Skip to content

Regulation

Who does the US legal framework for Iran sanctions bind?

By Editorial TeamUpdated Aug 25, 2026
Authority
U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Rule type
regulation
Jurisdiction scope
US federal
Effective date
Aug 24, 2026
Source text
Read primary rule text ↗

Verify US nexus, ownership/control, and license status under layered Iran sanctions authorities.

Current through August 26, 2026. This is a US-framework-only obligations map for Iran sanctions compliance. It is not legal advice, and it does not try to summarize every Iran-policy development. The working question is narrower and more useful: who is bound, by which authority, and through what US nexus?

The first error to remove is the sentence “Iran sanctions prohibit…” as if one rule covers every actor. A US parent, its non-US subsidiary, a foreign bank, a freight forwarder, and an importer into the United States may all be looking at Iran risk, but not necessarily at the same legal hook. Screening against the SDN List is only one part of the answer.

Layered legal authority stack connected to different corporate, banking, personal, and logistics actors

Start with the stack, not the slogan

OFAC’s current Iran sanctions page identifies four Iran-specific parts of Title 31, Chapter V of the Code of Federal Regulations: Part 535, Part 560, Part 561, and Part 562. That same program page also records the August 24, 2026 EO 13902 sector determination and the related general-license actions that now have to be tracked with the regulations rather than remembered as an alert in someone’s inbox.[1]

LayerWhat it does in the Iran frameworkTypical compliance question
IEEPA-based executive ordersDeclare and expand national-emergency authorities; create blocking authorities, sector authorities, and, in 2026, a tariff track.Which EO or determination applies, and did it change the conduct or sector being reviewed?
Congressional statutesAdd statutory sanctions architecture, including secondary-sanctions authorities and humanitarian/export-control carveout structures.Does a non-US party face exposure even where the ITSR does not directly prohibit its conduct?
OFAC regulationsTurn authorities into administered prohibitions, licensing rules, definitions, and recordkeeping expectations.Which CFR provision binds this entity or transaction?
OFAC licenses, determinations, FAQs, and designationsModify the practical answer for specific activities, sectors, parties, or time windows.Was the license, sector determination, or party status checked at source level on the date of action?

For most company-level analysis, 31 CFR Part 560 — the Iranian Transactions and Sanctions Regulations, or ITSR — is the core operating text. It is not the whole Iran sanctions program. It is, however, where a large share of direct OFAC-administered prohibitions, definitions, licensing rules, and foreign-subsidiary obligations sit.[2]

Part 535, Part 561, and Part 562 should not disappear from the register just because Part 560 is doing most of the daily work. Part 535 relates to Iranian assets control; Part 561 addresses Iranian financial sanctions; Part 562 covers Iranian human rights abuses sanctions. OFAC lists all four under the Iran program, which is the practical reason an obligations register should not label “Iran” as a single Part 560 issue.[1]

The Congressional Research Service has described US Iran sanctions as “arguably the most extensive and comprehensive set of sanctions that the United States maintains on any country.” That is a useful warning label, but it is not an answer to a business team. The answer still has to be built from authority, covered person, covered conduct, and license status. The CRS version used here was accessed through LegiStorm because the congressional source could not be verified for this record.[4]

The ITSR binds by person, place, ownership, and transaction

Part 560 does not ask only whether Iran is somewhere in the commercial chain. It asks who is acting, where the conduct occurs, whether a US person is involved, whether property is blocked, whether a foreign entity is owned or controlled by a US person, and whether someone is trying to evade or cause a violation. Those distinctions are not academic. They decide whether the company has a direct prohibition problem, a licensing problem, a secondary-sanctions problem, a customs/tariff problem, or a risk that sits outside the US framework altogether.

