Data last synced:
Last updated:
SAP SE, a software company headquartered in Germany that provides enterprise application software, cloud-based services, and associated maintenance and support, settled its potential civil liability for 190 apparent violations of the Iranian Transactions and Sanctions Regulations, agreeing to pay $2,132,174. The apparent violations involved the export of software and related services from the United States to Iran β arising from SAP's exportation to companies in third countries with knowledge or reason to know the software or services were intended specifically for Iran, as well as from the sale of cloud-based software subscription services accessed remotely through SAP's cloud businesses in the United States to customers that made the services available to their employees in Iran.
Penalty Amount
$2,132,174.00
Enforcement Date
April 29, 2021
Rank in Top Penalties
#80
From approximately June 1, 2013 to January 1, 2018, SAP authorized 13 sales of SAP software licenses, 169 sales of related maintenance services and updates, and eight sales of cloud-based subscription services. SAP Partners in Turkey, the UAE, Germany, and Malaysia sold software licenses and maintenance services to "pass-through entities," companies in third countries, including companies controlled by Iranian companies, that provided the SAP software to users in Iran. The software was delivered from SAP servers in the United States and SAP's U.S.-headquartered content delivery provider. The sales of cloud-based subscription services were conducted by two of SAP's cloud business group (CBG) subsidiaries in the United States, with SAP's knowledge or reason to know the services would be provided specifically to Iran.
The apparent violations connected with sales by SAP Partners to pass-through entities were caused in part by shortcomings in SAP's compliance processes. Internal audits conducted in 2006, 2007, 2010, and 2014 found that SAP did not screen customers' IP addresses, resulting in SAP's inability to identify the country in which SAP software was downloaded. Despite recommendations as early as 2006 to implement geolocation IP address screening, and despite being aware that its U.S.-based content delivery provider had the capability years earlier, SAP failed to implement the recommended screening until 2015. Internal communications show that SAP product line and overseas subsidiary managers oversaw the sale of SAP software and services from the United States or U.S. persons to pass-through entities knowing they would provide the software and services to Iranian companies. In one instance, SAP personnel traveled to Iran to secure SAP software sales. SAP also failed to adequately investigate whistleblower allegations received between approximately July 2011 and March 2016 claiming SAP software had been sold to Iranian front companies registered in UAE, Turkey, and Malaysia.
Additional apparent violations occurred when SAP's CBG subsidiaries in the United States sold cloud-based software subscription services to customers that enabled access to employees or customers in Iran. Pre- and post-acquisition due diligence on the CBGs found that they generally lacked comprehensive export controls and sanctions compliance programs, and in some instances had no sanctions compliance measures at all. SAP permitted the CBGs to continue operations as standalone entities without fully integrating them into SAP's existing compliance measures, and the small U.S.-based Export Compliance Team tasked with coordinating compliance for the CBGs was not resourced or empowered to manage these processes appropriately. The total value of the transactions constituting the apparent violations is $3,693,898.
The statutory maximum civil monetary penalty applicable in this matter is $56,025,470. OFAC determined that SAP voluntarily self-disclosed the apparent violations and that the apparent violations constitute a non-egregious case. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines, the base civil monetary penalty amount applicable in this matter is $1,316,157. The settlement amount of $2,132,174 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines. SAP's obligation to pay the settlement amount due to OFAC shall be deemed satisfied by SAP's payment of a greater amount in satisfaction of penalties assessed by DOJ and BIS arising from the same course of conduct.
SAP was concurrently investigated by DOJ and BIS. DOJ entered into a non-prosecution agreement with SAP, and BIS entered into a settlement agreement with SAP, both arising from the same course of conduct. SAP's obligation to pay the OFAC settlement amount of $2,132,174 shall be deemed satisfied by SAP's payment of a greater amount in satisfaction of the penalties assessed by DOJ and BIS.
This enforcement action highlights for global companies providing software products online, including through cloud-based services, direct downloads, or other such means, the importance of implementing a risk-based sanctions compliance program commensurate with their size and sophistication and appropriate to their marketing and operational structures. Screening processes for such programs will generally include IP address identification and blocking capabilities and are especially important for companies that use sales models where engagement with the end-user is indirect. Such companies include those using third-party vendors or distributors for product delivery, or who deliver services to customers who might provide them to employees or other users. As in other industries, due diligence for software distributors, resellers, and agents is essential.
This enforcement action also emphasizes the importance of conducting sufficient pre- and post-acquisition due diligence to identify and promptly remediate compliance deficiencies in newly acquired subsidiaries. Compliance efforts in such circumstances should be sufficiently resourced and empowered to undertake thorough examinations of risks and to implement appropriate controls, including, if needed, any stopgap measures.
OFAC sanctions compliance programs should further maintain the support and commitment of senior-level managers to be effective. In circumstances where senior-level managers are made aware of potentially violative conduct or compliance deficiencies, it is incumbent on them to take expeditious action to seek and abide by appropriate guidance.
This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.
Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.
Archived on June 13, 2026
SHA-256: 0c42a23803b55fc23e91a39f05f16f41f323c3e40f21ecb5e8192c2f70d0f9e6