A mid-sized technology distributor routes a payment through a US correspondent bank. The goods have already shipped. The bank's automated system flags the transaction against a restricted-party database – not because the end customer is listed, but because the underlying export licence for the goods required the distributor to notify BIS before receiving payment in certain circumstances. The payment is held. The distributor's compliance team has never heard of a payment-processing control obligation under the Export Administration Regulations (the EAR, the US Commerce Department's export-control rules administered by the Bureau of Industry and Security, or BIS). They assumed the export licence satisfied every obligation. It did not.
Payment-processing controls under BIS / EAR explained: under the EAR, licences and licence exceptions can impose ongoing conditions that affect how a business collects, processes, and records payments linked to a controlled export. These conditions are distinct from the export transaction itself. Where a business fails to observe them, the resulting apparent violation can attract civil or criminal liability – even when the underlying shipment was fully licensed. As of July 2026, this gap between shipping compliance and payment compliance remains one of the most consistently underestimated exposure areas in cross-border trade.
This analysis sets out the governing authority and legal basis, explains the mechanics of payment-related conditions under the EAR, compares the position under parallel regimes (OFAC, OFSI, and the EU), identifies the risk patterns we most often encounter in practice, and explains when to involve specialist counsel.
What is the governing authority and legal basis?
BIS administers the EAR under the authority of the Export Control Reform Act and IEEPA, and it is BIS – not OFAC – that sets the primary payment-related conditions attached to export licences for controlled items.
The distinction matters immediately. OFAC's mandate is economic and financial sanctions: it targets persons and countries. BIS's mandate is export control: it targets items, technology, software, and – importantly – transactions. A business can be OFAC-clean and still face BIS liability if the payment terms of an approved export licence are not satisfied. The two regimes sit on separate legal foundations, operate through separate agency procedures, and are enforced by separate teams. In our experience, compliance programmes that treat BIS as simply a shipping problem, rather than a transaction-lifecycle problem, systematically leave the payment leg unmanaged.
Controlled exports are assigned an Export Control Classification Number, or ECCN (a code on the Commerce Control List that defines why an item is controlled and under which conditions). An ECCN determines whether a licence is required and, if granted, what conditions attach. Some of those conditions reach forward in time to the receipt of payment, the documentation of the payment, and the reporting of payment defaults or disputes. None of that ends at the port of departure.
How do payment conditions attach to an approved export licence?
When BIS approves a licence for a controlled export, the approval document can carry licence conditions that the applicant must fulfil throughout the transaction – including after delivery and after payment is received.
Common categories of licence condition with payment implications include: requirements to notify BIS if a buyer fails to pay on agreed terms (which can indicate a diversion or re-export risk), obligations to maintain records that link each payment receipt to the authorised export, requirements to obtain written assurances from the consignee before payment is released, and – in more sensitive classifications – conditions requiring the licence holder to confirm end-use before releasing the final instalment. Do not assume that conditions end at the customs declaration.
Licence exceptions under the EAR present an additional complexity. Some exceptions are self-executing: a business that meets defined criteria can proceed without a formal licence. But self-executing exceptions can carry recordkeeping and notification requirements of their own, and a business that relies on an exception without maintaining contemporaneous documentation of eligibility may find, at the point of a BIS audit or an enforcement inquiry, that it cannot demonstrate compliance at the payment stage. The exception was available; the documentation proving it was applied correctly is missing. That gap is a classic enforcement entry point.
The position above covers the standard case. Your specific item classification, your end-user profile, and the jurisdiction of the receiving bank change the analysis materially.
For an initial review of BIS licence conditions applicable to your export programme, contact Calder & Vance at info@caldervance.com.
How does the EAR position compare with OFAC, OFSI, and EU controls?
The EAR payment-processing obligation is item-and-transaction focused; OFAC's equivalent is person-and-property focused – and the interaction of the two creates exposure that neither programme, considered alone, fully reveals.
Under OFAC, a US person (or any person processing a US-dollar payment through a US correspondent) must block or reject a payment that involves a sanctioned party or territory. The obligation fires at the payment itself: the relevant question is whether the funds touch a blocked person or prohibited geography. Under BIS, the obligation fires at the export transaction, and the payment is one element of that transaction that must be documented and – where a licence condition requires – reported. A payment that passes OFAC screening can still breach a BIS licence condition if it arrives in circumstances (wrong instalment structure, wrong bank, wrong timing) that the approved licence did not authorise.
Under OFSI in the United Kingdom, the test for a financial-sanctions breach in a payment context is whether a UK person or a person in the UK is making funds available to, or for the benefit of, a designated person. OFSI's licensing regime allows certain payments to proceed under a specific licence – a case-by-case authorisation to conduct an otherwise prohibited transaction – but the obligation to report knowledge or suspicion of a sanctions breach sits independently of any licence. A business holding an OFSI licence cannot assume that the licence extinguishes the reporting obligation. In our cross-border practice, that distinction surprises clients who have processed a licence application carefully and believe the matter is closed.
The EU position under the relevant Council regulations similarly separates the prohibition from the reporting obligation. A payment by an EU operator to a designated counterparty is prohibited; a payment that inadvertently passes through an account where designated funds are co-mingled triggers a freeze obligation and, in most member states, a competent authority notification requirement. The 50 percent or more ownership threshold applies in both the OFSI and EU contexts to determine whether a non-listed entity is caught: an entity owned or controlled 50 percent or more by a designated person is treated as itself subject to the restrictions. That test is separate from – and additional to – any BIS end-user obligation.
What does this mean in practice? A single cross-border payment can simultaneously engage BIS licence conditions, OFAC blocking obligations, OFSI reporting duties, and EU freeze requirements. The strictest applicable prohibition governs. Compliance counsel working on a transaction must map all four simultaneously – not sequentially.
What are the most commonly missed risk areas?
In advising financial institutions and exporters on payment-processing compliance under the EAR, we regularly encounter the same clusters of error – and they are not the ones that make the headlines.
Instalment structures and partial shipments. A licence may authorise a total transaction value across multiple shipments. Each partial shipment generates a partial payment. Where the shipments and payments are spread across months or quarters, businesses frequently fail to document the mapping: which payment corresponds to which shipment, and whether the aggregate to date remains within the licence ceiling. At audit, that mapping cannot be reconstructed retrospectively. The resulting gap is treated as a failure of record-keeping, which is itself a violation independent of any export breach.
Third-party payment arrangements. In many supply chains, the end customer's payment passes through a trading house, a distributor, or a factoring arrangement. The exporter receives funds from a party that is not the licensed end-user. BIS licence conditions are written on the basis of the named parties in the licence application. When the payment structure diverges from the party structure in the licence, the exporter must confirm that the divergence is permitted – which it sometimes is not, and which is almost never verified in practice.
Returned payments and refunds. When a buyer cancels an order for a controlled item, the exporter processes a refund. That refund is itself a financial transaction connected to a controlled export. Where the original shipment was made under a BIS licence, a refund to a party in a restricted jurisdiction may require separate authorisation. We have seen enforcement inquiries arise from routine refund processing that no one thought to check against the original export authorisation.
Correspondent-bank mismatches. The authorised payment channel in a BIS licence may specify a particular jurisdiction or class of financial institution. A buyer who routes payment through a correspondent in a different jurisdiction – a common occurrence in markets where local banking infrastructure is fragmented – creates a mismatch that the exporter may not notice until a bank flags or holds the transaction. At that point, the issue is not merely administrative.
Record-keeping horizons. The EAR requires exporters to maintain records supporting each controlled transaction. Practitioners advising on BIS matters note that record-keeping obligations extend well beyond the date of shipment. A business that purges payment records on its standard commercial cycle – often three years – may destroy records that BIS would require in an audit of a transaction made several years earlier. The applicable record-keeping period under the EAR is a five-year minimum from the date of the export, not from the date of the most recent payment.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential review.
How does voluntary self-disclosure interact with payment-processing violations?
A voluntary self-disclosure, or VSD, is a proactive disclosure to BIS of an apparent violation, made before BIS initiates an investigation. For payment-processing compliance failures, the VSD mechanism is particularly important because the violation often surfaces through an internal audit or a bank query – not through BIS enforcement action.
BIS treats a timely and complete VSD as a significant mitigating factor in its penalty assessment. This means that a business that identifies a payment-record gap and discloses promptly is in a materially different position than one that waits for BIS to discover the issue. Do not assume, however, that a VSD guarantees any particular outcome. BIS retains full discretion as to the weight it gives a disclosure, the scope of the inquiry it opens in response, and the penalty (if any) it imposes. A VSD that is incomplete, or that omits a related apparent violation on the assumption BIS will not notice, can make the position worse.
OFAC operates a parallel VSD mechanism for apparent sanctions violations, with a similar structure: timely and complete disclosure is treated as a mitigating factor; incomplete disclosure is an aggravating one. Where a single payment transaction generates both a BIS apparent violation (for breach of a licence condition) and an OFAC apparent violation (for a payment touching a sanctioned party), the two disclosures must be coordinated. Filing a BIS VSD without addressing the OFAC dimension – or vice versa – leaves a gap that the second agency may fill by initiating its own inquiry. In our practice, coordinated dual-agency VSDs are more demanding to prepare but produce far more orderly outcomes.
