A US-headquartered technology group acquires a European distributor. Three months later, its new compliance team discovers that the distributor has been shipping items listed on the Commerce Control List (CCL – the US government's itemised list of goods, software, and technology subject to export-licensing requirements under the Export Administration Regulations) to end-users in restricted destinations without checking whether a licence was required. The deals closed. The goods moved. The question now is: how serious is the exposure, and what can the business do about it?
Compliance audit and testing under BIS / EAR legal support begins with a structured review of how a business classifies its items, screens its counterparties, and records its licence determinations – and then tests whether those controls actually work. The Bureau of Industry and Security (BIS) administers the Export Administration Regulations (EAR) under the authority of the Export Control Reform Act. Where a review surfaces apparent violations, voluntary self-disclosure to BIS can be a meaningful mitigant, though outcomes are never guaranteed.
This page explains what an EAR compliance audit covers, how it differs from an OFAC or EU dual-use review, where the risk flags typically sit, and how Calder & Vance assists businesses from classification to remediation.
What does a BIS / EAR compliance audit actually cover?
A BIS / EAR compliance audit examines the full lifecycle of a controlled-item transaction: classification, licence determination, authorisation, end-use screening, and record-keeping – using the EAR and BIS guidance as the governing standard. It is not a financial audit and not a general trade-compliance review; it tests the specific controls that the EAR demands.
In practice, the scope falls into four interlocking workstreams. First, item classification: does the business hold accurate Export Control Classification Numbers (ECCNs – the alphanumeric codes that place an item on the CCL and determine which destinations, end-uses, and end-users require a licence)? Second, licence determination: for each ECCN, does the business correctly identify the applicable controls and exceptions? Third, counterparty and end-use screening: are customers, distributors, and end-users checked against BIS's Entity List, Denied Persons List, and Unverified List – as well as OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons)? Fourth, records: does the business retain export-transaction documentation for the period the EAR requires?
What the audit does not do is search for ways to avoid controls. Every workstream is directed at ensuring that the controls work and that apparent gaps are properly documented and, where necessary, reported.
In our experience, classification is consistently the weakest link. Businesses that manufacture or trade in dual-use goods – items with both civil and military applications – frequently rely on self-classification that has never been tested against the CCL's technical parameters. An item a business treats as EAR99 (below the CCL threshold, no licence required for most destinations) can turn out to carry an ECCN with regional or end-use restrictions. That error compounds silently across hundreds of shipments before a review catches it.
What is the legal basis and who administers it?
BIS, a bureau of the US Department of Commerce, administers the EAR under the Export Control Reform Act and, to the extent it remains operative, the International Emergency Economic Powers Act (IEEPA). The EAR applies to all items "subject to the EAR" – a category that includes most US-origin commercial goods, software, and technology, as well as certain foreign-made items that contain controlled US content above defined thresholds or are produced using controlled US technology.
Two extraterritorial rules define the EAR's cross-border reach. The de minimis rule catches foreign goods that incorporate US-controlled content above a certain percentage. The foreign direct product rule catches foreign-made goods produced from US-controlled technology or software. Both rules mean that a non-US manufacturer can find itself subject to the EAR without shipping a single US-origin item. We regularly advise non-US exporters who discover this exposure only when a US customer or investor asks for an EAR compliance review.
The BIS Office of Export Enforcement (OEE) handles criminal and administrative enforcement. The DOJ handles criminal export-control prosecutions. A voluntary self-disclosure (VSD – a proactive report to BIS of a potential violation before OEE discovers it independently) is evaluated under BIS's enforcement guidelines, which treat a well-prepared VSD as a significant mitigating factor. The difference in treatment between a VSD and a reactive response to a government inquiry can be substantial, though the precise outcome in any given case depends on the facts.
The position above covers the standard structure of the EAR regime. Your facts – the items, the destinations, the end-users, the volume of transactions, and whether any went to parties on restricted lists – change the analysis materially.
