Author: Sam Finkelstein

Nasdaq Settles Iran Sanctions Violations for Pennies on the Dollar, Thanks to Voluntary Disclosure

Nasdaq Settles Iran Sanctions Violations for Pennies on the Dollar, Thanks to Voluntary Disclosure

When it comes to OFAC sanctions violations, honesty is the best policy. Promptly and voluntarily disclosing violations upon their discovery can pay serious dividends. So was the case for Nasdaq, Inc., which this week settled Iran sanctions violations in what could have been a $458 million OFAC penalty, for just $4.04 million, less than 1% of the applicable statutory maximum.  For those who view compliance...

The EU Corporate Sustainability Reporting Directive is (Almost) Here. Is Your Company Ready?

The EU Corporate Sustainability Reporting Directive is (Almost) Here. Is Your Company Ready?

On January 1, 2024, the long-awaited EU Corporate Sustainability Reporting Directive (“CSRD”) begins to take effect. The CSRD is intended to redefine corporate social responsibility expectations for both in-scope companies and out-of-scope third-parties with whom they transact. This regulatory overhaul concentrates enforcement efforts on global supply chains, requiring in-scope companies to take an active role in safeguarding human rights not just within their own operations,...

OFAC Settlement with DaVinci Payments Is Wake-Up Call for Prepaid Access Industry

OFAC Settlement with DaVinci Payments Is Wake-Up Call for Prepaid Access Industry

Rewards programs have become ubiquitous in recent years. These so-called loyalty management programs exist to nudge customers or employees in a particular direction; a company’s workers might be inclined to exercise more regularly, for example, if they know there is a $5 gift card waiting for them after a specified number of gym check-ins. Their rapid expansion and cash-equivalent, pre-paid nature make loyalty management programs...

SEC Sues SolarWinds and its CISO for Fraud Over Botched Data Breach Response, Marking New Era in Cyber Enforcement

SEC Sues SolarWinds and its CISO for Fraud Over Botched Data Breach Response, Marking New Era in Cyber Enforcement

The U.S. Securities and Exchange Commission has a message for publicly-traded companies that suffer a data breach: own up. On Monday, the SEC sued Texas-based SolarWinds––and its Chief Information Security Officer (“CISO”)––for defrauding investors by allegedly failing to disclose known security risks in public filings. This marks the SEC’s first ever enforcement action against an individual corporate officer over their mishandling of a data breach––but...