Select your language

Blog

Blog description

OFAC, BIS, or ITAR: Understanding the Three U.S. Trade Control Regimes and Why One International Transaction May Trigger All Three

OFAC, BIS, or ITAR: Understanding the Three U.S. Trade Control Regimes and Why One International Transaction May Trigger All Three

Companies engaged in international trade often refer broadly to "sanctions compliance" without recognizing that U.S. trade controls are administered through multiple legal frameworks, each serving a distinct purpose. While sanctions screening has become standard practice for many businesses, compliance frequently requires much more than checking a customer against a restricted-party list.

A single international transaction may simultaneously implicate the regulations administered by the U.S. Department of the Treasury's Office of Foreign Assets Control ("OFAC"), the U.S. Department of Commerce's Bureau of Industry and Security ("BIS"), and the U.S. Department of State's Directorate of Defense Trade Controls ("DDTC"). Each agency regulates different aspects of cross-border commerce, and authorization under one regime does not eliminate obligations under another.

Understanding the distinctions between these regulatory systems is essential for exporters, manufacturers, technology companies, financial institutions, logistics providers, and multinational corporations. Failure to analyze each applicable regime independently may result in significant civil penalties, criminal liability, shipment delays, contractual disputes, and reputational harm.

This article provides a practical overview of the three principal U.S. trade-control regimes, explains how they interact, and highlights common compliance pitfalls businesses should avoid.

One Transaction, Three Different Regulatory Regimes

One of the most common misconceptions encountered by international businesses is the belief that sanctions compliance consists solely of screening customers against OFAC's Specially Designated Nationals and Blocked Persons ("SDN") List.

While sanctions screening is an essential compliance measure, it represents only one component of a broader legal analysis.

Before completing an international transaction, companies should answer three separate questions:

  • Who are the parties involved?
  • What is being transferred?
  • Where is it going, who will receive it, and how will it ultimately be used?

Different federal agencies regulate each of these questions.

Agency

Primary Focus

Key Question

OFAC

Economic sanctions

May a U.S. person engage in this transaction?

BIS

Export Administration Regulations (EAR)

Does this item require export authorization?

DDTC

International Traffic in Arms Regulations (ITAR)

Does the transaction involve defense articles or defense services?

Although these regulatory regimes frequently overlap, they operate independently.

A transaction that is permissible under one framework may nevertheless require authorization—or even be prohibited—under another.

OFAC: Regulating Transactions and Sanctioned Parties

OFAC administers U.S. economic sanctions programs under various statutes and Executive Orders designed to advance U.S. foreign policy and national security objectives.

Unlike export-control regulations, OFAC generally focuses on who is involved in a transaction rather than what is being exported.

Depending on the applicable sanctions program, OFAC regulations may prohibit or restrict transactions involving:

1o.png

Sanctions programs are not identical.

Some comprehensively prohibit nearly all transactions involving particular jurisdictions, while others target only specific individuals, companies, industries, or activities.

Accordingly, identifying that an OFAC sanctions program applies is merely the beginning of the legal analysis. Counsel must determine which sanctions program governs the transaction, whether a General License authorizes the activity, or whether a Specific License must be obtained before proceeding.

The SDN List Is Only the Beginning

Many businesses mistakenly believe that screening customers against OFAC's SDN List is sufficient to satisfy sanctions compliance obligations.

It is not.

One of OFAC's most important compliance principles is the 50 Percent Rule.

Under this guidance, an entity owned, directly or indirectly, 50 percent or more in the aggregate by one or more blocked persons is itself considered blocked—even if it does not appear on the SDN List.

For example:

  • Company A is owned 30% by SDN One;
  • 20% by SDN Two; and
  • 50% by non-sanctioned investors.

Although Company A is not listed on the SDN List, it is considered blocked because sanctioned owners collectively hold a 50 percent ownership interest.

Consequently, effective sanctions compliance requires more than automated name screening. Companies should also evaluate ownership structures, identify beneficial owners, and understand indirect ownership relationships where appropriate.

BIS and the Export Administration Regulations (EAR)

While OFAC primarily regulates parties and transactions, BIS regulates exports, reexports, and certain transfers of commodities, software, and technology through the Export Administration Regulations ("EAR").