For an assessment of your export-control exposure under BIS / EAR, contact Calder & Vance at info@caldervance.com.
How does the audit procedure work in practice?
A BIS / EAR compliance audit follows a four-phase sequence: scoping, testing, gap analysis, and remediation planning. Each phase has a defined output, and the programme is typically run against BIS's published guidance on export-compliance programmes.
Phase one – scoping – maps the business's product lines, supply chains, and transaction flows against the CCL. The output is a risk-tiered scope: which product families carry ECCN classifications with real licence requirements, and which destination markets and customer types carry the greatest exposure. This phase also identifies whether the de minimis rule or the foreign direct product rule brings any part of the supply chain under EAR jurisdiction.
Phase two – testing – applies structured test procedures to a sample of completed transactions. We check whether the ECCN assigned to each item was accurate, whether the correct licence determination was made, whether any applicable exceptions were properly invoked, and whether the counterparties were screened at the time of the transaction. Sampling methodology follows risk tiers: high-risk destinations and end-users receive larger samples.
Phase three – gap analysis – maps the test findings to the five elements BIS expects in a well-designed export-compliance programme: management commitment, risk assessment, export authorisation procedures, recordkeeping, and training. Each gap is rated by severity and likelihood of regulatory interest.
Phase four – remediation planning – produces a prioritised action list: classification corrections, licence applications or retro-authorisation assessments, screening-tool reconfiguration, records remediation, and – where the gap analysis reveals apparent violations – a decision framework for voluntary self-disclosure.
Timelines depend on the size of the business, the number of product lines, and the depth of the transaction history under review. A focused audit of a single product family for a mid-sized manufacturer can be completed in a matter of weeks. A group-wide review across multiple jurisdictions requires more time. We scope each engagement clearly at the outset and provide a fixed-fee entry point for the initial scoping phase.
How does a BIS / EAR audit differ from an OFAC, EU, or UK review?
The BIS / EAR audit is item-driven and destination-driven; the OFAC financial-sanctions review is counterparty-driven and transaction-blocking. Understanding the difference matters because a business subject to both regimes – which most US-linked exporters are – needs both types of control and cannot substitute one for the other.
Under OFAC, the central question is whether the counterparty is a blocked person or a sanctioned entity, or whether the transaction touches a sanctioned jurisdiction. The 50 percent rule (OFAC's rule treating any entity owned 50 percent or more in the aggregate by blocked persons as itself blocked) operates automatically, without any licence being issued. The OFAC review therefore focuses on ownership chains, beneficial-control structures, and the completeness of SDN screening.
Under the EAR, the central question is whether the item requires a licence for the destination, end-use, or end-user in question. An item may ship lawfully to a country that is the subject of comprehensive OFAC sanctions for certain humanitarian purposes under a general licence, while the same item may independently require a BIS licence because its ECCN carries regional controls unrelated to the OFAC programme. The two regimes operate in parallel, not in sequence.
The EU dual-use rules – Council Regulation on the control of exports, brokering, technical assistance, transit, and transfer of dual-use items – apply a broadly similar classification logic to the EAR but differ on catch-all controls, intra-EU transfer obligations, and the treatment of intangible technology transfers. The UK's Export Control Order, administered by ECJU, follows its own control list and licensing procedures. A business that exports from both the EU and the United Kingdom must satisfy both regimes and cannot rely on an EU licence to cover a UK-controlled export.
The cross-regime implication is direct: a business with operations in more than one jurisdiction cannot run a single-regime audit and declare itself compliant. In our practice, we map each regime's bite on the specific transaction flow before recommending an audit scope. Our related service pages set out the EU and Australian positions in detail.
Related practices
- Compliance audit and testing under EU dual-use rules – specialist support for export-control reviews under EU Council regulations
- Compliance audit and testing under Australia's autonomous sanctions regime – DFAT-regime reviews for exporters with Australian operations
- Compliance audit and testing under OFAC sanctions – counterparty screening, the 50 percent rule, and VSD advice
Where do the risk flags concentrate in a BIS / EAR programme?
