A technology company based in Europe agrees to acquire a US-incorporated software business. The deal looks clean on sanctions screening. But the target holds a portfolio of export licences, ships controlled software to distributors across multiple jurisdictions, and employs engineers who have access to items on the Commerce Control List. Three weeks before signing, the acquirer's legal team realises it has not assessed the target's export-control posture at all. The closing timetable is now the problem.
Sanctions due diligence in M&A under BIS / EAR rules requires an acquirer to assess the target's export-control classification obligations, licence portfolio, end-use controls, and any prior violations before the transaction closes. The Bureau of Industry and Security (BIS) administers the Export Administration Regulations (EAR) under the Export Control Reform Act; a successor entity inherits the target's violations and compliance obligations from the closing date. As of January 2026, successor liability under the EAR is a settled doctrine that deal teams cannot plan around.
This briefing sets out who administers the regime, what the EAR prohibits in an M&A context, how the due-diligence procedure works in practice, where the BIS / EAR analysis diverges from OFAC and from allied regimes, the risk flags that most often surface in cross-border deals, and when to involve specialist export-control counsel.
Who administers BIS / EAR and what legal authority does it carry?
BIS administers the EAR under the Export Control Reform Act, which provides the statutory basis for US controls on the export, re-export, and transfer of commercial and dual-use items. The EAR applies to items subject to US jurisdiction – items physically located in the United States, items of US origin wherever located, and items containing more than a defined threshold of US-controlled content or technology (the de minimis rule). That extraterritorial dimension is what makes BIS due diligence material to any cross-border deal, even where neither the acquirer nor the target is a US entity.
The Commerce Control List (CCL) catalogues controlled items by Export Control Classification Number (ECCN), each carrying a set of reasons for control – national security, missile technology, chemical or biological weapons, anti-terrorism, and others. Items not on the CCL fall under the catch-all designation EAR99, which carries fewer licensing requirements but is not unrestricted: EAR99 items cannot be exported to embargoed destinations, denied persons, or parties on the Entity List (a list of foreign parties subject to licence requirements because of their link to activities contrary to US national-security or foreign-policy interests).
For M&A, the enforcement mechanism matters. BIS can impose civil penalties and, in the most serious cases, refer matters to the Department of Justice for criminal prosecution. The department responsible for a target's export-control compliance is the compliance function – not the commercial team – and in our experience that function is often the last to be consulted in a deal process.
What does the EAR prohibit in an M&A context?
The EAR does not prohibit acquisitions as such, but it attaches obligations and risks to the assets and activities of the acquired entity that transfer to the acquirer by operation of law. Three categories of exposure arise specifically in M&A.
First, inherited violations. If the target has exported or re-exported controlled items without the required licence, under an incorrect ECCN, without the required end-use certificates, or to a denied party, those violations survive the transaction. BIS treats the successor as liable for pre-closing conduct once the acquisition is complete. The acquirer may discover exposure it did not cause and cannot undo – but it can manage the disclosure and remediation process if it identifies the violations before closing.
Second, licence continuity. Licences issued by BIS are specific to the applicant. On a change of ownership, existing licences may not automatically transfer. Where the target's business depends on BIS licences – for example, a defence-technology business supplying allied governments under a government-to-government programme – the acquirer must assess which licences require novation, reapplication, or a prior-approval from BIS before the deal closes. Failing to do so can result in the post-closing business operating without valid authorisation.
Third, the Entity List and denied-persons exposure. The target may have customers, distributors, joint-venture partners, or suppliers that are on the Entity List, the Denied Persons List, or the Unverified List. After closing, the acquirer is transacting with those parties. Its own export-control programme must be capable of identifying and managing that exposure from day one.
Does your deal team know which items in the target's product catalogue carry an ECCN, and which customers they ship to? That question, answered honestly, usually determines how much BIS diligence the deal needs.
How does the BIS / EAR due-diligence procedure work in practice?
Effective BIS / EAR sanctions due diligence in M&A follows a defined sequence of enquiries, each building on the last. The procedure is not simply a list-screening exercise. It maps the target's controlled-item footprint, tests its classification logic, reviews its licence portfolio, and assesses prior conduct.
The first stage is item classification review. Export-control counsel reviews the target's product and technology catalogue and confirms whether items are classified under the CCL, under which ECCN, and with which reasons for control. Misclassification – either overly broad or (more damagingly) insufficiently controlled – is among the most common findings in deal-level diligence. A target that has been treating a controlled item as EAR99 has potentially been operating without required licences for years.
