A payment platform processes thousands of cross-border transactions daily. Its compliance team flags a beneficiary whose goods description matches a dual-use classification. Is that payment blocked? Does the platform need an export licence? Could processing the payment expose the firm to BIS enforcement even though no physical goods changed hands? These questions now arrive on compliance desks with increasing frequency – and the answers carry material consequences.
Payment-processing controls under BIS / EAR (the Export Administration Regulations administered by the Bureau of Industry and Security) apply when a financial intermediary processes a payment that facilitates the export, re-export, or transfer of controlled items, technology, or software. The obligation does not fall only on exporters. As of mid-2026, BIS has made clear that service providers – including payment platforms, correspondent banks, and fintech operators – can be drawn into EAR liability when they knowingly or with reason to know facilitate a transaction that requires a licence. The cross-regime dimension matters: OFAC's financial-sanctions rules operate in parallel, and the EU dual-use controls impose comparable obligations on European payment operators in the same transaction chain.
This page sets out the governing regime, the compliance tests that payment processors must apply, the cross-regime dimensions that amplify risk, and how Calder & Vance assists firms that need to build or stress-test their payment-screening and controls architecture.
What does BIS / EAR authority cover in the payments context?
BIS administers the EAR under authority delegated through the Export Control Reform Act (ECRA) and the broader framework of IEEPA. The EAR controls the export, re-export, and in-country transfer of dual-use items, commercial technology, and software appearing on the Commerce Control List (CCL – the schedule that assigns an Export Control Classification Number to each controlled item). A payment that directly enables a controlled transaction is not categorically exempt from the EAR's reach simply because no goods physically pass through the payment intermediary's hands.
The test turns on knowledge and facilitation. Where a payment processor has information – through the transaction record, the goods description, the destination, or the end-use declared – that a payment finances or enables an EAR-controlled transaction, and where that transaction requires a licence, the processor's participation can constitute a violation. BIS's enforcement posture treats knowledge broadly: reason to know is sufficient, and wilful blindness does not protect.
Practical scope for payment operators therefore covers four categories. First, direct payments for goods or software on the CCL destined for restricted destinations or denied parties. Second, payments for technology transfers, including licensing fees for dual-use software or technical data. Third, correspondent and intermediary payments where a downstream bank or platform routes funds tied to a controlled export. Fourth, trade-finance structures – letters of credit, documentary collections – where the payment mechanism is tied to a bill of lading covering controlled goods.
The position above covers the standard case. Your facts – the goods, the routing, the counterparty's relationship to a denied person, the regime in play – change the analysis materially.
For an initial assessment of your exposure under BIS / EAR, contact Calder & Vance at info@caldervance.com.
How does the compliance test work for payment processors?
The compliance test for a payment processor under the EAR operates in three sequential layers: item classification, party screening, and transaction-type review. Each layer is a gate; a failure at any gate requires the processor to pause and seek legal review before completing the payment.
The first layer is item classification. When a payment record carries goods or technology information, the processor must assess whether the item falls on the CCL. Many processors do not classify items themselves. Instead, they rely on the exporter's declared ECCN (Export Control Classification Number under the US Commerce Control List) or on an EAR99 self-classification. Reliance on a shipper's ECCN is defensible only where the processor has no independent information contradicting it. Red-flag indicators in the payment record – unusual goods descriptions, discrepancies between declared value and market pricing, routing through transshipment jurisdictions – shift the burden.
The second layer is party screening. BIS maintains the Entity List (a list of foreign persons subject to licence requirements), the Denied Persons List (persons prohibited from participating in EAR transactions), the Unverified List, and related restricted-party registers. OFAC's SDN List (Specially Designated Nationals and blocked persons) operates alongside these. A payment processor that screens only against one list, or that screens at initiation without rescreening on settlement date, carries residual risk.
The third layer is transaction-type review. Certain EAR licence exceptions – including the License Exception ENC for encryption items and various consumer-electronics exceptions – are transaction-specific and condition-dependent. A payment that appears clean under party and classification screening may still require a review if the transaction conditions fall outside the exception's scope.
In our experience, payment platforms that invest in the first two layers but neglect the third layer create a false sense of compliance completeness. A screening tool that flags SDNs and Entity List matches does not substitute for a review of whether the underlying transaction meets the conditions of any available licence exception.
