A payments team at a technology-hardware business flags an incoming wire transfer. The originating bank sits in a jurisdiction subject to US export controls. The goods referenced in the underlying commercial invoice carry a classification that restricts certain destinations. The question lands on the compliance desk within hours: can this payment proceed, and if so, under what authority?
Under the Export Administration Regulations ("EAR"), administered by the Bureau of Industry and Security ("BIS"), payments connected to controlled transactions – whether for goods, software, or technology – require a licence, an applicable licence exception, or a confirmed "no licence required" determination before the underlying transaction proceeds. As of June 2026, BIS enforces this position across a broad range of commercial items, and the financial leg of a restricted transaction is not exempt simply because money, rather than goods, is what crosses the border.
This guide walks through the governing authority, the classification and authorisation sequence, the points where businesses most commonly misread the rules, and the moments that call for specialist legal input. It pairs the BIS / EAR position with comparators from the OFAC and OFSI regimes, because in practice a payment flagged for export-control purposes will often trigger a parallel sanctions-screening question.
What authority governs payment authorisations under BIS / EAR?
BIS administers the EAR under the authority of the Export Control Reform Act, drawing on powers that ultimately trace to IEEPA. The EAR governs the export, re-export, and in-country transfer of items on the Commerce Control List ("CCL") – physical goods, software, and technology with potential dual-use application. When a payment is made in connection with a controlled export, it is treated as part of the transaction. BIS does not regulate the wire transfer independently; it regulates the underlying transaction, of which the payment is an inseparable element.
This framing has a practical implication. A company cannot lawfully make a payment for a shipment that requires a licence but has not obtained one, even if the payment itself is processed by a third-party bank that is unaware of the underlying classification. The obligation runs with the US person, the US-origin item, and in extraterritorial cases – under the de minimis rule and the foreign direct product rules – with non-US persons who handle items incorporating more than a threshold proportion of US-controlled content. Does your accounts-receivable process capture export-control status before approving an invoice for payment? That is the first diagnostic question.
The governing authority for enforcement is BIS's Office of Export Enforcement ("OEE"). Violations can attract both civil and criminal consequences. Civil penalties have a statutory maximum that is periodically adjusted; criminal exposure applies in wilful-violation cases and can involve individual liability for responsible officers. Where a payment is made against a transaction that also touches an OFAC-designated party, OFAC's authority runs concurrently. The stricter prohibition governs, and both agencies may act independently.
Step 1: Classify the item and confirm whether a licence is required
Before any authorisation question can be answered, the item underlying the payment must be correctly classified. Classification determines whether an Export Control Classification Number ("ECCN") applies and, if so, which of the CCL's reasons for control are triggered. An item that is not on the CCL is EAR99 – subject to the EAR but generally exportable without a licence except to embargoed destinations or parties listed by BIS.
Classification is a technical exercise. A company self-classifying a product must work through the relevant CCL category against the item's actual technical parameters. Misclassification in either direction carries risk. Over-classifying delays transactions unnecessarily. Under-classifying exposes the business to enforcement action, and a payment made on the basis of an incorrect "no licence required" conclusion provides no safe harbour against a later BIS finding.
Where classification is genuinely uncertain, BIS offers a formal Commodity Classification request. This produces an official determination and, importantly, a written record that demonstrates good-faith enquiry. In our experience, businesses in technology-hardware and semiconductor supply chains benefit materially from holding formal classification records for their product lines, particularly where dual-use parameters sit close to control thresholds.
Once the ECCN is confirmed, the next step is to check the matrix of destinations, end-users, and end-uses against which that ECCN is controlled. This check must be run both against the CCL and against the BIS Entity List, the Denied Persons List, and other restricted-party databases. A payment to an entity on the Entity List requires a licence regardless of whether the underlying item would otherwise qualify for a licence exception. Missing this step – screening the item but not the party – is a common source of apparent violations.