Actor or nexusPrimary ITSR hook to checkCompliance consequence
US persons, wherever locatedPart 560 prohibitions, including import, export, reexport, services, facilitation, blocked-property, and evasion provisions.Treat the transaction as directly within OFAC’s administered rule set unless an exemption or license applies.
A person physically in the United StatesUS-place nexus under Part 560.Do not assume non-US citizenship or foreign incorporation removes the prohibition if the conduct occurs in the United States.
A non-US entity owned or controlled by a US person31 CFR 560.215.Review whether the foreign entity is knowingly engaging in conduct involving Iran or the Government of Iran that would be prohibited if performed by a US person or in the United States.
A non-US counterparty using US goods, technology, services, banks, staff, or infrastructureExport/reexport, causing, facilitation, evasion, and blocked-property provisions depending on the facts.Map the US nexus before deciding the transaction is “foreign-to-foreign.”
A transaction involving the Government of Iran or an Iranian financial institution31 CFR 560.211 and related blocking provisions.Determine whether property or interests in property must be blocked when they come within the United States or within the possession or control of a US person.
A non-US party with no obvious US transaction nexusUsually outside direct ITSR prohibitions, but not necessarily outside US sanctions exposure.Check secondary-sanctions statutes, EO 13846, EO 13902, CAPTA-related risks, designations, and sector determinations.

The core prohibitions are not one prohibition

The provisions clustered in 31 CFR 560.201 through 560.215 do different work. Some address importation of Iranian-origin goods and services. Some address exportation, reexportation, sale, or supply of goods, technology, or services to Iran or the Government of Iran. Others address facilitation, blocked property, evasion, and foreign entities owned or controlled by US persons. A register that collapses them into “Iran embargo” will miss the very distinctions that decide who is bound.[2]

For a US company, the familiar baseline is broad: direct and indirect dealings with Iran, the Government of Iran, Iranian-origin goods or services, exports and services to Iran, and facilitation of transactions by non-US persons must be tested under Part 560 before the business asks whether the deal is commercially sensible. The legal issue comes first because a transaction that looks operationally remote may still be close enough to US staff, US systems, US-origin items, or US approval rights to trigger the rule.

Section 560.203 is the provision that makes many “workaround” conversations dangerous. It prohibits transactions that evade or avoid, have the purpose of evading or avoiding, cause a violation of, attempt to violate, or conspire to violate the prohibitions in Part 560. That is where an instruction, approval, routing choice, documentation change, or payment structure can become the problem even when the nominal contracting party is outside the United States.[2]

Section 560.211 is a separate blocking rule. It blocks property and interests in property of the Government of Iran and Iranian financial institutions when that property or interest is in the United States, comes within the United States, or comes within the possession or control of a US person, including a foreign branch. That is not the same compliance task as deciding whether an export to Iran is prohibited. It requires property-interest analysis, counterparty classification, and escalation procedures for blocked or rejectable transactions.[2]

Section 560.215 is the provision that prevents a US group from ending the analysis at the parent-company border. It prohibits an entity owned or controlled by a US person and established or maintained outside the United States from knowingly engaging in transactions, directly or indirectly, with the Government of Iran or any person subject to the jurisdiction of the Government of Iran, if the transaction would be prohibited by Part 560 if performed by a US person or in the United States.[2]

That rule is the reason a foreign subsidiary’s local-law permission is not enough. The relevant compliance file needs ownership and control analysis, not just sanctions screening. Who appoints management? Who approves budgets? Who controls policy? Who provides shared services? The answers may be more important than the subsidiary’s place of incorporation.

Secondary sanctions sit beside the ITSR

The secondary-sanctions layer is not simply Part 560 with a broader mood. It is a different kind of US pressure tool. It can target non-US persons for specified conduct even when the underlying conduct is not directly prohibited for that non-US person under the ITSR. CNAS describes the US secondary-sanctions architecture for Iran as involving statutory and executive-order tools including the Iran Sanctions Act, CISADA, the Iran Threat Reduction and Syria Human Rights Act, EO 13846, EO 13902, and correspondent-account or payable-through-account restrictions commonly discussed as CAPTA measures.[5]

That distinction matters in contract review. If a non-US bank is financing a non-US customer’s Iran-related activity with no US persons, no US goods, no US services, and no US clearing path, the ITSR question may not be the only or even the main question. The review still has to ask whether the conduct falls into a sanctionable sector, supports a sanctioned party, involves an Iranian financial institution, or creates exposure to correspondent-account restrictions or designation risk.

