Buying a Sanctions Violation, Part 2: When Diligence Misses the Problem, or Finds It and Still Can’t Stop It

Part 1 of this series drew the analogy between buying an FCPA problem and buying a sanctions problem, explained why sanctions are worse because ownership by a U.S. person can itself create jurisdiction, and reviewed what OFAC’s 2019 Framework for Compliance Commitments says about mergers and acquisitions. Part 2 turns to the enforcement record. The four cases below share a common feature: in each one, a sophisticated acquirer completed a deal, and a sanctions problem surfaced afterward. In two of them, the diligence never saw the problem. In one, diligence saw it and the acquirer’s safeguards still failed. In the fourth, the problem was sitting in plain view on the day of closing and integration was too slow to catch it.
Unicat and White Deer: The First Declination, and a Very Expensive One for the Target
The most recent and most instructive case involves Unicat Catalyst Technologies, a Texas manufacturer of chemical catalysts used in refining and steel production. According to the government’s announcements, Unicat’s co-founder and chief executive led a scheme, running from 2014 into 2021, to sell to customers in Iran, Venezuela, Syria, and Cuba, generating roughly $3.3 million in revenue. The company’s founder concealed the activity by creating false records.
In September 2020, the private equity firm White Deer Management acquired Unicat. Before closing, White Deer hired outside counsel to conduct diligence on Unicat’s international operations. That diligence did not uncover the sanctions problem. The sellers also gave contractual representations that the company was compliant with sanctions and export control laws. As later described, a historical sales agent agreement tied to Iran had in fact been provided to White Deer in the data room before closing but was overlooked. The problem surfaced in mid-2021, when Unicat’s new chief executive, visiting the business, spotted a pending transaction with an Iranian customer and canceled it. White Deer and the new executive then retained counsel, investigated, and found multiple illegal sales.
What happened next is the part that makes this case worth studying. White Deer self-disclosed to the Justice Department’s National Security Division about ten months after closing and roughly one month after learning of the problem, and it also disclosed to OFAC and the Commerce Department’s Bureau of Industry and Security. Unicat also disclosed a customs scheme in which invoices had understated the value of imports. In June 2025, the Justice Department announced that it had declined to prosecute White Deer, the first such declination of an acquirer under the NSD’s M&A policy. The department cited the firm’s prompt disclosure, what it called exceptional cooperation, including collecting evidence from personal devices and from overseas in compliance with foreign data privacy laws, and the firm’s remediation, including terminating the prior management responsible. Unicat’s former chief executive pleaded guilty.