The EAR governs many products used in ordinary commercial activities, including:

2o.png

Unlike OFAC, BIS asks a different series of questions:

  • What is the item?
  • Where is it being exported?
  • Who is receiving it?
  • How will it be used?

Each question must be analyzed independently.

Classification Under the EAR

Every export-control analysis begins by determining whether an item is subject to the EAR.

If it is, the next step is classification.

Many controlled items are assigned an Export Control Classification Number ("ECCN") listed on the Commerce Control List.

An ECCN identifies:

  • technical characteristics;
  • reasons for control;
  • applicable licensing requirements; and
  • restrictions based upon destination.

Exporters then compare the item's reasons for control with the Commerce Country Chart to determine whether a BIS license is required.

Proper classification is often one of the most technically challenging aspects of export compliance and frequently requires input from engineers, product specialists, and legal counsel.

EAR99 Does Not Mean "No Restrictions"

Perhaps the most common misconception under the EAR concerns the designation EAR99.

Businesses often assume that an EAR99 item may be exported anywhere without restriction.

That assumption is incorrect.

EAR99 simply means the item is subject to the EAR but is not specifically listed on the Commerce Control List.

An EAR99 item may still require a license because of:

3o.png

For example, a standard commercial laptop may qualify as EAR99. Exporting that same laptop to a prohibited military end user or a company appearing on the BIS Entity List may nevertheless require prior authorization or be prohibited altogether.

Accordingly, classification never ends the export-control analysis.

Destination, End User, and End Use

After classification, exporters should carefully evaluate three additional factors.

Destination

Some countries are subject to comprehensive export restrictions, while others require licenses only for specific categories of controlled items.

End User

The identity of the recipient is often just as important as the product itself.

BIS maintains several restricted-party lists, including the Entity List, Denied Persons List, and Unverified List. Each carries different legal consequences and should not be confused with OFAC's SDN List.

End Use

Even an ordinary commercial product may require authorization if it will ultimately be used in prohibited nuclear, missile, military, or other restricted activities identified under the EAR.

Understanding all three elements is essential to a legally compliant export.

ITAR: Regulating Defense Articles, Technical Data, and Defense Services

While the Export Administration Regulations ("EAR") govern a broad range of commercial and dual-use items, the International Traffic in Arms Regulations ("ITAR") regulate defense-related articles, technical data, defense services, and certain brokering activities that the U.S. Government considers critical to national security.

The ITAR is administered by the Directorate of Defense Trade Controls ("DDTC") within the U.S. Department of State under the authority of the Arms Export Control Act ("AECA").

Unlike the EAR, which applies to many commercial products, the ITAR focuses on military and defense-related technologies identified on the United States Munitions List ("USML").

Because ITAR-controlled items are generally considered more sensitive than EAR-controlled items, they are subject to significantly stricter licensing, registration, and compliance requirements.

What Does ITAR Regulate?

Many companies mistakenly believe that ITAR applies only to weapons.

In reality, ITAR controls a much broader range of defense-related items and activities, including:

4o.png

Importantly, ITAR regulates much more than physical exports.

Providing controlled technical information to a foreign person may itself constitute an export, even if no product ever leaves the United States.

Technical Data and Defense Services

One of the most misunderstood aspects of ITAR concerns technical data.

Technical data generally includes information required for the design, manufacture, production, assembly, operation, repair, testing, maintenance, or modification of defense articles.

Examples include:

  • engineering drawings;
  • manufacturing specifications;
  • blueprints;
  • CAD files;
  • design documentation;
  • military source code;
  • testing procedures; and
  • classified technical information.

Similarly, ITAR regulates defense services, which may include furnishing technical assistance, training, engineering support, consulting services, or other assistance relating to defense articles.

Consequently, a U.S. engineer participating in a video conference with a foreign defense contractor may trigger ITAR obligations without shipping a single physical item.

Registration Is Not a License

Another common misconception is that DDTC registration authorizes exports.

It does not.

Many companies engaged in manufacturing or exporting defense articles are required to register with DDTC. However, registration merely identifies the company to the U.S. Government.

