A mid-sized trade-finance bank processes a payment for a long-standing corporate client. Its automated screening returns a clean result. The wire is routed through a US dollar clearing bank. That correspondent reviews the underlying beneficiary and identifies an export-control red flag – not a sanctions designation, but an Entity List (the Bureau of Industry and Security's list of parties subject to enhanced export-control licence requirements) match. The correspondent suspends the payment and signals it is reviewing the relationship. The originating bank has one question: is this an OFAC issue or a BIS issue, and does the difference matter?
The difference matters enormously. Correspondent-banking de-risking (a financial institution exiting or restricting payment relationships to reduce sanctions or export-control exposure) is driven by two distinct US regulatory regimes with different triggers, different legal bases, and different risk profiles. OFAC's rules operate on designated parties and blocked transactions; the BIS Export Administration Regulations (the EAR) address the movement of controlled goods and technology, with financial penalties available where banks facilitate prohibited exports. Neither regime's exposure is a proxy for the other.
This analysis maps the two regimes side by side, identifies where they converge and diverge for correspondent banks, and sets out the practical tests a compliance team should apply before deciding whether to exit, restrict, or retain a relationship.
What drives de-risking decisions: the two legal triggers
OFAC de-risking is triggered by a designation or a geographic programme – the legal obligation not to process a transaction involving a blocked person or a comprehensively restricted jurisdiction. BIS / EAR de-risking is triggered differently: the concern is not that a party is on a sanctions list but that a payment may facilitate an export, re-export, or transfer of controlled technology or goods without the required licence.
These are structurally separate obligations. OFAC's jurisdiction under IEEPA and related statutes is transaction-based and person-based. A wire transfer that touches a Specially Designated National (SDN List – OFAC's master list of blocked persons and entities) must be blocked or rejected regardless of whether goods move at all. The EAR, by contrast, is goods- and technology-focused. A payment that funds the acquisition of a controlled item – even if the item is described innocuously in the payment instructions – can implicate the EAR where the bank has knowledge of the end use or end user.
In our cross-border practice, we regularly advise correspondent banks that conflate these two triggers. A party can sit on the BIS Entity List without appearing on any OFAC list. Equally, an SDN designation does not automatically make every commercial transaction involving that person an export-control violation – though it typically makes it a prohibited transaction under OFAC. The compliance question is always: which regime is activated by these specific facts?
How does the ownership test differ between OFAC and the EAR?
OFAC applies its 50 percent rule (the rule treating any entity owned 50 percent or more in the aggregate by one or more blocked persons as itself blocked) to correspondent-banking transactions. A payment routed to or from an entity that crosses that ownership threshold is treated as a payment to a blocked person even without a separate designation. The test is mechanical and applies regardless of where the entity is incorporated or where the correspondent bank sits.
The EAR does not have a directly equivalent ownership rule. Instead, the key concept is "knowledge" of a prohibited end use or end user. A bank that knows, or has reason to know, that a transaction will fund the acquisition of an Export Control Classification Number (ECCN) item for an end user on the Entity List, Denied Persons List, or Unverified List cannot process that payment without implicating BIS. The ownership question under the EAR is one factor in that knowledge analysis rather than an automatic legal trigger.
This divergence has a direct operational consequence. Under OFAC, automated screening against ownership-aggregated beneficial-ownership data is the first line of defence. Under the EAR, no screening tool replicates the knowledge test: the bank must have a system to receive red-flag indicators, assess them, and make a documented judgement. Do your screening and due-diligence procedures treat these as separate analytical steps?
Where do the regimes converge: the US correspondent as a chokepoint
Both regimes use the US correspondent bank as a primary enforcement chokepoint. OFAC's jurisdiction over US dollar clearing means any wire routed through a US bank – even a transaction with no other US nexus – is subject to OFAC's rules. BIS's extraterritorial reach applies to items subject to the EAR, which includes a broad category of items with US-origin content above a de minimis threshold, regardless of where the transaction is booked.
In practice, this means a non-US originating bank routing a payment through a US correspondent is exposed to both sets of rules simultaneously. If the underlying transaction relates to goods with US-origin controlled content, the EAR is engaged. If the beneficiary or a party in the chain is an SDN or an entity captured by the 50 percent rule, OFAC is engaged. The correspondent will assess both when it reviews the payment.
We have acted for non-US originating banks that received simultaneous queries from their US correspondent on both grounds. The banks had strong OFAC screening processes but inadequate controls around EAR red-flag indicators. The practical result was a relationship suspension that the bank's compliance team could not resolve quickly because it had no internal workflow for responding to EAR-specific queries. That asymmetry – strong on sanctions, weak on export controls – is the pattern we see most frequently.
What are the de-risking risk flags specific to each regime?
The risk flags that should trigger enhanced review differ materially between the two regimes and should not be assessed under a single generic "sanctions red flag" protocol.
For OFAC, the core flags are: a counterparty name that generates a fuzzy match against the SDN List; a beneficial owner in the ownership chain that is designated or appears in a jurisdiction under a comprehensive programme; transaction routing through a financial institution that is itself designated; and payment instructions that obscure the originator or beneficiary identity. Each flag calls for a block-or-reject decision under OFAC's compliance framework.
For the EAR, the red-flag indicators are qualitatively different. They include: a payment purpose that could fund acquisition of controlled goods or technology; a beneficiary in a country subject to stringent EAR controls; a description of goods that is vague or inconsistent with the stated value; a customer who is reluctant to confirm end use; and any prior BIS advisory opinion that names the industry sector or technology class. These indicators do not trigger a block – they trigger an inquiry obligation and, where the bank cannot resolve the red flag, an obligation not to proceed.
