Data last synced:
Last updated:
Amazon.com, Inc., a company that provides retail, e-commerce, and digital services to millions of customers worldwide, settled its potential civil liability for apparent violations of multiple OFAC sanctions programs, agreeing to pay $134,523. As a result of deficiencies related to Amazon's sanctions screening processes, Amazon provided goods and services to persons sanctioned by OFAC; to persons located in the sanctioned region or countries of Crimea, Iran, and Syria; and to individuals located in or employed by the foreign missions of countries sanctioned by OFAC. Amazon also failed to timely report several hundred transactions conducted pursuant to a general license issued by OFAC that included a mandatory reporting requirement, thereby nullifying that authorization with respect to those transactions.
Penalty Amount
$134,523.00
Enforcement Date
July 8, 2020
Rank in Top Penalties
#218
From on or about November 15, 2011, to on or about October 18, 2018, persons located in Crimea, Iran, and Syria placed orders or otherwise conducted business on Amazon's websites for consumer and retail goods and services where the transaction details demonstrated that the goods or services would be provided to persons in those jurisdictions. Amazon also accepted and processed orders on its websites for persons located in or employed by the foreign missions of Cuba, Iran, North Korea, Sudan, and Syria.
Additionally, Amazon accepted and processed orders from persons listed on OFAC's List of Specially Designated Nationals and Blocked Persons (the "SDN List") who were blocked pursuant to the Narcotics Trafficking Sanctions Regulations, the Weapons of Mass Destruction Proliferators Sanctions Regulations, the Transnational Criminal Organizations Sanctions Regulations, the Democratic Republic of the Congo Sanctions Regulations, the Venezuela Sanctions Regulations, the Zimbabwe Sanctions Regulations, the Global Terrorism Sanctions Regulations, and the Foreign Narcotics Kingpin Sanctions Regulations. The apparent violations consisted primarily of transactions involving low-value retail goods and services, with a total transaction value of approximately $269,000.
These apparent violations occurred primarily because Amazon's automated sanctions screening processes failed to fully analyze all transaction and customer data relevant to compliance with OFAC's sanctions regulations. In some instances, orders specifically referenced a sanctioned jurisdiction, a city within a sanctioned jurisdiction, or a common alternative spelling of a sanctioned jurisdiction, yet Amazon's screening processes did not flag the transactions for review. For example, Amazon's screening processes did not flag orders with address fields containing an address in "Yalta, Krimea" for the term "Yalta," a city in Crimea, nor for the variation of the spelling of Crimea. Amazon also failed to interdict or otherwise flag orders shipped to the Embassy of Iran located in third countries. Moreover, in several hundred instances, Amazon's automated screening processes failed to flag the correctly spelled names and addresses of persons on OFAC's SDN List.
The conduct resulted in apparent violations of the Cuban Assets Control Regulations, 31 C.F.R. Part 515 (CACR); the Democratic Republic of the Congo Sanctions Regulations, 31 C.F.R. Part 547 (DRCSR); the Foreign Narcotics Kingpin Sanctions Regulations, 31 C.F.R. Part 598 (FNKSR); the Global Terrorism Sanctions Regulations, 31 C.F.R. Part 594 (GTSR); the Iranian Transactions and Sanctions Regulations, 31 C.F.R. Part 560 (ITSR); the Narcotics Trafficking Sanctions Regulations, 31 C.F.R. Part 536 (NTSR); the North Korea Sanctions Regulations, 31 C.F.R. Part 510 (NKSR); the Syrian Sanctions Regulations, 31 C.F.R. Part 542 (SySR); the Sudanese Sanctions Regulations, 31 C.F.R. Part 538 (SSR); the Transnational Criminal Organizations Sanctions Regulations, 31 C.F.R. Part 590 (TCOSR); Executive Order 13685 of December 19, 2014; the Venezuela Sanctions Regulations, 31 C.F.R. Part 591 (VSR); the Weapons of Mass Destruction Proliferators Sanctions Regulations, 31 C.F.R. Part 539 (WMDPSR); and the Zimbabwe Sanctions Regulations, 31 C.F.R. Part 541 (ZSR).
Amazon also disclosed to OFAC that it failed to timely report 362 transactions involving Crimea conducted pursuant to General License No. 5 (GL 5), which authorized certain transactions prohibited by E.O. 13685 through February 1, 2015, subject to a requirement that transactions be reported within 10 days after wind-down activities concluded. Amazon had previously reported 245 such transactions on February 13, 2015 within the required period, but did not report the additional 362 transactions until well after the deadline had expired. As a result, the authorization in GL 5 is nullified with respect to those 362 transactions.
The statutory maximum civil monetary penalty amount for the apparent violations was $1,038,206,212. OFAC determined that Amazon voluntarily self-disclosed the apparent violations and that the apparent violations constitute a non-egregious case. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines, 31 C.F.R. Part 501, app. A., the base civil monetary penalty amount equals the sum of one-half of the transaction value for each apparent violation, which in this case is $134,523. The settlement amount of $134,523 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines.
This case demonstrates the importance of implementing and maintaining effective, risk-based sanctions compliance controls, including sanctions screening measures appropriate for e-commerce and other internet-based businesses that operate on a global scale. Such large and sophisticated businesses should implement and employ compliance tools and programs that are commensurate with the speed and scale of their business operations. In particular, global companies that rely heavily on automated sanctions screening processes should take reasonable, risk-based steps to ensure that their processes are appropriately configured to screen relevant customer information and to capture data quality issues, such as common misspellings. Routine testing of these processes to ensure effectiveness and identify deficiencies may also be appropriate. Moreover, companies that learn of a weakness in their internal compliance controls may benefit by taking immediate and effective action, to the extent possible, to identify and implement compensating controls until the root cause of the weakness can be determined and remediated.
This case also demonstrates the importance of compliance with all aspects of the terms of OFAC's general licenses, including the timely fulfillment of any reporting obligations pursuant to those licenses.
This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.
Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.
Archived on June 13, 2026
SHA-256: e729720e4d30eea9d74f516059ec6e657dd51088856592cea78c90224296f97c