Skip to main content
NFRisk Non-Financial Risk advisory Start a Conversation
NFR-0003 Evidence-controlled risk scenario

BNP Paribas S.A.

When external warnings accumulated, could sanctions controls still be trusted?

BNP Paribas pleaded guilty in 2014 to conspiring to violate US sanctions law after moving more than $8.8 billion through the US financial system for sanctioned entities; the plea agreement imposed $8.9736 billion in total financial penalties.

Financial Crime & Control Integrity Data & Control Integrity Conduct & Governance Risk Sanctions Payments & clearing Data integrity Governance & escalation Control assurance

Documented impact

$9bn Total forfeiture and criminal fine
5 years Five-year probation and enhanced compliance obligations

Authoritative findings

The documented event

On 9 July 2014, BNP Paribas S.A. pleaded guilty in the Southern District of New York to a one-count felony information charging conspiracy to violate the International Emergency Economic Powers Act and the Trading with the Enemy Act. The court accepted an agreement requiring forfeiture of $8.8336 billion, a $140 million criminal fine and five years of probation. BNP Paribas admitted that, from 2004 through 2012, it knowingly and wilfully moved more than $8.8 billion through the US financial system for sanctioned entities in Sudan, Iran and Cuba, including more than $4.3 billion involving specifically designated entities. The DOJ stated that transactions were structured and concealed to evade detection and that the conduct continued despite warnings from US regulators and other banks. In a parallel New York State proceeding, the bank also pleaded guilty to falsifying business records and conspiracy to falsify business records.

Hypothetical institutional scenario

How might the same control pattern appear?

An institution receives separate warning signals about the same payment practice: a correspondent bank declines a transaction, a regulator asks how messages are formatted, and an internal reviewer identifies routing that obscures the underlying party. Each signal is handled locally and closed. The payment practice continues because no process joins the warnings or requires a single accountable decision on whether it must stop.

Stress-test questions

Questions for challenge and assurance

  1. Risk committee

    Do regulator queries, correspondent-bank refusals and peer warnings trigger a documented investigation, or remain separate items of correspondence?

  2. Operations

    Can the institution evidence who decided that a sanctions-related warning was closed, on what basis and with whose independent challenge?

  3. Audit

    Does sanctions-control assurance test payment content, routing and exceptions for concealment risk, rather than testing only policy and screening-rule configuration?

  4. Board

    Who verifies, after remediation or settlement, that enhanced compliance obligations remain effective in live payment activity?

NFRisk practitioner interpretation

Control implication

External warnings should be treated as control evidence, not background correspondence. A resilient sanctions-control framework connects regulator queries, correspondent-bank refusals and internal findings, assigns an accountable owner, records the basis for closure and independently verifies that remediation remains effective. The relevant risk is not only whether screening rules exist, but whether payment content, routing and exceptions can undermine them.

Framework relevance

Explicitly labelled analytical mappings

NFRisk analytical mapping

Basel event-type lens: Clients, Products & Business Practices

NFRisk maps the admitted sanctions-control circumvention to the Basel event type covering clients, products and business practices. This is an analytical mapping, not a categorisation made by the DOJ.

Sound Practices for the Management and Supervision of Operational Risk · Basel Committee on Banking Supervision
NFRisk analytical mapping

COSO ERM lens: Governance & Culture

NFRisk maps the continuation of conduct despite external warnings to COSO's Governance & Culture component. This is a retrospective analytical mapping, not a DOJ or COSO finding about BNP Paribas.

Enterprise Risk Management - Integrating with Strategy and Performance · Committee of Sponsoring Organizations of the Treadway Commission (COSO)

Evidence register

Primary and supporting sources

  1. US Department of Justice

    BNP Paribas Agrees to Plead Guilty and to Pay $8.9 Billion for Illegally Processing Financial Transactions for Countries Subject to U.S. Economic Sanctions (opens in a new tab) 30 June 2014 · Authoritative primary source
  2. US Department of Justice

    BNP Paribas Pleads Guilty to Conspiring to Violate U.S. Economic Sanctions in Manhattan Federal Court (opens in a new tab) 9 July 2014 · Authoritative primary source
  3. Basel Committee on Banking Supervision

    Sound Practices for the Management and Supervision of Operational Risk (opens in a new tab) 1 February 2003 · Authoritative primary source
  4. COSO

    Enterprise Risk Management - Integrating with Strategy and Performance (opens in a new tab) 1 June 2017 · Authoritative primary source

Publication note

A documented external event—not an NFRisk client engagement.

The named organisations are included because authoritative sources document the event. Their inclusion does not imply that they are or were NFRisk clients, that they endorse this analysis, or that NFRisk participated in the event or response. Framework relevance and NFRisk practitioner interpretation are analytical layers applied after the event.

Return to the Risk Scenario Library

From scenario to mandate

Test the equivalent control assumption in your environment.

NFRisk can use this scenario as a starting point for a focused structural diagnostic, risk-architecture review or delivery-assurance discussion.

Start a conversation