Data last synced:
Last updated:
TradeStation Securities, Inc., a Florida-headquartered brokerage firm that operates online securities trading platforms, settled with OFAC for $1,110,661 to resolve 481 apparent violations of multiple sanctions programs. From June 21, 2021 to June 15, 2022, TradeStation provided investment services to customers located in Iran, Syria, and the Crimea region of Ukraine following a series of compliance control failures, enabling those customers to execute securities-related transactions in apparent violation of the Iranian Transaction and Sanctions Regulations, the Syrian Sanctions Regulations, and the Ukraine-/Russia-Related Sanctions Regulations.
Penalty Amount
$1,110,661.00
Enforcement Date
March 17, 2026
Rank in Top Penalties
#100
The violations stemmed from a series of cascading failures in TradeStation's two-tier geo-blocking system. The first tier was a firewall that denied access from IP addresses associated with sanctioned jurisdictions. The second tier was a third-party IP verification tool that authenticated a user's IP address upon login to TradeStation's web-based and mobile platforms.
In April 2018, TradeStation deployed new proprietary software to improve its mobile platform. This software inadvertently rendered the second-tier geo-blocking ineffective for mobile users: rather than screening the user's actual IP address at login, the second-tier protocol detected the IP address of the U.S.-located server running TradeStation's mobile platform software, making it incapable of identifying users in Iran, Syria, and Crimea.
On June 21, 2021, a TradeStation employee disabled the first-tier geo-blocking to install a software update and inadvertently failed to reenable it. The first-tier controls remained disabled until at least June 15, 2022, leaving no effective restriction on mobile platform access for users in sanctioned jurisdictions.
Two additional failures compounded the problem. TradeStation's internal automated testing tool, which simulated access attempts from sanctioned IP addresses, was discontinued in November 2021 without replacement, leaving no mechanism to detect that the geo-blocking controls had failed. Separately, in September 2021, an affiliated employee failed to renew a third-party subscription that delivered daily alerts of access attempts from sanctioned jurisdictions; sanctions compliance personnel failed to address the absence of these notifications for over eight months and did not consider what their disappearance might signal.
As a result, users located in Iran, Syria, and Crimea executed 481 trades totaling $4,442,645 through TradeStation's mobile application, in apparent violation of ยง 560.204 of the Iranian Transaction and Sanctions Regulations (ITSR), 31 C.F.R. part 560; ยง 542.207 of the Syrian Sanctions Regulations (SySR), 31 C.F.R. part 542; and ยง 589.207 of the Ukraine-/Russia-Related Sanctions Regulations (URSR), 31 C.F.R. part 589.
OFAC determined that TradeStation self-disclosed the apparent violations and that the apparent violations constitute a non-egregious case. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A, the base civil monetary penalty applicable in this matter equals the sum of one-half of the transaction value for each apparent violation, which is $2,221,322. The settlement amount of $1,110,661 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines.
This enforcement action highlights the importance of regular testing and auditing to ensure sanctions compliance controls are effectively mitigating risk and preventing sanctions violations. Controls only work if they are effectively implemented. The most well-designed sanctions compliance program can be rendered wholly ineffectual by human and technical errors. Comprehensive, independent, and objective testing and auditing can help catch problems early and provide opportunities for remediation, thereby limiting risk of violating sanctions.
Regular testing and auditing also provide opportunities for evaluating sources of sanctions risk and ensuring that appropriate controls are in place to address them. Controls should be well designed to address particular sanctions risks, including those presented by particular technology offerings. These controls may include appropriately calibrated screening protocols, geo-blocking controls, and Virtual Private Network detection software. They may also include controls to validate proper system operation and execution following any outage, including due to planned maintenance or upgrade. Broker-dealers utilizing real-time order placement and trade execution platforms should also consider appropriate investments to ensure the modernization and adequate functionality of their sanctions-related compliance solutions.
Firms should not treat testing and auditing, or any other sanctions compliance undertaking, as a box-checking exercise. Sanctions risks are dynamic and may fluctuate as prohibitions change or as businesses evolve. While technological solutions are often a critical part of an effective sanctions compliance program, firms should ensure they are not overly relying on a patchwork of software or taking a "set it and forget it" approach to compliance.
This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.
Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.
Archived on June 13, 2026
SHA-256: d14302b0db2bbca14d552493a6353a6525f55d89452962309bd2898f97f3ecb3