A mid-sized technology exporter ships components to a distributor in a third market. Months later, an internal review surfaces a red flag: the distributor appears on the Entity List (the Bureau of Industry and Security's list of parties subject to enhanced licence requirements). The shipment already cleared. The exporter now faces potential liability under the Export Administration Regulations ("the EAR") – the US export-control regime administered by BIS – without ever having intended to break the rules. That gap between intent and compliance is precisely what a well-designed sanctions compliance programme under BIS / EAR is built to close.
As of August 2026, the BIS / EAR sanctions compliance programme legal support question is this: a business that exports, re-exports, or transfers items subject to US jurisdiction requires a structured export-compliance programme aligned to BIS guidance, covering classification, screening, licence determination, and red-flag due diligence. The EAR applies to goods, software, and technology with a US nexus, regardless of where the exporting company is incorporated. Failure to maintain an effective programme is both a standalone risk factor in penalty determinations and an indicator of systemic non-compliance.
This page explains what a BIS / EAR compliance programme must cover, where BIS looks when it assesses programme adequacy, how the EAR interacts with OFAC sanctions and the export-control regimes of the UK, EU, and allied jurisdictions, and how Calder & Vance supports clients in building, testing, and repairing these programmes.
What does a BIS / EAR compliance programme actually cover?
A BIS / EAR compliance programme covers classification of items on the Commerce Control List ("CCL"), screening of parties against the restricted-party lists maintained by BIS and other US agencies, determination of licence requirements and available exceptions, implementation of red-flag due diligence procedures, and record-keeping – with five years as the standard retention period under the EAR. These elements are not optional enhancements; they are the building blocks BIS expects to find in place when it reviews an exporter's conduct.
Classification is the first gate. Every item subject to the EAR carries an Export Control Classification Number ("ECCN"), which determines which countries, end-users, and end-uses require a licence and which licence exceptions are available. A misclassification at this stage cascades through every downstream control. In our experience, exporters who have not formally classified their product portfolio carry the highest classification-related exposure, particularly where software updates or product redesigns have altered the technical parameters of existing items.
Screening sits alongside classification. BIS maintains the Entity List and the Denied Persons List; other US agencies contribute to the Consolidated Screening List, which aggregates restricted-party data across the government. A programme that screens only against the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) but omits BIS lists is materially incomplete. These are distinct legal obligations arising from distinct statutory bases – IEEPA and the Export Control Reform Act for BIS; IEEPA and TWEA for OFAC – and the compliance infrastructure must address both.
How does BIS assess whether a programme is adequate?
BIS assesses programme adequacy by reference to its own published compliance guidance, which sets out the elements it expects a well-designed export-compliance programme to address. The core elements are management commitment, risk assessment, export controls policies and procedures, training, screening and due diligence, record-keeping, and internal auditing. A programme is adequate when it operates as a genuine control system, not as a paper policy.
The distinction matters in enforcement. BIS's penalty calculus explicitly treats the existence, quality, and effectiveness of a compliance programme as a mitigating factor in determining the severity of a civil penalty. A business with no programme, or one that exists only in writing, is assessed differently from a business whose programme demonstrably detected and escalated the issue that gave rise to the apparent violation. Does your programme have evidence it was actually used in the transactions now under review?
BIS also examines whether the programme is proportionate to the exporter's risk profile. A large electronics manufacturer exporting dual-use items to multiple high-risk destinations requires more granular controls than a domestic software firm with limited overseas sales. Calibration to actual risk is as important as structural completeness. A programme modelled on a template without adjustment for the firm's actual CCL footprint, counterparty geography, and distribution channels will not satisfy BIS if a violation occurs.
The position on voluntary self-disclosure ("VSD") connects directly to programme design. Where an exporter discovers an apparent violation and submits a VSD (a disclosure to BIS of an apparent violation before the agency discovers it independently), the quality of the compliance programme already in place shapes how BIS characterises the disclosure. A strong programme that detected the issue and triggered the VSD is treated as evidence of good faith. We regularly advise clients on whether and how to disclose, and on the programme improvements that accompany that decision.
Where does the EAR interact with OFAC sanctions – and why does that gap create risk?
