A trading company sources a specialised component from a US manufacturer. The component falls on the Commerce Control List. The end-user is a distributor in a region subject to heightened BIS scrutiny. Does the exporter need to look past the immediate buyer? What does "knowing" your counterparty actually require under the Export Administration Regulations? The answers determine whether a lawful shipment becomes a criminal export-control violation.
Counterparty due diligence under the BIS / EAR – the Export Administration Regulations (the principal US export-control rulebook administered by the Bureau of Industry and Security) – requires exporters, re-exporters, and transferors to identify and assess every party in a transaction, screen against restricted-party lists, and refuse to proceed where red flags remain unresolved. The legal duty is grounded in the Export Control Reform Act and in IEEPA, with BIS guidance setting out the standard expected of a reasonable exporter. As of August 2026, BIS enforcement posture remains active, with the Entity List expanding regularly to reflect national-security and foreign-policy concerns.
This briefing covers who administers the regime, what the due-diligence obligation requires in practice, how the restricted-party lists interact, where cross-border divergences with OFAC, OFSI, and EU controls create additional exposure, how enforcement works, and when to involve specialist export-control counsel.
Who administers BIS / EAR counterparty due diligence – and what is the legal foundation?
The Bureau of Industry and Security, a division of the US Department of Commerce, administers the EAR and is the primary authority for counterparty due-diligence obligations in US export control. BIS derives its rulemaking power from the Export Control Reform Act and from IEEPA, which together authorise controls on the export, re-export, and in-country transfer of items subject to US jurisdiction.
The EAR covers a defined universe of items: those listed on the Commerce Control List (CCL – the schedule of controlled goods, software, and technology, each assigned an Export Control Classification Number or ECCN), plus items subject to the EAR99 designation (items not specifically listed but still within EAR jurisdiction). Even EAR99 items require due diligence. An EAR99 widget shipped with knowledge that it will be incorporated into a weapons programme triggers liability just as a listed item would.
BIS is not the only US authority in this space. The Department of Justice carries criminal jurisdiction over wilful violations. The Department of State administers ITAR for defence articles. And OFAC operates a parallel sanctions architecture that a BIS-clean transaction can still breach. In our experience advising exporters, the assumption that passing a BIS screen clears all US obligations is one of the costliest errors a cross-border compliance function can make.
What is the scope of the due-diligence obligation under the EAR?
The EAR imposes a standard of knowledge and a duty of reasonable inquiry that together define the counterparty due-diligence obligation. A person acts unlawfully when they export, re-export, or transfer an item "knowing" that a violation will occur – and the EAR defines knowledge to include not only actual awareness but also a conscious disregard of facts that should prompt further inquiry.
BIS has articulated this through its red-flag guidance (a list of indicators that, if present and unaddressed, defeat a claim of good faith). Red flags include: an order for a controlled item with no apparent legitimate end-use; a buyer's refusal to identify the end-user; a request for unusual packaging or shipping routes inconsistent with the destination; payment terms or pricing that do not match a commercial transaction; and a buyer in a country subject to heightened controls who insists on rapid delivery with no documentation review. Any one of these, unresolved, places the exporter on constructive notice.
The practical scope of the obligation moves through four layers:
- Item classification – determine the ECCN or confirm EAR99 status before the transaction, not after.
- Party screening – check all parties against the Entity List, the Denied Persons List, the Unverified List, and the Military End-User List, as well as OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons).
- End-use and end-user review – confirm the stated end-use is consistent with the item's characteristics and the buyer's stated business; escalate when they do not match.
- Red-flag resolution – document the steps taken to resolve any indicator; do not ship while a red flag is live.
Documentation discipline is not optional. BIS inspections and post-shipment verifications often turn on whether a company's files show that it asked the right questions and received credible answers. A paper trail that stops at the first-tier buyer, with no inquiry into the ultimate destination, will not satisfy the standard.
Which restricted-party lists must an exporter check – and how do they interact?
BIS maintains four primary restricted-party lists, each with distinct legal consequences. Understanding what each list means for a transaction is the operational core of BIS / EAR counterparty due diligence.
The Entity List designates foreign parties that BIS has determined pose a risk of diversion or misuse. Exports to Entity-List parties require a licence, and that licence application faces a presumption of denial for most controlled items. The list is expanded regularly; in our practice we have seen clients discover mid-transaction that a counterparty added to the Entity List weeks earlier has rendered a signed supply agreement unperformable without a licence.
The Denied Persons List identifies individuals and companies whose export privileges have been revoked by BIS order. Dealing with a denied person – in any capacity, including as a freight forwarder, financier, or intermediary – is itself a violation. The prohibition is categorical.
The Unverified List is a pre-enforcement signal. Parties appear here when BIS has been unable to verify their bona fides through a post-shipment check. An Unverified List party is not yet prohibited, but shipping to one without resolving the unverified status and without enhanced due diligence creates exposure.
