ClickCease

Something we said? Don’t leave just yet!

For more information about latest events, news and insights, leave us your email address below.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form
Dismiss

Operation Economic Outcast: what compliance teams must action

Michael Joseph on what the US Department of the Treasury's Iran campaign and the Banque Misr UAE proposal actually require from sanctions screening controls and compliance programs.

Michael Joseph
September 6, 2026

On August 24, the US Department of the Treasury launched Operation Economic Outcast, a whole-of-government campaign against Iran and the foreign businesses that help it trade, move money, procure technology, and sell oil. Four days later, the Financial Crimes Enforcement Network (FinCEN) proposed cutting the United Arab Emirates (UAE) branches of Banque Misr out of US correspondent banking. Neither is the kind of event a sanctions list update prepares teams to manage.

What Treasury actually did

Treasury designated around sixty entities and vessels across Hong Kong, mainland China, Malaysia, Singapore, the UAE and other third countries for facilitating Iran-related sanctions evasion, and exposed five sectors of the Iranian economy to sanctions: aviation, digital assets, gold, shipping and technology.

That is not a blanket sanction on those sectors. It is an authority to designate persons determined to operate in them, which sharply raises secondary-sanctions risk for non-US parties. The authorities themselves are not new. What changed is that they are being used together, and pointed at foreign enablers rather than at Iranian entities alone.

Treasury Secretary Scott Bessent put it plainly: “Any entity that facilitates money laundering on behalf of Iran will be removed from the US dollar system. The clock just started ticking.” The target is the intermediary, not the endpoint.

Translating the action into screening configurations

FinCEN found Banque Misr's five UAE branches to be of primary money laundering concern under section 311 of the USA PATRIOT Act, and proposed prohibiting US institutions from maintaining correspondent accounts for them, including indirectly through another foreign bank. Treasury says the branches processed roughly $1.8 billion (USD) involving 103 companies between January 2024 and June 2026, activity it links to Iranian shadow banking and to procurement for Iran's Ministry of Defense and the Islamic Revolutionary Guard Corps.

The finding is current, but the restriction is a proposal that has to be finalized before it takes effect. It covers five UAE branches, not Banque Misr everywhere, so a control reading only an institution name will either miss those branches or halt activity the rule never touched. And the bank was never added to the US blocking list: FinCEN used a separate authority to reach a similar outcome, so a name run against the Specially Designated Nationals (SDN) list would have surfaced none of this. A bank does not need to be listed to become a control problem.

Foreign enablers operate through third countries by design, so an Iran connection is far more likely to sit in ownership structures, correspondent chains, vessel and port records, wallet addresses or payment narrative than in a name you are screening. Name screening remains necessary; treating it as sufficient is how institutions end up surprised by their own data. Equally, an indicator is not proof of a violation. An Iranian sector or geographic signal justifies review, not an assumption that activity was prohibited or that a customer should be exited.

4 considerations for screening technology

Can it identify the correct entity and branch?

One institution maps to several legal names, bank codes, branch addresses, and routing details. You should be able to say which of those your controls read, and who maintains them.

Can it see the whole payment chain?

A restricted bank can reach a payment through a foreign correspondent rather than a direct relationship, so screening has to consider sending, receiving and intermediary institutions, not customer names alone.

Does it process the geography you already hold?

Geography turns up in identity documents, addresses, bank and card codes, ports, shipping records and free-text payment fields. Data providers supply sanctions names and identifiers; none supplies a file telling your institution which countries, sectors and products to restrict. A current vendor feed is not evidence of control coverage, because a screening system can only test the data and rules it receives.

Can investigators connect the facts, and search history?

Today's permitted counterparty is tomorrow's designation, so searching past activity by name, branch code, address, owner and payment data — and explaining the scope of that search — is the difference between answering an examiner and reconstructing a story across systems.

3 learnings for screening programs

Start with actual exposure rather than the headline.

No two institutions are exposed the same way, so each should identify the customers, products, countries, channels, sectors and third parties that could connect it to this activity, and write that down.

Test from the source data, not from the alert.

Alert testing shows whether investigators handled the alerts they received. It says nothing about data that never reached the screening system and so never created an alert. Tracing representative fields from source to control is stronger evidence of operating effectiveness than alert counts. While you are there, establish how quickly a control can actually change: if adding an identifier means a vendor change request measured in weeks, that is your real response time to the next action.

Keep the decision record.

Leaving the program unchanged can be entirely reasonable. It is only defensible if you retained the facts considered, the tests performed, the limitations found, the decision, its owner and the follow-up actions.

What to expect next from U.S. Treasury

Treasury has indicated that further bank actions will follow quickly, and the UAE measure reads as the first of a series. When the next one lands, look at the authority used, the operations covered, and the target's role in global payments. Those three things determine what you have to do.

The question worth rehearsing now is the one an examiner will ask: can your institution show what it assessed, what it tested, what it found, and why it decided to change (or not change) its program?

For a detailed look at contextual name matching, multi-configuration and real-time screening, download the white paper:

The Power of Multiconfiguration: Why smarter configuration, not AI clean-up, is the key to reducing false positives in screening
Michael is a Certified Anti-Money Laundering Specialist and Financial Crimes Compliance expert with 10+ years of experience leading teams and projects focused on designing, enhancing and implementing innovative AML and Sanctions compliance strategies. Previous roles include advisory and consulting services at Grant Thornton and KPMG as well as investigations work at SCB and JPMC.