A technology exporter finalises a licensing agreement with a buyer in a third market. The deal is structured with a milestone-based escrow: funds released on delivery of each software build. The export-control team classifies the item, checks the Entity List (BIS's list of parties subject to heightened licence requirements under the Export Administration Regulations), and clears the buyer. The deal proceeds. Then, eighteen months later, a routine internal audit flags that the escrow bank itself – not the buyer – sits in a jurisdiction subject to EU restrictive measures. The payment structure is suddenly a compliance problem on two separate continents, under two separate regimes, with different legal bases, different enforcement authorities, and different ideas about what "structured correctly" means.
Payment and escrow structuring under the BIS / EAR (the US Bureau of Industry and Security's Export Administration Regulations) turns primarily on whether the payment mechanism facilitates a controlled transaction – who is paying, what they are paying for, and whether any intermediate financial institution triggers a licence requirement or an end-use concern. The EU's parallel regime, built around Council regulations and administered through national competent authorities, applies a different analytical lens: it focuses on whether the financial arrangement provides funds or economic resources to a designated person, or enables a prohibited transaction, regardless of who formally issues the payment instruction. As of early 2026, cross-border businesses routinely underestimate how differently these two bodies of law treat the same escrow structure.
This analysis maps the divergences that matter most, identifies the risk flags that in-house teams miss, and sets out the practical questions counsel needs to answer before a structured payment closes.
What does the BIS / EAR actually regulate in a payment context?
The EAR governs the export, re-export, and in-country transfer of US-origin items and technology, and its reach into payment structuring is indirect but consequential. BIS does not regulate payments as such. What it regulates is the controlled transaction – and a payment structure that facilitates that transaction without the required authorisation can render the entire arrangement a violation.
The key mechanism is the Export Control Classification Number (ECCN – the alphanumeric code under the US Commerce Control List that determines whether an item needs a licence and for what destinations). If the underlying goods or technology carry an ECCN that requires a licence for the destination country, then an escrow arrangement that releases funds on delivery of those goods is – functionally – a payment for a controlled transaction. Whether the escrow bank is a US institution or a foreign one caught by the EAR's extraterritorial reach matters enormously. Under the EAR, foreign persons can become subject to its provisions when they deal in US-origin items or items incorporating US content above a defined de minimis threshold. The escrow bank that holds the funds, the trustee that manages release conditions, and the correspondent bank routing the wire can all be drawn into the analysis.
In our experience, businesses structure payment milestones carefully around delivery and acceptance events, but they rarely map those milestones against the moment of "export" as BIS defines it. Technology can be "exported" when it is transmitted electronically, when access is granted, or when a foreign national in the United States receives it. The payment trigger in the escrow may fire after any of these events. If the licence was not in place at the moment of the controlled transfer, the post-transfer payment does not cure the prior violation – it compounds it.
The position above covers the standard case. Your facts – the item classification, the buyer, the escrow bank's jurisdiction, and the payment routing – change the analysis entirely.
For a confidential review of a potential exposure under the EAR or a related OFAC question on the same transaction, contact Calder & Vance at info@caldervance.com. Our cross-border practice covers both regimes under one engagement.
How does the EU restrictive-measures regime treat the same escrow?
The EU approach to payment and escrow structuring operates through a fundamentally different legal concept: the prohibition on making funds or economic resources available, directly or indirectly, to or for the benefit of designated persons. This prohibition, found in the relevant Council regulations for each regime, does not require that the payment be for a controlled item. It requires only that the designated person benefits from the arrangement.
That framing catches structures that pass cleanly through the BIS / EAR analysis. Consider an escrow held for the benefit of a joint-venture company. The EAR analysis might focus on the goods being delivered under the contract. The EU analysis asks a different question: does any listed person hold an interest in the escrow beneficiary or in the distributions the escrow generates? Under the EU's ownership and control test (the test that treats non-listed entities as subject to the asset-freeze prohibition when a designated person owns or controls them), the answer can be yes even if the listed person is not named on the instruction.
The divergence sharpens further when you consider what "economic resources" means under EU law. Unlike assets – cash, securities, receivables – economic resources are things that can be used to obtain funds. A contractual right to receive milestone payments from an escrow is an economic resource. If a designated person can reach that right, the escrow arrangement may itself contravene the asset-freeze prohibition, not merely the specific-item prohibitions of the goods-focused regime.
National competent authorities within the EU apply these rules. Enforcement posture varies by member state, and a licence or authorisation granted by one authority does not automatically satisfy the requirements of another. In our cross-border practice, we regularly advise clients on structures that have been cleared in one EU jurisdiction only for a correspondent bank in a second jurisdiction to block the payment on a different domestic interpretation of the same regulation.
Where do the two regimes diverge most sharply?
The deepest divergence is between an item-centred regime and a person-centred regime. The EAR asks: is this controlled goods or technology leaving the United States or being re-exported with US content? The EU regime asks: is this person, or any entity that person owns or controls, receiving a benefit from this transaction? Those questions can be answered independently, and the transaction can fail one test while passing the other.
Four specific divergences create the highest cross-border risk.
The trigger event. Under the EAR, the compliance obligation attaches to the transfer of the controlled item. Under the EU regime, it attaches to the making-available of funds or economic resources to a designated person or an entity they own or control. A payment that is made after delivery, held in a third-country escrow, and released only after acceptance might satisfy the EAR requirement – but if the escrow beneficiary is subject to the EU prohibition, the release event triggers the EU obligation regardless of delivery timing.
The extraterritorial reach. The EAR applies to US-origin items and, through the Foreign Direct Product Rule (the rule that brings certain foreign-made goods within the EAR's reach when they are produced using US-origin technology or equipment), to a wider class of goods than many non-US businesses anticipate. The EU regulations apply to all persons within the EU, to EU-flag vessels and aircraft, and to EU nationals anywhere in the world. A payment routed through a Frankfurt correspondent bank is therefore subject to EU restrictive measures regardless of whether the goods are US-origin. The intersection of these two extraterritorial regimes is where most cross-border structuring errors originate.
Ownership thresholds and control. The EAR does not have an equivalent of the EU's ownership and control test for payment prohibitions in the way OFAC's 50 percent rule (the rule that treats entities owned 50 percent or more by blocked persons as themselves blocked) operates for OFAC sanctions. BIS focuses on the end-user, not the ultimate beneficial ownership of the payment recipient. The EU test is more expansive: control can be established through board appointment rights, contractual veto rights, or any mechanism that effectively places the designated person in a position to direct the entity's activities. A buyer structured to keep a listed shareholder just below a simple majority may still be caught.
Licensing and authorisations. A BIS licence for an export does not authorise the associated payment under EU law. A specific EU authorisation to make funds available does not cure an EAR licence requirement. The two systems run in parallel, and cross-border businesses must ensure they hold the required authorisation under each regime independently.
If a transaction has already been flagged – by a bank, by a screening hit, or by a compliance review – early advice can preserve options that become narrower with time. Write to us at info@caldervance.com.
What do businesses typically miss when structuring cross-border payments?
Three structural misses account for the majority of compliance failures we see in cross-border payment and escrow work.
The first is treating export-control clearance as payment clearance. A valid BIS licence for the underlying transaction does not authorise the payment mechanism under any other regime. It does not authorise the payment under OFAC's sanctions programmes. It does not authorise the payment under EU restrictive measures. Export-control counsel and sanctions counsel are solving different legal problems, even when the transaction is the same. In our experience, deals are sometimes closed with only one leg of this analysis completed.
The second miss is the correspondent-banking chain. An escrow is not just a contract between a buyer and a seller. It involves a custodian bank, often a trustee, frequently one or more correspondent banks for wire transfers, and sometimes a letter-of-credit issuing bank sitting behind it. Each institution has its own compliance obligations. Each will apply its own screening. If any institution in the chain identifies a sanctions concern – under any regime it is subject to – the payment can be frozen, returned, or blocked. The business learns about the problem not from its own compliance process, but from the bank. That is not a good way to discover a compliance gap. Our work on cross-border transactions includes mapping the full correspondent chain before close; you can read more about our approach to correspondent banking and de-risking.
The third miss is the escrow release condition. Businesses spend considerable time negotiating the conditions under which escrow funds are released. They spend much less time asking whether the release event itself is compliant. If the release condition is tied to the delivery of a controlled item, the release is – legally – part of the controlled transaction. It needs to be authorised under the EAR. If the release condition is tied to the acceptance of a service provided by an entity that a designated person controls, the release may be a making-available of economic resources under EU law. Drafting the release condition without reference to the regulatory analysis is a common source of post-signing problems.
A related gap is the handling of disputed escrow funds. If a dispute arises and the funds sit in escrow pending resolution, the question of who "holds" the funds for EU law purposes – and whether the passage of time changes the characterisation of the escrow – is not a theoretical one. We have acted in matters where funds held for more than a year in a third-country escrow attracted regulatory scrutiny under EU law because the ultimate beneficial entitlement was contested and potentially linked to a designated person.
How should a business structure payments and escrow for a dual-regime transaction?
The starting point is to map the transaction across all applicable regimes before structuring the payment. That means identifying whether the underlying goods or technology carry an ECCN that creates an EAR licence requirement, whether any party to the transaction – buyer, intermediary, financial institution, ultimate beneficial owner – is on any relevant sanctions list, and whether the payment routing involves any jurisdiction subject to heightened measures under the EU, OFAC, or BIS.
From that map, a decision sequence follows.
Where the goods are EAR-controlled and a BIS licence is required, the payment structure must be contingent on licence receipt. The escrow agreement should include a condition precedent: no funds are released until the relevant export authorisation is in place and the export has been completed consistently with its terms. End-use certifications and post-shipment verification requirements that come with a BIS licence need to be reflected in the payment milestones.
Where EU restrictive measures are relevant – because the buyer, the beneficiary, or the payment institution is within EU jurisdiction, or because an EU-regulated bank is in the correspondent chain – a separate EU analysis is required. That analysis must address: whether any party to the escrow is designated or is owned or controlled by a designated person under the relevant EU regime; whether the transaction requires a specific authorisation from a national competent authority; and whether the escrow custodian is in a position to discharge its own obligations if a listing event occurs during the life of the escrow.
In a recent matter, a manufacturing business structured an escrow for a multi-year supply agreement with a buyer in a third market. The escrow was held by a bank in a neutral jurisdiction. Partway through the agreement, a shareholder of the buyer was listed under the relevant EU regime. We were engaged to assess whether the listing event triggered an obligation to freeze the escrow balance, whether the remaining payment obligations under the supply agreement could continue, and whether the escrow bank was exposed under the EU rules. The analysis turned on the control test: whether the newly listed shareholder could be said to control the buyer. We assessed the ownership structure, the shareholder agreement, and the board composition. The conclusion was that the control test was not met – but the escrow bank needed its own legal basis for continued operation, and a specific authorisation was required from the relevant national authority before the next scheduled release. The authorisation was obtained. The payment proceeded. No guarantee of that outcome exists in a different set of facts; the point is that the analysis needed to happen before the release date, not after.
The decision matrix, in brief: if the transaction involves EAR-controlled items and EU-regulated counterparties, run both analyses independently and obtain all required authorisations before the payment milestone. If the transaction is clean under the EAR but involves a correspondent bank subject to EU jurisdiction, assess the EU exposure through the correspondent-bank chain. If a listing event occurs during the life of the escrow, treat it as a day-one compliance event, not a transactional afterthought.
What risk flags should compliance teams monitor?
The risk flags that practitioners should build into ongoing monitoring – not just pre-close due diligence – cluster around four areas.
Ownership changes in the counterparty. A buyer that is clean at the time of signing can become subject to the EU ownership and control test if a listed person acquires a stake during the life of the escrow. Under EU law, a listing event during a contract does not automatically extinguish the contract, but it does trigger an obligation to assess whether continued performance – including future payment milestones – amounts to making funds available to a designated person. Under the EAR, a change in end-user can trigger a licence condition that was not present at the time of original clearance. Monitoring frameworks should include triggers for ownership changes, not just list-screening of the original counterparty name.
Correspondent bank changes. Banks restructure their correspondent relationships. A wire that transited through a New York correspondent at signing may transit through a different institution eighteen months later. If that institution has a stricter sanctions policy – as many do following regulatory pressure – it may block a payment that has been flowing without incident. The business learns of the change only when the payment is stopped. Including a requirement in the escrow agreement for the counterparty to notify any change in its settlement bank is a simple and underused protection.
Technology transfer embedded in delivery. Software updates, technical data, and services associated with the original supply often continue after the initial delivery. Each of these continuing transfers may carry an independent EAR classification obligation. If the original export licence was limited to the initial delivery, subsequent transfers of technical data – even those incidental to warranty or maintenance obligations under the contract – may require separate authorisation. The escrow should not release payment for continuing services without a corresponding export-control clearance for the associated technology transfer.
Divergence between OFAC and BIS postures on the same transaction. A transaction that receives OFAC general-licence cover may still require a BIS export licence. A specific BIS licence does not provide OFAC authorisation. In our cross-border practice, we regularly see in-house teams assume that a clearance from one US agency is a clearance from the other. It is not. For a comparative view of how OFAC and BIS interact on the same transaction, see our analysis of payment structuring under OFAC vs BIS / EAR, and for the parallel EU-OFAC picture, our OFAC vs EU payment structuring analysis sets out where those regimes converge and diverge.
A common myth: "The escrow is neutral – it does not move funds until we instruct it"
One objection that surfaces regularly in structuring conversations is the argument that a properly drafted escrow is "neutral" – that because the funds do not move until a release instruction is given, no prohibited transfer has occurred. The business controls the timing; it can simply not instruct release if there is a compliance concern. This logic is appealing. It is also legally incorrect in both regimes.
Under EU law, the act of depositing funds into an escrow for the benefit of a party that turns out to be a designated person – or an entity that designated person controls – can itself constitute making funds available. The availability of the funds to that party, even before the release instruction is given, can engage the prohibition. The escrow mechanism does not create a compliance buffer; it may simply be where the prohibited act occurs.
Under the EAR, the analysis is different but equally unfavourable to the "neutral escrow" position. If the escrow funds are held as consideration for a controlled transaction that requires a licence, and no licence exists, the absence of an instruction to release does not undo the fact that the controlled transfer has already occurred – or that the payment obligation, now contractually crystallised, is part of the unlicensed transaction. BIS's enforcement guidance indicates that willingness to look at the totality of the transaction, including payment arrangements, as part of an export-control violation assessment.
We regularly advise boards and compliance committees on this specific misconception. The correction matters not because escrow is a bad structure – it is often the right one – but because the compliance work needs to be done before the escrow is established, not managed retrospectively through the release mechanics.
Related practices
- Correspondent Banking and De-risking – sanctions-driven bank withdrawal, screening, and re-engagement strategy
- OFAC vs BIS / EAR: payment structuring analysis – how the two US regimes treat the same cross-border payment
- OFAC vs EU: payment structuring analysis – divergence between US and EU approaches to structured payments