Calder & Vance International Sanctions & Compliance Counsel

Cross-Border Transactions & Diligence · BIS / EAR

Correspondent-banking de-risking under BIS / EAR: scope and obligations

A correspondent bank in a major financial centre receives a payment instruction involving a technology goods shipment routed through an intermediary in a third market. The goods appear on the Commerce Control List (CCL – the US Bureau of Industry and Security's catalogue of items subject to export-control licensing under the Export Administration Regulations, known as the EAR). The bank's compliance team hesitates. Does BIS/EAR create obligations for the bank itself? Can the bank process the payment, or does processing expose it to US export-control liability? These questions sit at the intersection of export-control law and correspondent-banking practice – and, as of January 2026, they are among the most actively litigated areas of US trade-control enforcement.

The BIS / EAR regime, administered by the US Bureau of Industry and Security under the authority of the Export Control Reform Act and IEEPA, applies to any person who acts as a US person or who facilitates a transaction that involves items subject to the EAR – irrespective of whether that person is a bank or a goods exporter. Correspondent banks that process payments related to controlled goods transactions are not automatically exempt: where knowledge of a violation is present, the EAR's prohibition on facilitation attaches. The practical consequence is that financial institutions engaged in cross-border correspondent-banking must treat BIS/EAR exposure as a parallel track alongside OFAC sanctions screening.

This briefing sets out who administers correspondent-banking de-risking obligations under BIS/EAR, the core prohibitions and tests, how the regime interacts with OFAC and EU export-control rules, the risk flags that trigger deeper review, and the point at which specialist counsel should be engaged.

Who administers BIS / EAR and what is the legal basis?

The Bureau of Industry and Security, a division of the US Department of Commerce, administers the EAR under delegated authority from the Export Control Reform Act and, in part, from IEEPA. BIS controls the export, re-export, and in-country transfer of dual-use items (goods, software, and technology that have both commercial and potential military or proliferation applications). It maintains the CCL, classifies items by their Export Control Classification Number (ECCN – the alphanumeric code on the CCL that determines whether a licence is required and for which destinations or end-uses), and issues denied-party lists including the Entity List and the Denied Persons List.

The legal reach of BIS/EAR is explicitly extraterritorial. The EAR governs items of US origin wherever they travel, items produced outside the United States that incorporate a defined threshold of US-origin content (the de minimis rule), and certain foreign-made items that are the direct product of US technology or software (the foreign direct product rule). For correspondent-banking purposes, this means that a non-US bank processing a payment related to a shipment of foreign-made goods can still be within scope if those goods meet the de minimis or foreign direct product tests. We regularly advise financial institutions that discover this exposure only after a transaction has settled.

The position above covers the standard framework. Your specific correspondent-banking exposures – the goods, the counterparties, the routing, the destination – change the analysis considerably. For an initial assessment of your institution's BIS/EAR exposure, contact Calder & Vance at info@caldervance.com.

What does the EAR prohibit in correspondent-banking contexts?

The EAR's core prohibition is on the export, re-export, or transfer of items subject to the EAR without a required licence. In a correspondent-banking context, three specific provisions are most relevant: the prohibition on proceeding with a transaction with knowledge that a violation has occurred or is about to occur; the prohibition on financing, forwarding, or facilitating a controlled transaction; and the requirement not to service, ship, or otherwise deal with parties on the Entity List, the Denied Persons List, or the Unverified List without the appropriate authorisation.

The knowledge standard under the EAR is broader than it first appears. It encompasses not only actual knowledge but also a conscious disregard of facts that would lead a reasonable person to inquire further – a standard sometimes described as "wilful blindness." This matters enormously for correspondent banks. A bank that processes a payment and takes no steps to understand what the underlying transaction involves, despite red flags in the transaction documentation, may be found to have acted with the requisite knowledge. Red flags identified in BIS guidance include unusual payment routing, requests to omit information from shipping documents, end-users in high-risk destinations that have no apparent commercial need for the goods, and counterparties with names that closely resemble denied-party entries. Have your compliance procedures been designed specifically to detect these patterns in correspondent-payment flows?

