK manufacturer exporting goods with embedded US technology may be subject to BIS controls regardless of whether it ever exports to or from the United States. In our cross-border practice, we regularly advise clients who first encounter EAR extraterritoriality mid-transaction rather than at programme design stage.

Ownership and control screening. OFAC's 50 percent rule (treating entities owned 50 percent or more by blocked persons as themselves blocked) is a US-specific mechanical test. The UK and EU apply a broader ownership and control test that can catch entities below that ownership threshold. A programme that screens against the SDN List but does not apply OFSI's or the EU's control analysis may clear a counterparty under OFAC standards while missing a prohibition under the applicable UK or EU regime.

For a detailed treatment of the EU programme standard, see our Regime Briefing on sanctions compliance programmes under EU rules. The Japan approach – which is increasingly relevant for electronics, semiconductor equipment, and advanced materials exporters – is examined in our Regime Briefing on compliance programme design under Japan's export-control regime.

Where do BIS / EAR compliance programmes most commonly fail?

BIS enforcement actions and the firm's advisory work point to a consistent set of failure patterns. They rarely involve deliberate evasion. More often, they reflect a programme that was designed once and then not maintained, or one whose scope was drawn too narrowly at the outset.

The most frequently recurring gaps are as follows.

Static classification libraries. Products evolve. Firmware updates, new software modules, and hardware revisions can change an item's ECCN. A company that classified its product range two years ago and has not revisited classifications since the last product revision is operating on stale data. BIS does not accept that an old classification covers a materially modified item.

Incomplete end-user screening. Screening the direct customer is necessary but not sufficient. The EAR's know your customer guidance directs exporters to look through the transaction to the likely end-user, particularly where there are red flags (indicators of possible diversion). A distributor in a permitted country buying items in quantities inconsistent with its own market is a textbook red flag. We have acted for exporters who had robust customer-screening tools but no procedure for assessing the consignee's own customers.

Unverified List and Entity List gaps. Many compliance systems are calibrated primarily to the SDN List. BIS's own lists – the Entity List, the Denied Persons List, and the Unverified List – require separate and current screening. An entity on the Unverified List cannot simply be screened out and cleared; EAR rules impose specific due-diligence steps before proceeding. Those steps are distinct from the treatment of SDN-listed parties, and a single combined screening tool will not automatically apply the correct rules for each list type.

Licence exception misapplication. Licence exceptions reduce administrative burden but carry conditions. Technology Control Plans, end-user certificates, and post-shipment verification requirements attach to particular exceptions. When the conditions are not met – because they were not documented, not communicated to logistics, or not followed in practice – the exception is unavailable retroactively and the shipment becomes an apparent violation.

No programme for deemed exports. The EAR's deemed export rule treats the release of controlled technology or source code to a foreign national within the United States as an export to the person's country of nationality. Employers in technology, research, and manufacturing frequently overlook this. A compliance programme that covers only physical shipments misses an entire class of controlled transfers occurring in offices, laboratories, and cloud environments.

If a transaction has already been flagged, a shipment held, or a filing refused, an early review can preserve options that narrow with time. For a confidential assessment of an apparent BIS / EAR compliance gap, contact Calder & Vance at info@caldervance.com.

How is a BIS / EAR compliance programme enforced, and what does a VSD achieve?

BIS enforcement runs through two primary channels: administrative proceedings before an administrative law judge, leading to civil penalties and denial orders; and criminal referral to the Department of Justice, which can result in prosecution of individuals and entities. The civil and criminal channels can operate in parallel, and both can touch non-US parties where the EAR's extraterritorial provisions apply.

A denial order – a BIS administrative order prohibiting an entity from participating in any transaction subject to the EAR – is one of the most operationally disruptive outcomes BIS can impose. It affects not just the company's own exports but any transaction in which the denied person is involved, including purchases of US-origin items by third parties. For a multinational, a denial order against one group entity can disrupt the entire supply chain.