The practical compliance problem is sequencing. First, test direct prohibitions: US person, US location, US-origin item, US service, facilitation, blocked property, foreign-subsidiary rule. Then test secondary exposure: sector, counterparty, financial institution, material support, and statutory or EO authority. Mixing those two steps produces bad advice in both directions — either overclaiming that US law directly prohibits a foreign party’s conduct, or underclaiming that the conduct is irrelevant because no US person signs the contract.

For related cross-border mapping problems, the same discipline appears in the site’s separate records on Iran snapback response, law-firm ITSR exposure, and Strait of Hormuz sanctions exposure. Those records are adjacent; they do not replace the US-only statutory and CFR map here.

The 2026 changes belong in the obligations register, not in a news folder

Minimal 2026 sanctions timeline with nodes for tariff, determination, and license changes

Two 2026 developments are enough to disprove the comfortable assumption that the Iran framework is static.

First, EO 14382 was issued on February 6, 2026, took effect on February 7, 2026, and was published in the Federal Register on February 11, 2026. It added a tariff track under IEEPA for threats attributed to the Government of Iran. For compliance purposes, the important point is not to treat that measure as just another OFAC list update. It affects import-facing analysis and therefore has to be owned with customs, trade compliance, procurement, and finance. The 25 percent duty language in the Federal Register text should be read carefully in context rather than converted into a universal fixed-rate shorthand.[3]

Second, OFAC’s Iran page records an EO 13902 sector determination effective August 24, 2026, identifying the aviation, digital asset, gold, shipping, and technology sectors of the Iranian economy. The same OFAC update records Iran General Licenses AA and BB and the suspension of Iran General Licenses F and G. Those are not decorative developments. They change what a live review has to verify before approval, rejection, blocking, reporting, or escalation.[1]

A business team may experience those changes as one headline: “Iran sanctions tightened.” The obligations register cannot. EO 14382 raises an import/tariff question. The EO 13902 determination raises a sector-exposure question. General licenses raise authorized-conduct and timing questions. Suspended licenses raise reliance and wind-down questions. They belong in different fields of the same record.

2026 itemWhat to trackWho needs to be in the review
EO 14382 tariff trackEffective date, covered imports, duty mechanism, customs instructions, and whether the item is a product of Iran.Customs, trade compliance, procurement, tax/finance, sanctions counsel.
August 24, 2026 EO 13902 sector determinationWhether the activity touches aviation, digital asset, gold, shipping, or technology sectors of the Iranian economy.Sanctions counsel, business owner, third-party risk, logistics, treasury.
Iran GL AA and GL BBAuthorized activities, conditions, parties, dates, reporting or recordkeeping requirements, and whether the license text has been pulled from the source.Legal, compliance operations, business approver, records owner.
Suspension of Iran GL F and GL GWhether any workflow, template, payment, or customer communication still assumes the suspended authorization is available.Legal, compliance operations, sales operations, finance, systems owner.

The license point deserves a small procedural irritation. A law-firm alert may be the fastest way a company learns that a general license changed. It should not be the final source in the approval file. If the transaction depends on GL AA, GL BB, or the status of GL F or GL G, the file should contain the OFAC source text or a source-level citation, not only a summary.

What a compliance program has to maintain

OFAC’s 2019 Framework for OFAC Compliance Commitments identifies five essential components of a sanctions compliance program: management commitment, risk assessment, internal controls, testing and auditing, and training. Those components are often repeated as a checklist. For Iran, they have to be translated into source-level work because the risk is not merely that a name was missed; it is that the wrong layer was checked.[6]

Source-level tracking

The obligations register should identify the source type for each rule: statute, executive order, CFR provision, OFAC determination, OFAC general license, OFAC FAQ, designation record, or customs instruction. A field labeled “Iran sanctions” is not enough. The record should also show last-verified date, source URL, effective date, internal owner, affected business process, and whether the rule is direct, secondary, blocking, licensing, reporting, or tariff-related.

