SanctionsLookup

Data last synced:

SAP SE OFAC Settlement: $2.1M (2021)

Last updated:

SAP SE, a software company headquartered in Germany that provides enterprise application software, cloud-based services, and associated maintenance and support, settled its potential civil liability for 190 apparent violations of the Iranian Transactions and Sanctions Regulations, agreeing to pay $2,132,174. The apparent violations involved the export of software and related services from the United States to Iran β€” arising from SAP's exportation to companies in third countries with knowledge or reason to know the software or services were intended specifically for Iran, as well as from the sale of cloud-based software subscription services accessed remotely through SAP's cloud businesses in the United States to customers that made the services available to their employees in Iran.

Penalty Amount

$2,132,174.00

Enforcement Date

April 29, 2021

Rank in Top Penalties

#80

Case Details

Type:
Entity
Name:
SAP SE
Country:
πŸ‡©πŸ‡ͺ Germany
Industry:
Software
Address:
Walldorf, Germany
Penalty amount:
$2,132,174.00
Base civil monetary penalty:
$1,316,157.00
Max civil monetary penalty:
$56,025,470.00
Egregious case:
No
Apparent violations:
190
Voluntary self disclosure:
Yes
Case:
Settlement
Violation period:
June 1, 2013 to January 1, 2018
Program:
Iranian Transactions and Sanctions Regulations, 31 C.F.R. part 560 (ITSR)
Enforcement date:
April 29, 2021

Nature of the Apparent Violations

From approximately June 1, 2013 to January 1, 2018, SAP authorized 13 sales of SAP software licenses, 169 sales of related maintenance services and updates, and eight sales of cloud-based subscription services. SAP Partners in Turkey, the UAE, Germany, and Malaysia sold software licenses and maintenance services to "pass-through entities," companies in third countries, including companies controlled by Iranian companies, that provided the SAP software to users in Iran. The software was delivered from SAP servers in the United States and SAP's U.S.-headquartered content delivery provider. The sales of cloud-based subscription services were conducted by two of SAP's cloud business group (CBG) subsidiaries in the United States, with SAP's knowledge or reason to know the services would be provided specifically to Iran.

The apparent violations connected with sales by SAP Partners to pass-through entities were caused in part by shortcomings in SAP's compliance processes. Internal audits conducted in 2006, 2007, 2010, and 2014 found that SAP did not screen customers' IP addresses, resulting in SAP's inability to identify the country in which SAP software was downloaded. Despite recommendations as early as 2006 to implement geolocation IP address screening, and despite being aware that its U.S.-based content delivery provider had the capability years earlier, SAP failed to implement the recommended screening until 2015. Internal communications show that SAP product line and overseas subsidiary managers oversaw the sale of SAP software and services from the United States or U.S. persons to pass-through entities knowing they would provide the software and services to Iranian companies. In one instance, SAP personnel traveled to Iran to secure SAP software sales. SAP also failed to adequately investigate whistleblower allegations received between approximately July 2011 and March 2016 claiming SAP software had been sold to Iranian front companies registered in UAE, Turkey, and Malaysia.

Additional apparent violations occurred when SAP's CBG subsidiaries in the United States sold cloud-based software subscription services to customers that enabled access to employees or customers in Iran. Pre- and post-acquisition due diligence on the CBGs found that they generally lacked comprehensive export controls and sanctions compliance programs, and in some instances had no sanctions compliance measures at all. SAP permitted the CBGs to continue operations as standalone entities without fully integrating them into SAP's existing compliance measures, and the small U.S.-based Export Compliance Team tasked with coordinating compliance for the CBGs was not resourced or empowered to manage these processes appropriately. The total value of the transactions constituting the apparent violations is $3,693,898.

How OFAC Determined the Penalty

The statutory maximum civil monetary penalty applicable in this matter is $56,025,470. OFAC determined that SAP voluntarily self-disclosed the apparent violations and that the apparent violations constitute a non-egregious case. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines, the base civil monetary penalty amount applicable in this matter is $1,316,157. The settlement amount of $2,132,174 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines. SAP's obligation to pay the settlement amount due to OFAC shall be deemed satisfied by SAP's payment of a greater amount in satisfaction of penalties assessed by DOJ and BIS arising from the same course of conduct.

