A US-incorporated technology company is about to fulfil a software order for a distributor in a third market. The distributor's parent holds a minority stake in a company already on the Entity List (BIS's list of foreign persons subject to additional export-licence requirements). Does that relationship trigger a licence requirement? Is the distributor itself a restricted end-user? These are not abstract questions. They decide whether the shipment can proceed, and when.
Under the Export Administration Regulations ("EAR"), BIS assesses ownership and control of foreign entities to determine whether a non-listed person is nonetheless subject to additional restrictions because of its relationship with a listed or restricted party. Unlike OFAC's mechanical 50 percent rule (which blocks any entity owned 50 percent or more in the aggregate by a blocked person), the BIS / EAR analysis turns on a broader set of factors – ownership percentage, voting rights, board composition, contractual control, and operational direction – and applies across the Entity List, the Denied Persons List, and the Unverified List, as well as the end-user and end-use controls embedded in the EAR. As of August 2026, this assessment sits at the centre of due diligence for any exporter, re-exporter, or in-country transferor handling items subject to the EAR.
This page sets out the legal basis, the assessment methodology, how the BIS / EAR analysis compares with the OFAC, OFSI, and EU approaches, the practical risk flags our team sees most often, and how Calder & Vance supports businesses that need a structured ownership and control assessment for export-control purposes.
What is an ownership and control assessment under the EAR, and who needs one?
An ownership and control assessment under the EAR is a structured legal review of the corporate structure, shareholding chain, governance arrangements, and operational relationships of a foreign counterparty, designed to determine whether that counterparty is, in substance, directed or controlled by a person or entity that triggers a licence requirement or an end-use restriction. It sits within the broader category of know-your-end-user obligations that the EAR imposes on exporters, re-exporters, and in-country transferors of US-origin controlled items.
Businesses that need this analysis include US exporters shipping items classified under the Commerce Control List ("CCL"), foreign subsidiaries of US groups handling US-origin goods or technology, distributors and resellers in distribution chains that touch controlled items, financial institutions financing controlled-goods transactions, and M&A teams acquiring entities that hold US-origin technology. The analysis is not optional. An exporter who proceeds without adequate due diligence, and whose item reaches a restricted end-user, faces the same enforcement exposure as one who knowingly shipped without a licence.
The position above covers the standard case. Your facts – the counterparty's jurisdiction, the nature of the items, the ownership structure, and the regime in play – can shift the analysis significantly.
To discuss an assessment before a transaction closes, contact Calder & Vance at info@caldervance.com.
What is the legal basis and governing authority for BIS ownership and control analysis?
BIS administers the EAR under the authority of the Export Control Reform Act ("ECRA") and, historically, the International Emergency Economic Powers Act ("IEEPA"). The EAR governs the export, re-export, and in-country transfer of items subject to US jurisdiction, whether by US persons or – through the EAR's extraterritorial reach – by foreign persons handling items that meet the applicable US-origin content or technology thresholds.
Ownership and control analysis enters the EAR through several intersecting mechanisms. First, the Entity List itself designates parties by name and, where relevant, by affiliated entities. When BIS adds a named entity, it may separately list its subsidiaries or affiliates; where it does not, the question of whether an unlisted affiliate is effectively controlled by the listed person becomes a matter of legal assessment. Second, the EAR's end-use and end-user controls – including the restrictions on dealing with parties that have been denied export privileges or that appear on the Unverified List – require exporters to assess not only the named counterparty but the persons who will ultimately direct, use, or benefit from the item. Third, the Militarily End-User ("MEU") controls, which apply to certain dual-use items destined for military end-uses in specified countries, require exporters to assess whether the end-user is a military end-user, including through indirect means such as a commercially presented intermediary that routes goods to a prohibited military programme.
BIS guidance, including the Know Your Customer guidance and the Red Flags list, structures the due diligence inquiry. These are not voluntary best practices. They define the standard of care against which BIS measures whether an exporter took adequate precautions before shipping. An exporter who ignored red flags faces a much harder penalty-mitigation argument than one who ran a structured assessment and reached a defensible conclusion.
How does the BIS / EAR ownership and control test work in practice?
The BIS / EAR ownership and control analysis is not a single bright-line test. It is a structured factual inquiry that examines multiple indicators across the counterparty's corporate structure and operations, and it applies differently depending on which restriction is in play.
