How does a sophisticated global company process over 30 high-risk transactions without stopping once?
It’s the uncomfortable question at the center of a recent $275 million settlement involving a large multinational energy and infrastructure business that purchased liquified petroleum gas (LPG) through a Dubai-based supplier. The company had a compliance program, conducted sanctions screening, and reviewed transaction documents. According to the Office of Foreign Assets Control (OFAC), however, these measures were insufficient and caused U.S. financial institutions to process payments connected to Iranian-origin goods, resulting in 32 apparent violations across several transactions over a multi-year period.
The control measures did not prevent the OFAC compliance failures because the system lacked the operational capability to connect red flags across deal cycles and stop unresolved high-risk transactions from advancing.
Workflow failures that result in sanctions violations matter to every team in the organization managing vendors, partners, and transactions. Sanctions screening must be embedded in the commercial process and be strong enough to force holds when the risk profile demands it. That means bringing restricted party screening and risk controls directly into business systems like Salesforce.
Integrated Salesforce sanctions screening puts compliance checks where records are created and converted into transactions, so risky relationships can be stopped before they harm the business.
Key Takeaways
- The OFAC compliance violation was caused by overreliance on basic KYC, OFAC SDN screening, and facially valid shipping documents, without escalating obvious sanctions red flags into enhanced due diligence.
- Energy, maritime, logistics, and commodity trading businesses require greater scrutiny than standard onboarding procedures provide.
- Risk-based controls must reflect the full deal context including threat thresholds based on product, geography, payment currency, route, customer, supplier, sector, and transaction structure.
- CRM platforms like Salesforce are where deals are created, processed, approved, and executed, which makes them ideal places to embed risk-based sanctions controls.
- Red flags must trigger action. A Salesforce-integrated solution can turn warning signs into enforceable workflow steps that freeze deal progression, require compliance approval before next-movement, and create defensible audit trails.
Anatomy of the $275M OFAC Compliance Failure
At its core, the company was fined for apparent violations of the Iranian Transactions and Sanctions Regulations (ITSR), specifically the prohibition on causing U.S. persons, including U.S. financial institutions, to facilitate transactions involving Iranian-origin goods. The LPG cargo was represented as Omani or Iraqi in origin when it was property in which Iran, a sanctioned jurisdiction, held an interest.
Image 1. OFAC Violation Red Flags That Should Have Been Caught Earlier

To understand how this happened, we need to examine the workflow that supported a systematic breakdown and compounding of risk across stages of the business:
- Vendor Onboarding — Suppliers were approved without proper due diligence. Although initial screening did not identify a direct sanctions list hit, the relationship warranted deeper review because it involved an intermediary, a sanctions-sensitive commodity, and sourcing from jurisdictions neighboring Iran.
- Deal Execution — Payments, often routed through third parties, moved forward without a compliance checkpoint to halt them.
- Repeated Transactions — The same pattern recurred across 32 violations because no control caught it the first time or any time after.
Each stage was an opening for integrated Salesforce sanctions screening to intervene.

What the OFAC Enforcement Action Reveals About Today’s Sanctions Compliance Risk
“The documents look fine.”
It is a common and potentially dangerous conclusion in sanctions compliance. Documents may confirm what a counterparty claims, but they do not always reveal when shipping routes have been manipulated or pricing that only works because something prohibited is happening.
The enforcement action is a broader lesson in operational compliance exposure, where sanctions failures are driven by missing context and risk intelligence. A company may have all the relevant screening data such as names, documents, and payment records in its systems, but still fail if those data points are not connected into a meaningful risk picture.
As sanctions-evasion tactics grow more sophisticated, regulators expect companies to identify restricted entities that try to stay hidden. In this case, red flags were scattered across different systems, different teams, and different decisions. Basic screening was blind to the surrounding transaction facts that pointed to a bigger threat level.
The most noteworthy risk-intelligence gaps from this enforcement action include:
1. Origin Risk Intelligence to Identify When Claims Don’t Match Commercial Reality
Multiple clues pointed to a discrepancy in origin claims, including shipments allegedly loaded from locations that were not significant LPG trading hubs and lacked the export infrastructure to support the type of cargo being shipped. The company was missing trade-flow intelligence, geographic risk detection, and validation capabilities to challenge the sourcing information that appeared legitimate on paper but was inconsistent with real-world supply chain conditions.
