Skip to content
RiskTemplates · The Daily Brief Monday, September 21, 2026
Wire Nodus Bank CEO Sentenced: The Control Failures Behind a $24.9M Fraud and Sanctions Scheme SEP 20

Breaking Regulatory Compliance

Nodus Bank CEO Sentenced: The Control Failures Behind a $24.9M Fraud and Sanctions Scheme

The Nodus Bank fraud mixed insider self-dealing with sanctions evasion. Here are the controls bank boards and compliance teams should test now.

By Rebecca Leung · September 21, 2026 ·
Table of Contents

TL;DR

  • Former Nodus International Bank CEO Tomás Niembro Concha received 112 months in prison on September 21, 2026, plus three years of supervised release.
  • DOJ said he led a scheme to obtain at least $24.9 million from the bank and ordered forfeiture of more than $16.9 million.
  • The same case included a prohibited plan to sell a foreclosed New York home back to a Treasury-designated person for $4 million through a front company.
  • The practitioner lesson is not “screen harder.” It is to connect insider-benefit detection, board independence, transaction purpose, beneficial ownership, license scope, and issue escalation.

The Nodus Bank fraud is what happens when conflicts, credit approval, and sanctions compliance are treated as separate control programs.

On September 21, the Justice Department announced the sentencing of former Nodus International Bank CEO Tomás Niembro Concha. He received 112 months in prison and three years of supervised release. The court ordered him to forfeit more than $16.9 million, representing the proceeds DOJ said he derived from the wire-fraud conspiracy.

The headline numbers are ugly. The control design is worse.

According to DOJ, Niembro and his co-conspirators concealed transactions benefiting Niembro and Nodus Bank Board Chairman Juan Ramirez from other directors, executives, and the bank’s Puerto Rico regulator. One structure used a bank investment in a lender. Another used dozens of promissory notes purchased from a company the two insiders owned. A third converted an OFAC-authorized foreclosure into an alleged plan to return the property to a sanctioned person through a front company.

Each transaction could look explainable when reviewed in its own silo. Together, they describe a bank whose controls could not reliably answer three basic questions: Who benefits? Who approved it? Is the transaction actually within the permission being claimed?

What happened in the Nodus Bank fraud

The March 20 DOJ guilty-plea release provides the clearest chronology. Niembro pleaded guilty to conspiracy to commit wire fraud and conspiracy to violate the International Emergency Economic Powers Act, or IEEPA.

PeriodDOJ’s descriptionControl question that should have stopped it
2017–2023Nodus Bank invested $11 million in a Miami-based lender so funds could be loaned to Niembro and RamirezDid independent reviewers identify the ultimate borrowers and executive benefit?
Jan. 2018–Sept. 2021The bank bought at least 47 promissory notes totaling about $25.3 million from Nodus Finance, which Niembro and Ramirez jointly ownedWas common ownership disclosed, independently validated, and excluded from insider influence?
Early March 2023After Puerto Rico’s Office of the Commissioner of Financial Institutions notified the bank that it would be liquidated, the bank accepted a loan portfolio from Nodus Finance to pay down the note debtWho validated the portfolio, valuation, collectability, and transaction purpose under liquidation pressure?
2021–2023Niembro conspired to transact with a person designated by Treasury for supporting Venezuela’s state-owned oil company, PDVSADid sanctions review cover the economic substance and the full sequence, not just the first licensed step?

DOJ said the scheme ultimately led to Nodus Bank’s failure in 2023. That is an allegation incorporated into Niembro’s guilty plea and sentencing record, not a general statement that every control weakness causes a bank failure.

The figures also need careful reading. The $11 million investment and approximately $25.3 million in promissory notes describe components of the conduct. They should not be casually added to claim a larger loss. DOJ’s stated overall figure is at least $24.9 million fraudulently obtained, while the forfeiture order exceeds $16.9 million.

The sanctions transaction was a purpose-control failure

The sanctions conduct is unusually useful for compliance teams because the initial foreclosure had OFAC authorization.

DOJ said an OFAC-designated person’s company owed Nodus Bank approximately $2.5 million before sanctions were imposed. Niembro and the designated person arranged for the bank to foreclose on the person’s Southampton, New York home, and they obtained OFAC authorization for that foreclosure. But DOJ said they separately reached a private agreement for the bank to sell the property back to the designated person for $4 million through a front company. That resale was prohibited and not otherwise licensed.

