A trade-finance desk at a European bank is processing a documentary credit for the export of precision machining equipment. The buyer is in a third country. The goods are dual-use. The financing bank's sanctions team clears the buyer. But has anyone checked the Export Control Classification Number of the goods under the US Export Administration Regulations? Has anyone confirmed whether the EU's dual-use controls add a layer of authorisation that the credit documentation does not reflect? Two regimes, two compliance programmes, one transaction – and the gaps between them are where enforcement actions begin.
Trade-finance sanctions controls under the BIS / EAR (the Export Administration Regulations administered by the US Bureau of Industry and Security) and the EU's dual-use and financial-sanctions rules operate on different legal bases, use different classification methodologies, and impose obligations on different actors in the financing chain. As of July 2026, the divergence between the two regimes creates material blind spots for banks, exporters, and freight intermediaries who apply only one compliance lens to a cross-border transaction. Understanding where the regimes align and where they part is the starting point for managing the risk.
This analysis compares the BIS / EAR and EU positions across the key trade-finance touchpoints: legal basis and scope, classification and licensing mechanics, the obligations of financial intermediaries, documentary and record-keeping requirements, enforcement posture, and the practical steps a cross-border business should take to align both programmes.
What legal authority governs each regime, and why does it matter for trade finance?
The BIS / EAR derives its authority from the Export Control Reform Act and is implemented through the Export Administration Regulations. It applies to the export, re-export, and in-country transfer of US-origin items and, critically, to foreign-produced items that incorporate a defined threshold of US-controlled content or technology – the de minimis and foreign direct product rules that extend US jurisdiction well beyond US territory. A trade-finance transaction structured entirely outside the United States can still engage the EAR if the goods, the software, or the underlying technology has US-origin characteristics above the applicable threshold.
The EU regime rests on the relevant Council Regulation on dual-use items and supplementary Council decisions that impose autonomous financial sanctions. These instruments apply on the basis of the location of the exporter or the transit point within EU territory, and on the nationality of EU persons involved in the transaction. An EU-established bank providing a letter of credit for dual-use goods is subject to EU controls on the goods side regardless of whether the exporter is itself EU-based.
The jurisdictional asymmetry matters enormously in practice. The EAR can reach a transaction that the EU considers outside its territorial scope, because US extraterritorial application turns on the origin and content of the item rather than the location of the parties. Conversely, an EU-established intermediary may face EU licensing obligations on goods that BIS has classified as EAR99 – the category of items subject to the EAR but not controlled to most destinations. In our experience, trade-finance teams that treat EAR99 as a green light for the EU analysis are making precisely the wrong inference.
How do the classification systems compare, and where do businesses miss the step?
Under the EAR, goods, software, and technology are assigned an ECCN (Export Control Classification Number under the US Commerce Control List) that determines which destinations, end-uses, and end-users require a licence. The classification is item-specific, exporters bear the primary obligation to classify correctly, and a wrong ECCN at the outset corrupts every downstream control in the transaction.
The EU uses a separate dual-use list that is aligned in broad structure with the Wassenaar Arrangement, the Missile Technology Control Regime, and other multilateral export-control bodies. Items on the EU list require an authorisation for export to certain destinations, and the EU regime provides both individual licences and a set of Union general export authorisations covering defined categories of goods to approved destinations. The EU list and the US CCL overlap significantly but are not identical. A controlled item under the EAR may sit in a different entry on the EU list, carry different licence exceptions, or – in some cases – not appear on the EU list at all.
The practical miss occurs at the classification step. A trade-finance team relying on the exporter's export-control classification for EU compliance purposes, without independently verifying the EU list entry, is exposed if the two classifications are not congruent. Which classification governs? Both do – simultaneously, as the stricter prohibition governs. That principle applies across all major regimes and is frequently overlooked when a bank's trade-finance team and its export-control compliance team operate in separate silos.
What obligations fall on financial intermediaries under each regime?