OFSI in the UK operates a mandatory reporting obligation where a person knows or has reasonable cause to suspect a sanctions breach. That obligation is not a VSD in the US sense; it is a statutory duty that cannot be waived by a business decision to stay quiet. The practical effect is that a cross-border business that becomes aware of a payment potentially breaching both BIS licence conditions and UK financial sanctions has, at the same time, a discretionary BIS VSD opportunity and a mandatory OFSI notification obligation. These run on different timescales and require different information. Conflating the two, or handling them through a single process, creates material compliance risk.
In a recent matter: how the gap between shipping compliance and payment compliance emerged
In a recent matter, a specialist industrial-equipment manufacturer had secured a BIS licence for a series of controlled exports to a buyer in a third market. The shipping documentation was meticulous. The internal customs team had been briefed on the licence conditions. But the payment terms – a structured arrangement under which the buyer would pay three instalments over eighteen months – had been negotiated by the commercial team, not the compliance team. The instalment schedule did not correspond to the delivery milestones specified in the licence. When BIS reviewed the transaction in the course of a broader audit, the payment records could not be reconciled against the authorised transaction structure. The manufacturer had exported lawfully. Its payment documentation had not followed the licence.
We assessed the apparent violation, advised on the scope of BIS's likely inquiry, prepared a voluntary self-disclosure that set out the full sequence of events and the corrective measures the manufacturer had implemented, and supported the manufacturer through BIS's review. The matter proceeded under the voluntary self-disclosure process. No outcome is guaranteed from a VSD; but complete and prompt disclosure, paired with demonstrable corrective action, positions a business far better than discovery by the regulator. The manufacturer now requires the commercial team to obtain compliance sign-off before any payment schedule is agreed on a licensed export.
When does payment-processing compliance require specialist counsel, and what does that involve?
The threshold for involving external counsel in a BIS payment-processing matter is lower than most businesses expect. Internal compliance teams are well placed to manage routine screening and standard licence administration. They are less well placed to assess the interaction between BIS conditions, OFAC screening requirements, OFSI reporting obligations, and EU freezing duties in a single cross-border payment – and it is precisely at that intersection that enforcement actions arise.
Counsel adds most value at three points. First, at the design stage: when a new export programme is being structured, before the first licence application is submitted and before the commercial team negotiates payment terms. A well-drafted payment structure that is aligned with the export licence from the outset prevents the vast majority of the risk patterns described above. Second, at the alert stage: when a bank flags or holds a payment, or when an internal audit surfaces a documentation gap. Speed matters here, because voluntary self-disclosure options have their own timescales, and because the steps taken in the first days after discovery affect what options remain available. Third, at the enforcement stage: when BIS or OFAC has opened an inquiry or issued a subpoena, and the business must decide whether to cooperate, how to scope its disclosure, and how to present corrective-action evidence.
At Calder & Vance, we classify the item, confirm licence requirements and exceptions, and design the end-use controls. For payment-processing work specifically, we map the payment structure against the licence conditions, identify documentation gaps, and – where a gap has already occurred – scope the apparent violation, advise on voluntary self-disclosure, and prepare the penalty defence. We also assess secondary-sanctions risk under OFAC and cross-regime reporting obligations under OFSI and the EU, which are often relevant to the same payment.
A common misconception in this space is that BIS payment-processing controls apply only to defence-sector or dual-use goods of obvious strategic sensitivity. That is not the position. The EAR's reach extends to a wide range of commercial technology, software, and commodities that businesses do not think of as export-controlled. A standard-grade semiconductor, a routine software update delivered by electronic download, or a commercial chemical product can each carry an ECCN that brings payment conditions into scope. The question is not whether the item seems sensitive; it is what ECCN applies. Where an item has not been formally classified, a business cannot assume it is EAR99 (the catch-all designation for items not specified on the Commerce Control List), particularly where the buyer is in a jurisdiction subject to heightened end-user scrutiny.
Related practices
- Compliance audit and testing (Australia) – systematic review of sanctions and export-control screening controls and record-keeping.
- Payment-processing controls: Canada – how Canadian sanctions and export-control rules interact with cross-border payment obligations.
- Payment-processing controls: EU – Council-regulation obligations, EU freeze procedures, and reporting requirements for cross-border payments.