Data last synced:
Last updated:
MidFirst Bank received a Finding of Violation (FOV) from OFAC for violations of the Weapons of Mass Destruction Proliferators Sanctions Regulations. The violations related to MidFirst Bank's maintaining accounts for and processing of 34 payments on behalf of two individuals added to OFAC's List of Specially Designated Nationals and Blocked Persons for 14 days post-designation. OFAC determined that the appropriate administrative action in this matter was an FOV in lieu of a civil monetary penalty.
Penalty Amount
-
Enforcement Date
July 21, 2022
Rank in Top Penalties
-
On September 21, 2020, at 12:36 p.m. EDT, OFAC designated and added two individuals to the SDN List ("the blocked persons") pursuant to the WMDPSR. Between 2:00 p.m. EDT and 5:48 p.m. EDT on the same day, MidFirst processed five transactions totaling $604,000 on behalf of accounts held by the blocked persons. Two of those transactions, totaling $400,000, were internal book transfers between one of the blocked person's accounts at MidFirst. Between September 22, 2020 and October 5, 2020, MidFirst processed 29 additional transactions totaling $9,879.02 on behalf of the blocked persons. Ninety-eight percent of the value of the post-designation transactions occurred within six hours of designation.
The violations stemmed from MidFirst's misunderstanding of its vendor's screening frequency. The agreement between MidFirst and its vendor provided for periodic screening of MidFirst's customers against the SDN List. Although the vendor conducted daily screenings of new customers and of existing customers with certain account changes (e.g., changes to a customer's name or address), the vendor only screened MidFirst's entire existing customer base once a month. MidFirst mistakenly believed that the daily screenings would screen its entire customer base against additions and changes to the SDN List. As a result, depending on the timing of additions to the SDN List in relation to the monthly screening, MidFirst could be unaware for up to 30 days that it was maintaining an account for a blocked person. MidFirst also maintained its own process to screen existing customers, but this process also screened on a monthly basis only.
MidFirst's vendor notified it that the blocked persons had been added to the SDN List on October 5, 2020, 14 days after designation, at which point MidFirst promptly blocked the accounts. MidFirst's maintaining of accounts for and processing of 34 transactions on behalf of the blocked persons was in violation of Β§ 544.201 of the WMDPSR.
OFAC determined that the appropriate administrative action in this matter was a Finding of Violation in lieu of a civil monetary penalty. The determination to issue a Finding of Violation to MidFirst reflects OFAC's consideration of all of the information provided and points made by MidFirst as it evaluated the conduct in accordance with the General Factors Affecting Administrative Action set forth in OFAC's Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A.
Financial institutions should take a risk-based approach when developing their sanctions compliance program, including with respect to screening accounts and transactions for potential violations of OFAC regulations. There is no "one-size-fits-all" approach to sanctions screening. Different financial institutions may have different risk tolerances and divergent approaches to sanctions compliance based on an institution's unique risk profile. Accordingly, the frequency with which financial institutions screen and review existing customers and accounts should be based on the financial institution's assessment of its unique sanctions risk. Consistent with that risk-based approach to sanctions compliance, this FOV demonstrates that understanding the scope and capabilities of outsourced sanctions compliance services is critical to ensuring that those services are aligned with the financial institution's expectations for managing its self-assessed sanctions risk.
This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.
Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.
Archived on June 13, 2026
SHA-256: caa08a41b352ba917e07b0ff8cd42cd864a64d62fbc954280524e3ed66d45973