SanctionsLookup

Data last synced:

OFAC Red Flags: 19 Signs of Potential Violations

Four common OFAC red flags: sanctioned country, hidden ownership, evasive documents, unusual payments.

OFAC red flags are warning signs that may indicate potential violations of U.S. sanctions. These indicators help organizations identify suspicious activity, high-risk transactions, or possible dealings with sanctioned individuals and entities before a prohibited transaction occurs.

Below are 19 red flags for potential OFAC violations based on real enforcement cases, along with guidance on what to do when they appear.

Common OFAC red flags

Most violations in OFAC's enforcement record involve several of these flags at once, not one in isolation.

Customer and Counterparty Warning Signs

1. Name matches: Close or exact matches to the Specially Designated Nationals (SDN) List.

Enforcement example: CSE TransTel settled for $12M after making payments to SDN-listed Iranian companies.

2. List-change exposure: An existing customer or counterparty is added to a newly updated sanctions list.

Enforcement example: UniCredit Bank settled for $553M after continuing IRISL-linked payments for almost two years after IRISL was designated during the relationship.

3. Vague ownership details: Refusal or inability to provide beneficial ownership or control information.

Enforcement example: Clearstream Banking settled for $152M after the Central Bank of Iran’s beneficial ownership interest in U.S.-held securities was not made transparent.

4. Evasive answers: Inconsistent or vague explanations about the transaction or parties involved.

Enforcement example: Swedbank Latvia settled for $3.4M after a counterparty falsely assured it that transactions did not involve Crimea.

5. Linked crypto wallets: Transactions involving digital asset addresses linked to SDN List entries.

Enforcement example: Binance settled for $969M after matching virtual-currency trades between U.S. users and blocked persons.

Geographic and Jurisdiction Exposure

6. Sanctioned-region footprint: IP addresses, shipping details, billing addresses, or IDs linked to sanctioned jurisdictions.

Enforcement example: Payoneer settled for $1.4M for failing to screen IP and shipping addresses tied to sanctioned regions.

7. Evasion hubs: Transactions routed through jurisdictions commonly used to evade sanctions.

Enforcement example: SCG Plastics settled for $20M after disguising Iranian-origin goods through UAE transshipment.

8. Route detours: Shipping or payment routes that obscure the true origin or destination.

Enforcement example: Construction Specialties settled for $661K after falsifying or omitting the ultimate destination of goods bound for Iran.

Transaction and Payment Anomalies

9. High-risk routes: Payments routed through unrelated countries without a legitimate business reason.

Enforcement example: Toll Holdings settled for $6.1M after routing nearly 3,000 payments through U.S. banks for shipments tied to North Korea, Iran, and Syria.

10. Third-party payers: Payment from a party with no apparent connection to the transaction.

Enforcement example: Danfoss settled for $4.4M after using third-party payers that disguised the originators and beneficiaries of Iran-, Syria-, and Sudan-related transfers.

11. Unusual methods: Unexpected banking changes, large cash payments, or complex payment structures.

Enforcement example: British Arab Commercial Bank settled for $4M after using complex bulk-funding payment structures involving Sudanese banks.

12. Document mismatches: Inconsistencies between invoices, shipping documents, contracts, or bills of lading.

Enforcement example: Eagle Shipping settled for $1.1M after a counterparty substituted an alternate shipper name for SDN-listed Myawaddy on shipping documents.

13. Structured payments: Split or repetitive payments designed to avoid detection or review.

Enforcement example: BNP Paribas settled for $964M after structuring payments to omit or obscure sanctioned parties in USD messages.

Trade and Goods Red Flags

14. End-use doubts: Refusal or inability to identify the end user or final destination of goods.

Enforcement example: Aiotec settled for $14.6M after misrepresenting a Turkish company as the end user while exporting a plant to Iran.

15. Cargo mismatches: Goods inconsistent with the customer’s business or stated purpose.

Enforcement example: Adani Enterprises settled for $275M after ignoring red flags (vessel activity, documentation gaps, and below-market pricing) that showed Omani-labeled LPG was Iranian.

16. Letter-of-credit edits: Unjustified changes to beneficiaries, payment locations, or other key terms.

Enforcement example: UBAF settled for $8.6M after processing back-to-back letters of credit involving sanctioned Syrian beneficiaries.

Ownership and Sham Transactions

17. Opaque setups: Shell companies, offshore trusts, or nominee directors used to conceal beneficial ownership.

Enforcement example: FTI Consulting settled for $1.05M after an intermediary arrangement obscured a sanctioned client.

18. Recent transfers: Assets transferred to family members or associates after sanctions are imposed.

Enforcement example: Family International Realty settled for $1.1M after transferring sanctioned oligarchs’ property to family members and shell companies.

19. Unreasonable terms: Illogical commercial terms suggesting a blocked person retains a hidden interest.

Enforcement example: British American Tobacco settled for $509M after divestment terms let it reacquire a North Korea joint venture for one euro while keeping effective control.

What are OFAC red flags?

OFAC red flags are indicators of potential sanctions violations under U.S. laws administered by the Office of Foreign Assets Control. They signal heightened sanctions risk and may suggest exposure to blocked persons, restricted jurisdictions, or prohibited transactions.

These warning signs often overlap with anti-money laundering (AML) and export controls risks, particularly in cross-border trade and financial transactions. However, the presence of a red flag does not automatically mean a violation has occurred; it requires further review, due diligence, and, where appropriate, escalation.

Who is responsible for spotting OFAC red flags?

Responsibility for identifying OFAC red flags applies to all U.S. persons and entities subject to U.S. jurisdiction, not just banks. Any organization engaged in cross-border transactions, trade, payments, or financial services must assess sanctions risk and monitor for warning signs.

This includes financial institutions, exporters and importers, payment processors, fintech companies, and other businesses involved in international commerce. Within an organization, corporate compliance teams, senior management, and designated OFAC compliance officers are responsible for implementing controls, escalating concerns, and ensuring appropriate investigation and reporting.

What to do when a red flag is identified

When an OFAC red flag is detected, organizations should act promptly and follow a structured escalation process.

  • Pause or escalate the transaction for internal review
  • Conduct enhanced due diligence to clarify the risk
  • Screen relevant parties against OFAC sanctions lists; where policies allow, use an OFAC screening tool for browser-based triage before formal disposition
  • Assess potential exposure under the 50 Percent Rule
  • Consult internal compliance personnel or external legal counsel if needed
  • Block or reject the transaction where required by regulation
  • Report to OFAC within required timeframes if property or funds are blocked

Timely documentation and clear escalation procedures are essential to demonstrate good-faith compliance within a broader sanctions control framework.

Compliance and enforcement risk

OFAC enforcement operates under a strict liability standard, meaning civil penalties can apply even if a violation was unintentional. Organizations may face significant monetary penalties for processing prohibited transactions or failing to block reportable property.

In cases involving willful misconduct, criminal liability, including substantial fines and potential imprisonment, may apply. A well-designed, risk-based compliance program can significantly reduce enforcement exposure and serve as a mitigating factor in penalty determinations.

FAQ

Is processing a transaction involving a foreign country an OFAC red flag?

No. Simply processing a transaction involving a foreign country is not, by itself, an OFAC red flag. It becomes one combined with other indicators, such as a sanctioned jurisdiction, evasive documentation, or an unclear counterparty.