# Export-Control List Monitoring: Track BIS Entity List, Denied Persons, and Unverified List Changes

Source: PageCrawl.io Blog
URL: https://pagecrawl.io/blog/bis-entity-list-export-control-monitoring

---

At 9:14 a.m. on a Tuesday, a trade-compliance analyst at a mid-sized electronics distributor clicked "release" on a $480,000 order of signal-processing chips bound for an overseas reseller. The customer had cleared screening at the quote stage three weeks earlier, and nothing in the order management system had flagged it. What the analyst did not know was that the previous Friday, a final rule in the Federal Register had added the reseller's parent company to the BIS Entity List with a license requirement and a presumption of denial. The pallet left the dock that afternoon. The violation surfaced during an internal audit forty days later, and it turned into a voluntary self-disclosure, outside counsel, and a six-figure remediation bill that no one had budgeted for.

The painful part is that the information was public the whole time. The Bureau of Industry and Security (BIS), the export-control arm of the U.S. Department of Commerce, publishes every Entity List change as a final rule, and the new party appeared on the public list pages within hours. The gap was not access to the data. The gap was that nobody was watching the data between the day the order was screened and the day it shipped. Screening once, at quote time, is a snapshot of a target that moves constantly.

Export-control lists run under the Export Administration Regulations (EAR), a separate regulatory regime from Treasury's sanctions programs, and they change on their own schedule. This guide covers which BIS and Commerce lists to monitor, why export control is a distinct compliance target from OFAC sanctions, what the 2024 cross-listing trend and the late-2025 Affiliates Rule changed, and exactly how to set up continuous monitoring so your team re-screens open orders the moment a list moves.

<iframe src="/tools/bis-entity-list-export-control-monitoring.html" style="width: 100%; height: 500px; border: none; border-radius: 4px;" loading="lazy"></iframe>

### What is the BIS Entity List and why does it need monitoring?

The BIS Entity List, codified as Supplement No. 4 to Part 744 of the EAR, names foreign companies, institutions, and individuals that threaten U.S. national security or foreign-policy interests. Exporting specified items to a listed party requires a BIS license, usually reviewed under a presumption of denial, so a single addition can instantly make a routine shipment illegal.

The list is not static. BIS adds, modifies, and removes parties throughout the year, and each action takes effect as a final rule. A "modification" can change the license requirement, the items covered, or the aliases and addresses tied to an entry, which means a party you screened last month may carry different restrictions today even if the name looks familiar. Because the legal consequence attaches the instant the rule is effective, the practical compliance question is not "did we screen this customer" but "have we re-screened every open order against the version of the list that is live right now." That is fundamentally a regulatory change management problem, and continuous monitoring is what solves it.

<picture>
<source srcset="/images/blog/previews/bis-entity-list-export-control-monitoring.webp" type="image/webp">
[Image: Screenshot of bis.doc.gov in a browser window, an example of a page PageCrawl can monitor for changes]
</picture>
bis.doc.gov under watch: PageCrawl archives every version and highlights the differences.

### How is BIS export-control screening different from OFAC sanctions?

BIS export-control screening and OFAC sanctions screening run under different agencies, laws, and prohibitions, so treating them as one list is a compliance mistake. OFAC, part of Treasury, administers blocking sanctions against parties on the Specially Designated Nationals (SDN) list, freezing assets. BIS, part of Commerce, controls export of goods, software, and technology to listed parties.

The distinction matters operationally. An OFAC SDN designation generally blocks the relationship entirely. A BIS Entity List entry, by contrast, is item-specific and license-driven: the same foreign customer might be perfectly fine to sell office furniture to and prohibited to sell controlled semiconductors to without a license. The [OFAC and EU sanctions list changes](/blog/ofac-eu-sanctions-list-change-alerts) post covers the Treasury and EU side of this picture, and you genuinely need both. A trade-compliance program that watches only sanctions lists will miss every Commerce export-control action, and vice versa.

#### The lists BIS and Commerce maintain

Four primary lists sit under the export-control regime, and a fifth source aggregates them with the sanctions lists:

| List | Source | What it restricts |
|------|--------|-------------------|
| Entity List | BIS (Supp. No. 4, Part 744) | License required for specified items, often presumption of denial |
| Denied Persons List | BIS | Individuals and firms stripped of export privileges entirely |
| Unverified List | BIS (Supp. No. 6, Part 744) | Parties whose bona fides could not be verified; license exceptions suspended, UVL statement required |
| Military End-User List | BIS (Supp. No. 7, Part 744) | Named military end users in covered countries |
| Consolidated Screening List | ITA / trade.gov | Combines BIS lists plus OFAC SDN and State Department debarred parties |

### Which BIS and Commerce lists should you monitor?

You should monitor all four BIS-administered lists directly plus the Consolidated Screening List, because each catches a different category of risk and a party can appear on one without the others. Watching only the Entity List, the most famous of them, leaves the Denied Persons, Unverified, and Military End-User lists as blind spots.

