A payment firm processing cross-border transactions receives an automated alert: a beneficiary's name matches a string on a watchlist. The compliance officer pauses the transfer. But which regime governs? Is this an OFAC matter – a question of whether funds touch a blocked person or a comprehensively sanctioned territory? Or does the Export Administration Regulations regime administered by the Bureau of Industry and Security also apply, because the payment is financing the transfer of controlled technology? The two regimes run in parallel. Neither pre-empts the other. And the interaction between them is exactly where businesses make consequential errors.
Payment-processing controls under OFAC prohibit the processing of transactions that involve blocked persons, blocked property, or comprehensively sanctioned jurisdictions, regardless of where in the transaction chain the processing firm sits. The BIS / EAR layer adds a separate but overlapping obligation: payments that finance, facilitate, or are otherwise integral to the export, re-export, or in-country transfer of controlled items can independently trigger export-control liability. As of July 2026, enforcement across both regimes confirms that the stricter prohibition governs wherever the two regimes interact – and that most payment-processing failures arise from treating them as alternatives rather than cumulative obligations.
This analysis sets out the governing authority for each regime, maps the points of divergence and convergence, identifies the practical risk flags that payment processors and their corporate clients most consistently miss, and explains when to involve sanctions counsel.
What authority governs payment-processing controls under OFAC?
OFAC's authority to impose payment-processing controls derives from IEEPA and, for older programmes, TWEA. Those statutes authorise the President to block transactions and property in which a designated person or a comprehensively sanctioned country has any interest. OFAC then issues programme-specific regulations that translate the blocking authority into operational prohibitions. For payment processors, the key consequence is that the prohibition runs to any person in the transaction chain – originating bank, correspondent, intermediary, payment platform, and beneficiary institution – not only to the direct counterparty.
The SDN List (OFAC's list of Specially Designated Nationals and blocked persons) is the primary screening reference. Any payment in which a listed person has any interest, however indirect, must be blocked and reported. OFAC's guidance on the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) extends this: a payment to a company that is majority-owned by an SDN is itself a blocked transaction, even if the company is not on the list. 50 percent or more of ownership by one or more blocked persons – aggregated across direct and indirect holdings – is the trigger.
The position above covers the standard case. Your facts – the counterparty, the goods or services being financed, the routing, the regimes in play – change the analysis significantly. For an assessment of your payment-processing exposure under OFAC, contact Calder & Vance at info@caldervance.com.
How does BIS / EAR payment-processing liability arise?
BIS administers the Export Administration Regulations under the Export Control Reform Act. EAR liability in the payment context is less widely understood than OFAC exposure, yet it catches financial intermediaries and payment platforms with significant frequency. The route is financing: where a payment facilitates the export, re-export, or transfer of an item that is controlled under the Commerce Control List – including software, technology, and certain financial-services technology – the payment processor can be a party to an EAR violation.
The key concepts are the Entity List (BIS's list of persons subject to heightened export-licensing requirements) and the concept of a deemed export (the release of controlled technology to a foreign national, treated as an export to that person's home country). A payment platform that processes transactions funding software licences or cloud-service access for Entity List parties may independently face BIS scrutiny, even if OFAC has no concurrent objection.
The ECCN (Export Control Classification Number under the US Commerce Control List) of the underlying goods or technology is therefore relevant to every payment processor that handles transactions for technology vendors, defence-related businesses, or cross-border software distribution. In our cross-border practice, we regularly advise payment platforms that have strong OFAC screening programmes but no visibility into whether the underlying transaction involves EAR-controlled items – a gap that BIS enforcement has been willing to exploit.
Where do the two regimes diverge on payment-processing controls?
The regimes diverge on four dimensions that matter operationally: the trigger, the legal standard, the licence route, and the record-keeping obligation.
Trigger. OFAC's trigger is transactional: is a blocked person or blocked property involved in this payment? The question is entity-based. BIS's trigger is commodity-based: is this payment financing the movement or access of a controlled item? The same payment can satisfy both triggers, one only, or neither. Where it satisfies both, both regimes apply and the stricter prohibition governs.
Legal standard. OFAC applies a strict liability standard to most sanctions violations. A payment processor that unknowingly routes funds to an SDN can still face civil liability. BIS maintains a similar strict liability standard for certain violations, but also applies a knowledge-based standard for others: a person who knows or has reason to know that an export will violate the EAR bears EAR liability. For payment processors, this creates an asymmetry. OFAC exposure can arise even from a technically clean screening process that missed a de-listed-but-re-designated name. BIS exposure may require evidence of constructive knowledge about the end use.
Licence route. An OFAC specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) or a general licence (a standing authorisation that permits a defined category of transactions without a separate application) can authorise an otherwise blocked payment. The BIS licence process is separate and is submitted to a different agency. Holding an OFAC licence does not mean BIS has authorised the associated export transaction. We have acted for clients who obtained OFAC authorisation in good faith, then faced a BIS inquiry because the underlying goods required a separate export licence that was never applied for.
Record-keeping. Both regimes impose record-keeping requirements. For EAR purposes, businesses must retain records relating to export transactions for a prescribed period; under OFAC, records relating to blocked property and rejected transactions must be retained and reported. The periods and the required content differ. A compliance programme that satisfies OFAC's record-keeping requirements may not satisfy those of BIS.
What does the cross-border picture look like beyond OFAC and BIS?
For any payment processor with cross-border operations, the US regime is rarely the only relevant one. OFSI – the UK's Office of Financial Sanctions Implementation – administers financial-sanctions rules under SAMLA and the relevant thematic regulations. OFSI's ownership and control test differs from OFAC's: it includes a control limb, meaning a company that is controlled by a designated person can be caught even if the 50 percent ownership threshold is not met. A payment that is clean under OFAC's mechanical 50 percent rule may still be prohibited under OFSI's broader ownership and control (the UK and EU test for whether a non-listed entity is caught through a listed person) standard.
The EU regime operates similarly. Council regulations implement a control test alongside the ownership threshold. The EU General Court has confirmed that control – through contractual, economic, or other dependency – can bring a non-listed entity within the prohibition independently of ownership percentage. A payment from a eurozone correspondent therefore needs to be assessed against EU Council regulations, not OFAC rules, and the two assessments may reach different conclusions on the same counterparty.
For Singapore, Japan, the UAE, and Australia, the applicable country regime adds further layers. None of these regimes simply mirrors the US position, and none automatically excludes transactions that OFAC has licensed. In our experience, payment businesses that rely on a single OFAC-focused screening system as their entire compliance programme are systematically under-screening against the UK, EU, and Asia-Pacific regimes – often without realising the gap exists.
If a transaction has already been flagged, or a payment has been blocked and the business is uncertain which regime applies, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com.
What are the risk flags payment processors most commonly miss?
The most consequential gaps in payment-processing compliance are structural, not transactional. They arise not from a single missed name but from the design of the compliance architecture itself.
Nested ownership chains. Screening against direct counterparty names does not satisfy the 50 percent rule if blocked persons hold majority ownership through intermediate vehicles. The rule requires aggregation across all layers. A payment processor that screens the named beneficiary but does not look through to ultimate beneficial ownership will miss exactly the cases that OFAC's rule was designed to capture.
Technology-layer payments. Software-as-a-service subscription payments, API access fees, and cloud-infrastructure invoices may all constitute payments for EAR-controlled technology. A payment platform that processes these without visibility into whether the underlying product has an ECCN – or whether the recipient is on the Entity List – has a BIS exposure it has not assessed.
Correspondent banking chains. A payment processor that is not itself the originating institution can still face OFAC liability if it processes a transaction that it knows or could determine involves blocked property. The reach of OFAC's rules extends to intermediaries. Correspondent and intermediary banks have faced significant civil enforcement actions for processing transactions routed through their systems that involved sanctioned jurisdictions, even where the ultimate transaction parties were not directly their clients.
Stale screening lists. OFAC updates the SDN List on a rolling basis. A firm that downloads the list weekly, or that relies on a vendor update cycle longer than daily, has a systematic gap during the window between updates. Designations can be effective immediately upon publication.
Rejections versus blocks. OFAC distinguishes between transactions that must be rejected (declined and returned) and transactions that must be blocked (frozen and held, with reporting to OFAC). Payment processors sometimes conflate the two, returning funds that should have been blocked. That is itself a reportable error.
Voluntary self-disclosure timing. Where a processor identifies a potential violation, a VSD (voluntary self-disclosure to a regulator) submitted promptly and with appropriate supporting evidence can materially affect the outcome of any subsequent enforcement action. Delay reduces the mitigating value of the disclosure. We regularly advise payment firms on the decision to self-disclose and on the content of the disclosure package – a decision that should involve counsel before the submission is made.
How does a common objection misread the dual-regime obligation?
A frequent assumption among compliance teams is this: "We have a strong OFAC screening programme, so our payment-processing controls are adequate." That assumption is the central myth in this space, and it is dangerous in two specific ways.
First, it treats OFAC screening as equivalent to export-control compliance. It is not. OFAC and BIS maintain separate lists, separate licensing regimes, and separate enforcement authorities. An OFAC-clean transaction may still require a BIS licence for the export that the payment finances. The two authorities have coordinated enforcement, and the fact that OFAC found no violation does not insulate a business from BIS inquiry.
Second, it treats OFAC as the global standard. For a business operating across the UK, the EU, and Asia-Pacific, the OFAC ownership test is the minimum, not the ceiling. OFSI's control limb, the EU General Court's approach to economic dependency, and the autonomous regimes of Australia and Singapore all impose obligations that may be stricter than OFAC's mechanical rule. A compliance programme calibrated only to OFAC will be systematically insufficient in non-US jurisdictions, and the gap will not be visible from within the programme itself.
The practical correction is a compliance architecture that is built around the strictest applicable obligation at each transactional step, with a clear mapping of which regime governs which element of the payment chain. That is not the same as duplicating effort; it is a matter of knowing which regime applies and ensuring the controls match it.
When should a business involve sanctions counsel on payment-processing controls?
Sanctions counsel should be involved at four distinct trigger points in the payment-processing context. Each is a point where independent legal review materially changes the outcome.
Programme design. When a payment business is building or redesigning its compliance programme, counsel involvement at the design stage ensures that the architecture maps to all applicable regimes, not only to the primary one. A programme designed by reference to OFAC rules alone will have structural gaps on day one.
A screening hit. When an automated system flags a match, the legal analysis – whether the hit is a true match, whether a general licence applies, whether the transaction must be blocked or rejected, and whether a report is required – should not rest solely on the compliance team's internal judgment. The distinction between a block and a rejection carries legal consequences. Getting it wrong creates a second compliance event.
An identified potential violation. If internal review or an audit surfaces a transaction that may have violated OFAC rules or the EAR, the decision on whether and how to make a voluntary self-disclosure is a legal judgment that should not be made without counsel. The structure, content, and timing of a VSD are factors in the regulator's penalty assessment. They require careful analysis before submission.
A regulatory inquiry. If OFAC or BIS has initiated contact – whether through a subpoena, a request for information, or an informal query – the business should involve counsel immediately. Early engagement allows the scope of the inquiry to be assessed and the response strategy to be set before positions harden.
In a recent matter, a payment-technology business identified, during a routine internal audit, a series of transactions that had been processed for a client whose beneficial owner appeared on the SDN List through a layered intermediate structure. We scoped the apparent violations, assessed the voluntary self-disclosure question, and prepared the evidence package for submission. The matter was resolved without a public enforcement action. We state that as a description of the route taken, not as a guarantee of any outcome.
Related practices
- Sanctions compliance audit and testing – Australia – Structured testing of screening and programme controls against the Australian regime.
- Payment-processing controls: OFSI vs Australia – Comparative analysis of UK OFSI and Australian DFAT obligations for payment processors.
- Payment-processing controls: SECO – Swiss SECO obligations for cross-border payment processing.