Data last synced:
Last updated:
Swift Prepaid Solutions, Inc. d/b/a daVinci Payments (daVinci), a financial services and payments firm, settled with OFAC for $206,213 to resolve 12,391 apparent violations of the Cuban Assets Control Regulations, the Iranian Transactions and Sanctions Regulations, the Ukraine-/Russia-Related Sanctions Regulations, and the Syrian Sanctions Regulations. Between November 15, 2017 and July 27, 2022, daVinci, which manages prepaid reward card programs, enabled reward cards to be redeemed from persons apparently resident in sanctioned jurisdictions. OFAC determined that daVinci's conduct was non-egregious and was voluntarily self-disclosed.
Penalty Amount
$206,213.00
Enforcement Date
November 6, 2023
Rank in Top Penalties
#189
DaVinci provides digital or physical payment reward card programs for corporate, non-profit, and government clients through an online platform. These programs allow daVinci's clients to issue payment cards to select recipients, typically as part of a loyalty, award, or promotional incentive for employees, customers, and other beneficiaries. Clients funded the card programs through an issuing bank; upon receiving a list of card recipients including names and email addresses, daVinci would send each authorized user a token to redeem for a prepaid card. To redeem, users went to daVinci's website and provided their names, addresses, and email addresses. Users could not enter an address in a sanctioned jurisdiction and were screened against sanctions lists. However, daVinci lacked comprehensive geolocation controls.
Between March 2020 and February 2022, in the course of a compliance review and subsequent investigation, daVinci discovered that on 12,378 occasions it had redeemed prepaid cards for users with Internet Protocol (IP) addresses associated with Iran, Syria, Cuba, and Crimea. After daVinci began preventing access to its platform from IP addresses associated with these sanctioned jurisdictions, the company further discovered it had redeemed prepaid cards for 13 card recipients who had used email addresses with top-level domain suffixes associated with sanctioned jurisdictions (e.g., .sy for Syria, .ir for Iran) during the redemption process and who were apparently resident therein.
Over the relevant period — November 15, 2017 to July 27, 2022 — this absence of comprehensive geolocation controls led daVinci to process 12,391 redemptions totaling $549,134.89 for cardholders apparently located in sanctioned jurisdictions, resulting in apparent violations of the Cuban Assets Control Regulations, 31 C.F.R. § 515.201; the Iranian Transactions and Sanctions Regulations, 31 C.F.R. § 560.204; the Ukraine-/Russia-Related Sanctions Regulations, 31 C.F.R. § 589.287; and the Syrian Sanctions Regulations, 31 C.F.R. § 542.207.
The statutory maximum civil monetary penalty applicable in this matter is $4,399,759,685. OFAC determined that the apparent violations were voluntarily self-disclosed and non-egregious. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A, the base civil monetary penalty equals the sum of one-half of the transaction value for each apparent violation, which is $274,950. The settlement amount of $206,213 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines.
This enforcement action underscores the importance of obtaining and using all available information to verify a customer's identity or residency, including by using location-related data, such as IP address and top-level domains, for sanctions compliance purposes. As appropriate, firms providing services through online platforms should integrate such information into a risk-based sanctions compliance program to prevent the provision of services to persons in sanctioned jurisdictions. This case further demonstrates the potential shortcomings of controls that rely on customer-provided information, rather than a holistic information-gathering system that can mitigate evasion or misrepresentation. The action further highlights the value of conducting proactive, self-initiated reviews to identify compliance gaps, disclose any potential violations to OFAC, and taking steps to remediate deficiencies, including by instituting periodic independent testing to ensure adequate controls.
This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.
Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.
Archived on June 13, 2026
SHA-256: aec16973854bfd1b5af4f1d1cd053791a95e41d76740088925d4c40231074c32