A trading company sources precision components from a network of suppliers across four continents. Each shipment clears customs without incident – until a due-diligence review surfaces a sub-tier manufacturer whose ultimate parent appears on the Entity List (the Bureau of Industry and Security's list of parties subject to enhanced or denied export privileges under the Export Administration Regulations). The deal is already signed. The components are already in transit. At that point, the question is no longer whether to map the supply chain. It is how much exposure has already accrued.
Supply-chain sanctions mapping under the BIS / EAR (the Bureau of Industry and Security's Export Administration Regulations, the primary US export-control regime governing dual-use and commercial goods) requires systematic identification of every party in the chain against the US denied-party lists (the Entity List, the Denied Persons List, and the Unverified List), classification of controlled items against the Commerce Control List (CCL), and assessment of extraterritorial reach through the de minimis and foreign-direct product rules. As of early 2026, enforcement posture under the EAR remains active and the extraterritorial rules extend US jurisdiction well beyond US-origin goods.
This page sets out the legal basis and governing authority, the mapping procedure and the cross-regime comparison, the risk flags that most frequently produce enforcement exposure, and how Calder & Vance supports businesses working through this analysis.
What does supply-chain sanctions mapping under the BIS / EAR actually cover?
Supply-chain sanctions mapping under the EAR covers three distinct but related inquiries: party screening, item classification, and transaction-path analysis. Each inquiry carries independent legal risk; a business that screens parties but never classifies its goods – or that classifies goods but does not trace the foreign-direct product rule through its sub-tier suppliers – has completed only part of the legal requirement.
Party screening means checking every principal in the transaction – supplier, freight forwarder, financial intermediary, end-user, and beneficial owner – against the denied-party lists maintained by BIS and, for financial flows, the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The Entity List is not binary: some listed parties may still receive certain items under a licence; others are subject to a presumption of denial. Reading the list entry correctly is itself a specialist task.
Item classification means assigning an ECCN (Export Control Classification Number, the alphanumeric code used in the CCL to identify the level of control over a given item) to each product or technology in the chain. An incorrect or missing ECCN is a source of enforcement risk, particularly where a supplier has self-classified at a lower control level. In our experience, classification errors at the sub-tier level are among the most common findings in a supply-chain review.
Transaction-path analysis means tracing the movement of controlled US-origin content – and, critically, items produced abroad using US equipment, software, or technology – through each tier of the chain. This is where the extraterritorial reach of the EAR bites hardest.
What is the legal basis, and which authority governs?
The EAR is administered by BIS within the US Department of Commerce. Its legal authority derives from the Export Control Reform Act and, where national-security controls are engaged, IEEPA. BIS maintains the CCL, the Entity List, the Denied Persons List, and the Unverified List. It also issues general orders restricting trade with specific end-users or in specific items.
Two doctrines give the EAR its extraterritorial reach. First, the de minimis rule brings foreign-made goods within US jurisdiction when they incorporate US-controlled content above a defined threshold by value. Second, the foreign-direct product rule (FDP rule) extends EAR jurisdiction to foreign-made items that are the direct product of certain US-origin technology or software, or are produced by a plant or major component of a plant that is itself a direct product of such technology. The FDP rule has been expanded in recent years and now covers a broader range of semiconductor and advanced-technology supply chains than many businesses appreciate.
Where goods are also subject to OFAC controls – because the end-user, the financing party, or the jurisdiction of delivery engages a sanctions programme – the EAR and the OFAC regime operate concurrently. The stricter prohibition governs. A transaction may be EAR-permissible under a licence exception but simultaneously blocked by an OFAC programme. Both analyses must be completed.
The position above covers the standard case. Your goods, your sub-tier suppliers, the jurisdiction of delivery, and the ultimate end-user may each alter the analysis materially. For a structured assessment of your supply-chain exposure under the EAR, contact Calder & Vance at info@caldervance.com.
How is a supply-chain mapping exercise structured in practice?
A well-structured mapping exercise follows a defined sequence. Compressing or skipping stages is a common source of incomplete findings and, in the event of an enforcement inquiry, an incomplete record.
