Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFAC

Deemed exports and technology transfer under OFAC: a compliance guide

A US university research lab hires a visiting scholar from a country subject to broad OFAC programme restrictions. The scholar will work on a controlled software project. Does the hiring decision trigger sanctions exposure before a single line of code is shared? For many multinationals, technology companies, and academic institutions, this question arrives without warning – and the answer determines whether they face a strict-liability civil penalty.

A deemed export occurs when controlled technology or source code is released to a foreign national inside the United States, treating that release as an export to the person's home country. Under OFAC's sanctions programmes, any such release to a national of a comprehensively sanctioned country, or to a specially designated national (SDN List – OFAC's list of Specially Designated Nationals and blocked persons), is a prohibited transaction regardless of the physical location of the parties. OFAC jurisdiction is strict-liability: intent does not eliminate exposure.

This guide sets out how OFAC's deemed-export analysis works, how it intersects with the Bureau of Industry and Security's parallel rules under the Export Administration Regulations, where the UK and EU regimes diverge, and what a business must do before it brings foreign nationals into contact with controlled technical data. As of April 2026, OFAC continues to treat technology-transfer violations as priority enforcement targets.

Step 1: Understand the OFAC deemed-export concept and its legal basis

The OFAC deemed-export prohibition flows from the same statutory authority – the International Emergency Economic Powers Act (IEEPA) and the Trading with the Enemy Act (TWEA) – that underpins all US economic sanctions. When a person "exports" technology, they engage in a transaction with the foreign national's country of nationality. If that country is subject to a comprehensive OFAC programme, the transaction is presumptively prohibited. If the foreign national is on the SDN List, the prohibition applies regardless of which country they are from.

Two separate triggers must be tracked. First, country-based programmes: a release to a national of a comprehensively designated country is treated as a transaction with that country's government or economy. Second, person-based designations: if a foreign national employed at your facility, even temporarily, is themselves an SDN, or is 50 percent or more owned or controlled by a blocked person, the release is itself a blocked transaction under the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked – applied by analogy to individuals through control analysis). Practitioners sometimes treat these as one question. They are not.

In our experience, businesses that maintain clean country-screening records still accumulate SDN exposure because they fail to re-screen existing employees and contractors against updated list additions. OFAC updates the SDN List without a fixed schedule. A clean screen at hire is not a clean screen today.

Step 2: Map which technology and source code is within scope

OFAC does not maintain a technology control list of its own; instead it prohibits all transactions with blocked persons and countries, making the scope question one of breadth rather than classification. Any technical data, source code, software, or proprietary know-how that a business releases to a foreign national can constitute a deemed export if the other jurisdictional conditions are met. There is no minimum-value threshold, no de minimis exception for brief demonstrations, and no carve-out for publicly available information that has been integrated into a proprietary system.

The contrast with the Export Administration Regulations (EAR – BIS's rules governing dual-use goods, software, and technology) is instructive. The EAR applies a classification-based test: technology falls under a specific Export Control Classification Number (ECCN – a code on the Commerce Control List that determines which countries and end-uses require a licence). Only technology that is not in the public domain, or that has a non-EAR99 classification, triggers the EAR deemed-export rule. OFAC's scope is categorically wider. A business may conclude that its technology is EAR99 – unclassified for export-control purposes – and still face a direct OFAC sanctions violation if the recipient is a national of a comprehensively sanctioned country.

Do you know whether your standard IP-access protocols distinguish between EAR classification and OFAC country exposure? Most enterprise compliance programmes conflate the two, which is one of the most common errors we see in cross-border technology businesses.

Step 3: Conduct nationality and designation screening for all persons with access

Effective deemed-export screening covers everyone with access to controlled systems, repositories, physical laboratories, or technical presentations – not just new hires. The population includes permanent employees, contractors, temporary staff, visiting researchers, joint-venture counterparts, and participants in conference calls where controlled technical content is shared.

For OFAC purposes, the relevant identity markers are nationality (country of birth and current nationality, not merely passport held) and designation status (SDN List and the relevant OFAC consolidated lists). A person may hold a US green card or even a US passport and still be a national of a comprehensively sanctioned country under OFAC's interpretation. Dual nationals require case-by-case analysis.

The screening process should be structured in three layers:

  1. Initial screen at the point of onboarding against the current OFAC SDN List and the relevant country programme lists.
  2. Periodic re-screen at defined intervals – the appropriate frequency depends on the risk profile of the role and the volatility of the relevant programme, but in our cross-border practice we advise clients to re-screen at least annually for all roles involving access to controlled technology.
  3. Triggered re-screen whenever OFAC announces significant list updates, particularly those affecting the counterparty's sector or region.

A record of each screen, including the date, the list version consulted, and the result, should be retained. OFAC expects businesses to maintain records sufficient to demonstrate a compliance posture. The UK regime under OFSI and the EU equivalent both impose explicit record-keeping obligations, and where a business operates under multiple regimes, a single integrated screening log that satisfies the most demanding standard is the efficient solution.

Step 4: Assess parallel BIS/EAR obligations and where the regimes diverge

For most technology businesses, a deemed export that triggers OFAC exposure will simultaneously engage BIS obligations under the EAR. The two regimes are administered by separate agencies – OFAC sits within the US Department of the Treasury, BIS within the Department of Commerce – and each enforces independently. A voluntary self-disclosure (VSD – a formal self-report of an apparent violation to a regulator) to one agency does not protect the disclosing party from enforcement by the other. Both must be assessed separately.

The critical divergence is in the licensing architecture. BIS issues technology-specific licences tied to the ECCN classification, the destination country, and the end-use. OFAC issues specific licences (specific licence – a case-by-case authorisation to conduct an otherwise prohibited transaction) for sanctioned-country programmes, and general licences (standing authorisations permitting defined categories of transactions) for limited carve-outs such as academic research or personal remittances. The OFAC specific-licence route for technology transfer to a national of a comprehensively sanctioned country is narrow: OFAC's general licences rarely extend to controlled technical data, and specific-licence applications in this area receive close scrutiny.

In a recent matter, a technology company in the semiconductor supply chain discovered that three contractors had been granted access to a controlled technical repository without a deemed-export analysis. The nationality of two was unproblematic, but the third was a national of a country subject to a comprehensive OFAC programme. We assessed the apparent violation, scoped the disclosure options under both OFAC and BIS, and supported the company through the self-disclosure process. The matter resolved without the maximum penalty exposure that strict-liability enforcement would otherwise have generated.

The position above covers the standard case. Your facts – the specific programme, the nationality involved, the technology classification, and the route to access – change the analysis materially.

For an assessment of your deemed-export exposure under OFAC and BIS, contact Calder & Vance at info@caldervance.com.

Step 5: Apply the cross-regime comparison – UK, EU, and beyond

US businesses with UK or EU operations face parallel deemed-export obligations that do not mirror the OFAC model. Understanding the divergences prevents both over-compliance (refusing all foreign-national access on a misreading of UK or EU rules) and under-compliance (assuming the US screen is sufficient for a London or Amsterdam operation).

Under the UK regime, the Sanctions and Anti-Money Laundering Act (SAMLA) and the relevant thematic sanctions regulations administered by the Office of Financial Sanctions Implementation (OFSI) prohibit making funds and economic resources available to designated persons. The OFSI ownership and control test (the UK test for whether a non-listed entity is caught through a listed person's ownership or control) is broader in one direction and narrower in another compared with OFAC: it includes a control limb that OFAC's purely mechanical 50 percent test does not, but it does not extend OFSI restrictions to foreign nationals of comprehensively sanctioned countries in the same way OFAC does. The UK export licensing authority, the Export Control Joint Unit (ECJU), administers a separate technology-transfer control that is classification-based, broadly analogous to the BIS model rather than the OFAC model.

In the EU, Council regulations prohibit making technical assistance and technology available to designated persons, but the EU dual-use rules – governed by the EU Dual-Use Regulation – operate on a classification basis, and comprehensive country embargoes vary by programme. The EU does not operate a deemed-export doctrine as broad as OFAC's. However, where EU sanctions apply comprehensively to a country's government and economy, releasing technology to a national of that country who is connected to a designated entity may constitute a prohibited transaction under EU law – the analysis is fact-specific.

For businesses with operations across all three regimes, the practical approach is to design the deemed-export screening and access-control programme to the most restrictive applicable standard (ordinarily OFAC's), and then test whether that design also satisfies UK and EU obligations. Where it does not – because the UK or EU rules impose additional steps, such as OFSI-specific reporting or EU-specific technical-assistance prohibitions – those steps must be layered in.

Step 6: Design and document the internal compliance architecture

A deemed-export compliance programme that satisfies OFAC's expectation of a credible compliance posture has five structural elements: management commitment, risk assessment, internal controls, testing and auditing, and training. OFAC's published compliance guidance makes clear that the presence or absence of these elements is a factor in assessing penalties and in treating a VSD favourably.