Registration does not authorize exports.

Separate DDTC authorization is generally required before exporting ITAR-controlled defense articles, furnishing defense services, or transferring controlled technical data unless an exemption applies.

This distinction is frequently misunderstood by businesses entering the defense sector for the first time.

One Transaction May Trigger OFAC, BIS, and ITAR Simultaneously

Perhaps the most important lesson for compliance professionals is that these three regulatory regimes frequently overlap.

Consider the following example.

A U.S. aerospace company intends to sell:

  • aircraft components;
  • commercial design software;
  • engineering support services; and
  • maintenance documentation

to a foreign defense contractor.

Several questions immediately arise.

 

OFAC

Is the customer located in a sanctioned jurisdiction?

Is the purchaser owned by a blocked person?

Will payment pass through a sanctioned financial institution?

Does an OFAC sanctions program prohibit the transaction?

BIS

Is the commercial software subject to the EAR?

Does it have an Export Control Classification Number (ECCN)?

Is the destination country subject to licensing requirements?

Does the customer appear on the Entity List?

Is the software intended for a prohibited military end use?

DDTC

Are the aircraft components listed on the U.S. Munitions List?

Does the engineering support constitute a defense service?

Will controlled technical data be transferred?

Is DDTC authorization required before any information is disclosed?

5o.png

 

Five Common Compliance Mistakes

Through our work with businesses engaged in international trade, several recurring compliance mistakes appear with surprising frequency.

1. Screening Only the SDN List

Many companies rely exclusively on sanctions-screening software.

Restricted-party screening is essential, but it does not replace export classification, licensing analysis, or ownership investigations.

2. Assuming EAR99 Means "Unrestricted"

EAR99 does not mean "export anywhere."

Destination, end user, and end use may independently trigger licensing requirements.

3. Ignoring Beneficial Ownership

Companies frequently screen only the immediate customer.

OFAC's 50 Percent Rule requires additional ownership analysis that automated screening alone may not capture.

4. Confusing the SDN List with the Entity List

These lists have different legal consequences.

An SDN designation generally blocks property and prohibits dealings by U.S. persons.

An Entity List designation generally imposes BIS licensing requirements rather than comprehensive blocking sanctions.

Treating them as interchangeable can produce significant compliance errors.

5. Believing One Government License Solves Everything

Perhaps the most dangerous assumption is that obtaining a license from one agency resolves all regulatory issues.

International transactions should instead be viewed as a series of independent legal analyses.

Each applicable regulatory framework should be evaluated separately.

 

Practical Compliance Checklist

Before completing an international transaction, businesses should consider the following questions.

6o.png

A structured review process significantly reduces compliance risk and demonstrates good-faith efforts should regulators later examine the transaction.

Key Takeaways

Although OFAC, BIS, and DDTC all regulate aspects of international trade, each addresses different legal questions.

  • OFAC focuses primarily on who U.S. persons may transact with and whether sanctions prohibit a particular transaction.
  • BIS regulates what may be exported, where it may be sent, who may receive it, and how it will be used.
  • DDTC regulates exports of defense articles, technical data, defense services, and related activities under the ITAR.

Understanding these distinctions is essential because international transactions increasingly involve overlapping regulatory obligations.

Businesses should resist the temptation to view sanctions screening as a complete compliance program. Effective trade compliance requires careful evaluation of the parties, the products, the destination, the end user, and the intended end use before a transaction proceeds.

Conclusion

As global supply chains become increasingly complex and U.S. trade controls continue to evolve, businesses face a regulatory environment in which a single transaction may simultaneously implicate sanctions laws, export controls, and defense trade regulations.

A successful compliance program therefore requires more than automated screening tools or product classifications. It demands a comprehensive, risk-based approach that considers every aspect of the transaction, including the parties involved, the items being transferred, the destination, the ultimate end user, and the intended use.

Early legal analysis can help identify licensing requirements, reduce enforcement risk, avoid costly delays, and protect valuable commercial relationships. Organizations engaged in international business should periodically review their trade compliance procedures to ensure they remain aligned with evolving regulatory requirements and enforcement priorities.

Select your language