A correspondent bank processes a documentary credit for a machinery shipment. The goods are commercial grade. The end-buyer is a distributor in a third market. Nothing on the surface raises a flag. Yet the transaction may sit squarely within the reach of the Bureau of Industry and Security – not because any party is designated, but because the goods carry an Export Control Classification Number (ECCN, the identifier that determines whether an item falls under the US Commerce Control List and what authorisation it needs) that requires a licence to the destination, and no licence was sought. Trade-finance sanctions controls under BIS / EAR are where financial institutions and their corporate clients most consistently underestimate their exposure.
As of July 2026, trade-finance sanctions controls under BIS / EAR require every party to a controlled-goods transaction – exporter, freight forwarder, bank, and in certain circumstances the buyer – to assess whether the goods, software, or technology involved need a licence under the Export Administration Regulations (EAR), and to refuse participation where a red-flag review cannot be completed. The obligation is not satisfied by screening counterparties alone. It attaches to the item, the end-use, and the end-user, independently of whether any party appears on a sanctions list.
This analysis maps the BIS / EAR obligations that apply to trade-finance transactions, compares the position under OFAC economic sanctions, OFSI, and the EU Council regulations, identifies the most common control failures, and sets out the practical steps that reduce exposure.
What is the legal authority and who administers BIS / EAR controls on trade finance?
The Bureau of Industry and Security (BIS), a division of the US Department of Commerce, administers the EAR under the authority of the Export Control Reform Act and, to the extent not superseded, earlier economic-security statutes including IEEPA. The EAR governs the export, re-export, and in-country transfer of items subject to US jurisdiction – meaning items with a US origin, items that contain more than a de minimis proportion of US-controlled content, and items produced outside the United States using certain US technology or software.
That last category – items produced abroad using US technology – is the extraterritoriality limb that surprises non-US banks most. A European bank confirming a letter of credit for goods manufactured in Asia, using US-origin production equipment or software, may find that the transaction is subject to EAR jurisdiction even though no party and no shipment touches US territory. In our practice, this is the single most frequently missed control point in trade-finance compliance reviews.
BIS enforces through the Office of Export Enforcement (OEE). Separately, OFAC administers the economic-sanctions programmes under IEEPA and TWEA. Both agencies can be engaged by the same transaction, and their analyses run in parallel. Compliance counsel must check both tracks.
How does the BIS / EAR classification test apply to a trade-finance transaction?
Every item that may be exported or re-exported must be classified against the Commerce Control List. Items with an ECCN designation are controlled for one or more specified reasons – national security, nuclear non-proliferation, chemical and biological controls, regional stability, crime control, and others. Items without an ECCN designation are classified as EAR99, the residual category that covers most mass-market goods. EAR99 is not a blanket clearance: even EAR99 items cannot be exported to embargoed destinations or to parties on BIS's Entity List or Denied Persons List without authorisation.
For a trade-finance transaction, the classification sequence runs as follows. First, identify whether the goods, software, or technology are subject to the EAR at all – the jurisdiction question. Second, determine the ECCN, either from the exporter's classification or from an independent classification review. Third, map the ECCN against the destination country and the applicable Country Chart to identify which licence requirements are triggered. Fourth, determine whether a licence exception applies. Fifth, check whether the end-user or end-use triggers a separate restriction – the Entity List, the Denied Persons List, the Unverified List, or a specific end-use concern under the applicable provisions.
Banks and trade-finance houses typically receive step two in the form of a shipper's letter of instruction or an export declaration. They do not classify goods themselves. But they carry an independent obligation to act on red flags – and an ECCN listed on a document that conflicts with the apparent nature of the goods is itself a red flag requiring resolution before a credit or guarantee is issued.
What happens when a bank issues a letter of credit against documents that carry a red flag it did not address? The answer under the EAR is that the financial institution may be treated as a party to an unlicensed export. That exposure is not theoretical. Enforcement actions in this area have targeted banks, freight forwarders, and logistics companies as well as exporters.
Where do BIS / EAR trade-finance controls diverge from OFAC, OFSI, and EU obligations?
The divergence between the BIS / EAR regime and the parallel OFAC, OFSI, and EU positions is material – and understanding it is the core compliance challenge for any cross-border business or financial institution.
OFAC operates a list-based and country-based regime. It prohibits transactions with designated persons and with comprehensively embargoed destinations, and it imposes blocking obligations on property in which a designated person holds an interest. The analysis is primarily counterparty-facing. If no party is designated and the destination is not comprehensively embargoed, many transactions clear OFAC's primary controls. The secondary-sanctions layer is different – OFAC can impose consequences on non-US persons who deal with certain designated parties – but even then the focus remains on who the counterparty is.
