The Strategic Opportunity Hidden in Your Sanctions Compliance Program
-
July 24, 2026
-
There’s an adage about two people fighting over a single orange until they find out that one only wants to eat the fruit and the other just wants to zest the peel. Geolocation data is the same when it comes to compliance: it can satisfy multiple needs with minimal additional effort. Organization-agnostic geolocation controls use geographic signals to help determine where a user or device is physically located. Financial institutions already use geolocation controls as part of their anti-financial crime framework to detect, prevent, or mitigate potentially risky or prohibited activity, just as technology services companies regularly utilize geolocation tools to enforce subscription license agreements or restrict access by unauthorized users.
Geolocation data has long been leveraged for financial crime detection, fraud prevention and access management, yet its use for sanctions compliance has remained narrow in scope, typically limited to preventing access from IP addresses associated with certain sanctioned jurisdictions. This is a reasonable starting point, but it leaves significant capability on the table. Location data collected for purposes of fraud identification, cybersecurity or product analytics often sits unused by compliance teams and is rarely fully operationalized for sanctions compliance.
As sanctions evasion becomes more digitally enabled and harder to detect through traditional controls alone, that gap between potential uses of geolocation data and the current limited reality becomes more consequential.
Regulatory Expectations Are Growing
Although the U.S. Department of the Treasury’s Office of Foreign Assets Control (“OFAC”) had previously remarked on IP address blocking as a sanctions compliance tool – including in FAQ 731 published in 2004 and in a 2020 virtual currency enforcement settlement2 – the 2021 brochure “Sanctions Compliance Guidance for the Virtual Currency Industry” represented the first detailed announcement of expectations around the use of geolocation controls. The document, which remains available and has not been updated, states that institutions should incorporate geolocation tools and IP address blocking, detect virtual public network (“VPN”) usage and IP anonymization techniques, and leverage for compliance purposes any location data in their possession, regardless of why it was originally collected.3 While directed at the virtual currency industry, the underlying principles reflect OFAC’s broader compliance expectations and are equally applicable to any institution within OFAC’s regulatory reach.
Beyond formal guidance, OFAC has used enforcement actions as a signaling tool, publishing detailed settlement agreements that communicate compliance expectations to the wider industry. On geolocation controls specifically, the message is unambiguous: approximately 20 percent of OFAC enforcement actions between 2022 and 2025 cited the absence of, or deficiencies in, geolocation controls as a contributing factor in the violations.4 Across those actions, several recurring themes emerge:
- Available but unused data: Executive releases for several enforcement actions cite the fact that the subject institutions held IP address data but failed to apply it to sanctions screening. One case is a striking example: a payment company processed 12,378 transactions in violation of sanctions despite holding IP data that would have identified the geographic risk.5 The principle OFAC consistently applies is clear: if the data exists, it must be used.
- VPN use: A number of enforcement actions highlight failures to detect VPN usage, which can bypass IP blocking controls. One case is particularly notable: the staff at a virtual currency platform not only failed to detect VPN usage but actively advised users from sanctioned jurisdictions to use VPNs to avoid controls, a significant governance failure.6 Furthermore, in another settlement notice OFAC listed the implementation of VPN detection tooling as a mitigating factor, recognizing this type of capability as a necessary component of effective geolocation controls.7
- Limited scope controls: Several settlements releases highlight as weaknesses programs in which geolocation controls were applied only at customer onboarding and not throughout the customer lifecycle. This is exemplified in a settlement release in relation to a major global cryptocurrency exchange, in which OFAC explicitly warned that “limiting the use of such controls only to the time of account opening – and not throughout the lifetime of the account or with respect to subsequent transactions – could present sanctions risks to virtual currency-related companies.”8 This principle extends beyond cryptocurrency to any customer-facing financial service and certain software and technologies.
- Technical system defects: OFAC’s enforcement actions have also highlighted technical failures that undermined geolocation controls in practice, reinforcing the idea that implementation alone is insufficient without ongoing testing and audits. One enforcement in 2025 on a global electronic brokerage firm documents how a technical bug in the IP geo-blocking system allowed customers in multiple sanctioned jurisdictions to access the platform, a failure OFAC attributed in part to inadequate audit and testing.9 Similarly, 2023 OFAC enforcement on a cryptocurrency platform calls out how automated screening failed to flag Crimea addresses when paired with Russia as country of residence, exposing a logic gap in the screening configuration.10
These enforcements demonstrate that effective controls require not only collecting geolocation data but also integrating the data into compliance processes, preventing circumvention, applying the controls throughout the customer lifecycle, and ensuring technical systems are robust and regularly tested.
