Smaller than BNP Paribas and more instructive about mechanism, because OFAC’s enforcement information for 12 March 2015 describes not just what was removed from the messages but the process built to keep removing it.
What the notice says
Commerzbank settled potential civil liability for 1,596 apparent violations across five authorities: the Iranian Transactions and Sanctions Regulations, the Sudanese Sanctions Regulations, Executive Order 13382 and the Weapons of Mass Destruction Proliferators Sanctions Regulations, the Burmese Sanctions Regulations and the Cuban Assets Control Regulations.
The conduct ran for several years up to and including January 2010. As early as 2002, bank employees deleted or omitted references to Iranian financial institutions and replaced the originating bank information with Commerzbank’s own name.
The queue
The detail that distinguishes this case is what came next. OFAC records that Commerzbank later created a process to route payments involving Iranian counterparties to a payment queue requiring manual processing by bank employees rather than routine, automated processing.
That is a system change, not a series of individual decisions. Automated straight-through processing is where screening happens; diverting a defined class of payments into a manual lane takes them out of the control by design, and it requires someone to specify it, someone to build it and someone to staff it.
It is also why cases like this are provable. A process leaves documentation — a requirements note, a change request, a work instruction, a rota — in a way that a series of unrecorded individual choices does not.
The composition
| Programme | Transactions | Approximate value | Base penalty |
|---|---|---|---|
| Iran | 959 | $22.0m | $242.0m |
| Sudan | 375 | $78.3m | $209.5m |
| SDN List parties (E.O. 13382 / WMDPSR) | 142 | $39.6m | $99.8m |
| Burma | 64 | $5.1m | — |
The Iranian transactions carried the largest base penalty despite being by some distance the smallest by value. Penalties accrue per violation against a statutory maximum, so transaction count drives the arithmetic far more than transaction size — which is why 959 small payments outweigh 375 much larger ones.
Where it sits in the sequence
Commerzbank is one instance of a pattern that runs from Credit Suisse in 2009 through Lloyds, Barclays, ING, HSBC, Standard Chartered, Crédit Agricole, Société Générale and UniCredit. Institutions outside the United States needed to move dollars for customers whose connection to a restricted jurisdiction would have caused a US correspondent to block the payment, and the payment message was the thing that had to be managed.
The analysis of the full penalty record sets out what happened to that sequence after 2019.