For technology-transfer risk specifically, the internal controls element must address the following:

  • Access-control architecture: who can reach what repository, laboratory, or technical data room, and on what terms.
  • Nationality and designation data: how nationality information is collected, stored, and updated for all persons with access.
  • Screening cadence and record-keeping: the schedule for periodic and triggered rescreens, and the format in which records are retained.
  • Escalation path: who reviews a potential hit, at what seniority, and within what timeframe.
  • VSD readiness: a pre-established process for scoping an apparent violation and preparing a disclosure, so that when an issue surfaces it is not handled ad hoc.

Training is frequently the weakest element. In our experience, engineering teams and laboratory managers who handle controlled technology on a daily basis have received little or no sanctions training. They know about IP confidentiality and export-control classification because those topics feature in their onboarding. They do not know that showing a controlled process diagram to a visiting researcher may be a deemed export requiring a prior licence assessment. That gap is an enforcement risk.

If a transaction has already been flagged, or a foreign-national access event has been identified as potentially unlawful, an early legal review preserves options that narrow quickly. Contact Calder & Vance at info@caldervance.com.

Step 7: Recognise the risk flags that signal immediate counsel involvement

Deemed-export risk is not uniformly distributed across a business. Certain patterns signal elevated exposure that warrants immediate specialist review rather than routine compliance processing.

The first risk flag is a workforce or contractor base drawn from a broad range of nationalities in a business that handles controlled technology – particularly where nationality data has not been systematically collected or where it has been collected but not mapped against OFAC programme coverage. Many businesses that underwent rapid international hiring in the past five years have this gap.

The second flag is an acquisition or joint venture that brings in a new team with different access controls. Post-acquisition integration frequently exposes the acquirer to deemed-export violations that pre-dated the deal: the target's employees had access to the acquirer's technology before the combined screening programme was in place.

The third flag is an OFAC list update that adds a new designation in a sector where you have existing foreign-national contractors or employees. OFAC's enforcement posture does not treat post-designation retention of a now-designated person as an innocent continuation of a prior status. The violation runs from the moment the designation is effective.

The fourth – and perhaps most important for technology businesses – is a pattern of sharing technical data through collaboration platforms, shared development environments, or version-control repositories where access permissions are broad and nationality screening has not been applied to every participant. The mechanism of transfer (digital, physical, or verbal) does not change the legal analysis.

A common myth in this area deserves direct correction: many technology businesses believe that if their product is not subject to EAR controls – because it is EAR99 or because it is software designed for a consumer market – they face no deemed-export exposure. That belief is wrong. OFAC's prohibition on transactions with blocked persons and comprehensively sanctioned countries applies independently of EAR classification. The OFAC analysis is a separate, additional question that must be answered even after a clean EAR classification exercise.

Related practices

Frequently asked questions

What are the steps to manage deemed-export risk under OFAC?
Effective management requires seven sequential steps: establish the legal basis and scope of OFAC's jurisdiction over your technology; map the controlled technology and source code that sits within that scope; screen all persons with access against the SDN List and relevant country programmes; assess parallel BIS/EAR obligations and their licensing routes; apply cross-regime analysis for UK and EU operations; build and document the five-element compliance architecture; and identify risk flags that trigger immediate legal review. Each step produces a documented output that forms part of your compliance record. Where an apparent violation surfaces, the VSD process must be assessed before deciding whether and how to disclose.
What is the most common mistake in deemed exports and technology transfer?
The most common mistake is equating a clean BIS/EAR classification with full compliance. A business that determines its technology is EAR99 – outside BIS licensing requirements – may conclude it has no deemed-export obligations. That conclusion is incorrect: OFAC's prohibition operates independently of BIS classification and extends to any release of technology to a national of a comprehensively sanctioned country or to any SDN. The second most frequent error is screening only at the point of hire and not re-screening when OFAC updates its lists. A clean hire-date screen does not protect against post-hire designations.
How does OFAC differ from other regimes here?
OFAC's deemed-export rule is categorically broader than its UK and EU equivalents. OFAC applies it to all releases of technology to nationals of comprehensively sanctioned countries, with no requirement for BIS-style classification. The UK's OFSI approach is designation-based rather than country-national-based, and ECJU's technology-transfer control tracks the BIS classification model more closely. The EU Dual-Use Regulation is also classification-based. For businesses operating under all three regimes, OFAC sets the widest obligation, but UK and EU rules add distinct requirements – particularly OFSI's ownership-and-control test and the EU's technical-assistance prohibitions – that must be assessed separately.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.