Where do BIS / EAR controls diverge from OFSI and EU dual-use rules?
The cross-regime question is where payment processors most frequently underestimate their exposure. A transaction processed through a European correspondent bank may simultaneously engage BIS / EAR, EU dual-use controls under the relevant Council Regulation on dual-use items, and OFSI financial-sanctions obligations under the UK Sanctions and Anti-Money Laundering Act (SAMLA).
Three divergences are operationally significant. First, the ownership-and-control test differs. OFAC applies the 50 percent rule (an entity owned 50 percent or more in the aggregate by blocked persons is itself blocked). OFSI and the EU apply a broader ownership and control test (extending to de facto control even below a 50 percent ownership threshold). A payment counterparty that passes the OFAC ownership screen may still be caught under OFSI or EU control analysis. Payment processors with multi-currency or cross-border ledgers need both tests applied.
Second, the scope of controlled items diverges. The CCL and the EU's dual-use list are not identical. Items controlled under the EAR may have no EU parallel restriction, and vice versa. A payment for an item that is EAR99 (not specifically listed on the CCL) may still require an EU licence if the goods fall within an EU catch-all clause triggered by an end-use concern. Conversely, items controlled under EU dual-use rules may not require a BIS licence but still attract OFAC sectoral restrictions.
Third, reporting obligations differ. BIS does not impose a general duty on payment processors to report suspect transactions in the same way that financial-intelligence reporting obligations do in many jurisdictions. However, where a processor identifies a potential violation, a voluntary self-disclosure (VSD – a self-initiated report to BIS of an apparent violation) can significantly affect any enforcement outcome. The UK and EU regimes each have their own reporting timelines and licensing-report obligations that run in parallel.
For payment operators managing multi-currency ledgers, the stricter prohibition governs at each point in the chain. A transaction that passes muster under BIS / EAR but fails an OFSI financial-sanctions test is not compliant simply because one regime is satisfied.
What are the risk flags that require immediate legal review?
Risk flags in the BIS / EAR payment context fall into three categories: counterparty indicators, transaction indicators, and routing indicators. A single flag does not necessarily establish a violation. A cluster of flags triggers the obligation to pause, investigate, and – where resolution is not achievable internally – seek legal advice before processing.
Counterparty indicators include: a party appearing on the Entity List or Denied Persons List; a beneficial owner whose identity cannot be confirmed to the processor's reasonable satisfaction; a counterparty in a jurisdiction subject to comprehensive BIS controls; or a payment destination in a free-trade zone with a history of transshipment concerns.
Transaction indicators include: a goods description that is generic, inconsistent with the declared value, or corresponds to a known dual-use category; payment terms that are inconsistent with commercial norms for the stated goods; a fee or commission structure that suggests a third-party intermediary is being compensated outside the transaction; or a declared ECCN that appears inconsistent with the item description provided.
Routing indicators include: payments routed through multiple correspondent banks without commercial justification; use of a jurisdiction that does not appear in the declared origin-destination corridor; and payments structured in a way that fragments what would otherwise be a single reportable transaction.
If a transaction has already been processed and a flag is identified retrospectively, early legal review preserves options. A VSD filed promptly, with a well-structured representation, can materially affect how BIS treats an apparent violation.
If a payment has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss the position.
What is the five-element standard for a payment-controls programme?
BIS has articulated, through its enforcement guidance and published compliance frameworks, a five-element standard for export-compliance programmes that applies equally to payment processors operating within the EAR's reach. A programme that meets all five elements is in a materially stronger position in any enforcement interaction, and can support a VSD that benefits from the most favourable treatment available.
The five elements are: management commitment, risk assessment, written export-compliance procedures, training, and internal audit and corrective action. For a payment processor, each element has a specific operational translation.
Management commitment means that a named senior officer has accountability for the programme and that the programme receives resource commensurate with the volume and risk profile of the firm's payment flows. Risk assessment means a documented analysis of the payment corridors, goods categories, and counterparty types the processor handles, mapped against the CCL, the restricted-party registers, and the applicable licence exceptions. Written procedures means documented decision trees that tell a compliance officer what to do when each type of flag arises. Training means periodic, tested education for staff who touch the screening and payment-release function. Internal audit means periodic testing of whether the procedures are being followed and whether the screening logic is current.