Step 2: Determine whether a licence exception covers the transaction
A licence exception is a standing authorisation – built into the EAR – that permits an otherwise controlled transaction without a case-by-case licence application, provided all conditions of the exception are met. Licence exceptions are specific in their scope: they attach to defined combinations of item classification, destination, end-user type, and end-use. No licence exception covers a transaction with a denied party or an entity on the Entity List; those transactions require a specific licence or must not proceed.
The most commonly relied-upon exceptions in commercial payment contexts include the Technology and Software – Unrestricted exception, the Licence Exception for civil end-uses, and the Intra-Company Transfer exception for technology moving within a corporate group. Each carries detailed conditions. A business that structures a payment on the assumption that an exception applies, without verifying every condition, is in the same legal position as a business with no authorisation at all.
In our cross-border practice, we regularly advise businesses that a licence exception that was properly relied upon at the time of the original export no longer applies to a subsequent re-export. Re-export authorisation runs from the original classification and the conditions applicable at the time of the re-export, not at the time of first export. This is a particularly common pitfall for technology businesses whose clients pass on software or technical data to subsidiaries or sub-contractors in third countries.
The position here differs from the UK regime under the ECJU. UK Open General Export Licences provide analogous standing permissions, but the eligibility criteria, record-keeping requirements, and registration obligations differ in ways that matter for businesses holding both a UK and a US authorisation. Always verify the applicable country regime before treating a UK licence as confirming a BIS position.
Step 3: Apply for a specific licence when no exception is available
Where no licence exception covers the transaction, the business must apply to BIS for a specific licence – a case-by-case authorisation to proceed. The application is submitted through BIS's electronic system and must describe the item, the transaction, the parties, the destination, and the end-use in sufficient detail to allow a licensing officer to assess the application on the merits.
BIS processes licence applications within a statutory review period, though complex applications involving multiple agency referrals take longer. The licensing officer may approve, approve with conditions, deny, or return the application without action requesting further information. A "return without action" is not a denial but requires resubmission with additional documentation; it resets the review clock.
Conditions attached to an approved licence are legally binding. They may specify permitted end-uses, require delivery-verification certificates, restrict re-transfer without separate authorisation, or require the applicant to obtain a written end-user undertaking. A payment made after a licence is granted but in breach of a condition can constitute a violation. The licence does not insulate the transaction from all subsequent scrutiny; it creates the legal basis on which the transaction may proceed – and only on the terms stated.
The bridge between a licence application and a payment is often under-managed. In a recent matter, a technology-sector business held a valid BIS specific licence for an export. The payment terms were amended after the licence was granted, resulting in the transaction value exceeding the amount specified in the licence. We identified the discrepancy before the payment cleared, advised on the need for a licence amendment application, and managed the submission. The matter was resolved without any enforcement contact. Small post-approval changes are easy to overlook and expensive to correct after the fact.
What are the cross-border and extraterritorial dimensions of this question?
The EAR's reach extends beyond US persons and US borders. Two mechanisms make this a cross-border compliance question for non-US businesses. First, the de minimis rule treats a non-US item as subject to the EAR when US-controlled content incorporated in it exceeds a defined percentage of the item's total value, measured by the applicable threshold for the destination. Second, the foreign direct product rule – expanded in recent years and now applied to a growing number of CCL categories – captures non-US goods that are the direct product of US-origin technology or software subject to the EAR.
For a payment desk in London, Frankfurt, or Singapore, this means that a wire transfer supporting a transaction in a product that contains no US components may still touch EAR requirements if the manufacturing technology used to produce it is of US origin and the foreign direct product rule applies. We regularly advise European and Asian clients who have discovered mid-transaction that their product line triggers EAR jurisdiction under this route – often after a US counterparty or end-user raises the point.
OFAC operates in parallel. Where a payment is made in US dollars through a US correspondent bank, OFAC's jurisdiction attaches to that clearing step regardless of whether the transacting parties are US persons. A payment that would be permissible under BIS's licensing analysis may still be blocked by OFAC's prohibited-party or prohibited-programme restrictions. The two agencies share information on apparent violations. An export-control clearance from BIS does not pre-empt an OFAC finding, and vice versa. Cross-regime screening – for both the item classification and the party status under each authority – must run together.