For Entity List purposes, the core question is whether the unlisted entity is effectively the same party as the listed entity, or is so closely controlled by it that a licence requirement imposed on the listed entity would be meaningless if it did not extend to the unlisted entity. BIS looks at: direct or indirect ownership percentage; voting rights and the ability to appoint the board or senior management; shared employees, premises, or intellectual property; contractual arrangements that give the listed entity direction over the unlisted entity's commercial decisions; and the flow of financial benefit between the two. No single factor is determinative. BIS weighs them in combination.
For MEU and end-user-based controls, the analysis is broader still. An entity can be a restricted end-user without being owned by a listed person at all, if its operations, procurement patterns, or stated end-uses indicate that controlled items would reach a prohibited programme. This is where the ownership assessment intersects with the end-use assessment: a clean ownership chain does not discharge the exporter's obligation if other red flags point toward a problematic end-use.
In our cross-border practice, we apply a five-stage methodology: (1) map the counterparty's direct and indirect ownership chain against the applicable restricted-party lists; (2) review governance documents – articles of incorporation, shareholder agreements, board composition, management contracts – for control indicators; (3) assess operational relationships, including intercompany service agreements, shared infrastructure, and financial flows; (4) identify and evaluate red flags against the BIS Red Flags guidance; and (5) document the assessment and the conclusion in a format that can be produced to BIS in the event of a post-shipment inquiry.
Documentation is not a formality. In our experience, the quality of the written assessment is the single most important factor in the penalty-mitigation process if a shipment is later questioned.
How does the BIS / EAR approach compare with OFAC, OFSI, and EU ownership tests?
The divergence between the BIS / EAR analysis and the ownership tests applied by OFAC, OFSI, and the EU is one of the most practically significant sources of compliance complexity for cross-border businesses – and it is one that our team addresses on almost every multi-regime mandate.
OFAC's 50 percent rule is the most mechanical of the major tests. Any entity owned 50 percent or more in the aggregate by one or more persons on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) is treated as itself blocked, regardless of whether it is named. The rule is automatic. If the aggregate direct and indirect ownership by SDN-listed persons reaches the threshold, the entity is blocked. Voting rights, control, and operational direction are irrelevant to the OFAC test where the ownership threshold is met.
The UK OFSI and EU analyses apply an ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person). Under both regimes, a non-listed entity can be caught if a designated person owns or controls it – and "control" extends beyond share ownership to include the ability to direct the entity's affairs through voting rights, contractual arrangements, or any other means. This makes the UK and EU tests both broader and, in some respects, more fact-intensive than OFAC's threshold rule. An entity owned 40 percent by a designated person might pass the OFAC test but fail the OFSI or EU control assessment if the designated person holds board veto rights.
The BIS / EAR analysis occupies a different position again. It is not primarily concerned with whether the counterparty is blocked (that is OFAC's domain). It is concerned with whether dealing with the counterparty requires a licence under the EAR, or whether the counterparty presents a prohibited-end-user risk. The control indicators BIS uses overlap with, but are not identical to, the OFSI and EU tests. What this means in practice is that a counterparty can be clear under OFAC (below the 50 percent threshold), clear under OFSI and the EU (no designated-person control), and still require a BIS licence assessment because of its relationship with an Entity-Listed party or its procurement patterns.
For businesses operating across US, UK, and EU export and sanctions regimes simultaneously, a single integrated assessment – rather than three separate regime-by-regime reviews – is significantly more efficient and reduces the risk of a conclusion in one regime being undermined by a gap in another.
If a transaction has already been flagged, or a filing has been refused, an early legal review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com.
What are the extraterritorial dimensions of the BIS / EAR ownership test?
The EAR's extraterritorial reach is among its most operationally significant features, and it is where ownership and control analysis becomes most pressing for non-US businesses.
The de minimis rule and the foreign direct product rule ("FDPR") extend BIS jurisdiction to foreign-made items that incorporate a defined threshold of US-controlled content, or that are the direct product of US-origin technology or software. Under the FDPR, a foreign manufacturer who produces a good using US-origin equipment or technology may find that the resulting product is subject to the EAR – and that its customer's ownership and control profile therefore determines whether a BIS licence is required.
This creates a compliance obligation for entities that have no direct relationship with the United States. A Taiwanese electronics manufacturer, a German machine-tool exporter, or a South-East Asian distributor may each find that their customer's ownership structure triggers a BIS licence requirement, because the item they are selling or re-selling falls within the FDPR's scope. The ownership and control assessment is therefore not exclusively a US-exporter task. It is a task for any company in a supply chain that includes US-origin controlled technology.
