A trading company with operations spanning three continents receives a request to ship specialised equipment to a long-standing client. Screening flags a potential issue. The compliance team knows a licence may be available – but which kind, under which regime, and through which authority? Get the route wrong and the application fails. Miss a general licence that already covers the transaction and the business waits months unnecessarily.
Choosing between specific and general licences cross-border guide: the correct licence route depends on the regime in play, the nature of the activity, and whether a standing authorisation already exists. Under OFAC, OFSI, and the EU Council regulations, general licences (standing authorisations for defined categories) can permit an otherwise prohibited transaction without a separate application – but only if every condition of that licence is strictly met. Where no general licence fits, a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) is the route, and the standards for grant differ meaningfully across regimes.
This guide walks through the decision sequence: identifying the applicable regime, testing whether a general licence fits, building a specific-licence application where necessary, managing cross-regime divergence, and flagging the risk points that most frequently cause applications to fail or businesses to over-apply.
Step 1: Identify which regimes govern the transaction
Every licence analysis starts with jurisdiction. Until you know which regime – or regimes – apply, you cannot determine which authority issues the licence or what the conditions for grant are.
The US regime is the most far-reaching in its jurisdictional claims. OFAC's sanctions rules apply to US persons wherever located, to transactions processed through the US financial system, and – for certain programmes – to non-US persons who transact in goods or services with a US-origin nexus. BIS, administering the Export Administration Regulations (the EAR), adds a separate layer: jurisdiction attaches to items that are subject to the EAR by virtue of their US origin, content above a defined threshold, or technology produced from US-origin software or technical data. A business that is neither US-owned nor US-located may still need a BIS licence if its product contains a US-origin component above the relevant threshold. As of June 2026, that extraterritorial reach makes BIS jurisdiction the first question to resolve in any dual-use or military-end-use export.
UK jurisdiction under OFSI (the Office of Financial Sanctions Implementation) and the ECJU (the Export Control Joint Unit) is territorial and connects to UK nexus: UK persons, UK-registered entities, conduct in the United Kingdom, and Sterling-denominated or UK-cleared transactions. Unlike OFAC, OFSI licensing operates on a general and specific licence model where the general licences are narrower in scope and the specific-licence process is more tightly case-managed. The relevant thematic sanctions regulations govern each programme separately.
EU jurisdiction connects to EU persons and entities, conduct in the Union, and transactions in Euros cleared through EU-correspondent banks. The relevant Council Regulation for each programme is the governing instrument. The EU also publishes a list of humanitarian and other derogations, but these function differently from a US general licence – they are often automatic exemptions rather than pre-issued authorisations requiring a separate application.
Cross-border transactions frequently engage more than one regime. A European bank acting as correspondent for a payment involving a US-dollar leg faces OFAC rules at the same time as EU Council regulations. In our cross-border practice, the regime-mapping stage is where most errors originate: teams focus on the regime they know best and miss the one that actually controls the transaction.
Step 2: Test whether a general licence already covers the activity
A general licence (a standing authorisation that permits a defined category of transactions without a separate application) is always the first thing to check, because it saves time and eliminates application risk. But using a general licence incorrectly – when one or more conditions is not met – creates a more serious exposure than having applied for a specific licence.
General licences under OFAC cover a wide range of activities: personal remittances, certain food and medicine, journalistic activities, legal services, and a series of activity-specific categories that vary by programme. Each general licence is self-contained. It specifies the permitted activity, the persons who may rely on it, the conditions that must all be met simultaneously, and any reporting or record-keeping obligations. Missing one condition voids the entire authorisation.
OFSI's general licences are fewer in number and more narrowly drawn. They tend to address specific humanitarian corridors, insolvency-related payments, and payments for legal costs up to a defined cap. Critically, OFSI requires that a person relying on a general licence maintains records sufficient to demonstrate compliance for a period of five years from the date of the activity. That record-keeping obligation is the same duration as the standard sanctions record-keeping period, and it applies whether or not OFSI ever requests the records.
EU derogations embedded in Council regulations are not labelled "general licences" in the US sense, but they function as standing permissions where the conditions in the relevant regulation are satisfied. The distinction matters: an EU automatic exemption does not require a separate competent-authority authorisation, while an EU-specific authorisation (the equivalent of a specific licence) does. Misreading an exemption as the end of the analysis – when an authorisation is actually required – is a recurring error we see in cross-border M&A due diligence.
