Issue #16 | August 11, 2026 | 7 min read

The Brief

BNP Paribas paid $8.9 billion in 2014 for moving money through the U.S. financial system on behalf of Sudan, Iran, and Cuba. Twelve years later it's still the largest sanctions settlement any bank has ever paid. DOJ's own statement of facts says compliance and legal staff were informed of how the bank was getting around its sanctions filters, and in some instances supervisors were the ones directing it.

This issue breaks down how the workaround actually functioned, why the resulting penalty barely touched the business line responsible for it, and what the case tests for anyone who assumes a control's existence means people are following it.

Main Feature

BNP Paribas Didn't Miss the Sanctions Violations. It Built a System to Get Around Them.

The bank's own compliance and legal staff knew what the practice was for. Supervisors directed it anyway.

Between 2004 and 2012, BNP Paribas moved more than $8.8 billion through the U.S. financial system on behalf of clients in Sudan, Iran, and Cuba: $6.4 billion for Sudanese entities, $1.7 billion for Cuban entities, $650 million for Iranian entities, all countries the bank had no license to serve under U.S. sanctions law. In June 2014 the bank pleaded guilty in Manhattan federal court to conspiring to violate the International Emergency Economic Powers Act and the Trading with the Enemy Act, and agreed to pay $8.97 billion combined across the Department of Justice, the Federal Reserve, the New York Department of Financial Services, and OFAC.

What DOJ's statement of facts actually described wasn't a bank that failed to build sanctions controls. It was a bank that built the controls, then engineered around them on purpose. Payments bound for Sudanese and Cuban counterparties got routed through non-sanctioned "satellite" banks to obscure where the money was really going. When a batch of Cuban payments got blocked in 2006 after reaching a U.S. correspondent bank, BNP's response was to strip the SWIFT messages of any reference to the Cuban parties and resubmit them as a lump sum, so the same institution that had just flagged the payments would clear them the second time without knowing what it was clearing. DOJ counted 3,897 transactions manipulated this way over eight years. The practice wasn't a handful of traders improvising under pressure. Compliance and legal personnel were informed of it, and in some instances supervisors were the ones instructing staff to strip the messages.

$8.97B — total combined penalty across DOJ, the Fed, NYDFS, and OFAC
3,897 — transactions with sanctioned-party references stripped from SWIFT messages, 2004–2012
$6.4B / $1.7B / $650M — illegal transaction volume for Sudan / Cuba / Iran, respectively
13 — employees terminated or separated under the settlement, including the Group COO

The DOJ line that "this conduct, this conspiracy was known and condoned at the highest levels of BNP" wasn't rhetorical color. It was the finding that set the size of the penalty. Which makes the actual operational consequence worth a closer look, because it was far narrower than the headline figure suggests. The one-year suspension of direct dollar clearing didn't touch BNP Paribas generally, it applied only to the oil and gas Energy & Commodity Finance business line, and only at specific booking centers: Geneva, Paris, and Singapore clearing through the New York branch, plus Milan and Rome, for twelve months starting January 2015. The exact business line that generated the violations kept clearing dollars everywhere else the bank operated.

Red flags in this case

  • A years-long, cross-departmental practice of stripping sanctioned-party identifiers from SWIFT payment messages before resubmission, not a handful of isolated exceptions

  • Use of non-sanctioned intermediary ("satellite") banks specifically to obscure a payment's true origin or destination

  • Compliance and legal staff informed of a sanctions-evasion practice without escalating it, and in some cases supervisors directing it themselves

  • A previously blocked payment resubmitted in altered form to the same institution that had just flagged it

  • A remedial dollar-clearing suspension scoped narrowly enough, one business line, five booking centers, twelve months, to leave the rest of the bank's dollar-clearing access untouched

The lesson here isn't just "watch for wire stripping," though that's a specific, checkable pattern: repeat resubmissions of a previously rejected payment, message formats unusually clean of counterparty detail for the corridor and dollar volume involved. The bigger lesson is that a documented control tells you nothing about whether the people running it are actually complying with it. If your sanctions screening depends entirely on the payment message reaching the filter intact, and nobody periodically pulls a sample of cleared payments to check whether identifying information was ever present and later removed, you're trusting the same assumption BNP's compliance function apparently ran on for eight years.