The EU's dual-use regime and the UK's Export Control Order impose equivalent classification and authorisation requirements that can apply concurrently when goods transit EU or UK territory, or when the exporter or its affiliated entity is established in those jurisdictions. Where an item requires a BIS licence and an EU or UK licence, both must be in place before the transaction – and the payment – can proceed. If the applicable country regime in the EU or UK imposes a stricter prohibition, that prohibition governs the conduct of the EU or UK person even if BIS has granted its own authorisation.
If a transaction has already been flagged – a payment has been refused, a licence application is under review, or a compliance query has been raised by a correspondent bank – an early legal review can preserve options that narrow with time. To discuss the position on a live transaction, contact Calder & Vance at info@caldervance.com.
What are the most common risk flags and pitfalls?
Several patterns recur across the payment-authorisation questions we handle. Each represents a distinct failure mode rather than a variation on a single theme.
- Screening the item but not the party. A correct ECCN and a valid licence exception do not authorise a payment to an Entity List or Denied Persons List counterparty. Party screening must be run at the time of each payment, not only at the point of original contract.
- Treating EAR99 as synonym for "no licence required". EAR99 items still require a licence for export to embargoed destinations and to denied parties. The absence of an ECCN is not the absence of control.
- Relying on a licence exception without verifying every condition. Many exceptions carry conditions that change with the end-user, the destination, or the nature of the technology. A transaction that met the exception conditions at contracting may fail them at the time of payment if the end-user's status or the destination has changed.
- Making a payment before the licence is formally issued. An application in process is not an authorisation. The payment must wait for the licence. A "return without action" response is not a denial but is not a grant either.
- Post-licence changes to transaction value or end-user. Licence conditions run to the transaction as described in the application. Changes to price, quantity, end-user, or end-use require an amendment application.
- Ignoring re-export risk. Payments for goods or technology that the original buyer will re-sell or transfer require analysis of re-export authorisation, not merely the original export.
One myth worth addressing directly: "If the bank clears the payment, we have no liability." This view conflates the bank's clearing decision with the exporter's authorisation obligation. A correspondent bank that processes a dollar-denominated wire conducts its own OFAC screening. That screening does not assess BIS export-control classification. A payment that passes through a bank without being blocked may still constitute a BIS violation if the underlying transaction was unlicensed. The bank's decision and the exporter's compliance position are independent.
When should a business involve specialist counsel?
Not every payment-authorisation question requires outside legal advice. A well-resourced in-house team with current classification records, a maintained restricted-party screening programme, and clear written procedures for licence-exception reliance can manage standard transactions internally. The moments that warrant specialist input are more specific.
Seek legal advice before the payment when: the item classification is uncertain and the product parameters sit close to a CCL control threshold; the transaction involves a party in a jurisdiction subject to extensive US controls and both BIS and OFAC jurisdiction may be live; the licence exception conditions cannot be confirmed for the specific end-user and end-use; or the transaction involves re-export and the receiving country imposes additional EAR restrictions.
Seek legal advice when a problem has emerged: a licence application has been denied or returned without action; a correspondent bank has blocked or queried a payment; a business-partner compliance questionnaire has revealed a classification issue; or an employee has raised an internal concern about a payment that has already been made. In this last scenario, the question of whether to make a voluntary self-disclosure ("VSD") to BIS is one that carries significant consequences and should not be decided without advice.
We have acted for businesses that discovered an apparent violation months after the relevant transactions closed. The response options available – and the likely BIS treatment of the matter – depend heavily on how quickly the issue is surfaced, whether the disclosure is voluntary, and how the company documents its remedial steps. Early legal involvement is not a cost; it is what keeps an apparent violation from becoming an enforcement matter.
Related practices
- Frozen-account management under BIS / EAR – specialist support where accounts or transactions have been blocked pending authorisation
- Payment authorisations under BIS / EAR: advanced scenarios – extended analysis of complex party-screening and re-export situations
- Payment authorisations under the Canadian regime – comparative guide for transactions with a Canada-nexus component