The Military End-User List identifies foreign military end-users in specified countries. Items subject to the Military End-User control require a licence when the listed entity is the end-user or a party to the transaction.
These lists do not operate in isolation. A party may be absent from every BIS list and still appear on the OFAC SDN List, triggering a full asset-freeze and transaction prohibition independent of BIS controls. The prudent compliance function screens all four BIS lists alongside OFAC's SDN List and the OFAC non-SDN lists as a single integrated step.
How does BIS / EAR due diligence compare with OFAC, OFSI, and EU obligations?
BIS / EAR counterparty due diligence and OFAC sanctions screening are distinct obligations that operate in parallel, often on the same transaction. The distinction matters: a transaction can be BIS-clean and OFAC-prohibited, or vice versa. Cross-border businesses routinely underestimate this divergence.
Under OFAC, the primary counterparty test is whether a party is on the SDN List or is owned 50 percent or more by SDN-listed persons in the aggregate – the 50 percent rule. That test is mechanical: if the ownership threshold is met, the entity is blocked regardless of whether it is named. BIS has no identical numerical bright line, but the red-flag and knowledge standards require comparable depth of inquiry into beneficial ownership, particularly where complex ownership structures obscure the ultimate end-user.
OFSI (the Office of Financial Sanctions Implementation in the UK) and the EU Council apply an ownership and control test that is broader than OFAC's mechanical threshold. Under OFSI and the relevant EU Council regulations, an entity is caught not only by direct ownership of 50 percent or more but also by effective control exercised through other means – board dominance, contractual override, or veto rights. A party that clears the OFAC 50 percent screen may still be caught under OFSI or EU rules. For a business operating supply chains that touch the UK and EU as well as the US, all three tests apply concurrently, and the stricter prohibition governs for each leg of the transaction.
The EU dual-use rules and the UK Export Control Order add a further layer for goods, software, and technology with both civil and military applications. Under those regimes, the end-use assurance and end-user certificate requirements broadly mirror the BIS standard but carry distinct procedural requirements and are administered by different authorities – the EU member-state competent authorities and the UK's Export Control Joint Unit (ECJU). In our cross-border practice, we frequently advise businesses that a single product shipment requires coordinated review under BIS, ECJU, and EU dual-use rules simultaneously.
For businesses with exposure to the Singapore, UAE, or Japan regimes, the counterparty-screening obligations are narrower in scope than BIS but still require checking against the UN Security Council Consolidated List and relevant national restricted-party lists. Non-compliance in those jurisdictions can also create reputational exposure and trigger concerns under US secondary-sanctions rules.
The position above covers the standard cross-border comparison. Your facts – the goods, the route, the parties, and the jurisdiction of the receiving entity – change the analysis materially. For a confidential assessment of your cross-regime exposure, contact Calder & Vance at info@caldervance.com.
What are the key risk flags that escalate BIS / EAR counterparty exposure?
Risk flags under the EAR are not abstract; they are the specific indicators that BIS and DOJ examine when assessing whether an exporter had constructive knowledge of a violation. Missing one – or recognising it and failing to document a resolution – transforms a good-faith transaction into a provable violation.
The most common escalating risk factors we see in practice include:
- A counterparty whose stated business does not match the end-use of the item requested (a trading company with no apparent manufacturing capacity ordering precision machining tools).
- A request to ship to a freight forwarder, intermediary, or consolidator rather than directly to a disclosed end-user, with no explanation of the onward distribution.
- A transaction involving a country subject to a comprehensive US sanctions programme or a heightened BIS licence review policy – where the licence exception analysis requires affirmative confirmation of eligibility.
- An end-user that appears on the Unverified List or that previously appeared on a BIS list and was subsequently removed (removal does not erase the prior concern).
- Ownership or management with ties to a jurisdiction subject to BIS export restrictions, undisclosed in the counterparty's representations.
- A request for an unusual export route – transshipment through a third country with no apparent logistical purpose other than obscuring the final destination.
When any of these arise, the obligation is to pause the transaction, investigate, document the findings, and resolve the flag before proceeding. Shipping under time pressure without completing that resolution is exactly the fact pattern that produces enforcement referrals. Have you built a documented escalation path into your export approval process, or does the decision to ship rest on a single compliance officer's unrecorded judgment call?
If a transaction has already been flagged internally, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.
How does BIS enforce counterparty due diligence obligations – and what are the consequences?
BIS enforcement combines administrative penalties, denial of export privileges, and criminal referral to DOJ – and the range of consequences turns directly on whether the violation was wilful, knowing, or negligent, and whether the exporter made a voluntary self-disclosure (VSD – a pre-enforcement report to BIS of an apparent violation).
