INTERNATIONAL TRADE LAW
Export Compliance Audit: A Practical Guide

An export compliance audit is a structured review of a company’s export transactions, records, and internal controls to confirm they meet the requirements of U.S. export law — chiefly the Export Administration Regulations (EAR) and the International Traffic in Arms Regulations (ITAR). It answers one question: if a regulator examined your exports tomorrow, would your classifications, licenses, screening, and records hold up? Done before a problem surfaces, it is one of the cheapest forms of insurance an exporter can buy.
What an Export Audit Examines
A meaningful audit goes transaction by transaction and system by system. It typically reviews:
- Classification — whether products are correctly classified (ECCN under the EAR, USML category under ITAR) and whether jurisdiction is right.
- Licensing — whether shipments that needed a license or exemption had one, and whether license conditions were met.
- Party screening — whether customers, consignees, and end users were screened against the restricted party lists, and whether hits were resolved and documented.
- End-use and destination controls — whether sensitive shipments had appropriate end-use documentation and were not destined for prohibited uses or parties.
- Recordkeeping — whether required export records exist, are complete, and are retained for the legally required period.
The output is not just a pass/fail. A good audit produces a list of specific gaps, ranked by risk, with corrective actions.
Why Recordkeeping Sits at the Center
Export audits live or die on records, because the government’s own rules require you to keep them. Under the EAR, export records must be retained for five years from the latest relevant event — the export, any known re-export or transfer, or the termination of the transaction (15 CFR 762.6). ITAR imposes a comparable five-year retention requirement on registrants. If a regulator requests records, you also may not destroy them even past the retention period without authorization.
Missing or disorganized records turn a manageable inquiry into a serious one. An audit that confirms your records are complete and retrievable is often the single most valuable thing it accomplishes.
Internal Audit vs. Government Examination
Not all “audits” are the same, and the distinction matters.
| Type | Who runs it | Purpose |
|---|---|---|
| Internal / self-audit | The company or its counsel | Find and fix gaps before they become violations |
| Outreach or end-use check | BIS or DDTC | Verify a specific transaction or party (e.g., a post-shipment end-use check) |
| Investigation | Enforcement agencies | Examine suspected violations; can carry penalties |
A self-audit is voluntary and protective. A government examination is not something you schedule — which is exactly why the self-audit comes first. (Note that a CBP “audit” of imports, such as a Focused Assessment, is a separate, customs-side process from the export audits described here.)
What to Do When an Audit Finds a Problem
Finding a violation in your own audit is not a disaster — it is the system working. The EAR and ITAR both have voluntary self-disclosure (VSD) procedures, and agencies treat a timely, complete self-disclosure as a significant mitigating factor in any penalty analysis. The wrong move is to bury the finding. The right sequence is to stop the conduct, preserve the records, assess the scope with counsel, and decide whether a voluntary disclosure is warranted. Privilege and timing matter here, which is why companies typically involve a lawyer before disclosing.
How to Prepare for an Audit
A few steps make any audit — internal or external — go more smoothly:
- Map your exports. Know what you ship, where, to whom, and under what authorization.
- Centralize records. Keep classification rationales, licenses, screening results, and shipping documents together and retrievable.
- Document your screening. A screen you cannot prove you ran is, for audit purposes, a screen you did not run.
- Run a mock audit. Test a sample of transactions against the checklist above before anyone else does.
- Write down your program. A short, followed Export Management and Compliance Program is worth more than a long one nobody uses.
Frequently Asked Questions
How long do I have to keep export records?
Under the EAR, five years from the latest of the export, any known re-export or transfer, or the end of the transaction (15 CFR 762.6). ITAR similarly requires five-year retention. If an agency requests records, do not destroy them even after five years without written authorization.
Is an export audit required by law?
A periodic self-audit is not a standalone legal mandate, but it is a core expectation of a credible compliance program and a near-universal best practice. Government-initiated audits and end-use checks, by contrast, are not optional once they begin.
What should I do if an audit uncovers a violation?
Stop the conduct, preserve records, and assess the scope with counsel. The EAR and ITAR both offer voluntary self-disclosure procedures that agencies weigh heavily as mitigation. Get legal advice before disclosing.
Who should perform the audit?
Internal compliance staff can run routine self-audits, but where potential violations or privilege questions arise, involving outside counsel protects the analysis and helps preserve options.
A focused export audit turns unknown risk into a short, prioritized fix list — long before a regulator is the one asking. Reidel Law Firm reviews export programs and records and advises on disclosures on flat-fee terms. Get an import/export compliance memo.


