An export of controlled technology clears customs. Six months later, a routine audit surfaces a classification error. The item needed a licence. None was obtained. The question facing the compliance team is not whether a violation occurred – it did – but what happens next, and how badly the company is exposed.
Enforcement risk after a breach under BIS / EAR rules is administered by the Bureau of Industry and Security within the US Department of Commerce. The Export Administration Regulations govern what is controlled and what penalties apply. A single apparent violation can attract a civil penalty per transaction, and criminal referral to the Department of Justice is available for wilful violations. The outcome depends heavily on how the company responds in the hours and days after discovery.
This briefing sets out the BIS enforcement regime – who administers it, what triggers a case, how the procedure runs, how the penalties are calculated, and where the critical decision points lie. It also compares the BIS approach with the OFAC and OFSI enforcement postures, because a company with cross-border exposure is rarely dealing with only one regime.
Who administers BIS / EAR enforcement, and under what authority?
The Bureau of Industry and Security administers the Export Administration Regulations under authority delegated through the Export Control Reform Act and the International Emergency Economic Powers Act. BIS sits within the US Department of Commerce. Its Office of Export Enforcement – OEE – conducts investigations, executes administrative proceedings, and refers criminal matters to DOJ. The distinction between a Commerce-led civil matter and a DOJ criminal prosecution is one of the most consequential facts in any post-breach assessment.
The legal instruments are generic in the way sanctions lawyers use that term: the EAR as a whole, the Commerce Control List, and the Entity List together form the operating architecture. An item is controlled if it carries an Export Control Classification Number (ECCN, its assigned position on the Commerce Control List that determines which licence requirements and exceptions apply) that triggers a licence requirement for the destination, end-user, or end-use in question. Where an item has no ECCN and is designated EAR99, it generally requires no licence – but the end-user and end-use checks remain, and Entity List restrictions apply independently of classification.
BIS also administers Denied Persons Orders and Temporary Denial Orders (TDOs) – the latter being emergency measures that can halt a company's export privileges immediately, without a full hearing. A TDO is one of the most disruptive remedies in the BIS toolkit. We regularly advise exporters on the steps that reduce TDO risk in the period between self-disclosure and final resolution.
What triggers a BIS enforcement case after a breach?
An enforcement case begins when OEE becomes aware of an apparent violation – either because the company disclosed it, because a third party reported it, because OEE's own intelligence and investigation work surfaced it, or because a related OFAC or customs matter drew BIS into the picture. The trigger is important because self-initiated disclosure is the single most effective mitigation factor in the BIS penalty scheme.
Common trigger events include: a classification error that leads to an unlicensed export; a shipment to a party that has since appeared on the Entity List (or was already on it); a re-export by an overseas distributor without the required authorisation; a deemed export of controlled technology to a foreign national on a restricted list; or a technology transfer that occurs during a commercial partnership without an appropriate licence exception being assessed. In our cross-border practice, the deemed-export category – where the "export" is a disclosure of controlled source code or technical data to a foreign national inside the United States – generates some of the most overlooked exposure.
A further trigger that multinationals underestimate: extraterritorial reach. The EAR applies to US-origin items and US-person transactions wherever they occur. A German subsidiary shipping a US-origin item from Germany to a restricted destination needs BIS authorisation, not merely German export approval. This is where BIS enforcement diverges sharply from domestic trade assumptions, and why a purely local compliance review misses the risk.
How does the BIS enforcement procedure run from discovery to resolution?
Once an apparent violation is identified, the procedure follows a broadly predictable sequence – but the timing at each stage is largely within BIS's discretion, and the company's conduct throughout shapes the outcome.
The first decision is whether to make a voluntary self-disclosure (VSD, a formal written submission to OEE reporting the apparent violation before BIS becomes aware of it through other means). BIS's penalty guidelines treat a timely VSD as a significant mitigating factor. The initial notification should be submitted promptly; a more complete narrative report follows within a defined period. Missing or delaying that initial notification reduces the mitigation credit available.
After a VSD or after OEE opens an independent investigation, the agency may issue a Request for Information, conduct site visits, take witness statements, or issue subpoenas. The company is expected to cooperate – and non-cooperation is itself an aggravating factor. At the close of the investigation, BIS may offer a settlement. Most civil enforcement matters settle. A settlement takes the form of a Charging Letter resolved by consent order, carrying a civil penalty and potentially a period of suspended or active denial of export privileges.
