TRAFEED

[2026 Edition] Customer Due Diligence (End-User Screening) in Practice — How to Cross-Reference the Foreign User List and Entity List

Published2026-01-23Updated2026-07-07Ryuta Hamamoto

How to conduct customer due diligence (end-user screening) in export control. Covers practical use of Japan's Foreign User List, the U.S. Entity List, and the Consolidated Screening List, with step-by-step workflows.

[2026 Edition] Customer Due Diligence (End-User Screening) in Practice — How to Cross-Reference the Foreign User List and Entity List
Share

[2026 Edition] Customer Due Diligence (End-User Screening) in Practice — How to Cross-Reference the Foreign User List and Entity List

This is Hamamoto from TIMEWELL.

"Can we really trust this counterparty?"

When conducting international business, the reliability of your counterparties is critically important. In export control in particular, you have an obligation to verify that counterparties are not organizations involved in the development of weapons of mass destruction or military institutions.

Failing to carry out this verification creates risk of violating Japan's Foreign Exchange Act — and "I didn't know" will not be accepted as a defense.

This article explains the specific methods for customer due diligence (end-user screening / customer screening) in practical terms, including how to use Japan's Foreign User List and the U.S. Entity List.

Put your list-checking routine into a written, fill-in procedure: The lists discussed here — Japan's Foreign End User List, the US Entity List, the SDN and the rest — organized as five systems (US OFAC, US BIS, the EU, the UK, the UN) plus Japan's list, with fields for which official source to check, how often, and against what. The 50% / ownership-control tests and Red Flags are included, so you can fix a routine that currently varies by person into an internal standard. → Download the Five Sanctions-List Systems Screening Procedure (2026) (Free. Registration with your company name and work email address is required.)


If you are reviewing export-control operations or classification workflows, download the TRAFEED product catalog (PDF) or contact us.

Summary (What You'll Learn from This Article)

  • Obligation to conduct customer due diligence: Exporters are required to verify intended end-use and end-user
  • Foreign User List: METI's list of organizations of concern (748 entities)
  • Entity List: The U.S. BIS-managed list of export-restricted parties
  • How to conduct investigations: Combining list cross-referencing, web research, and direct verification
  • The scale of the task: Cross-referencing multiple lists, multilingual handling — a massive workload

How to Check the Entity List Right Now (the Short Answer First)

If you came to this article looking for where to find the latest version of the Entity List, here is the answer up front. As of July 2026, the current Entity List can be checked free of charge on official U.S. government sites.

Where to check Location When to use it
Consolidated Screening List (CSL) trade.gov/consolidated-screening-list Cross-searches the Entity List and other major U.S. restricted-party lists at once. In practice, start here
BIS official site bis.gov The agency that administers the Entity List. Amendment notices and guidance can be traced from here
Legal source text eCFR, Supplement No. 4 to Part 744 of the EAR The authoritative version. Consult it whenever a CSL search result leaves any doubt

That said, searching counterparties one by one on official sites has real limits. The Entity List is updated on a rolling basis, and you also need to track name variations — abbreviations, local-language names — plus subsidiaries and affiliates. How to automate this manual work is covered in the second half of this article.


Table of Contents

  1. What Is Customer Due Diligence (End-User Screening)?
  2. Why Is Customer Due Diligence Necessary?
  3. How to Use the Foreign User List
  4. The U.S. Entity List and Consolidated Screening List
  5. Step-by-Step Customer Due Diligence Process
  6. How to Identify Suspicious Transactions (Red Flags)
  7. How to Streamline Customer Due Diligence with AI

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

What Is Customer Due Diligence (End-User Screening)?

Definition

Customer due diligence (end-user screening) is the process of verifying the intended end-use and end-user of exported goods or provided technology, and reviewing whether any national security concerns exist.

In English this is also called "Customer Due Diligence," "End-User Screening," or "Customer Screening."

Three Elements to Verify

Customer due diligence involves verifying three elements:

Element What to verify
End-Use What the exported item will be used for
End-User The organization or individual who will actually use it
Intermediary Trading companies or agents in the transaction chain

Where Customer Due Diligence Fits in Export Control

Customer due diligence occupies the following position in the export control process:

[Step 1] Export Classification (List Control Check)
    ↓
[Step 2] Customer Due Diligence (End-Use and End-User Verification) ← Here
    ↓
[Step 3] Determining Whether a License Application Is Required
    ↓
[Step 4] Export and Shipment Control

Why Is Customer Due Diligence Necessary?