- Scope definition. Identify the goods or technologies in scope, the jurisdictions of origin, manufacture, and delivery, and the complete list of transaction parties from tier-one supplier to end-user. Define what counts as a "sub-tier" for the purposes of this review. In complex supply chains, practical judgement is needed: mapping every node is rarely proportionate; mapping the nodes that carry the highest classification or the highest-risk end-use is the defensible standard.
- Item classification review. Confirm or challenge each existing ECCN. Where a supplier has classified an item as EAR99 (the residual category for items not specifically listed on the CCL), verify that classification. EAR99 goods can still be subject to licence requirements under OFAC programmes or general orders.
- Party screening against all applicable lists. Screen each party against the Entity List, the Denied Persons List, the Unverified List, and the SDN List. Where a party is a legal entity, apply the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) and review the ownership and control structure of each counterparty. Note that BIS denied-party rules are not identical to the OFAC blocking rules; they operate under different legal tests.
- FDP and de minimis tracing. For each item that incorporates US-controlled content, calculate whether the de minimis threshold is reached. For items produced using US-controlled technology or equipment, assess whether the FDP rule applies. This step is often absent from compliance programmes that pre-date the expanded FDP rules.
- Licence-requirement determination. Having confirmed the ECCN and the destination and end-user, determine whether a licence exception is available or whether a licence application to BIS is required. Where the transaction involves listed parties, determine whether the applicable list entry permits any transaction under a licence or imposes a presumption of denial.
- Findings documentation and gap remediation. Record the methodology, the findings, and any gap identified. Where a gap requires remediation – a revised supplier agreement, an additional end-use certificate, a licence application, or a voluntary self-disclosure – document the remediation steps and their completion.
Timelines vary significantly by the complexity of the supply chain, the number of parties requiring manual review, and whether any party or item presents a licence question that requires engagement with BIS. In our practice, a focused review of a defined supply chain typically runs to several weeks; a broader programme covering a full supplier base can extend to several months.
How does the BIS / EAR analysis compare with the EU and UK regimes?
Supply-chain mapping under the EAR differs in structure and reach from parallel exercises under the EU dual-use regime and the UK export-control regime. Understanding those differences is essential for any business that sources or ships across more than one jurisdiction.
Under the EU dual-use regime (governed by Council Regulation on the control of exports of dual-use items), the classification system uses a separate category and entry structure, and the catch-all control can apply to unclassified items where the exporter knows or has reason to know the goods may contribute to weapons programmes. The EU framework does not have a direct equivalent to the FDP rule: in principle, EU export controls apply to goods exported from EU territory, not to goods produced abroad using EU-origin technology. This creates an asymmetry in extraterritorial reach that matters for supply-chain design.
Under the UK regime, administered by the ECJU (Export Control Joint Unit), classification follows a schedule that substantially mirrors the pre-2021 EU list but has since diverged in some areas. The ECJU administers open general export licences (OGELs, standing authorisations covering defined categories of goods to defined destinations) alongside specific licensing. Businesses that hold an OGEL for certain destinations may find that a parallel BIS analysis still requires a separate licence or end-use undertaking.
For multi-jurisdiction supply chains, the operative question is which regime imposes the strictest obligation on a given transaction. Where US-origin content is present, the EAR typically sets the floor. Where EU-controlled technology has been incorporated into goods that are then re-exported from outside the EU, the EU regime may also apply. Running both analyses in sequence – and mapping the points of divergence – is the defensible approach. We regularly advise clients on exactly this cross-regime matrix, identifying which control is determinative for a given shipment.
If a supply-chain review has already produced a finding – a listed party, a potential FDP issue, or a classification gap – options narrow with time. For an early review of a specific finding, contact Calder & Vance at info@caldervance.com.
What are the main risk flags in a BIS / EAR supply-chain review?
Experience across a range of supply-chain reviews points to a consistent set of risk patterns. Most enforcement exposure arises not from deliberate misconduct but from programme gaps that have never been stress-tested against the actual structure of the business's supplier base.
