A payment-processing firm running cross-border transactions through a US correspondent network received an automated alert. One beneficiary name had generated a partial match on a commercial screening database. The compliance team cleared it within the hour and the payment settled. Eighteen months later, during an internal audit, a broader pattern emerged: the firm's screening logic had been configured to suppress alerts below a defined confidence threshold. Multiple payments had been processed to entities whose underlying customers were subject to controls under the Export Administration Regulations (EAR – the US Commerce Department's rules governing the export, re-export, and in-country transfer of controlled items, technology, and software). The question was no longer whether a single payment had been wrongly cleared. The question was whether the firm had a systemic exposure.
Payment processors and financial intermediaries are not direct exporters, yet the EAR can reach their activity when they facilitate transactions involving controlled items, technology, or software destined for restricted end-users or end-uses. The Bureau of Industry and Security (BIS) – the US Department of Commerce agency that administers the EAR – has made clear that "facilitation" of a prohibited export can attract liability even where the facilitating party never touches the goods. The governing instrument is the EAR itself, administered under the authority of the Export Control Reform Act and the statutory powers delegated to BIS.
This case comment walks through how such a matter typically presents, the legal questions it raises under the EAR, where it intersects with parallel OFAC and OFSI obligations, and the practical steps a payment processor should take the moment systemic exposure is identified.
How the Situation Presented
The trigger in this type of matter is rarely a single identifiable payment. It is an audit finding that reveals a configuration gap in the screening architecture – a gap that, once surfaced, calls into question a population of transactions rather than a handful of individual credits.
In the matter described here, the firm had configured its transaction monitoring to apply a lower scrutiny threshold to payments denominated below a defined value. The rationale had been operational: reducing false-positive rates for high-volume, low-value consumer-adjacent flows. What the configuration did not account for was that BIS controls operate on the basis of the nature of the item, technology, or software involved – not the monetary value of the transaction. A payment for a modest-value component can carry the same export-control significance as a payment for equipment worth many times more, if the underlying item sits on the Commerce Control List (CCL) under a classification that requires a licence.
The audit finding therefore created two immediate problems. First, the firm could not readily identify, within its payment records, which transactions had involved controlled items, because the payment data did not systematically capture commodity descriptions or ECCN (Export Control Classification Number – the alphanumeric code on the CCL that determines which controls and licence requirements apply to a given item). Second, the firm had no documented process for requesting that information from originating customers at the time of payment.
The compliance team escalated to external counsel. The first conversation was about scope: how many payments, over what period, and to what counterparty types? The second was about risk characterisation: facilitation liability under the EAR, or something broader?
The Legal Questions Under the EAR
BIS jurisdiction under the EAR extends to any person who causes, aids, abets, counsels, commands, induces, procures, or is otherwise involved in an export, re-export, or in-country transfer of an item subject to the EAR to a restricted party or end-use. The prohibition on facilitation is not confined to exporters. A financial intermediary that processes payment for a shipment it knows, or has reason to know, is destined for a restricted party can be drawn into a BIS enforcement matter.
The "reason to know" standard is significant. It does not require actual knowledge. BIS guidance indicates that a firm is on notice – and therefore potentially liable – when the facts available to it would lead a reasonable person to suspect that the transaction involves a restricted party or end-use. That standard places an operational burden on payment processors that goes beyond simple name-screening against the SDN List.
In a situation where a firm's screening logic has systematically suppressed alerts, the "reason to know" question becomes acute. Can the firm argue that it had no reason to know, when its own configuration choices reduced the information available to its reviewers? In our experience advising firms in equivalent positions, that argument is a difficult one to sustain. BIS and enforcement agencies more broadly take the view that a firm cannot rely on a process it has itself designed to be less sensitive than the baseline the regulators would expect.
Two further EAR concepts were relevant. The first was the Entity List – BIS's list of parties to whom exports, re-exports, and in-country transfers require a specific licence, regardless of the item's ECCN. The second was the end-use and end-user controls that apply to certain categories of technology independent of list-based controls. The audit needed to address both.