Japan's Foreign Exchange and Foreign Trade Act (FEFTA) imposes a duty to verify intended use and end-user on exporters.

Under catch-all controls in particular, a license application is required in two cases:

Requirement Content
Objective requirement (Inform) When notified by the Minister of Economy, Trade and Industry
Subjective requirement (Catch) When the exporter itself becomes aware of a concern

In other words, "I didn't know" is not a defense. Failing to investigate what you should have investigated is itself a problem.

Risks if Violated

Exporting to a party of concern without conducting proper due diligence creates the following risks:

Risk Content
Criminal penalties Up to 10 years imprisonment, fines up to 1 billion yen (for corporations)
Administrative sanctions Export ban for up to 3 years, public disclosure of company name
Reputational damage Collapse of social credibility
Transaction termination Major business partners terminating transactions

Liability Even for Negligence

FEFTA violations are subject to administrative sanctions even when they result from negligence. "I trusted the counterparty" or "I had no means to check" are not valid defenses.


How to Use the Foreign User List

What Is the Foreign User List?

The Foreign User List is a list published by Japan's Ministry of Economy, Trade and Industry (METI) identifying "overseas entities where concerns about the development of weapons of mass destruction have not been dispelled."

Item Details
Jurisdiction Ministry of Economy, Trade and Industry (METI)
Number of entries 748 entities (as of September 2025 revision)
Covered countries 15 countries and regions
Update frequency As needed (revised several times per year)

Countries and Regions on the List

Major countries and regions represented include:

  • China
  • North Korea
  • Iran
  • Pakistan
  • India
  • Syria
  • Russia (added)
  • Others

How to Use the List

Step 1: Download from METI's website

The Foreign User List can be downloaded free of charge from METI's website.

Step 2: Cross-reference counterparty names

Cross-reference the names of your counterparties against the organization names on the list.

Step 3: Watch for name variations

Be alert to name variations such as:

Pattern Example
Language differences English name vs. local language name
Abbreviations University → Univ.
Old/new names Organizations that have changed their names
Affiliated organizations Subsidiaries, affiliated institutions

How to Respond if a Match Is Found

Exporting to an organization on the Foreign User List requires a license application, unless it is clear that the export will not be used for the development of weapons of mass destruction.


The U.S. Entity List and Consolidated Screening List

Why You Also Need to Check U.S. Lists

Under Japanese law, the only list that Japanese exporters are legally required to check is the Foreign User List.

However, checking U.S. lists is also recommended for the following reasons:

Reason Content
Secondary sanctions risk Sanctions from the U.S. for transacting with U.S.-sanctioned parties
Re-export of U.S.-origin items Products containing U.S. components are subject to U.S. law
Counterparty reliability Appearance on a U.S. list is a warning signal
Global standard Many companies check U.S. lists as a matter of course

What Is the Entity List?

The Entity List is a list of export-controlled parties maintained by the U.S. Department of Commerce's Bureau of Industry and Security (BIS).

Item Details
Jurisdiction U.S. Department of Commerce (BIS)
Number of entries Hundreds of organizations
Effect Export prohibition for U.S.-origin goods and technology
Update frequency As needed

The Consolidated Screening List

The Consolidated Screening List is a "unified screening list" provided by the U.S. government.

It allows cross-search across multiple regulatory lists, enabling efficient verification:

Lists Included Administering Agency
Entity List Department of Commerce (BIS)
SDN List Department of the Treasury (OFAC)
Denied Persons List Department of Commerce (BIS)
Unverified List Department of Commerce (BIS)
Military End User List Department of Commerce (BIS)
Others Department of State, etc.

How to Check

The U.S. government provides an online searchable tool:

  1. Access the Consolidated Screening List website
  2. Enter the counterparty name
  3. If a hit is returned, verify the details

For the full picture across U.S., UN, and Japanese lists, see our guide to the five sanctions list families.


Step-by-Step Customer Due Diligence Process

Overview of the Investigation Flow

[Step 1] Collect Basic Information
    ↓
[Step 2] Cross-Reference with Regulatory Lists
    ↓
[Step 3] Additional Research (Web research, etc.)
    ↓
[Step 4] Direct Verification (if needed)
    ↓
[Step 5] Determination and Documentation

Step 1: Collect Basic Information

First, collect the following information about the counterparty:

Item Content
Legal name Corporate name (local language and English)
Location Country, city, address
Industry Business activities
Representatives Executives, key persons
End-use Intended purpose of the exported item

Step 2: Cross-Reference with Regulatory Lists

Cross-reference against the following lists:

List Purpose
Foreign User List Japanese legal obligation
Entity List U.S. regulatory risk
SDN List Sanctions target verification
UN Sanctions List International sanctions verification

Step 3: Additional Research (Web Research, etc.)

Even if not on any list, conduct the following additional research:

Research method What to check
Official website Business activities, customers, business partners
News search Presence of negative news
Registration information Verify existence as a legal entity
Industry information Reputation in the industry

Step 4: Direct Verification (if needed)

If concerns remain, verify directly with the counterparty:

Item to verify Specific questions
End-use "What purpose will the product be used for?"
Re-export "Do you plan to re-export to any third countries?"
Military connections "Do you transact with military or military-affiliated institutions?"
Declaration Obtain a declaration regarding end-use and re-export

Step 5: Determination and Documentation

Based on the investigation results, determine whether the transaction can proceed and create a record:

Determination Action
No concerns Proceed with transaction; retain records
Concerns present Request additional clarification; consider license application
Cannot proceed Halt the transaction

How to Identify Suspicious Transactions (Red Flags)

What Are Red Flags?

Red flags are warning signs indicating that a transaction may have national security concerns.

If any of the following signs are present, additional investigation is required.

Sign Details
Company information unclear No website; business activities unknown
Potential military connection Relationship with Ministry of Defense, military, or military research institutions
Connection to listed organizations Subsidiary or affiliate of an entity of concern
Suspicious location Possible shell company
Sign Details
Cannot explain intended use "I can't say what it's for"
Use and product do not match Agricultural company purchasing high-performance measuring instruments
Excessive quantities Orders disproportionately large relative to the scale of operations
Declining technical support "We don't need any support"
Sign Details
Cash payment Paying cash for high-value products
Unusual pricing Willing to pay far above market price
Urgent ordering "Please ship immediately"
Avoiding documentation "No contract needed"
Sign Details
Shipping destination mismatch Ordering entity and shipping destination are in different countries
Routing through free zones Transit through regions with lax regulations
Multiple transit points Unnecessarily complex routing
Special packaging requests "Please package it so it won't stand out"

How to Streamline Customer Due Diligence with AI

Challenges in Customer Due Diligence

Customer due diligence involves the following challenges:

Challenge Details
Multiple list cross-referencing Foreign User List, Entity List, SDN List, etc.
Name variation handling Multiple languages, abbreviations, old and new names
Identifying affiliated organizations Tracking subsidiaries and affiliated institutions
Keeping up with list updates Following frequent revisions
Enormous volume All new and ongoing transactions must be covered

There are real limits to what can be done manually.

The Reality of Investigation Workload

Estimated time per customer due diligence investigation:

Task Time required
Basic information collection 15–30 minutes
List cross-referencing (multiple) 30 minutes – 1 hour
Web research 30 minutes – 1 hour
Documentation 15–30 minutes
Total 1.5–3 hours per case

With 100 new counterparties per month, that's 150–300 hours per month.

How TRAFEED (formerly ZEROCK ExCHECK) Solves This

TRAFEED (formerly ZEROCK ExCHECK) is an export control-specialized AI agent that automates customer due diligence. It is, per our own research as of March 2026, the world's first AI agent in Japan's security export control domain, and holds a patent (Japanese Patent No. 7862062). In a joint proof of concept with Okayama University, a national university, it achieved AI screening accuracy of over 95% (per our own research) on roughly 30,000 past screening records, and as of July 2026 it has been adopted by more than 20 organizations across universities and companies.