In our cross-border practice, we regularly find that payment platforms have the first two elements in reasonable shape but lack the documented decision trees that translate risk knowledge into operational action. That gap is precisely what an enforcement review will expose. We work with compliance teams to map the gap, design the procedures, and test the screening logic against current restricted-party data.
How does a voluntary self-disclosure work, and when should it be considered?
A VSD (voluntary self-disclosure to BIS of an apparent EAR violation) is a formal submission that initiates a review of the disclosed matter and seeks mitigation of any penalty. BIS treats a timely and complete VSD as a significant mitigating factor in the penalty calculation. The decision to disclose is legal and strategic, not purely procedural.
The VSD process under the EAR involves an initial notification letter, followed by a full submission that sets out the facts, the applicable EAR provisions implicated, and the corrective measures taken or proposed. The timing of the initial notification is material. Delay after discovery – particularly where the firm has continued to process similar transactions during the interval – can reduce or eliminate the mitigation credit that a timely disclosure would have produced.
Who should consider a VSD? A payment processor that discovers, through internal audit or a compliance review, that it has processed payments facilitating exports that required a licence should take legal advice promptly. The questions are: Is this an apparent violation? Is BIS likely to become aware through other means? What is the penalty exposure if BIS initiates? What mitigation is available? Is the corrective action sufficient to demonstrate changed practice?
The cross-regime dimension is important here. A VSD to BIS does not discharge any OFAC reporting obligation where OFAC sanctions are also implicated. A disclosure to one agency requires a parallel assessment of whether disclosure to the other is warranted. In our experience, processors that focus on the BIS disclosure and overlook the OFAC dimension create a different exposure precisely when they are seeking to resolve the first.
A common myth: payment processors are outside BIS / EAR jurisdiction
The most frequently encountered misconception in this area is that the EAR applies only to manufacturers, exporters, and freight forwarders – not to financial intermediaries who never touch the goods. That position has not been correct for some time, and BIS enforcement actions have reached service providers whose role was purely financial.
The EAR's prohibition on proceeding with a transaction with knowledge that an EAR violation is occurring or about to occur is explicit. A payment processor that processes a payment knowing it finances an unlicensed export of a controlled item is not protected by the fact that it held no title to the goods and never shipped anything. The liability analysis turns on knowledge and facilitation, not on physical possession.
The practical implication is significant for fintech operators, digital-payment platforms, and correspondent banks. These entities process high volumes of payments with limited goods-level visibility. That limited visibility does not reduce the obligation; it increases the importance of robust screening logic, documented red-flag procedures, and a compliance programme that has been tested against current BIS guidance.
We regularly advise payment platforms that have operated on the assumption that EAR exposure was a problem for their exporter clients, not for themselves. That assumption, once tested by an enforcement inquiry, can prove very costly to correct under time pressure.
How Calder & Vance assists payment processors under BIS / EAR
Our Sanctions Risk & Compliance practice advises payment processors, correspondent banks, fintech operators, and digital-asset platforms on the full range of BIS / EAR compliance obligations that arise in the payments context. We bring together US export-controls expertise and cross-regime coverage so that a multi-currency or multi-jurisdiction operator does not need to manage separate counsel relationships for each regime.
Our work in this area includes: auditing the screening logic against current restricted-party registers and CCL categories; mapping the firm's payment corridors against the applicable licence exceptions and documenting where review is required; designing the written decision-tree procedures that translate a risk assessment into operational compliance; training compliance and operations staff on BIS / EAR obligations and red-flag recognition; and, where a potential violation has been identified, scoping the apparent violation, advising on voluntary self-disclosure, and preparing the penalty defence or disclosure submission.
In a recent matter, a cross-border payments operator discovered through an internal audit that a category of technology-licensing payments it had processed over several months potentially facilitated unlicensed transfers of dual-use software. We scoped the apparent violation, assessed the BIS and OFAC exposure in parallel, advised on the VSD decision, and prepared the disclosure package and corrective-action plan. The matter was resolved through the disclosure process. We state no outcome guarantee; we describe only the actions taken.
Related practices
- Compliance audit and testing – Australia – Structured testing of sanctions-screening programmes against the Australian autonomous sanctions regime.
- Payment-processing controls – Canada – Advisory on payment-channel compliance under Canadian sanctions and export-control rules.
- Payment-processing controls – EU – Cross-border payment compliance under EU Council regulations on financial sanctions and dual-use controls.