Napier AI flags sanctions screening flaws after Treasury’s Iran push

The US Department of the Treasury opened Operation Economic Outcast on 24 August, a government-wide push against Iran and the foreign firms helping it trade, move funds, source technology and sell oil.

Four days on, the Financial Crimes Enforcement Network (FinCEN) moved to cut the UAE branches of Banque Misr out of US correspondent banking altogether. According to analysis from Napier AI, neither move is the sort of update that a routine sanctions list refresh leaves compliance teams ready for.

Treasury named around sixty entities and vessels spanning Hong Kong, mainland China, Malaysia, Singapore, the UAE and other third countries for enabling Iran-related sanctions evasion, while opening up five sectors of Iran’s economy, aviation, digital assets, gold, shipping and technology, to further designations.

Napier AI notes this isn’t a blanket sectoral sanction; it’s an authority to pursue anyone operating within them, which sharply raises secondary-sanctions exposure for non-US firms. Treasury secretary Scott Bessent said, “Any entity that facilitates money laundering on behalf of Iran will be removed from the US dollar system. The clock just started ticking.”

FinCEN separately found Banque Misr’s five UAE branches to be of primary money laundering concern under section 311 of the USA PATRIOT Act, proposing to bar US institutions from holding correspondent accounts for them, directly or through another foreign bank. Treasury links roughly $1.8bn processed through those branches between January 2024 and June 2026 to Iranian shadow banking and procurement tied to Iran’s Ministry of Defense and the Revolutionary Guard Corps. Critically, Napier AI points out that Banque Misr was never added to the SDN list, so name-only screening against that list would have caught none of it.

For screening programmes, Napier AI flags four practical tests: can the system pinpoint the correct entity and branch, rather than just an institution name; can it trace a full payment chain including correspondent banks, not just customers; does it actually process the geography already sitting in existing data, since no vendor feed tells a firm which countries or sectors to restrict; and can investigators search historical activity by branch, address, owner and payment data quickly enough to answer an examiner.

Napier AI also underscores three broader lessons: map actual exposure rather than reacting to headlines, test controls from source data rather than from generated alerts, since untested data creates no alert at all, and keep a documented decision record even where a programme stays unchanged.

For more, read the full story here.

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.