Breaking Regulatory Compliance
Nodus Bank CEO Sentenced: The Control Failures Behind a $24.9M Fraud and Sanctions Scheme
The Nodus Bank fraud mixed insider self-dealing with sanctions evasion. Here are the controls bank boards and compliance teams should test now.
Table of Contents
TL;DR
- Former Nodus International Bank CEO Tomás Niembro Concha received 112 months in prison on September 21, 2026, plus three years of supervised release.
- DOJ said he led a scheme to obtain at least $24.9 million from the bank and ordered forfeiture of more than $16.9 million.
- The same case included a prohibited plan to sell a foreclosed New York home back to a Treasury-designated person for $4 million through a front company.
- The practitioner lesson is not “screen harder.” It is to connect insider-benefit detection, board independence, transaction purpose, beneficial ownership, license scope, and issue escalation.
The Nodus Bank fraud is what happens when conflicts, credit approval, and sanctions compliance are treated as separate control programs.
On September 21, the Justice Department announced the sentencing of former Nodus International Bank CEO Tomás Niembro Concha. He received 112 months in prison and three years of supervised release. The court ordered him to forfeit more than $16.9 million, representing the proceeds DOJ said he derived from the wire-fraud conspiracy.
The headline numbers are ugly. The control design is worse.
According to DOJ, Niembro and his co-conspirators concealed transactions benefiting Niembro and Nodus Bank Board Chairman Juan Ramirez from other directors, executives, and the bank’s Puerto Rico regulator. One structure used a bank investment in a lender. Another used dozens of promissory notes purchased from a company the two insiders owned. A third converted an OFAC-authorized foreclosure into an alleged plan to return the property to a sanctioned person through a front company.
Each transaction could look explainable when reviewed in its own silo. Together, they describe a bank whose controls could not reliably answer three basic questions: Who benefits? Who approved it? Is the transaction actually within the permission being claimed?
What happened in the Nodus Bank fraud
The March 20 DOJ guilty-plea release provides the clearest chronology. Niembro pleaded guilty to conspiracy to commit wire fraud and conspiracy to violate the International Emergency Economic Powers Act, or IEEPA.
| Period | DOJ’s description | Control question that should have stopped it |
|---|---|---|
| 2017–2023 | Nodus Bank invested $11 million in a Miami-based lender so funds could be loaned to Niembro and Ramirez | Did independent reviewers identify the ultimate borrowers and executive benefit? |
| Jan. 2018–Sept. 2021 | The bank bought at least 47 promissory notes totaling about $25.3 million from Nodus Finance, which Niembro and Ramirez jointly owned | Was common ownership disclosed, independently validated, and excluded from insider influence? |
| Early March 2023 | After Puerto Rico’s Office of the Commissioner of Financial Institutions notified the bank that it would be liquidated, the bank accepted a loan portfolio from Nodus Finance to pay down the note debt | Who validated the portfolio, valuation, collectability, and transaction purpose under liquidation pressure? |
| 2021–2023 | Niembro conspired to transact with a person designated by Treasury for supporting Venezuela’s state-owned oil company, PDVSA | Did sanctions review cover the economic substance and the full sequence, not just the first licensed step? |
DOJ said the scheme ultimately led to Nodus Bank’s failure in 2023. That is an allegation incorporated into Niembro’s guilty plea and sentencing record, not a general statement that every control weakness causes a bank failure.
The figures also need careful reading. The $11 million investment and approximately $25.3 million in promissory notes describe components of the conduct. They should not be casually added to claim a larger loss. DOJ’s stated overall figure is at least $24.9 million fraudulently obtained, while the forfeiture order exceeds $16.9 million.
The sanctions transaction was a purpose-control failure
The sanctions conduct is unusually useful for compliance teams because the initial foreclosure had OFAC authorization.
DOJ said an OFAC-designated person’s company owed Nodus Bank approximately $2.5 million before sanctions were imposed. Niembro and the designated person arranged for the bank to foreclose on the person’s Southampton, New York home, and they obtained OFAC authorization for that foreclosure. But DOJ said they separately reached a private agreement for the bank to sell the property back to the designated person for $4 million through a front company. That resale was prohibited and not otherwise licensed.