Cross-Regime Intersections: OFAC, OFSI, and the EU
Payment processing sits at the intersection of export-control and financial-sanctions regimes. A transaction that raises an EAR facilitation concern will almost always raise parallel OFAC questions, and, for a firm with EU or UK operations, parallel questions under EU Council regulations and OFSI's rules.
The OFAC exposure in this scenario was distinct from the BIS exposure. OFAC's SDN List (the Office of Foreign Assets Control's list of Specially Designated Nationals and Blocked Persons) operates independently of the CCL. A party that appears on neither list may still be a restricted end-user under the EAR because of their industry, their location, or their stated end-use. Conversely, a party may appear on the SDN List without necessarily being associated with EAR-controlled technology. The two analyses must be run separately and then reconciled.
For the firm in this matter, which operated EU-incorporated subsidiaries, EU Council regulation prohibitions were also in play. The EU dual-use rules impose their own classification and licensing architecture, and – critically – the EU Blocking Regulation created a potential conflict-of-laws dimension: the firm's EU entities could not automatically give effect to US instructions that fell within the Regulation's scope. That conflict required careful legal mapping before any remediation steps were taken, because steps that corrected the EAR position could, in the wrong sequence, create an EU law problem.
OFSI's rules in the UK added a third dimension. The UK financial-sanctions regime imposes an obligation to report knowledge or reasonable suspicion that a person is a designated person or has committed an offence. Where a payment firm's internal review surfaces past transactions with potentially designated parties, the question of whether a reporting obligation has been triggered – and whether the reporting window remains open – requires immediate assessment. We regularly advise firms on exactly this sequencing problem: the internal review that generates knowledge can itself start a regulatory clock.
What Does Remediation Look Like Under the EAR?
Once the scope of a potential systemic EAR exposure is identified, the firm faces a structured set of decisions, each of which carries its own risk and timeline.
The first decision is whether to conduct a voluntary self-disclosure (VSD – a proactive disclosure to BIS of an apparent violation, which BIS's enforcement guidance recognises as a significant mitigating factor). VSD is not mandatory in all cases under the EAR. Whether to file one depends on the severity of the apparent violation, the strength of the evidence, the likely enforcement posture BIS would take on investigation, and whether other regulatory bodies have already been notified or are likely to open their own enquiries.
In a systemic screening failure, the case for VSD is strong. BIS's enforcement process distinguishes between firms that surface problems and act on them, and firms where problems are discovered through external investigation. The distinction affects both the structure of any resolution and the penalty outcome – though we emphasise that no outcome is guaranteed.
The second decision concerns interim controls. While the review is underway, the firm needs to strengthen its screening configuration immediately. Leaving the deficient configuration in place during an ongoing review is not a neutral position: it is a continuing failure, and regulators treat it as such. Interim controls typically include raising the alert sensitivity threshold, implementing manual review for payment categories that were previously below the suppression threshold, and suspending payments to categories of counterparty where the review has not yet been completed.
The third decision concerns customer outreach. For payments already processed, the firm may need to go back to originating customers to obtain commodity descriptions and end-use certifications that should have been collected at the time. That outreach must be carefully designed: it cannot suggest to customers that the firm is building a record for litigation, and it must comply with any confidentiality obligations triggered by the investigation itself.
The position above covers the standard case. Your facts – the geography of your payment flows, the CCL classifications of the underlying goods, the extent of your US nexus, and the other regimes in play – change the analysis materially.
For an assessment of your exposure under the EAR or across the relevant combined regime, contact Calder & Vance at info@caldervance.com.
Risk Flags That Indicate a Systemic Problem Rather Than an Isolated Incident
Not every screening alert that resolves to a false positive indicates a structural problem. But certain patterns, when they appear together, are reliable indicators that the firm's controls architecture has a gap rather than a single point failure.