US-nexus analysis

Every Iran review should force the US-nexus question into writing. Is there a US person? Is someone acting in the United States? Are US-origin goods, technology, or services involved? Is a US bank, server, approval chain, employee, agent, or shared-services function involved? Is the company asking a US person to approve, support, finance, insure, ship, amend, or conceal something? If the answer is yes, the review stays in the direct-prohibition lane until the relevant Part 560 provisions have been cleared.

Ownership and control review

For multinationals, the register needs an entity map that can be used without rebuilding the corporate chart for every transaction. The § 560.215 question is not answered by the subsidiary’s brand name. It is answered by ownership, control, establishment or maintenance outside the United States, knowledge, and whether the conduct would be prohibited if done by a US person or in the United States.[2]

General-license monitoring

A general license is not a permanent comfort letter. It has text, conditions, dates, covered parties, exclusions, and sometimes reporting or recordkeeping obligations. The 2026 GL AA and GL BB actions, and the suspension of GL F and GL G, are a reminder that license reliance has to be monitored after the first approval. Templates, ERP flags, payment instructions, and customer-facing guidance should be updated when a license changes, not after the next blocked transaction review.[1]

Sector-determination updates

Sector determinations need their own watch process because they can change the risk profile of conduct that is not captured by a simple party-screening result. After the August 24, 2026 determination, aviation, digital asset, gold, shipping, and technology touchpoints in Iran-related activity require a more careful sector analysis under EO 13902 authorities.[1]

Enforcement-learning review

Enforcement examples are useful when they are kept in the right place. They should test whether management commitment, risk assessment, controls, auditing, and training are working in practice. They should not be used as substitutes for the actual prohibition. Recent practitioner discussions of Iran-related enforcement have emphasized familiar control failures: under-resourced compliance ownership, weak escalation paths, incomplete subsidiary oversight, and payments or services moving through US touchpoints. Before penalty figures or settlement terms are reused in a board paper, they should be rechecked against the underlying OFAC release PDFs.

Record-level verification

A defensible file should show what was checked and when. That means the SDN result, the ownership/control result, the Part 560 provision, any blocked-property analysis, the secondary-sanctions screen, the sector determination check, the license text, any tariff review, and the final approver. The file should also show what was not decided. If counsel has not reached a view on a non-US party’s secondary-sanctions exposure, the approval record should not imply that it has.

This is where OFAC’s five compliance components become operational rather than decorative. Management commitment funds the map. Risk assessment decides which Iran touchpoints get enhanced review. Internal controls stop unsupported approvals. Testing and auditing find stale licenses and broken screening assumptions. Training teaches business teams why “no SDN hit” is not the same as “no Iran issue.”[6]

The question to ask

A company cannot ask, in the abstract, whether it is “covered by Iran sanctions.” The answer depends on the layer. Which legal authority applies? What US nexus exists? Which entity is acting? Is a US person approving, supporting, facilitating, exporting, reexporting, importing, paying, insuring, or blocking? Is a foreign subsidiary owned or controlled by a US person? Is the counterparty, sector, bank, property interest, or import article covered by a newer determination, license change, designation, or tariff measure? When was the source last verified?

That is the compliance answer the Iran framework requires: not one moral weather report, but a current, source-linked map of enforceable hooks.

References

  1. Iran Sanctions, U.S. Department of the Treasury, Office of Foreign Assets Control
  2. 31 CFR Part 560 — Iranian Transactions and Sanctions Regulations, eCFR
  3. Addressing Threats to the United States by the Government of Iran, Federal Register, February 11, 2026
  4. U.S. Sanctions on Iran, Congressional Research Service via LegiStorm
  5. Sanctions by the Numbers: U.S. Secondary Sanctions, Center for a New American Security
  6. A Framework for OFAC Compliance Commitments, U.S. Department of the Treasury, Office of Foreign Assets Control, 2019

Operationalizing workflow

No workflow has been explicitly linked to this obligation yet. See Workflows generally.

Illustrative cases

No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.

← Back to Regulation

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →