A payment-processing team at a mid-sized fintech flags a transaction destined for a third-country distributor. The goods are software. The buyer is not on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons), and no OFAC programme appears to touch the deal. Yet the transaction still fails a compliance review. Why? Because the Bureau of Industry and Security's Export Administration Regulations (the EAR) – the US export-control regime administered by BIS – reach the payment leg of a transaction whenever the underlying goods, software, or technology carry a US-origin or US-content nexus. As of mid-2026, that extraterritorial pull is broader than many payment-processing teams realise.
Payment-processing controls under the BIS / EAR require every payment processor, bank, and fintech that touches a US-nexus transaction to determine whether the underlying item is subject to the EAR, whether it requires a licence, and whether the end-use and end-user are permissible. The governing authority is BIS, operating under the Export Control Reform Act and IEEPA. No numeric penalty ceiling appears in the registry available to this guide; the consequences are qualitatively severe, including criminal exposure for wilful violations and civil penalties on a per-transaction basis.
This guide works through the practical control steps in sequence: classification, end-user and end-use screening, payment-processing-specific risk flags, cross-regime divergence from OFAC and OFSI, and when to involve specialist export-control and sanctions counsel.
Step 1 – Understand the legal basis: what makes a payment subject to the EAR?
A payment transaction is subject to the EAR when the goods, software, or technology being paid for are "subject to the EAR" – a defined concept under the regulations meaning they originate from the United States, incorporate a threshold proportion of US-controlled content, or are the direct product of US-origin technology or software. BIS administers this under authority derived from the Export Control Reform Act and, where applicable, IEEPA. The UN Security Council Consolidated List and country-based UN Chapter VII measures also feed into the end-user analysis.
Payment processors are not exempt. The EAR catches the facilitation of an export or re-export, and a payment that funds an unlicensed or prohibited transaction can itself constitute a violation. In our experience, this is the most consistent gap we observe when reviewing payment-firm compliance programmes: teams apply OFAC screening but apply no EAR-based item or end-use filter.
The practical consequence is that a payment firm's control logic must run two distinct checks in parallel. The first is a sanctions screen (OFAC, OFSI, EU Council regulations, the UN Consolidated List). The second is an EAR export-control check covering the item classification, the destination, the end-user, and the stated end-use. Neither check is a substitute for the other.
Step 2 – Classify the item and confirm its ECCN
An ECCN (Export Control Classification Number under the US Commerce Control List) determines which controls, if any, apply to the item being paid for. Payment processors typically do not classify items themselves; that is the exporter's or merchant's responsibility. However, a well-designed payment-processing control programme requires the processor to obtain and record the ECCN for any item that has a US-origin or US-content flag, or where the merchant's business involves technology, software, or goods with potential dual-use application.
Items classified EAR99 – the residual category for items not specifically listed on the Commerce Control List – are generally subject to fewer controls, but they are not entirely exempt. An EAR99 item shipped to a party on BIS's Entity List (the list of parties subject to specific licence requirements imposed by BIS) still requires a licence. Items with a specific ECCN carry controls keyed to the destination, end-user, and end-use.
For payment processors, the practical implication is this: the merchant data file or API payload should carry the item's ECCN or a self-certified EAR99 designation. Where it does not, the processor should have a documented escalation procedure that pauses the payment and requests classification confirmation before release. Have you reviewed whether your onboarding documentation for merchants captures this information at all?
Step 3 – Screen the end-user and the end-use
End-user screening under the EAR goes beyond checking the buyer's name against sanctions lists. BIS maintains the Entity List, the Denied Persons List, and the Unverified List, each of which carries distinct legal consequences. A payment to a party on the Entity List without the applicable licence is a violation of the EAR, even if that party appears on no OFAC or OFSI list. In our cross-border practice, we regularly advise clients who have strong OFAC-screening infrastructure but no feed from the BIS restricted-party lists at all.
End-use screening is the harder discipline. The EAR prohibits certain transactions when the processor knows or has reason to know that the item will be used in a prohibited application – weapons of mass destruction programmes, certain military end-uses, or transactions with entities acting contrary to US national-security interests. "Reason to know" is not a high bar. Red flags in the payment data – unusual routing, inconsistent stated purpose, a declared end-use that does not match the item type – can fix knowledge on the processor.