BIS's penalty framework distinguishes between egregious and non-egregious violations, and between cases where a VSD was filed and cases where it was not. Filing a timely and complete VSD – covering the full scope of the apparent violation, not a curated subset of it – is treated as a significant mitigating factor. It does not guarantee a reduced penalty, and it does not immunise against criminal referral where the conduct is sufficiently serious. However, experience consistently shows that entities that self-disclose, co-operate fully, and present a remediated programme are treated more favourably than those discovered through third-party reporting or OEE investigation.

The VSD process requires care. A disclosure that under-reports the scope of the apparent violation, or that is filed before the internal review is complete enough to be accurate, can create additional exposure. We regularly advise on scoping internal reviews, preparing VSD submissions, and managing BIS's queries during the review period.

A common misconception: does a strong OFAC programme cover BIS obligations?

A persistent assumption among compliance teams is that a well-designed OFAC programme – with SDN screening, transaction monitoring, and a licencing procedure – provides adequate coverage for BIS obligations. It does not, and treating the two as interchangeable is a structurally significant gap.

OFAC and BIS share some screening targets. The SDN List is relevant to both regimes, and both impose record-keeping and training expectations. But the EAR's classification, licence-exception, end-user assurance, deemed-export, and re-export controls are entirely distinct from OFAC's transaction-prohibition structure. An OFAC programme answers the question "is this party or country prohibited?" The EAR programme answers the additional questions: "is this item controlled, what is its ECCN, what licence requirement applies, is an exception available and satisfied, and who is the actual end-user?"

The gap is widest for technology companies, manufacturers, and distributors. Financial institutions whose primary BIS exposure is to the Financial Action Task Force – referenced EAR financial-services provisions sometimes manage with a lighter export-control overlay, but that is a risk decision, not a compliance safe harbour. Any business whose product line includes items that appear on the CCL, or that embeds US-origin technology in goods manufactured elsewhere, needs a BIS-specific programme element that goes well beyond SDN screening.

We have acted for a technology-sector business that had invested significantly in its OFAC compliance infrastructure – automated screening, a licensing team, documented procedures for blocked property. When it received an OEE inquiry about a series of technology transfers, it became clear that its export-control classification process was inconsistent, its licence exception documentation was incomplete, and it had no deemed-export procedure. The OFAC programme was sound. The BIS gap was material. The matter was resolved through a scoped internal review, a VSD covering the relevant period, and a remediated programme. No outcome is predictable in enforcement proceedings, but early action and a credible remediation plan consistently improve the position.

Related practices

Frequently asked questions

Who administers sanctions compliance programmes under BIS / EAR?
BIS – the Bureau of Industry and Security within the US Department of Commerce – administers the EAR and sets the EMCP standard for export-control compliance programmes. Within BIS, the Office of Export Enforcement investigates apparent violations and conducts outreach. The Department of Justice handles criminal prosecutions arising from serious EAR violations. OFAC administers the separate economic-sanctions programmes; the two agencies operate in parallel and a transaction may require compliance with both.
What does BIS / EAR prohibit in relation to sanctions compliance programmes?
The EAR does not mandate a specific programme structure, but it prohibits the export, re-export, and in-country transfer of controlled items without the required licence or applicable licence exception. A deficient compliance programme is not itself a violation; it is evidence of systemic non-compliance that aggravates the treatment of underlying violations. BIS also prohibits proceeding with a transaction when known red flags have not been resolved, regardless of whether a formal programme exists.
How is sanctions compliance enforced under BIS / EAR?
BIS enforces the EAR through civil administrative proceedings – which can result in monetary penalties and denial orders – and through criminal referrals to the Department of Justice for the most serious violations. BIS's penalty guidelines distinguish egregious from non-egregious conduct and reduce penalties where a complete VSD has been filed. OEE conducts investigations, issues administrative subpoenas, and can refer matters involving individuals as well as corporate entities. The presence of a functioning, documented compliance programme is a material mitigating factor in penalty determinations.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.