SanctionsLookup

Data last synced:

Microsoft Corporation OFAC Settlement: $2.98M (2023)

Last updated:

Microsoft Corporation, on behalf of itself and its subsidiaries Microsoft Ireland Operations Ltd. and Microsoft Rus LLC, settled with OFAC for $2,980,265.86 for apparent violations of the Cuban Assets Control Regulations, the Iranian Transactions and Sanctions Regulations, the Syrian Sanctions Regulations, and the Ukraine-/Russia-Related Sanctions Regulations, arising from the exportation of services or software from the United States to comprehensively sanctioned jurisdictions and to Specially Designated Nationals or blocked persons.

Penalty Amount

$2,980,265.86

Enforcement Date

April 6, 2023

Rank in Top Penalties

#71

Case Details

Type:
Entity
Name:
Microsoft Corporation
Country:
🇺🇸 United States
Industry:
Software
Address:
Redmond, Washington
Penalty amount:
$2,980,265.86
Base civil monetary penalty:
$5,960,531.72
Max civil monetary penalty:
$404,646,121.89
Egregious case:
No
Apparent violations:
1339
Voluntary self disclosure:
Yes
Case:
Settlement
Violation period:
July 2012 to April 2019
Program:
Cuban Assets Control Regulations, 31 C.F.R. part 515 ("CACR")Iranian Transactions and Sanctions Regulations, 31 C.F.R. part 560 ("ITSR")Syrian Sanctions Regulations, 31 C.F.R. part 542 ("SySR")Ukraine-/Russia Related Sanctions Regulations, 31 C.F.R. part 589 ("URSR")
Enforcement date:
April 6, 2023

Nature of the Apparent Violations

Between July 2012 and April 2019, the Microsoft Entities engaged in 1,339 apparent violations of multiple OFAC sanctions programs when they sold software licenses, activated software licenses, and/or provided related services from servers and systems located in the United States and Ireland to SDNs, blocked persons, and other end users located in Cuba, Iran, Syria, Russia, and the Crimea region of Ukraine. The total value of these sales and related services was $12,105,189.79.

The apparent violations occurred in the context of Microsoft's volume licensing sales and incentive programs, under which the Microsoft Entities engaged with third-party distributors and resellers to sell Microsoft software products. In Russia, the Microsoft Entities employed an indirect resale model through third-party Licensing Solution Partners ("LSPs"). Under this model, Microsoft Russia worked with LSPs to develop sales leads and negotiate bulk sales agreements with end customers, while the LSP and the end customer would negotiate the final sales price and sign a commercial supply agreement. Microsoft Ireland would bill the LSPs annually for licenses it supplied, and the LSPs would separately bill and collect payment from end customers. The process of facilitating Microsoft software downloads, license activations, product key verifications, and subsequent usages relied, at least in part, on U.S.-based servers and systems managed by personnel in the United States or third countries.

The causes of the apparent violations included the lack of complete or accurate information on the identities of end customers. In certain volume-licensing programs involving sales by intermediaries, Microsoft was not provided, nor did it otherwise obtain, complete or accurate information on the ultimate end customers from its distributors and resellers. At times, Microsoft Russia employees appear even to have intentionally circumvented Microsoft's screening controls to prevent other Microsoft affiliates from knowing the identity of the ultimate end customers. For example, following OFAC's 2014 designation of Stroygazmontazh, a Russian company operating in the oil and gas industry, and Microsoft's initial rejection of one of this entity's subsidiaries as a potential customer upon screening, certain Microsoft Russia employees successfully used a pseudonym for that subsidiary to arrange orders on behalf of the SDN.

Screening architecture failures further contributed: Microsoft's restricted-party screening did not aggregate information known to Microsoft, such as an address, name, and tax-identification number, across its databases to identify SDNs or blocked persons. Microsoft also failed to timely screen and evaluate pre-existing customers following changes to OFAC's SDN List and implement timely corrective measures to avoid continued dealings with SDNs or blocked persons. Additionally, Microsoft's screening did not identify blocked parties owned 50 percent or more by SDNs, or SDNs' Cyrillic or Chinese names, even though many customers in Russia and China supplied order and customer information in their native scripts.

In total, the Microsoft Entities appear to have engaged in 54 apparent violations of § 515.201(b)(2) of the Cuban Assets Control Regulations, 31 C.F.R. part 515 ("CACR"); 30 apparent violations of § 560.204 and § 560.206(a)(2) of the Iranian Transactions and Sanctions Regulations, 31 C.F.R. part 560 ("ITSR"); 3 apparent violations of § 542.207 of the Syrian Sanctions Regulations, 31 C.F.R. part 542 ("SySR"); and 1,252 apparent violations of § 589.207 of the Ukraine-/Russia Related Sanctions Regulations, 31 C.F.R. part 589 ("URSR").

How OFAC Determined the Penalty

The statutory maximum civil monetary penalty applicable in this matter is $404,646,121.89. OFAC determined that Microsoft voluntarily self-disclosed the Apparent Violations, and that the Apparent Violations constitute a non-egregious case. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines ("Enforcement Guidelines"), 31 C.F.R. part 501, app. A, the base civil monetary penalty amount applicable in this matter is $5,960,531.72, equaling one-half the transactional value for each of the Apparent Violations. The settlement amount of $2,980,265.86 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines.