BIS / EAR, by contrast, is item-facing first. The question is not (only) who you are dealing with, but what you are selling, where it is going, and for what purpose. A transaction with a clean counterparty that ships controlled goods to a permissible destination without a required licence is still a violation.
OFSI in the United Kingdom focuses on financial-sanctions prohibitions – asset freezes and restrictions on making funds available to designated persons. OFSI does not itself administer export-control licensing (that is the ECJU's role), but UK financial institutions must comply with both regimes. The UK's ownership and control test for financial-sanctions purposes differs from OFAC's mechanical 50 percent rule: OFSI applies a broader control analysis, which can catch entities that are operationally directed by a designated person even where the formal ownership threshold is not reached.
The EU Council regulations similarly combine asset-freeze and trade-restriction obligations. For dual-use goods, EU Regulation 2021/821 sets the EU-wide export-control regime, and both the EU sanctions regulations and that regulation may be engaged by the same transaction. The EU's ownership and control test tracks OFSI's position rather than OFAC's: control through other means can attribute a non-listed entity to a listed person. Critically, where EU sanctions and BIS / EAR controls both apply to a transaction, the stricter prohibition governs each element. A business cannot use a BIS licence exception to satisfy an EU prohibition, or vice versa.
In our cross-border practice, the gap that creates most difficulty is this: a transaction may be cleared under OFAC screening because no party appears on the SDN List, yet remain prohibited under BIS because the goods require a licence that has not been obtained. Both analyses are mandatory. Neither substitutes for the other.
The position under the bridge text below:
The standard case above covers the primary alignment. Your facts – the goods, the destination, the counterparty structure, and the specific licence exceptions available – change the analysis at each step. For a transaction-specific assessment under BIS / EAR and the parallel regimes, contact Calder & Vance at info@caldervance.com.
What are the most common control failures in trade-finance sanctions compliance?
Practical experience across trade-finance mandates identifies a consistent set of control failures. They are not dramatic acts of evasion. They are process gaps – each individually manageable, collectively significant.
First: overreliance on counterparty screening. Compliance teams run counterparty names against the SDN List, the Entity List, and consolidated UN lists. That is necessary but not sufficient. An unlisted buyer importing controlled goods without an end-use certificate, or diverting controlled goods post-delivery, creates BIS exposure that counterparty screening will not surface.
Second: failure to classify goods accurately. Shippers' letters of instruction are sometimes prepared without a proper ECCN classification. Financial institutions that rely on those letters without a cross-check – particularly when the goods have any dual-use characteristic – are taking on risk that a basic item-classification step would identify.
Third: de minimis miscalculations. A product assembled outside the United States may contain US-controlled components or run US-origin software. If that content exceeds the applicable de minimis threshold, the finished item is subject to the EAR even if it has never been in the United States. Banks financing the trade of foreign-assembled goods with complex supply chains routinely miss this.
Fourth: red-flag recognition failures. BIS guidance identifies specific circumstances that should prompt inquiry before a transaction proceeds: unusual payment terms, requests to omit ECCN or country-of-origin markings, buyers who are unwilling to confirm end-use, and destinations that are inconsistent with the buyer's stated business. When any of these appear in the trade-finance documents, the obligation is to pause and investigate – not to proceed in good faith. In a recent matter, a financial institution in the payments sector received a letter-of-credit application whose goods description was vague and whose stated end-use did not align with the buyer's known sector. We advised on the red-flag analysis and the appropriate due-diligence steps before the credit was confirmed. The matter resolved without enforcement action.
Fifth: inadequate record-keeping. The EAR requires that records supporting an export or re-export be retained for a specified period. When BIS opens a post-shipment verification or an enforcement inquiry, the ability to produce those records promptly is the difference between a minor administrative matter and a prolonged investigation.
Sixth: failure to apply transaction-specific end-use controls. Some end-uses – military end-use in certain destinations, nuclear end-use anywhere outside authorised frameworks, and proliferation-related end-use – trigger licence requirements that apply regardless of ECCN. A business that screens for ECCN and licence exceptions without separately checking end-use has a gap in its controls.
If a transaction has already been flagged, or a licence has been refused, an early review of the position can preserve options that narrow quickly. Contact Calder & Vance at info@caldervance.com for a confidential preliminary assessment.
How does the EAR's extraterritorial reach affect non-US banks and trade-finance houses?
Non-US financial institutions frequently conclude that BIS / EAR is a US-exporter concern and that their involvement in confirming, advising, or discounting a letter of credit does not engage US jurisdiction. That conclusion is wrong in three specific circumstances.
