A financial institution processing a wire transfer halts the payment. The originating account is linked to a technology company that exports controlled items. The compliance officer wants to know: does the Export Administration Regulations regime reach this payment, and if so, what authorisation is needed before funds move? The answer determines whether a routine treasury transaction becomes an enforcement matter.
Payment authorisations under BIS / EAR govern whether a US-origin or US-routed financial transaction connected to a controlled export or re-export may lawfully proceed. The Bureau of Industry and Security administers the Export Administration Regulations, and its controls can reach payment flows that touch controlled technology, software, or commodities – even where the payment itself originates outside the United States. As of June 2026, exporters, banks, and payment intermediaries must assess each transaction against the Commerce Control List and the applicable Entity List restrictions before clearing funds.
This briefing covers the governing authority, the key prohibitions that affect payment flows, the authorisation routes available, how the BIS / EAR regime interacts with OFAC and other major sanctions regimes, the enforcement posture, and the risk flags that should trigger specialist review.
Who administers BIS / EAR, and what is the legal basis for payment-related controls?
The Bureau of Industry and Security, a division of the US Department of Commerce, administers the Export Administration Regulations under authority derived from the Export Control Reform Act. The EAR controls the export, re-export, and in-country transfer of items – goods, software, and technology – that appear on the Commerce Control List or that are otherwise subject to EAR jurisdiction through US-origin content rules.
Payment authorisations become relevant whenever a financial transaction is connected to a controlled activity. A bank that processes payment for a controlled shipment, a payment platform that settles an invoice for EAR-subject software, or a correspondent bank routing funds linked to an end-use that BIS has restricted – each of these can face exposure if the underlying transaction lacked a valid licence or exception. The EAR is an activity-based regime: the payment does not stand apart from the underlying transaction it funds.
This is distinct from OFAC's sanctions regime, which operates asset-by-asset and person-by-person. BIS controls are item- and activity-based. The two regimes can apply simultaneously to the same transaction. In our experience, firms that treat BIS exposure as purely a logistics or shipping issue – and leave it to the freight team – regularly miss the financial-institution dimension entirely.
What does the EAR prohibit in relation to payment flows?
The EAR prohibits knowing participation in a transaction that violates the regulations, and this prohibition extends explicitly to payments. A party that finances, insures, orders, pays for, forwards, transports, or otherwise facilitates a controlled export without the required authorisation may itself be in violation, even if it never touches the physical goods.
Three patterns produce the bulk of payment-related BIS exposure.
The first is payment to or for an entity on the Entity List. BIS's Entity List identifies companies and individuals to which exports, re-exports, and in-country transfers require a licence. Payments that fund procurement for listed parties – particularly where the goods are EAR-subject – require scrutiny. The licence requirement attaches to the transaction, not merely the shipping documentation.
The second is payment in connection with a controlled item without a licence or applicable exception. Where a commodity, software, or technology on the Commerce Control List requires a licence for the destination or end-use in question, funding the transaction without that licence is itself a violation. The payer, the correspondent bank, and any payment intermediary can each face liability.
The third – and frequently overlooked – is the deemed re-export risk. Technology transferred to a foreign national can be treated as a re-export to their country of origin. Payments that fund access to EAR-controlled technology platforms by foreign-national employees or contractors carry exposure that many treasury and compliance teams have not mapped.
What connects all three patterns is knowledge. The EAR prohibits transactions where a party knows or has reason to know that a violation will occur. Red flags – destination, end-user, the nature of the goods, pricing inconsistent with market rates – impose a duty of inquiry. Ignoring them does not cure the knowledge problem.
How do authorisation routes work under the EAR?
An authorisation under the EAR takes one of two forms: a licence exception or a specific licence issued by BIS. Each has different eligibility conditions, scope, and procedural requirements.
Licence exceptions are standing authorisations embedded in the EAR itself that permit certain categories of transaction without a prior BIS decision. They are condition-specific: the exporter must confirm that all eligibility criteria are met before relying on an exception, and must document that confirmation. From a payment perspective, the exception that covers the underlying export or re-export also covers the payment for it – but only if the exception applies in full. Partial reliance is not available.