In our experience, non-US clients most frequently underestimate two things: first, the breadth of the FDPR and the range of goods it captures; and second, the obligation to reassess the ownership picture periodically, not only at the point of the initial transaction. An end-user's ownership structure can change. A new shareholder, a merger, or a management-services agreement can introduce a new control indicator without any public announcement. Have you built a reassessment trigger into your compliance programme, or does your due diligence treat first-transaction approval as a standing clearance?
What are the common risk flags and mistakes in BIS / EAR ownership assessments?
The most common mistakes we see in BIS / EAR ownership and control assessments fall into five categories, each of which has produced real enforcement exposure for exporters and re-exporters.
First, incomplete list-screening. Businesses that screen against the SDN List and stop there miss the Entity List, the Denied Persons List, the Unverified List, and the MEU list. These are distinct lists, maintained by different US agencies, and each triggers different consequences. A counterparty that is clear on OFAC's SDN List may appear on BIS's Entity List – and shipping to an Entity-Listed party without the required licence is a standalone violation.
Second, single-layer ownership mapping. Exporters who verify only the direct shareholder of the counterparty and do not trace the ownership chain through intermediate holding companies are applying an incomplete analysis. BIS guidance makes clear that the inquiry extends to indirect ownership and control.
Third, ignoring non-equity control indicators. A service agreement, a management contract, a nominee-director arrangement, or an exclusive distribution agreement can give a restricted party effective control over an entity it does not nominally own. These arrangements must be reviewed.
Fourth, treating a clean initial assessment as permanent. Ownership structures change. An acquisition, a new investor, or a restructuring can alter the control picture materially. A static assessment that is not refreshed before each significant transaction provides a false sense of security.
Fifth, inadequate documentation. An exporter who ran a thorough assessment but recorded only a one-line "pass" conclusion cannot demonstrate the quality of that assessment to BIS if questioned. The documentation of the methodology, the evidence reviewed, the red flags considered, and the conclusion reached is what differentiates a defensible compliance decision from an unexplained shipment.
A common myth among businesses new to BIS / EAR compliance is that the Entity List only captures major state-affiliated actors, and that a commercially conventional counterparty presenting standard trade documentation is unlikely to be a concern. This underestimates the scope of the Entity List, which includes private companies, research institutions, and individuals across many jurisdictions. It also underestimates the MEU controls, which can apply to entities whose procurement patterns – rather than their designated status – make them a risk. The correct approach is structured assessment, not assumption.
How does Calder & Vance support ownership and control assessments under BIS / EAR?
Calder & Vance delivers structured, documented ownership and control assessments for exporters, re-exporters, distributors, financial institutions, and M&A teams operating within or adjacent to the BIS / EAR regime. Our work covers the full assessment cycle: mapping the counterparty's direct and indirect ownership chain against the applicable BIS and OFAC lists, reviewing governance documents and operational relationships for control indicators, assessing red flags against BIS guidance, and producing a written assessment that records the methodology, the evidence reviewed, and the conclusion reached.
We regularly advise clients on multi-regime assessments that span the BIS / EAR, OFAC, OFSI, and EU ownership and control tests simultaneously. This is particularly relevant for M&A teams, financial institutions, and distributors whose counterparty relationships touch multiple jurisdictions. In a recent matter, a European distributor in the semiconductor sector faced a question about whether its end-customer – a commercially active entity with no designation – was effectively controlled by an Entity-Listed party through a management services agreement and shared technical personnel. We assessed the control indicators under the BIS / EAR analysis, mapped the parallel OFAC and EU positions, produced a written assessment for the client's compliance file, and identified the transaction structuring changes needed to reduce ongoing exposure. The matter was resolved without a referral to BIS.
We also advise on the periodic reassessment of counterparty ownership profiles, the integration of BIS / EAR ownership-assessment requirements into broader compliance programmes, and the preparation of voluntary self-disclosure where a prior shipment is identified as potentially problematic.
Our work under this service is distinct from legal advice on circumventing or evading restrictions. We assess what the law requires and how to meet it. We do not advise on ownership-disguise, false end-user statements, or any technique designed to defeat the EAR's controls.
Related practices
- Compliance audit and testing – Australia – structured testing of sanctions and export-control compliance programmes against the Australian DFAT regime and applicable international overlaps.
- Ownership and control assessments – Canada – legal support for ownership and control analysis under the Canadian sanctions and export-control regime administered by Global Affairs Canada.
- Ownership and control assessments – EU – analysis of the EU Council-regulation ownership and control test, including divergences from the OFAC and BIS approaches, and assessment for cross-border transactions.