A commodity trader books a shipment from a South-East Asian port to a buyer in Central Europe. Before the vessel sails, the trade-finance bank flags the transaction. One screening system raises an OFAC alert on the consignee's address. A second system flags the cargo's classification for export-control review under the EAR (the Export Administration Regulations, administered by the US Bureau of Industry and Security). Two alerts, two separate legal regimes, two entirely different analytical paths. Which takes priority? What must be done first? And who bears the legal exposure?
Trade-transaction screening under OFAC and under BIS / EAR are complementary but structurally distinct obligations. OFAC screening is a sanctions compliance function: it asks whether a party or property is blocked. BIS / EAR screening is an export-control function: it asks whether the item, the destination, and the end-user require a licence before the export proceeds. A business operating across borders almost always faces both simultaneously, and as of January 2026 the enforcement posture of both agencies has hardened. Missing either layer exposes the firm to civil and, in serious cases, criminal liability.
This analysis compares the two screening regimes criterion by criterion – legal authority, trigger, scope, party lists, analytical tests, and enforcement – and maps the practical decision sequence a compliance team must run before a trade transaction closes.
What legal authority governs each screening obligation?
OFAC's sanctions authority derives primarily from IEEPA and, for older programmes, TWEA; it is implemented through programme-specific regulations issued by the Treasury Department. The core obligation is absolute: no US person, and no person within the reach of OFAC's jurisdiction, may deal in blocked property or with a designated party. The SDN List (the Specially Designated Nationals and Blocked Persons list) is the principal screening target, but OFAC administers multiple additional lists – sectoral lists, non-SDN lists, and consolidated lists – each with different transactional prohibitions attached.
BIS operates under the Export Control Reform Act and administers the EAR. The EAR's jurisdiction is item-driven: it covers items that are physically in the United States, items of US-origin wherever they are in the world, and – critically – items containing US-controlled content above a defined threshold. The primary screening reference points under the EAR are the Entity List (parties to whom exports, re-exports, and transfers require a licence regardless of the item), the Denied Persons List, and the Unverified List. The ECCN (Export Control Classification Number under the US Commerce Control List) assigned to the item determines whether a licence exception is available.
The fundamental structural difference is this: OFAC's prohibitions are party-centred and property-centred. The EAR's controls are item-centred and destination-centred. Both can apply to the same transaction. In our experience, compliance programmes that treat these as alternative checks rather than cumulative ones routinely miss dual-exposure scenarios.
What triggers each screening obligation – and where do the triggers diverge?
OFAC screening is triggered by any connection to US jurisdiction: a US person involved, US dollars clearing through a US correspondent bank, US-origin property, or a transaction touching US territory in any way. The trigger is broad and the jurisdictional reach of secondary-sanctions risk extends it further. A non-US bank processing a dollar payment for a non-US client can find itself within OFAC's effective reach even if no US person is a party to the underlying trade. That extraterritorial dimension is the source of most compliance complexity for non-US businesses.
EAR screening is triggered by the movement of a controlled item. "Movement" includes physical export from the United States, re-export from one foreign country to another, and in-country transfers between parties within a foreign jurisdiction. The de minimis rule (the EAR provision that brings foreign-made items within US jurisdiction when they contain more than a threshold percentage of US-controlled content) and the foreign direct product rule (which extends US export-control jurisdiction to foreign-made products that are the direct product of certain US technology or software) are the two mechanisms most frequently encountered in cross-border supply chains that do not, on their face, touch US soil.
These triggers operate independently. A shipment may be EAR-controlled even if every party to the transaction is clean on all OFAC lists. Conversely, a transaction with a blocked party may involve entirely EAR99 goods (items below the threshold requiring classification) for which no export licence would otherwise be needed. The compliance team must run both analyses to completion before relying on either result.
How do the party-list structures differ in practice?
