Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · BIS / EAR

Sanctions risk assessment under BIS / EAR: compliance counsel

A precision-goods manufacturer ships a batch of components to a distributor in a third market. Months later, a routine audit surfaces evidence that the items were re-exported to an end-user on the BIS Entity List. The original exporter had no direct contact with that end-user. Under the Export Administration Regulations ("EAR"), that distinction may not save the company from enforcement. Could a structured sanctions risk assessment have caught the exposure before the shipment left the dock?

A sanctions risk assessment under BIS / EAR (a systematic review of a business's export-control posture against the requirements of the Export Administration Regulations, administered by the US Bureau of Industry and Security) is the foundational step for any company that manufactures, re-exports, or transfers items subject to US jurisdiction. The assessment maps classification gaps, screens against the BIS restricted-party lists, tests end-use controls, and surfaces exposure to extraterritorial reach – including secondary-sanctions risk under OFAC. As of mid-2026, BIS enforcement posture remains assertive, with civil and criminal penalties available for violations of the EAR.

This page sets out what a BIS / EAR sanctions risk assessment involves, how it differs from an OFAC or EU sanctions review, the common risk flags we encounter, and how Calder & Vance assists businesses that need a defensible compliance position.

What does a BIS / EAR sanctions risk assessment cover?

A BIS / EAR sanctions risk assessment examines every control point at which the EAR could impose an obligation – from the classification of an item on the Commerce Control List through the screening of counterparties and end-users to the documentation of licence exceptions and the adequacy of end-use assurances. The governing authority is BIS, operating under the Export Control Reform Act and IEEPA. The EAR applies not only to US-origin items but also to foreign-produced goods that incorporate US-controlled content above a defined threshold, giving the regime a reach well beyond the United States' own borders.

In practice, an assessment under this regime has four main pillars. First, item classification: confirming whether each product, software, or technology carries an Export Control Classification Number (ECCN – the code on the Commerce Control List that determines which destinations, end-uses, and end-users require a licence). Second, destination and end-user screening: checking buyers, intermediaries, freight forwarders, and known end-users against the BIS Entity List, Denied Persons List, and Unverified List, as well as OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons). Third, licence-exception eligibility: verifying whether a claimed exception genuinely covers the transaction. Fourth, programme adequacy: testing whether internal policies, training records, and audit trails would withstand BIS scrutiny in an enforcement inquiry.

We regularly advise manufacturers and trading companies that have assumed an item is EAR99 – and therefore licence-free everywhere – only to discover that recent control-list amendments brought it under an ECCN. That reclassification gap is one of the most common sources of unintentional violation.

How does BIS / EAR exposure differ from OFAC and EU sanctions risk?

BIS / EAR risk is primarily a licensing and classification problem; OFAC risk is primarily a counterparty-status problem. Both can be present in the same transaction, and a risk assessment that treats them as separate exercises will miss the interaction between them. For cross-border businesses, understanding where the regimes converge – and where they diverge – is critical.

Under OFAC, the central question is whether a counterparty or its beneficial owners appear on a designated-persons list, or whether a transaction involves a sanctioned jurisdiction. The 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked, regardless of whether the entity itself is listed) can make a supplier blocked even where no ECCN or licence issue exists. A BIS assessment must therefore include an OFAC ownership-chain check alongside the classification review.

The EU position adds a third layer. EU sanctions regulations establish their own ownership and control test (the EU and UK test for whether a non-listed entity is caught through a listed person, which turns on control as well as ownership). A European-headquartered business with US-origin items in its supply chain faces simultaneous exposure under the EAR and under the relevant EU Council regulations. The two regimes' restricted-party lists do not overlap perfectly: an entity may appear on the EU Consolidated List but not on any BIS list, or vice versa. A credible cross-border risk assessment must screen against all applicable lists.

For a detailed review of how the EU sanctions risk assessment process works alongside BIS exposure, see our EU sanctions risk assessment service page. For the OFAC-specific counterparty and ownership analysis, our OFAC sanctions risk assessment service sets out the applicable methodology.

The position above covers the standard multi-regime interaction. Your specific facts – the item's classification, the distribution chain's geography, the end-user's sector – change the analysis considerably.

For a first assessment of your cross-regime exposure, contact Calder & Vance at info@caldervance.com.

What is the procedure for a BIS / EAR risk assessment?

A structured BIS / EAR risk assessment follows a defined sequence, each phase building on the previous one, and the output of each phase informing whether the next requires expansion or can proceed on a targeted basis.

The first phase is scoping. Counsel and the client's compliance team agree on which product lines, business units, markets, and supply-chain participants are in scope. A broad initial scope is usually appropriate for a business conducting its first formal assessment; subsequent periodic reviews can be targeted to areas where the prior assessment identified gaps, or to new products and markets.

