SanctionsLookup

Data last synced:

Payoneer Inc. OFAC Settlement: $1.4M (2021)

Last updated:

Payoneer Inc., a publicly traded online money transmitter and provider of prepaid access, settled its potential civil liability for 2,220 apparent violations of multiple sanctions programs for $1,385,901.40. Payoneer processed 2,201 payments for parties located in jurisdictions and regions subject to sanctions—including the Crimea region of Ukraine, Iran, Sudan, and Syria—and 19 payments on behalf of sanctioned persons on OFAC's List of Specially Designated Nationals and Blocked Persons.

Penalty Amount

$1,385,901.40

Enforcement Date

July 23, 2021

Rank in Top Penalties

#94

Case Details

Type:
Entity
Name:
Payoneer Inc.
Country:
🇺🇸 United States
Industry:
Payments
Address:
New York
Penalty amount:
$1,385,901.40
Base civil monetary penalty:
$3,849,726.00
Max civil monetary penalty:
$654,357,316.00
Egregious case:
No
Apparent violations:
2220
Voluntary self disclosure:
Partial
Case:
Settlement
Violation period:
February 4, 2013 to February 20, 2018
Program:
Section 1(a)(iii) and Section 2 of Executive Order 13685 of December 19, 2014, "Blocking Property of Certain Persons and Prohibiting Certain Transactions with Respect to the Crimea Region of Ukraine"Zimbabwe Sanctions Regulations, 31 C.F.R. § 541.201Weapons of Mass Destruction Proliferators Sanctions Regulations, 31 C.F.R. § 544.201Iranian Transactions and Sanctions Regulations, 31 C.F.R. § 560.204Sudanese Sanctions Regulations (SSR), 31 C.F.R. § 538.205Syrian Sanctions Regulations, 31 C.F.R. § 542.207
Enforcement date:
July 23, 2021

Nature of the Apparent Violations

Between February 4, 2013 and February 20, 2018, Payoneer processed 2,220 transactions totaling $793,950.70 in apparent violation of multiple OFAC-administered sanctions programs. Of these, 2,201 were payments for parties located in jurisdictions and regions subject to sanctions, including the Crimea region of Ukraine, Iran, Sudan, and Syria; 19 were payments on behalf of sanctioned persons on OFAC's SDN List.

The apparent violations, which related to commercial transactions processed by Payoneer on behalf of its corporate customers and card-issuing financial institutions, resulted from multiple sanctions compliance control breakdowns: (i) weak algorithms that allowed close matches to SDN List entries not to be flagged by its filter; (ii) failure to screen for Business Identifier Codes (BICs) even when SDN List entries contained them; (iii) during backlog periods, allowing flagged and pended payments to be automatically released without review; and (iv) lack of focus on sanctioned locations, especially Crimea, because it was not monitoring IP addresses or flagging addresses in sanctioned locations.

Payoneer's policies and procedures dating back as far as June 2015 specified that transactions involving parties in sanctioned locations were prohibited, but the testing and auditing conducted to verify that these policies and procedures were being implemented failed to identify the compliance deficiencies that led to the apparent violations.

These compliance deficiencies resulted in apparent violations of Section 1(a)(iii) and Section 2 of Executive Order 13685 of December 19, 2014; the Zimbabwe Sanctions Regulations, 31 C.F.R. § 541.201; the Weapons of Mass Destruction Proliferators Sanctions Regulations, 31 C.F.R. § 544.201; the Iranian Transactions and Sanctions Regulations, 31 C.F.R. § 560.204; the now-repealed Sudanese Sanctions Regulations, 31 C.F.R. § 538.205; and the Syrian Sanctions Regulations, 31 C.F.R. § 542.207.

How OFAC Determined the Penalty

The statutory maximum civil monetary penalty applicable in this matter is $654,357,316. OFAC determined that 2,201 of the apparent violations were not voluntarily self-disclosed, 19 were voluntarily self-disclosed, and all were non-egregious. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines, the base civil monetary penalty amount applicable in this matter is $3,849,726. The settlement amount of $1,385,901.40 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines.

Aggravating Factors

  • Payoneer failed to exercise a minimal degree of caution or care for its sanctions compliance obligations when it allowed persons on the SDN List and persons in sanctioned locations to open accounts and transact as a result of deficient sanctions compliance processes that persisted for a number of years.
  • Payoneer had reason to know the location of the users it subsequently identified as located in jurisdictions and regions subject to sanctions based on common indicators of location within its possession, including billing, shipping, or IP addresses, or copies of identification issued in jurisdictions and regions subject to sanctions.
  • The Apparent Violations caused harm to six different sanctions programs.

Mitigating Factors

  • Upon discovering potential sanctions compliance issues, senior management acted quickly to self-disclose the Apparent Violations related to blocked persons and provided substantial cooperation throughout the investigation.
  • Payoneer has not received a penalty notice or Finding of Violation from OFAC in the five years preceding the date of the earliest transaction giving rise to the Apparent Violations.
  • Payoneer has represented that it has terminated the conduct that led to the Apparent Violations and undertook the following remedial measures intended to minimize the risk of recurrence of similar conduct in the future: replacing its Chief Compliance Officer, retraining all compliance employees, and hiring new compliance positions focused specifically on testing; enhancing its screening software to include financial institution alias names and BIC codes and automatically triggering a manual review of payments or accounts that match persons on the SDN List; enabling the screening of names, shipping and billing addresses, and IP information associated with account holders to identify jurisdictions and regions subject to sanctions; pending transactions flagged by its filter instead of allowing them to complete during a backlog; and implementing a daily review of identification documents uploaded to Payoneer, and a rule engine that stops payments with identification indicating jurisdictions and regions subject to sanctions.
  • As part of its agreement with OFAC, Payoneer has undertaken to continue its implementation of these and other compliance commitments.

Compliance Takeaways

This action highlights that money services businesses, like all financial service providers, are responsible for ensuring that they do not engage in unauthorized transactions prohibited by OFAC sanctions, such as dealings with blocked persons or property, or engaging in prohibited trade-related transactions with jurisdictions and regions subject to sanctions. To mitigate such risks, money services businesses should develop a tailored, risk-based sanctions compliance program predicated on at least five essential components: (1) management commitment; (2) risk assessment; (3) internal controls; (4) testing and auditing; and (5) training.

This enforcement action emphasizes the importance of effective screening not only for persons on the SDN List but also for sanctioned locations; ensuring that audits of OFAC compliance programs focus not only on persons on the SDN List but also on sanctioned locations; performing algorithm testing to be sure filters are flagging payments within expected parameters; screening for BIC codes, especially when OFAC includes them in SDN List entries; and holding flagged payments until they have been reviewed.

Official Source Documents

This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.

Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.

Archived on June 13, 2026

SHA-256: 39d5d788c734dbe51824bbc07625c634f4186caa1cd2ec50368af32b1bb8a56d

More OFAC Cases