OFAC case shows why sanctions checks cannot stop at the distributor
An OFAC settlement involving indirect exports through a UAE distributor shows how end-user, destination and subsidiary risks can sit beyond the immediate counterparty.

What happened
The US Office of Foreign Assets Control has announced a $60,764 settlement with Rice Lake Weighing Systems over eight apparent violations of sanctions on Iran. The case involved the company’s Italian subsidiary, Dini Argeo, selling equipment worth approximately $121,527 to a distributor in the United Arab Emirates between June 2019 and November 2021, with the goods ultimately destined for an Iranian end user.
The Iranian company was not identified as the final recipient in the sales documents. However, its employees continued to contact the Italian subsidiary with product and technical questions, their email signatures referred to Iran, and the UAE distributor eventually confirmed the intended destination.
Rice Lake had informed its subsidiary that transactions involving Iran were prohibited after a previous authorisation was revoked. According to OFAC’s enforcement release, the company did not take sufficient steps to explain how the restrictions applied to indirect sales, confirm that the subsidiary understood them or monitor adherence. Rice Lake stopped the sales after receiving a tip, investigated and voluntarily disclosed the matter. OFAC classified the case as non-egregious.
Why it matters for KYB teams
Screening the immediate customer would not necessarily have revealed the full exposure in this case. The distributor was located in the UAE; the sanctions risk arose from the destination and end user beyond it.
For businesses using distributors, resellers or agents, KYB needs to establish more than legal identity. The customer’s role in the supply chain, expected markets, product use and relationships with other parties may become material when the goods, geography or business model create a meaningful diversion risk.
The evidence may also sit outside the onboarding file. Here, the sales documents did not name the Iranian recipient, while commercial correspondence and technical-support interactions pointed to the destination. A useful control has to connect those signals and escalate contradictions rather than treating each system as a separate record.
The case also illustrates the difference between issuing a group policy and making it work inside a subsidiary. Local procedures, training, language, monitoring and testing need to reflect how employees actually sell, support and ship products. Because sanctions restrictions can change, affected relationships may also need to be re-screened and reviewed when the rules or risk context changes.
This does not mean every distributor requires full end-user verification. It means the workflow should define when jurisdiction, product and distribution risk make that information necessary.
What teams should review
- Does onboarding distinguish distributors, resellers, agents and end customers rather than treating every counterparty the same?
- When diversion risk is elevated, does the workflow capture expected destination, end user and end use?
- Are all relevant parties screened when the risk assessment requires checks beyond the immediate customer?
- Can conflicts between declarations, invoices, shipping information, commercial correspondence and support activity trigger review?
- Have foreign subsidiaries translated group sanctions policies into local procedures, training and escalation paths?
- Do sanctions changes trigger rule updates, re-screening and documented review of affected relationships?




