A cross-border payment that looked routine at the point of contract can become a blocked transaction the moment it touches US-origin goods, US-controlled technology, or a supply chain routed through a US financial institution. The Export Administration Regulations – administered by the Bureau of Industry and Security (BIS) – govern not just the physical movement of controlled goods but also the financial authorisations that make those movements possible. Many businesses only discover that a payment requires separate treatment under the EAR after a bank has already flagged the transfer.
Payment authorisations under the BIS / EAR regime are the licences, licence exceptions, and deemed-export controls that govern whether a financial transaction connected to a controlled item or technology transfer may lawfully proceed. The governing authority is BIS, acting under the Export Control Reform Act and the EAR. Where no licence exception applies, a specific licence application to BIS is the required route – and that application must be in place before the payment, not after.
This guide sets out the step-by-step process for identifying when a payment requires BIS authorisation, what the application procedure looks like, how the regime compares with OFAC and key allied regimes, and what risk flags should trigger immediate legal review.
Step 1 – Determine whether the payment has an export-control nexus
A payment acquires a BIS / EAR nexus whenever it is linked, directly or indirectly, to the export, re-export, or in-country transfer of an item subject to the EAR. The first analytical step is therefore not to look at the payment itself but at the underlying transaction it funds.
Ask three threshold questions. First, is the item or technology on the Commerce Control List (CCL)? Every item subject to the EAR carries an Export Control Classification Number – an ECCN – or falls under the residual EAR99 category. Items with a non-EAR99 ECCN may carry restrictions based on destination, end-use, or end-user. Second, does the destination, end-user, or end-use trigger a licence requirement? BIS publishes the Entity List, the Denied Persons List, and the Unverified List; any payment to a party on those lists raises immediate concerns regardless of the goods involved. Third, does US-origin content in the goods, or US-controlled technology in the service, bring the transaction within the EAR's reach even if the goods never physically touch the United States?
That third question is the one most businesses underestimate. The EAR applies extraterritorially: foreign-produced items that incorporate more than a defined threshold of US-controlled content, or that are the direct product of certain US technology or software, remain subject to EAR requirements even when shipped between two non-US parties. In our experience, payment teams that handle only domestic currency flows often have no visibility over this analysis at all – leaving the compliance gap to surface during a bank's correspondent-banking review.
Step 2 – Classify the item and map the licence requirement
Once the export-control nexus is confirmed, the next step is to identify the precise ECCN and to read the applicable licence requirements against the country group, end-user, and end-use in front of you. Classification is the foundation of every subsequent decision: an incorrect ECCN produces incorrect conclusions about whether a licence exception is available, and incorrect conclusions about licence exceptions produce unlicensed transfers.
BIS classification requires matching the technical parameters of the item – or the technical content of the technology transfer – against the CCL categories. The CCL runs from Category 0 (nuclear materials and equipment) through Category 9 (aerospace and propulsion). Each entry specifies the reasons for control and the corresponding country-group matrix. A payment authorisation can only be determined once you know whether, for example, the item is controlled for national-security, anti-terrorism, or crime-control reasons – because each reason generates a different licence requirement across different country groups.
Where classification is genuinely uncertain, BIS operates a formal commodity classification request process. Submitting a classification request is a legitimate step and, in our practice, can also serve as evidence of good-faith compliance efforts if the matter later attracts enforcement scrutiny. Do not guess and do not rely on a supplier's classification without independent verification: the obligation rests on the exporter.
Step 3 – Assess whether a licence exception covers the payment
If a licence requirement applies, the next question is whether any BIS licence exception removes the need for a specific authorisation. Licence exceptions under the EAR are statutory categories – such as the Technology and Software Unrestricted exception, the Shipments to Country Group B exception, or the Strategic Trade Authorisation exception – each with defined eligibility conditions that must be met in full before the exception can be used. Using an exception that does not apply is itself a violation of the EAR.
Several conditions recur across exceptions and are commonly missed. The exception must be available for the specific ECCN and its reason for control. The end-user must not appear on a restricted-party list. The end-use must not be a prohibited end-use under BIS rules, such as weapons-of-mass-destruction development or certain military end-uses in designated destinations. And the transaction must not have been structured in a way that defeats the purposes of the exception – a point of obvious relevance to payment routing.
If no exception applies, a specific licence application is required. Attempting to proceed with the payment in the absence of a licence or a valid exception is a strict-liability violation: intent is not a necessary element for administrative liability under the EAR, though it is relevant to the severity of the penalty.
Related practices
- Frozen account management under BIS / EAR – specialist service for businesses managing blocked or frozen accounts within the US export-control regime.
- Payment authorisation under the Canadian regime – step-by-step guide for cross-border businesses facing the GAC sanctions and export-control rules.
- Payment authorisation under Canada: advanced issues – deeper analysis of multi-regime exposure for transactions with a Canadian nexus.
The position above covers the standard case. Your facts – the item's classification, the identity and location of the counterparty, the payment route, and the technology in play – change the analysis significantly. For an assessment of your exposure under the BIS / EAR regime, contact Calder & Vance at info@caldervance.com.
Step 4 – Submit the BIS specific licence application
Where no licence exception applies, BIS specific licence applications are submitted through the Simplified Network Application Resubmission Electronically (SNAP-R) system. The application requires a precise description of the item, the ECCN, the stated end-use and end-user, the ultimate consignee, and, in many cases, an end-use statement from the foreign party. Missing or inconsistent information in any of these fields is the most common reason for delays or returns without action.
What documentation should you prepare before filing? At a minimum: a full technical description of the item or technology; the ECCN with the basis for that classification; a written end-use and end-user certificate from the recipient; any prior export authorisations covering the same item; and a transaction diagram showing all intermediate parties in the supply and payment chain. BIS may issue a Request for Additional Information after submission, and the response window is typically short. Delays in responding extend the review period.
BIS reviews applications in priority order, applying a presumption of approval or a presumption of denial depending on the destination, end-user, and reason for control. For items controlled for national-security reasons destined for certain country groups, inter-agency referral – involving the Departments of Defense, State, and Energy where relevant – is standard, and timelines extend accordingly. In our experience, transactions that reach inter-agency review take materially longer than straightforward single-agency determinations; building that time into the commercial contract's conditions-precedent clause is a basic risk-management step.
How does the BIS / EAR regime compare with OFAC, OFSI, and the EU on payment authorisations?
BIS payment authorisations and OFAC-related payment authorisations are legally distinct and administered by different agencies, even though a single transaction can engage both. A business that has secured a BIS export licence has not thereby obtained OFAC authorisation for payments to a sanctioned person – and vice versa. The two requirements operate independently and must both be satisfied where both apply.
The structural difference is fundamental. BIS controls turn on the item, the technology, and the end-user: the question is whether the goods or knowledge being transferred are controlled under the CCL. OFAC controls turn on the identity of the counterparty: the question is whether the payment touches a sanctions target or a target's property. A shipment of EAR99 goods to a company on the OFAC SDN list still requires OFAC authorisation, even though it requires no BIS licence.
How does this compare with allied regimes? The UK's export-licensing regime, administered by ECJU, and the UK financial-sanctions regime, administered by OFSI, operate on the same conceptual separation as BIS and OFAC. The EU dual-use regulation similarly separates the export-authorisation question from the asset-freeze and payment prohibition question, which is governed by the relevant Council regulation. In practice, however, EU export controls cover a somewhat narrower field than the EAR's extraterritorial reach, and the EU's de minimis thresholds for foreign-produced items differ from BIS's foreign direct product rules. A transaction that clears EU export-control requirements may still be caught by BIS if US-origin technology is embedded in the goods.
For businesses operating between the United States and allied jurisdictions such as Singapore, Japan, or the UAE, there is an additional layer. Singapore administers strategic goods controls under its Strategic Goods (Control) Act; Japan operates its Foreign Exchange and Foreign Trade Act export-control regime; the UAE has its own strategic-goods controls. None of these removes the need for BIS authorisation where US-origin goods or technology are involved. In our cross-border practice, we regularly advise clients who have obtained clearance under one regime and assumed, incorrectly, that BIS coverage is thereby resolved.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment of your position.
Risk flags that require immediate legal review
Several indicators, taken alone or together, should cause a compliance team to pause a payment and seek specialist advice before proceeding. Any one of them, handled incorrectly, can convert a routine commercial transaction into a strict-liability enforcement matter.
- A party in the payment chain – including an intermediary bank, a freight forwarder, or an end-user – appears on the Entity List, the Denied Persons List, or the Unverified List.
- The goods, software, or technology have not been formally classified against the CCL, or the classification has been taken from a third party without independent verification.
- The proposed payment route passes through a US correspondent bank, triggering OFAC screening in addition to the BIS analysis.
- The end-use stated in the contract differs from the end-use indicated in shipping or payment documentation – a discrepancy that can indicate a diversion risk and is actively monitored in BIS enforcement.
- The transaction involves technology that could be transferred by knowledge or demonstration – a so-called deemed export – rather than by physical shipment; deemed exports to foreign nationals in the United States require the same licensing analysis as physical exports.
- The deal structure involves a re-export by a non-US intermediary: re-exports of US-origin items are subject to the EAR regardless of the intermediary's location.
- A licence exception is being used, but the conditions for that exception have not been documented or do not clearly apply on the face of the transaction.
In a recent matter, a financial-services firm sought to process a series of payments related to a software licensing arrangement covering technology with dual-use characteristics. The item had been informally classified as EAR99 by the original vendor, but an independent review identified a more specific ECCN with national-security controls. We assessed the licence-exception options, found that the available exception did not cover the full set of end-users, and prepared a specific licence application. The matter was resolved through the licensing process before any payment was made. No guarantee of a particular outcome can be given, but early identification of the issue preserved the commercial relationship and avoided the need for voluntary self-disclosure.
A common misconception: "our goods are EAR99, so no authorisation is needed"
The most persistent myth in BIS payment-authorisation work is that EAR99 classification removes all authorisation requirements from the transaction. It does not. EAR99 means the item does not have a specific ECCN on the CCL; it does not mean the item is freely exportable without restriction.
Four situations require careful attention even when goods are EAR99. First, EAR99 items cannot be exported to embargoed destinations under a BIS-administered embargo programme without a licence. Second, EAR99 items cannot be sold to a party on the Entity List, the Denied Persons List, or another BIS restricted-party list. Third, EAR99 items cannot be exported where the exporter has knowledge of a prohibited end-use – weapons-of-mass-destruction development, for example – even if the goods themselves are not inherently controlled. Fourth, where US-controlled technology is used to produce a foreign item, the EAR's foreign direct product rules can bring even a foreign-manufactured EAR99-equivalent item back within EAR coverage for re-export purposes.
The payment arm of the transaction is affected in each of these cases. A payment for EAR99 goods to a party on the Entity List is not saved by the EAR99 classification: the restricted-party prohibition applies independently of item classification. We regularly advise businesses that have run what they describe as a "clean" compliance check – meaning item classification only – and missed the counterparty screening step entirely.
Record-keeping and ongoing compliance obligations
A BIS licence authorisation does not end the compliance obligation; it begins a record-keeping and monitoring period that runs for the life of the authorised transaction and beyond. Exporters are required to maintain all export-related records – including the licence or exception documentation, end-use certificates, shipping documents, payment records, and any BIS correspondence – for a prescribed period from the date of export or from the expiry of the licence.
Where a specific licence is issued with conditions – such as restrictions on re-transfer, requirements for end-use verification visits, or reporting obligations on the volume of items shipped under the licence – those conditions must be tracked and fulfilled. A licence obtained and then administered carelessly creates its own enforcement exposure: BIS post-shipment verifications can check compliance with licence conditions, and failures identified in that process can generate voluntary self-disclosure obligations or enforcement referrals.
For businesses managing multiple transactions across a portfolio of BIS licences and exceptions, a systematic compliance programme is not optional. The programme should document the classification basis for each item, the exception or licence relied upon for each shipment, the screening check performed at the point of each transaction, and the record-keeping measures in place. In our practice, we have found that the businesses most exposed in BIS enforcement are those that obtained licences correctly but failed to implement the compliance controls needed to stay within their terms.