Summary. Export control and sanctions law reaches ordinary companies that do not think of themselves as exporters, because the definitions capture software downloads, cloud access, engineering emails, and hiring a foreign national. This article covers the Export Administration Regulations — classification, license determination, and license exceptions, plus the deemed export rule — then ITAR's far stricter regime for defense articles and technical data, and OFAC sanctions including the SDN List, the fifty percent rule, and the difference between list-based and comprehensive programs. Later sections address antiboycott rules, screening and program design, voluntary self-disclosure, and penalties.
A 40-person analytics software company hires a talented graduate student from Iran who holds valid US work authorization. She is assigned to the encryption module.
No product leaves the country. No sale is made abroad. And the company has just committed a potential export violation, because releasing controlled technology or source code to a foreign national inside the United States is a deemed export to that person's country of nationality — and Iran is subject to a comprehensive embargo.
The same company later posts its software for download on its website. Sixty-one downloads originate from countries where the applicable encryption classification requires a license or notification. The company has never heard of an ECCN.
Neither of these acts felt like exporting. Both are, under regulations that define "export" to include transmission of technology across a border by any means, including email, cloud access, and a phone call.
Export controls are among the few regulatory regimes where a company can violate the law without shipping anything, without intending anything, and without knowing the regime exists.
The short answer
Three regimes, three agencies:
- The Export Administration Regulations (EAR), 15 C.F.R. parts 730-774, administered by the Bureau of Industry and Security at Commerce. Covers dual-use items — commercial goods, software, and technology with potential military application — plus some purely commercial items.
- The International Traffic in Arms Regulations (ITAR), 22 C.F.R. parts 120-130, administered by the Directorate of Defense Trade Controls at State. Covers defense articles, defense services, and technical data on the United States Munitions List.
- Sanctions programs, 31 C.F.R. chapter V, administered by the Office of Foreign Assets Control at Treasury. Restricts dealings with designated persons, countries, and regimes.
Four questions for any transaction:
- What is it — item, software, or technology, and what is its classification?
- Where is it going — the destination country?
- Who will receive it — the end user, and every party to the transaction?
- What will it be used for — the end use?
The definitions that catch people: "export" includes releasing technology to a foreign national in the United States (deemed export); "technology" includes technical data required for development, production, or use; and "reexport" captures shipment from one foreign country to another of US-origin items or foreign-made items with sufficient US content.
Strict liability. Most sanctions violations are strict liability civil offenses. Good faith is relevant to penalty, not to whether a violation occurred.
The EAR: classification
Scope. The EAR applies to items in the United States, US-origin items wherever located, foreign-made items incorporating more than a de minimis amount of controlled US content, and certain foreign-produced direct products of US technology or software under the foreign direct product rules — which have been expanded significantly for advanced computing and semiconductor manufacturing equipment destined for particular countries.
Classification is the foundational step and produces one of two answers:
- An Export Control Classification Number (ECCN) from the Commerce Control List, 15 C.F.R. part 774 supplement 1. An ECCN has five characters (e.g., 5A002) encoding a category (0 through 9: nuclear; materials and chemicals; electronics; computers; telecommunications and information security; sensors and lasers; navigation and avionics; marine; aerospace and propulsion) and a product group (A systems and equipment, B test equipment, C materials, D software, E technology).
- EAR99 — the residual designation for items subject to the EAR but not listed on the CCL. Most commercial products are EAR99. That does not mean no license is required: EAR99 items still require licenses for embargoed destinations, prohibited end users, and prohibited end uses.
Who classifies. The exporter is responsible. Options are self-classification with documented technical analysis, a request for a commodity classification from BIS through the electronic system, or an advisory opinion. Keep the analysis, the parameters relied on, and the date.
Encryption deserves special mention because it captures ordinary software. Category 5 Part 2 controls information security items, and many commercial products with encryption fall under 5A002, 5D002, or 5D992. The regime provides self-classification reporting, mass market treatment under Note 3 to Category 5 Part 2, and License Exception ENC, but each carries conditions and reporting obligations. Software companies that ship anything with TLS, disk encryption, or a cryptographic library should have a documented encryption classification.
The EAR: license determination and exceptions
Once classified, determine whether a license is required for the destination:
- Find the ECCN's Reasons for Control — national security, missile technology, nuclear nonproliferation, chemical and biological weapons, regional stability, crime control, antiterrorism, encryption, or others.
