SanctionsLookup

Data last synced:

Wells Fargo Bank, N.A. OFAC Settlement: $30M (2023)

Last updated:

Wells Fargo Bank, N.A. settled with OFAC for $30,000,000 to resolve 124 apparent violations of the Iranian Transactions and Sanctions Regulations, the now-repealed Sudanese Sanctions Regulations, and the Syrian Sanctions Regulations. For approximately seven years beginning in 2008 and ending in 2015, Wells Fargo and its predecessor, Wachovia Bank, provided a foreign bank located in Europe with software that the foreign bank then used to process trade finance transactions with U.S.-sanctioned jurisdictions and persons.

Penalty Amount

$30,000,000.00

Enforcement Date

March 30, 2023

Rank in Top Penalties

#24

Case Details

Type:
Entity
Name:
Wells Fargo Bank, N.A.
Country:
🇺🇸 United States
Industry:
Banking
Address:
Washington, D.C.
Penalty amount:
$30,000,000.00
Base civil monetary penalty:
$533,369,211.00
Max civil monetary penalty:
$1,066,738,422.22
Egregious case:
Yes
Apparent violations:
124
Voluntary self disclosure:
Yes
Case:
Settlement
Violation period:
December 27, 2010 to December 7, 2015
Program:
Iranian Transactions and Sanctions Regulations, 31 C.F.R. § 560.208Sudanese Sanctions Regulations (SSR), 31 C.F.R. § 538.206Syrian Sanctions Regulations, 31 C.F.R. § 542.210
Enforcement date:
March 30, 2023

Nature of the Apparent Violations

Wachovia's trade insourcing platform, Eximbills, operated in two versions: a "Comprehensive" version where Wachovia processed trade transactions on behalf of the customer, and a "Hosted" version where the software was provided to the customer to manage its own transactions. In May 2006, Wachovia and Bank A agreed in writing that Bank A bore primary responsibility to screen for OFAC issues on the Hosted version and would refrain from using it for transactions with sanctioned jurisdictions or entities.

Around May 2007, Bank A sought a single platform for all of its trade finance services, including those involving sanctioned jurisdictions and persons. A mid-level manager within Wachovia's legacy Global Trade Services unit directed Wachovia to specially design a customized Hosted version of Eximbills so that Bank A could use it to handle trade finance instruments involving OFAC-sanctioned jurisdictions and persons. Around July 2008, Wachovia and Bank A modified their agreements accordingly, and Bank A began using this platform for such transactions. Bank A's use of the Hosted Eximbills platform relied on Wachovia's (and later Wells Fargo's) technology infrastructure at the bank's branch in Hong Kong and data facility in North Carolina. Wachovia also built a redirect mechanism into the software: if Bank A inadvertently sent a transaction involving a sanctioned jurisdiction or person to the Comprehensive version, the program would route it to Bank A for processing through the Hosted version. Seven of the 124 apparent violations arose through this mechanism.

After Wells Fargo acquired Wachovia in 2008, Wells Fargo personnel raised potential sanctions concerns from the inherited trade insourcing relationships on multiple occasions, including to senior management. No regular or systematic process was established to review Bank A's use of Eximbills for OFAC compliance. An internal working group formed around 2013 recognized potential facilitation risks under OFAC regulations but its proposed three-point remediation plan was absorbed into a broader holistic review of the trade finance technology business and never implemented. A 2014 internal audit relied on the business line's self-assessment that the platform was not high risk and did not specifically review the Hosted Eximbills business. It was not until late 2015, nearly seven years after Bank A began using the customized platform, that a business review discovered that Bank A had been processing non-compliant trade instruments since 2008.

Between approximately December 27, 2010 and December 7, 2015, Wells Fargo facilitated 124 transactions processed by Bank A involving sanctioned parties or jurisdictions, totaling approximately $532,068,794, that would have been prohibited if performed by Wells Fargo or another U.S. person or within the United States. These constituted apparent violations of the Iranian Transactions and Sanctions Regulations, 31 C.F.R. § 560.208, the now-repealed Sudanese Sanctions Regulations, 31 C.F.R. § 538.206, and the Syrian Sanctions Regulations, 31 C.F.R. § 542.210.

How OFAC Determined the Penalty

The statutory maximum civil monetary penalty applicable in this matter is $1,066,738,422.22. OFAC determined that the apparent violations were voluntarily self-disclosed and egregious. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A, the base civil monetary penalty applicable in this matter is one-half of the statutory maximum, which is $533,369,211. The settlement amount of $30,000,000 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines.

Aggravating Factors

  • The legacy GTS business unit demonstrated reckless disregard for U.S. sanctions requirements when it specially designed and provided the Hosted Eximbills platform for Bank A to engage in transactions, using Wachovia's underlying technological infrastructure, that both the business unit and Bank A knew or should have known would include transactions involving sanctioned jurisdictions or persons in violation of OFAC regulations. Moreover, Wells Fargo failed to exercise a minimal degree of caution or care in failing to identify and prevent such transactions for seven years after it acquired Wachovia, despite potential sanctions concerns (including specifically with respect to possible facilitation issues) raised internally at senior-management levels on multiple occasions.
  • The development of the specially designed Hosted Eximbills platform for Bank A was led by a mid-level manager within the legacy GTS business unit at Wachovia. Moreover, Wells Fargo's senior management should reasonably have known that Bank A was using the Hosted version of Eximbills to engage in transactions with sanctioned jurisdictions and persons in light of the potential sanctions concerns raised internally to senior managers in Wells Fargo on multiple occasions, including after major sanctions enforcement cases prompted a renewed focus within Wells Fargo on assessing the risks associated with the bank's international trade-related services.
  • By providing Bank A with a software platform specially designed to make it easier for Bank A to engage in trade finance transactions with persons located in Iran, Sudan, on one occasion Syria, and, on six occasions, sanctioned entities, Wells Fargo undermined the policy objectives of three U.S. sanctions programs.
  • Wachovia, and its successor, Wells Fargo, are large and commercially sophisticated international financial institutions with sophisticated understandings of applicable sanctions requirements.

Mitigating Factors

  • The legacy GTS was a relatively small business unit within Wachovia, and there is no indication that senior management either directed or had actual knowledge that Wachovia provided the Eximbills platform to Bank A for the purpose, at least in part, of engaging in transactions with OFAC-sanctioned jurisdictions. Moreover, OFAC acknowledges that, more broadly, Wells Fargo had a strong sanctions compliance program at the time of the Apparent Violations, including in the trade finance line of business, and that the failure by Wells Fargo and its senior management to identify and prevent the Apparent Violations was not a result of any systemic compliance breakdown within the broader Wells Fargo organization.
  • The true magnitude of the sanctions harm of the underlying conduct is more limited than the total value of transactions conducted by Bank A using the Hosted Eximbills platform, which totaled the USD equivalent of approximately $532,068,794. Moreover, the majority of the 124 apparent violations related to agriculture, medicine, and telecommunications and therefore may have been eligible for a general or specific license, thus mitigating the harm to sanctions policy objectives.
  • Wells Fargo has not received a penalty notice or Finding of Violation from OFAC in the five years preceding the date of the earliest transaction giving rise to the Apparent Violations.
  • Promptly after Wells Fargo identified the Apparent Violations, the bank terminated Bank A's access to the Hosted version of Eximbills, voluntarily disclosed the matter to OFAC, conducted an extensive internal investigation and produced the results to OFAC, and otherwise provided substantial cooperation with OFAC's investigation, including by agreeing to toll the statute of limitations.
  • Wells Fargo remediated the compliance issue by immediately suspending the Hosted version of the Eximbills platform for Bank A. As part of an overall shift away from insourcing, the successor platform to Eximbills is now managed by Wells Fargo personnel and uses Wells Fargo's sanctions screening system for all trade instruments. In September 2018, Wells Fargo instituted a more robust risk management policy for new or revised product or service offerings. This policy seeks to identify and control any areas of risk, including sanctions-related risk, associated with new business initiatives prior to, during, and after implementation.

Compliance Takeaways

This action highlights the risks that companies may face when employees pursue new business opportunities or the preservation of existing business relationships without proper oversight. Such oversight is important across all business units within an organization, including lines of business that may be small relative to the larger organization or that involve products or services falling outside the larger organization's core business. Moreover, when sanctions compliance risks are raised internally — including concerns arising from smaller, non-core business lines — companies should promptly seek to thoroughly investigate and address those risks. Finally, this action emphasizes the necessity for comprehensive due diligence regarding potential sanctions risk when one entity acquires another through merger or acquisition.

Official Source Documents

This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.

Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.

Archived on June 13, 2026

SHA-256: 6a8506fcbeed066df8d3c16cde1f4f04208d55d886a879db83ddf95ca778d3e3

More OFAC Cases