Skip to main content
Binance Sanctions Probe: Where Controls Broke DownSanctions Lists & Screening
5 min readFor FinTech Compliance Teams

Binance Sanctions Probe: Where Controls Broke Down

What Happened

U.S. federal prosecutors are investigating if Binance failed to prevent transactions involving Iran, potentially violating U.S. sanctions. The Manhattan U.S. Attorney's Office is leading the probe, with the DOJ's criminal division involved. Authorities are examining whether the exchange knowingly allowed sanctioned activity despite restrictions. No findings have been announced yet.

This isn't Binance's first compliance crisis. In 2023, the exchange and former CEO Changpeng Zhao reached a $4.3 billion settlement with U.S. authorities after Zhao pleaded guilty to violating anti-money laundering requirements.

Timeline

While the investigation's exact start date hasn't been disclosed, it comes amid heightened U.S. sanctions enforcement targeting Iranian financial networks. In September, U.S. authorities sanctioned firms and individuals accused of supporting Hezbollah and other Iranian-linked networks. Around the same time, U.S. authorities also targeted an Iranian cryptocurrency exchange over alleged sanctions evasion.

The timing matters. These enforcement actions signal that digital assets are now a primary focus for sanctions compliance scrutiny.

Which Controls Failed or Were Missing

The investigation centers on whether Binance's sanctions screening and transaction monitoring controls were sufficient to detect and block Iran-related activity. Based on the allegations, several control layers appear to have failed:

Geographic screening at onboarding. If Iranian users or entities accessed the platform, your customer screening didn't catch them. This means either the Know Your Customer process didn't collect reliable location data, or the screening logic didn't flag high-risk jurisdictions effectively.

Ongoing transaction monitoring. Even if a customer passes initial screening, transaction patterns can reveal sanctions risk. If funds moved between wallets tied to Iran or Iranian intermediaries, your monitoring rules should have flagged them. The investigation suggests these patterns went undetected or unreviewed.

IP address and device fingerprinting. Cryptoasset platforms can track where transactions originate. If users accessed Binance from Iranian IP ranges or used VPNs to mask their location, controls should have triggered enhanced due diligence or blocked the activity. The absence of these alerts suggests gaps in technical controls.

Sanctions Name Screening. OFAC's Specially Designated Nationals (SDN) List and other sanctions lists must be screened continuously, not just at account opening. If designated persons or entities transacted on the platform after being added to sanctions lists, your screening frequency or match logic failed.

Escalation and Suspicious Activity Report. Even if alerts fired, they're worthless if your team doesn't escalate them. If sanctions-related alerts sat unreviewed or were closed without proper investigation, the breakdown was operational, not technical.

What the Relevant Standard Requires

U.S. sanctions compliance isn't optional, and the requirements are specific.

OFAC's 50 Percent Rule states that entities owned 50% or more by one or more designated persons are themselves blocked, even if they're not explicitly listed. Your screening must identify both direct matches and ownership structures that trigger this rule.

FATF Recommendation 6 requires countries to implement targeted financial sanctions related to terrorism financing without delay. For you, that means screening customers and transactions against UN and domestic sanctions lists in real time.

FATF Recommendation 7 extends these obligations to proliferation financing. Iran is a proliferation financing concern, so your controls must detect not just direct Iranian counterparties but also transactions that could support weapons programs or sanctioned activities.

31 CFR Part 501 (OFAC regulations) requires U.S. persons and entities under U.S. jurisdiction to block property and interests in property of designated persons. If your platform serves U.S. customers or operates in the U.S., you're subject to these rules. "We didn't know" isn't a defense if you failed to implement reasonable controls.

The Bank Secrecy Act requires financial institutions to establish risk-based AML/CFT programs that include sanctions compliance. After Binance's 2023 settlement for BSA violations, any ongoing sanctions gaps signal that the compliance overhaul didn't go far enough.

Lessons and Action Items for Your Team

If you're running compliance at a cryptoasset firm, here's what you need to do now:

Test your sanctions screening against Iranian typologies. Run a retrospective analysis of transactions from the past 12 months. Screen wallet addresses, counterparties, and transaction patterns against OFAC lists and known Iranian intermediaries. If you find undetected matches, your controls have the same gaps Binance allegedly had.

Implement continuous screening, not batch updates. Sanctions lists change daily. If you're screening customers once at onboarding and then only when they transact, you'll miss designations that occur in between. Automate daily rescreening of your entire customer base against updated lists.

Layer geographic controls. Don't rely on self-reported location data. Cross-reference IP addresses, device fingerprints, and wallet activity patterns. If a customer claims to be in Germany but consistently transacts from Iranian IP ranges, that's a red flag your KYC missed.

Build transaction monitoring rules for sanctions evasion patterns. Look for rapid movement of funds through multiple wallets, use of mixers or tumblers, transactions with known high-risk exchanges, and counterparties in sanctioned jurisdictions. These patterns indicate deliberate circumvention, not accidental exposure.

Document your risk assessment for high-risk jurisdictions. OFAC expects you to assess sanctions risk as part of your overall AML/CFT risk assessment. If Iran, North Korea, Syria, or other sanctioned jurisdictions appear in your customer base or transaction flows, document why and what enhanced controls you've applied.

Train your alert review team on sanctions typologies. Technical controls only work if your analysts know what they're looking at. Sanctions evasion doesn't always look like a direct match to a list. Train your team to recognize layering, use of nested entities, and transactions structured to avoid detection.

Establish a clear escalation path to legal and executive leadership. If your team identifies potential sanctions violations, they need to know exactly who to notify and when. Delays in escalation can turn a compliance issue into a criminal investigation.

The Binance investigation isn't an outlier. It's a preview of how regulators will scrutinize every cryptoasset platform's sanctions controls. If your screening, monitoring, or escalation processes have gaps, fix them before prosecutors come asking why you didn't.

You Might Also Like