- Cross-reference the Commerce Country Chart, 15 C.F.R. part 738 supplement 1, for the destination. An "X" in the box for that reason and destination means a license is required.
- Check whether a License Exception in part 740 is available.
- Check the end user and end use prohibitions in part 744 regardless of the answers above.
Common license exceptions:
- LVS — limited value shipments.
- GBS — shipments to Country Group B destinations of items controlled only for national security.
- TSU — technology and software, including operation technology and software, sales technology, and software updates.
- ENC — encryption items, subject to review requirements, reporting, and eligibility conditions.
- TMP — temporary imports, exports, and reexports, including tools of trade taken abroad by employees.
- BAG — personal baggage.
- STA — strategic trade authorization to specified destinations, with prior consignee statements and notification requirements.
- RPL — servicing and replacement of parts and equipment.
- GOV — shipments to specified government agencies.
Each exception has conditions and recordkeeping requirements, and using one requires documenting eligibility on the export documentation.
End use and end user controls, part 744, apply regardless of classification — including to EAR99 items:
- Prohibited weapons of mass destruction end uses.
- Military end use and military end user controls for specified destinations.
- Military intelligence end user controls.
- Entity List parties, 15 C.F.R. part 744 supplement 4 — a license is required for the transactions specified in the list, generally with a presumption or policy of denial, and license exceptions are usually unavailable.
- Denied Persons List — persons whose export privileges have been denied. Any transaction involving them is prohibited.
- Unverified List — parties BIS could not verify, requiring additional diligence and an end-user statement.
- Military End User List.
The catch-all obligation. Even where no license is required on the face of the rules, an exporter may not proceed with knowledge — including conscious disregard or willful avoidance — that a violation is about to occur, 15 C.F.R. § 736.2(b)(10). This is where BIS's published red flags guidance operates.
Antiboycott. Part 760 prohibits participating in unsanctioned foreign boycotts, requires reporting boycott requests received, and prohibits furnishing information about business relationships with boycotted countries or with blacklisted persons. The provisions are triggered by boilerplate in letters of credit and purchase orders from certain markets, and companies violate them by processing paperwork without reading it. The reporting obligation applies even where the request is refused.
ITAR: the stricter regime
If an item is a defense article on the United States Munitions List, 22 C.F.R. § 121.1, the ITAR applies instead of the EAR, and nearly everything is harder.
Registration. Any person who manufactures, exports, or brokers defense articles or defense services must register with DDTC and pay an annual fee — even if they never export. A domestic-only manufacturer of a USML item is required to register. Failure to register is itself a violation and is discovered routinely.
Licensing. Most exports require a specific license or agreement:
- DSP-5 — permanent export of unclassified defense articles and technical data.
- DSP-73 — temporary export.
- DSP-61 — temporary import.
- Technical Assistance Agreement (TAA) — for furnishing defense services or technical data to foreign persons.
- Manufacturing License Agreement (MLA) — for manufacturing abroad.
- Warehouse and Distribution Agreement — for offshore distribution.
Exemptions exist but are narrow, condition-heavy, and unforgiving. Reliance on an exemption requires strict compliance with its terms and appropriate documentation.
Technical data includes information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modification of defense articles — including blueprints, drawings, photographs, plans, instructions, and documentation. It excludes information in the public domain and general scientific, mathematical, or engineering principles commonly taught.
Defense services — furnishing assistance to a foreign person in the design, development, engineering, manufacture, production, assembly, testing, repair, maintenance, modification, operation, demilitarization, destruction, processing, or use of defense articles, or furnishing technical data — is itself controlled, which means a US engineer advising a foreign counterpart may require an agreement even where nothing physical moves.
Deemed exports under ITAR work like the EAR's rule but are stricter: releasing technical data to a foreign person in the United States is an export requiring authorization, and ITAR's employment-related exemptions are narrower.
Brokering, part 129, separately regulates persons who act as brokers for defense articles, with its own registration, prior approval, and reporting requirements — and it reaches non-US persons in defined circumstances.
Congressional notification is required for certain sales above statutory thresholds.
Export Control Reform moved many items formerly on the USML to the CCL's "600 series" ECCNs, which remain controlled under the EAR but with more available license exceptions. An item's history matters: a component classified as ITAR-controlled a decade ago may now be a 600 series item, and the classification should be verified rather than assumed.
The practical rule. ITAR jurisdiction is determined by the item, not by the customer or the intent. A company that manufactures a part to a defense specification should obtain a commodity jurisdiction determination from DDTC if there is any doubt, and should register if there is not.