2. Entity Risk Data to Detect When Counterparties Look Safe but Behave Differently
The Dubai-based intermediary and its affiliates did not appear on any restricted party list, yet these counterparties masked a higher-risk supply chain. The intermediary played a key role in obscuring the cargo’s true origin and was linked to repeated concerns about prohibited hydrocarbon supplies. Missing adverse media screening, politically exposed persons (PEP) intelligence, and enhanced third-party risk analysis left critical context outside the compliance review process.
3. Ownership Transparency to Reveal When Transaction Participants Obscure Who Is Really Involved
Third-party wires and payment arrangements helped distance the transactions from sanctioned actors. The company focused primarily on the parties named in transaction documents rather than the broader network of relationships behind them. Missing ownership-aware screening, such as OFAC 50 Percent Rule analysis, reduced its ability to identify hidden sanctions vulnerabilities.
4. Pattern Recognition Across Transactions to See When Repeated Warnings Become a Trend
OFAC cited numerous warning signs across the life of the relationship, including third-party allegations, vessel irregularities, questionable documentation, payment disruptions, and unusually discounted pricing. The inability to act on these indicators points to shortcomings in centralized alert management, cross-transaction monitoring, continuous rescreening, and enterprise-wide reporting. As a result, recurring red flags were prevented from accumulating into a risk profile that would have triggered further investigation or stopped future transactions.
Image 2. Key Risk Intelligence Gaps

Why Salesforce Screening Has Become Key to Reducing Sanctions Exposure
The missing capabilities identified in the OFAC enforcement action depend on access to operational business data. To be effective, they also need to influence business decisions where they happen.
Business systems like Salesforce are where that data and those decisions already exist. In Salesforce, prospects become customers, vendors are onboarded, partner relationships are managed, addresses are maintained, transactions are approved, and commercial activity progresses. As a result, it often contains the operational context needed to determine whether a potential sanctions risk should be investigated, escalated, or blocked.
When compliance intelligence is not connected to customer records and processes, problematic scenarios thrive:
- Sales teams can move forward with risky accounts before compliance reviews occur.
- Existing customers often go unscreened after initial verification.
- Screening happens without enforcement; resolution depends on manual handoffs rather than automated controls.
- Manual processes create limited visibility making it difficult to map risk across related entities and transactions.
Compliance cannot protect the business if it shows up after the deal has already moved to quote, contract, order, or payment. As regulators increasingly focus on how organizations identify and act on sanctions risk, the ability to embed compliance controls directly into business processes is becoming just as important as the screening itself. To meet this expectation, Salesforce sanctions screening must be robust enough to detect, connect, and act on warning signals.
How Integrated Salesforce Sanctions Screening Prevents OFAC Compliance Violations
Compliance capability shows up in how an organization handles ambiguity and accumulating exposure because before a sanctions violation occurs, there is often an execution failure. In highly regulated sectors such as energy, commodities, logistics, maritime trade, and infrastructure, sanctions risks rarely appear as a single obvious watchlist match. As happened in this case, risk emerged through shadow networks, document inconsistencies, re-export hubs, and deals that seemed too good to question.
An automated global sanctions screening workflow inside Salesforce could have produced a different compliance outcome for the company’s energy business—and for organizations facing similar challenges—by helping them identify risk, act on it consistently, and demonstrate compliance decisions through a complete audit trail.
Image 3. Salesforce Sanctions Screening Software Features

Key capabilities that make a difference:
1. Automated OFAC and Global Sanctions Screening
An advanced solution provides the breadth to screen customers, vendors, partners, intermediaries, vessels, banks, and other relevant parties at onboarding, record and opportunity creation, quote approval, contract review, and order submission. In this case, a broader screening perimeter would have helped assess all entities and shipments tied to the transaction rather than only relying on named entities and documents.
2. Continuous Monitoring of Existing Customers and Vendors
Modern compliance solutions can be configured to automatically rescreen Salesforce records when lists change, transaction details are updated, or new risk indicators appear. This would have mattered where repeated shipments and payments continued even as additional red flags developed across the relationship.
3. Sanctioned-Party Ownership and Affiliation Analysis
Beyond publicly available sanctions lists, leading integrated solutions provide ownership-aware screening content to ensure compliance with the OFAC 50% Rule, BIS 50% affiliate restrictions, and EU ownership and control principles. These specialized datasets are maintained by compliance intelligence providers and help uncover indirect exposure that traditional screening can miss. In this case, such data could have identified the intermediary’s historical connections to Iran-related trade activity and marked the relationship for further review.
4. Enhanced Risk Intelligence for High-Risk Sectors
Energy and maritime trade attract sanctions-evasion risk because commodities can be rerouted, origin can be misrepresented, vessels can obscure movement, and associates can disguise supply chains. Salesforce screening incorporates geography, maritime datasets, adverse media, PEP, and other threat indicators. In this case, these controls could have elevated the warning signs for priority review.
5. Workflow-based alert adjudication
Alerts can be routed automatically to compliance teams with clear case ownership, risk scoring, required evidence, escalation paths, and resolution workflows. In the OFAC enforcement action, this feature would have provided a structured way for repeated concerns to be consolidated and managed.
6. Record Locking Pending Review
Top-performing integrated screening solutions have configurable controls to stop dangerous activity until compliance clears them. The system should prevent users from bypassing unresolved sanctions alerts or moving deals forward through manual workarounds. This capability directly addresses the enforcement-case failure: the deals continued even though multiple warning signs should have triggered a pause.
7. Detailed Reporting and Audit Trails
Salesforce-integrated screening solutions make it easy to capture every screening result, escalation, decision, approval, and override. This creates the evidence needed to demonstrate that the organization took appropriate action. In a repeated-transaction scenario, reporting helps leadership see when individual alerts are becoming a systemic exposure pattern. Documentation is also maintained in line with OFAC’s reporting and recordkeeping mandate.
Together, these Salesforce sanctions screening controls turn compliance into an enforceable workflow that follows the full commercial lifecycle.
What Effective OFAC Compliance Programs Require for Organizations Operating Globally
The case also highlights several operational practices that global organizations should have in place even if they don’t use Salesforce screening solutions:
- Train teams on U.S. sanctions jurisdiction and “cause” liability. Non-U.S. companies often underestimate how quickly OFAC jurisdiction can apply when prohibited transactions involve U.S. dollars and entities.
- Maintain sanctions-evasion awareness programs. Help employees recognize evasion techniques.
- Implement sector-specific controls. Policies should be tailored to sensitive sectors like maritime trade.
- Establish mandatory escalation criteria. Certain combinations of red flags should automatically pause transactions rather than allowing business teams to make case-by-case judgment calls.
- Create clear authority to pause transactions. Compliance teams should be empowered to stop activity when concerns cannot be resolved quickly. There should be cross-functional clarity on who is responsible for reporting and clearing sanctions issues.
- Promote a culture of challenge. Employees should be encouraged to question transactions that appear commercially implausible, even when documents appear valid at face value.
- Encourage evidence-based decisioning. Document what was reviewed, why the decision was made, and what conditions were imposed.
- Perform periodic program testing. Controls should be tested against realistic scenarios to confirm that operational enforcement is effective. Existing counterparties should also be reviewed frequently.
- Keep up to date with regulatory standards and best practices. Take advantage of industry events, webinars and knowledge resources provided by trade compliance vendors, and professional associations.
De-Risk Business Decisions with Descartes Salesforce Sanctions Screening
The $275 million OFAC enforcement case is the latest example that sanctions compliance failures often occur in the space between detection and decision.
Descartes’ Salesforce sanctions screening solution helps organizations close that gap. Our global sanctions compliance software gives teams the breadth to identify hidden risk, the authority to stop deals before they proceed, and the risk-based controls needed to prevent high-risk transactions from being treated like ordinary business.
Book a demo to see how Descartes OFAC compliance solutions and comprehensive risk management solutions can reduce sanctions exposure in your maritime trade and payment flows directly within Salesforce.
Find out what our customers are saying about Descartes Denied Party Screening on G2, an online third-party business software review platform. Additionally, you can read this essential buyer’s guide to denied party screening to help you select a solution that fits your needs.
