Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · BIS / EAR

Re-export and extraterritorial reach under BIS / EAR: legal support

A trading group headquartered in Europe sources US-origin electronic components, ships them to a regional distribution hub, and re-sells them onward into several third markets. No one at the group thinks to ask whether US export-control rules follow the goods beyond the American border. They do. That oversight can translate into criminal exposure for the parent company, denial of export privileges for its subsidiaries, and civil penalties calculated per shipment – even though not one of those shipments ever passed through a US port after the initial export.

Re-export and extraterritorial reach under BIS / EAR – legal support begins with understanding that the Export Administration Regulations (the EAR, administered by the Bureau of Industry and Security, BIS) govern the re-export of US-origin items and, in many cases, foreign-produced items incorporating US-controlled content, wherever in the world those items travel. The reach is not symbolic. BIS has jurisdiction to pursue non-US persons and companies that re-export controlled items without the required authorisation, and its enforcement division cooperates with the Department of Justice on criminal referrals.

This page explains the legal basis for BIS extraterritorial reach, the re-export authorisation analysis a cross-border business must conduct, how the EAR interacts with parallel EU, UK, and OFAC controls, and how Calder & Vance supports businesses working through these obligations.

What gives BIS jurisdiction over re-exports by non-US businesses?

BIS derives authority to regulate re-exports from the Export Control Reform Act and the EAR issued under it, which extend US jurisdiction to any item that has a sufficient nexus to the United States – whether through US origin, US-controlled technology content, or the involvement of US persons or financial channels. A non-US company re-exporting such an item without the correct authorisation is, in the eyes of BIS, committing a violation of the EAR regardless of where the company is incorporated or where the transaction closes.

Three categories of items attract extraterritorial reach most frequently. First, items that are of US origin and were originally exported under a licence or a licence exception: the conditions of that original authorisation frequently carry through to re-export. Second, foreign-produced items that incorporate US-controlled content above the applicable de minimis threshold (the percentage of US-controlled value or technology below which the EAR does not apply to the foreign product). Third, the products of US-controlled technology: where a non-US manufacturer has licensed US technology to produce a foreign item, that item may itself be subject to the EAR under the foreign direct product rule (FDP rule), which extends BIS jurisdiction to items produced using certain US-origin technology or software.

In our cross-border practice, the FDP rule generates the most surprise. A European semiconductor assembler that has licensed US process technology may find that its own finished chips are EAR-controlled items when re-exported to certain destinations, irrespective of whether any US component was physically incorporated. That is not an edge case. It is a structural feature of how BIS constructs its extraterritorial regime.

The position above covers the standard case. Your facts – the item's classification, the US technology licensed, the destination, the end-user – change the analysis materially. For a preliminary assessment of your exposure, contact Calder & Vance at info@caldervance.com.

How does the re-export classification and authorisation analysis work?

Before any re-export of a potentially EAR-controlled item, the responsible party must work through a sequential classification and authorisation determination. The analysis has four stages, and a failure at any stage is a violation.

The first stage is classification. The item must be located on the Commerce Control List (CCL) by its Export Control Classification Number (ECCN – the alphanumeric code that identifies the controlled category, the reason for control, and the licence requirements that follow from it). Items not on the CCL are classified EAR99, meaning they are subject to the EAR but generally require no licence except to embargoed destinations or for prohibited end-uses. A classification error – treating a controlled item as EAR99, or under-classifying the ECCN tier – is itself an EAR violation.

The second stage is destination, end-user, and end-use screening. Once the ECCN is confirmed, the analyst checks the licence requirements triggered by the combination of that ECCN, the proposed country of re-export, and any further country of ultimate destination. The Commerce Country Chart maps each reason for control to the destinations where a licence is required. Even an EAR99 item requires a licence if it is destined for a party on the Entity List, the Denied Persons List, or the Unverified List, or if the exporter has knowledge of a prohibited end-use.

The third stage is licence exception availability. Where a licence is required, the analyst tests whether a published licence exception applies. The EAR carries a structured set of exceptions. Eligibility depends on the ECCN, the destination tier, the end-user, and in some cases a written assurance from the consignee. A re-export that relies on a licence exception must satisfy every condition of that exception; partial reliance does not work.

The fourth stage, where no exception is available, is a specific licence application to BIS. This is a case-by-case submission. BIS evaluates the item, the end-user, the stated use, and the strategic context. Processing times vary by item sensitivity and destination; BIS may refer the application to interagency review, which extends the timeline. Conditional approvals are common: licences for sensitive technology routinely carry end-use and reporting conditions that survive the transaction.

What is the de minimis rule, and when does the foreign direct product rule apply?

The de minimis rule and the FDP rule are the two principal mechanisms through which the EAR captures foreign-produced items, and understanding both is essential for any non-US business that sources, manufactures, or distributes items with a US-technology heritage.

Under the de minimis rule, a foreign-produced item is subject to the EAR if it incorporates US-origin controlled content – components, materials, or software – above a threshold expressed as a percentage of the total value of the finished item. The threshold differs depending on the destination. For most destinations it sits at a higher level; for a limited set of destinations subject to more restrictive treatment, the threshold is lower, meaning that even modest US content in a foreign product can render the whole item EAR-controlled for re-export to those locations. Businesses maintaining Bills of Materials across a multinational supply chain must track US-origin content at each production node, not merely at the point of final assembly.

The FDP rule operates differently. It does not require US content to be present in the finished item. Instead, it asks whether the foreign item is the direct product of US-origin technology or software that is subject to the EAR. Where a non-US manufacturer has licensed US-controlled technology to produce an item – process nodes in semiconductor fabrication are the paradigm case – BIS treats the output as subject to the EAR for purposes of re-export to specified destinations or to specified parties. The FDP rule has been expanded in scope by BIS in recent regulatory cycles, and its application to certain advanced-technology supply chains is now broad.

We regularly advise manufacturers and distributors who discover mid-transaction that a product they believed to be purely domestic in origin is, in fact, EAR-controlled because of upstream licensed technology. The conversation with the technology licensor, the review of the licence agreement's re-export provisions, and the classification of the finished item must happen before the re-export – not after a BIS inquiry has begun.

How does BIS extraterritorial reach interact with EU, UK, and OFAC controls?

The EAR does not operate in isolation. A re-export that is lawful under the EAR may still require separate authorisation under the EU dual-use regime, a UK export licence from the ECJU, or may be prohibited entirely because the end-user is on an OFAC list – irrespective of whether that party appears on any BIS list.

Under the EU dual-use rules, the catch-all control can require a licence for items that are not otherwise listed, where the exporter has been informed that they are intended for weapons-related programmes. The EU control perimeter is drawn by a separate control list and a separate country assessment. An ECCN that requires no licence for a given destination under the EAR may still carry a licence requirement under EU rules for the same destination, because the two regimes use different classification methodologies and different country-tier structures. A business moving controlled goods through a EU-based distribution hub must run both analyses in parallel.

The UK position, post-implementation of its own strategic export-control regime through ECJU, is separately applicable. UK-incorporated subsidiaries and UK-registered branches of non-UK groups are bound by UK export-control law. The UK has largely maintained alignment with the EU control list structure as a starting point, but its licensing practice and its published guidance on end-user commitments differ from the EU in ways that matter for high-sensitivity items.

The OFAC dimension is distinct again. OFAC's sanctions programmes prohibit transactions with SDN-listed parties regardless of the goods involved. A re-export that is EAR-licensed can still violate OFAC sanctions if the end-user or a party in the payment chain is a Specially Designated National. In our experience, compliance teams sometimes treat BIS and OFAC screening as sequential rather than concurrent. They are not. Both must be satisfied before the transaction proceeds.

If a transaction has already been flagged for a potential control violation – whether under BIS, OFAC, ECJU, or EU rules – an early review can preserve options that narrow quickly with time. Contact us at info@caldervance.com for a confidential assessment.

What are the main risk flags for re-exporting businesses?

Several patterns generate a disproportionate share of BIS enforcement actions involving re-exports, and recognising them is the first line of risk management.

The first is distributor chains without flow-through controls. A US supplier exports under a licence exception to a foreign distributor. The distributor, unaware of or indifferent to the end-use conditions attached to the exception, re-sells to a customer whose ultimate destination or end-use would have required a licence. The original exporter can face liability; so can the distributor. Licence exception conditions do not dissolve at the first transfer.

The second is the newly listed party problem. An end-user who was not on any BIS or OFAC list when the commercial relationship began may be listed mid-contract. The addition of a counterparty to the Entity List or Unverified List changes the licence requirement for any future shipment to that party. Most distributor agreements and purchase-order terms do not contain adequate trigger clauses to address this. Ongoing screening is not optional.

The third is FDP rule non-awareness in manufacturing groups. A non-US subsidiary of a global industrial group licenses US process technology to manufacture components at an overseas plant. No one in the group's compliance structure has mapped the resulting EAR classification of those components. When the components are sold to a third-market buyer, the re-export occurs without a licence. The violation is complete. The size of the group provides no defence.

The fourth is voluntary self-disclosure (VSD) misjudgement. Where a potential violation is identified, BIS operates a VSD programme. A well-prepared VSD (voluntary self-disclosure to BIS of an apparent violation) can materially affect the penalty outcome. A poorly prepared one – incomplete, inaccurate, or submitted without a considered assessment of the violation's scope – can expand exposure rather than limit it. The decision to file a VSD and the content of the disclosure require careful legal preparation.

A fifth risk arises in M&A and joint-venture transactions. When a business acquires a target that manufactures or distributes dual-use items, it inherits the target's EAR obligations – and any prior apparent violations. Pre-closing due diligence that does not include an EAR classification review of the target's product portfolio, an export-licence audit, and a BIS-list screening of key customers is incomplete. Post-closing discovery of historic violations is both expensive and disruptive.

What does the BIS re-export compliance programme look like in practice?

A programme adequate to manage re-export risk under the EAR combines four operational elements, each of which must be documented and tested regularly.

The first element is product classification. Every item the business manufactures, distributes, or brokers that has a US-technology nexus must carry a confirmed ECCN (or a documented EAR99 determination). Classification must be reviewed when the product changes, when the technology-licence terms change, or when BIS amends the CCL in ways that affect the relevant categories. A classification carried over from a prior version of the CCL without review is a known vulnerability.

The second element is counterparty and destination screening. All customers, distributors, freight forwarders, financial intermediaries, and ultimate end-users must be screened against BIS lists (Entity List, Denied Persons List, Unverified List), OFAC lists (SDN List, sectoral lists), and the UN Consolidated List before every transaction and at set periodic intervals within ongoing relationships. Screening of the first-tier customer is not sufficient. The analysis must extend to the known or reasonably knowable ultimate destination.

The third element is transaction review for red flags. The EAR's red-flag guidance describes circumstances that should prompt enquiry before a transaction proceeds: a buyer's reluctance to provide end-use information, a stated use that is inconsistent with the product's technical specifications, a request for unusual shipping routes, payment through jurisdictions unconnected to the buyer's stated location. A compliance programme that does not embed red-flag review into sales and logistics workflows will not satisfy BIS's expectation of due diligence.

The fourth element is record-keeping. BIS requires that export and re-export records be retained for a defined period. Failure to maintain adequate records – including the basis for a licence exception determination – is itself a violation, separately from any underlying export error. Records must be accessible and retrievable on BIS request.

A common misconception: "The EAR only applies if we use US components"

The most frequent myth we encounter in advising manufacturing and technology businesses is that the EAR applies only to items that physically incorporate US-origin parts. The de minimis and FDP rules show why that is wrong. A product produced entirely with non-US materials, in a non-US factory, by a non-US company, can be subject to the EAR if the manufacturing process used US-controlled technology under licence. Equally, a foreign product that incorporates only a small fraction of US-origin content by value may still be EAR-controlled for the most restricted destinations.

The practical consequence is that a business cannot exit BIS jurisdiction simply by avoiding US suppliers at the component level. The technology-licence review must accompany any classification assessment. In a recent matter, a technology business in the Asia-Pacific region had structured its supply chain specifically to avoid US-origin components. Its compliance assessment was correct as far as it went. But the business had not reviewed the technology licence governing its core manufacturing process, which brought the finished product within the FDP rule for the destination it was targeting. We conducted the full classification review, identified the applicable rule and the destination constraint, and structured a compliant pathway to market. The matter concluded without a BIS filing.

Related practices

Frequently asked questions

How long does managing re-export risk take under BIS / EAR?
The timeline depends on the scope of the issue. A classification review for a defined product line with good documentation can typically be completed within several weeks. A full programme assessment across a multinational product portfolio takes longer – often two to three months for a manufacturing group with multiple production sites. A BIS licence application for a controlled item to a sensitive destination can take significantly longer, particularly where interagency review is triggered. We advise clients to begin the process well before transaction deadlines and to build BIS review time into their commercial calendars.
What are the main risks in re-export and extraterritorial reach under BIS / EAR?
The principal risks are: exporting or re-exporting without a required licence (including reliance on a licence exception that does not apply); supplying a listed party on the Entity List or Denied Persons List; failing to conduct adequate end-use due diligence; and missing a red flag that would have required enquiry before the transaction proceeded. Civil penalties are assessed per violation and can be substantial. Criminal exposure arises where wilful violation is found. BIS may also impose a denial of export privileges, which can affect an entire corporate group.
Do we need specialist counsel for re-export and extraterritorial reach?
For routine compliance – screening, classification maintenance, record-keeping – a well-resourced in-house team with current training can manage day-to-day obligations. Specialist counsel adds material value in four situations: where the FDP rule or de minimis analysis is uncertain; where a licence application is required for a sensitive item or destination; where a potential violation has been identified and a VSD decision must be made; and where a transaction – M&A, joint venture, new distribution arrangement – requires an independent EAR audit of inherited obligations. We regularly act in all four contexts.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.