Calder & Vance International Sanctions & Compliance Counsel

Cross-Border Transactions & Diligence · BIS / EAR

Correspondent-banking de-risking under BIS / EAR: procedure and pitfalls

A trade-finance bank processes a payment for an equipment supplier. The goods appear routine. The end-user, however, sits on the BIS Entity List. The correspondent bank – three time zones away – has no direct relationship with the buyer. Yet the transaction could expose it to a denial order and a loss of export-privilege access. The question is not whether the BIS / EAR rules apply to payments. It is whether the bank has a structured procedure to find out before the wire clears.

Correspondent-banking de-risking (the practice of a financial institution exiting or restricting relationships to avoid trade-control exposure) under the Export Administration Regulations ("the EAR", administered by the Bureau of Industry and Security, "BIS") requires banks to screen not only against the financial-sanctions lists maintained by OFAC, but also against the BIS-maintained lists – principally the Entity List and the Denied Persons List – and to assess whether a transaction involves EAR-controlled items or technology. As of January 2026, BIS enforcement priorities include financial facilitators of controlled-technology transfers, making the correspondent-banking channel a live enforcement target.

This guide walks through the procedure – from initial list screening to end-use assessment and relationship exit decisions – and identifies the pitfalls that most commonly produce enforcement exposure. It also addresses how the BIS / EAR regime sits alongside OFAC sanctions, UK export controls, and the EU dual-use rules, because a correspondent bank operating across those regimes cannot treat them in isolation.

Step 1: Understanding the BIS / EAR obligation on financial institutions

The EAR applies to any person who participates in an export transaction, and that term includes financial institutions that knowingly facilitate the movement of goods, software, or technology that requires a BIS licence or is destined for a listed party. The word "knowingly" matters – but so does wilful blindness, which BIS has historically treated as equivalent to knowledge in enforcement proceedings.

Most correspondent banks approach the EAR as a secondary concern behind OFAC screening. That ordering is understandable: OFAC penalties dominate the enforcement headlines. The EAR, however, operates on a different basis. A transaction may involve no OFAC-listed counterparty and still be subject to BIS licence requirements because the underlying goods have a specific Export Control Classification Number ("ECCN", the code on the Commerce Control List that determines whether a licence is needed). A bank processing the trade-finance leg of an ECCN-controlled shipment without assessing that dimension is operating blind to one of the two major US control regimes.

For a correspondent bank, the practical scope of the obligation is three-dimensional: screen the parties, assess the goods or technology, and evaluate the end-use or end-user. Weakness in any one dimension can produce liability. We regularly advise financial institutions that have strong OFAC controls but no structured EAR overlay. The gap is common; the risk it creates is real.

Step 2: Mapping the BIS lists that drive de-risking decisions

The BIS maintains several lists, each with different legal effects, and a correspondent-banking de-risking programme must address each on its own terms.

The Entity List identifies foreign persons subject to licence requirements for the export, re-export, or transfer of specified items. A licence requirement on the Entity List is not a blanket prohibition – it is a trigger for a licence application – but in practice BIS regularly applies a presumption of denial for listed entities, which makes the commercial effect close to a prohibition for most controlled items. Any bank processing a payment where the beneficiary or end-user appears on the Entity List must assess whether the underlying transaction involves EAR-controlled items and, if so, whether a licence exception applies or an application has been filed.

The Denied Persons List operates differently. Denied persons are subject to an active BIS denial order: all US persons, including correspondent banks, are prohibited from participating in any transaction involving them. The prohibition is categorical; there are no licence exceptions. A payment that passes through a US correspondent bank and involves a denied person is a violation, full stop.

The Unverified List is a softer instrument. It identifies parties for whom BIS has been unable to verify end-use. No licence requirement automatically attaches, but a bank that proceeds without heightened due diligence on an unverified-list party risks a "red flag" finding. The military end-user and military intelligence end-user designations operate similarly: they are triggers for enhanced assessment rather than automatic prohibitions, but ignoring them is not a tenable compliance posture.

In our experience, correspondent banks frequently screen against the Denied Persons List and the SDN List, but do not maintain a structured feed for Entity List updates. BIS adds parties to the Entity List with little advance notice and does so frequently. A static screening configuration built in one quarter may be out of date by the next.

Step 3: The end-use and end-user assessment – where procedure meets judgement

List screening tells you about the parties. It does not tell you about the goods or their destination use. The EAR's controls are item-and-destination driven, not solely party-driven. A correspondent bank that clears a payment because no listed party appears on any list may still be facilitating an unlicensed export of a controlled item.

