Calder & Vance International Sanctions & Compliance Counsel

Cross-Border Transactions & Diligence · BIS / EAR

Correspondent-banking de-risking under BIS / EAR: the essentials

A correspondent bank in New York receives a wire instruction routed through its account for a payment platform in a third country. The platform's compliance team has already screened the end-customer against OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons). Clean result. Deal proceeds. Six months later, the bank's export-control team flags that the transaction financed the procurement of dual-use components now on the Entity List (BIS's list of parties subject to enhanced export-licence requirements). The OFAC screen was irrelevant. The BIS / EAR exposure was the one that mattered.

Correspondent-banking de-risking (a financial institution exiting or restricting relationships to reduce regulatory exposure) is not only an OFAC problem. The Bureau of Industry and Security ("BIS") and the Export Administration Regulations ("EAR") impose separate, parallel obligations that bear directly on correspondent and trade-finance relationships. As of January 2026, BIS enforcement activity has made clear that financial institutions which facilitate payments for unlicensed exports of controlled items face significant civil and criminal exposure, regardless of whether those items or parties appear on a sanctions list.

This briefing sets out who administers the BIS / EAR regime as it touches correspondent banking, what the core prohibitions are, how the ownership and control analysis differs from OFAC and OFSI, what the licensing picture looks like, how enforcement operates, and where the cross-border divergences create the sharpest practical risk.

Who administers BIS / EAR and why does it reach correspondent banks?

BIS, an agency within the US Department of Commerce, administers the EAR under authority delegated by the Export Control Reform Act and the International Emergency Economic Powers Act. The EAR governs the export, re-export, and in-country transfer of US-origin items – goods, software, and technology – that appear on the Commerce Control List ("CCL"). Its reach extends to any transaction that involves a US-origin item or US-person involvement, regardless of where the financing leg occurs.

This extraterritorial reach is the reason correspondent banks in London, Frankfurt, or Singapore cannot treat BIS / EAR as a purely domestic US matter. A payment routed through a US correspondent account, or denominated in US dollars and cleared through a US bank, can bring the financing institution within BIS's jurisdiction if that payment facilitates an unlicensed export. In our cross-border practice, we regularly see compliance teams that treat BIS screening as an exporter's task and OFAC screening as the bank's task. That division misses the statutory position: both sets of obligations can bite the same institution on the same transaction.

BIS also maintains the Denied Persons List (individuals and entities denied export privileges) and the Entity List, which imposes a licence requirement for exports of items subject to the EAR to listed parties. Correspondent banks processing trade-finance transactions must check both, in addition to OFAC's SDN List and the EU or UK lists where those regimes also apply.

The position above covers the standard case. Your facts – the counterparty's jurisdiction, the goods or technology being financed, the route of the payment, the regimes in play – change the analysis. For a transaction-specific assessment, contact Calder & Vance at info@caldervance.com.

What does the EAR prohibit in correspondent-banking and trade-finance transactions?

The EAR prohibits any person from facilitating a transaction that the person knows, or has reason to know, is intended to evade or violate export-control requirements. "Facilitating" includes processing a payment, issuing a letter of credit, or providing trade finance where those actions support an unlicensed export of a controlled item to a restricted party or destination.

The critical prohibition for correspondent banks sits in the EAR's general prohibition on proceeding with a transaction when there are red flags – indicators that a party to the transaction intends to use or divert a controlled item inconsistently with the EAR. BIS has published guidance on red flags, none of which are reproduced verbatim in the EAR itself. The guidance identifies patterns such as: a buyer unfamiliar with the product's technical specifications; a destination that is inconsistent with the stated end-use; routing through jurisdictions with no apparent commercial rationale; payment terms that are unusual for the goods involved.

For a correspondent bank, the practical question is whether the bank's knowledge at the time of processing – including any red flags in the documentation it receives – is sufficient to trigger the facilitation prohibition. BIS does not require the bank to have actual knowledge that a controlled item is involved. Constructive knowledge, built from the totality of the transaction pattern, is enough. That standard is close to the "reasonable grounds to suspect" test familiar from financial-crime law, but it applies to export-control facts rather than proceeds of crime.

A second prohibition that bears on correspondent banking is the ban on dealings with parties on the Entity List without a licence. Unlike the SDN List, the Entity List does not freeze assets and does not prohibit all transactions. It imposes a licence requirement for exports, re-exports, and in-country transfers of EAR-controlled items to the listed party. A correspondent bank that finances a shipment of controlled goods to an Entity List party – without confirming that a BIS licence exists – is exposed regardless of the OFAC status of that party.

If a transaction has already been flagged, or if a filing has been refused, an early review can preserve options that narrow with time. To discuss an urgent matter, contact Calder & Vance at info@caldervance.com.

How does the BIS ownership and control test differ from OFAC, OFSI, and the EU?

The BIS / EAR analysis does not apply a single bright-line ownership threshold equivalent to OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked). Instead, BIS focuses on whether a party is subject to a specific licence requirement – through listing on the Entity List or the Denied Persons List – or whether a transaction pattern triggers the red-flag constructive-knowledge test.

This is a meaningful structural difference. Under OFAC, the ownership percentage drives the answer: 50 percent or more aggregate ownership by blocked persons renders the owned entity blocked, regardless of the facts of the transaction. The test is mechanical. Under BIS, the question is whether the item being transacted is subject to the EAR, whether a licence exception applies, and whether the parties and end-use are legitimate. Ownership of the counterparty is relevant context, but it is not the statutory trigger.

OFSI and the EU add a further layer of divergence. Both use an ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person) that extends beyond the 50 percent ownership line to capture entities controlled by a designated person through non-ownership means – board composition, contractual arrangements, or operational dependency. BIS has no direct equivalent. Where the same transaction engages all three regimes simultaneously – as cross-border correspondent transactions frequently do – the strictest applicable prohibition governs each element of the transaction. A compliance team cannot satisfy itself with the most permissive answer across the three regimes.

In our experience, correspondent banks operating across OFAC, OFSI, and EU jurisdictions consistently underestimate this divergence. The OFAC screen returns a clear result; the EU control analysis, applied to the same counterparty, may not. For a side-by-side comparison of how OFAC and EU positions interact in correspondent relationships, see our briefing at Correspondent-banking de-risking under EU sanctions: the essentials.

What is the licensing position under the EAR for correspondent-banking relationships?

BIS administers a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) and a body of licence exceptions (standing authorisations permitting defined categories of transactions without a case-by-case application). For correspondent banks, licence exceptions are the more operationally relevant category: they define the space in which a controlled-item transaction can proceed without a pre-authorised licence.

Certain licence exceptions are unavailable where the counterparty is on the Entity List. BIS frequently attaches footnotes to Entity List designations specifying which licence exceptions – if any – remain available for the listed party. A correspondent bank processing a trade-finance transaction should, in principle, have a mechanism to confirm whether the relevant goods are EAR-controlled, whether the destination and end-user fall within a valid exception, and whether any Entity List footnote restricts that exception. In practice, most correspondent banks do not receive the level of commodity detail in the payment instructions that would allow this assessment. That gap is itself a risk-management issue.

For US-origin technology transferred within a multinational group, the Technology and Software Unrestricted exception and the Intra-Company Transfer provisions reduce friction in routine banking. But controlled items destined for parties in jurisdictions subject to comprehensive US controls – or where BIS has identified diversion risk – will require a specific licence. Timelines for specific-licence review by BIS are not fixed by statute at a precise number of days; in our experience they are significantly shorter than OFAC licensing timelines for some categories, but can extend considerably for complex end-use and end-user reviews. Verify the current position before relying on any indicative timeline.

An important cross-border licensing point: a BIS licence does not authorise a transaction under OFAC, OFSI, or EU rules. Where the same transaction engages multiple regimes, each licensing requirement must be satisfied independently. The interaction between a BIS licence and the EU Blocking Regulation – where EU operators face obligations that can conflict with US export controls – adds a further layer that requires coordinated advice.