The party-list structures of the two regimes reflect their different legal purposes and produce meaningfully different screening workloads. Under OFAC, the SDN List is the hard prohibition: any transaction involving a listed person, entity, or vessel is blocked regardless of the item, the destination, or any business rationale. Other OFAC lists impose more targeted restrictions – sectoral prohibitions that limit specific transaction types with listed parties rather than blocking all dealings – and the 50 percent rule (OFAC's rule treating entities owned 50 percent or more in the aggregate by SDN-listed persons as themselves blocked, even if not separately listed) extends the SDN's reach into corporate structures that do not appear on the list at all.
BIS maintains three primary lists with distinct legal effects. The Entity List imposes a presumption of denial: exports, re-exports, or transfers to a listed entity require a licence, and BIS will typically not grant one. The Denied Persons List is harder still: dealing with a denied person in any export transaction is prohibited. The Unverified List does not create an absolute prohibition but flags a party whose bona fides BIS has been unable to confirm; proceeding with an Unverified List party without conducting additional due diligence creates "red flag" exposure that removes the "knowledge" safe harbour available under the EAR.
Where the regimes materially diverge is in the treatment of non-listed affiliated parties. OFAC's 50 percent rule creates a hard constructive-listing standard: if the ownership calculation is met, the entity is treated as blocked without any separate designation. BIS has no equivalent mechanical rule. Under the EAR, knowledge or reason to know that a non-listed party intends to redirect goods to a prohibited end-user or end-use is the operative test. That makes the BIS analysis more fact-specific and less formulaic than the OFAC ownership calculation – and in practice harder to automate in a screening system. Do your screening tools surface ownership-chain data, or only direct-name matches?
The position above covers the standard case. Your facts – the nature of the goods, the structure of the counterparty, the payment route, the shipping intermediaries involved – change both analyses. For a review of where your transaction sits, contact Calder & Vance at info@caldervance.com.
What analytical tests must the compliance team run under each regime?
The OFAC analytical sequence for a trade transaction has four principal steps. First, identify all parties: the buyer, the seller, the freight forwarder, the shipping agent, the vessel owner or operator, the bank, and any intermediate consignees. Second, screen each party against all relevant OFAC lists – not only the SDN List but also the applicable non-SDN and sectoral lists for the regimes in play. Third, apply the 50 percent rule: for any party that is not itself listed, trace the ownership chain to determine whether blocked persons hold 50 percent or more in the aggregate, directly or through intermediaries. Fourth, consider secondary-sanctions risk: even where a transaction is not directly prohibited, does the counterparty's exposure to a secondary-sanctions programme create liability risk for a non-US correspondent or financial institution involved in clearing the payment?
The EAR analytical sequence is structurally different. First, classify the item: determine whether the goods, software, or technology have a specific ECCN on the Commerce Control List, or whether they are EAR99. Second, determine the jurisdiction: does the EAR apply at all – is the item of US origin, does it contain sufficient US content to trigger de minimis, or is it a foreign direct product of controlled US technology? Third, check the destination: is there a comprehensive embargo (administered concurrently by OFAC) or a heightened review policy for the destination country? Fourth, screen all parties – exporter, consignee, end-user – against the Entity List, Denied Persons List, and Unverified List. Fifth, determine whether an exception applies, or whether a licence application to BIS is required.
The most important operational point is sequence: the OFAC analysis must not wait for the EAR analysis to complete, and vice versa. In a time-sensitive trade transaction, both tracks run in parallel. A clean OFAC result does not clear the EAR; a clean EAR result does not clear OFAC. We regularly advise clients who have conflated these into a single "sanctions check" and found themselves with an incomplete analysis on one track.
Where does enforcement posture differ – and which regime carries the higher immediate risk?
Neither regime is lenient. But the enforcement mechanics differ in ways that affect a compliance team's prioritisation. OFAC enforcement is strict-liability in its civil dimension: a violation can be established without proof that the responsible party knew the transaction was prohibited. The existence of a sanctions compliance programme is relevant to penalty calculation and to whether a case is settled as an apparent violation, but it does not prevent the finding of a violation. Civil penalties are calculated against the greater of a statutory per-transaction maximum or the value of the transaction, and both figures have been set at levels that represent material exposure for any firm involved in cross-border trade.