Aggravating Factors

  • The Microsoft Entities demonstrated a reckless disregard for U.S. sanctions by failing to identify that over a seven-year period, more than $12,000,000 worth of software and services were exported from the United States through Microsoft systems and servers to SDNs, blocked persons, and to multiple sanctioned jurisdictions. The Apparent Violations were not isolated or atypical in nature, and the Microsoft Entities had reason to know that such conduct was occurring.
  • The Microsoft Entities harmed U.S. foreign policy objectives by providing U.S. software and related services that facilitated the operations of, or otherwise benefited, more than 100 SDNs or blocked persons, including major Russian enterprises that generated substantial revenues for the Russian state.
  • Microsoft is a world-leading technology company operating globally with substantial experience and expertise in software and related services sales and transactions.

Mitigating Factors

  • Evidence in the record did not show that persons in Microsoft's U.S. offices or management were aware of the apparently violative activity at the time. Microsoft's Apparent Violations came to light in the course of a self-initiated lookback, after which it conducted a comprehensive investigation to discover the causes and extent of the conduct leading to the Apparent Violations. Among other efforts, Microsoft conducted a retrospective review of thousands of past transactions, engaged in extensive ownership research and data analysis, engaged a team of more than 20 Russian-speaking attorneys to analyze relevant correspondence, and conducted numerous interviews.
  • Microsoft voluntarily self-disclosed the Apparent Violations to OFAC and cooperated with OFAC's investigation, including by proactively providing voluminous, detailed information and engaging responsively with OFAC.
  • Microsoft terminated the accounts of the SDNs or blocked persons at issue, and deactivated the license keys so that the prohibited parties cannot activate Microsoft's software programs. Further, Microsoft updated its "suspension and shutdown" procedures to disable access to its products and services when a sanctioned party is discovered.
  • Upon discovering the Apparent Violations, Microsoft undertook significant remedial measures and enhanced its sanctions compliance program through substantial investment and structural changes, including: enhancing Microsoft's trade compliance program; improving the governance structure of its sanctions compliance program and increasing its resources, including enhancements to its screening resources, technology, and methodology; prior to its suspension of new sales in Russia in March 2022, requiring that Russian service contracts be cleared by Microsoft's High Risk Deal Desk, which provided additional compliance oversight including pre-contract review of the ultimate end customer, deal structure, and any existing trade or sanctions restrictions; implementing an "end-to-end" screening system that gathers data when an outside party makes its first contact with the company and screens on a persistent rather than transactional basis; improving restricted-party screening methods and expanding the scope and volume of data screened, including deploying a multi-disciplinary internal investigative team fluent or proficient in 16 foreign languages including Russian, Chinese, Farsi, and Arabic; deploying detailed sanctions compliance training for certain employees and jurisdictions; adopting a new "Three Lines of Defense" model to govern its trade compliance program emphasizing management oversight and compliance monitoring; and terminating or otherwise disciplining the Microsoft Russia employees engaged in the activity.

As part of a joint administrative enforcement effort, the Bureau of Industry and Security ("BIS"), U.S. Department of Commerce, settled with Microsoft for $624,013 for related violations of the Export Administration Regulations. In light of OFAC's settlement, BIS credited Microsoft $276,382 against its settlement figure, contingent upon Microsoft fulfilling its commitments under its settlement agreement with OFAC.

Compliance Takeaways

Companies with sophisticated technology operations and a global customer base should ensure that their sanctions compliance controls remain commensurate with that risk and leverage appropriate technological compliance solutions. Such companies should also consider conducting a holistic risk assessment to identify and remediate instances where the company may, directly or indirectly, engage with OFAC-prohibited persons, parties, countries, or regions. Such an assessment is particularly important for companies operating in or exposed to high-risk jurisdictions.

This action also highlights the importance of companies conducting business through foreign-based subsidiaries, distributors, and resellers having sufficient visibility into end users with which they may have an ongoing relationship, including through the provision of services after an initial sale, to avoid engaging in business dealings with prohibited parties. Because OFAC's SDN List is dynamic, when changes to OFAC's SDN List are implemented, companies should evaluate their pre-existing trade relationships to avoid dealings with prohibited parties.

This action further emphasizes the importance of ensuring a company's employees, including employees located in foreign jurisdictions, adhere to the company's sanctions compliance program. By engaging in periodic auditing, a company may promptly identify instances where employees have attempted to circumvent internal policies and procedures. Testing or auditing, whether conducted on a specific element of a compliance program or at the enterprise-wide level, are important tools to ensure the program is working as designed and weaknesses are promptly remediated.

Lastly, this action underscores the persistent efforts of actors in the Russian Federation to evade U.S. sanctions. Sanctioned Russian enterprises may use a variety of means, including obscuring the identity of actual end users, to circumvent U.S. restrictions. All persons continuing to engage in business with Russia should be aware of such evasion techniques and associated red flags, such as those described in the Treasury-Commerce-Justice March 2023 Alert, "Cracking Down on Third-Party Intermediaries Used to Evade Russia-Related Sanctions and Export Controls" and FinCEN's March 2022 Alert, "FinCEN Advises Increased Vigilance for Potential Russian Sanctions Evasion Attempts."

Official Source Documents

This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.

Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.

Archived on June 13, 2026

SHA-256: a2afb89d99313146e2430af35d81238f9377ff934be16986ef53805f6a96f91e

More OFAC Cases