SanctionsLookup

Data last synced:

Swedbank Latvia AS OFAC Settlement: $3.4M (2023)

Last updated:

Swedbank Latvia AS, a subsidiary of Swedbank AB (publ), settled with OFAC for $3,430,900 to resolve 386 apparent violations of OFAC sanctions on Crimea. Throughout 2015 and 2016, a customer of Swedbank Latvia used Swedbank Latvia's e-banking platform from an internet protocol ("IP") address in Crimea to send payments to persons in Crimea through U.S. correspondent banks. OFAC determined that Swedbank Latvia's conduct was non-egregious and not voluntarily self-disclosed.

Penalty Amount

$3,430,900.00

Enforcement Date

June 20, 2023

Rank in Top Penalties

#67

Case Details

Type:
Entity
Name:
Swedbank Latvia AS
Country:
🇱🇻 Latvia
Industry:
Banking
Address:
Riga, Latvia
Penalty amount:
$3,430,900.00
Base civil monetary penalty:
$6,238,000.00
Max civil monetary penalty:
$112,322,552.00
Egregious case:
No
Apparent violations:
386
Voluntary self disclosure:
No
Case:
Settlement
Violation period:
February 5, 2015 to October 14, 2016
Program:
Executive Order 13685 of December 19, 2014, "Blocking Property of Certain Persons and Prohibiting Certain Transactions with Respect to the Crimea Region of Ukraine" ("E.O. 13685")
Enforcement date:
June 20, 2023

Nature of the Apparent Violations

Prior to Russia's 2014 invasion of the Crimea region of Ukraine, Swedbank Latvia had onboarded a shipping industry client in Crimea (the "Client" or "SPC Owner") that owned three special purpose companies ("SPCs"), each with an account at Swedbank Latvia. Between February 5, 2015 and October 14, 2016, the Client initiated 386 transactions totaling $3,312,120 through accounts belonging to the SPCs that were processed through U.S. correspondent banks.

Around March 2016, the SPC Owner attempted to send payments related to his business from an IP address in Crimea using Swedbank Latvia's e-banking platform to a U.S. correspondent bank, which rejected the payments citing a potential connection to Crimea and alerted Swedbank Latvia. Swedbank Latvia requested additional information from the correspondent bank and from the SPC Owner. The SPC Owner falsely assured Swedbank Latvia that none of the transactions involved Crimea. Based on this representation, a relationship manager at Swedbank Latvia re-routed the rejected payments to a different U.S. correspondent bank, which ultimately processed the transactions.

Swedbank Latvia had reason to know that the Client's assurances were incorrect. When onboarding the Client and the SPCs, Swedbank Latvia obtained Know Your Customer ("KYC") data — including addresses, telephone numbers, and a customer questionnaire — clearly indicating that the Client and the SPCs had a physical presence in Crimea. Although Swedbank Latvia collected and stored customer IP data, it did not integrate this IP data into its sanctions screening processes; if screened, the IP data would have indicated that the Client was present in Crimea at the time of the apparent violations.

This conduct resulted in 386 apparent violations of Section 6(a) of Executive Order 13685 of December 19, 2014, specifically the export of financial services to Crimea in violation of E.O. 13685(1)(a)(iii). In 2016 and 2017, Swedbank Latvia offboarded the Client and the SPCs during a lookback review.

How OFAC Determined the Penalty

The statutory maximum civil monetary penalty applicable in this matter is $112,322,552. OFAC determined that Swedbank Latvia did not voluntarily self-disclose the apparent violations, as a third party was required to and did notify OFAC first. OFAC also determined that the apparent violations constitute a non-egregious case. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A, the base civil monetary penalty applicable in this matter equals the sum of the applicable schedule amount for each violation, totaling $6,238,000. The settlement amount of $3,430,900 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines.

Aggravating Factors

  • Swedbank Latvia failed to exercise due caution or care in neglecting to account for information in its possession regarding its Client's presence in Crimea and by solely relying on the Client's assurances when it possessed contrary information, including KYC and IP data.
  • Swedbank Latvia knew it had customers in Crimea and had reason to know it was processing payments on behalf of the three SPCs located in Crimea.
  • Swedbank Latvia is a sophisticated financial institution with over one million customers and is one of the largest banks in Latvia by assets.

Mitigating Factors

  • Swedbank Latvia did not receive a penalty notice or Finding of Violation from OFAC in the five years preceding the earliest date of the transactions giving rise to the apparent violations.
  • Swedbank AB and Swedbank Latvia took significant remedial action in response to the apparent violations, including: exiting the client relationships with the SPCs in December 2016 and the SPC Owner in February 2017; implementing geofencing that prevents customers from sending payments through online banking platforms from IP addresses in comprehensively sanctioned jurisdictions; implementing an automated system control within their transaction screening solution to identify potential resubmissions of payments after rejection; establishing enhanced due diligence and screening procedures for high-risk customers undertaking any payments in U.S. dollars; implementing enhanced diligence and transparency protocols for responses to correspondent banks; expanding their compliance staff to implement the new protocols; and undertaking measures to improve KYC, AML, and financial sanctions controls more broadly.
  • Swedbank AB and Swedbank Latvia substantially cooperated by conducting an extensive lookback, providing well organized responses to OFAC's requests for information, and by tolling the statute of limitations.

Compliance Takeaways

This case demonstrates the importance of implementing and maintaining effective, risk-based sanctions compliance controls, especially for sophisticated financial institutions operating in proximity to high-risk regions. Such controls should account for changes to applicable sanctions and incorporate all relevant available information to conduct responsive and regular screening, including ensuring that KYC information (such as passports, phone numbers, nationalities, and addresses) and IP data are appropriately integrated into sanctions screening protocols.

This case also illustrates the importance of undertaking reasonable efforts to investigate red flags. Ignoring or failing to heed such warnings can cause apparent violations to multiply quickly. Rather than dismissing such concerns and relying on unsubstantiated assurances, financial institutions and other persons made aware of such issues should diligently work to identify risks that may exist. Here, the bank's own KYC information supported the concerns of its correspondent bank, yet it went ignored. Instituting effective protocols to address such situations can help mitigate the risk of providing services to entities and individuals located in comprehensively sanctioned jurisdictions.

This matter further underscores the importance of remaining vigilant against efforts by persons in Crimea, as well as in Russia and other high-risk areas, to evade sanctions and elude compliance controls. In July 2015, OFAC published an advisory on the "Obfuscation of Critical Information in Financial and Trade Transactions Involving the Crimea Region of Ukraine," which discussed evasive practices used to circumvent or evade OFAC's sanctions, including "the omission or obfuscation of references to Crimea and locations within Crimea in documentation underlying transactions involving U.S. persons or the United States."

Official Source Documents

This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.

Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.

Archived on June 13, 2026

SHA-256: 5dd952a31c3947e6315f783000fa45c5d292921c0fb1d2bb77ec299cd86f3db2

More OFAC Cases