If the matter is not settled, BIS can refer it to an Administrative Law Judge. Criminal referrals to DOJ follow a separate path; the standard is whether the violation was wilful. Parallel criminal and civil proceedings are possible. The company's legal team needs to assess both tracks simultaneously from the moment a potentially wilful element appears.
Under OFAC – the comparable US sanctions enforcement authority – the voluntary self-disclosure scheme operates similarly, but the statutory penalty bases, the aggravating factor list, and the licensing interaction differ. Where a transaction touches both export controls and financial sanctions (a payment for a controlled item to a restricted destination, for example), BIS and OFAC may both open files. Coordination between the two is common; the company should assume both agencies are informed.
How does BIS calculate the civil penalty after a breach?
The civil penalty calculation under the EAR applies per violation – meaning per transaction, per shipment, or per unlicensed disclosure. Where a course of conduct involves multiple shipments over time, the aggregate exposure multiplies quickly. BIS publishes penalty guidelines that weigh aggravating and mitigating factors against a base penalty level, but the guidelines are discretionary, not binding. They set a ceiling, a floor, and a matrix of factors; the outcome is negotiated in practice.
Aggravating factors that increase the penalty include: awareness of the violation (actual knowledge or reason to know), a history of prior violations, the harm to national security or foreign policy interests, and obstruction of the investigation. Mitigating factors include: a timely VSD, full cooperation, a first-time violation, remedial action taken, and the existence of a functioning compliance programme at the time of the violation. The last point matters. BIS does not give the same credit to a paper compliance programme that was never tested as it gives to one that demonstrably identified and caught the issue – even if imperfectly.
A critical cross-border dimension: UK OFSI and the EU Council both apply their own penalty regimes to export control violations within their respective jurisdictions. The EU dual-use rules and the relevant Council regulations give the competent authority in each member state primary enforcement responsibility. The UK Export Control Order empowers ECJU and the relevant enforcement bodies to act. A multi-jurisdiction exporter may face parallel civil proceedings in the US, the UK, and an EU member state simultaneously. Each penalty calculation is independent; there is no formal "global settlement" mechanism that binds all three.
What are the critical risk flags after a BIS / EAR breach?
Several facts consistently worsen the enforcement outcome and are worth checking immediately on discovering an apparent violation.
First, the degree of awareness. If emails, meeting notes, or product data sheets show that someone in the organisation knew the item was controlled and the licence was required but proceeded anyway, the matter is on the criminal-referral spectrum. Anything that looks like a knowing or reckless decision deserves immediate legal review – ideally before OEE is contacted.
Second, the end-user profile. A shipment to a civilian commercial buyer that later turns out to carry an incorrect ECCN is very different from a shipment to a party with a known military or proliferation affiliation. End-use controls and end-user screening records are the first documents OEE will request.
Third, the question of whether the conduct was isolated or systemic. One mis-classified shipment is a different case from a four-year pattern of unlicensed exports to the same destination. Systemic violations suggest compliance-programme failure and attract a higher penalty and a longer period of remediation oversight.
Fourth, timing relative to any concurrent sanctions investigation. If OFAC has already issued a subpoena or opened a file, BIS is almost certainly aware. The sequencing of voluntary disclosures across agencies requires careful coordination. A VSD to BIS that contradicts a position already taken with OFAC compounds the problem. In our experience, the multi-agency dimension is where companies without coordinated counsel suffer the most avoidable damage.
Fifth, the company's export-compliance history. Prior BIS or OFAC settlements are listed on the public record. OEE's investigators will check. A prior settlement – even years old – can shift the baseline penalty upward and reduce the mitigation credit for an otherwise strong VSD.
Does a voluntary self-disclosure change the enforcement outcome?
Yes – materially. A timely and complete VSD is the most reliably documented mitigating factor in the BIS penalty scheme. BIS's published guidance confirms that a VSD can reduce the penalty significantly and, in some circumstances, lead to the matter being resolved with a warning letter rather than a monetary penalty. That does not mean a VSD guarantees a favourable result; the underlying facts determine the ceiling of what mitigation can achieve.
