When the CEO of Nodus International Bank pleaded guilty to wire fraud and sanctions violations, he forfeited $16.9 million and received 112 months in federal prison. This wasn't about a rogue trader or a junior analyst missing red flags. It was about the executive who designed the controls choosing to bypass them.
If your sanctions screening and fraud detection systems rely solely on executive oversight without independent validation, you're vulnerable to the same issues that collapsed Nodus Bank.
Understanding the Risks
This guide outlines the control framework fraud managers need to detect and prevent executive-led sanctions evasion and wire fraud. It highlights vulnerabilities that arise when senior leadership has both operational authority and the ability to conceal transactions from boards, regulators, and compliance teams.
You'll find requirements tied to OFAC sanctions compliance under the International Emergency Economic Powers Act (IEEPA), segregation of duties standards, and board-level oversight mechanisms that prevent concealment.
Key Concepts
Executive Override Risk: Senior management's ability to approve transactions, modify controls, or access systems without independent review creates a gap that standard fraud detection can't close.
OFAC Specially Designated Nationals (SDN): Individuals and entities designated by the Treasury Department's Office of Foreign Assets Control with whom U.S. persons are prohibited from engaging in financial transactions unless specifically licensed.
Freezing Without Delay: The requirement under FATF Recommendation 6 and U.S. sanctions law to immediately block assets and transactions involving designated persons without waiting for internal approval processes.
Front Company Structure: The use of shell entities or intermediaries to disguise the beneficial ownership or ultimate recipient of funds in a transaction that would otherwise trigger sanctions screening.
Requirements Breakdown
OFAC Compliance Under IEEPA
The International Emergency Economic Powers Act gives the President authority to impose economic sanctions. OFAC administers these sanctions through designation lists.
Your obligations:
- Screen all customers, beneficiaries, and counterparties against the SDN list before initiating any transaction.
- Block transactions involving SDN-listed persons immediately.
- Report blocked transactions to OFAC within 10 business days using the appropriate reporting form.
- Maintain records of all OFAC screening decisions for at least five years.
In the Nodus case, the CEO obtained OFAC authorization to foreclose on a designated individual's property, then separately structured an unauthorized $4 million sale back to that individual through a front company. The foreclosure was legal. The resale was not. Your screening must catch both the direct transaction and the beneficial owner behind the intermediary.
Segregation of Duties
No single individual should have the authority to:
- Approve high-value wire transfers.
- Modify transaction monitoring rules.
- Override sanctions screening alerts.
- Approve exceptions to CDD requirements.
- Access the systems that generate compliance reports to the board or regulators.
At Nodus, executives concealed fraudulent transactions from the board, other executives, and Puerto Rico's Office of the Commissioner of Financial Institutions. That concealment required the ability to control both transaction approval and reporting.
Standard practice: Wire transfers above your institutional threshold (commonly $100,000 to $250,000) require dual approval from individuals in separate reporting lines. One approver should not have IT admin rights to the wire system.
Board-Level Financial Reporting
Your board should receive monthly reports that cannot be modified by operating executives. These reports must include:
- All wire transfers above the dual-approval threshold, listed by approver.
- All OFAC license applications and approvals.
- All transactions involving high-risk jurisdictions.
- All accounts opened or closed for customers in sanctioned sectors.
- All overrides of fraud or sanctions alerts, by approver name.
The report should come directly from your core banking system or compliance platform, not filtered through the CEO or CFO.
Implementation Guidance
Name Screening Architecture
Deploy real-time sanctions screening at the point of transaction initiation, not just at the end-of-day batch review. If a wire transfer involves an SDN-listed individual or a front company owned by that individual, the system should block it before any executive sees an approval queue.
Your screening vendor should:
- Update SDN list data within four hours of OFAC publication.
- Screen beneficial owners, not just the named account holder.
- Flag transactions where the beneficiary address matches a known address of a designated person, even if the name is slightly different.
In the Nodus resale, the designated individual used a front company. Your screening should have flagged the Southampton, New York property address as matching the individual's known residence.
Dual-Control Wire Transfer Workflow
For any wire transfer above your threshold:
- Initiator enters the transaction and submits for approval.
- First approver (business line manager) reviews business justification.
- Second approver (compliance or finance) reviews sanctions screening, beneficiary due diligence, and source of funds.
- System logs both approvals with timestamp and IP address.
- Transaction releases only after both approvals.
Neither approver should have system admin rights to delete logs or modify the approval queue.
OFAC License Tracking
If your institution applies for an OFAC license to engage in an otherwise-prohibited transaction, create a separate tracking system that logs:
- The specific transaction authorized by the license.
- The license number and expiration date.
- The individuals authorized to execute under that license.
- Any subsequent transactions that reference the licensed activity.
At Nodus, the CEO obtained a legitimate OFAC license for the foreclosure, then executed a separate, unlicensed transaction. Your system should flag any transaction involving the same customer or property that falls outside the scope of the original license.
Quarterly Control Testing
Your internal audit team should test executive override capabilities quarterly:
- Attempt to process a simulated wire transfer to a shell company owned by a sanctioned individual.
- Verify that the transaction is blocked before reaching any approval queue.
- Confirm that the block cannot be overridden by a single executive.
- Review all overrides from the prior quarter and validate the documented justification.
Common Pitfalls
Pitfall 1: Treating OFAC licenses as blanket authorizations. A license for one transaction doesn't authorize related transactions with the same counterparty. In the Nodus case, the foreclosure license didn't cover the resale.
Pitfall 2: Screening only the named parties, not beneficial owners. If your screening stops at the front company name, you'll miss the designated individual behind it. Screen the registered agent, the ownership chain, and known addresses.
Pitfall 3: Allowing the CEO to approve exceptions to dual-control requirements. If your CEO can waive the dual-approval threshold for "urgent" wires, you've created the override path that enabled Nodus's fraud.
Pitfall 4: Sending compliance reports to executives before the board sees them. If your MLRO reports to the CEO, and the CEO reviews all board materials before distribution, the CEO can suppress adverse findings. Your MLRO should have a direct reporting line to the board's audit or risk committee.
Pitfall 5: Failing to screen transactions during liquidation or wind-down. At Nodus, executives continued to execute fraudulent transactions even after Puerto Rico regulators ordered liquidation. Your controls must remain active until the receiver takes possession of all systems.
Quick Reference Table
| Control | Requirement | Test Frequency | Owner |
|---|---|---|---|
| SDN list update | Within 4 hours of OFAC publication | Daily automated check | Sanctions Analyst |
| Real-time screening | Block before approval queue | Per transaction | Compliance System |
| Dual approval threshold | No single approver for wires >$100K | Quarterly sample test | Internal Audit |
| Beneficial owner screening | Screen ownership chain, not just entity name | Per new customer, per transaction | KYC/Sanctions Team |
| OFAC license scope validation | Confirm transaction matches license terms | Per licensed transaction | Sanctions Analyst |
| Board reporting independence | Reports bypass executive review | Monthly | MLRO/Board Audit Committee |
| Override log review | Document and validate all alert overrides | Quarterly | Internal Audit |
| Executive system access review | Confirm no single user has approve + admin rights | Semi-annually | IT Security + Compliance |
Critical takeaway: Nodus International Bank's CEO obtained $16.9 million through fraud and sanctions evasion because he controlled both transaction approval and compliance reporting. Your fraud prevention framework must assume that executives can be the threat actor, not just the control owner. Independent screening, dual approval, and board-level reporting that bypasses executive filtering are essential. If your current wire transfer system allows a single executive to approve high-value payments, you're one bad hiring decision away from a similar case.