OFAC sanctions
Sanctions are the regime most likely to catch a company with no international operations, because they apply to transactions, not exports.
Who must comply. All US persons — US citizens and permanent residents wherever located, entities organized under US law including foreign branches, and any person in the United States. Several programs also reach foreign subsidiaries of US companies (Cuba and Iran most notably) and impose secondary sanctions on non-US persons.
Two structural types:
List-based programs target designated persons. The central list is the Specially Designated Nationals and Blocked Persons List (SDN List). Property and interests in property of an SDN in the possession or control of a US person must be blocked — frozen, reported to OFAC within 10 business days, and held in an interest-bearing blocked account. US persons may not deal with SDNs at all absent authorization.
Other lists carry different consequences: the Sectoral Sanctions Identifications (SSI) List prohibits specified categories of transactions rather than all dealings; the Non-SDN Menu-Based Sanctions List; the Foreign Sanctions Evaders List; and the Correspondent Account or Payable-Through Account Sanctions (CAPTA) List.
The 50 Percent Rule. OFAC treats any entity owned 50 percent or more, directly or indirectly, individually or in the aggregate, by one or more blocked persons as itself blocked — whether or not it appears on any list. This is the single most important sanctions concept for ordinary businesses, because a counterparty that screens clean may be majority-owned by persons who do not. Ownership diligence, not list screening, is what catches it. Note that the rule addresses ownership, not control; OFAC cautions that entities controlled but not majority-owned by blocked persons present risk even though they are not automatically blocked.
Comprehensive programs embargo entire jurisdictions — currently including Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine, with the specific scope and any authorizations varying by program and changing. Virtually all transactions with those jurisdictions are prohibited absent a general or specific license.
Other significant programs target Russia and Belarus (extensive, including sectoral, financial, energy, and export-related measures), Venezuela, Burma, Afghanistan, and thematic programs covering narcotics trafficking, terrorism, cyber-enabled activities, human rights abuses under the Global Magnitsky program, and transnational criminal organizations.
Licenses. General licenses authorize categories of transactions without application — for example, humanitarian activity, personal remittances, or wind-down periods following a designation. Specific licenses are applied for individually. Read general licenses carefully: they are narrow, they carry conditions and reporting obligations, and they expire.
Facilitation. A US person may not approve, finance, facilitate, or guarantee a transaction by a foreign person that would be prohibited if performed by a US person. This catches the US parent that steps back and lets a foreign subsidiary do the deal, and the US employee who refers the inquiry to a foreign colleague. Referring business away is not a solution; it is a violation.
Reporting. Blocked property must be reported within 10 business days and annually. Rejected transactions must also be reported.
Screening and compliance program design
Restricted party screening is the operational core. Screen:
- Customers, prospects, and their beneficial owners.
- Vendors, suppliers, freight forwarders, and banks.
- Distributors, agents, resellers, and consultants.
- Employees, contractors, and job applicants where deemed export exposure exists.
- Visitors to controlled facilities.
- Investors and lenders.
- Parties to any transaction, including intermediaries and consignees.
Against what: the consolidated screening list (which aggregates Commerce, State, and Treasury lists), plus the SDN List and other OFAC lists, plus the sanctioned jurisdictions, plus any customer's ownership structure for the 50 Percent Rule.
When: at onboarding, before each transaction, on any change to the party's information, and on a periodic rescreen of the entire database, because designations are added continuously.
How: automated screening software integrated with the ERP or CRM, with documented fuzzy-match thresholds, a defined false-positive resolution workflow, and retention of screening records. Manual screening of a customer list once a year is not a program.
The rest of a program, following BIS's Export Compliance Program guidelines and OFAC's Framework for Compliance Commitments:
- Management commitment — a written policy, signed at the senior level, with resources.
- Risk assessment — products, technologies, destinations, customers, end uses, channel partners, and personnel nationalities.
- Written procedures covering classification, licensing, screening, recordkeeping, and escalation.
- Training, role-specific, for sales, engineering, shipping, HR, finance, and legal.
- Recordkeeping — five years for both EAR and OFAC records, and ITAR requires retention as well. Records include classification analyses, license determinations, screening results, end-user statements, shipping documents, and licenses.
- Testing and auditing, including transaction sampling.
- Corrective action and a documented escalation path.
Technology controls that matter for a software company: geo-blocking downloads from embargoed jurisdictions; IP-based access controls with awareness that they are imperfect; export control terms in the end user license agreement; controls on cloud and repository access; and segregation of controlled technology behind access controls tied to nationality where deemed export rules apply.
Human resources controls: confirm whether a role will access controlled technology before extending an offer; understand that ITAR and the EAR permit consideration of nationality only where required for export control compliance, and that overbroad citizenship requirements violate the anti-discrimination provision of 8 U.S.C. § 1324b; and apply the analysis consistently with a documented basis.
Red flags
BIS publishes red flag indicators, and they are worth training into a sales organization because the catch-all prohibition turns an ignored red flag into knowledge.
- The customer or purchasing agent is reluctant to offer information about the end use of the item.
- The product's capabilities do not fit the buyer's line of business.
- The item ordered is incompatible with the technical level of the destination country.
- The customer is willing to pay cash for a very expensive item when the terms would normally call for financing.
- The customer has little or no business background.
- The customer is unfamiliar with the product's performance but wants it anyway.
- Routine installation, training, or maintenance services are declined.
- Delivery dates are vague, or deliveries are planned for out-of-the-way destinations.
- A freight forwarding firm is listed as the product's final destination.
- The shipping route is abnormal for the product and destination.
- Packaging is inconsistent with the stated method of shipment or destination.
- When questioned, the buyer is evasive about whether the product is for domestic use, export, or reexport.
- The customer requests excessive spare parts or components inconsistent with normal use.
- The buyer requests that the product be shipped to an address different from the one on record, especially in a different country.
The rule: a red flag must be resolved and the resolution documented, or the transaction must be declined. Proceeding without inquiry is precisely the conscious disregard the regulations reach.
Enforcement, penalties, and voluntary self-disclosure
EAR penalties. Civil penalties per violation under the International Emergency Economic Powers Act, adjusted annually for inflation, or twice the value of the transaction, whichever is greater. Criminal penalties up to $1 million and 20 years' imprisonment per willful violation. Administrative sanctions include denial of export privileges, which is commercially fatal for an exporter, and exclusion from practice before BIS.
ITAR penalties. Civil penalties per violation, criminal penalties up to $1 million and 20 years per willful violation, debarment from defense trade, and seizure and forfeiture.
OFAC penalties. Civil penalties per violation under IEEPA, adjusted annually, or twice the transaction value; substantially higher under some statutes. Criminal penalties up to $1 million and 20 years for willful violations. Most sanctions violations are strict liability — intent is not an element of the civil offense.
OFAC's Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501 appendix A, set the framework. The single largest mitigating factor is a voluntary self-disclosure, which can reduce the base penalty by 50 percent. Other factors include willfulness, awareness by management, harm to sanctions program objectives, the existence and quality of a compliance program, remedial response, and cooperation.
Voluntary self-disclosure is available under all three regimes and is the standard response to a discovered violation:
- BIS: an initial notification followed by a narrative account, submitted before BIS learns of the violation from another source. BIS policy treats VSD as a great weight mitigating factor, and it has emphasized that disclosure of a third party's violation may itself earn mitigation credit in an unrelated matter.
- DDTC: disclosure is "strongly encouraged" and is a mitigating factor; some ITAR provisions make disclosure effectively mandatory in practice.
- OFAC: disclosure before OFAC or another agency discovers the violation, with a complete report.
The decision to disclose is not automatic. It requires an internal investigation under privilege, a determination of what happened and how many violations occurred, an assessment of the likelihood of independent discovery, and a remediation plan. But the arithmetic usually favors disclosure, and the failure to disclose a known violation compounds the exposure substantially — including under the False Statements Act if the company later certifies compliance.
Enforcement trends. The agencies have created a Disruptive Technology Strike Force and have emphasized coordinated criminal and administrative enforcement, corporate self-disclosure policies that offer declinations for prompt disclosure with full cooperation and remediation, and successor liability for acquired violations — which makes export and sanctions diligence a standard M&A workstream.
A worked example
Northfield Instruments manufactures precision motion control systems. Revenue $60 million, 15 percent international.
The assessment.
- Classification. Its controllers are classified under a Category 2 ECCN controlled for national security and antiterrorism reasons. Its software includes a cryptographic library, requiring separate Category 5 Part 2 analysis. Its spare fasteners are EAR99.
- Destinations. Sales to 22 countries. The Country Chart shows licenses required for four of them for the applicable reason for control; License Exception GBS covers two others.