This is the distinction the case should force into sanctions procedures:
| Weak control | Defensible control |
|---|---|
| Store the OFAC authorization in the file and mark the matter approved | Translate the authorization into permitted parties, property, actions, amounts, dates, and conditions |
| Screen the named buyer | Identify the buyer’s beneficial owners, controllers, source of funds, and relationship to the prior owner |
| Review each step as a separate transaction | Review the foreclosure, holding period, resale, payment path, and end beneficiary as one economic sequence |
| Ask whether a transaction has a license | Ask whether this exact transaction is within the license’s scope |
| Close the alert after Legal approves the first step | Require reapproval when the counterparty, amount, ownership, or transaction purpose changes |
The statutory text of 50 U.S.C. § 1705 makes it unlawful to violate, attempt to violate, conspire to violate, or cause a violation of a license, order, regulation, or prohibition issued under IEEPA. It also provides for imprisonment of up to 20 years for a natural person who willfully commits or conspires to commit an unlawful act. Niembro’s IEEPA-conspiracy charge carried that maximum; his actual combined sentence was 112 months.
A license is not a blanket clearance for the business objective around it. Compliance needs a license-conditions register tied to transaction monitoring and change control. If operations can substitute a front company after approval without sending the deal back to sanctions counsel, the approval workflow is cosmetic.
Four controls that should connect—but often do not
1. Conflict declarations must reconcile to transaction data
Annual director and officer questionnaires are not enough. The bank needs an event-driven related-party inventory containing legal entities, ownership percentages, control roles, family or business connections where applicable, and customer identifiers used in every booking system.
The control test is straightforward: take the executive and director population, map every connected legal entity, and match it against loans, investments, note purchases, vendor payments, and recoveries. Unmatched entities become exceptions. Changes in ownership or outside business interests should trigger updates before the next annual certification.
A realistic evidence package includes the signed declaration, corporate records, beneficial-ownership support, system IDs, the match output, reviewer disposition, and escalation record. For broader insider-credit design, the site’s Regulation O control walkthrough explains why relationship aggregation and abstention evidence matter even when a transaction sits under a visible dollar threshold.
2. Recusal must remove influence, not merely record an abstention
A board minute saying an interested director “abstained” proves very little if that person originated the proposal, selected the counterparty, supplied the valuation, negotiated the terms, or pressured staff before the vote.
The Corporate Secretary and General Counsel should document an influence perimeter for each related-party deal:
- when the conflict was disclosed;
- which materials the interested person could access;
- whether that person left the meeting;
- who selected independent advisers;
- who validated pricing and credit quality;
- how questions and dissent were recorded;
- who monitored performance after approval.
The practical test is to trace the transaction before, during, and after formal approval. Recusal is a process, not one line in minutes.
3. Asset substitutions need independent valuation and collectability testing
DOJ said Nodus Bank accepted a loan portfolio from insider-owned Nodus Finance after the regulator notified the bank that liquidation was coming. A portfolio transfer under that pressure demands more than a spreadsheet of face values.
Credit Risk—not the transaction sponsor—should validate borrower identity, payment history, delinquency, collateral, lien priority, concentration, legal enforceability, expected cash flow, and any relationship to insiders. Finance should reconcile carrying value to the general ledger. Internal Audit or an independent third party should sample the underlying files.
A useful acceptance memo shows both gross face value and independently supported recoverable value. It also records rejected assets and exceptions. Without that evidence, a “debt repayment” can be an exchange of a collectible obligation for assets that are difficult or impossible to recover.
4. Sanctions escalation must test economic beneficiaries
Name screening would not necessarily expose a front company formed or used to repurchase property. The bank needs beneficial-ownership review and purpose testing when a deal involves a previously blocked or licensed asset, a designated person’s former property, an unusual special-purpose entity, or funds supplied by an unexplained third party.
OFAC’s Framework for OFAC Compliance Commitments identifies five essential components: management commitment, risk assessment, internal controls, testing and auditing, and training. In this fact pattern, those components meet in one file. Management cannot override the sanctions function; risk assessment must recognize designated-person and Venezuela exposure; controls must enforce license scope; testing must trace the sequence; and staff must know that a new buyer does not erase the original sanctions concern.
For a deeper program review, use the OFAC risk assessment walkthrough and the site’s guide to sanctions screening beyond exact-name matching.