The EAR and OFAC sanctions occupy distinct but overlapping legal space, and a business operating only one set of controls is exposed on both flanks. The EAR controls the export, re-export, and in-country transfer of items; OFAC controls financial transactions and property dealings involving sanctioned persons or jurisdictions. Both sets of rules can apply to the same transaction, and a transaction that clears one does not automatically clear the other.
The practical intersection arises most often in three situations. First, a counterparty may not appear on any BIS list but may be owned 50 percent or more by a person on the OFAC SDN List – meaning the payment or the underlying transaction is blocked even if the export licence question has been resolved. Second, an item may be EAR99 (below the CCL threshold) and therefore not subject to BIS licence requirements, yet the end-user or the destination may trigger OFAC prohibitions independently. Third, a general licence under OFAC may authorise a payment while a BIS licence requirement still applies to the underlying goods – the two authorisations are not interchangeable.
We have acted for exporters and distributors who discovered, mid-transaction, that their EAR compliance process was complete but their OFAC screening had not been applied to the full counterparty chain. Integrating BIS and OFAC controls into a single screening and diligence workflow is standard practice in a well-designed programme, but it requires deliberate architectural choices that many businesses have not made.
The position above covers the standard configuration. Your specific facts – the goods, the counterparty, the payment route, the jurisdiction of your affiliates – change the analysis materially.
For an assessment of your BIS / EAR compliance exposure, contact Calder & Vance at info@caldervance.com.
How does the EAR interact with UK, EU, and allied export-control regimes?
The EAR has explicit extraterritorial reach through the de minimis rule and the foreign direct product rule, which extend US export-control jurisdiction to non-US items that incorporate US-origin content above defined thresholds or that are produced using certain US technology or equipment. This means a UK or EU exporter shipping a non-US item may still require a BIS authorisation if that item crosses the relevant threshold for US-controlled content.
For a business operating between the United States, the United Kingdom, and the European Union, the compliance programme must therefore address at minimum three parallel sets of controls: the EAR for US-origin or US-nexus items; the UK Export Control Order administered by the ECJU (the Export Control Joint Unit); and EU dual-use rules under the relevant Council Regulation. The control lists differ, the licensing authorities differ, and the enforcement postures differ. A single-jurisdiction programme is structurally incomplete for a cross-border exporter.
Allied jurisdictions – Japan, Australia, Canada, Singapore – have adopted export-control regimes that are broadly convergent with the US framework, partly because each operates within the Wassenaar Arrangement and related multilateral agreements. In practice, however, convergence is not equivalence. Japan's Foreign Exchange and Foreign Trade Act regime, Australia's Defence Export Controls framework, and Canada's Export and Import Permits Act each carry distinct licence triggers, end-user certificate requirements, and catch-all provisions. A compliance programme that manages BIS / EAR alone without mapping these adjacent obligations will leave gaps that a regulator in any one of those jurisdictions can exploit.
A practical cross-regime point: in several jurisdictions, a stricter prohibition governs. Where the EAR permits a transaction under a licence exception but the applicable country regime applies a more restrictive control, the stricter prohibition governs for that jurisdiction. Compliance counsel advising cross-border exporters must map the intersection, not simply confirm that BIS has been addressed.
What are the most common risk flags in BIS / EAR programme design?
The most common risk flags in BIS / EAR programme design are classification gaps, incomplete screening, insufficient red-flag training, record-keeping failures, and programme atrophy after the initial build. Each of these has appeared in BIS enforcement actions and in the narratives of disclosed apparent violations.
Classification gaps arise when a firm has never formally classified its products, when it relies on supplier classifications without independent verification, or when product modifications have not triggered reclassification. ECCN classification is a legal determination, not a commercial one, and it must be owned by counsel or a qualified export-compliance officer rather than delegated to sales or logistics.
Incomplete screening is the second-most frequent finding. Programmes that screen only at the point of sale, omit re-export screening requirements for known distributors, or fail to screen against the full set of applicable lists – SDN, Entity List, Denied Persons, and the relevant lists of allied jurisdictions – are structurally exposed. Screening must cover the full counterparty chain, not only the direct buyer.