The second phase is item classification. Each item, software, and technology is reviewed against the Commerce Control List. Where an item is already classified, the classification is verified for accuracy and currency – control-list amendments can change an ECCN without any change to the product itself. Where no prior classification exists, counsel conducts a classification analysis and prepares a classification memorandum. This is a legal document; it should be prepared with legal professional privilege in mind.

The third phase is restricted-party screening. The client's counterparty lists – customers, distributors, freight forwarders, agents, and known end-users – are screened against the BIS Entity List, Denied Persons List, Unverified List, and the OFAC SDN List. Where a potential match arises, counsel conducts a deeper ownership-chain analysis to determine whether the 50 percent rule or the EU / UK ownership-and-control test is engaged.

The fourth phase is programme gap analysis. The existing compliance programme – policies, training records, screening workflows, audit trails, licence-exception documentation, and end-use assurance procedures – is tested against the five-element compliance standard that BIS expects of exporters. Gaps are ranked by severity and likelihood of detection in an enforcement inquiry.

The fifth phase is the assessment report. Counsel prepares a written report setting out findings, risk rankings, and a prioritised remediation plan. The report is structured to be defensible: it can be placed before a board, a regulator in a voluntary self-disclosure (VSD – a proactive notification to a regulator of a potential violation, which BIS treats as a significant mitigating factor in penalty determinations) context, or a compliance committee. Timelines for the full assessment vary with the complexity of the product portfolio and the depth of the supply chain; in our experience, a focused assessment of a single business unit takes materially less time than a group-wide review of a diversified manufacturer.

Which risk flags most often surface in BIS / EAR assessments?

The risk flags that appear most frequently in BIS / EAR assessments fall into four categories: classification errors, screening gaps, programme weaknesses, and transaction red flags.

Classification errors are the single most common finding. The Commerce Control List is amended regularly; a product classified several years ago may have moved to a different ECCN, or may have lost an available licence exception, as a result of amendments that the company never tracked. Dual-use items – those with both civil and military applications – are particularly prone to this problem because control-list amendments in the dual-use space follow technology-control lists agreed at multilateral export-control regimes, and the cadence of those updates is not always visible to commercial compliance teams.

Screening gaps arise where a business screens its direct customers but not the intermediate freight forwarders, consolidators, or agents who handle the physical shipment. BIS expects exporters to screen the full transaction chain. A single unscreened forwarder with a link to a denied party is sufficient to establish a potential violation, even where the ultimate customer is unimpeachable.

Programme weaknesses tend to cluster around documentation. Licence exceptions under the EAR require specific conditions to be met and – for some exceptions – specific records to be maintained. Where documentation is absent or incomplete, the exception is unavailable as a defence. In a number of assessments, we have found that a company was eligible for an exception but had not kept the required paperwork, leaving it formally exposed on transactions that were substantively permissible.

Transaction red flags are the behavioural signals that BIS and DOJ use to identify potential violations: requests for unusual payment terms, resistance to end-use-certificate requirements, routing through third countries with no obvious commercial rationale, and inconsistency between a buyer's stated business and the technical specification of the goods ordered. Red-flag recognition is a training issue as much as a policy issue; an assessment should test whether front-line staff – sales, logistics, customer service – have been trained to escalate and what escalation procedures exist.

How does extraterritorial reach affect a non-US company's risk exposure?

The EAR's extraterritorial reach is one of the most practically significant features of BIS jurisdiction for non-US businesses. A foreign company that re-exports or in-country transfers items subject to the EAR is bound by the EAR to the same degree as a US exporter, even if neither the exporter nor the recipient is a US person and the transaction has no other US nexus beyond the item's US origin or US-content percentage.

The de minimis rule (the threshold below which foreign-produced items incorporating US-controlled content are not subject to the EAR) is relevant here, but it is frequently misapplied. The calculation is not simply a matter of the percentage of US-origin parts by value; it depends on the ECCN of the US-controlled content and the destination. For certain controlled destinations, a lower threshold applies, and for military end-uses or end-users a controlled item may remain subject to the EAR regardless of content percentage.

The foreign direct product rule extends jurisdiction further. Under this rule, items produced abroad using US-origin technology or software subject to the EAR can themselves become subject to EAR controls when destined for certain specified entities or end-uses. This is a specialised area of the regime that non-US semiconductor manufacturers, equipment makers, and software developers have had to address in their risk assessments as the rule's scope has expanded.

In our cross-border practice, we regularly advise European and Asian manufacturers that believed their supply chain was outside BIS jurisdiction, only to find that a US-licensed software tool used in their production process brought the finished product within EAR reach. The assessment of foreign direct product rule exposure is a discrete analytical step that should be built into any BIS / EAR risk assessment for non-US companies.

If a transaction has already been flagged as a potential EAR violation, or if a customer or freight forwarder has appeared on the Entity List after a shipment was made, an early legal review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss the position confidentially.

