A trading house with operations across three continents executes dozens of transactions each week. Its compliance team screens counterparties against the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and flags clean. The shipment is cleared. Weeks later, the firm receives an administrative subpoena – not from OFAC, but from BIS. The item shipped had a dual-use classification. The end-user was on the Entity List (BIS's list of parties to whom US-origin items may not be exported without a licence). The screening programme had checked the wrong list entirely.
As of January 2026, trade-transaction screening in the United States sits across two separate regulatory regimes with different authorities, different list architectures, and different legal triggers. OFAC administers economic sanctions under IEEPA and related authorities; BIS administers export controls under the EAR. A programme that checks only OFAC lists is incomplete. One that checks only BIS restricted-party lists is equally incomplete. The gap between them is where enforcement actions are made.
This analysis maps where the two regimes diverge, identifies the points of overlap, and sets out the risk flags that cross-border businesses most commonly miss – drawing comparisons with OFSI, EU, and UN obligations where the divergence is operationally significant.
What each regime controls and why they are not the same
OFAC controls who you deal with; BIS controls what you ship and to whom – and those two questions are distinct in law even when they converge on the same transaction. OFAC's legal basis is a set of economic-sanctions authorities, primarily IEEPA, under which the US Treasury designates persons, entities, and vessels. Its list infrastructure is the SDN List, plus programme-specific lists such as the Non-SDN Consolidated Sanctions List. The prohibition is transactional: you may not deal with a blocked person or their property, regardless of what the goods or services are.
BIS, by contrast, is focused on items. Its authority derives from the Export Control Reform Act and the EAR. The Entity List is the most widely known BIS restricted-party tool, but it sits alongside the Denied Persons List, the Unverified List, and the Military End-User List. Each carries different licence requirements and prohibitions. The Commerce Control List classifies items by ECCN (Export Control Classification Number under the US Commerce Control List), and whether a specific transaction needs a licence depends on the item's classification, the destination, the end-use, and the end-user simultaneously.
In our cross-border practice, the confusion most often arises at precisely this seam: a business treats its OFAC screening as its export-controls check, or vice versa. The two programmes share certain restricted parties – some SDNs also appear on BIS lists – but the overlap is partial. An entity that appears on neither OFAC list nor the Entity List could still be subject to EAR controls because of its end-use or the military-end-user analysis. That risk falls entirely outside a standard sanctions-screening tool.
The architecture of OFAC screening: what a complete programme must check
A complete OFAC screening programme covers not just the SDN List but the full constellation of OFAC list products, and applies the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) to the ownership chain behind every counterparty. The SDN List is the primary list; the Non-SDN Consolidated Sanctions List aggregates several programme-specific lists including the Foreign Sanctions Evaders List and the Sectoral Sanctions Identifications List.
The 50 percent ownership threshold is mechanical. Two blocked persons each holding twenty-five percent of the same entity reach the threshold in aggregate. OFAC does not require that the ownership be direct: intermediate holding companies, subsidiaries, and nominees all count. Screening tools that work from legal-entity name alone – without mapping the beneficial ownership structure – will miss this category systematically.
Beyond list checks, OFAC's sanctions programmes carry transactional prohibitions that are not reducible to a list. Sectoral sanctions restrict certain categories of transaction – particular debt tenors, particular equity instruments – with designated entities in specific sectors. A counterparty may not be on the SDN List at all, yet a proposed transaction could be prohibited by the operative sectoral restrictions. Does your screening programme flag this, or does it only report a list match?
The position above covers the standard analysis. Your counterparty, the structure of the transaction, and the jurisdiction of the goods will each modify the risk profile.
For a tailored review of your OFAC screening architecture, contact Calder & Vance at info@caldervance.com.
How BIS / EAR screening differs: the item-classification layer
BIS screening is not a list check with an ownership analysis appended; it is a multi-variable classification exercise that runs in parallel with, and independently of, the party-screening component. The EAR's control structure requires a business to determine whether its item has an ECCN, what the corresponding reasons for control are, whether a licence exception applies, and whether the end-user triggers additional restrictions – all before a single list is consulted.
The Entity List carries case-specific conditions. A party may appear on the Entity List with a licence requirement of "all items subject to the EAR" – meaning a licence is required even for items that would otherwise qualify for a licence exception. Another entry may specify particular ECCNs or particular countries. Reading an Entity List entry as a binary hit-or-no-hit, the same way an OFAC SDN match is read, is a category error. Each entry must be read as a licence condition statement.
The Unverified List and the Military End-User List carry implications that require a different response entirely. An Unverified List appearance does not prohibit the transaction outright; it requires the exporter to take specific steps to resolve the unverified status before shipping. Failure to do so converts a potential concern into an actual violation. In our experience, exporters that have robust OFAC screening programmes often have no corresponding procedure for Unverified List hits, because the lists look superficially similar.
BIS also operates an extraterritorial reach through the de minimis and foreign direct product rules, which extend US export-control jurisdiction to non-US goods that incorporate a defined proportion of US-controlled content or that are the direct product of US technology. A European manufacturer shipping to a third country may be subject to EAR obligations it has not assessed.
Where do the regimes overlap – and where does the gap create exposure?
The regimes overlap most visibly when an OFAC-designated person also appears on a BIS list: both prohibitions then apply to the same counterparty, and a single transaction triggers obligations under both authorities. The more dangerous scenario is the gap: a party that appears on neither OFAC list nor the SDN List but is subject to BIS control because of its sector, its ownership by a military-end-user, or the nature of the items being procured.
