Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

5 Actions Required for EAR Compliance: A Checklist for Research Offices

A practical, five-item checklist for what a university EAR compliance program actually needs in place: written policy, restricted-party screening, deemed-export access controls, training, and recordkeeping.

Most export control guidance for research institutions either explains the underlying regulations or describes how a compliance office is organized. This page does neither. It is a narrow, action-oriented checklist: the five concrete things a research office needs to have in place to run a defensible Export Administration Regulations (EAR) compliance program, independent of ITAR (which has its own registration and licensing regime — see CASRAI’s ITAR vs. EAR comparison) and independent of the deeper mechanics of classifying a specific item, which CASRAI’s ECCN lookup guide already covers in detail.

For the broader operational framework these five actions sit inside, see The Four Pillars of Export Control Compliance. That guide organizes a program around four exposure points — deemed exports/cybersecurity, international travel, foreign talent program disclosure, and training. This checklist is deliberately narrower: it is specific to EAR obligations and framed as five discrete, auditable actions rather than an organizing structure, so a compliance office can use it as a literal to-do list or self-assessment.

Why a checklist, not just the regulation

The EAR itself (15 CFR Parts 730-774) does not mandate that every institution maintain a formal, written export compliance program. But the Bureau of Industry and Security (BIS), which administers the EAR, publishes its own guidance identifying eight elements of an effective Export Compliance Program (ECP): management commitment, risk assessment, export authorization, recordkeeping, training, audits, handling violations and corrective action, and ongoing program maintenance. Universities rarely need all eight formalized the way a defense contractor would, but five of them map directly onto obligations a research office cannot skip without creating real exposure — either because a regulation directly requires it (recordkeeping) or because skipping it is what actually causes deemed-export and hand-carry violations in practice (screening, access control, training, and having a documented policy to point to when something goes wrong).

Action 1 — Adopt a written EAR compliance policy and name a responsible official

A written policy does two things a verbal understanding cannot: it gives every PI, lab manager, and international-programs staff member the same answer regardless of who they ask, and it gives the institution something to produce if BIS ever asks how a violation happened. At minimum, the policy should state:

  • Who in the institution has authority to make or approve export control determinations (a designated export control officer or compliance official, not “whoever the PI asks”).
  • What triggers a review — new international collaborators, equipment purchases with dual-use potential, shipping items abroad, hosting foreign visitors in a controlled-technology lab, or participating in a foreign talent recruitment program.
  • How the ECCN determination process and the Commerce Control List factor into a review, and when a matter needs to be escalated to the compliance office rather than resolved at the lab level.
  • What the fundamental research exclusion does and does not cover — a common source of false confidence, since publication intent alone does not exempt controlled equipment, software, or pre-publication technical data shared with foreign nationals.

This is the item most often missing entirely, not just informal. An institution with strong practices but no written policy has nothing to show an auditor, a new hire, or its own leadership when a question of “who decided this” comes up.

Action 2 — Screen people, destinations, and shipments before you engage them

EAR General Prohibitions bar transactions with parties on specific restricted lists and with knowledge of certain end-uses, which means screening has to happen before an interaction, not after. In practice this covers three overlapping populations a research office regularly deals with:

  • International collaborators and visiting scholars — screened against restricted-party lists before an invitation, appointment, or lab access is finalized.
  • Shipping destinations — screened for comprehensively sanctioned or embargoed countries before equipment, samples, or software leave the US. CASRAI’s embargoed countries list guide covers current OFAC comprehensive-sanctions programs in detail.
  • Vendors, subcontractors, and foreign subrecipients — screened the same way, since a match on a restricted list makes a transaction prohibited regardless of who initiated it.

The US government’s Consolidated Screening List (CSL), published by the Commerce Department at trade.gov, is the practical tool for this: it merges the Commerce/BIS Denied Persons, Entity, Unverified, and Military End-User Lists; the State Department’s AECA Debarred List; and Treasury/OFAC’s SDN List and related sanctions programs into a single searchable and API-accessible source, refreshed daily. A screening hit still has to be traced back to its source list to determine what it actually prohibits — the CSL is a lookup convenience, not itself a rule — but running the check before, rather than after, an interaction is the part that actually prevents a violation. Screening travel destinations and personal conduct abroad is covered separately in CASRAI’s foreign travel security policy guide.

Action 3 — Control access to controlled technology and technical data (deemed-export controls)

This is the action most exposure actually comes from, because it does not require anyone to cross a border. Under the deemed export rule (15 CFR 734.13(a)(2)), releasing controlled technology or source code to a foreign person inside the United States — in a lab meeting, over email, or by granting server or equipment access — is treated as an export to that person’s country of citizenship or permanent residency. A research office’s job here is not to re-litigate the rule (CASRAI’s ITAR and EAR and Four Pillars pages cover the rule itself) but to make sure two things exist operationally:

  • A completed classification — has the item, software, or technical data been assigned an ECCN, or determined to be EAR99 or otherwise not controlled — before lab access decisions are made, not after.
  • A Technology Control Plan (TCP) for any lab that has both controlled technology and foreign-national personnel, documenting exactly what is restricted, who has access, and how physical and electronic access (badge control, segregated network access, locked storage) is actually enforced day to day rather than just on paper.

Action 4 — Train the people who actually trigger EAR obligations

Most deemed-export and hand-carry violations don’t come from a deliberate transfer — they come from an ordinary lab conversation, an email attachment, or a piece of equipment packed for a conference, done by someone who didn’t know it implicated export control at all. Training has to reach beyond the compliance office to the people actually creating exposure: PIs and lab managers who supervise foreign-national staff, procurement and shipping staff who handle equipment leaving the country, and international-programs staff coordinating visiting scholars. CASRAI’s research security training guide covers which populations and formats different funder and institutional mandates require; export control training specifically should be role-based rather than a single generic module, since a shipping coordinator and a PI running a foreign-national lab encounter EAR in genuinely different ways.

Action 5 — Keep records for the required retention period, and self-audit

Unlike the previous four items, this one is a direct regulatory requirement, not just good practice. Under 15 CFR 762.6, records required to be kept under the EAR — export control documents, correspondence, classification determinations, license applications, and related memoranda — must be retained for five years from the latest of: the export itself, any known reexport or transfer of the item, the termination of the transaction, or (for boycott-related records) receipt of a boycott-related request. Records subject to a BIS or other agency request cannot be destroyed without written authorization, even after the five-year period would otherwise have run.

In practice, this means a research office needs somewhere durable — not a departing employee’s inbox — to keep classification determinations, screening results, TCPs, and license records, plus a periodic self-audit to confirm the other four actions are actually happening as documented, not just written down once and forgotten. BIS’s own ECP guidance lists audits and corrective action as separate elements from recordkeeping for exactly this reason: keeping records and actually reviewing them for gaps are different disciplines.

How this checklist relates to CASRAI’s other export control pages

Frequently asked questions

Is a written export compliance program legally required under the EAR?

Not as a blanket requirement in the regulatory text itself, but BIS strongly recommends one through its published Export Compliance Program guidelines, and having one is frequently treated as a mitigating factor if a violation is later investigated. Some license conditions also require the recipient to maintain a compliance program as a condition of the license.

How is deemed-export screening different from restricted-party screening?

Restricted-party screening (Action 2) checks whether a specific person, organization, or destination appears on a government list before an interaction happens. Deemed-export access control (Action 3) is a separate, ongoing question about who inside the institution — regardless of whether they’re on any list — can access already-controlled technology or technical data without that access itself constituting an export.

Does the fundamental research exclusion remove the need for these five actions?

No. The fundamental research exclusion can remove certain published, basic, non-proprietary research results from EAR licensing requirements, but it does not exempt controlled equipment, software, or pre-publication technical data, and it does not apply automatically — an institution still has to determine that a given project qualifies. Screening, access control, and recordkeeping obligations apply independently of whether a project’s eventual output will be publishable.

How long do EAR compliance records need to be kept?

Five years from the latest of the export itself, any known reexport or transfer, or the termination of the transaction, per 15 CFR 762.6 — see Action 5 above.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →