Treasury publishes every OFAC civil penalty and settlement, by year, with the party, the date, the number of violations and the amount. Read one at a time these are individual enforcement stories. Read together they are a dataset, and it says several things that the individual stories do not.
The figures below come from this site’s own ingest of those tables. The chart and the full year-by-year table are on the cases page.
The distribution is extremely lopsided
A small number of actions account for most of the money. The largest handful of settlements — a virtual currency exchange, several correspondent banks, a tobacco company — between them exceed the entire remainder of the published record.
That has a practical consequence for anyone reasoning about deterrence. The median published penalty is small, in the tens or low hundreds of thousands of dollars. The mean is enormous. Quoting either without the other misdescribes the regime, and press coverage almost always quotes the mean.
The sectoral composition changed completely
Between roughly 2009 and 2019 the largest penalties were, with very few exceptions, correspondent banking cases: non-US institutions moving dollars for parties whose connection to a restricted jurisdiction had been kept out of the payment message.
That sequence effectively ends. After 2019 the very large banking settlements largely stop appearing, and the substantial figures move to other sectors — technology and telecommunications, tobacco, virtual currency exchanges, commodities and industrial groups.
Two readings are available and they are not exclusive. The banking sequence may have worked: payment message integrity is now a board-level matter at every major correspondent bank, and the transparency standards introduced in response are the direct legacy of those cases. Or the conduct moved: if correspondent chains became genuinely harder to use, the value had to travel some other way, and the sectors now appearing are where it went.
The virtual currency settlements support the second reading at least in part, though not in the way the technology narrative suggests. Neither of the two largest turned on cryptographic obfuscation. The Bittrex settlement turned on an exchange collecting customer location data at onboarding and not screening it. The Binance settlement — the single largest entry in the whole dataset — turned on a trade-matching engine that paired US users with users in sanctioned jurisdictions while, in OFAC’s finding, senior management knew and kept the compliance programme a paper one.
Volume and value move independently
The count of published actions per year is remarkably stable — usually somewhere between eight and thirty — while the annual total swings by two orders of magnitude depending on whether a very large settlement landed that year.
This is worth remembering when reading any year-on-year comparison of “enforcement activity”. A year with a large settlement and a year without one can involve identical amounts of investigative work.
What this dataset does not contain
Three important absences.
It is OFAC only. The Department of Justice’s criminal resolutions, the Bureau of Industry and Security’s export control penalties, and state regulators’ actions are all separate, and in the largest cases the OFAC component has frequently been a fraction of the total. Reading an OFAC figure as the penalty for a case will usually understate it severalfold.
It is civil penalties only. Cautionary letters, findings of violation without a monetary penalty, and matters closed with no action do not appear, and there are many more of those than there are penalties.
It is not a measure of how much evasion happens. It is a measure of how much was found, established and published, by one authority, in a form that survives to a published notice.
The data
Fetched by scripts/ingest/ofac-penalties.mjs from Treasury’s own yearly enforcement tables, weekly. The
last fetch date and the record count are on the sources page, which is generated from the
ingest metadata rather than maintained by hand.