Specific licences are case-by-case authorisations issued by BIS following a licence-application review. A specific licence is required where no exception applies or where the item, destination, or end-user falls outside all available exceptions. The application is filed through BIS's online system. BIS may consult other agencies – including the Departments of State and Defense – during review, and the processing period varies with the classification and the destination. We regularly advise clients that the licence application is not the end of the analysis: conditions attached to the licence govern what payment terms, what end-use undertakings, and what documentation the licence-holder must maintain.
For payment authorisations specifically, the practical question is whether the payment intermediary – the bank, the correspondent, the payment platform – can rely on the exporter's licence documentation, or whether it must independently verify eligibility. BIS's "know your transaction" standard means that a payment intermediary with red-flag knowledge cannot take the exporter's word alone. This is a live compliance design question for banks that process high volumes of dual-use trade finance.
The position above covers the standard licensing analysis. Your specific facts – the classification of the goods, the identity and jurisdiction of the payer and payee, the end-use, and the routing of the payment – change the analysis materially.
For an assessment of your EAR exposure in a specific payment or trade-finance transaction, contact Calder & Vance at info@caldervance.com.
How does the BIS / EAR regime interact with OFAC, OFSI, and EU controls?
Payments connected to controlled exports frequently cross more than one regulatory boundary. A single wire transfer can simultaneously engage BIS controls on the underlying goods, OFAC's sanctions on the counterparty or destination, OFSI obligations on the UK leg of a correspondent chain, and EU dual-use controls if EU-origin goods or technology are in the same shipment. The regimes do not coordinate automatically: compliance with one does not satisfy another.
The OFAC / BIS interaction is the most common dual-exposure pattern for US-connected payment flows. OFAC prohibits transactions with designated persons and blocked countries regardless of what the goods are. BIS prohibits transactions involving controlled items regardless of whether the counterparty is designated. The practical consequence is that a payment to a non-designated party in a non-OFAC-targeted country can still require a BIS licence if the goods or technology involved are EAR-controlled. Conversely, an OFAC-compliant shipment of EAR-exempt items can still require an OFAC specific licence if the payment route touches a blocked jurisdiction.
The EU dual-use regime, administered at member-state level under EU rules, applies separately to goods exported from EU territory. A multinational that processes payment through a European subsidiary for controlled goods exported from both the US and an EU member state must satisfy both the EAR and the applicable EU controls. The two regimes use different control-list structures, different licence-exception categories, and different enforcement authorities. Applying the stricter applicable prohibition is the conservative – and legally correct – default.
The UK Export Control regime, administered by ECJU, adds a further layer for transactions routed through UK entities or involving UK-origin goods. OFSI's financial-sanctions obligations can additionally bite on the payment itself if the payee is a UK-designated person or if the UK correspondent bank's obligations under the relevant UK thematic sanctions regulations are engaged.
In our cross-border practice, the most dangerous assumption is that a single-regime clearance covers the transaction. We have acted for exporters who received BIS approval but whose payment was blocked by a European correspondent bank applying EU controls – and for financial institutions that cleared the OFAC check but faced BIS inquiry on the goods classification. A payment authorisation strategy must map all relevant regimes before funds move.
What are the principal risk flags for payment authorisation failures?
BIS identifies a set of recognised red flags that impose a duty of inquiry on exporters, freight forwarders, financial intermediaries, and anyone else in the transaction chain. The presence of one or more red flags does not automatically establish a violation – but ignoring them does not protect a party from liability. The duty is to inquire, assess, and document.
Seven patterns consistently produce payment-related BIS exposure.
- An end-user or consignee that appears on the Entity List, the Denied Persons List, or the Unverified List – or that is controlled by such a party.
- A payment route that passes through an intermediary in a high-risk jurisdiction with no apparent commercial purpose for the routing.
- Pricing that is inconsistent with the fair market value of the goods, suggesting that the stated transaction does not reflect the actual transaction.
- A purchaser or freight forwarder that is reluctant to identify the end-user or the ultimate destination of the goods.
- A request for export packaging inconsistent with the stated destination – for example, ruggedised packaging for an item notionally going to a commercial office.
- A payment structure that splits what appears to be a single commercial transaction into multiple smaller payments, particularly where the split has no evident commercial rationale.
- A mismatch between the technical capability of the goods and the stated business of the end-user – a manufacturing company purchasing items typically used in advanced defence applications.
For financial institutions, a further risk flag is customer behaviour inconsistent with onboarding representations. An exporter that represented itself as selling consumer electronics but whose payment flows now show transactions with military-use end-users is exhibiting a pattern that a well-designed know-your-customer programme should detect and escalate.
