SanctionsLookup

Data last synced:

MidFirst Bank OFAC Finding of Violation (2022)

Last updated:

MidFirst Bank received a Finding of Violation (FOV) from OFAC for violations of the Weapons of Mass Destruction Proliferators Sanctions Regulations. The violations related to MidFirst Bank's maintaining accounts for and processing of 34 payments on behalf of two individuals added to OFAC's List of Specially Designated Nationals and Blocked Persons for 14 days post-designation. OFAC determined that the appropriate administrative action in this matter was an FOV in lieu of a civil monetary penalty.

Penalty Amount

-

Enforcement Date

July 21, 2022

Rank in Top Penalties

-

Case Details

Type:
Entity
Name:
MidFirst Bank
Industry:
Banking
Egregious case:
Unknown
Voluntary self disclosure:
Unknown
Case:
Finding of Violation
Violation period:
September 21, 2020 to October 5, 2020
Program:
Weapons of Mass Destruction Proliferators Sanctions Regulations (WMDPSR)
Enforcement date:
July 21, 2022

Nature of the Apparent Violations

On September 21, 2020, at 12:36 p.m. EDT, OFAC designated and added two individuals to the SDN List ("the blocked persons") pursuant to the WMDPSR. Between 2:00 p.m. EDT and 5:48 p.m. EDT on the same day, MidFirst processed five transactions totaling $604,000 on behalf of accounts held by the blocked persons. Two of those transactions, totaling $400,000, were internal book transfers between one of the blocked person's accounts at MidFirst. Between September 22, 2020 and October 5, 2020, MidFirst processed 29 additional transactions totaling $9,879.02 on behalf of the blocked persons. Ninety-eight percent of the value of the post-designation transactions occurred within six hours of designation.

The violations stemmed from MidFirst's misunderstanding of its vendor's screening frequency. The agreement between MidFirst and its vendor provided for periodic screening of MidFirst's customers against the SDN List. Although the vendor conducted daily screenings of new customers and of existing customers with certain account changes (e.g., changes to a customer's name or address), the vendor only screened MidFirst's entire existing customer base once a month. MidFirst mistakenly believed that the daily screenings would screen its entire customer base against additions and changes to the SDN List. As a result, depending on the timing of additions to the SDN List in relation to the monthly screening, MidFirst could be unaware for up to 30 days that it was maintaining an account for a blocked person. MidFirst also maintained its own process to screen existing customers, but this process also screened on a monthly basis only.

MidFirst's vendor notified it that the blocked persons had been added to the SDN List on October 5, 2020, 14 days after designation, at which point MidFirst promptly blocked the accounts. MidFirst's maintaining of accounts for and processing of 34 transactions on behalf of the blocked persons was in violation of Β§ 544.201 of the WMDPSR.

How OFAC Determined the Penalty

OFAC determined that the appropriate administrative action in this matter was a Finding of Violation in lieu of a civil monetary penalty. The determination to issue a Finding of Violation to MidFirst reflects OFAC's consideration of all of the information provided and points made by MidFirst as it evaluated the conduct in accordance with the General Factors Affecting Administrative Action set forth in OFAC's Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A.

Aggravating Factors

  • MidFirst had reason to know that it maintained the accounts for the blocked persons, and that its vendor was re-screening MidFirst's existing accounts against changes to the SDN List on a monthly basis only.
  • By allowing the accounts to operate for two weeks post-designation, there was harm to the objectives of the sanctions program, and potential for significant harm as it could have aided asset flight.

Mitigating Factors

  • The violations occurred within two weeks of the designations, and the overwhelming majority (98 percent) of the value associated with the violations relates to transactions that took place within hours of designation.
  • The sanctions harm was substantially less than the face amount of the violations as two of the largest transactions were internal book transfers between a blocked person's accounts at MidFirst.
  • After discovering the violations, the vendor began re-screening existing accounts more frequently, and MidFirst implemented a manual process to be notified of all OFAC list updates and to manually rescreen the customer base whenever there are updates to the SDN List.
  • MidFirst cooperated with OFAC.
  • MidFirst has not received a Penalty Notice or FOV from OFAC in the five years preceding the first violation noted herein.

Compliance Takeaways

Financial institutions should take a risk-based approach when developing their sanctions compliance program, including with respect to screening accounts and transactions for potential violations of OFAC regulations. There is no "one-size-fits-all" approach to sanctions screening. Different financial institutions may have different risk tolerances and divergent approaches to sanctions compliance based on an institution's unique risk profile. Accordingly, the frequency with which financial institutions screen and review existing customers and accounts should be based on the financial institution's assessment of its unique sanctions risk. Consistent with that risk-based approach to sanctions compliance, this FOV demonstrates that understanding the scope and capabilities of outsourced sanctions compliance services is critical to ensuring that those services are aligned with the financial institution's expectations for managing its self-assessed sanctions risk.

Official Source Documents

This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.

Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.

Archived on June 13, 2026

SHA-256: caa08a41b352ba917e07b0ff8cd42cd864a64d62fbc954280524e3ed66d45973

More OFAC Cases