ARTICLE
8 October 2026

Iran-Related Whistleblower Tips: An Internal-Investigation Agenda For Financial Institutions

FinCEN's September 2026 whistleblower bulletin targeting Iran-related sanctions violations provides financial institutions with a roadmap for identifying prohibited conduct, but implementing an effective response requires careful attention to intake procedures, evidence preservation, and fact-specific legal analysis. How should institutions structure their investigation protocols to address allegations involving Iranian networks while maintaining independence and avoiding bias?
United States Government, Public Sector

FinCEN is actively seeking whistleblower information concerning Iran-related BSA and sanctions violations. Financial institutions should preserve evidence, investigate independently, and distinguish legitimate Iran-related activity from potentially sanctionable conduct.

Updated September 26, 2026: This article retains its complete original text, with researched updates integrated into the relevant sections.

FinCEN’s September 10, 2026 whistleblower bulletin invites information from U.S. and non-U.S. persons about possible Bank Secrecy Act violations and violations of sanctions authorities involving Iran, including conduct by proxies and facilitators outside Iran. Six days later, FinCEN convened global financial institutions to exchange information about revenue streams and procurement networks tied to the Iranian government.

The bulletin supports Treasury’s Operation Economic Outcast and is explicit about the information the government considers useful. It does not itself create a universal new duty to report every internal allegation, change the elements of an OFAC violation, or turn a red flag into proof of misconduct. For financial institutions, its value is as an investigation-planning document that can improve intake, transaction reconstruction, and escalation.

Read the allegation against the actual authorities

The bulletin says FinCEN’s program covers information concerning specified statutes enforced by Treasury and the Department of Justice, including the BSA and national-security laws underlying U.S. trade and economic sanctions. It notes that a potential OFAC violation requires a U.S. nexus, including direct or indirect transactions with or involving the United States, U.S. persons, or entities owned or controlled by U.S. persons. It separately identifies restrictions applicable to non-U.S. persons, including causing U.S. persons to violate sanctions, conspiracy and evasion, while Treasury has also emphasized potential secondary-sanctions exposure involving Iran.

An investigation should identify the legal theory rather than treating “Iran-related” as a conclusion. Relevant questions may include which persons and property were involved, where services were performed, which currencies and correspondent accounts were used, whether a U.S. person approved or facilitated conduct, and what sanctions were in effect on the transaction dates. OFAC designations and program rules change, so the analysis should preserve the historical record.

The same discipline applies to BSA concerns. A complaint about customer due diligence, beneficial ownership, monitoring, or suspicious activity reporting should be tested against the institution’s type, applicable rules, and facts. The enforcement initiative does not replace that work.

Use the typologies as leads, not verdicts

FinCEN highlights shipping-document irregularities that hide links to Iran, dealings with Iranian or front digital-asset service providers, exchange-house patterns inconsistent with customary business, unusual digital-asset payments involving petroleum or trading companies, nested exchanges, and foreign money-services businesses. It also identifies opaque trading companies, transaction notes associated with terrorist organizations, unexplained transfers to high-risk jurisdictions, crowdfunding payouts, and many-to-one wallet flows.

Each indicator can have an innocent explanation. A connection to Türkiye, China, the UAE, Iraq, or Hong Kong is not itself evidence of evasion. An investigator should define the anomaly, compare it with the customer’s expected activity, and seek corroboration from transactional, communications, corporate, shipping, device, and open-source records.

That approach also limits bias. Reviews should be based on behavior, counterparties, ownership, routing, and documented risk, not nationality, ethnicity, language, or unsupported assumptions about a region.

Escalation should bypass implicated personnel

An employee tip may allege that a relationship manager ignored ownership concerns, an operations team altered payment information, a sanctions alert was overridden, or management discouraged escalation. The first response should preserve the allegation and identify conflicts in the normal reporting chain.

When the subject includes senior management, AML or sanctions leadership, or the legal team, the institution may need an unconflicted executive, board committee, or outside counsel to direct the matter. Independence requires control over scope, evidence access, interviews, experts, and reporting. The organization should document who made the escalation decision and why.

The reporter should receive a clear anti-retaliation channel. The institution should restrict identity information to those who need it, monitor employment actions, and avoid promises of secrecy it cannot keep. Nothing in an internal process should be presented as preventing communication with the government.

Document the decision path

A defensible investigation file should record:

  • the allegation;
  • scope;
  • preservation steps;
  • relevant transactions;
  • legal authorities;
  • factual findings;
  • remediation;
  • disclosure analysis; and
  • escalation decisions.

If the institution decides not to file a SAR, make a voluntary self-disclosure, or take another external action, the factual basis for that decision should be documented.

Reconstruction requires more than payment messages

Iran-related networks may use front companies, trade intermediaries, exchange houses, digital assets, shipping structures, and correspondent accounts. A reconstruction should connect customer onboarding records, beneficial-ownership information, screening results, alert histories, payment messages, invoices, bills of lading, vessel and port data, device or IP information, wallet analytics, communications, and employee approvals.

Time matters. Sanctions status, ownership, vessel identity, routing, and customer explanations may change. Investigators should preserve the versions available when the transaction was initiated and reviewed. They should also record data limitations, especially when foreign affiliates, vendors, or counterparties hold relevant records.

Legal, AML, sanctions, cybersecurity, fraud, trade-finance, and digital-asset specialists may each see only part of the pattern. A coordinated chronology and entity map can expose connections that separate queues miss. It can also prevent parallel teams from interviewing the same witness with inconsistent assumptions.

What FinCEN is asking for

FinCEN says it welcomes information about potential violations of the Bank Secrecy Act and U.S. sanctions laws involving Iran.

The bulletin highlights possible activity involving:

  • Iranian proxies;
  • facilitators outside Iran;
  • foreign companies supporting illicit Iranian commerce;
  • foreign financial institutions; and
  • companies facilitating conduct that violates U.S. sanctions or the BSA.

The agency says qualifying whistleblowers may be eligible for awards.

External reporting and remediation are fact-specific

The FinCEN Exchange is a voluntary public-private partnership, not a substitute for an institution’s filing obligations. After facts are developed, counsel and compliance teams should separately analyze suspicious activity reporting, OFAC reporting, blocking or rejection obligations, voluntary self-disclosure, law-enforcement contact, and obligations in other jurisdictions. Different standards, timelines, confidentiality restrictions, and privileges may apply.

Remediation should address both the conduct and the control failure. Depending on the evidence, that may include restricting transactions, correcting customer risk, improving ownership verification, tuning scenarios, changing override authority, preserving additional trade data, disciplining employees, or reviewing related accounts. Broad de-risking without a fact-based rationale can create other legal and policy concerns.

FinCEN says a person who voluntarily provides information leading to a successful covered enforcement action with collected penalties above $1 million may be eligible for an award of 10 to 30 percent, subject to 31 U.S.C. § 5323 and implementing requirements. Eligibility and award amounts are not automatic. The bulletin’s incentive reinforces a simple governance point: institutions should assume credible reporters have a functioning external route and build an internal response that can withstand scrutiny.

Received an allegation involving potentially prohibited transactions or failures in financial-crime controls? Contact Braeden Anderson to discuss investigation scope, preservation, escalation, and coordination with the appropriate specialists. Discuss a financial-crime investigation.

FinCEN's September 2026 Iran whistleblower bulletin should change how financial institutions think about internal sanctions reports.

A whistleblower complaint can become a regulatory lead before the institution completes its own review.

Iran-related does not mean prohibited

Financial institutions should avoid turning the bulletin into a blanket rule that every transaction connected to Iran is unlawful.

The legal analysis can depend on:

  • the parties;
  • beneficial ownership;
  • sanctions lists;
  • sectoral restrictions;
  • location;
  • U.S.-person involvement;
  • licenses;
  • exemptions;
  • humanitarian exceptions; and
  • the purpose and structure of the transaction.

The investigation must determine what actually occurred.

Preserve evidence first

A credible internal report should trigger targeted preservation.

Relevant records may include:

  • customer onboarding;
  • beneficial-ownership data;
  • wires;
  • payment messages;
  • trade finance records;
  • sanctions-screening alerts;
  • false-positive dispositions;
  • SAR-related material;
  • internal communications;
  • account notes;
  • device records; and
  • third-party diligence.

A preservation decision should be made before routine systems delete or overwrite relevant evidence.

Protect the reporter and the investigation

Access to the complaint should be limited to personnel with a legitimate investigative role.

The institution should assess whether anyone in:

  • business leadership;
  • compliance;
  • legal;
  • operations; or
  • the reporting chain

has a conflict that could impair the investigation.

Where senior personnel or the compliance function itself is implicated, independent oversight or outside counsel may be appropriate.

September 2026 researched developments

September 26, 2026 researched update: The following developments supplement the original article where the current research did not map cleanly to an existing section.

Map BSA and sanctions issues separately

A transaction can raise multiple legal questions.

For example, an institution may need to analyze:

  • OFAC sanctions;
  • BSA suspicious-activity reporting;
  • customer due diligence;
  • false statements;
  • export controls;
  • correspondent banking;
  • money laundering; and
  • DOJ voluntary self-disclosure considerations.

Those issues should not be collapsed into a single “sanctions violation” label.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More