The second stage is licence-portfolio mapping. Counsel identifies every BIS licence currently held by the target, confirms the scope of each (authorised items, authorised parties, end-uses, and geographic limits), and assesses which licences will need to be addressed before or at closing. This includes general authorisations under the EAR: technology-control plans and licence exceptions that the target may have been relying upon without having documented them properly.
The third stage is end-use and end-user verification. The EAR requires that controlled items are exported only for authorised end-uses, to verified end-users. In our practice, we regularly find that targets have sold through distributors who have themselves re-exported without the required authorisation, or who are on the Unverified List because BIS has been unable to confirm their bona fides. Post-closing, those distributors are the acquirer's distribution network.
The fourth stage is prior-conduct review. Counsel reviews the target's export records – shipping documents, Electronic Export Information filings, end-use certificates, and any prior BIS correspondence – for evidence of violations. Where violations are identified, the deal team must assess materiality, consider whether a voluntary self-disclosure (VSD) to BIS is appropriate before closing, and factor the likely BIS response into the deal structure.
In a recent matter, a mid-market industrial manufacturer was acquiring a US target with a mature export business. During classification review, we identified a category of components that the target had been exporting under an incorrect, lower-controlled ECCN for several years. We scoped the apparent violation, advised on the VSD process, and structured the representations and warranties in the purchase agreement to address the exposure. The matter resolved without the deal collapsing, but the timeline required adjustment to allow BIS to process the disclosure.
How does BIS / EAR diligence differ from OFAC and allied regimes?
BIS / EAR and OFAC address different legal questions, even though both are relevant to cross-border M&A and both sit within the US regulatory architecture. The distinction has direct procedural consequences for deal teams.
OFAC sanctions are status-based. A counterparty is either designated – on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) or otherwise subject to a programme prohibition – or it is not. The 50 percent rule (OFAC's rule treating any entity owned 50 percent or more in the aggregate by one or more blocked persons as itself blocked) extends that status automatically to unlisted entities. OFAC diligence in M&A is therefore primarily about identity: who owns the target, and does any owner appear on a consolidated list?
BIS / EAR diligence is conduct- and item-based. The question is not only who the target is, but what it makes, what it ships, to whom, and under what authorisation. A target with no SDN or OFAC exposure can still carry material BIS liability if it has been exporting controlled items to end-users on the Entity List or shipping dual-use technology to restricted destinations without a licence.
This divergence matters for resourcing the deal. Sanctions screening tools address the OFAC question efficiently. They do not address the EAR question at all. BIS / EAR diligence requires a separate workstream with export-control specialists, access to the target's product documentation and shipping records, and the ability to interpret CCL classification criteria.
Allied-regime divergence adds a further layer. Under the EU's dual-use rules, controlled items may carry different control reasons and different licence requirements than their EAR counterparts. A product that requires a BIS licence for export to a particular destination may be freely exportable under the EU regime, or vice versa. For deals involving European acquirers or targets with EU operations, the two regimes must be assessed in parallel – the stricter prohibition governs for the entities subject to it. Our cross-border practice addresses this on EU sanctions due diligence in M&A as well.
The UK export-control regime, administered by ECJU, maintains its own control list and licensing architecture that diverged from the EU position after 2020. A deal involving a UK-incorporated entity or UK-based technology will require ECJU assessment alongside the BIS workstream. For completeness, Asian-jurisdiction exposure – common in supply-chain-intensive deals – is addressed in our related briefing on sanctions due diligence in M&A under Japan's regime.
What are the BIS / EAR risk flags that most often arise in deals?
Experienced M&A teams know the OFAC red flags: an SDN-adjacent shareholder, a counterparty routed through a high-risk jurisdiction, a beneficial owner who cannot be identified. BIS risk flags are less familiar, and they surface later in deal processes – often at the point when the acquirer's integration team starts reviewing the target's operations.
The following situations are, in our experience, the most reliable indicators of potential BIS / EAR exposure in a target.
- Technology-intensive products with broad international distribution. A target that manufactures controlled hardware or software and ships globally through third-party distributors is exposed to re-export risk it may not have monitored. Ask for the distributor agreements and the end-user-certificate programme.
- Customers or suppliers in high-risk export-control destinations. Some jurisdictions are subject to comprehensive controls under the EAR regardless of the item's classification. A target with active customers in any such destination warrants close review of its licence portfolio and shipping records.