The Denied Persons List is the most severe in one sense: a denied party has lost export privileges outright, so even items that are otherwise uncontrolled can be off-limits. The Unverified List is subtler. A UVL addition does not prohibit the transaction, but it suspends license exceptions and requires you to obtain a signed UVL statement before shipping, and it is widely treated as a red flag that may precede an Entity List action. The Military End-User List ties restrictions to named parties in covered countries. The Consolidated Screening List, published by the International Trade Administration at trade.gov, merges the BIS lists with OFAC and State Department designations into a single feed with a public search API, which makes it ideal for automated field-level monitoring alongside the human-readable agency pages. If you already run a broader [regulatory website monitoring](/blog/track-multiple-regulatory-websites) program, these list pages slot in as high-priority sources.

### What changed with the 2024 cross-listing trend and the 2025 Affiliates Rule?

Two recent developments raised the stakes: the 2024 acceleration of joint BIS and OFAC actions, where one party increasingly lands on both the Entity List and the SDN list, and the late-September 2025 Affiliates Rule, which extends Entity List and Military End-User restrictions to entities owned 50 percent or more by listed parties.

Both developments expand the restricted universe faster than periodic review can track. The cross-listing trend means a change on one agency's list is now a leading indicator for the other. When BIS and OFAC coordinate a designation, the Federal Register rule and the SDN update often land within days of each other, so a team watching only one side gets a partial picture and a delayed one. The Affiliates Rule, sometimes called the BIS 50 percent rule by analogy to OFAC's long-standing 50 Percent Rule, is the bigger structural shift. It means that screening the named entity is no longer enough. A subsidiary or affiliate that is majority-owned by a listed party is now itself restricted even though its own name never appears in any Federal Register rule. That pushes compliance teams toward continuous ownership-aware re-screening rather than name-match checks, and it makes catching every list change promptly far more important, because each new listing can silently sweep in a web of affiliates you sell to.

### How do Federal Register additions feed the export-control lists?

Every change to the Entity List, Denied Persons List, Unverified List, and Military End-User List is published as a final rule in the Federal Register, which is the authoritative legal record and usually the earliest public signal. The agency list pages are then updated to reflect the rule, and the Consolidated Screening List feed picks up the change shortly after.

This creates two distinct monitoring surfaces that work together. The Federal Register rule is the primary, legally operative source: it states the effective date, the parties added or modified, and the precise license requirements, and it appears before some downstream systems catch up. The list pages and the Consolidated Screening List are the operational sources your screening workflow actually checks orders against. Watching both means you see the rule as it publishes (the early warning) and confirm when the live list your team screens against has actually been updated (the trigger to re-screen). Teams that already monitor [Federal Register rulemaking and comment deadlines](/blog/federal-register-rulemaking-comment-deadline-monitoring) can extend the same approach to capture export-control final rules the moment they post. The same logic applies to adjacent Commerce actions such as [Section 232 tariff and HTS changes](/blog/section-232-tariff-hts-2026-change-monitoring), which often move in the same policy cycle.

### What does a missed Entity List update actually cost?

A missed export-control change is among the most expensive compliance failures a company can have, because penalties scale with the transaction and the conduct, not the size of the oversight. Under the EAR and the Export Control Reform Act, civil penalties can reach the greater of $350,000 per violation or twice the transaction value, and criminal cases add prison time.

Those criminal violations carry fines up to $1 million per count and up to 20 years of imprisonment, and the civil figure is inflation-adjusted every year, so the ceilings only climb. The direct penalty is only part of the cost. A violation typically triggers a voluntary self-disclosure decision, outside trade counsel, an internal audit to scope how many other shipments were affected, and potentially a denial of export privileges or a temporary denial order that can halt a company's ability to ship at all. There is reputational exposure too, since BIS publishes enforcement actions. Set against that, the cost of monitoring the relevant list pages continuously is trivial. It is the controlled-export equivalent of knowing your counterparty's status changed before you act on the old status.

### How do you set up BIS export-control list monitoring with PageCrawl?

You set it up by pointing PageCrawl at each list page and its Federal Register source, choosing the right tracking mode for each one, and routing alerts straight into the channel your compliance team already watches. The goal is a re-screen trigger that fires within minutes of a list moving, not a quarterly manual review. Here is a six-step setup.

[Image: PageCrawl change diff for BIS Entity List - Supplement No. 4 to Part 744, highlighting the added and removed text]

**Step 1: Add the source pages as monitors.** Create one monitor for each list you screen against: the Entity List page, the Denied Persons List, the Unverified List, the Military End-User List, and the Consolidated Screening List. Add a separate monitor for the Federal Register search results filtered to BIS export-administration rules so you catch the legal source as it publishes. PageCrawl renders each page fully, including pages that load their content dynamically, so the list data is captured reliably even on government sites that build the table client-side.