- Parties. Screening of 1,100 counterparties returns four hits. Three are false positives resolved and documented. One is a distributor in a third country that is 55 percent owned by an SDN-designated individual — blocked under the 50 Percent Rule although the distributor itself is not listed.
- End use. A prospective customer in a fifth country states the equipment is for "research applications" and declines installation and training. Two red flags.
- Personnel. Three engineers with access to controlled technology hold foreign nationality; two are from countries requiring a deemed export license for the applicable ECCN.
- Antiboycott. A letter of credit from a Middle Eastern bank contains a clause requiring certification that the goods are not of Israeli origin — a reportable boycott request, whether or not it is complied with.
The response.
- Stop the distributor relationship, block any property in the company's possession, file the blocking report within 10 business days, and apply for a specific license to wind down if any obligation remains.
- Decline the fifth-country prospect and document the red flag analysis; do not simply route the sale through a reseller, which is facilitation.
- Apply for deemed export licenses for the two engineers, and in the interim restrict their access to the controlled technology through technical controls, with the restriction documented as export-compliance based.
- Report the boycott request on the required form and refuse the clause; negotiate a substitute.
- Implement automated screening at order entry and a quarterly rescreen; geo-block software downloads from embargoed jurisdictions; add export control terms to the EULA and distributor agreements; and require end-user statements above a threshold.
- Investigate whether prior shipments to the blocked distributor occurred, quantify them, and evaluate voluntary self-disclosure to OFAC.
- Train sales on red flags, engineering on deemed exports, and HR on the interaction between export control and citizenship-status discrimination law.
Result. Two prior shipments to the distributor were identified, disclosed voluntarily, and resolved with a cautionary letter rather than a penalty, on the strength of the disclosure and the remediation. The engineering access controls were in place before any license was needed for a new hire.
A screening and compliance checklist
Know your items
- Classify every product, software release, and technology, and document the analysis and its date.
- Obtain a commodity classification or commodity jurisdiction determination where the answer is uncertain.
- Reclassify on any material product change, and revisit encryption classifications on each release.
- Determine whether foreign-made products are subject to the EAR through de minimis or foreign direct product rules.
Know your parties
- Screen every counterparty and intermediary at onboarding and before each transaction.
- Conduct beneficial ownership diligence sufficient to apply the 50 Percent Rule.
- Rescreen the full database periodically; designations change constantly.
- Document false-positive resolutions.
Know your destinations and end uses
- Apply the Country Chart for each reason for control.
- Check part 744 end use and end user prohibitions regardless of classification.
- Obtain end-user statements for sensitive items and destinations.
- Train on red flags and require documented resolution.
Operational controls
- Geo-blocking and access controls for software and cloud services.
- Export control clauses in EULAs, distributor agreements, and purchase orders, with reexport restrictions and audit rights.
- HR process to identify deemed export exposure before an offer, applied consistently and documented.
- Antiboycott review of every letter of credit and purchase order from affected markets, with reporting.
- Travel procedures for laptops and tools of trade, including License Exception TMP conditions.
Program
- Written policy, procedures, training, recordkeeping (five years), auditing, and escalation.
- A named compliance owner with authority to stop a shipment.
- Export and sanctions diligence in every acquisition, with successor liability in view.
- A documented voluntary self-disclosure decision process.
Frequently asked questions
We only sell domestically. Does any of this apply? Sanctions apply to transactions with blocked persons wherever they occur, and the deemed export rules apply to disclosures inside the United States. Both reach purely domestic operations.
Our product is EAR99. Are we free to ship anywhere? No. EAR99 items still require authorization for embargoed destinations, listed parties, and prohibited end uses.
We screened the customer and it came back clean. Is that enough? Not necessarily. The 50 Percent Rule blocks entities majority-owned by blocked persons even when they are not listed. Screening alone will not find them; ownership diligence will.
Can we let our foreign subsidiary handle a transaction we cannot do? No. Facilitation by a US person is itself prohibited, and several programs reach foreign subsidiaries of US companies directly.
Can we ask a job applicant about citizenship? Only as export control compliance requires, applied consistently and documented. Overbroad citizenship requirements violate 8 U.S.C. § 1324b, and companies have been penalized for job postings that exclude work-authorized non-citizens on unfounded ITAR grounds.
A customer asked us to certify our goods are not of Israeli origin. What do we do? Refuse the certification and report the request. The reporting obligation applies whether or not you comply.