Practical test: map the proposed transaction against each element of the candidate general licence. If every element maps cleanly, document that analysis and retain it. If a single element is uncertain, do not proceed on the basis of the general licence without counsel advice. Move to Step 3.
Step 3: Build a specific-licence application that meets the regime's standard
Where no general licence covers the activity, a specific-licence application is the route – and the grounds, format, and processing timelines differ materially between OFAC, OFSI, and the relevant EU competent authority.
OFAC reviews specific-licence applications against defined policy factors. For most commercial transactions, OFAC considers the nature of the activity, the identity of the parties, any US policy interest in permitting the transaction, and the absence of derogatory information about the applicant. Processing time under OFAC is not guaranteed. In our experience, straightforward humanitarian licences can be processed more quickly than complex commercial authorisations, but the timeline depends heavily on programme-specific policy and current workload at OFAC's licensing division. Applicants should not commit contractually to a completion date that depends on OFAC processing.
OFSI operates a case-management model. The applicant submits a licence request with a statement of facts, supporting documentation, and a statement of why the activity should be permitted. OFSI's published guidance sets out the information required and the general approach to specific-licence applications. OFSI applies a public-interest or humanitarian test, or a proportionality assessment, depending on the programme. OFSI will correspond with the applicant during the process and may request additional information. There is no binding statutory processing deadline published for OFSI specific licences, and timelines vary significantly by complexity.
EU competent authorities – the member state authority in the country where the applicant is established – apply the criteria in the relevant Council Regulation. Some programmes provide for licences to be issued within a defined period; others do not. Where a cross-border group has entities in multiple member states, it must apply in the jurisdiction of the entity undertaking the prohibited activity, not the jurisdiction of the group parent. In our practice, this is a frequent source of delay when the compliance team is centralised in one jurisdiction but the transacting entity is in another.
What makes a specific-licence application succeed? Three things matter above others. First, factual precision: every party, every transaction step, and every goods or services description must be accurate and complete. Incomplete applications are returned, costing weeks. Second, legal framing: the application must articulate the policy basis on which the licence should be granted – not just describe what the applicant wants to do. Third, advance engagement: for complex or sensitive applications, early informal contact with the relevant authority can confirm whether the application is within scope before the formal submission is made.
How do the OFAC, OFSI, and EU processes differ in practice?
The three major regimes share the same basic architecture – general licence first, specific licence second – but the procedural and substantive differences are significant enough to require separate analysis for each.
Under OFAC, the concept of a general licence is broad and well-documented. OFAC publishes general licences as part of the programme regulations and as stand-alone licences on its website. They are searchable by programme and activity. Specific licences are granted to the named applicant and are not transferable. OFAC can revoke a specific licence at any time, and the holder must comply with any conditions attached.
Under OFSI, the general-licence regime is more limited. OFSI publishes its general licences publicly and provides guidance on reliance. Specific licences are issued to the applicant entity and attach strict conditions. Critically, a breach of a licence condition is itself a potential sanctions violation, separate from the underlying prohibition. OFSI's enforcement posture has become more active in recent years, and compliance teams should not treat a licence as a guaranteed shield if they have not monitored ongoing compliance with its conditions.
The EU approach introduces a further variable: the competent authority varies by member state. A Paris-based subsidiary and a Frankfurt-based subsidiary of the same group apply to different authorities, under the same Council Regulation but with potentially different national administrative practices. The EU Blocking Regulation adds a further consideration for EU operators facing US secondary-sanctions pressure: it prohibits compliance with certain extraterritorial measures and requires notification to the European Commission. In our cross-border practice, advising a European group that is simultaneously subject to OFAC reach and the Blocking Regulation requires careful sequencing of the licensing strategy.
One practical point on cross-regime divergence: where OFAC and OFSI or the EU diverge on whether a particular activity is prohibited, the more restrictive position governs the conduct of persons subject to both regimes. A specific licence from OFAC does not authorise a UK person to do what OFSI prohibits, and vice versa. Cross-regime licensing – obtaining authorisations from two or more authorities in sequence – is sometimes required for a single transaction. Is your licensing strategy coordinated across every regime that applies?
Step 4: Manage record-keeping and post-licence compliance
Receiving a licence is not the end of the process. Post-licence compliance – maintaining records, monitoring conditions, reporting when required, and responding to changes in the counterparty's status – is an ongoing obligation and a frequent source of enforcement risk.