In our cross-border practice, the same five risk flags appear in BIS / EAR programmes across sectors and business sizes. Each is predictable. Each is also easy to miss without structured testing.
First, stale ECCNs. Classification work is done once at product launch and rarely revisited. When a product is updated – a new chipset, a new firmware function, a new maximum transmission speed – the ECCN can shift. A business that sold under EAR99 three years ago may have been shipping a controlled item for the past eighteen months without knowing it.
Second, unlicensed deemed exports. A deemed export is the release of controlled technology to a foreign national inside the United States – treated as an export to the national's home country. Businesses that employ non-US nationals in R&D or manufacturing roles without checking whether those roles involve access to ECCN-controlled technology are exposed to deemed-export violations that produce no shipping records and therefore no obvious audit trail.
Third, distributor and re-export risk. When a business sells through a distributor, the distributor's on-sale creates a re-export that remains subject to the EAR. If the distributor lacks its own export-compliance programme, the manufacturer's initial due diligence becomes the only control. Does your distribution agreement require the distributor to maintain EAR-compliant records and to notify you before re-exporting to restricted destinations?
Fourth, incomplete restricted-party screening. Screening against the SDN List alone is insufficient. The EAR's own restricted-party lists – Entity List, Denied Persons List, Unverified List – operate independently of OFAC and impose their own prohibitions and due-diligence obligations. A counterparty not on the SDN List can still be an Entity List party against whom an ECCN-controlled export requires a licence (typically unavailable under a policy of denial).
Fifth, records gaps. The EAR requires exporters to retain records sufficient to reconstruct the basis of each licence determination. Businesses that rely on EAR99 self-classifications or on licence exceptions need to have documented the basis for those determinations at the time of the transaction. Reconstructing records after an inquiry is significantly harder than maintaining them prospectively, and BIS's enforcement guidelines treat records failures as independent aggravating factors.
How does Calder & Vance support a BIS / EAR compliance audit?
We assess eligibility, prepare and submit licence applications, and manage BIS's queries; we classify items against the CCL and confirm licence requirements and exceptions; we test the screening logic, map ownership and control, and redesign the programme to the five-element standard; and where an audit surfaces apparent violations, we scope the apparent violation, advise on voluntary self-disclosure, and prepare the penalty defence.
In a recent matter, a mid-sized manufacturer of precision instruments discovered, during pre-acquisition due diligence, that the target company had been exporting items under EAR99 self-classifications that had never been validated. A classification review of the product range identified several items that carried ECCNs with licence requirements for certain destinations. We classified the items, assessed the transaction history, and developed a remediation plan that included a VSD for the most significant apparent violations. The acquirer proceeded to closing with a clear-eyed view of the residual risk.
We work on a fixed-fee basis for defined phases of the engagement, beginning with a scoping assessment. For group-wide or multi-regime programmes, we provide a phased engagement structure so that the business controls cost at each stage. We do not invoice on open-ended hourly rates for compliance reviews unless the client specifically requires it.
A common myth in this area is that a general trade-compliance review – covering import duties, origin, and customs classification – also satisfies the EAR. It does not. The EAR runs entirely separately from customs law. A business can be in full customs compliance and in significant EAR violation simultaneously. Export-control classification is a discrete discipline; it requires specialists who work with the CCL and BIS's technical parameters, not generalist trade lawyers applying a tariff schedule.
If a transaction has already been flagged by BIS, an end-user customer, or an internal audit team, an early review preserves options that narrow with time. The window for voluntary self-disclosure is not unlimited, and the mitigating value of a VSD diminishes once BIS has independently identified the issue.
For a confidential review of a potential breach or to stress-test your export-compliance programme, contact Calder & Vance at info@caldervance.com.