Blog · Sanctions screening

What is the BIS Entity List,
and how does it fit into screening?

The Bureau of Industry and Security doesn't maintain just one restricted party list, it maintains several, and each one is a watchlist a sanctions screening program needs to check counterparties against. This guide explains what these lists are, who ends up on them, and how to screen against them properly.

6 min read · Sanctions screening basics

What the BIS lists actually are

The Bureau of Industry and Security, BIS, sits inside the US Department of Commerce. Alongside OFAC and the other agencies that maintain restricted-party lists, BIS publishes several of its own: the Entity List, the Denied Persons List, the Unverified List, and the Military End User List. Each is a distinct watchlist, and each is a standard part of the group of lists a sanctions screening program checks counterparties against.

BIS does not fold these into a single list. Screening against "BIS" is not one check, it is several, and a counterparty can be clear on one list and still appear on another. That distinction is the single most important thing to understand about how these lists fit into a screening program.

Why the distinction between lists matters

ListWhat a match typically signals
Entity ListThe party has been flagged for activity BIS considers a national security or foreign policy concern.
Denied Persons ListThe party's standing with US authorities has been revoked outright; this is the most severe of the four lists.
Unverified ListBIS was unable to confirm the party's legitimacy or identity, a lower-severity flag but still one worth investigating.
Military End User ListThe party has been tied to a country's military, security, or intelligence services.

Doing business with a party on any of these lists carries real legal exposure, and the severity varies by list and by the specific listing. Getting the screening wrong is rarely a one-time, contained mistake; it tends to surface only after a pattern of transactions has already built up.

Who ends up on these lists

Entity List additions are typically tied to activity BIS considers contrary to US national security or foreign policy interests, including supporting weapons proliferation, diverting controlled technology, or acting on behalf of an already-restricted party. The other three lists follow their own criteria, but the underlying theme is consistent: BIS has identified the party as a heightened risk to screen for before doing business with it.

  • Companies and research institutes flagged for proliferation or diversion risk.
  • Foreign government entities and state-owned enterprises in specific sectors.
  • Parties added to the Military End User List for supplying or supporting a country's military, security, or intelligence services.
  • Parties on the Unverified List simply because BIS could not complete an identity or legitimacy check, which does not necessarily imply wrongdoing on its own.

How screening against these lists works in practice

A workable screening process checks a counterparty against all four BIS lists together, not just the Entity List, since a clean Entity List result says nothing about Denied Persons or Unverified List status. As with other watchlists, matching needs to go beyond exact name comparison: aliases, transliteration differences, and partial name overlaps are common, and a rigid exact-match check will miss real hits or bury them under noise.

These lists are also updated on their own schedule, independent of OFAC, the EU, or the UN. A screening program needs to check them on an ongoing basis, and ideally extend that check past the immediate counterparty to known intermediaries where that information is available, since risk often shows up a step or two removed from the party named on a transaction.

Common mistakes

01

Treating "BIS lists" as one list

A party can be clear on the Entity List and still be on the Denied Persons or Unverified List. Screening only one is not a complete check.

02

Screening once and not re-checking

These lists change on their own schedule. A counterparty that screened clean at onboarding is not guaranteed to still be clear months later.

03

Relying on exact name matches alone

Aliases and transliteration differences are common across these lists, the same as with OFAC's SDN List. A rigid exact-match check misses real hits.

Getting started

  • Screen against all four BIS lists together, on every new counterparty and on an ongoing basis afterward.
  • Use fuzzy name matching rather than exact string comparison to catch aliases and transliteration variants.
  • Extend screening to known intermediaries where that information is available, not just the named counterparty.
  • Keep a record of every screening result and how any hit was reviewed, so it can be explained later if questioned.

Most problems with these lists trace back to a screening check that stopped at one list, or one that only ran once instead of continuously.

Next step

See every counterparty
checked automatically against every list.

Enthron screens counterparties against the BIS Entity List, Denied Persons List, Unverified List, and Military End User List alongside OFAC, EU, UK, and UN watchlists, continuously and in one place.