Skip to content

Regulation

Iran Sanctions Legal Compliance Starts With Your Own Firm

By Editorial TeamUpdated Aug 25, 2026
Authority
U.S. Treasury OFAC
Rule type
regulation
Jurisdiction scope
US federal
Source text
Read primary rule text ↗

Law firms must document the specific authorized legal-service category, verify fee-payment authorization, and ensure any Iran-related due diligence does not itself violate the ITSR.

The matter usually arrives already softened by business language: a long-standing client, an Iran-adjacent transaction, a narrow request for sanctions advice, a partner who says the firm will not touch the underlying deal. That is the wrong place to relax. The Iran sanctions legal compliance implications start with the firm’s own conduct: opening the file, screening the client and related parties, accepting money, instructing local fact-gatherers, reviewing Iranian-source documents, and deciding whether someone must report a blocked or rejected transaction.

Modern law firm intake area with legal files passing through a security screening checkpoint

A law firm is not outside the sanctions system merely because it is advising on sanctions. If it is a U.S. person, it is a regulated participant. If it provides legal services involving Iran, it is relying on a limited authorization. If it collects fees, the payment path has to stand on its own. If it performs diligence in or with Iran, the diligence may itself become the transaction OFAC cares about.

The first source text a firm should put on the matter-opening record is 31 CFR § 560.525. It authorizes specified categories of legal services involving Iran, including advice on U.S. legal compliance and representation in certain U.S. or international proceedings. That matters because the regulation gives real room for legal representation; it is not a prohibition dressed up as permission. But it also matters because the permission is bounded. The firm has to identify the service it is actually providing and keep the file from sliding into business support, transaction execution, or unlicensed facilitation under the cover of legal advice.[1]

That distinction can sound fussy until the engagement starts to move. A sanctions memorandum may require interviews, records collection, counterparties’ ownership information, payment histories, or local verification. A pleading may require evidence gathering. A compliance review may require vendor checks. Each step should be tested against the authorization, not merely against the engagement letter’s label.

For risk and knowledge-management staff, the useful question is not whether the partner can describe the work as “legal.” It is whether the file shows which authorized legal-service category covers the work and where the category stops. Section 560.525 is a permissioning rule, not a firmwide comfort letter.

Fee receipt needs its own answer

The fastest way an otherwise careful Iran matter becomes administratively ugly is the retainer. Section 560.525 itself points away from treating legal-services authorization as fee authorization: payment of professional fees and reimbursement of expenses from blocked persons require separate authority, including under § 560.553 or a specific license where applicable.[1]

That means the intake memo should not stop at “sanctions advice authorized.” It needs to say who will pay, where the funds will originate, which bank will process the payment, whether any blocked person is involved, and what the firm will do if the payment is blocked or rejected. OFAC states that it may impose civil penalties on a strict-liability basis, and its Iran FAQ material identifies 10-day blocking and reporting duties for U.S. persons, as well as 10-day rejection and reporting duties for financial institutions in the covered circumstances.[2]

Nor is legal-fee handling a dormant corner of the rules. OFAC’s Civil Penalties and Enforcement Information page records a 2024 final rule updating authorizations for payments for legal services.[3] The practical lesson is modest but important: fee mechanics are not back-office cleanup after the legal analysis. They are part of the sanctions analysis.

Partner assumptionRisk-review correction
The work is authorized because it is sanctions advice.Identify the specific § 560.525 legal-service category and document why the actual work stays inside it.
The client can pay the retainer if the representation is allowed.Analyze the payor, source of funds, bank path, blocked-person status, and whether § 560.553 or a specific license is needed.
Compliance diligence is protective.Check whether the diligence requires services, verification, or payments in or with Iran.
The bank will catch any problem.The firm still needs its own screening, escalation, and reporting process.

The IPSA settlement is the due-diligence warning firms should not skip

The IPSA International settlement is not new 2026 law. It is older than many current Iran briefings. That is why it is useful: it is not a reaction to this quarter’s political pressure, and it does not depend on a broad “gatekeeper” theory. It shows how ordinary compliance work can become the prohibited activity.

In 2017, IPSA International Services settled with OFAC for $259,200 over 72 apparent violations involving due-diligence work connected to Iran. Akin Gump’s analysis of the settlement emphasizes three uncomfortable points for U.S. companies and advisers: due diligence requiring verification inside Iran was treated as importing Iranian-origin services, benefit to the U.S. parent mattered, and payments approved by the U.S. parent created facilitation exposure.[4]

That is exactly the kind of fact pattern that can hide inside a law-firm matter. A client asks for sanctions diligence on an Iranian counterparty. The firm wants confirmation from someone local. A third-party investigator, affiliate, consultant, or vendor is asked to verify facts in Iran. Someone approves an invoice. The work product comes back to the U.S. team and is used to advise the client. The file may look compliance-minded, but the steps require separate sanctions analysis.

The point is not that every Iran-related factual inquiry is prohibited. The point is that the compliance purpose does not immunize the mechanism. If the firm’s diligence depends on Iranian-origin services, Iranian in-country verification, or U.S.-approved payments for prohibited activity, the firm needs to know before the instruction goes out, not when an invoice reaches accounts payable.

Workflow diagram showing intake, payment, due diligence, and reporting nodes

Gatekeeper pressure is real, but it is not the whole analysis

There is a current enforcement reason not to treat law firms as observers. Paul Weiss, writing in Corporate Compliance Insights on OFAC sanctions enforcement in 2025–26, identifies a pattern of attention to non-bank gatekeepers, including private equity, real estate actors, and attorneys. The same discussion notes OFAC’s skepticism toward formal ownership legal opinions where the surrounding control or benefit facts do not support the conclusion, and uses the IMG Academy matter to illustrate that “predominantly domestic” businesses can still carry sanctions risk.[5]

That enforcement climate should make partners more careful, but it should not replace the regulatory work. “Gatekeeper” is a pressure term, not an authorization test. A law firm still needs the quieter answers: which service is authorized, which payment is authorized, which parties were screened, which diligence steps involved Iran, and which report was made if property was blocked or a transaction rejected.

Where the exposure moves inside the firm

Iran matters rarely stay with the lawyer who first describes them. They move through conflicts, risk, finance, billing, records, knowledge management, vendors, and sometimes outside counsel or local contacts. Each handoff can either preserve the authorization analysis or erase it.

Intake and screening

The client name is only the start. Conflicts and intake should capture beneficial owners, controllers, payors, affiliates, counterparties, proposed local agents, banks, and any person expected to provide information from Iran. The firm should screen before the engagement letter is issued and again when new parties appear. A blocked-party hit is not a partner-service issue; it is a legal and reporting issue, and OFAC’s strict-liability posture leaves little room for “the client told us it was fine” as an internal control.[2]

For firms that already use sanctions checklists in insurance, shipping, or energy matters, the same discipline belongs in legal intake. The prior Hormuz insurers screening checklist is a useful analogy: do not screen only the visible contracting party when the risk often sits in ownership, control, routing, or service providers.

Payment and retainer handling

Finance needs the same facts risk reviewed. If the file says the firm may advise under § 560.525, finance still needs to know whether the payor is blocked, whether payment from that payor is separately authorized, whether the payment path involves a blocked bank, and whether rejected or blocked funds trigger reporting. A retainer sitting in suspense while lawyers continue working is not a neutral event if no one has decided whether the funds may be accepted.

The billing lawyer should not have to reconstruct the sanctions analysis from scattered emails. The matter record should identify the approved payor, approved route, licensing basis if needed, and escalation owner if the payment does not process as expected.

