TRAFEED

Complete Guide: Entity List vs. MEU List vs. SDN List — When Japanese Companies Get Caught by the U.S. Big Three Restricted-Party Lists

Published2026-05-20Updated2026-07-06Ryuta Hamamoto

Both are U.S. restricted-party lists, but the agencies, the way restrictions attach, and the delisting procedures are different.

Complete Guide: Entity List vs. MEU List vs. SDN List — When Japanese Companies Get Caught by the U.S. Big Three Restricted-Party Lists
Share

Hello, this is Ryuta Hamamoto from TIMEWELL. One of the first questions new dual-hatted export-control owners ask me is: "What's the real difference between the Entity List and the SDN List?"

Both are U.S. restricted-party lists, but the agencies, the way restrictions attach, and the delisting procedures are different. Add the MEU List (Military End-User List), created in 2020, and you have the three lists every export-control and sanctions program needs as an entry point. List placement is a regulatory designation. It is not, by itself, a judgment that a company is a "bad actor."

Below I organize the differences and the typical ways Japanese companies get caught without realizing it, with tables and cases. By the end, a reader about six months into export control should be able to picture how to re-check their counterparty list.

What you will learn

  • Differences across Entity List / MEU List / SDN List by agency, scope, and effect (one comparison table)
  • Five ways your company can get caught (de minimis, FDP Rule, 50% rules, and more)
  • Penalties and recent enforcement/settlement examples (including a ~$250 million settlement)
  • Five practical steps (CSL match → 50% verification → end-use checks → internal controls → records)
  • Common misconceptions / FAQ (unlisted affiliates; Affiliates Rule during suspension)

A fill-in screening procedure covering all five list systems: It maps where to look, what to check and how to record it for US OFAC, US BIS, the EU, the UK and the UN, plus Japan's Foreign End User List — including the 50% / ownership-control test, official source URLs and update cadence, and the Red Flags. You can turn the five steps in this article (CSL match, 50% verification, end-use checks, internal controls, records) into your own written procedure, and show it when a counterparty or an auditor asks how the screening was done. Listing is a regulatory classification, not a judgment about a company. → Download the Five Sanctions-List Systems Screening Procedure (2026) (Free; your company name and work email address are required.)

Three terms to understand first

U.S. restricted-party lists are numerous and hard to map at first glance. Start with how the big three fit.

Entity List

  • Formal name: Entity List (EAR Supplement No. 4 to Part 744)
  • Agency: Bureau of Industry and Security (BIS), U.S. Department of Commerce
  • Role: Foreign persons, companies, and organizations that BIS has determined present a significant risk of involvement in activities contrary to U.S. national security or foreign policy interests (regulatory standard under the EAR; not a court finding of corporate guilt)
  • Effect: Exports, re-exports, and in-country transfers of "items specified on the list entry" to that entity require a BIS individual license. License exceptions are generally unavailable; the review policy is "Presumption of Denial"
  • Entries (as of May 2026): more than 3,400 (figure BIS published as of September 2025)

The key point is license requirement, not an absolute ban. In theory a license can be granted; in practice approval is rare, so operationally the list often means "stop the deal."

MEU List (Military End-User List)

  • Formal name: Military End-User List (EAR Supplement No. 7 to Part 744)
  • Agency: BIS, U.S. Department of Commerce
  • Role: Lists foreign parties identified as "military end users" located in China, Russia, or Venezuela (created December 23, 2020). Again, this is a regulatory category under the EAR.
  • Covered items: only certain ECCNs listed in EAR Supplement No. 2 to Part 744 (semiconductors, sensors, communications equipment, etc.)
  • Feature: Even unlisted parties can be covered if they meet the "military end user" definition. Listing is illustrative, not exhaustive

The biggest difference from the Entity List is item scope. The Entity List can reach EAR-subject items broadly; the MEU List reaches only specified ECCNs. Geographic scope is also limited to China, Russia, and Venezuela.