OFAC requires that persons relying on a general or specific licence retain records for a period that supports audit and enforcement inquiry. The standard record-keeping period under the applicable OFAC regulations is five years. Records should capture: the identity of all parties, the value and description of the transaction, the licence relied upon, the analysis confirming that every licence condition was met, and any correspondence with OFAC.
OFSI applies the same five-year record-keeping standard. Records should cover the licence terms, the transactions undertaken pursuant to it, and any steps taken to verify compliance with conditions. A business that relies on a general licence but cannot produce its contemporaneous compliance analysis has a more difficult conversation with OFSI if a question arises later.
Conditions on specific licences require active management. A licence may restrict the transaction to defined parties: if the counterparty's ownership structure changes mid-licence, the business must re-assess whether the licence still covers the activity. A counterparty that was not listed at the time of licensing may become listed during the licence period. The business is responsible for monitoring this and ceasing activity that would no longer qualify.
Reporting obligations attached to licences vary by regime and by programme. Some OFAC general licences require the holder to file a report with OFAC after the authorised transaction is completed. OFSI may require periodic reporting under certain specific licences. Missing a reporting requirement, even where the underlying transaction was fully authorised, is a breach that can attract a civil penalty. Build the reporting obligation into the transaction management process at the time of licence receipt, not retrospectively.
Risk flags that most often cause applications to fail or businesses to over-apply
Experience across multiple regimes reveals a consistent set of errors. Avoiding them shortens application timelines and reduces the chance of a compliance failure after the licence is granted.
The first and most common error is assuming that a general licence covers the transaction without completing the full condition-mapping analysis. A business that relies on a general licence and later discovers that one condition was not met has potentially committed an unlicensed prohibited transaction. That is a harder position to remedy than a delayed specific-licence application.
The second error is submitting incomplete specific-licence applications. Authorities return incomplete applications rather than processing them. Each return resets the queue. Common omissions include: incomplete ownership information for the counterparty, missing end-use or end-user certifications, insufficient description of the goods or services, and absence of a statement of the policy basis for the licence.
The third error is single-regime thinking. A business that obtains an OFAC specific licence and proceeds without checking whether OFSI or an EU competent authority also has jurisdiction has licensed only part of its exposure. In a multi-currency, multi-entity transaction, the licensing strategy must account for every regime that touches the transaction.
The fourth is failing to monitor post-licence compliance. Licences are not permanent. Conditions can be breached through events the original applicant did not anticipate – changes in counterparty ownership, re-routing of goods, substitution of end users. A business that has not assigned responsibility for ongoing monitoring is exposed from the moment the licence is granted.
A fifth risk flag specific to export controls: where a transaction involves goods, software, or technology that could require a BIS licence under the EAR, the classification step must be completed before the OFAC or OFSI analysis is finalised. An ECCN (Export Control Classification Number under the US Commerce Control List) determines whether a BIS licence is needed and on what grounds. Misfiling a classification – treating a controlled item as EAR99 (not subject to a licence requirement) when it is not – is a separate and independent risk from the financial-sanctions analysis.
A frequent myth we encounter in compliance reviews: "If the counterparty is not on any list, we do not need a licence." This is incorrect. Licence requirements under the EAR and under some OFAC programmes attach to the destination, the end use, or the nature of the goods – not only to the identity of the counterparty. A transaction involving an unlisted buyer in a restricted destination for a controlled item may still require a licence, regardless of the buyer's status on any screening list. The counterparty screen is one component of the analysis; it is not the whole of it.
The position above covers the standard commercial case. Your facts – the counterparty's ownership chain, the goods classification, the payment currency, the routing, and the regimes in play – change the analysis materially. If there is uncertainty at any step in the decision sequence, the cost of obtaining early advice is a fraction of the cost of an incorrectly relied-upon general licence or a failed specific-licence application.
If a transaction has already been flagged or a filing has been refused, an early review can preserve options that narrow with time. For a confidential review of a licence question or a refused application, contact Calder & Vance at info@caldervance.com.
Related practices
- Frozen Account Management – BIS/EAR – managing blocked or frozen accounts under US export-control and sanctions regimes
- Specific vs General Licence – EU Guide – how the EU competent-authority licensing process works and where it diverges from OFAC and OFSI
- Specific vs General Licence – Japan Guide – licensing under Japan's applicable country regime and its interaction with US and EU controls