Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFAC

Deemed exports and technology transfer under OFAC: step by step

A technology company hires a national of a country subject to a comprehensive OFAC sanctions programme. The new employee will work in the same building as the firm's engineers, access the same code repositories, and attend the same product briefings. Nobody has exported anything. Yet, in legal terms, an export may already have occurred – or be about to.

Under OFAC's sanctions programmes, transferring technology, software, or technical data to a national of a sanctioned country – even within the United States – can constitute a prohibited transaction. The same logic applies to sharing controlled information with a blocked person, wherever they are located. As of April 2026, this remains one of the least-understood exposure points for US-connected businesses operating internationally.

This guide walks through the deemed-export analysis under OFAC, regime by regime, and sets out the practical steps a compliance team should take before technology changes hands.

Step 1: Understand what a deemed export is – and why OFAC matters here

A deemed export is a release of technology or source code to a foreign national that is legally treated as an export to that person's home country, even when it occurs inside the exporting country's borders. Under the US regime, both the Export Administration Regulations (EAR, administered by BIS) and OFAC's sanctions programmes can independently restrict or prohibit such a release.

The OFAC angle is distinct from BIS. OFAC's prohibitions run not by commodity classification but by the identity of the person and the destination country. If the foreign national is a Specially Designated National (SDN List – OFAC's list of Specially Designated Nationals and blocked persons), transferring any economic value to that person – including intangible services or technical assistance – is prohibited regardless of how the technology is classified. If the national is from a comprehensively sanctioned country and the transfer constitutes a service to that country, OFAC's country-programme rules engage directly.

In our experience, compliance teams that focus exclusively on BIS licensing requirements miss the OFAC overlay entirely. The two regimes address different questions. BIS asks: what is the item, and where is it going? OFAC asks: who is involved, and does this transaction provide economic benefit to a blocked person or sanctioned territory? A single technology transfer can require analysis under both.

The practical implication is significant. A company that secures a BIS licence for a deemed export has not thereby satisfied its OFAC obligations. The screening check, the SDN analysis, and any country-programme assessment must be completed separately and in parallel.

Step 2: Map the technology and identify the triggering event

Before any sanctions or export-control analysis can be completed, the compliance team must identify exactly what is being transferred, to whom, and in what circumstances. This sounds straightforward. In practice, it is where most deemed-export problems begin.

Technology subject to deemed-export analysis includes source code, technical specifications, manufacturing processes, software, and oral or visual instruction. A product demonstration, an engineering workshop, access credentials to a repository, or a slide deck sent to a foreign national can each constitute a deemed export depending on the content and the recipient.

The triggering events a team should document include:

  • Hiring or onboarding a foreign national who will have access to controlled technology or software
  • Granting system or repository access to a contractor, consultant, or partner based in or a national of a sanctioned country
  • Providing technical assistance or training to a counterparty whose beneficial owner is a blocked person
  • Sharing technical data in a joint-venture or licensing arrangement with a foreign entity
  • Conducting a virtual product demonstration or briefing with a participant in a comprehensively sanctioned territory

The sequence matters. The triggering event must be identified before the recipient is screened, because the screening logic differs depending on whether the concern is an SDN exposure or a country-programme exposure.

Step 3: Screen the recipient – SDN, country programme, and the 50 percent rule

Every person who will receive the technology must be screened against the SDN List before any transfer occurs. A match – or a potential match – stops the transfer until the compliance team has assessed it. This is non-negotiable under OFAC's enforcement expectations.

Screening must go beyond the individual. If the technology is being transferred under a contractual arrangement, the employer, sponsor, or funding entity of the recipient must also be screened. The 50 percent rule (OFAC's rule treating entities owned 50 percent or more by one or more blocked persons as themselves blocked) means that a foreign national employed by a company in which blocked persons hold a majority stake can be treated as a blocked-person counterparty, even if the individual is not themselves listed.

Country-programme screening is a separate step. If the recipient is a national of a comprehensively sanctioned country, the relevant country programme may prohibit services – including technical assistance, training, or information transfer – to that country or its nationals. The prohibition does not depend on the person being an SDN. It depends on the programme rules and whether the service benefits the sanctioned territory.

In our cross-border practice, we regularly see businesses that run SDN checks but do not apply country-programme analysis to their deemed-export population. That gap creates exposure that a standard OFAC SDN-list hit will not catch.

Step 4: Apply the cross-regime comparison – where OFAC, BIS, and other jurisdictions diverge

A business operating across multiple jurisdictions cannot treat deemed-export compliance as a US-only question. The OFAC analysis must be read alongside BIS, and – for multinationals with European, UK, or other operations – alongside the relevant controls in those jurisdictions.

Under BIS and the EAR, the deemed-export analysis centres on the Export Control Classification Number (ECCN – the item's classification under the Commerce Control List) and the nationality of the recipient. A foreign national's home country determines whether a BIS licence is required for access to items of a given classification. This is a commodity-and-destination analysis. OFAC's analysis, as noted above, is a person-and-programme analysis. The two do not map neatly onto each other.

The European Union's dual-use controls introduce a further dimension for businesses with EU operations. The EU rules on deemed exports are still developing and are not yet co-extensive with the US position; however, transfers of technology to nationals of countries subject to EU-level controls can engage EU restrictions independently of the US position. UK controls under ECJU add a comparable layer for UK-based operations and personnel.

What does this mean in practice? A technology transfer that OFAC permits under a general licence may still require a BIS licence. A transfer that BIS exempts may still be prohibited by an applicable country programme under OFAC. And a transaction cleared under US rules may independently engage EU or UK controls if it involves EU or UK persons or infrastructure. The strictest applicable prohibition governs; clearing one regime does not clear the others.

For businesses with operations in Singapore, Japan, or the UAE, comparable deemed-export questions arise under those countries' own strategic trade controls. The analysis for each regime must be conducted on its own terms, under the applicable country regime.

The position above covers the standard analytical structure. Your facts – the technology involved, the recipient's nationality and employment context, the regimes in play, and the contractual structure – change the analysis significantly. For a regime-specific assessment of your exposure, contact Calder & Vance at info@caldervance.com.

Step 5: Assess whether a licence or authorisation is available

Where the screening analysis identifies a potential prohibition, the next step is to assess whether a licence or authorisation is available. This applies both to the OFAC analysis and to the BIS analysis; the two applications are submitted to different authorities and evaluated on different criteria.

Under OFAC, a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) may be available where the facts support a policy basis for authorisation. General licences – standing authorisations that permit defined categories of transactions without a separate application – may also apply; for example, certain information and informational-materials transfers are broadly authorised under most OFAC country programmes, though the scope of that authorisation is programme-specific and must be verified against the applicable rules.

Where a specific licence is required, the application must set out the facts clearly, address the OFAC licensing policy applicable to the relevant programme, and be submitted before the transaction proceeds. Submitting after the fact does not cure a violation; it may, however, be relevant to the enforcement posture and any penalty assessment.

Under BIS, the licence-exception and licence-requirement analysis runs parallel to and independently of the OFAC application. A compliance team preparing a deemed-export clearance for a complex hire or a joint-venture technology-sharing arrangement should coordinate both tracks from the outset, not sequentially. Delays on one track will hold the other.

Step 6: Design and document the controls

Clearing the initial deemed-export question is not the end of the obligation. Ongoing access controls must be designed, documented, and monitored for the life of the relationship.