Beyond the facilitation prohibition, financial institutions that are themselves US persons – including US branches and subsidiaries of non-US banks – face an additional layer of obligation. They may not process transactions that they know, or have reason to know, will further a violation. The practical upshot: a US correspondent bank that clears a dollar payment for a foreign trade-finance transaction involving EAR-controlled goods to a restricted destination may face BIS enforcement action even if the bank is not the exporter and has no commercial relationship with the goods.

How does the 50 percent rule and ownership-chain analysis differ under BIS/EAR compared with OFAC?

The OFAC 50 percent rule – under which an entity owned 50 percent or more in the aggregate by one or more blocked persons is itself treated as blocked, regardless of whether it is separately listed – is a bright-line ownership threshold. BIS/EAR does not replicate this mechanical test for most purposes, but it operates a conceptually parallel (and in some respects broader) analysis when it comes to the Entity List and denied-party controls.

Under BIS/EAR, the Entity List restriction attaches to the listed entity and to transactions that would benefit it. BIS guidance and enforcement history indicate that BIS looks beyond the listed entity to transactions structured to route controlled items through affiliates, subsidiaries, or related parties where the evident purpose is to reach a listed entity. This is not an automatic percentage-ownership test; it is an effects-based analysis that asks whether the ultimate recipient or beneficiary is the listed party. For a correspondent bank, the operational difference is significant: OFAC screening produces a binary hit-or-no-hit answer at the 50 percent ownership level, whereas BIS compliance requires an assessment of transaction purpose and routing that is more fact-specific and judgment-intensive.

In our experience, financial institutions that run OFAC-style list screening and conclude they have discharged their BIS obligations are consistently underestimating their exposure. The two regimes demand different analytical approaches, and a clean OFAC screen does not foreclose BIS liability.

How does BIS / EAR interact with OFSI, EU export controls, and other regimes?

Correspondent-banking de-risking decisions almost never arise in a single-regime context. A dollar-clearing bank subject to BIS/EAR will simultaneously face OFAC sanctions exposure on the same transaction. A European bank processing euro payments in trade-finance chains involving dual-use goods will be subject to EU dual-use export-control rules under the applicable EU regulation, as well as potential UK ECJU obligations if the goods originated in or transited through the United Kingdom.

Three interaction points are particularly important for cross-border practitioners.

Divergence between BIS and OFAC on the same counterparty. A party may appear on the BIS Entity List but not on the OFAC SDN List, or vice versa. In our cross-border practice, we frequently see financial institutions that run only OFAC list-screening and miss the BIS dimension entirely. The two lists have different legal consequences, different licensing routes, and different enforcement pathways. Where the same transaction triggers both, the stricter prohibition governs the permissibility of the transaction; both sets of licence requirements must be assessed separately.

EU export controls and the blocking regulation. European banks that also operate US branches face a structural tension. The EU Blocking Regulation, as amended, seeks to neutralise the extraterritorial effect of certain US secondary-sanctions measures on EU operators. It does not, however, address BIS/EAR primary-jurisdiction controls, which apply to items of US origin or content irrespective of the Blocking Regulation's scope. A cross-border institution must therefore assess whether a given BIS measure falls within or outside the Blocking Regulation's protection before deciding how to proceed.

UK ECJU alignment and post-Brexit divergence. UK export-control rules, administered by ECJU under the Export Control Order and related instruments, have diverged from EU rules since Brexit. The UK maintains its own control lists and licensing requirements, and OFSI administers financial-sanctions obligations separately from ECJU. For a correspondent bank clearing sterling payments related to dual-use goods exports, both ECJU and OFSI exposure must be assessed alongside BIS/EAR. If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact us at info@caldervance.com for a confidential assessment.

What are the principal risk flags for correspondent banks under BIS / EAR?

BIS has published guidance identifying transaction patterns that should prompt a correspondent bank to pause and investigate further before processing. These red flags are not exhaustive, but they represent the categories most frequently cited in BIS enforcement contexts.