Aggravating Factors

  • SAP demonstrated reckless disregard and failed to exercise a minimal degree of caution or care for U.S. economic sanctions by failing to act upon the findings of multiple internal audits conducted over a period of at least eight years highlighting sanctions risks, as well as warnings from its compliance personnel indicating compliance program deficiencies that could lead to violations of U.S. economic sanctions regulations. SAP also ignored other warning signs, including whistleblower claims alleging sales of SAP software from the United States to Iran. It further permitted its U.S.-based CBGs to operate as standalone entities despite pre- and post-acquisition due diligence and reports from its U.S.-based Export Compliance Team notifying SAP headquarters of significant compliance deficiencies.
  • SAP also acted recklessly by having a compliance program that was not commensurate to SAP's size and sophistication and that did not: 1) implement adequate controls in a timely manner (e.g., instituting geo-location IP address screening for SAP software delivered from the United States); 2) conduct an adequate degree of due diligence on SAP Partners; and 3) implement robust controls or compliance requirements for SAP Partner sales and SAP CBGs.
  • SAP had direct knowledge or reason to know that SAP software and cloud services were being sold or used by entities and end-users in Iran and were supported from the United States. In some cases, SAP managers and other personnel had direct knowledge and facilitated the purchases of SAP software by third-country entities that enabled the use of SAP products in Iran. SAP had reason to know, from IP address data, that SAP software, updates, and services were being downloaded from the United States by end-users located in Iran. In addition, information posted on SAP Partners' websites publicized business ties with Iranian companies.
  • SAP's exportation from the United States of business enterprise software and services to Iran caused harm to U.S. sanctions program objectives and undermined U.S. policy objectives by providing economic benefit to Iran, including the provision of leading business enterprise software in the amount of $3.9 million to be used by Iranian businesses.
  • SAP is a sophisticated software company with significant international operations and has numerous foreign subsidiaries.

Mitigating Factors

  • SAP has no prior OFAC sanctions history, including no penalty notice or Finding of Violation in the five years preceding the earliest date of the transactions giving rise to the apparent violations.
  • SAP substantially cooperated with OFAC's investigation, including arranging interviews with SAP employees.
  • SAP took significant remedial actions, including: terminating all users associated with the third-country entities that provided software and services to Iran, and Iranian cloud services; terminating SAP Partners engaged in sales to Iranian companies; blocking all downloads of software, support, and maintenance from Iran and other embargoed countries; implementing a risk-based export control framework for SAP Partners that requires a stringent review of proposed sales by a third-party auditor; developing and implementing an improved compliance program, including geolocation IP screening; hiring more than six new employees responsible for export control and trade sanctions compliance; and terminating five employees found to have knowingly engaged in the sale of SAP products to Iran or failed to adhere to SAP internal policy prohibiting sales to embargoed countries.

SAP was concurrently investigated by DOJ and BIS. DOJ entered into a non-prosecution agreement with SAP, and BIS entered into a settlement agreement with SAP, both arising from the same course of conduct. SAP's obligation to pay the OFAC settlement amount of $2,132,174 shall be deemed satisfied by SAP's payment of a greater amount in satisfaction of the penalties assessed by DOJ and BIS.

Compliance Takeaways

This enforcement action highlights for global companies providing software products online, including through cloud-based services, direct downloads, or other such means, the importance of implementing a risk-based sanctions compliance program commensurate with their size and sophistication and appropriate to their marketing and operational structures. Screening processes for such programs will generally include IP address identification and blocking capabilities and are especially important for companies that use sales models where engagement with the end-user is indirect. Such companies include those using third-party vendors or distributors for product delivery, or who deliver services to customers who might provide them to employees or other users. As in other industries, due diligence for software distributors, resellers, and agents is essential.

This enforcement action also emphasizes the importance of conducting sufficient pre- and post-acquisition due diligence to identify and promptly remediate compliance deficiencies in newly acquired subsidiaries. Compliance efforts in such circumstances should be sufficiently resourced and empowered to undertake thorough examinations of risks and to implement appropriate controls, including, if needed, any stopgap measures.

OFAC sanctions compliance programs should further maintain the support and commitment of senior-level managers to be effective. In circumstances where senior-level managers are made aware of potentially violative conduct or compliance deficiencies, it is incumbent on them to take expeditious action to seek and abide by appropriate guidance.

Official Source Documents

This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.

Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.

Archived on June 13, 2026

SHA-256: 0c42a23803b55fc23e91a39f05f16f41f323c3e40f21ecb5e8192c2f70d0f9e6

More OFAC Cases