Export Compliance Program Best Practices: What BIS Actually Recommends
If your company ships anything subject to the Export Administration Regulations (EAR) — hardware, software, or even technology shared with a foreign national on U.S. soil — the Bureau of Industry and Security (BIS) expects you to run an Export Compliance Program (ECP). It isn’t legally mandatory in most cases, but it is the single thing regulators look at first when something goes wrong, and a real program is what separates an honest mistake from a penalty. BIS publishes what a good one looks like; this is that guidance, distilled, with the counterparty-screening piece — the part that trips up most sellers — spelled out.
The eight core elements of an effective ECP
BIS frames an effective program around eight elements. They are not a checklist to file and forget — each is a live function someone has to own.
| Element | What it means in practice |
|---|---|
| 1. Management commitment | BIS calls senior-management commitment the single most important factor in an ECP’s success. It shows up as budget, a named responsible person, and a written policy signed at the top — not a memo from compliance alone. |
| 2. Risk assessment | Identify where your export exposure actually is — products and their classifications, destinations, customers, and end-uses — and build safeguards around the real risks. BIS recommends doing this before you draft the program, and revisiting it at least annually. |
| 3. Export authorization | Procedures to determine jurisdiction, classify the item (its ECCN on the Commerce Control List), decide whether a license or exception applies, and screen every party to the transaction against the restricted-party lists. |
| 4. Recordkeeping | Keep the export-related records the EAR requires, for the required period, in a system you can actually retrieve from. The general EAR retention period is five years. |
| 5. Training | Job-specific export-control training at every level that touches an export — sales, shipping, engineering, finance — not a single annual slide deck for the compliance team. |
| 6. Audits | Periodic internal checks that the procedures are actually being followed and are working, with a route to corrective action when they aren’t. |
| 7. Handling violations & corrective action | A mechanism to detect, report, investigate and remediate a suspected violation — including deciding whether to file a Voluntary Self-Disclosure with BIS (more below). |
| 8. Build & maintain the ECP manual | Write it all down in a manual that describes the procedures and who owns them, and keep it current as the rules and your business change. |
BIS’s best practices for the program itself
Alongside the elements, the BIS toolkit lists best practices for how to write and run the program. The theme running through all of them is the same: make the compliant path the easy path.
- Assess your risk first. Do a full risk assessment before you draft the ECP so it reflects your real risk profile, and review it annually.
- Tailor it to your transactions. Design the program around the specific exports, reexports, transfers and deemed exports your organization actually does under the EAR — not a generic template.
- Make doing the right thing simple. Give personnel step-by-step instructions and clear recordkeeping requirements so the compliant action is the obvious one.
- Keep it accessible and re-share it. The ECP should be readily available to everyone, reinforced with regular export-awareness training — a manual nobody can find protects no one.
- Publish the contacts. List clear compliance contacts at every level so employees know exactly who to ask before they act.
- Make reporting everyone’s job. State plainly that all personnel are responsible for reporting suspected or actual violations, and that reports get investigated immediately.
- Review and update it. Reassess the program’s effectiveness routinely and update it for regulatory changes and how the business evolves.
- Use BIS’s free review. BIS Export Compliance Specialists will review your ECP against their formal guidelines at no charge — a rare free second opinion from the regulator itself.
Where due diligence fits: screening and red flags
Element 3 — export authorization — is where an ECP meets the outside world, and it’s where the day-to-day risk lives. Two habits carry most of the weight.
Screen every party, and re-screen
Before goods or technology move, check each party to the transaction — customer, end-user, intermediate consignee, freight forwarder — against the U.S. restricted-party lists: the BIS Entity List, Denied Persons List, Unverified List and Military End-User List, plus Treasury’s OFAC lists and State’s ITAR debarred parties. A clean screen has a shelf life: these lists change constantly, so screen at onboarding, re-screen before each shipment, and keep the record. Our companion guide, OFAC & Export-Control Screening, walks through how to screen a name without fooling yourself.
Know the red flags
Screening a name against a list is necessary but not sufficient — a party with no hits can still be a problem. BIS’s longstanding Know Your Customer guidance lists warning signs that call for extra diligence before you proceed:
- The customer is reluctant to say how the item will be used, or is evasive about whether it’s for domestic use, export or reexport.
- The product’s capabilities don’t fit the buyer’s line of business — or are too advanced for the destination.
- The customer is unfamiliar with the product’s performance but wants it anyway, and declines routine installation, training or maintenance.
- The buyer is willing to pay cash for an expensive item that would normally be financed, or has little business background.
- Delivery is vague or routed oddly — out-of-the-way destinations, an abnormal shipping route, or a freight forwarder listed as the final destination.
A red flag isn’t a verdict; it’s a duty to inquire. BIS is explicit that you cannot self-blind — ignoring red flags is itself a compliance failure. Resolve the concern in writing before you ship, or don’t ship.
A compliance sequence you can run
- Assess the risk. Map your products, destinations, customers and end-uses, and rank where the exposure really sits.
- Classify the item. Determine jurisdiction and the ECCN, and whether a license or license exception applies to the destination.
- Screen the parties. Check every party to the deal against the restricted-party lists, follow the ownership, and clear any red flags in writing.
- Authorize and document. Only release the export once classification, licensing and screening all clear — and keep the record for five years.
- Train, audit, repeat. Train the people who touch exports, audit that the steps are actually happening, and update the manual as things change.
If something goes wrong
When you find a violation — and a working program is designed to find them — the ECP should route it to a decision on a Voluntary Self-Disclosure (VSD) to BIS. BIS treats a genuine, timely self-disclosure as a significant mitigating factor in any enforcement action. That calculus is fact-specific and usually a lawyer’s call, but the program’s job is to surface the issue fast enough that self-disclosure is still on the table.
Disclaimer. This article is general information for exporters, not legal advice, and the accuracy of the information here is not guaranteed. The EAR, the restricted-party lists and BIS guidance change frequently, and how they apply depends on your specific items, destinations and end-uses. Verify the current rules against BIS’s own materials and take qualified trade-compliance advice before relying on anything here. OpenDD accepts no liability for reliance on this content.
Sources: BIS — Export Compliance Program best practices, BIS — Export Compliance Guidelines: The Elements of an Effective Export Compliance Program, and BIS’s Know Your Customer Guidance and Red Flags (EAR Part 732, Supp. No. 3). Companion guide: OFAC & Export-Control Screening.