  • Unusual routing or third-country intermediaries. Payments that pass through jurisdictions with no apparent commercial nexus to the underlying transaction, particularly where the intermediate party is in a jurisdiction known to transit controlled goods to restricted destinations, warrant scrutiny.
  • Discrepancies in documentation. Mismatches between invoice values and market rates for the described goods, generic or vague descriptions of items in payment documentation, or references to items that appear on the CCL as a plausible match for the described goods.
  • End-users without apparent commercial need. A purchasing entity with no evident legitimate commercial application for the goods described – for example, a small trading company purchasing items with obvious semiconductor-related specifications.
  • Requests to omit or alter information. Instructions from a customer to exclude or modify standard shipping or banking information in a manner that would obscure the nature or destination of goods.
  • Counterparty proximity to denied-party entries. Names, addresses, or corporate structures that closely resemble entries on the Entity List, the Denied Persons List, or the SDN List, even where an exact match is not returned by screening software.
  • Goods descriptions that map to high-risk ECCNs. Items described in terms that a compliance officer with export-control knowledge would associate with controlled categories – advanced electronics, certain software, optical or sensing equipment – particularly when the destination is a restricted or high-scrutiny jurisdiction.

None of these flags, individually, creates automatic liability. Each requires a proportionate investigation. What BIS enforcement actions make clear is that a bank that identifies a red flag and does nothing further – processes the payment without inquiry – is in a materially worse position than one that documents its review, escalates appropriately, and reaches a reasoned conclusion. The record of the review matters at least as much as the conclusion.

What are the reporting and record-keeping obligations for financial institutions?

The EAR does not impose a standing affirmative obligation on correspondent banks to report every transaction involving potentially controlled goods. However, several specific reporting obligations and triggers are relevant to financial institutions operating in this space.

First, where a bank receives a request to participate in a transaction and has reason to believe the request violates the EAR, it is required under the anti-boycott and related provisions to report certain requests to BIS. The anti-boycott provisions apply most directly to requests to refuse to deal with particular parties on grounds connected with certain foreign policy boycotts, rather than to standard export-control transactions; their scope is distinct and must not be conflated with the facilitation prohibition.

Second, financial institutions that discover they have processed a transaction that turns out to violate the EAR should consider a voluntary self-disclosure (VSD – a proactive report to BIS disclosing the apparent violation before BIS initiates an investigation). VSD practice under BIS operates separately from OFAC's voluntary disclosure regime, with its own procedures, timelines, and mitigation criteria. In our practice, clients who make a well-prepared VSD – with a thorough internal investigation completed before submission – consistently achieve better outcomes than those who wait for BIS to identify the matter first. The window to act is not unlimited; the longer a potential violation is left undisclosed, the more limited the mitigation credit available.

Record-keeping requirements under the EAR are substantial. Persons who are parties to export transactions subject to the EAR are required to retain records – including transaction documentation, correspondence, and financial records – for a defined period. As currently in force, verify the current position before relying on it, but the standard record-keeping period under the EAR is five years from the date of the export, re-export, or in-country transfer. For a correspondent bank, this means retaining payment records, correspondent instructions, and any compliance review documentation related to EAR-relevant transactions for at least that period.

What is de-risking, and when is it a proportionate response?

De-risking (a financial institution exiting a relationship or declining a transaction to avoid export-control or sanctions exposure) is a legitimate business decision, but it is not cost-free and it is not always the correct outcome of a BIS/EAR analysis. Regulators in multiple jurisdictions – including BIS itself and the Financial Stability Board at the international level – have noted concerns about the systemic effects of disproportionate de-risking, particularly where it affects legitimate trade flows in developing markets or disrupts correspondent-banking access for smaller financial institutions.

The question a compliance team should ask is not simply "could this transaction have BIS/EAR implications?" Almost any cross-border payment involving goods could theoretically involve controlled items. The operative question is whether, after a proportionate risk assessment, there is a genuine, articulable reason to believe that the specific transaction involves items subject to the EAR, a restricted end-user, or a prohibited end-use. Where the answer is no, de-risking the transaction is not a compliant outcome – it is an over-correction that carries its own commercial and regulatory consequences.