Red-flag recognition deserves separate treatment. BIS requires exporters to address red flags – indicators that a transaction may be intended for an unlicensed end-use or end-user. Common red flags include a buyer with no evident commercial need for the product, a willingness to accept higher prices without negotiation, requests to omit the ECCN from documentation, and unusual shipping routes. A compliance programme that lists red flags on paper but provides no training on how to escalate them is not functioning.
Record-keeping failures are particularly damaging in enforcement because they prevent a business from reconstructing what it knew and when. The five-year retention requirement applies to export control documents, and gaps in records are interpreted unfavourably. In our experience, exporters who have maintained complete, contemporaneous records in a format that mirrors the transaction lifecycle are in a materially stronger position when a question arises than those who cannot produce the underlying documents.
Programme atrophy – where a programme was well-designed at launch but has not been updated to reflect CCL amendments, new designations, or personnel changes – is an under-recognised risk. Regulatory review cycles for the CCL and the Entity List are frequent. A programme that was accurate two years ago may no longer reflect the current rules.
What does the programme-design process look like in practice?
The programme-design process at Calder & Vance follows a structured sequence beginning with a risk-scoped assessment and ending with a tested, documented control system ready for BIS review if needed. The sequence varies depending on whether the engagement is a first-build, a remediation, or a gap-fill ahead of a transaction or regulatory inquiry.
In a first-build engagement, we classify the client's item portfolio against the CCL, map the counterparty and distribution geography, identify the applicable licence requirements and exceptions, design the screening and escalation workflow, draft the written compliance procedures, and build the record-keeping architecture. We then run a tabletop exercise against the client's actual transaction types to test whether the controls respond as designed before they go live.
In a remediation engagement – typically following a voluntary self-disclosure or a BIS inquiry – the sequence is compressed. We scope the apparent violation, assess the compliance programme that was in place, identify the specific failures, advise on disclosure, and design the corrective measures. The corrective measures feed directly into the VSD narrative or the penalty-mitigation argument, so the programme work and the enforcement defence are closely integrated.
In a gap-fill engagement ahead of a significant transaction or a corporate acquisition, we conduct a targeted audit of the specific controls relevant to the transaction, identify gaps that could affect the deal's completion or valuation, and advise on the steps needed to close them before signing.
In a recent matter, a precision-engineering business in the defence supply chain had operated for several years with a compliance programme inherited from a prior owner. The programme had not been updated after a product line change that elevated the ECCN classification of its principal export item. We reclassified the portfolio, mapped the new licence requirements, identified a small number of historical shipments that appeared to require BIS authorisation that had not been obtained, and advised on a voluntary self-disclosure. The matter was resolved without litigation. No outcome can be guaranteed in any similar situation, and each case turns on its own facts.
A common misconception: the EAR does not apply to us because we are not a US company
The most persistent misconception we encounter among non-US businesses is that the EAR does not apply to them because they have no US presence. That position is incorrect. The EAR applies to any item that is subject to US jurisdiction – meaning US-origin items and, through the foreign direct product rule and the de minimis rule, non-US items that meet the relevant US-content or US-technology thresholds.
A German manufacturer shipping components that incorporate US-origin integrated circuits above the relevant de minimis level may require a BIS authorisation for that shipment, regardless of whether the manufacturer has any US employees, contracts, or subsidiaries. The same applies to a Singapore-based distributor re-exporting US-origin software, or a UK systems integrator incorporating US technology into a platform sold to a third-country customer. The governing question is whether the item is subject to the EAR – not whether the exporter is a US person.
This misconception has a practical cost. Non-US businesses that have not mapped their US-origin content or their foreign direct product rule exposure are operating without controls that BIS expects to be in place. If a violation subsequently comes to light, the absence of any compliance programme is treated as an aggravating factor rather than an excusable gap. The earlier a non-US business maps its EAR exposure, the more options it has for managing it.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. For a confidential review of your BIS / EAR position, contact Calder & Vance at info@caldervance.com.
Related practices
- Compliance audit and testing – Australia – independent testing of export-control and sanctions controls against the Australian regime
- Sanctions compliance programme design – EU – programme design aligned to EU Council regulations and dual-use rules
- Sanctions compliance programme design – Japan – programme design under Japan's export-control and sanctions regime