The VSD must be accurate. A VSD that understates the scope of the violation – whether by error or by design – undermines the company's credibility throughout the process and can be characterised as obstruction. The initial notification is typically a short letter; the narrative report must be thorough, based on a genuine internal investigation, and supported by document evidence. Rushing the narrative to meet a deadline while the internal investigation is still incomplete creates precisely the risk of inaccuracy that OEE will scrutinise.
How does the BIS VSD compare with OFAC's? The structure is similar – prompt initial notice, followed by a fuller report – but OFAC's penalty guidelines are calibrated differently, and the statutory maximum penalty per violation differs between the two regimes. A company making parallel disclosures to both agencies should ensure the factual narrative is consistent between them. Inconsistency across VSD submissions to different agencies is an aggravating circumstance that has featured in multiple enforcement outcomes.
The position under OFSI in the UK differs in a further respect. OFSI does not operate an equivalent voluntary-disclosure programme with the same formal mitigation structure. Cooperation with OFSI's investigation is a mitigating factor, but the UK enforcement guidance frames it differently. Understanding the interaction between the three regimes – BIS, OFAC, and OFSI – is essential for any company with transatlantic operations facing a potential multi-jurisdiction enforcement exposure.
When should a company involve external counsel after a BIS / EAR breach?
Immediately. Not after the internal investigation concludes. Not after the board has been briefed. Before any documents are produced to OEE, before any written representations are made, and before any decision is taken about whether to disclose. The reason is privilege. Statements made before counsel is instructed may not be protected; documents generated in the investigation must be handled in a way that preserves whatever privilege is available.
In a matter with a criminal-referral risk, the question of privilege is not abstract. If DOJ later issues a grand jury subpoena, the scope of protected materials will be determined by decisions taken in the first days after discovery. Those decisions cannot be undone.
External counsel also brings a function that internal teams cannot reliably perform: an objective assessment of the actual scope of the violation. Internal counsel – however capable – is in a difficult position when the company they advise is assessing its own culpability. The assessment of whether the violation was isolated or systemic, whether the compliance programme meets the BIS standard for mitigation credit, and whether there is a criminal-referral risk all require an independent view. Our practice regularly acts for companies at this exact moment. The first question we ask is: what do we actually know, and what do we not yet know?
A further consideration: if the company is publicly listed, the apparent violation may have disclosure implications. Securities regulators in the US and the UK take the view that material sanctions and export-control violations are potentially reportable. That assessment should be made by counsel simultaneously with the enforcement analysis, not weeks later when the enforcement position has hardened.
The position above covers the standard case. Your facts – the item, the destination, the end-user, the degree of knowledge, and the regimes in play – change the analysis significantly.
For a confidential assessment of your BIS / EAR enforcement exposure, contact Calder & Vance at info@caldervance.com.
A common misconception: "We have a compliance programme, so the penalty will be minor"
Companies regularly arrive at post-breach counsel with the belief that having a compliance programme is, by itself, a substantial defence. It is not. BIS gives mitigation credit for a compliance programme only when that programme is operationally effective – when it reflects the company's actual product range and export markets, when it is tested and updated, and when staff who make export decisions are genuinely trained under it.
A compliance programme written by a consultant three years ago and never updated for changes to the Commerce Control List, for new Entity List additions, or for a product line that moved into a different ECCN carries very limited mitigation value. OEE's investigators will ask for training records, classification logs, screening documentation, and evidence that the programme was actively used. Paper compliance that was not embedded in operational decision-making is treated as an aggravating circumstance – evidence that the company had the form of compliance but not the substance.
We have acted for clients who entered the BIS enforcement process confident that their programme would carry the mitigation argument, and who found – on a detailed review – that the programme was substantively inadequate for the transactions in question. The gap between the programme on paper and the programme in practice is one of the most common risk factors we identify in post-breach mandates.
If a transaction has already been flagged, or a filing has been refused, early review can preserve options that narrow with time. Contact us at info@caldervance.com.
Related practices
- Apparent violation assessment – EU – identifying and assessing apparent violations under EU export-control and sanctions rules
- Enforcement risk after a breach under OFAC – how OFAC's enforcement procedure and penalty scheme operate for US financial sanctions
- Enforcement risk after a breach under OFSI – the UK financial-sanctions enforcement posture and OFSI's penalty and licensing regime