SDN List (Specially Designated Nationals and Blocked Persons List)

  • Formal name: Specially Designated Nationals and Blocked Persons List
  • Agency: Office of Foreign Assets Control (OFAC), U.S. Department of the Treasury
  • Role: Lists parties designated under OFAC programs covering sanctioned jurisdictions, terrorism, narcotics trafficking, cybercrime, human-rights abuses, and related authorities
  • Effect: (1) property in the United States is blocked, (2) U.S. persons (U.S. citizens, permanent residents, U.S. companies, persons in the United States) are generally prohibited from all transactions
  • Secondary sanctions: Non-U.S. third-country companies dealing with SDNs can risk their own SDN listing or exclusion from U.S. markets

Among the three, the SDN List is the strictest. Unlike the Entity List's license model, it is a general ban across all goods and services plus asset blocking.

One table: the big three compared

Item Entity List MEU List SDN List
Agency Commerce BIS Commerce BIS Treasury OFAC
Authority EAR Part 744 EAR § 744.21 IEEPA and others + 31 CFR
Geography Worldwide China, Russia, Venezuela Worldwide
Nature of restriction License (Presumption of Denial) License (specified ECCNs only) General ban + asset blocking
Item scope EAR items specified on the entry Items in Supp. 2 to Part 744 All transactions regardless of item
Reach outside the U.S. EAR extraterritorial tools (de minimis, FDP Rule) EAR extraterritorial tools Secondary sanctions; 50% rule
Primary subjects Anyone dealing in EAR items worldwide Anyone dealing in EAR items worldwide Primarily U.S. persons; non-U.S. persons via secondary sanctions
Civil penalty cap Up to $374,474 per violation or twice the transaction value Same (as EAR violation) Up to ~$377,700 per violation or twice the transaction value
Criminal penalty cap Up to 20 years + $1M per count for individuals Same Same
Delisting Written petition to End-User Review Committee (ERC); unanimous ERC OFAC Reconsideration Petition; typically 1–3 years
Appeal No administrative appeal; judicial review only Same Administrative reconsideration available

Put differently: Entity List and MEU List belong to export control; SDN List belongs to economic sanctions. Japanese literature often mixes them. Separate them by statute and agency from day one.

CSL is only an entry point

Beyond the three, BIS runs the Denied Persons List (DPL) and Unverified List (UVL); OFAC runs Sectoral Sanctions Identifications (SSI); DDTC runs the Debarred List; and more. Consolidated Screening List (CSL) aggregates many of them; trade.gov provides free API and CSV feeds, updated daily at 5:00 a.m. EST.

Practitioners typically start with CSL, but CSL only hits listed parties. Unlisted affiliates that become blocked under the 50% rules (below) do not appear in CSL. That is the first trap for beginners.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

Five ways your company can get caught

Many teams assume "we don't export to the United States, so Entity List is irrelevant." Domestic Japan deals and third-country deals can still be captured. Five patterns I see most often:

Pattern 1: Re-export of products with >10% U.S. content (de minimis Rule)

Foreign products with U.S.-origin content above a threshold (generally 10%; 0% for certain terrorism-supporting destinations) become EAR-subject. Even products assembled in Japan can need a BIS license to re-export to Entity List parties if U.S. semiconductors or software exceed the threshold.

Pattern 2: Delivery of products made with U.S. equipment or technology (FDP Rule)

Under the Foreign-Produced Direct Product Rule, foreign-made products produced with U.S.-origin technology, software, or equipment can be EAR-subject. In semiconductor manufacturing equipment and AI-related items, Japanese-origin tools can still be captured once U.S. masks or U.S. EDA software are in the process.

Pattern 3: USD settlement with an SDN (U.S.-routed payments)

Even yen deals between Japanese companies can fall under OFAC if U.S. persons, U.S. products, or U.S.-routed funds are involved. Classic example: USD wires almost always transit U.S. correspondent accounts and thus U.S. jurisdiction.

Pattern 4: Deals with unlisted companies 50%+ owned by SDNs (OFAC 50% rule)

Under OFAC's 50% rule, unlisted companies that an SDN (or certain blocked persons) owns directly or indirectly, alone or in the aggregate, at 50% or more are automatically blocked. Critically, CSL will not surface them. You must research ownership separately.

Pattern 5: China subsidiaries selling EAR items to military end users (MEU List)

Even if Japan HQ never exports, a China subsidiary selling EAR items to parties that meet the military end-user definition onshore creates MEU List risk. MEU List is not only "is the name listed?" but also "does the counterparty meet the military end-user definition?" Local end-use diligence is essential.

Two 50% rule systems

As of May 2026, OFAC and BIS versions are in different operational states.

Rule Agency Content Status as of May 2026
OFAC 50% Rule Treasury OFAC Unlisted companies 50%+ owned (direct/indirect, alone/aggregate) by SDNs or certain blocked persons are automatically blocked In force (clarified since 2014)
BIS Affiliates Rule Commerce BIS Same EAR restrictions as the parent Entity List / MEU List entity automatically apply to unlisted foreign entities 50%+ owned (direct/indirect, alone/aggregate) Effective 2025/9/29 → suspended for one year from 2025/11/10 → scheduled to take effect 2026/11/10

OFAC's version auto-applies only to ownership (25% ownership with control may be a Red Flag but is not automatic blocking). BIS Affiliates Rule is also ownership-based but explicitly cascades: if A owns B owns C, C is covered.

BIS Affiliates Rule is suspended for one year as of May 2026. During suspension, 25%+ ownership and similar facts still function as Red Flags requiring enhanced diligence. Details: Complete guide to the BIS Affiliates Rule (50% rule).

If in-house capacity feels insufficient

Big-three list matching is not enough with CSL alone. You also need Affiliates Rule 50% aggregation, indirect ownership chains, and name-variant analysis. That work can take days manually.

TRAFEED (formerly ZEROCK ExCHECK) visualizes Entity List / MEU / SDN matching plus relationship-chain analysis in about five seconds, using a knowledge graph of over 200 million papers, patents, researchers, companies, and regulatory lists. It runs on AWS Tokyo-region servers in Japan.

Explore TRAFEED features Book a 30-minute consultation

Violation risk

EAR and OFAC penalties are roughly comparable and inflation-adjusted annually. 2026 caps:

  • EAR (Entity List / MEU List): civil up to $374,474 per violation or twice the transaction value, whichever is higher; criminal for individuals up to 20 years + $1,000,000 per count
  • OFAC (SDN List): civil up to about $377,700 per violation or twice the transaction value; criminal for individuals up to 20 years + $1,000,000 per count
  • Administrative: EAR violations can also strip export privileges (Denied Persons List). DPL is a full ban on EAR-item dealings and is the strictest of BIS's three lists

Three recent examples, stated as settlements or public enforcement facts (settlement does not by itself equal a court finding of guilt):

  • Semiconductor manufacturing equipment maker (announced February 2026): a major equipment maker settled with BIS for about $250 million in civil penalties over re-exports to Entity List parties via subsidiaries. Settlement resolves the matter by agreement and does not itself adjudicate guilt as a formal finding
  • HDD maker (2023): a major HDD maker settled with BIS for about $300 million where FDP Rule application was at issue
  • Consumer-goods company (2023): a company settled with OFAC and DOJ for about $629 million over North Korea–related sanctions laws

Recent Entity List expansions have reached operators in dual-use fields such as semiconductors, AI, quantum, hypersonics, and drones. The 32 additions in September 2025 have been analyzed by law firms as related to those fields and third-country routing. Listing is a regulatory classification, not a judgment of corporate wrongdoing.

Five practical steps

What to do starting tomorrow:

Step 1: Screen counterparties and end users on CSL

  • Match names, addresses, and aliases on trade.gov's Consolidated Screening List
  • Watch name variants (Chinese pinyin / traditional / simplified; Russian Cyrillic / Latin)
  • Re-screen monthly or before each deal even after a clean hit

Step 2: Verify 50% rules (ownership)

  • For major counterparties, walk one level up shareholders, parents, and affiliates
  • Check whether SDN / Entity List parties own 50%+ directly or indirectly, alone or aggregated
  • At 25%+ ownership or overlapping officers, treat as a Red Flag and enhance diligence
  • Use domestic data (Teikoku Databank, Tokyo Shoko Research) plus foreign registries (OpenCorporates, etc.)

Step 3: Confirm end use and end user

  • Military, national police, intelligence, or research-institute involvement (MEU List context)
  • Interview whether final use could involve WMD or military end uses
  • Obtain End-Use Statements and conduct site audits as needed

Step 4: Build internal controls (CP)

  • Document pre-deal screening, in-deal monitoring, and post-deal records
  • Separate screener and approver; apply four-eyes principle
  • Clarify reporting lines to management

Step 5: Retain records and prepare for voluntary disclosure

  • Keep screening results, ownership checks, and decision memos for at least five years
  • If a violation is discovered, immediately consider Voluntary Self-Disclosure (VSD)
  • U.S. authorities operate near strict liability. "We didn't know" is not a defense; VSD can substantially reduce civil penalties

Common misconceptions / FAQ

Q1. If a subsidiary is not on CSL, is the deal fine?

A. Not safe.

  • OFAC 50% rule automatically blocks unlisted companies 50%+ owned by SDNs
  • BIS Affiliates Rule (scheduled effective November 10, 2026) applies the same restrictions to unlisted foreign entities 50%+ owned by Entity List / MEU List parties
  • Below 50%, "significant minority" ownership can still be a Red Flag for enhanced diligence

Use CSL as an entry point and pair it with ownership-chain research.

Q2. BIS Affiliates Rule took effect September 29, 2025. What happened?

A. A one-year enforcement suspension was announced effective November 10, 2025. Formal effectiveness is scheduled for November 10, 2026.

During suspension, major U.S. law firms (White & Case, Sidley Austin, Morrison & Foerster, Baker McKenzie, and others) still treat 25%+ ownership and similar facts as Red Flags for enhanced diligence. "Suspended" does not mean "do nothing."

Q3. Which is stricter, Entity List or SDN List?

A. As a general matter, SDN List is stricter.

  • SDN List: general ban across items + asset blocking
  • Entity List: license requirement for specified items (Presumption of Denial)

But Entity List entries with Footnote 1 (certain well-known listed entities in the communications/equipment space) or Footnote 5 can pull in foreign-made products broadly via the FDP Rule and approach SDN-level impact. Always check footnotes on each Entity List entry. Placement remains a regulatory status.

Q4. A counterparty name appeared on the Entity List. Stop immediately?

A. Before stopping, check:

  1. Whether the deal items fall within that entry's License Requirement Column
  2. Whether the transaction is EAR-jurisdictional (de minimis / FDP Rule)
  3. Whether a license application is viable (Presumption of Denial is the default, but filing is still allowed)

For SDN List hits involving U.S. persons, stopping is the starting point. OFAC General or Specific Licenses may still apply. Involve counsel.

Q5. We dealt with a listed party without knowing. Now what?

A. Near strict liability. Lack of knowledge is not a defense.

  • Upon discovery, consider VSD promptly; large civil-penalty reductions are available
  • Records of pre-export screening (CSL, ownership checks) can mitigate
  • Contact U.S. counsel and Japanese export-control advisors immediately

Latest developments as of July 2026

Big-three screening is U.S.-origin, but Japan’s economic-security framework is also moving. The 16th Japan–India Annual Summit on July 2, 2026 produced a joint declaration deepening cooperation across semiconductors, critical minerals (rare earths), clean energy, ICT (subsea cables), and pharmaceuticals, with roughly ¥2 trillion in investment framed (Japan–India joint press statement (Prime Minister’s Office, July 2026)). As supply chains reconfigure, counterparties and end users change. New suppliers are exactly when Entity List / MEU / SDN first screening and ownership checks matter most. Background: Japan–India Summit 2026 and economic security.

If you want to improve export-control operations or classification efficiency, review the TRAFEED service catalog (PDF) or contact us.

Key takeaways

If you only do one thing tomorrow, re-screen major counterparties on CSL and walk ownership one level up. One more pass on the big three:

  • Entity List: Commerce BIS; license-based; specified items; worldwide; 3,400+ entries
  • MEU List: Commerce BIS; license-based; specified ECCNs only; China/Russia/Venezuela; definition-based coverage even if unlisted
  • SDN List: Treasury OFAC; general ban + asset blocking; all items; strict for U.S.-person dealings + secondary sanctions

Five typical Japanese-company capture patterns:

  1. Re-export of products with >10% U.S. content (de minimis Rule)
  2. Delivery of products made with U.S. equipment or technology (FDP Rule)
  3. USD settlement with SDNs (U.S.-routed payments)
  4. Deals with unlisted companies 50%+ owned by SDN / Entity List parties (50% rules)
  5. China / Russia / Venezuela subsidiaries selling EAR items to military end users (MEU List)

Operational minimum: CSL match, 50% verification, end-use checks, internal controls, record retention.

Final check: if in-house capacity feels insufficient

Again: big-three matching is not enough with CSL alone. Ownership under the 50% rules, indirect chains, multilingual name variants (Chinese, Russian, Arabic transcription), and Footnote status: covering all of that manually remains heavy even with dedicated staff.

TRAFEED (formerly ZEROCK ExCHECK) visualizes Entity List / MEU / SDN matching plus relationship-chain analysis in about five seconds on a 200M+ knowledge graph. METI-aligned, multilingual, AWS Tokyo-region operation.

Explore TRAFEED features Book a 30-minute consultation

References

U.S. government (official)

Japanese government and support bodies

Law-firm analysis (2026 practice)

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Free download

Recommended materials

Five Sanctions-List Systems Screening Procedure (US OFAC/BIS, EU, UK, UN + Japan's Foreign End User List, 2026)

A fill-in cross-list screening procedure for the five systems (US OFAC, US BIS, the EU, the UK, the UN) plus Japan's Foreign End User List — where, what and how to screen. Covers SDN/non-SDN and the BIS lists, the 50% / ownership-control tests, official source URLs and update cadence, and Red Flags. Based on each authority's primary sources; listing is a regulatory classification, not a judgment — final decisions rest with each authority's original list and your own officer.

Economic Security Management Guidelines (1st Edition): 44-Item Self-Check Worksheet (2026)

A fill-in worksheet built from the appendix checklist of the Economic Security Management Guidelines (1st Edition), published by METI's Trade and Economic Security Bureau on 23 January 2026. All 44 items are transcribed from the original text and laid out in its three-column form: check item, Y/N, and the structures (organisation, internal rules) and track record behind your answer. The breakdown follows the original: 5 items on principles executives should keep in mind, 13 on securing autonomy, 13 on securing indispensability, and 13 on strengthening governance, with the 8 items the original phrases as "it is also useful to" badged separately. Opens with a plain-language primer on what economic security, autonomy, indispensability, governance and duty of care actually mean. Includes METI-published survey data showing that 70.7% of 3,007 manufacturers had heard the term but had no concrete image of it, and that the share expecting lost revenue to outweigh the cost of action rises from 22.3% over one to three years to 31.9% over four to ten. As METI states explicitly, the guidelines are not an obligation imposed on companies and are not premised on transactions with any specific country, company, or person. This worksheet was produced by TIMEWELL and was not prepared or endorsed by METI. Final decisions should rest with your legal and compliance leadership and the latest publications of the relevant authorities.

Event Organiser's Migration & Data-Rescue Checklist (fill-in, 2026)

A fill-in worksheet for event organisers whose ticketing service has shut down. PassMarket closed on June 30, 2026, and its ticket management tool is announced as available until August 31, 2026 (planned). The sheet covers what to rescue before that deadline (attendee records, survey responses, revenue and payout records, event page copy, ticket configuration), an inventory of the channels through which you can still reach attendees, a formula and worksheet for calculating the effective cost of a new platform yourself, and the steps to launch a first event on it. Anything the official announcement does not state — when in-service messaging stops, the export specification for attendee lists and survey data, the timing of payouts — is marked "to be confirmed" rather than asserted. It does not rank providers; it supplies the formula and the checklist.

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles