Calder & Vance International Sanctions & Compliance Counsel

Licensing & Authorizations · BIS / EAR

BIS / EAR vs EU: Payment authorisations: the key divergences

A payment instruction arrives at a correspondent bank. The beneficiary is a legitimate trading company. But its goods were classified under the Export Administration Regulations, the transaction touches a restricted end-user, and the question of whether a payment authorisation is required – and from which regulator – has not been resolved. Under the US Bureau of Industry and Security regime, that question may carry criminal exposure. Under EU export-control rules, the answer may be different, and the procedural route diverges sharply.

Payment authorisations under BIS / EAR (the Bureau of Industry and Security's Export Administration Regulations, the primary US export-control instrument) and under EU export-control rules operate through fundamentally different legal architectures. The BIS / EAR ties authorisation requirements to the Export Control Classification Number of the item and the end-use and end-user controls; the EU regime applies a dual-use classification system under Council Regulation and requires separate national-competent-authority licensing in each Member State. As of May 2026, the two regimes share no mutual-recognition arrangement, and a payment that is authorised under one regime is not thereby authorised under the other.

This analysis maps the key divergences across six dimensions: legal basis and governing authority, the classification and authorisation trigger, the procedure for obtaining a payment authorisation, cross-border and extraterritorial reach, risk flags that practitioners see in cross-border transactions, and the practical approach for a business caught between the two regimes. The related OFAC comparison is addressed separately.

Legal basis and governing authority: where the two regimes start from different foundations

The BIS / EAR derives its authority from the Export Control Reform Act and IEEPA; the Bureau of Industry and Security administers the regime through the Commerce Control List and maintains the Entity List as a supplementary control. The EU dual-use regime is founded on Council Regulation and is given domestic effect through the implementing regulations of each Member State; the European Commission coordinates, but licensing decisions are made at the national level by each Member State's competent authority.

That structural difference has immediate practical consequences for payment authorisations. Under the BIS / EAR, a single application goes to BIS in Washington. Under the EU regime, a business operating across multiple Member States may need to engage several national authorities – the relevant body in, say, Germany, France, or the Netherlands – for what is commercially the same transaction. There is no EU-wide single-window for export-control licensing that covers financial flows associated with controlled goods.

The scope of what is controlled also differs at the foundation level. BIS uses the ECCN (Export Control Classification Number under the US Commerce Control List) to define what requires a licence. The EU dual-use regime uses its own classification annexes. Mapping between the two lists is possible but imperfect; an item classified under one system does not automatically map to an equivalent classification under the other. In our cross-border practice, the mismatch in classification is the single most common source of missed authorisation requirements on payment flows.

How does the authorisation trigger work under each regime?

Under the BIS / EAR, the authorisation trigger for a payment associated with a controlled-goods transaction is determined by three questions: what is the ECCN of the item; what country does it go to; and who is the end-user? The Commerce Control List sets out the combinations of ECCN, destination, and end-use that require a licence. The Entity List adds a separate layer: where the end-user appears on the List, a licence is required regardless of the ECCN, and BIS has the authority to impose a licence policy of "presumption of denial".

The EU regime applies a parallel but structurally distinct trigger. The basic control categories in the EU annexes correspond broadly to multilateral control-list categories, but the EU also operates a catch-all control: even an item not listed in the annexes may require a licence if the exporter has been informed, or is aware, that it is intended for a prohibited end-use. That catch-all is broader in practice than the BIS end-use controls, which are more specifically defined. Is your transaction team checking the EU catch-all as well as the formal classification list?

For payments specifically, the BIS / EAR analysis typically runs through the underlying goods transaction: if the export of the goods requires a licence, the financial flow that funds it is also subject to control, and facilitating a prohibited export – including processing a payment – can constitute a violation. The EU regime takes a similar integrated view of the goods and financial transaction, but the precise mechanics of how a payment falls within a Member State's export-control jurisdiction vary by national implementation.

What is the procedure for obtaining a payment authorisation under BIS / EAR compared with the EU?

Under the BIS / EAR, a business seeking authorisation for a payment associated with a controlled export applies directly to BIS for a licence. The application is submitted through SNAP-R (the electronic licensing system). BIS applies a review process that may involve interagency consultation, and the agency's published guidance indicates that licence applications are reviewed on a case-by-case basis; processing times are variable and depend on the commodity, the destination, and the end-user. There is no published statutory deadline for BIS to determine a licence application, and in our experience processing times can range from weeks to several months for complex or sensitive items.

The EU procedure is fragmented by design. Each Member State competent authority operates its own application process, its own assessment criteria, and its own timelines. A payment authorisation tied to an export from Germany is handled by the relevant German authority; the same transaction originating in France is assessed by the French authority. The legal basis – the EU Council Regulation – is uniform, but its application is not. Businesses engaged in multi-country supply chains or trade-finance structures routinely encounter different decisions from different Member State authorities on materially similar fact patterns.

One critical procedural divergence concerns general authorisations (standing instruments that permit defined categories of transactions without a case-by-case application). The BIS / EAR issues licence exceptions – standing regulatory provisions that authorise specific categories of exports, re-exports, and in-country transfers without a specific licence application. The EU regime provides EU General Export Authorisations for certain destinations and categories of goods, but their scope is narrower and their availability is not uniform across all Member States. Where a BIS licence exception covers a transaction, the EU general authorisation may not, and the business must identify which instrument, if any, applies under each regime independently.

The position above covers the procedural framework. Your facts – the counterparty, the goods classification, the route, and the regime in play – change the analysis significantly. For a preliminary assessment of whether a specific payment requires a BIS or EU authorisation, contact Calder & Vance at info@caldervance.com.

Extraterritorial reach: how far does each regime extend over payments?

The BIS / EAR has significant extraterritorial reach. The de minimis rule treats foreign-made items as subject to the EAR when they incorporate a threshold level of US-origin controlled content; the foreign-direct product rule extends EAR jurisdiction to certain foreign-made products that are the direct product of US technology or software. Both rules can bring payments made outside the United States, by non-US parties, within the scope of BIS jurisdiction. A European bank processing a payment for a foreign buyer of goods that contain US-origin components above the applicable threshold may, depending on the facts, be processing a transaction subject to the EAR.

The EU dual-use regime's extraterritorial scope is more limited. The EU regime applies to exports from EU territory and, in certain circumstances, to the brokering of controlled items by EU persons. It does not generally assert jurisdiction over transactions between two non-EU parties for goods that do not pass through EU territory. That asymmetry matters. A payment processed through a bank with no EU presence, for goods with no EU connection, may be outside EU jurisdiction but still subject to BIS jurisdiction if US-origin content or US technology is involved.

Secondary-sanctions risk adds another layer. While BIS / EAR is primarily a direct-controls regime rather than a secondary-sanctions regime, violations of the EAR can trigger US DOJ criminal referrals and can interact with OFAC measures – particularly where a controlled export involves a designated person or a jurisdiction subject to comprehensive OFAC measures. A payment that is BIS-authorised is not automatically OFAC-cleared, and the OFAC analysis must run separately. We regularly advise financial institutions on exactly this parallel-analysis obligation.

Risk flags in cross-border payment flows: where violations occur in practice

Practitioners working across both regimes see a consistent pattern of risk flags. The first is classification gap: a goods transaction is classified under one regime but not cross-checked under the other, and the payment proceeds on the assumption that a single authorisation covers the full transaction. It does not. Each regime requires its own analysis, and the BIS / EAR and EU classification systems do not map precisely.

The second risk flag is entity-list exposure. The BIS Entity List and the EU asset-freeze lists are maintained independently. An entity that does not appear on the EU lists may appear on the BIS Entity List – and a payment to that entity for goods, even goods not requiring a licence under the EU annexes, may require a BIS licence. Screening programmes that consult only EU or OFAC lists without running a BIS Entity List check leave this risk unaddressed.

A third risk flag is the catch-all trap. A payment for goods that are not formally listed under either the BIS Commerce Control List or the EU dual-use annexes may still require authorisation if the transaction involves a prohibited end-use. The EU catch-all is triggered by actual or constructive knowledge of the end-use; the BIS end-use controls attach similar obligations. Financial institutions processing payments without end-use visibility – which is common in correspondent-banking chains – are exposed to this risk without necessarily having the information needed to assess it.

Finally, there is the licence-exception mismatch. A BIS licence exception that permits a US exporter to proceed without a specific licence does not create any permission under EU law. A counterpart EU General Export Authorisation does not create any permission under the EAR. Each authorisation instrument is regime-specific, and relying on one to cover obligations under the other is a structural error we see regularly in cross-border trade-finance reviews.

If a transaction has already been flagged, or a payment has been refused or frozen pending licence review, early engagement can preserve options that narrow with time. For a confidential review of a specific payment or transaction, contact Calder & Vance at info@caldervance.com.

Is one regime stricter? A practical comparison for compliance teams

Framing this as a strict-versus-lenient comparison misses the more important point: the two regimes are strict in different directions, and a transaction can be outside the scope of one while firmly inside the scope of the other. That said, there are clear practical asymmetries that compliance teams need to understand.

The BIS / EAR is structurally more expansive in two respects. First, its extraterritorial reach through the de minimis and foreign-direct product rules means that transactions with no US party and no US territory connection can still be subject to EAR jurisdiction. Second, the Entity List creates a universal licence requirement that overrides the classification-based analysis: once a counterparty is listed, the ECCN of the goods is largely irrelevant, and a licence – almost always subject to a presumption of denial – is required.