How does a bank assess item control classification without being the exporter? The short answer is: it cannot perform a full ECCN analysis on every transaction. What it can do – and what BIS enforcement guidance supports as a reasonable compliance posture – is build a risk-tiered system that flags transactions by sector, goods description, and destination. High-risk sectors include advanced semiconductors, telecommunications equipment, encryption technology, and certain chemicals. Transactions in those sectors, to certain destinations, warrant enhanced review and a request for the underlying export documentation from the originating bank.

The cross-regime angle bites here. A UK bank acting as a correspondent is subject not only to the EAR (through its US correspondent relationship) but also to ECJU export-control rules on dual-use items and to EU dual-use regulations if it has EU-based operations. A transaction involving dual-use goods may require export authorisation under all three regimes simultaneously. A de-risking decision made on UK-control grounds alone may leave BIS exposure unaddressed. Conversely, an item that does not require a BIS licence may still require an EU authorisation.

What should the procedure look like in practice? The minimum is a documented decision flow: identify the goods category, check it against high-risk sectors, request shipping and customs documentation for elevated-risk payments, and escalate to a sanctions and export-control specialist for determination. That flow must be applied before the wire clears, not after. A post-payment review process has value for trend analysis, but it does not address the individual transaction risk.

Step 4: How does BIS / EAR differ from OFAC sanctions in the correspondent-banking context?

The BIS / EAR regime and the OFAC sanctions regime share the same ultimate US government enforcement machinery but operate on materially different legal bases, and the differences directly shape a correspondent bank's de-risking decisions.

OFAC prohibitions are primarily party-based. If a person or entity appears on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons) or is owned 50 percent or more by a blocked person (the 50 percent rule), all transactions with that person are blocked. The test is largely mechanical once you have identified the party. OFAC also maintains country-programme prohibitions that operate as blanket restrictions on certain jurisdictions.

BIS controls are item-, destination-, and end-use-driven. The same counterparty might be permissible under OFAC but require a BIS licence for specific goods. Or the counterparty might appear on the Entity List but not the SDN List, meaning the OFAC screen returns clean while the BIS screen requires a licence determination. A correspondent-banking compliance programme that conflates the two regimes – treating a clean OFAC screen as a complete export-control clearance – is structurally deficient.

The enforcement posture also differs. OFAC enforcement focuses heavily on the financial system: banks, payment processors, and money-services businesses are the primary targets of OFAC civil enforcement. BIS enforcement has historically focused on exporters, freight forwarders, and manufacturers. The shift toward financial facilitators of technology transfer is a documented BIS enforcement priority as of 2026, but the institutional culture of BIS enforcement still places primary accountability with the exporter. That does not absolve the bank; it means the bank's risk is more likely to arise through a referral from a parallel criminal investigation than through a stand-alone BIS civil proceeding. For compliance-programme purposes, the relevant question is the same: is the bank's procedure sufficient to avoid the "knowing" or "wilful blindness" findings?

Under UK export controls administered by the ECJU, the legal framework similarly distinguishes financial facilitation from direct export. A UK correspondent bank may face ECJU questions about payments it processes for certain trade flows, particularly where those flows involve dual-use goods to controlled destinations. The UK's ownership and control test (the test for whether a non-listed entity is caught through a listed person) mirrors the EU approach more closely than the mechanical OFAC 50 percent rule, which creates divergences in how de-risking decisions map across regimes for the same counterparty.

Step 5: Red flags, risk indicators, and when to escalate

De-risking decisions in the correspondent-banking context are rarely obvious. A bank that exits every relationship involving any potential trade-control issue will terminate vast amounts of legitimate trade. The challenge is calibration – identifying the patterns that genuinely signal export-control risk and acting on those, rather than applying blanket exclusions that produce over-de-risking without reducing real risk.

BIS has articulated specific red flags that practitioners should embed into transaction-monitoring logic. The following are illustrative, not exhaustive: a buyer reluctant to identify the end-use of goods; shipping routes that are circuitous relative to the declared destination; payments structured to route through intermediate jurisdictions without apparent commercial purpose; goods descriptions that are vague relative to the invoice values involved; requests to omit standard export documentation from the payment instruction.

Consider what these red flags mean in practice. A payment instruction that omits a destination on goods described only as "electronic components" to a freight forwarder with no traceable principals is a multiple-flag transaction. A well-designed monitoring system should route that payment to manual review before release. That review should include a request to the originating bank for the full shipping documentation and end-user information, and a hold on funds pending receipt.