Five tests to run this week
| Test | Owner | Evidence to retain | Failure trigger |
|---|---|---|---|
| Match directors, executives, and related entities against all loans, investments, notes, vendors, and asset sales | Compliance + Data | Population, matching logic, exceptions, dispositions | Any undeclared relationship or manual-only match |
| Review transactions where an insider proposed or influenced both sides | General Counsel + Corporate Secretary | Conflict analysis, recusal timeline, independent approval | Interested person influenced valuation, adviser selection, or vote |
| Revalue assets accepted from insiders or affiliates | Credit Risk + Finance | File sample, valuation support, collectability analysis, GL reconciliation | Unsupported face value, missing files, related borrowers, or delinquency |
| Inventory open and closed OFAC licenses and authorizations | Sanctions Officer | Conditions register linked to transactions and alerts | Transaction step, party, amount, or purpose falls outside documented scope |
| Search for front companies tied to blocked persons or licensed assets | Financial Crimes + Investigations | Beneficial-ownership records, source-of-funds evidence, network analysis | New entity lacks business purpose or returns value to a designated person |
Do not wait for all five tests to finish before opening issues. If the related-party population is incomplete on day one, log that gap with an accountable owner, interim control, severity, and due date. If sanctions-license conditions are trapped in Legal’s email, create the register now and restrict affected transactions until the scope is operationalized.
A 30/60/90-day remediation plan
Days 1–30: Find the hidden relationships. The CCO and Corporate Secretary should certify the insider population; Data should run relationship matching; the Sanctions Officer should inventory licensed activity; and Credit Risk should identify insider-originated investments, notes, and asset substitutions. Deliver a single exception register rather than four disconnected workpapers.
Days 31–60: Reperform the decisions. Independent reviewers should reconstruct approval, valuation, beneficial ownership, transaction purpose, license scope, and recusal for the highest-risk exceptions. Internal Audit should select samples based on executive influence and unusual structure, not random volume alone.
Days 61–90: Prove the fix operates. Compliance Testing should rerun the matching logic, test that changed parties route back for approval, verify overdue issues escalate, and present results to directors who were not involved in the original decisions. Closure evidence should show the control operated on real transactions—not merely that a policy was rewritten.
The Nodus Bank case is not primarily a screening story or an insider-lending story. It is a control-connection story. A bank can have a conflicts policy, board approvals, an OFAC process, and a credit review function while still failing if none of them shares the same picture of who benefits from the transaction.
Start with that picture. Then make every approval, screen, valuation, and issue record trace back to it.
If your review produces a pile of disconnected findings, use the Issues Management Tracker & Template to assign owners, preserve closure evidence, and stop high-risk exceptions from disappearing between Legal, Credit, and Compliance.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What sentence did the former Nodus Bank CEO receive?
How much money did the Nodus Bank fraud involve?
How did the Nodus Bank case involve sanctions evasion?
What were the main control failures in the Nodus Bank case?
What should a bank board ask after the Nodus Bank sentencing?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
● Don't wait for your own enforcement action
Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Regulatory Compliance
FDIC Just Proposed Faster Bank Merger Reviews. Here's What Community Banks, Sponsor Banks, and Their Fintech Partners Need to Know.
The FDIC's September 17, 2026 proposed rule would cut bank merger review to as little as five business days for small deals and create a predictable 90-day track for standard transactions. Here's what state nonmember banks — and the fintechs that partner with them — need to understand before the 60-day comment window closes.
Sep 21, 2026
Regulatory Compliance
Vitol Trader Sentenced in FCPA Bribery Scheme: The Payment Controls That Failed
The Vitol bribery scheme used sham invoices, shell companies, and alias email. Here is how compliance teams should test anti-bribery payment controls.
Sep 21, 2026
Regulatory Compliance
The BSA's Biggest Overhaul in Decades Just Cleared Its Last Comment Deadline. Here's What the FinCEN Program Reform NPRM Actually Changes.
FinCEN's April 2026 NPRM to fundamentally reform AML/CFT programs — combined with the Federal Reserve's companion rulemaking, whose comment period just closed September 8 — is the most significant BSA update since the PATRIOT Act. Here's what effectiveness-based evaluation means for your compliance program.
Sep 20, 2026