The most significant flags we see in practice are: screening configurations that suppress alerts by transaction value rather than by risk category; the absence of any process for capturing commodity or technology descriptions at the payment instruction stage; no documented escalation path for partial name matches that are resolved below a defined score; gaps in periodic review of screening lists – EAR-specific lists such as the Entity List, the Denied Persons List, and the Unverified List update on a different schedule from OFAC's SDN List and must be refreshed independently; and the absence of end-use and end-user certification requirements in the firm's customer onboarding documentation.
A further risk flag is jurisdictional: payment processors that route transactions through US correspondent banks are subject to the EAR as a consequence of that routing, even if the processor itself is not US-incorporated. The US nexus created by the correspondent relationship is sufficient to extend BIS jurisdiction. This is a point that non-US payment firms regularly underestimate, and it is the reason that a purely OFSI or EU-focused compliance programme will not be sufficient for a firm with US correspondent exposure.
If a transaction has already been flagged, or an internal review has surfaced a potential gap, an early external review can preserve options that narrow with time.
For a confidential review of a potential breach or screening gap, contact us at info@caldervance.com.
A Common Misconception About Payment Processors and the EAR
Payment firms frequently proceed on the assumption that the EAR applies only to those who physically export goods. The regime, on this reading, is an exporter's problem. Payment processing is a financial service, not an export transaction, and therefore sits outside BIS's remit.
That reading is incorrect, and relying on it is one of the more consequential compliance errors we see. The EAR covers the export of "items" – a category that expressly includes technology and software, including intangible transfers. A payment that facilitates the transfer of controlled technology, or that enables a transaction involving a restricted end-user, is capable of engaging the EAR even where no physical goods cross a border. BIS's enforcement guidance explicitly addresses the liability of persons who facilitate prohibited exports without themselves executing the shipment.
The misconception is compounded by the structure of commercial screening tools. Most tools deployed by payment firms are calibrated against OFAC's SDN List and equivalent financial-sanctions lists. They are not designed to screen against the CCL or to capture end-use information. A clean SDN screen therefore says nothing about EAR compliance. The two regimes require different data and different analytical steps, and a compliance programme that treats one as a proxy for the other will have a structural gap.
In our cross-border practice, we advise payment firms to treat EAR screening as a separate workstream from financial-sanctions screening, with its own data requirements, its own escalation paths, and its own documentation standards. The operational cost of maintaining two workstreams is real. The cost of discovering, in an audit, that only one workstream was running, is considerably higher.
When to Involve Counsel, and What Counsel Does
External counsel should be involved at the point that an internal review has produced a credible indication of systemic exposure – not after the scope has been fully mapped, and certainly not after the firm has decided on its remediation steps without legal input.
The reason the timing matters is that the decisions made in the first days of an internal review shape the options available later. A firm that begins customer outreach before assessing its disclosure obligations may inadvertently waive legal privilege or generate documents that complicate a subsequent VSD. A firm that strengthens its screening configuration without preserving evidence of the prior configuration may find it difficult to demonstrate the good-faith corrective action that BIS's enforcement guidance recognises as a mitigating factor.
In this matter, we assessed the legal basis for each EAR prohibition potentially engaged, mapped the cross-regime OFAC and OFSI obligations that ran alongside the BIS exposure, advised on the VSD decision and the timing and content of any disclosure, designed the interim controls to demonstrate ongoing corrective action, and prepared the customer-outreach process in a way that preserved the firm's legal position throughout.
The scope of that work is consistent with our standard engagement in payment-processing control failures. It draws on the export-controls and financial-sanctions practices together, because the two cannot be addressed independently where the underlying transaction base is the same.
Related practices
- Compliance audit and testing – systematic review of screening logic, control gaps, and programme design across jurisdictions
- Payment-processing controls – OFSI matter – a parallel case comment on the UK financial-sanctions dimension of payment-control failures
- Sanctions contract clauses – Canada matter – how contractual controls intersect with cross-border compliance obligations