If a transaction has already been flagged by a payment intermediary, or if an inquiry from BIS has been received, an early internal review can preserve options – including voluntary self-disclosure – that narrow as time passes.
If a payment has been blocked or a BIS inquiry has arrived, contact Calder & Vance at info@caldervance.com for a confidential initial review.
How is the EAR enforced in the payment-authorisation context?
BIS enforces the EAR through its Office of Export Enforcement. Civil enforcement produces significant penalties; criminal enforcement, where wilful violations are pursued by the Department of Justice, can result in custodial sentences and criminal fines. Financial institutions and payment intermediaries are not immune: enforcement actions have reached banks, payment platforms, and trade-finance providers that processed payments for unlicensed controlled-goods transactions.
Civil penalties are calculated per violation. Where a transaction involves multiple shipments, multiple invoices, or multiple payments, each may constitute a separate violation and carry a separate penalty. The aggregate exposure in a large-volume trade relationship can therefore be substantial even where the individual transaction value is modest.
Voluntary self-disclosure (VSD – the process of proactively reporting a potential violation to BIS before the agency identifies it independently) is a significant mitigant in the civil-enforcement context. BIS's enforcement guidelines treat a timely, thorough, and co-operative VSD as a factor that can materially reduce the penalty. In our practice, the VSD decision – when to file, what scope to disclose, how to structure the narrative – is one of the most consequential calls a compliance team makes after discovering a potential violation. Filing too late, or filing a VSD that is incomplete, can worsen rather than improve the outcome.
BIS also uses administrative orders – denial orders and temporary denial orders – that can effectively remove a party from export markets. A denial order bars the named party from participating in any export transaction subject to the EAR, and it can be issued against non-US parties for conduct that occurred outside the United States. For a financial institution, appearing on a denial order would prevent it from processing any EAR-related payment, which in practice means most international trade finance involving US-origin goods or technology.
The extraterritorial reach of the EAR is one of its most consequential characteristics for non-US businesses. The EAR applies to items that are of US origin, contain more than a de minimis proportion of controlled US-origin content, or are produced abroad using controlled US-origin technology. This means a European bank or an Asian payment platform can face BIS exposure for transactions that never touch US territory, if the underlying goods meet the applicable jurisdictional threshold. This is not a theoretical risk: BIS has pursued enforcement against non-US parties acting outside the United States where the jurisdictional trigger was satisfied.
Common misconceptions about BIS / EAR payment authorisations
One persistent misconception in cross-border compliance is that the EAR applies only to physical goods crossing a US border, and that payment intermediaries are shielded by their distance from the underlying shipment. Neither is correct.
The EAR's "facilitation" prohibition reaches parties who finance, forward, or otherwise participate in a controlled transaction, regardless of physical proximity to the goods. A European bank processing a wire transfer that funds an unlicensed export of EAR-controlled technology is potentially within the scope of the prohibition if it had knowledge – or reason to know – that the payment was connected to a controlled activity. The notion that "we just move money" is not a recognised defence.
A second misconception is that obtaining an OFAC-compliant clearance for a payment is sufficient. OFAC compliance is necessary but not sufficient where the underlying transaction involves EAR-controlled items. BIS and OFAC use entirely different legal instruments, different lists, and different analytical frameworks. Clearing one does not clear the other.
A third misconception – common among technology companies – is that software delivered by download or cloud access is outside the EAR. Software and technology controlled under the EAR remain subject to export controls whether they are transferred physically or electronically. Payment for access to controlled software platforms by foreign nationals or foreign entities can require a BIS licence, and the payment itself is part of the facilitated export chain.
We regularly advise on exactly this gap: a technology company has built a strong OFAC screening programme but has not mapped its cloud-delivery model against the EAR's technology-transfer rules. The payment flow is clean on the OFAC screen – but the underlying access granted to controlled-technology users is unlicensed.
Related practices
- Frozen account management under BIS / EAR – account-level remediation and licence engagement when funds are held by a payment intermediary.
- Payment authorisations under EU controls – parallel analysis of the EU dual-use and financial-sanctions regime for cross-border payment flows.
- EU payment authorisations: advanced analysis – detailed treatment of licensing routes and enforcement posture under EU dual-use and sanctions rules.