BNP Paribas didn't get caught because a filter missed something. It got caught because eight years is a long time to keep several hundred people quiet about a system built to make a filter miss something.

Source: U.S. Department of Justice, "BNP Paribas Agrees to Plead Guilty and to Pay $8.9 Billion for Illegally Processing Financial Transactions for Countries Subject to U.S. Economic Sanctions," June 30, 2014 | Board of Governors of the Federal Reserve System, Order of Assessment of a Civil Money Penalty, June 30, 2014 | New York State Department of Financial Services, Consent Order, June 30, 2014

Intelligence Briefing

FinCEN — On August 3, FinCEN assessed a $125 million civil money penalty against UBS Financial Services Inc., the largest BSA penalty ever imposed on a broker-dealer and the firm's second FinCEN enforcement action in eight years. FinCEN found UBS failed to reasonably monitor more than 60,000 foreign-currency wires totaling over $10 billion between January 2019 and June 2023, with inadequate due diligence on high-risk clients tied to Russia and Latin America. Source: FinCEN, "FinCEN Assesses Historic $125 Million Penalty Against UBS Financial Services Inc. for Recidivist BSA Violations," August 3, 2026.

OFAC — On July 29, OFAC designated two firms, Persian Gulf Marine Insurance Company and HormuzSafe Marine Services Authority, tied to an IRGC-backed scheme that forces commercial vessels to buy mandatory maritime "insurance" to transit the Strait of Hormuz. Source: U.S. Department of the Treasury, "Treasury Disrupts Iranian Regime's Strait of Hormuz Extortion Network," July 29, 2026.

Career Intel

UBS's $125 million penalty this week came with a requirement most people outside compliance never think about: a third-party lookback to identify suspicious transactions the bank's own program missed, plus an independent review of its AML program. Both are staffed heavily by outside contractors and consultants brought in specifically for the engagement, not by the bank's permanent headcount.

If you're trying to break into financial crimes without a compliance title yet, lookback and remediation engagements are one of the more accessible entry points. Firms hire in bulk, on contract, precisely because the bank's own team is the one that missed the activity in question. It's not permanent work, but it's real casework, and it reads better on a resume than a certification with no case experience behind it.

Open Roles

In partnership with Artha. If you apply through a listing below, we may earn a commission at no cost to you. We only pick roles we'd tell a colleague to apply for.

Role

Company

Location

Apply

Financial Intelligence Group Analyst

S&T Bank

Multiple Locations

Compliance Analyst

Exol

New York

Sr. Fraud Data Analyst

Renishaw

Remote

Financial Crime Risk Investigator

TD

Mount Laurel, NJ

Cryptocurrency Analyst

Mantech

Sterling, VA

Tip Line

Got any idea for something you'd want to see covered here? Doesn't have to fit neatly into a category. If you think it's interesting, we probably will too.

Send it to [email protected].

If someone forwarded this to you, welcome.

The AML Brief goes out every Tuesday. Subscribe for free and get the Top 10 AML Red Flags cheat sheet as a thank-you:

[BUTTON: Subscribe → theamlbrief.com]

Already subscribed? Forward this to one colleague who works in financial crimes. That's how we grow.

The AML Brief | theamlbrief.com

Disclaimer: The AML Brief is an independent financial crimes intelligence publication. All content is sourced from publicly available regulatory documents, enforcement actions, and published research. Nothing published here constitutes legal, compliance, or regulatory advice. The AML Brief is not affiliated with any financial institution, regulator, law firm, or employer. For advice specific to your situation, consult a qualified attorney or compliance professional.