Compliance work and factual verification

This is where IPSA has the most practical bite. A firm may think it is reducing sanctions risk by asking for more facts. Sometimes that is true. Sometimes the method of getting the facts creates a new sanctions question. Before anyone instructs an investigator, local affiliate, consultant, translator, document collector, or technical verifier, the firm should ask whether the person will perform services in Iran, obtain Iranian-origin services, deal with a blocked person, or require a U.S. person to approve payment connected to prohibited activity.[4]

A careful file does not need theatrical language. It needs a short record showing who requested the diligence, what facts were needed, who would gather them, where the work would occur, how the vendor would be paid, and why the route was authorized. If the answer is uncertain, the work should stop long enough for a licensing or no-go decision.

Current Iran pressure is context, not a substitute for authorization

The broader 2026 Iran sanctions cycle matters because it creates more urgent client calls, more proposed workarounds, and more pressure on firms to answer quickly. Prior analysis of U.S.–Iran sanctions and oil-market disruption and Hormuz-related sanctions exposure gives that commercial setting. But a market shock, a wind-down issue, or a political announcement does not change the firm’s need to identify the operative legal authority for its own acts.

The same caution applies to U.S.–Iran political framework material. King & Spalding’s discussion of the U.S.–Iran memorandum of understanding treats the MOU as a political framework, not an operative legal authorization. It also flags the separate constraint created by the IRGC’s status as a Foreign Terrorist Organization, including potential extraterritorial criminal and civil exposure under 18 U.S.C. § 2339B.[6]

That outer boundary matters for lawyers who otherwise find comfort in § 560.525. A legal-services authorization under the Iran sanctions regulations should not be treated as permission to provide material support or to ignore separate terrorism-law constraints. Some matters need to be declined even if part of the requested work sounds like authorized representation.

What should be in the file before the firm says yes

A partner briefing does not need to rehearse the entire history of Iran sanctions. It needs enough structure to prevent the firm from accepting a matter on one authorization while violating another rule through the payment path or diligence plan.

  • Authorized service: identify the § 560.525 category and describe the actual work the firm will perform.
  • Excluded work: state what the firm will not do, including transaction execution, unlicensed facilitation, or business services outside the legal-services lane.
  • Fee path: identify the payor, source of funds, banks, blocked-person analysis, and whether § 560.553 or a specific license is required.
  • Screened parties: record screening for the client, owners, controllers, affiliates, payors, counterparties, vendors, and any local fact-gatherers.
  • Diligence route: state whether any verification, investigation, translation, collection, or vendor work will occur in or with Iran.
  • Reporting owner: assign responsibility for blocked-property or rejected-transaction escalation and reporting if a problem appears.
  • Refresh trigger: require renewed review when a new payor, bank, counterparty, vendor, or factual-verification method is introduced.

The last item is often the one that saves the file. Iran matters change as they are staffed. A clean opening memo can become stale when the client proposes a different affiliate as payor, when a vendor offers to verify facts locally, or when a newly identified counterparty screens differently from the original client contact.

The firm’s exposure is not outsourced to the client relationship. The regulated acts are the firm’s own: providing the service, accepting the fee, using the vendor, approving the diligence route, handling blocked or rejected funds, and keeping the record that explains why each step was permitted.

References

  1. 31 CFR § 560.525 - Provision of certain legal services, Cornell Legal Information Institute
  2. OFAC Iran Sanctions FAQ topic 1551, U.S. Department of the Treasury Office of Foreign Assets Control
  3. Civil Penalties and Enforcement Information, U.S. Department of the Treasury Office of Foreign Assets Control
  4. OFAC Puts Companies on Notice: Due Diligence in Iran Can Trigger Sanctions Violations, Akin Gump
  5. The State of OFAC Sanctions Enforcement in 2025-26, Corporate Compliance Insights
  6. U.S. Sanctions Implications of the U.S.–Iran Memorandum of Understanding, King & Spalding

Operationalizing workflow

No workflow has been explicitly linked to this obligation yet. See Workflows generally.

Illustrative cases

No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.

← Back to Regulation

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →