May through July 2026 | Compliance & Risk Newsletter | Volume 3
May 2026
FinCEN Alert: IRGC Sanctions Evasion & Shadow Banking Networks
On May 11, 2026, FinCEN issued an alert containing a list of red flags, to assist financial institutions in identifying and mitigating risks associated with financial facilitation networks supporting Iran’s Islamic Revolutionary Guard Corps (IRGC). The IRGC relies on networks to evade U.S. sanctions and launder proceeds. OFAC issued new sanctions targeting individuals and entities supporting Iran’s destabilizing activities, including financial facilitators and procurement networks.
Key Takeaways:
Shadow Fleet Commodity Sales: The IRGC supplements its budget by smuggling oil to international buyers using an old, "shadow fleet" (or "dark fleet") operating outside standard maritime regulations.
Layered Front Companies: The network utilizes exchange houses, trading firms, and front companies outside of Iran to receive and remit payments. This allows sanctioned actors to access the global financial system without repatriating funds directly to Iran.
Institutional Action: Financial institutions are reminded of their Bank reporting obligations and are urged to utilize heightened vigilance and file SARs regarding suspected IRGC-linked procurement and digital asset infrastructure. SARs should reference “IRGC Illicit Finance Alert.”
Enhanced due diligence is recommended for high-risk jurisdictions and sectors, including Iran linked trade, shipping, and financial flows.
Screening systems must be updated to reflect newly designated persons and entities.
Source: FinCEN IRGC Alert PDF
June 2026
OFAC Issues Compliance Guide
On June 1, 2026, OFAC published a compliance guide titled "Introduction to the Office of Foreign Assets Control." This guide is designed for both U.S. and non-U.S. persons; it consolidates core regulatory concepts into a single document and contains a list of link and resources. It describes how U.S. sanctions operate, compliance expectations, licensing processes, procedures for removal from sanctions lists (delisting), and OFAC’s enforcement.
The guidance serves as an official benchmark for what OFAC considers fundamental compliance across operational touchpoints.
Key Takeaways:
Strict Liability Standard Reminders: OFAC re-emphasizes that civil violations operate on a strict-liability basis. In such instance, a financial institution can be held liable even without intent or knowledge of prohibited activity. Maintaining a robust, risk-based Sanctions Compliance Program remains the primary mitigating factor in potential enforcement actions.
Screening & Operational Decision-Making: Beyond baseline automated name matching, OFAC expects financial institutions to utilize context-driven evaluation (e.g., customer due diligence, geolocation monitoring, and typology risk reviews) to make informed determinations on whether to block, reject, or proceed with transactions.
Strict Reporting Windows & Deadlines:
Blocked & Rejected Transactions: Must be reported to OFAC within 10 business days of the action.
Annual Report of Blocked Property: Must account for all blocked property held as of June 30 and be submitted to OFAC by September 30 annually.
Recordkeeping: Full transaction and blocked-property records must be retained for at least 10 years.
Licensing & Delisting Frameworks: Clarifies the operational steps for applying for Specific Licenses (authorizations for otherwise prohibited transactions) and navigating Administrative Reconsideration (SDN list removal under 31 C.F.R. § 501.807).
Utility for Training & Counterparty Due Diligence: Compliance officers should leverage this consolidated guide as an authoritative training resource for internal non-specialist business lines, front-office teams, and third-party/foreign counterparties to align overall risk management practices with Treasury's baseline expectations.
Source: U.S. Department of the Treasury – OFAC Guidance Document
Interagency Update on Reputation Risk Removal
On June 2, 2026, the FDIC, OCC, and Federal Reserve jointly updated 15 interagency guidance documents, spanning asset securitization, subprime lending, remote deposit capture, customer identification, and cybersecurity, to completely remove references to "reputation risk." This follows the agencies' April 2026 final rule codifying the elimination of reputation risk from bank supervisory programs, ensuring examination decisions remain focused strictly on quantifiable, material risks.
Key Takeaways:
Align Risk Frameworks: Review internal policies, governance materials, and risk assessments to ensure "reputation risk" is not maintained as a standalone supervisory risk category.
Focus on Core Risk Pillars: Structure compliance and risk reporting around established, measurable categories: credit, market, liquidity, operational, legal, and compliance risks. Expect more precise supervisory language focused on safety, soundness, and compliance, not “reputation risk” concepts.
Mitigate Subjective Scrutiny: The updates remove subjective criteria historically used in supervisory oversight, providing clearer expectations during examinations.
FinCEN Section 314(b) Information-Sharing Guidance
On June 12, 2026, FinCEN issued updated guidance clarifying how financial institutions can share real-time information with peer institutions regarding suspected fraud under Section 314(b) of the USA PATRIOT Act. The guidance outlines safe harbor protections and operational mechanisms to encourage collaborative information sharing to detect and prevent complex fraud schemes before funds leave the financial ecosystem.
Key Takeaways:
Leverage Safe Harbor for Fraud: Re-evaluate internal Section 314(b) procedures to ensure fraud prevention teams actively exchange information with peer institutions under legal safe harbor protections. Cyber indicators (IP addresses, device fingerprints) and behavioral red flags (new payees + large transfers, distant logins) are explicitly permitted.
Upgrade Real-Time Data Sharing: Streamline communication channels between AML, fraud, and cyber intelligence units to facilitate rapid, real-time responses to suspicious transactions.
Register & Participate: Ensure your institution is properly registered with FinCEN’s 314(b) network to participate in peer-to-peer information sharing.
Sources: U.S. Department of the Treasury Press Release (SB0531) and https://www.fincen.gov/system/files/shared/314bfactsheet.pdf
Joint U.S.-UK Economic Sanctions Comparison Guide
On June 23, 2026, OFAC and the UK’s Office of Financial Sanctions Implementation (OFSI) published a joint guide comparing U.S. and UK economic sanctions regimes. The document breaks down similarities and differences across legal authorities, key terminology (e.g., U.S. "blocking" vs. UK "freezing"), ownership threshold standards, licensing processes, and reporting obligations.
Key Takeaways:
Harmonize Cross-Border Compliance: Multi-jurisdictional compliance teams should review procedural differences, such as OFAC’s Strict 50% Rule versus OFSI’s "control" criteria.
Refine Terminology & Escalations: Align transaction screening systems and escalation paths to accurately handle jurisdiction-specific requirements (e.g., U.S. 10-day blocking reports vs. UK asset-freeze notifications).
Training Resource: Use this guide to train global compliance officers navigating overlapping U.S. and UK sanctions regimes.
Treasury Actions Targeting Overseas Scam Operations
On June 23, 2026, Treasury announced targeted actions and sanctions aimed at dismantling transnational criminal networks operating investment, romance, and "pig butchering" scams. The release details how cybercriminals exploit virtual currency platforms, money mules, and shell companies to siphon funds from American consumers. OFAC sanctioned 35 individuals and entities linked to the Prince Group TCO, a major Southeast Asia–based scam network responsible for billions in fraud targeting Americans. FinCEN simultaneously proposed expanding rules to cover additional entities involved in laundering scam proceeds.
Key Takeaways:
Enhance Fraud Monitoring: Adjust transaction monitoring models to flag sudden, out-of-character wire transfers or crypto-fiat conversions associated with investment scam typologies.Heightened exposure risk: Prince Group‑linked entities may appear in customer onboarding, payments, or digital asset flows.
Focus on Vulnerable Demographics: Strengthen front-line protocols for identifying potential victims of elder financial exploitation and coercive romance scams.
Crypto Exchange Screening: Heighten due diligence on non-hosted wallet transfers and non-compliant virtual asset service providers (VASPs) linked to scam operations.
Non-U.S. institutions risk: secondary sanctions for facilitating significant transactions with designated persons.
Source: U.S. Department of the Treasury Press Release (SB0538)
Treasury Sanctions CJNG Fuel Smuggling Networks
On June 30, 2026, OFAC designated major criminal networks and facilitators responsible for cross-border fuel theft and illicit oil trade benefiting the Jalisco New Generation Cartel (CJNG). The illegal operations involve northbound crude oil smuggling and southbound refined fuel trafficking through complex logistics networks. Treasury sanctioned individuals and entities involved in CJNG’s cross border fuel smuggling and tax evasion schemes. FinCEN issued supplemental alerts detailing red flags for fuel related smuggling, money laundering, and trade-based schemes.
Key Takeaways:
Energy & Commodity Due Diligence: Institutions offering trade finance, commercial lending, or payment services in the energy sector must conduct EDD on cross-border fuel distributors and logistics counterparties.
Identify Shell Entities: Audit trade documentation and bill-of-lading records involving Mexican/U.S. border energy transfers for obscure intermediate shell companies.
Immediate Asset Freezing: Ensure newly designated individuals and business entities associated with CJNG fuel operations are immediately blocked across core screening systems.
Expect increased scrutiny: of oil, fuel, logistics, and transportation sector transactions, especially near the U.S.–Mexico border.
Review FinCEN’s red flags: for fuel theft schemes, including falsified customs documents, shell distributors, and unusual cross border fuel payments.
Strengthen monitoring: for structured cash deposits, trade-based money laundering, and digital asset payments linked to fuel transactions.
Foreign financial institutions face potential secondary sanctions: for facilitating CJNG linked transactions.
Source: U.S. Department of the Treasury Press Release (SB0545)
July 2026
Joint Agency Statement on Handling Highly Sensitive Examination Data
On July 16, 2026, the Federal Reserve, FDIC, and OCC issued a joint statement outlining enhanced, coordinated procedures for reviewing highly sensitive bank information during examinations. To minimize cybersecurity risks, examiners will prioritize secure, on-site reviews of critical data rather than transferring proprietary materials onto agency systems.
Key Takeaways:
Establish Secure Exam Protocols: Collaborate with regulatory exam teams to designate secure on-site rooms or encrypted viewing portals for highly sensitive files.
Reduce Cyber Exposure: Take advantage of agency procedures designed to keep core trade secrets, customer data, and proprietary systems off external agency servers during routine audits.
Maintain Full Regulatory Access: Ensure protocols protect sensitive data while giving examiners full, unimpeded access required by law.
Banks should prepare: for more on site supervisory reviews of sensitive data.
Agencies will notify institutions of any material data breach involving supervisory information within 72 hours.



Comments