A practical control sequence for end-user and end-use screening includes:
- Automated match against the BIS Entity List, Denied Persons List, and Unverified List at onboarding and at each transaction.
- A documented re-screen trigger when the merchant's business type, product line, or destination pattern changes materially.
- A structured red-flag review for transactions where the stated end-use is inconsistent with the buyer's business profile.
- An escalation path to specialist export-control counsel when the red-flag review is inconclusive.
Step 4 – Map the cross-regime exposure: how does BIS / EAR differ from OFAC and OFSI?
BIS and OFAC are distinct US agencies with distinct legal authorities, and the tests they apply diverge in ways that directly affect payment-processing control design. OFAC's sanctions programmes focus on persons, entities, and jurisdictions: a payment is blocked because the counterparty is on the SDN List or because the transaction touches a comprehensively sanctioned jurisdiction. BIS's controls focus on items and activities: a transaction is controlled because of what is being paid for and how it will be used.
The 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) has no direct BIS equivalent. Under the EAR, the Entity List designation is party-specific and does not automatically extend to subsidiaries or affiliates on an ownership basis. However, BIS does look to whether a non-listed entity is acting as an agent or front for a listed party. This is a knowledge-and-purpose test, not a mechanical ownership threshold – and that distinction matters for how you structure your due-diligence review.
OFSI, the UK financial-sanctions authority, and the EU Council regulations add further divergence. UK financial sanctions under the Sanctions and Anti-Money Laundering Act apply an ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person) that is broader than OFAC's mechanical 50-percent threshold, because it includes effective control through other means. A payment that clears OFAC screening may still be prohibited under OFSI or EU rules if a listed person exercises effective control over the counterparty. Any payment processor operating in GBP or EUR clearing must run both the BIS and the OFSI / EU checks.
Switzerland (SECO), Canada (GAC), Australia (DFAT), Singapore, the UAE, and Japan each operate export-control and sanctions regimes that may apply concurrently, particularly where goods transit through those jurisdictions or where the processor is locally incorporated there. The rule is the same in each case: the stricter prohibition governs, and compliance with US rules alone does not discharge obligations under the applicable country regime.
The position above covers the standard cross-regime framework. Your facts – the item, the routing, the currency, the correspondent bank chain – change the analysis in ways that can only be assessed against the specific transaction profile.
If your transaction has already been flagged by a correspondent bank, or a payment has been returned with a compliance note, early specialist review can preserve options that narrow quickly. Contact Calder & Vance at info@caldervance.com for a confidential initial review.
Step 5 – Identify the specific risk flags in payment processing
Payment-processing controls under the BIS / EAR require active detection of red flags, not merely passive list-screening. BIS publishes guidance on the indicators that should trigger enhanced review. They are not exhaustive, but the following appear consistently in enforcement-facing situations.
First, the item description in the payment instruction is vague or generic. "Electronic components", "technical equipment", or "software" without further specification should prompt a classification enquiry before the payment is released. Second, the destination country or the intermediate routing country has a heightened export-control risk profile. Third, the buyer's stated business does not plausibly align with the item being purchased. A retail-grocery business purchasing advanced semiconductor fabrication equipment is a paradigmatic example. Fourth, the buyer requests that documentation be altered, minimised, or omitted. Fifth, a cash payment or a structuring pattern that seems designed to fragment a single purchase below a documentation threshold.
In our experience, the third and fifth flags are the ones that generate enforcement interest most frequently, because they are the most indicative of intentional concealment rather than inadvertent error. A well-designed system captures these at the point of payment instruction, not after clearing.
Step 6 – Design and test your control programme
A BIS / EAR-compliant payment-processing control programme has five operational components. They map to the "five elements" standard that US and UK regulators consistently reference when assessing the adequacy of a sanctions and export-control compliance programme.
- Management commitment: documented board or senior-management approval of the programme, with named accountability.