Function Content
Multi-list screening Batch screening across multiple lists
Name variation handling Automatically detects similar names
Affiliated organization detection Automatically identifies subsidiaries and affiliated institutions
Real-time updates Automatically reflects list revisions
Automated report generation Automatically creates investigation records

In concrete terms, it supports same-day reflection of regulatory changes across jurisdictions, in-house approval workflows, advance due diligence on international students and new counterparties, and integration with major global paper, patent, and corporate databases.

One caveat worth stating plainly: TRAFEED's role ends at assembling the evidence without gaps. It is designed on the premise that the final export classification decision is made by your company's export control officer.

Lists Covered by Screening

TRAFEED (formerly ZEROCK ExCHECK) integrates screening across the following lists:

List Country/Agency
Foreign User List Japan (METI)
Entity List United States (BIS)
SDN List United States (OFAC)
Denied Persons List United States (BIS)
Military End User List United States (BIS)
UN Sanctions List United Nations

Conclusion

Key Points for Customer Due Diligence

  • Legal obligation: Exporters are required to verify intended use and end-user
  • Check multiple lists: Foreign User List + U.S. lists
  • Additional research: Even if not on lists, verify that no concerns exist
  • Red flags: Suspicious transactions require additional investigation
  • Retain records: Document and retain all investigation results

What Companies Must Do

  • Establish a customer due diligence process
  • Conduct list cross-referencing without gaps
  • Train employees to recognize red flags
  • Retain investigation records appropriately
  • Be prepared — "I didn't know" is not a defense

The Reality of Due Diligence Work

  • 1.5–3 hours of work per case
  • Multiple lists, multiple languages, name variation handling
  • Keeping up with frequent list updates
  • Manual processes alone have real limits

TIMEWELL Customer Due Diligence Support

TIMEWELL offers solutions to streamline customer due diligence (customer screening).

Consult About TRAFEED (formerly ZEROCK ExCHECK)

  • Implementation consultation: Diagnose your company's current due diligence process
  • Demo: Experience AI-powered screening
  • Customization: Optimization tailored to your industry and transaction patterns

"Is this company safe? AI delivers the answer."

For questions about streamlining customer due diligence, please feel free to reach out.


Reference Information

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Free download

Recommended materials

Five Sanctions-List Systems Screening Procedure (US OFAC/BIS, EU, UK, UN + Japan's Foreign End User List, 2026)

A fill-in cross-list screening procedure for the five systems (US OFAC, US BIS, the EU, the UK, the UN) plus Japan's Foreign End User List — where, what and how to screen. Covers SDN/non-SDN and the BIS lists, the 50% / ownership-control tests, official source URLs and update cadence, and Red Flags. Based on each authority's primary sources; listing is a regulatory classification, not a judgment — final decisions rest with each authority's original list and your own officer.

Event Organiser's Migration & Data-Rescue Checklist (fill-in, 2026)

A fill-in worksheet for event organisers whose ticketing service has shut down. PassMarket closed on June 30, 2026, and its ticket management tool is announced as available until August 31, 2026 (planned). The sheet covers what to rescue before that deadline (attendee records, survey responses, revenue and payout records, event page copy, ticket configuration), an inventory of the channels through which you can still reach attendees, a formula and worksheet for calculating the effective cost of a new platform yourself, and the steps to launch a first event on it. Anything the official announcement does not state — when in-service messaging stops, the export specification for attendee lists and survey data, the timing of payouts — is marked "to be confirmed" rather than asserted. It does not rank providers; it supplies the formula and the checklist.

China-Related Transactions Export-Control Screening Sheet (fill-in / Export Control Law & Dual-Use Regulations, critical minerals, Control List, 2026)

A fill-in working sheet for companies trading with China: screen a single transaction against China's export-control regime (the Export Control Law and the Dual-Use Items Export Control Regulations), the controls on critical minerals (gallium/germanium/graphite/antimony/tungsten etc./rare earths/helium), and the four counterparty-list systems (Control List, Watch List, Unreliable Entity List, countermeasure lists). A procedure for "what to check before the deal," not a roster of "who is listed." With a plain-language intro, based on MOFCOM announcements. Listing is a regulatory category, not a judgment about any company (including the Japanese firms on the Japan-directed lists); controls change continually, so verify current announcements and consult your officer. Match counterparties using the original simplified-Chinese wording.

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles