Podcasts
Watch videos featuring supply chain experts
For thirty years, restricted-party screening in U.S. export controls was, at heart, a spelling problem. A shipment cleared or it did not clear based on whether a counterparty's name matched one of roughly a dozen government lists. The Bureau of Industry and Security has now redefined the problem. Under the Affiliates Rule, published as an interim final rule on September 29, 2025, restrictions extend automatically to any foreign entity owned 50 percent or more, directly or indirectly, individually or in aggregate, by one or more parties on the Entity List, the Military End-User List. In plain terms: a company can now be fully restricted without ever being named. The old “legally distinct” standard, under which an unlisted subsidiary of a listed parent could still be a lawful customer, is gone. What remains is a strict liability regime, aligned at last with the ownership look-through logic OFAC has applied to financial sanctions since 2014.
The regulatory clock is unambiguous. Faced with industry pushback, BIS suspended the rule on November 10, 2025 and, per the Federal Register, will reimpose its license requirements on November 10, 2026. The suspension is not a reprieve. It is a construction window, and it is closing.

Legacy screening architecture does one thing very well: it fuzzy-matches a counterparty name against the U.S. Consolidated Screening List. Under the old regime, that was enough, because the list was, in principle, the universe of restricted parties. The Affiliates Rule breaks that equivalence, and it does so in three distinct ways that a name-matching engine cannot recover from.
The first is the aggregation of minority stakes. If an Entity List party holds 25 percent of a Malaysian distributor and a Military End-User List party holds another 25 percent, the distributor is captured at exactly 50 percent, even though neither restricted name appears on the invoice, the purchase order, or the bill of lading. At the string level, the transaction is clean. The violation exists only at the graph level, where two separate ownership edges meet.
The second is cumulative indirect control. BIS applies the look-through down chains of majority ownership. In the example BIS itself uses in its guidance, if a listed Party A owns 50 percent of Company B, and B owns 50 percent of Company C, then C is restricted even though A's indirect economic interest in C is only 25 percent. Route those layers through a Hong Kong holding company, a British Virgin Islands special-purpose vehicle, and a Cayman fund, and the restricted party sits three to five hops away from the counterparty on the export declaration. Flat, list-shaped databases cannot traverse hops. Only a corporate-tree data model can.
The third is a data problem the government has not solved. Washington publishes the trigger lists for free. It does not publish the ownership data needed to apply them. Shareholder information sits in dozens of national registries with wildly inconsistent disclosure standards, and several favoured holding jurisdictions maintain no public register of beneficial owners at all. Compliance teams are being asked to join a public dataset of names against a private, fragmented, multilingual dataset of equity relationships. That join is precisely what static screening tools were never built to perform, which is why BIS's own guidance warns that even a significant minority stake, well below the 50 percent line, is now a red flag that must be actively resolved.

The scale of the problem is no longer theoretical; it is measurable from public sources. The Entity List and MEU List together name more than 3,000 entities. But independent analyses of the rule's ownership mechanics converge on a much larger effective universe. Corporate-graph research firm WireScreen, applying the 50 percent test to its ownership data as of October 18, 2025, found that roughly 1,300 China-related parties named on the Entity List translate into more than 20,000 Chinese subsidiaries and indirectly owned entities captured under the Affiliates Rule, a more than fifteenfold expansion in a single jurisdiction.

Two independent triangulation points support the same conclusion. Law firm Mayer Brown estimates that the combined restricted universe has grown “well into the tens of thousands” once affiliates are counted, spanning not only China and Russia but also the EU, UK, Japan, Switzerland, and India. And risk-analytics firm Kharon, in a pre-rule study published in June 2025, found that a 50 percent standard would immediately cover thousands of subsidiaries, few of which appear on any government screening list. BIS itself conceded the point in the rule's rollout: the Consolidated Screening List will no longer be an exhaustive listing of parties subject to Entity List license requirements. That single sentence is the formal death certificate of static screening.
The arithmetic implication is stark. If the China multiplier alone is roughly 15x, a screening program whose coverage is defined by the named lists is, by construction, blind to more than nine out of every ten entities the rule actually restricts. No tuning of fuzzy-match thresholds closes a gap of that shape, because the missing entities are not misspellings of listed names; they are different names entirely, connected only by equity.
Before turning to what a properly built compliance function looks like, it is worth pausing on the growth curve of the list itself, because that curve tells its own story about where this is going. From the end of 2019 to the end of 2025, the Entity List more than doubled in size, with BIS publishing addition rules at a pace that averaged one every thirty-five days across the 2018 to 2024 window. The growth was not gradual and uniform. It surged with the Huawei-era designations in 2019, jumped again with Russia-linked additions after February 2022, and continued through 2024 with a broadening focus on semiconductor, quantum, and drone-supply networks.