The core controls for a deemed-export programme include:

  • A technology-access policy that identifies which personnel may access which categories of controlled technology, and on what basis
  • System access controls that segregate controlled items from those available to all personnel
  • A re-screening schedule that ensures recipients are re-checked against OFAC lists at regular intervals and upon any change in their status or employment arrangements
  • A record-keeping programme that preserves all screening results, licensing documents, and access-log records for a minimum of five years, consistent with OFAC's record-keeping expectations under its enforcement guidance
  • An escalation path for new hires, new contractors, and new technology-sharing arrangements that routes each through the deemed-export compliance check before access is granted

Record-keeping is frequently under-resourced in deemed-export programmes. In an enforcement or audit context, a firm that cannot produce contemporaneous documentation of its screening, its licensing analysis, and its access decisions is in a materially weaker position than one that can. Good records are not merely an administrative obligation; they are the primary evidence of good faith.

If a transaction has already proceeded without full deemed-export screening, or if a compliance gap has been identified, a review is needed urgently. Early assessment can preserve options – including a voluntary self-disclosure (VSD – a proactive report to OFAC of an apparent violation) – that narrow with time. For a confidential review of a potential breach or a compliance gap, contact us at info@caldervance.com.

Step 7: Know the risk flags and when to involve counsel

Deemed-export risk does not arise only at the point of hire. It is a recurring compliance question that must be addressed each time technology access changes, each time a new contractual arrangement is entered, and each time the OFAC lists are updated.

The risk flags that should trigger an immediate compliance review include:

  • A foreign national in a technical role whose nationality has not been verified against the current list of comprehensively sanctioned countries
  • A joint-venture or licensing arrangement with a foreign entity that has not been screened for SDN exposure or beneficial-ownership chains into blocked persons
  • A cloud-infrastructure or remote-access arrangement that could make controlled technology accessible to persons in sanctioned territories
  • A recent OFAC designation affecting a country or sector relevant to the business's technology partners or customers
  • An M&A or integration process that will bring new personnel – and their access rights – into the combined business without a deemed-export review
  • A virtual collaboration or open-source contribution model in which code or technical data could be accessed by persons in restricted territories without a formal access check

What is the most common error we see? Businesses treat deemed exports as a one-time hiring-form question rather than a live compliance obligation. The screening that was completed at onboarding does not account for new designations, changed nationalities, or altered access rights in the months and years that follow.

Counsel should be involved when the screening result is ambiguous, when the technology involved is sensitive or dual-use, when a licence application is contemplated, when a VSD is being considered, or when an M&A or restructuring will alter the technology-access population. These are not situations for a generalised compliance checklist; they require a fact-specific legal assessment of both OFAC and BIS obligations.

A common myth in this space is that deemed-export obligations apply only to large defence contractors or government-connected businesses. In our experience, the exposure is equally acute for technology companies, research institutions, software developers, and any business that shares technical data or source code internationally. The obligations scale with the technology, not the size of the firm.

Related practices

Frequently asked questions

What are the steps to manage deemed-export risk under OFAC?
The core steps are: identify the triggering event (the technology and the recipient); screen the recipient and any affiliated entities against the SDN List and for country-programme exposure; apply the 50 percent rule to any entity counterparty; assess whether a licence or general-licence authorisation is available; obtain the authorisation before the transfer; design ongoing access controls; and maintain records for at least five years. These steps must be completed in sequence and documented throughout. OFAC and BIS obligations run in parallel and must both be addressed.
What is the most common mistake in deemed exports and technology transfer?
The most frequent error is treating deemed-export screening as a one-time event completed at the point of hire or at contract execution. OFAC lists change. Designations are added and removed. A recipient who was clean at onboarding may become an SDN – or their employer may become blocked through a subsequent designation. Without a re-screening programme and an ongoing access-control protocol, the initial clearance offers no protection for later transfers. The obligation is continuous, not point-in-time.
How does OFAC differ from other regimes here?
OFAC's deemed-export analysis turns on the identity of the person and the applicable country programme, not on the classification of the technology. BIS focuses on the ECCN of the item and the recipient's nationality. The EU dual-use rules and UK controls under ECJU apply their own criteria independently. Clearing the BIS analysis does not clear the OFAC position, and vice versa. A compliant deemed-export programme must address each applicable regime on its own terms; the strictest applicable prohibition governs the transaction.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.