- Risk assessment: a current, written assessment of the specific EAR exposure from the payment firm's merchant base, item types, and destination profile.
- Controls: automated BIS restricted-party screening, ECCN-data requirements in onboarding, end-use self-certification for higher-risk merchants, and a structured red-flag review workflow.
- Training: role-specific EAR training for compliance, onboarding, and relationship-management staff – not generic AML training relabelled as export-control training.
- Testing and audit: periodic independent testing of the screening logic, the escalation path, and the documentation standard, with findings reported to management.
A programme that passes an internal audit but has never been tested against a live scenario is not well-tested. We regularly advise clients to run tabletop exercises using fictionalised versions of real transaction patterns drawn from their merchant data. The gaps identified in those exercises are consistently more material than the gaps internal audit finds through document review alone.
Record-keeping is a programme component in its own right. The EAR requires that records relevant to a controlled transaction be retained for a defined period. Verify the current retention requirement under the applicable regulations before relying on any number stated elsewhere; the obligation attaches to the transaction date, not the payment-processing date.
If a compliance gap surfaces during testing, the question of whether to make a VSD (voluntary self-disclosure to a regulator) arises immediately. VSD practice under the EAR is distinct from OFAC VSD practice in both timing and form. An incorrect or untimely VSD can make a penalty position worse. Specialist export-control counsel should assess the facts before any disclosure is made.
Related practices
- Compliance audit and testing – Australia regime – independent testing of screening logic, escalation paths, and documentation standards.
- Payment-processing controls – Canada guide – parallel analysis of GAC and SEMA obligations for cross-border payment firms.
- Payment-processing controls – cross-border guide – managing concurrent OFAC, OFSI, EU, and other-regime obligations in a single transaction.
Step 7 – When to involve export-control counsel
The EAR does not require a lawyer to process every payment. It does require a legally sound control programme, and there are specific moments where the involvement of specialist export-control and sanctions counsel is not optional in practice.
The first is at programme design or redesign. A control programme built without legal review of the EAR requirements specific to the payment-processing context is very likely to have gaps in the end-use and end-user layers, because those controls are not standard in AML or OFAC compliance toolkits.
The second is when a red flag cannot be resolved through the standard escalation path. If the compliance team cannot determine whether a particular item or end-user is permissible, the payment should be held and legal advice obtained. Releasing a payment because the team could not conclude it was prohibited is not a defence to an EAR violation.
The third is when a correspondent bank, a card network, or a clearing infrastructure returns a payment with a compliance notation, or when the firm receives a BIS compliance inquiry, subpoena, or administrative order. At that point, the legal position is crystallising and early counsel involvement is essential to preserve the firm's position, including the option of a VSD.
The fourth – and the one most consistently deferred too long – is when the firm is expanding into a new merchant vertical, a new product line, or a new destination market. The EAR risk profile of a payment processor changes with the underlying goods it facilitates. An early classification review of the new product line costs materially less than a post-incident remediation.
Myths and misconceptions: what payment firms get wrong about EAR exposure
A persistent belief among payment-processing compliance teams is that the EAR applies only to exporters and freight forwarders – not to financial intermediaries. This is incorrect. The EAR reaches any person, wherever located, who facilitates an export or re-export of an item subject to the EAR, and facilitation through a payment is expressly within scope.
A related misconception is that passing OFAC screening is sufficient. In our practice, we have reviewed programmes at banks and fintechs where OFAC, OFSI, and EU sanctions screening was genuinely sophisticated, but the BIS layer – the Entity List, the Denied Persons List, the ECCN check, the end-use analysis – was absent entirely. A business that screens well for sanctions persons but not for export-control parties is running a programme with a structural blind spot.
A third myth is that EAR compliance is a US-only obligation, relevant only if the processor has a US entity or US-dollar clearing exposure. This understates the extraterritorial reach of the EAR's de minimis rules and the foreign-direct-product rules, both of which can bring a non-US processor within BIS jurisdiction when the goods, software, or technology being paid for meet the applicable US-content or US-technology thresholds. The applicable country regime for the processor's home jurisdiction may impose additional obligations on top of this.