What are the key risk flags in correspondent banking and trade finance under the EAR?

BIS has identified a series of transaction patterns that should prompt a correspondent bank – or any financial intermediary – to pause and investigate before processing. These patterns function as constructive-knowledge indicators: if a bank encounters them and proceeds without inquiry, it risks being found to have facilitated a prohibited export.

The most operationally significant risk flags for correspondent and trade-finance banks include:

  • Payment for goods that are inconsistent with the stated business of the buyer or end-user
  • Shipment routing through jurisdictions not commercially associated with the end-destination
  • Buyer requests to omit product descriptions, ECCNs, or country-of-origin details from documentation
  • Payment terms – including advance payment with no standard trade-finance documentation – that are unusual for the goods involved
  • End-user or buyer is a recently incorporated entity with limited commercial history
  • Goods that have well-known military or dual-use applications being shipped to a destination with elevated diversion risk

For correspondent banks specifically, the challenge is that the bank often does not receive the underlying trade documentation. It sees the payment instruction, not the shipping documents or export licence. That structural information gap does not eliminate the obligation: BIS guidance makes clear that the obligation to investigate red flags applies where a bank has reason to know, not only where it has full knowledge. The practical answer for banks is a transaction-monitoring programme calibrated to flag payment patterns – not just counterparty identities – for BIS-relevant indicators. Most screening programmes are calibrated to OFAC and EU list hits. BIS red-flag monitoring requires a different logic.

What happens when a correspondent bank's monitoring produces a hit against the Entity List rather than the SDN List? The response timeline, the licensing analysis, and the reporting obligations differ across the two regimes, and conflating them is a common and material error.

How is the EAR enforced against financial institutions, and what does a voluntary self-disclosure involve?

BIS enforces the EAR through civil and criminal channels. The civil track is administered by BIS's Office of Export Enforcement, which can impose significant monetary penalties on a per-violation basis. Criminal prosecution for knowing and wilful violations is pursued by the Department of Justice. For financial institutions, the risk sits primarily on the civil track – but knowing facilitation of exports to designated parties or sanctioned destinations can cross into criminal territory.

A VSD (voluntary self-disclosure to a regulator) to BIS is a formally recognised route to penalty mitigation. BIS's penalty guidelines treat a timely and complete VSD as a mitigating factor that can substantially reduce the base penalty. The guidelines also recognise the existence of an effective compliance programme, cooperation with the investigation, and remediation steps as additional mitigants. There is no statutory guarantee of a specific reduction; the outcome depends on the facts.

The VSD decision in a BIS matter is often more complex than in an OFAC matter because the same set of facts may simultaneously engage OFAC and, where a US bank is the correspondent, the Federal Reserve or OCC. Multiple regulators may need to be notified in coordinated sequence. A VSD to BIS that omits a parallel OFAC dimension – or vice versa – is worse than no VSD, because it creates an incomplete picture that each agency will discover independently. We advise assessing the full regulatory perimeter before any disclosure is made.

Record-keeping obligations under the EAR are a separate enforcement risk. BIS requires that records related to EAR-controlled transactions be retained for a defined period. Any financial institution that processes trade-finance transactions and does not retain the relevant documentation faces an independent violation risk on audit, separate from the underlying transaction. Verify the current retention period with counsel before implementing a document-management policy, as the period is not reproduced in this briefing from the verified facts registry.

For a full discussion of how OFAC enforcement and licensing interact in correspondent-banking relationships, see our service page at Correspondent-banking de-risking – OFAC service.

De-risking as a compliance response: is exiting the relationship always the right answer?

De-risking – exiting a correspondent or trade-finance relationship to reduce BIS / EAR exposure – is a real and sometimes appropriate response. But it is not cost-free. A bank that exits a relationship without proper analysis may later discover the exit was unnecessary, creating a lost-business cost with no regulatory benefit. Worse, blanket de-risking of entire product categories or geographic corridors can itself attract regulatory attention, particularly where it affects access to financial infrastructure in ways that regulators consider disproportionate.

The correct analytical sequence before a de-risking decision is:

  1. Identify the specific EAR-relevant risk: is the concern an Entity List listing, a red-flag pattern, a controlled-item type, or a destination risk?
  2. Assess whether enhanced due diligence – additional documentation, end-use certification, or commodity screening – can reduce the risk to an acceptable level.
  3. Assess whether a BIS licence is available and, if so, whether the licensing timeline is commercially compatible with the relationship.
  4. If de-risking proceeds, document the analysis: a well-documented exit is a mitigating factor if the bank later faces questions about the relationship.
  5. Consider whether the same facts engage OFAC, OFSI, or EU rules, and whether those regimes require different or additional steps before an exit.

The myth that de-risking always reduces risk is one we address frequently. Exiting a relationship without understanding the underlying regulatory basis may transfer the exposure rather than eliminate it – particularly where the bank is a US correspondent for a non-US institution that retains the underlying business. The non-US bank's continued exposure may, in some structures, remain a secondary-sanctions concern for the US correspondent regardless of the exit.

A second persistent myth is that BIS / EAR is the exporter's problem, not the bank's. As this briefing has set out, the EAR's facilitation prohibition reaches the financing institution directly. The bank that processes the payment for an unlicensed export of a controlled item is not insulated by the fact that it did not physically move the goods.

For an assessment of how a de-risking decision interacts with OFAC disposals of sanctioned interests, see our analysis at Divesting a sanctioned interest under OFAC: the essentials.

When should a financial institution or exporter involve counsel?

BIS / EAR counsel should be involved at the earliest of: a transaction flag against the Entity List or Denied Persons List; identification of a red-flag pattern on a current or recent transaction; receipt of any BIS inquiry, subpoena, or notice of investigation; and the point at which a de-risking decision is being made for BIS-related reasons.

In our experience, the most common error is delayed involvement. An institution identifies a potential issue, attempts to resolve it internally, and involves counsel only when the matter has escalated. At that point, the VSD window may have narrowed, remediation records may be incomplete, and the ability to shape the narrative for BIS has diminished. Early involvement preserves options.

The cross-regime dimension is equally important. Where the same transaction engages OFAC, BIS, and OFSI – as cross-border correspondent transactions frequently do – the advice must coordinate all three. Counsel advising only on one regime and assuming the others are handled can produce a gap that each agency discovers separately. We advise across all three regimes from a single engagement, which is the approach a GC or compliance head should expect for any genuinely cross-border matter.

Related practices

Frequently asked questions

Who administers correspondent-banking de-risking under BIS / EAR?
BIS – the Bureau of Industry and Security, within the US Department of Commerce – administers the EAR under the Export Control Reform Act and IEEPA. Its Office of Export Enforcement handles civil investigations and penalty proceedings. The Department of Justice handles criminal prosecutions for knowing and wilful violations. Unlike OFAC, which administers financial-sanctions lists, BIS's regime is item-and-transaction focused rather than person-and-asset focused, though the Entity List and Denied Persons List impose person-specific restrictions.
What does BIS / EAR prohibit in relation to correspondent-banking de-risking?
The EAR prohibits facilitating an unlicensed export, re-export, or in-country transfer of a controlled item, and it prohibits proceeding with a transaction where red flags indicate a possible violation. For correspondent banks, the key prohibition is the facilitation bar: processing a payment for a controlled-item shipment to a restricted party or destination – without confirming that a licence or exception applies – can constitute a violation. The Entity List imposes a licence requirement for EAR-controlled items shipped to listed parties, and dealing with Denied Persons is broadly prohibited.
How is correspondent-banking de-risking enforced under BIS / EAR?
BIS enforces through civil monetary penalties imposed by its Office of Export Enforcement and through criminal referrals to the Department of Justice for knowing and wilful violations. A timely and complete VSD (voluntary self-disclosure) is a recognised mitigant in the civil penalty guidelines. Where the same transaction engages OFAC and other regulators, enforcement may proceed in parallel across agencies. Record-keeping failures are an independent civil risk on audit, separate from the underlying transaction.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.