In a recent matter, a financial-institution client in the payments sector received an instruction to block a category of correspondent-payment flows entirely following a BIS enforcement notice in the same sub-sector. We assessed the specific payment flows against the EAR's scope criteria, identified which categories genuinely required enhanced due diligence, and restructured the institution's transaction-monitoring procedures to apply proportionate controls without a wholesale exit from the business line. The result was a defensible compliance posture that preserved commercially important relationships.

The myth to address here is a common one: that de-risking the entire correspondent-banking relationship is a safe harbour from BIS/EAR liability. It is not. Exiting a relationship does not cure a past violation; it does not prevent BIS from investigating transactions that occurred while the relationship was active; and it can, in certain circumstances, attract scrutiny if the exit itself was motivated by a desire to destroy records or avoid investigation. The only sustainable protection is a well-designed, proportionate compliance programme applied to active transactions.

When should a financial institution involve sanctions and export-control counsel?

Early involvement of specialist counsel is consistently more effective – and less costly – than reactive engagement after an enforcement action has begun. The specific triggers that should prompt an institution to seek external advice include the following.

  • A transaction or payment instruction has generated a red flag under the institution's BIS/EAR procedures and the compliance team cannot resolve the question of EAR scope or end-use internally.
  • A goods shipment underlying a correspondent payment involves items that may be on the CCL, and the institution has not previously conducted an ECCN classification review for that goods category.
  • A counterparty or beneficiary appears on the Entity List, the Denied Persons List, or the Unverified List, and the institution requires advice on whether a licence or licence exception applies.
  • An internal review has identified a potential prior violation and the institution is assessing whether to make a VSD to BIS.
  • A BIS administrative subpoena, information request, or enforcement notice has been received.
  • The institution is expanding into a new correspondent-banking corridor involving goods-intensive trade flows and requires a BIS/EAR risk assessment of the new business line.
  • A cross-border merger or acquisition involves a target that has a correspondent-banking book with exposure to EAR-controlled goods transactions, and pre-closing due diligence is required.

In our cross-border practice, the matters that produce the most difficult outcomes are those where in-house teams attempted to resolve a BIS/EAR question using OFAC analytical frameworks, concluded (incorrectly) that a clean OFAC screen resolved the BIS exposure, and proceeded with the transaction. The two regimes are complementary but distinct. A compliance counsel trained only in OFAC practice may not be equipped to assess the BIS dimension without specialist input.

Related practices

Frequently asked questions

Who administers correspondent-banking de-risking under BIS / EAR?
The Bureau of Industry and Security, a division of the US Department of Commerce, administers the Export Administration Regulations. BIS has authority to investigate and bring enforcement actions against any person – including financial institutions – that facilitates a transaction with knowledge that the transaction violates the EAR. Enforcement cases involving financial institutions are frequently coordinated with OFAC, DOJ, and other US agencies. The Entity List, Denied Persons List, and Unverified List are all administered by BIS and updated on a rolling basis throughout the year.
What does BIS / EAR prohibit in relation to correspondent-banking de-risking?
The EAR prohibits any person from proceeding with a transaction with knowledge – including wilful blindness – that the transaction will violate the EAR. For correspondent banks, the most directly relevant prohibitions are: financing or facilitating a controlled export or re-export without the required licence; processing payments where a red flag has been identified and no due diligence has been conducted; and dealing with parties on the Entity List or Denied Persons List without authorisation. The regime does not impose a standing duty to screen every payment for export-control compliance, but it does impose a duty not to facilitate a known or apparent violation.
How is correspondent-banking de-risking enforced under BIS / EAR?
BIS enforces the EAR through its Office of Export Enforcement. Civil penalties for EAR violations can be significant – the statutory maximum per violation is substantial, and BIS applies a schedule of aggravating and mitigating factors in calculating the penalty. Voluntary self-disclosure before BIS initiates an investigation is the most important mitigating factor available; it can result in a substantially reduced penalty or a no-action outcome. Criminal enforcement for wilful violations is handled by DOJ. In practice, financial-institution matters frequently involve parallel OFAC and BIS proceedings, and the two enforcement tracks must be managed together.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.