Self-classification errors at the sub-tier level. A tier-one supplier may hold an accurate ECCN for the finished component it delivers. The sub-tier manufacturer of a key sub-component may have self-classified at a lower level – or not classified at all – because its goods did not historically move on a US-origin pathway. When the FDP rule extends to that sub-tier, the classification becomes material. In our experience, this is the single most common finding in supply-chain reviews for businesses in the advanced-manufacturing and semiconductor sectors.
Ownership-chain gaps in party screening. Screening the entity named in the contract is necessary but not sufficient. Where the contracting entity is a subsidiary, the beneficial ownership structure may connect to a listed parent through indirect holdings that a standard screening tool will not surface. The aggregation question – whether two or more listed persons together reach the ownership threshold – requires a manual review of the ownership chain, not just an automated name-check.
FDP exposure from recent rule expansions. The FDP rule has been extended on several occasions in recent years to cover additional sectors and additional categories of US-origin technology. A programme built to the pre-expansion standard may not capture items that are now within scope. Reviewing the current scope of the FDP rule and testing it against the actual equipment and software used in the supply chain is a periodic, not a one-time, task.
Jurisdiction-of-delivery mischaracterisation. Where goods are sold to a buyer in one jurisdiction for onward delivery to a third market, the licence-requirement analysis turns on the actual destination of the goods, not the location of the contracting party. Contracts that do not include a robust end-use undertaking and destination control clause may obscure the true end-point of the shipment.
Failure to screen financial intermediaries. A payment routed through a financial institution that is itself on a denied-party list, or whose controlling shareholder is blocked under an OFAC programme, can convert an otherwise compliant goods transaction into an enforcement risk across two regimes simultaneously.
A common misconception: "our goods are low-tech, so the EAR does not apply"
A persistent assumption among businesses outside the defence and semiconductor sectors is that the EAR applies only to high-technology or military goods. This is not correct, and acting on that assumption is itself a risk flag.
EAR99, the residual category, covers items not specifically listed on the CCL. EAR99 goods are generally exportable without a licence to most destinations – but they are still subject to the EAR. They may require a licence for export to sanctioned destinations, to listed end-users under the Entity List or a general order, or when the exporter has knowledge that the goods will be used for a prohibited end-use such as weapons proliferation. Compliance programmes that screen only CCL-controlled items against denied-party lists miss the EAR99 exposure entirely.
The FDP rule can also extend to goods that are not themselves classified on the CCL, if they are produced by plant or equipment that is a direct product of US-controlled technology. A business producing what it regards as a purely commercial, non-controlled product may still be within the scope of the FDP rule by virtue of the manufacturing equipment it uses.
We regularly advise clients who have made a good-faith assumption of non-applicability that has not been tested. The starting point for any supply-chain review should be a positive determination that the EAR does not apply – not an absence of any determination at all.
How Calder & Vance supports supply-chain mapping under BIS / EAR
Our practice in cross-border transactions and export controls covers the full scope of the supply-chain mapping exercise: we classify items, confirm licence requirements and exceptions, screen parties against all applicable denied-party and sanctions lists, and design end-use controls to reduce forward exposure.
In a recent matter, a manufacturing business in the precision-engineering sector identified – partway through a supply-chain rationalisation exercise – that one of its long-standing sub-tier suppliers had been added to the Entity List in a list update the business had not processed. The supplier was providing a component used across multiple product lines. We scoped the apparent violation, assessed the FDP implications for the onward sales, advised on the voluntary self-disclosure position, and worked through the licence options available for continued supply during the transition to an alternative source. The matter was resolved without a referral to DOJ.
Our work in this area draws on experience across the US, EU, and UK regimes. Where a mapping exercise raises questions that require local counsel in a third jurisdiction, we coordinate that engagement. We offer fixed-fee entry points for defined-scope reviews, allowing a business to understand the likely findings before committing to a full programme.
Related practices
- Correspondent banking and de-risking under OFAC – screening, blocked-property obligations, and enforcement risk for financial institutions
- Supply-chain mapping under Canadian sanctions – GAC regime analysis and cross-border comparison for businesses trading with Canada
- Supply-chain mapping under EU sanctions and dual-use controls – Council regulation analysis and cross-border compliance for EU-facing supply chains