BIS enforcement under the EAR requires knowledge or reason to know in its civil dimension for most violations, though certain strict-liability provisions apply to embargo violations. The "red flag" standard – under which a party is on constructive notice of a potential violation if sufficient warning signs exist, regardless of subjective awareness – effectively narrows the knowledge defence in practice. BIS also has the power to deny export privileges, which for a business dependent on US-origin goods, technology, or software can be more commercially damaging than any civil penalty.
For financial institutions and payment processors, OFAC exposure tends to dominate the immediate risk calculus because payment clearing creates direct OFAC-jurisdictional exposure with every dollar transaction. For manufacturers, exporters, and freight forwarders, EAR exposure is often the primary operational risk because item classification and end-user controls sit at the heart of every shipment. In our cross-border practice, the transactions generating the most acute combined exposure are those that involve advanced manufacturing, semiconductor, or dual-use goods moving through multi-leg supply chains with layered intermediaries. Is your screening programme calibrated to that dual-track exposure, or is it running a single check?
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss an urgent review.
How do the regimes interact with other major sanctions systems?
OFAC and BIS / EAR do not operate in isolation. For a cross-border business, the same transaction will almost always engage the sanctions or export-control rules of at least one other jurisdiction. The interaction pattern varies by the transaction's structure and the parties' nationalities.
The UK position is administered by OFSI for financial sanctions and ECJU for export licensing. The UK's financial-sanctions rules adopt an ownership and control test (the UK and EU standard for whether a non-listed entity is caught through a listed person's position) that goes beyond the purely mechanical OFAC 50 percent calculation: a non-listed entity can be caught if a designated person controls it, even without meeting the ownership threshold. For a business with UK operations or a UK bank in the payment chain, OFSI compliance is a parallel obligation, not a subset of OFAC compliance. The EU position under the relevant Council regulations applies a broadly comparable ownership-and-control standard, but the scope of prohibited conduct and the licensing routes differ from both OFAC and OFSI.
The extraterritorial reach of US controls creates a layer of obligation for non-US businesses that screens through the EAR. A European manufacturer incorporating US-origin components above the de minimis threshold into a finished product faces EAR jurisdiction over re-exports of that finished product, even if the re-export is entirely between non-US parties. For that manufacturer, BIS Entity List screening is not a US law matter; it is a direct business obligation affecting every export sale. The foreign direct product rule, as expanded in recent BIS rulemaking, has extended this logic further still, covering items produced using certain US equipment or software even when no US-origin material is incorporated into the finished product.
For businesses operating in Singapore, Japan, or the UAE, local export-control and financial-sanctions regimes add a further layer. Each of those jurisdictions maintains its own controlled-goods lists and its own sanctions obligations, which in some respects mirror but do not replicate OFAC or BIS / EAR requirements. Where divergence exists, a business must satisfy the stricter prohibition; it cannot rely on compliance with one regime to discharge its obligations under another.
What are the most common screening failures in trade transactions?
Screening failures in trade transactions cluster around a small number of recurring patterns. Understanding them is the first step to closing the gap.
The first failure is insufficient party coverage. Screening the buyer and the seller but not the freight forwarder, the shipping agent, or the vessel is a routine gap. OFAC's vessel-screening obligations are well-established: a vessel owned or operated by a blocked party is itself a target for sanctions compliance purposes. BIS entity concerns can arise equally at the logistics level, where a party coordinating the movement of goods may itself be listed or may be acting on behalf of a listed end-user.
The second failure is static rather than dynamic screening. A party that is clean at the time of contract execution may be added to a list between signing and delivery. Transactions with long lead times – project cargo, construction materials, capital equipment – are particularly exposed. A compliance programme that screens once at onboarding and not again at the time of each transaction creates an interval during which an undetected designation can occur.
The third failure is conflating the OFAC and EAR tracks. Compliance teams that treat a clean OFAC result as clearance for the EAR, or vice versa, will miss scenarios in which one track is clean and the other is not. Each regime requires its own documented analysis.
The fourth failure is inadequate ownership tracing. The OFAC 50 percent rule requires aggregating all blocked-person holdings in the counterparty. A counterparty that is 49 percent owned by one SDN and zero percent by another is clean. But a counterparty held at 30 percent by one SDN and 25 percent by a second SDN is blocked. Screening tools that do not surface aggregated beneficial-ownership data cannot perform this calculation correctly. We have seen this gap produce compliance failures even in programmes that were otherwise well-designed.
The fifth failure – and arguably the one with the most immediate enforcement consequence – is treating red flags as items to be resolved administratively rather than as legal questions. Under the EAR, a party that proceeds with a transaction after identifying red flags, without resolving them through adequate due diligence, has constructive knowledge of the violation. The same logic applies under OFAC's guidance on the circumstances in which a sanctions compliance programme provides penalty mitigation. A red flag that is documented and not escalated is worse, from an enforcement standpoint, than a red flag that was never identified at all.
What is the practical decision sequence before a trade transaction closes?
The decision sequence for a cross-border trade transaction with OFAC and EAR exposure follows a defined analytical path. Compressing or skipping steps creates legal exposure that the transaction's commercial value rarely justifies.
Step one: classify the item at the outset. Before any counterparty screening begins, determine the ECCN of the goods, software, or technology. If the item is EAR99, the EAR licensing analysis is shorter – but EAR99 does not mean EAR-exempt, and party and destination screening under the EAR still applies. If the item has a specific ECCN, identify the applicable licence requirements and available exceptions for the destination.
Step two: map all parties and screen against all relevant lists. OFAC lists: the SDN List, the relevant sectoral and non-SDN lists, and the OFAC Consolidated Sanctions List. BIS lists: the Entity List, the Denied Persons List, and the Unverified List. Parties to screen: buyer, seller, freight forwarder, shipping agent, vessel owner, vessel operator, any intermediate consignee, and the issuing bank or payment intermediary.
Step three: apply the ownership test. For each party that is not itself listed but presents ownership complexity, trace the beneficial-ownership chain and aggregate any blocked-person holdings under the OFAC 50 percent rule. Apply the UK and EU ownership-and-control test if those regimes are in scope for the transaction.
Step four: assess the destination. Determine whether OFAC administers a comprehensive or partial embargo on the destination country. Determine the EAR's licensing policy for that destination. Identify any heightened-review requirements under either regime.
Step five: resolve red flags before proceeding. If any party appears on the Unverified List, BIS guidance sets out the steps required before the transaction may proceed. If any party presents an unresolved hit on an OFAC list, the transaction must pause until the hit is resolved – confirmed as a false positive with documented rationale, or escalated as a potential prohibited transaction.
Step six: document the analysis. A compliance record that sets out the lists checked, the date of the check, the results, the ownership analysis, and the basis for any red-flag resolution is the foundation of both an enforcement defence and a voluntary self-disclosure if a problem later emerges. Records should be retained for a period consistent with each regime's record-keeping requirements; verify the applicable period before relying on any default assumption.
In a recent matter, a financial institution with a trade-finance portfolio discovered that its screening system was returning results only against the SDN List, without checking sectoral lists or BIS lists. We conducted a portfolio review, identified the exposure, and redesigned the screening protocol to cover all required lists with dynamic rescreening at each transaction stage. The matter was resolved without enforcement action.
Related practices
- Correspondent banking and de-risking – OFAC screening obligations for banks and payment institutions in correspondent relationships
- Trade-transaction screening: OFAC vs EU – criterion-by-criterion comparison of US and EU screening obligations for cross-border transactions
- Trade-transaction screening: OFAC vs EU (2) – further analysis of divergence points and practical compliance implications