For Chinese exporters and technology companies, the question is no longer whether the United States will impose export controls and sanctions risk on their operations, but how quickly the risk shifts. Between the expansion of the BIS Entity List and the implementation of the Affiliates Rule in 2025, the practical footprint of US export controls has grown far beyond the companies actually named. This article focuses on the preventive side of the problem: how a Chinese company that sells, ships or develops products with US content can build an Export Compliance Program (ECP) that meets the expectations of the Bureau of Industry and Security (BIS) and the Office of Foreign Assets Control (OFAC), and how the program should be structured when the company's customers, suppliers and employees cross multiple jurisdictions.
Attribution
Reviewed by Helen Yao, Beijing Yingke (Zhuhai) Law Firm. Advises Chinese companies on export-control and trade-sanctions compliance programmes (ECP), licence applications, entity-list themes and supply-chain de-risking across PRC, US and EU regimes. View directory profile →
Review tier: Reviewed by — accuracy review of drafts for orientation only. Content remains general information — not legal advice for a specific matter, and no attorney–client relationship is created by reading these pages.
Last reviewed: August 2026 · Related: Primary sources · Outbound decision hub.
The case for a written program: what the agencies expect
BIS publishes the Export Compliance Guidelines, including the Eight Elements of an Effective Export Compliance Program, which provide baseline guidance for drafting and maintaining an ECP. BIS defines an ECP as a series of procedures and tools that facilitate compliance with export controls, mitigate the risk of export violations and streamline compliance within an organization's operations. It is developed and maintained by organizations that engage in export, re-export or in-country transfer activities subject to the EAR.
- trade-and-customs-blog
- ECP PILLARS
- Item classification
- US/EU/China control lists
OFAC, for its part, published the Framework for Compliance Commitments, which sets out five components of a risk-based sanctions compliance program: management commitment, risk assessment, internal controls, testing and auditing, and training. The two frameworks are not identical, but they overlap substantially. A company that builds its program to satisfy both BIS and OFAC expectations will be in a stronger position during an audit or an enforcement review than a company that treats compliance as a single checklist.
Why the 2025 changes make an ECP more urgent for Chinese companies
On September 16, 2025, BIS added 32 entities to the Entity List across various jurisdictions, with a majority located in China. All of the additions carry a licence requirement for all items subject to the EAR, with little to no licence exceptions available and a general presumption of denial. On September 29, 2025, BIS implemented the Affiliates Rule under the EAR, which extends the export-control restrictions of a listed parent company to affiliates based on ownership stakes. Depending on the ownership analysis, a Chinese company that is not itself listed can nevertheless be treated as "constructively listed" because it is a subsidiary of, or is more than 50 percent owned by, a listed entity. Industry analyses have estimated that more than 20,000 Chinese subsidiaries and indirectly owned entities could fall under the same restrictions as their listed parents.
The consequence is a compliance environment in which a company's own screening, ownership documentation and counterparty due diligence are the primary line of defense. A written ECP is the mechanism that turns that defense into an auditable record.
Where an ECP for a Chinese company should start: classification
Every export or re-export begins with classification. A company must determine whether its products, software or technology are subject to the EAR, whether they fall under the Commerce Control List (CCL) and which ECCN applies, or whether they are EAR99. For items on the CCL, the company must either obtain a formal Commodity Classification Automated Tracking System (CCATS) determination from BIS or complete a documented self-classification. The classification decision drives everything downstream: licence requirements, licence exceptions, record-keeping and screening.
For technology companies, the more complex questions involve software and technology, including deemed exports. A "deemed export" occurs when controlled technology is released to a foreign national inside the United States. Chinese companies with US facilities, or US subsidiaries that employ Chinese nationals holding H-1B, L-1 or other visas, must assess whether the release of controlled technology to those employees requires a licence. The ECP should contain a clear procedure for identifying technology transfers, including deemed-export screening at the point of hiring and project assignment.
Building the ECP: the eight elements in practice
A BIS-aligned ECP manual covers eight elements: management commitment; risk assessment; screening of transactions and parties; classification and licensing; record-keeping; training; audits and corrective action; and communication with the agency. For a Chinese company, several of these elements need particular attention.
- Management commitment. The program must have visible support from senior leadership. OFAC and BIS both look for evidence that compliance is a board-level priority, not a function buried in the logistics department.
- Risk assessment. The risk profile should be documented: which products, destinations, customers and payment routes present exposure, and how the company has decided to address each.
- Screening and transaction controls. The program should cover restricted-party screening of customers, suppliers, intermediaries and beneficial owners against the OFAC SDN List, the BIS Entity List, the Unverified List (UVL), the Denied Persons List and the Department of State's Debarred Parties List. Screening should be automated where volume justifies it, with a documented process for resolving false positives and escalating true matches.
- Classification and licensing. The program should assign ownership for classification decisions, maintain a product matrix and a list of ECCNs, and document the basis for each self-classification.
- Record-keeping. The EAR requires records to be kept for five years. The ECP should define what is retained, where, and for how long, including licence applications, screening results and shipment documentation.
- Training. Training should be role-specific and repeated: engineering staff who work with controlled technology need different training from the sales team that quotes prices and the logistics team that books shipments.
- Audits and corrective action. The program should include a periodic audit cycle and a documented process for correcting weaknesses. BIS offers a free ECP review service for US organizations, which can be a useful benchmark, but a Chinese company should rely on its own counsel and auditors for the primary assessment.
- Communication and escalation. The ECP should name the person responsible for escalation when a red flag appears: an embargoed destination, an unusual routing, a suspicious end use or a designation that affects an existing customer.
- Charter ECP
- ['Independence and board mandate']
- Write procedures
- Class/screen/license
- Integrate ERP gates
Sanctions clauses and downstream controls
The ECP should also cover the contractual layer. Sanctions clauses in sales and supply contracts serve two purposes: they preserve the company's right to stop performance when a transaction becomes prohibited, and they document the company's compliance posture if a counterparty later asserts that the company should have performed despite the controls. For a Chinese company, this layer intersects with Chinese law: the Anti-Foreign Sanctions Law, the blocking measures and countermeasure rules may create obligations that conflict with a US sanctions clause. The ECP should include a procedure for escalating such conflicts to counsel rather than resolving them informally at the contract level.
Practical steps for the first ninety days
- Map the current product and technology portfolio and complete a baseline classification review, including CCATS determinations where formal guidance is needed.
- Document the ownership and control chain for every entity in the group, because the Affiliates Rule can reach subsidiaries that are not themselves listed.
- Stand up or re-validate restricted-party screening across customers, suppliers, intermediaries and beneficial owners, with a documented false-positive process.
- Identify technology transfers and deemed-export exposure, especially where foreign-national employees access controlled software or technical data.
- Draft the ECP manual around the BIS eight elements and the OFAC five components, assign owners, and set a training and audit calendar.
- Review contracts for sanctions and no-re-export clauses and align them with the program's escalation procedure.
An ECP is not a document that is written once and filed away. It is a living system that must be re-tested as the Entity List grows, as the Affiliates Rule is applied, and as new designations change the counterparty risk. Companies that invest in the system early, and keep the records current, convert compliance from a cost into a competitive advantage: they can ship faster, bank more easily and withstand agency scrutiny when it comes.
This article is for general information only and does not constitute legal advice. Export-control and sanctions rules change frequently; consult qualified counsel for the current state of the law.