The escalation trigger for counsel is not the appearance of a red flag alone. It is the combination of a red flag with uncertainty about the applicable BIS licence requirement or the applicable licence exception. A bank's internal compliance team can apply the screening logic. Determining whether a specific item and end-user combination requires a licence – or whether an exception, such as the licence exception for technology in the public domain, applies – requires a classification analysis that is properly the work of export-control counsel or a qualified compliance specialist.

Is your monitoring system updated to reflect the BIS lists as currently published? Stale data is one of the most common findings in BIS-adjacent enforcement reviews. Have you defined, in writing, which goods categories trigger enhanced review in your correspondent-banking flows? Without a documented standard, escalation decisions are inconsistent – and inconsistency is itself a risk indicator in a BIS review.

Step 6: The de-risking decision and exit process – managing the relationship

When a correspondent bank concludes that a respondent relationship presents unacceptable BIS / EAR risk, the exit must be managed carefully. A sudden, unilateral termination can itself create legal exposure if the bank holds funds subject to a pending shipment or a payment obligation under a letter of credit. It may also leave the respondent bank in a position where legitimate transactions are stranded, generating contractual and reputational consequences.

The preferred approach is a risk-graduated exit. First, elevate the relationship to enhanced monitoring and documentation requirements. Second, notify the respondent of the specific control concerns and give a short period – defined by the bank's internal risk policy – for the respondent to provide the information needed to resolve the concern. Third, if the information is not provided or does not resolve the concern, begin a managed wind-down of the relationship, processing only pre-existing commitments and declining new business during the run-off period.

That process creates a documented record. If BIS or DOJ subsequently reviews the bank's conduct in relation to that respondent relationship, a documented, graduated exit demonstrates a good-faith compliance posture. An abrupt termination without documentation looks reactive; a managed exit with contemporaneous records looks deliberate.

In a recent matter, a financial institution in Asia identified a correspondent relationship where the respondent bank was processing payments for a supplier of electronic components to destinations that the financial institution's enhanced-review system flagged as high-risk. We assessed the underlying transaction patterns, the goods classifications involved, and the BIS list status of the parties. The result was a structured exit protocol, with contemporaneous documentation of each decision point. The matter closed without regulatory referral.

The cross-border dimension requires one more observation. A correspondent bank with a European parent faces the EU dual-use rules simultaneously with the EAR. The EU rules impose their own controls on the export of dual-use items from EU territory, and they contain their own provisions on technical assistance and brokering that can capture payments processed by EU-based affiliates of the bank. A de-risking decision that resolves the BIS exposure for the US correspondent operation must also be tested against the EU position. Relying on local counsel in the relevant jurisdiction is essential where the two regimes diverge.

Related practices

Frequently asked questions

What are the steps to manage de-risking exposure under BIS / EAR?
The core steps are: screen all parties against the full BIS list suite (Entity List, Denied Persons List, Unverified List, and military end-user designations), not solely the SDN List; build a risk-tiered goods-category overlay that flags high-risk sectors for enhanced review; establish a documented decision flow that is applied before payment release; request end-use documentation for elevated-risk transactions; and maintain a managed-exit protocol with contemporaneous records. Each step must be documented and applied consistently to support a good-faith compliance finding in any subsequent BIS review. Verify all current list content and licence requirements before relying on any assessment, as the lists are updated frequently and without advance notice.
What is the most common mistake in correspondent-banking de-risking?
The most common mistake is treating a clean OFAC screen as a complete trade-control clearance. OFAC and BIS operate on different bases: OFAC screening addresses party identity; BIS controls address the item, the destination, and the end-use. A transaction can clear every OFAC list and still require a BIS licence for the underlying goods. Banks that do not maintain a separate, item-sensitive BIS overlay in their correspondent-banking monitoring are systematically under-screening for export-control risk. A secondary common mistake is using a static screening configuration that is not updated as BIS adds parties to the Entity List – additions that can occur at any time and with limited public advance notice.
How does BIS / EAR differ from other regimes here?
The EAR is fundamentally item- and destination-driven, whereas OFAC sanctions and most financial-sanctions regimes (OFSI in the UK, the EU Council regulations) are primarily party-driven. This means the same counterparty can be clean on every financial-sanctions list yet still trigger BIS licence requirements for specific goods. Additionally, BIS enforcement of financial-facilitator liability is a stated priority as of 2026, bringing correspondent banks squarely within scope. The UK's ECJU dual-use controls and the EU dual-use rules operate on a similar item-and-destination logic but with different commodity lists, thresholds, and licence exceptions. A bank operating across these regimes must address each separately; a single screen or a single exit decision does not resolve all three.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.