Five Actions To Take
The OFAC guidance and enforcement record discussed above translate into a clear set of practical considerations for organizations within OFAC’s regulatory reach.
- Audit your data and how it is used
Organizations should conduct a structured requirements-gathering exercise, including a comprehensive data inventory, to identify what geolocation data is collected, where it resides, and whether and how it’s being used for sanctions compliance purposes. OFAC’s guidance makes clear that the intended purpose of data collection is not a defense for failing to apply it to sanctions risk management. If geolocation data exists within the organization, sanctions compliance teams are expected to use it to identify, assess and mitigate sanctions risk. - Enable data sharing
Geolocation data collected by fraud, cybersecurity or product teams frequently fails to reach the sanctions compliance function. Closing this gap requires both technical integration and organizational alignment. In most organizations, the latter is the harder challenge. Compliance leadership has an important role to play in driving cross-functional data sharing, governance and accountability, as outlined further in the next section. - Treat geolocation as customer data
OFAC’s guidance explicitly lists IP addresses associated with transactions and log-ins as data to be collected and considered part of Know Your Customer (“KYC”) procedures.11 This framing explicitly positions IP geolocation (and implicitly other geolocation data) not as a data point to be used only in a security context but as a core compliance input with the same standing as personal information such as a passport number or physical address, which data is to be collected and monitored on an ongoing basis. - Implement geolocation controls
At a minimum, organizations should implement controls to identify – and prevent where appropriate – access from IP addresses associated with jurisdictions subject to broad sanctions prohibitions. Geolocation controls should also extend to identifying VPN usage and other IP anonymization techniques, which can be used to circumvent geographic restrictions. Blanket blocking of all VPN traffic may not be a proportionate response because there are legitimate reasons for using VPNs. However, organizations should monitor such usage, assess the associated risks, and define clear policies for maintaining compliance within this context.
Beyond IP addresses, organizations should leverage the broader range of location data available through digital channels. Data collected via web and mobile platforms, including GPS coordinates, wi-fi positioning, and cell tower triangulation, can be as useful as IP-based geolocation in determining a user’s physical location. Where such data is available, it should be incorporated into the organization’s sanctions compliance framework to enhance geographic risk identification and escalation. - Incorporate Geolocation in Testing and Risk Assessment
A sanctions compliance program is only as strong as its ability to detect where risk is actually emerging. That means geolocation controls cannot be treated as a one-time implementation exercise. They need to be periodically tested, challenged and assessed as part of the organization’s broader sanctions risk framework. Furthermore, a sanctions risk assessment that does not consider the geographic origins or locations of customers, counterparties and activities is incomplete. As part of the risk assessment, compliance teams should evaluate factors such as:- What is the proportion of customers, users or transactions being connected to locations geographically close to a sanctioned jurisdiction?
- How often are remote access tools such as VPNs or proxies used to conduct transactions or access the organization’s systems or services?
- What controls are in place to identify and investigate such cases?
- Who owns the controls and the testing of such controls?
- Is geolocation data incorporated in KYC and transaction monitoring controls?
Leveraging Geolocation Data as a Unifier
Organizations are required to retain geolocation data for a defined period. For example, OFAC mandates that certain data must be retained up to 10 years.12 Organizations should not see storing this data as merely a regulatory burden or storage cost, but rather as an opportunity to leverage this data to optimize and enhance their first and second lines of defense, and to respond to regulatory outreach.
Geolocation data has a unique value proposition as an organizational unifier. If the marketing department invests significant resources to measure brand presence and geographic market opportunity by tracking customer location, shouldn’t organizations also use the same information to find out which customers are potentially introducing sanctions risk? Fraud, customer operations, compliance and product teams can all rely on this data to improve customer service, analyze behavior, inform product development and enhance first and second line investigations. When operationalized across functions, this data enables organizations to quickly identify potential risk actors, support engagement with regulatory authorities and preserve their duties of safety and soundness.
Unlike many compliance inputs that require complex analysis to build a picture of customer behavior, geolocation signals can be more definitive: a device is either connecting from a sanctioned jurisdiction or it is not. That simplicity makes it a high signal-to-noise input, and one that organizations should leverage alongside other signals. While location spoofing tools are frequently used by individuals and entities involved in sanctions evasion, organizations often already utilize tools and techniques to identify when users may be attempting to hide their true location. Coalescing around geolocation controls across compliance purposes is thus responsive to OFAC guidance that sanctions compliance should be “fully integrated into [an] organization’s daily operations,” and “empower its personnel.”13 Sanctions compliance departments should work with their relevant internal teams to consider how best to share, use, and assign corresponding controls.
Use What You Got To Get What You Want
Geolocation controls are not new technology, nor are they particularly complex. For most organizations, the data already exists, the tooling is already in place, and the fraud and cybersecurity teams are already using it. The sanctions compliance gap is therefore not a technical problem but an organizational one.
OFAC enforcement actions have repeatedly penalized organizations not for lacking data, but for failing to use data they already had. Organizations that have not yet extended geolocation controls beyond basic IP blocking should treat that deficiency as an open risk finding, not as an optional enhancement. And, beyond regulatory requirements and expectations, geolocation controls have a broader purpose: to enable organizations to better serve and protect customers. A sanctions breach that could have been prevented by use of geolocation controls can impact relationships, reputation and trust, not just the bottom line.
Footnotes:
1: “Frequently Asked Questions 73: Compliance for Internet, Web Based Activities, and Personal Communications,” United States Department of the Treasury, Office of Foreign Assets Control (April 13, 2004)3.
2: “OFAC Enters Into $98,830 Settlement with BitGo, Inc. for Apparent Violations of Multiple Sanctions Programs Related to Digital Currency Transactions,” United States Department of the Treasury (Dec. 30, 2020).
3: “Sanctions Compliance Guidance For The Virtual Currency Industry,” United States Department of the Treasury, Office of Foreign Assets Control (Oct. 2021), 14.
4: A total of 11 out of 53 OFAC enforcement actions between 2022 and 2025, per FTI Consulting analysis based on OFAC enforcement data available here.
5: “OFAC Settles with daVinci Payments for $206,213 Related to Apparent Violations of Multiple Sanctions Programs,” United States Department of the Treasury (Nov. 6, 2023).
6: “Settlement Agreement between the U.S. Department of the Treasury's Office of Foreign Assets Control and Exodus Movement, Inc.,” United States Department of the Treasury, Office of Foreign Assets Control (Nov. 18, 2025).
7: “OFAC Settles with CoinList Markets LLC for $1,207,830 Related to Apparent Violations of the Ukraine-/Russia-Related Sanctions Regulations,” United States Department of the Treasury (Dec. 13, 2023).
8: “OFAC Settles with Virtual Currency Exchange Kraken for $362,158.70 Related to Apparent Violations of the Iranian Transactions and Sanctions Regulations,” United States Department of the Treasury (Nov. 28, 2022).
9: “Interactive Brokers LLC Settles with OFAC for $11,832,136 Related to Apparent Violations of Multiple Sanctions Regulations,” United States Department of the Treasury, Office of Foreign Assets Control (July 15, 2025).
10: “OFAC Settles with CoinList Markets LLC for $1,207,830 Related to Apparent Violations of the Ukraine-/Russia-Related Sanctions Regulations,” United States Department of the Treasury (Dec. 13, 2023).
11: “Sanctions Compliance Guidance For The Virtual Currency Industry,” United States Department of the Treasury, Office of Foreign Assets Control (Oct. 2021), 14 - 15.
12: OFAC's recordkeeping requirements under 31 CFR § 501.601 require any person engaging in a transaction subject to OFAC's regulations to maintain a full and accurate record of each such transaction available for examination for at least 10 years, as per the Code of Federal Regulations available here.
13: “A Framework for OFAC Compliance Commitments,” United States Department of the Treasury (May 2, 2019).
Related Insights
Related Information
Published
July 24, 2026
Key Contacts
Senior Managing Director
Managing Director
Managing Director
Senior Director