Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFAC

Deemed exports and technology transfer under OFAC: a practical guide

A US-headquartered manufacturer prepares to transfer technical drawings to an overseas colleague working on a dual-use product. The colleague is a national of a country subject to comprehensive OFAC sanctions. No goods cross a border. No export-control licence application appears on the compliance team's radar. Yet the transfer may already have occurred — the moment the drawings are shared on a screen in the same room.

A deemed export (the legal fiction that sharing controlled technology or source code with a foreign national inside the United States constitutes an export to that person's country of nationality) sits at the intersection of two distinct US regulatory regimes: the Export Administration Regulations administered by the Bureau of Industry and Security, and the economic-sanctions programmes administered by the Office of Foreign Assets Control. Compliance counsel must manage both. OFAC's controls operate alongside, and sometimes independently of, BIS deemed-export requirements — and as of April 2026 the interaction between the two remains a source of systematic underestimation by in-house teams.

This guide walks through the governing authorities, the analysis required, a step-by-step risk-management procedure, the cross-regime comparison with OFSI and the EU, and the risk flags that should prompt immediate involvement of sanctions and export-control counsel.

Step 1: Understand the governing authorities and what each controls

Two federal authorities govern deemed-export and technology-transfer risk for US operations: BIS, which administers the Export Administration Regulations and the Commerce Control List, and OFAC, which administers the economic-sanctions programmes enacted under IEEPA, TWEA, and related statutes. They control different things, apply different tests, and are enforced by different agencies — but they can bite on exactly the same transaction.

BIS focuses on the technical characteristics of the item being transferred. It asks whether the technology or source code in question has an ECCN (Export Control Classification Number under the US Commerce Control List) that restricts release to nationals of particular countries or that requires a licence for the transfer at all. The analysis begins with item classification and ends with an end-user and end-use check.

OFAC's analysis is person-centric and transaction-centric. OFAC asks whether the recipient is a Specially Designated National (a person on OFAC's list of Specially Designated Nationals and blocked persons) or an entity owned 50 percent or more by one or more SDNs in the aggregate. It also asks whether the subject matter of the transfer — the technology, the project it supports, the sector it touches — is caught by a country-based comprehensive or sectoral programme.

In our practice, the most common structural error is running only a BIS deemed-export analysis and treating a clean ECCN result as a green light for OFAC purposes. It is not. The two analyses must run in parallel, not in sequence.

Step 2: Map the transfer and identify the foreign-national nexus

Before any analysis can begin, the business must identify every transfer and every person involved. A deemed export occurs not only when technology is sent abroad but also when it is released within the United States — or from any location — to a person who is not a US citizen, lawful permanent resident, or protected individual under applicable immigration and nationality law.

For OFAC purposes the relevant question is nationality, not immigration status. A person may hold a valid US work authorisation and yet still carry the nationality of a comprehensively sanctioned country. That nationality determines whether OFAC's country-programme prohibitions apply to the release of technology to that person.

Mapping the transfer means answering five questions in sequence:

  1. What is being transferred — is it technology, software, source code, or technical data? In what form: drawings, verbal briefings, access to a system, demonstration?
  2. Who is the recipient? What is their nationality or nationalities? Are they on any sanctions list?
  3. Where is the transfer occurring? Inside the United States, from a US person abroad, or by a non-US subsidiary of a US parent?
  4. What project or end use is the technology intended to support?
  5. Does the recipient's employer, client, or project-owner itself have a sanctions nexus — through designation, ownership, or sectoral restrictions?

Do not assume that verbal technical briefings, on-site demonstrations, or collaborative software sessions fall outside the definition. In our experience, engineering and R&D teams routinely underestimate the breadth of what counts as a "release" for these purposes. The question is whether the foreign national gains access to or knowledge of the controlled technology — the medium is secondary.

Step 3: Run the OFAC-specific analysis — list screening, ownership, and programme scope

With the transfer mapped, the OFAC analysis has three distinct components: list screening, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked), and programme-scope review.

List screening covers the individual recipient, their immediate employer, any associated entities, and — critically — the ultimate beneficial owners of those entities. The SDN List is the primary check, but OFAC also maintains the Consolidated Sanctions List, which aggregates designations across all programmes. Where the transfer involves any identified foreign counterparty, the screening must reach through the ownership chain to the level at which any SDN interest might aggregate above the threshold. Screening tools that stop at the first-tier entity miss the ownership-chain problem entirely.