Administrative penalties for EAR violations can be significant on a per-transaction basis, assessed separately for each unlawful shipment. The EAR treats each consignment as a discrete violation for penalty-calculation purposes. A company with a systemic due-diligence failure – shipping without adequate party screening across multiple transactions – can face aggregate liability that far exceeds any single transaction value. Verify the current penalty bands before relying on any specific figure, as BIS periodically adjusts the schedule.
Denial of export privileges is a structural sanction: a company or individual denied export privileges cannot participate in any EAR-regulated transaction in any capacity, including as a supplier, intermediary, or financier. For an exporter whose core business involves controlled goods, a denial order is operationally catastrophic.
Criminal referral follows where BIS identifies wilful conduct – typically where internal communications show actual knowledge of the prohibited end-use or end-user, or where the company took active steps to conceal the transaction. DOJ prosecutions in export-control matters can result in significant custodial sentences for individuals.
A VSD, properly prepared and submitted, is the single most effective mitigation tool available after an apparent violation is identified. BIS guidance treats a timely, accurate, and complete VSD as a significant mitigating factor in penalty calculation. The window to make a VSD is not unlimited: delay diminishes its mitigating value, and if BIS discovers the violation before the VSD is filed, the voluntary character of the disclosure is lost entirely. In our experience, the decision to self-disclose, and how to scope and frame the disclosure, is one of the most consequential judgment calls an exporter faces after a compliance failure.
Extraterritorial reach extends the enforcement exposure beyond US persons. The EAR applies to items of US origin or containing a threshold proportion of US-controlled content, regardless of where the re-exporter is located. A European or Asian distributor re-exporting a US-origin item without an applicable licence exception or BIS licence faces the same EAR prohibition as the original US exporter – and the same enforcement exposure if BIS or DOJ pursues the matter.
How does a business build a BIS-compliant counterparty due-diligence programme?
A BIS-compliant counterparty due-diligence programme is not a single screening step; it is a repeatable, documented process that applies the EAR's knowledge and red-flag standards at every stage of the transaction lifecycle. The following sequence reflects the standard we apply when reviewing a client's export-compliance function.
- Item classification: Determine the ECCN for every item in the product range. Where an item's classification is genuinely uncertain, obtain a commodity jurisdiction determination or a formal BIS classification request. Do not proceed to party screening until the item's control status is known.
- Party identification: Identify every party to the transaction – seller, buyer, freight forwarder, financial institution, consignee, and ultimate end-user. For multi-leg transactions, map the entire chain before beginning any screen.
- Restricted-party screening: Screen all identified parties against the four BIS lists (Entity List, Denied Persons List, Unverified List, Military End-User List), the OFAC SDN List, and any applicable OFAC non-SDN lists. Run the screen at the time of first engagement and re-run it before shipment; list updates are frequent.
- End-use and end-user verification: Obtain a written end-user statement or end-use certificate for controlled items. Assess whether the stated end-use is commercially plausible given the counterparty's business and the item's characteristics.
- Red-flag resolution: Document the review of every red-flag indicator and the steps taken to resolve or rule out each one. Where a flag cannot be resolved, do not proceed.
- Record-keeping: Maintain records of the classification, screening, end-use review, and red-flag analysis for the period required under the EAR. BIS inspections frequently examine records from prior transaction years; a gap in documentation is treated as evidence of non-compliance, not mere administrative failure.
- Ongoing monitoring: Screen counterparties periodically throughout long-term supply relationships, not only at on-boarding. An existing customer can be added to the Entity List mid-relationship.
A myth we encounter regularly is that smaller exporters are beneath BIS enforcement attention, or that a first-time violation will be treated leniently without a formal compliance programme in place. BIS enforcement actions do not correlate reliably with company size; they correlate with the sensitivity of the item and the visibility of the end-user. A company shipping a modest volume of controlled electronics to a sanctioned end-user without adequate due diligence faces the same exposure as a large industrial exporter – sometimes more, because smaller companies often lack the documented compliance infrastructure that mitigates penalty calculations.
In a recent matter, a mid-sized technology distributor in the Asia-Pacific region discovered, during a contract renewal review, that a long-standing customer had been added to the Entity List during the course of their relationship. The distributor had not re-screened the customer after on-boarding. We assessed the compliance gap, scoped the apparent violation, prepared a voluntary self-disclosure, and advised on the remediation programme. The matter was addressed through the administrative process. No outcome can be guaranteed; the point is that early legal involvement shaped the strategy.
Related practices
- Sanctions compliance audit and testing – independent review of screening logic, ownership mapping, and programme design against the five-element standard.
- Counterparty due diligence under EU sanctions – how the EU ownership-and-control test applies and where it diverges from the BIS and OFAC standards.
- Counterparty due diligence under OFAC – the 50 percent rule, SDN screening, and the interaction with BIS restricted-party lists.