Under the EAR, US financial institutions and, in certain circumstances, non-US banks providing US-dollar clearing or US-correspondent services have obligations that arise from their role in facilitating the transaction. A bank that knows or has reason to know that a letter of credit or a payment will be used in connection with an export that requires a licence it does not hold is in a materially different position from a bank that processed a clean transaction in good faith without red flags. The EAR's knowledge standard – which includes wilful blindness – means that a financial institution cannot rely on the absence of a licence number in the documentation as a complete defence if the surrounding circumstances put it on inquiry.
The EU approach treats the exporter as the primary licence holder and the financial intermediary as a supporting party with screening and due-diligence obligations that flow from the applicable financial-sanctions regulations rather than directly from the dual-use export-control rules. However, EU autonomous sanctions frequently impose asset-freeze and prohibition-of-economic-resources obligations that sweep in financial services, and a bank providing trade finance to a sanctioned counterparty – or to an entity that is 50 percent or more owned by a listed person under the EU's ownership-and-control test – is in breach regardless of whether it holds or is named on any export licence.
The divergence is sharpest at the level of what triggers the financial intermediary's own obligation. Under the EAR, the trigger is knowledge of the end-use or end-user risk. Under EU financial sanctions, the trigger is the status of the counterparty on the EU lists, or its capture through the ownership-and-control analysis. A bank that screens for the latter but not the former – or vice versa – is operating a compliance programme with a structural gap.
The position above covers the standard case. Your facts – the goods, the financing structure, the counterparty's ownership chain, the currency of the transaction, the jurisdictions of the correspondent banks – change the analysis. For a review of your trade-finance compliance programme against both regimes, contact Calder & Vance at info@caldervance.com.
What documentary and record-keeping obligations does each regime impose on the transaction?
The EAR imposes record-keeping obligations on exporters, re-exporters, and certain other parties, requiring retention of export-related records for a defined period. Those records include the licence or licence exception used, the classification of the item, shipping documentation, and relevant communications. In practice, a trade-finance bank that is party to the transaction – as the issuing bank, confirming bank, or paying bank – should be retaining its own set of transaction records that would allow it to demonstrate, in an enforcement context, the due diligence it performed. The regime does not exempt financial intermediaries from scrutiny simply because the exporter holds the classification.
The EU's dual-use rules and the supplementary financial-sanctions regulations each carry their own documentation and reporting requirements. Under the financial-sanctions side, an obligation to report arises where a firm has reason to suspect that a counterparty is a designated person or a person caught by ownership and control. Reporting must go to the relevant national competent authority within the applicable national timeframe – which varies between EU member states and should be verified against the current position in the relevant jurisdiction before relying on it.
For a cross-border transaction involving both regimes, the practical implication is that the record-keeping programme must satisfy both sets of requirements. A single file that meets EAR standards may be insufficient for EU reporting obligations, and vice versa. We regularly advise trade-finance teams to design a unified transaction file that captures the classification evidence, the screening records, the beneficial-ownership checks, and any internal escalation decisions, structured so that it would satisfy a query from either BIS or the relevant EU competent authority.
How does enforcement posture differ, and what does that mean for cross-border risk?
BIS has a well-developed enforcement programme that produces penalty notices for EAR violations including unlicensed exports, false statements in export documents, and facilitation of prohibited transactions by US and non-US persons. Civil monetary penalties can be substantial on a per-violation basis and are calculated on the transaction value or a statutory maximum per violation, whichever is greater. The US Department of Justice handles criminal export-control matters where wilfulness is alleged. A voluntary self-disclosure (VSD) to BIS, made promptly and completely, is a significant mitigating factor in the penalty calculus, though it does not guarantee a particular outcome.