The EU regime, by contrast, applies a catch-all that is broader in knowledge-based scope: the obligation to apply for a licence can arise from what the exporter knows or has reason to know about the end-use, even for unlisted items. In practice, this places a heavier burden of due diligence on EU exporters in transactions where end-use information is incomplete or ambiguous. Under the BIS / EAR, the end-use controls are more specifically defined; under the EU regime, constructive knowledge of a prohibited end-use can trigger the obligation.

For a payment-processing institution, the practical conclusion is that both regimes must be assessed independently and in parallel. Neither regime's authorisation covers the other, and the question "do we have a licence?" must be asked twice – once under each regime – before a payment associated with controlled goods can proceed.

A common misconception – and what the rules actually require

A widely held belief among cross-border businesses is that obtaining a BIS licence covers the payment from a regulatory standpoint, and that EU authorisation is relevant only for physical exports originating in the EU. This is incorrect on both counts.

The BIS authorisation covers the US export-control obligation. It does not address EU obligations arising from the goods classification under EU law, EU catch-all obligations arising from end-use knowledge, or Member State licensing requirements that apply to a parallel export leg originating from EU territory. A multinational with supply chains that involve both US-origin goods and EU-based entities routinely has obligations under both regimes for the same commercial transaction.

Equally, the assumption that EU licensing is handled entirely at the EU level – and that one application covers all Member States – is a structural misunderstanding of the EU regime. The Council Regulation sets the legal basis, but the licensing decision is taken at the national level. A business that has obtained a licence from one Member State competent authority has not thereby obtained authorisation for a parallel export or financial transaction originating in a different Member State. In our experience, this misconception causes compliance gaps in multi-country supply chains where the payment-processing leg and the goods-dispatch leg originate from different EU jurisdictions.

How Calder & Vance advises on cross-regime payment authorisations

Our approach to cross-regime payment authorisation matters runs in four stages. We first classify the goods and map the applicable controls under both the BIS / EAR Commerce Control List and the relevant EU dual-use annex, identifying any divergence in classification or in the authorisation trigger. Second, we assess entity-level exposure across the BIS Entity List, the EU asset-freeze lists, and the OFAC SDN List, identifying any list-specific licence requirement that overrides the classification-based analysis. Third, we identify the applicable authorisation instruments – BIS licence exceptions, EU General Export Authorisations, and any available specific-licence route – and advise on which instruments are available, which applications must be filed, and with which authorities. Fourth, where a specific-licence application is required, we prepare and submit the application, manage the regulator's queries, and advise on structuring the transaction to comply with any conditions attached to the authorisation.

In a recent matter, a financial-services group with correspondent-banking relationships in multiple jurisdictions was processing payment flows for a client whose goods were subject to dual classification – falling within both the BIS Commerce Control List and EU dual-use annexes. The group had obtained BIS clearance for the US-origin component but had not assessed the EU position. We mapped the dual classification, identified the applicable EU General Export Authorisation for part of the transaction and a Member State licensing requirement for another leg, prepared the national-authority application, and advised on interim payment-flow structuring during the licence-pending period. The matter resolved without enforcement exposure.

Related practices

Frequently asked questions

Where do the regimes diverge on payment authorisations?
The BIS / EAR and EU regimes diverge on legal basis, authorisation trigger, procedure, and extraterritorial reach. BIS applies a single federal authority with list-based and end-use triggers; the EU applies national-competent-authority licensing in each Member State, with a broader catch-all based on end-use knowledge. BIS licence exceptions do not create EU authorisations, and EU General Export Authorisations do not satisfy BIS requirements. Classification mapping between the two systems is imperfect, and a transaction may require authorisation under one regime but not the other, or under both simultaneously. Each regime must be analysed independently.
Which regime is stricter on payment authorisations?
Neither regime is uniformly stricter. The BIS / EAR is broader in extraterritorial reach – the de minimis and foreign-direct product rules can bring non-US transactions within EAR jurisdiction – and the Entity List creates a near-universal licence requirement for listed counterparties. The EU catch-all control is broader in knowledge-based scope: constructive knowledge of a prohibited end-use can trigger an EU licensing obligation even for unlisted items. Compliance programmes must assess both regimes in parallel. A transaction outside BIS scope may be within EU scope, and vice versa, depending on the origin of the goods, the parties, and the route.
What should a cross-border business do about payment authorisations?
A cross-border business should run classification checks under both the BIS Commerce Control List and the relevant EU dual-use annex before processing a payment for controlled goods. It should screen counterparties against the BIS Entity List as well as EU and OFAC lists. It should identify applicable licence exceptions and general authorisations under each regime independently. Where a specific licence is required under either or both regimes, it should apply before the payment proceeds. Where the position is unclear, it should seek legal advice before proceeding. Verify the current position under both regimes before relying on any general statement.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.