This is the distinction the case should force into sanctions procedures:

Weak controlDefensible control
Store the OFAC authorization in the file and mark the matter approvedTranslate the authorization into permitted parties, property, actions, amounts, dates, and conditions
Screen the named buyerIdentify the buyer’s beneficial owners, controllers, source of funds, and relationship to the prior owner
Review each step as a separate transactionReview the foreclosure, holding period, resale, payment path, and end beneficiary as one economic sequence
Ask whether a transaction has a licenseAsk whether this exact transaction is within the license’s scope
Close the alert after Legal approves the first stepRequire reapproval when the counterparty, amount, ownership, or transaction purpose changes

The statutory text of 50 U.S.C. § 1705 makes it unlawful to violate, attempt to violate, conspire to violate, or cause a violation of a license, order, regulation, or prohibition issued under IEEPA. It also provides for imprisonment of up to 20 years for a natural person who willfully commits or conspires to commit an unlawful act. Niembro’s IEEPA-conspiracy charge carried that maximum; his actual combined sentence was 112 months.

A license is not a blanket clearance for the business objective around it. Compliance needs a license-conditions register tied to transaction monitoring and change control. If operations can substitute a front company after approval without sending the deal back to sanctions counsel, the approval workflow is cosmetic.

Four controls that should connect—but often do not

1. Conflict declarations must reconcile to transaction data

Annual director and officer questionnaires are not enough. The bank needs an event-driven related-party inventory containing legal entities, ownership percentages, control roles, family or business connections where applicable, and customer identifiers used in every booking system.

The control test is straightforward: take the executive and director population, map every connected legal entity, and match it against loans, investments, note purchases, vendor payments, and recoveries. Unmatched entities become exceptions. Changes in ownership or outside business interests should trigger updates before the next annual certification.

A realistic evidence package includes the signed declaration, corporate records, beneficial-ownership support, system IDs, the match output, reviewer disposition, and escalation record. For broader insider-credit design, the site’s Regulation O control walkthrough explains why relationship aggregation and abstention evidence matter even when a transaction sits under a visible dollar threshold.

2. Recusal must remove influence, not merely record an abstention

A board minute saying an interested director “abstained” proves very little if that person originated the proposal, selected the counterparty, supplied the valuation, negotiated the terms, or pressured staff before the vote.

The Corporate Secretary and General Counsel should document an influence perimeter for each related-party deal:

  • when the conflict was disclosed;
  • which materials the interested person could access;
  • whether that person left the meeting;
  • who selected independent advisers;
  • who validated pricing and credit quality;
  • how questions and dissent were recorded;
  • who monitored performance after approval.

The practical test is to trace the transaction before, during, and after formal approval. Recusal is a process, not one line in minutes.

3. Asset substitutions need independent valuation and collectability testing

DOJ said Nodus Bank accepted a loan portfolio from insider-owned Nodus Finance after the regulator notified the bank that liquidation was coming. A portfolio transfer under that pressure demands more than a spreadsheet of face values.

Credit Risk—not the transaction sponsor—should validate borrower identity, payment history, delinquency, collateral, lien priority, concentration, legal enforceability, expected cash flow, and any relationship to insiders. Finance should reconcile carrying value to the general ledger. Internal Audit or an independent third party should sample the underlying files.

A useful acceptance memo shows both gross face value and independently supported recoverable value. It also records rejected assets and exceptions. Without that evidence, a “debt repayment” can be an exchange of a collectible obligation for assets that are difficult or impossible to recover.

4. Sanctions escalation must test economic beneficiaries

Name screening would not necessarily expose a front company formed or used to repurchase property. The bank needs beneficial-ownership review and purpose testing when a deal involves a previously blocked or licensed asset, a designated person’s former property, an unusual special-purpose entity, or funds supplied by an unexplained third party.

OFAC’s Framework for OFAC Compliance Commitments identifies five essential components: management commitment, risk assessment, internal controls, testing and auditing, and training. In this fact pattern, those components meet in one file. Management cannot override the sanctions function; risk assessment must recognize designated-person and Venezuela exposure; controls must enforce license scope; testing must trace the sequence; and staff must know that a new buyer does not erase the original sanctions concern.

For a deeper program review, use the OFAC risk assessment walkthrough and the site’s guide to sanctions screening beyond exact-name matching.

Five tests to run this week

TestOwnerEvidence to retainFailure trigger
Match directors, executives, and related entities against all loans, investments, notes, vendors, and asset salesCompliance + DataPopulation, matching logic, exceptions, dispositionsAny undeclared relationship or manual-only match
Review transactions where an insider proposed or influenced both sidesGeneral Counsel + Corporate SecretaryConflict analysis, recusal timeline, independent approvalInterested person influenced valuation, adviser selection, or vote
Revalue assets accepted from insiders or affiliatesCredit Risk + FinanceFile sample, valuation support, collectability analysis, GL reconciliationUnsupported face value, missing files, related borrowers, or delinquency
Inventory open and closed OFAC licenses and authorizationsSanctions OfficerConditions register linked to transactions and alertsTransaction step, party, amount, or purpose falls outside documented scope
Search for front companies tied to blocked persons or licensed assetsFinancial Crimes + InvestigationsBeneficial-ownership records, source-of-funds evidence, network analysisNew entity lacks business purpose or returns value to a designated person

Do not wait for all five tests to finish before opening issues. If the related-party population is incomplete on day one, log that gap with an accountable owner, interim control, severity, and due date. If sanctions-license conditions are trapped in Legal’s email, create the register now and restrict affected transactions until the scope is operationalized.

A 30/60/90-day remediation plan

Days 1–30: Find the hidden relationships. The CCO and Corporate Secretary should certify the insider population; Data should run relationship matching; the Sanctions Officer should inventory licensed activity; and Credit Risk should identify insider-originated investments, notes, and asset substitutions. Deliver a single exception register rather than four disconnected workpapers.

Days 31–60: Reperform the decisions. Independent reviewers should reconstruct approval, valuation, beneficial ownership, transaction purpose, license scope, and recusal for the highest-risk exceptions. Internal Audit should select samples based on executive influence and unusual structure, not random volume alone.

Days 61–90: Prove the fix operates. Compliance Testing should rerun the matching logic, test that changed parties route back for approval, verify overdue issues escalate, and present results to directors who were not involved in the original decisions. Closure evidence should show the control operated on real transactions—not merely that a policy was rewritten.

The Nodus Bank case is not primarily a screening story or an insider-lending story. It is a control-connection story. A bank can have a conflicts policy, board approvals, an OFAC process, and a credit review function while still failing if none of them shares the same picture of who benefits from the transaction.

Start with that picture. Then make every approval, screen, valuation, and issue record trace back to it.

If your review produces a pile of disconnected findings, use the Issues Management Tracker & Template to assign owners, preserve closure evidence, and stop high-risk exceptions from disappearing between Legal, Credit, and Compliance.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What sentence did the former Nodus Bank CEO receive?
On September 21, 2026, a federal judge sentenced former Nodus International Bank CEO Tomás Niembro Concha to 112 months in prison and three years of supervised release. The court also ordered him to forfeit more than $16.9 million.
How much money did the Nodus Bank fraud involve?
The Justice Department said Niembro led a scheme to fraudulently obtain at least $24.9 million from Nodus Bank. The conduct included an $11 million investment routed through a Miami lender and at least 47 promissory notes totaling approximately $25.3 million, although those figures describe overlapping parts of the charged scheme and should not be added together.
How did the Nodus Bank case involve sanctions evasion?
DOJ said Niembro and a Treasury-designated person arranged for Nodus Bank to foreclose on a Southampton, New York home under OFAC authorization, then privately planned to sell the property back to that person for $4 million through a front company. DOJ said the resale was prohibited and not licensed by OFAC.
What were the main control failures in the Nodus Bank case?
The alleged facts point to failures in conflict-of-interest identification, related-party transaction review, independent board challenge, beneficial-ownership verification, sanctions-license scope controls, and escalation. A bank should test those controls as one connected system rather than as separate credit, governance, and OFAC processes.
What should a bank board ask after the Nodus Bank sentencing?
The board should ask for a complete related-party population, all executive-benefit transactions matched to approvals, a list of deals relying on OFAC licenses, independent evidence of beneficial ownership for unusual counterparties, and open issues with owners and due dates.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

● Don't wait for your own enforcement action

Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.