The first is the foreign-direct-product rule. Where goods are produced outside the United States using technology or software that is itself subject to the EAR, and the production tool or software was controlled for specific reasons, the resulting foreign-made product can itself become subject to the EAR. This rule has been significantly expanded in recent years, with additional country and technology categories added to its scope. A non-US bank financing the sale of foreign-made goods must consider whether the foreign-direct-product rule brings those goods into the EAR's reach.
The second is the de minimis rule. Foreign-origin items that incorporate controlled US-origin content above the applicable threshold are subject to the EAR for re-export purposes. Trade-finance documents for goods with complex, multi-country supply chains frequently do not capture this exposure.
The third is the dollar-clearing exposure. A transaction that ultimately clears in US dollars through a US correspondent bank may expose that US bank to liability. But – and this is the point non-US institutions often miss – BIS enforcement does not require US-dollar clearing as a precondition. The jurisdictional hook is in the goods, the technology, or the software, not the currency of payment.
We regularly advise non-US banks and trading houses on the extraterritoriality question at the outset of a transaction – before documents are issued and before payment obligations crystallise. The cost of early advice is a fraction of the cost of a post-shipment enforcement inquiry.
What is the voluntary self-disclosure process and when does it apply to trade-finance matters?
A voluntary self-disclosure (VSD) to BIS is a formal report submitted by a party that has identified a potential violation of the EAR before BIS has begun an investigation. A VSD, if properly prepared and submitted, is treated by OEE as a significant mitigating factor in penalty calculations. It does not guarantee a particular outcome, and it requires careful assessment: a poorly scoped VSD that omits related violations can create greater exposure than a well-prepared one that covers the full picture.
Trade-finance VSD situations typically arise in one of three ways. An internal audit identifies unlicensed exports or re-exports in a historical trade file. A post-shipment verification by BIS reveals a discrepancy between the licensed and actual goods. Or a compliance-programme review surfaces systematic ECCN misclassification across a category of transactions.
The VSD decision requires a preliminary scope assessment: how many transactions are potentially affected, over what period, across which destinations, and what licence exceptions – if any – might have applied retrospectively. That assessment shapes both the VSD filing and any concurrent voluntary disclosure to OFAC if the underlying transactions also engaged OFAC-administered programmes.
Concurrent disclosure to two agencies is a coordination challenge. OFAC's voluntary self-disclosure process and BIS's process differ in their filing requirements, timelines, and the way each agency weights the disclosure in its penalty analysis. Both reward early, complete, and proactive disclosure – but satisfying one agency's process does not satisfy the other's. We have acted on matters requiring coordinated disclosure to both agencies and can advise on sequencing and scope.
For a confidential review of a potential breach or a VSD question, contact us at info@caldervance.com.
How should a cross-border business structure its trade-finance sanctions compliance programme?
A trade-finance compliance programme that addresses BIS / EAR as well as OFAC, OFSI, and EU obligations needs five interconnected elements.
Item classification: maintain a live classification database for every product category the business exports or finances. Classifications should be reviewed when products are modified, when supply-chain inputs change, and when BIS updates the Commerce Control List.
End-user and end-use screening: counterparty name screening is the floor, not the ceiling. End-use certificate requirements must be mapped against the ECCN and the destination, and red-flag indicators in trade-finance documents must trigger a structured escalation before instruments are issued.
Transaction-level controls: for each letter of credit, documentary collection, or bank guarantee, a compliance checklist should confirm jurisdiction, classification, licence requirement or exception, and end-use check. The checklist is not a formality; it is the contemporaneous record that demonstrates a good-faith review if OEE or OFAC later asks.
Record-keeping: the EAR imposes a mandatory record-retention obligation, and records must be producible promptly. A trade-finance compliance programme must ensure that classification records, shipper letters, licence documents, and end-use certificates are retained and retrievable by transaction reference for the required period. OFAC and OFSI impose their own parallel record-keeping obligations; the longest applicable period across all engaged regimes sets the working standard.
Training and escalation: the most common control failure is not a system failure but a human-recognition failure. Trade-finance operations teams must be trained to recognise the red-flag indicators that BIS guidance identifies and to escalate rather than proceed. Escalation paths must be clear, quick, and unambiguous.
Do the five elements above describe your current programme, or are there gaps? In our experience, the gap most frequently identified in a compliance-programme review is the absence of item-level classification controls in the trade-finance workflow. That gap is addressable. We test screening logic, map ownership and control, and redesign the programme to the five-element standard.
Related practices
- Compliance audit and testing – independent programme review and gap-identification for cross-border businesses.
- BIS / EAR versus EU trade-finance controls – criterion-by-criterion comparison of the US and EU export-control regimes in trade-finance transactions.
- EU trade-finance sanctions controls – analysis of the EU Council regulations as they apply to letters of credit, guarantees, and documentary collections.