The line ends where the Affiliates Rule begins. Everything to the left of September 2025 is a story about a growing but still enumerable list. Everything to the right is a story about a list that stopped being the answer to the question “who are we restricted from shipping to?” The dashed extension in the chart is the honest picture of what changed on September 29, 2025: the named universe did not stop growing, but the effective universe stepped up by roughly an order of magnitude. Any compliance program still measuring itself against the solid line is measuring the wrong thing.
The paradigm shift did not happen without warning. In the eighteen months before the Affiliates Rule was published, two of the largest export-control settlements in recent memory made the case, in advance, that name-based screening was no longer sufficient. Both companies had compliance programs. Both had screening tools. Both wrote very large checks. Cadence Design Systems, July 2025. Cadence settled with BIS for $95.3 million and, in a parallel resolution with the U.S. Department of Justice, agreed to a guilty plea and further payments that brought total civil and criminal exposure to more than $140 million. The BIS settlement admitted to 56 violations of the EAR. The underlying facts read like a textbook demonstration of why list matching fails. Cadence's Chinese subsidiary, Cadence Design Systems Management (Shanghai), sold Electronic Design Automation software and semiconductor design tools between 2015 and 2021 to the National University of Defense Technology (NUDT), a PRC military university on the Entity List, through a front company called Central South CAD Center (CSCC). When Cadence eventually connected CSCC to NUDT and froze the account, its Chinese employees assigned the same contracts to Tianjin Phytium Information Technology, another Entity List party linked to NUDT through overlapping personnel. Employees deliberately referred to NUDT in Chinese only and stripped references to the PRC military from internal correspondence to evade detection. Screening flagged the front company by name, exactly as designed. What it could not do was follow the personnel graph and the corporate substitution that immediately came next.
Robert Bosch GmbH, June 2026: Bosch agreed to pay a BIS civil penalty of $36.2 million and, with parallel DOJ disgorgement, faced total exposure of roughly $40 million for exporting approximately $72 million of MEMS sensors and automotive software to Huawei between September 2020 and September 2024. Huawei has been on the Entity List since May 2019. Bosch's two German subsidiaries, BST and ETAS, believed they were shipping foreign manufactured goods that fell outside U.S. jurisdiction. They were wrong: the Foreign Direct Product Rules (FDPR) captured the items because U.S.-origin technology sat somewhere upstream in the production chain. One hundred and nine violations accumulated over four years without triggering the company's internal compliance systems. Bosch's remediation is the sentence that should be circled by every compliance leader reading this piece: the company added sixty-six employees to its trade compliance organization and expanded its export control screening tools. That is roughly one new compliance FTE per two months of missed violations, an emergency staffing pattern nobody should aspire to run.
The structural answer is not a better list, and it is not more analysts. It is a change in where compliance logic lives. The screening step has to move out of the front-door queue at order entry and into the transactional data layer itself, so that every counterparty record carries a continuously refreshed ownership graph rather than a one-time screening timestamp. This is what modern Global Trade Management platforms are being rebuilt to do: embed ownership intelligence directly into ERP master data, bill of lading feeds, and HS code flows, so that the ownership question is answered before an order is ever cut, not after. Three capabilities separate a genuine shield from a rebranded list-checker. Each of them addresses a specific way the Affiliates Rule can hurt a company that has not prepared, and each is worth understanding in plain terms.
First, the Rule of Most Restrictiveness, which is simpler than it sounds. When a single company is co-owned by parties sitting on different U.S. restriction lists, say, one owner on the Entity List and another on the Military End-User List, the system must treat the shipment as if it faced the strictest set of rules that applies to any of those owners, not the mildest. In practice, this often means the tighter Foreign-Direct Product Rules (FDPR) requirements travel with the shipment even for foreign-made goods. Choosing the softer path because it lets an order move today is not a shortcut. Under strict liability, it is a violation waiting to be found.
Second, automatic Red Flag 29 handling. Red Flag 29 is BIS's way of saying: if you cannot figure out how much of a foreign company is actually owned by listed parties, you are required to assume the worst, that the 50 percent line has been crossed, and stop the transaction until either the ownership is resolved or a BIS license is obtained. A properly built GTM engine should do this at the moment an order is entered or a booking is made, right inside the ERP, not weeks later in a compliance review after the goods have already left the warehouse.
Third, an immutable digital audit trail. Because the Affiliates Rule is enforced on a strict liability basis, “we did not know” is not a defense. What actually reduces penalties, if BIS ever comes asking, is proof: proof of what ownership data the company had, when it had it, what the system concluded, and how the transaction was handled. A tamper-proof, system-generated record of every ownership check, every hold, and every override is the single most persuasive document a company can produce, and the only one that can be produced fast enough to matter.
The organizations that will clear November 10, 2026 comfortably are already migrating from static list screening to dynamic data orchestration: continuous ownership monitoring, event-driven re-screening when equity moves upstream, and license-determination logic wired into the order-to-cash cycle. They are treating the suspension window for what it is, a runway, not a pause. Everyone else will meet the Affiliates Rule the way companies usually meet paradigm shifts they underestimated, through a voluntary self-disclosure.
The most dangerous customer under the Affiliates Rule is not the one you refuse. It is the one you approve. That inversion is the whole story, and it is why I think the industry conversation about “screening upgrades” is mispriced. For thirty years, the compliance failure mode was a false positive: a legitimate buyer flagged, a shipment delayed, a customer lost. Under strict liability with aggregated ownership, the failure mode flips. The costly mistake is now the false negative, the invisible affiliate that passes every check the system knows how to run, right up to the moment it does not. Every clean screening record between now and November 10, 2026 is, statistically, mostly noise. The one that is wrong is what counts. Something quieter is also happening inside the compliance function itself. For decades, the strongest voice in the room belonged to whoever managed the screening list. After November 10, it will belong to whoever owns the ownership graph, the same shift the finance function went through when anti-money-laundering work moved from checklists to networks. That is a re-org, not a software purchase, and most companies have not yet noticed they are in one. The last thing worth saying is the one that matters most. The Affiliates Rule rewards asymmetric preparation. Companies that arrive at November 10 with a working ownership graph will not just be compliant; they will know things about their own supply chain that their peers do not, which distributors are quietly captured, which vendors changed hands last quarter, where the ghosts actually live. Compliance infrastructure, done well, becomes intelligence infrastructure. That is a much larger prize than avoiding a fine, and it is why the leading trade operations are moving now, not later.