We think we made a mistake. Should we disclose? Investigate first under privilege, then decide. Voluntary self-disclosure is the single largest mitigating factor across all three regimes, and the arithmetic usually favors it.
How long do we keep records? Five years under the EAR and OFAC regulations, with ITAR retention requirements as well. Retain classification analyses, screening results, licenses, end-user statements, and shipping documents.
Conclusion
Export controls and sanctions are the clearest example in American regulation of a regime that punishes companies for not knowing it exists. There is no revenue threshold, no employee-count exemption, and no requirement that anything be shipped abroad.
What makes compliance tractable is that the whole regime reduces to four questions asked before each transaction — what, where, who, and what for — and to two controls that catch nearly everything: classify the products once, properly, and screen every party every time, including their owners.
The companies that get into serious trouble are almost never the ones that misjudged a classification. They are the ones that never classified anything, screened nobody, and discovered the regime when an agent arrived to ask about a shipment made three years earlier.
Adjacent regimes that travel with the same shipment
Export control and sanctions are two of several regimes governing cross-border commerce, and companies that build a program around only those two are regularly surprised by the others.
Customs and import. Customs and Border Protection enforces classification under the Harmonized Tariff Schedule, valuation, country of origin marking, and duty payment. The importer of record bears a duty of reasonable care, 19 U.S.C. § 1484, and errors are corrected through prior disclosure under 19 U.S.C. § 1592, which caps liability at interest where the disclosure precedes agency knowledge. Free trade agreement claims — USMCA in particular — require documented origin certification, and antidumping and countervailing duty orders can attach retroactively to merchandise the importer believed was duty-free. Section 301 tariffs and exclusion processes have made classification and origin determinations commercially significant in a way they were not a decade ago.
Forced labor. Section 307 of the Tariff Act, 19 U.S.C. § 1307, prohibits importing merchandise made wholly or in part with forced labor, enforced through Withhold Release Orders and findings. The Uyghur Forced Labor Prevention Act creates a rebuttable presumption that goods made wholly or in part in the Xinjiang region, or by listed entities, are made with forced labor and are barred from entry. Rebutting the presumption requires clear and convincing evidence and complete supply chain traceability to the raw material — a documentation burden most supply chains cannot meet on short notice. Mapping tier-two and tier-three suppliers is the practical control.
Anti-money laundering. The Bank Secrecy Act regime reaches financial institutions, but its definitions capture money services businesses and, increasingly, other intermediaries. FinCEN's beneficial ownership reporting under the Corporate Transparency Act sits alongside it, and OFAC screening obligations are administered together with AML controls in most compliance programs.
Anti-boycott, again. The Treasury Department administers a separate antiboycott regime under 26 U.S.C. § 999, with its own quarterly reporting on IRS Form 5713 and tax consequences for participation — distinct from the Commerce regime discussed above. Companies frequently report to one agency and not the other.
Foreign investment. CFIUS review can reach a transaction involving critical technology precisely because the technology is export-controlled — the mandatory filing trigger for critical technology is defined by reference to export control licensing requirements.
The practical point. These regimes share facts: the same product classification, the same supplier map, the same counterparty data, and the same shipping documents. A company that builds the underlying data once — classifications, origin, supplier tiers, beneficial ownership — can serve all of them. A company that answers each regime separately, when it arrives, rebuilds the same information under deadline every time.
Related articles
- Business Immigration Basics — the deemed export overlay on hiring.
- The Foreign Corrupt Practices Act — the other cross-border compliance regime.
- The UCC Article 2 Sale of Goods — the underlying sales contracts.
- Distribution, Reseller, and Channel Partner Agreements — reexport and diversion controls in the channel.
- Cloud and SaaS Agreements — access controls and technology release.
- Responding to a Government Subpoena or Civil Investigative Demand — responding to an agency inquiry.
- Internal Investigation and Upjohn Warning Checklist — investigating before disclosing.
- IP Due Diligence Checklist for Mergers and Acquisitions — successor liability in a transaction.
- International Data Transfers After Schrems II — the parallel data-transfer regime.
- AI Vendor Procurement and Governance Checklist — controlled technology in AI supply chains.
This article is provided for general informational purposes and does not constitute legal advice. Sanctions programs, entity listings, and export control rules change frequently and without notice, and penalty amounts adjust annually. Consult qualified trade counsel before exporting, hiring for a role with access to controlled technology, or transacting with a party in a sanctioned jurisdiction.