EU enforcement of both dual-use controls and financial sanctions is decentralised. Each member state's competent authority handles investigations and penalties within its jurisdiction. This means that the same underlying conduct – a single cross-border transaction – could in principle attract enforcement attention in more than one member state simultaneously, with different procedural rules, penalty ranges, and settlement options applying in each. For a business with operations or correspondent relationships across multiple EU jurisdictions, that decentralisation creates a coordination challenge that a single-country compliance lens does not address.
A further asymmetry is the US government's use of the Entity List – BIS's list of parties subject to enhanced licence requirements for specified items – and the denied persons list. These lists operate differently from OFAC's SDN List and from EU designation lists. An entity on the Entity List is not necessarily a sanctioned person; it is a party to which specified items may not be exported without a BIS licence that will presumptively be denied. EU trade-finance teams that screen only against sanctions lists – and not against BIS's lists – are missing a category of restriction that can make a transaction unlawful under the EAR even where no sanctions designation exists.
If a transaction has already been flagged by a correspondent bank, or if a filing has been refused, an early review by specialist counsel can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential initial assessment.
What do businesses most commonly miss in a trade-finance compliance programme?
In our cross-border practice, the most common gap is the treatment of the financial intermediary as a secondary actor rather than as a directly obligated party under both regimes. Banks and non-bank financial institutions providing trade-finance products – letters of credit, supply-chain finance, documentary collections, bank guarantees – are often structured around a sanctions-screening workflow that checks counterparty names and does not reach the goods, the technology, or the end-use.
A second consistent miss is the failure to apply the stricter prohibition governs principle when the EAR and EU controls diverge on a specific item. Compliance teams trained predominantly in one regime default to that regime's outcome and treat it as definitive. It is not. Both regimes apply simultaneously where both have jurisdiction, and the more restrictive control governs the permissibility of the transaction.
A third area is the treatment of intangible technology transfers. The EAR controls the export, re-export, and transfer of technology – including technical data sent by email, provided in a training context, or made available through remote access to a controlled manufacturing system. An EU-established supplier that sends US-controlled technical specifications to a third-country buyer by electronic means has made an export for EAR purposes even if no physical goods cross a border. Trade-finance documentation rarely reflects these intangible flows, and the compliance check rarely extends to them.
There is a prevalent myth among mid-market exporters that trade-finance banks bear primary responsibility for export-control compliance and that the exporter's obligation is limited to providing accurate shipping documents. This is incorrect under both the EAR and the EU dual-use rules. The exporter retains the classification obligation, the licence obligation, and the record-keeping obligation regardless of who finances the shipment. The bank's compliance obligations are layered on top, not substituted for the exporter's.
A cross-border scenario: where the two regimes produce different answers
Consider a representative matter from our practice. A European trading house arranged a letter of credit for the export of industrial control system components to a buyer in a third market. The components had an EU dual-use list entry. The exporter obtained the applicable EU general export authorisation. The trade-finance bank screened the buyer against EU and UN lists and found no hits. The transaction was approved and executed.
On a post-transaction review, it emerged that the components incorporated US-origin software above the EAR de minimis threshold, bringing them within EAR jurisdiction. The destination required a BIS licence that was not obtained. The EU general export authorisation did not address the EAR requirement. The exporter had not classified the item under the US CCL. The financing bank had not asked whether the EAR applied.
We were instructed to assess the exposure and advise on voluntary self-disclosure. The situation required a reconstruction of the classification analysis, a review of all transaction documentation, and a careful assessment of the knowledge standard under the EAR. The lesson the trading house drew from the matter – and which we have seen replicated in several similar instructions – is that a dual-use compliance programme designed around EU controls alone is not adequate for goods with US-origin content. A parallel EAR classification exercise is not optional; it is the threshold step for any cross-border trade involving items with US technology input.
What should a cross-border business do to align both compliance programmes?
The first step is a classification audit: for every product or technology in the export portfolio, confirm both the US ECCN under the Commerce Control List and the corresponding EU dual-use list entry, and record the analysis in a format that can be produced in an enforcement context. Where the two classifications produce different licence requirements, the more restrictive applies.
The second step is a counterparty and ownership-chain review that extends beyond sanctions-list screening. This means checking the Entity List and denied persons lists under BIS, the EU consolidated list, the UN Consolidated List, and OFSI's list, in addition to OFAC's SDN List. It also means tracing beneficial ownership to the level that would satisfy both the EU's ownership-and-control test and OFAC's 50 percent rule, because the two tests are not identical in their application and a structure that passes one may not pass the other.
The third step is end-use and end-user due diligence on the substance of the transaction, not just the name of the buyer. What will the goods be used for? What is the buyer's industry? Are there red flags in the transaction structure – unusual routing, third-country intermediaries, inconsistencies between the stated end-use and the capabilities of the goods – that a reasonable compliance officer would escalate? This qualitative layer is where the knowledge standard under the EAR engages, and it is where a bank's or exporter's documented reasoning becomes the first line of defence in an enforcement review.
The fourth step is a review of the documentation and record-keeping programme to confirm that the transaction file captures all elements required under both regimes, including the classification evidence, the screening records, the beneficial-ownership analysis, and any licence or exception relied on. A unified file designed to address both BIS and EU requirements costs little to assemble and is invaluable if either regulator sends a query.
For businesses with repeated or high-volume trade-finance activity, the fifth step is a periodic compliance-testing exercise that stress-tests the classification logic, the screening workflow, and the escalation procedures against a set of hypothetical transactions designed to surface the gaps. We regularly design and run such exercises for financial institutions and exporters whose primary exposure sits at the intersection of the EAR and EU controls.
Related practices
- Sanctions compliance audit and testing – stress-test your trade-finance controls across multiple regimes
- EU trade-finance sanctions controls analysis – detailed review of the EU regime's obligations for trade-finance participants
- OFAC vs EU trade-finance controls comparison – how OFAC and EU financial-sanctions rules diverge for cross-border transactions
Frequently asked questions on trade-finance sanctions controls: BIS / EAR vs EU
Where do the regimes diverge on trade-finance sanctions controls?
The regimes diverge at four points: jurisdictional basis (US extraterritorial reach via de minimis and foreign direct product rules vs EU territorial and nationality-based scope); classification methodology (the US Commerce Control List and ECCNs vs the EU dual-use list); the obligations of financial intermediaries (knowledge-standard triggers under the EAR vs entity-status triggers under EU financial sanctions); and enforcement structure (centralised US federal enforcement vs decentralised EU member-state competent authorities). A transaction may engage both regimes simultaneously, and the stricter prohibition governs.
Which regime is stricter on trade-finance sanctions controls?
Neither regime is categorically stricter; the answer is item-specific and counterparty-specific. The EAR's extraterritorial reach can impose licensing obligations on transactions that the EU considers outside its scope entirely. Conversely, EU autonomous financial sanctions – particularly the ownership-and-control test – can capture counterparties that are not on any US list. The correct question is not which regime is stricter in the abstract but which regime or combination of regimes applies to your specific transaction, goods, and parties, and what each requires.
What should a cross-border business do about trade-finance sanctions controls?
A cross-border business should run a parallel classification exercise under both the US CCL and the EU dual-use list for every item in its export portfolio, conduct counterparty screening against all relevant lists (SDN, Entity List, EU consolidated list, UN Consolidated List), and document beneficial-ownership analysis to the level that satisfies both OFAC's 50 percent rule and the EU's ownership-and-control test. Where the two regimes produce different results, apply the stricter. If a transaction raises doubt on either limb, take specialist advice before proceeding.
About the author
Renata Costa advises banks, payment firms, and virtual-asset businesses on sanctions screening, compliance-programme design, and financial-crime controls. Her practice covers the intersection of financial-sanctions obligations and export-control requirements for trade-finance participants across US, UK, and EU regimes. Calder & Vance – International Sanctions & Export Control Counsel.
About Calder & Vance
Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.
Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.