OpenDD
← All articles

Export Compliance Program Best Practices: What BIS Actually Recommends

Compliance · Updated September 2026

If your company ships anything subject to the Export Administration Regulations (EAR) — hardware, software, or even technology shared with a foreign national on U.S. soil — the Bureau of Industry and Security (BIS) expects you to run an Export Compliance Program (ECP). It isn’t legally mandatory in most cases, but it is the single thing regulators look at first when something goes wrong, and a real program is what separates an honest mistake from a penalty. BIS publishes what a good one looks like; this is that guidance, distilled, with the counterparty-screening piece — the part that trips up most sellers — spelled out.

The eight core elements of an effective ECP

BIS frames an effective program around eight elements. They are not a checklist to file and forget — each is a live function someone has to own.

ElementWhat it means in practice
1. Management commitmentBIS calls senior-management commitment the single most important factor in an ECP’s success. It shows up as budget, a named responsible person, and a written policy signed at the top — not a memo from compliance alone.
2. Risk assessmentIdentify where your export exposure actually is — products and their classifications, destinations, customers, and end-uses — and build safeguards around the real risks. BIS recommends doing this before you draft the program, and revisiting it at least annually.
3. Export authorizationProcedures to determine jurisdiction, classify the item (its ECCN on the Commerce Control List), decide whether a license or exception applies, and screen every party to the transaction against the restricted-party lists.
4. RecordkeepingKeep the export-related records the EAR requires, for the required period, in a system you can actually retrieve from. The general EAR retention period is five years.
5. TrainingJob-specific export-control training at every level that touches an export — sales, shipping, engineering, finance — not a single annual slide deck for the compliance team.
6. AuditsPeriodic internal checks that the procedures are actually being followed and are working, with a route to corrective action when they aren’t.
7. Handling violations & corrective actionA mechanism to detect, report, investigate and remediate a suspected violation — including deciding whether to file a Voluntary Self-Disclosure with BIS (more below).
8. Build & maintain the ECP manualWrite it all down in a manual that describes the procedures and who owns them, and keep it current as the rules and your business change.

BIS’s best practices for the program itself

Alongside the elements, the BIS toolkit lists best practices for how to write and run the program. The theme running through all of them is the same: make the compliant path the easy path.

Where due diligence fits: screening and red flags

Element 3 — export authorization — is where an ECP meets the outside world, and it’s where the day-to-day risk lives. Two habits carry most of the weight.

Screen every party, and re-screen

Before goods or technology move, check each party to the transaction — customer, end-user, intermediate consignee, freight forwarder — against the U.S. restricted-party lists: the BIS Entity List, Denied Persons List, Unverified List and Military End-User List, plus Treasury’s OFAC lists and State’s ITAR debarred parties. A clean screen has a shelf life: these lists change constantly, so screen at onboarding, re-screen before each shipment, and keep the record. Our companion guide, OFAC & Export-Control Screening, walks through how to screen a name without fooling yourself.

Know the red flags

Screening a name against a list is necessary but not sufficient — a party with no hits can still be a problem. BIS’s longstanding Know Your Customer guidance lists warning signs that call for extra diligence before you proceed:

A red flag isn’t a verdict; it’s a duty to inquire. BIS is explicit that you cannot self-blind — ignoring red flags is itself a compliance failure. Resolve the concern in writing before you ship, or don’t ship.

Screen the counterparty in one step. OpenDD checks a name against the BIS, OFAC and DDTC restricted-party lists via the U.S. government Consolidated Screening List, follows the ownership, and hands back a report — the diligence Element 3 asks for. Screen a party →

A compliance sequence you can run

  1. Assess the risk. Map your products, destinations, customers and end-uses, and rank where the exposure really sits.
  2. Classify the item. Determine jurisdiction and the ECCN, and whether a license or license exception applies to the destination.
  3. Screen the parties. Check every party to the deal against the restricted-party lists, follow the ownership, and clear any red flags in writing.
  4. Authorize and document. Only release the export once classification, licensing and screening all clear — and keep the record for five years.
  5. Train, audit, repeat. Train the people who touch exports, audit that the steps are actually happening, and update the manual as things change.

If something goes wrong

When you find a violation — and a working program is designed to find them — the ECP should route it to a decision on a Voluntary Self-Disclosure (VSD) to BIS. BIS treats a genuine, timely self-disclosure as a significant mitigating factor in any enforcement action. That calculus is fact-specific and usually a lawyer’s call, but the program’s job is to surface the issue fast enough that self-disclosure is still on the table.

Disclaimer. This article is general information for exporters, not legal advice, and the accuracy of the information here is not guaranteed. The EAR, the restricted-party lists and BIS guidance change frequently, and how they apply depends on your specific items, destinations and end-uses. Verify the current rules against BIS’s own materials and take qualified trade-compliance advice before relying on anything here. OpenDD accepts no liability for reliance on this content.

Sources: BIS — Export Compliance Program best practices, BIS — Export Compliance Guidelines: The Elements of an Effective Export Compliance Program, and BIS’s Know Your Customer Guidance and Red Flags (EAR Part 732, Supp. No. 3). Companion guide: OFAC & Export-Control Screening.