Consider a technology exporter. Its counterparty is a commercial entity with no OFAC designation and no Entity List appearance. But the item being shipped is an advanced semiconductor with a specific ECCN for national-security reasons, destined for a jurisdiction with heightened end-use risk. Under the EAR, this transaction requires a licence regardless of whether any party is listed. An OFAC-only screening programme returns clean. The shipment goes. The violation is complete.
The reverse exposure also exists. A party that does not appear on any BIS list may still be blocked under OFAC's 50 percent ownership rule because of indirect shareholding by an SDN. The EAR party-screening component would not detect this; only the OFAC ownership analysis would. A business that runs EAR party screening but not a full OFAC beneficial-ownership check carries a mirror-image gap.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Write to info@caldervance.com for a confidential preliminary review.
The cross-border dimension: OFSI, EU, and UN obligations alongside OFAC and BIS
A business incorporated in the United Kingdom or operating within the European Union faces a third and fourth layer of screening obligation that does not duplicate OFAC or BIS. OFSI administers UK financial sanctions under the Sanctions and Anti-Money Laundering Act ("SAMLA"); its consolidated list is maintained separately and does not track the SDN List automatically. Post-2020, UK and EU designations have diverged. A person removed from the EU list may remain on the OFSI list, or vice versa.
The EU maintains its own consolidated list of persons and entities subject to asset freezes and transactional restrictions under the relevant Council regulations. Ownership and control (the UK and EU test for whether a non-listed entity is caught through a listed person) differs from OFAC's mechanical 50 percent threshold. Both OFSI and the EU apply a control test in addition to ownership – meaning that an entity majority-owned by a non-listed person, but effectively controlled by a listed one, may still be caught. This is a materially different standard from OFAC's, and it affects how the ownership-structure analysis is conducted.
The UN Security Council Consolidated List represents a baseline: states are obligated under Chapter VII resolutions to implement its asset-freeze and travel-ban provisions. In practice, OFAC, OFSI, and EU designations typically exceed the UN list in breadth and detail. But UN-list screening is independently required, particularly for businesses operating in jurisdictions that have not adopted autonomous national regimes beyond the UN baseline.
For businesses operating across regimes – an American exporter with a European affiliate, or a UK trading house with a US-dollar correspondent banking relationship – the screening architecture must address each regime's list products, each regime's ownership-and-control test, and the transactional prohibitions that attach independently of list matches. We regularly advise on exactly this intersection.
Risk flags that trade-transaction screening programmes most commonly miss
The most common gap is the one already described: treating OFAC list screening as the entirety of the trade-compliance check. Several other recurring risk flags are worth addressing directly.
First, correspondent-banking exposure for financial institutions processing trade finance. A bank that processes a documentary credit for a client's trade transaction may bear OFAC exposure even where the underlying goods are not US-origin and the parties are not US persons. The dollar-clearing link creates jurisdiction. The bank's screening must capture not only the named applicant and beneficiary but also the vessels, ports, and any intermediate parties referenced in the shipping documents. OFSI applies a comparable principle to sterling-clearing transactions.
Second, transit and transshipment risk. The EAR's country-of-ultimate-destination analysis looks through transit points. A shipment routed through an intermediary jurisdiction does not escape EAR jurisdiction if the goods are subject to the EAR and the ultimate destination is a controlled country. Screening only the first-leg counterparty misses the end-destination analysis entirely.
Third, the timing of screening. Sanctions designations and Entity List additions occur without advance notice. A counterparty that was clean at the time of contract signature may be listed before delivery. A screening programme that runs a one-time check at onboarding, without rescreening at each transaction, carries a gap that enforcement authorities have repeatedly noted in civil penalty proceedings.
Fourth, vessel and flag-state screening for maritime transactions. Shipping documentation names vessels, operators, and port agents. OFAC and OFSI both maintain lists of blocked vessels. A transaction routed through a blocked vessel is a prohibited transaction even if every named party is clean. Freight forwarders and trade-finance banks are particularly exposed here.
Fifth, record-keeping. Both OFAC and BIS impose retention obligations. Under OFAC's rules, records of blocked or rejected transactions must be retained for the required period – verify the current obligation before relying on any stated figure. BIS maintains its own record-keeping requirements for export transactions, including documentation of the licence determination and end-use statement.
What the common myth gets wrong about screening sufficiency
The prevalent assumption among cross-border businesses is that a commercially available screening tool with daily list updates constitutes a compliant programme. This is incorrect in three respects.
A screening tool is an input into a compliance programme, not a programme in itself. It cannot perform an ownership-and-control analysis without structured, accurate beneficial-ownership data being fed into it. It cannot apply the transactional prohibitions of sectoral sanctions without a rule set that goes beyond list matching. And it cannot make the item-classification determination that BIS requires. We have acted for clients whose screening technology was market-leading but whose compliance architecture around it was insufficient to meet the five-element standard that regulators apply when assessing a programme's adequacy.
The second misconception is that a "no-match" result confirms the transaction is permissible. Under the EAR, a no-match result on restricted-party lists is a necessary but not sufficient condition for clearance. The item-classification and end-use analysis runs independently. Under OFAC, a no-match result at the named-entity level does not resolve the ownership-chain question.
Third, many businesses assume that EU or UK compliance satisfies OFAC obligations for their US affiliates, or that OFAC compliance satisfies EU obligations for their European entities. The regimes are independent. Extraterritorial reach, particularly OFAC's jurisdiction over US-dollar transactions and US-person involvement, extends US obligations beyond US-incorporated entities. But it does not reverse into treating US-compliance as global compliance.
Related practices
- Correspondent banking and de-risking – managing OFAC exposure in dollar-clearing and trade-finance relationships
- Trade-transaction screening: further analysis – extended regime comparison for complex multi-leg transactions