What are the common myths about BIS / EAR compliance?

One persistent myth is that a company with no US operations and no US employees has no EAR obligations. This is incorrect. The EAR's jurisdictional reach follows the item and the technology, not the nationality of the exporter. A foreign company that re-exports a US-origin item, or that transfers EAR-controlled technology to a third party, is subject to the EAR on that transaction regardless of where the company is incorporated or where its employees are based.

A second myth is that EAR99 classification means a product is unrestricted everywhere. EAR99 means the item is not listed on the Commerce Control List and does not require a licence to most destinations for most end-users. It does not mean the item can be shipped to denied parties, to persons on the Entity List, or to certain controlled destinations. A company that ships EAR99 goods to a listed party has still committed a violation; the absence of an ECCN does not remove the restricted-party screening obligation.

A third myth is that the BIS regime and the OFAC regime are alternatives – that a company in compliance with one is necessarily in compliance with the other. They are parallel obligations. A transaction can be permissible under the EAR and simultaneously prohibited under OFAC, or vice versa. A credible BIS / EAR sanctions risk assessment must always include the OFAC overlay, and vice versa. Businesses that run separate, siloed compliance programmes for each regime routinely find gaps at the intersection.

How Calder & Vance conducts a BIS / EAR sanctions risk assessment

Calder & Vance assists exporters, manufacturers, trading companies, and financial institutions in assessing, structuring, and strengthening their BIS / EAR compliance posture across the full assessment lifecycle.

In a recent matter, a European industrial equipment supplier was preparing to enter a new distribution arrangement covering several third-country markets. The compliance team had existing ECCN classifications for its product range, but had not reviewed them since a major control-list amendment cycle. We conducted a classification review, identified a reclassification affecting two product families, assessed the impact on pending transactions, and advised on voluntary self-disclosure. The matter was resolved with the company having a current, documented classification record and a strengthened screening workflow before the new distribution contracts were signed.

Our approach across engagements involves five consistent elements: we assess eligibility, prepare and submit licence applications, and manage the regulator's queries where a licence is required; we test the screening logic, map ownership and control chains, and redesign the programme to the five-element compliance standard where gaps are found; we classify items and confirm licence requirements and exceptions; we design end-use controls appropriate to the product, the distribution channel, and the markets served; and we advise on voluntary self-disclosure and prepare the penalty defence where a potential violation has occurred or is suspected.

We operate across the major regimes – BIS / EAR, OFAC, OFSI, the EU Council regulations, and the UN Consolidated List – from a single practice. That cross-regime coverage means we can run a coordinated assessment that does not miss the overlaps between the regimes, which is where cross-border businesses most often find their exposure.

For businesses that have already completed an internal assessment and want an independent review, we offer a targeted gap-analysis engagement at a defined fee. For businesses beginning their first formal BIS / EAR assessment, we offer a scoping call at no charge to define the appropriate scope and structure.

Related practices

Frequently asked questions: BIS / EAR sanctions risk assessment

How long does carrying out a sanctions risk assessment take under BIS / EAR?

The duration depends primarily on the scope – the number of product lines, the size of the counterparty base, and the depth of the supply chain under review. A focused assessment of a single business unit or product family can typically be completed within a few weeks. A group-wide review of a diversified manufacturer with a complex distribution network takes longer. We agree the scope and an indicative timeline at the outset of each engagement; the written assessment report is delivered at the close of the engagement. Verify the current position with us based on your specific facts.

What are the main risks in a sanctions risk assessment under BIS / EAR?

The principal risks are: discovering a classification error that affects completed transactions, which may require a voluntary self-disclosure to BIS; finding that a counterparty or end-user is on a restricted-party list and that shipments have been made to that party; identifying that licence-exception documentation is insufficient to support the claimed exception; and finding that the compliance programme would not withstand scrutiny in a BIS enforcement inquiry. Early identification through a structured assessment preserves options. A VSD, where appropriate, is treated by BIS as a significant mitigating factor in penalty determinations.

Do we need specialist counsel for a sanctions risk assessment?

A well-designed internal assessment is a sound starting point. Specialist counsel adds value where the product portfolio involves dual-use or military items with complex ECCN questions; where the distribution chain crosses multiple jurisdictions and the extraterritorial reach of the EAR is in play; where the assessment may lead to a voluntary self-disclosure, in which case legal professional privilege over the assessment document is important; or where findings need to be presented to a board or regulator in a way that carries independent credibility. For a first assessment or for a business entering a new market, external counsel typically identifies material issues that internal reviews do not.

About the author

Viktor Lindqvist advises exporters and trading houses on dual-use export controls, maritime and trade sanctions, and end-use compliance. Calder & Vance – International Sanctions & Export Control Counsel.

Published: 24 August 2026

About Calder & Vance

Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.

Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.