The distinction matters for the compliance workflow. OFAC red flags lead to a defined decision tree: screen, match, block, report. EAR red flags lead to a more judgement-based process: identify, inquire, document, decide. Neither process substitutes for the other.
How do reporting and record-keeping obligations compare?
OFAC requires that a US person (including a US correspondent bank acting for a foreign bank) report blocked transactions and retain records. The reporting window is short and the record-keeping period is specified in OFAC's regulations. For record-keeping, OFAC mandates retention for five years from the date of the transaction. Rejected transactions – those the bank turns away without blocking – carry their own report-and-retain obligations.
The EAR's record-keeping requirement for parties involved in export transactions is also five years. Where a bank is classified as a party to an export transaction – because it has processed a payment or provided financing for a controlled export – it is subject to that standard. In our experience, most correspondent banks do not have record-keeping systems calibrated to both OFAC and EAR retention requirements in the same transaction record. That gap creates audit exposure.
A further divergence: OFAC has a structured voluntary self-disclosure or VSD (a voluntary report of a potential violation to the regulator, which can reduce civil penalties) process that is well-developed and frequently used. BIS also accepts VSDs, but the mechanics are handled through different channels, and the penalty-reduction framework operates differently. A bank that discovers it has processed a transaction later identified as both an OFAC and an EAR potential violation needs separate disclosure strategies – a combined filing with one agency is not a substitute for disclosure to the other.
Is BIS / EAR exposure really relevant for correspondent banks?
The common assumption – that the EAR concerns exporters and freight forwarders, not banks – is the most significant compliance myth we encounter in this area. In fact, BIS's enforcement posture has made clear that financial institutions that facilitate prohibited exports, provide financing, or process payments for controlled goods transfers can be held to account under the EAR where they have the requisite knowledge.
This myth persists partly because OFAC enforcement against financial institutions is high-profile and well-documented, whereas BIS civil enforcement actions against banks receive less public attention. The consequence is a systematic under-investment in EAR-specific compliance capability at correspondent banks. Screening teams are trained for OFAC; trade-finance teams may understand export documentation controls; but the intersection – the payment that funds a controlled export – sits in a gap between the two.
The EAR also carries criminal enforcement risk. Where a bank employee has actual knowledge of an illegal export and the bank processes the payment, DOJ involvement is possible alongside the BIS civil action. That escalation path is well-established under US export-control law and is not limited to the exporter. Any party in the transaction chain – including the financing bank – can be in scope.
The cross-border dimension: non-US banks and the reach of both regimes
For a non-US correspondent bank operating in a third country, the question is how US jurisdiction attaches. Under OFAC, the answer turns on US nexus: US dollar denomination, a US person in the transaction chain, or a US correspondent as clearing agent. Any one of those is sufficient to bring the transaction within OFAC's reach. The bank does not need to be US-incorporated.
Under the EAR, jurisdiction attaches to the item or technology rather than the currency. If the item has US-origin content above the applicable de minimis threshold, or if it is a foreign-made item with controlled US technology incorporated, the EAR follows the item regardless of where the payment is processed. A European or Asian correspondent bank financing the sale of such an item to a restricted end user is within BIS's jurisdiction even if no US dollar clears and no US person is involved in the transaction.
This extraterritorial dimension means that non-US banks cannot treat OFAC and EAR compliance as a US domestic concern that applies only when they route through New York. The correct analysis is item-based for the EAR and nexus-based for OFAC, and both analyses run in parallel. Non-US regulators – including OFSI in the United Kingdom and the EU sanctions authorities – have their own overlapping regimes, which means a non-US bank may face parallel obligations under multiple regimes simultaneously. Where the jurisdictions diverge, the stricter prohibition governs for that jurisdiction's obligations.
The position above covers the standard analytical case. Your specific counterparties, payment routes, goods descriptions, and beneficial-ownership structures change the analysis significantly.
For a confidential assessment of your correspondent-banking exposure under OFAC and the EAR, contact Calder & Vance at info@caldervance.com.
Practical decision sequence: OFAC first, then EAR, then both together
The correct workflow for a correspondent bank reviewing a payment runs in a defined sequence. It is not a single sanctions screen; it is a two-stage analysis with a third combined step where both regimes are potentially engaged.
Stage one – OFAC screen. Run the transaction parties – originator, beneficiary, intermediaries, and beneficial owners through the ownership chain – against the SDN List and the relevant geographic programme lists. Apply the 50 percent rule to any entity where a listed person appears in the ownership structure. A match requires a block or rejection decision and the applicable report.
Stage two – EAR red-flag review. Assess whether the payment purpose could fund the acquisition, re-export, or transfer of a controlled item. Does the goods description map to a category on the Commerce Control List? Is the beneficiary on the Entity List, Denied Persons List, or Unverified List? Are there indicators of diversion risk – a third-country intermediary in an industry inconsistent with the stated end use, vague descriptions, or a beneficiary that has not provided confirmable end-use documentation?
Stage three – combined analysis. Where both flags are present, the bank faces simultaneous obligations. The OFAC obligation is to block; the EAR obligation is not to proceed. The outcomes are consistent in that case, but the reporting and record-keeping requirements are distinct and must both be satisfied. A bank that blocks under OFAC but does not assess and document its EAR position has completed only half the compliance process.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time.
To discuss a correspondent-banking matter or review a pending compliance query, contact Calder & Vance at info@caldervance.com.
Related practices
- Correspondent-banking de-risking under OFAC – OFAC-specific screening, blocking, and reporting services for banks and payment firms.
- OFAC vs EU: Correspondent-banking de-risking compared – regime-by-regime analysis of US and EU divergences for cross-border payment institutions.
- OFSI vs Australia: Correspondent-banking de-risking compared – how UK and Australian obligations interact for banks with dual-jurisdiction exposure.