But look at what the target paid. Unicat entered a non-prosecution agreement and forfeited about $3.3 million. OFAC imposed a civil penalty of roughly $3.9 million, with the forfeiture credited against most of it. BIS imposed a penalty of about $391,000, and customs authorities collected roughly $1.7 million in underpaid duties and fees. Even for an acquirer that did nearly everything right after discovering the problem, the company it had purchased bore millions in costs. For the buyer, those costs are real: they land on the balance sheet of the business it owns. The lesson is not that disclosure is a bad idea. The lesson is that disclosure protects the acquirer from prosecution while the purchase price, and your indemnity, are what protect you from the cost.
Murad and Unilever: A Problem That Outlived the Acquisition by More Than Two Years
The Murad matter involves a skincare and supplements company based in California. According to OFAC, from late 2009 into January 2018, Murad worked with two distributors, one in Iran and later its affiliate in the United Arab Emirates, to supply Murad products to Iran. The distributors made at least 62 exports, worth roughly $11 million.
Unilever’s U.S. subsidiary acquired Murad in September 2015. Murad did not tell its new owner about the Iran business, and Unilever’s pre-acquisition diligence did not find it. The activity then continued under Unilever’s ownership until early 2018. In February 2018, Unilever submitted a voluntary self-disclosure to OFAC. In May 2023, OFAC settled with Murad for about $3.33 million, treating the case as egregious, and separately settled with a former senior executive for $175,000.
Two points stand out. First, the violating activity was run by Murad itself, a U.S. company, so this was a classic inherited-liability case rather than a jurisdiction-trigger case. Second, the violations continued for roughly two and a half years after closing. The acquirer’s knowledge was nil, and the target’s managers were hiding the business. It illustrates a point I made in Part 1: the post-closing audit and testing function the 2019 Framework describes is meant to find precisely this kind of continuation, and the penalty here fell on the acquired company, which was by then part of a global consumer-products group.
It also shows the individual dimension. A senior executive of the acquired business was separately penalized, a reminder that the people who run the target’s compliance blind spot are exposed too.
Kollmorgen: The Acquirer Found the Iran Exposure in Diligence and Still Lost
The 2019 Kollmorgen settlement is the case I would show any deal team that believes diligence plus controls is enough. Kollmorgen, a Virginia-based company, acquired a Turkish business, Elsim Elektroteknik, in early 2013. Unlike the acquirers above, Kollmorgen’s diligence, performed with outside counsel and auditors, did find that Elsim had Iranian customers. Kollmorgen then did the things the playbook calls for. It blocked Iranian customers from ordering, notified Elsim’s employees about U.S. sanctions, required Elsim’s senior managers to certify quarterly that nothing was being supplied to Iran, and set up an ethics hotline.
None of it worked. Between July 2013 and July 2015, Elsim serviced machines in Iran and supplied parts and services with knowledge that they were headed to Iranian end users, a small volume in dollar terms, about $14,900 across six transactions. Elsim’s managers directed employees to falsify records, and they gave Kollmorgen false certifications. When an employee used the hotline, Kollmorgen investigated, and Elsim’s managers tried to obstruct that investigation by telling employees to remove references to Iran, misleading Kollmorgen’s lawyers, and deleting emails.

OFAC’s response had two parts. It imposed a modest penalty of about $13,400, which reflected Kollmorgen’s extensive efforts and its voluntary disclosure, and it treated Kollmorgen’s own conduct as non-egregious. And, in an unprecedented step, it designated Elsim’s managing director as a Foreign Sanctions Evader, the first time OFAC paired a corporate settlement with the designation of a foreign individual. The message to acquirers was dual: even excellent controls may not prevent a determined local management team from violating sanctions, and the penalty to the acquirer can nonetheless be mitigated if the acquirer’s response is strong. The message to individuals was that the exposure follows them personally.
S&P Global and PIRA: Integration Speed
The fourth case is smaller in dollars but has a clear integration lesson. In August 2016, S&P Global acquired Petroleum Industry Research Associates, a U.S. research firm. PIRA had billed Rosneft, the Russian state-owned oil company subject to OFAC’s sectoral sanctions, in 2015, and Rosneft had not paid. The sanctions restricted dealing in Rosneft debt with maturity longer than 90 days. When Rosneft’s payment attempts were rejected by banks, PIRA staff suggested alternative payment methods. After the acquisition, former PIRA employees, now working for S&P Global, reissued and redated the old invoice, and then did so again with split invoices and again in 2017, in order to receive the money. Internal messages, according to OFAC, recognized that payment against an old invoice could look like an extension of credit to a Russian company. S&P Global received about $82,500 and did not voluntarily disclose. It settled with OFAC in April 2022 for $78,750.
This is a much smaller case than Unicat or Murad, but it shows how fast things can go wrong. The first reissued invoice appeared in the very month of the acquisition. The compliance program had not yet been extended to the new employees, and staff continued the workaround they had designed before closing. OFAC’s announcement stressed the need for U.S. companies to conduct sanctions diligence and then take active steps to extend compliance programs, including training and monitoring, to newly acquired businesses and their employees.
What the Four Cases Teach Reading the four together, a few lessons emerge. Contractual representations and seller certifications are not diligence; Unicat’s sellers and Murad’s managers each gave comfort that turned out to be wrong. Data rooms contain the answer more often than deal teams realize, and the Unicat Iran sales agency agreement was apparently sitting in the data room. Controls that rely on the target’s own managers to self-certify will fail when those managers are the problem, as Kollmorgen shows. And integration clocks start on closing day, as S&P Global shows. Part 3 looks at the other category of case: where the acquisition itself switched on U.S. jurisdiction and the foreign target kept doing what it had always done.











