A technology exporter finalises a supply agreement with a distributor in a market where both OFAC programme restrictions and BIS / EAR controls apply. The compliance team identifies that the transaction needs authorisation. Two tracks are theoretically available: use an existing general authorisation or apply for a specific one. Choosing the wrong track wastes time, creates regulatory exposure, or kills the deal. Which path is right – and who decides?
Under OFAC, a general licence (a standing authorisation permitting a defined class of transactions without a separate application) and a specific licence (a case-by-case authorisation granted to a named applicant) operate on distinct legal bases and serve different commercial situations. Under the BIS / EAR system, the equivalent instruments are licence exceptions (self-executing, condition-based authorisations) and individually validated licences. As of June 2026, the choice between the two tracks turns on the transaction's factual profile, the programme in scope, and the identity of the parties – not simply on which path is faster.
This analysis compares the two tracks across OFAC and BIS / EAR, maps the points of divergence that most affect cross-border businesses, and sets out the practical decision sequence a compliance team should work through before filing.
What is the structural difference between general and specific licences under OFAC?
General licences under OFAC are programme-level instruments: they authorise a category of transactions for any person who meets the stated conditions, with no application, no prior approval, and no licence document issued to the individual user. The authorisation is self-executing. A business relying on a general licence must satisfy itself that every element of the conditions is met – and must document that analysis. OFAC's general licences are published in the relevant programme regulations.
Specific licences are different in character. They are bilateral instruments: issued to a named applicant, for defined transactions, with conditions that OFAC sets at the time of grant. The application goes to OFAC's Licensing Division. The agency reviews the application against the applicable programme's policy priorities, the humanitarian and human-rights standards embedded in US law, and any relevant US foreign-policy considerations. A decision to grant or deny reflects OFAC's assessment of the individual case.
The consequence of this structural difference is that general licences carry the risk of mis-application. A business that reads the conditions incorrectly and proceeds may be conducting an unlicensed transaction even though it believed it was covered. In our experience, this is one of the most common sources of apparent violations in OFAC-regulated businesses: not a deliberate breach, but a confident mis-reading of a general licence's scope.
Specific licences carry a different risk. They are slow. The process is not statutory-bound in the way that some other regulatory approvals are, and timelines vary considerably by programme and workload. For a time-sensitive transaction, an application may not return an answer before the commercial window closes.
How does the BIS / EAR licence-exception system compare?
The BIS / EAR system does not use the term "general licence." Instead, the Export Administration Regulations (EAR) provide licence exceptions – self-authorising provisions that permit exports, re-exports, or in-country transfers of specified items to specified destinations and end-users when the stated conditions are satisfied. Each licence exception has a designated symbol (a two-letter code) that appears on the export documentation. Use is self-determining: BIS issues no approval in advance.
Individually validated licences (IVLs) under the EAR are the closest analogue to OFAC's specific licences. An IVL application goes to BIS for review. BIS applies a policy of denial, a case-by-case policy, or a policy of approval, depending on the destination, end-user, and end-use. The review typically involves inter-agency consultation where the transaction raises national-security or foreign-policy concerns.
Two points distinguish the EAR system from OFAC's. First, a key threshold question in the EAR is the Export Control Classification Number (ECCN – the alphanumeric code on the Commerce Control List that determines what controls apply to a particular item). Businesses must classify their items before they can determine which licence exceptions are available. OFAC's general licences are triggered by the nature of the transaction and the identity of the parties, not by a product classification. Second, the EAR licence-exception conditions are highly technical: they address re-export, technology, software, deemed-export, and country-tier rules that have no direct parallel in the OFAC general-licence architecture.
What does this mean in practice? A business exporting dual-use technology must answer two separate questions before it can identify its authorisation route: what is the ECCN classification, and are any parties on OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons) or BIS's Entity List (a BIS list of foreign parties subject to specific licence requirements for exports, re-exports, and transfers)? The two questions are independent and neither subsumes the other.
The position above covers the standard analysis. Your specific goods, destination, and counterparty chain change the answer in ways that matter commercially. For a preliminary assessment of which authorisation track applies to your transaction, contact Calder & Vance at info@caldervance.com.
What criteria govern the choice of track under OFAC?
The governing criterion is whether the transaction falls within the conditions of an available general licence. If it does, the business may proceed – after completing and retaining its condition-analysis documentation. If the transaction falls outside every available general licence, a specific licence application is the only path to authorisation (absent a change to the transaction's structure).
Three practical filters determine which track is viable.
First, party identity. General licences commonly exclude transactions involving the SDN List directly – for example, a general licence covering a government's official transactions may exclude dealings with an entity on the SDN List even if that entity is technically a government instrumentality. If the counterparty is designated, general licences rarely apply without an additional reading of the specific licence conditions.
Second, transaction type. General licences are often category-specific: personal remittances, authorised exports of informational materials, certain humanitarian transactions. A commercial sale of goods rarely fits neatly within a general licence unless the programme regulations have been amended to accommodate ordinary trade. Where the transaction is commercial and complex, the specific licence route is more common.
Third, geographic scope. Certain programme-level restrictions apply to entire territories or governments. General licences for those programmes may address defined sub-categories of permissible trade. Whether a specific transaction falls within a sub-category is a question of careful textual analysis – and errors in that analysis create apparent violations.
Practitioners working across OFAC and OFSI (the UK Office of Financial Sanctions Implementation) regularly note one important divergence here. Under OFSI, the licensing framework under the UK's Sanctions and Anti-Money Laundering Act ("SAMLA") uses a grounds-based approach: a licence must fit a statutory ground (such as humanitarian assistance, legal fees, or prior contractual obligations). OFAC's general licences are self-contained within programme regulations and are not structured around equivalent statutory grounds in the same way. A business that moves between the two regimes must understand that neither borrows from the other's architecture.
How does the EAR IVL application process differ from OFAC specific licensing?
The mechanics of an IVL application to BIS and a specific-licence application to OFAC share some surface features – both require an applicant to describe the transaction, the parties, and the item or service in detail – but the review logic differs substantially.
BIS reviews IVL applications against end-use and end-user concerns. The key analytical questions are: what will the item be used for, will it contribute to weapons proliferation or other controlled end-uses, and is the end-user subject to a specific restriction? BIS may require a pre-licence check or a post-shipment verification. The review involves the Departments of State, Defense, and Energy for items that implicate their respective equities.
OFAC's specific-licence review is programme-driven. OFAC assesses whether the application falls within a licensing policy – whether an authorisation is consistent with the purpose and scope of the programme. For certain programmes, OFAC has published licensing policies that signal how applications in particular categories will be treated. For others, the policy is less publicly defined and practitioners must draw inferences from how OFAC has treated comparable applications.
One significant operational difference concerns response time. BIS has published processing-time guidance, though actual timelines vary by item, destination, and agency workload. OFAC's specific-licence timelines are not fixed by statute, and in our practice we have seen the range vary substantially by programme. A business planning a transaction that requires a specific licence should not assume a short turnaround, and should build application lead-time into the commercial schedule.
Documentation requirements also differ. BIS applications require ECCN classification, commodity-code information, and technical specifications. OFAC applications focus on party identification, transaction detail, and the licensing-policy basis. Neither process accepts an incomplete application, and deficiencies generate a request for additional information that extends the timeline.
If a transaction has already been structured and submitted, and the response is delayed or the application has been denied, an early review of the options can preserve routes that close with time. Contact Calder & Vance at info@caldervance.com to discuss your position.
What are the risk flags in general licence and licence exception reliance?
Self-executing authorisations create their own compliance risks, and those risks are distinct from the risks of a formal licensing process. Four flags arise most frequently in cross-border transactions.
The first is condition creep. General licences and licence exceptions are frequently amended. A condition that was satisfied when the compliance team first reviewed it may have changed by the time the transaction closes or recurs. We regularly advise clients to build scheduled re-reviews into their transaction management, particularly for recurring or long-term contracts that rely on standing authorisations.
The second is multi-leg transactions. A general licence covers the specific transaction it describes. Where a cross-border supply chain involves intermediate jurisdictions, the general licence covering the first leg may not cover the second or third. Under the EAR, re-export and in-country transfer controls operate independently of the original export authorisation, and a licence exception available for the initial shipment may not be available for re-export to a third destination. This point is frequently missed in distributed supply chains.
The third is the Entity List and Unverified List interaction. Even where an OFAC general licence appears to apply to a transaction, the presence of an EAR-restricted party on the Entity List requires a specific BIS licence for items subject to the EAR. The two regimes operate simultaneously, and a clean OFAC analysis does not resolve the BIS question. In our cross-border practice, we treat the two screening processes as parallel, not sequential.
The fourth is deemed exports. The EAR's deemed-export rule treats the release of controlled technology to a foreign national in the United States as an export to that person's home country. No equivalent doctrine operates in the OFAC general-licence context in the same way. A business that correctly identifies a licence exception for a physical shipment may still require a specific licence for the technology transfer that accompanies it.
Each of these flags raises the same underlying question: has the compliance team verified every element of the authorisation, documented that verification, and connected it to the specific transaction? An affirmative answer to all three is the minimum standard.
Where do the regimes diverge most sharply for cross-border businesses?
The most commercially significant divergence between OFAC and BIS / EAR on the authorisation question is the role of product classification. OFAC's licensing analysis begins with the parties and the transaction. BIS's analysis begins with the item. A business advising its compliance team to run the OFAC analysis first and the EAR analysis second will sometimes reach the correct answer – but will also sometimes make the mistake of concluding that an OFAC clearance resolves the licensing question when BIS controls still apply.
A second point of divergence concerns the treatment of controlled technology and services. OFAC's sanctions programmes control transactions broadly, including services to blocked persons or within sanctioned territories, regardless of whether goods are involved. The EAR's controls are item-centric: they attach to specific items, technology, and software on the Commerce Control List. A purely service-based transaction may require OFAC analysis but trigger no EAR licensing requirement. Conversely, a transaction involving controlled dual-use technology may require a BIS IVL even where OFAC has issued a general licence for the relevant programme.
Third, the extraterritorial reach of the two regimes differs in character. OFAC's secondary-sanctions provisions can affect non-US persons who are not otherwise subject to US jurisdiction, by threatening to cut them off from the US financial system. The EAR's reach is grounded in the US-origin rule – controls follow items and technology that originate in the United States or contain a requisite proportion of US-origin content, under the de minimis rule and the foreign direct product rule. A European business buying and re-selling a product with significant US-origin content may be subject to EAR re-export controls even where it has no OFAC exposure. A European business transacting with a person under secondary-sanctions risk may have the opposite profile: OFAC concern with no EAR exposure.
Understanding both vectors of extraterritorial reach is not optional for a cross-border business. The assumption that one regime's clearance resolves the other's questions is a persistent source of compliance failure.
Our analysis of the parallel EU licensing architecture, including the way EU general authorisations and specific licences operate in comparison to OFAC, is available at Specific vs general licence: OFAC and EU compared. The follow-on discussion of EU procedural mechanics and divergence points from OFAC practice is at Specific vs general licence: OFAC and EU compared – Part 2.
When does a multi-regime transaction require parallel licensing applications?
A transaction that touches both OFAC-regulated parties or programmes and EAR-controlled items may require authorisation from both agencies simultaneously. The two licences are independent: OFAC cannot authorise an EAR violation, and BIS cannot authorise an OFAC violation. A single filing with one agency does not constitute or substitute for a filing with the other.
Parallel applications arise most commonly in three situations. The first is dual-use technology exports to restricted territories where both OFAC programme controls and CCL controls apply to the same shipment. The second is financial transactions that require an OFAC specific licence and that involve a goods component requiring a BIS IVL – for example, a payment to a party in a restricted territory for a controlled item. The third is services transactions that are partially goods-related and partially financial: a maintenance-and-repair contract covering controlled equipment in a restricted market may require both OFAC and BIS authorisation for different components of the same engagement.
Where parallel applications are needed, coordination matters. The two agencies do not communicate on behalf of the applicant. If the OFAC application is approved but the BIS application is denied, the approved OFAC licence is of limited practical use. Sequencing and parallel filing need to be planned at the outset of the licensing strategy, not discovered at the point of approval.
Is your transaction structured in a way that allows both applications to be filed concurrently, and have you addressed the possibility that one may return a different answer than the other? These questions are worth working through before the commercial deadline arrives.
Common misconceptions and the compliance decision a business must make
One persistent misconception in the businesses we advise is that the general-licence or licence-exception track is always preferable because it avoids the delay and cost of a formal application. That view conflates speed with certainty. A transaction conducted under a mis-read general licence carries no less legal risk than an unlicensed transaction – it simply carries the additional fact that the business believed it was authorised. OFAC's enforcement analysis considers the adequacy of the compliance programme and the quality of the legal review, not simply whether the business intended to comply.
A second misconception is that the BIS / EAR system and the OFAC system are alternatives: that clearing one means the other is resolved. They are not alternatives. They are parallel controls, each with independent authority, each capable of triggering civil or criminal consequences, and each administered by a different agency with different review standards.
A third misconception – common at the board level rather than the compliance level – is that a prior licensing approval creates a precedent that simplifies or accelerates the next application. In general, it does not. OFAC issues licences on a transaction-specific basis. A prior licence for a comparable transaction may inform the strategy for the next application, but it does not bind the agency on the subsequent one. Businesses that assume they can proceed by analogy with a prior approval without fresh analysis are taking a risk that may not be visible to them until enforcement follows.
The practical decision a cross-border business must make when it identifies a potential licensing requirement is this: does the transaction fit, clearly and documentably, within the conditions of a general licence or licence exception? If yes – is that analysis documented, signed off, and retained? If the answer to either question is uncertain, the general licence track is not yet available. At that point, the choice is between restructuring the transaction, filing a formal application, or declining the transaction.
Related practices
- Frozen account management under BIS / EAR – managing blocked or frozen assets while pursuing authorisation
- Specific vs general licence: OFAC and EU compared – parallel analysis of the EU licensing architecture