The 50 percent rule applies automatically. If a non-listed entity is owned in the aggregate 50 percent or more by one or more blocked persons, the entity is itself treated as blocked regardless of whether it appears on any list. This captures subsidiaries, joint ventures, and special-purpose vehicles where a blocked person holds a controlling or majority stake. Aggregation of multiple blocked-person holdings is required — two SDNs each holding 30 percent of the same entity together cross the threshold.

Programme-scope review is often overlooked in a deemed-export context. OFAC's comprehensive country programmes prohibit transactions with persons in the relevant country — or, in some cases, with persons who are nationals of that country regardless of where they are located. If a foreign national to whom technology is being transferred is a national of a country subject to a comprehensive programme, that transfer may constitute a prohibited transaction even if the individual is not personally designated. Practitioners must check the applicable country programme's scope definition carefully.

The position above covers the standard case. Your facts — the counterparty's nationality, the programme in play, the nature of the technology, the project it supports — change the analysis materially. For an assessment of your exposure under OFAC, contact Calder & Vance at info@caldervance.com.

Step 4: Assess the BIS–OFAC interaction and identify licence requirements

A BIS licence authorisation — or a BIS licence exception — does not relieve a party of its OFAC obligations. The two regimes are legally independent. This point is fundamental, and it is misunderstood with surprising frequency even by experienced export-compliance teams.

Where BIS requires a licence for a deemed export to a particular foreign national (because the technology's ECCN controls it for the country in question), that BIS licence obligation must be satisfied on its own terms. But even if BIS would authorise the transfer, if the recipient or the associated project is caught by an OFAC programme, the transfer is still prohibited under sanctions law unless OFAC has separately authorised it — through a general licence (a standing authorisation that permits a defined category of transactions without a separate application) or a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) obtained from OFAC directly.

Conversely, a clean BIS result — where the technology requires no BIS licence — leaves the OFAC question entirely open. OFAC's controls operate irrespective of the EAR classification of the item. The technology could be EAR99, the lowest-control classification, and yet the transfer could be a complete OFAC prohibition.

The practical implication is structural: compliance teams must maintain two separate decision pathways for deemed-export and technology-transfer matters, and both must reach a positive clearance before a transfer can proceed. Where the OFAC pathway flags a potential prohibition, the business must determine whether a general licence covers the situation or whether a specific-licence application is required. General licences require careful reading — their scope conditions, duration, and reporting requirements vary across programmes.

How does OFAC differ from other regimes on deemed exports and technology transfer?

The US approach is notably more granular on deemed exports than the comparable regimes administered by OFSI in the United Kingdom or by the EU Council. Understanding the divergence matters for businesses with operations or employees in multiple jurisdictions.

Under UK sanctions administered by OFSI, the financial-sanctions prohibitions focus on transactions involving listed persons and blocked assets. The ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person) applies to entities rather than to individual technology-release scenarios. OFSI's framework does not contain a specific deemed-export concept equivalent to the US model — the UK export-control regime administered by the ECJU handles export-licence requirements for controlled goods and technology separately. A US person seconded to a UK affiliate faces US OFAC obligations in addition to any ECJU requirements; the UK rules alone do not cover the OFAC exposure.

The EU dual-use regime operates on the basis of technical assistance restrictions and end-user controls rather than a deemed-export concept as such. The relevant Council regulations and the EU dual-use rules address the provision of technical assistance in connection with listed goods and technology, with restrictions on providing such assistance to designated parties or to parties in specified contexts. The analysis is more activity-focused and less person-nationality-focused than the US deemed-export construct.

One practical cross-border implication: a European entity that receives technology from a US parent must consider whether the receipt itself — or its subsequent internal sharing — could constitute a re-export or deemed re-export under the EAR with US-origin technology. OFAC's reach can extend beyond the initial transfer. For guidance on the UK-side deemed-export analysis, see our companion guide at Deemed export and technology transfer under OFSI and its follow-on at Deemed export and technology transfer under OFSI: advanced questions.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact us at info@caldervance.com for a confidential assessment.

Step 5: Identify the risk flags that require immediate counsel

Some patterns carry disproportionate enforcement risk. Identifying them early gives the business options — including a voluntary self-disclosure (a VSD, the mechanism for proactively reporting a potential violation to OFAC) — that are unavailable once an investigation begins.

The following situations require immediate involvement of sanctions counsel:

  • A foreign national employee is identified as a national of a country subject to a comprehensive OFAC programme, and they have already had access to controlled technology or to restricted project information.
  • Screening of a foreign counterparty's ownership chain reveals a beneficial owner who is an SDN, at any level of the structure.
  • An ongoing R&D collaboration involves a foreign university, institute, or government body with a connection — however indirect — to a designated entity or to a sanctioned sector.
  • A joint venture partner has shareholders from a comprehensively sanctioned country, even if the joint venture itself is registered elsewhere.
  • A merger or acquisition is in progress and the target has employees, contractors, or research collaborators with the relevant nationality or affiliation profile.
  • Technology has been transferred and the compliance team is uncertain whether the recipient's employer clears the 50 percent rule.

In our cross-border practice, we consistently see that delay in identifying a deemed-export issue — particularly where technology has already been shared — significantly narrows the available remediation options. A VSD to OFAC, properly scoped and prepared, is a material mitigant. An untimely disclosure, or none at all, is not.

Is your screening programme designed to catch the nationality-based OFAC risk that a standard name-screening run will miss? Many are not.

Step 6: Build and maintain a deemed-export control programme

A point-in-time analysis is not a programme. Managing deemed-export risk under OFAC requires a standing set of controls integrated into the hiring, onboarding, project-assignment, and technology-access processes of the organisation.

Effective programme design addresses six elements:

  1. Employee and contractor screening: collect nationality information at onboarding; re-screen against updated OFAC and BIS lists on a defined cycle; maintain records.
  2. Technology classification register: maintain a current classification of all technology, software, and technical data in use or development, mapped to ECCN status and to any OFAC programme relevance.
  3. Access controls and segregation: restrict access to controlled technology based on the results of the sanctions and export-control analysis; do not allow pending clearances to default to access.
  4. Third-party due diligence: screen all research collaborators, joint-venture partners, subcontractors, and licensees through the full OFAC analysis before sharing any controlled technology or technical data.
  5. Record-keeping: maintain documented records of every screening decision, every classification determination, and every licence application or reliance on a general licence.
  6. Escalation protocol: define when a potential match or a classification uncertainty requires escalation to sanctions counsel rather than internal resolution.

We regularly advise clients on testing the logic of existing screening controls, mapping ownership and control chains for third-party collaborators, and redesigning compliance programmes to address the OFAC-BIS interface. A programme that addresses one regime but not the other is a programme with a gap.

One common myth worth addressing directly: some businesses assume that because a foreign national is physically present in the United States and subject to US law, the deemed-export rules do not apply to transfers made to them in a US facility. That assumption is wrong. The deemed-export concept applies precisely to that situation. The location of the transfer does not change the nationality analysis or the OFAC programme-scope question.

Related practices

Frequently asked questions

What are the steps to manage deemed-export risk under OFAC?
Managing deemed-export risk under OFAC requires five steps: (1) map the transfer and identify all foreign nationals involved and their nationalities; (2) screen each individual and their associated entities against the full OFAC Consolidated Sanctions List, applying the 50 percent rule to ownership chains; (3) review the applicable country programme scope for nationality-based prohibitions; (4) determine whether a general licence covers the transfer or whether a specific-licence application is required; and (5) maintain documented records of each determination. This analysis must run in parallel with any BIS deemed-export analysis — a clean BIS result does not clear the OFAC question.
What is the most common mistake in deemed exports and technology transfer?
The most common mistake is treating the BIS deemed-export analysis as the whole of the compliance obligation. Many teams conduct a thorough ECCN classification and end-user review under the EAR and then proceed on the basis that no further check is required. OFAC's analysis is independent: it focuses on the nationality of the recipient, the ownership structure of associated entities, and the scope of the applicable country programme — not the technical classification of the item. A transfer that clears BIS can still be a prohibited transaction under OFAC. Running both analyses, consistently and in parallel, is the only reliable approach.
How does OFAC differ from other regimes here?
OFAC's deemed-export concept is more explicit and more person-nationality-focused than the equivalent rules under OFSI in the UK or under EU dual-use regulations. OFSI's financial-sanctions prohibitions focus on transactions involving designated persons and blocked assets; there is no direct UK equivalent of the US deemed-export model for individual technology releases. The EU dual-use regime addresses technical assistance rather than individual-release scenarios. For US businesses, OFAC's reach can extend extraterritorially — including to non-US subsidiaries of US parents and to transfers of US-origin technology by non-US persons — in ways that have no direct parallel in the UK or EU rules.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.