- Reliance on deemed-export authorisations. A deemed export occurs when technology is released to a foreign national in the United States – for example, an employee who is a national of a controlled destination. Where a target employs a significant proportion of foreign nationals working on controlled technology, its deemed-export controls and any applicable licence conditions must be assessed before the acquirer takes on those employees and that technology.
- Prior BIS correspondence or voluntary disclosures. Any prior communication from BIS – a warning letter, a Commodity Classification request, a prior VSD, or a request for information – is a direct signal that the target has been under scrutiny. In our experience, these documents are not always disclosed promptly in a data-room process; a targeted request is necessary.
- Post-acquisition integration plans that involve technology transfer. If the acquirer's integration model involves transferring the target's controlled technology to non-US engineering teams, that is itself a re-export or deemed re-export. The deal diligence must assess whether the planned integration is lawful under the EAR before the integration commences, not after.
If the position above covers the standard case, your facts – the target's product line, its customer geography, its prior compliance history, and the acquirer's integration intentions – change the analysis. For an early-stage assessment of BIS / EAR exposure in a deal, contact Calder & Vance at info@caldervance.com.
How is BIS / EAR export-control compliance enforced after closing?
BIS enforcement in an M&A context operates on the basis that the acquiring entity succeeds to the target's compliance obligations and – critically – to any violations that existed at the time of closing. This is successor liability, and it applies whether or not the acquirer had knowledge of the underlying conduct at the time of the transaction.
The penalty regime under the EAR is tiered by the seriousness of the conduct. At the civil level, penalties can reach significant per-violation figures. Criminal exposure arises where BIS refers a matter to DOJ, typically in cases involving wilful violations, repeated conduct, or items with direct weapons-proliferation relevance. Record-keeping violations – failing to maintain the shipping documents, end-use certificates, and export records that the EAR requires – carry their own penalty exposure. The record-keeping obligation runs for a defined period from the date of the transaction; verify the current period before relying on it.
VSD is a material tool in post-acquisition enforcement management. Where the due-diligence process surfaces apparent violations, an acquirer that discloses to BIS before closing – or promptly after closing once the facts are confirmed – is generally treated more favourably in enforcement than one that does not. The EAR's VSD procedure has a structure, a timeline, and a set of disclosures that must be made accurately; it is not an informal conversation with the regulator. Specialist export-control counsel should manage the process.
The financial-institution dimension should not be overlooked. Banks and payment firms processing deal-related transactions are subject to their own BIS / OFAC compliance obligations. A correspondent bank presented with a deal involving a target under BIS scrutiny may freeze or decline the transaction. For businesses managing the financing side of a cross-border deal, our related service on correspondent banking and de-risking under OFAC sets out the relevant considerations.
If a transaction has already been flagged, or a BIS filing has been refused or queried, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss an enforcement or disclosure matter.
A common misconception: "Our target has no SDN exposure, so BIS is not an issue"
The single most persistent misconception we encounter among acquirers – and sometimes among their advisers – is that a clean OFAC screen means a clean export-control position. It does not. OFAC and BIS address different legal questions with different analytical tools.
OFAC's SDN List does not reflect BIS's Entity List. The two lists are maintained independently, under different statutory authorities, by different parts of the US government. A party can appear on the Entity List without appearing on the SDN List, and vice versa. More importantly, BIS exposure in a deal can arise entirely without any party being listed anywhere – it arises from what items the target ships, under what classification, to which destinations, and with what authorisation. That is a factual and technical analysis, not a list-matching exercise.
The second misconception is that BIS diligence is only relevant for defence contractors and technology companies. That view is increasingly dated. The scope of items subject to the EAR has expanded significantly in recent years, particularly in areas including advanced semiconductors, artificial intelligence infrastructure, certain manufacturing equipment, and biotechnology. A target that considers itself a conventional industrial business may nonetheless hold controlled technology within the meaning of the EAR. Classification review is the only way to confirm the position.
In our cross-border practice, we advise deal teams early in the process – at the stage when scope decisions are made – rather than at the point when BIS exposure has already been discovered under pressure of closing. The cost difference is significant.
Related practices
- Correspondent Banking and De-Risking under OFAC – managing bank counterparty and transaction exposure in cross-border deals
- EU Sanctions Due Diligence in M&A – Council-regulation obligations and dual-use rules for European deal teams
- Sanctions Due Diligence in M&A: Japan Regime – Japan export-control and sanctions obligations in cross-border transactions