**Step 2: Choose the right tracking mode per source.** For the human-readable agency list pages, use fullpage content tracking so any addition, removal, or modification to the entries registers as a change. For the Consolidated Screening List, which exposes a structured search API, use [JSON and API field tracking with path filters](/blog/monitor-json-api-field-jsonpath-jq-filters) to watch a specific result count or party record without noise from unrelated fields. For the Federal Register feed, combine fullpage tracking with [keyword and text matching](/blog/conditional-alerts-price-keyword-threshold-rules) on terms like "Entity List," "Supplement No. 4," and your highest-risk customer names so a relevant rule jumps the queue.

**Step 3: Set check frequency to match the risk.** Export-control lists can change any business day, so set the agency list pages and the Federal Register feed to check every 5 to 15 minutes during business hours. The faster the interval, the shorter the window between a list moving and your team being told, and that window is exactly where the opening anecdote's shipment slipped through.

**Step 4: Route alerts to where your team works.** Send notifications to the channel your compliance desk actually monitors. Many teams use a dedicated [Slack alert channel](/blog/website-change-alerts-slack) so a list change lands in front of the whole desk at once. PageCrawl also supports Telegram, Discord, email, and [webhook automation](/blog/webhook-automation-website-changes) so you can push the change directly into your order-management or screening system to auto-flag open orders for that counterparty.

**Step 5: Keep screenshots on for the evidence trail.** New monitors capture screenshots by default, and you should leave that on. A timestamped before-and-after image of the list page is contemporaneous evidence of exactly when an entry appeared and what it said, which is invaluable if you ever have to reconstruct the timeline for a self-disclosure or an auditor.

**Step 6: Tune thresholds and conditions to cut noise.** Use conditional and threshold rules so cosmetic page edits (a footer date, a banner) do not page the on-call analyst, while any change inside the actual list table or any match on a watched party name does. Tying alerts to meaningful content rather than raw page diffs keeps the signal high and the false positives low, which is what keeps the team trusting the alerts.

### How often should you check, and what should trigger a re-screen?

You should check the agency list pages and the Federal Register feed every few minutes during business hours, and treat any change inside a list table or any keyword match on a watched party as an automatic trigger to re-screen open orders and holds for that counterparty. The re-screen, not just the alert, is the control that prevents the shipment.

In practice, build the workflow as a loop. The monitor detects a change and fires the alert. The alert, ideally via webhook, flags every open order tied to the affected party or its affiliates for hold and review. An analyst confirms the new license requirement against the Federal Register rule, documents the decision with the captured screenshot, and releases or blocks accordingly. Because the 2025 Affiliates Rule sweeps in majority-owned subsidiaries that never appear by name, the re-screen step should check ownership relationships, not just exact-name matches. Pairing list-change monitoring with this disciplined re-screen turns a pile of public data into an actual control, the same way a mature [regulatory intelligence](/blog/what-is-regulatory-intelligence-monitoring) program turns horizon-scanning into decisions rather than reading.

### Choosing your PageCrawl plan

PageCrawl's **Free plan** lets you monitor **6 pages** with **220 checks per month**, which is enough to validate the approach on your most critical pages. Most teams graduate to a paid plan once they see the value.

| Plan | Price | Pages | Checks / month | Frequency |
|------|-------|-------|----------------|-----------|
| Free | $0 | 6 | 220 | every 60 min |
| Standard | $8/mo or $80/yr | 100 | 15,000 | every 15 min |
| Enterprise | $30/mo or $300/yr | 500 | 100,000 | every 5 min |
| Ultimate | $99/mo or $999/yr | 1,000 | 100,000 | every 2 min |

Annual billing saves two months across every paid tier. Enterprise and Ultimate scale up to 100x if you need thousands of pages or multi-team access.

### How do you get started with export-control monitoring?

Start with the Free plan and point it at four sources: the Entity List, the Denied Persons List, the Unverified List, and a BIS-filtered Federal Register feed. Wire the alerts into your team's Slack or screening system, then add the Military End-User and Consolidated Screening List monitors as your program grows.

Export-control lists move on a schedule no one controls, and the difference between a clean shipment and a six-figure self-disclosure is often a few hours of awareness. The setup takes an afternoon, and from that point on the lists watch themselves while your analysts spend their time on the orders that actually need a decision. Build the loop once, and never ship against a stale list again.

---

Need more? The complete PageCrawl.io help center, with every article, is available as a single document at https://pagecrawl.io/llms-full.txt. Read it for context on anything this page does not cover.
